From: bruce.ashfield@gmail.com
To: richard.purdie@linuxfoundation.org
Cc: openembedded-core@lists.openembedded.org
Subject: [meta-yocto-bsp][PATCH 04/06] yocto-bsps: update to v6.18.36
Date: Mon, 20 Jul 2026 11:58:39 -0400 [thread overview]
Message-ID: <20260720155842.569263-5-bruce.ashfield@gmail.com> (raw)
In-Reply-To: <20260720155842.569263-1-bruce.ashfield@gmail.com>
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.18 to the latest korg -stable release that comprises
the following commits:
275d294b2b24 Linux 6.18.36
5d634afb8b83 netfilter: require Ethernet MAC header before using eth_hdr()
bf7a9cacd95e cfi: Include uaccess.h for get_kernel_nofault()
f455405e3207 vsock/virtio: fix skb overhead overflow on 32-bit builds
36a0faaa4e3d block: fix handling of dead zone write plugs
7b569b3a2f29 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
99abe00c605e arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
d4fd42822040 arm64: errata: Mitigate TLBI errata on various Arm CPUs
8097f93f9b77 arm64: cputype: Add C1-Premium definitions
e9ea7cb17677 arm64: cputype: Add C1-Ultra definitions
eca6743b148a vsock/virtio: fix skb overhead accounting to preserve full buf_alloc
9bdc637fde66 vsock/virtio: fix potential unbounded skb queue
cdce1e797add ipvs: skip ipv6 extension headers for csum checks
afd35fec9297 RDMA/umem: Fix truncation for block sizes >= 4G
cd26d54bfbc2 RDMA: Move DMA block iterator logic into dedicated files
ebf22feff492 RDMA/umem: fix kernel-doc warnings
84d8f58cf28a netfilter: nft_fib: fix stale stack leak via the OIFNAME register
2904e985a291 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
f58efaf9fcf7 RDMA/umem: Add helpers for umem dmabuf revoke lock
5f3286ca5fbb RDMA/umem: Move umem dmabuf revoke logic into helper function
ceddd32231dd RDMA/umem: Add ib_umem_dmabuf_get_pinned_and_lock helper
0ffcad63b19a sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()
37c059d4d92f wifi: mac80211: tests: mark HT check strict
4dac39a4db14 wifi: mac80211: skip ieee80211_verify_sta_ht_mcs_support check in non-strict mode
17faa39ba980 driver core: reject devices with unregistered buses
20a93e397abe fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
e09689286385 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
454d3b3d499c drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
bb6f705b73b5 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
c000da79df78 drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs
3f32d52ec604 drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
1906064d50d1 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
0e56f460bddb drm/amd/display: Bound VBIOS record-chain walk loops
57607fe55e6d drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range
932642791cb1 drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2
8979ded4d899 drm/amd/pm: fix smu13 power limit default/cap calculation
39b5397bf8de drm/amdgpu: set noretry=1 as default for GFX 10.1.x (Navi10/12/14)
fcd51a085e9a drm/amdgpu: restart the CS if some parts of the VM are still invalidated
68455b117258 drm/amdgpu: fix waiting for all submissions for userptrs
9655b56b6de9 drm/v3d: Skip CSD when it has zeroed workgroups
90b629269088 drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
3e1947573140 drm/v3d: Fix global performance monitor reference counting
11e9bdf8824b drm/v3d: Wait for pending L2T flush before cleaning caches
4c10fd55187a drm/xe: Clear pending_disable before signaling suspend fence
0f68ddfaaebf drm/xe/display: fix oops in suspend/shutdown without display
d3efcadfe3ee drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
72e259a32084 drm/amdkfd: fix NULL dereference in get_queue_ids()
c0639ede2f24 drm/gem: Try to fix change_handle ioctl, attempt 4
9f0d45d509b4 slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
8f4b371f4939 slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
5204cd22c1c7 slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership
dd8e1025a84e slimbus: qcom-ngd-ctrl: Initialize controller resources in controller
24ec89123fc9 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
3bb2ac834ed3 slimbus: qcom-ngd-ctrl: Fix probe error path ordering
d6cb003e4661 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
6890bd2451a9 slimbus: qcom-ngd-ctrl: fix OF node refcount
b5daa920f44c thunderbolt: Limit XDomain response copy to actual frame size
46da5c3ea011 thunderbolt: Validate XDomain request packet size before type cast
fcbd0cdab928 thunderbolt: Clamp XDomain response data copy to allocation size
60ba62174607 thunderbolt: Bound root directory content to block size
2e0ddac549eb thunderbolt: Reject zero-length property entries in validator
d5ea0b3e261f sctp: stream: fully roll back denied add-stream state
78c4f964b2f9 sctp: diag: reject stale associations in dump_one path
566c4c1244de rxrpc: Fix the ACK parser to extract the SACK table for parsing
1bf84f4013fa rtase: Reset TX subqueue when clearing TX ring
54f9cdcd7311 rtase: Avoid sleeping in get_stats64()
ddcf84b25af0 pmdomain: ti_sci: add wakeup constraint to parent devices of wakeup source
0d11992d1898 pmdomain: imx: fix OF node refcount
0aecf3c7b8f8 mmc: sdhci: add signal voltage switch in sdhci_resume_host
535ff092b686 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
2f72d36f8acc mmc: litex_mmc: Set mandatory idle clocks before CMD0
7f8007be13e6 mmc: dw_mmc-rockchip: Add missing private data for very old controllers
c677b13671dc mmc: core: Fix host controller programming for fixed driver type
a8f91ddf67f6 mm/mincore: handle non-swap entries before !CONFIG_SWAP guard
c19ff4351214 mm/list_lru: drain before clearing xarray entry on reparent
c72469ac0f27 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
ecc24f0a8a30 mm/hugetlb: avoid false positive lockdep assertion
66bc00ea37fa mm/damon/reclaim: handle ctx allocation failure
6d48f1565939 mm/damon/lru_sort: handle ctx allocation failure
d83390b21a02 mm/cma_debug: fix invalid accesses for inactive CMA areas
52078596dce1 mm/cma: fix reserved page leak on activation failure
d5d37b7b72a9 io_uring/wait: fix min_timeout behavior
c888d5198ffc io_uring/kbuf: don't truncate end buffer for bundles
3fdcca838f97 pinctrl: mcp23s08: Read spi-present-mask as u8 not u32
e646b86b3b48 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
4a4d21f531cc nvmem: layouts: onie-tlv: fix hang on unknown types
cb85ef5a227b nvmem: core: fix use-after-free bugs in error paths
bef389a210e7 net: sfp: initialize i2c_block_size at adapter configure time
1d4ec754ee38 net: rds: clear i_sends on setup unwind
52b8f5ef82c8 net: phonet: free phonet_device after RCU grace period
4a73cacb5586 net: mv643xx: fix OF node refcount
bcb8fad90f27 net: bonding: fix NULL pointer dereference in bond_do_ioctl()
01f7d4b50458 net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()
e0df4d9c0909 net/mlx5: Reorder completion before putting command entry in cmd_work_handler
0a46c7a5646d firmware: samsung: acpm: Fix mailbox channel leak on probe error
d5de9cb5355d misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
53e06f8a3c2b misc: fastrpc: fix DMA address corruption due to find_vma misuse
992f121796b7 misc: fastrpc: fix use-after-free race in fastrpc_map_create
5278ccd357e0 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
89bd8215e25a memcg: use round-robin victim selection in refill_stock
a388e3dfaf95 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
db752ebfdaf2 ipc/shm: serialize orphan cleanup with shm_nattch updates
ab61c990a87d iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
f35a368fee8a Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
a3dff1e1a554 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
7f59e4f72a78 i2c: tegra: Fix NOIRQ suspend/resume
6018d73137cd i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
a162a260c8c4 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
9fa82cf393ba i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
b39f30c0a72f i2c: imx-lpi2c: fix resource leaks switching to devm_dma_request_chan()
16f8e17184b3 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
56763afa0134 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
12df4cfa738a fuse: reject fuse_notify() pagecache ops on directories
57a9c085be07 fs/qnx6: fix pointer arithmetic in directory iteration
2990f143ec86 pidfd: refuse access to tasks that have started exiting harder
89b909e97045 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
df422fd273c9 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
32138633e51e fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
3884976f8744 bnxt_en: Fix NULL pointer dereference
6f72b902c34d ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
735dabdf2156 staging: rtl8723bs: fix buffer over-read in rtw_update_protection
1d6c2062b77b timers/migration: Fix livelock in tmigr_handle_remote_up()
ba9ad6015937 vsock/vmci: fix sk_ack_backlog leak on failed handshake
265c07c09c83 wifi: nl80211: reject oversized EMA RNR lists
ac2000be0cbe wifi: iwlwifi: pcie: simplify the resume flow if fast resume is not used
fcfdff42e841 xfs: fix rtgroup cleanup in CoW fork repair
d84ed2f9718e xfs: fix error returns in CoW fork repair
9f21885c11ba mptcp: add-addr: always drop other suboptions
6ea1134f1b5f selftests: mptcp: add test for extra_subflows underflow on userspace PM
7bbc11437a20 mptcp: sockopt: set sockopt on all subflows
f591cbc088c9 mptcp: sockopt: check timestamping ret value
c0c152fc4ae6 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
653245266913 mptcp: allow subflow rcv wnd to shrink
3b8cbba7c0ed mptcp: close TOCTOU race while computing rcv_wnd
edaf0c955ace mptcp: fix retransmission loop when csum is enabled
95f27fcda681 arm64: mm: call pagetable dtor when freeing hot-removed page tables
517720913bd3 ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
da295adc9dab ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
6243a363ec90 ARM: socfpga: Fix OF node refcount leak in SMP setup
6822eed69572 udp: clear skb->dev before running a sockmap verdict
c96786d6ff1a zram: fix use-after-free in zram_bvec_write_partial()
f92a285db7ff RDMA/srp: bound SRP_RSP sense copy by the received length
bd5e818be796 RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
96b6e98ff12d RDMA/core: Validate the passed in fops for ib_get_ucaps()
e99807bdcd20 mm/huge_memory: update file PUD counter before folio_put()
cb5230b6d8a0 mm/damon/ops-common: call folio_test_lru() after folio_get()
5f5b604e1e6b mm/huge_memory: update file PMD counter before folio_put()
edabfe80e34e drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
8348567a6afb drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
0bbc9481f970 io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
3d39da65b5c4 ALSA: timer: Fix UAF at snd_timer_user_params()
f46093dd2296 ALSA: timer: Forcibly close timer instances at closing
372f33ebed74 USB: serial: kl5kusb105: fix bulk-out buffer overflow
85bd2b3afa0a USB: serial: option: add usb-id for Dell Wireless DW5826e-m
294692d3296e USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
f96cf7bf9fbf USB: serial: io_ti: fix heap overflow in get_manuf_info()
a13ca53e47e5 xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
dd66f7f6e360 xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
f9b38a8fbfa0 xfrm: espintcp: do not reuse an in-progress partial send
14d2eee0193a ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
0b38870d81ab hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
32d4c5d328a3 drm/i915/gem: Fix phys BO pread/pwrite with offset
0b79bcff7210 KVM: arm64: Restore POR_EL0 access to host EL0
196f1ee137eb KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA
343e95c8ecc4 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
0864bdde152e mshv: add a missing padding field
8bcbedce9bfa mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
a0a4600b396b rust: kasan/kbuild: fix rustc-option when cross-compiling
d0f25a1755f2 rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES
5037b2ee1a17 ARM: Do not select HAVE_RUST when KASAN is enabled
00875811f372 rust: x86: support Rust >= 1.98.0 target spec
592be0dc491d tracing/probes: Point the error offset correctly for eprobe argument error
09df291fdf96 tracing: Fix CFI violation in probestub being called by tprobes
45cb105b8642 accel/ivpu: Fix signed integer truncation in IPC receive
fa598556ecef accel/ivpu: Add buffer overflow check in MS get_info_ioctl
8ec70c0dbdf0 accel/ivpu: Add bounds checks for firmware log indices
dd77a83915b0 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
cc160ce08540 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
dedc92b96dc1 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
dafc9f57140e Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
c10c9c48b290 tee: shm: fix shm leak in register_shm_helper()
07acb9798477 netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
941d7394efda netfilter: nft_tunnel: fix use-after-free on object destroy
e83fc4c28226 accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
361e97d81331 drm/xe: fix refcount leak in xe_range_fence_insert()
02f5e4db57c0 drm/vc4: fix krealloc() memory leak
19a6a00ff50c drm/virtio: Fix driver removal with disabled KMS
dda720b2928d drm/i915/edp: Check supported link rates DPCD read
489f6d759fa4 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
3a4fc3617b7e clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs
656939c67595 clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from getting parked
f34689e7a0b3 KVM: VMX: Update SVI during runtime APICv activation
07d9a0870a17 ipv6: Fix a potential NPD in cleanup_prefix_route()
2c98343c9b23 net: txgbe: initialize module info buffer
19a4d2aace1d net: txgbe: rename the SFP related
9157060fed92 net: txgbe: support CR modules for AML devices
7649ba2b1291 net: txgbe: optimize the flow to setup PHY for AML devices
af08fe9ba091 net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
8a2126c5afe8 net: mvpp2: refill RX buffers before XDP or skb use
910617a4e67d net: mvpp2: limit XDP frame size to the RX buffer
a13199fa224e net: mvpp2: sync RX data at the hardware packet offset
78069a6d8bc8 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
af1b7699466f netfilter: nf_log: validate MAC header was set before dumping it
08a3e218064d netfilter: x_tables: avoid leaking percpu counter pointers
9d017671dcfc netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
4beffcd726e2 netfilter: revalidate bridge ports
865e94f6d8a5 spi: rzv2h-rspi: Fix SPDR read access width for 16-bit RX
5ae8a38169fc rds: mark snapshot pages dirty in rds_info_getsockopt()
2abfb19bbb81 ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
5fd1fa5a4254 tun: zero the whole vnet header in tun_put_user()
dcf458120add net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
3dde4fb941fa net: guard timestamp cmsgs to real error queue skbs
7560afb8cdda sctp: validate embedded INIT chunk and address list lengths in cookie
ecf8904067dc ip6_vti: set netns_immutable on the fallback device.
f76a8b323e28 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
d23d53355300 ASoC: SOF: amd: fix for ipc flags check
6c75ee4d1d40 net: mctp: usb: don't fail mctp_usb_rx_queue on a deferred submission
9c46f3ee1837 net: mctp: usb: fix race between urb completion and rx_retry cancellation
bace7b99bfa5 gpio: rockchip: fix generic IRQ chip leak on remove
5d4bca5cbb69 gpio: zynq: fix runtime PM leak on remove
c838ffc154cb r8152: handle the return value of usb_reset_device()
ecc55aad3390 net: openvswitch: fix possible kfree_skb of ERR_PTR
2fa49b2715e1 ipv6: sit: reload inner IPv6 header after GSO offloads
289c06418ed9 net/mlx5: Use effective affinity mask for IRQ selection
2789b74ae1f4 net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
0f807764bb12 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
ab269990ed58 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
3a254779c169 net: phy: clean the sfp upstream if phy probing fails
c299321bc623 netdev: fix double-free in netdev_nl_bind_rx_doit()
c09c2e236eef net: ibm: emac: Fix use-after-free during device removal
8b0541231091 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
0cde3a004119 net: add pskb_may_pull() to skb_gro_receive_list()
ede69b8f6670 tcp: restrict SO_ATTACH_FILTER to priv users
12e579b88962 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
6136c1474db8 gpio: mvebu: fix NULL pointer dereference in suspend/resume
0c4bb32ad7fd netlabel: validate unlabeled address and mask attribute lengths
972c106f5d01 bnge: fix context mem iteration
6b8baf42b1b7 net: ena: PHC: Add missing barrier
640edc281d2f idpf: fix mailbox capability for set device clock time
6bdbe6f43ecf ice: fix missing priority callbacks for U.FL DPLL pins
b5316e2b8614 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
5513dcb378f9 dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device
4ee4d628c4d9 dma-mapping: direct: fix missing mapping for THRU_HOST_BRIDGE segments
8d9a79fbf517 xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
e27c17346628 tap: free page on error paths in tap_get_user_xdp()
0c03692e2372 verification/rvgen: Fix ltl2k writing True as a literal
43ad0a0da486 verification/rvgen: Fix options shared among commands
73590b4cfd05 tools/rv: Fix cleanup after failed trace setup
fd1923910bbf tools/rv: Fix substring match when listing container monitors
2122d68f0864 tools/rv: Fix substring match bug in monitor name search
618193aba6fe tools/rv: Ensure monitor name and desc are NUL-terminated
65046b0d853d cpufreq/amd-pstate: drop stale @epp_cached kdoc
63a9f6012f45 spi: cadence-quadspi: fix unclocked access on unbind
6671a46144f8 ALSA: seq: dummy: fix UMP event stack overread
cd98837db15f ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
6b71956c25f9 time: Fix off-by-one in settimeofday() usec validation
ed0ad6574126 hyperv: Clean up and fix the guest ID comment in hvgdk.h
8c046f36222c signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
6dc6e5b5c32e selftests: harness: fix pidfd leak in __wait_for_test
752e22ecf4df drm/hyperv: During panic do VMBus unload after frame buffer is flushed
b0f77f76231b Drivers: hv: vmbus: Provide option to skip VMBus unload on panic
1639df1a9844 Drivers: hv: VMBus protocol version 6.0
a6207349e703 sctp: purge outqueue on stale COOKIE-ECHO handling
42446ca0f357 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
285b0842f2e0 ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
3b7ee029b556 vxlan: vnifilter: fix spurious notification on VNI update
8e4d1188bad7 vxlan: vnifilter: send notification on VNI add
eb676fb14427 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
cc272185c9a9 sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
b198ed4e5258 net/sched: fix pedit partial COW leading to page cache corruption
e634408d2b0c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
6f829e2c17a5 net: airoha: Fix use-after-free in metadata dst teardown
9a263bbd1ec0 ptp: vclock: Switch from RCU to SRCU
a4f3fd651692 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
91106d0348a5 af_unix: Fix inq_len update problem in partial read
f010cf9aea01 octeontx2-af: Fix initialization of mcam's entry2target_pffunc field
ddf930f28be6 octeontx2-pf: Fix NDC sync operation errors
0dfe05b93843 xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
58d810354de1 Bluetooth: MGMT: Fix backward compatibility with userspace
446a17b1b509 Bluetooth: SCO: Fix data-race on sco_pi fields in sco_connect
ab84fd7779a2 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
33d677d2e371 Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
ce4b4cac3c57 Bluetooth: fix memory leak in error path of hci_alloc_dev()
c893e17d2809 Bluetooth: bnep: reject short frames before parsing
7f5367f1ad9b Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
3eabc6d47a0a Bluetooth: RFCOMM: validate skb length in MCC handlers
1a3c8ffbb469 Bluetooth: MGMT: validate advertising TLV before type checks
8802413ce631 Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
fb8db813eba2 wifi: fix leak if split 6 GHz scanning fails
15be7e9fdbff ipv6: anycast: insert aca into global hash under idev->lock
23bf7d5c250b net: fec: fix pinctrl default state restore order on resume
76244b33640b net: lan743x: permit VLAN-tagged packets up to configured MTU
04e22fefac1a net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
66a46e22396f hsr: Remove WARN_ONCE() in hsr_addr_is_self().
07f13816be5a net: Annotate sk->sk_write_space() for UDP SOCKMAP.
83810d51d699 pcnet32: stop holding device spin lock during napi_complete_done
9b40c59bab08 wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
e3f6ba5f8cf3 drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
927f96861f93 devlink: Release nested relation on devlink free
e251d4cdfc72 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
c32f30ef5e66 6lowpan: fix off-by-one in multicast context address compression
b60e9391142e net/sched: act_api: use RCU with deferred freeing for action lifecycle
42ff6774ecd9 dm cache policy smq: check allocation under invalidate lock
b18675263db1 netfilter: bridge: make ebt_snat ARP rewrite writable
f071b0bf0781 netfilter: nft_ct: bail out on template ct in get eval
9e5da2379f96 netfilter: conntrack_irc: fix possible out-of-bounds read
aaf80701dc2f netfilter: synproxy: add mutex to guard hook reference counting
25918720ba97 ipvs: clear the svc scheduler ptr early on edit
cdaf13260c99 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
e735dbd489e3 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
9dca67624721 wifi: iwlwifi: mvm: don't support the reset handshake for old firmwares
00bf6868df65 erofs: fix use-after-free on sbi->sync_decompress
50fd261b1ec4 erofs: tidy up synchronous decompression
8db2fabb5ecd tee: qcomtee: add missing va_end in early return qcomtee_object_user_init()
ac7eca1ae4e5 tee: fix tee_ioctl_object_invoke_arg padding
633db9a1991a soc: qcom: ice: Return -ENODEV if the ICE platform device is not found
40fc6ed12f91 ARM: dts: microchip: sam9x7: fix GMAC clock configuration
9cb93ec617fb arm64: dts: qcom: x1-dell-thena: remove i2c20 (battery SMBus) and reserve its pins
a171bc68e9af soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
d5b57bb314d7 tee: optee: prevent use-after-free when the client exits before the supplicant
dcd90f42a33e net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
4203806f700b ipv6: mcast: Fix use-after-free when processing MLD queries
ffbcf31f032e i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
97706097f9b8 KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation
9e767af5f109 ARM: fix branch predictor hardening
05e22564a4f9 ARM: fix hash_name() fault
8bdb574b2176 ARM: allow __do_kernel_fault() to report execution of memory faults
22e26df355af ARM: group is_permission_fault() with is_translation_fault()
87dfb977bdb6 bpf: Free reuseport cBPF prog after RCU grace period.
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
---
meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend
index 7505946..c012ad3 100644
--- a/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend
+++ b/meta-yocto-bsp/recipes-kernel/linux/linux-yocto_6.18.bbappend
@@ -8,4 +8,4 @@ KMACHINE:genericx86 ?= "common-pc"
KMACHINE:genericx86-64 ?= "common-pc-64"
KBRANCH:genericarm64 ?= "v6.18/standard/genericarm64"
-SRCREV_machine:genericarm64 ?= "d6f3a955dcf77a71454a2d70f291bd39d06422ff"
+SRCREV_machine:genericarm64 ?= "c02123f16c412c8b8629ff2a9f06e9feca9077d6"
--
2.43.0
next prev parent reply other threads:[~2026-07-20 15:58 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 15:58 [PATCH 0/6] kernel-yocto: stable udpates bruce.ashfield
2026-07-20 15:58 ` [meta][PATCH 01/06] linux-yocto/6.18: update to v6.18.36 bruce.ashfield
2026-07-20 16:19 ` Patchtest results for " patchtest
2026-07-20 15:58 ` [meta][PATCH 02/06] linux-yocto/6.18: update to v6.18.38 bruce.ashfield
2026-07-20 15:58 ` [meta][PATCH 03/06] linux-yocto/6.18: update to v6.18.39 bruce.ashfield
2026-07-20 15:58 ` bruce.ashfield [this message]
2026-07-20 16:19 ` Patchtest results for [meta-yocto-bsp][PATCH 04/06] yocto-bsps: update to v6.18.36 patchtest
2026-07-20 15:58 ` [meta-yocto-bsp][PATCH 05/06] yocto-bsps: update to v6.18.38 bruce.ashfield
2026-07-20 16:19 ` Patchtest results for " patchtest
2026-07-20 15:58 ` [meta-yocto-bsp][PATCH 06/06] yocto-bsps: update to v6.18.39 bruce.ashfield
2026-07-20 16:19 ` Patchtest results for " patchtest
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720155842.569263-5-bruce.ashfield@gmail.com \
--to=bruce.ashfield@gmail.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=richard.purdie@linuxfoundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox