stable.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
 messages from 2026-09-12 13:28:15 to 2026-09-12 13:44:30 UTC [more...]

[PATCH 6.6 0000/1424] 6.6.157-rc1 review
 2026-09-12  6:44 UTC  (200+ messages)
` [PATCH 6.6 0006/1424] ALSA: aloop: Fix racy access at PCM trigger
` [PATCH 6.6 0007/1424] ALSA: aloop: Fix peer runtime UAF during format-change stop
` [PATCH 6.6 0008/1424] perf/x86/intel/uncore: Fix die ID init and look up bugs
` [PATCH 6.6 0009/1424] alpha: fix ieee_swcr_to_fpcr setting FPCR_DNOD unconditionally
` [PATCH 6.6 0023/1424] tracing: Fix crash passing ERR_PTR to kthread_stop()
` [PATCH 6.6 0024/1424] tracing: Fix use-after-free with same-name named triggers
` [PATCH 6.6 0025/1424] device property: fix infinite loop in fwnode_for_each_child_node()
` [PATCH 6.6 0026/1424] powerpc/powermac: fix OF node refcount
` [PATCH 6.6 0027/1424] rapidio: mport_cdev: fix use-after-free in dma_req_free()
` [PATCH 6.6 0028/1424] Revert "media: v4l2-dev: fix error handling in __video_register_device()"
` [PATCH 6.6 0029/1424] staging: greybus: hid: fix SET_REPORT return value
` [PATCH 6.6 0030/1424] usb: dwc2: gadget: Exit partial power down state when changing USB pull-up
` [PATCH 6.6 0031/1424] USB: phy: fsl-usb: fix missing static keywords
` [PATCH 6.6 0032/1424] usb: gadget: u_audio: Fix use-after-free on sound card disconnect
` [PATCH 6.6 0033/1424] usb: gadget: snps_udc_plat: clean up PHY on probe deferral
` [PATCH 6.6 0034/1424] usb: gadget: midi2: remove default configfs groups on teardown
` [PATCH 6.6 0035/1424] usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
` [PATCH 6.6 0036/1424] usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()
` [PATCH 6.6 0037/1424] usb: gadget: f_fs: Prevent deadlock during ep0 read loop
` [PATCH 6.6 0038/1424] fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
` [PATCH 6.6 0039/1424] HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
` [PATCH 6.6 0040/1424] lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen()
` [PATCH 6.6 0041/1424] media: cec: stm32: prevent out-of-bounds write on RX overflow
` [PATCH 6.6 0042/1424] media: vicodec: fix out-of-bounds write in FWHT encoder
` [PATCH 6.6 0043/1424] nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation
` [PATCH 6.6 0044/1424] of: fix out-of-bounds read in of_alias_scan() stem parser
` [PATCH 6.6 0045/1424] ubifs: fix out-of-bounds read in signature length check
` [PATCH 6.6 0046/1424] NFSD: Encode only the status in NFS-ACL v2 GETACL error replies
` [PATCH 6.6 0047/1424] NFSD: Fix off-by-one in DRC bucket pruning limit
` [PATCH 6.6 0048/1424] NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock
` [PATCH 6.6 0049/1424] NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
` [PATCH 6.6 0050/1424] NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
` [PATCH 6.6 0051/1424] nfsd: release path refs on follow_down() error
` [PATCH 6.6 0052/1424] nfsd: Reset write verifier when async COPY writeback fails
` [PATCH 6.6 0053/1424] nfsd: return NFS4ERR_NOTSUPP for unsupported netloc4 types
` [PATCH 6.6 0054/1424] nfsd: sample writeback error cursor before async COPY loop
` [PATCH 6.6 0055/1424] nfsd: validate symlink target length in NFSv4 CREATE
` [PATCH 6.6 0056/1424] nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
` [PATCH 6.6 0057/1424] nfsd: add filehandle match check to nfsd4_delegreturn()
` [PATCH 6.6 0058/1424] nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
` [PATCH 6.6 0059/1424] nfsd: check client ownership when cancelling a copy-notify stateid
` [PATCH 6.6 0060/1424] nfsd: fix cpntf publish race in nfs4_init_cp_state
` [PATCH 6.6 0061/1424] nfsd: fix version mismatch loops in nfsd_acl_init_request()
` [PATCH 6.6 0062/1424] nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
` [PATCH 6.6 0063/1424] nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
` [PATCH 6.6 0064/1424] nfsd: gate nfs2 setacl by argp->mask
` [PATCH 6.6 0065/1424] nfsd: gate nfs3 "
` [PATCH 6.6 0066/1424] nfsd: initialize copy-notify stateid before publishing it
` [PATCH 6.6 0067/1424] nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
` [PATCH 6.6 0068/1424] nfsd: reject reclaim LOCK after RECLAIM_COMPLETE
` [PATCH 6.6 0069/1424] nfsd: revoke copy-notify stateids before dropping their reference
` [PATCH 6.6 0070/1424] NFSD: Prevent lock owner use-after-free during client teardown
` [PATCH 6.6 0071/1424] libceph: validate OSD extent maps before cursor advance
` [PATCH 6.6 0072/1424] libceph: reject buckets with mismatched CRUSH ids
` [PATCH 6.6 0073/1424] ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
` [PATCH 6.6 0074/1424] ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
` [PATCH 6.6 0075/1424] ceph: bound copied dentry name length in NFS export get_name
` [PATCH 6.6 0076/1424] ceph: bound num_export_targets array for mds info v2/v3
` [PATCH 6.6 0077/1424] ceph: bound xattr value length in __build_xattrs()
` [PATCH 6.6 0078/1424] audit: avoid dropping live tree ref on fsnotify rule autoremove
` [PATCH 6.6 0079/1424] cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
` [PATCH 6.6 0080/1424] smb: client: clear ce->tgthint in free_tgts()
` [PATCH 6.6 0081/1424] smb: client: fix ALIGN() overflow in symlink_data() error context loop
` [PATCH 6.6 0082/1424] smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
` [PATCH 6.6 0083/1424] smb: client: harden DFS cache against invalid target hints
` [PATCH 6.6 0084/1424] HID: picolcd: clamp eeprom debugfs read to bytes actually received
` [PATCH 6.6 0085/1424] HID: roccat: free buffered reports when destroying device
` [PATCH 6.6 0086/1424] HID: sensor: custom: Fix field sysfs group cleanup on failure
` [PATCH 6.6 0087/1424] HID: mcp2221: stop device IO before hid_hw_stop
` [PATCH 6.6 0088/1424] HID: mcp2221: validate report size in mcp2221_raw_event()
` [PATCH 6.6 0089/1424] eventfs: Initialize ei->children and ei->list in init_ei()
` [PATCH 6.6 0090/1424] fs/ntfs3: validate dirty page table on log replay
` [PATCH 6.6 0091/1424] fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
` [PATCH 6.6 0092/1424] fs/ntfs3: bound page_lcns[] index by the log record
` [PATCH 6.6 0093/1424] eCryptfs: bound the packet-length peek to the user buffer
` [PATCH 6.6 0094/1424] ecryptfs: fix tag 11 packet exact-fit size check
` [PATCH 6.6 0095/1424] ecryptfs: hold msg ctx list lock when cleaning daemon queue
` [PATCH 6.6 0096/1424] ecryptfs: pass packet set buffer size to parser
` [PATCH 6.6 0097/1424] ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
` [PATCH 6.6 0098/1424] ecryptfs: reject too-small tag 70 packets
` [PATCH 6.6 0099/1424] ecryptfs: release message context on send failure
` [PATCH 6.6 0100/1424] ecryptfs: show filename encryption options
` [PATCH 6.6 0101/1424] efivarfs: Rate limit statfs() handler
` [PATCH 6.6 0102/1424] fat: restore original value when fat_ent_write failed
` [PATCH 6.6 0103/1424] fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
` [PATCH 6.6 0104/1424] fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
` [PATCH 6.6 0105/1424] fbdev: ssd1307fb: defer I2C transfers from damage callbacks
` [PATCH 6.6 0106/1424] fbdev: uvesafb: unregister connector callback on init failure
` [PATCH 6.6 0107/1424] forcedeth: fix off-by-one when saving/restoring non-PCI config space
` [PATCH 6.6 0108/1424] fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
` [PATCH 6.6 0109/1424] hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
` [PATCH 6.6 0110/1424] ACPI: pfr_update: fix stack buffer overflow in query_capability()
` [PATCH 6.6 0111/1424] alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
` [PATCH 6.6 0112/1424] alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
` [PATCH 6.6 0113/1424] alpha: marvel: Fix lock ordering in init_io7_irqs()
` [PATCH 6.6 0114/1424] ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
` [PATCH 6.6 0115/1424] ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
` [PATCH 6.6 0116/1424] auxdisplay: charlcd: cancel backlight work on registration failure
` [PATCH 6.6 0117/1424] block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
` [PATCH 6.6 0118/1424] Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
` [PATCH 6.6 0119/1424] Bluetooth: btusb: Add ASUS USB-BT600 "
` [PATCH 6.6 0120/1424] Bluetooth: eir: Fix OOB read in eir_get_service_data()
` [PATCH 6.6 0121/1424] bnx2x: fix double free in bnx2x_init_firmware() error path
` [PATCH 6.6 0122/1424] bpf: Harden bloom filter sizing and indexing on 32-bit kernels
` [PATCH 6.6 0123/1424] dm-era: fix shadowed superblock leak on take-snap failure
` [PATCH 6.6 0124/1424] dm raid1: reserve space for NUL-terminator in build_constructor_string()
` [PATCH 6.6 0125/1424] dm array: reject an array block whose value size is not the callers
` [PATCH 6.6 0126/1424] cpufreq: schedutil: Fix rate limit overflow
` [PATCH 6.6 0127/1424] cxl/pmem: Format the nvdimm serial number as unsigned decimal
` [PATCH 6.6 0128/1424] Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
` [PATCH 6.6 0129/1424] Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
` [PATCH 6.6 0130/1424] Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
` [PATCH 6.6 0131/1424] Bluetooth: RFCOMM: serialize security confirmation handling
` [PATCH 6.6 0132/1424] Bluetooth: hci_conn: re-enable advertising only for peripheral role
` [PATCH 6.6 0133/1424] Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
` [PATCH 6.6 0134/1424] Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
` [PATCH 6.6 0135/1424] Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
` [PATCH 6.6 0136/1424] Bluetooth: hci_intel: "
` [PATCH 6.6 0137/1424] Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
` [PATCH 6.6 0138/1424] kasan: fix cache shrink race with CPU hotplug
` [PATCH 6.6 0139/1424] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
` [PATCH 6.6 0140/1424] ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
` [PATCH 6.6 0141/1424] ip6_gre: fix hardware header length for NBMA tunnels
` [PATCH 6.6 0142/1424] ipv6: use RCU iterator to dump route exceptions
` [PATCH 6.6 0143/1424] libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
` [PATCH 6.6 0144/1424] mailbox: qcom-ipcc: fix duplicate channel allocation across holes
` [PATCH 6.6 0145/1424] md: do overflow check for sb->bblog_shift in super_1_load()
` [PATCH 6.6 0146/1424] mpls: reload header after pskb_may_pull()
` [PATCH 6.6 0147/1424] mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
` [PATCH 6.6 0148/1424] nouveau/gem: reserve the bo in the info ioctl around the vma lookup
` [PATCH 6.6 0149/1424] SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
` [PATCH 6.6 0150/1424] SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
` [PATCH 6.6 0151/1424] SUNRPC: svcauth_gss: enforce krb5 token minimum length
` [PATCH 6.6 0152/1424] sunrpc: route to a populated pool in svc_pool_for_cpu()
` [PATCH 6.6 0153/1424] SUNRPC: always drain cache_cleaner before destroying a cache_detail
` [PATCH 6.6 0154/1424] SUNRPC: Check svc pool percpu counter allocation
` [PATCH 6.6 0155/1424] SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
` [PATCH 6.6 0156/1424] SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
` [PATCH 6.6 0157/1424] SUNRPC: harden gss_unwrap_resp_priv length checks
` [PATCH 6.6 0158/1424] sunrpc: init gssp_lock before publishing proc entry
` [PATCH 6.6 0159/1424] SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
` [PATCH 6.6 0160/1424] SUNRPC: wait for in-flight client TLS handshake callback
` [PATCH 6.6 0161/1424] svcrdma: Fix offset arithmetic in read_chunk_range
` [PATCH 6.6 0162/1424] svcrdma: Fix pcl_for_each_segment for empty chunks
` [PATCH 6.6 0163/1424] udf: reject VAT indexes equal to the entry count
` [PATCH 6.6 0164/1424] wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
` [PATCH 6.6 0165/1424] staging: media: tegra-video: fix of_node_put() on VIP parse errors
` [PATCH 6.6 0166/1424] staging: media: tegra-video: vi: fix probe failure on skipped last port
` [PATCH 6.6 0167/1424] rpmsg: glink: smem: order FIFO read after availability check
` [PATCH 6.6 0168/1424] arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
` [PATCH 6.6 0169/1424] arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
` [PATCH 6.6 0170/1424] remoteproc: scp: Fix device reference leak on failed lookup
` [PATCH 6.6 0171/1424] qede: Fix NULL pointer dereference in TPA fragment processing
` [PATCH 6.6 0172/1424] RDMA/cxgb4: Cancel reg_work before freeing device on remove
` [PATCH 6.6 0173/1424] RDMA/ucma: Lock the handler in ucma_set_ib_path()
` [PATCH 6.6 0174/1424] regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
` [PATCH 6.6 0175/1424] regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
` [PATCH 6.6 0176/1424] regulator: qcom-refgen: correct the regulator type to CURRENT
` [PATCH 6.6 0177/1424] orangefs: fix double-free of trailer_buf on readdir copy failure
` [PATCH 6.6 0178/1424] orangefs: skip leading spaces before parsing client debug masks
` [PATCH 6.6 0179/1424] ocfs2: always run deallocs on copy-on-write completion
` [PATCH 6.6 0180/1424] ocfs2: bound namelen in dlm_migrate_request_handler
` [PATCH 6.6 0181/1424] ocfs2: validate lengths in dlm_mig_lockres_handler
` [PATCH 6.6 0182/1424] ocfs2: validate rl_used against rl_count in refcount block validator
` [PATCH 6.6 0183/1424] ocfs2: cluster: dont sleep while holding o2hb_live_lock in o2hb_region_pin()
` [PATCH 6.6 0184/1424] ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
` [PATCH 6.6 0185/1424] ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
` [PATCH 6.6 0186/1424] ocfs2: fix readdir position truncation on 32-bit kernels
` [PATCH 6.6 0187/1424] openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
` [PATCH 6.6 0188/1424] openvswitch: only skb_tx_error() a packet we are about to drop
` [PATCH 6.6 0189/1424] ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
` [PATCH 6.6 0190/1424] arm64: compat: Fix decrementing LDM/STM alignment emulation
` [PATCH 6.6 0191/1424] ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
` [PATCH 6.6 0192/1424] hwmon: (max6621) fix negative temperature offset and crit readings
` [PATCH 6.6 0193/1424] hwmon: (max6621) fix temperature clamp range
` [PATCH 6.6 0194/1424] lockd: pin next file across nlm_inspect_file lock-drop
` [PATCH 6.6 0195/1424] nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
` [PATCH 6.6 0196/1424] nvme: zero the discard fallback page
` [PATCH 6.6 0197/1424] nvme-pci: disable controller on admin queue IRQ setup failure
` [PATCH 6.6 0198/1424] nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
` [PATCH 6.6 0199/1424] nvme-tcp: fix host memory disclosure on R2T for a read command
` [PATCH 6.6 0200/1424] nvme-tcp: reject a read that transferred too few bytes
` [PATCH 6.6 0201/1424] sctp: stop processing a packet once its association is deleted
` [PATCH 6.6 0202/1424] sctp: drop a chunk if its transport was removed
` [PATCH 6.6 0203/1424] sctp: fix NULL deref on untransmitted RECONF completion
` [PATCH 6.6 0204/1424] sctp: distinguish sequence zero from wildcard in reconf lookup
` [PATCH 6.6 0205/1424] sctp: fix stream->outcnt underflow on duplicate RECONF responses
` [PATCH 6.6 0207/1424] power: supply: bq256xx: drain usb_work before freeing the charger
` [PATCH 6.6 0208/1424] power: supply: bq25890: Fix power_supply reference leak
` [PATCH 6.6 0216/1424] power: supply: max17040: drop incorrect I2C functionality check
` [PATCH 6.6 0217/1424] power: supply: max17040: synchronize work cancellation on suspend
` [PATCH 6.6 0218/1424] s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
` [PATCH 6.6 0219/1424] s390/dasd: Do not complete a failed ESE read as successful
` [PATCH 6.6 0220/1424] s390/dasd: Guard sysfs discipline callbacks against unallocated private data
` [PATCH 6.6 0221/1424] s390/dasd: Propagate partial completion length across ERP recovery
` [PATCH 6.6 0222/1424] PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
` [PATCH 6.6 0223/1424] PCI: meson: Fix GPIO state while requesting PERST#
` [PATCH 6.6 0224/1424] PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
` [PATCH 6.6 0225/1424] PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).