stable.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
 messages from 2026-09-12 13:32:18 to 2026-09-12 13:48:26 UTC [more...]

[PATCH 6.6 0000/1424] 6.6.157-rc1 review
 2026-09-12  6:45 UTC  (201+ messages)
` [PATCH 6.6 0023/1424] tracing: Fix crash passing ERR_PTR to kthread_stop()
` [PATCH 6.6 0032/1424] usb: gadget: u_audio: Fix use-after-free on sound card disconnect
` [PATCH 6.6 0069/1424] nfsd: revoke copy-notify stateids before dropping their reference
` [PATCH 6.6 0070/1424] NFSD: Prevent lock owner use-after-free during client teardown
` [PATCH 6.6 0071/1424] libceph: validate OSD extent maps before cursor advance
` [PATCH 6.6 0072/1424] libceph: reject buckets with mismatched CRUSH ids
` [PATCH 6.6 0073/1424] ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
` [PATCH 6.6 0074/1424] ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
` [PATCH 6.6 0075/1424] ceph: bound copied dentry name length in NFS export get_name
` [PATCH 6.6 0076/1424] ceph: bound num_export_targets array for mds info v2/v3
` [PATCH 6.6 0077/1424] ceph: bound xattr value length in __build_xattrs()
` [PATCH 6.6 0078/1424] audit: avoid dropping live tree ref on fsnotify rule autoremove
` [PATCH 6.6 0079/1424] cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
` [PATCH 6.6 0080/1424] smb: client: clear ce->tgthint in free_tgts()
` [PATCH 6.6 0081/1424] smb: client: fix ALIGN() overflow in symlink_data() error context loop
` [PATCH 6.6 0082/1424] smb: client: fix copy-paste error in WSL EA length accounting for $LXDEV
` [PATCH 6.6 0083/1424] smb: client: harden DFS cache against invalid target hints
` [PATCH 6.6 0084/1424] HID: picolcd: clamp eeprom debugfs read to bytes actually received
` [PATCH 6.6 0085/1424] HID: roccat: free buffered reports when destroying device
` [PATCH 6.6 0086/1424] HID: sensor: custom: Fix field sysfs group cleanup on failure
` [PATCH 6.6 0087/1424] HID: mcp2221: stop device IO before hid_hw_stop
` [PATCH 6.6 0088/1424] HID: mcp2221: validate report size in mcp2221_raw_event()
` [PATCH 6.6 0089/1424] eventfs: Initialize ei->children and ei->list in init_ei()
` [PATCH 6.6 0090/1424] fs/ntfs3: validate dirty page table on log replay
` [PATCH 6.6 0091/1424] fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
` [PATCH 6.6 0092/1424] fs/ntfs3: bound page_lcns[] index by the log record
` [PATCH 6.6 0093/1424] eCryptfs: bound the packet-length peek to the user buffer
` [PATCH 6.6 0094/1424] ecryptfs: fix tag 11 packet exact-fit size check
` [PATCH 6.6 0095/1424] ecryptfs: hold msg ctx list lock when cleaning daemon queue
` [PATCH 6.6 0096/1424] ecryptfs: pass packet set buffer size to parser
` [PATCH 6.6 0097/1424] ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
` [PATCH 6.6 0098/1424] ecryptfs: reject too-small tag 70 packets
` [PATCH 6.6 0099/1424] ecryptfs: release message context on send failure
` [PATCH 6.6 0100/1424] ecryptfs: show filename encryption options
` [PATCH 6.6 0101/1424] efivarfs: Rate limit statfs() handler
` [PATCH 6.6 0102/1424] fat: restore original value when fat_ent_write failed
` [PATCH 6.6 0103/1424] fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
` [PATCH 6.6 0104/1424] fbdev: pvr2fb: correct user pointer annotation and sentinel initializer
` [PATCH 6.6 0105/1424] fbdev: ssd1307fb: defer I2C transfers from damage callbacks
` [PATCH 6.6 0106/1424] fbdev: uvesafb: unregister connector callback on init failure
` [PATCH 6.6 0107/1424] forcedeth: fix off-by-one when saving/restoring non-PCI config space
` [PATCH 6.6 0108/1424] fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration
` [PATCH 6.6 0109/1424] hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
` [PATCH 6.6 0110/1424] ACPI: pfr_update: fix stack buffer overflow in query_capability()
` [PATCH 6.6 0111/1424] alpha/PCI: Fix I/O port accessor argument order in pci_legacy_write()
` [PATCH 6.6 0112/1424] alpha: marvel: Fix irq_set_status_flags to use correct IRQ number
` [PATCH 6.6 0113/1424] alpha: marvel: Fix lock ordering in init_io7_irqs()
` [PATCH 6.6 0114/1424] ARM: 9477/1: Disable broken eBPF JIT on the Risc PC
` [PATCH 6.6 0115/1424] ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
` [PATCH 6.6 0116/1424] auxdisplay: charlcd: cancel backlight work on registration failure
` [PATCH 6.6 0117/1424] block: set QUEUE_FLAG_DYING unconditionally in blk_mark_disk_dead()
` [PATCH 6.6 0118/1424] Bluetooth: btusb: Add ASUS USB-BT540 for Realtek 8761CU
` [PATCH 6.6 0119/1424] Bluetooth: btusb: Add ASUS USB-BT600 "
` [PATCH 6.6 0120/1424] Bluetooth: eir: Fix OOB read in eir_get_service_data()
` [PATCH 6.6 0121/1424] bnx2x: fix double free in bnx2x_init_firmware() error path
` [PATCH 6.6 0122/1424] bpf: Harden bloom filter sizing and indexing on 32-bit kernels
` [PATCH 6.6 0123/1424] dm-era: fix shadowed superblock leak on take-snap failure
` [PATCH 6.6 0124/1424] dm raid1: reserve space for NUL-terminator in build_constructor_string()
` [PATCH 6.6 0125/1424] dm array: reject an array block whose value size is not the callers
` [PATCH 6.6 0126/1424] cpufreq: schedutil: Fix rate limit overflow
` [PATCH 6.6 0127/1424] cxl/pmem: Format the nvdimm serial number as unsigned decimal
` [PATCH 6.6 0128/1424] Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
` [PATCH 6.6 0129/1424] Bluetooth: hci_uart: Fix false success return in hci_uart_setup()
` [PATCH 6.6 0130/1424] Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
` [PATCH 6.6 0131/1424] Bluetooth: RFCOMM: serialize security confirmation handling
` [PATCH 6.6 0132/1424] Bluetooth: hci_conn: re-enable advertising only for peripheral role
` [PATCH 6.6 0133/1424] Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
` [PATCH 6.6 0134/1424] Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection
` [PATCH 6.6 0135/1424] Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative
` [PATCH 6.6 0136/1424] Bluetooth: hci_intel: "
` [PATCH 6.6 0137/1424] Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request
` [PATCH 6.6 0138/1424] kasan: fix cache shrink race with CPU hotplug
` [PATCH 6.6 0139/1424] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
` [PATCH 6.6 0140/1424] ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
` [PATCH 6.6 0141/1424] ip6_gre: fix hardware header length for NBMA tunnels
` [PATCH 6.6 0142/1424] ipv6: use RCU iterator to dump route exceptions
` [PATCH 6.6 0143/1424] libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
` [PATCH 6.6 0144/1424] mailbox: qcom-ipcc: fix duplicate channel allocation across holes
` [PATCH 6.6 0145/1424] md: do overflow check for sb->bblog_shift in super_1_load()
` [PATCH 6.6 0146/1424] mpls: reload header after pskb_may_pull()
` [PATCH 6.6 0147/1424] mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
` [PATCH 6.6 0148/1424] nouveau/gem: reserve the bo in the info ioctl around the vma lookup
` [PATCH 6.6 0149/1424] SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
` [PATCH 6.6 0150/1424] SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
` [PATCH 6.6 0151/1424] SUNRPC: svcauth_gss: enforce krb5 token minimum length
` [PATCH 6.6 0152/1424] sunrpc: route to a populated pool in svc_pool_for_cpu()
` [PATCH 6.6 0153/1424] SUNRPC: always drain cache_cleaner before destroying a cache_detail
` [PATCH 6.6 0154/1424] SUNRPC: Check svc pool percpu counter allocation
` [PATCH 6.6 0155/1424] SUNRPC: Guard svcauth_gss_release() dispatch on rq_auth_stat
` [PATCH 6.6 0156/1424] SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
` [PATCH 6.6 0157/1424] SUNRPC: harden gss_unwrap_resp_priv length checks
` [PATCH 6.6 0158/1424] sunrpc: init gssp_lock before publishing proc entry
` [PATCH 6.6 0159/1424] SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
` [PATCH 6.6 0160/1424] SUNRPC: wait for in-flight client TLS handshake callback
` [PATCH 6.6 0161/1424] svcrdma: Fix offset arithmetic in read_chunk_range
` [PATCH 6.6 0162/1424] svcrdma: Fix pcl_for_each_segment for empty chunks
` [PATCH 6.6 0163/1424] udf: reject VAT indexes equal to the entry count
` [PATCH 6.6 0164/1424] wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
` [PATCH 6.6 0165/1424] staging: media: tegra-video: fix of_node_put() on VIP parse errors
` [PATCH 6.6 0166/1424] staging: media: tegra-video: vi: fix probe failure on skipped last port
` [PATCH 6.6 0167/1424] rpmsg: glink: smem: order FIFO read after availability check
` [PATCH 6.6 0168/1424] arm64: dts: rockchip: fix eMMC reset polarity on PX30 Ringneck
` [PATCH 6.6 0169/1424] arm64: dts: rockchip: Fix rk3399-roc-pc-plus analog audio
` [PATCH 6.6 0170/1424] remoteproc: scp: Fix device reference leak on failed lookup
` [PATCH 6.6 0171/1424] qede: Fix NULL pointer dereference in TPA fragment processing
` [PATCH 6.6 0172/1424] RDMA/cxgb4: Cancel reg_work before freeing device on remove
` [PATCH 6.6 0173/1424] RDMA/ucma: Lock the handler in ucma_set_ib_path()
` [PATCH 6.6 0174/1424] regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
` [PATCH 6.6 0175/1424] regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata
` [PATCH 6.6 0176/1424] regulator: qcom-refgen: correct the regulator type to CURRENT
` [PATCH 6.6 0177/1424] orangefs: fix double-free of trailer_buf on readdir copy failure
` [PATCH 6.6 0178/1424] orangefs: skip leading spaces before parsing client debug masks
` [PATCH 6.6 0179/1424] ocfs2: always run deallocs on copy-on-write completion
` [PATCH 6.6 0180/1424] ocfs2: bound namelen in dlm_migrate_request_handler
` [PATCH 6.6 0181/1424] ocfs2: validate lengths in dlm_mig_lockres_handler
` [PATCH 6.6 0182/1424] ocfs2: validate rl_used against rl_count in refcount block validator
` [PATCH 6.6 0183/1424] ocfs2: cluster: dont sleep while holding o2hb_live_lock in o2hb_region_pin()
` [PATCH 6.6 0184/1424] ocfs2: cluster: avoid lock order inversion in o2hb_region_pin() from drop_item
` [PATCH 6.6 0185/1424] ocfs2: cluster: fix o2hb_dependent_users leak on pin failure
` [PATCH 6.6 0186/1424] ocfs2: fix readdir position truncation on 32-bit kernels
` [PATCH 6.6 0187/1424] openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
` [PATCH 6.6 0188/1424] openvswitch: only skb_tx_error() a packet we are about to drop
` [PATCH 6.6 0189/1424] ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion
` [PATCH 6.6 0190/1424] arm64: compat: Fix decrementing LDM/STM alignment emulation
` [PATCH 6.6 0191/1424] ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC
` [PATCH 6.6 0192/1424] hwmon: (max6621) fix negative temperature offset and crit readings
` [PATCH 6.6 0193/1424] hwmon: (max6621) fix temperature clamp range
` [PATCH 6.6 0194/1424] lockd: pin next file across nlm_inspect_file lock-drop
` [PATCH 6.6 0195/1424] nvme: nvme-fc: Fix nvme_fc_create_hw_io_queues() queue deletion in error path
` [PATCH 6.6 0196/1424] nvme: zero the discard fallback page
` [PATCH 6.6 0197/1424] nvme-pci: disable controller on admin queue IRQ setup failure
` [PATCH 6.6 0198/1424] nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
` [PATCH 6.6 0199/1424] nvme-tcp: fix host memory disclosure on R2T for a read command
` [PATCH 6.6 0200/1424] nvme-tcp: reject a read that transferred too few bytes
` [PATCH 6.6 0201/1424] sctp: stop processing a packet once its association is deleted
` [PATCH 6.6 0202/1424] sctp: drop a chunk if its transport was removed
` [PATCH 6.6 0203/1424] sctp: fix NULL deref on untransmitted RECONF completion
` [PATCH 6.6 0204/1424] sctp: distinguish sequence zero from wildcard in reconf lookup
` [PATCH 6.6 0205/1424] sctp: fix stream->outcnt underflow on duplicate RECONF responses
` [PATCH 6.6 0206/1424] power: supply: bq24257: fix use-after-free on remove
` [PATCH 6.6 0207/1424] power: supply: bq256xx: drain usb_work before freeing the charger
` [PATCH 6.6 0208/1424] power: supply: bq25890: Fix power_supply reference leak
` [PATCH 6.6 0209/1424] power: supply: cros_usbpd-charger: bound the EC-reported port count
` [PATCH 6.6 0210/1424] power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
` [PATCH 6.6 0211/1424] power: supply: lp8727: fix use-after-free in lp8727_release_irq()
` [PATCH 6.6 0212/1424] power: supply: qcom_battmgr: terminate the strings from firmware
` [PATCH 6.6 0213/1424] power: supply: rt9455: quiesce delayed work before teardown
` [PATCH 6.6 0214/1424] power: supply: twl4030_charger: cancel workers via devm
` [PATCH 6.6 0215/1424] power: supply: ucs1002: fix use-after-free on remove
` [PATCH 6.6 0216/1424] power: supply: max17040: drop incorrect I2C functionality check
` [PATCH 6.6 0217/1424] power: supply: max17040: synchronize work cancellation on suspend
` [PATCH 6.6 0218/1424] s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
` [PATCH 6.6 0219/1424] s390/dasd: Do not complete a failed ESE read as successful
` [PATCH 6.6 0220/1424] s390/dasd: Guard sysfs discipline callbacks against unallocated private data
` [PATCH 6.6 0221/1424] s390/dasd: Propagate partial completion length across ERP recovery
` [PATCH 6.6 0222/1424] PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk
` [PATCH 6.6 0223/1424] PCI: meson: Fix GPIO state while requesting PERST#
` [PATCH 6.6 0224/1424] PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608]
` [PATCH 6.6 0225/1424] PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses
` [PATCH 6.6 0226/1424] PCI/MSI: Enable memory decoding before restoring MSI-X messages
` [PATCH 6.6 0227/1424] PCI/proc: Avoid spurious runtime PM wakeup on config space accesses
` [PATCH 6.6 0228/1424] PCI/proc: Use file_ns_capable() when checking config space read access
` [PATCH 6.6 0229/1424] PCI/proc: Warn on writes to kernel-exclusive config space regions
` [PATCH 6.6 0230/1424] iommu/vt-d: Fix no_iommu to disable platform opt-in
` [PATCH 6.6 0231/1424] iommu/vt-d: Force requesting ACS when tboot is enabled
` [PATCH 6.6 0232/1424] platform/x86: dell-wmi-sysman: Dont hex dump attribute security buffer
` [PATCH 6.6 0233/1424] platform/x86: ISST: Validate level in perf mask ioctls
` [PATCH 6.6 0234/1424] platform/x86: ISST: Validate socket ID in clos_assoc ioctl
` [PATCH 6.6 0235/1424] mmc: via-sdmmc: stop card-detect handling on probe failure
` [PATCH 6.6 0236/1424] platform/x86: ISST: Just allow 2 bits for SST feature enable
` [PATCH 6.6 0237/1424] platform/x86: ISST: Validate logical CPU id and clos id
` [PATCH 6.6 0238/1424] platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path
` [PATCH 6.6 0239/1424] platform/chrome: sensorhub: Bound the EC-reported sensor number
` [PATCH 6.6 0240/1424] platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS
` [PATCH 6.6 0241/1424] platform/x86: hp-bioscfg: advance elem past consumed array elements
` [PATCH 6.6 0242/1424] platform/x86: hp-bioscfg: bound ordered-list parsing by the package count
` [PATCH 6.6 0243/1424] platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
` [PATCH 6.6 0244/1424] platform/x86: hp-bioscfg: fix heap OOB read on empty password write
` [PATCH 6.6 0245/1424] platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password
` [PATCH 6.6 0246/1424] platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
` [PATCH 6.6 0247/1424] platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed
` [PATCH 6.6 0248/1424] platform/x86: hp-bioscfg: pass validated element count to package parsers
` [PATCH 6.6 0249/1424] platform/x86: hp-bioscfg: warn on element type mismatch instead of failing
` [PATCH 6.6 0250/1424] interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
` [PATCH 6.6 0251/1424] ipmi: ipmb: validate write message length
` [PATCH 6.6 0253/1424] net/iucv: filter frames in afiucv_hs_rcv() by ingress device
` [PATCH 6.6 0254/1424] xdp: fix zero-copy frame layout
` [PATCH 6.6 0262/1424] net: thunderbolt: Mark the connection down when bringing it up fails
` [PATCH 6.6 0263/1424] NTB: ntb_transport: Recycle TX entries before client callbacks
` [PATCH 6.6 0264/1424] NTB: ntb_transport: Fail TX enqueue when the QP link is down
` [PATCH 6.6 0265/1424] NTB: ntb_transport: Reject oversized TX buffers
` [PATCH 6.6 0266/1424] net: ntb_netdev: Avoid double-accounting netif_rx() drops
` [PATCH 6.6 0267/1424] net: ntb_netdev: Count packets dropped on RX refill failure
` [PATCH 6.6 0268/1424] net/smc: do not dereference an unset send buffer on the SMC-D teardown path
` [PATCH 6.6 0269/1424] net/smc: fix socket refcount leak in smc_switch_conns()
` [PATCH 6.6 0270/1424] net/smc: fix use-after-free in smc_rx_pipe_buf_release()
` [PATCH 6.6 0271/1424] net/smc: unregister the connection before draining the rx tasklet
` [PATCH 6.6 0272/1424] net: cap advertised IP tunnel headroom
` [PATCH 6.6 0273/1424] net: fix spurious TX timeout after dev_activate()
` [PATCH 6.6 0274/1424] net: skbuff: dont touch shared zerocopy state in skb_tx_error()


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).