* [OE-core][wrynose 00/38] Patch review
@ 2026-09-09 7:28 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
` (37 more replies)
0 siblings, 38 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:28 UTC (permalink / raw)
To: openembedded-core
Please review this set of changes for wrynose and have comments back by
end of day Friday, September 11.
Passed a-full on autobuilder:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/29/builds/4697
The following changes since commit 31def396136be047e10c507a50264aad52ba6b0f:
scripts/install-buildtools: Update to 6.0.3 (2026-09-04 16:21:55 +0200)
are available in the Git repository at:
https://git.openembedded.org/openembedded-core-contrib stable/wrynose-nut
https://git.openembedded.org/openembedded-core-contrib/log/?h=stable/wrynose-nut
for you to fetch changes up to 4ce10a99a44924dd629fbd79268207b145ccfc62:
gawk: skip randtest in ptest suite (2026-09-09 00:58:52 +0200)
----------------------------------------------------------------
Adarsh Jagadish Kamini (1):
gnutls: fix CVE-2026-33845
Ankur Tyagi (1):
wpa-supplicant: patch CVE-2026-58374
Bruce Ashfield (4):
linux-yocto/6.18: update to v6.18.41
linux-yocto/6.18: update to v6.18.43
linux-yocto/6.18: update to v6.18.44
linux-yocto/6.18: update to v6.18.48
Daniel Turull (1):
libarchive: mark CVE-2026-14164 as fixed-version
Darsh Kelaiya (1):
python3-lxml: fix CVE-2026-41066
Ghanshyam Banait (1):
wget: fix CVE-2026-16599
Harish Sadineni (1):
glibc: fix CVE-2026-19542
Hetvi Thakar (7):
python3-pip: Fix CVE-2026-13346
u-boot-tools: Ignore CVE-2026-29007
u-boot-tools: Ignore CVE-2026-29008
u-boot-tools: Ignore CVE-2026-29009
u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix
wget: Fix CVE-2026-58470
python3-pip: Fix CVE-2026-8643
Hiago De Franco (1):
improve_kernel_cve_report: fix backported-patch check
Himani Ramesh Barde (1):
gawk: skip randtest in ptest suite
Himanshu Jadon (1):
grub: disable grub-protect for native builds
Hitendra Prajapati (6):
vim: Fix for CVE-2026-73072
vim: Fix for CVE-2026-73073
vim: Fix for CVE-2026-73074
vim: Fix for CVE-2026-73076
vim: Fix for CVE-2026-73077
vim: Fix for CVE-2026-73078
Jaipaul Cheernam (1):
p11-kit: upgrade 0.26.4 -> 0.26.5
Peter Marko (4):
openssl: upgrade 3.5.7 -> 3.5.8
apr-util: upgrade 1.6.3 -> 1.6.5
curl: patch CVE-2026-11352
curl: patch CVE-2026-11586
Peter Tatrai (2):
testimage: handle bootlog variants on failed qemu tests
time64: enable 64-bit time/file-offset flags for 32-bit nativesdk
Pratik Farkase (1):
procps: ptest: skip flaky pgrep full process name match test
Vijay Anusuri (4):
libxfont: Fix CVE-2026-56001
libxfont: Fix CVE-2026-56002
libxfont: Fix CVE-2026-56003
perl: Fix CVE-2026-57433
meta/classes-recipe/testimage.bbclass | 27 +-
meta/conf/distro/include/time64.inc | 10 +
meta/recipes-bsp/grub/grub2.inc | 2 +
...-2026-33243.patch => CVE-2026-46728.patch} | 11 +-
.../u-boot/u-boot-tools_2026.01.bb | 8 +
meta/recipes-bsp/u-boot/u-boot_2026.01.bb | 4 +-
.../{openssl_3.5.7.bb => openssl_3.5.8.bb} | 2 +-
.../wpa-supplicant/CVE-2026-58374-1.patch | 52 +++
.../wpa-supplicant/CVE-2026-58374-2.patch | 47 +++
.../wpa-supplicant/CVE-2026-58374-3.patch | 55 +++
.../wpa-supplicant/CVE-2026-58374-4.patch | 46 +++
.../wpa-supplicant/CVE-2026-58374-5.patch | 47 +++
.../wpa-supplicant/wpa-supplicant_2.11.bb | 5 +
.../glibc/glibc/0023-CVE-2026-19542.patch | 98 +++++
meta/recipes-core/glibc/glibc_2.43.bb | 1 +
.../perl/files/CVE-2026-57433.patch | 32 ++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
.../python/python3-lxml/CVE-2026-41066.patch | 349 ++++++++++++++++++
.../python/python3-lxml_6.0.2.bb | 4 +-
.../python/python3-pip/CVE-2026-13346.patch | 206 +++++++++++
.../CVE-2026-8643-regression_p1.patch | 35 ++
.../CVE-2026-8643-regression_p2.patch | 69 ++++
.../python/python3-pip/CVE-2026-8643.patch | 80 ++++
.../python/python3-pip_26.0.1.bb | 7 +-
meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 +-
.../libarchive/libarchive_3.8.7.bb | 4 +
...p-pgrep-full-process-name-match-test.patch | 39 ++
meta/recipes-extended/procps/procps_4.0.6.bb | 1 +
.../wget/wget/CVE-2026-16599.patch | 68 ++++
.../wget/wget/CVE-2026-58470-regression.patch | 48 +++
.../wget/wget/CVE-2026-58470.patch | 79 ++++
meta/recipes-extended/wget/wget_1.25.0.bb | 3 +
.../xorg-lib/libxfont/CVE-2026-56001.patch | 87 +++++
.../xorg-lib/libxfont/CVE-2026-56002.patch | 150 ++++++++
.../xorg-lib/libxfont/CVE-2026-56003.patch | 114 ++++++
.../xorg-lib/libxfont_1.5.4.bb | 5 +
.../linux/linux-yocto-rt_6.18.bb | 6 +-
.../linux/linux-yocto-tiny_6.18.bb | 6 +-
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +-
...le-function-prototype-warning-with-c.patch | 130 -------
...ion-Check-if-transform-is-supported-.patch | 37 --
.../apr/apr-util/configfix.patch | 4 +-
.../{apr-util_1.6.3.bb => apr-util_1.6.5.bb} | 4 +-
.../curl/curl/CVE-2026-11352.patch | 48 +++
.../curl/curl/CVE-2026-11586.patch | 203 ++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 2 +
.../gnutls/gnutls/CVE-2026-33845.patch | 166 +++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
.../{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
.../vim/files/CVE-2026-73072.patch | 64 ++++
.../vim/files/CVE-2026-73073.patch | 105 ++++++
.../vim/files/CVE-2026-73074.patch | 115 ++++++
.../vim/files/CVE-2026-73076.patch | 167 +++++++++
.../vim/files/CVE-2026-73077.patch | 105 ++++++
.../vim/files/CVE-2026-73078.patch | 94 +++++
meta/recipes-support/vim/vim.inc | 6 +
scripts/contrib/improve_kernel_cve_report.py | 4 +-
57 files changed, 2889 insertions(+), 205 deletions(-)
rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%)
rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%)
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch
create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
create mode 100644 meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-16599.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
delete mode 100644 meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
delete mode 100644 meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
rename meta/recipes-support/apr/{apr-util_1.6.3.bb => apr-util_1.6.5.bb} (93%)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11352.patch
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11586.patch
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (97%)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73076.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch
^ permalink raw reply [flat|nested] 42+ messages in thread
* [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
` (36 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:
2fe596715f840 Linux 6.18.41
6a7ecc25abe6f posix-cpu-timers: Prevent UAF caused by non-leader exec() race
9f7268928ac0c posix-timers: Expand timer_[re]arm() callbacks with a boolean return value
221fc2f4d0eda Linux 6.18.40
478c4d24193fe RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
b87cbd4d198ae RDMA/bnxt_re: Initialize dpi variable to zero
81e6faa5b6405 ksmbd: fix durable reconnect double-bind race in ksmbd_reopen_durable_fd
1badb6866482d perf callchain: Handle multiple address spaces
275eb39930947 seqlock: fix scoped_seqlock_read kernel-doc
453cb79a15641 perf inject: With --convert-callchain ignore the dummy event for dwarf stacks
2764d031efd6d PCI: Fix Resizable BAR restore order
2fb74141ec54e PCI: Fix BAR resize rollback path overwriting ret
7425e7d82cb93 perf symbol: Fix ENOENT case for filename__read_build_id
a888f3d5970ff pinctrl: airoha: fix pinctrl function mismatch issue
267fdd9b6530c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
779480ea79551 iommufd: Move vevent memory allocation outside spinlock
73b5d5cb1f5a1 iommufd: Propagate allocation failure in iommufd_veventq_deliver_fetch()
ea7a76d7d614b KVM: arm64: nv: Re-translate VNCR before injecting abort
459adfc6cd35f KVM: arm64: Deduplicate ASID retrieval code
9d360fb820a3b samples/damon/mtier: fail early if address range parameters are invalid
ec976851ad934 mm/damon/core: trace esz at first setup
3b91c35961fa5 mm/damon/core: always put unsuccessfully committed target pids
ba37cd4d8a751 KVM: arm64: Fix propagation of TLBI level in kvm_pgtable_stage2_relax_perms()
19d9996435db8 KVM: arm64: Ensure level is always initialized when relaxing perms
c3a3d39867190 btrfs: fix incorrect buffered IO fallback for append direct writes
998ee7f01ecfa btrfs: fix false IO failure after falling back to buffered write
a4497a122e27f crypto: qat - fix restarting state leak on allocation failure
6c78081d047c5 btrfs: remove folio parameter from ordered io related functions
1a648c50a5057 btrfs: replace for_each_set_bit() with for_each_set_bitmap()
99d4ae3fbb5b1 btrfs: concentrate the error handling of submit_one_sector()
382fd8004cc60 crypto: atmel-sha204a - fail on hwrng registration error in probe path
952db4b985c79 usb: gadget: f_fs: Tie read_buffer lifetime to ffs_epfile
69faa3779250d usb: gadget: f_fs: initialize reset_work at allocation time
8a2fdbf92cdc7 functionfs: use spinlock for FFS_DEACTIVATED/FFS_CLOSING transitions
5fb0b09180a0f functionfs: switch to simple_remove_by_name()
4744f07f6bb7c functionfs: don't bother with ffs->ref in ffs_data_{opened,closed}()
901c036cf6254 functionfs: don't abuse ffs_data_closed() on fs shutdown
c3e6860252102 new helper: simple_remove_by_name()
509b51327320b usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect()
b78826a657998 usb: atm: ueagle-atm: remove function entry/exit debug messages
6e5ef54b884f4 usb: atm: ueagle-atm: use dev_dbg() for 'device found' message
41a4e80d5af04 usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
e534790c4c272 usb: dwc3: Support USB3340x ULPI PHY high-speed negotiation.
bce232923aa9e xfs: use bio_reuse in the zone GC code
adadb181ad42a xfs: only log freed extents for the current RTG in zoned growfs
47c0e07433021 xfs: add a xfs_groups_to_rfsbs helper
57454944737f3 bpf: Allow LPM map access from sleepable BPF programs
8fccaeeb9e9c5 bpf: Consistently use bpf_rcu_lock_held() everywhere
0b92ad64d6e4b bpf: Keep dynamic inner array lookups nullable
c447be8d88c30 bpf: Introduce struct bpf_map_desc in verifier
dccb3c557879d bpf: Consistently use reg_state() for register access in the verifier
60eed44674295 xfs: initialize iomap->flags earlier in xfs_bmbt_to_iomap
607217f7ad419 hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
7676ea09beb5d hfs/hfsplus: prevent getting negative values of offset/length
f9b4b03ccc9c6 proc: protect ptrace_may_access() with exec_update_lock (part 1)
07bf18dc63f78 seqlock: Change do_task_stat() to use scoped_seqlock_read()
c897fd63762e0 seqlock: Introduce scoped_seqlock_read()
497c6bae51674 proc: protect ptrace_may_access() with exec_update_lock (FD links)
903d78e5aca77 proc: rename proc_setattr to proc_nochmod_setattr
b56400364aed5 ksmbd: validate NTLMv2 response before updating session key
74c2f0ffb81c8 ksmbd: Use HMAC-MD5 library for NTLMv2
51c5f7e84cfed ksmbd: Use HMAC-SHA256 library for message signing and key generation
bd27d9504d200 ksmbd: Use SHA-512 library for SMB3.1.1 preauth hash
427faaa52b0b3 ksmbd: track the connection owning a byte-range lock
6a37bc484f12e ksmbd: centralize ksmbd_conn final release to plug transport leak
c7c884a1305aa ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
e205f3e7e8c31 ksmbd: use opener credentials for FSCTL mutations
90a93fb3230c9 cifs: SMB1 split: Add some #includes
ff943e1f3d31f cifs: SMB1 split: Rename cifstransport.c
36da806f7fbae Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
6d0eeebe22ba7 Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister
ef382a6baf0a9 media: nxp: imx8-isi: Fix use-after-free on remove
4278953ff0cd4 media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code
49cd5ac6de8de crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
4b51ee8a40fe4 staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
5d76bc296bb58 staging: rtl8723bs: fix spaces around binary operators
48323ebaeeeed staging: rtl8723bs: core: move constants to right side in comparison
73cc54326de45 PCI: Skip Resizable BAR restore on read error
f33837a754473 PCI: Move Resizable BAR code to rebar.c
2242c75b63286 PCI: Add kerneldoc for pci_resize_resource()
4b5322f0002aa PCI: Fix restoring BARs on BAR resize rollback path
c18646165f21f PCI: Free saved list without holding pci_bus_sem
534f20cdddc31 PCI: Try BAR resize even when no window was released
dbb1d8507dd92 PCI: Change pci_dev variable from 'bridge' to 'dev'
0d1c263e6fd73 PCI/IOV: Adjust ->barsz[] when changing BAR size
0dfad346c293e PCI: imx6: Configure REF_USE_PAD before PHY reset for i.MX95
e53d54b92f0c2 PCI: imx6: Fix reference clock source selection for i.MX95
1228926e1e4d6 binder: cache secctx size before release zeroes it
79ac87bb1a4c8 binder: Use LIST_HEAD() to initialize on stack list head
7ed120b1a007b vfio/mlx5: Fix racy bitfields and tighten struct layout
f8272331da877 ALSA: hda/tas2781: Cancel async firmware request at unbind
6438d0707087e firmware_loader: Add cancel helper for async requests
1ed7ff33cfc8c ALSA: scarlett2: Update offsets for 2i2 Gen 4 firmware 2417
ad5c5bdb0f580 ALSA: scarlett2: Allow selecting config_set by firmware version
2745574697ee4 iio: hid-sensor-rotation: Fix stale or zero output when reading raw values
7f680924c5c2b ACPI: NFIT: core: Fix possible deadlock and missing notifications
cf5f93228e7ab ACPI: NFIT: core: Use devm_acpi_install_notify_handler()
d57d2aae87b23 ACPI: bus: Introduce devm_acpi_install_notify_handler()
34f4d0e4e5065 ACPI: driver: Check ACPI_COMPANION() against NULL during probe
3b2628f7682ae ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
83f29da85dc9d crypto: xilinx-trng - Remove crypto_rng interface
f84c0bae0e8dd mmc: sdhci-esdhc-imx: fix resume error handling
174dc8103ab7b mmc: sdhci-esdhc-imx: make non-fatal errors non-blocking in suspend
5b8f11cbe8ad5 mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend
4f96903e2fd22 mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
aa276aa6cbfbc mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore
52990f6b57526 mmc: sdhci-esdhc-imx: restore DLL override for DDR modes on resume
eefcd3ca245c1 mmc: sdhci-esdhc-imx: remove unnecessary mmc_card_wake_sdio_irq check for tuning save/restore
c02237966c199 mmc: sdhci-of-dwcmshc: check bus clock enable result in the probe() method
8d94498cc4453 mmc: block: fix RPMB device unregister ordering
cf7258f57d180 mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
4b5de4007e5bf mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout
de2bc884d8870 mtd: rawnand: fsl_ifc: return errors for failed page reads
bf9848a22a8e5 mmc: vub300: defer reset until cmd_mutex is unlocked
04ebd3766861f mtd: mchp23k256: use SPI match data for chip caps
ac2d9f6b4f905 mtd: onenand: samsung: report DMA completion timeouts
a59cfa165aee3 wifi: mwifiex: fix permanently busy scans after multiple roam iterations
b8df3a993f690 wifi: mac80211: free ack status frame on TX header build failure
90576bd6921a9 wifi: ieee80211: validate MLE common info length
584657c5fc58d wifi: cfg80211: validate EHT MLE before MLD ID read
3c1e92f75e11a powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
82753ac86cb3d reset: sunxi: fix memory region leak on ioremap failure
3fb7edd2018bb ipvs: reload ip header after head reallocation
d4ec18f48ce78 ipvs: fix more places with wrong ipv6 transport offsets
39151f0708c84 memstick: ms_block: reject a card that reports too many blocks
a75d2b5249e38 macsec: fix promiscuity refcount leak in macsec_dev_open()
fd701fc0d0652 llc: fix SAP refcount leak when creating incoming sockets
6744ab60dfac5 Bluetooth: btrtl: validate firmware patch bounds
dbd14f736be02 net: openvswitch: reject oversized nested action attrs
6926d13865aaa regulator: ltc3676: Fix incorrect IRQSTAT bit offsets
688bd4c6144d2 riscv: vdso: Do not use LTO for the vDSO
55b26abb1fa1e wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
bdc0b8bfdc142 wifi: mac80211: fix memory leak in ieee80211_register_hw()
65446b85595a4 wifi: mwifiex: fix roaming to different channel in host_mlme mode
816559409e340 wifi: rt2x00: avoid full teardown before work setup in probe
262da8b6ea03d net/mlx5: free mlx5_st_idx_data on final dealloc
9b8df4da2cf79 powerpc/pseries: fix memory leak on krealloc failure in papr_init
afa0db5322c5f mmc: sdhci-esdhc-imx: restore pinctrl before restoring ios timing on resume
d94160a5d1ac3 selftests/landlock: Fix screwed up pointers in the scoped_signal_test
ba481c0b53760 selftests/landlock: Skip scoped_signal subtest with MSG_OOB if not available
4ff3960f35271 pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
9a0464fcfae4f pmdomain: imx: Fix i.MX8MP power notifier
c844b7d9a9586 cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed
8131a91fe2dea selftests/rseq: Fix a building error for riscv arch
3dfec7490f3a2 s390/mm: Fix type mismatch in get_align_mask().
c6b4d454865a8 s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
fad36954b2959 tracing/osnoise: Call synchronize_rcu() when unregistering
eadd0c2c76aee riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
38cc4867540ae drbd: reject data replies with an out-of-range payload size
91ec52dd2a5d9 ata: libata-core: Allow capacity transition to zero for locked drives
7a9a69641b68a ata: libata-core: Skip HPA resize for locked drives
52007bfdce531 fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
1155a9d0a2e0d fs/resctrl: Free mon_data structures on rdt_get_tree() failure
ccdf1770a4ba2 cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable()
5f5783c7806fc arm64: smp: Fix hot-unplug tearing by forcing unregistration
26b131b2d5b55 net: macb: drop in-flight Tx SKBs on close
b2f426a9a2288 dibs: loopback: validate offset and size in move_data()
2cf10d0425622 macsec: don't read an unset MAC header in macsec_encrypt()
83fb4c2c5344f ipvs: reset full ip_vs_seq structs in ip_vs_conn_new
247d055504dcc ipvs: use parsed transport offset in SCTP state lookup
61a7ff4a62003 llc: fix SAP refcount leak in llc_ui_autobind()
685fb410d90e5 selftests: net: make busywait timeout clock portable
5df30f05db965 octeontx2-pf: fix SQB pointer leak on init failure
77caf2d6eba7c mac802154: remove interfaces with RCU list deletion
f0745496f7c17 s390/monwriter: Reject buffer reuse with different data length
a5a367756926d irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure
018d7ad26cb8b mm/compaction: handle free_pages_prepare() properly in compaction_free()
2faf0198168d2 riscv: probes: save original sp in rethook trampoline
d8d4fa0c4f818 hwmon: (asus_atk0110) Check package count before accessing element
07f5eb6d268a3 net: wwan: iosm: bound device offsets in the MUX downlink decoder
1286a41563337 ata: pata_pxa: Fix DMA channel leak on probe error
1dce4f4bb3c1c net/mlx5: HWS, fix matcher leak on resize target setup failure
82fc886e244c7 orangefs: keep the readdir entry size 64-bit in fill_from_part()
2c76c01a505c1 tracing/probes: Fix double addition of offset for @+FOFFSET
b4427ee3667c5 hwmon: (max1619) add missing 'select REGMAP' to Kconfig
6c52226072a3c fhandle: reject detached mounts in capable_wrt_mount()
e2b7ee61989f2 net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked
5889064919a1e net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
99a6f37b113c4 net: lan743x: Initialize eth_syslock spinlock before use
ac58088d70b8a fsl/fman: Free init resources on KeyGen failure in fman_init()
f0aad157576da hwmon: (occ) unregister sysfs devices outside occ lock
715cce38424fb net: liquidio: fix BAR resource leak on PF number failure
664480021f6a4 hwmon: (w83793) remove vrm sysfs file on probe failure
c6c990f7208c9 hwmon: (w83627hf) remove VID sysfs files on error and remove
8dc6c7e8c9678 rtc: mpfs: fix counter upload completion condition
6e21d1253ef13 rtc: renesas-rtca3: Fix PIE clear polling condition in alarm setup error path
6c98ccdb9a096 bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
f5c5065963024 ipmi: fix refcount leak in i_ipmi_request()
a66d45e0ce6d7 espintcp: use sk_msg_free_partial to fix partial send
ddbb6e3dc9bb4 ipmi: Fix user refcount underflow in event delivery
a65f49b6f7ece LoongArch: Fix missing dirty page tracking in {pte,pmd}_wrprotect()
20ac8131f8c90 LoongArch: Fix nr passing in set_direct_map_valid_noflush()
612cda6630f2e pwm: rzg2l-gpt: Fix period_ticks type from u32 to u64
4b73889941b95 selftests/bpf: Add simple strscpy() implementation
da7f17c2d5bb4 KVM: TDX: Account all non-transient page allocations for per-TD structures
d0cc2c74060be drm/xe/userptr: Stub notifier_lock helpers when DRM_GPUSVM=n
6cec36c795c03 net/sched: sch_teql: move rcu_read_lock()/spin_lock() from _bh variants
55da782eb4545 platform/x86/amd/pmc: Avoid logging "(null)" for DMI values
35267819b2507 gve: fix header buffer corruption with header-split and HW-GRO
2059c28bd725b ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit
cb5cca1d2a908 ieee802154: ca8210: fix cas_ctl leak on spi_async failure
314f21c9dd0dc ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation
1905ebabe638c ieee802154: admin-gate legacy LLSEC dump operations
19c148cb82d11 octeontx2-af: Free BPID bitmap on setup failure
234cd54fc500f net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
03d8843b143eb net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
68cadc3698c7d net: ipip: require CAP_NET_ADMIN in the device netns for changelink
9571af2eec802 net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
0b2f9c908f930 net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
6596baf804110 net: ena: clean up XDP TX queues when regular TX setup fails
ab625256882e0 selftests: net: fix file owner for broadcast_ether_dst test
b3d8354078461 net/sched: act_ct: preserve tc_skb_cb across defragmentation
3f85fcd520aa7 net: ixp4xx_hss: fix duplicate HDLC netdev allocation
e89b8829693e6 net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
121c5f31c3fb7 net: ethernet: ti: icssg: guard PA stat lookups
3118e97dae533 net: sit: require CAP_NET_ADMIN in the device netns for changelink
5d7bd8790309b gpios: palmas: add .get_direction() op
d3b9026ef78da gpio: mt7621: avoid corruption of shared interrupt trigger state
4e16bc75c7502 gpio-f7188x: Add support for NCT6126D version B
b6e040b5143cc gpio: mt7621: be sure IRQ domain is created before exposing GPIO chips
ac761e66708d5 gpio: tegra: do not call pinctrl for GPIO direction
0630f2c3c16c0 gpio: mt7621: more robust management of IRQ domain teardown
6cb15b81ff545 cpu: hotplug: Bound hotplug states sysfs output
f77117530fc3f cpu: hotplug: Preserve per instance callback errors
afd147e59b32a selftests/ftrace: Drop invalid top-level local in test_ownership
ea6a188ee805e posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
633cadbc0b832 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
fcff712d0e3d1 wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
b33ac2d39953e tracing/user_events: Fix use-after-free in user_event_mm_dup()
ed3cc4218070d net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
0e8115a7ed9a9 Input: ims-pcu - fix type confusion in CDC union descriptor parsing
f516cba88bf95 Input: ims-pcu - fix race condition in reset_device sysfs callback
383934c249a98 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
9c964fc9507ae Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
99c428d7ef644 Input: ims-pcu - fix firmware leak in async update
05ac85da12198 Input: ims-pcu - fix DMA mapping violation in line setup
f28c5cabb2df0 Input: ims-pcu - add response length checks
c8d3d83f2eaaf Input: ims-pcu - validate control endpoint type
6329d1af316a4 Input: ims-pcu - release data interface on disconnect
87e2f89dea078 Input: ims-pcu - only expose sysfs attributes on control interface
6aacc18004b1a Input: ims-pcu - fix use-after-free and double-free in disconnect
df87532e92122 scsi: elx: efct: Fix I/O leak on unsupported additional CDB
9b871369cbb45 scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
cb7bdae7fba40 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
004ccd2d3b4ac scsi: target: Bound PR-OUT TransportID parsing to the received buffer
f1516c56ac540 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it
255fb7b0cdc94 scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
d0a8a6660d58e scsi: sg: Report request-table problems when any status is set
ed08497977820 scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
d495b403d5b35 scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
257321a1c036d accel/ivpu: Reject firmware log with size smaller than header
4e370b5289624 accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap()
7aa8f3dba5342 dma-fence: Make dma_fence_dedup_array() robust against 0-count input
089e05b644d5a dm-verity: make error counter atomic
c8d743bb0e98a dm-verity: increase sprintf buffer size
f15eaa3801f2f dm-verity: fix a possible NULL pointer dereference
2a0858cba1dab dm-verity: avoid double increment of &use_bh_wq_enabled
5dfd804263527 dm-integrity: don't increment hash_offset twice
aa5113e7155f4 dm-integrity: fix a bug if the bio is out of limits
0c4e9bb1d4101 dm-integrity: fix leaking uninitialized kernel memory
92e3c93d60be1 dm_early_create: fix freeing used table on dm_resume failure
ee458c3c18343 dm-stats: fix merge accounting
461d36b5ddafc dm-stats: fix dm_jiffies_to_msec64
1247615aadb74 dm-pcache: reject option groups without values
e0b0163a65758 dm-log: fix a bitset_size overflow on 32bit machines
d61c12573ed97 dm-ioctl: fix a possible overflow in list_version_get_info
021dab70eb37d dm-bufio: fix wrong count calculation in dm_bufio_issue_discard
1fcb5e29dd7a5 dm era: fix out-of-bounds memory access for non-zero start sector
7f76245960a33 dm thin metadata: fix metadata snapshot consistency on commit failure
ac2136dc4441d dm thin metadata: fix superblock refcount leak on snapshot shadow failure
8a3c44a003176 net: sparx5: unregister blocking notifier on init failure
ffd17a393921a block: fix IORING_URING_CMD_REISSUE flags check in blkdev_uring_cmd
2977b5fe401c1 block: fix race in blk_time_get_ns() returning 0
af382ffca93e5 block: remove redundant GD_NEED_PART_SCAN in add_disk_final()
0b6252afcd196 bpf: Add missing access_ok call to copy_user_syms
c4f626ddf2350 bpf,fork: wipe ->bpf_storage before bailouts that access it
0993dc5fc619c bpf: Reset register bounds before narrowing retval range in check_mem_access()
b06a4a397ac82 can: bcm: add missing rcu list annotations and operations
35f0ac19efb1a can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure
cd830e0bc25ee can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
37beb16e08cae can: isotp: serialize TX state transitions under so->rx_lock
7bef39ba76eb7 can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER
b88a511308779 can: isotp: use unconditional synchronize_rcu() in isotp_release()
765ba1c91823a can: esd_usb: kill anchored URBs before freeing netdevs
5e4c8e08ce957 netdev-genl: report NAPI thread PID in the caller's pid namespace
26355295ce21c nvmet: fix refcount leak in nvmet_sq_create()
2944113ad5fbc nvmet-rdma: handle inline data with a nonzero offset
2eaa3ad450141 nvmet-auth: reject short AUTH_RECEIVE buffers
59cef6abc924a nvme-apple: Prevent shared tags across queues on Apple A11
0ffc032294a29 NFS: Charge unstable writes by request size, not folio size
ebe0a55d954fa sctp: validate STALE_COOKIE cause length before reading staleness
d44b828eb551b spi: uniphier: Fix completion initialization order before devm_request_irq()
9b092f9e6b34d time: Fix off-by-one in compat settimeofday() usec validation
ada4b9a5087ea tpm: Make the TPM character devices non-seekable
95bdf3950d668 tpm: fix event_size output in tpm1_binary_bios_measurements_show
8ca2a19a987a7 xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink
e0f688ccb20f1 xfrm: use compat translator only for u64 alignment mismatch
5b0c4c916f202 xfrm: nat_keepalive: avoid double free on send error
16d3ccdabb8de xen/gntdev: fix error handling in ioctl
e497fef9ad7e9 ufs: core: tracing: Do not dereference pointers in TP_printk()
0ced34b4bbc04 tcp: Decrement tcp_md5_needed static branch
33a1bee413628 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect
bccae122dab8f ice: fix ice_init_link() error return preventing probe
8bd84316bbaf3 i2c: spacemit: fix spurious IRQ handling returning IRQ_HANDLED
e6a395a71f465 i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource()
2f3f471a448a5 i2c: mediatek: fix WRRD for SoCs without auto_restart option
5d3240f42a667 i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
6d2c973926d06 i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
500716a007b2e hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig
1dcd7565e5909 hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig
3cd6f93f3d593 ksmbd: fix integer overflow in set_file_allocation_info()
6cc1518357369 smb: client: use kvzalloc() for megabyte buffer in simple fallocate
fe623f9515bb0 pkey: Move keytype check from pkey api to handler
eafc5aca71564 platform/x86/amd/pmc: Don't log during intermediate wakeups
e628d9169f9e1 platform/x86/amd/pmc: Add delay_suspend module parameter
27d16a19ae74f platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops
d8bc45c4c1a45 platform/x86/amd/pmc: Check for intermediate wakeup in function
cea03d67db3a8 platform/x86: ISST: Restore SST-PP control to all domains
1e41ca4a7fba2 platform/x86: dell-laptop: fix missing cleanups in init error path
ddbc4a8a4fe29 dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK
7926c1e4be863 dmaengine: tegra: Fix burst size calculation
933654508b2bc sunrpc: fix uninitialized xprt_create_args structure
934d1cd40e289 tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
ba33b4f9d3423 tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
781f28bd982cf tpm: restore timeout for key creation commands
36ca587f55a2c irqchip/crossbar: Use correct index in crossbar_domain_free()
0d078152fcab7 taskstats: retain dead thread stats in TGID queries
9ac007affa77c mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
3fac46068fe4c openrisc: Fix jump_label smp syncing
ff7bcc9d71bf4 mtd: rawnand: Pause continuous reads at block boundaries
0fd20c1905abc mtd: spi-nor: spansion: use die erase for multi-die devices only
c0806df5cf806 mtd: spi-nor: swp: Improve locking user experience
433e5e70cdc1e s390/pkey: Check length in pkey_pckmo handler implementation
693bf91d4db13 s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
c9ef79e34bc1e fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
e5824d5b841d9 net: thunderbolt: Fix frags[] overflow by bounding frame_count
fc74244e0cc25 bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path
3ebe0ee6527e8 bus: mhi: host: pci_generic: Fix the physical function check
012683accbb7d fpga: dfl: add bounds check in dfh_get_param_size()
2174c68f623b7 ocfs2: reject non-inline dinodes with i_size and zero i_clusters
5e512d370a01b ocfs2: reject dinodes whose i_rdev disagrees with the file type
4db3b6a2a8ecf ocfs2: reject dinodes with non-canonical i_mode type
499714de42ab4 ocfs2: add journal NULL check in ocfs2_checkpoint_inode()
671889c553ea5 ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec
bd73971fad89d ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
d5d5a21fb33cd ocfs2: avoid moving extents to occupied clusters
4bbfcf9c7e46c mtd: rawnand: fix condition in 'nand_select_target()'
a8874c34c4a97 net/9p: fix infinite loop in p9_client_rpc on fatal signal
ace3a0c839f3b mtd: rawnand: pl353: fix probe resource allocation
b6337e3687d3d ocfs2: use kzalloc for quota recovery bitmap allocation
bf53557a96d4c openrisc: Add full instruction cache invalidate functions
8d263bae573dc scsi: sas: Skip opt_sectors when DMA reports no real optimization hint
83405848e4030 scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished()
a7bbf83dfebdc power: supply: bq257xx: Fix VSYSMIN clamping logic
8d610017c992d 9p: skip nlink update in cacheless mode to fix WARN_ON
d8dcbbfa0d695 mtd: slram: remove failed entries from the device list
4e4beef747c68 kcov: use WRITE_ONCE() for selftest mode stores
da5234df09416 mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE
749e2051da3b0 powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors
07ed8b1785480 fs/proc: fix KPF_KSM reported for all anonymous pages
b6a6fb6803d52 proc: only bump parent nlink when registering directories
4d67bdef35c32 fs/proc/task_mmu: use huge_page_size() in pagemap_scan_hugetlb_entry()
43b987ed35be9 fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
40a04601a3f66 mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
f18c561eb9c51 mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs()
f322955d9a1c3 riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
1caee6e084a96 mips: sched: Fix CPUMASK_OFFSTACK memory corruption
bd2e9be9ebb64 selftests/landlock: Test SCOPE_SIGNAL on the SIGIO/fowner pgid path
193e6471e985c power: supply: charger-manager: fix refcount leak in is_full_charged()
1f18aac263722 landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
ff05a98150ebb ntfs3: fix out-of-bounds read in decompress_lznt
f3624cc069195 ntfs3: validate split-point offset in indx_insert_into_buffer
aaa1f956c0fc4 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
0fad25687d4d3 ntfs3: cap RESTART_TABLE free-chain walker at rt->used
be306b8d9143a fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
908c9243ba309 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
7adb38279812c fs/ntfs3: validate lcns_follow in log_replay conversion
50b5e83384e7f fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
d240cd98f5f7b fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
09fddd52c1b0c fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
ccd6b70798737 fs/ntfs3: fix syncing wrong inode on DIRSYNC cross-directory rename
640627f07c79b mm/damon/core: make charge_addr_from aware of end-address exclusivity
722e6c54bde63 mm/memory_hotplug: fix incorrect altmap passing in error path
1697d253f51cf mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
9227b387eee50 power: supply: max17042: fix OF node reference imbalance
a3d81de441233 power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
a39d281f207b9 mm/mm_init: fix pageblock migratetype for ZONE_DEVICE compound pages
d3fd2d358df0c MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf()
11a3bc25f2c30 MIPS: ip22-gio: fix device reference leak in probe
2c551f14f55e4 MIPS: ip22-gio: fix kfree() of static object
620a37ea7d626 MIPS: ip22-gio: fix gio device memory leak
51aad3d89a2dd remoteproc: qcom: Fix leak when custom dump_segments addition fails
69e18135e2a00 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
46d59ff421824 lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
1161c4b5bd004 lockd: Plug nlm_file leak when nlm_do_fopen() fails
66014ab165cb0 sunrpc: harden rq_procinfo lifecycle to prevent double-free
65b23bec1fca6 sunrpc: wait for in-flight TLS handshake callback when cancel loses race
3f9ee75a97a76 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
30d490bb2c4cd nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
f4ca396bdd60b nvdimm/btt: Free arenas on btt_init() error paths
78955fdce8ff6 jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
7199c78c3a3e3 Bluetooth: SCO: hold sk properly in sco_conn_ready
77eb0cf57009e Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready
96dd35f1942cd HID: playstation: validate num_touch_reports in DualShock 4 reports
88ba845468508 mfd: tps6586x: Fix OF node refcount
d8e2f3e1bc207 cifs: invalidate cfid on unlink/rename/rmdir
3256c05d5a9db batman-adv: tt: prevent TVLV OOB check overflow
d2b657c9653fc batman-adv: mcast: avoid OOB read of num_dests header
a90f4fff90253 batman-adv: frag: fix primary_if leak on failed linearization
c945f6007e785 batman-adv: clean untagged VLAN on netdev registration failure
8f54162e07d3e batman-adv: frag: free unfragmentable packet
2c989ab8e2054 batman-adv: fix VLAN priority offset
6a65ac8a81e90 batman-adv: tt: avoid request storms during pending request
ee878decf9e57 batman-adv: dat: fix tie-break for candidate selection
9e16b6751a820 batman-adv: ensure minimal ethernet header on TX
8f76277d02176 batman-adv: dat: ensure accessible eth_hdr proto field
e5e18886aadd3 batman-adv: bla: reacquire gw address after skb realloc
3b4c70c40f2e1 batman-adv: dat: acquire ARP hw source only after skb realloc
b8afcf799b2cc batman-adv: access unicast_ttvn skb->data only after skb realloc
85a71a81854e0 batman-adv: retrieve ethhdr after potential skb realloc on RX
e6b43acd34b21 batman-adv: gw: acquire ethernet header only after skb realloc
fa1ebae4206e6 s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
8514585aa9553 cpufreq: intel_pstate: Set non-turbo capacity to HWP_GUARANTEED_PERF()
221ee479a49fb cpufreq: schedutil: Fix uncleared need_freq_update on the .adjust_perf() path
5ab0eba9c8819 perf/x86/amd/lbr: Fix kernel address leakage
046f6244da9b6 perf/x86/amd/brs: Fix kernel address leakage
394e2bdf7594e x86/boot: Reject too long acpi_rsdp= values
f7c67c97b37c1 x86/boot: Validate console=uart8250 baud rate to fix early boot hang
1a1d6e3ef6cf5 x86/video: Only fall back to vga_default_device() without screen info
19ffeb30fdfce tools/power/x86/intel-speed-select: Harden daemon pidfile open
16a42c88c4667 mfd: sm501: Fix reference leak on failed device registration
6dd51d84a9502 leds: uleds: Fix potential buffer overread
3a134c3fb5f0d selinux: fix incorrect execmem checks on overlayfs
d61a80b17254b selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
fc633a598206d selinux: check connect-related permissions on TCP Fast Open
e9cdf741ffcb4 soc: fsl: qe: panic on ioremap() failure in qe_reset()
c6854d9f4e1bd soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy
c4d6442ac3ed0 gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
1c4f67c89fd27 netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
679ced28a9dc2 netfilter: xt_nat: reject unsupported target families
b2dbbedfa935c netfilter: ecache: fix inverted time_after() check
3cd9a5792cbea netfilter: nf_conncount: fix zone comparison in tuple dedup
a58230f3a7c4f netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag
2bcf2c5052fb5 netfilter: nf_nat_sip: reload possible stale data pointer
02b6b0e892aea netfilter: nft_set_pipapo: don't leak bad clone into future transaction
0ca505346c5e2 netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
07f9ddbf5e799 netfilter: xt_cluster: reject template conntracks in hash match
a1b672a3b5372 netfilter: nfnl_cthelper: apply per-class values when updating policies
aff589556ed77 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
ca028334343a1 ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
e42d8322b67f2 ASoC: mediatek: mt8183: Release reserved memory on cleanup
4b068759d3087 ASoC: mediatek: mt8183: Check runtime resume during probe
51c367230e30e ASoC: mediatek: mt8192: Release reserved memory on cleanup
e0f276f1918a2 ASoC: mediatek: mt8192: Check runtime resume during probe
d3abaedf6a584 ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
121577383b5cf ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
4ebe2c3a7db63 fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
009a8514745b1 fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
58bc18e03481b fbdev: vesafb: fix memory leak in vesafb_probe()
d81860691e4cf fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
e1ca9b8559e0f fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
12fe6a56506ed fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
ad54698255a4b fbdev: s3fb: fix potential memory leak in s3_pci_probe()
146b708bc75f1 fbdev: i740fb: fix potential memory leak in i740fb_probe()
c2c795a320e7e fbdev: radeon: fix potential memory leak in radeonfb_pci_register()
febb5b4f67ace fbdev: efifb: fix memory leak in efifb_probe()
9423e1f105270 fbdev: sm712: Fix operator precedence in big_swap macro
d684ce2db92b1 fbdev: hecubafb: fix potential memory leak in hecubafb_probe()
e8c9aae8c9508 fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe()
6854cf33dddb2 fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
d5436e18e4fc2 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
4ead4def04659 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
5c50db5bcbb90 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR
884b44256041e KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
09f35145f3a4a KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions
5000bcae71c86 KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
7099e7148f81c KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
7996013b85687 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
d1379888cc423 KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
97542f15dc4cf KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
ba06690b28be9 KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs
df72596278b0e KVM: s390: pci: Fix handling of AIF enable without AISB
d19dca8194ebe KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
79fdd2aa774e4 KVM: arm64: vgic: Check the interrupt is still ours before migrating it
5fb75c5272950 KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
9f8eaef40e955 powerpc/pseries/Kconfig: Enable CONFIG_VPA_PMU to be used with KVM
33d79ad6ecedf LoongArch: KVM: Return full old CSR value from kvm_emu_xchg_csr()
f3efcef6648ba LoongArch: KVM: Fix FPU register width with user access API
45f2e6505fcf6 LoongArch: KVM: Check the return values for put_user()
efe27b19a15c3 LoongArch: KVM: Check irq validity in kvm_vcpu_ioctl_interrupt()
199b570d7fca1 LoongArch: KVM: Validate irqchip index in irqfd routing
1ee200a1764f8 ARM: dts: stm32: stm32mp15x-mecio1-io: Move expander gpio-line-names to board files
f550bf32b9a06 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix expander gpio line typo
7da4d1a6b7400 ARM: dts: stm32: stm32mp15x-mecio1-io: Move gpio-line-names to board files
804821b69b2d1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix GPIO names typo
c632a27f35cff arm64: dts: imx8ulp-evk: Correct Type-C int GPIO flags
bd938c985ab34 ARM: dts: stm32: stm32mp15x-mecio1-io: Enable internal ADC reference
ead9f10428c73 arm64: dts: ti: k3-am62a7-sk: Add bootph-all tag to vqmmc
a98bda2305f3f ARM: dts: stm32: stm32mp15x-mecio1-io: Move divergent mecio1 ADC channels to board files
4fd52ac541ce1 ARM: dts: stm32: stm32mp15x-mecio1-io: Fix ADC sampling times
68f9773754f05 arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Ringneck
e2e3fb995175c arm64: dts: qcom: sdm630: describe adsp_mem region properly
508e55e81870d ARM: dts: imx6ul-var-som: fix warning for non-existent dc-supply property
e8dc96a42571e arm64: dts: s32g3: Fix SWT8 watchdog address
89edae4161412 arm64: fpsimd: Fix type mismatch in sve_{save,load}_state()
5526d1997aea6 net: ife: require ETH_HLEN to be pullable in ife_decode()
908391d801b24 octeontx2-vf: clear stale mailbox IRQ state before request_irq()
eebf439aa7a13 octeontx2-pf: clear stale mailbox IRQ state before request_irq()
e62adb157c2ea net: atm: reject out-of-range traffic classes in QoS validation
22100a8f73d4a net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post()
61a55fa24a5d7 tipc: restrict socket queue dumps in enqueue tracepoints
d34deef34c99b ASoC: SOF: topology: validate vendor array size before parsing
0c4fbdaca225b ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
711d912b18763 ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
fb4293173db2d ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
d8715b5a8fdb2 vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
3a2b47d1b4b3d mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace()
2d8b3c3e12997 mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
b65e46eed9e52 idpf: add padding to PTP virtchnl structures
1627e7d5c9b09 smb: client: fix overflow in passthrough ioctl bounds check
327595e7c34e3 drm/xe: remove duplicate <kunit/test-bug.h> include
3de77d2f34c2b octeontx2-af: fix VF bringup affecting PF promiscuous state
ee3f7566bcf33 net/mlx5: Fix L3 tunnel entropy refcount leak
1550b07bca2bb selftests/net: fix EVP_MD_CTX leak in tcp_mmap
346e2d666a29a regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
14e03ecd3b1b5 dm era: fix NULL pointer dereference in metadata_open()
5b0427ba582d1 SUNRPC: pin upper rpc_clnt across the TLS connect_worker
13965a7b190f3 SUNRPC: release lower rpc_clnt if killed waiting for XPRT_LOCKED
b784cd1c24d89 cifs: validate DFS referral string offsets
df0e3e70f6995 s390/zcrypt: Remove the empty file
8f48cfe657409 ipvs: ensure inner headers in ICMP errors are in headroom
7510451a58c27 ipvs: fix PMTU for GUE/GRE tunnel ICMP errors
d73f4249776dd ipvs: use parsed transport offset in TCP state lookup
d340e351a0a74 ipvs: pass parsed transport offset to state handlers
238c612357b5a netfilter: nft_lookup: fix catchall element handling with inverted lookups
f60ec3058a854 ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
27506827a01f6 ipv4: igmp: annotate data-races around timer-related fields
d269eb67d2e58 ipv4: igmp: annotate data-races around im->users
9ce741c22df4f ipv6: mcast: Fix potential UAF in MLD delayed work
75e984fe0cb9e ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
3bfcce441c552 gpio: mvebu: free generic chips on unbind
7cc438c99bba3 perf/x86/amd/core: Avoid enabling BRS from the SVM reload path
9579d625171a1 octeontx2-pf: check DMAC extraction support before filtering
7aa0e64fea778 net/sched: cake: reject overhead values that underflow length
72119397cdff6 net: mdio: select REGMAP_MMIO instead of depending on it
762116dfa7286 drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
267809e2c56fb accel/amdxdna: Fix potential amdxdna_umap lifetime race
1cd434ac1c222 tracing: Make tracepoint_printk static as not exported
5e15cf51982f8 gpio: dwapb: Defer clock gating until noirq
6c736c5ccf4a3 gpio: dwapb: reduce allocation to single kzalloc
d7b5497e0e45b gpio: dwapb: Use modern PM macros
a3010b732d620 net: usb: lan78xx: disable VLAN filter in promiscuous mode
e8a4c9fc437b1 net/tls: Consume empty data records in tls_sw_read_sock()
b3eeb586f94c7 accel/amdxdna: Use unsigned long for nr_pages in amdxdna_hmm_register()
ec5e96aee75d2 ring-buffer: Fix event length with forced 8-byte alignment
0c602cb8f148a Bluetooth: L2CAP: fix tx ident leak for commands without a response
bfc9e7be289df Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
b69b1ab121fe8 Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length
da4d8eea0c5f3 Bluetooth: sco: Fix a race condition in sco_sock_timeout()
dfc8373893b18 Bluetooth: MGMT: Fix adv monitor add failure cleanup
23a83bac3356e Bluetooth: 6lowpan: hold L2CAP conn across debugfs control
026c236f0eefe amt: fix size calculation in amt_get_size()
3bfb96d9bc6a7 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
6f9b23eb92a89 net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload
1b12612c367e4 net: qualcomm: rmnet: validate MAP frame length before ingress parsing
b066420e57f34 qede: fix off-by-one in BD ring consumption on build_skb failure
1e71a40d10154 net: microchip: vcap: fix races on the shared Super VCAP block
5c7e3755abf66 net/mlx5e: Fix publication race for priv->channel_stats[]
60fddda7207d8 net/mlx5e: Fix HV VHCA stats agent registration race
420aabb32da43 net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
6a802de97a8bf net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
4eef84b09a383 netfilter: xt_connmark: reject invalid shift parameters
b29b67c729de0 netfilter: nft_set_rbtree: get command skips end element with open interval
3d441be2b1c5e netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
e702f6dd5d21e netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt()
a597a722fb71a netfilter: xt_u32: reject invalid shift counts
4a4a1d41c6e90 gue: validate REMCSUM private option length
b153cfe84b134 net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
66f57dc92aeb6 arm64/sysreg: Fix BWE field encoding in ID_AA64DFR2_EL1
a6185c21d5510 selftests/hid: Cover hid_bpf_get_data() size overflow
91ac1d7fd51e3 selftests/hid: Load only requested struct_ops maps
61a959b82f1ae HID: bpf: Fix hid_bpf_get_data() range check
4c65c3d9f660b arm64/mm: Optimize TLB flush in unmap_hotplug_[pmd|pud]_range()
dd395744e4ed8 HID: core: Fix OOB read in hid_get_report for numbered reports
d354e523c6f74 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
793b55c3f36f5 ata: libata-scsi: limit simulated SCSI command copy to response length
232a2f2fce9b9 ata: sata_gemini: unwind clocks on IDE pinctrl errors
86652704a7fd4 cifs: Fix missing credit release on failure in cifs_issue_read()
c9170c83b0e0f uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
2265b2b1c5aaa x86/uprobes: Keep shadow stack in sync for emulated CALLs
adc7dda728ca3 drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays
a0a56b4480a0d drm/xe/hw_engine: Fix double-free of managed BO in error path
f9a9abd7bbdab drm/xe/userptr: Hold notifier_lock for write on inject test path
78b1074966d29 drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
a9b89752c2726 netfs: Fix folio state after ENOMEM whilst under writeback iteration
1bb33d959aabc netfs: Fix writeback error handling
7838131e296df netfs: Fix writethrough to use collection offload
8ab75e445c161 netfs: Fix netfs_create_write_req() to handle async cache object creation
1f38f65bf965f iomap: guard io_size EOF trim against concurrent truncate underflow
08b2145470667 ovl: fix comment about locking order
abe3536a4bedc minix: avoid overflow in bitmap block count calculation
ce6aced2e8554 afs: Fix unchecked-length string display in debug statement
158c5a0b1dfc0 afs: Fix the volume AFS_VOLUME_RM_TREE is set on
657449e5581a4 afs: Fix premature cell exposure through /afs
2ffb70a8a0198 afs: Fix lack of locking around modifications of net->cells_dyn_ino
8afb1a787a280 afs: Fix vllist leak
5492799ec5d27 afs: Fix missing NULL pointer check in afs_break_some_callbacks()
0acbc09d2aca0 afs: Fix callback service message parsers to pass through -EAGAIN
63d3f283858fa afs: Fix reinitialisation of the inode, in particular ->lock_work
5ea289ca751c4 afs: Fix misplaced inc of net->cells_outstanding
b5bc1e5d5ce57 afs: Fix bulk lookup malfunction due to change in dir_emit() API
083a0ddc9cd49 afs: Remove erroneous seq |= 1 in volume lookup loop
6eb0d929202a3 afs: use kvfree() to free memory allocated by kvcalloc()
aa24cec5b3470 afs: Fix double netfs initialisation in afs_root_iget()
8530206911fd6 afs: Fix error code in afs_extract_vl_addrs()
a2038514e6937 fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
374fd8122421f net/sched: hhf: clear heavy-hitter state on reset
fba8e250ce5f3 net/sched: dualpi2: clear stale classification on filter miss
a203f2c3892b1 pinctrl: meson: restore non-sleeping GPIO access
47120164c63d3 gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe
5a5ac2852cd32 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
d020e7f27bf65 ksmbd: reject undersized DACLs before parsing ACEs
6b1304ce6cff0 net/sched: act_bpf: use rcu_dereference_bh() to read the filter
a03387e1f6251 selftests: drv-net: tso: don't touch dangerous feature bits
df9ffdceac053 cxgb4: Fix decode strings dump for T6 adapters
124440df267dc virtio_net: disable cb when NAPI is busy-polled
a8323fb2ab6cd sctp: fix addr_wq_timer race in sctp_free_addr_wq()
4e8d498d32b6c irqchip/ts4800: Fix missing chained handler cleanup on remove
c5d75800539bc irqchip/gic-v3-its: Fix OF node reference leak
f0069a262bd41 tracing/probes: Make the $ prefix mandatory for comm access
62988204162fc tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
898cb5a7c4154 tracing: eprobe: read the complete FILTER_PTR_STRING pointer
e0881f5cc4d71 tracing/events: Fix to check the simple_tsk_fn creation
f148f86c65b8f tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
3b51d6f07a199 tracing/eprobes: Allow use of BTF names to dereference pointers
acbf1ecc22f3c drm/panthor: Interrupt group start/resumption if group_bind_locked() fails
a9d098b346db5 drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
1497a438ea34a drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick()
dd0b2976b7c0f drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
b4b3458ef88df bridge: stp: Fix a potential use-after-free when deleting a bridge
9b7d05cbaa601 net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
ef940e042f329 net: gianfar: dispose irq mappings on probe failure and device removal
58ba00999898b net: libwx: fix VMDQ mask for 1-queue mode
86d379fcf1b79 net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy
0a7d9c7c5f1f2 usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
d8a01d27873e0 ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump
83df3e2594cd7 eth: fbnic: don't cache shinfo across skb realloc
898ca04b096b9 hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
489291b6b5697 hwmon: (pmbus) Fix passing events to regulator core
36554592e2f5c hwmon: adm1275: Prevent reading uninitialized stack
1797eb92f0b39 ASoC: codecs: lpass-va-macro: Fix LPASS Codec Version for SC7280
f14c3926fee38 ASoC: codecs: lpass-va-macro: add SM6115 compatible
3d3638fe92137 MIPS: mm: Add check for highmem before removing memory block
4e9f4ca9dc73c MIPS: DEC: Ensure RTC platform device deregistration upon failure
bca3100f55028 sctp: add INIT verification after cookie unpacking
ad6215d76b644 sctp: fix SCTP_RESET_STREAMS stream list length limit
1681cc7974a61 net: enetc: check the number of BDs needed for xdp_frame
b17751a2ebc4a qede: fix out-of-bounds check for cqe->len_list[]
8dba7a94a269b seg6: validate SRH length before reading fixed fields
8d501b1411548 net: pse-pd: scope pse_control regulator handle to kref lifetime
e94d53a9ac22c gpio: htc-egpio: use managed gpiochip registration
f4af803269ccd gpio: mvebu: fail probe if gpiochip registration fails
46dee20d30b70 riscv: Fix 32-bit call_on_irq_stack() frame pointer ABI
8e0b7f94fb394 ACPI: RIMT: Only defer the IOMMU configuration in init stage
776f70bafd45c spi: sh-msiof: abort transfers when reset times out
d6cd34d17b951 tracing: probes: fix typo in a log message
f28d7b5f1578a ALSA: FCP: Fix NULL pointer dereference in interface lookup
d990a01b853e5 net: hns3: differentiate autoneg default values between copper and fiber
2d149a20275ac net: hns3: fix permanent link down deadlock after reset
92d05883ef337 net: hns3: refactor MAC autoneg and speed configuration
43a6c6fb6ec50 net: hns3: unify copper port ksettings configuration path
de051b146022c selftests: tls: size splice_short pipe by page size
6727f580cf462 dt-bindings: net: renesas,ether: Drop example "ethernet-phy-ieee802.3-c22" fallback
9075efb9b2c1d net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync
c1e7286d05318 ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count
7a7c7263bbbc4 LoongArch: BPF: Fix off-by-one error in tail call
ed295077a2214 LoongArch: BPF: Fix outdated tail call comments
0a8a729481c8e LoongArch: Move struct kimage forward declaration before use
2f3c0895fb20a net: ethernet: sunplus: spl2sw: fix phy_node refcount leak in remove
b15a3cc68e245 net: sungem: fix probe error cleanup
b84dd48f9da1e net: mvneta: re-enable percpu interrupt on resume
e0ac054416bf4 octeontx2-af: Validate NIX maximum LFs correctly
9dc3cf8a35906 net: phy: realtek: Clear MDIO_AN_10GBT_CTRL_ADV10G bit
0c11a1da41a64 net: dsa: realtek: fix memory leak in rtl8366rb_setup_led()
a69ccea6d7eb6 rtc: cmos: unregister HPET IRQ handler on probe failure
5fd1f0512748d rtc: ds1307: Fix off-by-one issue with wday for rx8130
d0bfd7004a87f smb/client: preserve errors from smb2_set_sparse()
5b6165d7ec384 ACPI: processor_idle: Mark LPI enter functions as __cpuidle
ea43e7a231aa2 thermal: testing: zone: Flush work items during cleanup
4e62be1490d23 eth: fbnic: fix ordering of heartbeat vs ownership
123b559aa6bb6 ipv6: fix missing notification for ignore_routes_with_linkdown
419017dd2dda2 ipv6: fix state corruption during proxy_ndp sysctl restart
ae58dbf1d78d7 ipv6: fix error handling in disable_policy sysctl
2bf70e0306f8d ipv6: fix error handling in forwarding sysctl
b060606bc7e46 ipv6: fix error handling in ignore_routes_with_linkdown sysctl
56c26538f0e58 ipv6: fix error handling in disable_ipv6 sysctl
2140c2f3f2e7b net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
ff127c0aa5279 net: usb: lan78xx: restore VLAN and hash filters after link up
a9e6707322ef2 veth: fix NAPI leak in XDP enable error path
4106295280670 net: dsa: sja1105: round up PTP perout pin duration
7557df1b60f20 net: do not acquire dev->tx_global_lock in netdev_watchdog_up()
03b743586a246 net, bpf: check master for NULL in xdp_master_redirect()
a0904f7d27035 alpha/PCI: Fix __pci_mmap_fits() overflow for zero-length BARs
94defb18ac792 alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
04117aea9bc11 NTB: epf: Fix doorbell bitmask and IRQ vector handling
56ec2a08d27b5 NTB: epf: Report 0-based doorbell vector via ntb_db_event()
d2a41c85beb56 NTB: epf: Make db_valid_mask cover only real doorbell bits
60a6689b9a5df gpio: davinci: fix IRQ domain leak on devm_kzalloc failure
33e1875d6b5b5 netfilter: nft_compat: ebtables emulation must reject non-bridge targets
d3e9a7e2ce9dc netfilter: nft_synproxy: stop bypassing the priv->info snapshot
329f2626ee5cb netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
a73e7ac3f3b69 netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
49fa1be621dde bpf: Disable xfrm_decode_session hook attachment
4d919c9b77099 md/raid5: avoid R5_Overlap races while breaking stripe batches
3db13f82ba314 md/raid5: use stripe state snapshot in break_stripe_batch_list()
828fad4fd418b ipv4: fib: Don't ignore error route in local/main tables.
630ce3806b706 eth: bnxt: improve the timing of stats
c0057e5f762b9 eth: bnxt: rename ring_err_stats -> ring_drv_stats
33168db149d01 eth: bnxt: gather and report HW-GRO stats
b0d0eb13a0441 ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
77bb0bbfcc4e7 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
1f6a4aec0d366 rtc: msc313: fix NULL deref in shared IRQ handler at probe
68115a7a336fc i40e: Fix i40e_debug() to use struct i40e_hw argument
de80d04b13dec ice: dpll: fix memory leak in ice_dpll_init_info error paths
eaffdd113f560 ice: dpll: set pointers to NULL after kfree in ice_dpll_deinit_info
854065a75e375 rtc: isl1208: Balance enable_irq_wake() with disable_irq_wake() on cleanup
4cc632fe63df8 ice: call netif_keep_dst() once when entering switchdev mode
04c082b7dc5bf ice: fix AQ error code comparison in ice_set_pauseparam()
dd6d8e4412f80 ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs()
9415a94cf6227 PCI: endpoint: pci-epf-ntb: Add check to detect 'db_count' value of 0
e1e7c72a2301d PCI: endpoint: pci-epf-vntb: Add check to detect 'db_count' value of 0
9cc0f8e63e8c3 drm/edid: fix OOB read in drm_parse_tiled_block()
5e4c4ab99abc9 gpiolib: initialize return value in gpiochip_set_multiple()
7550becf33014 power: sequencing: fix ABBA deadlock in pwrseq_device_unregister()
9697db03e0103 bpf: Fix effective prog array index with BPF_F_PREORDER
3bdfa0e435f31 bpf: zero-initialize the fib lookup flow struct
b05337635be3c bpftool: Fix vmlinux BTF leak in cgroup commands
68b41e68a6229 bpf: Fix stack slot index in nospec checks
aa33b44f70bfe rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231
56e5f8a409f8c rtc: abx80x: fix the RTC_VL_CLR clearing all status flags
93f95538b611a dpaa2-switch: do not accept VLAN uppers while bridged
ea24f911ead85 ipv6: ioam: fix type confusion of dst_entry
a6450f7cfae57 ipv6: ndisc: fix NULL deref in accept_untracked_na()
2066e692ec7a1 net: airoha: Fix skb->priority underflow in airoha_dev_select_queue()
1d51aff78f078 net/sched: act_ct: fix nf_connlabels leak on two error paths
a103cdb0681e7 net: emac: Fix NULL pointer dereference in emac_probe
2855ec137a224 octeontx2-pf: mcs: Fix mcs resources free on PF shutdown
da603b606ceb3 octeontx2-pf: Clear stats of all resources when freeing resources
5636f0f3bd99b octeontx2-af: mcs: Fix unsupported secy stats read
ceef83f0eaf9c net: ethernet: mtk_ppe: Fix rhashtable leak in mtk_ppe_init error paths
a0c5fdeb5fa25 tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
5dda4f164a633 net: marvell: prestera: initialize err in prestera_port_sfp_bind
9200c8149910d selftests/mm: fix exclusive_cow test fork() handling
55fc2f99d0979 selftests/mm: allow PUD-level entries in compound testcase of hmm tests
c8add1d06512b selftests/mm: clarify alternate unmapping in compaction_test
0caa28e978941 selftests/mm: skip uffd-stress test when nr_pages_per_cpu is zero
471b62966c782 selftests/mm: ensure destination is hugetlb-backed in hugetlb-mremap
9dbfd514148dd selftest/mm: register existing mapping with userfaultfd in hugetlb-mremap
a8673dbd3d4a0 selftests/mm: free dynamically allocated PMD-sized buffers in split_huge_page_test
31b28910abe34 selftests/mm: size tmpfs according to PMD page size in split_huge_page_test
fff7d3ea3a4c4 selftests/mm: fix cgroup task placement and drop memory.current checks in hugetlb_reparenting_test.sh
8c65c58868ecc selftests/mm: fix hugetlb pathname construction in hugetlb_reparenting_test.sh
58cd8ff69e33c selftests/mm: restore default nr_hugepages value via exit trap in hugetlb_reparenting_test.sh
b805de2abfa34 selftests/mm: restore default nr_hugepages value via exit trap in charge_reserved_hugetlb.sh
37e3e8a2c3bfd alloc_tag: fix use-after-free in /proc/allocinfo after module unload
502b3ae43f798 irqchip/crossbar: Fix parent domain resource leak
002ebbcc8414c mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx()
7e23965d44f06 netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
d32e4301a0e5e netfilter: nf_reject: skip iphdr options when looking for icmp header
8e935c51b65d9 netfilter: nft_flow_offload: zero device address for non-ether case
4c61d28634fbf netfilter: flowtable: move path discovery infrastructure to its own file
13c6ba6e0f216 netfilter: nft_meta_bridge: add validate callback for get operations
5baa149abb41a netfilter: nft_payload: reject offsets exceeding 65535 bytes
12088da6add5b netfilter: ipset: make sure gc is properly stopped
8087bb360a936 netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
c4d257734e91b netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
a0afd353c2f7e netfilter: ipset: annotate "pos" for concurrent readers/writers
7228cc8ff6265 netfilter: ipset: Fix data race between add and dump in all hash types
6d92dbd73d19a md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry
2c5384c40a4ce md/raid1: honor REQ_NOWAIT when waiting for behind writes
119903c320830 md: merge mddev serialize_policy into mddev_flags
2e414af05a7cf md: merge mddev faillast_dev into mddev_flags
9408c233a5bbe md: merge mddev has_superblock into mddev_flags
5464ee6442376 mac802154: Prevent overwrite return code in mac802154_perform_association()
de3bd9809af75 ieee802154: fix kernel-infoleak in dgram_recvmsg()
d22e278cd0679 ieee802154: Remove WARN_ON() in cfg802154_pernet_exit()
f4860dd988b10 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
5d17ebdf6c236 ieee802154: Restore initial state on failed device_rename() in cfg802154_switch_netns()
3b40ebc19ad02 ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone()
45465b0e01354 ACPI: resource: Amend kernel-doc style
7ae67f0e1c16b thermal: intel: Fix dangling resources on thermal_throttle_online() failure
679fd0bf4f8ab arm64/hw_breakpoint: reject unaligned watchpoints that would truncate BAS
4c16176fc11a6 ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints
a762b9865f494 selftests: vlan_bridge_binding: Fix flaky operational state check
c6d3bcb0f934d flow_dissector: check device type before reading ETH_ADDRS
68af74ad696ce net: macb: add TX stall timeout callback to recover from lost TSTART write
112b5eff24e04 net: airoha: fix foe_check_time allocation size
5ffb2b4987cc9 devlink: Fix parent ref leak on tc-bw failure
02c884d9aaca3 devlink: Fix parent ref leak in devl_rate_node_create()
0dafdaaf8684b dpaa2-switch: fix VLAN upper check not rejecting bridge join
c7fc9adf4e006 virtio-net: fix len check in receive_big()
0d95587d662a5 spi: rpc-if: Use correct device for hardware reinitialization on resume
f37f2f804796e PCI: iproc: Restore .map_irq() for the platform bus driver
53c23d56b46b1 ALSA: usb-audio: qcom: clear opened when stream enable fails
25a867aa5e67a ALSA: usb-audio: qcom: reject stream disable with no active interface
207bb4ce8fe7d sctp: hold socket lock when dumping endpoints in sctp_diag
a6cfb924ad74e net: psample: fix info leak in PSAMPLE_ATTR_DATA
3d45d40b872ae octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
290ad0a548915 drm/amdgpu: initialize irq.lock spinlock earlier
96ac562a9ea30 drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm
211bb9d8f17c4 drm/amd/display: Fix mem_type change detection for async flips
0e27d92f69b8e drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
7bcd4ef375fa3 ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode
ca297485271c6 perf dso: Set standard errno on decompression failure
05b11debdffe0 perf bpf: Validate array presence before casting BPF prog info pointers
c8cb4a92eda6e perf cs-etm: Bounds-check CPU in cs_etm__get_queue()
b389a5b215e35 perf cs-etm: Require full global header in auxtrace_info size check
c13532ff67fae perf cs-etm: Validate num_cpu before metadata allocation
87d23f25b5e97 perf machine: Use snprintf() for guestmount path construction
6d99379c58f7f xfrm: validate selector family and prefixlen during match
7248ae02a9453 xfrm: annotate data-races around xfrm_policy_count[] and xfrm_policy_default[]
a1a3360a0c44b xfrm: Fix xfrm state cache insertion race
1467ca02ddac4 ALSA: usb-audio: qcom: Free sideband sg_table objects
507a7b07f3fa3 i3c: master: Add missing runtime PM get in dev_nack_retry_count_store()
34cd92141a024 i3c: master: Update dev_nack_retry_count under maintenance lock
95028569589f4 spi: dw: fix wrong BAUDR setting after resume
355e51eeffc6b drm/xe: Fix wa_oob codegen recipe for external module builds
2024940522ef4 drm/i915: clear CRTC color blob pointers after dropping refs
1348bf64c1978 gpio: mlxbf3: fail probe if gpiochip registration fails
7d3532a0b11a2 perf cs-etm: Reject CPU IDs that would overflow signed comparison
a56f29ad8aacf perf: Remove redundant kernel.h include
f8898d2eb71ae perf bpf: Bounds-check array offsets in bpil_offs_to_addr()
cafd80d81f08b perf bpf: Reject oversized BPF metadata events that truncate header.size
1935d213aeb23 perf bpf: Validate func_info_rec_size and sub_id in synthesize_bpf_prog_name()
aea30b437ebd0 perf sched: Replace (void*)1 sentinel with proper runtime allocation
bc27041e8971e perf hwmon: Fix fd check to accept fd 0 in hwmon_pmu__describe_items()
661f60a8a5cf8 perf tools: Use snprintf() for root_dir path construction
5d080b7324f07 perf dso: Set error code when open() fails on uncompressed fallback path
debfcd673a6d1 perf dso: Fix heap overflow in dso__get_filename() on decompressed path
95bf4dbcd5022 perf tools: Fix uninitialized pathname on uncompressed fallback in filename__decompress()
fa870f951793d perf tools: Add O_CLOEXEC to open() calls in DSO and ELF code
3ae7947101b97 perf tools: Don't read build-ids from non-regular files
2c19e40753ec1 perf symbols: Break infinite loop on zero-filled notes in sysfs__read_build_id()
137eabe3c18ff perf symbols: Validate p_filesz before use in filename__read_build_id()
ca3393e258f63 perf symbols: Fix bswap copy-paste error for 32-bit ELF p_filesz
f231387f3d2bb sparc: led: avoid trimming a newline from empty writes
17955f1995bf9 accel/ivpu: fix HWS command queue leak on registration failure
85873b1bd3664 apparmor: fix label can not be immediately before a declaration
38d3d33bf42c2 i3c: master: Prevent reuse of dynamic address on device add failure
c4f2afcdc5470 i3c: master: Defer new-device registration out of DAA caller context
3891c061341fb i3c: master: Ensure Hot-Join operations are stopped on shutdown
57490b302b984 i3c: master: Consolidate Hot-Join DAA work in the core
0bd450d40f874 i3c: master: Move rstdaa error suppression
fd32e8d4a2933 i3c: master: Add i3c_master_do_daa_ext() for post-hibernation address recovery
b07a318afca16 i3c: master: Introduce optional Runtime PM support
882ee831366a1 i3c: master: Replace WARN_ON() with dev_err() in i3c_dev_free_ibi_locked()
de2106d99b87a i3c: add sysfs entry and attribute for Device NACK Retry count
0d66830f302fd i3c: master: Make hot-join workqueue freezable to block hot-join during suspend
eb9db96a5deb3 i3c: master: add WQ_PERCPU to alloc_workqueue users
45bbc1e1fe626 i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring
d22ab94261c7b i3c: mipi-i3c-hci: Switch PIO data allocation to devm_kzalloc()
973fda38b124c i3c: mipi-i3c-hci: Allow for Multi-Bus Instances
5625b8767ce3e i3c: mipi-i3c-hci: Quieten initialization messages
2791dd42d41e3 apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()
fdf610a9a9e72 apparmor: don't audit files pointing to aa_null.dentry
b58d240883dfe apparmor: put secmark label after secid lookup
66a6c61369d41 apparmor: aa_getprocattr free procattr leak on format failure
22dc9433d458c apparmor: fail policy unpack on accept2 allocation failure
3b918f6f52390 apparmor: Fix return in ns_mkdir_op
566d1ef98a711 apparmor: remove or add symlinks to rawdata according to export_binary
fbfdb5a94a487 apparmor: fix NULL pointer dereference in unpack_pdb
57b1bd4486d56 apparmor: fix potential UAF in aa_replace_profiles
b427061ca4983 apparmor: grab ns lock and refresh when looking up changehat child profiles
9111f76e8dc8c apparmor: fix rawdata_f_data implicit flex array
ae02e603c0b39 apparmor: aa_label_alloc use aa_label_free on alloc failure
d821601323456 apparmor: check label build before no_new_privs test
ad965f36d2986 security/apparmor/apparmorfs.c: conditionally compile get_loaddata_common_ref()
045dbe89ac317 apparmor: fix refcount leak when updating the sk_ctx
d8ea44f6090c0 apparmor: fix race in unix socket mediation when peer_path is used
ef488d7429d23 apparmor: fix shadowing of plabel that prevents cache from being updated
f79519f636059 Revert "PCI/MSI: Unmap MSI-X region on error"
514b84b1bf30f PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
11016555d7510 phy: freescale: phy-fsl-imx8qm-lvds-phy: Fix missing pm_runtime_disable() on probe error path
872f9a63a108e PCI: mediatek: Use actual physical address instead of virt_to_phys()
f77c490c45d46 PCI: mediatek: Fix possible truncation in mtk_pcie_parse_port()
9ca0a78a5d561 dt-bindings: phy: sc8280xp-qmp-pcie: Disallow bifurcation register on Purwa
f1f5f8d334e91 perf symbols: Add bounds checks to read_build_id() note iteration in minimal build
cc6cd3fe8b8b1 perf symbols: Add bounds checks to elf_read_build_id() note iteration
a3e758e741228 perf bpf: Fix metadata leak in perf_env__add_bpf_info() on duplicate insert
f593775fecf5a perf bpf: Fix map data leak in bpf_metadata_create() on alloc failure
bafb6bfb346fe perf bpf: Add NULL check for btf__type_by_id() in synthesize_bpf_prog_name()
fe4d8ad2e96f4 tools lib api: Fix mount_overload() snprintf truncation and toupper range
b0385203a09f0 tools lib api: Fix filename__write_int() writing uninitialized stack data
41b3a92310450 perf tools: Use snprintf() in dso__read_running_kernel_build_id()
fbaf9bdfc0917 perf hwmon: Guard label read against empty or failed reads
d34b42ee0c74d perf symbols: Bounds-check descsz in sysfs__read_build_id() GNU fallback
bc2fc12ce6e4d perf hwmon: Fix parse_hwmon_filename() strlcpy buffer overflow
f830bb8d221f3 perf hwmon: Use scnprintf() in hwmon_pmu__for_each_event()
76dfa13a0acb1 perf hwmon: Fix off-by-one null termination on sysfs reads
56b17c84394f1 perf tools: Fix thread__set_comm_from_proc() on empty comm file
f2e5262589d94 perf intel-pt: Fix snprintf size tracking bug in insn decoder
45e7900e1555c perf symbols: Bounds-check .gnu_debuglink section data
4f883ab5bc7b7 perf symbols: Fix signed overflow in sysfs__read_build_id() size check
490473192ac2f tools lib api: Fix missing null termination in filename__read_int/ull()
09962b811ef14 perf pmu: Fix perf_pmu__parse_scale/unit() OOB access on empty sysfs file
a6eec54329b43 perf pmu: Fix pmu_id() heap underwrite on empty identifier file
e274dfa05904f perf cs-etm: Queue context packets for frontend
fa9eb50ddfea3 perf s390: Fix TEXTREL in Python extension by compiling as PIC
b5a0a4a564d21 xprtrdma: Return sendctx slot after Send preparation failure
007b4da2f38dc xprtrdma: Repost Receive buffers for malformed replies
469b22376ee73 xprtrdma: Sanitize the reply credit grant after parsing
d7a2870dde3bb xprtrdma: Fix bcall rep leak and unbounded peek
345652531400f xprtrdma: Resize reply buffers before reposting receives
47b3dc59e09e9 xprtrdma: Document and assert reply-handler invariants
7471e66373a44 xprtrdma: Check frwr_wp_create() during connect
28743571c17b5 xprtrdma: Initialize re_id before removal registration
d0479c2b12974 xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
6d52921f47020 perf hists: Fix snprintf() in hists__scnprintf_title() UID filter path
56ad33189ed5f perf bpf: Use scnprintf() in snprintf_hex() and synthesize_bpf_prog_name()
c32fe40b0c745 perf sched: Fix idle-hist callchain display using wrong rb_first variant
77051ef66e4ad perf sched: Bounds-check prio before test_bit() in timehist
2e0dd50e5a4da PCI: rcar-host: Remove unused LIST_HEAD(res)
b9e8406651dcc perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
504028f561b19 perf tools: Use scnprintf() in cpu_map__snprint() to prevent overflow
2a8244988316a perf tools: Fix get_max_num() size_t underflow on empty sysfs file
3f4476a089a6d platform/x86/intel/vsec: Restore BAR fallback for header walk
d6565e08166c8 platform/x86/intel/vsec: Return real error codes from registration path
4df30a4dc0e97 platform/x86/intel/vsec: Switch exported helpers from pci_dev to device
817ab332d37ce platform/x86/intel/vsec: Decouple add/link helpers from PCI
e6523bcafeb61 platform/x86/intel/vsec: correct kernel-doc comments
c0d97519c9dfb platform/x86:intel/pmc: Relocate lpm_req_guid to pmc_reg_map
b95e1facc5b7f platform/x86:intel/pmc: Rename PMC index variable to pmc_idx
3e86797c0699d platform/x86:intel/pmc: Add support for multiple DMU GUIDs
4f129fc6f756f fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
d3491b23bc207 PCI: meson: Add missing remove callback
a5c0ba31eef9e PCI: meson: Propagate devm_add_action_or_reset() failure
f0aaa198e068b pwm: rzg2l-gpt: Add missing newlines to dev_err_probe() messages
a57692ad365f3 PCI: mediatek: Fix operator precedence in PCIE_FTS_NUM_L0 macro
f161ef7b0dd2f nfs: use nfsi->rwsem to protect traversal of the file lock list
a6f147b23e361 NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS in pg_get_mirror_count_write
a70375f0b793e NFSv4/flexfiles: honor FF_FLAGS_NO_IO_THRU_MDS on fatal DS connect errors
b694c7de94bc5 nfs: keep PG_UPTODATE clear after read errors in page groups
f84949dd17847 NFSv4/pnfs: defer return_range callbacks until after inode unlock
53442c7d0c888 xprtrdma: Decouple req recycling from RPC completion
becc90a04780a xprtrdma: Use sendctx DMA state for Send signaling
e7ae0883c8c89 xprtrdma: Post receive buffers after RPC completion
f043dd58fbd79 xprtrdma: Close lost-wakeup race in xprt_rdma_alloc_slot
b7bc8e7f09ae4 xprtrdma: Avoid 250 ms delay on backlog wakeup
44b73b4b7eff7 pNFS/filelayout: fix cheking if a layout is striped
f3f21b94cf980 sunrpc: Fix error handling in rpc_sysfs_xprt_switch_add_xprt_store()
e8dc126e80395 clk: qcom: a53: Corrected frequency multiplier for 1152MHz
c0e6bb2b0408f dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor
9f1ef67c041ef dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
329ec20a86091 dmaengine: Fix possible use after free
7d49f0ddaf5a4 dmaengine: qcom: gpi: set DMA_PRIVATE capability
8e2c460a8f0e4 mshv: add bounds check on vp_index in mshv_intercept_isr()
eaf937b501fd0 clk: qcom: camcc-x1e80100: Add support for camera QDSS debug clocks
032692e4525a0 dt-bindings: clock: qcom: Add X1P42100 camera clock controller
c7c8bab87d0df perf tools: Fix int16_t truncation of max_cpu_num in set_max_cpu_num()
e16012f8f63d3 perf timechart: Fix cpu2y() OOB read on untrusted CPU index
330219fe8523f perf c2c: Fix use-after-free in he__get_c2c_hists() error path
01564c1a260f6 perf stat: Introduce perf_env__get_cpu_topology() to guard NULL env->cpu
c05ba5b57505a perf mmap: Fix NULL deref in aio cleanup on alloc failure
c4406dbe5d8f4 perf sched: Replace BUG_ON and add NULL checks in replay event helpers
b1f7683632712 perf sched: Use thread__put() in free_idle_threads()
1517402d0a81c perf sched: Clean up idle_threads entry on init failure
d6b586bb8f489 perf c2c: Bounds-check CPU IDs in setup_nodes() topology loop
2f9f7224e7691 perf c2c: Bounds-check CPU and node IDs before bitmap and array access
278e30717c356 perf stat: Bounds-check CPU index in topology aggregation callbacks
21a9b87ada08d perf mmap: Guard cpu__get_node() return in aio_bind()
652cea73b7b7b perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
068e9b6a07bc0 perf sched: Cap max_cpu at MAX_CPUS in timehist sample processing
1d25a8418c890 perf tools: Add bounds check to cpu__get_node()
89489a31f4443 perf sched: Fix thread reference leak in latency_switch_event
ea486d61b1663 perf tools: Guard test_bit from out-of-bounds sample CPU
18961e0f8966e perf annotate: Fix crashes on empty annotate windows
93f3e84fc74e6 perf: Fix off-by-one stack buffer overflow in kallsyms__parse()
d78b16d078149 dt-bindings: dma: nvidia,tegra186-gpc-dma: Make reset optional
a498063f95bdd dmaengine: imx-sdma: Refine spba bus searching in probe
da40583823153 thunderbolt: debugfs: Fix margining error counter buffer leak
038a0f01dda59 drm/amd/display: Add missing kdoc for ALLM parameters
c5388a957cf1d fs/ntfs3: fix mount failure on 64K page-size kernels
a318932065883 fs/ntfs3: add bounds check to run_get_highest_vcn()
097fcf945d93a HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter
26fa946925a09 clk: at91: keep securam node alive while mapping it
0147c544cbc6e iio: tcs3472: power down chip on probe failure
1cddef80a180a iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
9ac3675bf8757 iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
3d57672119525 iio: magnetometer: ak8975: fix potential kernel stack memory leak
6ec473b360342 iio: light: si1133: prevent race condition on timeout
f835b69fbeaeb iio: light: si1133: reset counter to prevent race condition
fd6b65ade1190 perf header: Sanity check HEADER_EVENT_DESC attr.size before swap
be62602fe0797 PCI: qcom: Disable ASPM L0s for SA8775P
de93ef83f99e8 powerpc tools perf: Initialize error code in auxtrace_record_init function
96c8f732cadf7 clk: renesas: rzg2l: Rename iterator in for_each_mod_clock() to avoid shadowing
fdee9f207a48c gpib: fix double decrement of descriptor_busy in command_ioctl()
3d5e4cc0d9dce char: tlclk: fix use-after-free in tlclk_cleanup()
d72ece584c448 gpib: Fix inappropriate ioctl error return
92f8b1d833834 perf test amd ibs: Fix incorrect kernel version check
2b2b1613b734b usb: host: max3421: Reject hub port requests for non-existent ports
02d03c61e8a7b usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
43078449ad623 staging: most: video: avoid double free on video register failure
45652323ce74b perf inject: Add --convert-callchain option
28ebd287a7fad perf build-id: Fix off-by-one bug when printing kernel/module build-id
fc5ce5606db57 PCI: dwc: Fix signedness bug in fault injection test code
7d881615fb637 mailbox: mtk-adsp: fix UAF during device teardown
91353d63bbf61 mailbox: mpfs: fix check for syscon presence in mpfs_mbox_inbox_isr()
e6bc4e127707d coresight: Fix source not disabled on idr_alloc_u32 failure
67d0475e78b39 soundwire: intel_ace2x: release bpt_stream when close it
5732869c70d42 clk: at91: sam9x7: Fix gmac_gclk clock definition
f28906e7e32fd perf pmu: Skip test on Arm64 when #slots is zero
210c202c0576b phy: phy-can-transceiver: Check driver match and driver data against NULL
226feccaac818 clk: qcom: cmnpll: Account for reference clock divider
6abdf27fbcfb3 coresight: fix missing error code when trace ID is invalid
5bb87456dcd66 bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
601a9b2e3b2fb rust: alloc: fix assert in `Vec::reserve` doc test
b773c7161cea7 PCI: loongson: Do not ignore downstream devices on external bridges
e1b79f77336d1 perf sched: Add missing mmap2 handler in timehist
c788955b4a145 platform/x86: xo15-ebook: Fix wakeup source and GPE handling
2ce4d93768d2c x86/platform/olpc: xo15: Drop wakeup source on driver removal
1d495446ec7ac PCI: Check ROM header and data structure addr before accessing
78f264c0cb2ac PCI: Introduce named defines for PCI ROM
10021c2d33061 PCI/ASPM: Don't reconfigure ASPM entering low-power state
48dde5c56426c coresight: etm4x: Correct TRCVMIDCCTLR1 save and restore
65d87f28daec3 coresight: ete: Always save state on power down
1ac8f4c112aa9 coresight: etm4x: Remove the state_needs_restore flag
a454f61747c97 soundwire: fix bug in sdw_add_element_group_count found by syzkaller
d3896c944338c soundwire: don't program SDW_SCP_BUSCLOCK_SCALE on a unattached Peripheral
c3ca7c6741af3 coresight: cti: Fix DT filter signals silently ignored
fb940466fd4d3 perf debuginfo: Fix libdw API contract violations
bb3d592c7d6c4 staging: nvec: fix use-after-free in nvec_rx_completed()
466c7f87de52d i3c: master: svc: Fix missed IBI after false SLVSTART on NPCM845
db2d8b6525bdd gpiolib: acpi: Only trigger ActiveBoth interrupts on boot
02e2dadd62eae eventpoll: Fix epoll_wait() report false negative
f938bc8fde518 eventpoll: rename epi->next and txlist for clarity
430dac191905b eventpoll: wrap EP_UNACTIVE_PTR in typed sentinel helpers
d8f88803152f0 eventpoll: extract ep_deliver_event() from ep_send_events()
4fd51f413d7b5 eventpoll: split ep_insert() into alloc + register stages
25e85dc040a6c eventpoll: rename attach_epitem() to ep_attach_file()
baebd892f8a2c eventpoll: expand top-of-file overview / locking doc
f04166c8677aa eventpoll: rename ep_remove_safe() back to ep_remove()
13bf9879b778b net/9p: fix race condition on rdma->state in trans_rdma.c
9c1c120471a67 9p: avoid returning ERR_PTR(0) from mkdir operations
ae1f3460833d3 ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
d35e4032f16d7 mfd: cs42l43: Sanity check firmware size
706fe1ce4f3a5 mfd: rsmu: Fix page register setup
35d3d6ff2bc1e ksmbd: fix use-after-free in same_client_has_lease()
aa0c43c13c0bf RDMA/bnxt_re: Fail DBR related page allocation UAPIs if the feature is disabled
0fe155aa844e4 RDMA/bnxt_re: Move the UAPI methods to a dedicated file
95d46a8d3ba9f RDMA/bnxt_re: Avoid displaying the kernel pointer
104a7ff382a58 RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
5a48dd5150d7c ionic: Fix check in ionic_get_link_ext_stats
4c55003566c0b net: ethernet: oa_tc6: Remove FCS size in RX frame
93e133b9193cb net: airoha: Fix always-true condition in PPE1 queue reservation loop
d774cdbda6634 tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
0d8a12d714312 tipc: fix UAF in tipc_l2_send_msg()
db1616263a2c5 KEYS: Use acquire when reading state in keyring search
66919a6d72b9e powerpc/kexec: fix double get_cpu() imbalance in kexec_prepare_cpus
527cd14a416f2 powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down
73711688479df powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
92f38fe85198a MIPS: mm: Fix out-of-bounds write in maar_res_walk()
fe09dd288722f bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
81567d2b3f4dc sockmap: Fix use-after-free in udp_bpf_recvmsg()
073d957252696 net: remove addr_len argument of recvmsg() handlers
4e40056bb5c82 bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
264d6a79c96ee udf: fix nls leak on udf_fill_super() failure
5e8627b7a7b7c bpf: Fix bpf_get/setsockopt to tos for ipv4-mapped ipv6 socket
e803077769248 selftests/bpf: Initialize operation name before use
9f32d4c2de85f selftests/bpf: Fix typo in verify_umulti_link_info
74badb5e2b00a smb/client: always return a value for FS_IOC_GETFLAGS
21303c4a2b727 cifs: remove all cifs files before kill super
7a59146cb9ade ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait()
87d1eaffeec41 netfilter: nf_conncount: callers must hold rcu read lock
98a965cb1e767 ALSA: seq: avoid stale FIFO cells during resize
287d506d4e086 ALSA: seq: oss: Serialize readq reset state with q->lock
f01fb6138f8eb kcm: use WRITE_ONCE() when changing lower socket callbacks
4d48c08a0bf6c net: airoha: Fix debugfs new-tuple display for IPv4 ROUTE entries
dcac6e4221f39 net: airoha: Fix register index for Tx-fwd counter configuration
36edab340a067 net: bcmgenet: Use weighted round-robin TX DMA arbitration
b91b241a4eefe landlock: Fix unmarked concurrent access to socket family
1bb02353e79f7 dpll: balance create/delete notifications in __dpll_pin_(un)register
77a1ea975c877 dpll: guard sync-pair removal on full pin unregister
8008ef973f012 dpll: emit per-dpll delete notifications in dpll_pin_on_pin_unregister()
6564ce3a2f9c2 dpll: send delete notification before unregister in on-pin rollback
f1e1c6eb82482 dpll: fix stale iteration in dpll_pin_on_pin_unregister()
20575400fc1ba dpll: Enhance and consolidate reference counting logic
ebe4bd3560a7a dpll: Support dynamic pin index allocation
f7aebaee2961b net: wwan: t7xx: check skb_clone in control TX
34bd255dba321 net: ethernet: mtk_wed: debugfs: correct index in wed_amsdu_show()
1d072cc3ba433 octeontx2-af: npc: Fix size of entry2cntr_map
417bd36a085d7 bpf: Fix setting retval to -EPERM for cgroup hooks not returning errno
3d90b15fb1918 net/mlx5: Check max_macs devlink param value against max capability
8d5f4be134882 bpf: Run generic devmap egress prog on private skb
450e48271827b net/sched: sch_dualpi2: Add missing module alias
6d585d0dc6743 net: ethernet: mtk_wed: fix loading WO firmware for MT7986
446fe8ce699ce net: watchdog: fix refcount tracking races
697db22a9dcc4 net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
62ce489acb428 net: mana: initialize gdma queue id to INVALID_QUEUE_ID
bd851b10daee7 net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
755108bb7a508 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
0500af8630c32 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
a05d638b60746 virtio_net: do not allow tunnel csum offload for non GSO packets
ce311bd2e3659 tcp: clear sock_ops cb flags before force-closing a child socket
67cec2f1eb9e5 handshake: Require admin permission for DONE command
d0503357653ee power: supply: core: fix supplied_from allocations
7f4aa81f5bb27 ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO
0c22c00924359 iommu: Avoid copying the user array twice in the full-array copy helper
1c9246a199e19 spi: xilinx: use FIFO occupancy register to determine buffer size
dae23c545eb5a ALSA: seq: Fix kernel heap address leak in bounce_error_event()
1749fef4bda0f ALSA: usb-audio: qcom: Guard sideband endpoint removal
2ba2373151936 crypto: rng - Free default RNG on module exit
fb4d57b83356d crypto: cavium/cpt - fix DMA cleanup using wrong loop index
5f99a396f706a crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
4941205f5fa39 cxl/test: Add check after kzalloc() memory in alloc_mock_res()
a27481516d32f cxl/test: Unregister cxl_acpi in cxl_test_init() error path
7e401233f9bb7 tipc: reject inverted service ranges from peer bindings
3cfa3d8e0dc16 tipc: prevent snt_unacked underflow on CONN_ACK
cebaefe1aceb6 tipc: require net admin for TIPCv2 netlink mutators
66dbb13eeb2fc net/sched: sch_hfsc: Don't make class passive twice
51a1d9836acc7 net: pfcp: allocate per-cpu tstats for PFCP netdevs
ed8605c6f39b9 sctp: validate embedded address parameter length
a090880c1f544 bridge: cfm: reject invalid CCM interval at configuration time
bb4a5b3c91af3 net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
0a8b5b74f0e6b net/sched: cls_flow: Dont expose folded kernel pointers
10e05634ddc19 net: dsa: qca8k: fix led devicename when using external mdio bus
e098c9c6477df ASoC: tegra: tegra210_ahub: Validate written enum value
0f1510e84d7bf ASoC: fsl: fsl_audmix: Validate written enum values
9131e4b023e0d ASoC: codecs: hdac_hdmi: Validate written enum value
cb527e063a32e ASoC: SOF: Intel: hda-sdw-bpt: select SND_SOF_SOF_HDA_SDW_BPT properly
d3ff718c0c715 RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
4b87a2497276a RDMA/mlx5: Fix undefined shift of user RQ WQE size
1bc1487f7a7f5 RDMA/mlx5: Remove raw RSS QP restrack tracking
f704db4b0318a RDMA/mlx5: Remove DCT restrack tracking
3a1687e0506be fs: efs: remove unneeded debug prints
7e694ac97591c Bluetooth: vhci: validate devcoredump state before side effects
ec4d352747a62 Bluetooth: hci: validate codec capability element length
7f206a8d8d822 Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
a0fd1086a57b9 Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
e8815ae9dcdc5 Bluetooth: hci_event: fix simultaneous discovery stuck in FINDING
f1b4df9c260c5 Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
e284bb94ad451 Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
c86c861c64b58 s390/process: Fix kernel thread function pointer type
0eab19ab9cb1b ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset()
c83255f3cf22d arm64: dts: allwinner: a523: Add missing GPIO interrupt
ad6963c3bb458 pinctrl: airoha: an7581: fix misprint in gpio19 pinconf
5985ddfd3e83f pinctrl: airoha: an7581: add missed gpio32 pin group
db3cd694ded4c pinctrl: airoha: generalize pins/group/function/confs handling
0234e8fc296e7 pinctrl: sunxi: a523: Remove unneeded IRQ remuxing flag
46fbafe3d2d56 bpf: Tighten cgroup storage cookie checks for prog arrays
d416dcefdbac9 vfio/qat: fix f_pos race in qat_vf_resume_write()
1201dbb260507 of: cpu: add check in __of_find_n_match_cpu_property()
d2acea4f47475 cxl/test: Zero out LSA backing memory to avoid leaking to user
42a9a76f314ef cxl/test: Fix integer overflow in mock LSA bounds checks
91ad3088ee1b7 selftests/bpf: Fix bpf_iter/task_vma test
f00f5c0dd5531 ext4: fix kernel BUG in ext4_write_inline_data_end
c998a09c7144e bonding: 3ad: fix mux port state on oper down
f0ada4846d11b bonding: 3ad: fix carrier when no usable slaves
cb20a9b50efe0 bonding: 3ad: add lacp_strict configuration knob
47636f0a70b36 netlink: specs: rt-link: missed broadcast-neigh
6b2c271d2c394 tools: missed broadcast_neigh if_link uapi header
484b3b9aa7986 ext4: fix ERR_PTR(0) in ext4_mkdir()
88cb304c0be0c ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails
8b55e7ec116ca ASoC: cs35l56: Fix missing calls to wm_adsp2_remove()
3ef0cfa77a3d5 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
54556d5394382 vdpa/octeon_ep: Fix PF->VF mailbox data address calculation
86e0b37738dea tools/virtio: check mmap return value in vringh_test
321c73baf54d9 vhost/net: complete zerocopy ubufs only once
646614dcb1607 vduse: Requeue failed read to send_list head
f9d9220234451 virtio_console: read size from config space during device init
79366023aa891 virtio: rtc: tear down old virtqueues before restore
1f5f94c6c6b2e vhost/vdpa: validate virtqueue index in mmap and fault paths
a2d0a57538fd0 vduse: hold vduse_lock across IDR lookup in open path
3d56f3fb201ff ASoC: codecs: aw88261: fix incorrect masks for boost regs
ecb9be4fc8be0 spi: meson-spifc: fix runtime PM leak on remove
da6f86ff4f2dd NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
37e85be551c4d IB/mlx4: Fill in the access_flags if IB_MR_REREG_ACCESS is not specified
e6d83f877d5ab ASoC: sma1307: Fix uevent string leaks in fault worker
701ea71c17c92 igc: skip RX timestamp header for frame preemption verification
2aa37c8ef1092 btrfs: fix deadlock cloning inline extent when using flushoncommit
f85410ebf20bb btrfs: annotate lockless read of defrag_bytes in should_nocow()
18285888cb41a btrfs: zoned: always set max_active_zones for zoned devices
943f5917c53ca Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()"
ba641829c11cb btrfs: zoned: don't account data relocation space-info in statfs free space
bd5e90b0f5a09 hwmon: (it87) Clamp negative values to zero in set_fan()
ebb579c5c0f0f vfs: add FS_USERNS_DELEGATABLE flag and set it for NFS
de590cdf7efec fbdev: sm501fb: Fix buffer errors in OF binding code
0678fed27def9 wifi: ath12k: enable IEEE80211_VHT_EXT_NSS_BW_CAPABLE when NSS ratio is reported
47e5302722e09 gpio: mt7621: fix interrupt banks mapping on gpio chips
90a9c909c5b75 ALSA: aloop: Drop superfluous break
3b15d02be05e7 btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
7ec839c7c0bc1 wifi: mt76: mt7996: fix potential tx_retries underflow
ad12fdaaed16c wifi: mt76: mt7925: fix potential tx_retries underflow
3b6e6fefa57f4 wifi: mt76: mt7921: fix potential tx_retries underflow
6b8e35685c18c wifi: mt76: mt7915: fix potential tx_retries underflow
6356a829a1edc wifi: mt76: fix argument to ieee80211_is_first_frag()
42f34c478fcdf wifi: mt76: mt7996: limit work in set_bitrate_mask
1a399103cacc9 wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()
dfb27e5dd9e4d wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
06e65d6cf8049 wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
c386e90a7ce8d wifi: mt76: mt7925: validate skb length in testmode query
856fa6a21586f wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX
a10e4959a73be wifi: mt76: mt7925: keep TX BA state in the primary WCID
b8bf7c221b364 wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links
bd3b91ff13006 wifi: mt76: mt7996: add missing max_remain_on_channel_duration
c7a83899203ed wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
3f0ea6d14fa44 wifi: mt76: mt7925: clean up DMA on probe failure
ce9d5a021cfca ARM: configs: Drop duplicated CONFIG_EXT4_FS
c788617705c3a sched/fair: Fix cpu_util runnable_avg arithmetic
a2e8b5264f92e hwspinlock: qcom: avoid uninitialized struct members
bbd664b7c77f6 vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
648a3960e3664 pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39
44cff0737127b pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39
f775e7bda9a4f scsi: target: Remove tcm_loop target reset handling
c2bd9fdb448d6 scsi: target: Fix hexadecimal CHAP_I handling
0404baeb9e430 pinctrl: qcom: Fix resolving register base address from device node
298821692d447 watchdog: unregister PM notifier on watchdog unregister
637ef4961470e configfs: fix lockless traversals of ->s_children
f25d6e4ec4c25 firmware_loader: Fix recursive lock in device_cache_fw_images()
9e82497138abe ASoC: amd: acp-sdw-sof: Bound DAI link iteration
1279bdab5fa1f ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
e8d89baf92170 spi: ep93xx: fix double-free of zeropage on DMA setup failure
e123f0ab02d05 IB/mlx5: Don't mangle the mr->pd inside the rereg callback
fd284b12810e4 IB/mlx5: Pull the pdn out of the depths of the umr machinery
8119fe468b01f IB/mlx5: Remove unused mkc bits in mlx5r_umr_update_mr_page_shift()
d4f84bfa089fe IB/mlx5: Properly support implicit ODP rereg_mr
f5657d399b7ef IB/mlx5: Don't take the rereg_mr fallback without a new translation
c213b71a2d416 btrfs: don't force DIO writes to be serialized
920dcf1cb8dae thermal: testing: reject missing command arguments
dde04550fd6ff cpufreq: Documentation: fix conservative governor freq_step description
6cb635ad1006d ACPI: IPMI: Fix message kref handling on dead device
b7474f4432dd9 bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
84932636d020b powerpc/8xx: implement get_direction() in cpm1
8daa1a64711ed kunit:tool: Don't write to stdout when it should be disabled
8b0510cc3a4a0 bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
74ac1ce1f4afd ALSA: seq: Clear variable event pointer on read
c04e0cde2fa38 riscv: stacktrace: Remove bogus -0x4 offset in non-FP walk_stackframe
834d4cc067fa6 riscv: cpu_ops: Change return value type of cpu_is_stopped() to bool
4b2b6bc7f5ebe ALSA: seq: Fix partial userptr event expansion
af8f0ea1f0a3a wifi: wcn36xx: fix OOB read from short trigger BA firmware response
f03782f7f41f2 wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
1b5d8a248c3af wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
495e7e832c670 bpf: Update transport_header when encapsulating UDP tunnel in lwt
efe57b72196ae bpf: Check tail zero of bpf_prog_info
58513d6d12410 bpf: Check tail zero of bpf_map_info
2eb39de4962f8 bpf: Clear rb node linkage when freeing bpf_rb_root
f6183983ce1ff RDMA/siw: Fix endpoint/socket association handling
04255bda8d795 arm64: dts: imx8mp-kontron: Fix GPIO for display power switch
e6ab22200e449 arm64: dts: tqma8mpql-mba8mpxl: configure sai clock in audio codec as well
f3ef944c55991 arm64: dts: lx2162a-clearfog: use rev2 SoC dtsi
b5087fc4ef1f8 arm64: dts: imx95: Correct PCIe outbound address space configuration
ab4b5a07e1c1a arm64: dts: imx8mp-kontron: Reduce EERAM SPI clock frequency
f9173e0fc026c RDMA/irdma: Initialize iwmr->access during MR registration
54cab78df0375 RDMA/irdma: Fix OOB read during CQ MR registration
844a1ae78e220 ALSA: hda: fix Kconfig dependency of HD Audio PCI
47831b503ecb7 IB/cm: Fix av cm device leak on an error path in cm_init_av_by_path()
fe5414d6b3995 RDMA/hfi1: Open-code rvt_set_ibdev_name()
77b4bfc1ce32a netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp
d53eecbca16f0 netfilter: conntrack: revert ct extension genid infrastructure
e6665d36b37b4 x86/cpu: Remove obsolete aperfmperf_get_khz() declaration
dd0d22fdae4cb ALSA: usb-audio: qcom: Initialize offload control return value
8ebc31b86dccd netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
5c9c67cf7a3d1 netfilter: synproxy: fix unaligned memory access in timestamp adjustment
b171119082bab netfilter: synproxy: adjust duplicate timestamp options
4dbb71c046f72 netfilter: synproxy: drop packets if timestamp adjustment fails
dce1e3cf735d1 netfilter: nfnetlink_cthelper: use {READ,WRITE}_ONCE for accessing helper flags
7b819a84f1d5f netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures
c3ebf67cf8a96 ocfs2: fix race between ocfs2_control_install_private() and ocfs2_control_release()
a087b2d3411e7 ocfs2/dlm: require a ref for locking_state debugfs open
3fa7139b5f427 ocfs2: reject FITRIM ranges shorter than a cluster
0e389fc290c35 ocfs2: fix buffer head management in ocfs2_read_blocks()
3fe2d0d21c8ae lib: kunit_iov_iter: repeatedly call alloc_pages_bulk()
bb44a7690a4d5 ocfs2: rebase copied fsdlm LVB pointers in locking_state
9af58d10d0d8c of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
9a030fcb4b192 drm/amdkfd: always resume_all after suspend_all
b8d15e85596ad cxl/fwctl: Fix __fortify_panic
b64120d54278e xfrm: fix NAT-related field inheritance in SA migration
ac9e29b191a03 perf/x86/amd/uncore: Use Node ID to identify DF and UMC domains
58cbb1c2aadf8 perf/x86/intel/uncore: Fix discovery unit lookup for multi-die systems
4e18e9361aab0 perf/x86/amd/core: Always use the NMI latency mitigation
f5102e0fc3c6d iommu/vt-d: Fix RB-tree corruption in probe error path
7f229d27bf27c vhost: fix vhost_get_avail_idx for a non empty ring
73f9f54d71749 bpftool: Use libbpf error code for flow dissector query
4beed798daf4d drm/amdgpu: set sub_block_index for mca ras sub-blocks
e82d515092a0c ext4: fix fast commit wait/wake bit mapping on 64-bit
8cbd587e8cdb6 lockdep/selftests: Restore sched_rt_mutex state on PREEMPT_RT
8d5ed4810e479 lockdep/selftests: Restore migrate_disable() state on PREEMPT_RT
c3b073a209a9b configfs_lookup(): don't leave ->s_dentry dangling on failure
778bb4939d457 riscv: dts: sophgo: sg2042: use hex for CPU unit address
efe71fbced524 riscv: dts: sophgo: sg2044: use hex for CPU unit address
5a1168ba0a95b lib/test_meminit: use && for bools
3777588848520 tick/sched: Fix TOCTOU in nohz idle time fetch
5cf2c85b12312 bpf: Reject exclusive maps for bpf_map_elem iterators
0830287cc6cb7 driver core: Use system_percpu_wq instead of system_wq
5e406928404d6 nvme: fix FDP fdpcidx bounds check
36bdda0c86d51 sched: restore timer_slack_ns when resetting RT policy on fork
ffa974b2f50ad ext2: fix ignored return value of generic_write_sync()
8d763babb2a2f mm/fake-numa: fix under-allocation detection in uniform split
61f1972972824 bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
d81370c6c4f5f scsi: ufs: Fix wrong value printed in unexpected UPIU response case
846052542cfa6 scsi: pm8001: Fix error code in non_fatal_log_show()
0de14eae6de88 libbpf: Skip max_entries override on signed loaders
abe383999640f libbpf: Skip initial_value override on signed loaders
b6862b6a25c6a libbpf: Reject non-exclusive metadata maps in the signed loader
3a0f73d27a8d3 bpf: Reject exclusive maps as inner maps in map-in-map
91ca9eab008b9 scsi: Revert "scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans"
5c53406098b59 nvdimm/btt: Handle preemption in BTT lane acquisition
d292b30e1b746 x86/cpu: Keep the PROCESSOR_SELECT menu together
901802925ebed ARM: imx31: Fix IIM mapping leak in revision check
617a5a67ce016 ata: libata: Fix ata_exec_internal()
cfcea221db933 wifi: ath12k: fix NULL deref in change_sta_links for unready link
eb9b89baf3087 wifi: ath12k: fix incorrect HT/VHT/HE/EHT MCS reporting in monitor mode
adf0eb748d21d HID: wiimote: Fix table layout and whitespace errors
2d642797dd1c1 ARM: imx3: Fix CCM node reference leak
f0742d09eb6ba NFSD: Fix delegation reference leak in nfsd4_revoke_states
9e565962d999e ASoC: rsnd: Fix RSND_SOC_MASK width to single nibble
8ec64276ecd24 spi: atmel: fix DMA channel and bounce buffer leaks
ab4d04bf8b2f3 ext4: fix LOGFLUSH shutdown ordering to allow ordered-mode data writeback
803087a16a4ea libbpf: Skip endianness swap when loader generation failed
f3389fbaff1a1 libbpf: Skip hash computation when loader generation failed
a441c0794ac28 selftests/bpf: add verification for BPF_PROG_QUERY attr size boundaries
a7131340d0f95 bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
5ac9e793ba258 raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
b7313f23ea5a7 md/raid10: reset read_slot when reusing r10bio for discard
e04e384274f83 rpmsg: use generic driver_override infrastructure
0e2f0833556c8 Drivers: hv: vmbus: use generic driver_override infrastructure
d2cf52ba2803b cdx: use generic driver_override infrastructure
b41923dbf6769 amba: use generic driver_override infrastructure
ff4e38a37ba53 media: qcom: venus: relax encoder frame/blur step size on v6
bc7c166cc1012 media: qcom: venus: relax encoder frame/blur dimension steps on v4
ffe754288750a media: qcom: venus: drop extra padding in NV12 raw size calculation
f8f48c851a0d2 Revert "media: venus: hfi_platform: Correct supported codecs for sc7280"
5420eebf3b3c1 RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
02558c86b6b76 RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
4779f435627b2 RDMA/umem: Add ib_umem_is_contiguous() stub for !CONFIG_INFINIBAND_USER_MEM
bae436a78a058 arm64: dts: st: Fix SAI addresses on stm32mp251
5da012c605fd5 EDAC/{skx_common,skx}: Fix UBSAN shift-out-of-bounds in skx_get_dimm_info
9a84ced0243c7 EDAC/igen6: Fix call trace due to missing release()
ed5c94cf4ee9e drm/msm/dp: Fix the ISR_* enum values
bdaea74abcf0c drm/msm/dp: fix HPD state status bit shift value
6d536a9107172 sched/deadline: Reject debugfs dl_server writes for offline CPUs
4f3c17f14cf90 crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm
5eac10c521396 crypto: tegra - Fix dma_free_coherent size error
5231093c08295 crypto: inside-secure/eip93 - Add check for devm_request_threaded_irq
8572232ed74f5 crypto: hisilicon/qm - disable error report before flr
ce7a2e26e144f ocfs2: kill osb->system_file_mutex lock
3852478d34c7b ocfs2: don't BUG_ON an invalid journal dinode
070f356ea4f41 rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
598ed7393a639 dax/kmem: account for partial discontiguous resource upon removal
afdb92d9c374d arm64: tegra: Add #{address,size}-cells to Chromium-based /firmware
e545fcba3660c ARM: tegra: Add #{address,size}-cells to Chromium-based /firmware
c87339cc08aa0 libbpf: Fix UAF in strset__add_str()
39e8be33387e3 bpftool: Fix typo in struct_ops map FD generation for light skeleton
ed7ba8d048a4c libbpf: Harden parse_vma_segs() path parsing
340936ebf5aec drm/nouveau/bios: specify correct display fuse register for Ampere and Ada
2ab7c96d8c3fb drm/tegra: Fix iommu_map_sgtable() return value check
79240eee5a400 gpu: host1x: Fix iommu_map_sgtable() return value check
142b34f7e329c drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output()
8c0d3cf0d5108 gpu: host1x: Allow entries in BO caches to be freed
6b617b6ccb6eb drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove
40a2a91da02c4 drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered
05d85fd32e4fe rtla/actions: Restore continue flag in actions_perform()
b7ac7ba19a0b8 rtla: Introduce for_each_action() helper
dc266f6c4e262 iommu/amd: Fix premature break in init_iommu_one()
10753da2d659d net/sched: cls_bpf: prevent unbounded recursion in offload rollback
0db1949084e85 ipv6: guard against possible NULL deref in __in6_dev_stats_get()
dc1470299d11d workqueue: drop spurious '*' from print_worker_info() fn declaration
3e8aed5edaeeb nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
140d6fff4ed26 nvme-multipath: fix flex array size in struct nvme_ns_head
cba2ee57fd302 nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
ba3209704b3cd nvmet-tcp: fix page fragment cache leak in error path
24639c4dc466e init/initramfs_test: wait_for_initramfs() before running
eb9280ea8dbd2 pinctrl: cs42l43: Fix polarity on debounce
2739d234d8952 pinctrl: cs42l43: Fix leaked pm reference on error path
95e0b4bc29ab9 pinctrl: nuvoton: ma35d1: fix MFP register offset and pin table
c418c956c21c9 selftests: Fix Makefile target for nsfs
11165fe2c5ea0 ALSA: seq: midi: Serialize output teardown with event_input
6dc781778b595 ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
de236b813d8b4 ALSA: xen-front: Connect event channel after stream prepare
56694f00fbe10 ALSA: xen-front: Reset event channel state on stream clear
02f156309de0d mtd: spi-nor: Drop duplicate Kconfig dependency
c4bb92b3ef54c mtd: spi-nor: debugfs: Fix the flags list
3880ee7c88d78 driver core: Guard deferred probe timeout extension with delayed_work_pending()
0a294feec21b6 driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout()
2c12b0dfcedad mips: n64: add __iomem for writel call
8db227dd895a8 mips: ralink: mt7621: add missing __iomem
0c83d13f9b3f1 MIPS: DEC: Remove do_IRQ() call indirection
c9a3ceeddc6ad MIPS: Fix big-endian stack argument fetching in o32 wrapper
c9670fd84df12 PM: sleep: Use complete() in device_pm_sleep_init()
80f8e2302e639 pinctrl: meson: amlogic-a4: fix gpio output glitch
9420871183eab RDMA/counter: Fix incorrect port index in rdma_counter_init() error cleanup
66f44ec974ab3 RDMA/hns: Fix log flood after cmd_mbox failure
16138ea9833d6 RDMA/hns: Fix warning in poll cq direct mode
f67fbbfc3beb8 IB/mlx4: Fix refcount leak in add_port() error path
e59a6aa89e0fc RDMA/rxe: Fix a use-after-free problem in rxe_mmap
424d51d33c754 RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
7a551951ebeb5 pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
394ed8ad05889 bus: sunxi-rsb: Always check register address validity
090f5fb1e3e23 RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed
c11039512df49 pwm: imx27: Fix variable truncation in .apply()
13db458099f28 cpufreq: conservative: Simplify frequency limit handling
3fcbfc50dd52f cpufreq: Documentation: fix sampling_down_factor range
376951c51cdd0 crypto: eip93 - fix reset ring register definition
4a6f5cc42c7bf of: dynamic: Fix overlayed devices not probing because of fw_devlink
ae62edb00c0eb Revert "treewide: Fix probing of devices in DT overlays"
2df37ead6d84b driver core: Use mod_delayed_work to prevent lost deferred probe work
62c8cc825f49e device property: fix fwnode reference leak in fwnode_graph_get_endpoint_by_id()
b0444205ba39e kernfs: fix suspicious RCU usage in kernfs_put()
29de8448174cf writeback: drop now-unnecessary rcu_barrier() in cgroup_writeback_umount()
2469039f0fd68 arm64: dts: qcom: lemans: Add eDP ref clock for eDP PHYs
baa333b2700a7 tracing: Bound synthetic-field strings with seq_buf
09a2a7d041a78 arm64: dts: qcom: sm8750: Add power-domain and iface clk for ice node
4ba44339fd3ac arm64: dts: qcom: sm8650: Add power-domain and iface clk for ice node
3c808cac676c5 arm64: dts: qcom: sm8550: Add power-domain and iface clk for ice node
0d0ce8c7025ac arm64: dts: qcom: sm8450: Add power-domain and iface clk for ice node
a8be1bc8d124f arm64: dts: qcom: kodiak: Add power-domain and iface clk for ice node
dc36463b283d9 arm64: dts: qcom: sc7180: Add power-domain and iface clk for ice node
a2303478e7301 arm64: dts: qcom: monaco: Add power-domain and iface clk for ice node
b3e05859cb516 arm64: dts: qcom: lemans: Add power-domain and iface clk for ice node
11daac2817dca firmware: arm_scmi: Fix OOB in scmi_power_name_get()
15e7368de5842 media: rockchip: rga: fix too small buffer size
a88f6da618e8b net/sched: sch_drr: annotate data-races around cl->deficit
276e731b1b577 nilfs2: Fix return in nilfs_mkdir
16bf3154f8a80 tools/nolibc: getopt: Fix potential out of bounds access
c67c672047667 regulator: dt-bindings: mt6359: Drop regulator-name pattern restrictions
75c0bc011abdd bitops: use common function parameter names
407aeb8c1aee8 sysfs: clamp show() return value in sysfs_kf_read()
bac3e70c2fb10 firmware: arm_scmi: Read sensor config as 32-bit value
1f60c3cc302d2 firmware: smccc: Fix Arm SMCCC SOC_ID name call
3024229e4a5af riscv: dts: spacemit: set console baud rate on Milk-V Jupiter
63aa7dda9a1ed staging: media: atomisp: fix loop shadowing in ia_css_stream_destroy()
d57e67ea48e4d media: atomisp: gc2235: fix UAF and memory leak
2e3e4cc0dd349 media: atomisp: Fix memory leak in atomisp_fixed_pattern_table()
5d6f34dc4f056 arm64: dts: imx95-19x19-evk: Fix PCIe EP vpcie-supply
084d7d5668f30 arm64: dts: imx8qxp-mek: Remove unnecessary PCIe EP vpcie-supply
6a576739ce4c9 arm64: dts: imx8dxl-evk: Remove unnecessary PCIe EP properties
0da72a88dbbab firmware: arm_ffa: Honor partition info descriptor size
5e353d9497f95 selftests/mm: Fix resv_sz when parsing arm64 signal frame
6a357ceb21100 iommu/arm-smmu-qcom: Fix fastrpc compatible string in ACTLR client match table
bcfc49f1bcf1b selftests/bpf: Fix test for refinement of single-value tnum
e4d599a286b5a selftests/bpf: Reject unsupported -k option in vmtest.sh
7471006cd854d drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
be2c137f23d15 RDMA/hns: Initialize seqfile before creating file
65572fbd86033 RDMA/srpt: fix integer overflow in immediate data length check
5100febf8e9d6 RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
ffa85a2c19793 RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
2cd221fca036b RDMA/hns: Fix arithmetic overflow in calc_hem_config()
65e344925fa30 IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
b61af0268e3d1 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
5c1196b5a3bf3 net/sched: sch_htb: annotate data-races (I)
d8cae30582f06 net/sched: sch_htb: do not change sch->flags in htb_dump()
68eae3592438d spi: hisi-kunpeng: Use dev_err_probe() for host registration failure
21650fe221ea9 crypto: ccp - Treat zero-length cert chain as query for blob lengths
cb414aff28e18 scsi: hisi_sas: Add slave_destroy interface for v3 hw
8b42290df1765 net/sched: sch_hfsc: annotate data-races in hfsc_dump_class_stats()
d29b9c38f6eb4 clk: scpi: Unregister child clock providers on remove
69bc4a3998742 thermal: hwmon: Fix critical temperature attribute removal
a0f64cf8bfcb3 evm: terminate and bound the evm_xattrs read buffer
4c57df82af833 drm/hisilicon/hibmc: use clock to look up the PLL value
28b91fd2adc4f drm/hisilicon/hibmc: move display contrl config to hibmc_probe()
94ab8a6e02bae drm/hisilicon/hibmc: fix no showing when no connectors connected
689bb48c828ca drm/hisilicon/hibmc: add updating link cap in DP detect()
27af16a44f590 arm64: dts: qcom: sm8450: Fix ICE reg size
886fb63981a92 arm64: dts: qcom: kodiak: Fix ICE reg size
2e2e5888764ba clk: scmi: Fix clock rate rounding
8200ffd8259f0 rust: alloc: fix `Vec::extend_with` SAFETY comment
9fe7605c1c143 arm64: dts: mediatek: mt8192-asurada: Move PCIe DMA bounce buffer to host
02367b12b303a uaccess: fix ignored_trailing logic in copy_struct_to_user()
e003f3a4be738 bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
8960088511ca1 soc: mediatek: mtk-mmsys: Restore MT8167 routing masks lost during merge
0dd1cf48a4217 iommu/amd: Fix a stale comment about which legacy mode is user visible
feb10ab7abc24 media: venus: scale MMCX power domain on SM8250
9e642727b97dd media: iris: scale MMCX power domain on SM8250
e725aedd26e96 media: qcom: camss: vfe: fix PIX subdev naming on VFE lite
f9f1a2cd912da nilfs2: fix backing_dev_info reference leak
712714f818d83 dlm: fix add msg handle in send_queue ordered
4695cfab48f90 ARM: multi_v7_defconfig: Correct QCOM_RPMH and QCOM_RPMHPD
6acd2fbd00f9c crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
9b21d5bd33a7f crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve
aac63bbea8fd5 crypto: atmel-sha204a - fix blocking and non-blocking rng logic
c5c79d92da0f9 crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
25b0061adc1c1 crypto: ccp - Reverse the cleanup order in psp_dev_destroy()
46696b0b21234 OPP: Fix race between OPP addition and lookup
8fe4736532639 alarmtimer: Remove stale return description from alarm_handle_timer()
224d7300b5691 drm: renesas: rz-du: mipi_dsi: Fix return path on error
4a8cde6f7281e vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
470984f1c2ed8 Revert "arm64: dts: imx8mp-kontron: Add support for reading SD_VSEL signal"
5f7777f0da030 Revert "arm64: dts: imx8mm-kontron: Add support for reading SD_VSEL signal"
b9c6ad49a942d arm64: dts: imx8x-colibri: Correct SODIMM PAD settings
a5e026d5b9487 arm64: dts: rockchip: fix rk809 interrupt pin on rk3566-roc-pc
6173c83d4d791 arm64: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
2b553fcec1cd8 ARM: dts: rockchip: Add #{address,size}-cells to Chromium-based /firmware
d003d9bb44da1 drm/panel: Clean up S6E3HA2 config dependencies and fill help text
76a4c3af3253d drm/gpuvm: take refcount on DRM device
02b001d89157a dt-bindings: vendor-prefixes: Add Displaytech Ltd.
a402b3d093815 pinctrl: sunxi: fix regulator leak in sunxi_pmx_request() error path
c599af2eacd66 dts: spacemit: set console baud rate on bpif3
796ff973077c7 lib/vsprintf: Fix to check field_width and precision
53baa6b90f499 crypto: qat - fix heartbeat error injection
928f758f8f214 memory: tegra: Wire up system sleep PM ops
2b2a17af8d8c7 media: v4l2-common: Add YUV24 format info
4534f70aa7042 media: cedrus: Fix failure to clean up hardware on probe failure
facbb592e22dd watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure
1917015aa0a1d watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5
d6e8d6b2f8f04 watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH
29fd4f4c73e2b Documentation/rv: Replace stale website link
19eb0ab0bdffb ARM: dts: am335x-sl50: Fix audio bitclock and frame master endpoint
5435fd3edcb11 wifi: ath9k: fix OOB access from firmware tx status queue ID
7c79be7e63447 pinctrl: mediatek: eint: Drop base from mtk_eint_chip_write_mask()
a83e77d1e52c0 soc: xilinx: Shutdown and free rx mailbox channel
fbeea02c3564d kconfig: fix potential NULL pointer dereference in conf_askvalue
ad445de67359f wifi: rtw89: add bounds check on firmware mac_id in link lookup
01155ded5d4da wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer
7a1ab5fdcae89 wifi: rtw89: Correct data type for scan index to avoid infinite loop
1ef3d1338d94e wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
aefc30e4a829c wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
cc77f0d91e321 driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
543ed0f61d565 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc
1638e178e4915 dt-bindings: pinctrl: nvidia,tegra234: Add missing required block
cc6ef5ee7d88a arm64: tegra: Fix Tegra234 MGBE PTP clock
228db770fb086 wifi: cfg80211: fix grammar in MLO group key error message
123e1cd95ba54 arm64: dts: qcom: sdm845-mezzanine: Fix camss ports unit_address_vs_reg warning
d8367ee271aba arm64: dts: qcom: sc8180x: Fix phy simple_bus_reg warning
d72ae2c63b683 arm64: dts: qcom: ipq5424: Fix USB simple_bus_reg warnings
8f8233d544aca arm64: dts: rockchip: Fix gmac0 reset pin for NanoPi R5S
58d0b4c55cdfd arm64: dts: rockchip: fix Ethernet PHY not found on PX30 Cobra
6005cdd9f48fd Documentation: proc: fix section numbering in table of contents
d10227f899c90 selftests/bpf: Use local type for bpf_fou_encap in test_tunnel_kern
595710e6838c3 selftests/bpf: Use local type for flow_offload_tuple_rhash in xdp_flowtable
2dfe817167af0 drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro
afea00ffcf41c dt-bindings: timer: Remove sifive,fine-ctr-bits property
bc4737e55ec41 selftests/bpf: Fix off-by-one in bpf_cpumask_populate related selftest
392c03362c278 libbpf: Report error when a negative kprobe offset is specified
06dc892561f5a drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
d9dfa176899d4 drm/radeon: fix integer overflow in radeon_align_pitch()
daf5d03ddb8cc drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch()
41a60487b5b04 drm/gpuvm: Do not prepare NULL objects
353f26c74660b drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
626fa93d194db drm/tidss: Drop extra drm_mode_config_reset() call
ab487bb0402af drm/rockchip: Test for imported buffers with drm_gem_is_imported()
b3ec263a719e0 drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
0d60b835bca42 drm/rockchip: dw_dp: Switch to drmm_kzalloc()
68dc52f308a17 accel/amdxdna: Fix leak when pinning ubuf pages
8e644d9a8c8dc clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive()
d50d320e88b4c openrisc: mm: Fix section mismatch between map_page and __set_fixmap
24186d6f9b07e fbcon: Use correct type for vc_resize() return value
6617df8c24631 fbcon: fix NULL pointer dereference for a console without vc_data
231414253b648 afs: Fix uncancelled rxrpc OOB message handler
8b4d1854295b0 afs: Fix further netns teardown to cancel the preallocation charger
cc848a080f7a6 afs: handle CB.InitCallBackState3 requests without a server record
23b3d457d8387 afs: fix NULL pointer dereference in afs_get_tree()
b83ecf80e28af afs: Fix netns teardown to cancel the preallocation charger
8cd8cf3052fff rxrpc: Fix double unlock in rxrpc_recvmsg()
a89a13aea38ae rxrpc: Fix leak of connection from OOB challenge
f9be514984471 rxrpc: Fix the reception of a reply packet before data transmission
8db6a2c95e369 rxrpc: Fix ACKALL packet handling
647e8e69c6ea3 rxrpc: Fix oob challenge leak in cleanup after notification failure
7940e5c535489 rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate
0fc5b37faec26 rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
2b69b61057eb0 rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
0d643a46fdea6 rxrpc: Fix socket notification race
844b8525ce503 rxrpc: Fix UAF in rxgk_issue_challenge()
9ada3931beb37 rxrpc: Don't move a peeked OOB message onto the pending queue
d3b642cf95d48 rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
35a967ff8b24d rxrpc: serialize kernel accept preallocation with socket teardown
2ecd118fb6913 serial: 8250_omap: clear rx_running on zero-length DMA completes
c37095c431c39 serial: max310x: implement gpio_chip::get_direction()
d354716245192 serial: msm: Disable DMA for kernel console UART
03fd857c33456 dt-bindings: power: imx93: Add MIPI PHY power domain
d97a6b4a5a4fb dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties
79982331c1738 media: uvcvideo: Fix sequence number when no EOF
19cb644d0ca59 media: uvcvideo: Relax the constrains for interpolating the hw clock
bf58be93c51ba media: uvcvideo: Do not add clock samples with small sof delta
aed8111f2392d media: uvcvideo: Fix dev_sof filtering in hw timestamp
0f64f808fb4ee media: uvcvideo: Fix buffer sequence in frame gaps
1a9baac645769 media: uvcvideo: Avoid partial metadata buffers
caf800e0cab94 media: uvcvideo: Use hw timestaming if the clock buffer is full
6b2c0cd5f9689 ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7
2f33044aedd7a ALSA: hda: Fix cached processing coefficient verbs
ae7f5b05d225c ALSA: hda: conexant: Remove mic bias threshold override
12e43f99242b0 ALSA: hda/realtek: Add quirk for TongFang X6xx45xU
e0a71cbf0c190 af_unix: Drop all SCM attributes for SOCKMAP.
9b6c12e1a6be0 iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19
a4fb0954f3dc2 iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19
62dde71ca2c8c exfat: preserve benign secondary entries during rename and move
f3a0dd2d88e83 selftests/bpf: Add tests for stale delta leaking through id reassignment
985b8a0e52c58 selftests/bpf: Add tests for delta tracking when src_reg == dst_reg
d75376fbc8563 bpf: Clear delta when clearing reg id for non-{add,sub} ops
19836e8145de9 selftests/bpf: Add a test cases for sync_linked_regs regarding zext propagation
07259d661c9d4 selftests/bpf: Add tests for improved linked register tracking
564e4ce9fb401 selftests: bpf: Add test for multiple syncs from linked register
3659deaf7bf69 media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
c401492e01c7b crypto: sun4i-ss - Remove insecure and unused rng_alg
088ee46c18d99 nvmet-tcp: Fix potential UAF when ddgst mismatch
2ed3c9d955e8c nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
588718101e844 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
c646431865f4b KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
d7860b682da55 crypto: algif_skcipher - force synchronous processing
de5a46f3b2c8d tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
e0caf7c3d49c7 smb/server: do not require delete access for non-replacing links
bbf04810b2a06 nvme-pci: DMA unmap the correct regions in nvme_free_sgls
40e44eff5116d perf trace: Deal with compiler const checks
30bbd7e8999d1 perf trace: Don't change const char strings
bc29e0699b35d perf diff: Constify strchr() return variables
292f32503eda3 perf list: Don't write to const memory
d03adc7039c39 perf list: Signal changing const memory is ok
4283a813d7089 perf tp_pmu: Address const-correctness errors in recent glibcs
018533cfe83cf perf units: Constify variables storing the result of strchr() on const tables
e7d3f92238a3d perf hwmon_pmu: Constify the variables returning bsearch() on const tables
5bcff7ce5c3b1 perf tools: Use const for variables receiving str{str,r?chr}() returns
ee8ab4e8e7029 perf metricgroup: Constify variables storing the result of strchr() on const tables
8bac35a8fd98f perf trace-event: Constify variables storing the result of strchr() on const tables
a816153dd8575 perf demangle-java: Constify variables storing the result of strchr() on const tables
f8cb25b1d5ed2 perf session: Don't write to memory pointed to a const pointer
5f6d997641de9 perf bpf-event: Constify variables storing the result of strchr() on const tables
3b540ba9606bf perf tools: Switch printf("...%s", strerror(errno)) to printf("...%m")
659a56ba86a96 perf list: Remove unused 'sep' variable
33250aa5cfade perf jitdump: Constify variables storing the result of strchr() on const tables
972c65697792c perf time-utils: Constify variables storing the result of strchr() on const tables
9ae21594ee518 perf strlist: Remove dont_dupstr logic, used only once
110ce8fed0f8e perf strlist: Don't write to const memory
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 197a98e6e4883e47335df4d8a742980ab0a2a6a4)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.18.bb | 6 ++---
.../linux/linux-yocto-tiny_6.18.bb | 6 ++---
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
3 files changed, 18 insertions(+), 18 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index 9d44c803eb9..37570538857 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "56572c42354027a50e261f16fe13b057604873e7"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 7ff47505aa0..5addcaae07e 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
include recipes-kernel/linux/cve-exclusion.inc
include recipes-kernel/linux/cve-exclusion_6.18.inc
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 6111ae89daa..3ceba003fa4 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.18/standard/base"
KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
-SRCREV_machine:qemuarm ?= "78e0248ce3cecd33f63926cd1d54c64e163d076c"
-SRCREV_machine:qemuarm64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuloongarch64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
+SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8"
+SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuriscv64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemuriscv32 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemux86 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_machine:qemux86-64 ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
+SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "9eb7db1359675f27707b030ba228f381c10cd53e"
-SRCREV_meta ?= "2f71b0a288c307062fc60948ac793d8d51c685e2"
+SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "f89c296854b755a66657065c35b05406fc18264d"
+SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.18/base"
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.39"
+LINUX_VERSION ?= "6.18.41"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
` (35 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:
7b923c78b50d2 Linux 6.18.43
bfe7f9993467b x86/bugs: Make Safe-RET robust against interrupt injection
856a9b51680cb Linux 6.18.42
0f33b1c457c21 KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug
846ed916cfa0c gpu: Fix uninitialized buddy for built-in drivers
bcb29986bbba8 net: stmmac: fix dwmac4 transmit performance regression
a0d1a11b90a51 net/mlx5e: Fix NULL pointer dereference in ioctl module EEPROM query
f282242906c12 usb: gadget: f_tcm: synchronize delayed set_alt with teardown
aeebcfa8237c3 rust: device: avoid trailing ; in printing macros
e94e820df37d4 rust: allow `suspicious_runtime_symbol_definitions` lint for Rust >= 1.98
6ce0db97fb37a mm/damon/core: disallow overlapping input ranges for damon_set_regions()
4b6f1d6d5d078 mm/damon/core: validate ranges in damon_set_regions()
deead12d2e650 i3c: mipi-i3c-hci: Fix handling of shared IRQs during early initialization
811b581fae651 i3c: mipi-i3c-hci: Fix Hot-Join NACK
4fd5b33faf092 pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI
c389893bb4037 pmdomain: imx93-blk-ctrl: convert to devm_* only
dc8347f263b21 net: ipa: fix SMEM state handle leaks in SMP2P init
4c1e8ccd8655e ata: libata-core: Reject an invalid concurrent positioning ranges count
9466dc5e377f0 bootconfig: fix NULL-pointer arithmetic in xbc_snprint_cmdline()
a88c2a70ea0ad bootconfig: move xbc_snprint_cmdline() to lib/bootconfig.c
c73b8795b45f4 octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF
4467fa514482b octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
ae5ae3d5bfaa6 net: mana: Optimize irq affinity for low vcpu configs
6d13eaa13341a net: mana: Validate the packet length reported by the NIC
7b7bb07efe41b fs/resctrl: Fix use-after-free during unmount
d48cf914c739e fs/resctrl: Move RMID initialization to first mount
682d3c2cd20e0 fs/resctrl: Move allocation/free of closid_num_dirty_rmid[]
8c5925f0fa128 x86,fs/resctrl: Rename some L3 specific functions
696c34a1964f4 x86,fs/resctrl: Rename struct rdt_mon_domain and rdt_hw_mon_domain
ad4ea2a169a48 fs/resctrl: Split L3 dependent parts out of __mon_event_count()
5b82af744e06c mmc: vub300: fix use-after-free on probe failure
73d397ab54f2a mmc: vub300: rename probe error labels
8ced1d242c34e dm: avoid leaking the caller's thread keyring via the table device file
dd73cc92a55d7 cred: add kernel_cred() helper
af7a4c2caa7a1 accel/amdxdna: reject command submission on devices without a submit op
62dae36be7a62 ovl: use linked upper dentry in copy-up tmpfile
043acb00e4edd dmaengine: dw-edma-pcie: Reject devices without driver data
277a035cda47d dmaengine: dw-edma: Fix confusing cleanup.h syntax
19360c25135fc mtd: maps: vmu-flash: fix fault in unaligned fixup
b8271be34bce1 kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
3d561f46fa784 mm/sparse-vmemmap: fix vmemmap accounting underflow
8af652cd99460 remoteproc: xlnx: Check remote core state
6fc1919a6f2ed cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
89b2ae039d188 cxl/pci: Remove CXL VH handling in CONFIG_PCIEAER_CXL conditional blocks from core/pci.c
eeab775069920 cxl/pci: Remove unnecessary CXL RCH handling helper functions
a64661dccb2eb cxl/pci: Remove unnecessary CXL Endpoint handling helper functions
5d964cb2b7bc8 SUNRPC: Return an error from xdr_buf_to_bvec() on overflow
b50b2cb87e7ac SUNRPC: Add helpers to convert xdr_buf byte ranges to scatterlists
a112b91dd6349 sunrpc: allocate a separate bvec array for socket sends
3120f21df3fb0 NFSD: pass nfsd_file to nfsd_iter_read()
6876f767b0490 pinctrl: renesas: rzg2l: Use -ENOTSUPP instead of -EOPNOTSUPP
7185c5262435b gpu/buddy: bail out of try_harder when alignment cannot be honoured
9634fd144cdc1 drm: drop lib from header search path.
65677f7a20c48 gpu: Move DRM buddy allocator one level up (part two)
09755dc62b026 netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
a1a94a00b8844 netfilter: nf_conntrack_sip: remove net variable shadowing
d01c913febead netfilter: nft_fib: reject fib expression on the netdev egress hook
beeda5bf78577 netfilter: nf_tables: remove register tracking infrastructure
1de827e24d0ad arm64: dts: qcom: hamoa: Fix OPP tables for all DisplayPort controllers
0d810ff7a6f65 arm64: dts: qcom: correct RBR opp entry
690fb82c4122f VDUSE: avoid leaking information to userspace
7764e9c727d58 vduse: take out allocations from vduse_dev_alloc_coherent
db5c554b36d50 vduse: remove unused vaddr parameter of vduse_domain_free_coherent
82e48ad2a1326 vduse: return internal vq group struct as map token
b1f38c3ec620a xfs: don't replace the wrong part of the cow fork
3bca70235a706 fuse-uring: fix race between registration and connection abortion
40879c39d6740 audit: fix recursive locking deadlock in audit_dupe_exe()
91b64f0be4163 audit: use 'unsigned int' instead of 'unsigned'
eef6914f2b456 audit: widen ino fields to u64
c5772ced573ea landlock: Account all audit data allocations to user space
a95b62759f3b9 landlock: Fix formatting
682a0066dde05 drm/amd/display: Fix DTB DTO updates breaking live pixel rate sources
81ea8e8221853 fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
337022d9dfac4 ksmbd: validate ACE size against SID sub-authorities
f1eba60db813e ksmbd: bound DACL dedup walk to copied ACEs
847ecd4eb3c11 ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
b6d3cc6a52441 ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
17e6b8c4319fa net: qrtr: ns: Raise node count limit to 512
7dd26adf7e7d4 ublk: wait on ublk_dev_ready() instead of ub->completion
5a15eaa50f92b drm/xe/uapi: Reject coh_none PAT index for CPU_ADDR_MIRROR
5488d3a69d205 dm-verity: fix buffer overflow in FEC calculation
3f31bde63f9ae dm-verity-fec: replace {MAX,MIN}_RSN with {MIN,MAX}_ROOTS
d47281b9a4472 dm-verity-fec: fix reading parity bytes split across blocks (take 3)
a556189c06756 dm-verity-fec: fix the size of dm_verity_fec_io::erasures
22400725de070 bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
15a7cb71a5748 drm/amdgpu: fix check in amdgpu_hmm_invalidate_gfx
ab7b40c638e0d drm/amd/pm: fix smu13 power limit range calculation
6405c4e75b3bc drm/amdgpu: fix aperture mapping leak
08fee493e0261 drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
68eab5a64ddbc drm/amdgpu: fix resource leak on ACP reset timeout
ffb33d466a68c drm/amdgpu: fix division by zero with invalid uvd dimensions
8c6d84a54823c drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
bd868c077f675 drm/amdgpu/vcn4: avoid rereading IB param length
7eebef042c12d drm/amdgpu/vce: fix integer overflow in image size
f7e9eeaccca54 drm/amdgpu/soc24: reset dGPU if suspend got aborted
dc3f5da1ba8e2 drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
76c977d396f12 drm/amdgpu/jpeg: fix jpeg_v5_0_1_is_idle detection
058373af59551 drm/amdgpu/jpeg: fix jpeg_v4_0_3_is_idle detection
042c047e8bc9c drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
05aea3344c422 drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
f70bd5235d9ef drm/amdgpu/gfx8: drop unecessary BUG_ON()
987bedd3ea89d drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
dfd9bf09fd8fe drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
7e22de67e545d drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
e75f71143b68b drm/amd/pm: make pp_features read-only when scpm is enabled
ada47af5c215e drm/amd/pm: fix amdgpu_pm_info power display units
7b263cf1dd4c0 watchdog: s32g_wdt: remove incorrect options in watchdog_info struct
79370b573e92e vxlan: mdb: Fix source list corruption on a failed replace
f60bac115d8dc vsock/virtio: collapse receive queue under memory pressure
5f5a41a48dbf9 tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
234f9ffbd9b2c tcp: challenge ACK for non-exact RST in SYN-RECEIVED
fadaff3f66e12 tcp: initialize standalone TCP-AO response padding
4a4f3aa6af205 rtase: Workaround for TX hang caused by hardware packet parsing
6866abf59976d pppoe: reload header pointer after dev_hard_header()
460b9f0609d26 ovpn: hold peer before scheduling keepalive work
b08526bf0bbf8 ovpn: fix peer refcount leak in TCP error paths
100a23b1613e9 openvswitch: fix GSO userspace truncation underflow
f80ba170d7b3a mctp: serial: handle zero-length frames to prevent rx buffer overflow
f20dedce0429b mac802154: llsec: reject frames shorter than the authentication tag
59c1d5463b7bc mac802154: hold an interface reference across the scan worker
472aba2603ca7 ila: reload IPv6 header after pskb_may_pull in checksum adjust
919d0accf2600 ice: use READ_ONCE() to access cached PHC time
5e496f2b615ce ice: reject out-of-range ptype in ice_parser_profile_init
91e0249f3ef62 gve: fix Rx queue stall on alloc failure
18705cace0619 ksmbd: defer destroy_previous_session() until after NTLM authentication
6098b55f6a0cf smb: client: handle STATUS_STOPPED_ON_SYMLINK responses without a symlink target
34f2a2f32af57 rbd: Reset positive result codes to zero in object map update path
63d78b546eefc super: fix emergency thaw deadlock on frozen block devices
e4406cbdd915f ice: fix PTP Call Trace during PTP release
b3efb4744abf4 ptp: ptp_s390: Add missing facility check
9a8a247f0f17b s390/ptff: Export ptff_function_mask[]
4afc58ea75b96 proc: Fix broken error paths for namespace links
4056cc19071a3 net: pcs: xpcs: fix SGMII state reading
80d977f280b4e net: hip04: fix RX buffer leak on build_skb failure
a4dfd46cc8f08 net: gro: fix double aggregation of flush-marked skbs
ec6d91a1bf2eb net/x25: fix use-after-free in x25_kill_by_neigh()
40f9a124ebbe0 net/mlx5e: Use sender devcom for MPV master-up
900cd6d8119b7 net/iucv: fix use-after-free of a severed iucv_path
33736ff5e7c97 net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
f8c498585d2a0 geneve: require CAP_NET_ADMIN in the device netns for changelink
5d07b178bef51 net: slip: serialize receive against buffer reallocation
730c7e5fea7f0 vxlan: require CAP_NET_ADMIN in the device netns for changelink
a48a889b60f73 phonet: pep: fix use-after-free in pep_get_sb()
03157872da5ed net: stmmac: intel: skip SerDes reconfig when rate is unchanged
1b44a5f584bff iommu/vt-d: Disallow SVA if page walk is not coherent
7037e7bdcd26f iomap: fix out-of-bounds bitmap_set() with zero-length range
f139498c5ebdd io_uring/rw: fix missing ERESTARTSYS conversion in read paths
65bf73bee1a4f ftrace: Add global mutex to serialize trace_parser access
95376fe9c145b fscrypt: Add missing superblock check in find_or_insert_direct_key()
a019b074903b3 fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
c78e38745ff1b fs/super: fix emergency thaw double-unlock of s_umount
89b9121c3b016 binfmt_elf_fdpic: only honour the first PT_INTERP
d309f8b52b34c ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP
c4d77740eca21 ASoC: fsl: imx-card: Skip sysclk reset for active DAIs in shutdown
1a644db2cf59f amt: fix use-after-free in AMT delayed works
8f5a3abc54ba2 libceph: remove debugfs files before client teardown
3b2f1937f5fce libceph: reject zero bucket types in crush_decode
e67e8b694872c libceph: Reject monmaps advertising zero monitors
0060ec912292a libceph: refresh auth->authorizer_buf{,_len} after authorizer update
4716a64b7cc27 libceph: guard missing CRUSH type name lookup
1732d89dfcd74 libceph: Fix multiplication overflow in decode_new_up_state_weight()
4e7ebfaa0d14c libceph: bound get_version reply decode to front len
7d03e08b763fd ceph: fix writeback_count leak in write_folio_nounlock()
a7c2dfa610a12 ceph: fix refcount leak in ceph_readdir()
a4228b93706fb ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
3bf0e349cbb4f sctp: close UDP tunnel sockets during netns teardown
be6aae9d1b91c sctp: avoid auth_enable sysctl UAF during netns teardown
85aca407c560a sctp: don't free the ASCONF's own transport in DEL-IP processing
3db217a4c2bdc mm/huge_memory: set PG_has_hwpoisoned only after new folio head is established
ac7a6f61f56fe mm/kmemleak: fix checksum computation for per-cpu objects
f2b2933599241 afs: Fix afs_edit_dir_remove() to get, not find, block 0
d64f6c02495f3 mptcp: pm: userspace: fix use-after-free in get_local_id
6cd3c3d631555 mptcp: only set DATA_FIN when a mapping is present
6c936b5ad557e mptcp: decrement subflows counter on failed passive join
35c4b274d4cc4 Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates"
64ab0964c7db9 arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
9cd4b1a52eff3 arm64: make huge_ptep_get handled unaligned addresses
9025946adec9a tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
3b3be8653c594 tracing/probes: Fix potential underflow in LEN_OR_ZERO macro
949ac1aeb37b8 tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
6b5098d745811 tracing/eprobe: Fix exact system name matching in eprobe_dyn_event_match()
b6a4575f22925 tracing: Fix union collision of module and refcnt for dynamic events
cf5a82bef623b tracing: Fix resource leak on mmiotrace trace_pipe close
8464427e1c177 tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
1f2e7cd0ff976 tracing: Fix context switch counter truncation
1da310b94504d misc: nsm: pin the module while the device is open
8f068342096b0 misc: nsm: only unlock nsm_dev on post-lock error paths
caba30eb8bd32 intel_th: fix MSC output device reference leak
59dd34854202d mei: bus: access mei_device under device_lock on cleanup
5118872357279 selftests: ntsync: correct CONFIG_NTSYNC name
b2a3eeb57ba24 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
4fae473b856b4 serial: sc16is7xx: implement gpio get_direction() callback
635be8b097f0c uio_hv_generic: Bind to FCopy device by default
cf26dd2d84158 comedi: comedi_parport: deal with premature interrupt
9bb71b59e0aa3 x86/boot/compressed: Disable jump tables
4f2db41a09eba firmware: stratix10-svc: fix memory leaks and list corruption bugs
3ff7c1dbf722c rhashtable: clear stale iter->p on table restart
d43c5c0c93552 cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
4427a33faabb4 LoongArch: Retrieve CPU package ID from PPTT when available
38b025fcdc45b LoongArch: Move jump_label_init() before parse_early_param()
6ab0abb5a2e0c LoongArch: Fix oops during single-step debugging
a94d6726ec868 LoongArch: Fix address space mismatch in kexec command line lookup
c404b1f30b252 objtool/rust: add one more `noreturn` Rust function for Rust 1.99.0
8ccfb3b315a0e rust: allow `clippy::unwrap_or_default` globally
6db0c42c87c46 rust: time: fix as_micros_ceil() to round correctly for negative Delta
12be1d75e9b29 rust_binder: only print failure if error has source
cc3bbff10b1a7 platform/loongarch: laptop: Explicitly reset bl_powered state when suspend
1cd4e9b7967da binfmt_misc: set have_execfd only once the interpreter is opened
2bc6bf70d4105 exec: fix unsigned loop counter wrap in transfer_args_to_stack()
780b04d09c941 Bluetooth: RFCOMM: Fix session UAF in set_termios
a42f5536ea9c0 Bluetooth: hci_sync: Protect UUID list traversal
91eff666c9078 staging: rtl8723bs: fix inverted HT40 secondary channel offset
875479f18835a staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
0dbaff14fd6a8 wifi: ath11k: fix refcount leak in ath11k_ahb_fw_resources_init()
efe9de178e4b9 wifi: brcmfmac: set F2 blocksize to 256 for BCM43752
044fca8f45ba9 wifi: brcmfmac: make release_scratchbuffers idempotent
9cb72f67e1502 wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
263816e92e8d6 wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
ab4d213393e84 wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
e511e93abd6ee wifi: wilc1000: validate assoc response length before subtracting header
9375a4ea41216 wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
18965470d41e6 wifi: ath6kl: fix use-after-free in aggr_reset_state()
58c6c8dc2e022 wifi: ath6kl: fix OOB access from firmware ADDBA window size
1395327a96614 ALSA: timer: don't re-enter an instance callback that is still running
426c0ff1c433d ALSA: timer: drain a slave's callback before its master detaches it
3bc4de57fc7d1 ALSA: hda: codecs: hdmi: disable keep-alive before audio format change
6a10025c7fd09 ALSA: seq: close a re-opened queue timer in the destructor
2ec8f95a08fed ALSA: hda/realtek: Fix speakers on Lunnen Ground 14
4091b216d11b3 media: vpif_capture: fix OF node reference imbalance
1349af7f87df5 media: vivid: fix cleanup bugs in vivid_init()
492c97cb50fea media: vivid: check for vb2_is_busy() when toggling caps
26e7a8ac286f3 media: vivid: add vivid_update_reduced_fps()
3780ad3810718 media: vimc: fix reference leak on failed device registration
86ece01fba2d5 media: vidtv: fix reference leak on failed device registration
16ae8c166e787 media: verisilicon: Export only needed pixels formats
b88c929188e3c media: vb2: use ssize_t for vb2_read/vb2_write
072a883061a46 media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely
cf9732fd6c4f2 media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor()
3068ab802fc98 media: v4l2-ctrls: validate HEVC active reference counts
836cfffb2ddbb media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete()
7e6521dd747ec media: ti: vpe: unwind v4l2 device registration on probe error
127fc44e83256 media: tegra-video: vi: fix invalid u32 return value in format lookup
118c2f5d1d363 media: synopsys: hdmirx: Fix HPD lane hold time
b5184b3f0e9d4 media: sun4i-csi: Return queued buffers on start_streaming() failure
931abe1deb65b media: stm32: dcmi: unregister notifier on probe failure
ed342a86bb2f9 media: stm32-dcmipp: Return queued buffers on start_streaming() failure
b7936e8cbec1b media: saa7134: Fix a possible memory leak in saa7134_video_init1
a7a141e4e93c8 media: rzg2l-cru: Skip ICnMC configuration when ICnSVC is used
894e83509c669 media: rtl2832_sdr: Return queued buffers on start_streaming() failure
2c71bda6edc63 media: rtl2832: fix use-after-free in rtl2832_remove()
64cb15878b35e media: radio-si476x: Unregister v4l2_device on probe failure
a58d01a0ed397 media: qcom: camss: Fix RDI streaming for CSID GEN3
c39a1d9fde82b media: qcom: camss: Fix RDI streaming for CSID GEN2
4e451100b35ee media: qcom: camss: Fix RDI streaming for CSID 680
cb16b79a2be2c media: pwc: Return queued buffers on start_streaming() failure
9afd605dcd96c media: pwc: Drain fill_buf on start_streaming() failure
08ddfd628a2db media: pci: dm1105: Free allocated workqueue
4e077bcb5e1f6 media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding
28ae75dba701d media: nxp: imx8-isi: Fix potential out-of-bounds issues
659a7cea0be80 media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path
4702afbd56f1d media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure
9e61258fbc3cf media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
181a0aeefd56f media: nuvoton: npcm-video: fix memory leaks in probe and remove
2147acb948a94 media: nuvoton: npcm-video: fix error handling in npcm_video_init()
264b5380c4f8a media: msi2500: Return queued buffers on start_streaming() failure
1391b75bf0119 media: meson: vdec: Fix memory leak in error path of vdec_open
18e3b838e09d7 media: marvell-cam: fix missing pci_disable_device() on remove
cf48e9db85652 media: iris: Fix use IRQF_NO_AUTOEN when requesting the IRQ
d56044558a757 media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges
00a98fb2a6fb2 media: imx219: Fix maximum frame length in lines
7337c88205ed0 media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
c68c4ce72feb6 media: cx23885: add ioremap return check and cleanup
f468b7ee5d633 media: cx231xx: fix devres lifetime
f24ca8b53fe15 media: chips-media: wave5: Move src_buf Removal to finish_encode
9924cb548ee77 media: cedrus: skip invalid H.264 reference list entries
000e51afb6068 media: cedrus: Fix missing cleanup in error path
73504935e4365 media: cedrus: clean up media device on probe failure
6efe665356ec8 media: cec: seco: unregister adapter on IR probe failure
0459a4304cff8 media: aspeed: fix missing of_reserved_mem_device_release() on probe failure
391fe3e36e59f media: amlogic-c3: Add validations for ae and awb config
73bd277986537 media: airspy: Return queued buffers on start_streaming() failure
a096a6aba6011 drm/v3d: Reach the GMP through the hub registers on V3D 7.x
a2212fef8e187 drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
6deaa31720185 drm/vc4: Prevent shader BO mappings from becoming writable
b1379f0c42b88 drm/vmwgfx: Validate vmw_surface_metadata::array_size
2b85e19792be4 drm/amd/display: Fix missing DCE check in dm_gpureset_toggle_interrupts()
a38f2724eb93a drm/vc4: Shut down BO cache timer before teardown
ee44ea4f7e309 drm/amd/display: Fix flip-done timeouts on mode1 reset
ba7b6444097a7 drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
fd2de80f28a07 drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge
490ceacd2162d drm/amd/display: Fix backlight max_brightness to match exported range
9c0432044d34b drm/amd/display: Force PWM backlight on Lenovo Legion 5 15ARH05
51ea665c30c42 drm/amd/display: dce100: skip non-DP stream encoders for DP MST
0b9fa4272e24b drm/amd/display: consolidate DCN vblank/flip handling onto vupdate_no_lock
679f23f0a3606 drm/amd/display: set new_stream to NULL after release
123692ebc1ea7 drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X)
d8dc3a9e815d6 drm/amdgpu: Fix VFCT bus number matching with soft filter
312278b309191 drm/amdgpu: Release VFCT ACPI table reference
e64b2f1e826af drm/panthor: return error on truncated firmware
22aa7fb4e7d0b drm/ttm: Account for NULL and handle pages in ttm_pool_backup
b2d8b66c67393 drm/virtio: Don't detach GEM from a non-created context
a4a1866d50c49 drm/gfx10: Program DB_RING_CONTROL
e163c5a0946de drm/amd/pm: fix smu14 power limit range calculation
e3bcd3bf7eeca drm/i915/mst: limit DP MST ESI service loop
726f27bca93e6 drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
37951ce1567cc drm/i915/gem: Do not leak siblings[] on proto context error
1173190412fb9 drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
5df5a59c32b46 drm/amd/amdgpu: disable ASPM on VI if pcie dpm is disabled
8b2da44446f9d drm/i915/bios: range check LFP Data Block panel_type2
cbec6a57959ab drm/i915: Return NULL on error in active_instance
d20b5c139b290 drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
09da54636bac1 drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
51fd520871651 drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
4c09483325360 drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
3d2ef8d389495 drm/i915/hdcp: check streams[] bounds before overflow
1f876bd8adc79 drm/i915/hdcp: require monotonically increasing seq_num_v
35be0e2c6862a drm/virtio: bound EDID block reads to the response buffer
4ee77643e6194 drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
8a77ccf9cb992 drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips
abce3276c57e3 drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
fd1691ec62701 drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
50319efb865f7 drm/amdkfd: Check bounds in allocate_event_notification_slot
14a631dca9df0 drm/amdkfd: Use kvcalloc to allocate arrays
6253bb56bb2eb drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
c45fafa69fe3f drm/imagination: fix error checking of pvr_vm_context_lookup()
b983a35dad370 drm/imagination: Fix user array stride in pvr_set_uobj_array()
c88fdbf3da26e drm/imagination: Fix double call to drm_sched_entity_fini()
c1954c66662de drm/xe: Hold a dma-buf reference for imported BOs
038d0b80ab778 drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds
90a8a938e0cae drm/xe: Return error on non-migratable faults requiring devmem
3e1f909556aa6 drm/radeon: fix r100_copy_blit for large BOs
fbb9effc81683 drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit()
45db277b2e1e3 drm/i915/gem: Add missing nospec on parallel submit slot
748d425e53c31 drm/displayid: fix Tiled Display Topology ID size
5452eb5c16630 drm/sysfb: Return errno code from drm_sysfb_get_visible_size()
154795885e8f0 drm/sysfb: Avoid possible truncation with calculating visible size
4e109faa9ea2b drm/nouveau: fix reversed error cleanup order in ucopy functions
315d2e5741a81 drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
3fb10ec43c25a drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT
9c2b01508831b drm/amdgpu/gfx9: Fix Ring and IB test fail after mode2
f835eda74cf65 drm/sysfb: Avoid truncating maximum stride
7daefc6d51952 drm/sysfb: Do not page-align visible size of the framebuffer
ddba17b3dfa0e drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
d068a2f53afc8 drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older
b3a01cda0ae16 drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2)
e28420e36542a drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
d5c70523cafa2 drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
e2c29d51c0f65 drm/imagination: Fit paired fragment job in the correct CCCB
1e5827839ad0c drm/dp/mst: fix buffer overflows in sideband chunk accumulation
533d9e2bede4a drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
c0384d6872f4d drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
943fa73ea0efa drm/imagination: Count paired job fence as dependency in prepare_job()
6ab29a8683572 drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
50cd8a7e98dd2 drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video()
86ab4d93b3d47 drm/tidss: Fix missing drm_bridge_add() call
300a2d970a535 drm: renesas: rzg2l_mipi_dsi: Move rzg2l_mipi_dsi_set_display_timing()
aa8ad3e0d1fe9 drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay
786d690257ec7 bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
3a924139cf526 net: airoha: fix ETS channel derivation in airoha_tc_setup_qdisc_ets()
391a23c503856 mctp: check register_netdevice_notifier() error in mctp_device_init()
74ecebfbf1555 ptp: netc: explicitly clear TMR_OFF during initialization
16df2d154ec82 rds: tcp: unregister sysctl before tearing down listen socket
1db34097998cc ipv6: Change allocation flags to match rcu_read_lock section requirements
684d4d0bda95a ice: prevent tstamp ring allocation for non-PF VSI types
a32604e8d9e2c ice: fix LAG recipe to profile association
3a81345467674 ice: allow creating VFs when !CONFIG_ICE_SWITCHDEV
5d54d603cf3e9 net: ipv6: fix dif and sdif mismatch in raw6_icmp_error
e60e6009d3bae octeontx2-pf: tc: fix egress ratelimiting
d612754a515cb net/mlx5e: Reject unsupported CB Shaper TSA in ETS validation
a7e430349fc5e net/mlx5e: Report zero bandwidth for non-ETS traffic classes
cdddc8188db46 net/mlx5: E-Switch, fix zero num_dest in prio_tag egress vlan rule
87b39a8c875ca net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
5f2ef3d53d374 net/mlx5: Refactor EEPROM query error handling to return status separately
953d47cfe529a raw: annotate lockless match fields in raw_v4_match()
8150c48fb978e net: qrtr: restrict socket creation to the initial network namespace
0d57d43d7c4c6 hinic: remove unused ethtool RSS user configuration buffers
8fc45a2a7cc24 ppp: annotate data races in ppp_generic
19fe119dfa93f ipv4: icmp: fill flow parameters in icmp_route_lookup decoy lookup
e037a41938c69 octeontx2-vf: set TC flower flag on MCAM entry allocation
15a1c5f2ed2ee net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
55515c1b1285a net: stmmac: enable the MAC on link up for all supported speeds
1bcb737fb884d net: stmmac: reset residual action in L3L4 filters on delete
370dde2b70e58 net: stmmac: fix l3l4 filter rejecting unsupported offload requests
55d2a8d184e24 net: stmmac: xgmac: fix l4 filter port overwrite on register update
40413da850363 net: stmmac: cores: remove many xxx_SHIFT definitions
4a3eea468a041 net: stmmac: socfpga: Add hardware supported cross-timestamp
01d45e6b2c500 net: stmmac: socfpga: Enable TBS support for Agilex5
dac8c2ab943a2 net: stmmac: socfpga: Agilex5 EMAC platform configuration
d67136a931e5f net: stmmac: remove xstats.pcs_* members
9f27c4f0ae35b bpf: tcp: fix double sock release on batch realloc
b43bb9ab60035 drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem
1b8fb5a20508b tipc: fix u16 MTU truncation in media and bearer MTU validation
c8e4b2a567efb iomap: correct the range of a partial dirty clear
279339aa8bdcf drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
d18d9b2c29a12 drm/xe/i2c: Allow per domain unique id
4fdb0f162ccdb vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
18957373920ca sctp: auth: verify auth requirement when auth_chunk is NULL
ae0ec759865e0 net: dpaa: fix mode setting
b5ded444621b6 net: hsr: fix memory leak on slave unregistration by removing synced VLANs
17bb59682b8e6 net: bridge: vlan: fix vlan range dumps starting with pvid
0a347ca1d6a2e amt: make the head writable before rewriting the L2 header
ca0e8b661957f amt: re-read skb header pointers after every pull
9ec22c8113d8c ovl: check access to copy_file_range source with src mounter creds
31f5f7c959c3e ovl: port ovl_copyfile() to cred guard
cde234a493f6d ovl: add override_creds cleanup guard extension for overlayfs
35f0b504394e0 cred: add scoped_with_kernel_creds()
3139b806923b1 drm/panel: s6e3ha8: fix unmet dependency on DRM_DISPLAY_HELPER
790da254031cc ovl: fix trusted xattr escape prefix matching
00ebbf030d8c4 wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
d5628f39fccc1 wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
95b0cf02731c7 wifi: mt76: mt7925: fix crash in reset link replay
d14238523ca4c wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
313343ab8cab7 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
c058786b09cfa wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
871549814eb4d wifi: mt76: mt7915: guard HE capability lookups
f1ee53e08fdd2 wifi: mt76: mt7925: guard link STA in decap offload
cc4d2f8b984c2 ppp: annotate concurrent dev->stats accesses
b52ff80948d1c ppp: don't store tx skb in the fastpath
cb9d3e0b55699 ppp: enable TX scatter-gather
e740e90ca8e7f tipc: fix infinite loop in __tipc_nl_compat_dumpit
d536bf205c71f nexthop: initialize extack in nh_res_bucket_migrate()
961e9b1e33445 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
023c5e0d0294a selftests: drv-net: increase timeout
fa065685c8a91 selftests: ovpn: increase timeout
e2b3d426c7ee5 selftests: ovpn: add IPV6 and VETH configs
69eab5c4d9aa6 selftests: openvswitch: add config file
340c389fd3d5d selftests: af_unix: add USER_NS config
fbd91910c5025 tls: device: push pending open record on splice EOF
a8bd8c109da5a net: mctp i3c: clean up notifier and buses if driver register fails
1a10fe1aa9c01 sctp: validate stream count in sctp_process_strreset_inreq()
c984a4184f810 pds_core: check for workqueue allocation failure
cf0ed2ba202f5 pds_core: fix auxiliary device add/del races
0e87fe52b560f pds_core: order completion reads after the ownership check
3a831f40e88d3 pds_core: yield the CPU while waiting for the adminq to drain
9e0f80fac50ab pds_core: fix use-after-free on workqueue during remove
19ef775c91c6b pds_core: fix deadlock between reset thread and remove
11092d79eb2b7 sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
2d34421bfa261 net: txgbe: fix FDIR filter leak on remove
245bfe72a5ad4 net: Call net_enable_timestamp() before failure in sk_clone().
4122792923312 soreuseport: Clear sk_reuseport_cb before failure in sk_clone().
f97d199287689 amd-xgbe: fix MAC_AUTO_SW handling in CL37 AN
e695cb9becbbb arm64: Correct value returned by ESR_ELx_FSC_ADDRSZ_nL()
f5b8b8ccf9a4a pds_core: reject component parameter in legacy firmware update
b5fcd1da05622 wifi: mac80211: recalculate TIM when a station enters power save
d06fea9b85f03 iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
e5ebe8544df1a iommu/amd: Bound the early ACPI HID map
d21464d93f8ba wifi: mwifiex: bound uAP association event IEs to the event buffer
a0980682d84d2 vhost-net: fix TX stall when vhost owns virtio-net header
59cbe6cfa0fa2 wan: wanxl: Only reset hardware after BAR mapping
3b1d4fc3b73ea nfp: Check resource mutex allocation
0f7eaeb950adb wifi: mac80211: tear down new links on vif update error path
d053eb7e09e10 iommu/amd: Wait for completion instead of returning early in iommu_completion_wait()
76fc5604308a1 net: airoha: Fix DMA direction for NPU mailbox buffer
f112df0744e2d dpaa2-eth: put MAC endpoint device on disconnect
46e3bed4b0710 net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
26ac2d3602347 dpaa2-switch: put MAC endpoint device on disconnect
c9165e199f569 rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
b78547914bee5 gtp: parse extension headers before reading inner protocol
9591042533140 rds: drop incoming messages that cross network namespace boundaries
992dce02bdabb bonding: fix devconf_all NULL dereference when IPv6 is disabled
1bc55c29cd858 net/packet: avoid fanout hook re-registration after unregister
9f4f75df77c89 netlink: specs: rt-link: convert bridge port flag attributes to u8
4264dbc84ca0a net: phy: marvell: fix return code
8881daaafadbe Bluetooth: btusb: validate Realtek vendor event length
9d208de7a8f64 regulator: mt6358: use regmap helper to read fixed LDO calibration
538d862cc0dbd hwmon: occ: validate poll response sensor blocks
2f0f661998941 ovpn: use monotonic clock for peer keepalive timeouts
5b96227c0e8b2 ovpn: fix use after free in unlock_ovpn()
47cd68e050a63 selftests/net: ovpn: fix getaddrinfo memory leak in ovpn_parse_remote()
c5bf6b39be235 ovpn: avoid putting unrelated P2P peer on socket release
2fdd6d196c656 smb: client: validate DFS referral PathConsumed
d6959dd79088a hwmon: (asus-ec-sensors) add missed handle for ENOMEM
dd6f730be95b5 hwmon: (asus-ec-sensors) fix EC read intervals
22e449c1dd543 hwmon: (asus-ec-sensors) fix looping over banks while reading from EC
d5913f97b5b60 drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook()
d0a57f19fe286 usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
2d5dec517b539 wifi: iwlwifi: mvm: fix read in wake packet notification handler
eae7fdf7d4469 wifi: iwlwifi: validate payload length in iwl_pnvm_complete_fn
70a6de303c9b3 wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
a076b0c457c71 wifi: iwlwifi: mvm: validate SAR GEO response payload size
cdf895bfd8035 ASoC: cs35l56: Use complete_all() to signal init_completion
3c26e8bb14cc6 ASoC: cs35l56: Fix potential probe() deadlock
1ddb3e0e502a1 ASoC: cs35l56: Don't use devres to unregister component
9153fa1ee99bf ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI
08433c71f1598 ALSA: hda: cs35l41: validate and free ACPI mute object
eca9fcf9f5d89 ASoC: sun4i-codec: Set quirks.playback_only for H616 codec
41ae2b7d37c3d ASoC: tas2781: bound firmware description string parsing
797dc567146c7 btrfs: free mapping node on duplicate reloc root insert
9304713b70e7e btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
39f196f64bd38 btrfs: fix u32 to s64 type conversion in dirty_metadata_bytes accounting
f49ff44831d52 btrfs: declare btrfs_ioctl_search_args_v2::buf as __u8
4503829843353 wifi: carl9170: fix buffer overflow in rx_stream failover path
fab6ff91d5b8c wifi: carl9170: fix OOB read from off-by-two in TX status handler
9aee949c68dc6 wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
33b5342d20806 wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
eb636fbc44314 wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
0177e578d7a88 firewire: net: Fix fragmented datagram reassembly
51516fda914cc wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
9a9b0ea72d8b9 wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET
a154ca3c441a6 wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
8681e5addf717 watchdog: airoha: Prevent division by zero when clock frequency is zero
7d1658b066de3 watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
305c23993e43d hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
205cff797a947 hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
f36e12cc8cfe9 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
56d2deb644837 hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
ec477af3a7e8d hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
e5394605f9a98 wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
48a69cedde738 wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
593072aae7fc8 selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
938bcf99f53e8 selftests/bpf: Adjust verifier_map_ptr for the map's excl field
fe7892d46921e usb: xhci-pci: Limit VIA VL805 DMA addressing to 36 bits
958624d638603 Revert "drm/amd/display: Add missing kdoc for ALLM parameters"
03eb7a8099474 RISC-V: KVM: Serialize virtual interrupt pending state updates
731acda5ba777 wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
0905b3ce1deb7 usb: typec: ucsi: Add duplicate detection to nvidia registration path
fe8cde072293c usb: typec: ucsi: Detect and skip duplicate altmodes from buggy firmware
67d2626827e3c USB: serial: option: add TDTECH MT5710-CN
601f75671b8fb USB: serial: keyspan_pda: fix data loss on receive throttling
cbe00048b69d6 USB: serial: io_edgeport: cap received transmit credits
c1611c6744e3a USB: serial: ftdi_sio: add support for E+H FXA291
1f03658f3e9b2 usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
dcf3e2f164435 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
40c706a0224bd usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
12b3edca90d4d USB: gadget: fsl-udc: fix dev_printk() device
66956a5a4258c USB: gadget: fsl-udc: fix device name leak on probe failure
e5ecfb7767526 USB: gadget: snps-udc: fix device name leak on probe failure
4cde0b38cc0cb usb: gadget: printer: fix infinite loop in printer_read()
f45089eaad0a0 usb: gadget: f_midi: cancel pending IN work before freeing the midi object
e239ea91b4818 usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
ace1a0adfc786 usb: chipidea: fix usage_count leak when autosuspend_delay is negative
8eca14198c202 USB: storage: add NO_ATA_1X quirk for Longmai USB Key
0950ac52426b0 usb: musb: omap2430: Do not put borrowed of_node in probe
7714fb896ed30 usb: core: port: Deattach Type-C connector on component unbind
fb1b50ab69921 wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
217774e143d7b usb: core: sysfs: add lock to bos_descriptors_read()
5f6e7b32bd1fb mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
a8d20ba0ab518 sctp: fix auth_hmacs array size in struct sctp_cookie
fed1b1ddab41a net/sched: act_tunnel_key: Defer dst_release to RCU callback
51c2fcc4cd2e4 dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
e666af5dcc905 tcp: fix TIME_WAIT socket reference leak on PSP policy failure
6875ee2bef48f accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
f6b522033bc83 drm/i915/selftests: Fix GT PM sort comparators
c23abdb922c39 drm/i915/wm: clear the plane ddb_y entries on plane disable
f0e337e7db67c ksmbd: validate compound request size before reading StructureSize2
6ecb252efa0b4 ksmbd: pin conn during async oplock break notification
5e5f298d0af64 drm/xe/wopcm: fix WOPCM size for LNL+
35ba43b541117 drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
c1b19d8556265 drm/xe/vf: Shadow buffer management for CCS read/write operations
bf293b5bcff41 drm/xe/sa: Shadow buffer support in the sub-allocator pool
65129a03a8018 drm/xe: Allow the caller to pass guc_buf_cache size
cfb66ad4aa8e5 can: j1939: fix lockless local-destination check
3f398d45f3c75 riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
1d9a2f01b3c4e s390/checksum: Fix csum_partial() without vector facility
5b06cf93341fe drm/panthor: Check debugfs GEM lock initialization
250474c69bc3f bpf, sockmap: Reject unhashed UDP sockets on sockmap update
c3e61df6fabca powerpc/vtime: Initialize starttime at boot for native accounting
5c3a1cede86fd powerpc/time: Prepare to stop elapsing in dynticks-idle
c1bbd0a6906b8 powerpc/85xx: Add fsl,ifc to common device ids
00ba4bf879824 can: raw: add locking for raw flags bitfield
479425744b219 drm/i915/gt: use correct selftest config symbol
7e08ab7a061b1 smb/client: handle overlapping allocated ranges in fallocate
cefb44c367b2b Bluetooth: hci_qca: Clear memdump state on invalid dump size
d5b3b484b62bb Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
ca58ad287bfc5 Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
83b7e67698d0b Bluetooth: hci_sync: extend conn_hash lookup critical sections
57059ff14d81d Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
a087ed960fce5 Bluetooth: qca: fix NVM tag length underflow in TLV parser
f4e23e661a259 ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC
b133f007ba02c accel/ivpu: Fix wrong register read in LNL failure diagnostics
1842d45f461a7 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
d28920db56960 ata: sata_dwc_460ex: fix clear_interrupt_bit() clearing all pending interrupts
678d874e6ae11 ata: sata_dwc_460ex: use platform_get_irq()
daa80b422ed92 ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
c7a1509123720 scsi: core: wake eh reliably when using scsi_schedule_eh
2c77ed279c4bb udmabuf: Ensure to perform cache synchronisation in begin_cpu_udmabuf()
c75a950e77356 net/iucv: take a reference on the socket found in afiucv_hs_rcv()
cb8be318b4432 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
c9574b8a8edeb ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
88f87cb4b52ed cpufreq: Make cpufreq_update_pressure() fall back to cpuinfo.max_freq
640a33e77f91b firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context
fb343716fad46 ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup
7f2cb99eaf53c ASoC: cs42l43: Correct report for forced microphone jack
9f393d8160435 ASoC: amd: ps: replace bitwise OR with logical OR in IRQ return check
3b2d32f528152 ASoC: amd: ps: fix wrong ACP version string in pci_request_regions()
f33ad19e3e3d6 ASoC: amd: ps: disable MSI on resume in ACP PCI driver
4801f6690f984 ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop
b39b08e6bee81 firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
cf5708c9d78c9 firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
11ac7a5e75f51 wifi: cfg80211: bound element ID read when checking non-inheritance
5c342437ea44b wifi: brcmfmac: initialize SDIO data work before cleanup
a424985c3ef2a wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
44eda4a8d1dcd wifi: mac80211: avoid non-S1G AID fallback for S1G assoc
fbaa8c31ef940 wifi: cfg80211: reject unsupported PMSR FTM location requests
cfbda103aeae6 wifi: cfg80211: validate PMSR FTM preamble range
0caf6416bfbb3 wifi: cfg80211: validate PMSR measurement type data
0b6efde0ed970 wifi: nl80211: constrain MBSSID TX link ID range
f8c547e543e12 wifi: nl80211: validate nested MBSSID IE blobs
f649dc9c5e657 wifi: cfg80211: derive S1G beacon TSF from S1G fields
fb052a6e2fa86 wifi: nl80211: free RNR data on MBSSID mismatch
133684982dd0c wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
d38f5d868a0a4 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
2aa1789880fa5 wifi: mac80211: defer link RX stats percpu free to RCU
6cda91bbb8dc3 wifi: libertas: fix memory leak in helper_firmware_cb()
5baaa1042f71d wifi: mac80211: fix fils_discovery double free on alloc failure
d62b55b7c7dc6 wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
6dc76371a9a36 wifi: mac80211_hwsim: clamp virtio RX length before skb_put
e67dc2b8d5ac4 wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
f442e581a8893 wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
9293574ac208d wifi: cfg80211: cancel sched scan results work on unregister
7acc5ed2f3360 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
ff636d7b7cba6 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
d8aaf06b29f5a xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
9845a35986a65 xfrm: clear mode callbacks after failed mode setup
9e632a70f2044 RDMA/irdma: Prevent overflows in memory contiguity checks
124382a2a9756 selftests/alsa: Fix memory leak in find_controls error path
f98ae09c727dc mtd: fix double free and WARN_ON in add_mtd_device() error paths
fcc9d50022bcd RDMA/siw: publish QP after initialization
e221dde026af2 RDMA/hns: Fix potential integer overflow in mhop hem cleanup
d842ef03d9145 RDMA/mana_ib: initialize err for empty send WR lists
14e519f93a48c RDMA/erdma: initialize ret for empty receive WR lists
ec675b4cdfd37 RDMA/irdma: Prevent user-triggered null deref on QP create
1cd56258fe1a0 RDMA/irdma: Remove redundant legacy_mode checks
ca1c29f05274b RDMA/irdma: Prevent rereg_mr for non-mem regions
dbb945b80a3a4 RDMA/umem: Add pinned revocable dmabuf import interface
c4ef25de94d73 RDMA/cma: Fix hardware address comparison length in netevent callback
d7fc6f351c478 xfrm: reject optional IPTFS templates in outbound policies
2907e9d0f05b5 sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
57acd51928333 sched/ext: Avoid null ptr traversal when ->put_prev_task() is called with NULL next
996c5c19d5b5a firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
8edc925251780 btrfs: fallback to transaction csum tree on a commit root csum miss
a84ca16ce07e7 btrfs: use bool type for btrfs_path members used as booleans
60a23d4ea169e btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
5e1b2ca6b3493 btrfs: reject free space cache with more entries than pages
0ac9c7d9ccfd7 mtd: nand: mtk-ecc: stop on ECC idle timeouts
fdb53a9b26071 mtd: mtdswap: remove debugfs stats file on teardown
98d2d468b4faa IB/mad: Drop unmatched RMPP responses before reassembly
59114e0ff6e3a firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits
33e1b0d25ca0d xfrm: fix stale skb->prev after async crypto steals a GSO segment
eae16fbc7ce20 xfrm: propagate -EINPROGRESS from validate_xmit_xfrm()
23bbb9eafec7a net: plumb drop reasons to __dev_queue_xmit()
4cc4d6fb08e75 net: dropreason: add SKB_DROP_REASON_RECURSION_LIMIT
4c22b4e3ff502 arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234
0b9858484d096 arm64: tegra: Remove fallback compatible for GPCDMA
903f2edc04770 fuse: fix writeback array overflow when max_pages is one
afe9cda0862aa Input: ims-pcu - fix logic error in packet reset
d03a740e087de Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
6cbed4be9a6ca xprtrdma: Clear receive-side ownership pointers on release
0892b427c4b8b crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin
5f4de3c717d34 gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
ec9f66c91bffd dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
eca8b44d51fc6 can: bcm: track a single source interface for ANYDEV timeout/throttle ops
136de17f38630 can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler()
6be3e1fedf03e can: bcm: fix stale rx/tx ops after device removal
b024c21c9066f can: bcm: add missing device refcount for CAN filter removal
deb6a697cce3f can: bcm: validate frame length in bcm_rx_setup() for RTR replies
bd46f55dec608 can: bcm: extend bcm_tx_lock usage for data and timer updates
8104bcdb2612f can: bcm: fix CAN frame rx/tx statistics
19b1994069dd2 can: bcm: add locking when updating filter and timer values
ec9daa8fd1b6f KVM: x86/mmu: Fix use-after-free on vendor module reload
8001d2ce9d9bd KVM: nVMX: Hide shadow VMCS right after VMCLEAR
dd50ad7935d57 KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN
f3477a6a4164f KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
865dfe76c150b seqlock: Allow UBSAN_ALIGNMENT to fail optimizing
3958b1aeef43b seqlock: Allow KASAN to fail optimizing
ec46baf830825 seqlock: Cure some more scoped_seqlock() optimization fails
8e39ed92d7c5c fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
89890a5fcefad drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker
f6410d18c1e2d netfilter: nf_tables: revert commit_mutex usage in reset path
0c8a9022f4c56 netfilter: nft_quota: use atomic64_xchg for reset
cd968dcdec6ae netfilter: nft_counter: serialize reset with spinlock
55904f1a4689a selftests/bpf: Add tests for ld_{abs,ind} failure path in subprogs
ce01a4e5cfac7 bpf: Fix ld_{abs,ind} failure path analysis in subprogs
bffc0b27e457c platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 24905528a09e7a6b2df9cba342b5f9ba6b8bcf3e)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.18.bb | 6 ++---
.../linux/linux-yocto-tiny_6.18.bb | 6 ++---
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
3 files changed, 18 insertions(+), 18 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index 37570538857..edb3696b25e 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "fa4de2c8b38ef83fd991db3b507630001104cac5"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 5addcaae07e..894267acdf1 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
include recipes-kernel/linux/cve-exclusion.inc
include recipes-kernel/linux/cve-exclusion_6.18.inc
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 3ceba003fa4..e510ff01aaf 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.18/standard/base"
KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
-SRCREV_machine:qemuarm ?= "fbf752dfa74a5be78586014f82002bca11063fa8"
-SRCREV_machine:qemuarm64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuloongarch64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697"
+SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuriscv64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemuriscv32 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemux86 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_machine:qemux86-64 ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
+SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "06f4fd92efb65a6108294f43855ca32fe22cb96f"
-SRCREV_meta ?= "24949c3ef490d79a73a821f688efdc2f562fc851"
+SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "2fe596715f840d053aed5cee5455f701bdcd2b50"
+SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.18/base"
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.41"
+LINUX_VERSION ?= "6.18.43"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
` (34 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:
1efe5d048a391 Linux 6.18.44
358b5dcf1fd7f drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info
e7731507270c2 drm/fb-helper: Fix a locking bug in an error path
7bc7af179916b usb: typec: ucsi: Correct teardown ordering in ucsi_init() error path
10be509fa8fd9 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering
0902f06a6c0bb can: use skb hash instead of private variable in headroom
157b1e3384d7d drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
b1a71151317c4 drm/xe: Add page reclamation info to device info
6107b64cfccef drm/xe: Stub out new pagefault layer
184de3d31f728 drm/xe: Use SVM range helpers in PT layer
df1582c0a101e drm/i915/vrr: require valid min/max vfreq for VRR
894d4a7395662 drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable()
21976fe525849 drm/xe: Wait on external BO kernel fences in exec IOCTL
b8ad916ba4e18 drm/exec: Remove the index parameter from drm_exec_for_each_locked_obj[_reverse]
d256dac008d1d drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
8fa8b0a463729 drm/xe/vm: Prevent binding of purged buffer objects
1ba553ee0b521 drm/xe/bo: Add purgeable bo state tracking and field madv to xe_bo
0015b054b06d3 drm/xe: add xe_migrate_resolve wrapper and is_vram_resolve support
005b9b4431606 drm/xe/pat: Add helper to query compression enable status
3cb42a973f889 drm/amd/display: Exit idle optimizations before programming
dbbe08d73b8bc drm/amd/display: check GRPH_FLIP status before sending event
b485bfb455551 drm/xe/guc: Fix buffer overflow in steered register list allocation
30b2d0843a410 drm/amdgpu: Respect placement requirements in amdgpu_gtt_mgr functions
e06c39cc1c48d drm/amdgpu: Fix context pstate override handling
4d49ca777cf1a drm/tegra: fbdev: Remove offset into framebuffer memory
3f58077457985 drm/fb-helper: Allocate and release fb_info in single place
165613191ad9d userfaultfd: prevent registration of special VMAs
02d378828af8b wifi: brcmfmac: drain bus_reset work on device removal
d6f322d68abfd media: uapi: rkisp: Correct name version enum
5c6d5d2484cab media: qcom: camss: Fix RDI streaming for CSID 340
f730ee0ef8fac media: qcom: camss: csid-340: Fix unused variables
276420a86e75f media: chips-media: wave5: Support CBP profile
3f7b3728dd901 usb: typec: ucsi: Fix race condition and ordering in port unregistration
58d9caa64f9c6 usb: typec: ucsi: split connector lock classes
2bf24a7e190aa net/handshake: Drain pending requests at net namespace exit
6e7b52bd13948 net/handshake: Close the submit-side sock_hold race
68eba6519cbd6 net/handshake: hand off the pinned file reference to accept_doit
b913801ad9b9a net/handshake: Take a long-lived file reference at submit
5ddfc47e1228d net/handshake: Fix null-ptr-deref in handshake_complete()
97e745b4ea055 net/handshake: convert handshake_nl_accept_doit() to FD_PREPARE()
f00dd592abe77 file: ensure cleanup
10827847c40c1 file: add FD_{ADD,PREPARE}()
10065fb891651 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios
be11b4bf498a3 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for unpopulated ptes
2b9a07002c2f2 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
fc0c76b0450f2 drm/xe/rtp: Ensure locking/ref counting for OA whitelists
9783d8662b565 drm/xe/oa: (De-)whitelist OA registers on OA stream open/release
f5966d9006623 drm/xe/rtp: (De-)whitelist OA registers for all hwe's for a gt
d43abc858f082 drm/xe/rtp: Toggle 'deny' bit to (de-)whitelist OA regs
c2cfee9bf8d46 drm/xe/rtp: Save OA nonpriv registers to register save/restore lists
4bb92418e749f drm/xe/rtp: Generalize whitelist_apply_to_hwe
cc716d3ac560f drm/xe/rtp: Keep track of non-OA nonpriv slots
f73e97080debd drm/xe/rtp: Maintain OA whitelists separately
7982678fa21ed drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
542d3b9fa8ec6 drm/xe/rtp: Refactor OAG MMIO trigger register whitelisting
2b70bebc70948 HID: logitech-dj: Fix maxfield check in DJ short report validation
6be3dbe45b287 spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX
042ca38779554 drm/vmwgfx: validate external BO copy bounds for both stride paths
cfd163169af3b drm/vmwgfx: use check_add_overflow for shader size+offset bound
1eb4f796695be drm/vmwgfx: enforce cursor size limits for MOB cursors
96efee36453b6 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure
7e40e6120fb23 drm/vmwgfx: bound DMA command body size against suffix pointer
dc0be7662b7b0 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
a8434b145b1e4 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import
b79e82ea18236 drm/vmwgfx: take fman->lock around fence list mutation in fifo_down
10460699c312e drm/vmwgfx: clamp dirty-page range with min, not max
e479240a1e076 drm/vmwgfx: reject DX_BIND_QUERY without a DX context
282f261cb035e drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
6a52f48157fa7 drm/amdkfd: hold event_mutex while checkpointing CRIU events
6189ceca5ce75 drm/amdkfd: Handle invalid event type in CRIU event restore
6dc0b4b39ed4f drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment
5f0f2ddeac738 drm/amdkfd: fix QID bit leak in pqm_create_queue()
9e52212aff8ed drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
02647d9834073 drm/amd/display: use proper context for logging
3c2ae9509717c drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames
1860818feb4db drm/amd/pm: fix torn gpu metrics reads
45ba7f091abf4 drm/amdgpu: cap GTT size to physical RAM on APUs
d330ac90d85f3 drm/amdgpu: restore UMD profile pstate after runtime resume
18d21c9d04b00 drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini
0f1ff05c58e17 drm/mediatek: ovl_adaptor: balance component registrations
c835f2b0b7167 drm/panthor: validate firmware interface structure sizes
2a761b9be5863 drm/panthor: reject firmware sections with oversized data
da898bb6faf32 drm/bridge: display-connector: Fix I2C adapter resource leak
57667eb7548fa drm/vc4: Zero the tile state data array before each BIN job
6cd5acf6f87c0 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size
58d2bb394e884 drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs
e8b797940536c can: ctucanfd: mark error-active controller status valid
7d1619f56a75a can: ctucanfd: handle bus error interrupts
46fc5aecde5cd can: ctucanfd: unmap BAR0 using base address
cae2880f8ffae can: ctucanfd: use self-test mode for PRESUME_ACK
aa5e790bf185e can: ctucanfd: add missing MODULE_DEVICE_TABLE()
2427ef427bdd7 can: peak_usb: validate uCAN receive record lengths
92d0de80ca222 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
1acab790b7cec can: peak_usb: add bounds check for USB channel index
2ee477e541a6d can: softing: fw_parse(): validate firmware record spans
185cb1fa38142 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
2e90b2b406077 can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams()
54258ea8d61fc can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking
8604a3b81b9d0 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
996eb21acdc9c can: gs_usb: gs_usb_receive_bulk_callback(): resubmit URB on skb allocation failure
c311f17c261fd can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
0b23144c59c12 can: ems_usb: validate CPC message lengths
26cf99713a96f can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured
affd62f5719a7 i2c: imx: Cancel hrtimer before clearing slave pointer
12a4f0950a158 i2c: imx: Fix slave registration race and error handling
7a5db225ab5a6 i2c: imx: mark I2C adapter when hardware is powered down
82233ff0e36df i2c: iproc: reset bus after timeout if START_BUSY is stuck
19b783335d62e i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock
40dd717445998 i2c: qcom-cci: drop custom suspend/resume and rely on runtime PM helpers
d9b5419df0654 i2c: spacemit: request IRQ after controller initialization
6a5cc2b4e6faf ice: fix memory leak in ice_lbtest_prepare_rings()
326c89ea2685a ice: fix VF interrupts cleanup
7e8789f5b5d8a ice: wait for reset completion in ice_resume()
e0ba8eaef2a0d net: openvswitch: fix skb leak on flow key update failure during ct
9c7246cc509fd net: openvswitch: fix skb leak on flow key update failure during recirculation
90623c9499627 net: openvswitch: fix potential UAF on meter attach failure
74b30e7ef4618 phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB
79a312664118f phy: zynqmp: use read-modify-write for SERDES scrambler bypass
4211450f0fecb phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask
013a4484f061a s390/zcrypt: Validate length for CCA ECC private key requests
ad93a1f1a4565 s390/zcrypt: Validate length for CCA AES cipher key requests
fbb0410986e8a s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
a57fd7fcdb63e s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
672b12940e3f1 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
e16e0fc54120c s390/dasd: Fix undersized format-check buffer
86cdfd061509b s390/dasd: Fix potential NULL pointer dereference
bd63c7879eaa8 s390/qeth: Check CAP_NET_ADMIN for private ioctls
ef1aa7cfb8c63 s390/pci: Fix s390_pci_mmio_write syscall error return without MIO
b039f13e095d2 power: supply: max17040: handle missing status supplier
6d89f33a64675 power: supply: bq25890: fix the -10 C NTC lookup entry
63d6c855b27df cpufreq: schedutil: Publish util hooks only after all sg_cpu are initialized
437b38a08c0a8 cpufreq: powernow-k8: Fix possible memory leak in powernowk8_cpu_init()
efbcecdecefc2 cifs: add fscache_resize_cookie() to cifs_setsize()
466ab0c41d5f5 gpio: pch: use raw_spinlock_t for the register lock
2e4bc8422cdee gpio: pca953x: fix cache_only and IRQ state on restore_context() failure
1883a09a37fed i2c: amd-mp2: Unregister callback on adapter add failure
7a91d07939e07 hwmon: (pmbus/core) notify on the hwmon device, not the i2c client
30ae663746378 hwmon: (npcm750-pwm-fan): stop fan timer on device detach
4ba5bf7ed50f2 sctp: prevent peer transport count overflow
a0d1693923f41 sctp: reject stale cookies with mismatched verification tags
2047ed09bf134 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
5b4d4d5a29f92 selftests/clone3: fix wild pointer access of getline due to missing init
a0bc578641d74 selftests/mm: fix potential wild pointer access of getline due to missing init
2e047b4171de4 spi: qcom-qspi: Correct max DMA length to avoid 64K boundary failure
581e5166f0780 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
c26a6477e149c tracing/filters: Fix false positive match in regex_match_full()
cbb5ed3be9cae tracing: Check return value of __register_event() in trace_module_add_events()
205feb72e5beb ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
ee799977d7941 vxlan: use pskb_network_may_pull() in route_shortcircuit()
94dee751aad62 vxlan: use pskb_network_may_pull() for transmit path header pulls
ff89415d34c3a vxlan: use neigh_ha_snapshot() in route_shortcircuit()
adeed09eeb3b6 vxlan: unclone skb head before modifying eth header in route_shortcircuit()
1235e017aa11c vxlan: re-fetch eth header after route_shortcircuit()
b24ba0bbffe3e veth: convert frag_list skbs before running XDP
3bd35a5e272a1 uprobes: Fix NULL pointer dereference in hprobe_expire()
180ff4c81faf0 um: vector: fix use-after-free in vector_mmsg_rx()
e4b98f9778dfc powerpc/ps3: Fix map failure path in dma_ioc0_map_pages()
4ef801b838d85 net: pktgen: fix proc entry use-after-free
dc3ab04220667 net: ipv6: clear suppressed fib6 rule result
0309ebbc57000 net: bridge: stop fast-leave after deleting a port group
332a546b4ee56 mm: memcg: initialize *locked in memcg1_oom_prepare() stub
b11907c905fa0 mm/page_reporting: use system_freezable_wq to fix UAF during suspend
63b361f228866 io_uring/net: initialize mshot_len for send
4dad8ca637d44 binfmt_misc: don't let an 'F' entry pin its own instance
840bb9c49c3e7 binfmt_misc: reject a flag character as the field delimiter
255a758697da8 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
fdc1d702bf300 binfmt_misc: restore write access when removing an entry
c9dcfe6b8b713 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames
bed792737b5f1 tipc: avoid use-after-free in poll trace queue dumps
88752b811f72a of/address: Fix NULL bus dereference in of_pci_range_parser_one()
4ae701848e4ba netfilter: ipset: do not update comments from kernel-side hash adds
f807a63d0d956 net/smc: fix socket use-after-free during link group termination
2060764e0f46c mshv: fix hv_input_get_system_property struct
a60b5da05e318 ksmbd: reject repeated SMB2 NEGOTIATE requests
b5ee5b266f833 ipvs: do not propagate one-packet flag to synced conns
3b5aee6fcbf6b igc: remove napi_synchronize() in igc_down()
845a9cdd9b03b igbvf: Fix leak in TX DMA error cleanup
b10bb77e91e97 e1000: fix memory leak in e1000_probe()
b0bdca3a49cf3 dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+
2db4535d6af79 ALSA: usb-audio: Clamp frame size in implicit-feedback mode
04595233e5606 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set
b5305a0d0bb8e ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
7ba01e0d3539d ALSA: usb-audio: fix stack info leak in RME Digiface status
cc014ebf80317 ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
79f8720029f26 ata: libata-sata: fix ata_scsi_lpm_supported() iteration
9562ddbc6ed8f ata: libata-eh: Increase STANDBY IMMEDIATE timeout
0a02b0c878071 ASoC: tas2562: fix broken entries in the volume lookup table
35d5f1852e390 ASoC: tas2562: fix DVC coefficient write order
cac7d2066b2f0 ASoC: fsl_easrc: fix m2m_init error path to use goto instead of bare return
6df5b32881602 ASoC: fsl_asrc: fix m2m_init error path to use goto instead of bare return
032746c2dd9a4 ALSA: ump: fix double free of out_cvts on rawmidi error
a26a2e52736f9 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes
5260e195c53e8 ALSA: seq: Fix division by zero in initialize_timer()
2940cc3cf43c7 ALSA: pcm: wake linked drain waiters on unlink
4969533a1b950 ALSA: lx6464es: fix period byte count for 16-bit streams
7484669d1fbab ALSA: hda/realtek: Add quirk for TongFang X6SP45xU
11e2953d9f4c7 ALSA: 6fire: Fix UAF at error handling during probe
c0d3b81f703b2 afs: Fix UAF when sending a message
d703f022a28a2 afs: Fix afs_fs_fetch_data() to subtract transferred from len
b53face003b4d afs: Fix afs_fs_fetch_data() to set call->async
5c7fdcbecbab2 bpf: lwt: Fix dst reference leak on reroute failure
27cc0e603355c Bluetooth: HIDP: validate numbered report payloads
2ebf63aa557a6 Bluetooth: HIDP: reject frames without a transaction header
eb1d8318764de Bluetooth: hci_sync: Fix advertising data UAFs
c569def320aa8 Bluetooth: mgmt: fix UAF in pair command cancellation
a33bc07b4730b Bluetooth: SCO: give the socket its own sco_conn reference
814f82f432dc6 Bluetooth: mgmt: fix pending command UAF in EIR updates
6936b367ee6d4 Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read()
f14d41dbc2fdf Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req()
cae0dfed5d307 audit: fix potential use-after-free in audit_del_rule()
185c784c98094 audit: fix potential integer overflow in audit_log_n_string()
17b412468c7a4 sctp: validate Adaptation Indication parameter length
c0837aeace961 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister
b878ba7e28144 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
e137d082325bb KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
1abf9ce39a862 KVM: s390: pci: Fix missing error codes and memory unaccounting
70871b121f81d KVM: s390: pci: Fix memory accounting for pinned/unpinned pages
6837f0ae85fd5 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
7668c58dcf465 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
5acc92947baa2 KVM: VMX: add memory clobber to asm for VMX instructions
e768ea3a422d1 tracing/fprobe: Roll back on enable_trace_fprobe() failure
3b2e08e0ede72 tracing/probes: Reject $arg0 in meta argument expansion
e0fa737783b5b mm/vmstat: fold stranded per-cpu node stats when a node comes online
126a70bf1a08d mm/hugetlb: fix list corruption in allocate_file_region_entries()
32134cf9211b8 mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
7d3e1d3a0dce9 fs/proc/task_mmu: fix PAGEMAP_SCAN written state for PMD holes
c091462e46f75 selftest: fix headers in fclog.c
9668ffe0e2a5e mm/util: don't read __page_2 for order-1 folios in snapshot_page()
2be94d6b20789 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
2205263b1e013 fortify: Disable -Wstringop-overread in tests
96b0aa79b0e1e pinctrl: bm1880: add missing select GENERIC_PINCONF
5aaa06dfc10f8 erofs: cap LZMA stream pool size
ad0ad3c228b6f pinctrl: devicetree: don't free uninitialized dev_name on error path
93d934668047f pinctrl: microchip-sgpio: add missing select REGMAP_MMIO
6da8f37419dd4 iommu/iommufd: Fix IOPF group ownership UAF
564ac339c0f8b iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace
ee2212b482320 iommufd/viommu: Publish a vDEVICE only after vdevice_init() succeeds
294b464b2be7e iommufd/viommu: Release the igroup lock on the vdevice_size error path
062aa5dcc49a9 mshv: Order pt_vp_array publish against irqfd assertion path
f50f5d3972da0 mshv: Fix level-triggered check on uninitialized data
fc362bfcb060e mshv: adjust interrupt control structure for ARM64
72a90ce4918b5 mshv: Fix race in mshv_irqfd_deassign
cfc686a1174aa iomap: add a separate bio_set for iomap_split_ioend
9be4a66f019ea ksmbd: fix use-after-free in __close_file_table_ids()
213b4568f6e5d ksmbd: return success for deferred final close
cebba11df714b drm/i915/hdmi: Poll for 200 msec for TMDS_Scrambler_Status
e51becb8f3377 qede: sync udp_tunnel ports outside qede_lock in the recovery path
51c52e493346f spi: spi-nxp-fspi: add per-SoC SDR/DTR clock rate limits for all supported SoCs
caeaaf23f7c36 sched/deadline: Use revised wakeup rule only for running dl_server
5a73e8c632c31 octeontx2-pf: Set correct sequence for carrier off and tx queue stop
b90916156b472 net: libwx: fix FDIR ATR queue mismatch for software VLAN packets
6bf322ab07418 ptp: netc: fix potential interrupt storm caused by incorrect unbind order
1e0dfb7e7a5d9 net: dsa: mt7530: error out on failed reads in MT7531 PHY polling
fd9586881d478 net: dsa: mt7530: check bus->read() errors in the MDIO regmap backend
54e07a158f7ae riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
b297559dc2f29 accel/qaic: use sizeof(*trans_hdr) for transaction length check
01bd01b61ad9e riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
a20a0010eb648 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
9b604041f1009 tracing/mmiotrace: Reset dropped_count in mmio_reset_data()
fc97dcb42fb46 fprobe: Fix module reference count leak on error in register_fprobe()
84b5aa55de7c8 drm/i915/dp: Ignore the sink's DSC max FRL rate without a PCON DSC encoder
50edffd0854fe can: isotp: check register_netdevice_notifier() error in module init
b4f8c33593f25 net: sxgbe: check descriptor ring allocation failures
42b87cfd9666e net: sxgbe: free TX rings on RX allocation failure
69a258a5a322e scsi: target: Clear cmd_cnt when initial counter enrollment fails
54c6fb24c6021 scsi: zfcp: Fix memory leak during adapter release by destroying gid_pn_req
ff333def31476 scsi: ufs: core: Revert "Delegate the interrupt service routine to a threaded IRQ handler"
c249cfe1d8df2 scsi: ufs: core: Avoid IRQ thread wakeup during active UIC command
e504204489993 scsi: ufs: core: Cancel RTC work in active-active suspend
bdd8a1297ef10 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
613aaeeaf8cb1 net: phylink: put link_gpio if phylink_create fails
5ea70ad040c1b x86/boot: Add volatile, clobbers and zero-length test in memcmp()
5576afebf726c Bluetooth: hci_sync: fix hci_conn_del() use in hci_le_create_conn_sync
e8f9fef362bab Bluetooth: hci_conn: hold conn reference in abort_conn_sync()
de17305393ec8 Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists
c618a9a5b08ea Bluetooth: btintel: Validate length before parsing diagnostics TLV
3b921533e8aa9 Bluetooth: ISO: fix refcounting of iso_conn
e941799c31f68 Bluetooth: ISO: ensure no dangling hcon references in iso_conn
82e982f54f962 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout
e76a0ae6542ae Bluetooth: ISO: fix leaking sk after socket release
4e9b5e8669b36 Bluetooth: ISO: hold sk properly in iso_conn_ready
09a69828ae594 Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release
cde36776cfe64 Bluetooth: ISO: Fix not updating BIS sender source address
dfce8d30fc5be Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis()
1fc2132950c23 Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos
e8e9cff6d80ee Bluetooth: ISO: lock sk in iso_connect_ind
3120664aa3330 Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths
f1f167991a68f Bluetooth: HCI: Add initial support for PAST
72d5bb1d77d7c Bluetooth: ISO: lock sk in iso_sock_getname
58e3c5289ad23 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp
63c0f396a18b7 Bluetooth: ISO: clear iso_data always when detaching conn from hcon
4e1f45de5b313 ice: suppress DPLL errors during reset recovery
6ebbf198e76ca idpf: Fix mailbox IRQ name leak on request failure
d44081c61dc92 idpf: adjust TxQ ring count minimum
ae7120102e1bb hwmon: (pmbus) Fix return value from pmbus_update_byte_data()
276f1f180f55d net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
2c148a31ca01f netfs: release readahead folios on iterator preparation failure
291ebecdf315d netfs: handle single writeback rolling buffer allocation failure
627826ef42080 netfs: clear PG_private_2 on copy-to-cache append failure
b558e07708d88 wifi: mac80211: validate individual TWT params before driver setup
f82a2ded3d7a9 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
acbf711a20669 powerpc/boot: Fix treeboot-akebono CPU node lookup check
b407b98cf665d powerpc/boot: Fix treeboot-currituck CPU node lookup check
3d24f2e5641b2 powerpc/boot: Fix simpleboot CPU node lookup check
db986098f3088 rtase: fix double free of multi-frag skb on DMA map failure
5a6b0ccb8b018 hwmon: (adt7470) Fix PWM auto temp state array and bounds check
96ad57d317635 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
ddd689bd72264 hwmon: (adt7470) Use cached PWM frequency value
1d6b54dbe8850 hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks
d5d4034bb6f6e hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read()
82d65f7ef11ed hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread
3e06ff0c79ea3 hwmon: (adt7470) Fix cache updated before hardware write on I2C error
28548ecc2b458 hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors
ae20a8a4de06a forcedeth: fix UAF of txrx_stats in nv_remove
2e0c6761c0553 net: bridge: mrp: fix Option TLV length in MRP_Test frames
1b722740ac5c2 hwmon: (nct6775-core) Prevent access to unsupported weight registers
5ec5f00fc606a net: do not send ICMP/NDISC Redirects when peer allocation fails
2332d35aaf206 hwmon: (nzxt-smart2) DMA-align output buffer
075fce376cf85 hwmon: (lm90) Only report alarms if driver is ready
c498adfd4c3e8 hwmon: (sht3x) Fix unaligned accesses
08aee6d45eefc hwmon: (ltc4282) Fix reading the minimum alarm voltage
b60e8486c04de hwmon: (ina2xx) Fix various overflow issues
e627f4ad9eea2 hwmon: (ina2xx) Shift INA234 shunt and current registers
fdfde077e025c hwmon: (ina2xx) Add support for INA234
8da94361f9ae1 hwmon: (ina2xx) Make it easier to add more devices
a42d727dae570 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
e28d478c003d7 spi: spi-cadence: Move TX FIFO full busy-wait into FIFO
d3337eefab626 spi: spi-cadence: supports transmission with bits_per_word of 16 and 32
fcc3d77fef02c ASoC: tas2781: Use correct calibration data for SINEGAIN2 register
b2851429afc5b smb: client: fix buffer leaks in SMB1 read and write
9e24b47ef81d4 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race
72815741715bd scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
3ef209ca0b4b6 scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer
8e0996418590b pinctrl-amd: Don't clear S4 wake bits at probe
ceb00cb87a22c xsk: drain continuation descs after overflow in xsk_build_skb()
411554cb868b8 xsk: use a smaller new lock for shared pool case
05e283466b86e xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
814c5b1590037 selftests/net/af_unix: test listen() rejects wrong socket states
643ec3e24a490 selftest: af_unix: Create its own .gitignore.
0372a52191127 selftests: af_unix: Add tests for ECONNRESET and EOF semantics
5c170577049f9 af_unix: fix listen() succeeding on sockets in the wrong state
b1d480fce05f8 rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check()
f6787fdffcae5 rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
4147866087fbe ASoC: SDCA: Ensure that Control Range is large enough for header
16b553c46e347 netfilter: nft_payload: fix mask build for partial field offload
e6f4b4b40db87 ipvs: do not mangle ICMP replies for non-first fragments
ce96c40a049be ipvs: fix places with wrong packet offsets
00eb23829fd08 ipvs: fix the checksum validations
d186f77d18bdf netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
63ba12b664a2c netfilter: nf_tables: make nft_object rhltable per table
adf1a3ba27ad1 assoc_array: trim the final shortcut word using the current chunk end
3d9f16c0b643c keys: make keyring key-chunk byte order agree with keyring_diff_objects()
e9417d21a22ad keys: fix out-of-bounds read in keyring_get_key_chunk()
6469ad3005087 KEYS: trusted: dcp: fix key_len validation and calc_blob_len() return type
31d491f9da948 KVM: arm64: Reject guest_memfd memslots when the VM has MTE
db1c4a8e9080f mshv: Fix sleeping under spinlock in mshv_portid_alloc
a920ead0bc2f1 mshv: Fix duplicate GSI detection for GSI 0
b215cb70e14c7 Drivers: hv: vmbus: Replace lockdep_hardirq_threaded() with lockdep annotation
d397787dbc4bf Drivers: hv: Allocate the paravisor SynIC pages when required
74d20e3cf88e4 Drivers: hv: Rename fields for SynIC message and event pages
82cdbb6155a2c arch/x86: mshyperv: Discover Confidential VMBus availability
6e70eba930a24 drm/mediatek: Check CRTC state before freeing
f74554e67ccf0 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp()
ec81ecd2ac093 phy: zynqmp: fix runtime PM leak on probe allocation failure
86fb88ac8c915 phy: zynqmp: fix clock error handling in xpsgtr_phy_init()
dff474e723ede btrfs: raid56: fix an incorrect csum skip during scrub
4d4ef6627304a btrfs: zoned: reset meta_write_pointer on zone reset
deddd28fd83c2 btrfs: zoned: fix deadlock between metadata writeback and transaction commit
762561c438599 btrfs: fix leaking BTRFS_FS_STATE_REMOUNTING flag
cfa7e27348773 of: reserved_mem: prevent OOB when too many dynamic regions are defined
f5edba9bc69d0 ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup
3cbfb9b886dc1 ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup
3fd94b9ffe997 phy: qcom: m31-eusb2: Fix return value of init call
9355f526c821f ata: ahci_ceva: fix error paths in ceva_ahci_platform_enable_resources()
a0f288ebe6d8a ata: sata_mv: accept 1 or 2 resources in platform probe
8229a53888540 selftests/seccomp: Fix pointer type mismatch build error
99dc2c143dfc0 selftests/lkdtm: rename STACKLEAK_ERASING to KSTACK_ERASE
094145989b31f gpio: sloppy-logic-analyzer: Fix memory leak in gpio_la_poll_probe()
3808bab5d95ae iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE
0679c0c189d25 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
9086b488f2737 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA
2ef9bb422dd6d pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151
3e55d28095476 pinctrl: qcom: Unconditionally mark gpio as wakeup enable
54a62153c765c thunderbolt: Prevent XDomain delayed work use-after-free on disconnect
d01e88d421a6d mm/slab: prevent unbounded recursion in free path with new kmalloc type
3e957c9b160cf lib/alloc_tag: introduce mem_alloc_profiling_permanently_disabled()
98f57011e6cd1 HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report
bc3bba4656ad2 HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write
df0f33293c0a3 HID: logitech-dj: Standardise hid_report_enum variable nomenclature
302eb87651326 ALSA: hda/realtek: add quirk for HP Dragonfly Folio G3 2-in-1
e8362523fd1b6 drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
a5cdd2407dd89 net: mpls: initialize rtm_tos in mpls_getroute()
85b94a74a0b83 netfilter: br_netfilter: Reallocate headroom if necessary in neigh_hh_bridge()
9bb3714e09986 kunit: tool: Terminate kernel under test on SIGINT
d36086cd1826e kunit: tool: skip stty when stdin is not a tty
285641eb82f0e netfilter: nf_conntrack_expect: restore helper propagation via expectation
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 5ad5ad94f023ec2149585f0e0bae9847fc5bb06d)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.18.bb | 6 ++---
.../linux/linux-yocto-tiny_6.18.bb | 6 ++---
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
3 files changed, 18 insertions(+), 18 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index edb3696b25e..a7051c6e47c 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "f3301719a9aa0f6e52a9ef3f54f7339a4241f7b9"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 894267acdf1..6f3c9b63e5a 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
include recipes-kernel/linux/cve-exclusion.inc
include recipes-kernel/linux/cve-exclusion_6.18.inc
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index e510ff01aaf..2a515e6bfe9 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.18/standard/base"
KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
-SRCREV_machine:qemuarm ?= "6e4861d133214a07c0b2f3e6d8de190fa2734697"
-SRCREV_machine:qemuarm64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuloongarch64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf"
+SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuriscv64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemuriscv32 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemux86 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_machine:qemux86-64 ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
+SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "73fd4709c133ba2ee6012cfb6a63eb908d1a5cc6"
-SRCREV_meta ?= "7f630b9b05e171d09925e2f0edd84697ff826f93"
+SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "7b923c78b50d2ec52690c4353e5aad8302e80599"
+SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.18/base"
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.43"
+LINUX_VERSION ?= "6.18.44"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
` (33 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:
5bbb9c9f8f808 Linux 6.18.48
c49f04e8d2b94 inet: frags: strip GSO state from fragments before reassembly
7519e95095c9b Linux 6.18.47
3ce832e2bd431 net: gro: properly validate BIG TCP aggregation criteria
5b4f2bec7bea6 ptp: vmclock: prevent read-only mappings from becoming writable
dba60d26e9dda futex: Avoid private hash use-after-free on final put
e1534d49a7b8b Bluetooth: hci_aml: validate firmware segment lengths
b7d9edcf9fe6e Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
1f6d1f2611af0 Bluetooth: ISO: zero the sockaddr before returning it in getname
753af97d8d423 Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
fe93a697a7a92 Bluetooth: hci_sync: Fix accept list UAF during suspend
e3f82e8f2a591 Bluetooth: hci_event: validate LE Set CIG Parameters response
39a3afb91be3c Bluetooth: hci_event: fix LE list UAF on reset
608f8fd8c0f7b HID: hyperv: validate initial device info bounds
849e537160bbb HID: uclogic: fix use-after-free of inrange_timer on remove
8406d4b69d48b HID: sensor: custom: Fix use-after-free in enable_sensor
1fa1591efd417 HID: core: fix number/pointer type confusion on long items
5efcd7bbfaaec HID: nintendo: stop device IO before hid_hw_stop on probe failure
268679f501386 HID: nintendo: register input device after capabilities are set
51cfd1adbe7a4 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
942b89f7824f8 futex: Fix might_sleep() warning in futex_pivot_pending()
86d12b34bafc9 futex: Fix race on the initial mm->futex.phash.ref allocation
fdf538b2e6965 futex/pi: Plug private futex exec() race
4da67def9efe6 futex: Sanitize and document task_struct::futex::state transitions
2b92e5562653b futex/pi: Reject cross-mm private futex owners
f303f6a4c9099 Input: atkbd - skip deactivate for HONOR ZQC-P
936ea65543da0 Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
0ea8f06454012 xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
39fc615e355b6 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
4529c03c3da8f HID: pidff: fix OOB write when hid->inputs is empty
9a1d7c5f0d82e HID: core: fix OOB read of field->usage in hid_set_field()
ace7fc4d38799 HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID
15b60ade825c8 HID: magicmouse: do not keep a stale msc->input if no input is claimed
62ec3c591ee81 HID: magicmouse: re-enable multitouch after reset-resume
02a88f8308ae7 HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C
b6baab796d11f ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
9fe5eebb664ec mptcp: pm: fix memory leak from alloc-during-teardown race
6fa2064761ec0 mptcp: pm: uniform announced addresses helpers
714c6d11aceaa mptcp: pm: rename add_entry structure to add_addr
defc59e74c1b4 mptcp: pm: use for_each_subflow helper
f31650243c1ab nvmet: pci-epf: put CQ ref on create_cq mapping failure
20be486d1c225 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
9c95f7e66c62e nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
6d27199ebe8cb nvmet-tcp: bound SGL data length before allocating command buffers
8bce9cd08aae4 nvmet-fc: fix invalid free in LS IOD error path
b26189d284421 nvmet-auth: zero the AUTH_RECEIVE response buffer
23a475ff24d29 dmaengine: fsl-edma: Add error handling for devm_kasprintf
364edaedf4125 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
3dc98e5fe82d0 ipv6: fix use-after-free in ip6_finish_output2()
d9d1a676b033a ipv4: reject undersized MTUs in ip_do_fragment()
f034150305791 drm/xe: Fix DPT allocation paths.
20892d2923e48 nfc: nci: free destination parameters when closing a connection
0d4b5cfab6891 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
2f08dbce3b376 nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
9620a91f8d643 nfc: nci: add data_len bound checks to activation parameter extractors
bfcca5f42c9aa nfc: st21nfca: validate ATR_REQ length against the received frame
2f5d093194ec2 nfc: pn533: purge fragmented skbs during cleanup
e969e98410051 nfc: llcp: reject PDUs shorter than the LLCP header
2d239590d1845 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
e87527b506c40 nfc: llcp: bound the connect_sn TLV walk to the skb
d0902a7c45432 nfc: microread: validate target discovery payload lengths
db7e464b35096 nfc: fdp: bound the device-reported read length and fix an skb leak
a56773e649ea9 nfc: digital: clamp SENSF_RES length to the destination buffer
cb8246e5846db libceph: fix OOB read in decode_watchers() via missing bounds check
184c1a80421a5 xfs: validate attr entry pointer before field access
e0e7f464d6ce8 ext4: fix incorrect function call when initializing s_resgid
458776af0061a ext4: don't enable DAX on new encrypted files
f3d2fa3a99336 ext4: propagate errors from fast commit range replay
5f46f084f74b5 ext4: avoid tail write_begin walk for uptodate folios
fb5980fbe44fc ext4: clear error before retrying inode xattr space fallback
e447f7edb99bd nilfs2: reject invalid block index in GC ioctl
4902a5cba21ae ext4: stop retrying saturated xattr cache entries
e11f5b48c8270 kcov: fix data corruption and race conditions on PREEMPT_RT
164ca33cf5366 null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
6176313622e34 ocfs2: fix missing metadata reservation for large xattrs
15ccf53709859 io_uring/uring_cmd: don't skip completion for a synchronous multishot cmd
45c945107e007 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
4074ae2f1da9e io_uring/io-wq: fix worker accounting when canceling creation callbacks
b6a768aa975b9 io_uring/cmd: fix iovec leak when the async cmd is not recycled
f20c2c32ec1c5 ALSA: dummy: Check card index validity at probe
3da64f2ed902b io_uring/futex: don't mark futex wake requests as inflight
61dc1a37e04d4 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
e971d956353d3 rndis_host: add overflow check in rndis_rx_fixup()
4305e4b52acc0 ALSA: scarlett2: Use a private URB for the notification endpoint
65aceb45ca91d ALSA: FCP: Use a private URB for the notification endpoint
7596354148c5a iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages
d2ab08437e913 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
d4b1a13b1eff2 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
0c55707bd5d0d PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
159d162fe80bd xfs: don't livelock in scrub on a circular unlinked list
a05a1b663464b xfs: hoist per-bucket unlinked list check to helper
8d678be8e58e9 xfs: rtsummary scrub should treat rtbitmap corruption errors as an xref error
00e2baf0b5ea9 xfs: add a xchk_ip_set_corrupt helper
755d0b7ee3563 serial: sc16is7xx: enable THRI before filling TX FIFO
c5a12344a043e serial: sc16is7xx: use guards for simple mutex locks
450fe8f6f1f8c serial: sc16is7xx: rename EFR mutex with generic name
1f99e9ab748fc Linux 6.18.46
b7ce4b3bc1068 ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
192f44513a03b firewire: ohci: initialize page array to use alloc_pages_bulk() correctly
e5e6ce7009a6c drm/vmwgfx: Set surface-framebuffer GEM objects
7e351209dc2f4 erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
67ac7e01c26be spi: virtio: mark device ready before registering the controller
a7d172b27aa3e drm/log: Fix infinite loop when scale is too large for display
a6325e2807dc2 drm/client: Remove drm_client_framebuffer_delete()
329731b3119f0 drm/client: Deprecate struct drm_client_buffer.gem
0763282e689e2 drm/client: Inline drm_client_buffer_addfb() and _rmfb()
60f1a2ecdf8b9 drm/client: Move dumb-buffer handling to drm_client_framebuffer_create()
841bc853a2b11 drm/client: Remove pitch from struct drm_client_buffer
16a2716910ecf drm/log: Fix out-of-bounds read on empty message length
948f346fe36e1 drm/xe/oa: Fix sync entry leak on OA config emit failure
ed5470771c7ed firewire: ohci: fix NULL pointer dereference in ar_context_release
384d9f04b38f4 firewire: ohci: split page allocation from dma mapping
adb3e7c26a51a net/sched: cls_bpf: reject dev-bound programs bound to a different device
1f493c44a2f04 accel/amdxdna: Skip unmapped range in aie2_populate_range()
72e4e3d7efc3b net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
6cf600b276a55 regmap: sdw-mbq: don't call an unset readable_reg callback
c27eed546ae20 m68k: Define NR_CPUS to 1
31f26a95eeee9 net/sched: cls_u32: skip hash tables in u32_bind_class()
abceabc4408fc net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
98c5914d6b7bd af_packet: Don't send zero-byte data in tpacket_snd().
37c5ccaaacd48 regmap: sdw-mbq: Fix swap of timeout and retry times
f51a540b14eec ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
82d9269f01ebf net/tls: Fail tls_sw_splice_read() after a failed async decrypt
cef4c5b9aca24 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
5ffaa5d7f56ab net: tap: fix wrong transport_header when sending VLAN-tagged frame
f9297abbcaba7 net: packet: fix wrong transport_header when sending VLAN-tagged frame
0af3afd054e7b net: phy: realtek: fix EEE advertisement write on the internal PHY MMD path
17e3181d740d1 tcp: fix icsk_ack.ato bitfield overflow
73f8dd22b1e53 veth: fix queue index used to wake the peer txq in veth_poll
96fa90b74385b macvlan: inherit needed_headroom and needed_tailroom from lowerdev
5f33188457bbc ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
1072f0f442820 eth: bnxt: keep the aRFS rmap updated when TPH is enabled
394f1b16c5d1b eth: bnxt: cancel IRQ notifier before freeing affinity mask
a26a1be1b6541 netfilter: ipset: let destroy callbacks adjust ext mem size
29c011b3537d7 netfilter: ipset: fix list type element drift bug
d9d3050a70efe netfilter: flowtable: publish GC-visible tuple last
4a923fe60939a netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
cb20da33839f2 netfilter: ipset: fix refcount race between list:set GC and swap
9e75e7da43740 ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
24d0f33f5415f gpio: ml-ioh: share the register lock across channels
7a03413f31c19 perf: Reject exited events as group leaders
6c85d169eeecc riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
a3a676495c641 ovpn: finish crypto callback cleanup before peer release
a47a080d06ee9 ovpn: fix NULL dereference when killing missing key
99a18e1d979e0 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
3e4bf50c94511 crypto: ccm - Set rfc4309 maxauthsize from child
d9ecc9787e118 arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
a4e340971fe8c NTB: ntb_netdev: Preserve RX queue depth on allocation failure
08437c5156b0a net: ntb_netdev: Introduce per-queue context
2a7d8fc0fd50e ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
8c685df5c3b26 drm/amd/pm: fix pptable use-after-free
2895aeb4327c9 drm/amd/pm: adjust the visibility of pp_table sysfs node
7755be923e325 mm/page_table_check: skip special zero mappings
4ae625d16eefb ring-buffer: Prevent resizing of persistent ring buffer
54fc67500ad1b ring-buffer: Store bpage pointers into subbuf_ids
27d7fcaf237df ring-buffer: Add helper functions for allocations
2ca6b43edf83f sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
f786e6652b931 sched_ext: Reorganize enable/disable path for multi-scheduler support
0907f81536f7d sched_ext: Update p->scx.disallow warning in scx_init_task()
4a7e941ca29a6 futex: Fix race in futex_pivot_pending() during private hash resize
870f8392b284e can: rcar_canfd: change the initializing flow for clocks and resets
45bf067681ad5 can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
e7a4ca927857a can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
f8c8c81707d17 can: rcar_canfd: Invert global vs. channel teardown
562d4befa9357 can: rcar_canfd: Invert reset assert order
867aed6a48487 binfmt_misc: don't leak the user namespace when the mount fails
4c8d7595a10a6 ata: libata-scsi: terminate deferred commands on time out
db488d653d896 ASoC: tas2562: Validate values for volume writes
5f0a99ea72120 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
ef60eca789ee6 userfaultfd: wait on source PMD during UFFDIO_MOVE
ea563ed2b10ae mm: replace pmd_to_swp_entry() with softleaf_from_pmd()
54a09573eb440 fs/proc/task_mmu: refactor pagemap_pmd_range()
549148d5aa4e3 btrfs: zoned: fix missing chunk metadata reservation
58ae8b7e8dc88 btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg()
d9e9753dfd43b ksmbd: validate minimum PDU size for transform requests
15a2fedb5dff3 smb/server: fix minimum SMB2 PDU size
23d34ce118857 smb/server: fix minimum SMB1 PDU size
5649004f71613 ksmbd: rename smb2_get_msg to smb_get_msg
29dbb4e29e1f1 ksmbd: Fix to handle removal of rfc1002 header from smb_hdr
df3cf61adbe68 smb/server: rename include guard in smb_common.h
9d154c3c0f5d9 smb: move get_rfc1002_len() to common/smbglob.h
8ddc2eb0d2da9 net/sched: serialize qdisc_rtab_list against concurrent get/put
89df5d71f83f8 libceph: fix two unsafe bare decodes in decode_lockers()
590b07ceea138 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
89a50fb32d69a libceph: Amend checking to fix `make W=1` build breakage
a3bc6b3e9ef3f ceph: fix hanging __ceph_get_caps() with stale mds_wanted
79d95b43ca090 ceph: avoid fs reclaim while using current->journal_info
bb13785d54999 xfs: check v5 superblock features early
04228b8ba196f xfs: check xfarray iteration errors when committing unlinked inode lists
33b56c6c465aa xfs: don't ignore runtime errors in xrep_iunlink_reload_next
38a4dbe588bd0 xfs: don't swallow dquot recovery verification errors
0f27b22343b63 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
cd1f876d1bc2e xfs: avoid UAF on sc->tempip in xrep_tempfile_create
e75150d494dcd xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
b6baf0db357fb xfs: fix another iunlink infinite loop bug in online fsck
fc7d8a5c5fcc7 xfs: fix allocated inodes that show up in the unlinked list
c36d7f68f1c2e xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
73ffd2620df3a xfs: don't zap the attr fork on repair when there are queued pptr updates
514a5d42d4188 xfs: fix ilock leak on error in xfs_dq_get_next_id
9680b1929d897 xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_prev
8b52fa8fb3abb xfs: nlink scrub must take IOLOCK before determining ILOCK state
7d1d82c463e22 xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
ab4e133370763 xfs: set the prev pointer when reinserting an inode on the unlinked list
ce2a7006ec5ed xfs: don't double-lock when deleting a self-referential directory
983588e756a30 xfs: only check mergeability of bnobt records
62c0b1435dfe2 xfs: zero i_nlink before repair puts inode on unlinked list
a9114c6d4ec2f xfs: fix transaction block reservation in xrep_rtbitmap
90a49b8fcf821 xfs: check cowextsize in xrep_inode_cowextsize
069c0eadc8df0 xfs: clear zapped attr fork state when bmap repair finds no attr fork
aeadf3fd2dc3c xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
f8288214459ea xfs: bounds-check buffer log item's dirty bitmap
8a0ecae2ecda9 xfs: fix off-by-one in rtrefcount btree root level validation
ec19cea4ef1ce xfs: propagate errors from xfs_rtginode_load
71aa45f7bfe46 drm/amdgpu: disallow multiple FENCE chunks in one submit
25ee120f3803a drm/amdgpu: Fix UVD decode image min size calculation
38914cb2c6afb drm/amdgpu: Fix UVD dpb min size calculation for H264
c76e5cca0675b drm/amdgpu: Fix UVD min buffer sizes
86a5cb0203221 drm/amdgpu: Implement insert_end for VCE 3
339deb76ee485 drm/amdgpu: Reject UVD message with dimensions above 4096
220aa2589d732 drm/amdgpu: validate GEM_CREATE domain combinations
a082bd76c5f25 drm/amdgpu: check ASPM on the dGPU host link
916e8a1550be1 drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
e304c3e0d9ce2 drm/amdgpu: Reject UVD message with invalid number of h265 refs
e3e6a631dcb1c drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
cd99fa1cbaf5a drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
5045fb4c70bfd drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
95c1de6923b06 s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
7902be374cbfc s390/vfio_ccw: Implement a crw lock
3b224d3c50a38 s390/vfio_ccw: Calculate idal length based on idaw type
b6aecea4b2b24 s390/vfio_ccw: Selectively expand io_mutex
af1759d8e6e6d s390/vfio_ccw: Move cp cleanup out of not operational
4c2e1d359d7a2 s390/vfio_ccw: Fix out of bounds check on CCW array
08ef2a8211569 s390/vfio_ccw: Ensure first IDAW remains constant
649badf3a2fd8 s390/vfio_ccw: Ensure index for read/write regions are within range
b7ae0f7993867 s390/vfio_ccw: Cancel existing workqueues
06f4d6e5a8af6 s390/vfio_ccw: Limit the number of channel program segments
32e3d364a7b82 s390/vfio_ccw: Free all memory if cp_init() fails
45aa38567c798 eth: bnxt: make sure we populate the qcfg defaults on old FW/HW
0382ed41c6645 eth: bnxt: always set the queue mgmt ops
31ef57083e785 drm/radeon: fix autosuspend cleanup during teardown
361114857813d drm/xe: Fix xe_device_probe() failure
7b90db6f024b8 drm/xe: Order ring writes before ring tail updates
198b4a89b9033 pmdomain: mediatek: Fix mt8183 hang on boot
8f7f7a6d5aed8 mmc: loongson2: Fix sg iteration in data reorder functions
e5b527804a1ea drm/connector/hdmi: Fix out of bounds memory read
b5060ff2f5460 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
78e59ab343372 pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
7c0d1767ce464 mmc: sdhci: make tuning_err a signed int
970b9c83a07c4 pmdomain: mediatek: fix remaining %pOF after of_node_put()
36d1b69c5c698 mmc: sdhci: unmap the bounce buffer before device release
0418b7ed2c1c6 mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit
b37e84280045b libceph: tolerate addrvecs with multiple entries of the same type
4490fad7992a7 ceph: fix MDS random selection readiness predicate
4f392fec07556 libceph: Avoid using invalid osd indices from primary_temp
f3854719fba9f Input: sur40 - fix V4L error path cleanup
5c1c5227c93f1 Input: sur40 - fix input device registration ordering
a88d688be8d7f openrisc: signal: do not restore privileged SR bits on sigreturn
f634598e8fb7b ftrace: Fix off-by-one fentry site disable in ftrace_free_mem()
f8fe843a96344 ftrace: Protect direct_functions in ftrace_find_rec_direct
d1bba38574d09 libceph: fix multiple unsafe decodes in decode_locker()
ebdecef6fd842 pmdomain: arm: Fix -EINVAL from scmi_pd_set_perf_state() on state 0
bc7934d0acd4f gpio: ml-ioh: use raw_spinlock_t for the register lock
9e678cffc11c2 gve: fix zero-length skb frag with header-split
bd4e5a97edf8c selftests/ftrace: Convert ELF entry point to file offset in uprobe test
23e9f32c0c7d2 gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
e9482feeed66d gve: fix NULL dereference due to missing ptp adjfine
a134e4b8102c0 crypto: qce - fix error path in devm_qce_register_algs
ef92c0ad0268e crypto: starfive - use scatterlist length before DMA mapping
38e7d5c1ade04 Input: hynitron_cstxxx - validate touch count and finger IDs
70f9aad394355 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
ff0849705d292 Input: synaptics-rmi4 - block s_input when F54 queue is busy
6b06aab79ff16 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
b28593a05afdd Input: synaptics-rmi4 - zero report size on F54 work error
828a8d1a9107a powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
2bdec532202b3 powerpc/pseries: lparcfg - fix kbuf[] underflow
8dbfd8e32a13e Input: byd - synchronize timer deletion before freeing private data
a64a8b6b31cd6 Input: iforce - validate input packet lengths
e7b8a107ecad5 Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard
8d622c58205ad Input: psxpad-spi - set driver data before use
83c265bfc084d Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
9b184c8337c6e Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
652e952850d9a powerpc/pseries: pci - logic bug
52a818c586ae2 Input: cs40l50-vibra - validate custom data from user space
455dbb5bdd814 Input: xpad - add support for ZENAIM LEVERLESS
6635d544bd6bc ASoC: SOF: topology: Use acpi mach from the machine driver
bcc66461f574a drm/amdgpu: fix aperture iounmap skipped on device removal
dffacbe8118fc drm/amdgpu: fix JPEG v4.0.5 queue reset failure in DPG mode
e45356f6adae4 drm/amdgpu: fix JPEG v5.0.0 queue reset failure in DPG mode
4550b90bd2e6c drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12
1474f3970d1af drm/amdgpu: reject oversized IBs with per-ring packet limits
25556a46ae6ec drm/panthor: skip zero-sized firmware sections
7ff87a01ae3a8 fbdev: core: Fix pointer desynchronization in fb_io_read()
2fe7a89b2b5b7 ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
cc61f0fa2c714 ASoC: cs35l41: sort the register default table
3298f13d1f126 ASoC: cs35l45: sort the register default table
d7bd683b0d90c ASoC: cs4265: sort the register default table
f2435a46dfa1a ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
8cba53b862e14 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
a308364774794 s390/qeth: validate user buffer length in SNMP and ARP query ioctls
75e564b2ced1c mptcp: fastopen: only mark MPTFO subflows with SYN data
3f8e5eb0c4999 mptcp: pm: fix data race in add_addr timer callback
1fade1b2ac5b1 mptcp: options: reset DSS fields in case of unexpected size
a04dcc784959e mptcp: avoid combining some incoming suboptions
0cb3846c26c11 selftests: mptcp: join: mark tests with data corruption as failed
473f1a5ab2abc mptcp: reclaim forward-allocated memory on RX path errors
9b46fba7528f5 selinux: reject a permission value exceeding the class permission count
841aea4d5a25e selinux: reject an unclaimed class value in security_get_classes()
1b4ff94ae7c58 selinux: do not cancel a policy conversion that never started
acd5b09be98fd selinux: reject a class permission count below its inherited common
42a7107f99d86 selinux: require every boolean value to be defined
1a4c3ffe2a48b ipvs: separate destination availability state
9ff46bf75bfad ubi: fastmap: fix ubi->fm memory leak
075036cea14ae mtd: ubi: skip programming unused bits in ubi headers
bb03b56d1d754 block: stop the timeout timer when releasing a never added disk
e2c3337c2238e ALSA: hda/realtek: Add quirk for HP Dragonfly Folio G3 2-in-1 (103c:8a05)
bf3be28f6721e Linux 6.18.45
1eb0dc458b6e8 netfilter: flowtable: ensure sufficient headroom in xmit path
99ec511f258e0 netfilter: always set route tuple out ifindex
9977321835c7a thunderbolt: Fix bandwidth group reservation indexing
40d2ffb74094c thunderbolt: Bound the DROM dual link port number before indexing sw->ports
ca33df36aa014 sctp: clear new_transport when removing a peer
07daf4f975010 sctp: fix use-after-free of cached ASCONF chunk
2b3b5eec8b2c3 sctp: keep chunk->transport in step with the list it is queued on
3bd46d33e3fd5 scsi: scsi_debug: Negate wrapped memcmp() result
a14e4ef1d90c3 bpf, sockmap: Fix sk_redir use-after-free in send verdict
3c6d4ffa0c6db fsverity: Fix silent truncation in bpf_get_fsverity_digest()
2a5cfcad1d56e fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
4917e3ebcab50 mm/filemap: __filemap_add_folio() restore index before retrying
dd21c96a71e87 ima: Instantiate file_truncate and path_truncate hooks
102fb2dacf450 sched/psi: Create the psimon kthread outside of cgroup_mutex
8037c5b2b2a44 sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
653e888a24c87 fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
4eb15c465337b ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
3b2231e358d26 ipv6: fix Route Information option length validation
7f740664aec1f mm/ptdump: always stabilise against page table freeing using init_mm
5b926fb04cb9e ring-buffer: Use current_context for safe per-CPU buffer swap
2e37f2bf11142 ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
5fd91dd4a1434 ptp: ocp: Fix board ID over-read
8d34019d14136 Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
5635211b44969 eventfs: Fix use-after-free in eventfs_remove_rec()
66bc868a33cf1 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
47976eaaf0a4e KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
1ffacbadc1453 smb: client: Fix use-after-free in cifs_try_adding_channels()
c3f2347a47754 tipc: read le->link under the node lock in tipc_node_link_down()
3fc5044796dd8 tls: don't leave a full plaintext sk_msg ring unpushed
68787940274ec tls: rx: restore msg_iter before TLS 1.3 optimistic retry
f1e21108e3ddf vhost: reset the vring metadata cache on vring reconfiguration
cdf745b7a777f veth: fix skb length accounting after XDP frag adjustment
38c7763fdc533 vsock/virtio: avoid refilling the RX queue after teardown
bd43a7ec668be vsock/virtio: read virtqueues under worker locks
46bb297ad7768 vxlan: do not arm the ageing timer on a device that is down
fab820f1691a9 xdp: reject clones that overrun skb_shared_info tailroom
e708fc1566ebd x86/mce: Set up the polling timer before CMCI discovery
846b92e26c8ab x86/CPU: Add a tlbi= cmdline switch
69298af46f397 arm64: remove redundant concurrent ptdump UAF mitigation
fe79571f40434 dibs: initialise dibs->lock in dibs_dev_alloc()
a2e326c52c4bc Revert "drm/amdgpu: fix aperture mapping leak"
24e95a24f151c binfmt_misc: don't warn when the mount is completed from another user namespace
be161fa31e3e9 ovl: don't warn when the mount is completed from another user namespace
92f00f1d4d204 net/sched: act_gact, act_police: range check the fallback control action
b47bb899e04b5 net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
782cc40b7ade4 net: atlantic: free RX pages of consumed but not refilled buffers
b13202d401e1a net: atlantic: free stranded TX buffers on ring deinit
0424186d570aa netfilter: nf_conntrack: defer invalid log until after unlock
c58d34fe8b7e4 netfilter: bridge: release template ct on non-IP path
e9bfe12b1d04c net: devmem: prevent net-iov / page mixing
4bc522b33438f net/x25: fix use-after-free of the socket by its timers
ece6426b61241 net/dibs: Correct freeing of dmb_clientid_arr
680fbd7942185 ipv6: prevent in6_dev_get() from resurrecting inet6_dev
0b7d54cedea5c net: smc: fix splice entry lifetime imbalance in smc_rx_splice
b65c11bc62216 net: phy: mediatek: fix TX blink masks using the RX bits
105d04edbec83 mm/huge_memory: fix huge_zero_pfn race
152a00440dc6e tracing: Fix NULL pointer dereference in module event cache removal
62978cf634797 ring-buffer: Prevent subbuf order change when resizing is disabled
bc9db0d879c65 fbdev: bitblit: bound-check glyph index in bit_cursor()
ed49684e69f84 tracing: Fix race between update_event_fields and, event_define_fields
a979a642402d0 perf/core: Fix group leader use-after-free after sibling detach
5884851a096d8 drm/v3d: Serialize the scheduler timeout handlers
7779249561d14 ALSA: us144mkii: re-anchor capture URBs on resubmission
a6b79dff1cc1c ALSA: hda/tas2781: fix ACPI reference handling
bb30e35c36ed0 ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
f75d6f61f0d9c ALSA: usx2y: bound the hwdep mmap fault offset
d217d723c5e43 ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
976da5475472e mm/damon: adjust isolated pages stat for DAMOS_MIGRATE_{HOT,COLD}
e16b8d640ec99 samples/damon/mtier: error out for zero quota goal target values
460181e4bb47a mm/damon/ops-common: putback folios on invalid migrate nid
6dd7a06894d6d ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
688c71bed6852 misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free
af6345159abcb misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
9bf22a7d950ce misc: fastrpc: Remove buffer from list prior to unmap operation
c5a03c2cadd2f misc: fastrpc: fix channel ctx ref leak when session alloc fails
cd02b93863159 misc: fastrpc: Fix initial memory allocation for Audio PD memory pool
8b3e4ed9c35d3 staging: rtl8723bs: validate monitor transmit frame lengths
a28a4b0592e4a staging: rtl8723bs: fix missing shared-key auth challenge length check
e5b7610008f4e staging: rtl8723bs: fix OOB read in WMM_param_handler()
e167a38a8a8f5 staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
5974cb66681ea serial: amba-pl011: synchronize DMA teardown
759ead98a39fb serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
2a0ee25f75cdb serial: amba-pl011: fix indefinite RS485 post-send delay
3ce24bc4d1153 serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
ae05d9e50b6b9 serial: 8250_dma: Clear stale RX state on shutdown
1c31e2377f4c1 serial: qcom-geni: fix TX DMA buffer flush
dd6946a70ddbd rust_binder: do not query current thread for all ioctls
9dbe1d0111893 nvmem: layouts: Add fixed-layout driver
da59844f561d1 nvmem: apple-spmi-nvmem: wrap regmap calls to satisfy CFI
104c2e8b8e38b mei: pull kvfree out of spinlock
63996ffc594d1 ipv4: fix use-after-free in fib_nhc_update_mtu()
a59edda6eda12 ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
94166072975aa selftests/bpf: Adapt sockmap update error handling
edee58a9c460a selftests/bpf: Ensure UDP sockets are bound
dc0c462fa838c Bluetooth: btusb: Add TP-Link UB600 for Realtek 8761BUV
373d425f7638a Bluetooth: btrtl: fix RTL8761B/BU broken LE extended scan
8545f4ef9eae6 netfilter: nf_tables: avoid softlockup warnings in nft_chain_validate
7b8c53263f887 futex: Prevent robust futex exit race some more
cf8a9672fc25c iommu/vt-d: Gather the unmapped range before freeing its page tables
643b410bdfa48 dt-bindings: crypto: qcom,ice: Fix missing power-domain and iface clk
8d817ef1aa4e9 KVM: s390: pci: Fix aisb calculation
cf895cd72e404 blk-mq: reinsert cached request to the list
97e2d08de282e blk-mq: pop cached request if it is usable
59b07ccca4c05 Revert "drm/amd/display: Fix backlight max_brightness to match exported range"
5912cf1822fbe net: bridge: mrp: fix uninitialised bytes on the wire
47a119ec8a7e2 netfilter: ebt_nflog: pin the NFLOG backend
a0e76de6a2f28 igc: fix netdev not re-attached after resume if interface is down
e6cd416a899ed mac802154: fix netdev use-after-free in beacon worker
9f904dd3e4557 inet: frags: publish queues before arming timer
dbb30dc943a93 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
99ae2239069ed net: octeontx2-pf: Fix UB in shift operation
a4b14a4df29d3 net/sched: reject overly deep qdisc hierarchies
23716dd9d8d46 net: openvswitch: reallocate update replies for mismatched IDs
5f30f9c302cea net: fix skb length accounting after generic XDP frag adjustment
2c7b5eb87b2b2 packet: synchronize pressure clearing with ring reconfiguration
971aa7d99242b net/packet: reset the MAC header on the packet-socket transmit path
27e068d1b35db packet: use consistent hard_header_len in TX_RING send path
5bb10753d428a packet: use consistent hard_header_len in non-ring send paths
75eec935444db ipvs: clear IPv4 options after rebasing tunnel ICMP errors
0f88fe0552bee ipvs: properly update the overload flag on dest edit
59b90c17bec5b ipvs: add totalconns for dest
e7f34f29b3302 ipvs: stop estimator after disabled calc phase
27f3924061592 ima: fix out-of-bounds read in xattr_verify()
c5bf8cd148cfe mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
bd3c4108a56de Input: evdev - fix information leak in evdev_pass_values()
b664592e9ba8c vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
a1c31e026c93e vt: add permission check for KDSKBMETA ioctl
2c7496124e94c net: usb: ipheth: fix carrier_work UAF on disconnect
58733b1dd46bb net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
d328fdc607fa1 usb: gadget: f_ncm: Use unsigned int for ndp_index
2dfefdd498ab4 usb: cdnsp: fix incorrect endian conversions for APB timeout register
6e4c09bea8e9c thunderbolt: icm: Preserve USB4 proxy data-valid bit
2f73a065791d2 usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
ebfd1e82ab0a6 usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
04b71290fb419 usb: quirks: Add ShanWan gamepad to quirk list
1740fd2aaa8fd usb: core: Add quirk for 255-bytes initial config read
0a235379825e1 ALSA: usb-audio: fix OOB write on Type II inbound URBs
4034ef247a9dd Input: evdev - sanitize event type index when fetching event masks
8b444b126cd8e net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
fad7cecb5c2c0 net: fec: do not release NULL pages when RX buffer allocation fails
c768fb2e43c8a hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt
de58b90a4d141 hwmon: (ltc4282) Clamp negative current limits
124bd4b006199 hwmon: (ltc4282) Avoid overflow in maximum power calculation
678a76c8fd33d hwmon: (ads7828) Fix external VREF regulator handling
5ee1f603a64bd hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination
29fe74c9aa69d watchdog: at91sam9_wdt: prevent timer rearm during teardown
6d1d3ca6c8f4a tls: don't abort the connection on signal-interrupted sends
18d704bdd8093 sctp: clear control chunk transport if it is being removed
9f77c1ab38218 net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
fc3021284050e s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
8fa684db8709b bnge: Fix resource leak in bnge_init_nic() error path
a837deeaa37cc ata: pata_sl82c105: fix bridge revision use-after-free
4dd71cb0d23d4 net: thunderbolt: Tear down DMA paths before stopping the rings
78e5ebcd1c10e net/smc: fix TOCTOU race between smc_listen_out() and listener close
c8f256dc84920 net: remove WARN_ON_ONCE() from sk_mc_loop()
363e048a9d0a6 net: prestera: validate firmware header length
02226af693627 net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
12afa450a6a6c netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
25d40cf9dab15 netfilter: flowtable: consolidate xmit path
a66e869cf0c90 tcp: fix TFO max_qlen accounting across reuseport migration
6c24ec01fb768 sctp: fix addip_serial increment on ASCONF_ACK allocation failure
1e8f24b1e3fee bnxt_en: Fix PTP PPS setting bug
aab3b5f4d8ec8 bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
6a2e50924e57e bnxt_en: Refresh VNIC default ring on queue restart if needed
f1a4e95e296b2 bnxt_en: Determine and store default RX ring in vnic structure
965c45be24e15 bnxt_en: Move RSS table fill outside __bnxt_hwrm_vnic_set_rss()
88664c48d7d1e net/mlx5e: fix BQL reset on SQ re-activation
beb47092fe8fc bnge: use int for bnge_fix_rings_count() return value
4901b23b5ca7b net: stmmac: resume PHY before hardware setup when opening the interface
99b7bcee01589 selftests/ftrace: refactor eprobes test to fix argument checks
a7a00ecf54243 hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations
2e5ea8272ceae hwmon: (nzxt-smart2) Check return value of init_device() in probe
9fccf43f05317 drm/xe/uc: Apply RCS/CCS yield policy to SR-IOV VFs
d6222af7274f0 net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
a8139285c8925 net/openvswitch: check Ethernet header length in key_extract()
a06e4611d4551 vhost-scsi: reject feature changes after endpoint
2417a498cf3fe vhost-scsi: Validate T10 PI scatterlist counts
cd2f1d9fe8a50 net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
64d322c288577 udp: fix potential use-after-free in tunnel segmentation
5fd121971912d xsk: validate metadata when processing requests
1a1534cc3b419 xsk: move xsk_tx_metadata_request() to xdp_sock_drv.h
af511afa1d297 xsk: validate launch-time metadata size
0ba2e1eb07a82 xsk: clear metadata pointer when no timestamp is requested
5ec4f525373bc xsk: pass TX metadata pointer by reference
642c6e73fce17 xsk: require at least 16 bytes of TX metadata
b0b7202f751bb bnxt: fix memory leak in bnxt_queue_mem_alloc error cases
ad9ffc61fafeb eth: bnxt: support qcfg provided rx page size
cd5485a702efd eth: bnxt: store rx buffer size per queue
9c1406e2ecd2e net: pass queue rx page size from memory provider
b3fecb888e94b net: add bare bone queue configs
96197286b0ac8 net: reduce indent of struct netdev_queue_mgmt_ops members
34debe05685d1 bnxt_en: Do not set EOP on RX AGG BDs on 5760X chips
5ba1a458c5e26 tcp: do not change rcv_ssthresh in tcp_measure_rcv_mss()
821f6416e6978 hwmon: (pmbus) Fix type confusion in notification logic
11720d869be1a hwmon: (pmbus_core) Use guard() for mutex protection
cde8931a25392 vdpa/mlx5: Fix buffer length in create_direct_keys()
a1c236b385d85 vhost/vdpa: reject overflowing PA map page counts on 32-bit
cefcbbe20846a bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
846ce792b6dd2 counter: microchip-tcb-capture: Fix DT channel validation
80094352bd40b net/mlx5: fw_tracer, return NULL on create error
7b02c6d2a3cd2 devlink: fix net namespace reference leak in reload
1efcc71140094 net: hisilicon: hix5hd2_gmac: remove redundant NAPI delete
0e7a8cf8895b0 net/sched: cls_route: fix fastmap use-after-free on filter
10cb31b2b74cb net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
d8a6f79935205 bpf: Propagate untrusted pointer state in commuted arithmetic
c2da73a1f715f bpf: split check_reg_sane_offset() in two parts
db6382ed3361b bpf: Preserve pointer state for commuted arithmetic
24a8f2c29aebb btrfs: fix memory leak in btrfs_do_encoded_write()
26e968526eb53 watchdog: bd96801_wdt: Fix timeout for enabled WDG
b3ff48c4ea8b2 ipvs: return the csum validation for forward hook
a69a4b3fff581 ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
1e8a5467a7a7b netfilter: ipset: switch ext_size to atomic64_t
970e9494f44af pds_core: cancel pending PCI reset work on AER recovery
ef8e37ac448d4 pds_core: keep the health thread stopped during reset
ff9e7d5e3500b net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
e506e704b7474 enic: fix tx_hang_reset use-after-free on device removal
2faf75a8a0650 bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
35ddcc856b5b3 Revert "net: thunderbolt: Enable end-to-end flow control also in transmit"
d512823059af8 net: hns3: fix speed configuration residue after driver reload
8701a643db231 drm/bridge: ps8640: propagate AUX transfer register errors
d47212d866906 ovpn: fix incorrect use of rcu_access_pointer()
54dd83f24b913 ovpn: ensure TCP vars are initialized first
f34949d63cbbe ovpn: disable IPv4 redirects on MP interfaces
e774f7d8fc733 ovpn: hash floated peer by transport identity only
9a776388ef8d5 ovpn: zero-initialize sockaddr before learning a floated endpoint
61fb3cca40ff9 ovpn: ensure socket is owned by ovpn before deref sk_user_data
157164812a0c5 ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET
d20c181088984 ovpn: skip rehash for peers already removed from by_id
9e5e88fbfc87d ARM: dts: BCM5301X: fix PCIe controller 2 second interrupt
92b9d92a35a0f ovpn: add missing rtnl_link_ops->get_size callback
d740dea9e2557 pinctrl: qcom: ipq806x: mark pci reset as a GPIO pin function
23c94a468efe3 pinctrl: qcom: ipq806x: mark gpio as a GPIO pin function
913d2295b772e selftests/sched_ext: Handle sleeping task affinity changes in numa test
ce0212d230bd6 ARM: npcm: Fix OF node refcount leaks in SMP setup
ccf6738adcafa xfs: handle NULL b_addr in xfs_buf_free
d90599a42f6c5 arm64: dts: broadcom: bcm2712: Remove non-functional EL2 virtual timer
d71dfffa512e7 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
bd45b89d7346f arm64: dts: qcom: sdm850-lenovo-yoga-c630: lower PSCI cluster idle
df9d22383d7c0 arm64: dts: qcom: purwa: Fix GPU IOMMU property
7a6e90afb696c arm64: dts: qcom: rename x1p42100 to purwa
1e2b408c1a769 arm64: dts: qcom: Rework X1-based Asus Zenbook A14's displays
387edbe4706b6 arm64: dts: qcom: rename x1e80100 to hamoa
d089f32d34f82 drm/amd/display: Check for tg ops in dce110_set_avmute
8aba384bfc8aa drm/amd/display: Add AV mute wait frames to dce110_set_avmute
50359c42e0eba selftests/bpf: Fail unbound UDP on sockmap update
62fefb817bb3b sched/fair: Revert 6d71a9c61604 ("sched/fair: Fix EEVDF entity placement bug causing scheduling lag")
4043e196dc882 sched/fair: Separate se->vlag from se->vprot
9a3eef676cd8b mount: honour SB_NOUSER in the new mount API
79a45d44323b3 KVM: s390: pci: Fix resource leak on IRQ registration failure
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 714654a1625f4f39a5c44c5ded9602d75b6cb6c8)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../linux/linux-yocto-rt_6.18.bb | 6 ++---
.../linux/linux-yocto-tiny_6.18.bb | 6 ++---
meta/recipes-kernel/linux/linux-yocto_6.18.bb | 24 +++++++++----------
3 files changed, 18 insertions(+), 18 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
index a7051c6e47c..a0c2abf1c5f 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb
@@ -15,13 +15,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "f987d803014658f4fbccff70cfb9c42cc381f710"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "40cf3a2e9ae15c3d4b3a528d4de015263639cac3"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
index 6f3c9b63e5a..0d4c98f2840 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb
@@ -9,7 +9,7 @@ require recipes-kernel/linux/linux-yocto.inc
include recipes-kernel/linux/cve-exclusion.inc
include recipes-kernel/linux/cve-exclusion_6.18.inc
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -18,8 +18,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
index 2a515e6bfe9..1a7a8659bf8 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb
@@ -17,25 +17,25 @@ KBRANCH:qemux86-64 ?= "v6.18/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.18/standard/base"
KBRANCH:qemumips64 ?= "v6.18/standard/mti-malta"
-SRCREV_machine:qemuarm ?= "ca14f75460e4cdd77e7f4b18e356d772236fc4bf"
-SRCREV_machine:qemuarm64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuloongarch64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuarm ?= "1cd95e881ac1b4f07906bd0e9482891e12f84a83"
+SRCREV_machine:qemuarm64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuloongarch64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
SRCREV_machine:qemumips ?= "62ea92a539f58803a222be98b81118403074206e"
-SRCREV_machine:qemuppc ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuriscv64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemuriscv32 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemux86 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_machine:qemux86-64 ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
+SRCREV_machine:qemuppc ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuriscv64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemuriscv32 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemux86 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_machine:qemux86-64 ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
SRCREV_machine:qemumips64 ?= "9fb4ff0187c85426f21fd40d4c61b742800f65c4"
-SRCREV_machine ?= "1b6ed62ce69bdf976f1b580c20f5271ed105958e"
-SRCREV_meta ?= "7b09e5efab49e4bae0c69f7f2c65b4df00e9c565"
+SRCREV_machine ?= "5b95344d2d0cfbe5889e3eb5a2ea3939dc3412f0"
+SRCREV_meta ?= "185549fc38a492dc3e431b32ac6774620ae6b468"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "1efe5d048a391de3ead2804b2e7f86376c356cc5"
+SRCREV_machine:class-devupstream ?= "5bbb9c9f8f808710e2123f2b30f0d61d7d698f52"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.18/base"
@@ -43,7 +43,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.18;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.18.44"
+LINUX_VERSION ?= "6.18.48"
PV = "${LINUX_VERSION}+git"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
` (32 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Tatrai <peter.tatrai.ext@siemens.com>
The failure summary path assumed the unsuffixed bootlog file always
exists and unconditionally opened it.
This is not guaranteed when SERIAL_CONSOLES has fewer than two
entries (including empty), where qemurunner can produce only
bootlog suffix variants (for example .2 or .stdout).
On test failures, collect snippets from all existing files matching
bootlog and bootlog.* and prefix each snippet with its filename.
Also skip creating a symlink for a missing bootlog path.
This prevents FileNotFoundError from masking the original test
failure and improves diagnostics across qemu serial configurations.
(From OE-Core rev: 7a6596925cb0eb8dd48a0362a51875cdd60152bc)
Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/classes-recipe/testimage.bbclass | 27 +++++++++++++++++++++++----
1 file changed, 23 insertions(+), 4 deletions(-)
diff --git a/meta/classes-recipe/testimage.bbclass b/meta/classes-recipe/testimage.bbclass
index 9902b8a5682..0f34d551e99 100644
--- a/meta/classes-recipe/testimage.bbclass
+++ b/meta/classes-recipe/testimage.bbclass
@@ -186,6 +186,7 @@ def get_testimage_boot_patterns(d):
def testimage_main(d):
import os
+ import glob
import json
import signal
import logging
@@ -409,15 +410,33 @@ def testimage_main(d):
# Copy additional logs to tmp/log/oeqa so it's easier to find them
targetdir = os.path.join(get_json_result_dir(d), d.getVar("PN"))
os.makedirs(targetdir, exist_ok=True)
- os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog)))
+ if os.path.exists(bootlog):
+ os.symlink(bootlog, os.path.join(targetdir, os.path.basename(bootlog)))
+ else:
+ bb.note("testimage: boot log not found at %s" % bootlog)
+
os.symlink(d.getVar("BB_LOGFILE"), os.path.join(targetdir, os.path.basename(d.getVar("BB_LOGFILE") + "." + d.getVar('DATETIME'))))
if not results or not complete:
bb.error('%s - FAILED - tests were interrupted during execution, check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True)
if results and not results.wasSuccessful():
- with open(bootlog, 'r') as bootlogfile:
- bootlines = "".join(bootlogfile.readlines()[-20:])
- bb.plain('%s - FAILED - Last lines of QEMU boot log:\n%s' % (pn, bootlines))
+ bootlog_files = []
+ for candidate in [bootlog] + sorted(glob.glob(bootlog + ".*")):
+ if os.path.exists(candidate) and candidate not in bootlog_files:
+ bootlog_files.append(candidate)
+
+ if bootlog_files:
+ snippets = []
+ for bootlog_file in bootlog_files:
+ try:
+ with open(bootlog_file, 'r') as bootlogfile:
+ bootlines = "".join(bootlogfile.readlines()[-20:])
+ except OSError as err:
+ bootlines = "<failed to read %s: %s>\n" % (bootlog_file, err)
+ snippets.append("--- %s ---\n%s" % (os.path.basename(bootlog_file), bootlines))
+ bb.plain('%s - FAILED - Last lines of QEMU boot logs:\n%s' % (pn, "\n".join(snippets)))
+ else:
+ bb.plain('%s - FAILED - QEMU boot logs not available at %s or %s.*' % (pn, bootlog, bootlog))
bb.error('%s - FAILED - also check the logs in %s' % (pn, d.getVar("LOG_DIR")), forcelog=True)
def get_runtime_paths(d):
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
` (31 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Release information [1]:
OpenSSL 3.5.8 is a security patch release. The most severe CVE fixed in this release is Moderate.
This release incorporates the following bug fixes and mitigations:
* Fixed QUIC server being able to trigger double free when processing INITIAL packet. (CVE-2026-18798)
* Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
* Fixed invalid pointer dereference in CMP server via crafted protectionAlg. (CVE-2026-63076)
* Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
* Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
* Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
* Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
* Fixed CMP indefinite cache growth of extraCerts. (CVE-2026-63074)
* Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
* Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher(). (CVE-2026-75803)
* Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.
[1] https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md#major-changes-between-openssl-357-and-openssl-358-25-aug-2026
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit db81c1a42a0f552d9a8ec124f004ae2063d58c33)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-connectivity/openssl/{openssl_3.5.7.bb => openssl_3.5.8.bb} (99%)
diff --git a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
similarity index 99%
rename from meta/recipes-connectivity/openssl/openssl_3.5.7.bb
rename to meta/recipes-connectivity/openssl/openssl_3.5.8.bb
index 212879dfa35..cc148f07c7d 100644
--- a/meta/recipes-connectivity/openssl/openssl_3.5.7.bb
+++ b/meta/recipes-connectivity/openssl/openssl_3.5.8.bb
@@ -19,7 +19,7 @@ SRC_URI:append:class-nativesdk = " \
file://environment.d-openssl.sh \
"
-SRC_URI[sha256sum] = "a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8"
+SRC_URI[sha256sum] = "a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2"
inherit lib_package multilib_header multilib_script ptest perlnative manpages
MULTILIB_SCRIPTS = "${PN}-bin:${bindir}/c_rehash"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
` (30 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Removed included patches and refresh remaining one.
Release Notes: [1]
Changes with APR-util 1.6.5
*) Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.
Changes with APR-util 1.6.4
*) SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached
client (cve.mitre.org)
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility memcached client
This issue affects Apache Portable Runtime Utility: from 1.3.0
through 1.6.3.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap
buffer overflow in APR redis client (cve.mitre.org)
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0
through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes
the issue.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL
Injection in apr_dbd_oracle (cve.mitre.org)
Improper Neutralization of Special Elements used in an SQL
Command ('SQL Injection') vulnerability in Apache Portable
Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0
through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes
the issue.
Credits: Elhanan Haenel
*) SECURITY: CVE-2026-32327: Apache Portable Runtime Utility:
apr-util XML stack recursion crash (cve.mitre.org)
A bug in APR-util version 1.6.3 (and earlier) allows a stack
recursion attack against any library consumer which parses XML
from untrusted sources and uses the apr_xml_quote_elem()
function.
Users are recommended to upgrade to version 1.6.4, which fixes
this issue.
Credits: Younghyo Cho @ CISLab, SeoulTech
*) SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to
timing attack (cve.mitre.org)
APR-util versions 1.6.3 (and earlier) function
apr_password_validate() was not constant-time with regards to
hashes or passwords comparisons, potentially leaking their
content via a side channel timing attack particularly on
platforms without crypt() such as Windows, BeOS, NetWare, or
Android.
Users are recommended to upgrade to version 1.6.4, which fixes
this issue.
Credits: Michael Rowley <michael csirt.global>
*) apr_brigade: Don't split the final LF in apr_brigade_split_line() to
avoid producing an empty bucket. PR 64273
[Barnim Dzwillo <dzwillo strato.de>, Joe Orton]
*) apr_brigade: Metadata buckets are now ignored in
apr_brigade_split_line, apr_brigade_flatten and
apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278
[Ben Kallus <benjamin.p.kallus.gr dartmouth.edu>, Joe Orton]
*) apr_crypto_openssl: Compatibility with OpenSSL 3. [Yann Ylavic]
*) apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL
on versions 1.1+. [Graham Leggett]
*) apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
[Lubos Uhliarik <luhliari redhat.com>]
*) configure: Fix Berkeley DB detection with compilers enforcing
strict C99 compliance. PR 66396.
[Florian Weimer <fweimer redhat.com>]
[1] https://github.com/apache/apr-util/blob/1.6.5/CHANGES
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit bb8e0e12c54c452ffb17ce600972edfa9455f459)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...le-function-prototype-warning-with-c.patch | 130 ------------------
...ion-Check-if-transform-is-supported-.patch | 37 -----
.../apr/apr-util/configfix.patch | 4 +-
.../{apr-util_1.6.3.bb => apr-util_1.6.5.bb} | 4 +-
4 files changed, 3 insertions(+), 172 deletions(-)
delete mode 100644 meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
delete mode 100644 meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
rename meta/recipes-support/apr/{apr-util_1.6.3.bb => apr-util_1.6.5.bb} (93%)
diff --git a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch b/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
deleted file mode 100644
index e523859927a..00000000000
--- a/meta/recipes-support/apr/apr-util/0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch
+++ /dev/null
@@ -1,130 +0,0 @@
-From 05afaf207eaff4c175198abd129ed1acde220df3 Mon Sep 17 00:00:00 2001
-From: Yann Ylavic <ylavic@apache.org>
-Date: Thu, 14 Mar 2024 15:52:25 +0000
-Subject: [PATCH] sdbm: Fix old style function prototype warning with clang
-
-This fixes the following warning with clang
-
-../dbm/sdbm/sdbm_pair.c:63:1: warning: a function definition without a prototype is
-deprecated in all versions of C and is not supported in C2x [-Wdeprecated-non-prototype]
- 63 | fitpair(pag, need)
- | ^
-
-Upstream-Status: Backport [https://github.com/apache/apr-util/commit/073368a46fbe92995927258ae2fc97d3920872f2]
-Signed-off-by: Biswapriyo Nath <nathbappai@gmail.com>
-Submitted by: Biswapriyo Nath <nathbappai@gmail.com>
-Github: closes #47
-
-Merges r1912679 from ^/apr/apr/trunk
-
-git-svn-id: https://svn.apache.org/repos/asf/apr/apr-util/branches/1.7.x@1916307 13f79535-47bb-0310-9956-ffa450edef68
-Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
----
- dbm/sdbm/sdbm_pair.c | 39 +++++++++------------------------------
- 1 file changed, 9 insertions(+), 30 deletions(-)
-
-diff --git a/dbm/sdbm/sdbm_pair.c b/dbm/sdbm/sdbm_pair.c
-index 50d7965..6ecaff6 100644
---- a/dbm/sdbm/sdbm_pair.c
-+++ b/dbm/sdbm/sdbm_pair.c
-@@ -60,9 +60,7 @@ static int seepair(char *, int, char *, int);
- */
-
- int
--fitpair(pag, need)
--char *pag;
--int need;
-+fitpair(char *pag, int need)
- {
- register int n;
- register int off;
-@@ -79,10 +77,7 @@ int need;
- }
-
- void
--putpair(pag, key, val)
--char *pag;
--apr_sdbm_datum_t key;
--apr_sdbm_datum_t val;
-+putpair(char *pag, apr_sdbm_datum_t key, apr_sdbm_datum_t val)
- {
- register int n;
- register int off;
-@@ -108,9 +103,7 @@ apr_sdbm_datum_t val;
- }
-
- apr_sdbm_datum_t
--getpair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+getpair(char *pag, apr_sdbm_datum_t key)
- {
- register int i;
- register int n;
-@@ -129,18 +122,14 @@ apr_sdbm_datum_t key;
- }
-
- int
--duppair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+duppair(char *pag, apr_sdbm_datum_t key)
- {
- register short *ino = (short *) pag;
- return ino[0] > 0 && seepair(pag, ino[0], key.dptr, key.dsize) > 0;
- }
-
- apr_sdbm_datum_t
--getnkey(pag, num)
--char *pag;
--int num;
-+getnkey(char *pag, int num)
- {
- apr_sdbm_datum_t key;
- register int off;
-@@ -159,9 +148,7 @@ int num;
- }
-
- int
--delpair(pag, key)
--char *pag;
--apr_sdbm_datum_t key;
-+delpair(char *pag, apr_sdbm_datum_t key)
- {
- register int n;
- register int i;
-@@ -231,11 +218,7 @@ apr_sdbm_datum_t key;
- * return 0 if not found.
- */
- static int
--seepair(pag, n, key, siz)
--char *pag;
--register int n;
--register char *key;
--register int siz;
-+seepair(char *pag, register int n, register char *key, register int siz)
- {
- register int i;
- register int off = PBLKSIZ;
-@@ -251,10 +234,7 @@ register int siz;
- }
-
- void
--splpage(pag, new, sbit)
--char *pag;
--char *new;
--long sbit;
-+splpage(char *pag, char *new, long sbit)
- {
- apr_sdbm_datum_t key;
- apr_sdbm_datum_t val;
-@@ -295,8 +275,7 @@ long sbit;
- * this could be made more rigorous.
- */
- int
--chkpage(pag)
--char *pag;
-+chkpage(char *pag)
- {
- register int n;
- register int off;
diff --git a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch b/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
deleted file mode 100644
index 261b78736f6..00000000000
--- a/meta/recipes-support/apr/apr-util/0001-test_transformation-Check-if-transform-is-supported-.patch
+++ /dev/null
@@ -1,37 +0,0 @@
-From 3a97f58cfb40fc1911bbfd067e8457a472613d75 Mon Sep 17 00:00:00 2001
-From: Khem Raj <raj.khem@gmail.com>
-Date: Tue, 18 Apr 2023 22:58:00 -0700
-Subject: [PATCH] test_transformation: Check if transform is supported before
- using it
-
-This helps in excluding these tests on systems where these are not
-available e.g. musl
-
-Upstream-Status: Submitted [https://bz.apache.org/bugzilla/show_bug.cgi?id=66570]
-Signed-off-by: Khem Raj <raj.khem@gmail.com>
----
- test/testxlate.c | 8 ++++++--
- 1 file changed, 6 insertions(+), 2 deletions(-)
-
-diff --git a/test/testxlate.c b/test/testxlate.c
-index 6981eff..de00fa4 100644
---- a/test/testxlate.c
-+++ b/test/testxlate.c
-@@ -116,8 +116,12 @@ static void test_transformation(abts_case *tc, void *data)
- }
-
- /* 4. Transformation using charset aliases */
-- one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p);
-- one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p);
-+ if (is_transform_supported(tc, "UTF-8", "UTF-7", p)) {
-+ one_test(tc, "UTF-8", "UTF-7", test_utf8, test_utf7, p);
-+ }
-+ if (is_transform_supported(tc, "UTF-7", "UTF-8", p)) {
-+ one_test(tc, "UTF-7", "UTF-8", test_utf7, test_utf8, p);
-+ }
- }
-
- #endif /* APR_HAS_XLATE */
---
-2.40.0
-
diff --git a/meta/recipes-support/apr/apr-util/configfix.patch b/meta/recipes-support/apr/apr-util/configfix.patch
index dbb1148809b..4cc0ad79ae0 100644
--- a/meta/recipes-support/apr/apr-util/configfix.patch
+++ b/meta/recipes-support/apr/apr-util/configfix.patch
@@ -4,7 +4,7 @@ Index: apr-util-1.3.4/apu-config.in
===================================================================
--- apr-util-1.3.4.orig/apu-config.in 2009-01-12 17:08:06.000000000 +0000
+++ apr-util-1.3.4/apu-config.in 2009-01-12 17:09:00.000000000 +0000
-@@ -134,14 +134,7 @@
+@@ -139,14 +139,7 @@ while test $# -gt 0; do
exit 0
;;
--includes)
@@ -19,7 +19,7 @@ Index: apr-util-1.3.4/apu-config.in
;;
--ldflags)
flags="$flags $LDFLAGS"
-@@ -155,28 +148,10 @@
+@@ -160,28 +153,10 @@ while test $# -gt 0; do
exit 0
;;
--link-ld)
diff --git a/meta/recipes-support/apr/apr-util_1.6.3.bb b/meta/recipes-support/apr/apr-util_1.6.5.bb
similarity index 93%
rename from meta/recipes-support/apr/apr-util_1.6.3.bb
rename to meta/recipes-support/apr/apr-util_1.6.5.bb
index cb5465f8729..ba1e3359ff5 100644
--- a/meta/recipes-support/apr/apr-util_1.6.3.bb
+++ b/meta/recipes-support/apr/apr-util_1.6.5.bb
@@ -11,12 +11,10 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=158aa0b1efe0c12f23d4b007ddb9a5db \
SRC_URI = "${APACHE_MIRROR}/apr/${BPN}-${PV}.tar.gz \
file://configfix.patch \
- file://0001-test_transformation-Check-if-transform-is-supported-.patch \
- file://0001-sdbm-Fix-old-style-function-prototype-warning-with-c.patch \
file://run-ptest \
"
-SRC_URI[sha256sum] = "2b74d8932703826862ca305b094eef2983c27b39d5c9414442e9976a9acf1983"
+SRC_URI[sha256sum] = "f43a1c8c79eef497a022ec6c99dddbdf57e42001da6ccbfae259631ed5aa2805"
EXTRA_OECONF = "--with-apr=${STAGING_BINDIR_CROSS}/apr-1-config \
--without-odbc \
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
` (29 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-13346
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed patch format]
---
.../python/python3-pip/CVE-2026-13346.patch | 206 ++++++++++++++++++
.../python/python3-pip_26.0.1.bb | 4 +-
2 files changed, 209 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
new file mode 100644
index 00000000000..e800f29e304
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-13346.patch
@@ -0,0 +1,206 @@
+From 10dfb6b9005484578b386f64b9f36982e3dc6679 Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Tue, 30 Jun 2026 21:52:39 -0400
+Subject: [PATCH] Fix Link.filename decoding URL path twice (#14110)
+
+Link already percent-decodes the URL path into `self._path`, but
+`Link.filename` decoded the basename again, so a doubly-encoded
+separator was decoded twice: `%252F` became `%2F` in `__init__`, then
+`/` in `filename`, turning the single component `a%2Fb.whl` into
+`a/b.whl`.
+
+Drop the second decode, and add a `join_within_directory` helper so the
+download-path joins treat the name as a single path component.
+
+CVE: CVE-2026-13346
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679]
+
+Backport Changes:
+- Omit news/14110.bugfix.rst and tests/unit/test_link.py because these
+ paths are absent from the pip 26.0.1 PyPI sdist used by this recipe.
+ All runtime-source changes are unchanged from upstream.
+
+(cherry picked from commit 10dfb6b9005484578b386f64b9f36982e3dc6679)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/models/link.py | 63 ++++++++++++++++++++-----
+ src/pip/_internal/network/download.py | 20 ++++++--
+ src/pip/_internal/operations/prepare.py | 6 +--
+ 3 files changed, 69 insertions(+), 20 deletions(-)
+
+diff --git a/src/pip/_internal/models/link.py b/src/pip/_internal/models/link.py
+index 200ec34c5..1a6439873 100644
+--- a/src/pip/_internal/models/link.py
++++ b/src/pip/_internal/models/link.py
+@@ -14,6 +14,7 @@ from dataclasses import dataclass
+ from typing import (
+ Any,
+ NamedTuple,
++ NewType,
+ )
+
+ from pip._internal.exceptions import InvalidEggFragment
+@@ -31,6 +32,49 @@ from pip._internal.utils.urls import path_to_url, url_to_path
+ logger = logging.getLogger(__name__)
+
+
++# A single path component: percent-decoded once and reduced to a basename, so it
++# contains no path separator and is not a ``.`` or ``..`` reference. The empty
++# string means "no component".
++PathComponent = NewType("PathComponent", str)
++
++
++def _to_path_component(name: str) -> PathComponent:
++ """Reduce ``name`` to a single path component, or ``""`` if it has none.
++
++ ``os.path.basename`` drops any directory part, drive letter, or separator;
++ a ``.``, ``..``, or empty result is not a component and becomes ``""``.
++ """
++ name = os.path.basename(name)
++ if name in ("", os.curdir, os.pardir):
++ return PathComponent("")
++
++ return PathComponent(name)
++
++
++def as_path_component(name: str) -> PathComponent:
++ """Like ``_to_path_component`` but reject the empty result.
++
++ Use where a file is about to be written, so a missing name is an error
++ rather than a silent fallback to the directory itself.
++ """
++ component = _to_path_component(name)
++ if not component:
++ raise ValueError(f"Unexpected file name derived from URL: {name!r}")
++
++ return component
++
++
++def join_within_directory(directory: str, component: PathComponent) -> str:
++ """Join a single path ``component`` onto ``directory``.
++
++ ``component`` is a :data:`PathComponent`, so by type it has no separator and
++ is not a ``.`` or ``..`` reference; the result can never escape ``directory``.
++ Requiring ``PathComponent`` rather than ``str`` lets the type checker enforce
++ at the call site that the name was reduced to a safe component beforehand.
++ """
++ return os.path.join(directory, component)
++
++
+ # Order matters, earlier hashes have a precedence over later hashes for what
+ # we will pick to use.
+ _SUPPORTED_HASHES = ("sha512", "sha384", "sha256", "sha224", "sha1", "md5")
+@@ -423,18 +467,13 @@ class Link:
+ return redact_auth_from_url(self.url)
+
+ @property
+- def filename(self) -> str:
+- path = self.path.rstrip("/")
+- name = posixpath.basename(path)
+- if not name:
+- # Make sure we don't leak auth information if the netloc
+- # includes a username and password.
+- netloc, user_pass = split_auth_from_netloc(self.netloc)
+- return netloc
+-
+- name = urllib.parse.unquote(name)
+- assert name, f"URL {self._url!r} produced no filename"
+- return name
++ def filename(self) -> PathComponent:
++ name = _to_path_component(posixpath.basename(self.path.rstrip("/")))
++ if name:
++ return name
++
++ # No component in the path; fall back to the netloc, dropping any auth.
++ return _to_path_component(split_auth_from_netloc(self.netloc)[0])
+
+ @property
+ def file_path(self) -> str:
+diff --git a/src/pip/_internal/network/download.py b/src/pip/_internal/network/download.py
+index 26966423f..fa71c75a3 100644
+--- a/src/pip/_internal/network/download.py
++++ b/src/pip/_internal/network/download.py
+@@ -20,7 +20,12 @@ from pip._vendor.urllib3.exceptions import ReadTimeoutError
+ from pip._internal.cli.progress_bars import BarType, get_download_progress_renderer
+ from pip._internal.exceptions import IncompleteDownloadError, NetworkConnectionError
+ from pip._internal.models.index import PyPI
+-from pip._internal.models.link import Link
++from pip._internal.models.link import (
++ Link,
++ PathComponent,
++ as_path_component,
++ join_within_directory,
++)
+ from pip._internal.network.cache import SafeFileCache, is_from_cache
+ from pip._internal.network.session import CacheControlAdapter, PipSession
+ from pip._internal.network.utils import HEADERS, raise_for_status, response_chunks
+@@ -117,11 +122,14 @@ def parse_content_disposition(content_disposition: str, default_filename: str) -
+ return filename or default_filename
+
+
+-def _get_http_response_filename(resp: Response, link: Link) -> str:
++def _get_http_response_filename(resp: Response, link: Link) -> PathComponent:
+ """Get an ideal filename from the given HTTP response, falling back to
+ the link filename if not provided.
++
++ The result is validated as a single path component, so it can be joined onto
++ a download directory without escaping it.
+ """
+- filename = link.filename # fallback
++ filename: str = link.filename # fallback
+ # Have a look at the Content-Disposition header for a better guess
+ content_disposition = resp.headers.get("content-disposition")
+ if content_disposition:
+@@ -135,7 +143,7 @@ def _get_http_response_filename(resp: Response, link: Link) -> str:
+ ext = os.path.splitext(resp.url)[1]
+ if ext:
+ filename += ext
+- return filename
++ return as_path_component(filename)
+
+
+ @dataclass
+@@ -188,7 +196,9 @@ class Downloader:
+ resp = self._http_get(link)
+ download_size = _get_http_response_size(resp)
+
+- filepath = os.path.join(location, _get_http_response_filename(resp, link))
++ filepath = join_within_directory(
++ location, _get_http_response_filename(resp, link)
++ )
+ with open(filepath, "wb") as content_file:
+ download = _FileDownload(link, content_file, download_size)
+ self._process_response(download, resp)
+diff --git a/src/pip/_internal/operations/prepare.py b/src/pip/_internal/operations/prepare.py
+index 67f9ee950..d260d15a2 100644
+--- a/src/pip/_internal/operations/prepare.py
++++ b/src/pip/_internal/operations/prepare.py
+@@ -29,7 +29,7 @@ from pip._internal.exceptions import (
+ from pip._internal.index.package_finder import PackageFinder
+ from pip._internal.metadata import BaseDistribution, get_metadata_distribution
+ from pip._internal.models.direct_url import ArchiveInfo
+-from pip._internal.models.link import Link
++from pip._internal.models.link import Link, join_within_directory
+ from pip._internal.models.wheel import Wheel
+ from pip._internal.network.download import Downloader
+ from pip._internal.network.lazy_wheel import (
+@@ -201,7 +201,7 @@ def _check_download_dir(
+ """Check download_dir for previously downloaded file with correct hash
+ If a correct file is found return its path else None
+ """
+- download_path = os.path.join(download_dir, link.filename)
++ download_path = join_within_directory(download_dir, link.filename)
+
+ if not os.path.exists(download_path):
+ return None
+@@ -683,7 +683,7 @@ class RequirementPreparer:
+ # No distribution was downloaded for this requirement.
+ return
+
+- download_location = os.path.join(self.download_dir, link.filename)
++ download_location = join_within_directory(self.download_dir, link.filename)
+ if not os.path.exists(download_location):
+ shutil.copy(req.local_file_path, download_location)
+ download_path = display_path(download_location)
+--
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
index 9640bc926aa..3ff6cd39cd2 100644
--- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
+++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
@@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=63ec52baf95163b597008bb46db68030 \
inherit pypi python_setuptools_build_meta
-SRC_URI += "file://no_shebang_mangling.patch"
+SRC_URI += "file://no_shebang_mangling.patch \
+ file://CVE-2026-13346.patch \
+ "
SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
` (28 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Tatrai <peter.tatrai.ext@siemens.com>
When SDKMACHINE is set to i686 or i586, nativesdk binaries are compiled
as 32-bit. Without -D_TIME_BITS=64 and -D_FILE_OFFSET_BITS=64, stat()
and time-related syscalls use 32-bit types, causing EOVERFLOW on
filesystems with large inode numbers (e.g. container overlay filesystems)
and Y2038 issues.
Add SDK_CC_ARCH appends for class-nativesdk:i686 and class-nativesdk:i586
using GLIBC_64BIT_TIME_FLAGS, mirroring how target architectures are
handled.
Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>"
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit d9f62a45555673842021d5746437e66c40d3f3cc)
Signed-off-by: Peter Tatrai <peter.tatrai.ext@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/conf/distro/include/time64.inc | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/meta/conf/distro/include/time64.inc b/meta/conf/distro/include/time64.inc
index 19177b1f3cc..a2fe03354d5 100644
--- a/meta/conf/distro/include/time64.inc
+++ b/meta/conf/distro/include/time64.inc
@@ -38,6 +38,16 @@ TARGET_CC_ARCH:append:x86 = "${@bb.utils.contains('TUNE_FEATURES', 'm32', '${GLI
GLIBC_64BIT_TIME_FLAGS:pn-glibc = ""
GLIBC_64BIT_TIME_FLAGS:pn-glibc-testsuite = ""
+# Apply the same flags to nativesdk packages when building for a 32-bit SDK
+# host (i686, i586).
+SDK_CC_ARCH:append:class-nativesdk:i686 = "${GLIBC_64BIT_TIME_FLAGS}"
+SDK_CC_ARCH:append:class-nativesdk:i586 = "${GLIBC_64BIT_TIME_FLAGS}"
+
+# nativesdk-pseudo wraps both 32-bit and 64-bit libc calls; enabling LFS flags
+# causes duplicate symbol errors (e.g. creat64, fopen64) on i686 because glibc
+# aliases the non-LFS names to their 64-bit counterparts via macros.
+GLIBC_64BIT_TIME_FLAGS:pn-nativesdk-pseudo = ""
+
# Caused by the flags exceptions above
INSANE_SKIP:append:pn-glibc = " 32bit-time"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 10/38] grub: disable grub-protect for native builds
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
` (27 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Himanshu Jadon <hjadon@cisco.com>
grub-native fails on hosts where libtasn1 headers are not available
when configure tries to build grub-protect:
util/grub-protect.c:25:10: fatal error:
libtasn1.h: No such file or directory
grub-protect is an optional utility for sealing disk-encryption keys
using the TPM2 key protector. It is not used by the GRUB native tools
staged for Yocto recipe execution.
Disable grub-protect for class-native so grub-native does not depend on
libtasn1. This keeps the native build focused on the tools needed by
Yocto and avoids adding another native library dependency only for an
unused utility.
Target and nativesdk builds keep the upstream default, so image and SDK
behaviour is unchanged.
Signed-off-by: Himanshu Jadon <hjadon@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 9290ca0517e5a8888ee8a695a87c0d7e7b5ea377)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-bsp/grub/grub2.inc | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-bsp/grub/grub2.inc b/meta/recipes-bsp/grub/grub2.inc
index 0656489ead3..466c772e5bf 100644
--- a/meta/recipes-bsp/grub/grub2.inc
+++ b/meta/recipes-bsp/grub/grub2.inc
@@ -73,6 +73,8 @@ EXTRA_OECONF = "--with-platform=${GRUBPLATFORM} \
--disable-werror \
"
+EXTRA_OECONF:append:class-native = " --disable-grub-protect"
+
PACKAGECONFIG ??= ""
PACKAGECONFIG[grub-mount] = "--enable-grub-mount,--disable-grub-mount,fuse"
PACKAGECONFIG[device-mapper] = "--enable-device-mapper,--disable-device-mapper,libdevmapper"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
` (26 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Pratik Farkase <pratik.farkase@est.tech>
The 'pgrep match against full process name' test uses pgrep -f with a
regex pattern close to ARG_MAX in size (~100KB). This intermittently
fails on qemuriscv64 where the process cmdline may not be fully visible
in /proc/<pid>/cmdline at the time pgrep reads it, or the large regex
match times out under TCG emulation.
Skip this single test case while keeping all other 30+ pgrep tests
which are reliable.
[YOCTO #16290]
Signed-off-by: Pratik Farkase <pratik.farkase@est.tech>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit b9166b8fda40bece8c2007ac1f06d51693ac617a)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
...p-pgrep-full-process-name-match-test.patch | 39 +++++++++++++++++++
meta/recipes-extended/procps/procps_4.0.6.bb | 1 +
2 files changed, 40 insertions(+)
create mode 100644 meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
diff --git a/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
new file mode 100644
index 00000000000..43c930ce086
--- /dev/null
+++ b/meta/recipes-extended/procps/procps/0001-testsuite-skip-pgrep-full-process-name-match-test.patch
@@ -0,0 +1,39 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Pratik Farkase <pratik.farkase@est.tech>
+Date: Mon, 17 Aug 2026 10:00:00 +0000
+Subject: [PATCH] testsuite: skip pgrep full process name match test
+
+The "pgrep match against full process name" test uses pgrep -f with a
+regex pattern close to ARG_MAX in size (~100KB). This intermittently
+fails on qemuriscv64 where the process cmdline may not be fully visible
+in /proc/<pid>/cmdline at the time pgrep reads it, or the large regex
+match times out under TCG emulation.
+
+Skip this single test case while keeping all other pgrep tests which
+are reliable.
+
+https://bugzilla.yoctoproject.org/show_bug.cgi?id=16290
+
+Upstream-Status: Inappropriate [OE-ptest specific: fails only under QEMU TCG emulation]
+Signed-off-by: Pratik Farkase <pratik.farkase@est.tech>
+---
+ testsuite/pgrep.test/pgrep.exp | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/testsuite/pgrep.test/pgrep.exp b/testsuite/pgrep.test/pgrep.exp
+index 54e75df..66edbaa 100644
+--- a/testsuite/pgrep.test/pgrep.exp
++++ b/testsuite/pgrep.test/pgrep.exp
+@@ -35,9 +35,9 @@ set test "pgrep with : delimiter"
+ spawn $pgrep -d : $testproc_comm
+ expect_pass "$test" "^${testproc1_pid}:${testproc2_pid}\\s*$"
+
+-set test "pgrep match against full process name"
+-spawn $pgrep -f "$testproc_path\\s+$testproc_arg_str"
+-expect_pass "$test" "^$testproc1_pid\\s*$"
++# Skip: intermittent failure on riscv64 - pgrep -f with large ARG_MAX
++# patterns can fail under QEMU emulation (timing/cmdline visibility race)
++untested "pgrep match against full process name"
+
+ set test "pgrep with matching gid"
+ spawn $pgrep -G $gid $testproc_comm
diff --git a/meta/recipes-extended/procps/procps_4.0.6.bb b/meta/recipes-extended/procps/procps_4.0.6.bb
index a9ec3f39d6c..541a8cd99cd 100644
--- a/meta/recipes-extended/procps/procps_4.0.6.bb
+++ b/meta/recipes-extended/procps/procps_4.0.6.bb
@@ -15,6 +15,7 @@ inherit autotools gettext pkgconfig update-alternatives ptest
SRC_URI = "git://gitlab.com/procps-ng/procps.git;protocol=https;branch=master;tag=v${PV} \
file://sysctl.conf \
file://0001-tests-Disable-twice-total-pmap-X-tests.patch \
+ file://0001-testsuite-skip-pgrep-full-process-name-match-test.patch \
file://run-ptest \
"
SRCREV = "4dafddf4c3f4646caa517f039a2307e92657ec93"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (10 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
` (25 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73072
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73072.patch | 64 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 65 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73072.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73072.patch b/meta/recipes-support/vim/files/CVE-2026-73072.patch
new file mode 100644
index 00000000000..0ae3b2b49e6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73072.patch
@@ -0,0 +1,64 @@
+From 05c41c922309c7a11b6ec2f124be66551c90d66a Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Fri, 24 Jul 2026 00:58:37 +0900
+Subject: [PATCH] patch 9.2.0846: [security]: heap buffer overflow in
+ set_sofo()
+
+Problem: [security]: heap buffer overflow in set_sofo()
+ (Yazan Balawneh)
+Solution: Reset sl_sal_first (Yasuhiro Matsumoto).
+
+A crafted spell file with an empty SN_SAL section before an SN_SOFO
+section reaches set_sofo() with sl_sal_first[] already set to -1 by
+set_sal_first(). The counting loop then under-counts colliding
+multi-byte "from" characters, allocates an undersized list and writes
+past its end.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73072
+Upstream-Status: Backport [https://github.com/vim/vim/commit/05c41c922309c7a11b6ec2f124be66551c90d66a]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/spellfile.c | 4 +++-
+ src/testdir/test_spellfile.vim | 5 +++++
+ 2 files changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/src/spellfile.c b/src/spellfile.c
+index b3ee9c0d63..a9f7e83752 100644
+--- a/src/spellfile.c
++++ b/src/spellfile.c
+@@ -1433,7 +1433,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to)
+ gap->ga_len = 256;
+
+ // First count the number of items for each list. Temporarily use
+- // sl_sal_first[] for this.
++ // sl_sal_first[] for this. Reset it first: a preceding SN_SAL section
++ // may have set the entries to -1 via set_sal_first().
++ vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256);
+ for (p = from, s = to; *p != NUL && *s != NUL; )
+ {
+ c = mb_cptr2char_adv(&p);
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 3a93883b4d..0b0cf42066 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -319,6 +319,11 @@ func Test_spellfile_format_error()
+ " SN_SOFO: multi-byte characters in sofofrom and sofoto
+ call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '')
+
++ " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters
++ " sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so
++ " without a reset set_sofo() under-counts and writes out of bounds.
++ call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '')
++
+ " SN_COMPOUND: compmax is less than 2
+ call Spellfile_Test(0z08000000000101, 'E759:')
+
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 1da47d92430..34d45079061 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-59856.patch \
file://CVE-2026-59857.patch \
file://CVE-2026-59858.patch \
+ file://CVE-2026-73072.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (11 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
` (24 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73073
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73073.patch | 105 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 106 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73073.patch b/meta/recipes-support/vim/files/CVE-2026-73073.patch
new file mode 100644
index 00000000000..5defa7339e6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73073.patch
@@ -0,0 +1,105 @@
+From 2f628d8104958fa7421664f792ca6d4f7a39a10f Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Fri, 17 Jul 2026 09:11:42 +0900
+Subject: [PATCH] patch 9.2.0845: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem: [security]: arbitrary Ex command execution during C
+ omni-completion (Threonine)
+Solution: Match tags typeref literally to block Ex command injection
+ (Yasuhiro Matsumoto).
+
+Escaping only "/" and "\" left the typeref able to break out of the
+:vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern
+skipping fail, and the parser then treats a following "|" as a command
+separator, so the tag value runs as Ex commands during C omni-completion.
+Match the field literally with \V so no regex metacharacter can affect
+pattern parsing.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73073
+Upstream-Status: Backport [https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/autoload/ccomplete.vim | 5 ++++-
+ src/testdir/test_plugin_ccomplete.vim | 26 ++++++++++++++++++++++++++
+ src/version.c | 4 ++++
+ 3 files changed, 34 insertions(+), 1 deletion(-)
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index dc3388b524..593789a84f 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -599,8 +599,11 @@ def StructMembers( # {{{1
+ if complete_check()
+ return []
+ endif
++ # Match "typename" literally (\V): escaping alone is not enough, as e.g.
++ # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of
++ # the tag value is then parsed as Ex commands.
+ execute 'silent! keepjumps noautocmd '
+- .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
++ .. n .. 'vimgrep ' .. '/\t\V' .. escape(typename, '/\') .. '\m\(\t\|$\)/j '
+ .. fnames
+
+ qflist = getqflist()
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+index a635bd50bd..c1754d17c1 100644
+--- a/src/testdir/test_plugin_ccomplete.vim
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref()
+ unlet! g:ccomplete_injected
+ endfunc
+
++" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed
++" "[" makes vimgrep's pattern skipping fail, and the command parser then treats
++" the first "|" as a command separator. The typeref must be matched literally.
++func Test_ccomplete_no_exec_via_typeref_bracket()
++ CheckUnix
++ let sentinel = tempname()
++ call delete(sentinel)
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:[|call system('touch " .. sentinel .. "')|####",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ call ccomplete#Complete(0, 'myvar.x')
++
++ call assert_false(filereadable(sentinel),
++ \ 'typeref field was executed as an Ex command during omni-completion')
++
++ bwipe!
++ let &tags = save_tags
++ call delete(sentinel)
++endfunc
++
+ " A legitimate typeref must still drive struct-member completion: escaping the
+ " field value must not break the normal path.
+ func Test_ccomplete_typeref_completion_still_works()
+diff --git a/src/version.c b/src/version.c
+index 92cd53129e..26e4e026c3 100644
+--- a/src/version.c
++++ b/src/version.c
+@@ -734,6 +734,10 @@ static char *(features[]) =
+
+ static int included_patches[] =
+ { /* Add new patch number below this line */
++/**/
++ 845,
++/**/
++ 846,
+ /**/
+ 736,
+ /**/
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 34d45079061..7ab7a405ffc 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -40,6 +40,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-59857.patch \
file://CVE-2026-59858.patch \
file://CVE-2026-73072.patch \
+ file://CVE-2026-73073.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (12 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
` (23 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73074
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73074.patch | 115 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 116 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73074.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73074.patch b/meta/recipes-support/vim/files/CVE-2026-73074.patch
new file mode 100644
index 00000000000..896298b7032
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73074.patch
@@ -0,0 +1,115 @@
+From a9336b476fd1a182e3f79b5f83c0ffb04f8a922b Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Thu, 23 Jul 2026 20:14:13 +0000
+Subject: [PATCH] patch 9.2.0841: [security]: heap overflow when adding > 65535
+ text properties
+
+Problem: [security]: heap overflow when adding > 65535 text properties
+ (Wang1rrr).
+Solution: Verify that the number of text properties falls within the
+ limit (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-hm4g-pjfx-m27j
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73074
+Upstream-Status: Backport [https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ src/errors.h | 4 ++++
+ src/po/vim.pot | 3 +++
+ src/testdir/test_textprop.vim | 18 ++++++++++++++++++
+ src/textprop.c | 7 +++++++
+ src/version.c | 2 ++
+ 5 files changed, 34 insertions(+)
+
+diff --git a/src/errors.h b/src/errors.h
+index 53e5b1dda6..1682c8587c 100644
+--- a/src/errors.h
++++ b/src/errors.h
+@@ -3812,3 +3812,7 @@ EXTERN char e_gethostbyname_in_channel_listen[]
+ EXTERN char e_cannot_create_pipes[]
+ INIT(= N_("E1575: Cannot create pipes"));
+ #endif
++#ifdef FEAT_PROP_POPUP
++EXTERN char e_too_many_text_properties_on_a_single_line[]
++ INIT(= N_("E1580: Too many text properties on a single line"));
++#endif
+diff --git a/src/po/vim.pot b/src/po/vim.pot
+index b2e3b0f647..aed7d833cf 100644
+--- a/src/po/vim.pot
++++ b/src/po/vim.pot
+@@ -8859,6 +8859,9 @@ msgstr ""
+ msgid "E1575: Cannot create pipes"
+ msgstr ""
+
++msgid "E1580: Too many text properties on a single line"
++msgstr ""
++
+ #. type of cmdline window or 0
+ #. result of cmdline window or 0
+ #. buffer of cmdline window or NULL
+diff --git a/src/testdir/test_textprop.vim b/src/testdir/test_textprop.vim
+index f94acfc97c..a293363a8a 100644
+--- a/src/testdir/test_textprop.vim
++++ b/src/testdir/test_textprop.vim
+@@ -4907,4 +4907,22 @@ func Test_textprop_materialize_list()
+ call assert_equal([], prop_list(1, #{ids: 3->range()}))
+ endfunc
+
++" Adding more than 65535 text properties to one line must be rejected instead
++" of wrapping the uint16_t property count and overflowing the allocation.
++func Test_prop_add_over_uint16_max()
++ CheckNotAsan
++ CheckNotValgrind
++ new
++ call setline(1, 'x')
++ call prop_type_add('overflow', {})
++ for _ in range(0xffff)
++ call prop_add(1, 1, {'type': 'overflow', 'length': 0})
++ endfor
++ call assert_equal(0xffff, prop_list(1)->len())
++ call assert_fails("call prop_add(1, 1, {'type': 'overflow', 'length': 0})", 'E1580:')
++ call assert_equal(0xffff, prop_list(1)->len())
++ call prop_type_delete('overflow')
++ bwipe!
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 5959ecc45f..fe453244c1 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -758,6 +758,13 @@ prop_add_one(
+ proplen = get_text_props(buf, lnum, &props, TRUE);
+ textlen = ml_get_buf_len(buf, lnum) + 1;
+
++ // prop_count is a uint16_t; stop before proplen + 1 wraps to zero.
++ if (proplen >= 0xffff)
++ {
++ emsg(_(e_too_many_text_properties_on_a_single_line));
++ goto theend;
++ }
++
+ if (lnum == start_lnum)
+ col = start_col;
+ else
+diff --git a/src/version.c b/src/version.c
+index 26e4e026c3..2a056f9da5 100644
+--- a/src/version.c
++++ b/src/version.c
+@@ -734,6 +734,8 @@ static char *(features[]) =
+
+ static int included_patches[] =
+ { /* Add new patch number below this line */
++/**/
++ 841,
+ /**/
+ 845,
+ /**/
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 7ab7a405ffc..9dda2c0be55 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-59858.patch \
file://CVE-2026-73072.patch \
file://CVE-2026-73073.patch \
+ file://CVE-2026-73074.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (13 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
` (22 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73076
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73076.patch | 167 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 168 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73076.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73076.patch b/meta/recipes-support/vim/files/CVE-2026-73076.patch
new file mode 100644
index 00000000000..5f5c92b1681
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73076.patch
@@ -0,0 +1,167 @@
+From 581a2f3ac9c6f96a26324f6b2c8c11415fd0d452 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Fri, 24 Jul 2026 17:43:51 +0200
+Subject: [PATCH] patch 9.2.0847: [security]: vimball: code execution via
+ .VimballRecord file
+
+Problem: [security]: vimball: code execution via .VimballRecord file
+ (tdjackey)
+Solution: Forbid arbitrary commands, fix broken directory deletion code,
+ refactor code
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-r22p-fhw4-84p2
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73076
+Upstream-Status: Backport [https://github.com/vim/vim/commit/581a2f3ac9c6f96a26324f6b2c8c11415fd0d452]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/autoload/vimball.vim | 50 ++++++++++++++++++++---------
+ src/testdir/test_plugin_vimball.vim | 16 ++++++++-
+ 2 files changed, 50 insertions(+), 16 deletions(-)
+
+diff --git a/runtime/autoload/vimball.vim b/runtime/autoload/vimball.vim
+index d661ded631..20ce55cd69 100644
+--- a/runtime/autoload/vimball.vim
++++ b/runtime/autoload/vimball.vim
+@@ -20,9 +20,9 @@ if &cp || exists("g:loaded_vimball")
+ finish
+ endif
+ let g:loaded_vimball = "v37"
+-if v:version < 704
++if v:version < 900
+ echohl WarningMsg
+- echo "***warning*** this version of vimball needs vim 7.4"
++ echo "***warning*** this version of vimball needs vim 9.0"
+ echohl Normal
+ finish
+ endif
+@@ -237,6 +237,12 @@ fun! vimball#Vimball(really,...)
+ bw! Vimball
+ call s:ChgDir(curdir)
+ return
++ elseif fname =~? '\%(^\|/\)\.VimballRecord$'
++ echomsg "(Vimball) Forbidding .VimballRecord filename, aborting..."
++ exe "tabn ".curtabnr
++ bw! Vimball
++ call s:ChgDir(curdir)
++ return
+ endif
+
+ if a:really
+@@ -264,7 +270,7 @@ fun! vimball#Vimball(really,...)
+ let fnamebuf = substitute(fnamebuf,'^.\{-}/\(.*\)$','\1','')
+ if !isdirectory(dirname)
+ call mkdir(dirname)
+- call s:RecordInVar(home,"rmdir('".dirname."')")
++ call s:RecordDirInVar(dirname)
+ endif
+ endwhile
+ endif
+@@ -295,7 +301,7 @@ fun! vimball#Vimball(really,...)
+ exe "silent w! ".fnameescape(fnamepath)
+ endif
+ echo "wrote ".fnameescape(fnamepath)
+- call s:RecordInVar(home,"call delete('".fnamepath."')")
++ call s:RecordInVar(fnamepath)
+ endif
+
+ " return to tab with vimball
+@@ -394,10 +400,17 @@ fun! vimball#RmVimball(...)
+ endif
+ let s:VBRstring= substitute(exestring,'call delete(','','g')
+ let s:VBRstring= substitute(s:VBRstring,"[')]",'','g')
+- sil! keepalt keepjumps exe exestring
++ let nr_files= 0
++ for line in split(exestring, '|')
++ if line !~ '^call delete(''[^'']\{-}''\(,"d"\)\?)$'
++ echomsg "ignoring .VimballRecord entry: " line
++ else
++ sil! keepalt keepjumps exe line
++ let nr_files+= 1
++ endif
++ endfor
+ sil! keepalt keepjumps d
+- let exestring= strlen(substitute(exestring,'call delete(.\{-})|\=',"D","g"))
+- echomsg "removed ".exestring." files"
++ echomsg "removed ".nr_files." files"
+ else
+ let s:VBRstring= ''
+ let curfile = substitute(curfile,'\.vmb','','')
+@@ -539,13 +552,20 @@ fun! s:ChgDir(newdir)
+ endfun
+
+ " ---------------------------------------------------------------------
+-" s:RecordInVar: record a un-vimball command in the .VimballRecord file {{{2
+-fun! s:RecordInVar(home,cmd)
++" s:RecordInVar: record a un-vimball file deletion in the .VimballRecord file {{{2
++fun! s:RecordInVar(file)
+ if !exists("s:recordfile")
+- let s:recordfile= a:cmd
+- else
+- let s:recordfile= s:recordfile."|".a:cmd
++ let s:recordfile=[]
++ endif
++ call add(s:recordfile, $'call delete({string(a:file)})')
++endfun
++
++" s:RecordDirInVar: record a un-vimball dir deletion in the .VimballRecord file {{{2
++fun! s:RecordDirInVar(dir)
++ if !exists("s:recorddir")
++ let s:recorddir = []
+ endif
++ call add(s:recorddir, $'call delete({string(a:dir)},"d")')
+ endfun
+
+ " ---------------------------------------------------------------------
+@@ -566,11 +586,11 @@ fun! s:RecordInFile(home)
+ setlocal ma
+ $
+ if exists("s:recordfile") && exists("s:recorddir")
+- let cmd= cmd.s:recordfile."|".s:recorddir
++ let cmd= cmd.join(s:recordfile, '|')."|".join(s:recorddir, '|')
+ elseif exists("s:recorddir")
+- let cmd= cmd.s:recorddir
++ let cmd= cmd.join(s:recorddir, '|')
+ elseif exists("s:recordfile")
+- let cmd= cmd.s:recordfile
++ let cmd= cmd.join(s:recordfile, '|')
+ else
+ return
+ endif
+diff --git a/src/testdir/test_plugin_vimball.vim b/src/testdir/test_plugin_vimball.vim
+index 2d5b4ba768..8025846694 100644
+--- a/src/testdir/test_plugin_vimball.vim
++++ b/src/testdir/test_plugin_vimball.vim
+@@ -65,7 +65,7 @@ func Test_vimball_basic()
+ call assert_true(filereadable('.VimballRecord'))
+ let record = readfile('.VimballRecord')
+ call assert_equal(1, record->len())
+- call assert_match('^Xtest.vmb: rmdir.*call delete(', record[0])
++ call assert_match('^Xtest.vmb: call delete(''.\{-}'')|call delete(''.\{-}'',"d")$', record[0])
+ call s:teardown()
+ endfunc
+
+@@ -83,3 +83,17 @@ func Test_vimball_path_traversal()
+ call assert_false(filereadable('../XVimball/Xtest.txt'))
+ call s:teardown()
+ endfunc
++
++func Test_vimball_VimballRecord_filenames()
++ call s:Mkvimball()
++ call delete('XVimball', 'rf')
++ sp Xtest.vmb
++ 4s#.*\ze\t#.VimballRecord#
++ so %
++ call feedkeys("\<cr>", "it")
++
++ let mess = execute(':mess')->split('\n')[-1]
++ call assert_match('(Vimball) Forbidding .VimballRecord filename.* aborting\.\.\.', mess)
++ call assert_false(filereadable('.VimballRecord'))
++ call s:teardown()
++endfunc
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 9dda2c0be55..f0524ba7300 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-73072.patch \
file://CVE-2026-73073.patch \
file://CVE-2026-73074.patch \
+ file://CVE-2026-73076.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (14 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
` (21 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73077
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73077.patch | 105 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 106 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73077.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73077.patch b/meta/recipes-support/vim/files/CVE-2026-73077.patch
new file mode 100644
index 00000000000..41a9fdb1586
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73077.patch
@@ -0,0 +1,105 @@
+From c5a82fe013e73c98004ad7cd4f906b1ad1ed610e Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Thu, 23 Jul 2026 19:13:15 +0000
+Subject: [PATCH] patch 9.2.0839: [security]: arbitrary code execution via
+ keyword lookup
+
+Problem: [security]: arbitrary code execution via keyword lookup in
+ sh.vim, zsh.vim and ps1.vim filetype plugin
+ (manus-use)
+Solution: For powershell, quote the commands using single quotes, for
+ sh/zsh pass the argument as a separate list item to term_start()/system()
+ (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73077
+Upstream-Status: Backport [https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/ftplugin/ps1.vim | 5 +++--
+ runtime/ftplugin/sh.vim | 5 +++--
+ runtime/ftplugin/zsh.vim | 8 ++++----
+ 3 files changed, 10 insertions(+), 8 deletions(-)
+
+diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim
+index f1fe78df4c..9ff764a282 100644
+--- a/runtime/ftplugin/ps1.vim
++++ b/runtime/ftplugin/ps1.vim
+@@ -6,6 +6,7 @@
+ " 2024 May 23 by Riley Bruins <ribru17@gmail.com> ('commentstring')
+ " 2024 Sep 19 by Konfekt (simplify keywordprg #15696)
+ " 2025 Jul 22 by phanium (use :hor term #17822)
++" 2026 Jul 10 by Vim Project (quote K argument, prevent command injection)
+
+ " Only do this when not done yet for this buffer
+ if exists("b:did_ftplugin") | finish | endif
+@@ -52,9 +53,9 @@ endif
+
+ if exists('s:pwsh_cmd')
+ if exists(':terminal') == 2
+- command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full "<args>"' . (executable('less') ? ' | less' : '')
++ command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')])
+ else
+- command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full <args>')
++ command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'"])
+ endif
+ setlocal keywordprg=:GetHelp
+ let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp"
+diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim
+index 18cd219cdc..45e6f44fcf 100644
+--- a/runtime/ftplugin/sh.vim
++++ b/runtime/ftplugin/sh.vim
+@@ -8,6 +8,7 @@
+ " 2024 Dec 29 by Vim Project (improve setting shellcheck compiler)
+ " 2025 Mar 09 by Vim Project (set b:match_skip)
+ " 2025 Jul 22 by phanium (use :hor term #17822)
++" 2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection)
+
+ if exists("b:did_ftplugin")
+ finish
+@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0))
+
+ if s:is_bash
+ if exists(':terminal') == 2
+- command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "<args>" 2>/dev/null || man "<args>""'
++ command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', <q-args>])
+ else
+- command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help <args>" 2>/dev/null || MANPAGER= man "<args>"')
++ command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', <q-args>])
+ endif
+ setlocal keywordprg=:ShKeywordPrg
+ let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg"
+diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim
+index 850bef055c..8163585939 100644
+--- a/runtime/ftplugin/zsh.vim
++++ b/runtime/ftplugin/zsh.vim
+@@ -2,7 +2,7 @@
+ " Language: Zsh shell script
+ " Maintainer: Christian Brabandt <cb@256bit.org>
+ " Previous Maintainer: Nikolai Weibull <now@bitwi.se>
+-" Latest Revision: 2025 Jul 23
++" Latest Revision: 2026 Jul 23
+ " License: Vim (see :h license)
+ " Repository: https://github.com/chrisbra/vim-zsh
+
+@@ -25,9 +25,9 @@ endif
+
+ if executable('zsh') && &shell !~# '/\%(nologin\|false\)$'
+ if exists(':terminal') == 2
+- command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help <args>"'
+- else
+- command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help <args> 2>/dev/null"')
++ command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', <q-args>])
++ elseif has("patch-9.2.0250")
++ command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', <q-args>])
+ endif
+ setlocal keywordprg=:ZshKeywordPrg
+ let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg'
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index f0524ba7300..c132444040a 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-73073.patch \
file://CVE-2026-73074.patch \
file://CVE-2026-73076.patch \
+ file://CVE-2026-73077.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (15 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
` (20 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hitendra Prajapati <hprajapati@mvista.com>
Pick the patch from [1], also referenced in the NVD report [2].
[1] https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-73078
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../vim/files/CVE-2026-73078.patch | 94 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 95 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-73078.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-73078.patch b/meta/recipes-support/vim/files/CVE-2026-73078.patch
new file mode 100644
index 00000000000..62d156f5680
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-73078.patch
@@ -0,0 +1,94 @@
+From 29c6fd090d4520592f8be7d9ec81190edf25ef69 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Mon, 6 Jul 2026 13:54:03 +0900
+Subject: [PATCH] patch 9.2.0840: [security]: code injection in netrw via
+ bookmarks
+
+Problem: [security]: code injection in netrw via bookmarks and history
+ (David Carliez)
+Solution: Escape the '|' explicitly (Yasuhiro Matsumoto)
+
+The bookmark and history menu builders interpolate paths into :execute'd
+:menu commands using g:netrw_menu_escape, which did not escape the Ex
+command separator '|'. A crafted path could break out of the :menu command
+and run arbitrary Ex/shell commands when the menu was built or triggered.
+
+Add '|' to g:netrw_menu_escape for the menu names, escape the :e right-hand
+side with fnameescape(), and quote the netrw#MakeTgt() argument with
+string() instead of raw single-quote interpolation.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-rcr7-f3wr-22r2
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73078
+Upstream-Status: Backport [https://github.com/vim/vim/commit/29c6fd090d4520592f8be7d9ec81190edf25ef69]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++-------
+ 1 file changed, 9 insertions(+), 7 deletions(-)
+
+diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+index d7eca30e45..c240bbd13f 100644
+--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+@@ -398,7 +398,7 @@ if has("win32")
+ else
+ call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\')
+ endif
+-call s:NetrwInit("g:netrw_menu_escape",'.&? \')
++call s:NetrwInit("g:netrw_menu_escape",'.&? \|')
+ call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\<C-V>\"")
+ if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4')
+ let s:treedepthstring= "│ "
+@@ -3752,13 +3752,14 @@ function s:NetrwBookmarkMenu()
+ if exists("g:netrw_bookmarklist") && g:netrw_bookmarklist != [] && g:netrw_dirhistmax > 0
+ let cnt= 1
+ for bmd in g:netrw_bookmarklist
+- let bmd= escape(bmd,g:netrw_menu_escape)
++ let ebmd= escape(bmd,g:netrw_menu_escape)
++ let fbmd= escape(fnameescape(bmd),'|')
+
+ " show bookmarks for goto menu
+- exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.bmd.' :e '.bmd."\<cr>"
++ exe 'sil! menu '.g:NetrwMenuPriority.".2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks.'.ebmd.' :e '.fbmd."\<cr>"
+
+ " show bookmarks for deletion menu
+- exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.bmd.' '.cnt."mB"
++ exe 'sil! menu '.g:NetrwMenuPriority.".8.2.".cnt." ".g:NetrwTopLvlMenu.'Bookmarks\ and\ History.Bookmark\ Delete.'.ebmd.' '.cnt."mB"
+ let cnt= cnt + 1
+ endfor
+
+@@ -3774,7 +3775,8 @@ function s:NetrwBookmarkMenu()
+ let priority = g:netrw_dirhistcnt + histcnt
+ if exists("g:netrw_dirhist_{cnt}")
+ let histdir= escape(g:netrw_dirhist_{cnt},g:netrw_menu_escape)
+- exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.histdir."\<cr>"
++ let ehistdir= escape(fnameescape(g:netrw_dirhist_{cnt}),'|')
++ exe 'sil! menu '.g:NetrwMenuPriority.".3.".priority." ".g:NetrwTopLvlMenu.'History.'.histdir.' :e '.ehistdir."\<cr>"
+ endif
+ let first = 0
+ let cnt = ( cnt - 1 ) % g:netrw_dirhistmax
+@@ -7119,7 +7121,7 @@ function s:NetrwTgtMenu()
+ let tgtdict[bmd]= cnt
+ let ebmd= escape(bmd,g:netrw_menu_escape)
+ " show bookmarks for goto menu
+- exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt('".bmd."')\<cr>"
++ exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.1.".cnt." ".g:NetrwTopLvlMenu.'Targets.'.ebmd." :call netrw#MakeTgt(".escape(string(bmd),'|').")\<cr>"
+ let cnt= cnt + 1
+ endfor
+ endif
+@@ -7137,7 +7139,7 @@ function s:NetrwTgtMenu()
+ endif
+ let tgtdict[histentry] = histcnt
+ let ehistentry = escape(histentry,g:netrw_menu_escape)
+- exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt('".histentry."')\<cr>"
++ exe 'sil! menu <silent> '.g:NetrwMenuPriority.".19.2.".priority." ".g:NetrwTopLvlMenu.'Targets.'.ehistentry." :call netrw#MakeTgt(".escape(string(histentry),'|').")\<cr>"
+ endif
+ let histcnt = histcnt + 1
+ endwhile
+--
+2.34.1
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index c132444040a..77f681410a9 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-73074.patch \
file://CVE-2026-73076.patch \
file://CVE-2026-73077.patch \
+ file://CVE-2026-73078.patch \
"
PV .= ".0340"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (16 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
` (19 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hiago De Franco <hfranco@baylibre.com>
The guard added in 80ff4903ea tests "detail" in cve_data, but cve_data is
keyed by CVE id, so it asks whether a CVE literally named "detail" was
scanned. That is never true, the condition short-circuits, and the guard
never runs: a CVE_STATUS[CVE-...] = "backported-patch" set for a vendor
cherry-picked patch is silently overwritten to Unpatched by the CNA.
Use .get() on the entry instead. Guard the fallthrough warning the same
way, it makes the same assumption.
Tested against a qemuarm64 linux-yocto report (6.6.142+git, 16221 entries,
4313 of them with no detail). Current master and this version produce
identical output, 18773 entries with no difference. Adding
CVE_STATUS[CVE-2024-42067] = "backported-patch" to that report then makes
the only difference between them: master overwrites it to Unpatched, this
version keeps it Patched. The pre-80ff4903ea code aborts on the same
report with "KeyError: 'detail'".
(cherry picked from commit f5da16b0d3c8f889dab061ba1d8808aba95d4c67)
AI-Generated: Uses Claude (claude-opus-5)
Fixes: 80ff4903ea1b ("improve_kernel_cve_report: validate that cve details field exists")
Signed-off-by: Hiago De Franco <hfranco@baylibre.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
scripts/contrib/improve_kernel_cve_report.py | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/scripts/contrib/improve_kernel_cve_report.py b/scripts/contrib/improve_kernel_cve_report.py
index b386c9383a7..f0e471be459 100755
--- a/scripts/contrib/improve_kernel_cve_report.py
+++ b/scripts/contrib/improve_kernel_cve_report.py
@@ -363,7 +363,7 @@ def cve_update(cve_data, cve, entry):
if entry['status'] == "Unpatched" and cve_data[cve]['status'] == "Patched":
# Backported-patch (e.g. vendor kernel repo with cherry-picked CVE patch)
# has priority over unpatch from CNA
- if "detail" in cve_data and cve_data[cve]['detail'] == "backported-patch":
+ if cve_data[cve].get('detail') == "backported-patch":
return
logging.warning("CVE entry %s update from Patched to Unpatched from the scan result", cve)
cve_data[cve] = copy_data(cve_data[cve], entry)
@@ -382,7 +382,7 @@ def cve_update(cve_data, cve, entry):
logging.debug("CVE entry %s updated from Unpatched to Ignored", cve)
return
logging.warning("Unhandled CVE entry update for %s %s from %s %s to %s",
- cve, cve_data[cve]['status'], cve_data[cve]['detail'], entry['status'], entry['detail'])
+ cve, cve_data[cve]['status'], cve_data[cve].get('detail'), entry['status'], entry['detail'])
def main():
parser = argparse.ArgumentParser(
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (17 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
` (18 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
ChangeLog: https://github.com/p11-glue/p11-kit/releases/tag/0.26.5
0.26.5 (stable)
* rpc: guard against overflow when decoding nested attributes (CVE-2026-18938) [PR#777]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 21a2c91ccca5257ede8994d30460b0dcda617c3a)
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
rename meta/recipes-support/p11-kit/{p11-kit_0.26.4.bb => p11-kit_0.26.5.bb} (97%)
diff --git a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
similarity index 97%
rename from meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
rename to meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
index fde122d3ca5..423c751307b 100644
--- a/meta/recipes-support/p11-kit/p11-kit_0.26.4.bb
+++ b/meta/recipes-support/p11-kit/p11-kit_0.26.5.bb
@@ -12,7 +12,7 @@ DEPENDS:append = "${@' glib-2.0' if d.getVar('GTKDOC_ENABLED') == 'True' else ''
SRC_URI = "gitsm://github.com/p11-glue/p11-kit;branch=master;protocol=https;tag=${PV} \
"
-SRCREV = "a14788849d1ef44422d679534a13821eab5bb5f4"
+SRCREV = "120050e353e8f43d7c40bbcc047f667f903f4de5"
PACKAGECONFIG ??= ""
PACKAGECONFIG[manpages] = "-Dman=true,-Dman=false,libxslt-native"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (18 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
` (17 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Darsh Kelaiya <dkelaiya@cisco.com>
This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].
[1] https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358
[2] https://github.com/lxml/lxml/security/advisories/GHSA-vfmq-68hx-4jfw
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../python/python3-lxml/CVE-2026-41066.patch | 349 ++++++++++++++++++
.../python/python3-lxml_6.0.2.bb | 4 +-
2 files changed, 352 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
diff --git a/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
new file mode 100644
index 00000000000..b1a6f6629d3
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-lxml/CVE-2026-41066.patch
@@ -0,0 +1,349 @@
+From 3a79355229f58e0fe51371385102dd7577bbfb26 Mon Sep 17 00:00:00 2001
+From: Stefan Behnel <stefan_ml@behnel.de>
+Date: Fri, 10 Apr 2026 10:13:03 +0200
+Subject: [PATCH] LP#2146291: Set "resolve_entities='internal'" as default for
+ all parser subclasses.
+
+CVE: CVE-2026-41066
+Upstream-Status: Backport [https://github.com/lxml/lxml/commit/ab431ea0b9a7357d968f1d1c5c614649e9aaf358]
+
+Backport Changes:
+- Reformat the iterparse signature and resolve_entities documentation
+ without semantic changes, preserving line numbers to avoid generated
+ source-location churn.
+- Regenerate src/lxml/etree.c with Cython 3.1.4, matching the version
+ recorded in the shipped file, using
+ "python setup.py build_ext -i --with-cython".
+- Restore the shipped Cython metadata field order and omit
+ the environment-only "-w" compiler flag to avoid unrelated
+ generated changes.
+
+(cherry picked from commit ab431ea0b9a7357d968f1d1c5c614649e9aaf358)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ src/lxml/etree.c | 60 +++++++++++++++++++++---------------------
+ src/lxml/iterparse.pxi | 10 +++----
+ src/lxml/parser.pxi | 6 ++---
+ 3 files changed, 38 insertions(+), 38 deletions(-)
+
+diff --git a/src/lxml/etree.c b/src/lxml/etree.c
+index 29553531..f2208e43 100644
+--- a/src/lxml/etree.c
++++ b/src/lxml/etree.c
+@@ -147986,7 +147986,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ * def __init__(self, *, encoding=None, attribute_defaults=False,
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<<
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ */
+ if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -147997,7 +147997,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ * def __init__(self, *, encoding=None, attribute_defaults=False,
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+ * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<<
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ */
+ if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148007,17 +148007,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ /* "src/lxml/parser.pxi":1734
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<<
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<<
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ * target=None, compact=True):
+ */
+ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True));
++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+
+ /* "src/lxml/parser.pxi":1735
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<<
+ * target=None, compact=True):
+ * XMLParser.__init__(self,
+@@ -148027,7 +148027,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True));
+
+ /* "src/lxml/parser.pxi":1736
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ * target=None, compact=True): # <<<<<<<<<<<<<<
+ * XMLParser.__init__(self,
+@@ -148054,7 +148054,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ * def __init__(self, *, encoding=None, attribute_defaults=False,
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False, # <<<<<<<<<<<<<<
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ */
+ if (!values[2]) values[2] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148065,7 +148065,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ * def __init__(self, *, encoding=None, attribute_defaults=False,
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+ * ns_clean=False, recover=False, schema=None, # <<<<<<<<<<<<<<
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ */
+ if (!values[6]) values[6] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -148075,17 +148075,17 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ /* "src/lxml/parser.pxi":1734
+ * dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True, # <<<<<<<<<<<<<<
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal', # <<<<<<<<<<<<<<
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ * target=None, compact=True):
+ */
+ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+- if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)Py_True));
++ if (!values[11]) values[11] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+
+ /* "src/lxml/parser.pxi":1735
+ * ns_clean=False, recover=False, schema=None,
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True, # <<<<<<<<<<<<<<
+ * target=None, compact=True):
+ * XMLParser.__init__(self,
+@@ -148095,7 +148095,7 @@ static int __pyx_pw_4lxml_5etree_17ETCompatXMLParser_1__init__(PyObject *__pyx_v
+ if (!values[14]) values[14] = __Pyx_NewRef(((PyObject *)Py_True));
+
+ /* "src/lxml/parser.pxi":1736
+- * huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ * huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ * remove_comments=True, remove_pis=True, strip_cdata=True,
+ * target=None, compact=True): # <<<<<<<<<<<<<<
+ * XMLParser.__init__(self,
+@@ -195499,7 +195499,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ * def __init__(self, source, events=("end",), *, tag=None,
+ * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<<
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ */
+ if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195508,7 +195508,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ * def __init__(self, source, events=("end",), *, tag=None,
+ * attribute_defaults=False, dtd_validation=False,
+ * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<<
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ */
+ if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195518,17 +195518,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ /* "src/lxml/iterparse.pxi":71
+ * attribute_defaults=False, dtd_validation=False,
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<<
++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<<
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ * html=False, recover=None, huge_tree=False, collect_ids=True,
+ */
+ if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True));
+- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True));
++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+ if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+
+ /* "src/lxml/iterparse.pxi":72
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<<
+ * html=False, recover=None, huge_tree=False, collect_ids=True,
+ * XMLSchema schema=None):
+@@ -195538,7 +195538,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None));
+
+ /* "src/lxml/iterparse.pxi":73
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<<
+ * XMLSchema schema=None):
+@@ -195588,7 +195588,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ * def __init__(self, source, events=("end",), *, tag=None,
+ * attribute_defaults=False, dtd_validation=False, # <<<<<<<<<<<<<<
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ */
+ if (!values[3]) values[3] = __Pyx_NewRef(((PyObject *)Py_False));
+ if (!values[4]) values[4] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195597,7 +195597,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ * def __init__(self, source, events=("end",), *, tag=None,
+ * attribute_defaults=False, dtd_validation=False,
+ * load_dtd=False, no_network=True, remove_blank_text=False, # <<<<<<<<<<<<<<
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ */
+ if (!values[5]) values[5] = __Pyx_NewRef(((PyObject *)Py_False));
+@@ -195607,17 +195607,17 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ /* "src/lxml/iterparse.pxi":71
+ * attribute_defaults=False, dtd_validation=False,
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False, # <<<<<<<<<<<<<<
++ * compact=True, resolve_entities='internal', remove_comments=False, # <<<<<<<<<<<<<<
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ * html=False, recover=None, huge_tree=False, collect_ids=True,
+ */
+ if (!values[8]) values[8] = __Pyx_NewRef(((PyObject *)Py_True));
+- if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)Py_True));
++ if (!values[9]) values[9] = __Pyx_NewRef(((PyObject *)__pyx_mstate_global->__pyx_n_u_internal));
+ if (!values[10]) values[10] = __Pyx_NewRef(((PyObject *)Py_False));
+
+ /* "src/lxml/iterparse.pxi":72
+ * load_dtd=False, no_network=True, remove_blank_text=False,
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None, # <<<<<<<<<<<<<<
+ * html=False, recover=None, huge_tree=False, collect_ids=True,
+ * XMLSchema schema=None):
+@@ -195627,7 +195627,7 @@ static int __pyx_pw_4lxml_5etree_9iterparse_1__init__(PyObject *__pyx_v_self, Py
+ if (!values[13]) values[13] = __Pyx_NewRef(((PyObject *)Py_None));
+
+ /* "src/lxml/iterparse.pxi":73
+- * compact=True, resolve_entities=True, remove_comments=False,
++ * compact=True, resolve_entities='internal', remove_comments=False,
+ * remove_pis=False, strip_cdata=True, encoding=None,
+ * html=False, recover=None, huge_tree=False, collect_ids=True, # <<<<<<<<<<<<<<
+ * XMLSchema schema=None):
+@@ -263283,7 +263283,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_XMLParser[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_XMLParser_slots[] = {
+ {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser},
+- {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")},
++ {Py_tp_doc, (void *)PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n ")},
+ {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+ {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+ {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_XMLParser},
+@@ -263326,7 +263326,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_XMLParser = {
+ 0, /*tp_setattro*/
+ 0, /*tp_as_buffer*/
+ Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+- PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/
++ PyDoc_STR("XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema: XMLSchema =None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, collect_ids=True, target=None, compact=True)\n\n The XML parser.\n\n Parsers can be supplied as additional argument to various parse\n functions of the lxml API. A default parser is always available\n and can be replaced by a call to the global function\n 'set_default_parser'. New parsers can be created at any time\n without a major run-time overhead.\n\n The keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if DTD\n validation or attribute default values are requested (unless you\n additionally provide an XMLSchema from which the default\n attributes can be read).\n\n Available boolean keyword arguments:\n\n - attribute_defaults - inject default attributes from DTD or XMLSchema\n - dtd_validation - validate against a DTD referenced by the document\n - load_dtd - use DTD for parsing\n - no_network - prevent network access for related files (default: True)\n - decompress - automatically decompress gzip input\n (default: False, changed in lxml 6.0, disabling only affects libxml2 2.15+)\n - ns_clean - clean up redundant namespace declarations\n - recover - try hard to parse through broken XML\n - remove_blank_text - discard blank text nodes that appear ignorable\n - remove_comments - discard comments\n - remove_pis - discard processing instructions\n - strip_cdata - replace CDATA sections by normal text content (default: True)\n - compact "" - save memory for short text content (default: True)\n - collect_ids - use a hash table of XML IDs for fast access\n (default: True, always True with DTD validation)\n - huge_tree - disable security restrictions and support very deep trees\n and very long text content\n\n Other keyword arguments:\n\n - resolve_entities - replace entities by their text value: False for keeping the\n entity references, True for resolving them, and 'internal' for resolving\n internal definitions only (no external file/URL access).\n The default used to be True and was changed to 'internal' in lxml 5.0.\n - encoding - override the document encoding (note: libiconv encoding name)\n - target - a parser target object that will receive the parse events\n - schema - an XMLSchema to validate against\n\n Note that you should avoid sharing parsers between threads. While this is\n not harmful, it is more efficient to use separate parsers. This does not\n apply to the default parser.\n "), /*tp_doc*/
+ __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+ __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+ 0, /*tp_richcompare*/
+@@ -263506,7 +263506,7 @@ static PyMethodDef __pyx_methods_4lxml_5etree_ETCompatXMLParser[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_ETCompatXMLParser_slots[] = {
+ {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree__BaseParser},
+- {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")},
++ {Py_tp_doc, (void *)PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n ")},
+ {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree__BaseParser},
+ {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree__BaseParser},
+ {Py_tp_methods, (void *)__pyx_methods_4lxml_5etree_ETCompatXMLParser},
+@@ -263549,7 +263549,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_ETCompatXMLParser = {
+ 0, /*tp_setattro*/
+ 0, /*tp_as_buffer*/
+ Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+- PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities=True, remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/
++ PyDoc_STR("ETCompatXMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, decompress=False, ns_clean=False, recover=False, schema=None, huge_tree=False, remove_blank_text=False, resolve_entities='internal', remove_comments=True, remove_pis=True, strip_cdata=True, target=None, compact=True)\n\n An XML parser with an ElementTree compatible default setup.\n\n See the XMLParser class for details.\n\n This parser has ``remove_comments`` and ``remove_pis`` enabled by default\n and thus ignores comments and processing instructions.\n "), /*tp_doc*/
+ __pyx_tp_traverse_4lxml_5etree__BaseParser, /*tp_traverse*/
+ __pyx_tp_clear_4lxml_5etree__BaseParser, /*tp_clear*/
+ 0, /*tp_richcompare*/
+@@ -266739,7 +266739,7 @@ static struct PyGetSetDef __pyx_getsets_4lxml_5etree_iterparse[] = {
+ #if CYTHON_USE_TYPE_SPECS
+ static PyType_Slot __pyx_type_4lxml_5etree_iterparse_slots[] = {
+ {Py_tp_dealloc, (void *)__pyx_tp_dealloc_4lxml_5etree_iterparse},
+- {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")},
++ {Py_tp_doc, (void *)PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n ")},
+ {Py_tp_traverse, (void *)__pyx_tp_traverse_4lxml_5etree_iterparse},
+ {Py_tp_clear, (void *)__pyx_tp_clear_4lxml_5etree_iterparse},
+ {Py_tp_iter, (void *)__pyx_pw_4lxml_5etree_9iterparse_7__iter__},
+@@ -266785,7 +266785,7 @@ static PyTypeObject __pyx_type_4lxml_5etree_iterparse = {
+ 0, /*tp_setattro*/
+ 0, /*tp_as_buffer*/
+ Py_TPFLAGS_DEFAULT|Py_TPFLAGS_HAVE_VERSION_TAG|Py_TPFLAGS_CHECKTYPES|Py_TPFLAGS_HAVE_NEWBUFFER|Py_TPFLAGS_BASETYPE|Py_TPFLAGS_HAVE_GC, /*tp_flags*/
+- PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, remove_comments=False, remove_pis=False, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pis: discard processing instructions\n - strip_cdata: repla""ce CDATA sections by normal text content (default: \n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: True)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/
++ PyDoc_STR("iterparse(self, source, events=(\"end\",), tag=None, attribute_defaults=False, dtd_validation=False, load_dtd=False, no_network=True, remove_blank_text=False, compact=True, resolve_entities='internal', remove_comments=False, remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)\n\n Incremental parser.\n\n Parses XML into a tree and generates tuples (event, element) in a\n SAX-like fashion. ``event`` is any of 'start', 'end', 'start-ns',\n 'end-ns'.\n\n For 'start' and 'end', ``element`` is the Element that the parser just\n found opening or closing. For 'start-ns', it is a tuple (prefix, URI) of\n a new namespace declaration. For 'end-ns', it is simply None. Note that\n all start and end events are guaranteed to be properly nested.\n\n The keyword argument ``events`` specifies a sequence of event type names\n that should be generated. By default, only 'end' events will be\n generated.\n\n The additional ``tag`` argument restricts the 'start' and 'end' events to\n those elements that match the given tag. The ``tag`` argument can also be\n a sequence of tags to allow matching more than one tag. By default,\n events are generated for all elements. Note that the 'start-ns' and\n 'end-ns' events are not impacted by this restriction.\n\n The other keyword arguments in the constructor are mainly based on the\n libxml2 parser configuration. A DTD will also be loaded if validation or\n attribute default values are requested.\n\n Available boolean keyword arguments:\n - attribute_defaults: read default attributes from DTD\n - dtd_validation: validate (if DTD is available)\n - load_dtd: use DTD for parsing\n - no_network: prevent network access for related files\n - remove_blank_text: discard blank text nodes\n - remove_comments: discard comments\n - remove_pi""s: discard processing instructions\n - strip_cdata: replace CDATA sections by normal text content (default:\n True for XML, ignored otherwise)\n - compact: safe memory for short text content (default: True)\n - resolve_entities: replace entities by their text value (default: 'internal' only)\n - huge_tree: disable security restrictions and support very deep trees\n and very long text content (only affects libxml2 2.7+)\n - html: parse input as HTML (default: XML)\n - recover: try hard to parse through broken input (default: True for HTML,\n False otherwise)\n\n Other keyword arguments:\n - encoding: override the document encoding\n - schema: an XMLSchema to validate against\n "), /*tp_doc*/
+ __pyx_tp_traverse_4lxml_5etree_iterparse, /*tp_traverse*/
+ __pyx_tp_clear_4lxml_5etree_iterparse, /*tp_clear*/
+ 0, /*tp_richcompare*/
+diff --git a/src/lxml/iterparse.pxi b/src/lxml/iterparse.pxi
+index 42b75249..9319f646 100644
+--- a/src/lxml/iterparse.pxi
++++ b/src/lxml/iterparse.pxi
+@@ -6,8 +6,8 @@ cdef class iterparse:
+ """iterparse(self, source, events=("end",), tag=None, \
+ attribute_defaults=False, dtd_validation=False, \
+ load_dtd=False, no_network=True, remove_blank_text=False, \
+- remove_comments=False, remove_pis=False, encoding=None, \
+- html=False, recover=None, huge_tree=False, schema=None)
++ compact=True, resolve_entities='internal', remove_comments=False, \
++ remove_pis=False, strip_cdata=True, encoding=None, html=False, recover=None, huge_tree=False, schema=None)
+
+ Incremental parser.
+
+@@ -42,10 +42,10 @@ cdef class iterparse:
+ - remove_blank_text: discard blank text nodes
+ - remove_comments: discard comments
+ - remove_pis: discard processing instructions
+- - strip_cdata: replace CDATA sections by normal text content (default:
++ - strip_cdata: replace CDATA sections by normal text content (default:
+ True for XML, ignored otherwise)
+ - compact: safe memory for short text content (default: True)
+- - resolve_entities: replace entities by their text value (default: True)
++ - resolve_entities: replace entities by their text value (default: 'internal' only)
+ - huge_tree: disable security restrictions and support very deep trees
+ and very long text content (only affects libxml2 2.7+)
+ - html: parse input as HTML (default: XML)
+@@ -68,7 +68,7 @@ cdef class iterparse:
+ def __init__(self, source, events=("end",), *, tag=None,
+ attribute_defaults=False, dtd_validation=False,
+ load_dtd=False, no_network=True, remove_blank_text=False,
+- compact=True, resolve_entities=True, remove_comments=False,
++ compact=True, resolve_entities='internal', remove_comments=False,
+ remove_pis=False, strip_cdata=True, encoding=None,
+ html=False, recover=None, huge_tree=False, collect_ids=True,
+ XMLSchema schema=None):
+diff --git a/src/lxml/parser.pxi b/src/lxml/parser.pxi
+index 3106e610..ba9875c0 100644
+--- a/src/lxml/parser.pxi
++++ b/src/lxml/parser.pxi
+@@ -1584,7 +1584,7 @@ cdef class XMLParser(_FeedParser):
+ """XMLParser(self, encoding=None, attribute_defaults=False, dtd_validation=False, \
+ load_dtd=False, no_network=True, decompress=False, ns_clean=False, \
+ recover=False, schema: XMLSchema =None, huge_tree=False, \
+- remove_blank_text=False, resolve_entities=True, \
++ remove_blank_text=False, resolve_entities='internal', \
+ remove_comments=False, remove_pis=False, strip_cdata=True, \
+ collect_ids=True, target=None, compact=True)
+
+@@ -1717,7 +1717,7 @@ cdef class ETCompatXMLParser(XMLParser):
+ """ETCompatXMLParser(self, encoding=None, attribute_defaults=False, \
+ dtd_validation=False, load_dtd=False, no_network=True, decompress=False, \
+ ns_clean=False, recover=False, schema=None, \
+- huge_tree=False, remove_blank_text=False, resolve_entities=True, \
++ huge_tree=False, remove_blank_text=False, resolve_entities='internal', \
+ remove_comments=True, remove_pis=True, strip_cdata=True, \
+ target=None, compact=True)
+
+@@ -1731,7 +1731,7 @@ cdef class ETCompatXMLParser(XMLParser):
+ def __init__(self, *, encoding=None, attribute_defaults=False,
+ dtd_validation=False, load_dtd=False, no_network=True, decompress=False,
+ ns_clean=False, recover=False, schema=None,
+- huge_tree=False, remove_blank_text=False, resolve_entities=True,
++ huge_tree=False, remove_blank_text=False, resolve_entities='internal',
+ remove_comments=True, remove_pis=True, strip_cdata=True,
+ target=None, compact=True):
+ XMLParser.__init__(self,
+--
+2.35.6
+
diff --git a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
index 876fda93b63..75894460ec5 100644
--- a/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
+++ b/meta/recipes-devtools/python/python3-lxml_6.0.2.bb
@@ -20,7 +20,9 @@ DEPENDS += "libxml2 libxslt"
SRC_URI[sha256sum] = "cd79f3367bd74b317dda655dc8fcfa304d9eb6e4fb06b7168c5cf27f96e0cd62"
-SRC_URI += "${PYPI_SRC_URI}"
+SRC_URI += "${PYPI_SRC_URI} \
+ file://CVE-2026-41066.patch"
+
inherit pkgconfig pypi setuptools3
# {standard input}: Assembler messages:
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (19 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-10 4:42 ` Hemanth Kumar M D
2026-09-09 7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
` (16 subsequent siblings)
37 siblings, 1 reply; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Harish Sadineni <Harish.Sadineni@windriver.com>
Allocate the maximum array sizes directly, instead of resizing
the arrays as needed. This eliminates alloca usage from the
function, and fixes the out-of-bounds accesses. The asserts
guard against the bug coming back if the balancing of the tree
turns out not to work correctly.
Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
CVE: CVE-2026-19542
Reference:
[1]https://security-tracker.debian.org/tracker/CVE-2026-19542
[2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
[3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: fixed CVE: tag in patch]
---
.../glibc/glibc/0023-CVE-2026-19542.patch | 98 +++++++++++++++++++
meta/recipes-core/glibc/glibc_2.43.bb | 1 +
2 files changed, 99 insertions(+)
create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
new file mode 100644
index 00000000000..094a50919dc
--- /dev/null
+++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
@@ -0,0 +1,98 @@
+From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
+From: Florian Weimer <fweimer@redhat.com>
+Date: Fri, 14 Aug 2026 13:41:16 +0200
+Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
+
+Allocate the maximum array sizes directly, instead of resizing
+the arrays as needed. This eliminates alloca usage from the
+function, and fixes the out-of-bounds accesses. The asserts
+guard against the bug coming back if the balancing of the tree
+turns out not to work correctly.
+
+CVE: CVE-2026-19542
+Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
+
+Reviewed-by: Adhemerval Zanella <adhemerval.zanella@linaro.org>
+Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
+---
+ misc/tsearch.c | 31 +++++++++++--------------------
+ 1 file changed, 11 insertions(+), 20 deletions(-)
+
+diff --git a/misc/tsearch.c b/misc/tsearch.c
+index 9b2eb34b25..e517dfa712 100644
+--- a/misc/tsearch.c
++++ b/misc/tsearch.c
+@@ -85,6 +85,7 @@
+ #include <assert.h>
+ #include <stdalign.h>
+ #include <stddef.h>
++#include <stdint.h>
+ #include <stdlib.h>
+ #include <string.h>
+ #include <search.h>
+@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ int cmp;
+ node *rootp = (node *) vrootp;
+ node root, unchained;
+- /* Stack of nodes so we remember the parents without recursion. It's
+- _very_ unlikely that there are paths longer than 40 nodes. The tree
+- would need to have around 250.000 nodes. */
+- int stacksize = 40;
++ /* Stack of nodes so we remember the parents without recursion. The
++ stack size is a conservative approximation of the maximum height
++ of a red-black tree, based on size of the address space.
++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */
++ enum { stacksize = 2 * UINTPTR_WIDTH };
+ int sp = 0;
+- node **nodestack = alloca (sizeof (node *) * stacksize);
++ node *nodestack[stacksize];
+
+ if (rootp == NULL)
+ return NULL;
+@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ root = DEREFNODEPTR(rootp);
+ while ((cmp = (*compar) (key, root->key)) != 0)
+ {
+- if (sp == stacksize)
+- {
+- node **newstack;
+- stacksize += 20;
+- newstack = alloca (sizeof (node *) * stacksize);
+- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
+- }
+-
++ assert (sp < stacksize);
+ nodestack[sp++] = rootp;
+ p = DEREFNODEPTR(rootp);
+ if (cmp < 0)
+@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ node upn;
+ for (;;)
+ {
+- if (sp == stacksize)
+- {
+- node **newstack;
+- stacksize += 20;
+- newstack = alloca (sizeof (node *) * stacksize);
+- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
+- }
++ assert (sp < stacksize);
+ nodestack[sp++] = parentp;
+ parentp = up;
+ upn = DEREFNODEPTR(up);
+@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ SETNODEPTR(pp,q);
+ /* Make sure pp is right if the case below tries to use
+ it. */
++ assert (sp < stacksize);
+ nodestack[sp++] = pp = LEFTPTR(q);
+ q = RIGHT(p);
+ }
+@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
+ SETLEFT(p,RIGHT(q));
+ SETRIGHT(q,p);
+ SETNODEPTR(pp,q);
++ assert (sp < stacksize);
+ nodestack[sp++] = pp = RIGHTPTR(q);
+ q = LEFT(p);
+ }
diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
index 9f3a3814d0a..3ef2301191d 100644
--- a/meta/recipes-core/glibc/glibc_2.43.bb
+++ b/meta/recipes-core/glibc/glibc_2.43.bb
@@ -55,6 +55,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
+ file://0023-CVE-2026-19542.patch \
"
B = "${WORKDIR}/build-${TARGET_SYS}"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (20 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
` (15 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56001
[2] https://security-tracker.debian.org/tracker/CVE-2026-56001
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont/CVE-2026-56001.patch | 87 +++++++++++++++++++
.../xorg-lib/libxfont_1.5.4.bb | 3 +
2 files changed, 90 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
new file mode 100644
index 00000000000..1de7f3e0372
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56001.patch
@@ -0,0 +1,87 @@
+From be0b08e2d354138d3222b4490e2a77c6ee42f778 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:46:10 +1000
+Subject: [PATCH] bitscale: fix integer overflow in BitmapScaleBitmaps
+ bytestoalloc
+
+bytestoalloc is declared as unsigned int (32-bit). When the sum of
+per-glyph byte counts exceeds 2^32, the value wraps around and calloc()
+allocates a buffer that is too small. The subsequent ScaleBitmap loop
+then writes past the end of the allocated buffer.
+
+Change bytestoalloc from unsigned int to size_t to match the actual
+allocation size type, and add an explicit overflow check in the
+accumulation loop to bail out if the total would exceed SIZE_MAX.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56001/ZDI-CAN-30558
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Note: 'SIZE_MAX' is defined in header '<stdint.h>'. Add '#include
+<stdint.h>' to fix build failure.
+
+Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
+Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/be0b08e2d354138d3222b4490e2a77c6ee42f778]
+CVE: CVE-2026-56001
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 24 +++++++++++++++++++++---
+ 1 file changed, 21 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 13ed924..32144d6 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -38,6 +38,7 @@ from The Open Group.
+ #include <X11/fonts/bitmap.h>
+ #include <X11/fonts/fontutil.h>
+ #include <math.h>
++#include <stdint.h>
+
+ #ifndef MAX
+ #define MAX(a,b) (((a)>(b)) ? a : b)
+@@ -1459,7 +1460,7 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */
+ opci;
+ FontInfoPtr pfi;
+ int glyph;
+- unsigned bytestoalloc = 0;
++ size_t bytestoalloc = 0;
+ int firstCol, lastCol, firstRow, lastRow;
+
+ double xform[4], inv_xform[4];
+@@ -1486,8 +1487,25 @@ BitmapScaleBitmaps(FontPtr pf, /* scaled font */
+ glyph = pf->glyph;
+ for (i = 0; i < nchars; i++)
+ {
+- if ((pci = ACCESSENCODING(bitmapFont->encoding, i)))
+- bytestoalloc += BYTES_FOR_GLYPH(pci, glyph);
++ if ((pci = ACCESSENCODING(bitmapFont->encoding, i))) {
++ size_t glyphsize = BYTES_FOR_GLYPH(pci, glyph);
++ if (bytestoalloc > SIZE_MAX - glyphsize) {
++ fprintf(stderr,
++ "Error: bitmap allocation overflow for scaled font\n");
++ goto bail;
++ }
++ bytestoalloc += glyphsize;
++ }
++ }
++
++ /* Reject unreasonably large bitmap allocations that could result
++ * from malicious fonts with extreme scale factors. 256 MiB is
++ * far beyond any legitimate scaled bitmap font. */
++#define BITMAP_SCALE_MAX_ALLOC (256 * 1024 * 1024)
++ if (bytestoalloc > BITMAP_SCALE_MAX_ALLOC) {
++ fprintf(stderr,
++ "Error: scaled bitmap size %zu exceeds limit\n", bytestoalloc);
++ goto bail;
+ }
+
+ /* Do we add the font malloc stuff for VALUE ADDED ? */
+--
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 9ec7cc30f58..59c489b785d 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -19,6 +19,9 @@ XORG_EXT = "tar.bz2"
BBCLASSEXTEND = "native"
+SRC_URI += "file://CVE-2026-56001.patch \
+ "
+
SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"
PACKAGECONFIG ??= "${@bb.utils.filter('DISTRO_FEATURES', 'ipv6', d)}"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (21 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
` (14 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56002
[2] https://security-tracker.debian.org/tracker/CVE-2026-56002
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont/CVE-2026-56002.patch | 150 ++++++++++++++++++
.../xorg-lib/libxfont_1.5.4.bb | 1 +
2 files changed, 151 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
new file mode 100644
index 00000000000..cef8a06a686
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56002.patch
@@ -0,0 +1,150 @@
+From b4389e0b1d84a690b819bb27b1439968811a3674 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:48:40 +1000
+Subject: [PATCH] pcfread: validate bitmap sizes and offsets against per-glyph
+ metrics
+
+pcfReadFont() uses bitmapSizes[] read directly from the PCF file to
+allocate the repadded bitmap buffer. However, per-glyph metrics (also
+from the file) control how much data RepadBitmap() writes. A malicious
+PCF font can declare a small bitmapSizes[] value while having per-glyph
+metrics that require more space, causing a heap buffer overflow.
+
+A similar issue happens with the encoding offsets: pcfReadFont reads
+encoding offsets from the PCF file and uses them to index into the
+metrics array without bounds checking. A crafted font can set an
+encoding offset larger than nmetrics, causing an out-of-bounds pointer
+that is later dereferenced when glyphs are accessed through the encoding
+table.
+
+And the no-repad bitmap path (when PCF_GLYPH_PAD matches the requested
+glyph pad) only validated that each glyph's offset was within the bitmap
+buffer, but did not check that the full glyph extent (offset +
+BYTES_PER_ROW * height) fits within the buffer. A crafted font with a
+glyph offset near the end of a small bitmap buffer but large glyph
+metrics causes a heap buffer over-read when the glyph is later rendered.
+
+This vulnerability was discovered by:
+ Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56002/ZDI-CAN-30559
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Note: 'INT_MAX' is defined in header '<limits.h>'. Add '#include
+<limits.h>' to fix build failure.
+
+Upstream-Status: Backport [import from debian libxfont1 1.5.2-4+deb9u1
+Upstream commit https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/b4389e0b1d84a690b819bb27b1439968811a3674]
+CVE: CVE-2026-56002
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/pcfread.c | 60 +++++++++++++++++++++++++++++++++++++++++---
+ 1 file changed, 57 insertions(+), 3 deletions(-)
+
+diff --git a/src/bitmap/pcfread.c b/src/bitmap/pcfread.c
+index 4a372c5..0cc9777 100644
+--- a/src/bitmap/pcfread.c
++++ b/src/bitmap/pcfread.c
+@@ -45,6 +45,7 @@ from The Open Group.
+ #include <stdarg.h>
+ #include <stdint.h>
+ #include <string.h>
++#include <limits.h>
+
+ void
+ pcfError(const char* message, ...)
+@@ -529,25 +530,74 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ int old,
+ new;
+ xCharInfo *metric;
++ int srcPad = PCF_GLYPH_PAD(format);
+
+- sizepadbitmaps = bitmapSizes[PCF_SIZE_TO_INDEX(glyph)];
+- padbitmaps = malloc(sizepadbitmaps);
++ /* Compute the actual required size from per-glyph metrics instead
++ * of trusting the file's bitmapSizes[] value, which may be smaller
++ * than the actual data written by RepadBitmap. */
++ sizepadbitmaps = 0;
++ for (i = 0; i < nbitmaps; i++) {
++ int w, h, glyphBytes;
++ metric = &metrics[i].metrics;
++ w = metric->rightSideBearing - metric->leftSideBearing;
++ h = metric->ascent + metric->descent;
++ glyphBytes = BYTES_PER_ROW(w, glyph) * h;
++ if (glyphBytes < 0 || (glyphBytes > 0 && sizepadbitmaps > INT_MAX - glyphBytes)) {
++ pcfError("pcfReadFont(): bitmap size overflow\n");
++ goto Bail;
++ }
++ sizepadbitmaps += glyphBytes;
++ }
++ padbitmaps = malloc(sizepadbitmaps ? sizepadbitmaps : 1);
+ if (!padbitmaps) {
+ pcfError("pcfReadFont(): Couldn't allocate padbitmaps (%d)\n", sizepadbitmaps);
+ goto Bail;
+ }
+ new = 0;
+ for (i = 0; i < nbitmaps; i++) {
++ int srcGlyphBytes;
++
+ old = offsets[i];
+ metric = &metrics[i].metrics;
++
++ /* Validate source offset and source glyph size against the
++ * source bitmap buffer to prevent out-of-bounds reads. */
++ srcGlyphBytes = BYTES_PER_ROW(
++ metric->rightSideBearing - metric->leftSideBearing,
++ srcPad) * (metric->ascent + metric->descent);
++ if (old < 0 || old > sizebitmaps ||
++ srcGlyphBytes < 0 || srcGlyphBytes > sizebitmaps - old) {
++ pcfError("pcfReadFont(): bitmap offset/size out of bounds\n");
++ free(padbitmaps);
++ goto Bail;
++ }
++
+ offsets[i] = new;
+ new += RepadBitmap(bitmaps + old, padbitmaps + new,
+- PCF_GLYPH_PAD(format), glyph,
++ srcPad, glyph,
+ metric->rightSideBearing - metric->leftSideBearing,
+ metric->ascent + metric->descent);
+ }
+ free(bitmaps);
+ bitmaps = padbitmaps;
++ } else {
++ /* Validate offsets and full glyph extents against bitmap buffer */
++ for (i = 0; i < nbitmaps; i++) {
++ int glyphBytes;
++ xCharInfo *metric = &metrics[i].metrics;
++
++ glyphBytes = BYTES_PER_ROW(
++ metric->rightSideBearing - metric->leftSideBearing,
++ glyph) * (metric->ascent + metric->descent);
++ if (offsets[i] >= (CARD32)sizebitmaps ||
++ glyphBytes < 0 ||
++ glyphBytes > sizebitmaps - (int)offsets[i]) {
++ pcfError("pcfReadFont(): bitmap offset/size out of bounds "
++ "(offset %u, size %d, total %d)\n",
++ offsets[i], glyphBytes, sizebitmaps);
++ goto Bail;
++ }
++ }
+ }
+ for (i = 0; i < nbitmaps; i++)
+ metrics[i].bits = bitmaps + offsets[i];
+@@ -622,6 +672,10 @@ pcfReadFont(FontPtr pFont, FontFilePtr file,
+ if (IS_EOF(file)) goto Bail;
+ if (encodingOffset == 0xFFFF) {
+ pFont->info.allExist = FALSE;
++ } else if (encodingOffset >= nmetrics) {
++ pcfError("pcfReadFont(): encoding offset %d out of range (nmetrics=%d)\n",
++ encodingOffset, nmetrics);
++ goto Bail;
+ } else {
+ if(!encoding[SEGMENT_MAJOR(i)]) {
+ encoding[SEGMENT_MAJOR(i)]=
+--
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 59c489b785d..08c96fdac87 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -20,6 +20,7 @@ XORG_EXT = "tar.bz2"
BBCLASSEXTEND = "native"
SRC_URI += "file://CVE-2026-56001.patch \
+ file://CVE-2026-56002.patch \
"
SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (22 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
` (13 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-56003
[2] https://security-tracker.debian.org/tracker/CVE-2026-56003
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../xorg-lib/libxfont/CVE-2026-56003.patch | 114 ++++++++++++++++++
.../xorg-lib/libxfont_1.5.4.bb | 1 +
2 files changed, 115 insertions(+)
create mode 100644 meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
diff --git a/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
new file mode 100644
index 00000000000..0092c712d44
--- /dev/null
+++ b/meta/recipes-graphics/xorg-lib/libxfont/CVE-2026-56003.patch
@@ -0,0 +1,114 @@
+From dff957a5158da038a282a59a31fe736702732939 Mon Sep 17 00:00:00 2001
+From: Peter Hutterer <peter.hutterer@who-t.net>
+Date: Mon, 1 Jun 2026 16:49:55 +1000
+Subject: [PATCH] bitscale: add bounds check to computeProps for property
+ buffer
+
+ComputeScaledProperties allocates a fixed-size property buffer of 70
+slots. computeProps iterates the source font's properties and writes 1
+slot for unscaled properties or 2 slots for scaledX/scaledY properties,
+with no bounds check. A malicious font with many duplicate properties
+matching fontPropTable entries can overflow the allocated buffer.
+
+Fix this by passing the remaining buffer capacity to computeProps and
+checking it before each write. Properties that would exceed the buffer
+are silently skipped.
+
+The function is also restructured to handle the buffer writes for
+scaledX/scaledY inside the switch cases directly, rather than in a
+separate block after the switch. This makes the control flow clearer and
+ensures the bounds check covers all writes.
+
+This vulnerability was discovered by:
+Anonymous working with TrendAI Zero Day Initiative
+
+CVE-2026-56003/ZDI-CAN-30560
+
+Assisted-by: Claude:claude-opus-4-6
+Signed-off-by: Peter Hutterer <peter.hutterer@who-t.net>
+Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxfont/-/merge_requests/34>
+
+Upstream-Status: Backport [https://gitlab.freedesktop.org/xorg/lib/libxfont/-/commit/dff957a5158da038a282a59a31fe736702732939]
+CVE: CVE-2026-56003
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/bitmap/bitscale.c | 39 ++++++++++++++++++++-------------------
+ 1 file changed, 20 insertions(+), 19 deletions(-)
+
+diff --git a/src/bitmap/bitscale.c b/src/bitmap/bitscale.c
+index 32144d6..2affc11 100644
+--- a/src/bitmap/bitscale.c
++++ b/src/bitmap/bitscale.c
+@@ -513,7 +513,8 @@ static int
+ computeProps(FontPropPtr pf, char *wasStringProp,
+ FontPropPtr npf, char *isStringProp,
+ unsigned int nprops, double xfactor, double yfactor,
+- double sXfactor, double sYfactor)
++ double sXfactor, double sYfactor,
++ int maxprops)
+ {
+ int n;
+ int count;
+@@ -528,14 +529,26 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+
+ switch (t->type) {
+ case scaledX:
+- npf->value = doround(xfactor * (double)pf->value);
+- rawfactor = sXfactor;
+- break;
+ case scaledY:
+- npf->value = doround(yfactor * (double)pf->value);
+- rawfactor = sYfactor;
++ if (count + 2 > maxprops)
++ continue;
++ npf->value = (t->type == scaledX)
++ ? doround(xfactor * (double)pf->value)
++ : doround(yfactor * (double)pf->value);
++ rawfactor = (t->type == scaledX) ? sXfactor : sYfactor;
++ npf->name = pf->name;
++ npf++;
++ count++;
++ npf->value = doround(rawfactor * (double)pf->value);
++ npf->name = rawFontPropTable[t - fontPropTable].atom;
++ npf++;
++ count++;
++ *isStringProp++ = *wasStringProp;
++ *isStringProp++ = *wasStringProp;
+ break;
+ case unscaled:
++ if (count + 1 > maxprops)
++ continue;
+ npf->value = pf->value;
+ npf->name = pf->name;
+ npf++;
+@@ -545,18 +558,6 @@ computeProps(FontPropPtr pf, char *wasStringProp,
+ default:
+ break;
+ }
+- if (t->type != unscaled)
+- {
+- npf->name = pf->name;
+- npf++;
+- count++;
+- npf->value = doround(rawfactor * (double)pf->value);
+- npf->name = rawFontPropTable[t - fontPropTable].atom;
+- npf++;
+- count++;
+- *isStringProp++ = *wasStringProp;
+- *isStringProp++ = *wasStringProp;
+- }
+ }
+ return count;
+ }
+@@ -671,7 +672,7 @@ ComputeScaledProperties(FontInfoPtr sourceFontInfo, /* the font to be scaled */
+ n = NPROPS;
+ n += computeProps(sourceFontInfo->props, sourceFontInfo->isStringProp,
+ fp, isStringProp, sourceFontInfo->nprops, dx, dy,
+- sdx, sdy);
++ sdx, sdy, nProps - NPROPS);
+ return n;
+ }
+
+--
+2.43.0
+
diff --git a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
index 08c96fdac87..e254516fcf9 100644
--- a/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
+++ b/meta/recipes-graphics/xorg-lib/libxfont_1.5.4.bb
@@ -21,6 +21,7 @@ BBCLASSEXTEND = "native"
SRC_URI += "file://CVE-2026-56001.patch \
file://CVE-2026-56002.patch \
+ file://CVE-2026-56003.patch \
"
SRC_URI[sha256sum] = "1a7f7490774c87f2052d146d1e0e64518d32e6848184a18654e8d0bb57883242"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 25/38] wget: fix CVE-2026-16599
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (23 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
` (12 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY
authentication functionality.
The server-supplied sequence number from the FTP challenge line is used
as an iteration count for an MD5 key-derivation loop without any upper
bound validation. A malicious FTP server or a network attacker
positioned to intercept FTP traffic can send a crafted OPIE challenge
with a sequence number near INT_MAX, causing wget to perform up to
approximately 2.1 billion MD5 computations and suspend for some time.
The --timeout option does not mitigate this because it applies only to
network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
Reference:
https://nvd.nist.gov/vuln/detail/cve-2026-16599
Backport the patch to fix CVE-2026-16599.
https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
Signed-off-by: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
[YC: rewrapped commit message]
---
.../wget/wget/CVE-2026-16599.patch | 68 +++++++++++++++++++
meta/recipes-extended/wget/wget_1.25.0.bb | 1 +
2 files changed, 69 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-16599.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-16599.patch b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch
new file mode 100644
index 00000000000..fbe8c0566cd
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-16599.patch
@@ -0,0 +1,68 @@
+From e9697d98e7249b0f68a6be040a4f3dcc5bc101fa Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Sat, 20 Jun 2026 14:39:54 +0200
+Subject: [PATCH] Fix server-controlled unbounded MD5 loop in FTP OPIE
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+* src/ftp-basic.c (ftp_login): Limit the skey sequence to 9999.
+
+Report:
+wget accepts an unbounded server-controlled integer as the iteration
+count for its OPIE/S-KEY MD5 key-derivation loop. No upper bound is
+enforced on the sequence number supplied by the server in the FTP
+challenge line. The value is passed directly to skey_response() as a
+loop counter, causing wget to perform up to ~2.1 billion full MD5
+computations before responding to the authentication challenge.
+
+Reported-by: Michał Majchrowicz and Marcin Wyczechowski
+
+CVE: CVE-2026-16599
+
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa]
+
+Signed-off-by: Ghanshyam Banait <Ghanshyam.BanaitSanjay@windriver.com>
+---
+ src/ftp-basic.c | 15 +++++++++++----
+ 1 file changed, 11 insertions(+), 4 deletions(-)
+
+diff --git a/src/ftp-basic.c b/src/ftp-basic.c
+index 0f4bb821..af38a69a 100644
+--- a/src/ftp-basic.c
++++ b/src/ftp-basic.c
+@@ -204,12 +204,11 @@ ftp_login (int csock, const char *acc, const char *pass)
+ "331 s/key ",
+ "331 opiekey "
+ };
+- size_t i;
+ const char *seed = NULL;
+
+- for (i = 0; i < countof (skey_head); i++)
++ for (size_t i = 0; i < countof (skey_head); i++)
+ {
+- int l = strlen (skey_head[i]);
++ size_t l = strlen (skey_head[i]);
+ if (0 == c_strncasecmp (skey_head[i], respline, l))
+ {
+ seed = respline + l;
+@@ -222,7 +221,15 @@ ftp_login (int csock, const char *acc, const char *pass)
+
+ /* Extract the sequence from SEED. */
+ for (; c_isdigit (*seed); seed++)
+- skey_sequence = 10 * skey_sequence + *seed - '0';
++ {
++ skey_sequence = 10 * skey_sequence + *seed - '0';
++ if (skey_sequence > 9999)
++ {
++ xfree (respline);
++ return FTPLOGREFUSED;
++ }
++ }
++
+ if (*seed == ' ')
+ ++seed;
+ else
+--
+GitLab
+
diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb
index dc4903429be..95845d695a9 100644
--- a/meta/recipes-extended/wget/wget_1.25.0.bb
+++ b/meta/recipes-extended/wget/wget_1.25.0.bb
@@ -21,6 +21,7 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://CVE-2026-58471.patch \
file://CVE-2026-58472.patch \
file://CVE-2026-58472-regression.patch \
+ file://CVE-2026-16599.patch \
"
SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (24 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
` (11 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Daniel Turull <daniel.turull@ericsson.com>
- The RAR5 double-free in init_unpack() is a regression introduced
upstream by commit 620bdafa on 2026-05-16 and existed only
on the git master branch until it was fixed by PR #3071 (commit
1c914cdf) on 2026-05-24. It was never part of an upstream release.
- The upstream release tarballs (3.6.x/3.7.x/3.8.6) use the older
init_unpack() with unchecked calloc and no early-return path, so the
freed window_buf/filtered_buf pointers are never left dangling and the
double-free cannot occur.
References:
https://nvd.nist.gov/vuln/detail/cve-2026-14164
https://lore.kernel.org/openembedded-core/0447ebc9d29b0736de8ba0c75f155ed4f880d072.camel@pbarker.dev/
Signed-off-by: Daniel Turull <daniel.turull@ericsson.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/libarchive/libarchive_3.8.7.bb | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
index e8c3a3bfe3d..afc06f85d4c 100644
--- a/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
+++ b/meta/recipes-extended/libarchive/libarchive_3.8.7.bb
@@ -92,3 +92,7 @@ RDEPENDS:${PN}-ptest += "bsdtar bsdcpio"
CVE_STATUS[CVE-2026-4426] = "fixed-version: fixed since 3.8.7"
CVE_STATUS[CVE-2026-5121] = "fixed-version: fixed since 3.8.7"
CVE_STATUS[CVE-2026-5745] = "fixed-version: fixed since 3.8.6"
+CVE_STATUS[CVE-2026-14164] = "fixed-version: Double-free regression in the RAR5\
+ reader's init_unpack() was introduced upstream by commit 620bdafa (2026-05-16) and existed\
+ only on the git master branch until the fix in PR #3071 (commit 1c914cdf, 2026-05-24). It was\
+ never part of an upstream release tarball."
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (25 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 17:00 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
` (10 subsequent siblings)
37 siblings, 1 reply; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
Analysis:
- NVD identifies the vulnerable code as net/tcp.c when
CONFIG_PROT_TCP is enabled [1].
- tools-only_defconfig disables networking, so this code is not built
into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 7eaf721ca83..0e57bb88849 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -1,2 +1,4 @@
require u-boot-common.inc
require u-boot-tools.inc
+
+CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (26 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
` (9 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
Analysis:
- NVD identifies the vulnerable code as net/tcp.c when
CONFIG_PROT_TCP is enabled [1].
- tools-only_defconfig disables networking, so this code is not built
into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29008
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 0e57bb88849..6b28718c54a 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -2,3 +2,4 @@ require u-boot-common.inc
require u-boot-tools.inc
CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
+CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (27 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
` (8 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
Analysis:
- NVD identifies the vulnerable code as the NFS client implementation
enabled by CONFIG_CMD_NFS [1].
- tools-only_defconfig disables networking, so net/nfs.c is not built
into u-boot-tools [2].
- Hence ignoring the CVE for this recipe.
Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-29009
[2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 6b28718c54a..5e2ed063868 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -3,3 +3,4 @@ require u-boot-tools.inc
CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
+CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools."
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (28 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
` (7 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
CVE-2026-33243 is assigned to barebox, but NVD currently also maps it
to denx:u-boot. That U-Boot mapping is incorrect because the U-Boot-side
FIT hashed-nodes verification issue is tracked separately as
CVE-2026-46728. A correction request has been sent to NVD to remove the
incorrect denx:u-boot mapping. The existing patch backports U-Boot commit
2092322b31cc8b1f8c9e2e238d1043ae0637b241 [3], which is the U-Boot fix
referenced by CVE-2026-46728 [2].
Rename the patch and update its CVE tag so the filename and metadata
identify the affected U-Boot vendor correctly.
Apply the same patch to u-boot-tools because that recipe builds
fit_check_sign, which uses the affected FIT signature-verification path.
The bootloader recipe already carried the backport, but u-boot-tools did
not.
[1] https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728
[3] https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../{CVE-2026-33243.patch => CVE-2026-46728.patch} | 11 ++++++++---
meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 4 ++++
meta/recipes-bsp/u-boot/u-boot_2026.01.bb | 4 +++-
3 files changed, 15 insertions(+), 4 deletions(-)
rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%)
diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
similarity index 98%
rename from meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch
rename to meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
index c7086e183fb..4e582d529ea 100644
--- a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch
+++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch
@@ -28,11 +28,16 @@ Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.c
Reported-by: Apple Security Engineering and Architecture (SEAR)
Tested-by: Tom Rini <trini@konsulko.com>
-[YB: Removed a skippable condition in fit_config_get_hash_list.
- This flag is not available in this version]
-CVE: CVE-2026-33243
+CVE: CVE-2026-46728
Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241]
+
+Backport Changes:
+Dropped the FIT_COMPAT_PROP condition because this macro is not
+available in U-Boot v2026.01.
+
+(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241)
Signed-off-by: Yanis Binard <yanis.binard@smile.fr>
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
boot/image-fit-sig.c | 226 +++++++++++++++++++++++++++++-------
doc/usage/fit/signature.rst | 19 ++-
diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
index 5e2ed063868..77e086815c1 100644
--- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
@@ -1,6 +1,10 @@
require u-boot-common.inc
require u-boot-tools.inc
+SRC_URI += "file://CVE-2026-46728.patch"
+
+CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport."
+
CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools."
diff --git a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
index 6d9bc126a16..9610d9e8fe0 100644
--- a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
+++ b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb
@@ -3,7 +3,9 @@ require u-boot.inc
DEPENDS += "bc-native dtc-native gnutls-native python3-pyelftools-native"
-SRC_URI += "file://CVE-2026-33243.patch"
+SRC_URI += "file://CVE-2026-46728.patch"
+
+CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport."
# workarounds for aarch64 kvm qemu boot regressions
SRC_URI:append:qemuarm64 = " file://disable-CONFIG_BLOBLIST.cfg"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (29 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
` (6 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Ankur Tyagi <ankur.tyagi85@gmail.com>
Apply patches recommended by upstream[1] as mentioned in the NVD[2]
[1] https://w1.fi/security/2026-1/
[2] https://nvd.nist.gov/vuln/detail/cve-2026-58374
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../wpa-supplicant/CVE-2026-58374-1.patch | 52 ++++++++++++++++++
.../wpa-supplicant/CVE-2026-58374-2.patch | 47 ++++++++++++++++
.../wpa-supplicant/CVE-2026-58374-3.patch | 55 +++++++++++++++++++
.../wpa-supplicant/CVE-2026-58374-4.patch | 46 ++++++++++++++++
.../wpa-supplicant/CVE-2026-58374-5.patch | 47 ++++++++++++++++
.../wpa-supplicant/wpa-supplicant_2.11.bb | 5 ++
6 files changed, 252 insertions(+)
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
create mode 100644 meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
new file mode 100644
index 00000000000..625371c2b55
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-1.patch
@@ -0,0 +1,52 @@
+From 708a4247581c98c0cc46504e4abb874b4c835ffe Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 23:24:04 +0300
+Subject: [PATCH 1/5] AP MLD: Fix link ID validation in Basic MLE parsing
+
+Link ID 15 can be indicated in the field, but that is not a valid value
+and must be rejected to avoid issues pointing beyond the array of links
+for a non-AP MLD. Without this, an invalid MLE could result in writing
+beyond the end of the buffer and causing process termination or
+unexpected behavior.
+
+Fixes: 5f5db9366cde ("AP: MLO: Process Multi-Link element from (Re)Association Request frame")
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=46dd5a4ffc9bcf44cf8fc45120b3e1e5ec922187]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/ieee802_11_eht.c | 10 ++++++++--
+ 1 file changed, 8 insertions(+), 2 deletions(-)
+
+diff --git a/src/ap/ieee802_11_eht.c b/src/ap/ieee802_11_eht.c
+index b935ee889a89..804808c0dbfd 100644
+--- a/src/ap/ieee802_11_eht.c
++++ b/src/ap/ieee802_11_eht.c
+@@ -1262,6 +1262,7 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ size_t sub_elem_len = *(pos + 1);
+ size_t sta_info_len;
+ u16 control;
++ u8 link_id;
+
+ wpa_printf(MSG_DEBUG, "MLD: sub element len=%zu",
+ sub_elem_len);
+@@ -1302,8 +1303,13 @@ u16 hostapd_process_ml_assoc_req(struct hostapd_data *hapd,
+ goto out;
+ }
+ control = WPA_GET_LE16(pos);
+- link_info = &info->links[control &
+- EHT_PER_STA_CTRL_LINK_ID_MSK];
++ link_id = control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++ if (link_id >= MAX_NUM_MLD_LINKS) {
++ wpa_printf(MSG_DEBUG,
++ "MLD: Invalid Link ID in Per-STA Profile subelement");
++ goto out;
++ }
++ link_info = &info->links[link_id];
+ pos += 2;
+ ml_len -= 2;
+ sub_elem_len -= 2;
+--
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
new file mode 100644
index 00000000000..07dd9d3a65f
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-2.patch
@@ -0,0 +1,47 @@
+From 00e74b2f6e21e4d01aa58433a441ca4c81fb10ab Mon Sep 17 00:00:00 2001
+From: Amarnath Hullur Subramanyam <amarnathhs@google.com>
+Date: Thu, 30 Apr 2026 18:24:35 -0700
+Subject: [PATCH 2/5] BSS: Add bounds check for link_id in Basic MLE parsing
+
+In wpa_bss_parse_basic_ml_element() in bss.c, an extracted link_id is
+used without validation against the maximum allowed links
+(MAX_NUM_MLD_LINKS). Processing a malformed Basic Multi-Link element
+(MLE) with an out-of-bounds link_id could lead to memory corruption.
+However, the modified location is within the body of the received frame
+and as such, this does not result in additional issues since that area
+is controlled by the transmitter of the frame. In any case, it is better
+to be explicit with validating the Link ID value.
+
+This commit introduces a strict bounds check immediately after link_id
+extraction. If link_id exceeds or equals MAX_NUM_MLD_LINKS, parsing is
+gracefully aborted with a debug log entry.
+
+Fixes: de5e01010cb2 ("wpa_supplicant: Support ML probe request")
+Signed-off-by: Amarnath Hullur Subramanyam <amarnathhs@google.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=aa9d345887389a251c63a3781d2ad2940d079193]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/bss.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/wpa_supplicant/bss.c b/wpa_supplicant/bss.c
+index e8aaf6fe1848..11950064a1b6 100644
+--- a/wpa_supplicant/bss.c
++++ b/wpa_supplicant/bss.c
+@@ -1710,6 +1710,11 @@ int wpa_bss_parse_basic_ml_element(struct wpa_supplicant *wpa_s,
+ ETH_ALEN);
+
+ link_id = ml_basic_common_info->variable[0] & EHT_ML_LINK_ID_MSK;
++ if (link_id >= MAX_NUM_MLD_LINKS) {
++ wpa_printf(MSG_DEBUG, "MLD: Invalid link ID %u in Basic MLE",
++ link_id);
++ goto out;
++ }
+
+ bss->mld_link_id = link_id;
+ seen = bss->valid_links = BIT(link_id);
+--
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
new file mode 100644
index 00000000000..9e28d0a95a3
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-3.patch
@@ -0,0 +1,55 @@
+From ae24a10634f6e19d75888f5d786f380bb7af5b86 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 23:16:08 +0300
+Subject: [PATCH 3/5] MLD: Validate MLE Link ID fields in association rejection
+ case
+
+The Link ID Info field in the Common Info field needs to ignore the
+reserved bits to be more extensible for future. Both that link ID for
+the association link and the link IDs for other links need to be
+verified to be within the valid range (0-14), so check that here. The
+parsed link ID was not used for anything yet, but it is better to make
+sure this in theory common parser is not exposing invalid data to the
+caller should it be used for additional purposes in the future.
+
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=a8531e3d871e6fa72f2f85d91e9f787326b2af8b]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/events.c | 11 ++++++++++-
+ 1 file changed, 10 insertions(+), 1 deletion(-)
+
+diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c
+index 49917f7aaf72..600718d8efc4 100644
+--- a/wpa_supplicant/events.c
++++ b/wpa_supplicant/events.c
+@@ -3864,7 +3864,12 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ pos = common_info->variable;
+
+ /* Store the information for the association link */
+- ml_info[i].link_id = *pos;
++ ml_info[i].link_id = *pos & EHT_ML_LINK_ID_MSK;
++ if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) {
++ wpa_printf(MSG_DEBUG,
++ "MLD: Invalid Link ID value for assoc link");
++ goto out;
++ }
+ pos++;
+
+ /* Skip the BSS Parameters Change Count */
+@@ -3999,6 +4004,10 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ MAC2STR(pos + 1), nstr_bitmap_len);
+
+ ml_info[i].link_id = ctrl & EHT_PER_STA_CTRL_LINK_ID_MSK;
++ if (ml_info[i].link_id >= MAX_NUM_MLD_LINKS) {
++ wpa_printf(MSG_DEBUG, "MLD: Invalid Link ID value");
++ goto out;
++ }
+ os_memcpy(ml_info[i].bssid, pos + 1, ETH_ALEN);
+
+ pos += sta_info_len;
+--
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
new file mode 100644
index 00000000000..1f42a4017f1
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-4.patch
@@ -0,0 +1,46 @@
+From c4fc1bf2fd7fe6bebf72d32385bc2bd20d144093 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Mon, 18 May 2026 15:45:15 +0300
+Subject: [PATCH 4/5] AP MLD: Verify AP MLD link ID validity before updating
+ bitmap of links
+
+Link ID is 0..14, so ignore value 15 if an invalid frame is processed.
+It does not look like the invalid value was actually used to reference
+any local array, but in any case, it is better to not mark an invalid
+link as being specified.
+
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=ce1a8612e309fe86133ecf05ffb452b0bdf3b035]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ src/ap/beacon.c | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/src/ap/beacon.c b/src/ap/beacon.c
+index cec0c9829fd9..cc295c18f61b 100644
+--- a/src/ap/beacon.c
++++ b/src/ap/beacon.c
+@@ -1305,6 +1305,7 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ for_each_element_id(sub, 0, pos, len) {
+ const struct ieee80211_eht_per_sta_profile *sta;
+ u16 sta_control;
++ u8 link_id;
+
+ if (*links == 0xffff)
+ *links = 0;
+@@ -1324,7 +1325,9 @@ static bool parse_ml_probe_req(const struct ieee80211_eht_ml *ml, size_t ml_len,
+ * partial profile was requested.
+ */
+ sta_control = le_to_host16(sta->sta_control);
+- *links |= BIT(sta_control & EHT_PER_STA_CTRL_LINK_ID_MSK);
++ link_id = sta_control & BASIC_MLE_STA_CTRL_LINK_ID_MASK;
++ if (link_id < MAX_NUM_MLD_LINKS)
++ *links |= BIT(link_id);
+ }
+
+ if (!for_each_element_completed(sub, pos, len)) {
+--
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
new file mode 100644
index 00000000000..34a0c0af3ba
--- /dev/null
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant/CVE-2026-58374-5.patch
@@ -0,0 +1,47 @@
+From dad0d98570e3615b441d1c1e72e2945483a6fe77 Mon Sep 17 00:00:00 2001
+From: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+Date: Tue, 31 Mar 2026 17:47:03 +0300
+Subject: [PATCH 5/5] MLD: Fix length check in common info for association
+ failure cases
+
+It is not sufficient to check that the indicated common info length is
+sufficiently large to contain the information; there needs to be a check
+for the indicated value to not be too large to go beyond the end of the
+MLE as well. Without this, invalid MLE might result in ml_len wrapping
+around to a huge value and reading beyond the end of the buffer for the
+received frame. This could result in process termination.
+
+Add the missed check for the Common Info field not being truncated in
+the MLE in association failure cases.
+
+Fixes: a58a0c592e20 ("MLD: Fix Multi-Link element parsing for association failures")
+Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
+
+CVE: CVE-2026-58374
+Upstream-Status: Backport [https://git.w1.fi/cgit/hostap/commit/?id=41c86a2ebed50567c73de23c102c2bf83eb883f2]
+Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
+---
+ wpa_supplicant/events.c | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c
+index 600718d8efc4..d81578438588 100644
+--- a/wpa_supplicant/events.c
++++ b/wpa_supplicant/events.c
+@@ -3852,6 +3852,13 @@ static unsigned int wpas_ml_parse_assoc(struct wpa_supplicant *wpa_s,
+ goto out;
+ }
+
++ if (sizeof(*ml) + common_info->len > ml_len) {
++ wpa_printf(MSG_DEBUG,
++ "MLD: Truncated common info (common_info->len=%u ml_len=%zu)",
++ common_info->len, ml_len);
++ goto out;
++ }
++
+ wpa_printf(MSG_DEBUG, "MLD: address: " MACSTR,
+ MAC2STR(common_info->mld_addr));
+
+--
+2.43.0
+
diff --git a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
index 7c7a8bd9c13..7d1f9ffc6d6 100644
--- a/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
+++ b/meta/recipes-connectivity/wpa-supplicant/wpa-supplicant_2.11.bb
@@ -21,6 +21,11 @@ SRC_URI = "http://w1.fi/releases/wpa_supplicant-${PV}.tar.gz \
file://0004-defconfig-Uncomment-CONFIG_IEEE80211BE-y.patch \
file://CVE-2025-24912-01.patch \
file://CVE-2025-24912-02.patch \
+ file://CVE-2026-58374-1.patch \
+ file://CVE-2026-58374-2.patch \
+ file://CVE-2026-58374-3.patch \
+ file://CVE-2026-58374-4.patch \
+ file://CVE-2026-58374-5.patch \
"
SRC_URI[sha256sum] = "912ea06f74e30a8e36fbb68064d6cdff218d8d591db0fc5d75dee6c81ac7fc0a"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 32/38] curl: patch CVE-2026-11352
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (30 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
` (5 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
[1] https://curl.se/docs/CVE-2026-11352.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-11352.patch | 48 +++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 49 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11352.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-11352.patch b/meta/recipes-support/curl/curl/CVE-2026-11352.patch
new file mode 100644
index 00000000000..df414b9112b
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-11352.patch
@@ -0,0 +1,48 @@
+From 56eca2afb4806f1032872fa97d1834b3c1385276 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Fri, 5 Jun 2026 08:34:46 +0200
+Subject: [PATCH] quic: count zero length packets against max
+
+With a flood of zero lenght UDP packets to curl, the receive loop might
+run longer than intended to. Count such packets against the max to
+terminate the loop as intended.
+
+URL: https://hackerone.com/reports/3783438
+Reported-by: vectorqueue on hackerone
+Closes #21869
+
+CVE: CVE-2026-11352
+Upstream-Status: Backport [https://github.com/curl/curl/commit/56eca2afb4806f1032872fa97d1834b3c1385276]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/vquic/vquic.c | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/lib/vquic/vquic.c b/lib/vquic/vquic.c
+index 2f0e072951..475f18e04a 100644
+--- a/lib/vquic/vquic.c
++++ b/lib/vquic/vquic.c
+@@ -454,8 +454,10 @@ static CURLcode recvmmsg_packets(struct Curl_cfilter *cf,
+ VERBOSE(++calls);
+ for(i = 0; i < mcount; ++i) {
+ /* A zero-length UDP packet is no QUIC packet. Ignore. */
+- if(!mmsg[i].msg_len)
++ if(!mmsg[i].msg_len) {
++ ++pkts;
+ continue;
++ }
+ total_nread += mmsg[i].msg_len;
+
+ gso_size = vquic_msghdr_get_udp_gro(&mmsg[i].msg_hdr);
+@@ -538,8 +540,10 @@ static CURLcode recvmsg_packets(struct Curl_cfilter *cf,
+ ++calls;
+
+ /* A 0-length UDP packet is no QUIC packet */
+- if(!nread)
++ if(!nread) {
++ ++pkts;
+ continue;
++ }
+
+ gso_size = vquic_msghdr_get_udp_gro(&msg);
+ if(gso_size == 0)
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 7497337cb95..6c9801f8792 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -27,6 +27,7 @@ SRC_URI = " \
file://CVE-2026-8927.patch \
file://CVE-2026-8932-dependent.patch \
file://CVE-2026-8932.patch \
+ file://CVE-2026-11352.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 33/38] curl: patch CVE-2026-11586
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (31 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
` (4 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch per [1].
Resolve fuzz caused by having additional tests in new version.
[1] https://curl.se/docs/CVE-2026-11586.html
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../curl/curl/CVE-2026-11586.patch | 203 ++++++++++++++++++
meta/recipes-support/curl/curl_8.19.0.bb | 1 +
2 files changed, 204 insertions(+)
create mode 100644 meta/recipes-support/curl/curl/CVE-2026-11586.patch
diff --git a/meta/recipes-support/curl/curl/CVE-2026-11586.patch b/meta/recipes-support/curl/curl/CVE-2026-11586.patch
new file mode 100644
index 00000000000..3444166b326
--- /dev/null
+++ b/meta/recipes-support/curl/curl/CVE-2026-11586.patch
@@ -0,0 +1,203 @@
+From 849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 Mon Sep 17 00:00:00 2001
+From: Stefan Eissing <stefan@eissing.org>
+Date: Mon, 8 Jun 2026 16:57:01 +0200
+Subject: [PATCH] ws: make pong sending lazy
+
+Do not send PONG frames unless there is sufficient space left in the
+websocket send buffer. A server might be lazy in reading our data and
+intermediary PONG frames can be skipped by a client (RFC 6455, ch.
+5.5.3).
+
+Add test case measuring no real RSS increase on a server blasting with
+PING frames.
+
+Closes #21911
+
+CVE: CVE-2026-11586
+Upstream-Status: Backport [https://github.com/curl/curl/commit/849317ff5c5a5e13f50ec3d001e46ddffa77d8a4]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/ws.c | 33 +++++++++-----
+ tests/http/test_20_websockets.py | 78 ++++++++++++++++++++++++++++++++
+ 2 files changed, 99 insertions(+), 12 deletions(-)
+
+diff --git a/lib/ws.c b/lib/ws.c
+index d7840f1ffb..d00891b83f 100644
+--- a/lib/ws.c
++++ b/lib/ws.c
+@@ -632,6 +632,7 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data,
+ size_t plen,
+ unsigned int frame_type)
+ {
++ (void)data;
+ DEBUGASSERT(plen <= WS_MAX_CNTRL_LEN);
+ if(plen > WS_MAX_CNTRL_LEN)
+ return CURLE_BAD_FUNCTION_ARGUMENT;
+@@ -641,13 +642,6 @@ static CURLcode ws_enc_add_cntrl(struct Curl_easy *data,
+ ws->pending.type = frame_type;
+ ws->pending.payload_len = plen;
+ memcpy(ws->pending.payload, payload, plen);
+-
+- if(!ws->enc.payload_remain) { /* not in the middle of another frame */
+- CURLcode result = ws_enc_add_pending(data, ws);
+- if(!result)
+- (void)ws_flush(data, ws, Curl_is_in_callback(data));
+- return result;
+- }
+ return CURLE_OK;
+ }
+
+@@ -716,7 +710,7 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+ {
+ struct ws_cw_ctx *ctx = writer->ctx;
+ struct websocket *ws;
+- CURLcode result;
++ CURLcode result = CURLE_OK;
+
+ CURL_TRC_WRITE(data, "ws_cw_write(len=%zu, type=%d)", nbytes, type);
+ if(!(type & CLIENTWRITE_BODY) || data->set.ws_raw_mode)
+@@ -749,7 +743,8 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+ if(result == CURLE_AGAIN) {
+ /* insufficient amount of data, keep it for later.
+ * we pretend to have written all since we have a copy */
+- return CURLE_OK;
++ result = CURLE_OK;
++ goto out;
+ }
+ else if(result) {
+ failf(data, "[WS] decode payload error %d", (int)result);
+@@ -760,10 +755,16 @@ static CURLcode ws_cw_write(struct Curl_easy *data,
+ if((type & CLIENTWRITE_EOS) && !Curl_bufq_is_empty(&ctx->buf)) {
+ failf(data, "[WS] decode ending with %zd frame bytes remaining",
+ Curl_bufq_len(&ctx->buf));
+- return CURLE_RECV_ERROR;
++ result = CURLE_RECV_ERROR;
+ }
+
+- return CURLE_OK;
++out:
++ if(!result) {
++ result = ws_flush(data, ws, Curl_is_in_callback(data));
++ if(result == CURLE_AGAIN)
++ result = CURLE_OK;
++ }
++ return result;
+ }
+
+ /* WebSocket payload decoding client writer. */
+@@ -1627,8 +1628,16 @@ CURLcode curl_ws_recv(CURL *d, void *buffer,
+ static CURLcode ws_flush(struct Curl_easy *data, struct websocket *ws,
+ bool blocking)
+ {
++ CURLcode result;
++
++ /* If there is space, add any pending control frame */
++ if(Curl_bufq_len(&ws->sendbuf) < ws->sendbuf.chunk_size) {
++ result = ws_enc_add_pending(data, ws);
++ if(result && (result != CURLE_AGAIN))
++ return result;
++ }
++
+ if(!Curl_bufq_is_empty(&ws->sendbuf)) {
+- CURLcode result;
+ const uint8_t *out;
+ size_t outlen, n;
+ #ifdef DEBUGBUILD
+diff --git a/tests/http/test_20_websockets.py b/tests/http/test_20_websockets.py
+index 3a55d41b2b..00fc394a3b 100644
+--- a/tests/http/test_20_websockets.py
++++ b/tests/http/test_20_websockets.py
+@@ -24,11 +24,15 @@
+ #
+ ###########################################################################
+ #
++import base64
++import hashlib
+ import logging
+ import os
++import re
+ import shutil
+ import socket
+ import subprocess
++import threading
+ import time
+ from datetime import datetime, timedelta
+ from typing import Dict
+@@ -207,3 +211,77 @@ class TestWebsockets:
+ large = 0
+ r = client.run(args=[f'-{model}', '-c', str(count), '-m', str(large), url])
+ r.check_exit_code(0)
++
++ def test_20_11_crazy_pings(self, env: Env):
++ st = {}
++ send_rounds = 1
++
++ def srv():
++ try:
++ with socket.socket() as s:
++ s.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
++ s.bind(("127.0.0.1", 0))
++ s.listen(1)
++ st["p"] = s.getsockname()[1]
++
++ c, _ = s.accept()
++ c.setsockopt(socket.SOL_SOCKET, socket.SO_RCVBUF, 4096)
++ c.settimeout(Env.SERVER_TIMEOUT)
++ req = b""
++ while b"\r\n\r\n" not in req:
++ req += c.recv(4096)
++
++ k = re.search(rb"(?im)^Sec-WebSocket-Key:\s*(\S+)", req).group(1)
++ a = base64.b64encode(
++ hashlib.sha1(k + b"258EAFA5-E914-47DA-95CA-C5AB0DC85B11").digest()
++ ).decode()
++ c.sendall(
++ (
++ "HTTP/1.1 101 Switching Protocols\r\n"
++ "Upgrade: websocket\r\n"
++ "Connection: Upgrade\r\n"
++ f"Sec-WebSocket-Accept: {a}\r\n\r\n"
++ ).encode()
++ )
++
++ f = b"\x89\x00" * 65536 # PING frames, many
++ try:
++ for _ in range(send_rounds):
++ c.sendall(f)
++ f = b"\x88\x00" # CLOSE frame
++ c.sendall(f)
++ except OSError:
++ pass
++ time.sleep(1)
++ c.close()
++ except OSError as e:
++ st["err"] = e
++
++ curl = CurlClient(env=env)
++ send_rounds = 2
++ threading.Thread(target=srv, daemon=True).start()
++ while "p" not in st and "err" not in st:
++ time.sleep(0.01)
++ assert "err" not in st, f'ws-ping server failed to start: {st["err"]}'
++
++ url = f'ws://127.0.0.1:{st["p"]}/'
++ r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True,
++ with_profile=True)
++ assert r.exit_code in [55, 56], f'{r.dump_logs()}' # SEND/RECV_ERROR
++ assert r.profile, f'{r}'
++ rss1 = r.profile.stats['rss'] / (1024 * 1024)
++
++ st.clear()
++ send_rounds = 10
++ threading.Thread(target=srv, daemon=True).start()
++ while "p" not in st and "err" not in st:
++ time.sleep(0.01)
++ assert "err" not in st, f'ws-ping server failed to start: {st["err"]}'
++
++ url = f'ws://127.0.0.1:{st["p"]}/'
++ r = curl.http_download(urls=[url], alpn_proto='http/1.1', with_stats=True,
++ with_profile=True)
++ assert r.exit_code in [55, 56], f'{r.dump_logs()}' # SEND/RECV_ERROR
++ assert r.profile, f'{r}'
++ rss2 = r.profile.stats['rss'] / (1024 * 1024)
++ assert (rss1 * 1.1) >= rss2, 'bad memory increase'
diff --git a/meta/recipes-support/curl/curl_8.19.0.bb b/meta/recipes-support/curl/curl_8.19.0.bb
index 6c9801f8792..a964868d872 100644
--- a/meta/recipes-support/curl/curl_8.19.0.bb
+++ b/meta/recipes-support/curl/curl_8.19.0.bb
@@ -28,6 +28,7 @@ SRC_URI = " \
file://CVE-2026-8932-dependent.patch \
file://CVE-2026-8932.patch \
file://CVE-2026-11352.patch \
+ file://CVE-2026-11586.patch \
"
SRC_URI:append:class-nativesdk = " \
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (32 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
` (3 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Backport patch to fix CVE-2026-33845.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-33845
Upstream fix:
https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../gnutls/gnutls/CVE-2026-33845.patch | 166 ++++++++++++++++++
meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 +
2 files changed, 167 insertions(+)
create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
new file mode 100644
index 00000000000..004d3082c5a
--- /dev/null
+++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-33845.patch
@@ -0,0 +1,166 @@
+From 490bfb28002fc0253010243ac387c756014c06e5 Mon Sep 17 00:00:00 2001
+From: Alexander Sosedkin <asosedkin@redhat.com>
+Date: Mon, 23 Mar 2026 15:09:43 +0100
+Subject: [PATCH] buffers: switch from end_offset over to frag_length
+
+Instead of maintaining an inclusive [start_offset, end_offset] range
+when reassembling DTLS handshake,
+track start_offset and a relative frag_length instead.
+
+You'd think it'd be a no-op, but it fixes:
+
+* 0-length fragments triggering completion if message was 1 byte long
+* a remotely triggerable underflow and an ensuing heap overrun
+
+Reported-by: Joshua Rogers of AISLE Research Team <joshua@joshua.hu>
+Fixes: #1811
+Fixes: CVE-2026-33845
+Fixes: GNUTLS-SA-2026-04-29-3
+CVSS: 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
+Signed-off-by: Alexander Sosedkin <asosedkin@redhat.com>
+
+CVE: CVE-2026-33845
+Upstream-Status: Backport [https://gitlab.com/gnutls/gnutls/-/commit/e5b72c53c7d789d19d1d1cd10b275e87d0415413]
+Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
+---
+ lib/buffers.c | 50 +++++++++++++++++++++++++-----------------------
+ lib/gnutls_int.h | 4 ++--
+ 2 files changed, 28 insertions(+), 26 deletions(-)
+
+diff --git a/lib/buffers.c b/lib/buffers.c
+index 09779a8f3..02cc222c4 100644
+--- a/lib/buffers.c
++++ b/lib/buffers.c
+@@ -919,10 +919,7 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel,
+ }
+ data_size = _mbuffer_get_udata_size(bufel) - handshake_header_size;
+
+- if (frag_size > 0)
+- hsk->end_offset = hsk->start_offset + frag_size - 1;
+- else
+- hsk->end_offset = 0;
++ hsk->frag_length = frag_size;
+
+ _gnutls_handshake_log(
+ "HSK[%p]: %s (%u) was received. Length %d[%d], frag offset %d, frag length: %d, sequence: %d\n",
+@@ -936,9 +933,10 @@ static int parse_handshake_header(gnutls_session_t session, mbuffer_st *bufel,
+
+ if (hsk->length > 0 &&
+ (frag_size > data_size ||
+- (frag_size > 0 && hsk->end_offset >= hsk->length))) {
++ (frag_size > 0 && hsk->start_offset + frag_size > hsk->length))) {
+ return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH);
+- } else if (hsk->length == 0 && hsk->end_offset != 0 &&
++ } else if (hsk->length == 0 &&
++ hsk->start_offset + frag_size != hsk->start_offset &&
+ hsk->start_offset != 0)
+ return gnutls_assert_val(GNUTLS_E_UNEXPECTED_PACKET_LENGTH);
+
+@@ -1002,11 +1000,10 @@ static int merge_handshake_packet(gnutls_session_t session,
+ hsk->data.length = hsk->length;
+ }
+
+- if (hsk->length > 0 && hsk->end_offset > 0 &&
+- hsk->end_offset - hsk->start_offset + 1 != hsk->length) {
++ if (hsk->length > 0 && hsk->frag_length > 0 &&
++ hsk->frag_length != hsk->length) {
+ memmove(&hsk->data.data[hsk->start_offset],
+- hsk->data.data,
+- hsk->end_offset - hsk->start_offset + 1);
++ hsk->data.data, hsk->frag_length);
+ }
+
+ session->internals.handshake_recv_buffer_size++;
+@@ -1040,20 +1037,27 @@ static int merge_handshake_packet(gnutls_session_t session,
+ }
+
+ if (hsk->start_offset < recv_buf[pos].start_offset &&
+- hsk->end_offset + 1 >= recv_buf[pos].start_offset) {
++ hsk->start_offset + hsk->frag_length >=
++ recv_buf[pos].start_offset) {
+ memcpy(&recv_buf[pos].data.data[hsk->start_offset],
+ hsk->data.data, hsk->data.length);
+ recv_buf[pos].start_offset = hsk->start_offset;
+- recv_buf[pos].end_offset =
+- MIN(hsk->end_offset, recv_buf[pos].end_offset);
+- } else if (hsk->end_offset > recv_buf[pos].end_offset &&
+- hsk->start_offset <= recv_buf[pos].end_offset + 1) {
++ recv_buf[pos].frag_length = MIN(
++ hsk->frag_length, recv_buf[pos].frag_length);
++ } else if (hsk->start_offset + hsk->frag_length >
++ recv_buf[pos].start_offset +
++ recv_buf[pos].frag_length &&
++ hsk->start_offset <=
++ recv_buf[pos].start_offset +
++ recv_buf[pos].frag_length) {
+ memcpy(&recv_buf[pos].data.data[hsk->start_offset],
+ hsk->data.data, hsk->data.length);
+
+- recv_buf[pos].end_offset = hsk->end_offset;
+ recv_buf[pos].start_offset = MIN(
+ hsk->start_offset, recv_buf[pos].start_offset);
++ recv_buf[pos].frag_length = hsk->start_offset +
++ hsk->frag_length -
++ recv_buf[pos].start_offset;
+ }
+ _gnutls_handshake_buffer_clear(hsk);
+ }
+@@ -1113,8 +1117,8 @@ static int get_last_packet(gnutls_session_t session,
+ }
+
+ else if ((recv_buf[LAST_ELEMENT].start_offset == 0 &&
+- recv_buf[LAST_ELEMENT].end_offset ==
+- recv_buf[LAST_ELEMENT].length - 1) ||
++ recv_buf[LAST_ELEMENT].frag_length ==
++ recv_buf[LAST_ELEMENT].length) ||
+ recv_buf[LAST_ELEMENT].length == 0) {
+ session->internals.dtls.hsk_read_seq++;
+ _gnutls_handshake_buffer_move(hsk,
+@@ -1125,8 +1129,9 @@ static int get_last_packet(gnutls_session_t session,
+ /* if we don't have a complete handshake message, but we
+ * have queued data waiting, try again to reconstruct the
+ * handshake packet, using the queued */
+- if (recv_buf[LAST_ELEMENT].end_offset !=
+- recv_buf[LAST_ELEMENT].length - 1 &&
++ if ((recv_buf[LAST_ELEMENT].start_offset +
++ recv_buf[LAST_ELEMENT].frag_length) !=
++ recv_buf[LAST_ELEMENT].length &&
+ record_check_unprocessed(session) > 0)
+ return gnutls_assert_val(
+ GNUTLS_E_INT_CHECK_AGAIN);
+@@ -1313,9 +1318,7 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session)
+ &session->internals.record_buffer,
+ bufel, ret);
+
+- data_size = MIN(tmp.length,
+- tmp.end_offset -
+- tmp.start_offset + 1);
++ data_size = MIN(tmp.length, tmp.frag_length);
+
+ ret = _gnutls_buffer_append_data(
+ &tmp.data,
+@@ -1331,7 +1334,6 @@ int _gnutls_parse_record_buffered_msgs(gnutls_session_t session)
+ ret = merge_handshake_packet(session, &tmp);
+ if (ret < 0)
+ return gnutls_assert_val(ret);
+-
+ } while (_mbuffer_get_udata_size(bufel) > 0);
+
+ prev = bufel;
+diff --git a/lib/gnutls_int.h b/lib/gnutls_int.h
+index 54d3c9f67..283f25c07 100644
+--- a/lib/gnutls_int.h
++++ b/lib/gnutls_int.h
+@@ -479,10 +479,10 @@ typedef struct {
+ uint16_t sequence;
+
+ /* indicate whether that message is complete.
+- * complete means start_offset == 0 and end_offset == length
++ * complete means start_offset == 0 and frag_length == length
+ */
+ uint32_t start_offset;
+- uint32_t end_offset;
++ uint32_t frag_length; /* used exclusively in DTLS reassembly */
+
+ uint8_t header[MAX_HANDSHAKE_HEADER_SIZE];
+ int header_size;
diff --git a/meta/recipes-support/gnutls/gnutls_3.8.12.bb b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
index 51ef394dfcf..d513752072c 100644
--- a/meta/recipes-support/gnutls/gnutls_3.8.12.bb
+++ b/meta/recipes-support/gnutls/gnutls_3.8.12.bb
@@ -40,6 +40,7 @@ SRC_URI = "https://www.gnupg.org/ftp/gcrypt/gnutls/v${SHRT_VER}/gnutls-${PV}.tar
file://CVE-2026-42011_p1.patch \
file://CVE-2026-42011_p2.patch \
file://CVE-2026-42010.patch \
+ file://CVE-2026-33845.patch \
"
SRC_URI[sha256sum] = "a7b341421bfd459acf7a374ca4af3b9e06608dcd7bd792b2bf470bea012b8e51"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (33 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
` (2 subsequent siblings)
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/cve-2026-57433
[2] https://security-tracker.debian.org/tracker/CVE-2026-57433
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../perl/files/CVE-2026-57433.patch | 32 +++++++++++++++++++
meta/recipes-devtools/perl/perl_5.42.0.bb | 1 +
2 files changed, 33 insertions(+)
create mode 100644 meta/recipes-devtools/perl/files/CVE-2026-57433.patch
diff --git a/meta/recipes-devtools/perl/files/CVE-2026-57433.patch b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch
new file mode 100644
index 00000000000..f0ea08b1fe0
--- /dev/null
+++ b/meta/recipes-devtools/perl/files/CVE-2026-57433.patch
@@ -0,0 +1,32 @@
+From e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 Mon Sep 17 00:00:00 2001
+From: "Paul \"LeoNerd\" Evans" <leonerd@leonerd.org.uk>
+Date: Sat, 9 May 2026 16:47:14 +0100
+Subject: [PATCH] Storable.xs: Avoid signed int overflow when unpacking a list
+ of hook data items
+
+Upstream-Status: Backport [https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7]
+CVE: CVE-2026-57433
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ dist/Storable/Storable.xs | 5 ++++-
+ 1 file changed, 4 insertions(+), 1 deletion(-)
+
+diff --git a/dist/Storable/Storable.xs b/dist/Storable/Storable.xs
+index 3930db6..62a1a6d 100644
+--- a/dist/Storable/Storable.xs
++++ b/dist/Storable/Storable.xs
+@@ -5035,7 +5035,10 @@ static SV *retrieve_hook_common(pTHX_ stcxt_t *cxt, const char *cname, int large
+ }
+ else
+ GETMARK(len3);
+- if (len3) {
++ if (len3 == I32_MAX)
++ /* If len3 is exactly I32_MAX it will upset av_extend below */
++ CROAK(("Invalid count of hook data items"));
++ else if (len3) {
+ av = newAV();
+ av_extend(av, len3 + 1); /* Leave room for [0] */
+ AvFILLp(av) = len3; /* About to be filled anyway */
+--
+2.43.0
+
diff --git a/meta/recipes-devtools/perl/perl_5.42.0.bb b/meta/recipes-devtools/perl/perl_5.42.0.bb
index 3469258f727..6f0092c1cc7 100644
--- a/meta/recipes-devtools/perl/perl_5.42.0.bb
+++ b/meta/recipes-devtools/perl/perl_5.42.0.bb
@@ -22,6 +22,7 @@ SRC_URI = "https://www.cpan.org/src/5.0/perl-${PV}.tar.gz;name=perl \
file://CVE-2026-57432-01.patch \
file://CVE-2026-57432-02.patch \
file://CVE-2026-42496.patch \
+ file://CVE-2026-57433.patch \
"
SRC_URI:append:class-native = " \
file://perl-configpm-switch.patch \
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (34 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch applies the upstream fix as referenced in [2],
using the commit shown in [1].
It also includes the upstream follow-up in [3],
which preserves 64-bit wgint parsing on 32-bit targets.
[1] https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-58470
[3] https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 9b2b418a1546ae4bd6d044474765fa817e9a95f8)
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../wget/wget/CVE-2026-58470-regression.patch | 48 +++++++++++
.../wget/wget/CVE-2026-58470.patch | 79 +++++++++++++++++++
meta/recipes-extended/wget/wget_1.25.0.bb | 2 +
3 files changed, 129 insertions(+)
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
create mode 100644 meta/recipes-extended/wget/wget/CVE-2026-58470.patch
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
new file mode 100644
index 00000000000..c452261a9ac
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58470-regression.patch
@@ -0,0 +1,48 @@
+From 01ff771caac1958662ca8665eed2021ec386a7af Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Wed, 12 Aug 2026 19:45:21 +0200
+Subject: [PATCH] * src/http.c (parse_content_range): Use strtoll instead of
+ strtol.
+
+CVE: CVE-2026-58470
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/01ff771caac1958662ca8665eed2021ec386a7af]
+
+(cherry picked from commit 01ff771caac1958662ca8665eed2021ec386a7af)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/http.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/src/http.c b/src/http.c
+index e5e75ee695..8170a43c27 100644
+--- a/src/http.c
++++ b/src/http.c
+@@ -949,7 +949,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ return false;
+
+ errno = 0;
+- num = strtol(hdr, &end, 10);
++ num = strtoll(hdr, &end, 10);
+ if (errno == ERANGE)
+ return false;
+ hdr = end;
+@@ -959,7 +959,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ *first_byte_ptr = num;
+
+ errno = 0;
+- num = strtol(hdr, &end, 10);
++ num = strtoll(hdr, &end, 10);
+ if (errno == ERANGE)
+ return false;
+ hdr = end;
+@@ -976,7 +976,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ else
+ {
+ errno = 0;
+- num = strtol(hdr, NULL, 10);
++ num = strtoll(hdr, NULL, 10);
+ if (errno == ERANGE)
+ return false;
+ }
+--
+2.35.6
diff --git a/meta/recipes-extended/wget/wget/CVE-2026-58470.patch b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
new file mode 100644
index 00000000000..5d864c5fda6
--- /dev/null
+++ b/meta/recipes-extended/wget/wget/CVE-2026-58470.patch
@@ -0,0 +1,79 @@
+From 8740efcdd0d9e7eb04122f63bdb151f1f4d94af8 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
+Date: Mon, 29 Jun 2026 18:57:54 +0200
+Subject: [PATCH] * src/http.c (parse_content_range): Fix integer overflow
+
+Reported-by: TristanInSec@gmail.com
+
+CVE: CVE-2026-58470
+Upstream-Status: Backport [https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf]
+
+(cherry picked from commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/http.c | 35 ++++++++++++++++++++++++-----------
+ 1 file changed, 24 insertions(+), 11 deletions(-)
+
+diff --git a/src/http.c b/src/http.c
+index 07af1867..ea2e591b 100644
+--- a/src/http.c
++++ b/src/http.c
+@@ -914,6 +914,7 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ wgint *last_byte_ptr, wgint *entity_length_ptr)
+ {
+ wgint num;
++ char *end;
+
+ /* Ancient versions of Netscape proxy server, presumably predating
+ rfc2068, sent out `Content-Range' without the "bytes"
+@@ -932,27 +933,39 @@ parse_content_range (const char *hdr, wgint *first_byte_ptr,
+ }
+ if (!c_isdigit (*hdr))
+ return false;
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
+- if (*hdr != '-' || !c_isdigit (*(hdr + 1)))
++
++ errno = 0;
++ num = strtol(hdr, &end, 10);
++ if (errno == ERANGE)
++ return false;
++ hdr = end;
++
++ if (*hdr++ != '-' || !c_isdigit (*hdr))
+ return false;
+ *first_byte_ptr = num;
+- ++hdr;
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
+- if (*hdr != '/')
++
++ errno = 0;
++ num = strtol(hdr, &end, 10);
++ if (errno == ERANGE)
++ return false;
++ hdr = end;
++
++ if (*hdr++ != '/')
+ return false;
+ *last_byte_ptr = num;
+- if (!(c_isdigit (*(hdr + 1)) || *(hdr + 1) == '*'))
++ if (!(c_isdigit (*hdr) || *hdr == '*'))
+ return false;
+ if (*last_byte_ptr < *first_byte_ptr)
+ return false;
+- ++hdr;
+ if (*hdr == '*')
+ num = -1;
+ else
+- for (num = 0; c_isdigit (*hdr); hdr++)
+- num = 10 * num + (*hdr - '0');
++ {
++ errno = 0;
++ num = strtol(hdr, NULL, 10);
++ if (errno == ERANGE)
++ return false;
++ }
+ *entity_length_ptr = num;
+ if ((*entity_length_ptr <= *last_byte_ptr) && *entity_length_ptr != -1)
+ return false;
diff --git a/meta/recipes-extended/wget/wget_1.25.0.bb b/meta/recipes-extended/wget/wget_1.25.0.bb
index 95845d695a9..26f5c84e5a7 100644
--- a/meta/recipes-extended/wget/wget_1.25.0.bb
+++ b/meta/recipes-extended/wget/wget_1.25.0.bb
@@ -22,6 +22,8 @@ SRC_URI = "${GNU_MIRROR}/wget/wget-${PV}.tar.gz \
file://CVE-2026-58472.patch \
file://CVE-2026-58472-regression.patch \
file://CVE-2026-16599.patch \
+ file://CVE-2026-58470.patch \
+ file://CVE-2026-58470-regression.patch \
"
SRC_URI[sha256sum] = "766e48423e79359ea31e41db9e5c289675947a7fcf2efdcedb726ac9d0da3784"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (35 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Hetvi Thakar <hthakar@cisco.com>
This patch backports the upstream fix for CVE-2026-8643 and the two
follow-up regression fixes. The primary commit is included in pip
26.1.2 and referenced in [1]. The public CVE advisory is referenced
in [2].
The first follow-up fixes doubled-slash directory handling and the
second reuses pip's shared directory-containment helper. The upstream
regression commits are referenced in [3] and [4].
[1] https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
[2] https://github.com/advisories/GHSA-wf93-45jw-7689
[3] https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5
[4] https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
.../CVE-2026-8643-regression_p1.patch | 35 ++++++++
.../CVE-2026-8643-regression_p2.patch | 69 ++++++++++++++++
.../python/python3-pip/CVE-2026-8643.patch | 80 +++++++++++++++++++
.../python/python3-pip_26.0.1.bb | 3 +
4 files changed, 187 insertions(+)
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
new file mode 100644
index 00000000000..e269dca667b
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p1.patch
@@ -0,0 +1,35 @@
+From 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5 Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Mon, 18 May 2026 23:22:51 -0400
+Subject: [PATCH] Fix is_within_directory for doubled-slash roots
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/7ff8bdd81ec5edca2bebf78ad8506dda710d6af5]
+
+Backport Changes:
+- Omitted tests/unit/test_utils_unpacking.py because the pip 26.0.1
+ PyPI sdist used by this recipe does not ship the upstream tests
+ directory.
+
+(cherry picked from commit 7ff8bdd81ec5edca2bebf78ad8506dda710d6af5)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/utils/unpacking.py | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py
+index 879b40c37e..ba7cb52579 100644
+--- a/src/pip/_internal/utils/unpacking.py
++++ b/src/pip/_internal/utils/unpacking.py
+@@ -83,8 +83,7 @@ def is_within_directory(directory: str, target: str) -> bool:
+ abs_directory = os.path.abspath(directory)
+ abs_target = os.path.abspath(target)
+
+- prefix = os.path.commonpath([abs_directory, abs_target])
+- return prefix == abs_directory
++ return abs_target == abs_directory or abs_target.startswith(abs_directory + os.sep)
+
+
+ def _get_default_mode_plus_executable() -> int:
+--
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
new file mode 100644
index 00000000000..bd40e3b9e8f
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643-regression_p2.patch
@@ -0,0 +1,69 @@
+From fa7854f6b37113a2c4698cdde902e1fcc9bebdd5 Mon Sep 17 00:00:00 2001
+From: Damian <damian.peter.shaw@gmail.com>
+Date: Sun, 24 May 2026 14:54:47 -0400
+Subject: [PATCH] Use is_within_directory for entry point check
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/fa7854f6b37113a2c4698cdde902e1fcc9bebdd5]
+
+Backport Changes:
+- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist
+ used by this recipe does not ship the upstream tests directory.
+
+(cherry picked from commit fa7854f6b37113a2c4698cdde902e1fcc9bebdd5)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ src/pip/_internal/operations/install/wheel.py | 18 ++++++------------
+ src/pip/_internal/utils/unpacking.py | 1 +
+ 2 files changed, 7 insertions(+), 12 deletions(-)
+
+diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py
+index 231e400658..6f9a983364 100644
+--- a/src/pip/_internal/operations/install/wheel.py
++++ b/src/pip/_internal/operations/install/wheel.py
+@@ -397,17 +397,6 @@ class MissingCallableSuffix(InstallationError):
+ )
+
+
+-def _script_within_dir(name: str, scripts_dir: str) -> bool:
+- """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
+-
+- distlib joins the entry point name onto the scripts directory, so a name
+- with path separators or ``..`` components can resolve elsewhere.
+- """
+- root = os.path.normpath(scripts_dir)
+- dest = os.path.normpath(os.path.join(scripts_dir, name))
+- return dest.startswith(root + os.sep)
+-
+-
+ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+ entry = get_export_entry(specification)
+ if entry is None:
+@@ -416,7 +405,12 @@ def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+ if entry.suffix is None:
+ raise MissingCallableSuffix(str(entry))
+
+- if not _script_within_dir(entry.name, scripts_dir):
++ # distlib joins the entry point name onto the scripts directory, so a name
++ # with path separators or ``..`` components can resolve elsewhere. The script
++ # must resolve to a path strictly inside the scripts directory.
++ dest = os.path.join(scripts_dir, entry.name)
++ resolves_to_scripts_dir = os.path.abspath(dest) == os.path.abspath(scripts_dir)
++ if resolves_to_scripts_dir or not is_within_directory(scripts_dir, dest):
+ raise InstallationError(
+ f"Invalid script entry point name {entry.name!r}: the script "
+ f"would be installed outside the scripts directory ({scripts_dir})."
+diff --git a/src/pip/_internal/utils/unpacking.py b/src/pip/_internal/utils/unpacking.py
+index ba7cb52579..8a9b2059ca 100644
+--- a/src/pip/_internal/utils/unpacking.py
++++ b/src/pip/_internal/utils/unpacking.py
+@@ -79,6 +79,7 @@ def has_leading_dir(paths: Iterable[str]) -> bool:
+ def is_within_directory(directory: str, target: str) -> bool:
+ """
+ Return true if the absolute path of target is within the directory
++ (including when target is equal to the directory).
+ """
+ abs_directory = os.path.abspath(directory)
+ abs_target = os.path.abspath(target)
+--
+2.35.6
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
new file mode 100644
index 00000000000..2f38ad0207c
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
@@ -0,0 +1,80 @@
+From 483d83c13c9d69c1916c06cab29991f6c2725cee Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Wed, 20 May 2026 15:20:25 -0400
+Subject: [PATCH] Reject entry point names that escape scripts dir (#14000)
+
+* Reject entry point names that escape scripts dir
+
+* NEWS ENTRY
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb]
+
+Backport Changes:
+- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist
+ does not ship the upstream test suite and the OE recipe does not
+ enable ptest.
+
+(cherry picked from commit 8eb178480bd1a2b223f509fc430796b265158dfb)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ news/14000.bugfix.rst | 2 ++
+ src/pip/_internal/operations/install/wheel.py | 26 ++++++++++++++++---
+ 2 files changed, 25 insertions(+), 3 deletions(-)
+ create mode 100644 news/14000.bugfix.rst
+
+diff --git a/news/14000.bugfix.rst b/news/14000.bugfix.rst
+new file mode 100644
+index 000000000..3b86f1b3b
+--- /dev/null
++++ b/news/14000.bugfix.rst
+@@ -0,0 +1,2 @@
++Reject ``console_scripts`` and ``gui_scripts`` entry points whose name would
++install a script outside the scripts directory.
+diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py
+index 40097d6a7..231e40065 100644
+--- a/src/pip/_internal/operations/install/wheel.py
++++ b/src/pip/_internal/operations/install/wheel.py
+@@ -397,11 +397,31 @@ class MissingCallableSuffix(InstallationError):
+ )
+
+
+-def _raise_for_invalid_entrypoint(specification: str) -> None:
++def _script_within_dir(name: str, scripts_dir: str) -> bool:
++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
++
++ distlib joins the entry point name onto the scripts directory, so a name
++ with path separators or ``..`` components can resolve elsewhere.
++ """
++ root = os.path.normpath(scripts_dir)
++ dest = os.path.normpath(os.path.join(scripts_dir, name))
++ return dest.startswith(root + os.sep)
++
++
++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+ entry = get_export_entry(specification)
+- if entry is not None and entry.suffix is None:
++ if entry is None:
++ return
++
++ if entry.suffix is None:
+ raise MissingCallableSuffix(str(entry))
+
++ if not _script_within_dir(entry.name, scripts_dir):
++ raise InstallationError(
++ f"Invalid script entry point name {entry.name!r}: the script "
++ f"would be installed outside the scripts directory ({scripts_dir})."
++ )
++
+
+ class PipScriptMaker(ScriptMaker):
+ # Override distlib's default script template with one that
+@@ -419,7 +439,7 @@ class PipScriptMaker(ScriptMaker):
+ def make(
+ self, specification: str, options: dict[str, Any] | None = None
+ ) -> list[str]:
+- _raise_for_invalid_entrypoint(specification)
++ _raise_for_invalid_entrypoint(specification, self.target_dir)
+ return super().make(specification, options)
+
+
diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
index 3ff6cd39cd2..b6581575580 100644
--- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
+++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
@@ -26,6 +26,9 @@ inherit pypi python_setuptools_build_meta
SRC_URI += "file://no_shebang_mangling.patch \
file://CVE-2026-13346.patch \
+ file://CVE-2026-8643.patch \
+ file://CVE-2026-8643-regression_p1.patch \
+ file://CVE-2026-8643-regression_p2.patch \
"
SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8"
^ permalink raw reply related [flat|nested] 42+ messages in thread
* [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
` (36 preceding siblings ...)
2026-09-09 7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
@ 2026-09-09 7:29 ` Yoann Congal
37 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 7:29 UTC (permalink / raw)
To: openembedded-core
From: Himani Ramesh Barde <HimaniRamesh.Barde@windriver.com>
randtest performs autocorrelation analysis on random number sequences
and fails intermittently on overloaded CI/autobuilder systems where
CPU scheduling and floating point conditions vary between runs.
An upstream fix was previously merged (ccabae3036a7) to improve sigma
threshold handling, but the test failed again on qemux86-64-musl-ptest
on 2026-07-21 with 'Tau= 162, Autocorr= 5.15181 sigma'.
The test is inherently unsuitable for shared overloaded build
infrastructure. Skip it, consistent with how 'time' and 'timeout'
are already handled.
[YOCTO #16254]
Signed-off-by: Himani Barde <HimaniRamesh.Barde@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 5266eed8f8c2096462da720093aa1556df726098)
Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
---
meta/recipes-extended/gawk/gawk_5.4.0.bb | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/meta/recipes-extended/gawk/gawk_5.4.0.bb b/meta/recipes-extended/gawk/gawk_5.4.0.bb
index f44d82b37c5..5be7efad452 100644
--- a/meta/recipes-extended/gawk/gawk_5.4.0.bb
+++ b/meta/recipes-extended/gawk/gawk_5.4.0.bb
@@ -85,7 +85,10 @@ do_install_ptest() {
# https://bugzilla.yoctoproject.org/show_bug.cgi?id=14371
rm -f ${D}${PTEST_PATH}/test/time.*
rm -f ${D}${PTEST_PATH}/test/timeout.*
- for t in time timeout; do
+ # randtest is a statistical test that intermittently fails on overloaded systems
+ # https://bugzilla.yoctoproject.org/show_bug.cgi?id=16254
+ rm -f ${D}${PTEST_PATH}/test/randtest.*
+ for t in time timeout randtest; do
echo $t >> ${D}${PTEST_PATH}/test/skipped.txt
done
}
^ permalink raw reply related [flat|nested] 42+ messages in thread
* Re: [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007
2026-09-09 7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
@ 2026-09-09 17:00 ` Yoann Congal
0 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-09 17:00 UTC (permalink / raw)
To: Yoann Congal, openembedded-core
On Wed Sep 9, 2026 at 9:29 AM CEST, Yoann Congal wrote:
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Analysis:
> - NVD identifies the vulnerable code as net/tcp.c when
> CONFIG_PROT_TCP is enabled [1].
> - tools-only_defconfig disables networking, so this code is not built
> into u-boot-tools [2].
> - Hence ignoring the CVE for this recipe.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
> [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
>
> Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
> ---
> meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> index 7eaf721ca83..0e57bb88849 100644
> --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> @@ -1,2 +1,4 @@
> require u-boot-common.inc
> require u-boot-tools.inc
> +
> +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."
Hello,
I just noticed that these CVEs are not visible from our tracking because
the CPE is "u-boot" vs the PN "u-boot-tools".
To fix this, I plan to add to this series the recent patch:
[wrynose][PATCH] u-boot: share CVE_PRODUCT with u-boot-tools - Hiago De Franco
https://lore.kernel.org/all/20260909-uboot-cve-product-wrynose-v1-1-072b994b426f@baylibre.com/
Regards,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 42+ messages in thread
* Re: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
2026-09-09 7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
@ 2026-09-10 4:42 ` Hemanth Kumar M D
2026-09-10 12:53 ` Yoann Congal
0 siblings, 1 reply; 42+ messages in thread
From: Hemanth Kumar M D @ 2026-09-10 4:42 UTC (permalink / raw)
To: openembedded-core, Yoann Congal
[-- Attachment #1: Type: text/plain, Size: 7063 bytes --]
Hi Yoann,
This CVE patch will come with the glibc 2.43 stable branch updates:
https://lists.openembedded.org/g/openembedded-core/message/245453
<https://lists.openembedded.org/g/openembedded-core/message/245453>
Please drop this patch.
On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
> CAUTION: This email comes from a non Wind River email account!
> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>
> From: Harish Sadineni<Harish.Sadineni@windriver.com>
>
> Allocate the maximum array sizes directly, instead of resizing
> the arrays as needed. This eliminates alloca usage from the
> function, and fixes the out-of-bounds accesses. The asserts
> guard against the bug coming back if the balancing of the tree
> turns out not to work correctly.
>
> Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> CVE: CVE-2026-19542
>
> Reference:
> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>
> Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> Signed-off-by: Yoann Congal<yoann.congal@smile.fr>
> [YC: fixed CVE: tag in patch]
> ---
> .../glibc/glibc/0023-CVE-2026-19542.patch | 98 +++++++++++++++++++
> meta/recipes-core/glibc/glibc_2.43.bb | 1 +
> 2 files changed, 99 insertions(+)
> create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>
> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> new file mode 100644
> index 00000000000..094a50919dc
> --- /dev/null
> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
> @@ -0,0 +1,98 @@
> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
> +From: Florian Weimer<fweimer@redhat.com>
> +Date: Fri, 14 Aug 2026 13:41:16 +0200
> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
> +
> +Allocate the maximum array sizes directly, instead of resizing
> +the arrays as needed. This eliminates alloca usage from the
> +function, and fixes the out-of-bounds accesses. The asserts
> +guard against the bug coming back if the balancing of the tree
> +turns out not to work correctly.
> +
> +CVE: CVE-2026-19542
> +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
> +
> +Reviewed-by: Adhemerval Zanella<adhemerval.zanella@linaro.org>
> +Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
> +---
> + misc/tsearch.c | 31 +++++++++++--------------------
> + 1 file changed, 11 insertions(+), 20 deletions(-)
> +
> +diff --git a/misc/tsearch.c b/misc/tsearch.c
> +index 9b2eb34b25..e517dfa712 100644
> +--- a/misc/tsearch.c
> ++++ b/misc/tsearch.c
> +@@ -85,6 +85,7 @@
> + #include <assert.h>
> + #include <stdalign.h>
> + #include <stddef.h>
> ++#include <stdint.h>
> + #include <stdlib.h>
> + #include <string.h>
> + #include <search.h>
> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> + int cmp;
> + node *rootp = (node *) vrootp;
> + node root, unchained;
> +- /* Stack of nodes so we remember the parents without recursion. It's
> +- _very_ unlikely that there are paths longer than 40 nodes. The tree
> +- would need to have around 250.000 nodes. */
> +- int stacksize = 40;
> ++ /* Stack of nodes so we remember the parents without recursion. The
> ++ stack size is a conservative approximation of the maximum height
> ++ of a red-black tree, based on size of the address space.
> ++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */
> ++ enum { stacksize = 2 * UINTPTR_WIDTH };
> + int sp = 0;
> +- node **nodestack = alloca (sizeof (node *) * stacksize);
> ++ node *nodestack[stacksize];
> +
> + if (rootp == NULL)
> + return NULL;
> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> + root = DEREFNODEPTR(rootp);
> + while ((cmp = (*compar) (key, root->key)) != 0)
> + {
> +- if (sp == stacksize)
> +- {
> +- node **newstack;
> +- stacksize += 20;
> +- newstack = alloca (sizeof (node *) * stacksize);
> +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +- }
> +-
> ++ assert (sp < stacksize);
> + nodestack[sp++] = rootp;
> + p = DEREFNODEPTR(rootp);
> + if (cmp < 0)
> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> + node upn;
> + for (;;)
> + {
> +- if (sp == stacksize)
> +- {
> +- node **newstack;
> +- stacksize += 20;
> +- newstack = alloca (sizeof (node *) * stacksize);
> +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
> +- }
> ++ assert (sp < stacksize);
> + nodestack[sp++] = parentp;
> + parentp = up;
> + upn = DEREFNODEPTR(up);
> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> + SETNODEPTR(pp,q);
> + /* Make sure pp is right if the case below tries to use
> + it. */
> ++ assert (sp < stacksize);
> + nodestack[sp++] = pp = LEFTPTR(q);
> + q = RIGHT(p);
> + }
> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
> + SETLEFT(p,RIGHT(q));
> + SETRIGHT(q,p);
> + SETNODEPTR(pp,q);
> ++ assert (sp < stacksize);
> + nodestack[sp++] = pp = RIGHTPTR(q);
> + q = LEFT(p);
> + }
> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
> index 9f3a3814d0a..3ef2301191d 100644
> --- a/meta/recipes-core/glibc/glibc_2.43.bb
> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
> @@ -55,6 +55,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
> file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
> file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
> file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
> +file://0023-CVE-2026-19542.patch \
> "
> B = "${WORKDIR}/build-${TARGET_SYS}"
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#245430):https://lists.openembedded.org/g/openembedded-core/message/245430
> Mute This Topic:https://lists.openembedded.org/mt/121158859/10244482
> Group Owner:openembedded-core+owner@lists.openembedded.org
> Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [Hemanth.KumarMD@windriver.com]
> -=-=-=-=-=-=-=-=-=-=-=-
--
Regards,
Hemanth Kumar M D
[-- Attachment #2: Type: text/html, Size: 9581 bytes --]
^ permalink raw reply [flat|nested] 42+ messages in thread
* Re: [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542
2026-09-10 4:42 ` Hemanth Kumar M D
@ 2026-09-10 12:53 ` Yoann Congal
0 siblings, 0 replies; 42+ messages in thread
From: Yoann Congal @ 2026-09-10 12:53 UTC (permalink / raw)
To: Hemanth Kumar M D, openembedded-core
On Thu Sep 10, 2026 at 6:42 AM CEST, Hemanth Kumar M D wrote:
> Hi Yoann,
>
> This CVE patch will come with the glibc 2.43 stable branch updates:
> https://lists.openembedded.org/g/openembedded-core/message/245453
> <https://lists.openembedded.org/g/openembedded-core/message/245453>
>
> Please drop this patch.
Right,
For the record, the patch fixing this CVE in this branch is:
0afa34adb0 misc: Fix out-of-bounds array write in tdelete (bug 34506)
I will drop this one before requesting a merge.
Thanks!
>
> On 09-09-2026 12:59 pm, Yoann Congal via lists.openembedded.org wrote:
>> CAUTION: This email comes from a non Wind River email account!
>> Do not click links or open attachments unless you recognize the sender and know the content is safe.
>>
>> From: Harish Sadineni<Harish.Sadineni@windriver.com>
>>
>> Allocate the maximum array sizes directly, instead of resizing
>> the arrays as needed. This eliminates alloca usage from the
>> function, and fixes the out-of-bounds accesses. The asserts
>> guard against the bug coming back if the balancing of the tree
>> turns out not to work correctly.
>>
>> Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> CVE: CVE-2026-19542
>>
>> Reference:
>> [1]https://security-tracker.debian.org/tracker/CVE-2026-19542
>> [2]https://sourceware.org/bugzilla/show_bug.cgi?id=34506
>> [3]https://sourceware.org/git/?p=glibc.git;a=commit;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3
>>
>> Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
>> Signed-off-by: Yoann Congal<yoann.congal@smile.fr>
>> [YC: fixed CVE: tag in patch]
>> ---
>> .../glibc/glibc/0023-CVE-2026-19542.patch | 98 +++++++++++++++++++
>> meta/recipes-core/glibc/glibc_2.43.bb | 1 +
>> 2 files changed, 99 insertions(+)
>> create mode 100644 meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>>
>> diff --git a/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> new file mode 100644
>> index 00000000000..094a50919dc
>> --- /dev/null
>> +++ b/meta/recipes-core/glibc/glibc/0023-CVE-2026-19542.patch
>> @@ -0,0 +1,98 @@
>> +From e2789c46e3bfdcd67a82bea9946b315c179e83d3 Mon Sep 17 00:00:00 2001
>> +From: Florian Weimer<fweimer@redhat.com>
>> +Date: Fri, 14 Aug 2026 13:41:16 +0200
>> +Subject: [PATCH] misc: Fix out-of-bounds array write in tdelete (bug 34506)
>> +
>> +Allocate the maximum array sizes directly, instead of resizing
>> +the arrays as needed. This eliminates alloca usage from the
>> +function, and fixes the out-of-bounds accesses. The asserts
>> +guard against the bug coming back if the balancing of the tree
>> +turns out not to work correctly.
>> +
>> +CVE: CVE-2026-19542
>> +Upstream-Status: Backport [https://sourceware.org/git/?p=glibc.git;a=patch;h=e2789c46e3bfdcd67a82bea9946b315c179e83d3]
>> +
>> +Reviewed-by: Adhemerval Zanella<adhemerval.zanella@linaro.org>
>> +Signed-off-by: Harish Sadineni<Harish.Sadineni@windriver.com>
>> +---
>> + misc/tsearch.c | 31 +++++++++++--------------------
>> + 1 file changed, 11 insertions(+), 20 deletions(-)
>> +
>> +diff --git a/misc/tsearch.c b/misc/tsearch.c
>> +index 9b2eb34b25..e517dfa712 100644
>> +--- a/misc/tsearch.c
>> ++++ b/misc/tsearch.c
>> +@@ -85,6 +85,7 @@
>> + #include <assert.h>
>> + #include <stdalign.h>
>> + #include <stddef.h>
>> ++#include <stdint.h>
>> + #include <stdlib.h>
>> + #include <string.h>
>> + #include <search.h>
>> +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> + int cmp;
>> + node *rootp = (node *) vrootp;
>> + node root, unchained;
>> +- /* Stack of nodes so we remember the parents without recursion. It's
>> +- _very_ unlikely that there are paths longer than 40 nodes. The tree
>> +- would need to have around 250.000 nodes. */
>> +- int stacksize = 40;
>> ++ /* Stack of nodes so we remember the parents without recursion. The
>> ++ stack size is a conservative approximation of the maximum height
>> ++ of a red-black tree, based on size of the address space.
>> ++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */
>> ++ enum { stacksize = 2 * UINTPTR_WIDTH };
>> + int sp = 0;
>> +- node **nodestack = alloca (sizeof (node *) * stacksize);
>> ++ node *nodestack[stacksize];
>> +
>> + if (rootp == NULL)
>> + return NULL;
>> +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> + root = DEREFNODEPTR(rootp);
>> + while ((cmp = (*compar) (key, root->key)) != 0)
>> + {
>> +- if (sp == stacksize)
>> +- {
>> +- node **newstack;
>> +- stacksize += 20;
>> +- newstack = alloca (sizeof (node *) * stacksize);
>> +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +- }
>> +-
>> ++ assert (sp < stacksize);
>> + nodestack[sp++] = rootp;
>> + p = DEREFNODEPTR(rootp);
>> + if (cmp < 0)
>> +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> + node upn;
>> + for (;;)
>> + {
>> +- if (sp == stacksize)
>> +- {
>> +- node **newstack;
>> +- stacksize += 20;
>> +- newstack = alloca (sizeof (node *) * stacksize);
>> +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *));
>> +- }
>> ++ assert (sp < stacksize);
>> + nodestack[sp++] = parentp;
>> + parentp = up;
>> + upn = DEREFNODEPTR(up);
>> +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> + SETNODEPTR(pp,q);
>> + /* Make sure pp is right if the case below tries to use
>> + it. */
>> ++ assert (sp < stacksize);
>> + nodestack[sp++] = pp = LEFTPTR(q);
>> + q = RIGHT(p);
>> + }
>> +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar)
>> + SETLEFT(p,RIGHT(q));
>> + SETRIGHT(q,p);
>> + SETNODEPTR(pp,q);
>> ++ assert (sp < stacksize);
>> + nodestack[sp++] = pp = RIGHTPTR(q);
>> + q = LEFT(p);
>> + }
>> diff --git a/meta/recipes-core/glibc/glibc_2.43.bb b/meta/recipes-core/glibc/glibc_2.43.bb
>> index 9f3a3814d0a..3ef2301191d 100644
>> --- a/meta/recipes-core/glibc/glibc_2.43.bb
>> +++ b/meta/recipes-core/glibc/glibc_2.43.bb
>> @@ -55,6 +55,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
>> file://0020-fix-create-thread-failed-in-unprivileged-process-BZ-.patch \
>> file://0021-tests-Skip-2-qemu-tests-that-can-hang-in-oe-selftest.patch \
>> file://0022-Propagate-ffile-prefix-map-from-CFLAGS-to-ASFLAGS.patch \
>> +file://0023-CVE-2026-19542.patch \
>> "
>> B = "${WORKDIR}/build-${TARGET_SYS}"
>>
>> -=-=-=-=-=-=-=-=-=-=-=-
>> Links: You receive all messages sent to this group.
>> View/Reply Online (#245430):https://lists.openembedded.org/g/openembedded-core/message/245430
>> Mute This Topic:https://lists.openembedded.org/mt/121158859/10244482
>> Group Owner:openembedded-core+owner@lists.openembedded.org
>> Unsubscribe:https://lists.openembedded.org/g/openembedded-core/unsub [Hemanth.KumarMD@windriver.com]
>> -=-=-=-=-=-=-=-=-=-=-=-
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 42+ messages in thread
end of thread, other threads:[~2026-09-10 12:53 UTC | newest]
Thread overview: 42+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
2026-09-10 4:42 ` Hemanth Kumar M D
2026-09-10 12:53 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
2026-09-09 17:00 ` Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-09 7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.