patches.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
* [PATCH 6.1 00/79] 6.1.185-rc1 review
@ 2026-08-25 13:25 Greg Kroah-Hartman
  2026-08-25 13:25 ` [PATCH 6.1 01/79] PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems Greg Kroah-Hartman
                   ` (86 more replies)
  0 siblings, 87 replies; 88+ messages in thread
From: Greg Kroah-Hartman @ 2026-08-25 13:25 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
	shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

This is the start of the stable review cycle for the 6.1.185 release.
There are 79 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Thu, 27 Aug 2026 13:25:02 +0000.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.1.185-rc1.gz
or in the git tree and branch at:
	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.1.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 6.1.185-rc1

Chengfeng Ye <nicoyip.dev@gmail.com>
    Bluetooth: hci_event: fix LE list UAF on reset

Michael Bommarito <michael.bommarito@gmail.com>
    HID: hyperv: validate initial device info bounds

Haoxiang Li <haoxiang_li2024@163.com>
    HID: sensor: custom: Fix use-after-free in enable_sensor

Jann Horn <jannh@google.com>
    HID: core: fix number/pointer type confusion on long items

Ibrahim Hashimov <security@auditcode.ai>
    HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()

Sukrut Bellary <sukrut.bellary@linux.com>
    misc: fastrpc: Fix double free of 'buf' in error path

Oliver Hartkopp <socketcan@hartkopp.net>
    can: isotp: fix timer drain order, wakeup handling and tx_gen ordering

Oliver Hartkopp <socketcan@hartkopp.net>
    can: use skb hash instead of private variable in headroom

Donglin Lyu <DongLin_Lyu@outlook.com>
    Input: atkbd - skip deactivate for HONOR ZQC-P

Cryolitia PukNgae <cryolitia.pukngae@linux.dev>
    Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard

Eric Farman <farman@linux.ibm.com>
    s390/vfio_ccw: Free all memory if cp_init() fails

Xiang Mei (Microsoft) <xmei5@asu.edu>
    xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

Baul Lee <baul.lee@xbow.com>
    HID: core: fix OOB read of field->usage in hid_set_field()

Lee Jones <lee@kernel.org>
    HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID

Jose Villaseñor Montfort <pepemontfort@gmail.com>
    HID: magicmouse: do not keep a stale msc->input if no input is claimed

Qing Luo <luoqing@kylinos.cn>
    mptcp: pm: fix data race in add_addr timer callback

Matthieu Baerts (NGI0) <matttbe@kernel.org>
    mptcp: pm: ADD_ADDR rtx: free sk if last

Matthieu Baerts (NGI0) <matttbe@kernel.org>
    mptcp: pm: ADD_ADDR rtx: always decrease sk refcount

Dawid Wróbel <me@dawidwrobel.com>
    ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses

Linmao Li <lilinmao@kylinos.cn>
    Input: byd - synchronize timer deletion before freeing private data

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations

Jiang HongHui <jiang_hh2019@163.com>
    nvmet-fc: fix invalid free in LS IOD error path

Bryam Vargas <hexlabsecurity@proton.me>
    nvmet-auth: zero the AUTH_RECEIVE response buffer

Luxiao Xu <rakukuip@gmail.com>
    ipv6: fix use-after-free in ip6_finish_output2()

Yong Wang <edragain@163.com>
    ipv4: reject undersized MTUs in ip_do_fragment()

Pavitra Jha <jhapavitra98@gmail.com>
    libceph: fix OOB read in decode_watchers() via missing bounds check

Eric Dumazet <edumazet@google.com>
    ndisc: ndisc_send_redirect() cleanup

Linmao Li <lilinmao@kylinos.cn>
    nfc: nci: free destination parameters when closing a connection

Samuel Page <sam@bynar.io>
    nfc: nci: fix uninit-value in the RF discover/activated NTF handlers

Samuel Page <sam@bynar.io>
    nfc: nci: fix out-of-bounds write in nci_target_auto_activated()

Doruk Tan Ozturk <doruk@0sec.ai>
    nfc: st21nfca: validate ATR_REQ length against the received frame

Xu Rao <raoxu@uniontech.com>
    nfc: pn533: purge fragmented skbs during cleanup

Doruk Tan Ozturk <doruk@0sec.ai>
    nfc: llcp: reject PDUs shorter than the LLCP header

Muhammad Bilal <meatuni001@gmail.com>
    nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers

Doruk Tan Ozturk <doruk@0sec.ai>
    nfc: llcp: bound the connect_sn TLV walk to the skb

Pengpeng Hou <pengpeng@iscas.ac.cn>
    nfc: microread: validate target discovery payload lengths

Bryam Vargas <hexlabsecurity@proton.me>
    nfc: fdp: bound the device-reported read length and fix an skb leak

Doruk Tan Ozturk <doruk@0sec.ai>
    nfc: digital: clamp SENSF_RES length to the destination buffer

Joanne Koong <joannelkoong@gmail.com>
    iomap: adjust read range correctly for non-block-aligned positions

Jakub Kicinski <kuba@kernel.org>
    tls: handle data disappearing from under the TLS ULP

Sabrina Dubroca <sd@queasysnail.net>
    tls: fix lockless read of strp->msg_ready in ->poll

Junjie Cao <junjie.cao@intel.com>
    gpio: ml-ioh: use raw_spinlock_t for the register lock

Yang Wang <kevinyang.wang@amd.com>
    drm/amdgpu: check ASPM on the dGPU host link

Ibrahim Hashimov <security@auditcode.ai>
    xfs: bounds-check buffer log item's dirty bitmap

Christoph Hellwig <hch@lst.de>
    xfs: don't use a xfs_log_iovec for ri_buf in log recovery

Eric Farman <farman@linux.ibm.com>
    s390/vfio_ccw: Implement a crw lock

Eric Farman <farman@linux.ibm.com>
    s390/vfio_ccw: Selectively expand io_mutex

Eric Farman <farman@linux.ibm.com>
    s390/vfio_ccw: Move cp cleanup out of not operational

Junrui Luo <moonafterrain@outlook.com>
    drm/amdgpu: disallow multiple FENCE chunks in one submit

Eric Farman <farman@linux.ibm.com>
    s390/vfio_ccw: Cancel existing workqueues

Pei Xiao <xiaopei01@kylinos.cn>
    mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition

Zhiling Zou <zhilinz@nebusec.ai>
    inet: frags: publish queues before arming timer

Zihan Xi <zihanx@nebusec.ai>
    packet: synchronize pressure clearing with ring reconfiguration

Eric Dumazet <edumazet@google.com>
    net/packet: convert po->pressure to an atomic flag

Luca Fresi <luca.fresi@bithiatec.com>
    serial: sc16is7xx: enable THRI before filling TX FIFO

Hugo Villeneuve <hvilleneuve@dimonoff.com>
    serial: sc16is7xx: use guards for simple mutex locks

Hugo Villeneuve <hvilleneuve@dimonoff.com>
    serial: sc16is7xx: rename EFR mutex with generic name

Lech Perczak <lech.perczak@camlingroup.com>
    serial: sc16is7xx: convert bitmask definitions to use BIT() macro

Lech Perczak <lech.perczak@camlingroup.com>
    serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants

Qihang Tang <q.h.hack.winter@gmail.com>
    packet: use consistent hard_header_len in TX_RING send path

Qihang Tang <q.h.hack.winter@gmail.com>
    packet: use consistent hard_header_len in non-ring send paths

Aditya Chillara <aditya.chillara@oss.qualcomm.com>
    perf/core: Fix group leader use-after-free after sibling detach

Yeoreum Yun <yeoreum.yun@arm.com>
    perf: Fix dangling cgroup pointer in cpuctx

Peter Zijlstra <peterz@infradead.org>
    perf: Fix cgroup state vs ERROR

Yeoreum Yun <yeoreum.yun@arm.com>
    perf/core: Fix child_total_time_enabled accounting bug at task exit

Fan Wu <fanwu01@zju.edu.cn>
    serial: amba-pl011: synchronize DMA teardown

Koichiro Den <den@valinux.co.jp>
    NTB: ntb_netdev: Preserve RX queue depth on allocation failure

Ekansh Gupta <ekansh.gupta@oss.qualcomm.com>
    misc: fastrpc: Remove buffer from list prior to unmap operation

Abel Vesa <abel.vesa@linaro.org>
    misc: fastrpc: Rework fastrpc_req_munmap

Hongling Zeng <zenghongling@kylinos.cn>
    xfs: validate attr entry pointer before field access

Guanghui Yang <3497809730@qq.com>
    ext4: clear error before retrying inode xattr space fallback

Matthias Goergens <matthias.goergens@gmail.com>
    ext4: stop retrying saturated xattr cache entries

Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
    kcov: fix data corruption and race conditions on PREEMPT_RT

Rik van Riel <riel@surriel.com>
    null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows

Ian Bridges <icb@fastmail.org>
    ocfs2: fix missing metadata reservation for large xattrs

Takashi Iwai <tiwai@suse.de>
    ALSA: dummy: Check card index validity at probe

Griffin Kroah-Hartman <griffin@kroah.com>
    rndis_host: add overflow check in rndis_rx_fixup()

Ali Ahmet Memis <ali@iusegentoo.com>
    Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept

Steffen Persvold <spersvold@gmail.com>
    PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems


-------------

Diffstat:

 Makefile                                   |   4 +-
 drivers/block/null_blk/zoned.c             |  10 +-
 drivers/gpio/gpio-ml-ioh.c                 |  36 ++--
 drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c     |   4 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |  50 ++++-
 drivers/hid/hid-core.c                     |  11 +-
 drivers/hid/hid-hyperv.c                   |  27 ++-
 drivers/hid/hid-magicmouse.c               |  26 +++
 drivers/hid/hid-nintendo.c                 |   7 +-
 drivers/hid/hid-sensor-custom.c            |  21 +-
 drivers/input/keyboard/atkbd.c             |  23 ++-
 drivers/input/mouse/byd.c                  |   2 +-
 drivers/misc/fastrpc.c                     |  64 +++---
 drivers/mmc/host/atmel-mci.c               |   2 +
 drivers/net/can/dev/skb.c                  |   2 -
 drivers/net/ntb_netdev.c                   |  15 +-
 drivers/net/usb/rndis_host.c               |   6 +-
 drivers/nfc/fdp/i2c.c                      |  27 +++
 drivers/nfc/microread/microread.c          |  31 ++-
 drivers/nfc/pn533/pn533.c                  |   1 +
 drivers/nfc/st21nfca/dep.c                 |   3 +
 drivers/nvme/target/fabrics-cmd-auth.c     |   2 +-
 drivers/nvme/target/fc.c                   |   2 +-
 drivers/nvme/target/tcp.c                  |   5 +-
 drivers/pci/controller/pci-host-generic.c  |  11 +-
 drivers/pci/ecam.c                         |  13 ++
 drivers/s390/cio/vfio_ccw_chp.c            |  26 ++-
 drivers/s390/cio/vfio_ccw_cp.c             |  30 ++-
 drivers/s390/cio/vfio_ccw_drv.c            |  26 ++-
 drivers/s390/cio/vfio_ccw_fsm.c            |   8 +-
 drivers/s390/cio/vfio_ccw_ops.c            |  27 +++
 drivers/s390/cio/vfio_ccw_private.h        |   9 +-
 drivers/tty/serial/amba-pl011.c            |   8 +-
 drivers/tty/serial/sc16is7xx.c             | 222 ++++++++++----------
 fs/ext4/xattr.c                            |   7 +-
 fs/iomap/buffered-io.c                     |  19 +-
 fs/ocfs2/xattr.c                           |  18 +-
 fs/xfs/libxfs/xfs_attr_leaf.c              |  14 ++
 fs/xfs/libxfs/xfs_log_recover.h            |   4 +-
 fs/xfs/xfs_attr_item.c                     |  24 +--
 fs/xfs/xfs_bmap_item.c                     |  18 +-
 fs/xfs/xfs_buf_item.c                      |   8 +-
 fs/xfs/xfs_buf_item.h                      |   2 +-
 fs/xfs/xfs_buf_item_recover.c              |  91 +++++---
 fs/xfs/xfs_dquot_item_recover.c            |  20 +-
 fs/xfs/xfs_extfree_item.c                  |  43 ++--
 fs/xfs/xfs_icreate_item.c                  |   2 +-
 fs/xfs/xfs_inode_item.c                    |   6 +-
 fs/xfs/xfs_inode_item.h                    |   4 +-
 fs/xfs/xfs_inode_item_recover.c            |  26 +--
 fs/xfs/xfs_log_recover.c                   |  16 +-
 fs/xfs/xfs_refcount_item.c                 |  16 +-
 fs/xfs/xfs_rmap_item.c                     |  16 +-
 fs/xfs/xfs_trans.h                         |   1 -
 include/linux/can/core.h                   |   1 +
 include/linux/can/skb.h                    |   2 -
 include/linux/netdevice.h                  |   6 +-
 include/linux/pci-ecam.h                   |   3 +
 include/linux/sched.h                      |   8 +
 include/net/tls.h                          |   3 +-
 kernel/events/core.c                       | 121 +++++------
 kernel/kcov.c                              |  90 ++++----
 lib/Kconfig.debug                          |   5 +-
 net/bluetooth/hci_event.c                  |   2 +
 net/bluetooth/rfcomm/core.c                |  24 ++-
 net/can/af_can.c                           |  14 +-
 net/can/bcm.c                              |   2 -
 net/can/isotp.c                            | 320 +++++++++++++++++++++--------
 net/can/j1939/socket.c                     |   1 -
 net/can/j1939/transport.c                  |   2 -
 net/can/raw.c                              |   7 +-
 net/ceph/osd_client.c                      |   5 +-
 net/ipv4/inet_fragment.c                   |   6 +-
 net/ipv4/ip_output.c                       |   4 +
 net/ipv6/ip6_output.c                      |   2 +
 net/ipv6/ndisc.c                           |   8 +-
 net/mptcp/pm_netlink.c                     |  36 ++--
 net/nfc/digital_technology.c               |   2 +
 net/nfc/llcp_commands.c                    |  18 +-
 net/nfc/llcp_core.c                        |  15 +-
 net/nfc/nci/ntf.c                          |  10 +-
 net/nfc/nci/rsp.c                          |   1 +
 net/packet/af_packet.c                     |  79 ++++---
 net/packet/internal.h                      |   2 +-
 net/tls/tls.h                              |   4 +-
 net/tls/tls_strp.c                         |  17 +-
 net/tls/tls_sw.c                           |   3 +-
 net/xfrm/xfrm_state.c                      |   4 +-
 sound/drivers/dummy.c                      |   6 +
 sound/soc/codecs/lpass-tx-macro.c          |   4 +-
 90 files changed, 1283 insertions(+), 670 deletions(-)



^ permalink raw reply	[flat|nested] 88+ messages in thread

end of thread, other threads:[~2026-08-27  2:40 UTC | newest]

Thread overview: 88+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 13:25 [PATCH 6.1 00/79] 6.1.185-rc1 review Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 01/79] PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 02/79] Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 03/79] rndis_host: add overflow check in rndis_rx_fixup() Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 04/79] ALSA: dummy: Check card index validity at probe Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 05/79] ocfs2: fix missing metadata reservation for large xattrs Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 06/79] null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 07/79] kcov: fix data corruption and race conditions on PREEMPT_RT Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 08/79] ext4: stop retrying saturated xattr cache entries Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 09/79] ext4: clear error before retrying inode xattr space fallback Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 10/79] xfs: validate attr entry pointer before field access Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 11/79] misc: fastrpc: Rework fastrpc_req_munmap Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 12/79] misc: fastrpc: Remove buffer from list prior to unmap operation Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 13/79] NTB: ntb_netdev: Preserve RX queue depth on allocation failure Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 14/79] serial: amba-pl011: synchronize DMA teardown Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 15/79] perf/core: Fix child_total_time_enabled accounting bug at task exit Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 16/79] perf: Fix cgroup state vs ERROR Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 17/79] perf: Fix dangling cgroup pointer in cpuctx Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 18/79] perf/core: Fix group leader use-after-free after sibling detach Greg Kroah-Hartman
2026-08-25 13:25 ` [PATCH 6.1 19/79] packet: use consistent hard_header_len in non-ring send paths Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 20/79] packet: use consistent hard_header_len in TX_RING send path Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 21/79] serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 22/79] serial: sc16is7xx: convert bitmask definitions to use BIT() macro Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 23/79] serial: sc16is7xx: rename EFR mutex with generic name Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 24/79] serial: sc16is7xx: use guards for simple mutex locks Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 25/79] serial: sc16is7xx: enable THRI before filling TX FIFO Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 26/79] net/packet: convert po->pressure to an atomic flag Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 27/79] packet: synchronize pressure clearing with ring reconfiguration Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 28/79] inet: frags: publish queues before arming timer Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 29/79] mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 30/79] s390/vfio_ccw: Cancel existing workqueues Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 31/79] drm/amdgpu: disallow multiple FENCE chunks in one submit Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 32/79] s390/vfio_ccw: Move cp cleanup out of not operational Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 33/79] s390/vfio_ccw: Selectively expand io_mutex Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 34/79] s390/vfio_ccw: Implement a crw lock Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 35/79] xfs: dont use a xfs_log_iovec for ri_buf in log recovery Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 36/79] xfs: bounds-check buffer log items dirty bitmap Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 37/79] drm/amdgpu: check ASPM on the dGPU host link Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 38/79] gpio: ml-ioh: use raw_spinlock_t for the register lock Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 39/79] tls: fix lockless read of strp->msg_ready in ->poll Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 40/79] tls: handle data disappearing from under the TLS ULP Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 41/79] iomap: adjust read range correctly for non-block-aligned positions Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 42/79] nfc: digital: clamp SENSF_RES length to the destination buffer Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 43/79] nfc: fdp: bound the device-reported read length and fix an skb leak Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 44/79] nfc: microread: validate target discovery payload lengths Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 45/79] nfc: llcp: bound the connect_sn TLV walk to the skb Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 46/79] nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 47/79] nfc: llcp: reject PDUs shorter than the LLCP header Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 48/79] nfc: pn533: purge fragmented skbs during cleanup Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 49/79] nfc: st21nfca: validate ATR_REQ length against the received frame Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 50/79] nfc: nci: fix out-of-bounds write in nci_target_auto_activated() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 51/79] nfc: nci: fix uninit-value in the RF discover/activated NTF handlers Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 52/79] nfc: nci: free destination parameters when closing a connection Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 53/79] ndisc: ndisc_send_redirect() cleanup Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 54/79] libceph: fix OOB read in decode_watchers() via missing bounds check Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 55/79] ipv4: reject undersized MTUs in ip_do_fragment() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 56/79] ipv6: fix use-after-free in ip6_finish_output2() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 57/79] nvmet-auth: zero the AUTH_RECEIVE response buffer Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 58/79] nvmet-fc: fix invalid free in LS IOD error path Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 59/79] nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 60/79] Input: byd - synchronize timer deletion before freeing private data Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 61/79] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 62/79] mptcp: pm: ADD_ADDR rtx: always decrease sk refcount Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 63/79] mptcp: pm: ADD_ADDR rtx: free sk if last Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 64/79] mptcp: pm: fix data race in add_addr timer callback Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 65/79] HID: magicmouse: do not keep a stale msc->input if no input is claimed Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 66/79] HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 67/79] HID: core: fix OOB read of field->usage in hid_set_field() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 68/79] xfrm: fix sk_dst_cache double-free in xfrm_user_policy() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 69/79] s390/vfio_ccw: Free all memory if cp_init() fails Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 70/79] Input: atkbd - skip deactivate for HONOR FMB-Ps internal keyboard Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 71/79] Input: atkbd - skip deactivate for HONOR ZQC-P Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 72/79] can: use skb hash instead of private variable in headroom Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 73/79] can: isotp: fix timer drain order, wakeup handling and tx_gen ordering Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 74/79] misc: fastrpc: Fix double free of buf in error path Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 75/79] HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 76/79] HID: core: fix number/pointer type confusion on long items Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 77/79] HID: sensor: custom: Fix use-after-free in enable_sensor Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 78/79] HID: hyperv: validate initial device info bounds Greg Kroah-Hartman
2026-08-25 13:26 ` [PATCH 6.1 79/79] Bluetooth: hci_event: fix LE list UAF on reset Greg Kroah-Hartman
2026-08-25 19:30 ` [PATCH 6.1 00/79] 6.1.185-rc1 review Pavel Machek
2026-08-25 21:31 ` Florian Fainelli
2026-08-26  0:22 ` Shuah Khan
2026-08-26  6:28 ` Ron Economos
2026-08-26 10:32 ` Brett A C Sheffield
2026-08-26 11:20 ` Peter Schneider
2026-08-26 11:50 ` Miguel Ojeda
2026-08-27  2:40 ` Barry K. Nathan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).