* [meta][scarthgap][PATCH 01/02] linux-yocto/6.6: update to v6.6.143
@ 2026-07-20 16:00 bruce.ashfield
2026-07-20 16:00 ` [meta][scarthgap][PATCH 02/02] linux-yocto/6.6: update to v6.6.144 bruce.ashfield
0 siblings, 1 reply; 2+ messages in thread
From: bruce.ashfield @ 2026-07-20 16:00 UTC (permalink / raw)
To: richard.purdie; +Cc: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:
d1cfde2d5d15 Linux 6.6.143
726abf975668 netfilter: require Ethernet MAC header before using eth_hdr()
05bd072e97fe x86/CPU/AMD: Rename init_amd_zn() to init_amd_zen_common()
4a83b435acf8 x86/CPU/AMD: Call the spectral chicken in the Zen2 init function
5e0c93dca433 x86/CPU/AMD: Move the Zen3 BTC_NO detection to the Zen3 init function
217f53b5e3c6 Revert "selftest/ptp: update ptp selftest to exercise the gettimex options"
189c7e57826f mptcp: fix missing wakeups in edge scenarios
c12e67a0ef93 mptcp: add-addr: always drop other suboptions
1111ab94fd49 arm64: errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
e5b6bdc3d8b8 arm64: errata: Mitigate TLBI errata on NVIDIA Olympus CPU
e717a4d08779 arm64: errata: Mitigate TLBI errata on various Arm CPUs
baf63e6a6435 arm64: cputype: Add C1-Premium definitions
1e4a5225b4d3 arm64: cputype: Add C1-Ultra definitions
f58e88f8653f arm64: cputype: Add NVIDIA Olympus definitions
2602d4b53925 ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6
9aa7edc1347b ipvs: skip ipv6 extension headers for csum checks
2de5c8eea0a9 net: bonding: fix use-after-free in bond_xmit_broadcast()
8fe0231adebe RDMA/umem: Fix truncation for block sizes >= 4G
3faebd387ed1 RDMA: Move DMA block iterator logic into dedicated files
a7c6be320c0e RDMA/umem: fix kernel-doc warnings
09dc18894148 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
09b8a7aa5a34 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
77b73b54801a mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
252bb328b36f mm/memory-failure: fix missing ->mf_stats count in hugetlb poison
05f1ad6d62a3 mm/hugetlb: rename folio_putback_active_hugetlb() to folio_putback_hugetlb()
471f5d78ea4b mm/migrate: don't call folio_putback_active_hugetlb() on dst hugetlb folio
411fa5113da0 mm/hugetlb: rename isolate_hugetlb() to folio_isolate_hugetlb()
eb8a8124484d netfilter: nft_fib: fix stale stack leak via the OIFNAME register
46582b0fd381 usb: typec: ucsi: Don't update power_supply on power role change if not connected
c91ea13375f7 serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
d3e9b79aa794 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
b4621e5ef634 thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
078c11224c7f usb: typec: ucsi: Check if power role change actually happened before handling
e15c414092b3 usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
5542d2c35930 usb: dwc3: xilinx: fix error handling in zynqmp init error paths
b987f380620b usb: musb: omap2430: Fix use-after-free in omap2430_probe()
a9c22e0f93ba tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
8809b7941c4a tty: serial: samsung: use u32 for register interactions
33da47d4a003 serial: samsung_tty: Use port lock wrappers
1cdb07d8946c ALSA: firewire-motu: Protect register DSP event queue positions
b3f4f82d1315 memfd: deny writeable mappings when implying SEAL_WRITE
2619d9d2aac3 iio: dac: ad5686: fix ref bit initialization for single-channel parts
f8dcef820161 usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure
e85bc501947f iio: chemical: scd30: fix division by zero in write_raw
73d8bf36f217 iio: chemical: scd30: Use guard(mutex) to allow early returns
86298fb6829c iio: gyro: adis16260: fix division by zero in write_raw
b35e71b7cc7a mptcp: handle first subflow closing consistently
792fa6eee73e Bluetooth: hci_qca: Convert timeout from jiffies to ms
c3fc351d256c Bluetooth: hci_qca: Migrate to serdev specific shutdown function
123724bb6ee5 serdev: Provide a bustype shutdown function
ca2f48b9c03d serdev: make serdev_bus_type const
c0e37017a452 mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
e7af1b15c884 mm/memory: fix spurious warning when unmapping device-private/exclusive pages
fe76413677e7 mptcp: do not drop partial packets
293b0e63136b mptcp: introduce the mptcp_init_skb helper
681d14ef45b1 iio: adc: npcm: fix unbalanced clk_disable_unprepare()
4ed1366f9f90 iio: adc: npcm: Convert to platform remove callback returning void
d766a49d9b55 arm64: tlb: Flush walk cache when unsharing PMD tables
4c29603498b0 octeontx2-pf: avoid double free of pool->stack on AQ init failure
26342087fac9 af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
db9389042db4 af_unix: Cache state->msg in unix_stream_read_generic().
c2c764b00c0f rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
a05bf6d9e621 rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
7713f4aafb57 net: hsr: defer node table free until after RCU readers
1dca7e491f07 ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
dcc42d701529 ipv6/addrconf: annotate data-races around devconf fields (II)
ada8dcfd5298 mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
04318e252c58 ice: fix VF queue configuration with low MTU values
d37a60086ee7 selftests: mptcp: drop nanoseconds width specifier
00ffe9893f4b mptcp: reset rcv wnd on disconnect
1521fecf44fc mptcp: cleanup fallback dummy mapping generation
78f9d747f386 mptcp: use plain bool instead of custom binary enum
e043017ac429 octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
1132ca7a1ba8 octeontx2-af: replace deprecated strncpy with strscpy
557edaf01062 platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error recovery
969bc6370334 smb: client: require net admin for CIFS SWN netlink
e19eff331240 genetlink: Use internal flags for multicast groups
14897ef9341c cgroup/cpuset: Reset DL migration state on can_attach() failure
850452af77f5 ksmbd: fix OOB write in QUERY_INFO for compound requests
6d8f52f3f80a fbdev/vt8500lcdfb: Initialize fb_ops with fbdev macros
666bd0598f37 ipmi:ssif: NULL thread on error
318a0403b270 ipmi:ssif: Remove unnecessary indention
ae9d4caf6f13 mm/huge_memory: update file PMD counter before folio_put()
310a8cc74612 soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
428a33573dcb mm/hugetlb: avoid false positive lockdep assertion
000e8f55fbc7 driver core: reject devices with unregistered buses
b5fa9e32fb67 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
201151e120f0 drm/amd/display: Use krealloc_array() in dal_vector_reserve()
7fc4fab4acc3 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
4d1c3c26c2ab drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
79e0273272a0 drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
3fe2c6af3f51 drm/amdgpu: restart the CS if some parts of the VM are still invalidated
16dad1fb0d78 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
62bd09e23a23 drm/amdkfd: fix NULL dereference in get_queue_ids()
d54a221b0f3c slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
9f4a76c7e9fa slimbus: qcom-ngd-ctrl: fix OF node refcount
fc261397295b thunderbolt: Limit XDomain response copy to actual frame size
0dd61ba03d05 thunderbolt: Validate XDomain request packet size before type cast
5db10c8ad8c0 thunderbolt: Clamp XDomain response data copy to allocation size
4d0b1524caad thunderbolt: Bound root directory content to block size
5f56bc6bddff thunderbolt: Reject zero-length property entries in validator
7dd9a42b044a sctp: stream: fully roll back denied add-stream state
e97c2a535e23 sctp: diag: reject stale associations in dump_one path
7e60d675288d mmc: sdhci: add signal voltage switch in sdhci_resume_host
b46521877611 mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
6dc14b9b431e mmc: litex_mmc: Set mandatory idle clocks before CMD0
30e727657185 mmc: core: Fix host controller programming for fixed driver type
8d6e1dd3ad13 mm/hugetlb: restore reservation on error in hugetlb folio copy paths
f0ca9c7f44a9 octeontx2-af: fix memory leak in rvu_setup_hw_resources()
033d498b0f47 nvmem: layouts: onie-tlv: fix hang on unknown types
e7cf30aa5f1f net: rds: clear i_sends on setup unwind
1ccad3ee7998 net: mv643xx: fix OF node refcount
a629418d463f net: bonding: fix NULL pointer dereference in bond_do_ioctl()
c090df5be6bc net/mlx5: Reorder completion before putting command entry in cmd_work_handler
8fb4a23df5b7 misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
d3e26df2e8eb misc: fastrpc: fix DMA address corruption due to find_vma misuse
8b080c891831 misc: fastrpc: fix use-after-free race in fastrpc_map_create
df08fadcf0e5 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
6560be3f6a5b ipc/shm: serialize orphan cleanup with shm_nattch updates
7a395a147f06 Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
81d60181ed55 Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
2d175d6aae9c i2c: tegra: Fix NOIRQ suspend/resume
5bebff5e8492 i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
7107627b8b35 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
dd92773d4d9c fuse: reject fuse_notify() pagecache ops on directories
254c469a404a pidfd: refuse access to tasks that have started exiting harder
0e823ca0e739 inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
c1234229399f IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
1a418ad0e5e5 bnxt_en: Fix NULL pointer dereference
6f5285a6054a ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
dfd853197615 vsock/vmci: fix sk_ack_backlog leak on failed handshake
688fcac7054a wifi: nl80211: reject oversized EMA RNR lists
eb13ab2f66e2 selftests: mptcp: add test for extra_subflows underflow on userspace PM
026c4a70e2a9 mptcp: sockopt: check timestamping ret value
b1fd13074f22 mptcp: allow subflow rcv wnd to shrink
907ac6b1658e mptcp: close TOCTOU race while computing rcv_wnd
f2c9012fc115 mptcp: fix retransmission loop when csum is enabled
c2e3aadc8fef ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow
b6290cc96dc8 ARM: 9474/1: io: avoid KASAN instrumentation of raw halfword I/O
c35c0763af34 ARM: socfpga: Fix OF node refcount leak in SMP setup
1b585673a224 udp: clear skb->dev before running a sockmap verdict
0c2821665ff7 zram: fix use-after-free in zram_bvec_write_partial()
0d64bc200ebe RDMA/srp: bound SRP_RSP sense copy by the received length
5c97ae9382de mm/damon/ops-common: call folio_test_lru() after folio_get()
5242b5f3c77f drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()
898bd0ccfed7 drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
e2331730175f ALSA: timer: Fix UAF at snd_timer_user_params()
a1288cd700f7 USB: serial: kl5kusb105: fix bulk-out buffer overflow
f71f8f99a9cd USB: serial: option: add usb-id for Dell Wireless DW5826e-m
4cb722747ed2 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
d92f17af7097 USB: serial: io_ti: fix heap overflow in get_manuf_info()
aa82a078f70f xfrm: espintcp: do not reuse an in-progress partial send
0da2e073f9cb ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
07c33be968d9 drm/i915/gem: Fix phys BO pread/pwrite with offset
033d39e41fc3 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
88520b2fecc4 mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
1e927a468500 tracing/probes: Point the error offset correctly for eprobe argument error
214a2042b16b Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
1338ee049a89 Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
8767fe4079af netfilter: nft_tunnel: fix use-after-free on object destroy
e0ce103e89d6 drm/vc4: fix krealloc() memory leak
ed3e134700a2 drm/virtio: Fix driver removal with disabled KMS
c5f438dd2fd8 clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration time
5e1c1d22268a netfilter: ctnetlink: ensure safe access to master conntrack
5f82b02b4059 ipv6: Fix a potential NPD in cleanup_prefix_route()
ccdd7f1949bb net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
580f92f27cb8 net: mvpp2: refill RX buffers before XDP or skb use
26c0986cb613 net: mvpp2: Add metadata support for xdp mode
3b8b0c3631b1 net: mvpp2: limit XDP frame size to the RX buffer
bede0f481b91 net: mvpp2: sync RX data at the hardware packet offset
cd513e43b4b2 netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
8a81e336da68 netfilter: nf_log: validate MAC header was set before dumping it
a0d16941adf3 netfilter: x_tables: avoid leaking percpu counter pointers
29d8cc44bbdf netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
eb7e77342e3e rds: mark snapshot pages dirty in rds_info_getsockopt()
f513f308cc4b ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
0f22412a2f4f net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
b903e9b5629e net: guard timestamp cmsgs to real error queue skbs
8ce96f118264 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
22f4ee66614e r8152: handle the return value of usb_reset_device()
25fdf5369853 net: openvswitch: fix possible kfree_skb of ERR_PTR
0bfa7bba1f41 ipv6: sit: reload inner IPv6 header after GSO offloads
41781f278930 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
2047c2aa0963 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
12fb84dc4dc8 net: phy: clean the sfp upstream if phy probing fails
838f411b8ef8 net/mlx4: avoid GCC 10 __bad_copy_from() false positive
ecfe9171b26a tcp: restrict SO_ATTACH_FILTER to priv users
10def23b67b4 ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
7db09011ce62 gpio: mvebu: fix NULL pointer dereference in suspend/resume
07a18f5c90dd netlabel: validate unlabeled address and mask attribute lengths
42827d03f800 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
f4e4b98cee82 iomap: don't revert iov_iter on partially completed buffered writes
fed65bc9de8e arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI
b7d3add1884c arm64: tlb: Allow XZR argument to TLBI ops
523bc49979b9 KVM: arm64: Remove VPIPT I-cache handling
d30aac0fa00c tap: free page on error paths in tap_get_user_xdp()
ceafb893b12f net: skbuff: fix missing zerocopy reference in pskb_carve helpers
9eaa4e8d5561 tools/rv: Fix cleanup after failed trace setup
7fce959e9be3 usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo
36c41e9724c9 usb: gadget: f_ncm: Fix net_device lifecycle with device_move
d68b621bb5a4 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
c12c4cae0cd7 time: Fix off-by-one in settimeofday() usec validation
f4aae11abb44 signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
6e39863cefe4 ipmi: Fix rcu_read_unlock to srcu_read_unlock in handle_read_event_rsp
2afc9e684dc7 sctp: purge outqueue on stale COOKIE-ECHO handling
6d6e42e8e17f net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
1a827b95e62b ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
9db4dd019a6b vxlan: vnifilter: fix spurious notification on VNI update
5a7ad529fd53 vxlan: vnifilter: send notification on VNI add
e4e7428349d9 octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
72775977e89c net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
cecdc6574a82 ptp: vclock: Switch from RCU to SRCU
8ff85dbabbbf ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
ba760c38b38b Bluetooth: MGMT: Fix backward compatibility with userspace
0622e527a31d Bluetooth: fix memory leak in error path of hci_alloc_dev()
691f14b6a48b Bluetooth: bnep: reject short frames before parsing
10e90715e68f Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling
98377e6b1a1a Bluetooth: RFCOMM: validate skb length in MCC handlers
74c08e4db35a Bluetooth: MGMT: validate advertising TLV before type checks
de31973ef00e Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
28a6a3762796 net: fec: fix pinctrl default state restore order on resume
caeb42f28f00 net: lan743x: permit VLAN-tagged packets up to configured MTU
74e02121be1d net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
271355c2ef61 hsr: Remove WARN_ONCE() in hsr_addr_is_self().
91cdbb9b308f net: Annotate sk->sk_write_space() for UDP SOCKMAP.
daf5a9eef894 pcnet32: stop holding device spin lock during napi_complete_done
e732c4444bcf drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
06ce6fc106b1 6lowpan: fix off-by-one in multicast context address compression
8b136f18ac4b net/sched: act_api: use RCU with deferred freeing for action lifecycle
b4892561552d dm cache policy smq: check allocation under invalidate lock
afd64b59c3de netfilter: bridge: make ebt_snat ARP rewrite writable
af80f78ce984 netfilter: nft_ct: bail out on template ct in get eval
7c34f9130529 netfilter: conntrack_irc: fix possible out-of-bounds read
0f8ba5e4c53d netfilter: synproxy: add mutex to guard hook reference counting
c6376b9b1b4d ipvs: clear the svc scheduler ptr early on edit
8122abd4fd92 netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
945a86b21b40 ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
9a0dc9279d09 tee: optee: prevent use-after-free when the client exits before the supplicant
5d27d2ffe487 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
2a613bf49702 ipv6: mcast: Fix use-after-free when processing MLD queries
aa6ef7340169 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
067579d5cf8c Disable -Wattribute-alias for clang-23 and newer
b26849cffaa7 hwmon: (pmbus/core) Protect regulator operations with mutex
d859e53596d1 RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug
7502c1cf303b Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
90dbad14b109 USB: serial: mct_u232: fix memory corruption with small endpoint
f8b8f1d4bb76 bpf: Free reuseport cBPF prog after RCU grace period.
37f488be2a82 usb: core: Fix SuperSpeed root hub wMaxPacketSize
ff3c2b623bfa HID: core: Fix size_t specifier in hid_report_raw_event()
9e36568e67f8 HID: pass the buffer size to hid_report_raw_event
20a816422e98 HID: core: Add printk_ratelimited variants to hid_warn() etc
bb2040484f90 serial: zs: Convert to use a platform device
c9e78361fe92 serial: dz: Convert to use a platform device
5fc2943ad6a1 serial: dz: Fix bootconsole handover lockup
bef9e8bdbc60 xhci: tegra: Fix ghost USB device on dual-role port unplug
8a65db5edd7b USB: serial: digi_acceleport: fix memory corruption with small endpoints
fbf718d5afe2 landlock: Fix handling of disconnected directories
0e96cd314c0d x86/kexec: Disable KCOV instrumentation after load_segments()
a55618c0f4ce Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
4bcaa59f403d USB: serial: cypress_m8: fix memory corruption with small endpoint
36f07474f2b9 serial: zs: Switch to using channel reset
633a33fe1a34 serial: zs: Fix bootconsole handover lockup
6f22119afe53 serial: dz: Fix bootconsole message clobbering at chip reset
a8bd09d3d843 drm/amdkfd: Check for pdd drm file first in CRIU restore path
4e5f808b4541 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
6495cc09f7e6 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
c33322ef3ce5 serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
ea7bdbee9fc3 serial: zs: Fix swapped RI/DSR modem line transition counting
4860f9821baf serial: sh-sci: fix memory region release in error path
70982b7ac673 serial: qcom-geni: fix UART_RX_PAR_EN bit position
3c29f8af029b serial: altera_jtaguart: handle uart_add_one_port() failures
a1b9535768ed drm/amd/pm/si: Disregard vblank time when no displays are connected
28b22dbaf407 drm/i915: Fix potential UAF in TTM object purge
049a6b474823 drm/hyperv: validate VMBus packet size in receive callback
1fb565b77b8f drm/hyperv: validate resolution_count and fix WIN8 fallback
edd06675a023 scsi: target: iscsi: Validate CHAP_R length before base64 decode
4e9f0c4a645c scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
163bd704d751 scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
0e3c6e5a8fc1 scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
5506c825f14d thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
8d4a758b407a thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
e835bf9a055f usb: gadget: f_fs: copy only received bytes on short ep0 read
a183b47fee46 usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
046870ff6b6f usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
5d39924ae38c usb: gadget: f_hid: fix device reference leak in hidg_alloc()
085652fda7f3 usb: gadget: net2280: Fix double free in probe error path
70bb9a2661d3 USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
be3a1ed4ae51 USB: serial: mxuport: fix memory corruption with small endpoint
0bde5431037a USB: serial: keyspan: fix missing indat transfer sanity check
be50533fe706 USB: serial: cypress_m8: validate interrupt packet headers
ffb739a49186 USB: serial: belkin_sa: validate interrupt status length
37a2ac9f5125 USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
5a0e65d56ffd USB: serial: option: add MeiG SRM813Q
17587492179c usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
5de7df75ef3a usb: usbtmc: check URB actual_length for interrupt-IN notifications
a0638db2340e usbip: vudc: Fix use after free bug in vudc_remove due to race condition
02c76e026c06 usb: storage: Add quirks for PNY Elite Portable SSD
aec4d38ac605 USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers
e21f5abf80ad usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
028cc2555eca usb: chipidea: core: convert ci_role_switch to local variable
6dd5c0ea139b tty: serial: pch_uart: add check for dma_alloc_coherent()
68f603bb8622 counter: Fix refcount leak in counter_alloc() error path
9fa854ea4318 comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest()
422af0f9ce0c comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest()
2ad3397f3cc5 Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
e9b62996ba53 Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
0fe08c5776a7 ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
ba451cf21f1d Input: xpad - add support for ASUS ROG RAIKIRI II
6e6de3eba8e4 Input: xpad - add "Nova 2 Lite" from GameSir
322e48187e02 xfrm: esp: restore combined single-frag length gate
d780c61bd2ef ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks
ed4e2ff1ddd1 ASoC: qcom: q6asm-dai: close stream only when running
2bb6d82b586e netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
32aa292fbcb9 xfrm: ah: use skb_to_full_sk in async output callbacks
00f2c451e57d xfrm: route MIGRATE notifications to caller's netns
c4cc6b3b0013 nfc: hci: fix out-of-bounds read in HCP header parsing
1552b979a0b6 iommu, debugobjects: avoid gcc-16.1 section mismatch warnings
ed598de9f615 HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
f1e89a943ee5 ip6: vti: Use ip6_tnl.net in vti6_changelink().
48ce101cd630 xfrm: input: hold netns during deferred transport reinjection
a29768d56eb3 ipv6: validate extension header length before copying to cmsg
1acfb7d9c6fc ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
12d957979e4a ipv6: exthdrs: refresh nh after handling HAO option
f21a9285147a ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params
bddaa4dfc7f3 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
679e13a65e68 macsec: fix replay protection at XPN lower-PN wrap
96b72672ce84 bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
48b0aa9c08a3 Input: elan_i2c - validate firmware size before use
0584af4fe40f usb: dwc2: Fix use after free in debug code
c28bfafa9d70 usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles
96291794d162 usb: cdns3: gadget: fix request skipping after clearing halt
9a3860454bdf USB: serial: omninet: fix memory corruption with small endpoint
29783e6b6ec0 iio: buffer: hw-consumer: fix use-after-free in error path
d291f76e4231 iio: light: cm3323: fix reg_conf not being initialized correctly
d534936cf3ac iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
c43741113cd6 iio: temperature: tsys01: fix broken PROM checksum validation
b5d9befff543 iio: ssp_sensors: cancel delayed work_refresh on remove
31bbd4b87dd6 iio: gyro: itg3200: fix i2c read into the wrong stack location
d434a6abd101 iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
1c375f2c4a7a iio: dac: ad5686: acquire lock when doing powerdown control
99d8feee7560 iio: dac: ad5686: fix input raw value check
9a8fca2af3aa iio: dac: max5821: fix return value check in powerdown sync
baff1f00d8b5 iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
7b9dcbe89d7a wireguard: send: append trailer after expanding head
a452ca80b7ad KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC
c881af73ae98 KVM: arm64: PMU: Preserve AArch32 counter low bits
ecc9635e7501 USB: cdc-acm: Fix bit overlap and move quirk definitions to header
15b1723c1472 parport: Fix race between port and client registration
bcfb4833cd40 Input: xpad - fix out-of-bounds access for Share button
35f68f36d988 Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
119fb6f80c44 Bluetooth: ISO: fix UAF in iso_recv_frame
d313683d6ccd Bluetooth: HIDP: fix missing length checks in hidp_input_report()
63cd225cc13d Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
89dec9204171 Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
8776032fe989 auxdisplay: line-display: fix OOB read on zero-length message_store()
157ce2c6836c ipc: limit next_id allocation to the valid ID range
7c58c55a2a16 hpfs: fix a crash if hpfs_map_dnode_bitmap fails
dcd2b02b095f Bluetooth: btusb: Allow firmware re-download when version matches
4c52e31e9ea6 HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
0cd7b3a15a49 Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
060fca8e0983 media: rc: igorplugusb: fix control request setup packet
9b3145b3001f USB: serial: safe_serial: fix memory corruption with small endpoint
156b6f0aec61 usb: typec: ucsi: validate connector number in ucsi_connector_change()
0af00f1459f5 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
5cd0e7ac4eef usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
70e7045849e9 usb: typec: altmodes/displayport: validate count before reading Status Update VDO
592cbdc644c6 usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
3f432b820306 usb: typec: ucsi: ccg: reject firmware images without a ':' record header
d42ac0bfb6a1 iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
d1c9c79eb06e soc/tegra: pmc: Fix unsafe generic_handle_irq() call
0bb1522d3081 hwmon: (pmbus/adm1266) serialize NVMEM blackbox read with pmbus_lock
96852c116071 hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
7e2476057950 x86/kexec: add a sanity check on previous kernel's ima kexec buffer
566db3370f12 of/kexec: refactor ima_get_kexec_buffer() to use ima_validate_range()
43308106a176 ima: verify the previous kernel's IMA buffer lies in addressable RAM
e1d839efc1e4 phy: mscc: Use PHY_ID_MATCH_EXACT for VSC8584, VSC8582, VSC8575, VSC856X
64858b76ec67 arm64: io: Extract user memory type in ioremap_prot()
4356c4d85050 arm64: io: Rename ioremap_prot() to __ioremap_prot()
05ff52238039 drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line used
45e27857b24e drm/dp: Add eDP 1.5 bit definition
ac7045d3f6d3 drm/i915/psr: Read Intel DPCD workaround register
28557e9deb23 drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register
22ee4010866d inet: frags: flush pending skbs in fqdir_pre_exit()
e0fc5427d6a8 inet: frags: add inet_frag_queue_flush()
711ebd961190 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
f707f53f9ff5 drm/fbdev-helper: Set and clear VGA switcheroo client from fb_info
228cc232079d media: rc: ttusbir: fix inverted error logic
a7becb58f6b8 media: rc: fix race between unregister and urb/irq callbacks
3edb8ebbf79b mm/page_alloc: clear page->private in free_pages_prepare()
a9393751ecf7 batman-adv: bla: avoid double decrement of bla.num_requests
99f17d1cdb37 batman-adv: tt: avoid empty VLAN responses
65a1e67339aa batman-adv: tt: fix TOCTOU race for reported vlans
5bc2d50fb66b batman-adv: tp_meter: directly shut down timer on cleanup
3c19cb8a84ef net: af_key: zero aligned sockaddr tail in PF_KEY exports
100953b5011d batman-adv: tp_meter: avoid role confusion in tp_list
cf12f8881832 batman-adv: iv: recover OGM scheduling after forward packet error
13493b00dd1e batman-adv: tvlv: reject oversized TVLV packets
2a8c9e865291 batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
a5904f2c92b0 batman-adv: tt: reject oversized local TVLV buffers
fcedc98bd03c batman-adv: tvlv: abort OGM send on tvlv append failure
31dcb9711abd batman-adv: v: stop OGMv2 on disabled interface
ae1ada0af162 perf: Fix dangling cgroup pointer in cpuctx
1488367423a6 net: skbuff: fix pskb_carve leaking zcopy pages
c87cd3cb3096 ipv6: fix possible infinite loop in fib6_select_path()
279853aec9f5 ipv6: fix possible infinite loop in rt6_fill_node()
634a9af8a26a sctp: fix race between sctp_wait_for_connect and peeloff
95e414f83243 net: mana: Add NULL guards in teardown path to prevent panic on attach failure
88403b42faa8 gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
6319b38fe69f Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
cc2b4f749de0 Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
97e06791368c ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
65674d2489a1 ethtool: eeprom: add more safeties to EEPROM Netlink fallback
091b58d9a65b ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during fallback
f4d78a81f57d bonding: refuse to enslave CAN devices
b06203ac5f12 Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
5fe860af8630 ASoC: codecs: simple-mux: Fix enum control bounds check
3127a884525d ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE
e917d0c69f01 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
dc3bfa050f87 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
76cd9398a047 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
5165922a8b5c gpio: mxc: fix irq_high handling
a4b64f3e9c7b net: hsr: fix potential OOB access in supervision frame handling
e9e1dbdee16e ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
8e59d4d0dcde ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()
15fb19af49f2 scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
cd691beafea0 net/iucv: fix locking in .getsockopt
ed7a75831301 net/smc: Do not re-initialize smc hashtables
e523bb6d1de3 net: netlink: don't set nsid on local notifications
490a6ef32ab2 net: netlink: fix sending unassigned nsid after assigned one
20f977a75333 vsock: keep poll shutdown state consistent
60d9c0d6cdde tun: free page on build_skb failure in tun_xdp_one()
5b34f9e4fe2f tun: free page on short-frame rejection in tun_xdp_one()
b80ef316e978 netfilter: nf_tables: fix dst corruption in same register operation
ce0712149e21 netfilter: bitwise: add support for doing AND, OR and XOR directly
45cb4821021e netfilter: bitwise: rename some boolean operation functions
a27cb7325a6c netfilter: ebtables: fix OOB read in compat_mtw_from_user
21994d11461b netfilter: xt_cpu: prefer raw_smp_processor_id
af2c22ccb1f6 netfilter: synproxy: refresh tcphdr after skb_ensure_writable
d0cbeaa85b58 nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
fccd685b32df xfrm: Check for underflow in xfrm_state_mtu
ee2d1a8a1833 nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
e00f50f86977 nfc: llcp: Fix use-after-free in llcp_sock_release()
67cca9df4d17 net: cpsw_new: Fix potential unregister of netdev that has not been registered yet
4f33d74ccf69 bcache: fix uninitialized closure object
b4a659bae3b8 drm: Remove plane hsub/vsub alignment requirement for core helpers
6c153d97c100 net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked
963537a26fd8 net: mctp: ensure our nlmsg responses are initialised
5df49f0579f7 net/sched: cls_fw: fix NULL dereference of "old" filters before change()
d883312061cc Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
---
.../linux/linux-yocto-rt_6.6.bb | 6 ++--
.../linux/linux-yocto-tiny_6.6.bb | 6 ++--
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++----------
3 files changed, 20 insertions(+), 20 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index c3200cfd3f..e5a3882efe 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "1ceada58731a98237f70384921758a4df3951960"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index 563598a2bd..ed4b0c67ae 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
# CVE exclusions
include recipes-kernel/linux/cve-exclusion_6.6.inc
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "66e051144e21d531fa26ef67476dfdefbfc119a2"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index 07a06f1852..c682d6ff17 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.6/standard/base"
KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
-SRCREV_machine:qemuarm ?= "d81ffd8843535762fecf5aa5fb2ca7d2c4343038"
-SRCREV_machine:qemuarm64 ?= "1f7f3a52dacadfcc75863f25252a534b06fdaeeb"
-SRCREV_machine:qemuloongarch64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips ?= "4410226fddf113b89cceb26e7ee5ca5bb70c55fb"
-SRCREV_machine:qemuppc ?= "8f8faf1fe9183f295901f8f2b8916ff54f4a4bfb"
-SRCREV_machine:qemuriscv64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemuriscv32 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemux86-64 ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_machine:qemumips64 ?= "14ca63e9f1ce2090e189c16b1024ed3df8f833f0"
-SRCREV_machine ?= "a8a7d078f151a24e01d4501853c88c6b08c9cad9"
-SRCREV_meta ?= "4a6f16d14b76e28ab7615c88e2fbdf95ee15fc98"
+SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
+SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
+SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
+SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
+SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
+SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
+SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "924b4a879cbb75aef37c160b955b92f6894b11a4"
+SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.6/base"
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.142"
+LINUX_VERSION ?= "6.6.143"
PV = "${LINUX_VERSION}+git"
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* [meta][scarthgap][PATCH 02/02] linux-yocto/6.6: update to v6.6.144
2026-07-20 16:00 [meta][scarthgap][PATCH 01/02] linux-yocto/6.6: update to v6.6.143 bruce.ashfield
@ 2026-07-20 16:00 ` bruce.ashfield
0 siblings, 0 replies; 2+ messages in thread
From: bruce.ashfield @ 2026-07-20 16:00 UTC (permalink / raw)
To: richard.purdie; +Cc: openembedded-core
From: Bruce Ashfield <bruce.ashfield@gmail.com>
Updating linux-yocto/6.6 to the latest korg -stable release that comprises
the following commits:
da47cbc254661 Linux 6.6.144
6848a6e39cac4 crypto: qat - remove unused character device and IOCTLs
1a42f84b0f6b5 crypto: qat - Return pointer directly in adf_ctl_alloc_resources
30d648e225447 crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user()
c0b8e6eea1b2b Documentation: ioctl-number: Extend "Include File" column width
802e113cf120d drivers/base/memory: set mem->altmap after successful device registration
511d2b92f8d20 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
851e1847f881e serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
36599894fa853 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
2ef8f2a5695ae NFS: Prevent resource leak in nfs_alloc_server()
6c344fff2feff NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
abc978daffd26 nfsd: check get_user() return when reading princhashlen
1e96239fddcef nfsd: fix posix_acl leak on SETACL decode failure
1e04be34cafae NFSD: Fix SECINFO_NO_NAME decode error cleanup
1a7ee9f9f3957 fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
c7dc382439f7b fbdev: modedb: fix a possible UAF in fb_find_mode()
7640b4f68acb5 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
c04d606f8b35e power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
889c2a9c59897 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
d18756b12aab3 KVM: x86: hyper-v: Bound the bank index when querying sparse banks
b84f46179c806 9p: avoid putting oldfid in p9_client_walk() error path
c5a125eadba05 ocfs2: reject oversized group bitmap descriptors
ddf13f91ca82c rpmsg: char: Fix use-after-free on probe error path
fbaf509ad7cb2 fpga: region: fix use-after-free in child_regions_with_firmware()
44567537a2623 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
7e37e9b3e82ad pNFS: Fix use-after-free in pnfs_update_layout()
eaca7dae02fab tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
96e545410c4f7 blk-cgroup: fix UAF in __blkcg_rstat_flush()
508a0139d3bf6 hdlc_ppp: sync per-proto timers before freeing hdlc state
4fe388218826d gfs2: fix use-after-free in gfs2_qd_dealloc
8e0abc17fbd7e exfat: fix potential use-after-free in exfat_find_dir_entry()
ab465495b1ed5 MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
81fc9a13acae9 bpf: use kvfree() for replaced sysctl write buffer
fda128096fc84 f2fs: keep atomic write retry from zeroing original data
7e4d8f98be63f f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
1ddf3fd21c4c6 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
24f8c87070c3e f2fs: fix to round down start offset of fallocate for pin file
13e4b59d3a941 f2fs: validate compress cache inode only when enabled
bd499f138ccf7 wifi: iwlwifi: mvm: fix race condition in PTP removal
2b2060c2075a7 wifi: rtw88: usb: fix memory leaks on USB write failures
6579dcb5e0f74 wifi: rtw88: increase TX report timeout to fix race condition
16eef2a52687b wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
318703b6f71d1 wifi: ath11k: fix warning when unbinding
a2e631fa91bb2 wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
35ab4db86774d keys: Pin request_key_auth payload in instantiate paths
5966e4e2ba213 KEYS: fix overflow in keyctl_pkey_params_get_2()
03ef56495f0be err.h: use __always_inline on all error pointer helpers
5267eab88fa4c fbdev: fix use-after-free in store_modes()
06f6dd2ff2bd0 NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
15fd83a1e42ed apparmor: fix use-after-free in rawdata dedup loop
faea60deaa05c apparmor: mediate the implicit connect of TCP fast open sendmsg
0eb4c16c4adb2 net: skmsg: preserve sg.copy across SG transforms
e28e7fd34c449 mac802154: llsec: add skb_cow_data() before in-place crypto
82c17e13d404f af_unix: Set gc_in_progress to true in unix_gc().
5f0b95ef68ab9 nvmet-tcp: fix race between ICReq handling and queue teardown
e8852ae29868e ntfs3: reject direct userspace writes to reserved $LX* xattrs
ce494707a9c07 ipv4: account for fraggap on the paged allocation path
f79f0db614160 inet: add indirect call wrapper for getfrag() calls
65fb14cbebb0c ipv6: account for fraggap on the paged allocation path
2660bd8333ab6 batman-adv: tvlv: avoid race of cifsnotfound handler state
9c9f4e69368a4 batman-adv: tvlv: enforce 2-byte alignment
d7fdbab25eae6 batman-adv: dat: prevent false sharing between VLANs
a8da361cdd929 batman-adv: tt: track roam count per VID
e82a02a0c1aa2 batman-adv: tt: don't merge change entries with different VIDs
0e868200cf042 batman-adv: tp_meter: handle overlapping packets
31dec4dc86cf6 batman-adv: tp_meter: prevent parallel modifications of last_recv
be3af0c705a13 batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
f8c499fd275e5 batman-adv: tp_meter: restrict number of unacked list entries
97644fdaaf644 batman-adv: v: prevent OGM aggregation on disabled hardif
3af7f10d5fe44 batman-adv: frag: avoid underflow of TTL
cb96aa1737200 batman-adv: frag: ensure fragment is writable before modifying TTL
5263ff0bbd132 batman-adv: fix (m|b)cast csum after decrementing TTL
4741001ca0b04 batman-adv: ensure bcast is writable before modifying TTL
29f59324e61fc batman-adv: tp_meter: initialize last_recv_time during init
b88f8f4e5e78e batman-adv: prevent ELP transmission interval underflow
b5cf66cdc49b1 batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
75445cf501ac7 batman-adv: tp_meter: add only finished tp_vars to lists
4774a32baec46 batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
ec8ef37fea33c batman-adv: tp_meter: fix fast recovery precondition
cd74176cf1685 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
f58e5df92180e batman-adv: tp_meter: avoid window underflow
774d22045a8fa batman-adv: tp_meter: initialize dec_cwnd explicitly
0c610db91bbde batman-adv: tp_meter: initialize dup_acks explicitly
edae04afb11f6 batman-adv: tp_meter: keep unacked list in ascending ordered
bc6c380c1159d selinux: fix overlayfs mmap() and mprotect() access checks
41c5b269af8b1 lsm: add backing_file LSM hooks
ba3ebdd89fa20 fs: prepare for adding LSM blob to backing_file
922a03b26e354 Bluetooth: btmtk: accept too short WMT FUNC_CTRL events
36c85f7029484 Bluetooth: btmtk: validate WMT event SKB length before struct access
7536ebe0473d9 Revert "ptp: add testptp mask test"
48b91ed7e22bb KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
9291654d69e08 KVM: x86: Fix shadow paging use-after-free due to unexpected role
2de4db145b299 eventpoll: fix ep_remove struct eventpoll / struct file UAF
a0e685da1efe0 eventpoll: move epi_fget() up
20423e2c1c84a eventpoll: rename ep_remove_safe() back to ep_remove()
0a4a2db528b0e eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}()
f484ab90b2290 eventpoll: kill __ep_remove()
903070f8f3552 eventpoll: split __ep_remove()
ff4fe83a9aabb eventpoll: use hlist_is_singular_node() in __ep_remove()
44e8907b81fea file: add fput() cleanup helper
2181a09ba980f virtiofs: fix UAF on submount umount
cd923dadefadb media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
d2bbbb6c55812 ksmbd: reject non-VALID session in compound request branch
8232fca738011 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
08fbcba06e968 scripts/sorttable: Fix endianness handling in build-time mcount sort
80514e97c50ab scripts/sorttable: Allow matches to functions before function entry
9ba53f9808e1e scripts/sorttable: Use normal sort if theres no relocs in the mcount section
e115e9fa69b48 ftrace: Check against is_kernel_text() instead of kaslr_offset()
379e755ec2c54 ftrace: Test mcount_loc addr before calling ftrace_call_addr()
bf802b936a7b2 ftrace: Do not over-allocate ftrace memory
4c30b173b6176 ftrace: Have ftrace pages output reflect freed pages
dc06779d338de ftrace: Update the mcount_loc check of skipped entries
4893af6318fe8 scripts/sorttable: Zero out weak functions in mcount_loc table
bbfbacec9e000 scripts/sorttable: Always use an array for the mcount_loc sorting
38be2ffe9808b scripts/sorttable: Have mcount rela sort use direct values
fe0434d604a94 arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64
8297f13962063 scripts/sorttable: Use a structure of function pointers for elf helpers
ff7e015d63849 scripts/sorttable: Get start/stop_mcount_loc from ELF file directly
ecbb09356560c scripts/sorttable: Move code from sorttable.h into sorttable.c
7fbddce9a2685 scripts/sorttable: Use uint64_t for mcount sorting
23b5a9659a27d scripts/sorttable: Add helper functions for Elf_Sym
8cd6caaa4a244 scripts/sorttable: Add helper functions for Elf_Shdr
a03240485cf57 scripts/sorttable: Add helper functions for Elf_Ehdr
1dd7def1ae877 scripts/sorttable: Convert Elf_Sym MACRO over to a union
1afca399cc4d5 scripts/sorttable: Replace Elf_Shdr Macro with a union
7ce5ed40d976e scripts/sorttable: Convert Elf_Ehdr to union
e6bb2482b5b17 scripts/sorttable: Make compare_extable() into two functions
d5e14532a8b86 scripts/sorttable: Have the ORC code use the _r() functions to read
4f2fba2de0620 scripts/sorttable: Remove unneeded Elf_Rel
c13a4c1fd1b74 scripts/sorttable: Remove unused write functions
d9e259e63b36b scripts/sorttable: Remove unused macro defines
030fe3e9d8abd fuse: re-lock request before replacing page cache folio
fe95e90559bce slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
e65ae7c948640 slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
5d1ae4e17a3ec rxrpc: Fix the ACK parser to extract the SACK table for parsing
09c9b92c20104 net: phonet: free phonet_device after RCU grace period
210ac54bdd8df phonet: Pass net and ifindex to phonet_address_notify().
cf30797ea8cea phonet: Pass ifindex to fill_addr().
6707d7e0b7174 locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
67fde21e4522e Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
5df8310a41391 hv: utils: handle and propagate errors in kvp_register
23e5a1b9ae954 mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
4830fb44d12f5 netfilter: nf_tables: always walk all pending catchall elements
7109d69bec6ed dlm: prevent NPD when writing a positive value to event_done
c84860dac7af7 regulator: core: fix locking in regulator_resolve_supply() error path
c2716362ec335 ring-buffer: Remove ring_buffer_read_prepare_sync()
f155b8f1c9576 selftests/bpf: Update comments find_equal_scalars->sync_linked_regs
8e655dbef4c9e selftests/bpf: Tests for per-insn sync_linked_regs() precision tracking
78da8e1be90c5 bpf: Remove mark_precise_scalar_ids()
0252b9d262222 bpf: Track equal scalars history on per-instruction level
b741c9c6ef59f af_unix: Reject SIOCATMARK on non-stream sockets
f68f34033d403 selftests/bpf: Add test to ensure kprobe_multi is not sleepable
89327ed787746 bpf: Reject sleepable kprobe_multi programs at attach time
eb045714bc6a2 agp/amd64: Fix broken error propagation in agp_amd64_probe()
1078ae8175777 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
1c4ffe6b4f043 i2c: stub: Reject I2C block transfers with invalid length
c19b360fa10c5 RDMA/bnxt_re: zero shared page before exposing to userspace
218c24bfc3334 KVM: VMX: Update SVI during runtime APICv activation
de1ba6c93868f ARM: fix branch predictor hardening
1f7cc85046f1c ARM: fix hash_name() fault
98b209cd62ef9 ARM: allow __do_kernel_fault() to report execution of memory faults
89b37df6f805f ARM: group is_permission_fault() with is_translation_fault()
5d95f6b267f3d debugobjects: Dont call fill_pool() in early boot hardirq context
a3383df76f0d7 debugobjects: Do not fill_pool() if pi_blocked_on
c8cd2ca8f085c debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
0d2a64411b097 debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
40fe77146137b batman-adv: tt: prevent TVLV entry number overflow
abb069fdf51a9 drm/v3d: Skip CSD when it has zeroed workgroups
756724002c5a6 drm/v3d: Store the active job inside the queue's state
f4b6b4af7ef06 ip6_vti: set netns_immutable on the fallback device.
499c6b43a79dd drm/amd/display: Bound VBIOS record-chain walk loops
b685d6ef6f07a net/sched: fix pedit partial COW leading to page cache corruption
8bef2f840b43e fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
---
.../linux/linux-yocto-rt_6.6.bb | 6 ++--
.../linux/linux-yocto-tiny_6.6.bb | 6 ++--
meta/recipes-kernel/linux/linux-yocto_6.6.bb | 28 +++++++++----------
3 files changed, 20 insertions(+), 20 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
index e5a3882efe..cb8d8c418f 100644
--- a/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.6.bb
@@ -14,13 +14,13 @@ python () {
raise bb.parse.SkipRecipe("Set PREFERRED_PROVIDER_virtual/kernel to linux-yocto-rt to enable it")
}
-SRCREV_machine ?= "fcddef60733f35eb43e4f8d5c7fd23d1c5bc4b24"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "d7fbdb4e5e7a35bdb8bb87d159204d74ef130a32"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;branch=${KBRANCH};name=machine;protocol=https \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
index ed4b0c67ae..73d971f7ee 100644
--- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.6.bb
@@ -8,7 +8,7 @@ require recipes-kernel/linux/linux-yocto.inc
# CVE exclusions
include recipes-kernel/linux/cve-exclusion_6.6.inc
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
DEPENDS += "${@bb.utils.contains('ARCH', 'x86', 'elfutils-native', '', d)}"
@@ -17,8 +17,8 @@ DEPENDS += "openssl-native util-linux-native"
KMETA = "kernel-meta"
KCONF_BSP_AUDIT_LEVEL = "2"
-SRCREV_machine ?= "14b1b02cc139bf807405c9ad97a799a1dbfc0e4d"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine ?= "25b07b85b558f3587c11c9363cccd9cb93fcef45"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
PV = "${LINUX_VERSION}+git"
diff --git a/meta/recipes-kernel/linux/linux-yocto_6.6.bb b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
index c682d6ff17..64609554ee 100644
--- a/meta/recipes-kernel/linux/linux-yocto_6.6.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_6.6.bb
@@ -18,25 +18,25 @@ KBRANCH:qemux86-64 ?= "v6.6/standard/base"
KBRANCH:qemuloongarch64 ?= "v6.6/standard/base"
KBRANCH:qemumips64 ?= "v6.6/standard/mti-malta64"
-SRCREV_machine:qemuarm ?= "900d4f2a9c0cd33b2f32053ea438c709ca4fc69c"
-SRCREV_machine:qemuarm64 ?= "5f9c75b34f19ebfb1ac2cf26b0cdf1e637b0a67b"
-SRCREV_machine:qemuloongarch64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips ?= "d066c05c4207d69ff781175fbd4544af3a57a6e4"
-SRCREV_machine:qemuppc ?= "c9444b37f0f19f6f7186e4936f940b2e29cef806"
-SRCREV_machine:qemuriscv64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemuriscv32 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemux86-64 ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_machine:qemumips64 ?= "4c96d4f0d9ae5848015aa021c683bc1c68b596ee"
-SRCREV_machine ?= "d7c355e593fea6abba6099c009d0b4ec566ffba1"
-SRCREV_meta ?= "b32016757524151fa9577e2c13b2fcc0355a076f"
+SRCREV_machine:qemuarm ?= "3adc19c1e1e3ee865f9b0d7bc0fedd0e4aeee995"
+SRCREV_machine:qemuarm64 ?= "39a4fe09d3d795042cc14eb3c78f6a03874c48df"
+SRCREV_machine:qemuloongarch64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips ?= "ba0b8f925ec8b5926c6c2ddbc2c2c77305324bab"
+SRCREV_machine:qemuppc ?= "66c01b44545110249c940f865c4ed10d4d315b29"
+SRCREV_machine:qemuriscv64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemuriscv32 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemux86-64 ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_machine:qemumips64 ?= "1793417d6568e244579278e6f1fc7107987946f5"
+SRCREV_machine ?= "2baf8e92ef6ad38945005adf39342b9efb4509ec"
+SRCREV_meta ?= "a77e1b965423603456f2d9dbf3de53bb8a3d75af"
# set your preferred provider of linux-yocto to 'linux-yocto-upstream', and you'll
# get the <version>/base branch, which is pure upstream -stable, and the same
# meta SRCREV as the linux-yocto-standard builds. Select your version using the
# normal PREFERRED_VERSION settings.
BBCLASSEXTEND = "devupstream:target"
-SRCREV_machine:class-devupstream ?= "d1cfde2d5d15be14123bdd1689162bd27f995a90"
+SRCREV_machine:class-devupstream ?= "da47cbc254661aa66d61ef061485a7080305c4be"
PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v6.6/base"
@@ -44,7 +44,7 @@ SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRA
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-6.6;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
-LINUX_VERSION ?= "6.6.143"
+LINUX_VERSION ?= "6.6.144"
PV = "${LINUX_VERSION}+git"
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-20 16:01 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-20 16:00 [meta][scarthgap][PATCH 01/02] linux-yocto/6.6: update to v6.6.143 bruce.ashfield
2026-07-20 16:00 ` [meta][scarthgap][PATCH 02/02] linux-yocto/6.6: update to v6.6.144 bruce.ashfield
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox