======================================= Sat, 22 Jul 2023 - Debian 12.1 released ======================================= ========================================================================= [Date: Sat, 22 Jul 2023 09:14:45 -0000] [ftpmaster: Archive Administrator] Removed the following packages from stable: libtexluajit-dev | 2022.20220321.62855-5.1 | i386 libtexluajit2 | 2022.20220321.62855-5.1 | i386 ------------------- Reason ------------------- [auto-cruft] NBS ---------------------------------------------- ========================================================================= aide (0.18.3-1+deb12u2) bookworm; urgency=medium . * Upstream patch to fix child directory processing on equal match (Closes: #1039936) aide (0.18.3-1+deb12u1) bookworm; urgency=medium . * call dh_installsysusers manually in debian/rules Thanks to Tomasz Ciolek (Closes: #1037171) * Fix handling of extended attributes on symlinks. (Closes: #1037436) autofs (5.1.8-2+deb12u1) bookworm; urgency=medium . * debian/patches: + Add fix-missing-unlock-in-sasl-do-kinit-ext-cc.patch. Fix missing unlock in sasl_do_kinit_ext_cc(). (Closes: #1039967). ayatana-indicator-datetime (22.9.1-1+deb12u1) bookworm; urgency=medium . * debian/patches: + Add 0001_engine-eds-fix-retrieving-custom-alarm-sound-path.patch. Fix playing of custom alarm sounds. (Closes: #1037330). base-files (12.4+deb12u1) bookworm; urgency=medium . * Change /etc/debian_version to 12.1, for Debian 12.1 point release. bepasty (1.0.0-1+deb12u1) bookworm; urgency=medium . * Backport upstream fix for Pygments-2.12.0. (Closes: #1038452) bind9 (1:9.18.16-1~deb12u1) bookworm-security; urgency=high . * New upstream version 9.18.16 - CVE-2023-2828: The overmem cleaning process has been improved, to prevent the cache from significantly exceeding the configured max-cache-size limit. - CVE-2023-2911: A query that prioritizes stale data over lookup triggers a fetch to refresh the stale data in cache. If the fetch is aborted for exceeding the recursion quota, it was possible for named to enter an infinite callback loop and crash due to stack overflow. This has been fixed. bind9 (1:9.18.16-1~deb12u1~bpo11+1) bullseye-backports; urgency=high . * Rebuild for bullseye-backports. bind9 (1:9.18.13-1) unstable; urgency=medium . * New upstream version 9.18.13 boost1.81 (1.81.0-5+deb12u1) bookworm; urgency=medium . * debian/control: Add dependency on libboost-json1.81.0 for libboost-json1.81-dev (Closes: #1036986) bup (0.33.2-1~deb12u1) bookworm; urgency=medium . * Upstream version 0.33.2, with a fix for a problem that can cause POSIX.1e ACLs to be restored incorrectly. bup (0.33.1-1) unstable; urgency=medium . [ Rob Browning ] * 0.33.1 - conftest.py: switch to Path to support pytest 7+ - conftest.py: restore support for pytest < 7 - configure: handle relative MAKE paths - test_get: remove vestigial debug messages - configure: allow and prefer python3.11-config; ignore 3.6 - buptest init: get quote from shlex not pipes - test-comparative-split-join: accommodate varying HEAD names - cirrus: move to freebsd 12.4 to fix rsync-related test failures - compare-trees: add --features and disallow args with it and -h - Restore posix1e default acls as default, not access; improve tests - Fix ACL metadata format; delimit short form entries with commas - Update docs for 0.33.1 release - Update base_version for 0.33.1 release . [ Robert Edmonds ] * New upstream version 0.33.1 (Closes: #1038609) * debian/docs: Include upstream release note '0.33.1-from-0.33.md' chromium (114.0.5735.198-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2023-3420: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab. - CVE-2023-3421: Use after free in Media. Reported by Piotr Bania of Cisco Talos. - CVE-2023-3422: Use after free in Guest View. Reported by asnine. chromium (114.0.5735.198-1~deb11u1) bullseye-security; urgency=high . * New upstream security release. - CVE-2023-3420: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab. - CVE-2023-3421: Use after free in Media. Reported by Piotr Bania of Cisco Talos. - CVE-2023-3422: Use after free in Guest View. Reported by asnine. chromium (114.0.5735.133-1) unstable; urgency=high . - CVE-2023-3214: Use after free in Autofill payments. Reported by Rong Jian of VRI. - CVE-2023-3215: Use after free in WebRTC. Reported by asnine. - CVE-2023-3216: Type Confusion in V8. Reported by 5n1p3r0010 from Topsec ChiXiao Lab. - CVE-2023-3217: Use after free in WebXR. Reported by Sergei Glazunov of Google Project Zero. chromium (114.0.5735.133-1~deb12u1) bookworm-security; urgency=high . - CVE-2023-3214: Use after free in Autofill payments. Reported by Rong Jian of VRI. - CVE-2023-3215: Use after free in WebRTC. Reported by asnine. - CVE-2023-3216: Type Confusion in V8. Reported by 5n1p3r0010 from Topsec ChiXiao Lab. - CVE-2023-3217: Use after free in WebXR. Reported by Sergei Glazunov of Google Project Zero. chromium (114.0.5735.133-1~deb11u1) bullseye-security; urgency=high . - CVE-2023-3214: Use after free in Autofill payments. Reported by Rong Jian of VRI. - CVE-2023-3215: Use after free in WebRTC. Reported by asnine. - CVE-2023-3216: Type Confusion in V8. Reported by 5n1p3r0010 from Topsec ChiXiao Lab. - CVE-2023-3217: Use after free in WebXR. Reported by Sergei Glazunov of Google Project Zero. chromium (114.0.5735.106-1) unstable; urgency=high . * New upstream stable release. - CVE-2023-3079: Type Confusion in V8. Reported by Clément Lecigne of Google's Threat Analysis Group. * d/patches: - ppc64le/third_party/skia-vsx-instructions.patch: rewrite for POWER8 compatibility, fix graphics corruption, and enable in builds chromium (114.0.5735.106-1~deb12u1) bookworm-security; urgency=high . * New upstream stable release. - CVE-2023-3079: Type Confusion in V8. Reported by Clément Lecigne of Google's Threat Analysis Group. * d/patches: - ppc64le/third_party/skia-vsx-instructions.patch: rewrite for POWER8 compatibility, fix graphics corruption, and enable in builds chromium (114.0.5735.106-1~deb11u1) bullseye-security; urgency=high . * New upstream stable release. - CVE-2023-3079: Type Confusion in V8. Reported by Clément Lecigne of Google's Threat Analysis Group. * d/patches: - ppc64le/third_party/skia-vsx-instructions.patch: rewrite for POWER8 compatibility, fix graphics corruption, and enable in builds chromium (114.0.5735.90-2) unstable; urgency=high . * d/patches: - Add upstream/feature-list-static.patch This patch fixes an out of scope array access that can lead to crashes at startup chromium (114.0.5735.90-2~deb12u1) bookworm-security; urgency=high . * d/patches: - Add upstream/feature-list-static.patch This patch fixes an out of scope array access that can lead to crashes at startup . chromium (114.0.5735.90-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2023-2929: Out of bounds write in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori. - CVE-2023-2930: Use after free in Extensions. Reported by asnine. - CVE-2023-2931: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2932: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2933: Use after free in PDF. Reported by Quang Nguyễn (@quangnh89) of Viettel Cyber Security and Nguyen Phuong. - CVE-2023-2934: Out of bounds memory access in Mojo. Reported by Mark Brand of Google Project Zero. - CVE-2023-2935: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2936: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2937: Inappropriate implementation in Picture In Picture. Reported by NDevTK. - CVE-2023-2938: Inappropriate implementation in Picture In Picture. Reported by Alesandro Ortiz. - CVE-2023-2939: Insufficient data validation in Installer. Reported by ycdxsb from VARAS@IIE. - CVE-2023-2940: Inappropriate implementation in Downloads. Reported by Axel Chong. - CVE-2023-2941: Inappropriate implementation in Extensions API. Reported by Jasper Rebane. * d/copyright: properly delete some android & chromeos stuff. * d/patches: - fixes/clang-and-gcc11.patch: refresh. - upstream/webview-cstr.patch: drop, merged upstream. - upstream/monostate.patch: drop, merged upstream. - disable/unrar.patch: additional upstream changes required more reworking. - disable/android.patch: refresh, & add one more build fix. - disable/catapult.patch: refresh. - disable/swiftshader.patch: refresh. - disable/angle-perftest.patch: refresh. - system/jpeg.patch: refresh. - upstream/mojo.patch: regenerate from git. - upstream/sizet.patch: add an upstream build fix. - bookworm/typename.patch: include more build fixes. - bookworm/lambda-bug.patch -> bookworm/structured-binding-scope-bug.patch, and add another place it's happening (turns out it's not just lambdas). * Add build-dep on libevdev-dev - now required by upstream. . [ Timothy Pearson ] * d/patches: - Refresh ppc64le patches chromium (114.0.5735.90-2~deb11u1) bullseye-security; urgency=high . [ Timothy Pearson ] * d/patches: - Add upstream/feature-list-static.patch This patch fixes an out of scope array access that can lead to crashes at startup . [ Andres Salomon ] * d/patches: add bullseye/av1-vaapi.patch to disable av1 encoding on bullseye; libav-dev is too old. . chromium (114.0.5735.90-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2023-2929: Out of bounds write in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori. - CVE-2023-2930: Use after free in Extensions. Reported by asnine. - CVE-2023-2931: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2932: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2933: Use after free in PDF. Reported by Quang Nguyễn (@quangnh89) of Viettel Cyber Security and Nguyen Phuong. - CVE-2023-2934: Out of bounds memory access in Mojo. Reported by Mark Brand of Google Project Zero. - CVE-2023-2935: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2936: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2937: Inappropriate implementation in Picture In Picture. Reported by NDevTK. - CVE-2023-2938: Inappropriate implementation in Picture In Picture. Reported by Alesandro Ortiz. - CVE-2023-2939: Insufficient data validation in Installer. Reported by ycdxsb from VARAS@IIE. - CVE-2023-2940: Inappropriate implementation in Downloads. Reported by Axel Chong. - CVE-2023-2941: Inappropriate implementation in Extensions API. Reported by Jasper Rebane. * d/copyright: properly delete some android & chromeos stuff. * d/patches: - fixes/clang-and-gcc11.patch: refresh. - upstream/webview-cstr.patch: drop, merged upstream. - upstream/monostate.patch: drop, merged upstream. - disable/unrar.patch: additional upstream changes required more reworking. - disable/android.patch: refresh, & add one more build fix. - disable/catapult.patch: refresh. - disable/swiftshader.patch: refresh. - disable/angle-perftest.patch: refresh. - system/jpeg.patch: refresh. - upstream/mojo.patch: regenerate from git. - upstream/sizet.patch: add an upstream build fix. - bookworm/typename.patch: include more build fixes. - bookworm/lambda-bug.patch -> bookworm/structured-binding-scope-bug.patch, and add another place it's happening (turns out it's not just lambdas). * Add build-dep on libevdev-dev - now required by upstream. . [ Timothy Pearson ] * d/patches: - Refresh ppc64le patches chromium (114.0.5735.90-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2023-2929: Out of bounds write in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori. - CVE-2023-2930: Use after free in Extensions. Reported by asnine. - CVE-2023-2931: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2932: Use after free in PDF. Reported by Huyna at Viettel Cyber Security. - CVE-2023-2933: Use after free in PDF. Reported by Quang Nguyễn (@quangnh89) of Viettel Cyber Security and Nguyen Phuong. - CVE-2023-2934: Out of bounds memory access in Mojo. Reported by Mark Brand of Google Project Zero. - CVE-2023-2935: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2936: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero. - CVE-2023-2937: Inappropriate implementation in Picture In Picture. Reported by NDevTK. - CVE-2023-2938: Inappropriate implementation in Picture In Picture. Reported by Alesandro Ortiz. - CVE-2023-2939: Insufficient data validation in Installer. Reported by ycdxsb from VARAS@IIE. - CVE-2023-2940: Inappropriate implementation in Downloads. Reported by Axel Chong. - CVE-2023-2941: Inappropriate implementation in Extensions API. Reported by Jasper Rebane. * d/copyright: properly delete some android & chromeos stuff. * d/patches: - fixes/clang-and-gcc11.patch: refresh. - upstream/webview-cstr.patch: drop, merged upstream. - upstream/monostate.patch: drop, merged upstream. - disable/unrar.patch: additional upstream changes required more reworking. - disable/android.patch: refresh, & add one more build fix. - disable/catapult.patch: refresh. - disable/swiftshader.patch: refresh. - disable/angle-perftest.patch: refresh. - system/jpeg.patch: refresh. - upstream/mojo.patch: regenerate from git. - upstream/sizet.patch: add an upstream build fix. - bookworm/typename.patch: include more build fixes. - bookworm/lambda-bug.patch -> bookworm/structured-binding-scope-bug.patch, and add another place it's happening (turns out it's not just lambdas). * Add build-dep on libevdev-dev - now required by upstream. . [ Timothy Pearson ] * d/patches: - Refresh ppc64le patches context (2021.03.05.20230120+dfsg-1+deb12u1) bookworm; urgency=medium . * Explicitely enable socket in ConTeXt mtxrun (see #1036470). cpdb-libs (1.2.0-2+deb12u1) bookworm; urgency=medium . * CVE-2023-34095 (Closes: #1038253) buffer overflow via improper use of scanf()/fscanf() cpp-httplib (0.11.4+ds-1+deb12u1) bookworm; urgency=medium . * d/gbp.conf: adjust branch names for bookworm * d/patches: fix fox CVE-2023-26130. Backport of the security fix for CVE-2023-26130, a CRLF Injection, from upstream commit 5b397d455d25a391ba346863830c1949627b4d08 included in upstream release 0.12.4 and newer. (Closes: #1037100) crowdsec (1.4.6-6~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. * Adjust gbp.conf accordingly. crowdsec (1.4.6-5) unstable; urgency=medium . * Fix default acquis.yaml to also include the journalctl datasource, limited to the ssh.service unit, making sure acquisition works even without the traditional auth.log file (Closes: #1040976): - 0017-fix-default-acquisition.patch * Make sure an invalid datasource doesn't make the engine error out, making it possible to include the journalctl datasource in the default config file unconditionally, without having to worry whether journalctl is actually deployed and usable: - 0018-non-fatal-errors-for-invalid-datasources.patch cups (2.4.2-3+deb12u1) bookworm; urgency=medium . * CVE-2023-34241 (Closes: #1038885) use-after-free in cupsdAcceptClient() . * CVE-2023-32324 A heap buffer overflow vulnerability would allow a remote attacker to lauch a dos attack. cvs (2:1.12.13+real-28+deb12u1) bookworm; urgency=high . * configure-time hardcode full path for ssh(1) (Closes: #1038926) dbus (1.14.8-2~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm dbus (1.14.8-1) unstable; urgency=medium . [ Simon McVittie ] * New upstream stable release - Fixes a denial of service issue if the root or messagebus user is monitoring messages on the system bus with the Monitoring interface (dbus-monitor, busctl monitor, gdbus monitor or similar) (Closes: #1037151) . [ Helmut Grohne ] * Mark dbus-daemon and dbus-bin Multi-Arch: foreign (Closes: #1033056) dbus (1.14.8-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm * d/gbp.conf: Use debian/bookworm branch * d/watch: Only watch for 1.14.x releases . dbus (1.14.8-1) unstable; urgency=medium . [ Simon McVittie ] * New upstream stable release - Fixes a denial of service issue if the root or messagebus user is monitoring messages on the system bus with the Monitoring interface (dbus-monitor, busctl monitor, gdbus monitor or similar) (Closes: #1037151) . [ Helmut Grohne ] * Mark dbus-daemon and dbus-bin Multi-Arch: foreign (Closes: #1033056) debian-installer (20230607+deb12u1) bookworm; urgency=medium . * Bootstrap bookworm stable branch: - Set USE_PROPOSED_UPDATES=1 in debian/rules - Set USE_UDEBS_FROM?=bookworm in build/config/common * Bump Linux kernel ABI to 6.1.0-10. * Adjust linux-image build-deps as well. debian-installer-netboot-images (20230607+deb12u1) bookworm; urgency=medium . * Update to 20230607+deb12u1, from bookworm-proposed-updates. * Update DISTRIBUTION and DISTRIBUTION_FALLBACK for the bookworm branch. desktop-base (12.0.6+nmu1~deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Rebuild for bookworm. . desktop-base (12.0.6+nmu1) unstable; urgency=medium . * Non-maintainer upload. * prerm: Remove the emerald alternatives, too. (Closes: #1035431) dh-python (5.20230130+deb12u1) bookworm; urgency=medium . * Reintroduce Breaks+Replaces on python2 needed to help apt in some upgrade scenarios. (Closes: #1036943) dkms (3.0.10-8+deb12u1) bookworm; urgency=medium . * Add Breaks against obsolete *-dkms packages that are incompatible with the Linux 6.1 kernel in bookworm. (Closes: #1037425) dnf (4.14.0-3+deb12u1) bookworm; urgency=medium . * Fix default DNF const PYTNON_INSTALL_DIR. Closes: #1034828. . It was build with default DNF value which is not the same path in Debian. In consequence, dnf-plugins-core were broken. Reported by Aron . dpdk (22.11.2-2~deb12u1) bookworm; urgency=medium . * Revert "Drop old init script" * Revert "Add package for new librte-net-mana PMD" * Revert "d/control, d/dpdk.init: stop using lsb-base functions" * Explicitly disable new mana PMD. This gets enabled implicitly when a new enough rdma-core is available, but we do not want to introduce new libraries via bookworm-pu. * Upload to bookworm. . dpdk (22.11.2-2) unstable; urgency=medium . * No changes source-only upload. . dpdk (22.11.2-1) unstable; urgency=medium . [ Christian Ehrhardt ] * d/t/test-fastsuite: test env before breaking tests for known issues * d/rules: avoid path length issues in build time test * d/control, d/dpdk.init: stop using lsb-base functions . [ Luca Boccassi ] * Update upstream source from tag 'upstream/22.11.2' * Add package for new librte-net-mana PMD * Bump Standards-Version to 4.6.2, no changes * Add new internal/experimental symbols * Drop old init script dpdk (22.11.2-1) unstable; urgency=medium . [ Christian Ehrhardt ] * d/t/test-fastsuite: test env before breaking tests for known issues * d/rules: avoid path length issues in build time test * d/control, d/dpdk.init: stop using lsb-base functions . [ Luca Boccassi ] * Update upstream source from tag 'upstream/22.11.2' * Add package for new librte-net-mana PMD * Bump Standards-Version to 4.6.2, no changes * Add new internal/experimental symbols * Drop old init script exim4 (4.96-15+deb12u1) bookworm; urgency=medium . * 75_42-Fix-run-arg-parsing.patch (From upstream GIT master, backported by Bryce Harrington for Ubuntu): Fix argument parsing for ${run } expansion. Previously, when an argument included a close-brace character (eg. it itself used an expansion) an error occurred. Closes: #1025420 * 75_68-Fix-srs_encode-.-for-mod-1024-day-zero.patch from upstream GIT master: Fix ${srs_encode ..}. Previously it would give a bad result for one day every 1024 days. fai (6.0.3+deb12u1) bookworm; urgency=low . * fai: set IP address lifetime to forever, Closes: #1037329 firefox-esr (102.13.0esr-1~deb12u1) bookworm-security; urgency=medium . * New upstream release. * Fixes for mfsa2023-23, also known as: CVE-2023-37201, CVE-2023-37202, CVE-2023-37207, CVE-2023-37208, CVE-2023-37211. . * debian/rules, media/ffvpx/config_unix64.h: Work around https://sourceware.org/bugzilla/show_bug.cgi?id=30578. * debian/upstream.mk: Unstable is trixie. firefox-esr (102.13.0esr-1~deb11u1) bullseye-security; urgency=medium . * New upstream release. * Fixes for mfsa2023-23, also known as: CVE-2023-37201, CVE-2023-37202, CVE-2023-37207, CVE-2023-37208, CVE-2023-37211. . * debian/rules, media/ffvpx/config_unix64.h: Work around https://sourceware.org/bugzilla/show_bug.cgi?id=30578. * debian/upstream.mk: Unstable is trixie. firefox-esr (102.12.0esr-1) unstable; urgency=medium . * New upstream release. * Fixes for mfsa2023-19, also known as: CVE-2023-34414, CVE-2023-34416. firefox-esr (102.12.0esr-1~deb12u1) bookworm-security; urgency=medium . * New upstream release. * Fixes for mfsa2023-19, also known as: CVE-2023-34414, CVE-2023-34416. firefox-esr (102.12.0esr-1~deb11u1) bullseye-security; urgency=medium . * New upstream release. * Fixes for mfsa2023-19, also known as: CVE-2023-34414, CVE-2023-34416. ghostscript (10.0.0~dfsg-11+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Don't "reduce" %pipe% file names for permission validation (CVE-2023-36664) * Revisit fix for upstream bug 706761 (CVE-2023-36664) glibc (2.36-9+deb12u1) bookworm; urgency=medium . [ Aurelien Jarno ] * debian/patches/git-updates.diff: update from upstream stable branch: - Affecting bookworm release architectures: - Improve mcount overflow handling in gmon. - Fix a buffer overflow in gmon (CVE-2023-0687). - Fix a memory corruption when incorrectly calling gmon functions repeatedly on in wrong order. - Fix a deadlock in getaddrinfo (__check_pf) with deferred cancellation. - Fix y2038 support in strftime on 32-bit architectures. - Fix corner case parsing of /etc/gshadow which can return bad pointers causing segfaults in applications. - Fix a deadlock in system() when called concurrently from multiple threads. - cdefs: limit definition of fortification macros to __FORTIFY_LEVEL > 0 to support old C90 compilers. - Not affecting bookworm release architectures: - Fix LFS POSIX lock constants for powerpc64. - Fix GL(dl_phdr) and GL(dl_phnum) for static builds. Closes: #1028200. - Not affecting debian architectures: - Fix LFS POSIX lock constants on 32 bit arch with 64 bit default time_t. - No change in the generated code: - Fix asm constraints in amd64 version of feraiseexcept (bug not visible with GCC 12). . [ Andrej Shadura ] * debian/po/sk.po: Fix typos in the Slovak translation. gnome-control-center (1:43.6-2~deb12u1) bookworm; urgency=medium . * Team upload * Rebuild for bookworm . gnome-control-center (1:43.6-2) unstable; urgency=medium . * Team upload * Expand previous changelog entry to include more details of the upstream changes . gnome-control-center (1:43.6-1) unstable; urgency=medium . * New upstream bugfix release 43.5 - Populate list of previous WWAN (Mobile Network) connetions more reliably, avoiding creation of duplicate connections in NetworkManager (gnome-control-center#1468 upstream) - Stop listing displays in the reverse of the intended order - Add 32:9 as a well-known aspect ratio (gnome-control-center#2334 upstream) - Fix an assertion failure when activating the Users panel (gnome-control-center#2219 upstream) - Don't access User objects before they are fully loaded (gnome-control-center#2348, #2349 upstream) - Fix an assertion failure when cropping an avatar - Don't allow commas in users' "real name" field, because the GECOS encoding in /etc/passwd cannot represent those (gnome-control-center#888 upstream) - Automatically close user avatar chooser before showing file chooser (gnome-control-center#2315 upstream) - Restore the default cursor when leaving the dialog to crop an avatar (gnome-control-center#2359 upstream) - Fix a crash when cancelling authentication for Thunderbolt - Remove a duplicate property from the "add user" UI - Translation updates: ca, fr, hu * New upstream bugfix release 43.6 - Fix a use-after-free crash when editing network connections - Translation updates: ab, hu; add fo gnome-control-center (1:43.6-1) unstable; urgency=medium . * New upstream bugfix release gnome-maps (43.5-2~deb12u1) bookworm; urgency=medium . * Team upload * Rebuild for Debian 12 * d/control.in, d/gbp.conf: Use debian/bookworm packaging branch . gnome-maps (43.5-2) unstable; urgency=medium . * Team upload * d/p/transitArrivalRow-Disable-go-to-animation-when-clicked.patch, d/p/transitLegRow-Disable-go-to-animation-when-clicked.patch: Add patches from upstream 44.1 to disable more animations. Like the one in v43.5, these avoid animations that can trigger the tile server's rate limiting (gnome-maps#546 upstream). * Add some more detail to the previous changelog entry * d/control.in, d/gbp.conf: Use debian/trixie packaging branch * d/lintian-overrides: Update overrides syntax . gnome-maps (43.5-1) unstable; urgency=medium . * New upstream bugfix release - Disable an animation which caused too many tiles to be loaded from the remote server, resulting in rate-limiting and failure to redraw (gnome-maps#546 upstream) - Translation updates: en_GB * d/p/sendToDialog-Unbreak-OpenWithRows.patch: Add patch from upstream gnome-43 branch to fix "Send to" dialog when another geo: app is installed (Closes: #1036936) * d/watch, d/gbp.conf: Use appropriate branches for bookworm gnome-maps (43.5-1) unstable; urgency=medium . * New upstream bugfix release * Fix Send to Dialog when another geo: app is installed - Cherry-pick patch from upstream 43 branch (Closes: #1036936) gnome-shell (43.6-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm gnome-software (43.5-1~deb12u1) bookworm; urgency=medium . * Team upload * Rebuild for Debian 12 . gnome-software (43.5-1) unstable; urgency=medium . * d/gbp.conf: Use upstream/43.x branch to import new upstream versions * d/watch: Only watch for versions 43.x * New upstream release 43.5 - Fix some memory leaks (Closes: #1036312) * Refresh patch series (no functional changes) gosa (2.8~git20230203.10abe45+dfsg-1+deb12u1) bookworm; urgency=medium . [ Mike Gabriel ] * debian/patches: + Add 1003_php-deprecations.patch. Silence various PHP 8.2 deprecation warnings. (Closes: #1038682). . [ Daniel Teichmann ] * debian/patches: + Add 1004_missing_templates.patch. (Closes: #1039697) + Update 1002_php82-allow-dynamic-properties.patch: Tolerate dyn. prop. for ALL PHP classes. (Closes: #1039894) + Add 1005_preg_replace_deprecation.patch. + Add 1006_fix-overflow-debug-print_a-func.patch. (Closes: #1040839) groonga (13.0.0+dfsg-3~deb12u1) bookworm; urgency=medium . * Backport to bookworm - It fixes missing dependency to libjs-*. (#1036575) gst-plugins-bad1.0 (1.22.0-4+deb12u1) bookworm-security; urgency=medium . * GST-2023-0003 gst-plugins-base1.0 (1.22.0-3+deb12u1) bookworm-security; urgency=medium . * GST-2023-0001 / GST-2023-0002 gst-plugins-good1.0 (1.22.0-5+deb12u1) bookworm-security; urgency=medium . * GST-2023-0001 guestfs-tools (1.48.2-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. . [ Hilko Bengen ] * Add libguestfs-common patch, fixing CVE-2022-2211 (Closes: #1014764) hsqldb (2.7.1-1+deb12u1) bookworm-security; urgency=medium . * Team upload. . * fix CVE-2023-1183 hsqldb1.8.0 (1.8.0.10+dfsg-11+deb12u1) bookworm-security; urgency=medium . * add patch from upstream to avoid execution of spurious command in script or log file (CVE-2023-1183) indent (2.2.12-4+deb12u1) bookworm; urgency=medium . * Restore the ROUND_UP macro and adjust the initial buffer size. Patch from the author, backported from 2.2.13. Fix memory handling problem. Closes: #1036851. installation-guide (20230508+deb12u1) bookworm; urgency=medium . [ Holger Wansing ] * Add Indonesian (as a recently added new translation) to langlist, to get this translation into the package. kanboard (1.2.26+ds-2+deb12u1) bookworm; urgency=high . * Cherry-pick security fixes from kanboard_1.2.26+ds-[34] for bookworm. * backport fix for CVE-2023-32685 from kanboard v1.2.29 https://github.com/kanboard/kanboard/security/advisories/GHSA-hjmw-gm82-r4gv Based on upstream commits 26b6eeb & c9c1872. (cherry picked from commit d9b8d854f2d35831b04b84cfdda41cc7b49e3a28) (Closes: #1036874) * backport security fixes from kanboard v1.2.30. > CVE-2023-33956: Parameter based Indirect Object Referencing leading to private file exposure > CVE-2023-33968: Missing access control allows user to move and duplicate tasks to any project in the software > CVE-2023-33969: Stored XSS in the Task External Link Functionality > CVE-2023-33970: Missing access control in internal task links feature (cherry picked from commit 4ad0ad220613bbf04bef559addba8c363fdf0dfa) (Closes: #1037167) * point gbp & salsa at bookworm kf5-messagelib (4:22.12.3-2~deb12u1) bookworm; urgency=medium . * Rebuilt for bookworm. libmatekbd (1.26.0-1+deb12u1) bookworm; urgency=medium . * debian/patches: + Add 0001_matekbd-keyboard-drawing-fix-memory-leak.patch and 0002_matekbd-keyboard-drawing-fix-memory-leak.patch. Fix two memory leaks. Cherry-picked from recent upstream release v1.26.1. (Closes: #1038430). libreoffice (4:7.4.7-1) bookworm; urgency=medium . * "New" upstream release . * debian/control.postgresql.in: - depend on libreoffice-core-nogui | libreoffice-core (like the other -sdbc-*) (closes: #1034792) * debian/rules: - don't remove tabviewbar.ui in -impress-nogui (closes: #1028290) libreswan (4.10-2+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-30570 (Closes: #1035542) libx11 (2:1.8.4-2+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * InitExt.c: Add bounds checks for extension request, event, & error codes (CVE-2023-3138) (Closes: #1038133) libxml2 (2.9.14+dfsg-1.3~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm . libxml2 (2.9.14+dfsg-1.3) unstable; urgency=medium . * Non-maintainer upload. * Reset nsNr in xmlCtxtReset (CVE-2022-2309) (Closes: #1039991) * Also reset nsNr in htmlCtxtReset (CVE-2022-2309) (Closes: #1039991) linux (6.1.38-1) bookworm; urgency=medium . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.38 - drm/amd/display: Remove optimization for VRR updates - drm/amd/display: Do not update DRR while BW optimizations pending - PCI/ACPI: Validate acpi_pci_set_power_state() parameter - PCI/ACPI: Call _REG when transitioning D-states - execve: always mark stack as growing down during early stack setup - perf symbols: Symbol lookup with kcore can fail if multiple segments match stext - scripts/tags.sh: Resolve gtags empty index generation - drm/amdgpu: Validate VM ioctl flags. - drm/amd/display: Ensure vmin and vmax adjust for DCE . [ Salvatore Bonaccorso ] * drm: use mgr->dev in drm_dbg_kms in drm_dp_add_payload_part2 * mm/mmap: Fix VM_LOCKED check in do_vmi_align_munmap() * netfilter: nf_tables: do not ignore genmask when looking up chain by id (CVE-2023-31248) * netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (CVE-2023-35001) linux (6.1.37-1) bookworm-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.28 - [x86] ASOC: Intel: sof_sdw: add quirk for Intel 'Rooks County' NUC M15 - [x86] ASoC: Intel: soc-acpi: add table for Intel 'Rooks County' NUC M15 - ASoC: soc-pcm: fix hw->formats cleared by soc_pcm_hw_init() for dpcm - [x86] hyperv: Block root partition functionality in a Confidential VM - [x86] ASoC: amd: yc: Add DMI entries to support Victus by HP Laptop 16-e1xxx (8A22) - [x86] ASoC: Intel: bytcr_rt5640: Add quirk for the Acer Iconia One 7 B1-750 - [x86] ASoC: da7213.c: add missing pm_runtime_disable() - scsi: mpi3mr: Handle soft reset in progress fault code (0xF002) - net: sfp: add quirk enabling 2500Base-x for HG MXPD-483II - [x86] platform/x86: thinkpad_acpi: Add missing T14s Gen1 type to s2idle quirk list - wifi: ath11k: reduce the MHI timeout to 20s - tracing: Error if a trace event has an array for a __field() - [x86] cpu: Add model number for Intel Arrow Lake processor - wireguard: timers: cast enum limits members to int in prints - wifi: mt76: mt7921e: Set memory space enable in PCI_COMMAND if unset - [arm64] Always load shadow stack pointer directly from the task struct - [arm64] Stash shadow stack pointer in the task struct on interrupt - PCI: pciehp: Fix AB-BA deadlock between reset_lock and device_lock - [arm64] PCI: qcom: Fix the incorrect register usage in v2.7.0 config - [arm64] phy: qcom-qmp-pcie: sc8180x PCIe PHY has 2 lanes - [arm64,armhf] usb: dwc3: gadget: Stall and restart EP0 if host is unresponsive - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on probe errors - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on unbind - [x86] hwmon: (k10temp) Check range scale when CUR_TEMP register is read-write - hwmon: (adt7475) Use device_property APIs when configuring polarity - tpm: Add !tpm_amd_is_rng_defective() to the hwrng_unregister() call site - posix-cpu-timers: Implement the missing timer_wait_running callback - blk-stat: fix QUEUE_FLAG_STATS clear - blk-crypto: don't use struct request_queue for public interfaces - blk-crypto: add a blk_crypto_config_supported_natively helper - blk-crypto: move internal only declarations to blk-crypto-internal.h - blk-crypto: Add a missing include directive - blk-mq: release crypto keyslot before reporting I/O complete - blk-crypto: make blk_crypto_evict_key() return void - blk-crypto: make blk_crypto_evict_key() more robust - tty: Prevent writing chars during tcsetattr TCSADRAIN/FLUSH - xhci: fix debugfs register accesses while suspended - serial: fix TIOCSRS485 locking - serial: 8250: Fix serial8250_tx_empty() race with DMA Tx - tick/nohz: Fix cpu_is_hotpluggable() by checking with nohz subsystem - fs: fix sysctls.c built - [mips*] fw: Allow firmware to pass a empty env - ipmi:ssif: Add send_retries increment - ipmi: fix SSIF not responding under certain cond. - wifi: mt76: add missing locking to protect against concurrent rx/status calls - [arm64,armhf] pwm: meson: Fix axg ao mux parents - [arm64,armhf] pwm: meson: Fix g12a ao clk81 name - soundwire: qcom: correct setting ignore bit on v1.5.1 - ring-buffer: Ensure proper resetting of atomic variables in ring_buffer_reset_online_cpus - ring-buffer: Sync IRQ works before buffer destruction - crypto: api - Demote BUG_ON() in crypto_unregister_alg() to a WARN_ON() - [arm64] crypto: safexcel - Cleanup ring IRQ workqueues on load failure - [x86] crypto: ccp - Don't initialize CCP for PSP 0x1649 - rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed - reiserfs: Add security prefix to xattr name in reiserfs_security_write() - [x86] KVM: nVMX: Emulate NOPs in L2, and PAUSE if it's not intercepted - [arm64] KVM: arm64: Avoid vcpu->mutex v. kvm->lock inversion in CPU_ON - [arm64] KVM: arm64: Avoid lock inversion when setting the VM register width - [arm64] KVM: arm64: Use config_lock to protect data ordered against KVM_RUN - [arm64] KVM: arm64: Use config_lock to protect vgic state - [arm64] KVM: arm64: vgic: Don't acquire its_lock before config_lock - relayfs: fix out-of-bounds access in relay_file_read (CVE-2023-3268) - drm/amd/display: Remove stutter only configurations - drm/amd/display: limit timing for single dimm memory - drm/amd/display: fix PSR-SU/DSC interoperability support - drm/amd/display: fix a divided-by-zero error - ksmbd: fix racy issue under cocurrent smb2 tree disconnect (CVE-2023-32254) - ksmbd: call rcu_barrier() in ksmbd_server_exit() - ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem() - ksmbd: fix memleak in session setup - ksmbd: not allow guest user on multichannel - ksmbd: fix deadlock in ksmbd_find_crypto_ctx() - [x86] ACPI: video: Remove acpi_backlight=video quirk for Lenovo ThinkPad W530 - [arm64,armhf] i2c: omap: Fix standard mode false ACK readings - tracing: Fix permissions for the buffer_percent file - swsmu/amdgpu_smu: Fix the wrong if-condition - drm/amd/pm: re-enable the gfx imu when smu resume - [amd64] iommu/amd: Fix "Guest Virtual APIC Table Root Pointer" configuration in IRTE - Revert "ubifs: dirty_cow_znode: Fix memleak in error handling path" - ubifs: Fix memleak when insert_old_idx() failed - ubi: Fix return value overwrite issue in try_write_vid_and_data() - ubifs: Free memory for tmpfile name - ubifs: Fix memory leak in do_rename - ceph: fix potential use-after-free bug when trimming caps - xfs: don't consider future format versions valid - cxl/hdm: Fail upon detecting 0-sized decoders - bus: mhi: host: Remove duplicate ee check for syserr - bus: mhi: host: Use mhi_tryset_pm_state() for setting fw error state - bus: mhi: host: Range check CHDBOFF and ERDBOFF - rcu: Fix missing TICK_DEP_MASK_RCU_EXP dependency check - tpm, tpm_tis: Do not skip reset of original interrupt vector - tpm, tpm_tis: Claim locality before writing TPM_INT_ENABLE register - tpm, tpm_tis: Disable interrupts if tpm_tis_probe_irq() failed - tpm, tpm_tis: Claim locality before writing interrupt registers - tpm, tpm: Implement usage counter for locality - tpm, tpm_tis: Claim locality when interrupts are reenabled on resume - erofs: stop parsing non-compact HEAD index if clusterofs is invalid - erofs: initialize packed inode after root inode is assigned - erofs: fix potential overflow calculating xattr_isize - [arm64,armhf] drm/rockchip: Drop unbalanced obj unref - [x86] drm/i915/dg2: Drop one PCI ID - drm/vgem: add missing mutex_destroy - drm/probe-helper: Cancel previous job before starting new one - drm/amdgpu: register a vga_switcheroo client for MacBooks with apple-gmux - [arm64] dts: ti: k3-am62-main: Fix GPIO numbers in DT - [arm64] drm/msm/disp/dpu: check for crtc enable rather than crtc active to release shared resources - [amd64] EDAC/skx: Fix overflows on the DRAM row address mapping arrays - regulator: core: Shorten off-on-delay-us for always-on/boot-on by time since booted - [arm64] dts: ti: k3-am62a7-sk: Fix DDR size to full 4GB - [arm64] dts: qcom: msm8998: Fix stm-stimulus-base reg name - [arm64] dts: qcom: sdm845: correct dynamic power coefficients - [x86] MCE/AMD: Use an u64 for bank_map - [arm64] firmware: qcom_scm: Clear download bit during reboot - [arm64] drm/bridge: adv7533: Fix adv7533_mode_valid for adv7533 and adv7535 - [arm64] drm/msm/adreno: drop bogus pm_runtime_set_active() - [arm64] drm: msm: adreno: Disable preemption on Adreno 510 - [amd64] virt/coco/sev-guest: Double-buffer messages - [arm64] dts: qcom: sm8350-microsoft-surface: fix USB dual-role mode property - [x86] ACPI: processor: Fix evaluating _PDC method when running as Xen dom0 - [arm64] mmc: sdhci-of-esdhc: fix quirk to ignore command inhibit for data - [armhf] dts: gta04: fix excess dma channel usage - [arm64] firmware: arm_scmi: Fix xfers allocation on Rx channel - [arm64] perf/arm-cmn: Move overlapping wp_combine field - [armhf] dts: stm32: fix spi1 pin assignment on stm32mp15 - [arm64] cpufreq: qcom-cpufreq-hw: Revert adding cpufreq qos - [arm64,armhf] drm/lima/lima_drv: Add missing unwind goto in lima_pdev_probe() - [arm64,armhf] gpu: host1x: Fix potential double free if IOMMU is disabled - [arm64,armhf] gpu: host1x: Fix memory leak of device names - drm/ttm: optimize pool allocations a bit v2 - drm/ttm/pool: Fix ttm_pool_alloc error path - regulator: core: Consistently set mutex_owner when using ww_mutex_lock_slow() - regulator: core: Avoid lockdep reports when resolving supplies - [x86] apic: Fix atomic update of offset in reserve_eilvt_offset() - [arm64] dts: qcom: msm8994-angler: Fix cont_splash_mem mapping - [arm64] dts: qcom: msm8994-angler: removed clash with smem_region - [arm64,armhf] media: cedrus: fix use after free bug in cedrus_remove due to race condition (CVE-2023-35826) - [arm64] media: rkvdec: fix use after free bug in rkvdec_remove (CVE-2023-35829) - [amd64] platform/x86/amd: pmc: Don't try to read SMU version on Picasso - [amd64] platform/x86/amd: pmc: Hide SMU version and program attributes for Picasso - [amd64] platform/x86/amd: pmc: Don't dump data after resume from s0i3 on picasso - [amd64] platform/x86/amd: pmc: Move idlemask check into `amd_pmc_idlemask_read` - [amd64] platform/x86/amd: pmc: Utilize SMN index 0 for driver probe - [amd64] platform/x86/amd: pmc: Move out of BIOS SMN pair for STB init - media: dm1105: Fix use after free bug in dm1105_remove due to race condition (CVE-2023-35824) - media: saa7134: fix use after free bug in saa7134_finidev due to race condition (CVE-2023-35823) - media: v4l: async: Return async sub-devices to subnotifier list - drm/amd/display: Fix potential null dereference - [arm64,armhf] media: rc: gpio-ir-recv: Fix support for wake-up - [arm64] media: venus: dec: Fix handling of the start cmd - [arm64] media: venus: dec: Fix capture formats enumeration order - [armhf] regulator: stm32-pwr: fix of_iomap leak - [x86] ioapic: Don't return 0 from arch_dynirq_lower_bound() - [arm64] kgdb: Set PSTATE.SS to 1 to re-enable single-step - [arm64] perf/arm-cmn: Fix port detection for CMN-700 - [x86] drm/i915: Make intel_get_crtc_new_encoder() less oopsy - tick/common: Align tick period with the HZ tick. - ACPI: bus: Ensure that notify handlers are not running after removal - cpufreq: use correct unit when verify cur freq - [arm64] rpmsg: glink: Propagate TX failures in intentless mode as well - platform/chrome: cros_typec_switch: Add missing fwnode_handle_put() - wifi: ath6kl: minor fix for allocation size - wifi: ath9k: hif_usb: fix memory leak of remain_skbs - wifi: ath11k: Use platform_get_irq() to get the interrupt - wifi: ath5k: Use platform_get_irq() to get the interrupt - wifi: ath5k: fix an off by one check in ath5k_eeprom_read_freq_list() - wifi: ath11k: fix SAC bug on peer addition with sta band migration - wifi: brcmfmac: support CQM RSSI notification with older firmware - wifi: ath6kl: reduce WARN to dev_dbg() in callback - tools: bpftool: Remove invalid \' json escape - wifi: rtw88: mac: Return the original error from rtw_pwr_seq_parser() - wifi: rtw88: mac: Return the original error from rtw_mac_power_switch() - bpf: take into account liveness when propagating precision - bpf: fix precision propagation verbose logging - [x86] crypto: qat - fix concurrency issue when device state changes - scm: fix MSG_CTRUNC setting condition for SO_PASSSEC - wifi: ath11k: fix deinitialization of firmware resources - bpf: Remove misleading spec_v1 check on var-offset stack read - net: pcs: xpcs: remove double-read of link state when using AN - vlan: partially enable SIOCSHWTSTAMP in container - net/packet: annotate accesses to po->xmit - net/packet: convert po->origdev to an atomic flag - net/packet: convert po->auxdata to an atomic flag - libbpf: Fix ld_imm64 copy logic for ksym in light skeleton. - netfilter: keep conntrack reference until IPsecv6 policy checks are done - bpf: Fix __reg_bound_offset 64->32 var_off subreg propagation - scsi: target: core: Change the way target_xcopy_do_work() sets restiction on max I/O - scsi: target: Move sess cmd counter to new struct - scsi: target: Move cmd counter allocation - scsi: target: Pass in cmd counter to use during cmd setup - scsi: target: iscsit: isert: Alloc per conn cmd counter - scsi: target: iscsit: Stop/wait on cmds during conn close - scsi: target: Fix multiple LUN_RESET handling - scsi: target: iscsit: Fix TAS handling during conn cleanup - scsi: megaraid: Fix mega_cmd_done() CMDID_INT_CMDS - net: sunhme: Fix uninitialized return code - f2fs: handle dqget error in f2fs_transfer_project_quota() - f2fs: fix uninitialized skipped_gc_rwsem - f2fs: apply zone capacity to all zone type - f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() - f2fs: fix scheduling while atomic in decompression path - [arm64,armhf] crypto: caam - Clear some memory in instantiate_rng - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_rfreg() - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_reg() - scsi: libsas: Add sas_ata_device_link_abort() - [arm64] scsi: hisi_sas: Handle NCQ error when IPTT is valid - wifi: rt2x00: Fix memory leak when handling surveys - f2fs: fix iostat lock protection - net: qrtr: correct types of trace event parameters - bpftool: Fix bug for long instructions in program CFG dumps - crypto: drbg - Only fail when jent is unavailable in FIPS mode - xsk: Fix unaligned descriptor validation - f2fs: fix to avoid use-after-free for cached IPU bio - wifi: iwlwifi: fix duplicate entry in iwl_dev_info_table - bpf/btf: Fix is_int_ptr() - scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: rework optional clock handling - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: fix optional phy regulator handling - wifi: ath11k: fix writing to unintended memory region - bpf, sockmap: fix deadlocks in the sockhash and sockmap - nvmet: fix error handling in nvmet_execute_identify_cns_cs_ns() - nvmet: fix Identify Namespace handling - nvmet: fix Identify Controller handling - nvmet: fix Identify Active Namespace ID list handling - nvmet: fix I/O Command Set specific Identify Controller - nvme: fix async event trace event - blk-mq: don't plug for head insertions in blk_execute_rq_nowait - wifi: iwlwifi: debug: fix crash in __iwl_err() - wifi: iwlwifi: trans: don't trigger d3 interrupt twice - wifi: iwlwifi: mvm: don't set CHECKSUM_COMPLETE for unsupported protocols - bpf, sockmap: Revert buggy deadlock fix in the sockhash and sockmap - f2fs: fix to check return value of f2fs_do_truncate_blocks() - f2fs: fix to check return value of inc_valid_block_count() - md/raid10: fix task hung in raid10d - md/raid10: fix leak of 'r10bio->remaining' for recovery - md/raid10: fix memleak for 'conf->bio_split' - md/raid10: fix memleak of md thread - md/raid10: don't call bio_start_io_acct twice for bio which experienced read error - wifi: iwlwifi: mvm: don't drop unencrypted MCAST frames - wifi: iwlwifi: yoyo: skip dump correctly on hw error - wifi: iwlwifi: yoyo: Fix possible division by zero - wifi: iwlwifi: mvm: initialize seq variable - wifi: iwlwifi: fw: move memset before early return - jdb2: Don't refuse invalidation of already invalidated buffers - io_uring/rsrc: use nospec'ed indexes - wifi: iwlwifi: make the loop for card preparation effective - wifi: mt76: handle failure of vzalloc in mt7615_coredump_work - wifi: mt76: add flexible polling wait-interval support - wifi: mt76: mt7921e: fix probe timeout after reboot - wifi: mt76: fix 6GHz high channel not be scanned - mt76: mt7921: fix kernel panic by accessing unallocated eeprom.data - wifi: mt76: mt7921: fix missing unwind goto in `mt7921u_probe` - wifi: mt76: mt7921e: improve reliability of dma reset - wifi: mt76: mt7921e: stop chip reset worker in unregister hook - wifi: mt76: connac: fix txd multicast rate setting - wifi: iwlwifi: mvm: check firmware response size - netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert() - netfilter: conntrack: fix wrong ct->timeout value - wifi: iwlwifi: fw: fix memory leak in debugfs - ixgbe: Allow flow hash to be set via ethtool - ixgbe: Enable setting RSS table to default values - net/mlx5e: Don't clone flow post action attributes second time - net/mlx5: E-switch, Create per vport table based on devlink encap mode - net/mlx5: E-switch, Don't destroy indirect table in split rule - net/mlx5e: Fix error flow in representor failing to add vport rx rule - net/mlx5: Suspend auxiliary devices only in case of PCI device suspend - net/mlx5: Use recovery timeout on sync reset flow - net/mlx5e: Nullify table pointer when failing to create - net: stmmac:fix system hang when setting up tag_8021q VLAN for DSA ports - bpf: Fix race between btf_put and btf_idr walk. - bpf: Don't EFAULT for getsockopt with optval=NULL - netfilter: nf_tables: don't write table validation state without mutex - net/sched: sch_fq: fix integer overflow of "credit" - ipv4: Fix potential uninit variable access bug in __ip_make_skb() - Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" - netlink: Use copy_to_user() for optval in netlink_getsockopt(). - [x86] net: amd: Fix link leak when verifying config failed - tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp. - [x86] ASoC: cs35l41: Only disable internal boost - drivers: staging: rtl8723bs: Fix locking in _rtw_join_timeout_handler() - drivers: staging: rtl8723bs: Fix locking in rtw_scan_timeout_handler() - [arm64] usb: host: xhci-rcar: remove leftover quirk handling - [arm64,armhf] usb: dwc3: gadget: Change condition for processing suspend event - [armhf] serial: stm32: Re-assert RTS/DE GPIO in RS485 mode only if more data are transmitted - iio: light: max44009: add missing OF device matching - [arm64,armhf] spi: imx: Don't skip cleanup in remove's error path - [x86] ASoC: soc-compress: Inherit atomicity from DAI link for Compress FE - [arm64,armhf] PCI: imx6: Install the fault handler only on compatible match - ASoC: es8316: Handle optional IRQ assignment - [arm64] spi: qup: Don't skip cleanup in remove's error path - [x86] vmci_host: fix a race condition in vmci_host_poll() causing GPF - of: Fix modalias string generation - [amd64] HID: amd_sfh: Correct the structure fields - [amd64] HID: amd_sfh: Correct the sensor enable and disable command - [amd64] HID: amd_sfh: Fix illuminance value - [amd64] HID: amd_sfh: Add support for shutdown operation - [amd64] HID: amd_sfh: Correct the stop all command - [amd64] HID: amd_sfh: Increase sensor command timeout for SFH1.1 - [amd64] HID: amd_sfh: Handle "no sensors" enabled for SFH1.1 - cacheinfo: Check sib_leaf in cache_leaves_are_shared() - [arm64] coresight: etm_pmu: Set the module field - PCI/PM: Extend D3hot delay for NVIDIA HDA controllers - spi: cadence-quadspi: fix suspend-resume implementations - [arm64,armhf] usb: chipidea: fix missing goto in `ci_hdrc_probe` - [arm64] tty: serial: fsl_lpuart: adjust buffer length to the intended size - serial: 8250: Add missing wakeup event reporting - spi: cadence-quadspi: use macro DEFINE_SIMPLE_DEV_PM_OPS - [x86] staging: rtl8192e: Fix W_DISABLE# does not work after stop/start - [arm64] spmi: Add a check for remove callback when removing a SPMI driver - virtio_ring: don't update event idx on get_buf - [powerpc*] rtas: use memmove for potentially overlapping buffer copy - sched/fair: Fix inaccurate tally of ttwu_move_affine - perf/core: Fix hardlockup failure caused by perf throttle - Revert "objtool: Support addition to set CFA base" - sched/rt: Fix bad task migration for rt tasks - tracing/user_events: Ensure write index cannot be negative - [amd64] IB/hifi1: add a null check of kzalloc_node in hfi1_ipoib_txreq_init - [amd64] RDMA/rdmavt: Delete unnecessary NULL check - workqueue: Fix hung time report of worker pools - [armhf] rtc: omap: include header for omap_rtc_power_off_program prototype - RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() - [arm64,armhf] rtc: meson-vrtc: Use ktime_get_real_ts64() to get the current time - clk: add missing of_node_put() in "assigned-clocks" property parsing - [arm64] power: supply: rk817: Fix low SOC bugs - RDMA/cm: Trace icm_send_rej event before the cm state is reset - RDMA/srpt: Add a check for valid 'mad_agent' pointer - [amd64] IB/hfi1: Fix SDMA mmu_rb_node not being evicted in LRU order - [amd64] IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests - [arm64,armhf] clk: imx: fracn-gppll: fix the rate table - [arm64,armhf] clk: imx: fracn-gppll: disable hardware select control - NFSv4.1: Always send a RECLAIM_COMPLETE after establishing lease - [amd64] iommu/amd: Set page size bitmap during V2 domain allocation - [arm64] Input: raspberrypi-ts - fix refcount leak in rpi_ts_probe - swiotlb: relocate PageHighMem test away from rmem_swiotlb_setup - swiotlb: fix debugfs reporting of reserved memory pools - RDMA/mlx5: Check pcie_relaxed_ordering_enabled() in UMR - RDMA/mlx5: Fix flow counter query via DEVX - SUNRPC: remove the maximum number of retries in call_bind_status - RDMA/mlx5: Use correct device num_ports when modify DC - timekeeping: Fix references to nonexistent ktime_get_fast_ns() - SMB3: Add missing locks to protect deferred close file list - SMB3: Close deferred file handles in case of handle lease break - ext4: fix i_disksize exceeding i_size problem in paritally written case - ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline - [arm64] dmaengine: mv_xor_v2: Fix an error code. - [armhf] leds: tca6507: Fix error handling of using fwnode_property_read_string - soundwire: cadence: rename sdw_cdns_dai_dma_data as sdw_cdns_dai_runtime - [x86] soundwire: intel: don't save hw_params for use in prepare - [arm64,armhf] phy: tegra: xusb: Add missing tegra_xusb_port_unregister for usb2_port and ulpi_port - [arm64,armhf] pinctrl-bcm2835.c: fix race condition when setting gpio dir - [x86] ACPI: PM: Do not turn of unused power resources on the Toshiba Click Mini - PM: hibernate: Turn snapshot_test into global variable - PM: hibernate: Do not get block device exclusively in test_resume mode - afs: Fix updating of i_size with dv jump from server - afs: Fix getattr to report server i_size on dirs, not local size - afs: Avoid endless loop if file is larger than expected - ALSA: usb-audio: Add quirk for Pioneer DDJ-800 - [x86] ALSA: hda/realtek: Add quirk for ThinkPad P1 Gen 6 - [x86] ALSA: hda/realtek: Add quirk for ASUS UM3402YAR using CS35L41 - [x86] ALSA: hda/realtek: support HP Pavilion Aero 13-be0xxx Mute LED - [x86] ALSA: hda/realtek: Fix mute and micmute LEDs for an HP laptop - nilfs2: do not write dirty data after degenerating to read-only - nilfs2: fix infinite loop in nilfs_mdt_get_block() - mm: do not reclaim private data from pinned page - drbd: correctly submit flush bio on barrier - md/raid10: fix null-ptr-deref in raid10_sync_request - md/raid5: Improve performance for sequential IO - mtd: core: provide unique name for nvmem device, take two - mtd: core: fix nvmem error reporting - mtd: core: fix error path for nvmem provider - mtd: spi-nor: core: Update flash's current address mode when changing address mode - [arm64] mailbox: zynqmp: Fix IPI isr handling - [arm64] mailbox: zynqmp: Fix typo in IPI documentation - wifi: rtl8xxxu: RTL8192EU always needs full init - wifi: rtw89: fix potential race condition between napi_init and napi_enable - [arm64] clk: rockchip: rk3399: allow clk_cifout to force clk_cifout_src to reparent - btrfs: scrub: reject unsupported scrub flags - [s390x] dasd: fix hanging blockdevice after request requeue - mm/mempolicy: correctly update prev when policy is equal on mbind - dm verity: fix error handling for check_at_most_once on FEC - dm integrity: call kmem_cache_destroy() in dm_integrity_init() error path - dm flakey: fix a crash with invalid table line - dm ioctl: fix nested locking in table_clear() to remove deadlock concern (CVE-2023-2269) - dm: don't lock fs when the map is NULL in process of resume - blk-iocost: avoid 64-bit division in ioc_timer_fn - cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname - cifs: protect session status check in smb2_reconnect() - [x86] thunderbolt: Use correct type in tb_port_is_clx_enabled() prototype - wifi: ath11k: synchronize ath11k_mac_he_gi_to_nl80211_he_gi()'s return type - [x86] perf auxtrace: Fix address filter entire kernel size - [x86] perf intel-pt: Fix CYC timestamps after standalone CBR - i40e: Remove unused i40e status codes - i40e: Remove string printing for i40e_status - i40e: use int for i40e_status - scsi: libsas: Grab the ATA port lock in sas_ata_device_link_abort() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.29 - [arm64,armhf] USB: dwc3: gadget: drop dead hibernation code - [arm64,armhf] usb: dwc3: gadget: Execute gadget stop after halting the controller - drm/vmwgfx: Remove explicit and broken vblank handling - drm/vmwgfx: Fix Legacy Display Unit atomic drm support - [amd64] crypto: ccp - Clear PSP interrupt status register before calling handler - [x86] perf/x86/core: Zero @lbr instead of returning -1 in x86_perf_get_lbr() stub - [x86] KVM: x86: Track supported PERF_CAPABILITIES in kvm_caps - [x86] KVM: x86/pmu: Disallow legacy LBRs if architectural LBRs are available - mtd: spi-nor: spansion: Remove NO_SFDP_FLAGS from s28hs512t info - mtd: spi-nor: add SFDP fixups for Quad Page Program - mtd: spi-nor: Add a RWW flag - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s28hx SEMPER flash - [arm64] mailbox: zynq: Switch to flexible array to simplify code - [arm64] mailbox: zynqmp: Fix counts of child nodes - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s25hx SEMPER flash - drm/amd/display: Ext displays with dock can't recognized after resume - [x86] KVM: x86/mmu: Avoid indirect call for get_cr3 - [x86] KVM: x86: Do not unload MMU roots when only toggling CR0.WP with TDP enabled - [x86] KVM: x86: Make use of kvm_read_cr*_bits() when testing bits - [x86] KVM: VMX: Make CR0.WP a guest owned bit - [x86] KVM: x86/mmu: Refresh CR0.WP prior to checking for emulated permission faults - [x86] ASoC: Intel: soc-acpi-byt: Fix "WM510205" match no longer working - scsi: qedi: Fix use after free bug in qedi_remove() - drm/amd/display: Remove FPU guards from the DML folder - drm/amd/display: Add missing WA and MCLK validation - drm/amd/display: Return error code on DSC atomic check failure - drm/amd/display: Fixes for dcn32_clk_mgr implementation - drm/amd/display: Reset OUTBOX0 r/w pointer on DMUB reset - drm/amd/display: Do not clear GPINT register when releasing DMUB from reset - drm/amd/display: Update bounding box values for DCN321 - ixgbe: Fix panic during XDP_TX with > 64 CPUs - [armhf] net/ncsi: clear Tx enable mode when handling a Config required AEN - tcp: fix skb_copy_ubufs() vs BIG TCP - net/sched: cls_api: remove block_cb from driver_list before freeing - sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() - net: ipv6: fix skb hash for some RST packets - [arm64,armhf] net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu - writeback: fix call of incorrect macro - block: Skip destroyed blkg when restart in blkg_destroy_all() - [arm64,armhf] watchdog: dw_wdt: Fix the error handling path of dw_wdt_drv_probe() - [arm64,armhf] i2c: tegra: Fix PEC support for SMBUS block read - net/sched: act_mirred: Add carrier check - r8152: fix flow control issue of RTL8156A - r8152: fix the poor throughput for 2.5G devices - r8152: move setting r8153b_rx_agg_chg_indicate() - sfc: Fix module EEPROM reporting for QSFP modules - rxrpc: Fix hard call timeout units - [x86] drm/i915/mtl: Add the missing CPU transcoder mask in intel_device_info - ethtool: Fix uninitialized number of lanes - af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). - drm/amdgpu: add a missing lock for AMDGPU_SCHED - ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` - [s390x] KVM: s390: fix race in gmap_make_secure() - ice: block LAN in case of VF to VF offload - virtio_net: suppress cpu stall when free_unused_bufs - [arm64] net: enetc: check the index of the SFI rather than the handle - perf record: Fix "read LOST count failed" msg with sample read - perf scripts intel-pt-events.py: Fix IPC output for Python 2 - perf vendor events s390: Remove UTF-8 characters from JSON file - perf tests record_offcpu.sh: Fix redirection of stderr to stdin - perf ftrace: Make system wide the default target for latency subcommand - perf vendor events power9: Remove UTF-8 characters from JSON files - perf pmu: zfree() expects a pointer to a pointer to zero it after freeing its contents - perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() - perf cs-etm: Fix timeless decode mode detection - crypto: api - Add scaffolding to change completion function signature - crypto: engine - Use crypto_request_complete - crypto: engine - fix crypto_queue backlog handling - perf symbols: Fix return incorrect build_id size in elf_read_build_id() - perf tracepoint: Fix memory leak in is_valid_tracepoint() - perf stat: Separate bperf from bpf_profiler - [x86] retbleed: Fix return thunk alignment - btrfs: fix btrfs_prev_leaf() to not return the same key twice - btrfs: zoned: fix wrong use of bitops API in btrfs_ensure_empty_zones - btrfs: properly reject clear_cache and v1 cache for block-group-tree - btrfs: fix assertion of exclop condition when starting balance - btrfs: fix encoded write i_size corruption with no-holes - btrfs: don't free qgroup space unless specified - btrfs: zero the buffer before marking it dirty in btrfs_redirty_list_add - btrfs: make clear_cache mount option to rebuild FST without disabling it - btrfs: print-tree: parent bytenr must be aligned to sector size - btrfs: fix space cache inconsistency after error loading it from disk - btrfs: zoned: zone finish data relocation BG with last IO - btrfs: zoned: fix full zone super block reading on ZNS - cifs: fix pcchunk length type in smb2_copychunk_range - cifs: release leases for deferred close handles when freezing - [amd64] platform/x86/intel-uncore-freq: Return error on write frequency - [x86] platform/x86: touchscreen_dmi: Add upside-down quirk for GDIX1002 ts on the Juno Tablet - [x86] platform/x86: thinkpad_acpi: Fix platform profiles on T490 - [x86] platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i - [x86] platform/x86: thinkpad_acpi: Add profile force ability - inotify: Avoid reporting event with invalid wd - smb3: fix problem remounting a share after shutdown - SMB3: force unmount was failing to close deferred close files - [armhf] remoteproc: stm32: Call of_node_put() on iteration error - sysctl: clarify register_sysctl_init() base directory order - [armhf] ARM: dts: aspeed: asrock: Correct firmware flash SPI clocks - [armhf] ARM: dts: exynos: fix WM8960 clock name in Itop Elite - [armhf] ARM: dts: aspeed: romed8hm3: Fix GPIO polarity of system-fault LED - [arm64] drm/msm/adreno: fix runtime PM imbalance at gpu load - [x86] drm/i915/color: Fix typo for Plane CSC indexes - [arm64] drm/msm: fix NULL-deref on snapshot tear down - [arm64] drm/msm: fix NULL-deref on irq uninstall - [arm64] drm/msm: fix drm device leak on bind errors - [arm64] drm/msm: fix vram leak on bind errors - [arm64] drm/msm: fix workqueue leak on bind errors - [x86] drm/i915/dsi: Use unconditional msleep() instead of intel_dsi_msleep() - f2fs: fix null pointer panic in tracepoint in __replace_atomic_write_block - f2fs: fix potential corruption when moving a directory - [armhf] drm/panel: otm8009a: Set backlight parent to panel device - drm/amd/display: Add NULL plane_state check for cursor disable logic - drm/amd/display: Fix 4to1 MPC black screen with DPP RCO - drm/amd/display: filter out invalid bits in pipe_fuses - drm/amd/display: fix flickering caused by S/G mode - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v10_0_hw_fini - drm/amdgpu: fix an amdgpu_irq_put() issue in gmc_v9_0_hw_fini() - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_fini - drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras - drm/amdgpu/jpeg: Remove harvest checking for JPEG3 - drm/amdgpu: change gfx 11.0.4 external_id range - drm/amdgpu: Fix vram recover doesn't work after whole GPU reset (v2) - drm/amd/display: Enforce 60us prefetch for 200Mhz DCFCLK modes - drm/amd/pm: parse pp_handle under appropriate conditions - drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend - drm/amd/pm: avoid potential UBSAN issue on legacy asics - drm/amdgpu: remove deprecated MES version vars - drm/amd: Load MES microcode during early_init - drm/amd: Add a new helper for loading/validating microcode - drm/amd: Use `amdgpu_ucode_*` helpers for MES - HID: wacom: Set a default resolution for older tablets - HID: wacom: insert timestamp to packed Bluetooth (BT) events - [arm64] drm/msm/adreno: adreno_gpu: Use suspend() instead of idle() on load error - f2fs: specify extent cache for read explicitly - f2fs: move internal functions into extent_cache.c - f2fs: remove unnecessary __init_extent_tree - f2fs: refactor extent_cache to support for read and more - f2fs: allocate the extent_cache by default - f2fs: factor out victim_entry usage from general rb_tree use - [arm64] drm/msm/adreno: Simplify read64/write64 helpers - [arm64] drm/msm: Hangcheck progress detection - [arm64] drm/msm: fix missing wq allocation error handling - wifi: rtw88: rtw8821c: Fix rfe_option field width - [x86] drm/i915/mtl: update scaler source and destination limits for MTL - [x86] drm/i915: Check pipe source size when using skl+ scalers - drm/amd/display: Refactor eDP PSR codes - drm/amd/display: Add Z8 allow states to z-state support list - drm/amd/display: Add debug option to skip PSR CRTC disable - drm/amd/display: Fix Z8 support configurations - drm/amd/display: Add minimum Z8 residency debug option - drm/amd/display: Update minimum stutter residency for DCN314 Z8 - drm/amd/display: Lowering min Z8 residency time - [x86] ASoC: codecs: constify static sdw_slave_ops struct - drm/amd/display: Update Z8 watermarks for DCN314 - drm/amd/display: Update Z8 SR exit/enter latencies - drm/amd/display: Change default Z8 watermark values - ksmbd: Implements sess->ksmbd_chann_list as xarray - ksmbd: fix racy issue from session setup and logoff (CVE-2023-32250) - ksmbd: destroy expired sessions - ksmbd: block asynchronous requests when making a delay on session setup - ksmbd: fix racy issue from smb2 close and logoff with multichannel - drm: Add missing DP DSC extended capability definitions. - drm/dsc: fix drm_edp_dsc_sink_output_bpp() DPCD high byte usage - locking/rwsem: Add __always_inline annotation to __down_read_common() and inlined callers - ext4: fix WARNING in mb_find_extent - ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum (CVE-2023-34256) - ext4: fix data races when using cached status extents - ext4: check iomap type only if ext4_iomap_begin() does not fail - ext4: improve error recovery code paths in __ext4_remount() - ext4: improve error handling from ext4_dirhash() - ext4: fix deadlock when converting an inline directory in nojournal mode - ext4: add bounds checking in get_max_inline_xattr_value_size() - ext4: bail out of ext4_xattr_ibody_get() fails for any reason - ext4: fix lockdep warning when enabling MMP - ext4: remove a BUG_ON in ext4_mb_release_group_pa() - ext4: fix invalid free tracking in ext4_xattr_move_to_block() - drm/dsc: fix DP_DSC_MAX_BPP_DELTA_* macro values - f2fs: fix to do sanity check on extent cache correctly - f2fs: inode: fix to do sanity check on extent cache correctly - [x86] amd_nb: Add PCI ID for family 19h model 78h - [x86] fix clear_user_rep_good() exception handling annotation - drm/amd/display: Fix hang when skipping modeset https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.30 - drm/fbdev-generic: prohibit potential out-of-bounds access - drm/mipi-dsi: Set the fwnode for mipi_dsi_device - net: skb_partial_csum_set() fix against transport header magic value - scsi: ufs: core: Fix I/O hang that occurs when BKOPS fails in W-LUN suspend - tick/broadcast: Make broadcast device replacement work correctly - linux/dim: Do nothing if no time delta between samples - net: stmmac: Initialize MAC_ONEUS_TIC_COUNTER register - net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). - [arm64,armhf] net: phy: bcm7xx: Correct read from expansion register - netfilter: nf_tables: always release netdev hooks from notifier - netfilter: conntrack: fix possible bug_on with enable_hooks=1 - bonding: fix send_peer_notif overflow - netlink: annotate accesses to nlk->cb_running - net: annotate sk->sk_err write from do_recvmmsg() - net: deal with most data-races in sk_wait_event() - net: add vlan_get_protocol_and_depth() helper - tcp: add annotations around sk->sk_shutdown accesses - [amd64,arm64] gve: Remove the code of clearing PBA bit - ipvlan:Fix out-of-bounds caused by unclear skb->cb (CVE-2023-3090) - [arm64] net: mscc: ocelot: fix stat counter register values - net: datagram: fix data-races in datagram_poll() - af_unix: Fix a data race of sk->sk_receive_queue->qlen. - af_unix: Fix data races around sk->sk_shutdown. - [x86] drm/i915/guc: Don't capture Gen8 regs on Xe devices - [x86] drm/i915: Fix NULL ptr deref by checking new_crtc_state - [x86] drm/i915/dp: prevent potential div-by-zero - [x86] drm/i915: Expand force_probe to block probe of devices as well. - [x86] drm/i915: taint kernel when force probing unsupported devices - [x86] fbdev: arcfb: Fix error handling in arcfb_probe() - ext4: reflect error codes from ext4_multi_mount_protect() to its callers - ext4: allow to find by goal if EXT4_MB_HINT_GOAL_ONLY is set - ext4: allow ext4_get_group_info() to fail - rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access - open: return EINVAL for O_DIRECTORY | O_CREAT - fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() - drm/displayid: add displayid_get_header() and check bounds better - drm/amd/display: populate subvp cmd info only for the top pipe - drm/amd/display: Correct DML calculation to align HW formula - [x86] platform/x86: x86-android-tablets: Add Acer Iconia One 7 B1-750 data - drm/amd/display: Enable HostVM based on rIOMMU active - drm/amd/display: Use DC_LOG_DC in the trasform pixel function - regmap: cache: Return error in cache sync operations for REGCACHE_NONE - [arm64] dts: qcom: msm8996: Add missing DWC3 quirks - media: cx23885: Fix a null-ptr-deref bug in buffer_prepare() and buffer_finish() - media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() - [arm64,armhf] drm/rockchip: dw_hdmi: cleanup drm encoder during unbind - memstick: r592: Fix UAF bug in r592_remove due to race condition (CVE-2023-3141) - ACPI: EC: Fix oops when removing custom query handlers - drm/amd/display: fixed dcn30+ underflow issue - [armhf] remoteproc: stm32_rproc: Add mutex protection for workqueue - [arm64,armhf] drm/tegra: Avoid potential 32-bit integer overflow - [arm64] drm/msm/dp: Clean up handling of DP AUX interrupts - ACPICA: Avoid undefined behavior: applying zero offset to null pointer - ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects - [arm64] dts: qcom: sdm845-polaris: Drop inexistent properties - [arm64,armhf] irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 - ACPI: video: Remove desktops without backlight DMI quirks - drm/amd/display: Correct DML calculation to follow HW SPEC - drm/amd: Fix an out of bounds error in BIOS parser - drm/amdgpu: Fix sdma v4 sw fini error - [armhf] media: Prefer designated initializers over memset for subdev pad ops - wifi: ath: Silence memcpy run-time false positive warning - bpf: Annotate data races in bpf_local_storage - wifi: brcmfmac: pcie: Provide a buffer of random bytes to the device - wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex - scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow - scsi: lpfc: Correct used_rpi count when devloss tmo fires with no recovery - bnxt: avoid overflow in bnxt_get_nvram_directory() - net: Catch invalid index in XPS mapping - netdev: Enforce index cap in netdev_get_tx_queue - scsi: target: iscsit: Free cmds before session free - lib: cpu_rmap: Avoid use after free on rmap->obj array entries - scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition - gfs2: Fix inode height consistency check - [x86] scsi: ufs: ufs-pci: Add support for Intel Lunar Lake - ext4: set goal start correctly in ext4_mb_normalize_request - ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() - crypto: jitter - permanent and intermittent health errors - f2fs: Fix system crash due to lack of free space in LFS - f2fs: fix to drop all dirty pages during umount() if cp_error is set - f2fs: fix to check readonly condition correctly - bpf: Add preempt_count_{sub,add} into btf id deny list - md: fix soft lockup in status_resync - wifi: iwlwifi: pcie: fix possible NULL pointer dereference - wifi: iwlwifi: add a new PCI device ID for BZ device - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf - wifi: iwlwifi: mvm: fix ptk_pn memory leak - block, bfq: Fix division by zero error on zero wsum - wifi: ath11k: Ignore frags from uninitialized peer in dp. - wifi: iwlwifi: fix iwl_mvm_max_amsdu_size() for MLO - null_blk: Always check queue mode setting from configfs - wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace - wifi: ath11k: Fix SKB corruption in REO destination ring - nbd: fix incomplete validation of ioctl arg - ipvs: Update width of source for ip_vs_sync_conn_options - Bluetooth: btusb: Add new PID/VID 04ca:3801 for MT7663 - Bluetooth: Add new quirk for broken local ext features page 2 - Bluetooth: btrtl: add support for the RTL8723CS - Bluetooth: Improve support for Actions Semi ATS2851 based devices - Bluetooth: btrtl: check for NULL in btrtl_set_quirks() - Bluetooth: btintel: Add LE States quirk support - Bluetooth: hci_bcm: Fall back to getting bdaddr from EFI if not set - Bluetooth: Add new quirk for broken set random RPA timeout for ATS2851 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp - Bluetooth: btrtl: Add the support for RTL8851B - HID: apple: Set the tilde quirk flag on the Geyser 4 and later - [x86] ASoC: amd: yc: Add DMI entries to support HP OMEN 16-n0xxx (8A42) - HID: logitech-hidpp: Don't use the USB serial for USB devices - HID: logitech-hidpp: Reconcile USB and Unifying serials - [arm64,armhf] spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 - [x86] usb: typec: ucsi: acpi: add quirk for ASUS Zenbook UM325 - ALSA: hda: LNL: add HD Audio PCI ID - [x86] ASoC: amd: Add Dell G15 5525 to quirks list - [x86] ASoC: amd: yc: Add ThinkBook 14 G5+ ARP to quirks list for acp6x - [x86] HID: apple: Set the tilde quirk flag on the Geyser 3 - [x86] HID: Ignore battery for ELAN touchscreen on ROG Flow X13 GV301RA - HID: wacom: generic: Set battery quirk only when we see battery data - usb: typec: tcpm: fix multiple times discover svids error - serial: 8250: Reinit port->pm on port specific driver unbind - [x86] soundwire: dmi-quirks: add remapping for Intel 'Rooks County' NUC M15 - soundwire: qcom: gracefully handle too many ports in DT - soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow - [x86] mfd: intel_soc_pmic_chtwc: Add Lenovo Yoga Book X90F to intel_cht_wc_models - [x86] mfd: intel-lpss: Add Intel Meteor Lake PCH-S LPSS PCI IDs - [x86] platform/x86: Move existing HP drivers to a new hp subdir - [x86] hp-wmi: add micmute to hp_wmi_keymap struct - drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs - xfrm: don't check the default policy if the policy allows the packet - Revert "Fix XFRM-I support for nested ESP tunnels" - [arm64] drm/msm/dp: unregister audio driver during unbind - [arm64] drm/msm/dpu: Assign missing writeback log_mask - [arm64] drm/msm/dpu: Move non-MDP_TOP INTF_INTR offsets out of hwio header - [arm64] drm/msm/dpu: Remove duplicate register defines from INTF - platform: Provide a remove callback that returns no value - [arm64] ASoC: fsl_micfil: Fix error handler with pm_runtime_enable - cpupower: Make TSC read per CPU for Mperf monitor - xfrm: Reject optional tunnel/BEET mode templates in outbound policies - af_key: Reject optional tunnel/BEET mode templates in outbound policies - [arm64] drm/msm: Fix submit error-path leaks - [arm64,armhf] net: fec: Better handle pm_runtime_get() failing in .remove() - net: phy: dp83867: add w/a for packet errors seen with short cables - ALSA: firewire-digi00x: prevent potential use after free - wifi: mt76: connac: fix stats->tx_bytes calculation - [x86] ALSA: hda/realtek: Apply HP B&O top speaker profile to Pavilion 15 - sfc: disable RXFCS and RXALL features by default - vsock: avoid to close connected socket after the timeout - tcp: fix possible sk_priority leak in tcp_v4_send_reset() - [armhf] serial: arc_uart: fix of_iomap leak in `arc_serial_probe` - erspan: get the proto with the md version for collect_md - [arm64] net: hns3: fix output information incomplete for dumping tx queue info with debugfs - [arm64] net: hns3: fix sending pfc frames after reset issue - [arm64] net: hns3: fix reset delay time to avoid configuration timeout - [arm64] net: hns3: fix reset timeout when enable full VF - media: netup_unidvb: fix use-after-free at del_timer() - SUNRPC: double free xprt_ctxt while still in use - SUNRPC: always free ctxt when freeing deferred request - SUNRPC: Fix trace_svc_register() call site - [x86] ASoC: SOF: topology: Fix logic for copying tuples - net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() - virtio-net: Maintain reverse cleanup order - virtio_net: Fix error unwinding of XDP initialization - tipc: add tipc_bearer_min_mtu to calculate min mtu - tipc: do not update mtu if msg_max is too small in mtu negotiation - tipc: check the bearer min mtu properly when setting it by netlink - [s390x] cio: include subchannels without devices also for evaluation - can: dev: fix missing CAN XL support in can_put_echo_skb() - [arm64] net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() - [arm64] net: bcmgenet: Restore phy_stop() depending upon suspend/close - ice: introduce clear_reset_state operation - ice: Fix ice VF reset during iavf initialization - wifi: cfg80211: Drop entries with invalid BSSIDs in RNR - wifi: mac80211: fortify the spinlock against deadlock by interrupt - wifi: mac80211: fix min center freq offset tracing - wifi: mac80211: Abort running color change when stopping the AP - wifi: iwlwifi: mvm: fix cancel_delayed_work_sync() deadlock - wifi: iwlwifi: fw: fix DBGI dump - wifi: iwlwifi: fix OEM's name in the ppag approved list - wifi: iwlwifi: mvm: fix OEM's name in the tas approved list - wifi: iwlwifi: mvm: don't trust firmware n_channels - scsi: storvsc: Don't pass unused PFNs to Hyper-V host - net: tun: rebuild error handling in tun_get_user - tun: Fix memory leak for detached NAPI queue. - cassini: Fix a memory leak in the error handling path of cas_init_one() - [arm64,armhf] net: dsa: mv88e6xxx: Fix mv88e6393x EPC write command offset - igb: fix bit_shift to be in [1..8] range - vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() - net: wwan: iosm: fix NULL pointer dereference when removing device - net: pcs: xpcs: fix C73 AN not getting enabled - netfilter: nf_tables: fix nft_trans type confusion - netfilter: nft_set_rbtree: fix null deref on element insertion - ALSA: usb-audio: Add a sample rate workaround for Line6 Pod Go - USB: usbtmc: Fix direction for 0-length ioctl control messages - usb-storage: fix deadlock when a scsi command timeouts more than once - USB: UHCI: adjust zhaoxin UHCI controllers OverCurrent bit value - [arm64,armhf] usb: dwc3: gadget: Improve dwc3_gadget_suspend() and dwc3_gadget_resume() - [arm64,armhf] usb: dwc3: debugfs: Resume dwc3 before accessing registers - usb: gadget: u_ether: Fix host MAC address case - usb: typec: altmodes/displayport: fix pin_assignment_show - xhci-pci: Only run d3cold avoidance quirk for s2idle - xhci: Fix incorrect tracking of free space on transfer rings - ALSA: hda: Fix Oops by 9.1 surround channel names - ALSA: hda: Add NVIDIA codec IDs a3 through a7 to patch table - [x86] ALSA: hda/realtek: Add quirk for Clevo L140AU - [x86] ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 - [x86] ALSA: hda/realtek: Add quirk for 2nd ASUS GU603 - [x86] ALSA: hda/realtek: Add quirk for HP EliteBook G10 laptops - ALSA: hda/realtek: Fix mute and micmute LEDs for yet another HP laptop - can: j1939: recvmsg(): allow MSG_CMSG_COMPAT flag - can: isotp: recvmsg(): allow MSG_CMSG_COMPAT flag - wifi: rtw88: use work to update rate to avoid RCU warning - SMB3: Close all deferred handles of inode in case of handle lease break - SMB3: drop reference to cfile before sending oplock break - ksmbd: smb2: Allow messages padded to 8byte boundary - ksmbd: allocate one more byte for implied bcc[0] - ksmbd: fix wrong UserName check in session_user - ksmbd: fix global-out-of-bounds in smb2_find_context_vals - KVM: Fix vcpu_array[0] races - statfs: enforce statfs[64] structure initialization - maple_tree: make maple state reusable after mas_empty_area() (Closes: #1036755) - mm: fix zswap writeback race condition - serial: Add support for Advantech PCI-1611U card - serial: 8250_exar: Add support for USR298x PCI Modems - [arm64] serial: qcom-geni: fix enabling deactivated interrupt - [x86] thunderbolt: Clear registers properly when auto clear isn't in use - vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF - ceph: force updating the msg pointer in non-split case - drm/amd/pm: fix possible power mode mismatch between driver and PMFW - drm/amdgpu/gmc11: implement get_vbios_fb_size() - drm/amdgpu/gfx10: Disable gfxoff before disabling powergating. - drm/amdgpu/gfx11: Adjust gfxoff before powergating on gfx11 as well - drm/amdgpu: refine get gpu clock counter method - drm/amdgpu/gfx11: update gpu_clock_counter logic - [powerpc*] iommu: DMA address offset is incorrectly calculated with 2MB TCEs - [powerpc*] iommu: Incorrect DDW Table is referenced for SR-IOV device - tpm/tpm_tis: Disable interrupts for more Lenovo devices - [powerpc*] 64s/radix: Fix soft dirty tracking - nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() - [s390x] dasd: fix command reject error on ESE devices - [s390x] crypto: use vector instructions only if available for ChaCha20 - [s390x] qdio: fix do_sqbs() inline assembly constraint - [arm64] mte: Do not set PG_mte_tagged if tags were not initialized - [x86] rethook: use preempt_{disable, enable}_notrace in rethook_trampoline_handler - [x86] rethook, fprobe: do not trace rethook related functions - crypto: testmgr - fix RNG performance in fuzz tests - drm/amdgpu: declare firmware for new MES 11.0.4 - drm/amd/amdgpu: introduce gc_*_mes_2.bin v2 - drm/amdgpu: reserve the old gc_11_0_*_mes.bin https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.31 - [arm64,armhf] usb: dwc3: fix gadget mode suspend interrupt handler issue - tpm, tpm_tis: Avoid cache incoherency in test for interrupts - tpm, tpm_tis: Only handle supported interrupts - tpm_tis: Use tpm_chip_{start,stop} decoration inside tpm_tis_resume - tpm, tpm_tis: startup chip before testing for interrupts - tpm: Re-enable TPM chip boostrapping non-tpm_tis TPM drivers - tpm: Prevent hwrng from activating during resume - [x86] watchdog: sp5100_tco: Immediately trigger upon starting. - drm/amd/amdgpu: update mes11 api def - drm/amdgpu/mes11: enable reg active poll - skbuff: Proactively round up to kmalloc bucket size - [arm64,armhf] net: dsa: mv88e6xxx: Add RGMII delay to 88E6320 - drm/amd/display: hpd rx irq not working with eDP interface - ocfs2: Switch to security_inode_init_security() - [x86] mm: Avoid incomplete Global INVLPG flushes - [x86] ALSA: hda/ca0132: add quirk for EVGA X299 DARK - ALSA: hda: Fix unhandled register update during auto-suspend period - [x86] ALSA: hda/realtek: Enable headset onLenovo M70/M90 - SUNRPC: Don't change task->tk_status after the call to rpc_exit_task - [arm64,armhf] imc: sdhci-esdhc-imx: make "no-mmc-hs400" works - mmc: block: ensure error propagation for non-blk - [x86] power: supply: axp288_fuel_gauge: Fix external_power_changed race - [arm64] power: supply: bq25890: Fix external_power_changed race - ASoC: rt5682: Disable jack detection interrupt during suspend - net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize - btrfs: use nofs when cleaning up aborted transactions - [x86] drm/mgag200: Fix gamma lut not initialized. - drm/radeon: reintroduce radeon_dp_work_func content - drm/amd/pm: add missing NotifyPowerSource message mapping for SMU13.0.7 - drm/amd/pm: Fix output of pp_od_clk_voltage - Revert "binder_alloc: add missing mmap_lock calls when using the VMA" - Revert "android: binder: stop saving a pointer to the VMA" - binder: add lockless binder_alloc_(set|get)_vma() - binder: fix UAF caused by faulty buffer cleanup - binder: fix UAF of alloc->vma in race with munmap() - drm/amd/amdgpu: limit one queue per gang - [x86] perf/x86/uncore: Correct the number of CHAs on SPR - [x86] topology: Fix erroneous smp_num_siblings on Intel Hybrid platforms - [mips*] irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable - [mips*] irqchip/mips-gic: Use raw spinlock for gic_lock - debugobjects: Don't wake up kswapd from fill_pool() - fbdev: udlfb: Fix endpoint check - net: fix stack overflow when LRO is disabled for virtual interfaces - udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). - USB: core: Add routines for endpoint checks in old drivers - USB: sisusbvga: Add endpoint checks - media: radio-shark: Add endpoint checks - net: fix skb leak in __skb_tstamp_tx() - drm: fix drmm_mutex_init() - bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields - bpf: fix a memory leak in the LRU and LRU_PERCPU hash maps - ipv6: Fix out-of-bounds access in ipv6_find_tlv() - cifs: mapchars mount option ignored - power: supply: leds: Fix blink to LED on transition - power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition - power: supply: bq27xxx: Fix I2C IRQ race on remove - power: supply: bq27xxx: Fix poll_interval handling and races on remove - power: supply: bq27xxx: Add cache parameter to bq27xxx_battery_current_and_status() - power: supply: bq27xxx: Move bq27xxx_battery_update() down - power: supply: bq27xxx: Ensure power_supply_changed() is called on current sign changes - power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize - [arm64] power: supply: bq25890: Call power_supply_changed() after updating input current or voltage - [x86] power: supply: bq24190: Call power_supply_changed() after updating input current - [arm64] optee: fix uninited async notif value - fs: fix undefined behavior in bit shift for SB_NOUSER - [arm64] regulator: pca9450: Fix BUCK2 enable_mask - [x86] platform/x86: ISST: Remove 8 socket limit - [armhf] dts: imx6qdl-mba6: Add missing pvcie-supply regulator - [x86] pci/xen: populate MSI sysfs entries - [x86] show_trace_log_lvl: Ensure stack pointer is aligned, again - [x86] ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg - cxl: Wait Memory_Info_Valid before access memory related info - sctp: fix an issue that plpmtu can never go to complete state - [x86] forcedeth: Fix an error handling path in nv_probe() - net/mlx5e: Fix SQ wake logic in ptp napi_poll context - net/mlx5e: Fix deadlock in tc route query code - net/mlx5e: Use correct encap attribute during invalidation - net/mlx5e: do as little as possible in napi poll when budget is 0 - [s390x] net/mlx5: DR, Fix crc32 calculation to work on big-endian (BE) CPUs - net/mlx5: Handle pairing of E-switch via uplink un/load APIs - net/mlx5: DR, Check force-loopback RC QP capability independently from RoCE - net/mlx5: Fix error message when failing to allocate device memory - net/mlx5: Collect command failures data only for known commands - net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device - net/mlx5: Devcom, serialize devcom registration - [arm64] dts: imx8mn-var-som: fix PHY detection bug by adding deassert delay - net/smc: Reset connection when trying to use SMCRv2 fails. - [x86] 3c589_cs: Fix an error handling path in tc589_probe() - net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.32 - inet: Add IP_LOCAL_PORT_RANGE socket option - ipv{4,6}/raw: fix output xfrm lookup wrt protocol - tls: rx: device: fix checking decryption status - tls: rx: strp: set the skb->len of detached / CoW'ed skbs - tls: rx: strp: fix determining record length in copy mode - tls: rx: strp: force mixed decrypted records into copy mode - tls: rx: strp: factor out copying skb data - tls: rx: strp: preserve decryption status of skbs when needed - net/mlx5: E-switch, Devcom, sync devcom events and devcom comp register - [x86] gpio-f7188x: fix chip name and pin count on Nuvoton chip - bpf, sockmap: Pass skb ownership through read_skb - bpf, sockmap: Convert schedule_work into delayed_work - bpf, sockmap: Reschedule is now done through backlog - bpf, sockmap: Improved check for empty queue - bpf, sockmap: Handle fin correctly - bpf, sockmap: TCP data stall on recv before accept - bpf, sockmap: Wake up polling after data copy - bpf, sockmap: Incorrectly handling copied_seq - blk-mq: fix race condition in active queue accounting - vfio/type1: check pfn valid before converting to struct page - net: page_pool: use in_softirq() instead - page_pool: fix inconsistency for page_pool_ring_[un]lock() - net: phy: mscc: enable VSC8501/2 RGMII RX clock - wifi: iwlwifi: mvm: support wowlan info notification version 2 - wifi: iwlwifi: mvm: fix potential memory leak - RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" - drm/amd: Don't allow s0ix on APUs older than Raven - bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() - block: fix bio-cache for passthru IO - [x86] cpufreq: amd-pstate: Update policy->cur in amd_pstate_adjust_perf() - [x86] cpufreq: amd-pstate: Add ->fast_switch() callback - netfilter: ctnetlink: Support offloaded conntrack entry deletion https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.33 - [arm64,armhf] phy: amlogic: phy-meson-g12a-mipi-dphy-analog: fix CNTL2_DIF_TX_CTL0 value - [arm64] RDMA/hns: Fix timeout attr in query qp for HIP08 - [arm64] RDMA/hns: Fix base address table allocation - [arm64] RDMA/hns: Modify the value of long message loopback slice - [arm64,armhf] iommu/rockchip: Fix unwind goto issue - [amd64] iommu/amd: Don't block updates to GATag if guest mode is on - [amd64] iommu/amd: Handle GALog overflows - [amd64] iommu/amd: Fix up merge conflict resolution - nfsd: make a copy of struct iattr before calling notify_change - net/mlx5: Drain health before unregistering devlink - net/mlx5: SF, Drain health before removing device - net/mlx5: fw_tracer, Fix event handling - net/mlx5e: Don't attach netdev profile while handling internal error - netrom: fix info-leak in nr_write_internal() - af_packet: Fix data-races of pkt_sk(sk)->num. - tls: improve lockless access safety of tls_err_abort() - [amd64,arm64] amd-xgbe: fix the false linkup in xgbe_phy_status - perf ftrace latency: Remove unnecessary "--" from --use-nsec option - RDMA/irdma: Prevent QP use after free - RDMA/irdma: Fix Local Invalidate fencing - af_packet: do not use READ_ONCE() in packet_bind() - tcp: deny tcp_disconnect() when threads are waiting - tcp: Return user_mss for TCP_MAXSEG in CLOSE/LISTEN state if user_mss set - net/smc: Scan from current RMB list when no position specified - net/smc: Don't use RMBs not mapped to new link in SMCRv2 ADD LINK - net/sched: sch_ingress: Only create under TC_H_INGRESS - net/sched: sch_clsact: Only create under TC_H_CLSACT - net/sched: Reserve TC_H_INGRESS (TC_H_CLSACT) for ingress (clsact) Qdiscs - net/sched: Prohibit regrafting ingress or clsact Qdiscs - net: sched: fix NULL pointer dereference in mq_attach - net/netlink: fix NETLINK_LIST_MEMBERSHIPS length report - udp6: Fix race condition in udp6_sendmsg & connect - nfsd: fix double fget() bug in __write_ports_addfd() - nvme: fix the name of Zone Append for verbose logging - net/mlx5e: Fix error handling in mlx5e_refresh_tirs - net/mlx5: Read embedded cpu after init bit cleared - net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (CVE-2023-35788) - tcp: fix mishandling when the sack compression is deferred. - [arm64,armhf] net: dsa: mv88e6xxx: Increase wait after reset deactivation - [armhf] mtd: rawnand: marvell: ensure timing values are written - [armhf] mtd: rawnand: marvell: don't set the NAND frequency select - rtnetlink: call validate_linkmsg in rtnl_create_link - mptcp: avoid unneeded __mptcp_nmpc_socket() usage - mptcp: add annotations around msk->subflow accesses - mptcp: avoid unneeded address copy - mptcp: simplify subflow_syn_recv_sock() - mptcp: consolidate passive msk socket initialization - mptcp: fix data race around msk->first access - mptcp: add annotations around sk->sk_shutdown accesses - drm/amdgpu: release gpu full access after "amdgpu_device_ip_late_init" - ALSA: hda: Glenfly: add HD Audio PCI IDs and HDMI Codec Vendor IDs. - [x86] ASoC: Intel: soc-acpi-cht: Add quirk for Nextbook Ares 8A tablet - drm/amdgpu: Use the default reset when loading or reloading the driver - [arm64] drm/ast: Fix ARM compatibility - btrfs: abort transaction when sibling keys check fails for leaves - [armel,armhf] ARM: 9295/1: unwind:fix unwind abort for uleb128 case - [x86] hwmon: (k10temp) Add PCI ID for family 19, model 78h - gfs2: Don't deref jdesc in evict (CVE-2023-3212) - drm/amdgpu: set gfx9 onwards APU atomics support to be true - fbdev: modedb: Add 1920x1080 at 60 Hz video mode - nbd: Fix debugfs_create_dir error checking - nvme-pci: add NVME_QUIRK_BOGUS_NID for HS-SSD-FUTURE 2048G - nvme-pci: add quirk for missing secondary temperature thresholds - [x86] ASoC: amd: yc: Add DMI entry to support System76 Pangolin 12 - xfrm: Check if_id in inbound policy/secpath match - [x86] ALSA: hda/realtek: Add quirks for ASUS GU604V and GU603V - media: dvb_demux: fix a bug for the continuity counter - media: dvb-usb: az6027: fix three null-ptr-deref in az6027_i2c_xfer() - media: dvb-usb-v2: ec168: fix null-ptr-deref in ec168_i2c_xfer() - media: dvb-usb-v2: ce6230: fix null-ptr-deref in ce6230_i2c_master_xfer() - media: dvb-usb-v2: rtl28xxu: fix null-ptr-deref in rtl28xxu_i2c_xfer - media: dvb-usb: digitv: fix null-ptr-deref in digitv_i2c_xfer() - media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address - media: netup_unidvb: fix irq init by register it at the end of probe - media: dvb_ca_en50221: fix a size write bug - media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() - media: dvb-core: Fix use-after-free due on race condition at dvb_net - media: dvb-core: Fix use-after-free due to race at dvb_register_device() - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() (CVE-2023-31084) - media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 - [x86] ASoC: SOF: debug: conditionally bump runtime_pm counter on exceptions - [x86] ASoC: SOF: pcm: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: sof-client-probes: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: pm: save io region state in case of errors in resume - [s390x] topology: honour nr_cpu_ids when adding CPUs - ACPI: resource: Add IRQ override quirk for LG UltraPC 17U70P - wifi: rtl8xxxu: fix authentication timeout due to incorrect RCR value - [arm64] mm: mark private VM_FAULT_X defines as vm_fault_t - [arm64] vdso: Pass (void *) to virt_to_page() - wifi: mac80211: simplify chanctx allocation - wifi: mac80211: consider reserved chanctx for mindef - wifi: mac80211: recalc chanctx mindef before assigning - wifi: iwlwifi: mvm: Add locking to the rate read flow - scsi: core: Decrease scsi_device's iorequest_cnt if dispatch failed - nvme-multipath: don't call blk_mark_disk_dead in nvme_mpath_remove_disk - nvme: do not let the user delete a ctrl before a complete initialization - [arm64] drm/msm: Be more shouty if per-process pgtables aren't working - ceph: silence smatch warning in reconnect_caps_cb() - drm/amdgpu: skip disabling fence driver src_irqs when device is unplugged - nvme-pci: Add quirk for Teamgroup MP33 SSD - block: Deny writable memory mapping if block is read-only - [arm64] KVM: arm64: vgic: Fix a circular locking issue - [arm64] KVM: arm64: vgic: Wrap vgic_its_create() with config_lock - [arm64] KVM: arm64: vgic: Fix locking comment - drivers: base: cacheinfo: Fix shared_cpu_map changes in event of CPU hotplug - media: uvcvideo: Don't expose unsupported formats to userspace - iio: accel: st_accel: Fix invalid mount_matrix on devices without ACPI _ONT method - HID: google: add jewel USB id - HID: wacom: avoid integer overflow in wacom_intuos_inout() - iio: imu: inv_icm42600: fix timestamp reset - iio: light: vcnl4035: fixed chip ID check - iio: adc: ad_sigma_delta: Fix IRQ issue by setting IRQ_DISABLE_UNLAZY flag - iio: dac: mcp4725: Fix i2c_master_send() return value handling - iio: adc: ad7192: Change "shorted" channels to differential - net: usb: qmi_wwan: Set DTR quirk for BroadMobi BM818 - usb: gadget: f_fs: Add unbind event before functionfs_unbind - md/raid5: fix miscalculation of 'end_sector' in raid5_read_one_chunk() - ata: libata-scsi: Use correct device no in ata_find_dev() - drm/amdgpu: enable tmz by default for GC 11.0.1 - drm/amd/pm: reverse mclk and fclk clocks levels for SMU v13.0.4 - drm/amd/pm: reverse mclk and fclk clocks levels for vangogh - drm/amd/pm: resolve reboot exception for si oland - drm/amd/pm: reverse mclk clocks levels for SMU v13.0.5 - drm/amd/pm: reverse mclk and fclk clocks levels for yellow carp - drm/amd/pm: reverse mclk and fclk clocks levels for renoir - [x86] mtrr: Revert 90b926e68f50 ("x86/pat: Fix pat_x_mtrr_type() for MTRR disabled case") - mmc: vub300: fix invalid response handling - [armhf] mmc: pwrseq: sd8787: Fix WILC CHIP_EN and RESETN toggling order - [arm64] tty: serial: fsl_lpuart: use UARTCTRL_TXINV to send break instead of UARTCTRL_SBK - btrfs: fix csum_tree_block page iteration to avoid tripping on -Werror=array-bounds - [arm64] phy: qcom-qmp-combo: fix init-count imbalance - [arm64] phy: qcom-qmp-pcie-msm8996: fix init-count imbalance - block: fix revalidate performance regression - [powerpc*] iommu: Limit number of TCEs to 512 for H_STUFF_TCE hcall - [amd64] iommu/amd: Fix domain flush size when syncing iotlb - tpm, tpm_tis: correct tpm_tis_flags enumeration values - io_uring: undeprecate epoll_ctl support - mtdchar: mark bits of ioctl handler noinline - [rt] tracing/timerlat: Always wakeup the timerlat thread - tracing/histograms: Allow variables to have some modifiers - tracing/probe: trace_probe_primary_from_call(): checked list_first_entry - mptcp: fix connect timeout handling - mptcp: fix active subflow finalization - ext4: add EA_INODE checking to ext4_iget() - ext4: disallow ea_inodes with extended attributes - fbcon: Fix null-ptr-deref in soft_cursor - [arm64,armhf] serial: 8250_tegra: Fix an error handling path in tegra_uart_probe() - [powerpc*] xmon: Use KSYM_NAME_LEN in array size - [arm64] KVM: arm64: Populate fault info for watchpoint - [x86] KVM: x86: Account fastpath-only VM-Exits in vCPU stats - ksmbd: fix credit count leakage - ksmbd: fix UAF issue from opinfo->conn - ksmbd: fix incorrect AllocationSize set in smb2_get_info - ksmbd: fix slab-out-of-bounds read in smb2_handle_negotiate - ksmbd: fix multiple out-of-bounds read during context decoding - KEYS: asymmetric: Copy sig and digest in public_key_verify_signature() - fs/ntfs3: Validate MFT flags before replaying logs (CVE-2022-48425) - regmap: Account for register length when chunking - tpm, tpm_tis: Request threaded interrupt handler - [amd64] iommu/amd/pgtbl_v2: Fix domain max address - drm/amd/display: Have Payload Properly Created After Resume - xfs: verify buffer contents when we skip log replay (CVE-2023-2124) - tls: rx: strp: don't use GFP_KERNEL in softirq context - [arm64] efi: Use SMBIOS processor version to key off Ampere quirk - ext4: enable the lazy init thread when remounting read/write https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.34 - scsi: megaraid_sas: Add flexible array member for SGLs - net: sfp: fix state loss when updating state_hw_mask - [x86] platform/surface: aggregator: Allow completion work-items to be executed in parallel - [x86] platform/surface: aggregator_tabletsw: Add support for book mode in KIP subsystem - [arm64] spi: qup: Request DMA before enabling clocks - afs: Fix setting of mtime when creating a file/dir/symlink - wifi: mt76: mt7615: fix possible race in mt7615_mac_sta_poll - bpf, sockmap: Avoid potential NULL dereference in sk_psock_verdict_data_ready() - neighbour: fix unaligned access to pneigh_entry - net/ipv4: ping_group_range: allow GID from 2147483648 to 4294967294 - bpf: Fix UAF in task local storage - bpf: Fix elem_size not being set for inner maps - net/ipv6: fix bool/int mismatch for skip_notify_on_dev_down - net/smc: Avoid to access invalid RMBs' MRs in SMCRv1 ADD LINK CONT - [arm64] net: enetc: correct the statistics of rx bytes - [arm64] net: enetc: correct rx_bytes statistics of XDP - net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values - [x86] drm/i915: Explain the magic numbers for AUX SYNC/precharge length - [x86] drm/i915: Use 18 fast wake AUX sync len - Bluetooth: hci_sync: add lock to protect HCI_UNREGISTER - Bluetooth: Fix l2cap_disconnect_req deadlock - Bluetooth: ISO: don't try to remove CIG if there are bound CIS left - Bluetooth: L2CAP: Add missing checks for invalid DCID - wifi: mac80211: use correct iftype HE cap - wifi: cfg80211: reject bad AP MLD address - wifi: mac80211: mlme: fix non-inheritence element - wifi: mac80211: don't translate beacon/presp addrs - qed/qede: Fix scheduling while atomic - wifi: cfg80211: fix locking in sched scan stop work - netfilter: nft_bitwise: fix register tracking - netfilter: conntrack: fix NULL pointer dereference in nf_confirm_cthelper - netfilter: ipset: Add schedule point in call_ad(). - netfilter: nf_tables: out-of-bound check in chain blob - ipv6: rpl: Fix Route of Death. (CVE-2023-2156) - tcp: gso: really support BIG TCP - rfs: annotate lockless accesses to sk->sk_rxhash - rfs: annotate lockless accesses to RFS sock flow table - net: sched: add rcu annotations around qdisc->qdisc_sleeping - net: sched: move rtm_tca_policy declaration to include file - net: sched: act_police: fix sparse errors in tcf_police_dump() - net: sched: fix possible refcount leak in tc_chain_tmplt_add() - bpf: Add extra path pointer check to d_path helper - drm/amdgpu: fix Null pointer dereference error in amdgpu_device_recover_vram - lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release() - [arm64] net: bcmgenet: Fix EEE implementation - bnxt_en: Don't issue AP reset during ethtool's reset operation - bnxt_en: Query default VLAN before VNIC setup on a VF - bnxt_en: Skip firmware fatal error recovery if chip is not accessible - bnxt_en: Prevent kernel panic when receiving unexpected PHC_UPDATE event - bnxt_en: Implement .set_port / .unset_port UDP tunnel callbacks - batman-adv: Broken sync while rescheduling delayed work - Input: xpad - delete a Razer DeathAdder mouse VID/PID entry - Input: psmouse - fix OOB access in Elantech protocol - Input: fix open count when closing inhibited device - ALSA: hda: Fix kctl->id initialization - ALSA: ymfpci: Fix kctl->id initialization - [i386] ALSA: gus: Fix kctl->id initialization - ALSA: cmipci: Fix kctl->id initialization - [x86] ALSA: hda/realtek: Add quirk for Clevo NS50AU - ALSA: ice1712,ice1724: fix the kcontrol->id initialization - [x86] ALSA: hda/realtek: Add a quirk for HP Slim Desktop S01 - [x86] ALSA: hda/realtek: Add Lenovo P3 Tower platform - [x86] ALSA: hda/realtek: Add quirks for Asus ROG 2024 laptops using CS35L41 - [x86] drm/i915/gt: Use the correct error value when kernel_context() fails - drm/amd/pm: conditionally disable pcie lane switching for some sienna_cichlid SKUs - drm/amdgpu: fix xclk freq on CHIP_STONEY - drm/amdgpu: change reserved vram info print - drm/amd/pm: Fix power context allocation in SMU13 - drm/amd/display: Reduce sdp bw after urgent to 90% - wifi: iwlwifi: mvm: Fix -Warray-bounds bug in iwl_mvm_wait_d3_notif() - can: j1939: j1939_sk_send_loop_abort(): improved error queue handling in J1939 Socket - can: j1939: change j1939_netdev_lock type to mutex - can: j1939: avoid possible use-after-free when j1939_can_rx_register fails - mptcp: only send RM_ADDR in nl_cmd_remove - mptcp: add address into userspace pm list - mptcp: update userspace pm infos - ceph: fix use-after-free bug for inodes when flushing capsnaps - [s390x] dasd: Use correct lock while counting channel queue length - Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk - Bluetooth: fix debugfs registration - Bluetooth: hci_qca: fix debugfs registration - rbd: move RBD_OBJ_FLAG_COPYUP_ENABLED flag setting - rbd: get snapshot context after exclusive lock is ensured to be held - virtio_net: use control_buf for coalesce params - [arm64] pinctrl: meson-axg: add missing GPIOA_18 gpio group - usb: usbfs: Enforce page requirements for mmap - usb: usbfs: Use consistent mmap functions - [arm64] dts: imx8qm-mek: correct GPIOs for USDHC2 CD and WP signals - [arm*] ASoC: simple-card-utils: fix PCM constraint error check - blk-mq: fix blk_mq_hw_ctx active request accounting - [arm64] dts: imx8mn-beacon: Fix SPI CS pinmux - [arm*] i2c: mv64xxx: Fix reading invalid status value in atomic mode - soundwire: stream: Add missing clear of alloc_slave_rt - vhost: support PACKED when setting-getting vring_base - ksmbd: fix out-of-bound read in deassemble_neg_contexts() - ksmbd: fix out-of-bound read in parse_lease_state() - ksmbd: check the validation of pdu_size in ksmbd_conn_handler_loop - ext4: only check dquot_initialize_needed() when debugging - wifi: rtw89: correct PS calculation for SUPPORTS_DYNAMIC_PS - wifi: rtw88: correct PS calculation for SUPPORTS_DYNAMIC_PS https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.35 - [amd64] x86/head/64: Switch to KERNEL_CS as soon as new GDT is installed - cgroup: bpf: use cgroup_lock()/cgroup_unlock() wrappers - cgroup: always put cset in cgroup_css_set_put_fork - cgroup: fix missing cpus_read_{lock,unlock}() in cgroup_transfer_tasks() - EDAC/qcom: Get rid of hardcoded register offsets - ksmbd: validate smb request protocol id - of: overlay: Fix missing of_node_put() in error case of init_overlay_changeset() - power: supply: bq27xxx: Use mod_delayed_work() instead of cancel() + schedule() - [armhf] dts: vexpress: add missing cache properties - power: supply: Ratelimit no data debug output - PCI/DPC: Quirk PIO log size for Intel Ice Lake Root Ports - [x86] platform/x86: asus-wmi: Ignore WMI events with codes 0x7B, 0xC0 - regulator: Fix error checking for debugfs_create_dir - [arm64,armhf] irqchip/gic-v3: Disable pseudo NMIs on Mediatek devices w/ firmware issues - [arm64,armhf] irqchip/meson-gpio: Mark OF related data as maybe unused - power: supply: Fix logic checking if system is running from battery - drm: panel-orientation-quirks: Change Air's quirk to support Air Plus - btrfs: scrub: try harder to mark RAID56 block groups read-only - btrfs: handle memory allocation failure in btrfs_csum_one_bio - ASoC: soc-pcm: test if a BE can be prepared - [mips*] unhide PATA_PLATFORM - [mips*] Restore Au1300 support - [mips*] Move initrd_start check after initrd address sanitisation. - ASoC: cs35l41: Fix default regmap values for some registers - ASoC: dwc: move DMA init to snd_soc_dai_driver probe() - xen/blkfront: Only check REQ_FUA for writes - drm:amd:amdgpu: Fix missing buffer object unlock in failure path - io_uring: unlock sqd->lock before sq thread release CPU - NVMe: Add MAXIO 1602 to bogus nid list. - [arm64,armhf] irqchip/gic: Correctly validate OF quirk descriptors - wifi: cfg80211: fix locking in regulatory disconnect - wifi: cfg80211: fix double lock bug in reg_wdev_chan_valid() - epoll: ep_autoremove_wake_function should use list_del_init_careful - ocfs2: fix use-after-free when unmounting read-only filesystem - ocfs2: check new file size on fallocate call - zswap: do not shrink if cgroup may not zswap - nilfs2: fix incomplete buffer cleanup in nilfs_btnode_abort_change_key() - nilfs2: fix possible out-of-bounds segment allocation in resize ioctl - nilfs2: reject devices with insufficient block count - io_uring/net: save msghdr->msg_control for retries - kexec: support purgatories with .text.hot sections - [x86] purgatory: remove PGO flags - [powerpc*] purgatory: remove PGO flags - btrfs: do not ASSERT() on duplicated global roots - btrfs: fix iomap_begin length for nocow writes - btrfs: can_nocow_file_extent should pass down args->strict from callers - ALSA: usb-audio: Fix broken resume due to UAC3 power state - ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback - dm thin metadata: check fail_io before using data_sm - dm thin: fix issue_discard to pass GFP_NOIO to __blkdev_issue_discard - net: ethernet: stmicro: stmmac: fix possible memory leak in __stmmac_open - nouveau: fix client work fence deletion race - RDMA/uverbs: Restrict usage of privileged QKEYs - drm/amdgpu: vcn_4_0 set instance 0 init sched score to 1 - net: usb: qmi_wwan: add support for Compal RXM-G1 - drm/amd/display: edp do not add non-edid timings - drm/amd: Make sure image is written to trigger VBIOS image update flow - drm/amd: Tighten permissions on VBIOS flashing attributes - drm/amd/pm: workaround for compute workload type on some skus - drm/amdgpu: add missing radeon secondary PCI ID - ALSA: hda/realtek: Add a quirk for Compaq N14JP6 - [x86] thunderbolt: Do not touch CL state configuration during discovery - [x86] thunderbolt: dma_test: Use correct value for absent rings when creating paths - [x86] thunderbolt: Mask ring interrupt on Intel hardware as well - USB: serial: option: add Quectel EM061KGL series - usb: typec: ucsi: Fix command cancellation - usb: typec: Fix fast_role_swap_current show function - usb: gadget: udc: core: Offload usb_udc_vbus_handler processing - usb: gadget: udc: core: Prevent soft_connect_store() race - [arm64] USB: dwc3: qcom: fix NULL-deref on suspend - [arm64,armhf] USB: dwc3: fix use-after-free on core driver unbind - [arm64,armhf] usb: dwc3: gadget: Reset num TRBs before giving back the request - RDMA/rxe: Fix packet length checks - RDMA/rxe: Fix ref count error in check_rkey() - spi: cadence-quadspi: Add missing check for dma_set_mask - [arm64] spi: fsl-dspi: avoid SCK glitches with continuous transfers - netfilter: nf_tables: integrate pipapo into commit protocol - netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM - ice: Fix XDP memory leak when NIC is brought up and down - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE (CVE-2023-3390) - [arm64] net: enetc: correct the indexes of highest and 2nd highest TCs - ping6: Fix send to link-local addresses with VRF. - igb: Fix extts capture value format for 82580/i354/i350 - net/sched: simplify tcf_pedit_act - net/sched: act_pedit: remove extra check for key type - net/sched: act_pedit: Parse L3 Header for L4 offset - net/sched: cls_u32: Fix reference counter leak leading to overflow - wifi: mac80211: fix link activation settings order - wifi: cfg80211: fix link del callback to call correct handler - wifi: mac80211: take lock before setting vif links - RDMA/rxe: Removed unused name from rxe_task struct - RDMA/rxe: Fix the use-before-initialization error of resp_pkts - iavf: remove mask from iavf_irq_enable_queues() - RDMA/mlx5: Initiate dropless RQ for RAW Ethernet functions - RDMA/mlx5: Create an indirect flow table for steering anchor - RDMA/cma: Always set static rate to 0 for RoCE - IB/uverbs: Fix to consider event queue closing also upon non-blocking mode - RDMA/mlx5: Fix affinity assignment - IB/isert: Fix dead lock in ib_isert - IB/isert: Fix possible list corruption in CMA handler - IB/isert: Fix incorrect release of isert connection - net: ethtool: correct MAX attribute value for stats - ipvlan: fix bound dev checking for IPv6 l3s mode - sctp: fix an error code in sctp_sf_eat_auth() - igc: Clean the TX buffer and TX descriptor ring - igc: Fix possible system crash when loading module - igb: fix nvm.ops.read() error handling - net: phylink: report correct max speed for QUSGMII - net: phylink: use a dedicated helper to parse usgmii control word - drm/nouveau: don't detect DSM for non-NVIDIA device - [arm64] drm/bridge: ti-sn65dsi86: Avoid possible buffer overflow - drm/nouveau/dp: check for NULL nv_connector->native_mode - drm/nouveau: add nv_encoder pointer check for NULL - sched: add new attr TCA_EXT_WARN_MSG to report tc extact message - net/sched: Refactor qdisc_graft() for ingress and clsact Qdiscs - net/sched: qdisc_destroy() old ingress and clsact Qdiscs before grafting - cifs: fix lease break oops in xfstest generic/098 - ext4: drop the call to ext4_error() from ext4_get_group_info() - net/sched: cls_api: Fix lockup on flushing explicitly created chain - [arm64] net: dsa: felix: fix taprio guard band overflow at 10Mbps with jumbo frames - net: macsec: fix double free of percpu stats - sfc: fix XDP queues mode with legacy IRQ - dm: don't lock fs when the map is NULL during suspend or resume - net: tipc: resize nlattr array to correct size - afs: Fix vlserver probe RTT handling - rcu/kvfree: Avoid freeing new kfree_rcu() memory after old grace period - drm/amdgpu: Don't set struct drm_driver.output_poll_changed - net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy - Revert "net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy" - net/sched: act_api: add specific EXT_WARN_MSG for tc action - neighbour: delete neigh_lookup_nodev as not used - scsi: target: core: Fix error path in target_setup_session() - [mips*] Move '-Wa,-msoft-float' check from as-option to cc-option - [mips*] Prefer cc-option for additions to cflags - kbuild: Update assembler calls to use proper flags and language target https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.36 - drm/amd/display: Use dc_update_planes_and_stream - drm/amd/display: Add wrapper to call planes and stream update - drm/amd/display: fix the system hang while disable PSR - [arm64] tty: serial: fsl_lpuart: make rx_watermark configurable for different platforms - [arm64] tty: serial: fsl_lpuart: reduce RX watermark to 0 on LS1028A - ata: libata-scsi: Avoid deadlock on rescan after device resume - mm: Fix copy_from_user_nofault(). (Closes: #1033398) - tpm, tpm_tis: Claim locality in interrupt handler - tpm_crb: Add support for CRB devices based on Pluton - ksmbd: validate command payload size - ksmbd: fix out-of-bound read in smb2_write - ksmbd: validate session id and tree id in the compound request - tick/common: Align tick period during sched_timer setup (Closes: #1038754) - writeback: fix dereferencing NULL mapping->host on writeback_page_template - nilfs2: fix buffer corruption due to concurrent device reads - [x86] ACPI: sleep: Avoid breaking S3 wakeup due to might_sleep() - KVM: Avoid illegal stage2 mapping on invalid memory slot - Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails - Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs - PCI: hv: Fix a race condition bug in hv_pci_query_relations() - Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally" - PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev - PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic - PCI: hv: Add a per-bus mutex state_lock - io_uring/net: clear msg_controllen on partial sendmsg retry - io_uring/net: disable partial retries for recvmsg with cmsg - mptcp: handle correctly disconnect() failures - mptcp: fix possible divide by zero in recvmsg() - mptcp: fix possible list corruption on passive MPJ - mptcp: consolidate fallback and non fallback state machine - cgroup: Do not corrupt task iteration when rebinding subsystem - cgroup,freezer: hold cpu_hotplug_lock before freezer_mutex in freezer_css_{online,offline}() - [arm64] mmc: sdhci-msm: Disable broken 64-bit DMA on MSM8916 - [arm64] mmc: meson-gx: remove redundant mmc_request_done() call from irq context - [arm64,armhf] mmc: mmci: stm32: fix max busy timeout calculation - [arm64,armhf] mmc: bcm2835: fix deferred probing - [arm64,armhf] mmc: sunxi: fix deferred probing - bpf: ensure main program has an extable - wifi: iwlwifi: pcie: Handle SO-F device for PCI id 0x7AF0 - io_uring/poll: serialize poll linked timer start with poll removal - nilfs2: prevent general protection fault in nilfs_clear_dirty_page() - [x86] mm: Avoid using set_pgd() outside of real PGD pages - memfd: check for non-NULL file_seals in memfd_create() syscall - [arm64] mmc: meson-gx: fix deferred probing - ieee802154: hwsim: Fix possible memory leaks - xfrm: Treat already-verified secpath entries as optional - xfrm: interface: rename xfrm_interface.c to xfrm_interface_core.c - xfrm: Ensure policies always checked on XFRM-I input path - [arm64] KVM: arm64: PMU: Restore the host's PMUSERENR_EL0 - bpf: track immediate values written to stack by BPF_ST instruction - bpf: Fix verifier id tracking of scalars on spill - xfrm: fix inbound ipv4/udp/esp packets to UDPv6 dualstack sockets - bpf: Fix a bpf_jit_dump issue for x86_64 with sysctl bpf_jit_enable. - xfrm: Linearize the skb after offloading if needed. - net/mlx5: DR, Fix wrong action data allocation in decap action - sfc: use budget for TX completions - [armel,armhf] mmc: mvsdio: fix deferred probing - [armhf] mmc: omap: fix deferred probing - [armhf] mmc: omap_hsmmc: fix deferred probing - mmc: sdhci-acpi: fix deferred probing - ipvs: align inner_mac_header for encapsulation - be2net: Extend xmit workaround to BE3 chip - netfilter: nf_tables: fix chain binding transaction logic - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: drop map element references from preparation phase - netfilter: nft_set_pipapo: .walk does not deal with generations - netfilter: nf_tables: disallow element updates of bound anonymous sets - netfilter: nf_tables: reject unbound anonymous set before commit phase - netfilter: nf_tables: reject unbound chain set before commit phase - netfilter: nf_tables: disallow updates of anonymous sets - netfilter: nfnetlink_osf: fix module autoload - Revert "net: phy: dp83867: perform soft reset and retain established link" - bpf/btf: Accept function names that contain dots - bpf: Force kprobe multi expected_attach_type for kprobe_multi link - io_uring/net: use the correct msghdr union member in io_sendmsg_copy_hdr - sch_netem: acquire qdisc lock in netem_change() - revert "net: align SO_RCVMARK required privileges with SO_MARK" - [arm64] dts: rockchip: fix nEXTRST on SOQuartz - gpiolib: Fix GPIO chip IRQ initialization restriction - gpiolib: Fix irq_domain resource tracking for gpiochip_irqchip_add_domain() - scsi: target: iscsi: Prevent login threads from racing between each other - HID: wacom: Add error check to wacom_parse_and_register() - smb3: missing null check in SMB2_change_notify - media: cec: core: disable adapter in cec_devnode_unregister - media: cec: core: don't set last_initiator if tx in progress - nfcsim.c: Fix error checking for debugfs_create_dir - btrfs: fix an uninitialized variable warning in btrfs_log_inode - [i386] usb: gadget: udc: fix NULL dereference in remove() - nvme: double KA polling frequency to avoid KATO with TBKAS on - nvme: check IO start time when deciding to defer KA - nvme: improve handling of long keep alives - [x86] Input: soc_button_array - add invalid acpi_index DMI quirk handling - [s390x] cio: unregister device when the only path is gone - [arm*] ASoC: simple-card: Add missing of_node_put() in case of error - soundwire: dmi-quirks: add new mapping for HP Spectre x360 - soundwire: qcom: add proper error paths in qcom_swrm_startup() - [x86] ASoC: nau8824: Add quirk to active-high jack-detect - [x86] ASoC: amd: yc: Add Thinkpad Neo14 to quirks list for acp6x - gfs2: Don't get stuck writing page onto itself under direct I/O - [arm64] ASoC: fsl_sai: Enable BCI bit if SAI works on synchronous mode with BYP asserted - ALSA: hda/realtek: Add "Intel Reference board" and "NUC 13" SSID in the ALC256 - i2c: mchp-pci1xxxx: Avoid cast to incompatible function type - null_blk: Fix: memory release when memory_backed=1 - drm/radeon: fix race condition UAF in radeon_gem_set_domain_ioctl - vhost_net: revert upend_idx only on retriable error - [arm64] KVM: arm64: Restore GICv2-on-GICv3 functionality - [x86] apic: Fix kernel panic when booting with intremap=off and x2apic_phys - [arm64] i2c: imx-lpi2c: fix type char overflow issue when calculating the clock cycle - smb: move client and server files to common directory fs/smb https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.37 - mm/mmap: Fix error path in do_vmi_align_munmap() - mm/mmap: Fix error return in do_vmi_align_munmap() - mptcp: ensure listener is unhashed before updating the sk status - mm, hwpoison: try to recover from copy-on write faults - mm, hwpoison: when copy-on-write hits poison, take page offline - [x86] microcode/AMD: Load late on both threads too - [x86] smp: Make stop_other_cpus() more robust - [x86] smp: Dont access non-existing CPUID leaf - [x86] smp: Remove pointless wmb()s from native_stop_other_cpus() - [x86] smp: Use dedicated cache-line for mwait_play_dead() - [x86] smp: Cure kexec() vs. mwait_play_dead() breakage - can: isotp: isotp_sendmsg(): fix return error fix on TX path - maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() - mm: introduce new 'lock_mm_and_find_vma()' page fault helper - mm: make the page fault mmap locking killable - [arm64] mm: Convert to using lock_mm_and_find_vma() - [powerpc*] mm: Convert to using lock_mm_and_find_vma() - [mips*] mm: Convert to using lock_mm_and_find_vma() - [armhf] mm: Convert to using lock_mm_and_find_vma() - mm/fault: convert remaining simple cases to lock_mm_and_find_vma() - [powerpc*] mm: convert coprocessor fault to lock_mm_and_find_vma() - mm: make find_extend_vma() fail if write lock not held - execve: expand new process stack manually ahead of time - mm: always expand the stack with the mmap write lock held - fbdev: fix potential OOB read in fast_imageblit() - HID: hidraw: fix data race on device refcount - HID: wacom: Use ktime_t rather than int when dealing with timestamps - HID: logitech-hidpp: add HIDPP_QUIRK_DELAYED_INIT for the T651. (Closes: #1038271) . [ Salvatore Bonaccorso ] * d/salsa-ci.yml: Update for bookworm: Set RELEASE to bookworm * d/rules.real: Fix typo in setup_image target. * [amd64,arm64] drivers/virtio: Enable VIRTIO_MEM as module (Closes: #1038665) * Bump ABI to 10 * [rt] Update to 6.1.33-rt11 * Revert "drm/amd/display: edp do not add non-edid timings" . [ Cyril Brulebois ] * udeb: Add r8188eu to nic-wireless-modules (Closes: #1035824) . [ Ben Hutchings ] * Add pkg.linux.mintools profile for building minimal userland tools * d/b/test-patches: Build linux-{kbuild,bootwrapper} packages (Closes: #871216, #1035359) linux-signed-amd64 (6.1.38+1) bookworm; urgency=medium . * Sign kernel from linux 6.1.38-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.38 - drm/amd/display: Remove optimization for VRR updates - drm/amd/display: Do not update DRR while BW optimizations pending - PCI/ACPI: Validate acpi_pci_set_power_state() parameter - PCI/ACPI: Call _REG when transitioning D-states - execve: always mark stack as growing down during early stack setup - perf symbols: Symbol lookup with kcore can fail if multiple segments match stext - scripts/tags.sh: Resolve gtags empty index generation - drm/amdgpu: Validate VM ioctl flags. - drm/amd/display: Ensure vmin and vmax adjust for DCE . [ Salvatore Bonaccorso ] * drm: use mgr->dev in drm_dbg_kms in drm_dp_add_payload_part2 * mm/mmap: Fix VM_LOCKED check in do_vmi_align_munmap() * netfilter: nf_tables: do not ignore genmask when looking up chain by id (CVE-2023-31248) * netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (CVE-2023-35001) linux-signed-amd64 (6.1.37+1) bookworm-security; urgency=high . * Sign kernel from linux 6.1.37-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.28 - [x86] ASOC: Intel: sof_sdw: add quirk for Intel 'Rooks County' NUC M15 - [x86] ASoC: Intel: soc-acpi: add table for Intel 'Rooks County' NUC M15 - ASoC: soc-pcm: fix hw->formats cleared by soc_pcm_hw_init() for dpcm - [x86] hyperv: Block root partition functionality in a Confidential VM - [x86] ASoC: amd: yc: Add DMI entries to support Victus by HP Laptop 16-e1xxx (8A22) - [x86] ASoC: Intel: bytcr_rt5640: Add quirk for the Acer Iconia One 7 B1-750 - [x86] ASoC: da7213.c: add missing pm_runtime_disable() - scsi: mpi3mr: Handle soft reset in progress fault code (0xF002) - net: sfp: add quirk enabling 2500Base-x for HG MXPD-483II - [x86] platform/x86: thinkpad_acpi: Add missing T14s Gen1 type to s2idle quirk list - wifi: ath11k: reduce the MHI timeout to 20s - tracing: Error if a trace event has an array for a __field() - [x86] cpu: Add model number for Intel Arrow Lake processor - wireguard: timers: cast enum limits members to int in prints - wifi: mt76: mt7921e: Set memory space enable in PCI_COMMAND if unset - [arm64] Always load shadow stack pointer directly from the task struct - [arm64] Stash shadow stack pointer in the task struct on interrupt - PCI: pciehp: Fix AB-BA deadlock between reset_lock and device_lock - [arm64] PCI: qcom: Fix the incorrect register usage in v2.7.0 config - [arm64] phy: qcom-qmp-pcie: sc8180x PCIe PHY has 2 lanes - [arm64,armhf] usb: dwc3: gadget: Stall and restart EP0 if host is unresponsive - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on probe errors - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on unbind - [x86] hwmon: (k10temp) Check range scale when CUR_TEMP register is read-write - hwmon: (adt7475) Use device_property APIs when configuring polarity - tpm: Add !tpm_amd_is_rng_defective() to the hwrng_unregister() call site - posix-cpu-timers: Implement the missing timer_wait_running callback - blk-stat: fix QUEUE_FLAG_STATS clear - blk-crypto: don't use struct request_queue for public interfaces - blk-crypto: add a blk_crypto_config_supported_natively helper - blk-crypto: move internal only declarations to blk-crypto-internal.h - blk-crypto: Add a missing include directive - blk-mq: release crypto keyslot before reporting I/O complete - blk-crypto: make blk_crypto_evict_key() return void - blk-crypto: make blk_crypto_evict_key() more robust - tty: Prevent writing chars during tcsetattr TCSADRAIN/FLUSH - xhci: fix debugfs register accesses while suspended - serial: fix TIOCSRS485 locking - serial: 8250: Fix serial8250_tx_empty() race with DMA Tx - tick/nohz: Fix cpu_is_hotpluggable() by checking with nohz subsystem - fs: fix sysctls.c built - [mips*] fw: Allow firmware to pass a empty env - ipmi:ssif: Add send_retries increment - ipmi: fix SSIF not responding under certain cond. - wifi: mt76: add missing locking to protect against concurrent rx/status calls - [arm64,armhf] pwm: meson: Fix axg ao mux parents - [arm64,armhf] pwm: meson: Fix g12a ao clk81 name - soundwire: qcom: correct setting ignore bit on v1.5.1 - ring-buffer: Ensure proper resetting of atomic variables in ring_buffer_reset_online_cpus - ring-buffer: Sync IRQ works before buffer destruction - crypto: api - Demote BUG_ON() in crypto_unregister_alg() to a WARN_ON() - [arm64] crypto: safexcel - Cleanup ring IRQ workqueues on load failure - [x86] crypto: ccp - Don't initialize CCP for PSP 0x1649 - rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed - reiserfs: Add security prefix to xattr name in reiserfs_security_write() - [x86] KVM: nVMX: Emulate NOPs in L2, and PAUSE if it's not intercepted - [arm64] KVM: arm64: Avoid vcpu->mutex v. kvm->lock inversion in CPU_ON - [arm64] KVM: arm64: Avoid lock inversion when setting the VM register width - [arm64] KVM: arm64: Use config_lock to protect data ordered against KVM_RUN - [arm64] KVM: arm64: Use config_lock to protect vgic state - [arm64] KVM: arm64: vgic: Don't acquire its_lock before config_lock - relayfs: fix out-of-bounds access in relay_file_read (CVE-2023-3268) - drm/amd/display: Remove stutter only configurations - drm/amd/display: limit timing for single dimm memory - drm/amd/display: fix PSR-SU/DSC interoperability support - drm/amd/display: fix a divided-by-zero error - ksmbd: fix racy issue under cocurrent smb2 tree disconnect (CVE-2023-32254) - ksmbd: call rcu_barrier() in ksmbd_server_exit() - ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem() - ksmbd: fix memleak in session setup - ksmbd: not allow guest user on multichannel - ksmbd: fix deadlock in ksmbd_find_crypto_ctx() - [x86] ACPI: video: Remove acpi_backlight=video quirk for Lenovo ThinkPad W530 - [arm64,armhf] i2c: omap: Fix standard mode false ACK readings - tracing: Fix permissions for the buffer_percent file - swsmu/amdgpu_smu: Fix the wrong if-condition - drm/amd/pm: re-enable the gfx imu when smu resume - [amd64] iommu/amd: Fix "Guest Virtual APIC Table Root Pointer" configuration in IRTE - Revert "ubifs: dirty_cow_znode: Fix memleak in error handling path" - ubifs: Fix memleak when insert_old_idx() failed - ubi: Fix return value overwrite issue in try_write_vid_and_data() - ubifs: Free memory for tmpfile name - ubifs: Fix memory leak in do_rename - ceph: fix potential use-after-free bug when trimming caps - xfs: don't consider future format versions valid - cxl/hdm: Fail upon detecting 0-sized decoders - bus: mhi: host: Remove duplicate ee check for syserr - bus: mhi: host: Use mhi_tryset_pm_state() for setting fw error state - bus: mhi: host: Range check CHDBOFF and ERDBOFF - rcu: Fix missing TICK_DEP_MASK_RCU_EXP dependency check - tpm, tpm_tis: Do not skip reset of original interrupt vector - tpm, tpm_tis: Claim locality before writing TPM_INT_ENABLE register - tpm, tpm_tis: Disable interrupts if tpm_tis_probe_irq() failed - tpm, tpm_tis: Claim locality before writing interrupt registers - tpm, tpm: Implement usage counter for locality - tpm, tpm_tis: Claim locality when interrupts are reenabled on resume - erofs: stop parsing non-compact HEAD index if clusterofs is invalid - erofs: initialize packed inode after root inode is assigned - erofs: fix potential overflow calculating xattr_isize - [arm64,armhf] drm/rockchip: Drop unbalanced obj unref - [x86] drm/i915/dg2: Drop one PCI ID - drm/vgem: add missing mutex_destroy - drm/probe-helper: Cancel previous job before starting new one - drm/amdgpu: register a vga_switcheroo client for MacBooks with apple-gmux - [arm64] dts: ti: k3-am62-main: Fix GPIO numbers in DT - [arm64] drm/msm/disp/dpu: check for crtc enable rather than crtc active to release shared resources - [amd64] EDAC/skx: Fix overflows on the DRAM row address mapping arrays - regulator: core: Shorten off-on-delay-us for always-on/boot-on by time since booted - [arm64] dts: ti: k3-am62a7-sk: Fix DDR size to full 4GB - [arm64] dts: qcom: msm8998: Fix stm-stimulus-base reg name - [arm64] dts: qcom: sdm845: correct dynamic power coefficients - [x86] MCE/AMD: Use an u64 for bank_map - [arm64] firmware: qcom_scm: Clear download bit during reboot - [arm64] drm/bridge: adv7533: Fix adv7533_mode_valid for adv7533 and adv7535 - [arm64] drm/msm/adreno: drop bogus pm_runtime_set_active() - [arm64] drm: msm: adreno: Disable preemption on Adreno 510 - [amd64] virt/coco/sev-guest: Double-buffer messages - [arm64] dts: qcom: sm8350-microsoft-surface: fix USB dual-role mode property - [x86] ACPI: processor: Fix evaluating _PDC method when running as Xen dom0 - [arm64] mmc: sdhci-of-esdhc: fix quirk to ignore command inhibit for data - [armhf] dts: gta04: fix excess dma channel usage - [arm64] firmware: arm_scmi: Fix xfers allocation on Rx channel - [arm64] perf/arm-cmn: Move overlapping wp_combine field - [armhf] dts: stm32: fix spi1 pin assignment on stm32mp15 - [arm64] cpufreq: qcom-cpufreq-hw: Revert adding cpufreq qos - [arm64,armhf] drm/lima/lima_drv: Add missing unwind goto in lima_pdev_probe() - [arm64,armhf] gpu: host1x: Fix potential double free if IOMMU is disabled - [arm64,armhf] gpu: host1x: Fix memory leak of device names - drm/ttm: optimize pool allocations a bit v2 - drm/ttm/pool: Fix ttm_pool_alloc error path - regulator: core: Consistently set mutex_owner when using ww_mutex_lock_slow() - regulator: core: Avoid lockdep reports when resolving supplies - [x86] apic: Fix atomic update of offset in reserve_eilvt_offset() - [arm64] dts: qcom: msm8994-angler: Fix cont_splash_mem mapping - [arm64] dts: qcom: msm8994-angler: removed clash with smem_region - [arm64,armhf] media: cedrus: fix use after free bug in cedrus_remove due to race condition (CVE-2023-35826) - [arm64] media: rkvdec: fix use after free bug in rkvdec_remove (CVE-2023-35829) - [amd64] platform/x86/amd: pmc: Don't try to read SMU version on Picasso - [amd64] platform/x86/amd: pmc: Hide SMU version and program attributes for Picasso - [amd64] platform/x86/amd: pmc: Don't dump data after resume from s0i3 on picasso - [amd64] platform/x86/amd: pmc: Move idlemask check into `amd_pmc_idlemask_read` - [amd64] platform/x86/amd: pmc: Utilize SMN index 0 for driver probe - [amd64] platform/x86/amd: pmc: Move out of BIOS SMN pair for STB init - media: dm1105: Fix use after free bug in dm1105_remove due to race condition (CVE-2023-35824) - media: saa7134: fix use after free bug in saa7134_finidev due to race condition (CVE-2023-35823) - media: v4l: async: Return async sub-devices to subnotifier list - drm/amd/display: Fix potential null dereference - [arm64,armhf] media: rc: gpio-ir-recv: Fix support for wake-up - [arm64] media: venus: dec: Fix handling of the start cmd - [arm64] media: venus: dec: Fix capture formats enumeration order - [armhf] regulator: stm32-pwr: fix of_iomap leak - [x86] ioapic: Don't return 0 from arch_dynirq_lower_bound() - [arm64] kgdb: Set PSTATE.SS to 1 to re-enable single-step - [arm64] perf/arm-cmn: Fix port detection for CMN-700 - [x86] drm/i915: Make intel_get_crtc_new_encoder() less oopsy - tick/common: Align tick period with the HZ tick. - ACPI: bus: Ensure that notify handlers are not running after removal - cpufreq: use correct unit when verify cur freq - [arm64] rpmsg: glink: Propagate TX failures in intentless mode as well - platform/chrome: cros_typec_switch: Add missing fwnode_handle_put() - wifi: ath6kl: minor fix for allocation size - wifi: ath9k: hif_usb: fix memory leak of remain_skbs - wifi: ath11k: Use platform_get_irq() to get the interrupt - wifi: ath5k: Use platform_get_irq() to get the interrupt - wifi: ath5k: fix an off by one check in ath5k_eeprom_read_freq_list() - wifi: ath11k: fix SAC bug on peer addition with sta band migration - wifi: brcmfmac: support CQM RSSI notification with older firmware - wifi: ath6kl: reduce WARN to dev_dbg() in callback - tools: bpftool: Remove invalid \' json escape - wifi: rtw88: mac: Return the original error from rtw_pwr_seq_parser() - wifi: rtw88: mac: Return the original error from rtw_mac_power_switch() - bpf: take into account liveness when propagating precision - bpf: fix precision propagation verbose logging - [x86] crypto: qat - fix concurrency issue when device state changes - scm: fix MSG_CTRUNC setting condition for SO_PASSSEC - wifi: ath11k: fix deinitialization of firmware resources - bpf: Remove misleading spec_v1 check on var-offset stack read - net: pcs: xpcs: remove double-read of link state when using AN - vlan: partially enable SIOCSHWTSTAMP in container - net/packet: annotate accesses to po->xmit - net/packet: convert po->origdev to an atomic flag - net/packet: convert po->auxdata to an atomic flag - libbpf: Fix ld_imm64 copy logic for ksym in light skeleton. - netfilter: keep conntrack reference until IPsecv6 policy checks are done - bpf: Fix __reg_bound_offset 64->32 var_off subreg propagation - scsi: target: core: Change the way target_xcopy_do_work() sets restiction on max I/O - scsi: target: Move sess cmd counter to new struct - scsi: target: Move cmd counter allocation - scsi: target: Pass in cmd counter to use during cmd setup - scsi: target: iscsit: isert: Alloc per conn cmd counter - scsi: target: iscsit: Stop/wait on cmds during conn close - scsi: target: Fix multiple LUN_RESET handling - scsi: target: iscsit: Fix TAS handling during conn cleanup - scsi: megaraid: Fix mega_cmd_done() CMDID_INT_CMDS - net: sunhme: Fix uninitialized return code - f2fs: handle dqget error in f2fs_transfer_project_quota() - f2fs: fix uninitialized skipped_gc_rwsem - f2fs: apply zone capacity to all zone type - f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() - f2fs: fix scheduling while atomic in decompression path - [arm64,armhf] crypto: caam - Clear some memory in instantiate_rng - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_rfreg() - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_reg() - scsi: libsas: Add sas_ata_device_link_abort() - [arm64] scsi: hisi_sas: Handle NCQ error when IPTT is valid - wifi: rt2x00: Fix memory leak when handling surveys - f2fs: fix iostat lock protection - net: qrtr: correct types of trace event parameters - bpftool: Fix bug for long instructions in program CFG dumps - crypto: drbg - Only fail when jent is unavailable in FIPS mode - xsk: Fix unaligned descriptor validation - f2fs: fix to avoid use-after-free for cached IPU bio - wifi: iwlwifi: fix duplicate entry in iwl_dev_info_table - bpf/btf: Fix is_int_ptr() - scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: rework optional clock handling - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: fix optional phy regulator handling - wifi: ath11k: fix writing to unintended memory region - bpf, sockmap: fix deadlocks in the sockhash and sockmap - nvmet: fix error handling in nvmet_execute_identify_cns_cs_ns() - nvmet: fix Identify Namespace handling - nvmet: fix Identify Controller handling - nvmet: fix Identify Active Namespace ID list handling - nvmet: fix I/O Command Set specific Identify Controller - nvme: fix async event trace event - blk-mq: don't plug for head insertions in blk_execute_rq_nowait - wifi: iwlwifi: debug: fix crash in __iwl_err() - wifi: iwlwifi: trans: don't trigger d3 interrupt twice - wifi: iwlwifi: mvm: don't set CHECKSUM_COMPLETE for unsupported protocols - bpf, sockmap: Revert buggy deadlock fix in the sockhash and sockmap - f2fs: fix to check return value of f2fs_do_truncate_blocks() - f2fs: fix to check return value of inc_valid_block_count() - md/raid10: fix task hung in raid10d - md/raid10: fix leak of 'r10bio->remaining' for recovery - md/raid10: fix memleak for 'conf->bio_split' - md/raid10: fix memleak of md thread - md/raid10: don't call bio_start_io_acct twice for bio which experienced read error - wifi: iwlwifi: mvm: don't drop unencrypted MCAST frames - wifi: iwlwifi: yoyo: skip dump correctly on hw error - wifi: iwlwifi: yoyo: Fix possible division by zero - wifi: iwlwifi: mvm: initialize seq variable - wifi: iwlwifi: fw: move memset before early return - jdb2: Don't refuse invalidation of already invalidated buffers - io_uring/rsrc: use nospec'ed indexes - wifi: iwlwifi: make the loop for card preparation effective - wifi: mt76: handle failure of vzalloc in mt7615_coredump_work - wifi: mt76: add flexible polling wait-interval support - wifi: mt76: mt7921e: fix probe timeout after reboot - wifi: mt76: fix 6GHz high channel not be scanned - mt76: mt7921: fix kernel panic by accessing unallocated eeprom.data - wifi: mt76: mt7921: fix missing unwind goto in `mt7921u_probe` - wifi: mt76: mt7921e: improve reliability of dma reset - wifi: mt76: mt7921e: stop chip reset worker in unregister hook - wifi: mt76: connac: fix txd multicast rate setting - wifi: iwlwifi: mvm: check firmware response size - netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert() - netfilter: conntrack: fix wrong ct->timeout value - wifi: iwlwifi: fw: fix memory leak in debugfs - ixgbe: Allow flow hash to be set via ethtool - ixgbe: Enable setting RSS table to default values - net/mlx5e: Don't clone flow post action attributes second time - net/mlx5: E-switch, Create per vport table based on devlink encap mode - net/mlx5: E-switch, Don't destroy indirect table in split rule - net/mlx5e: Fix error flow in representor failing to add vport rx rule - net/mlx5: Suspend auxiliary devices only in case of PCI device suspend - net/mlx5: Use recovery timeout on sync reset flow - net/mlx5e: Nullify table pointer when failing to create - net: stmmac:fix system hang when setting up tag_8021q VLAN for DSA ports - bpf: Fix race between btf_put and btf_idr walk. - bpf: Don't EFAULT for getsockopt with optval=NULL - netfilter: nf_tables: don't write table validation state without mutex - net/sched: sch_fq: fix integer overflow of "credit" - ipv4: Fix potential uninit variable access bug in __ip_make_skb() - Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" - netlink: Use copy_to_user() for optval in netlink_getsockopt(). - [x86] net: amd: Fix link leak when verifying config failed - tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp. - [x86] ASoC: cs35l41: Only disable internal boost - drivers: staging: rtl8723bs: Fix locking in _rtw_join_timeout_handler() - drivers: staging: rtl8723bs: Fix locking in rtw_scan_timeout_handler() - [arm64] usb: host: xhci-rcar: remove leftover quirk handling - [arm64,armhf] usb: dwc3: gadget: Change condition for processing suspend event - [armhf] serial: stm32: Re-assert RTS/DE GPIO in RS485 mode only if more data are transmitted - iio: light: max44009: add missing OF device matching - [arm64,armhf] spi: imx: Don't skip cleanup in remove's error path - [x86] ASoC: soc-compress: Inherit atomicity from DAI link for Compress FE - [arm64,armhf] PCI: imx6: Install the fault handler only on compatible match - ASoC: es8316: Handle optional IRQ assignment - [arm64] spi: qup: Don't skip cleanup in remove's error path - [x86] vmci_host: fix a race condition in vmci_host_poll() causing GPF - of: Fix modalias string generation - [amd64] HID: amd_sfh: Correct the structure fields - [amd64] HID: amd_sfh: Correct the sensor enable and disable command - [amd64] HID: amd_sfh: Fix illuminance value - [amd64] HID: amd_sfh: Add support for shutdown operation - [amd64] HID: amd_sfh: Correct the stop all command - [amd64] HID: amd_sfh: Increase sensor command timeout for SFH1.1 - [amd64] HID: amd_sfh: Handle "no sensors" enabled for SFH1.1 - cacheinfo: Check sib_leaf in cache_leaves_are_shared() - [arm64] coresight: etm_pmu: Set the module field - PCI/PM: Extend D3hot delay for NVIDIA HDA controllers - spi: cadence-quadspi: fix suspend-resume implementations - [arm64,armhf] usb: chipidea: fix missing goto in `ci_hdrc_probe` - [arm64] tty: serial: fsl_lpuart: adjust buffer length to the intended size - serial: 8250: Add missing wakeup event reporting - spi: cadence-quadspi: use macro DEFINE_SIMPLE_DEV_PM_OPS - [x86] staging: rtl8192e: Fix W_DISABLE# does not work after stop/start - [arm64] spmi: Add a check for remove callback when removing a SPMI driver - virtio_ring: don't update event idx on get_buf - [powerpc*] rtas: use memmove for potentially overlapping buffer copy - sched/fair: Fix inaccurate tally of ttwu_move_affine - perf/core: Fix hardlockup failure caused by perf throttle - Revert "objtool: Support addition to set CFA base" - sched/rt: Fix bad task migration for rt tasks - tracing/user_events: Ensure write index cannot be negative - [amd64] IB/hifi1: add a null check of kzalloc_node in hfi1_ipoib_txreq_init - [amd64] RDMA/rdmavt: Delete unnecessary NULL check - workqueue: Fix hung time report of worker pools - [armhf] rtc: omap: include header for omap_rtc_power_off_program prototype - RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() - [arm64,armhf] rtc: meson-vrtc: Use ktime_get_real_ts64() to get the current time - clk: add missing of_node_put() in "assigned-clocks" property parsing - [arm64] power: supply: rk817: Fix low SOC bugs - RDMA/cm: Trace icm_send_rej event before the cm state is reset - RDMA/srpt: Add a check for valid 'mad_agent' pointer - [amd64] IB/hfi1: Fix SDMA mmu_rb_node not being evicted in LRU order - [amd64] IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests - [arm64,armhf] clk: imx: fracn-gppll: fix the rate table - [arm64,armhf] clk: imx: fracn-gppll: disable hardware select control - NFSv4.1: Always send a RECLAIM_COMPLETE after establishing lease - [amd64] iommu/amd: Set page size bitmap during V2 domain allocation - [arm64] Input: raspberrypi-ts - fix refcount leak in rpi_ts_probe - swiotlb: relocate PageHighMem test away from rmem_swiotlb_setup - swiotlb: fix debugfs reporting of reserved memory pools - RDMA/mlx5: Check pcie_relaxed_ordering_enabled() in UMR - RDMA/mlx5: Fix flow counter query via DEVX - SUNRPC: remove the maximum number of retries in call_bind_status - RDMA/mlx5: Use correct device num_ports when modify DC - timekeeping: Fix references to nonexistent ktime_get_fast_ns() - SMB3: Add missing locks to protect deferred close file list - SMB3: Close deferred file handles in case of handle lease break - ext4: fix i_disksize exceeding i_size problem in paritally written case - ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline - [arm64] dmaengine: mv_xor_v2: Fix an error code. - [armhf] leds: tca6507: Fix error handling of using fwnode_property_read_string - soundwire: cadence: rename sdw_cdns_dai_dma_data as sdw_cdns_dai_runtime - [x86] soundwire: intel: don't save hw_params for use in prepare - [arm64,armhf] phy: tegra: xusb: Add missing tegra_xusb_port_unregister for usb2_port and ulpi_port - [arm64,armhf] pinctrl-bcm2835.c: fix race condition when setting gpio dir - [x86] ACPI: PM: Do not turn of unused power resources on the Toshiba Click Mini - PM: hibernate: Turn snapshot_test into global variable - PM: hibernate: Do not get block device exclusively in test_resume mode - afs: Fix updating of i_size with dv jump from server - afs: Fix getattr to report server i_size on dirs, not local size - afs: Avoid endless loop if file is larger than expected - ALSA: usb-audio: Add quirk for Pioneer DDJ-800 - [x86] ALSA: hda/realtek: Add quirk for ThinkPad P1 Gen 6 - [x86] ALSA: hda/realtek: Add quirk for ASUS UM3402YAR using CS35L41 - [x86] ALSA: hda/realtek: support HP Pavilion Aero 13-be0xxx Mute LED - [x86] ALSA: hda/realtek: Fix mute and micmute LEDs for an HP laptop - nilfs2: do not write dirty data after degenerating to read-only - nilfs2: fix infinite loop in nilfs_mdt_get_block() - mm: do not reclaim private data from pinned page - drbd: correctly submit flush bio on barrier - md/raid10: fix null-ptr-deref in raid10_sync_request - md/raid5: Improve performance for sequential IO - mtd: core: provide unique name for nvmem device, take two - mtd: core: fix nvmem error reporting - mtd: core: fix error path for nvmem provider - mtd: spi-nor: core: Update flash's current address mode when changing address mode - [arm64] mailbox: zynqmp: Fix IPI isr handling - [arm64] mailbox: zynqmp: Fix typo in IPI documentation - wifi: rtl8xxxu: RTL8192EU always needs full init - wifi: rtw89: fix potential race condition between napi_init and napi_enable - [arm64] clk: rockchip: rk3399: allow clk_cifout to force clk_cifout_src to reparent - btrfs: scrub: reject unsupported scrub flags - [s390x] dasd: fix hanging blockdevice after request requeue - mm/mempolicy: correctly update prev when policy is equal on mbind - dm verity: fix error handling for check_at_most_once on FEC - dm integrity: call kmem_cache_destroy() in dm_integrity_init() error path - dm flakey: fix a crash with invalid table line - dm ioctl: fix nested locking in table_clear() to remove deadlock concern (CVE-2023-2269) - dm: don't lock fs when the map is NULL in process of resume - blk-iocost: avoid 64-bit division in ioc_timer_fn - cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname - cifs: protect session status check in smb2_reconnect() - [x86] thunderbolt: Use correct type in tb_port_is_clx_enabled() prototype - wifi: ath11k: synchronize ath11k_mac_he_gi_to_nl80211_he_gi()'s return type - [x86] perf auxtrace: Fix address filter entire kernel size - [x86] perf intel-pt: Fix CYC timestamps after standalone CBR - i40e: Remove unused i40e status codes - i40e: Remove string printing for i40e_status - i40e: use int for i40e_status - scsi: libsas: Grab the ATA port lock in sas_ata_device_link_abort() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.29 - [arm64,armhf] USB: dwc3: gadget: drop dead hibernation code - [arm64,armhf] usb: dwc3: gadget: Execute gadget stop after halting the controller - drm/vmwgfx: Remove explicit and broken vblank handling - drm/vmwgfx: Fix Legacy Display Unit atomic drm support - [amd64] crypto: ccp - Clear PSP interrupt status register before calling handler - [x86] perf/x86/core: Zero @lbr instead of returning -1 in x86_perf_get_lbr() stub - [x86] KVM: x86: Track supported PERF_CAPABILITIES in kvm_caps - [x86] KVM: x86/pmu: Disallow legacy LBRs if architectural LBRs are available - mtd: spi-nor: spansion: Remove NO_SFDP_FLAGS from s28hs512t info - mtd: spi-nor: add SFDP fixups for Quad Page Program - mtd: spi-nor: Add a RWW flag - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s28hx SEMPER flash - [arm64] mailbox: zynq: Switch to flexible array to simplify code - [arm64] mailbox: zynqmp: Fix counts of child nodes - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s25hx SEMPER flash - drm/amd/display: Ext displays with dock can't recognized after resume - [x86] KVM: x86/mmu: Avoid indirect call for get_cr3 - [x86] KVM: x86: Do not unload MMU roots when only toggling CR0.WP with TDP enabled - [x86] KVM: x86: Make use of kvm_read_cr*_bits() when testing bits - [x86] KVM: VMX: Make CR0.WP a guest owned bit - [x86] KVM: x86/mmu: Refresh CR0.WP prior to checking for emulated permission faults - [x86] ASoC: Intel: soc-acpi-byt: Fix "WM510205" match no longer working - scsi: qedi: Fix use after free bug in qedi_remove() - drm/amd/display: Remove FPU guards from the DML folder - drm/amd/display: Add missing WA and MCLK validation - drm/amd/display: Return error code on DSC atomic check failure - drm/amd/display: Fixes for dcn32_clk_mgr implementation - drm/amd/display: Reset OUTBOX0 r/w pointer on DMUB reset - drm/amd/display: Do not clear GPINT register when releasing DMUB from reset - drm/amd/display: Update bounding box values for DCN321 - ixgbe: Fix panic during XDP_TX with > 64 CPUs - [armhf] net/ncsi: clear Tx enable mode when handling a Config required AEN - tcp: fix skb_copy_ubufs() vs BIG TCP - net/sched: cls_api: remove block_cb from driver_list before freeing - sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() - net: ipv6: fix skb hash for some RST packets - [arm64,armhf] net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu - writeback: fix call of incorrect macro - block: Skip destroyed blkg when restart in blkg_destroy_all() - [arm64,armhf] watchdog: dw_wdt: Fix the error handling path of dw_wdt_drv_probe() - [arm64,armhf] i2c: tegra: Fix PEC support for SMBUS block read - net/sched: act_mirred: Add carrier check - r8152: fix flow control issue of RTL8156A - r8152: fix the poor throughput for 2.5G devices - r8152: move setting r8153b_rx_agg_chg_indicate() - sfc: Fix module EEPROM reporting for QSFP modules - rxrpc: Fix hard call timeout units - [x86] drm/i915/mtl: Add the missing CPU transcoder mask in intel_device_info - ethtool: Fix uninitialized number of lanes - af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). - drm/amdgpu: add a missing lock for AMDGPU_SCHED - ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` - [s390x] KVM: s390: fix race in gmap_make_secure() - ice: block LAN in case of VF to VF offload - virtio_net: suppress cpu stall when free_unused_bufs - [arm64] net: enetc: check the index of the SFI rather than the handle - perf record: Fix "read LOST count failed" msg with sample read - perf scripts intel-pt-events.py: Fix IPC output for Python 2 - perf vendor events s390: Remove UTF-8 characters from JSON file - perf tests record_offcpu.sh: Fix redirection of stderr to stdin - perf ftrace: Make system wide the default target for latency subcommand - perf vendor events power9: Remove UTF-8 characters from JSON files - perf pmu: zfree() expects a pointer to a pointer to zero it after freeing its contents - perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() - perf cs-etm: Fix timeless decode mode detection - crypto: api - Add scaffolding to change completion function signature - crypto: engine - Use crypto_request_complete - crypto: engine - fix crypto_queue backlog handling - perf symbols: Fix return incorrect build_id size in elf_read_build_id() - perf tracepoint: Fix memory leak in is_valid_tracepoint() - perf stat: Separate bperf from bpf_profiler - [x86] retbleed: Fix return thunk alignment - btrfs: fix btrfs_prev_leaf() to not return the same key twice - btrfs: zoned: fix wrong use of bitops API in btrfs_ensure_empty_zones - btrfs: properly reject clear_cache and v1 cache for block-group-tree - btrfs: fix assertion of exclop condition when starting balance - btrfs: fix encoded write i_size corruption with no-holes - btrfs: don't free qgroup space unless specified - btrfs: zero the buffer before marking it dirty in btrfs_redirty_list_add - btrfs: make clear_cache mount option to rebuild FST without disabling it - btrfs: print-tree: parent bytenr must be aligned to sector size - btrfs: fix space cache inconsistency after error loading it from disk - btrfs: zoned: zone finish data relocation BG with last IO - btrfs: zoned: fix full zone super block reading on ZNS - cifs: fix pcchunk length type in smb2_copychunk_range - cifs: release leases for deferred close handles when freezing - [amd64] platform/x86/intel-uncore-freq: Return error on write frequency - [x86] platform/x86: touchscreen_dmi: Add upside-down quirk for GDIX1002 ts on the Juno Tablet - [x86] platform/x86: thinkpad_acpi: Fix platform profiles on T490 - [x86] platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i - [x86] platform/x86: thinkpad_acpi: Add profile force ability - inotify: Avoid reporting event with invalid wd - smb3: fix problem remounting a share after shutdown - SMB3: force unmount was failing to close deferred close files - [armhf] remoteproc: stm32: Call of_node_put() on iteration error - sysctl: clarify register_sysctl_init() base directory order - [armhf] ARM: dts: aspeed: asrock: Correct firmware flash SPI clocks - [armhf] ARM: dts: exynos: fix WM8960 clock name in Itop Elite - [armhf] ARM: dts: aspeed: romed8hm3: Fix GPIO polarity of system-fault LED - [arm64] drm/msm/adreno: fix runtime PM imbalance at gpu load - [x86] drm/i915/color: Fix typo for Plane CSC indexes - [arm64] drm/msm: fix NULL-deref on snapshot tear down - [arm64] drm/msm: fix NULL-deref on irq uninstall - [arm64] drm/msm: fix drm device leak on bind errors - [arm64] drm/msm: fix vram leak on bind errors - [arm64] drm/msm: fix workqueue leak on bind errors - [x86] drm/i915/dsi: Use unconditional msleep() instead of intel_dsi_msleep() - f2fs: fix null pointer panic in tracepoint in __replace_atomic_write_block - f2fs: fix potential corruption when moving a directory - [armhf] drm/panel: otm8009a: Set backlight parent to panel device - drm/amd/display: Add NULL plane_state check for cursor disable logic - drm/amd/display: Fix 4to1 MPC black screen with DPP RCO - drm/amd/display: filter out invalid bits in pipe_fuses - drm/amd/display: fix flickering caused by S/G mode - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v10_0_hw_fini - drm/amdgpu: fix an amdgpu_irq_put() issue in gmc_v9_0_hw_fini() - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_fini - drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras - drm/amdgpu/jpeg: Remove harvest checking for JPEG3 - drm/amdgpu: change gfx 11.0.4 external_id range - drm/amdgpu: Fix vram recover doesn't work after whole GPU reset (v2) - drm/amd/display: Enforce 60us prefetch for 200Mhz DCFCLK modes - drm/amd/pm: parse pp_handle under appropriate conditions - drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend - drm/amd/pm: avoid potential UBSAN issue on legacy asics - drm/amdgpu: remove deprecated MES version vars - drm/amd: Load MES microcode during early_init - drm/amd: Add a new helper for loading/validating microcode - drm/amd: Use `amdgpu_ucode_*` helpers for MES - HID: wacom: Set a default resolution for older tablets - HID: wacom: insert timestamp to packed Bluetooth (BT) events - [arm64] drm/msm/adreno: adreno_gpu: Use suspend() instead of idle() on load error - f2fs: specify extent cache for read explicitly - f2fs: move internal functions into extent_cache.c - f2fs: remove unnecessary __init_extent_tree - f2fs: refactor extent_cache to support for read and more - f2fs: allocate the extent_cache by default - f2fs: factor out victim_entry usage from general rb_tree use - [arm64] drm/msm/adreno: Simplify read64/write64 helpers - [arm64] drm/msm: Hangcheck progress detection - [arm64] drm/msm: fix missing wq allocation error handling - wifi: rtw88: rtw8821c: Fix rfe_option field width - [x86] drm/i915/mtl: update scaler source and destination limits for MTL - [x86] drm/i915: Check pipe source size when using skl+ scalers - drm/amd/display: Refactor eDP PSR codes - drm/amd/display: Add Z8 allow states to z-state support list - drm/amd/display: Add debug option to skip PSR CRTC disable - drm/amd/display: Fix Z8 support configurations - drm/amd/display: Add minimum Z8 residency debug option - drm/amd/display: Update minimum stutter residency for DCN314 Z8 - drm/amd/display: Lowering min Z8 residency time - [x86] ASoC: codecs: constify static sdw_slave_ops struct - drm/amd/display: Update Z8 watermarks for DCN314 - drm/amd/display: Update Z8 SR exit/enter latencies - drm/amd/display: Change default Z8 watermark values - ksmbd: Implements sess->ksmbd_chann_list as xarray - ksmbd: fix racy issue from session setup and logoff (CVE-2023-32250) - ksmbd: destroy expired sessions - ksmbd: block asynchronous requests when making a delay on session setup - ksmbd: fix racy issue from smb2 close and logoff with multichannel - drm: Add missing DP DSC extended capability definitions. - drm/dsc: fix drm_edp_dsc_sink_output_bpp() DPCD high byte usage - locking/rwsem: Add __always_inline annotation to __down_read_common() and inlined callers - ext4: fix WARNING in mb_find_extent - ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum (CVE-2023-34256) - ext4: fix data races when using cached status extents - ext4: check iomap type only if ext4_iomap_begin() does not fail - ext4: improve error recovery code paths in __ext4_remount() - ext4: improve error handling from ext4_dirhash() - ext4: fix deadlock when converting an inline directory in nojournal mode - ext4: add bounds checking in get_max_inline_xattr_value_size() - ext4: bail out of ext4_xattr_ibody_get() fails for any reason - ext4: fix lockdep warning when enabling MMP - ext4: remove a BUG_ON in ext4_mb_release_group_pa() - ext4: fix invalid free tracking in ext4_xattr_move_to_block() - drm/dsc: fix DP_DSC_MAX_BPP_DELTA_* macro values - f2fs: fix to do sanity check on extent cache correctly - f2fs: inode: fix to do sanity check on extent cache correctly - [x86] amd_nb: Add PCI ID for family 19h model 78h - [x86] fix clear_user_rep_good() exception handling annotation - drm/amd/display: Fix hang when skipping modeset https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.30 - drm/fbdev-generic: prohibit potential out-of-bounds access - drm/mipi-dsi: Set the fwnode for mipi_dsi_device - net: skb_partial_csum_set() fix against transport header magic value - scsi: ufs: core: Fix I/O hang that occurs when BKOPS fails in W-LUN suspend - tick/broadcast: Make broadcast device replacement work correctly - linux/dim: Do nothing if no time delta between samples - net: stmmac: Initialize MAC_ONEUS_TIC_COUNTER register - net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). - [arm64,armhf] net: phy: bcm7xx: Correct read from expansion register - netfilter: nf_tables: always release netdev hooks from notifier - netfilter: conntrack: fix possible bug_on with enable_hooks=1 - bonding: fix send_peer_notif overflow - netlink: annotate accesses to nlk->cb_running - net: annotate sk->sk_err write from do_recvmmsg() - net: deal with most data-races in sk_wait_event() - net: add vlan_get_protocol_and_depth() helper - tcp: add annotations around sk->sk_shutdown accesses - [amd64,arm64] gve: Remove the code of clearing PBA bit - ipvlan:Fix out-of-bounds caused by unclear skb->cb (CVE-2023-3090) - [arm64] net: mscc: ocelot: fix stat counter register values - net: datagram: fix data-races in datagram_poll() - af_unix: Fix a data race of sk->sk_receive_queue->qlen. - af_unix: Fix data races around sk->sk_shutdown. - [x86] drm/i915/guc: Don't capture Gen8 regs on Xe devices - [x86] drm/i915: Fix NULL ptr deref by checking new_crtc_state - [x86] drm/i915/dp: prevent potential div-by-zero - [x86] drm/i915: Expand force_probe to block probe of devices as well. - [x86] drm/i915: taint kernel when force probing unsupported devices - [x86] fbdev: arcfb: Fix error handling in arcfb_probe() - ext4: reflect error codes from ext4_multi_mount_protect() to its callers - ext4: allow to find by goal if EXT4_MB_HINT_GOAL_ONLY is set - ext4: allow ext4_get_group_info() to fail - rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access - open: return EINVAL for O_DIRECTORY | O_CREAT - fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() - drm/displayid: add displayid_get_header() and check bounds better - drm/amd/display: populate subvp cmd info only for the top pipe - drm/amd/display: Correct DML calculation to align HW formula - [x86] platform/x86: x86-android-tablets: Add Acer Iconia One 7 B1-750 data - drm/amd/display: Enable HostVM based on rIOMMU active - drm/amd/display: Use DC_LOG_DC in the trasform pixel function - regmap: cache: Return error in cache sync operations for REGCACHE_NONE - [arm64] dts: qcom: msm8996: Add missing DWC3 quirks - media: cx23885: Fix a null-ptr-deref bug in buffer_prepare() and buffer_finish() - media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() - [arm64,armhf] drm/rockchip: dw_hdmi: cleanup drm encoder during unbind - memstick: r592: Fix UAF bug in r592_remove due to race condition (CVE-2023-3141) - ACPI: EC: Fix oops when removing custom query handlers - drm/amd/display: fixed dcn30+ underflow issue - [armhf] remoteproc: stm32_rproc: Add mutex protection for workqueue - [arm64,armhf] drm/tegra: Avoid potential 32-bit integer overflow - [arm64] drm/msm/dp: Clean up handling of DP AUX interrupts - ACPICA: Avoid undefined behavior: applying zero offset to null pointer - ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects - [arm64] dts: qcom: sdm845-polaris: Drop inexistent properties - [arm64,armhf] irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 - ACPI: video: Remove desktops without backlight DMI quirks - drm/amd/display: Correct DML calculation to follow HW SPEC - drm/amd: Fix an out of bounds error in BIOS parser - drm/amdgpu: Fix sdma v4 sw fini error - [armhf] media: Prefer designated initializers over memset for subdev pad ops - wifi: ath: Silence memcpy run-time false positive warning - bpf: Annotate data races in bpf_local_storage - wifi: brcmfmac: pcie: Provide a buffer of random bytes to the device - wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex - scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow - scsi: lpfc: Correct used_rpi count when devloss tmo fires with no recovery - bnxt: avoid overflow in bnxt_get_nvram_directory() - net: Catch invalid index in XPS mapping - netdev: Enforce index cap in netdev_get_tx_queue - scsi: target: iscsit: Free cmds before session free - lib: cpu_rmap: Avoid use after free on rmap->obj array entries - scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition - gfs2: Fix inode height consistency check - [x86] scsi: ufs: ufs-pci: Add support for Intel Lunar Lake - ext4: set goal start correctly in ext4_mb_normalize_request - ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() - crypto: jitter - permanent and intermittent health errors - f2fs: Fix system crash due to lack of free space in LFS - f2fs: fix to drop all dirty pages during umount() if cp_error is set - f2fs: fix to check readonly condition correctly - bpf: Add preempt_count_{sub,add} into btf id deny list - md: fix soft lockup in status_resync - wifi: iwlwifi: pcie: fix possible NULL pointer dereference - wifi: iwlwifi: add a new PCI device ID for BZ device - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf - wifi: iwlwifi: mvm: fix ptk_pn memory leak - block, bfq: Fix division by zero error on zero wsum - wifi: ath11k: Ignore frags from uninitialized peer in dp. - wifi: iwlwifi: fix iwl_mvm_max_amsdu_size() for MLO - null_blk: Always check queue mode setting from configfs - wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace - wifi: ath11k: Fix SKB corruption in REO destination ring - nbd: fix incomplete validation of ioctl arg - ipvs: Update width of source for ip_vs_sync_conn_options - Bluetooth: btusb: Add new PID/VID 04ca:3801 for MT7663 - Bluetooth: Add new quirk for broken local ext features page 2 - Bluetooth: btrtl: add support for the RTL8723CS - Bluetooth: Improve support for Actions Semi ATS2851 based devices - Bluetooth: btrtl: check for NULL in btrtl_set_quirks() - Bluetooth: btintel: Add LE States quirk support - Bluetooth: hci_bcm: Fall back to getting bdaddr from EFI if not set - Bluetooth: Add new quirk for broken set random RPA timeout for ATS2851 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp - Bluetooth: btrtl: Add the support for RTL8851B - HID: apple: Set the tilde quirk flag on the Geyser 4 and later - [x86] ASoC: amd: yc: Add DMI entries to support HP OMEN 16-n0xxx (8A42) - HID: logitech-hidpp: Don't use the USB serial for USB devices - HID: logitech-hidpp: Reconcile USB and Unifying serials - [arm64,armhf] spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 - [x86] usb: typec: ucsi: acpi: add quirk for ASUS Zenbook UM325 - ALSA: hda: LNL: add HD Audio PCI ID - [x86] ASoC: amd: Add Dell G15 5525 to quirks list - [x86] ASoC: amd: yc: Add ThinkBook 14 G5+ ARP to quirks list for acp6x - [x86] HID: apple: Set the tilde quirk flag on the Geyser 3 - [x86] HID: Ignore battery for ELAN touchscreen on ROG Flow X13 GV301RA - HID: wacom: generic: Set battery quirk only when we see battery data - usb: typec: tcpm: fix multiple times discover svids error - serial: 8250: Reinit port->pm on port specific driver unbind - [x86] soundwire: dmi-quirks: add remapping for Intel 'Rooks County' NUC M15 - soundwire: qcom: gracefully handle too many ports in DT - soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow - [x86] mfd: intel_soc_pmic_chtwc: Add Lenovo Yoga Book X90F to intel_cht_wc_models - [x86] mfd: intel-lpss: Add Intel Meteor Lake PCH-S LPSS PCI IDs - [x86] platform/x86: Move existing HP drivers to a new hp subdir - [x86] hp-wmi: add micmute to hp_wmi_keymap struct - drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs - xfrm: don't check the default policy if the policy allows the packet - Revert "Fix XFRM-I support for nested ESP tunnels" - [arm64] drm/msm/dp: unregister audio driver during unbind - [arm64] drm/msm/dpu: Assign missing writeback log_mask - [arm64] drm/msm/dpu: Move non-MDP_TOP INTF_INTR offsets out of hwio header - [arm64] drm/msm/dpu: Remove duplicate register defines from INTF - platform: Provide a remove callback that returns no value - [arm64] ASoC: fsl_micfil: Fix error handler with pm_runtime_enable - cpupower: Make TSC read per CPU for Mperf monitor - xfrm: Reject optional tunnel/BEET mode templates in outbound policies - af_key: Reject optional tunnel/BEET mode templates in outbound policies - [arm64] drm/msm: Fix submit error-path leaks - [arm64,armhf] net: fec: Better handle pm_runtime_get() failing in .remove() - net: phy: dp83867: add w/a for packet errors seen with short cables - ALSA: firewire-digi00x: prevent potential use after free - wifi: mt76: connac: fix stats->tx_bytes calculation - [x86] ALSA: hda/realtek: Apply HP B&O top speaker profile to Pavilion 15 - sfc: disable RXFCS and RXALL features by default - vsock: avoid to close connected socket after the timeout - tcp: fix possible sk_priority leak in tcp_v4_send_reset() - [armhf] serial: arc_uart: fix of_iomap leak in `arc_serial_probe` - erspan: get the proto with the md version for collect_md - [arm64] net: hns3: fix output information incomplete for dumping tx queue info with debugfs - [arm64] net: hns3: fix sending pfc frames after reset issue - [arm64] net: hns3: fix reset delay time to avoid configuration timeout - [arm64] net: hns3: fix reset timeout when enable full VF - media: netup_unidvb: fix use-after-free at del_timer() - SUNRPC: double free xprt_ctxt while still in use - SUNRPC: always free ctxt when freeing deferred request - SUNRPC: Fix trace_svc_register() call site - [x86] ASoC: SOF: topology: Fix logic for copying tuples - net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() - virtio-net: Maintain reverse cleanup order - virtio_net: Fix error unwinding of XDP initialization - tipc: add tipc_bearer_min_mtu to calculate min mtu - tipc: do not update mtu if msg_max is too small in mtu negotiation - tipc: check the bearer min mtu properly when setting it by netlink - [s390x] cio: include subchannels without devices also for evaluation - can: dev: fix missing CAN XL support in can_put_echo_skb() - [arm64] net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() - [arm64] net: bcmgenet: Restore phy_stop() depending upon suspend/close - ice: introduce clear_reset_state operation - ice: Fix ice VF reset during iavf initialization - wifi: cfg80211: Drop entries with invalid BSSIDs in RNR - wifi: mac80211: fortify the spinlock against deadlock by interrupt - wifi: mac80211: fix min center freq offset tracing - wifi: mac80211: Abort running color change when stopping the AP - wifi: iwlwifi: mvm: fix cancel_delayed_work_sync() deadlock - wifi: iwlwifi: fw: fix DBGI dump - wifi: iwlwifi: fix OEM's name in the ppag approved list - wifi: iwlwifi: mvm: fix OEM's name in the tas approved list - wifi: iwlwifi: mvm: don't trust firmware n_channels - scsi: storvsc: Don't pass unused PFNs to Hyper-V host - net: tun: rebuild error handling in tun_get_user - tun: Fix memory leak for detached NAPI queue. - cassini: Fix a memory leak in the error handling path of cas_init_one() - [arm64,armhf] net: dsa: mv88e6xxx: Fix mv88e6393x EPC write command offset - igb: fix bit_shift to be in [1..8] range - vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() - net: wwan: iosm: fix NULL pointer dereference when removing device - net: pcs: xpcs: fix C73 AN not getting enabled - netfilter: nf_tables: fix nft_trans type confusion - netfilter: nft_set_rbtree: fix null deref on element insertion - ALSA: usb-audio: Add a sample rate workaround for Line6 Pod Go - USB: usbtmc: Fix direction for 0-length ioctl control messages - usb-storage: fix deadlock when a scsi command timeouts more than once - USB: UHCI: adjust zhaoxin UHCI controllers OverCurrent bit value - [arm64,armhf] usb: dwc3: gadget: Improve dwc3_gadget_suspend() and dwc3_gadget_resume() - [arm64,armhf] usb: dwc3: debugfs: Resume dwc3 before accessing registers - usb: gadget: u_ether: Fix host MAC address case - usb: typec: altmodes/displayport: fix pin_assignment_show - xhci-pci: Only run d3cold avoidance quirk for s2idle - xhci: Fix incorrect tracking of free space on transfer rings - ALSA: hda: Fix Oops by 9.1 surround channel names - ALSA: hda: Add NVIDIA codec IDs a3 through a7 to patch table - [x86] ALSA: hda/realtek: Add quirk for Clevo L140AU - [x86] ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 - [x86] ALSA: hda/realtek: Add quirk for 2nd ASUS GU603 - [x86] ALSA: hda/realtek: Add quirk for HP EliteBook G10 laptops - ALSA: hda/realtek: Fix mute and micmute LEDs for yet another HP laptop - can: j1939: recvmsg(): allow MSG_CMSG_COMPAT flag - can: isotp: recvmsg(): allow MSG_CMSG_COMPAT flag - wifi: rtw88: use work to update rate to avoid RCU warning - SMB3: Close all deferred handles of inode in case of handle lease break - SMB3: drop reference to cfile before sending oplock break - ksmbd: smb2: Allow messages padded to 8byte boundary - ksmbd: allocate one more byte for implied bcc[0] - ksmbd: fix wrong UserName check in session_user - ksmbd: fix global-out-of-bounds in smb2_find_context_vals - KVM: Fix vcpu_array[0] races - statfs: enforce statfs[64] structure initialization - maple_tree: make maple state reusable after mas_empty_area() (Closes: #1036755) - mm: fix zswap writeback race condition - serial: Add support for Advantech PCI-1611U card - serial: 8250_exar: Add support for USR298x PCI Modems - [arm64] serial: qcom-geni: fix enabling deactivated interrupt - [x86] thunderbolt: Clear registers properly when auto clear isn't in use - vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF - ceph: force updating the msg pointer in non-split case - drm/amd/pm: fix possible power mode mismatch between driver and PMFW - drm/amdgpu/gmc11: implement get_vbios_fb_size() - drm/amdgpu/gfx10: Disable gfxoff before disabling powergating. - drm/amdgpu/gfx11: Adjust gfxoff before powergating on gfx11 as well - drm/amdgpu: refine get gpu clock counter method - drm/amdgpu/gfx11: update gpu_clock_counter logic - [powerpc*] iommu: DMA address offset is incorrectly calculated with 2MB TCEs - [powerpc*] iommu: Incorrect DDW Table is referenced for SR-IOV device - tpm/tpm_tis: Disable interrupts for more Lenovo devices - [powerpc*] 64s/radix: Fix soft dirty tracking - nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() - [s390x] dasd: fix command reject error on ESE devices - [s390x] crypto: use vector instructions only if available for ChaCha20 - [s390x] qdio: fix do_sqbs() inline assembly constraint - [arm64] mte: Do not set PG_mte_tagged if tags were not initialized - [x86] rethook: use preempt_{disable, enable}_notrace in rethook_trampoline_handler - [x86] rethook, fprobe: do not trace rethook related functions - crypto: testmgr - fix RNG performance in fuzz tests - drm/amdgpu: declare firmware for new MES 11.0.4 - drm/amd/amdgpu: introduce gc_*_mes_2.bin v2 - drm/amdgpu: reserve the old gc_11_0_*_mes.bin https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.31 - [arm64,armhf] usb: dwc3: fix gadget mode suspend interrupt handler issue - tpm, tpm_tis: Avoid cache incoherency in test for interrupts - tpm, tpm_tis: Only handle supported interrupts - tpm_tis: Use tpm_chip_{start,stop} decoration inside tpm_tis_resume - tpm, tpm_tis: startup chip before testing for interrupts - tpm: Re-enable TPM chip boostrapping non-tpm_tis TPM drivers - tpm: Prevent hwrng from activating during resume - [x86] watchdog: sp5100_tco: Immediately trigger upon starting. - drm/amd/amdgpu: update mes11 api def - drm/amdgpu/mes11: enable reg active poll - skbuff: Proactively round up to kmalloc bucket size - [arm64,armhf] net: dsa: mv88e6xxx: Add RGMII delay to 88E6320 - drm/amd/display: hpd rx irq not working with eDP interface - ocfs2: Switch to security_inode_init_security() - [x86] mm: Avoid incomplete Global INVLPG flushes - [x86] ALSA: hda/ca0132: add quirk for EVGA X299 DARK - ALSA: hda: Fix unhandled register update during auto-suspend period - [x86] ALSA: hda/realtek: Enable headset onLenovo M70/M90 - SUNRPC: Don't change task->tk_status after the call to rpc_exit_task - [arm64,armhf] imc: sdhci-esdhc-imx: make "no-mmc-hs400" works - mmc: block: ensure error propagation for non-blk - [x86] power: supply: axp288_fuel_gauge: Fix external_power_changed race - [arm64] power: supply: bq25890: Fix external_power_changed race - ASoC: rt5682: Disable jack detection interrupt during suspend - net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize - btrfs: use nofs when cleaning up aborted transactions - [x86] drm/mgag200: Fix gamma lut not initialized. - drm/radeon: reintroduce radeon_dp_work_func content - drm/amd/pm: add missing NotifyPowerSource message mapping for SMU13.0.7 - drm/amd/pm: Fix output of pp_od_clk_voltage - Revert "binder_alloc: add missing mmap_lock calls when using the VMA" - Revert "android: binder: stop saving a pointer to the VMA" - binder: add lockless binder_alloc_(set|get)_vma() - binder: fix UAF caused by faulty buffer cleanup - binder: fix UAF of alloc->vma in race with munmap() - drm/amd/amdgpu: limit one queue per gang - [x86] perf/x86/uncore: Correct the number of CHAs on SPR - [x86] topology: Fix erroneous smp_num_siblings on Intel Hybrid platforms - [mips*] irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable - [mips*] irqchip/mips-gic: Use raw spinlock for gic_lock - debugobjects: Don't wake up kswapd from fill_pool() - fbdev: udlfb: Fix endpoint check - net: fix stack overflow when LRO is disabled for virtual interfaces - udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). - USB: core: Add routines for endpoint checks in old drivers - USB: sisusbvga: Add endpoint checks - media: radio-shark: Add endpoint checks - net: fix skb leak in __skb_tstamp_tx() - drm: fix drmm_mutex_init() - bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields - bpf: fix a memory leak in the LRU and LRU_PERCPU hash maps - ipv6: Fix out-of-bounds access in ipv6_find_tlv() - cifs: mapchars mount option ignored - power: supply: leds: Fix blink to LED on transition - power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition - power: supply: bq27xxx: Fix I2C IRQ race on remove - power: supply: bq27xxx: Fix poll_interval handling and races on remove - power: supply: bq27xxx: Add cache parameter to bq27xxx_battery_current_and_status() - power: supply: bq27xxx: Move bq27xxx_battery_update() down - power: supply: bq27xxx: Ensure power_supply_changed() is called on current sign changes - power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize - [arm64] power: supply: bq25890: Call power_supply_changed() after updating input current or voltage - [x86] power: supply: bq24190: Call power_supply_changed() after updating input current - [arm64] optee: fix uninited async notif value - fs: fix undefined behavior in bit shift for SB_NOUSER - [arm64] regulator: pca9450: Fix BUCK2 enable_mask - [x86] platform/x86: ISST: Remove 8 socket limit - [armhf] dts: imx6qdl-mba6: Add missing pvcie-supply regulator - [x86] pci/xen: populate MSI sysfs entries - [x86] show_trace_log_lvl: Ensure stack pointer is aligned, again - [x86] ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg - cxl: Wait Memory_Info_Valid before access memory related info - sctp: fix an issue that plpmtu can never go to complete state - [x86] forcedeth: Fix an error handling path in nv_probe() - net/mlx5e: Fix SQ wake logic in ptp napi_poll context - net/mlx5e: Fix deadlock in tc route query code - net/mlx5e: Use correct encap attribute during invalidation - net/mlx5e: do as little as possible in napi poll when budget is 0 - [s390x] net/mlx5: DR, Fix crc32 calculation to work on big-endian (BE) CPUs - net/mlx5: Handle pairing of E-switch via uplink un/load APIs - net/mlx5: DR, Check force-loopback RC QP capability independently from RoCE - net/mlx5: Fix error message when failing to allocate device memory - net/mlx5: Collect command failures data only for known commands - net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device - net/mlx5: Devcom, serialize devcom registration - [arm64] dts: imx8mn-var-som: fix PHY detection bug by adding deassert delay - net/smc: Reset connection when trying to use SMCRv2 fails. - [x86] 3c589_cs: Fix an error handling path in tc589_probe() - net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.32 - inet: Add IP_LOCAL_PORT_RANGE socket option - ipv{4,6}/raw: fix output xfrm lookup wrt protocol - tls: rx: device: fix checking decryption status - tls: rx: strp: set the skb->len of detached / CoW'ed skbs - tls: rx: strp: fix determining record length in copy mode - tls: rx: strp: force mixed decrypted records into copy mode - tls: rx: strp: factor out copying skb data - tls: rx: strp: preserve decryption status of skbs when needed - net/mlx5: E-switch, Devcom, sync devcom events and devcom comp register - [x86] gpio-f7188x: fix chip name and pin count on Nuvoton chip - bpf, sockmap: Pass skb ownership through read_skb - bpf, sockmap: Convert schedule_work into delayed_work - bpf, sockmap: Reschedule is now done through backlog - bpf, sockmap: Improved check for empty queue - bpf, sockmap: Handle fin correctly - bpf, sockmap: TCP data stall on recv before accept - bpf, sockmap: Wake up polling after data copy - bpf, sockmap: Incorrectly handling copied_seq - blk-mq: fix race condition in active queue accounting - vfio/type1: check pfn valid before converting to struct page - net: page_pool: use in_softirq() instead - page_pool: fix inconsistency for page_pool_ring_[un]lock() - net: phy: mscc: enable VSC8501/2 RGMII RX clock - wifi: iwlwifi: mvm: support wowlan info notification version 2 - wifi: iwlwifi: mvm: fix potential memory leak - RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" - drm/amd: Don't allow s0ix on APUs older than Raven - bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() - block: fix bio-cache for passthru IO - [x86] cpufreq: amd-pstate: Update policy->cur in amd_pstate_adjust_perf() - [x86] cpufreq: amd-pstate: Add ->fast_switch() callback - netfilter: ctnetlink: Support offloaded conntrack entry deletion https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.33 - [arm64,armhf] phy: amlogic: phy-meson-g12a-mipi-dphy-analog: fix CNTL2_DIF_TX_CTL0 value - [arm64] RDMA/hns: Fix timeout attr in query qp for HIP08 - [arm64] RDMA/hns: Fix base address table allocation - [arm64] RDMA/hns: Modify the value of long message loopback slice - [arm64,armhf] iommu/rockchip: Fix unwind goto issue - [amd64] iommu/amd: Don't block updates to GATag if guest mode is on - [amd64] iommu/amd: Handle GALog overflows - [amd64] iommu/amd: Fix up merge conflict resolution - nfsd: make a copy of struct iattr before calling notify_change - net/mlx5: Drain health before unregistering devlink - net/mlx5: SF, Drain health before removing device - net/mlx5: fw_tracer, Fix event handling - net/mlx5e: Don't attach netdev profile while handling internal error - netrom: fix info-leak in nr_write_internal() - af_packet: Fix data-races of pkt_sk(sk)->num. - tls: improve lockless access safety of tls_err_abort() - [amd64,arm64] amd-xgbe: fix the false linkup in xgbe_phy_status - perf ftrace latency: Remove unnecessary "--" from --use-nsec option - RDMA/irdma: Prevent QP use after free - RDMA/irdma: Fix Local Invalidate fencing - af_packet: do not use READ_ONCE() in packet_bind() - tcp: deny tcp_disconnect() when threads are waiting - tcp: Return user_mss for TCP_MAXSEG in CLOSE/LISTEN state if user_mss set - net/smc: Scan from current RMB list when no position specified - net/smc: Don't use RMBs not mapped to new link in SMCRv2 ADD LINK - net/sched: sch_ingress: Only create under TC_H_INGRESS - net/sched: sch_clsact: Only create under TC_H_CLSACT - net/sched: Reserve TC_H_INGRESS (TC_H_CLSACT) for ingress (clsact) Qdiscs - net/sched: Prohibit regrafting ingress or clsact Qdiscs - net: sched: fix NULL pointer dereference in mq_attach - net/netlink: fix NETLINK_LIST_MEMBERSHIPS length report - udp6: Fix race condition in udp6_sendmsg & connect - nfsd: fix double fget() bug in __write_ports_addfd() - nvme: fix the name of Zone Append for verbose logging - net/mlx5e: Fix error handling in mlx5e_refresh_tirs - net/mlx5: Read embedded cpu after init bit cleared - net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (CVE-2023-35788) - tcp: fix mishandling when the sack compression is deferred. - [arm64,armhf] net: dsa: mv88e6xxx: Increase wait after reset deactivation - [armhf] mtd: rawnand: marvell: ensure timing values are written - [armhf] mtd: rawnand: marvell: don't set the NAND frequency select - rtnetlink: call validate_linkmsg in rtnl_create_link - mptcp: avoid unneeded __mptcp_nmpc_socket() usage - mptcp: add annotations around msk->subflow accesses - mptcp: avoid unneeded address copy - mptcp: simplify subflow_syn_recv_sock() - mptcp: consolidate passive msk socket initialization - mptcp: fix data race around msk->first access - mptcp: add annotations around sk->sk_shutdown accesses - drm/amdgpu: release gpu full access after "amdgpu_device_ip_late_init" - ALSA: hda: Glenfly: add HD Audio PCI IDs and HDMI Codec Vendor IDs. - [x86] ASoC: Intel: soc-acpi-cht: Add quirk for Nextbook Ares 8A tablet - drm/amdgpu: Use the default reset when loading or reloading the driver - [arm64] drm/ast: Fix ARM compatibility - btrfs: abort transaction when sibling keys check fails for leaves - [armel,armhf] ARM: 9295/1: unwind:fix unwind abort for uleb128 case - [x86] hwmon: (k10temp) Add PCI ID for family 19, model 78h - gfs2: Don't deref jdesc in evict (CVE-2023-3212) - drm/amdgpu: set gfx9 onwards APU atomics support to be true - fbdev: modedb: Add 1920x1080 at 60 Hz video mode - nbd: Fix debugfs_create_dir error checking - nvme-pci: add NVME_QUIRK_BOGUS_NID for HS-SSD-FUTURE 2048G - nvme-pci: add quirk for missing secondary temperature thresholds - [x86] ASoC: amd: yc: Add DMI entry to support System76 Pangolin 12 - xfrm: Check if_id in inbound policy/secpath match - [x86] ALSA: hda/realtek: Add quirks for ASUS GU604V and GU603V - media: dvb_demux: fix a bug for the continuity counter - media: dvb-usb: az6027: fix three null-ptr-deref in az6027_i2c_xfer() - media: dvb-usb-v2: ec168: fix null-ptr-deref in ec168_i2c_xfer() - media: dvb-usb-v2: ce6230: fix null-ptr-deref in ce6230_i2c_master_xfer() - media: dvb-usb-v2: rtl28xxu: fix null-ptr-deref in rtl28xxu_i2c_xfer - media: dvb-usb: digitv: fix null-ptr-deref in digitv_i2c_xfer() - media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address - media: netup_unidvb: fix irq init by register it at the end of probe - media: dvb_ca_en50221: fix a size write bug - media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() - media: dvb-core: Fix use-after-free due on race condition at dvb_net - media: dvb-core: Fix use-after-free due to race at dvb_register_device() - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() (CVE-2023-31084) - media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 - [x86] ASoC: SOF: debug: conditionally bump runtime_pm counter on exceptions - [x86] ASoC: SOF: pcm: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: sof-client-probes: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: pm: save io region state in case of errors in resume - [s390x] topology: honour nr_cpu_ids when adding CPUs - ACPI: resource: Add IRQ override quirk for LG UltraPC 17U70P - wifi: rtl8xxxu: fix authentication timeout due to incorrect RCR value - [arm64] mm: mark private VM_FAULT_X defines as vm_fault_t - [arm64] vdso: Pass (void *) to virt_to_page() - wifi: mac80211: simplify chanctx allocation - wifi: mac80211: consider reserved chanctx for mindef - wifi: mac80211: recalc chanctx mindef before assigning - wifi: iwlwifi: mvm: Add locking to the rate read flow - scsi: core: Decrease scsi_device's iorequest_cnt if dispatch failed - nvme-multipath: don't call blk_mark_disk_dead in nvme_mpath_remove_disk - nvme: do not let the user delete a ctrl before a complete initialization - [arm64] drm/msm: Be more shouty if per-process pgtables aren't working - ceph: silence smatch warning in reconnect_caps_cb() - drm/amdgpu: skip disabling fence driver src_irqs when device is unplugged - nvme-pci: Add quirk for Teamgroup MP33 SSD - block: Deny writable memory mapping if block is read-only - [arm64] KVM: arm64: vgic: Fix a circular locking issue - [arm64] KVM: arm64: vgic: Wrap vgic_its_create() with config_lock - [arm64] KVM: arm64: vgic: Fix locking comment - drivers: base: cacheinfo: Fix shared_cpu_map changes in event of CPU hotplug - media: uvcvideo: Don't expose unsupported formats to userspace - iio: accel: st_accel: Fix invalid mount_matrix on devices without ACPI _ONT method - HID: google: add jewel USB id - HID: wacom: avoid integer overflow in wacom_intuos_inout() - iio: imu: inv_icm42600: fix timestamp reset - iio: light: vcnl4035: fixed chip ID check - iio: adc: ad_sigma_delta: Fix IRQ issue by setting IRQ_DISABLE_UNLAZY flag - iio: dac: mcp4725: Fix i2c_master_send() return value handling - iio: adc: ad7192: Change "shorted" channels to differential - net: usb: qmi_wwan: Set DTR quirk for BroadMobi BM818 - usb: gadget: f_fs: Add unbind event before functionfs_unbind - md/raid5: fix miscalculation of 'end_sector' in raid5_read_one_chunk() - ata: libata-scsi: Use correct device no in ata_find_dev() - drm/amdgpu: enable tmz by default for GC 11.0.1 - drm/amd/pm: reverse mclk and fclk clocks levels for SMU v13.0.4 - drm/amd/pm: reverse mclk and fclk clocks levels for vangogh - drm/amd/pm: resolve reboot exception for si oland - drm/amd/pm: reverse mclk clocks levels for SMU v13.0.5 - drm/amd/pm: reverse mclk and fclk clocks levels for yellow carp - drm/amd/pm: reverse mclk and fclk clocks levels for renoir - [x86] mtrr: Revert 90b926e68f50 ("x86/pat: Fix pat_x_mtrr_type() for MTRR disabled case") - mmc: vub300: fix invalid response handling - [armhf] mmc: pwrseq: sd8787: Fix WILC CHIP_EN and RESETN toggling order - [arm64] tty: serial: fsl_lpuart: use UARTCTRL_TXINV to send break instead of UARTCTRL_SBK - btrfs: fix csum_tree_block page iteration to avoid tripping on -Werror=array-bounds - [arm64] phy: qcom-qmp-combo: fix init-count imbalance - [arm64] phy: qcom-qmp-pcie-msm8996: fix init-count imbalance - block: fix revalidate performance regression - [powerpc*] iommu: Limit number of TCEs to 512 for H_STUFF_TCE hcall - [amd64] iommu/amd: Fix domain flush size when syncing iotlb - tpm, tpm_tis: correct tpm_tis_flags enumeration values - io_uring: undeprecate epoll_ctl support - mtdchar: mark bits of ioctl handler noinline - [rt] tracing/timerlat: Always wakeup the timerlat thread - tracing/histograms: Allow variables to have some modifiers - tracing/probe: trace_probe_primary_from_call(): checked list_first_entry - mptcp: fix connect timeout handling - mptcp: fix active subflow finalization - ext4: add EA_INODE checking to ext4_iget() - ext4: disallow ea_inodes with extended attributes - fbcon: Fix null-ptr-deref in soft_cursor - [arm64,armhf] serial: 8250_tegra: Fix an error handling path in tegra_uart_probe() - [powerpc*] xmon: Use KSYM_NAME_LEN in array size - [arm64] KVM: arm64: Populate fault info for watchpoint - [x86] KVM: x86: Account fastpath-only VM-Exits in vCPU stats - ksmbd: fix credit count leakage - ksmbd: fix UAF issue from opinfo->conn - ksmbd: fix incorrect AllocationSize set in smb2_get_info - ksmbd: fix slab-out-of-bounds read in smb2_handle_negotiate - ksmbd: fix multiple out-of-bounds read during context decoding - KEYS: asymmetric: Copy sig and digest in public_key_verify_signature() - fs/ntfs3: Validate MFT flags before replaying logs (CVE-2022-48425) - regmap: Account for register length when chunking - tpm, tpm_tis: Request threaded interrupt handler - [amd64] iommu/amd/pgtbl_v2: Fix domain max address - drm/amd/display: Have Payload Properly Created After Resume - xfs: verify buffer contents when we skip log replay (CVE-2023-2124) - tls: rx: strp: don't use GFP_KERNEL in softirq context - [arm64] efi: Use SMBIOS processor version to key off Ampere quirk - ext4: enable the lazy init thread when remounting read/write https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.34 - scsi: megaraid_sas: Add flexible array member for SGLs - net: sfp: fix state loss when updating state_hw_mask - [x86] platform/surface: aggregator: Allow completion work-items to be executed in parallel - [x86] platform/surface: aggregator_tabletsw: Add support for book mode in KIP subsystem - [arm64] spi: qup: Request DMA before enabling clocks - afs: Fix setting of mtime when creating a file/dir/symlink - wifi: mt76: mt7615: fix possible race in mt7615_mac_sta_poll - bpf, sockmap: Avoid potential NULL dereference in sk_psock_verdict_data_ready() - neighbour: fix unaligned access to pneigh_entry - net/ipv4: ping_group_range: allow GID from 2147483648 to 4294967294 - bpf: Fix UAF in task local storage - bpf: Fix elem_size not being set for inner maps - net/ipv6: fix bool/int mismatch for skip_notify_on_dev_down - net/smc: Avoid to access invalid RMBs' MRs in SMCRv1 ADD LINK CONT - [arm64] net: enetc: correct the statistics of rx bytes - [arm64] net: enetc: correct rx_bytes statistics of XDP - net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values - [x86] drm/i915: Explain the magic numbers for AUX SYNC/precharge length - [x86] drm/i915: Use 18 fast wake AUX sync len - Bluetooth: hci_sync: add lock to protect HCI_UNREGISTER - Bluetooth: Fix l2cap_disconnect_req deadlock - Bluetooth: ISO: don't try to remove CIG if there are bound CIS left - Bluetooth: L2CAP: Add missing checks for invalid DCID - wifi: mac80211: use correct iftype HE cap - wifi: cfg80211: reject bad AP MLD address - wifi: mac80211: mlme: fix non-inheritence element - wifi: mac80211: don't translate beacon/presp addrs - qed/qede: Fix scheduling while atomic - wifi: cfg80211: fix locking in sched scan stop work - netfilter: nft_bitwise: fix register tracking - netfilter: conntrack: fix NULL pointer dereference in nf_confirm_cthelper - netfilter: ipset: Add schedule point in call_ad(). - netfilter: nf_tables: out-of-bound check in chain blob - ipv6: rpl: Fix Route of Death. (CVE-2023-2156) - tcp: gso: really support BIG TCP - rfs: annotate lockless accesses to sk->sk_rxhash - rfs: annotate lockless accesses to RFS sock flow table - net: sched: add rcu annotations around qdisc->qdisc_sleeping - net: sched: move rtm_tca_policy declaration to include file - net: sched: act_police: fix sparse errors in tcf_police_dump() - net: sched: fix possible refcount leak in tc_chain_tmplt_add() - bpf: Add extra path pointer check to d_path helper - drm/amdgpu: fix Null pointer dereference error in amdgpu_device_recover_vram - lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release() - [arm64] net: bcmgenet: Fix EEE implementation - bnxt_en: Don't issue AP reset during ethtool's reset operation - bnxt_en: Query default VLAN before VNIC setup on a VF - bnxt_en: Skip firmware fatal error recovery if chip is not accessible - bnxt_en: Prevent kernel panic when receiving unexpected PHC_UPDATE event - bnxt_en: Implement .set_port / .unset_port UDP tunnel callbacks - batman-adv: Broken sync while rescheduling delayed work - Input: xpad - delete a Razer DeathAdder mouse VID/PID entry - Input: psmouse - fix OOB access in Elantech protocol - Input: fix open count when closing inhibited device - ALSA: hda: Fix kctl->id initialization - ALSA: ymfpci: Fix kctl->id initialization - [i386] ALSA: gus: Fix kctl->id initialization - ALSA: cmipci: Fix kctl->id initialization - [x86] ALSA: hda/realtek: Add quirk for Clevo NS50AU - ALSA: ice1712,ice1724: fix the kcontrol->id initialization - [x86] ALSA: hda/realtek: Add a quirk for HP Slim Desktop S01 - [x86] ALSA: hda/realtek: Add Lenovo P3 Tower platform - [x86] ALSA: hda/realtek: Add quirks for Asus ROG 2024 laptops using CS35L41 - [x86] drm/i915/gt: Use the correct error value when kernel_context() fails - drm/amd/pm: conditionally disable pcie lane switching for some sienna_cichlid SKUs - drm/amdgpu: fix xclk freq on CHIP_STONEY - drm/amdgpu: change reserved vram info print - drm/amd/pm: Fix power context allocation in SMU13 - drm/amd/display: Reduce sdp bw after urgent to 90% - wifi: iwlwifi: mvm: Fix -Warray-bounds bug in iwl_mvm_wait_d3_notif() - can: j1939: j1939_sk_send_loop_abort(): improved error queue handling in J1939 Socket - can: j1939: change j1939_netdev_lock type to mutex - can: j1939: avoid possible use-after-free when j1939_can_rx_register fails - mptcp: only send RM_ADDR in nl_cmd_remove - mptcp: add address into userspace pm list - mptcp: update userspace pm infos - ceph: fix use-after-free bug for inodes when flushing capsnaps - [s390x] dasd: Use correct lock while counting channel queue length - Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk - Bluetooth: fix debugfs registration - Bluetooth: hci_qca: fix debugfs registration - rbd: move RBD_OBJ_FLAG_COPYUP_ENABLED flag setting - rbd: get snapshot context after exclusive lock is ensured to be held - virtio_net: use control_buf for coalesce params - [arm64] pinctrl: meson-axg: add missing GPIOA_18 gpio group - usb: usbfs: Enforce page requirements for mmap - usb: usbfs: Use consistent mmap functions - [arm64] dts: imx8qm-mek: correct GPIOs for USDHC2 CD and WP signals - [arm*] ASoC: simple-card-utils: fix PCM constraint error check - blk-mq: fix blk_mq_hw_ctx active request accounting - [arm64] dts: imx8mn-beacon: Fix SPI CS pinmux - [arm*] i2c: mv64xxx: Fix reading invalid status value in atomic mode - soundwire: stream: Add missing clear of alloc_slave_rt - vhost: support PACKED when setting-getting vring_base - ksmbd: fix out-of-bound read in deassemble_neg_contexts() - ksmbd: fix out-of-bound read in parse_lease_state() - ksmbd: check the validation of pdu_size in ksmbd_conn_handler_loop - ext4: only check dquot_initialize_needed() when debugging - wifi: rtw89: correct PS calculation for SUPPORTS_DYNAMIC_PS - wifi: rtw88: correct PS calculation for SUPPORTS_DYNAMIC_PS https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.35 - [amd64] x86/head/64: Switch to KERNEL_CS as soon as new GDT is installed - cgroup: bpf: use cgroup_lock()/cgroup_unlock() wrappers - cgroup: always put cset in cgroup_css_set_put_fork - cgroup: fix missing cpus_read_{lock,unlock}() in cgroup_transfer_tasks() - EDAC/qcom: Get rid of hardcoded register offsets - ksmbd: validate smb request protocol id - of: overlay: Fix missing of_node_put() in error case of init_overlay_changeset() - power: supply: bq27xxx: Use mod_delayed_work() instead of cancel() + schedule() - [armhf] dts: vexpress: add missing cache properties - power: supply: Ratelimit no data debug output - PCI/DPC: Quirk PIO log size for Intel Ice Lake Root Ports - [x86] platform/x86: asus-wmi: Ignore WMI events with codes 0x7B, 0xC0 - regulator: Fix error checking for debugfs_create_dir - [arm64,armhf] irqchip/gic-v3: Disable pseudo NMIs on Mediatek devices w/ firmware issues - [arm64,armhf] irqchip/meson-gpio: Mark OF related data as maybe unused - power: supply: Fix logic checking if system is running from battery - drm: panel-orientation-quirks: Change Air's quirk to support Air Plus - btrfs: scrub: try harder to mark RAID56 block groups read-only - btrfs: handle memory allocation failure in btrfs_csum_one_bio - ASoC: soc-pcm: test if a BE can be prepared - [mips*] unhide PATA_PLATFORM - [mips*] Restore Au1300 support - [mips*] Move initrd_start check after initrd address sanitisation. - ASoC: cs35l41: Fix default regmap values for some registers - ASoC: dwc: move DMA init to snd_soc_dai_driver probe() - xen/blkfront: Only check REQ_FUA for writes - drm:amd:amdgpu: Fix missing buffer object unlock in failure path - io_uring: unlock sqd->lock before sq thread release CPU - NVMe: Add MAXIO 1602 to bogus nid list. - [arm64,armhf] irqchip/gic: Correctly validate OF quirk descriptors - wifi: cfg80211: fix locking in regulatory disconnect - wifi: cfg80211: fix double lock bug in reg_wdev_chan_valid() - epoll: ep_autoremove_wake_function should use list_del_init_careful - ocfs2: fix use-after-free when unmounting read-only filesystem - ocfs2: check new file size on fallocate call - zswap: do not shrink if cgroup may not zswap - nilfs2: fix incomplete buffer cleanup in nilfs_btnode_abort_change_key() - nilfs2: fix possible out-of-bounds segment allocation in resize ioctl - nilfs2: reject devices with insufficient block count - io_uring/net: save msghdr->msg_control for retries - kexec: support purgatories with .text.hot sections - [x86] purgatory: remove PGO flags - [powerpc*] purgatory: remove PGO flags - btrfs: do not ASSERT() on duplicated global roots - btrfs: fix iomap_begin length for nocow writes - btrfs: can_nocow_file_extent should pass down args->strict from callers - ALSA: usb-audio: Fix broken resume due to UAC3 power state - ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback - dm thin metadata: check fail_io before using data_sm - dm thin: fix issue_discard to pass GFP_NOIO to __blkdev_issue_discard - net: ethernet: stmicro: stmmac: fix possible memory leak in __stmmac_open - nouveau: fix client work fence deletion race - RDMA/uverbs: Restrict usage of privileged QKEYs - drm/amdgpu: vcn_4_0 set instance 0 init sched score to 1 - net: usb: qmi_wwan: add support for Compal RXM-G1 - drm/amd/display: edp do not add non-edid timings - drm/amd: Make sure image is written to trigger VBIOS image update flow - drm/amd: Tighten permissions on VBIOS flashing attributes - drm/amd/pm: workaround for compute workload type on some skus - drm/amdgpu: add missing radeon secondary PCI ID - ALSA: hda/realtek: Add a quirk for Compaq N14JP6 - [x86] thunderbolt: Do not touch CL state configuration during discovery - [x86] thunderbolt: dma_test: Use correct value for absent rings when creating paths - [x86] thunderbolt: Mask ring interrupt on Intel hardware as well - USB: serial: option: add Quectel EM061KGL series - usb: typec: ucsi: Fix command cancellation - usb: typec: Fix fast_role_swap_current show function - usb: gadget: udc: core: Offload usb_udc_vbus_handler processing - usb: gadget: udc: core: Prevent soft_connect_store() race - [arm64] USB: dwc3: qcom: fix NULL-deref on suspend - [arm64,armhf] USB: dwc3: fix use-after-free on core driver unbind - [arm64,armhf] usb: dwc3: gadget: Reset num TRBs before giving back the request - RDMA/rxe: Fix packet length checks - RDMA/rxe: Fix ref count error in check_rkey() - spi: cadence-quadspi: Add missing check for dma_set_mask - [arm64] spi: fsl-dspi: avoid SCK glitches with continuous transfers - netfilter: nf_tables: integrate pipapo into commit protocol - netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM - ice: Fix XDP memory leak when NIC is brought up and down - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE (CVE-2023-3390) - [arm64] net: enetc: correct the indexes of highest and 2nd highest TCs - ping6: Fix send to link-local addresses with VRF. - igb: Fix extts capture value format for 82580/i354/i350 - net/sched: simplify tcf_pedit_act - net/sched: act_pedit: remove extra check for key type - net/sched: act_pedit: Parse L3 Header for L4 offset - net/sched: cls_u32: Fix reference counter leak leading to overflow - wifi: mac80211: fix link activation settings order - wifi: cfg80211: fix link del callback to call correct handler - wifi: mac80211: take lock before setting vif links - RDMA/rxe: Removed unused name from rxe_task struct - RDMA/rxe: Fix the use-before-initialization error of resp_pkts - iavf: remove mask from iavf_irq_enable_queues() - RDMA/mlx5: Initiate dropless RQ for RAW Ethernet functions - RDMA/mlx5: Create an indirect flow table for steering anchor - RDMA/cma: Always set static rate to 0 for RoCE - IB/uverbs: Fix to consider event queue closing also upon non-blocking mode - RDMA/mlx5: Fix affinity assignment - IB/isert: Fix dead lock in ib_isert - IB/isert: Fix possible list corruption in CMA handler - IB/isert: Fix incorrect release of isert connection - net: ethtool: correct MAX attribute value for stats - ipvlan: fix bound dev checking for IPv6 l3s mode - sctp: fix an error code in sctp_sf_eat_auth() - igc: Clean the TX buffer and TX descriptor ring - igc: Fix possible system crash when loading module - igb: fix nvm.ops.read() error handling - net: phylink: report correct max speed for QUSGMII - net: phylink: use a dedicated helper to parse usgmii control word - drm/nouveau: don't detect DSM for non-NVIDIA device - [arm64] drm/bridge: ti-sn65dsi86: Avoid possible buffer overflow - drm/nouveau/dp: check for NULL nv_connector->native_mode - drm/nouveau: add nv_encoder pointer check for NULL - sched: add new attr TCA_EXT_WARN_MSG to report tc extact message - net/sched: Refactor qdisc_graft() for ingress and clsact Qdiscs - net/sched: qdisc_destroy() old ingress and clsact Qdiscs before grafting - cifs: fix lease break oops in xfstest generic/098 - ext4: drop the call to ext4_error() from ext4_get_group_info() - net/sched: cls_api: Fix lockup on flushing explicitly created chain - [arm64] net: dsa: felix: fix taprio guard band overflow at 10Mbps with jumbo frames - net: macsec: fix double free of percpu stats - sfc: fix XDP queues mode with legacy IRQ - dm: don't lock fs when the map is NULL during suspend or resume - net: tipc: resize nlattr array to correct size - afs: Fix vlserver probe RTT handling - rcu/kvfree: Avoid freeing new kfree_rcu() memory after old grace period - drm/amdgpu: Don't set struct drm_driver.output_poll_changed - net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy - Revert "net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy" - net/sched: act_api: add specific EXT_WARN_MSG for tc action - neighbour: delete neigh_lookup_nodev as not used - scsi: target: core: Fix error path in target_setup_session() - [mips*] Move '-Wa,-msoft-float' check from as-option to cc-option - [mips*] Prefer cc-option for additions to cflags - kbuild: Update assembler calls to use proper flags and language target https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.36 - drm/amd/display: Use dc_update_planes_and_stream - drm/amd/display: Add wrapper to call planes and stream update - drm/amd/display: fix the system hang while disable PSR - [arm64] tty: serial: fsl_lpuart: make rx_watermark configurable for different platforms - [arm64] tty: serial: fsl_lpuart: reduce RX watermark to 0 on LS1028A - ata: libata-scsi: Avoid deadlock on rescan after device resume - mm: Fix copy_from_user_nofault(). (Closes: #1033398) - tpm, tpm_tis: Claim locality in interrupt handler - tpm_crb: Add support for CRB devices based on Pluton - ksmbd: validate command payload size - ksmbd: fix out-of-bound read in smb2_write - ksmbd: validate session id and tree id in the compound request - tick/common: Align tick period during sched_timer setup (Closes: #1038754) - writeback: fix dereferencing NULL mapping->host on writeback_page_template - nilfs2: fix buffer corruption due to concurrent device reads - [x86] ACPI: sleep: Avoid breaking S3 wakeup due to might_sleep() - KVM: Avoid illegal stage2 mapping on invalid memory slot - Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails - Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs - PCI: hv: Fix a race condition bug in hv_pci_query_relations() - Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally" - PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev - PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic - PCI: hv: Add a per-bus mutex state_lock - io_uring/net: clear msg_controllen on partial sendmsg retry - io_uring/net: disable partial retries for recvmsg with cmsg - mptcp: handle correctly disconnect() failures - mptcp: fix possible divide by zero in recvmsg() - mptcp: fix possible list corruption on passive MPJ - mptcp: consolidate fallback and non fallback state machine - cgroup: Do not corrupt task iteration when rebinding subsystem - cgroup,freezer: hold cpu_hotplug_lock before freezer_mutex in freezer_css_{online,offline}() - [arm64] mmc: sdhci-msm: Disable broken 64-bit DMA on MSM8916 - [arm64] mmc: meson-gx: remove redundant mmc_request_done() call from irq context - [arm64,armhf] mmc: mmci: stm32: fix max busy timeout calculation - [arm64,armhf] mmc: bcm2835: fix deferred probing - [arm64,armhf] mmc: sunxi: fix deferred probing - bpf: ensure main program has an extable - wifi: iwlwifi: pcie: Handle SO-F device for PCI id 0x7AF0 - io_uring/poll: serialize poll linked timer start with poll removal - nilfs2: prevent general protection fault in nilfs_clear_dirty_page() - [x86] mm: Avoid using set_pgd() outside of real PGD pages - memfd: check for non-NULL file_seals in memfd_create() syscall - [arm64] mmc: meson-gx: fix deferred probing - ieee802154: hwsim: Fix possible memory leaks - xfrm: Treat already-verified secpath entries as optional - xfrm: interface: rename xfrm_interface.c to xfrm_interface_core.c - xfrm: Ensure policies always checked on XFRM-I input path - [arm64] KVM: arm64: PMU: Restore the host's PMUSERENR_EL0 - bpf: track immediate values written to stack by BPF_ST instruction - bpf: Fix verifier id tracking of scalars on spill - xfrm: fix inbound ipv4/udp/esp packets to UDPv6 dualstack sockets - bpf: Fix a bpf_jit_dump issue for x86_64 with sysctl bpf_jit_enable. - xfrm: Linearize the skb after offloading if needed. - net/mlx5: DR, Fix wrong action data allocation in decap action - sfc: use budget for TX completions - [armel,armhf] mmc: mvsdio: fix deferred probing - [armhf] mmc: omap: fix deferred probing - [armhf] mmc: omap_hsmmc: fix deferred probing - mmc: sdhci-acpi: fix deferred probing - ipvs: align inner_mac_header for encapsulation - be2net: Extend xmit workaround to BE3 chip - netfilter: nf_tables: fix chain binding transaction logic - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: drop map element references from preparation phase - netfilter: nft_set_pipapo: .walk does not deal with generations - netfilter: nf_tables: disallow element updates of bound anonymous sets - netfilter: nf_tables: reject unbound anonymous set before commit phase - netfilter: nf_tables: reject unbound chain set before commit phase - netfilter: nf_tables: disallow updates of anonymous sets - netfilter: nfnetlink_osf: fix module autoload - Revert "net: phy: dp83867: perform soft reset and retain established link" - bpf/btf: Accept function names that contain dots - bpf: Force kprobe multi expected_attach_type for kprobe_multi link - io_uring/net: use the correct msghdr union member in io_sendmsg_copy_hdr - sch_netem: acquire qdisc lock in netem_change() - revert "net: align SO_RCVMARK required privileges with SO_MARK" - [arm64] dts: rockchip: fix nEXTRST on SOQuartz - gpiolib: Fix GPIO chip IRQ initialization restriction - gpiolib: Fix irq_domain resource tracking for gpiochip_irqchip_add_domain() - scsi: target: iscsi: Prevent login threads from racing between each other - HID: wacom: Add error check to wacom_parse_and_register() - smb3: missing null check in SMB2_change_notify - media: cec: core: disable adapter in cec_devnode_unregister - media: cec: core: don't set last_initiator if tx in progress - nfcsim.c: Fix error checking for debugfs_create_dir - btrfs: fix an uninitialized variable warning in btrfs_log_inode - [i386] usb: gadget: udc: fix NULL dereference in remove() - nvme: double KA polling frequency to avoid KATO with TBKAS on - nvme: check IO start time when deciding to defer KA - nvme: improve handling of long keep alives - [x86] Input: soc_button_array - add invalid acpi_index DMI quirk handling - [s390x] cio: unregister device when the only path is gone - [arm*] ASoC: simple-card: Add missing of_node_put() in case of error - soundwire: dmi-quirks: add new mapping for HP Spectre x360 - soundwire: qcom: add proper error paths in qcom_swrm_startup() - [x86] ASoC: nau8824: Add quirk to active-high jack-detect - [x86] ASoC: amd: yc: Add Thinkpad Neo14 to quirks list for acp6x - gfs2: Don't get stuck writing page onto itself under direct I/O - [arm64] ASoC: fsl_sai: Enable BCI bit if SAI works on synchronous mode with BYP asserted - ALSA: hda/realtek: Add "Intel Reference board" and "NUC 13" SSID in the ALC256 - i2c: mchp-pci1xxxx: Avoid cast to incompatible function type - null_blk: Fix: memory release when memory_backed=1 - drm/radeon: fix race condition UAF in radeon_gem_set_domain_ioctl - vhost_net: revert upend_idx only on retriable error - [arm64] KVM: arm64: Restore GICv2-on-GICv3 functionality - [x86] apic: Fix kernel panic when booting with intremap=off and x2apic_phys - [arm64] i2c: imx-lpi2c: fix type char overflow issue when calculating the clock cycle - smb: move client and server files to common directory fs/smb https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.37 - mm/mmap: Fix error path in do_vmi_align_munmap() - mm/mmap: Fix error return in do_vmi_align_munmap() - mptcp: ensure listener is unhashed before updating the sk status - mm, hwpoison: try to recover from copy-on write faults - mm, hwpoison: when copy-on-write hits poison, take page offline - [x86] microcode/AMD: Load late on both threads too - [x86] smp: Make stop_other_cpus() more robust - [x86] smp: Dont access non-existing CPUID leaf - [x86] smp: Remove pointless wmb()s from native_stop_other_cpus() - [x86] smp: Use dedicated cache-line for mwait_play_dead() - [x86] smp: Cure kexec() vs. mwait_play_dead() breakage - can: isotp: isotp_sendmsg(): fix return error fix on TX path - maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() - mm: introduce new 'lock_mm_and_find_vma()' page fault helper - mm: make the page fault mmap locking killable - [arm64] mm: Convert to using lock_mm_and_find_vma() - [powerpc*] mm: Convert to using lock_mm_and_find_vma() - [mips*] mm: Convert to using lock_mm_and_find_vma() - [armhf] mm: Convert to using lock_mm_and_find_vma() - mm/fault: convert remaining simple cases to lock_mm_and_find_vma() - [powerpc*] mm: convert coprocessor fault to lock_mm_and_find_vma() - mm: make find_extend_vma() fail if write lock not held - execve: expand new process stack manually ahead of time - mm: always expand the stack with the mmap write lock held - fbdev: fix potential OOB read in fast_imageblit() - HID: hidraw: fix data race on device refcount - HID: wacom: Use ktime_t rather than int when dealing with timestamps - HID: logitech-hidpp: add HIDPP_QUIRK_DELAYED_INIT for the T651. (Closes: #1038271) . [ Salvatore Bonaccorso ] * d/salsa-ci.yml: Update for bookworm: Set RELEASE to bookworm * d/rules.real: Fix typo in setup_image target. * [amd64,arm64] drivers/virtio: Enable VIRTIO_MEM as module (Closes: #1038665) * Bump ABI to 10 * [rt] Update to 6.1.33-rt11 * Revert "drm/amd/display: edp do not add non-edid timings" . [ Cyril Brulebois ] * udeb: Add r8188eu to nic-wireless-modules (Closes: #1035824) . [ Ben Hutchings ] * Add pkg.linux.mintools profile for building minimal userland tools * d/b/test-patches: Build linux-{kbuild,bootwrapper} packages (Closes: #871216, #1035359) linux-signed-arm64 (6.1.38+1) bookworm; urgency=medium . * Sign kernel from linux 6.1.38-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.38 - drm/amd/display: Remove optimization for VRR updates - drm/amd/display: Do not update DRR while BW optimizations pending - PCI/ACPI: Validate acpi_pci_set_power_state() parameter - PCI/ACPI: Call _REG when transitioning D-states - execve: always mark stack as growing down during early stack setup - perf symbols: Symbol lookup with kcore can fail if multiple segments match stext - scripts/tags.sh: Resolve gtags empty index generation - drm/amdgpu: Validate VM ioctl flags. - drm/amd/display: Ensure vmin and vmax adjust for DCE . [ Salvatore Bonaccorso ] * drm: use mgr->dev in drm_dbg_kms in drm_dp_add_payload_part2 * mm/mmap: Fix VM_LOCKED check in do_vmi_align_munmap() * netfilter: nf_tables: do not ignore genmask when looking up chain by id (CVE-2023-31248) * netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (CVE-2023-35001) linux-signed-arm64 (6.1.37+1) bookworm-security; urgency=high . * Sign kernel from linux 6.1.37-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.28 - [x86] ASOC: Intel: sof_sdw: add quirk for Intel 'Rooks County' NUC M15 - [x86] ASoC: Intel: soc-acpi: add table for Intel 'Rooks County' NUC M15 - ASoC: soc-pcm: fix hw->formats cleared by soc_pcm_hw_init() for dpcm - [x86] hyperv: Block root partition functionality in a Confidential VM - [x86] ASoC: amd: yc: Add DMI entries to support Victus by HP Laptop 16-e1xxx (8A22) - [x86] ASoC: Intel: bytcr_rt5640: Add quirk for the Acer Iconia One 7 B1-750 - [x86] ASoC: da7213.c: add missing pm_runtime_disable() - scsi: mpi3mr: Handle soft reset in progress fault code (0xF002) - net: sfp: add quirk enabling 2500Base-x for HG MXPD-483II - [x86] platform/x86: thinkpad_acpi: Add missing T14s Gen1 type to s2idle quirk list - wifi: ath11k: reduce the MHI timeout to 20s - tracing: Error if a trace event has an array for a __field() - [x86] cpu: Add model number for Intel Arrow Lake processor - wireguard: timers: cast enum limits members to int in prints - wifi: mt76: mt7921e: Set memory space enable in PCI_COMMAND if unset - [arm64] Always load shadow stack pointer directly from the task struct - [arm64] Stash shadow stack pointer in the task struct on interrupt - PCI: pciehp: Fix AB-BA deadlock between reset_lock and device_lock - [arm64] PCI: qcom: Fix the incorrect register usage in v2.7.0 config - [arm64] phy: qcom-qmp-pcie: sc8180x PCIe PHY has 2 lanes - [arm64,armhf] usb: dwc3: gadget: Stall and restart EP0 if host is unresponsive - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on probe errors - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on unbind - [x86] hwmon: (k10temp) Check range scale when CUR_TEMP register is read-write - hwmon: (adt7475) Use device_property APIs when configuring polarity - tpm: Add !tpm_amd_is_rng_defective() to the hwrng_unregister() call site - posix-cpu-timers: Implement the missing timer_wait_running callback - blk-stat: fix QUEUE_FLAG_STATS clear - blk-crypto: don't use struct request_queue for public interfaces - blk-crypto: add a blk_crypto_config_supported_natively helper - blk-crypto: move internal only declarations to blk-crypto-internal.h - blk-crypto: Add a missing include directive - blk-mq: release crypto keyslot before reporting I/O complete - blk-crypto: make blk_crypto_evict_key() return void - blk-crypto: make blk_crypto_evict_key() more robust - tty: Prevent writing chars during tcsetattr TCSADRAIN/FLUSH - xhci: fix debugfs register accesses while suspended - serial: fix TIOCSRS485 locking - serial: 8250: Fix serial8250_tx_empty() race with DMA Tx - tick/nohz: Fix cpu_is_hotpluggable() by checking with nohz subsystem - fs: fix sysctls.c built - [mips*] fw: Allow firmware to pass a empty env - ipmi:ssif: Add send_retries increment - ipmi: fix SSIF not responding under certain cond. - wifi: mt76: add missing locking to protect against concurrent rx/status calls - [arm64,armhf] pwm: meson: Fix axg ao mux parents - [arm64,armhf] pwm: meson: Fix g12a ao clk81 name - soundwire: qcom: correct setting ignore bit on v1.5.1 - ring-buffer: Ensure proper resetting of atomic variables in ring_buffer_reset_online_cpus - ring-buffer: Sync IRQ works before buffer destruction - crypto: api - Demote BUG_ON() in crypto_unregister_alg() to a WARN_ON() - [arm64] crypto: safexcel - Cleanup ring IRQ workqueues on load failure - [x86] crypto: ccp - Don't initialize CCP for PSP 0x1649 - rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed - reiserfs: Add security prefix to xattr name in reiserfs_security_write() - [x86] KVM: nVMX: Emulate NOPs in L2, and PAUSE if it's not intercepted - [arm64] KVM: arm64: Avoid vcpu->mutex v. kvm->lock inversion in CPU_ON - [arm64] KVM: arm64: Avoid lock inversion when setting the VM register width - [arm64] KVM: arm64: Use config_lock to protect data ordered against KVM_RUN - [arm64] KVM: arm64: Use config_lock to protect vgic state - [arm64] KVM: arm64: vgic: Don't acquire its_lock before config_lock - relayfs: fix out-of-bounds access in relay_file_read (CVE-2023-3268) - drm/amd/display: Remove stutter only configurations - drm/amd/display: limit timing for single dimm memory - drm/amd/display: fix PSR-SU/DSC interoperability support - drm/amd/display: fix a divided-by-zero error - ksmbd: fix racy issue under cocurrent smb2 tree disconnect (CVE-2023-32254) - ksmbd: call rcu_barrier() in ksmbd_server_exit() - ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem() - ksmbd: fix memleak in session setup - ksmbd: not allow guest user on multichannel - ksmbd: fix deadlock in ksmbd_find_crypto_ctx() - [x86] ACPI: video: Remove acpi_backlight=video quirk for Lenovo ThinkPad W530 - [arm64,armhf] i2c: omap: Fix standard mode false ACK readings - tracing: Fix permissions for the buffer_percent file - swsmu/amdgpu_smu: Fix the wrong if-condition - drm/amd/pm: re-enable the gfx imu when smu resume - [amd64] iommu/amd: Fix "Guest Virtual APIC Table Root Pointer" configuration in IRTE - Revert "ubifs: dirty_cow_znode: Fix memleak in error handling path" - ubifs: Fix memleak when insert_old_idx() failed - ubi: Fix return value overwrite issue in try_write_vid_and_data() - ubifs: Free memory for tmpfile name - ubifs: Fix memory leak in do_rename - ceph: fix potential use-after-free bug when trimming caps - xfs: don't consider future format versions valid - cxl/hdm: Fail upon detecting 0-sized decoders - bus: mhi: host: Remove duplicate ee check for syserr - bus: mhi: host: Use mhi_tryset_pm_state() for setting fw error state - bus: mhi: host: Range check CHDBOFF and ERDBOFF - rcu: Fix missing TICK_DEP_MASK_RCU_EXP dependency check - tpm, tpm_tis: Do not skip reset of original interrupt vector - tpm, tpm_tis: Claim locality before writing TPM_INT_ENABLE register - tpm, tpm_tis: Disable interrupts if tpm_tis_probe_irq() failed - tpm, tpm_tis: Claim locality before writing interrupt registers - tpm, tpm: Implement usage counter for locality - tpm, tpm_tis: Claim locality when interrupts are reenabled on resume - erofs: stop parsing non-compact HEAD index if clusterofs is invalid - erofs: initialize packed inode after root inode is assigned - erofs: fix potential overflow calculating xattr_isize - [arm64,armhf] drm/rockchip: Drop unbalanced obj unref - [x86] drm/i915/dg2: Drop one PCI ID - drm/vgem: add missing mutex_destroy - drm/probe-helper: Cancel previous job before starting new one - drm/amdgpu: register a vga_switcheroo client for MacBooks with apple-gmux - [arm64] dts: ti: k3-am62-main: Fix GPIO numbers in DT - [arm64] drm/msm/disp/dpu: check for crtc enable rather than crtc active to release shared resources - [amd64] EDAC/skx: Fix overflows on the DRAM row address mapping arrays - regulator: core: Shorten off-on-delay-us for always-on/boot-on by time since booted - [arm64] dts: ti: k3-am62a7-sk: Fix DDR size to full 4GB - [arm64] dts: qcom: msm8998: Fix stm-stimulus-base reg name - [arm64] dts: qcom: sdm845: correct dynamic power coefficients - [x86] MCE/AMD: Use an u64 for bank_map - [arm64] firmware: qcom_scm: Clear download bit during reboot - [arm64] drm/bridge: adv7533: Fix adv7533_mode_valid for adv7533 and adv7535 - [arm64] drm/msm/adreno: drop bogus pm_runtime_set_active() - [arm64] drm: msm: adreno: Disable preemption on Adreno 510 - [amd64] virt/coco/sev-guest: Double-buffer messages - [arm64] dts: qcom: sm8350-microsoft-surface: fix USB dual-role mode property - [x86] ACPI: processor: Fix evaluating _PDC method when running as Xen dom0 - [arm64] mmc: sdhci-of-esdhc: fix quirk to ignore command inhibit for data - [armhf] dts: gta04: fix excess dma channel usage - [arm64] firmware: arm_scmi: Fix xfers allocation on Rx channel - [arm64] perf/arm-cmn: Move overlapping wp_combine field - [armhf] dts: stm32: fix spi1 pin assignment on stm32mp15 - [arm64] cpufreq: qcom-cpufreq-hw: Revert adding cpufreq qos - [arm64,armhf] drm/lima/lima_drv: Add missing unwind goto in lima_pdev_probe() - [arm64,armhf] gpu: host1x: Fix potential double free if IOMMU is disabled - [arm64,armhf] gpu: host1x: Fix memory leak of device names - drm/ttm: optimize pool allocations a bit v2 - drm/ttm/pool: Fix ttm_pool_alloc error path - regulator: core: Consistently set mutex_owner when using ww_mutex_lock_slow() - regulator: core: Avoid lockdep reports when resolving supplies - [x86] apic: Fix atomic update of offset in reserve_eilvt_offset() - [arm64] dts: qcom: msm8994-angler: Fix cont_splash_mem mapping - [arm64] dts: qcom: msm8994-angler: removed clash with smem_region - [arm64,armhf] media: cedrus: fix use after free bug in cedrus_remove due to race condition (CVE-2023-35826) - [arm64] media: rkvdec: fix use after free bug in rkvdec_remove (CVE-2023-35829) - [amd64] platform/x86/amd: pmc: Don't try to read SMU version on Picasso - [amd64] platform/x86/amd: pmc: Hide SMU version and program attributes for Picasso - [amd64] platform/x86/amd: pmc: Don't dump data after resume from s0i3 on picasso - [amd64] platform/x86/amd: pmc: Move idlemask check into `amd_pmc_idlemask_read` - [amd64] platform/x86/amd: pmc: Utilize SMN index 0 for driver probe - [amd64] platform/x86/amd: pmc: Move out of BIOS SMN pair for STB init - media: dm1105: Fix use after free bug in dm1105_remove due to race condition (CVE-2023-35824) - media: saa7134: fix use after free bug in saa7134_finidev due to race condition (CVE-2023-35823) - media: v4l: async: Return async sub-devices to subnotifier list - drm/amd/display: Fix potential null dereference - [arm64,armhf] media: rc: gpio-ir-recv: Fix support for wake-up - [arm64] media: venus: dec: Fix handling of the start cmd - [arm64] media: venus: dec: Fix capture formats enumeration order - [armhf] regulator: stm32-pwr: fix of_iomap leak - [x86] ioapic: Don't return 0 from arch_dynirq_lower_bound() - [arm64] kgdb: Set PSTATE.SS to 1 to re-enable single-step - [arm64] perf/arm-cmn: Fix port detection for CMN-700 - [x86] drm/i915: Make intel_get_crtc_new_encoder() less oopsy - tick/common: Align tick period with the HZ tick. - ACPI: bus: Ensure that notify handlers are not running after removal - cpufreq: use correct unit when verify cur freq - [arm64] rpmsg: glink: Propagate TX failures in intentless mode as well - platform/chrome: cros_typec_switch: Add missing fwnode_handle_put() - wifi: ath6kl: minor fix for allocation size - wifi: ath9k: hif_usb: fix memory leak of remain_skbs - wifi: ath11k: Use platform_get_irq() to get the interrupt - wifi: ath5k: Use platform_get_irq() to get the interrupt - wifi: ath5k: fix an off by one check in ath5k_eeprom_read_freq_list() - wifi: ath11k: fix SAC bug on peer addition with sta band migration - wifi: brcmfmac: support CQM RSSI notification with older firmware - wifi: ath6kl: reduce WARN to dev_dbg() in callback - tools: bpftool: Remove invalid \' json escape - wifi: rtw88: mac: Return the original error from rtw_pwr_seq_parser() - wifi: rtw88: mac: Return the original error from rtw_mac_power_switch() - bpf: take into account liveness when propagating precision - bpf: fix precision propagation verbose logging - [x86] crypto: qat - fix concurrency issue when device state changes - scm: fix MSG_CTRUNC setting condition for SO_PASSSEC - wifi: ath11k: fix deinitialization of firmware resources - bpf: Remove misleading spec_v1 check on var-offset stack read - net: pcs: xpcs: remove double-read of link state when using AN - vlan: partially enable SIOCSHWTSTAMP in container - net/packet: annotate accesses to po->xmit - net/packet: convert po->origdev to an atomic flag - net/packet: convert po->auxdata to an atomic flag - libbpf: Fix ld_imm64 copy logic for ksym in light skeleton. - netfilter: keep conntrack reference until IPsecv6 policy checks are done - bpf: Fix __reg_bound_offset 64->32 var_off subreg propagation - scsi: target: core: Change the way target_xcopy_do_work() sets restiction on max I/O - scsi: target: Move sess cmd counter to new struct - scsi: target: Move cmd counter allocation - scsi: target: Pass in cmd counter to use during cmd setup - scsi: target: iscsit: isert: Alloc per conn cmd counter - scsi: target: iscsit: Stop/wait on cmds during conn close - scsi: target: Fix multiple LUN_RESET handling - scsi: target: iscsit: Fix TAS handling during conn cleanup - scsi: megaraid: Fix mega_cmd_done() CMDID_INT_CMDS - net: sunhme: Fix uninitialized return code - f2fs: handle dqget error in f2fs_transfer_project_quota() - f2fs: fix uninitialized skipped_gc_rwsem - f2fs: apply zone capacity to all zone type - f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() - f2fs: fix scheduling while atomic in decompression path - [arm64,armhf] crypto: caam - Clear some memory in instantiate_rng - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_rfreg() - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_reg() - scsi: libsas: Add sas_ata_device_link_abort() - [arm64] scsi: hisi_sas: Handle NCQ error when IPTT is valid - wifi: rt2x00: Fix memory leak when handling surveys - f2fs: fix iostat lock protection - net: qrtr: correct types of trace event parameters - bpftool: Fix bug for long instructions in program CFG dumps - crypto: drbg - Only fail when jent is unavailable in FIPS mode - xsk: Fix unaligned descriptor validation - f2fs: fix to avoid use-after-free for cached IPU bio - wifi: iwlwifi: fix duplicate entry in iwl_dev_info_table - bpf/btf: Fix is_int_ptr() - scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: rework optional clock handling - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: fix optional phy regulator handling - wifi: ath11k: fix writing to unintended memory region - bpf, sockmap: fix deadlocks in the sockhash and sockmap - nvmet: fix error handling in nvmet_execute_identify_cns_cs_ns() - nvmet: fix Identify Namespace handling - nvmet: fix Identify Controller handling - nvmet: fix Identify Active Namespace ID list handling - nvmet: fix I/O Command Set specific Identify Controller - nvme: fix async event trace event - blk-mq: don't plug for head insertions in blk_execute_rq_nowait - wifi: iwlwifi: debug: fix crash in __iwl_err() - wifi: iwlwifi: trans: don't trigger d3 interrupt twice - wifi: iwlwifi: mvm: don't set CHECKSUM_COMPLETE for unsupported protocols - bpf, sockmap: Revert buggy deadlock fix in the sockhash and sockmap - f2fs: fix to check return value of f2fs_do_truncate_blocks() - f2fs: fix to check return value of inc_valid_block_count() - md/raid10: fix task hung in raid10d - md/raid10: fix leak of 'r10bio->remaining' for recovery - md/raid10: fix memleak for 'conf->bio_split' - md/raid10: fix memleak of md thread - md/raid10: don't call bio_start_io_acct twice for bio which experienced read error - wifi: iwlwifi: mvm: don't drop unencrypted MCAST frames - wifi: iwlwifi: yoyo: skip dump correctly on hw error - wifi: iwlwifi: yoyo: Fix possible division by zero - wifi: iwlwifi: mvm: initialize seq variable - wifi: iwlwifi: fw: move memset before early return - jdb2: Don't refuse invalidation of already invalidated buffers - io_uring/rsrc: use nospec'ed indexes - wifi: iwlwifi: make the loop for card preparation effective - wifi: mt76: handle failure of vzalloc in mt7615_coredump_work - wifi: mt76: add flexible polling wait-interval support - wifi: mt76: mt7921e: fix probe timeout after reboot - wifi: mt76: fix 6GHz high channel not be scanned - mt76: mt7921: fix kernel panic by accessing unallocated eeprom.data - wifi: mt76: mt7921: fix missing unwind goto in `mt7921u_probe` - wifi: mt76: mt7921e: improve reliability of dma reset - wifi: mt76: mt7921e: stop chip reset worker in unregister hook - wifi: mt76: connac: fix txd multicast rate setting - wifi: iwlwifi: mvm: check firmware response size - netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert() - netfilter: conntrack: fix wrong ct->timeout value - wifi: iwlwifi: fw: fix memory leak in debugfs - ixgbe: Allow flow hash to be set via ethtool - ixgbe: Enable setting RSS table to default values - net/mlx5e: Don't clone flow post action attributes second time - net/mlx5: E-switch, Create per vport table based on devlink encap mode - net/mlx5: E-switch, Don't destroy indirect table in split rule - net/mlx5e: Fix error flow in representor failing to add vport rx rule - net/mlx5: Suspend auxiliary devices only in case of PCI device suspend - net/mlx5: Use recovery timeout on sync reset flow - net/mlx5e: Nullify table pointer when failing to create - net: stmmac:fix system hang when setting up tag_8021q VLAN for DSA ports - bpf: Fix race between btf_put and btf_idr walk. - bpf: Don't EFAULT for getsockopt with optval=NULL - netfilter: nf_tables: don't write table validation state without mutex - net/sched: sch_fq: fix integer overflow of "credit" - ipv4: Fix potential uninit variable access bug in __ip_make_skb() - Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" - netlink: Use copy_to_user() for optval in netlink_getsockopt(). - [x86] net: amd: Fix link leak when verifying config failed - tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp. - [x86] ASoC: cs35l41: Only disable internal boost - drivers: staging: rtl8723bs: Fix locking in _rtw_join_timeout_handler() - drivers: staging: rtl8723bs: Fix locking in rtw_scan_timeout_handler() - [arm64] usb: host: xhci-rcar: remove leftover quirk handling - [arm64,armhf] usb: dwc3: gadget: Change condition for processing suspend event - [armhf] serial: stm32: Re-assert RTS/DE GPIO in RS485 mode only if more data are transmitted - iio: light: max44009: add missing OF device matching - [arm64,armhf] spi: imx: Don't skip cleanup in remove's error path - [x86] ASoC: soc-compress: Inherit atomicity from DAI link for Compress FE - [arm64,armhf] PCI: imx6: Install the fault handler only on compatible match - ASoC: es8316: Handle optional IRQ assignment - [arm64] spi: qup: Don't skip cleanup in remove's error path - [x86] vmci_host: fix a race condition in vmci_host_poll() causing GPF - of: Fix modalias string generation - [amd64] HID: amd_sfh: Correct the structure fields - [amd64] HID: amd_sfh: Correct the sensor enable and disable command - [amd64] HID: amd_sfh: Fix illuminance value - [amd64] HID: amd_sfh: Add support for shutdown operation - [amd64] HID: amd_sfh: Correct the stop all command - [amd64] HID: amd_sfh: Increase sensor command timeout for SFH1.1 - [amd64] HID: amd_sfh: Handle "no sensors" enabled for SFH1.1 - cacheinfo: Check sib_leaf in cache_leaves_are_shared() - [arm64] coresight: etm_pmu: Set the module field - PCI/PM: Extend D3hot delay for NVIDIA HDA controllers - spi: cadence-quadspi: fix suspend-resume implementations - [arm64,armhf] usb: chipidea: fix missing goto in `ci_hdrc_probe` - [arm64] tty: serial: fsl_lpuart: adjust buffer length to the intended size - serial: 8250: Add missing wakeup event reporting - spi: cadence-quadspi: use macro DEFINE_SIMPLE_DEV_PM_OPS - [x86] staging: rtl8192e: Fix W_DISABLE# does not work after stop/start - [arm64] spmi: Add a check for remove callback when removing a SPMI driver - virtio_ring: don't update event idx on get_buf - [powerpc*] rtas: use memmove for potentially overlapping buffer copy - sched/fair: Fix inaccurate tally of ttwu_move_affine - perf/core: Fix hardlockup failure caused by perf throttle - Revert "objtool: Support addition to set CFA base" - sched/rt: Fix bad task migration for rt tasks - tracing/user_events: Ensure write index cannot be negative - [amd64] IB/hifi1: add a null check of kzalloc_node in hfi1_ipoib_txreq_init - [amd64] RDMA/rdmavt: Delete unnecessary NULL check - workqueue: Fix hung time report of worker pools - [armhf] rtc: omap: include header for omap_rtc_power_off_program prototype - RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() - [arm64,armhf] rtc: meson-vrtc: Use ktime_get_real_ts64() to get the current time - clk: add missing of_node_put() in "assigned-clocks" property parsing - [arm64] power: supply: rk817: Fix low SOC bugs - RDMA/cm: Trace icm_send_rej event before the cm state is reset - RDMA/srpt: Add a check for valid 'mad_agent' pointer - [amd64] IB/hfi1: Fix SDMA mmu_rb_node not being evicted in LRU order - [amd64] IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests - [arm64,armhf] clk: imx: fracn-gppll: fix the rate table - [arm64,armhf] clk: imx: fracn-gppll: disable hardware select control - NFSv4.1: Always send a RECLAIM_COMPLETE after establishing lease - [amd64] iommu/amd: Set page size bitmap during V2 domain allocation - [arm64] Input: raspberrypi-ts - fix refcount leak in rpi_ts_probe - swiotlb: relocate PageHighMem test away from rmem_swiotlb_setup - swiotlb: fix debugfs reporting of reserved memory pools - RDMA/mlx5: Check pcie_relaxed_ordering_enabled() in UMR - RDMA/mlx5: Fix flow counter query via DEVX - SUNRPC: remove the maximum number of retries in call_bind_status - RDMA/mlx5: Use correct device num_ports when modify DC - timekeeping: Fix references to nonexistent ktime_get_fast_ns() - SMB3: Add missing locks to protect deferred close file list - SMB3: Close deferred file handles in case of handle lease break - ext4: fix i_disksize exceeding i_size problem in paritally written case - ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline - [arm64] dmaengine: mv_xor_v2: Fix an error code. - [armhf] leds: tca6507: Fix error handling of using fwnode_property_read_string - soundwire: cadence: rename sdw_cdns_dai_dma_data as sdw_cdns_dai_runtime - [x86] soundwire: intel: don't save hw_params for use in prepare - [arm64,armhf] phy: tegra: xusb: Add missing tegra_xusb_port_unregister for usb2_port and ulpi_port - [arm64,armhf] pinctrl-bcm2835.c: fix race condition when setting gpio dir - [x86] ACPI: PM: Do not turn of unused power resources on the Toshiba Click Mini - PM: hibernate: Turn snapshot_test into global variable - PM: hibernate: Do not get block device exclusively in test_resume mode - afs: Fix updating of i_size with dv jump from server - afs: Fix getattr to report server i_size on dirs, not local size - afs: Avoid endless loop if file is larger than expected - ALSA: usb-audio: Add quirk for Pioneer DDJ-800 - [x86] ALSA: hda/realtek: Add quirk for ThinkPad P1 Gen 6 - [x86] ALSA: hda/realtek: Add quirk for ASUS UM3402YAR using CS35L41 - [x86] ALSA: hda/realtek: support HP Pavilion Aero 13-be0xxx Mute LED - [x86] ALSA: hda/realtek: Fix mute and micmute LEDs for an HP laptop - nilfs2: do not write dirty data after degenerating to read-only - nilfs2: fix infinite loop in nilfs_mdt_get_block() - mm: do not reclaim private data from pinned page - drbd: correctly submit flush bio on barrier - md/raid10: fix null-ptr-deref in raid10_sync_request - md/raid5: Improve performance for sequential IO - mtd: core: provide unique name for nvmem device, take two - mtd: core: fix nvmem error reporting - mtd: core: fix error path for nvmem provider - mtd: spi-nor: core: Update flash's current address mode when changing address mode - [arm64] mailbox: zynqmp: Fix IPI isr handling - [arm64] mailbox: zynqmp: Fix typo in IPI documentation - wifi: rtl8xxxu: RTL8192EU always needs full init - wifi: rtw89: fix potential race condition between napi_init and napi_enable - [arm64] clk: rockchip: rk3399: allow clk_cifout to force clk_cifout_src to reparent - btrfs: scrub: reject unsupported scrub flags - [s390x] dasd: fix hanging blockdevice after request requeue - mm/mempolicy: correctly update prev when policy is equal on mbind - dm verity: fix error handling for check_at_most_once on FEC - dm integrity: call kmem_cache_destroy() in dm_integrity_init() error path - dm flakey: fix a crash with invalid table line - dm ioctl: fix nested locking in table_clear() to remove deadlock concern (CVE-2023-2269) - dm: don't lock fs when the map is NULL in process of resume - blk-iocost: avoid 64-bit division in ioc_timer_fn - cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname - cifs: protect session status check in smb2_reconnect() - [x86] thunderbolt: Use correct type in tb_port_is_clx_enabled() prototype - wifi: ath11k: synchronize ath11k_mac_he_gi_to_nl80211_he_gi()'s return type - [x86] perf auxtrace: Fix address filter entire kernel size - [x86] perf intel-pt: Fix CYC timestamps after standalone CBR - i40e: Remove unused i40e status codes - i40e: Remove string printing for i40e_status - i40e: use int for i40e_status - scsi: libsas: Grab the ATA port lock in sas_ata_device_link_abort() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.29 - [arm64,armhf] USB: dwc3: gadget: drop dead hibernation code - [arm64,armhf] usb: dwc3: gadget: Execute gadget stop after halting the controller - drm/vmwgfx: Remove explicit and broken vblank handling - drm/vmwgfx: Fix Legacy Display Unit atomic drm support - [amd64] crypto: ccp - Clear PSP interrupt status register before calling handler - [x86] perf/x86/core: Zero @lbr instead of returning -1 in x86_perf_get_lbr() stub - [x86] KVM: x86: Track supported PERF_CAPABILITIES in kvm_caps - [x86] KVM: x86/pmu: Disallow legacy LBRs if architectural LBRs are available - mtd: spi-nor: spansion: Remove NO_SFDP_FLAGS from s28hs512t info - mtd: spi-nor: add SFDP fixups for Quad Page Program - mtd: spi-nor: Add a RWW flag - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s28hx SEMPER flash - [arm64] mailbox: zynq: Switch to flexible array to simplify code - [arm64] mailbox: zynqmp: Fix counts of child nodes - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s25hx SEMPER flash - drm/amd/display: Ext displays with dock can't recognized after resume - [x86] KVM: x86/mmu: Avoid indirect call for get_cr3 - [x86] KVM: x86: Do not unload MMU roots when only toggling CR0.WP with TDP enabled - [x86] KVM: x86: Make use of kvm_read_cr*_bits() when testing bits - [x86] KVM: VMX: Make CR0.WP a guest owned bit - [x86] KVM: x86/mmu: Refresh CR0.WP prior to checking for emulated permission faults - [x86] ASoC: Intel: soc-acpi-byt: Fix "WM510205" match no longer working - scsi: qedi: Fix use after free bug in qedi_remove() - drm/amd/display: Remove FPU guards from the DML folder - drm/amd/display: Add missing WA and MCLK validation - drm/amd/display: Return error code on DSC atomic check failure - drm/amd/display: Fixes for dcn32_clk_mgr implementation - drm/amd/display: Reset OUTBOX0 r/w pointer on DMUB reset - drm/amd/display: Do not clear GPINT register when releasing DMUB from reset - drm/amd/display: Update bounding box values for DCN321 - ixgbe: Fix panic during XDP_TX with > 64 CPUs - [armhf] net/ncsi: clear Tx enable mode when handling a Config required AEN - tcp: fix skb_copy_ubufs() vs BIG TCP - net/sched: cls_api: remove block_cb from driver_list before freeing - sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() - net: ipv6: fix skb hash for some RST packets - [arm64,armhf] net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu - writeback: fix call of incorrect macro - block: Skip destroyed blkg when restart in blkg_destroy_all() - [arm64,armhf] watchdog: dw_wdt: Fix the error handling path of dw_wdt_drv_probe() - [arm64,armhf] i2c: tegra: Fix PEC support for SMBUS block read - net/sched: act_mirred: Add carrier check - r8152: fix flow control issue of RTL8156A - r8152: fix the poor throughput for 2.5G devices - r8152: move setting r8153b_rx_agg_chg_indicate() - sfc: Fix module EEPROM reporting for QSFP modules - rxrpc: Fix hard call timeout units - [x86] drm/i915/mtl: Add the missing CPU transcoder mask in intel_device_info - ethtool: Fix uninitialized number of lanes - af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). - drm/amdgpu: add a missing lock for AMDGPU_SCHED - ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` - [s390x] KVM: s390: fix race in gmap_make_secure() - ice: block LAN in case of VF to VF offload - virtio_net: suppress cpu stall when free_unused_bufs - [arm64] net: enetc: check the index of the SFI rather than the handle - perf record: Fix "read LOST count failed" msg with sample read - perf scripts intel-pt-events.py: Fix IPC output for Python 2 - perf vendor events s390: Remove UTF-8 characters from JSON file - perf tests record_offcpu.sh: Fix redirection of stderr to stdin - perf ftrace: Make system wide the default target for latency subcommand - perf vendor events power9: Remove UTF-8 characters from JSON files - perf pmu: zfree() expects a pointer to a pointer to zero it after freeing its contents - perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() - perf cs-etm: Fix timeless decode mode detection - crypto: api - Add scaffolding to change completion function signature - crypto: engine - Use crypto_request_complete - crypto: engine - fix crypto_queue backlog handling - perf symbols: Fix return incorrect build_id size in elf_read_build_id() - perf tracepoint: Fix memory leak in is_valid_tracepoint() - perf stat: Separate bperf from bpf_profiler - [x86] retbleed: Fix return thunk alignment - btrfs: fix btrfs_prev_leaf() to not return the same key twice - btrfs: zoned: fix wrong use of bitops API in btrfs_ensure_empty_zones - btrfs: properly reject clear_cache and v1 cache for block-group-tree - btrfs: fix assertion of exclop condition when starting balance - btrfs: fix encoded write i_size corruption with no-holes - btrfs: don't free qgroup space unless specified - btrfs: zero the buffer before marking it dirty in btrfs_redirty_list_add - btrfs: make clear_cache mount option to rebuild FST without disabling it - btrfs: print-tree: parent bytenr must be aligned to sector size - btrfs: fix space cache inconsistency after error loading it from disk - btrfs: zoned: zone finish data relocation BG with last IO - btrfs: zoned: fix full zone super block reading on ZNS - cifs: fix pcchunk length type in smb2_copychunk_range - cifs: release leases for deferred close handles when freezing - [amd64] platform/x86/intel-uncore-freq: Return error on write frequency - [x86] platform/x86: touchscreen_dmi: Add upside-down quirk for GDIX1002 ts on the Juno Tablet - [x86] platform/x86: thinkpad_acpi: Fix platform profiles on T490 - [x86] platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i - [x86] platform/x86: thinkpad_acpi: Add profile force ability - inotify: Avoid reporting event with invalid wd - smb3: fix problem remounting a share after shutdown - SMB3: force unmount was failing to close deferred close files - [armhf] remoteproc: stm32: Call of_node_put() on iteration error - sysctl: clarify register_sysctl_init() base directory order - [armhf] ARM: dts: aspeed: asrock: Correct firmware flash SPI clocks - [armhf] ARM: dts: exynos: fix WM8960 clock name in Itop Elite - [armhf] ARM: dts: aspeed: romed8hm3: Fix GPIO polarity of system-fault LED - [arm64] drm/msm/adreno: fix runtime PM imbalance at gpu load - [x86] drm/i915/color: Fix typo for Plane CSC indexes - [arm64] drm/msm: fix NULL-deref on snapshot tear down - [arm64] drm/msm: fix NULL-deref on irq uninstall - [arm64] drm/msm: fix drm device leak on bind errors - [arm64] drm/msm: fix vram leak on bind errors - [arm64] drm/msm: fix workqueue leak on bind errors - [x86] drm/i915/dsi: Use unconditional msleep() instead of intel_dsi_msleep() - f2fs: fix null pointer panic in tracepoint in __replace_atomic_write_block - f2fs: fix potential corruption when moving a directory - [armhf] drm/panel: otm8009a: Set backlight parent to panel device - drm/amd/display: Add NULL plane_state check for cursor disable logic - drm/amd/display: Fix 4to1 MPC black screen with DPP RCO - drm/amd/display: filter out invalid bits in pipe_fuses - drm/amd/display: fix flickering caused by S/G mode - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v10_0_hw_fini - drm/amdgpu: fix an amdgpu_irq_put() issue in gmc_v9_0_hw_fini() - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_fini - drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras - drm/amdgpu/jpeg: Remove harvest checking for JPEG3 - drm/amdgpu: change gfx 11.0.4 external_id range - drm/amdgpu: Fix vram recover doesn't work after whole GPU reset (v2) - drm/amd/display: Enforce 60us prefetch for 200Mhz DCFCLK modes - drm/amd/pm: parse pp_handle under appropriate conditions - drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend - drm/amd/pm: avoid potential UBSAN issue on legacy asics - drm/amdgpu: remove deprecated MES version vars - drm/amd: Load MES microcode during early_init - drm/amd: Add a new helper for loading/validating microcode - drm/amd: Use `amdgpu_ucode_*` helpers for MES - HID: wacom: Set a default resolution for older tablets - HID: wacom: insert timestamp to packed Bluetooth (BT) events - [arm64] drm/msm/adreno: adreno_gpu: Use suspend() instead of idle() on load error - f2fs: specify extent cache for read explicitly - f2fs: move internal functions into extent_cache.c - f2fs: remove unnecessary __init_extent_tree - f2fs: refactor extent_cache to support for read and more - f2fs: allocate the extent_cache by default - f2fs: factor out victim_entry usage from general rb_tree use - [arm64] drm/msm/adreno: Simplify read64/write64 helpers - [arm64] drm/msm: Hangcheck progress detection - [arm64] drm/msm: fix missing wq allocation error handling - wifi: rtw88: rtw8821c: Fix rfe_option field width - [x86] drm/i915/mtl: update scaler source and destination limits for MTL - [x86] drm/i915: Check pipe source size when using skl+ scalers - drm/amd/display: Refactor eDP PSR codes - drm/amd/display: Add Z8 allow states to z-state support list - drm/amd/display: Add debug option to skip PSR CRTC disable - drm/amd/display: Fix Z8 support configurations - drm/amd/display: Add minimum Z8 residency debug option - drm/amd/display: Update minimum stutter residency for DCN314 Z8 - drm/amd/display: Lowering min Z8 residency time - [x86] ASoC: codecs: constify static sdw_slave_ops struct - drm/amd/display: Update Z8 watermarks for DCN314 - drm/amd/display: Update Z8 SR exit/enter latencies - drm/amd/display: Change default Z8 watermark values - ksmbd: Implements sess->ksmbd_chann_list as xarray - ksmbd: fix racy issue from session setup and logoff (CVE-2023-32250) - ksmbd: destroy expired sessions - ksmbd: block asynchronous requests when making a delay on session setup - ksmbd: fix racy issue from smb2 close and logoff with multichannel - drm: Add missing DP DSC extended capability definitions. - drm/dsc: fix drm_edp_dsc_sink_output_bpp() DPCD high byte usage - locking/rwsem: Add __always_inline annotation to __down_read_common() and inlined callers - ext4: fix WARNING in mb_find_extent - ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum (CVE-2023-34256) - ext4: fix data races when using cached status extents - ext4: check iomap type only if ext4_iomap_begin() does not fail - ext4: improve error recovery code paths in __ext4_remount() - ext4: improve error handling from ext4_dirhash() - ext4: fix deadlock when converting an inline directory in nojournal mode - ext4: add bounds checking in get_max_inline_xattr_value_size() - ext4: bail out of ext4_xattr_ibody_get() fails for any reason - ext4: fix lockdep warning when enabling MMP - ext4: remove a BUG_ON in ext4_mb_release_group_pa() - ext4: fix invalid free tracking in ext4_xattr_move_to_block() - drm/dsc: fix DP_DSC_MAX_BPP_DELTA_* macro values - f2fs: fix to do sanity check on extent cache correctly - f2fs: inode: fix to do sanity check on extent cache correctly - [x86] amd_nb: Add PCI ID for family 19h model 78h - [x86] fix clear_user_rep_good() exception handling annotation - drm/amd/display: Fix hang when skipping modeset https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.30 - drm/fbdev-generic: prohibit potential out-of-bounds access - drm/mipi-dsi: Set the fwnode for mipi_dsi_device - net: skb_partial_csum_set() fix against transport header magic value - scsi: ufs: core: Fix I/O hang that occurs when BKOPS fails in W-LUN suspend - tick/broadcast: Make broadcast device replacement work correctly - linux/dim: Do nothing if no time delta between samples - net: stmmac: Initialize MAC_ONEUS_TIC_COUNTER register - net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). - [arm64,armhf] net: phy: bcm7xx: Correct read from expansion register - netfilter: nf_tables: always release netdev hooks from notifier - netfilter: conntrack: fix possible bug_on with enable_hooks=1 - bonding: fix send_peer_notif overflow - netlink: annotate accesses to nlk->cb_running - net: annotate sk->sk_err write from do_recvmmsg() - net: deal with most data-races in sk_wait_event() - net: add vlan_get_protocol_and_depth() helper - tcp: add annotations around sk->sk_shutdown accesses - [amd64,arm64] gve: Remove the code of clearing PBA bit - ipvlan:Fix out-of-bounds caused by unclear skb->cb (CVE-2023-3090) - [arm64] net: mscc: ocelot: fix stat counter register values - net: datagram: fix data-races in datagram_poll() - af_unix: Fix a data race of sk->sk_receive_queue->qlen. - af_unix: Fix data races around sk->sk_shutdown. - [x86] drm/i915/guc: Don't capture Gen8 regs on Xe devices - [x86] drm/i915: Fix NULL ptr deref by checking new_crtc_state - [x86] drm/i915/dp: prevent potential div-by-zero - [x86] drm/i915: Expand force_probe to block probe of devices as well. - [x86] drm/i915: taint kernel when force probing unsupported devices - [x86] fbdev: arcfb: Fix error handling in arcfb_probe() - ext4: reflect error codes from ext4_multi_mount_protect() to its callers - ext4: allow to find by goal if EXT4_MB_HINT_GOAL_ONLY is set - ext4: allow ext4_get_group_info() to fail - rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access - open: return EINVAL for O_DIRECTORY | O_CREAT - fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() - drm/displayid: add displayid_get_header() and check bounds better - drm/amd/display: populate subvp cmd info only for the top pipe - drm/amd/display: Correct DML calculation to align HW formula - [x86] platform/x86: x86-android-tablets: Add Acer Iconia One 7 B1-750 data - drm/amd/display: Enable HostVM based on rIOMMU active - drm/amd/display: Use DC_LOG_DC in the trasform pixel function - regmap: cache: Return error in cache sync operations for REGCACHE_NONE - [arm64] dts: qcom: msm8996: Add missing DWC3 quirks - media: cx23885: Fix a null-ptr-deref bug in buffer_prepare() and buffer_finish() - media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() - [arm64,armhf] drm/rockchip: dw_hdmi: cleanup drm encoder during unbind - memstick: r592: Fix UAF bug in r592_remove due to race condition (CVE-2023-3141) - ACPI: EC: Fix oops when removing custom query handlers - drm/amd/display: fixed dcn30+ underflow issue - [armhf] remoteproc: stm32_rproc: Add mutex protection for workqueue - [arm64,armhf] drm/tegra: Avoid potential 32-bit integer overflow - [arm64] drm/msm/dp: Clean up handling of DP AUX interrupts - ACPICA: Avoid undefined behavior: applying zero offset to null pointer - ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects - [arm64] dts: qcom: sdm845-polaris: Drop inexistent properties - [arm64,armhf] irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 - ACPI: video: Remove desktops without backlight DMI quirks - drm/amd/display: Correct DML calculation to follow HW SPEC - drm/amd: Fix an out of bounds error in BIOS parser - drm/amdgpu: Fix sdma v4 sw fini error - [armhf] media: Prefer designated initializers over memset for subdev pad ops - wifi: ath: Silence memcpy run-time false positive warning - bpf: Annotate data races in bpf_local_storage - wifi: brcmfmac: pcie: Provide a buffer of random bytes to the device - wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex - scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow - scsi: lpfc: Correct used_rpi count when devloss tmo fires with no recovery - bnxt: avoid overflow in bnxt_get_nvram_directory() - net: Catch invalid index in XPS mapping - netdev: Enforce index cap in netdev_get_tx_queue - scsi: target: iscsit: Free cmds before session free - lib: cpu_rmap: Avoid use after free on rmap->obj array entries - scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition - gfs2: Fix inode height consistency check - [x86] scsi: ufs: ufs-pci: Add support for Intel Lunar Lake - ext4: set goal start correctly in ext4_mb_normalize_request - ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() - crypto: jitter - permanent and intermittent health errors - f2fs: Fix system crash due to lack of free space in LFS - f2fs: fix to drop all dirty pages during umount() if cp_error is set - f2fs: fix to check readonly condition correctly - bpf: Add preempt_count_{sub,add} into btf id deny list - md: fix soft lockup in status_resync - wifi: iwlwifi: pcie: fix possible NULL pointer dereference - wifi: iwlwifi: add a new PCI device ID for BZ device - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf - wifi: iwlwifi: mvm: fix ptk_pn memory leak - block, bfq: Fix division by zero error on zero wsum - wifi: ath11k: Ignore frags from uninitialized peer in dp. - wifi: iwlwifi: fix iwl_mvm_max_amsdu_size() for MLO - null_blk: Always check queue mode setting from configfs - wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace - wifi: ath11k: Fix SKB corruption in REO destination ring - nbd: fix incomplete validation of ioctl arg - ipvs: Update width of source for ip_vs_sync_conn_options - Bluetooth: btusb: Add new PID/VID 04ca:3801 for MT7663 - Bluetooth: Add new quirk for broken local ext features page 2 - Bluetooth: btrtl: add support for the RTL8723CS - Bluetooth: Improve support for Actions Semi ATS2851 based devices - Bluetooth: btrtl: check for NULL in btrtl_set_quirks() - Bluetooth: btintel: Add LE States quirk support - Bluetooth: hci_bcm: Fall back to getting bdaddr from EFI if not set - Bluetooth: Add new quirk for broken set random RPA timeout for ATS2851 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp - Bluetooth: btrtl: Add the support for RTL8851B - HID: apple: Set the tilde quirk flag on the Geyser 4 and later - [x86] ASoC: amd: yc: Add DMI entries to support HP OMEN 16-n0xxx (8A42) - HID: logitech-hidpp: Don't use the USB serial for USB devices - HID: logitech-hidpp: Reconcile USB and Unifying serials - [arm64,armhf] spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 - [x86] usb: typec: ucsi: acpi: add quirk for ASUS Zenbook UM325 - ALSA: hda: LNL: add HD Audio PCI ID - [x86] ASoC: amd: Add Dell G15 5525 to quirks list - [x86] ASoC: amd: yc: Add ThinkBook 14 G5+ ARP to quirks list for acp6x - [x86] HID: apple: Set the tilde quirk flag on the Geyser 3 - [x86] HID: Ignore battery for ELAN touchscreen on ROG Flow X13 GV301RA - HID: wacom: generic: Set battery quirk only when we see battery data - usb: typec: tcpm: fix multiple times discover svids error - serial: 8250: Reinit port->pm on port specific driver unbind - [x86] soundwire: dmi-quirks: add remapping for Intel 'Rooks County' NUC M15 - soundwire: qcom: gracefully handle too many ports in DT - soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow - [x86] mfd: intel_soc_pmic_chtwc: Add Lenovo Yoga Book X90F to intel_cht_wc_models - [x86] mfd: intel-lpss: Add Intel Meteor Lake PCH-S LPSS PCI IDs - [x86] platform/x86: Move existing HP drivers to a new hp subdir - [x86] hp-wmi: add micmute to hp_wmi_keymap struct - drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs - xfrm: don't check the default policy if the policy allows the packet - Revert "Fix XFRM-I support for nested ESP tunnels" - [arm64] drm/msm/dp: unregister audio driver during unbind - [arm64] drm/msm/dpu: Assign missing writeback log_mask - [arm64] drm/msm/dpu: Move non-MDP_TOP INTF_INTR offsets out of hwio header - [arm64] drm/msm/dpu: Remove duplicate register defines from INTF - platform: Provide a remove callback that returns no value - [arm64] ASoC: fsl_micfil: Fix error handler with pm_runtime_enable - cpupower: Make TSC read per CPU for Mperf monitor - xfrm: Reject optional tunnel/BEET mode templates in outbound policies - af_key: Reject optional tunnel/BEET mode templates in outbound policies - [arm64] drm/msm: Fix submit error-path leaks - [arm64,armhf] net: fec: Better handle pm_runtime_get() failing in .remove() - net: phy: dp83867: add w/a for packet errors seen with short cables - ALSA: firewire-digi00x: prevent potential use after free - wifi: mt76: connac: fix stats->tx_bytes calculation - [x86] ALSA: hda/realtek: Apply HP B&O top speaker profile to Pavilion 15 - sfc: disable RXFCS and RXALL features by default - vsock: avoid to close connected socket after the timeout - tcp: fix possible sk_priority leak in tcp_v4_send_reset() - [armhf] serial: arc_uart: fix of_iomap leak in `arc_serial_probe` - erspan: get the proto with the md version for collect_md - [arm64] net: hns3: fix output information incomplete for dumping tx queue info with debugfs - [arm64] net: hns3: fix sending pfc frames after reset issue - [arm64] net: hns3: fix reset delay time to avoid configuration timeout - [arm64] net: hns3: fix reset timeout when enable full VF - media: netup_unidvb: fix use-after-free at del_timer() - SUNRPC: double free xprt_ctxt while still in use - SUNRPC: always free ctxt when freeing deferred request - SUNRPC: Fix trace_svc_register() call site - [x86] ASoC: SOF: topology: Fix logic for copying tuples - net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() - virtio-net: Maintain reverse cleanup order - virtio_net: Fix error unwinding of XDP initialization - tipc: add tipc_bearer_min_mtu to calculate min mtu - tipc: do not update mtu if msg_max is too small in mtu negotiation - tipc: check the bearer min mtu properly when setting it by netlink - [s390x] cio: include subchannels without devices also for evaluation - can: dev: fix missing CAN XL support in can_put_echo_skb() - [arm64] net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() - [arm64] net: bcmgenet: Restore phy_stop() depending upon suspend/close - ice: introduce clear_reset_state operation - ice: Fix ice VF reset during iavf initialization - wifi: cfg80211: Drop entries with invalid BSSIDs in RNR - wifi: mac80211: fortify the spinlock against deadlock by interrupt - wifi: mac80211: fix min center freq offset tracing - wifi: mac80211: Abort running color change when stopping the AP - wifi: iwlwifi: mvm: fix cancel_delayed_work_sync() deadlock - wifi: iwlwifi: fw: fix DBGI dump - wifi: iwlwifi: fix OEM's name in the ppag approved list - wifi: iwlwifi: mvm: fix OEM's name in the tas approved list - wifi: iwlwifi: mvm: don't trust firmware n_channels - scsi: storvsc: Don't pass unused PFNs to Hyper-V host - net: tun: rebuild error handling in tun_get_user - tun: Fix memory leak for detached NAPI queue. - cassini: Fix a memory leak in the error handling path of cas_init_one() - [arm64,armhf] net: dsa: mv88e6xxx: Fix mv88e6393x EPC write command offset - igb: fix bit_shift to be in [1..8] range - vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() - net: wwan: iosm: fix NULL pointer dereference when removing device - net: pcs: xpcs: fix C73 AN not getting enabled - netfilter: nf_tables: fix nft_trans type confusion - netfilter: nft_set_rbtree: fix null deref on element insertion - ALSA: usb-audio: Add a sample rate workaround for Line6 Pod Go - USB: usbtmc: Fix direction for 0-length ioctl control messages - usb-storage: fix deadlock when a scsi command timeouts more than once - USB: UHCI: adjust zhaoxin UHCI controllers OverCurrent bit value - [arm64,armhf] usb: dwc3: gadget: Improve dwc3_gadget_suspend() and dwc3_gadget_resume() - [arm64,armhf] usb: dwc3: debugfs: Resume dwc3 before accessing registers - usb: gadget: u_ether: Fix host MAC address case - usb: typec: altmodes/displayport: fix pin_assignment_show - xhci-pci: Only run d3cold avoidance quirk for s2idle - xhci: Fix incorrect tracking of free space on transfer rings - ALSA: hda: Fix Oops by 9.1 surround channel names - ALSA: hda: Add NVIDIA codec IDs a3 through a7 to patch table - [x86] ALSA: hda/realtek: Add quirk for Clevo L140AU - [x86] ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 - [x86] ALSA: hda/realtek: Add quirk for 2nd ASUS GU603 - [x86] ALSA: hda/realtek: Add quirk for HP EliteBook G10 laptops - ALSA: hda/realtek: Fix mute and micmute LEDs for yet another HP laptop - can: j1939: recvmsg(): allow MSG_CMSG_COMPAT flag - can: isotp: recvmsg(): allow MSG_CMSG_COMPAT flag - wifi: rtw88: use work to update rate to avoid RCU warning - SMB3: Close all deferred handles of inode in case of handle lease break - SMB3: drop reference to cfile before sending oplock break - ksmbd: smb2: Allow messages padded to 8byte boundary - ksmbd: allocate one more byte for implied bcc[0] - ksmbd: fix wrong UserName check in session_user - ksmbd: fix global-out-of-bounds in smb2_find_context_vals - KVM: Fix vcpu_array[0] races - statfs: enforce statfs[64] structure initialization - maple_tree: make maple state reusable after mas_empty_area() (Closes: #1036755) - mm: fix zswap writeback race condition - serial: Add support for Advantech PCI-1611U card - serial: 8250_exar: Add support for USR298x PCI Modems - [arm64] serial: qcom-geni: fix enabling deactivated interrupt - [x86] thunderbolt: Clear registers properly when auto clear isn't in use - vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF - ceph: force updating the msg pointer in non-split case - drm/amd/pm: fix possible power mode mismatch between driver and PMFW - drm/amdgpu/gmc11: implement get_vbios_fb_size() - drm/amdgpu/gfx10: Disable gfxoff before disabling powergating. - drm/amdgpu/gfx11: Adjust gfxoff before powergating on gfx11 as well - drm/amdgpu: refine get gpu clock counter method - drm/amdgpu/gfx11: update gpu_clock_counter logic - [powerpc*] iommu: DMA address offset is incorrectly calculated with 2MB TCEs - [powerpc*] iommu: Incorrect DDW Table is referenced for SR-IOV device - tpm/tpm_tis: Disable interrupts for more Lenovo devices - [powerpc*] 64s/radix: Fix soft dirty tracking - nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() - [s390x] dasd: fix command reject error on ESE devices - [s390x] crypto: use vector instructions only if available for ChaCha20 - [s390x] qdio: fix do_sqbs() inline assembly constraint - [arm64] mte: Do not set PG_mte_tagged if tags were not initialized - [x86] rethook: use preempt_{disable, enable}_notrace in rethook_trampoline_handler - [x86] rethook, fprobe: do not trace rethook related functions - crypto: testmgr - fix RNG performance in fuzz tests - drm/amdgpu: declare firmware for new MES 11.0.4 - drm/amd/amdgpu: introduce gc_*_mes_2.bin v2 - drm/amdgpu: reserve the old gc_11_0_*_mes.bin https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.31 - [arm64,armhf] usb: dwc3: fix gadget mode suspend interrupt handler issue - tpm, tpm_tis: Avoid cache incoherency in test for interrupts - tpm, tpm_tis: Only handle supported interrupts - tpm_tis: Use tpm_chip_{start,stop} decoration inside tpm_tis_resume - tpm, tpm_tis: startup chip before testing for interrupts - tpm: Re-enable TPM chip boostrapping non-tpm_tis TPM drivers - tpm: Prevent hwrng from activating during resume - [x86] watchdog: sp5100_tco: Immediately trigger upon starting. - drm/amd/amdgpu: update mes11 api def - drm/amdgpu/mes11: enable reg active poll - skbuff: Proactively round up to kmalloc bucket size - [arm64,armhf] net: dsa: mv88e6xxx: Add RGMII delay to 88E6320 - drm/amd/display: hpd rx irq not working with eDP interface - ocfs2: Switch to security_inode_init_security() - [x86] mm: Avoid incomplete Global INVLPG flushes - [x86] ALSA: hda/ca0132: add quirk for EVGA X299 DARK - ALSA: hda: Fix unhandled register update during auto-suspend period - [x86] ALSA: hda/realtek: Enable headset onLenovo M70/M90 - SUNRPC: Don't change task->tk_status after the call to rpc_exit_task - [arm64,armhf] imc: sdhci-esdhc-imx: make "no-mmc-hs400" works - mmc: block: ensure error propagation for non-blk - [x86] power: supply: axp288_fuel_gauge: Fix external_power_changed race - [arm64] power: supply: bq25890: Fix external_power_changed race - ASoC: rt5682: Disable jack detection interrupt during suspend - net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize - btrfs: use nofs when cleaning up aborted transactions - [x86] drm/mgag200: Fix gamma lut not initialized. - drm/radeon: reintroduce radeon_dp_work_func content - drm/amd/pm: add missing NotifyPowerSource message mapping for SMU13.0.7 - drm/amd/pm: Fix output of pp_od_clk_voltage - Revert "binder_alloc: add missing mmap_lock calls when using the VMA" - Revert "android: binder: stop saving a pointer to the VMA" - binder: add lockless binder_alloc_(set|get)_vma() - binder: fix UAF caused by faulty buffer cleanup - binder: fix UAF of alloc->vma in race with munmap() - drm/amd/amdgpu: limit one queue per gang - [x86] perf/x86/uncore: Correct the number of CHAs on SPR - [x86] topology: Fix erroneous smp_num_siblings on Intel Hybrid platforms - [mips*] irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable - [mips*] irqchip/mips-gic: Use raw spinlock for gic_lock - debugobjects: Don't wake up kswapd from fill_pool() - fbdev: udlfb: Fix endpoint check - net: fix stack overflow when LRO is disabled for virtual interfaces - udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). - USB: core: Add routines for endpoint checks in old drivers - USB: sisusbvga: Add endpoint checks - media: radio-shark: Add endpoint checks - net: fix skb leak in __skb_tstamp_tx() - drm: fix drmm_mutex_init() - bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields - bpf: fix a memory leak in the LRU and LRU_PERCPU hash maps - ipv6: Fix out-of-bounds access in ipv6_find_tlv() - cifs: mapchars mount option ignored - power: supply: leds: Fix blink to LED on transition - power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition - power: supply: bq27xxx: Fix I2C IRQ race on remove - power: supply: bq27xxx: Fix poll_interval handling and races on remove - power: supply: bq27xxx: Add cache parameter to bq27xxx_battery_current_and_status() - power: supply: bq27xxx: Move bq27xxx_battery_update() down - power: supply: bq27xxx: Ensure power_supply_changed() is called on current sign changes - power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize - [arm64] power: supply: bq25890: Call power_supply_changed() after updating input current or voltage - [x86] power: supply: bq24190: Call power_supply_changed() after updating input current - [arm64] optee: fix uninited async notif value - fs: fix undefined behavior in bit shift for SB_NOUSER - [arm64] regulator: pca9450: Fix BUCK2 enable_mask - [x86] platform/x86: ISST: Remove 8 socket limit - [armhf] dts: imx6qdl-mba6: Add missing pvcie-supply regulator - [x86] pci/xen: populate MSI sysfs entries - [x86] show_trace_log_lvl: Ensure stack pointer is aligned, again - [x86] ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg - cxl: Wait Memory_Info_Valid before access memory related info - sctp: fix an issue that plpmtu can never go to complete state - [x86] forcedeth: Fix an error handling path in nv_probe() - net/mlx5e: Fix SQ wake logic in ptp napi_poll context - net/mlx5e: Fix deadlock in tc route query code - net/mlx5e: Use correct encap attribute during invalidation - net/mlx5e: do as little as possible in napi poll when budget is 0 - [s390x] net/mlx5: DR, Fix crc32 calculation to work on big-endian (BE) CPUs - net/mlx5: Handle pairing of E-switch via uplink un/load APIs - net/mlx5: DR, Check force-loopback RC QP capability independently from RoCE - net/mlx5: Fix error message when failing to allocate device memory - net/mlx5: Collect command failures data only for known commands - net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device - net/mlx5: Devcom, serialize devcom registration - [arm64] dts: imx8mn-var-som: fix PHY detection bug by adding deassert delay - net/smc: Reset connection when trying to use SMCRv2 fails. - [x86] 3c589_cs: Fix an error handling path in tc589_probe() - net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.32 - inet: Add IP_LOCAL_PORT_RANGE socket option - ipv{4,6}/raw: fix output xfrm lookup wrt protocol - tls: rx: device: fix checking decryption status - tls: rx: strp: set the skb->len of detached / CoW'ed skbs - tls: rx: strp: fix determining record length in copy mode - tls: rx: strp: force mixed decrypted records into copy mode - tls: rx: strp: factor out copying skb data - tls: rx: strp: preserve decryption status of skbs when needed - net/mlx5: E-switch, Devcom, sync devcom events and devcom comp register - [x86] gpio-f7188x: fix chip name and pin count on Nuvoton chip - bpf, sockmap: Pass skb ownership through read_skb - bpf, sockmap: Convert schedule_work into delayed_work - bpf, sockmap: Reschedule is now done through backlog - bpf, sockmap: Improved check for empty queue - bpf, sockmap: Handle fin correctly - bpf, sockmap: TCP data stall on recv before accept - bpf, sockmap: Wake up polling after data copy - bpf, sockmap: Incorrectly handling copied_seq - blk-mq: fix race condition in active queue accounting - vfio/type1: check pfn valid before converting to struct page - net: page_pool: use in_softirq() instead - page_pool: fix inconsistency for page_pool_ring_[un]lock() - net: phy: mscc: enable VSC8501/2 RGMII RX clock - wifi: iwlwifi: mvm: support wowlan info notification version 2 - wifi: iwlwifi: mvm: fix potential memory leak - RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" - drm/amd: Don't allow s0ix on APUs older than Raven - bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() - block: fix bio-cache for passthru IO - [x86] cpufreq: amd-pstate: Update policy->cur in amd_pstate_adjust_perf() - [x86] cpufreq: amd-pstate: Add ->fast_switch() callback - netfilter: ctnetlink: Support offloaded conntrack entry deletion https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.33 - [arm64,armhf] phy: amlogic: phy-meson-g12a-mipi-dphy-analog: fix CNTL2_DIF_TX_CTL0 value - [arm64] RDMA/hns: Fix timeout attr in query qp for HIP08 - [arm64] RDMA/hns: Fix base address table allocation - [arm64] RDMA/hns: Modify the value of long message loopback slice - [arm64,armhf] iommu/rockchip: Fix unwind goto issue - [amd64] iommu/amd: Don't block updates to GATag if guest mode is on - [amd64] iommu/amd: Handle GALog overflows - [amd64] iommu/amd: Fix up merge conflict resolution - nfsd: make a copy of struct iattr before calling notify_change - net/mlx5: Drain health before unregistering devlink - net/mlx5: SF, Drain health before removing device - net/mlx5: fw_tracer, Fix event handling - net/mlx5e: Don't attach netdev profile while handling internal error - netrom: fix info-leak in nr_write_internal() - af_packet: Fix data-races of pkt_sk(sk)->num. - tls: improve lockless access safety of tls_err_abort() - [amd64,arm64] amd-xgbe: fix the false linkup in xgbe_phy_status - perf ftrace latency: Remove unnecessary "--" from --use-nsec option - RDMA/irdma: Prevent QP use after free - RDMA/irdma: Fix Local Invalidate fencing - af_packet: do not use READ_ONCE() in packet_bind() - tcp: deny tcp_disconnect() when threads are waiting - tcp: Return user_mss for TCP_MAXSEG in CLOSE/LISTEN state if user_mss set - net/smc: Scan from current RMB list when no position specified - net/smc: Don't use RMBs not mapped to new link in SMCRv2 ADD LINK - net/sched: sch_ingress: Only create under TC_H_INGRESS - net/sched: sch_clsact: Only create under TC_H_CLSACT - net/sched: Reserve TC_H_INGRESS (TC_H_CLSACT) for ingress (clsact) Qdiscs - net/sched: Prohibit regrafting ingress or clsact Qdiscs - net: sched: fix NULL pointer dereference in mq_attach - net/netlink: fix NETLINK_LIST_MEMBERSHIPS length report - udp6: Fix race condition in udp6_sendmsg & connect - nfsd: fix double fget() bug in __write_ports_addfd() - nvme: fix the name of Zone Append for verbose logging - net/mlx5e: Fix error handling in mlx5e_refresh_tirs - net/mlx5: Read embedded cpu after init bit cleared - net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (CVE-2023-35788) - tcp: fix mishandling when the sack compression is deferred. - [arm64,armhf] net: dsa: mv88e6xxx: Increase wait after reset deactivation - [armhf] mtd: rawnand: marvell: ensure timing values are written - [armhf] mtd: rawnand: marvell: don't set the NAND frequency select - rtnetlink: call validate_linkmsg in rtnl_create_link - mptcp: avoid unneeded __mptcp_nmpc_socket() usage - mptcp: add annotations around msk->subflow accesses - mptcp: avoid unneeded address copy - mptcp: simplify subflow_syn_recv_sock() - mptcp: consolidate passive msk socket initialization - mptcp: fix data race around msk->first access - mptcp: add annotations around sk->sk_shutdown accesses - drm/amdgpu: release gpu full access after "amdgpu_device_ip_late_init" - ALSA: hda: Glenfly: add HD Audio PCI IDs and HDMI Codec Vendor IDs. - [x86] ASoC: Intel: soc-acpi-cht: Add quirk for Nextbook Ares 8A tablet - drm/amdgpu: Use the default reset when loading or reloading the driver - [arm64] drm/ast: Fix ARM compatibility - btrfs: abort transaction when sibling keys check fails for leaves - [armel,armhf] ARM: 9295/1: unwind:fix unwind abort for uleb128 case - [x86] hwmon: (k10temp) Add PCI ID for family 19, model 78h - gfs2: Don't deref jdesc in evict (CVE-2023-3212) - drm/amdgpu: set gfx9 onwards APU atomics support to be true - fbdev: modedb: Add 1920x1080 at 60 Hz video mode - nbd: Fix debugfs_create_dir error checking - nvme-pci: add NVME_QUIRK_BOGUS_NID for HS-SSD-FUTURE 2048G - nvme-pci: add quirk for missing secondary temperature thresholds - [x86] ASoC: amd: yc: Add DMI entry to support System76 Pangolin 12 - xfrm: Check if_id in inbound policy/secpath match - [x86] ALSA: hda/realtek: Add quirks for ASUS GU604V and GU603V - media: dvb_demux: fix a bug for the continuity counter - media: dvb-usb: az6027: fix three null-ptr-deref in az6027_i2c_xfer() - media: dvb-usb-v2: ec168: fix null-ptr-deref in ec168_i2c_xfer() - media: dvb-usb-v2: ce6230: fix null-ptr-deref in ce6230_i2c_master_xfer() - media: dvb-usb-v2: rtl28xxu: fix null-ptr-deref in rtl28xxu_i2c_xfer - media: dvb-usb: digitv: fix null-ptr-deref in digitv_i2c_xfer() - media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address - media: netup_unidvb: fix irq init by register it at the end of probe - media: dvb_ca_en50221: fix a size write bug - media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() - media: dvb-core: Fix use-after-free due on race condition at dvb_net - media: dvb-core: Fix use-after-free due to race at dvb_register_device() - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() (CVE-2023-31084) - media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 - [x86] ASoC: SOF: debug: conditionally bump runtime_pm counter on exceptions - [x86] ASoC: SOF: pcm: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: sof-client-probes: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: pm: save io region state in case of errors in resume - [s390x] topology: honour nr_cpu_ids when adding CPUs - ACPI: resource: Add IRQ override quirk for LG UltraPC 17U70P - wifi: rtl8xxxu: fix authentication timeout due to incorrect RCR value - [arm64] mm: mark private VM_FAULT_X defines as vm_fault_t - [arm64] vdso: Pass (void *) to virt_to_page() - wifi: mac80211: simplify chanctx allocation - wifi: mac80211: consider reserved chanctx for mindef - wifi: mac80211: recalc chanctx mindef before assigning - wifi: iwlwifi: mvm: Add locking to the rate read flow - scsi: core: Decrease scsi_device's iorequest_cnt if dispatch failed - nvme-multipath: don't call blk_mark_disk_dead in nvme_mpath_remove_disk - nvme: do not let the user delete a ctrl before a complete initialization - [arm64] drm/msm: Be more shouty if per-process pgtables aren't working - ceph: silence smatch warning in reconnect_caps_cb() - drm/amdgpu: skip disabling fence driver src_irqs when device is unplugged - nvme-pci: Add quirk for Teamgroup MP33 SSD - block: Deny writable memory mapping if block is read-only - [arm64] KVM: arm64: vgic: Fix a circular locking issue - [arm64] KVM: arm64: vgic: Wrap vgic_its_create() with config_lock - [arm64] KVM: arm64: vgic: Fix locking comment - drivers: base: cacheinfo: Fix shared_cpu_map changes in event of CPU hotplug - media: uvcvideo: Don't expose unsupported formats to userspace - iio: accel: st_accel: Fix invalid mount_matrix on devices without ACPI _ONT method - HID: google: add jewel USB id - HID: wacom: avoid integer overflow in wacom_intuos_inout() - iio: imu: inv_icm42600: fix timestamp reset - iio: light: vcnl4035: fixed chip ID check - iio: adc: ad_sigma_delta: Fix IRQ issue by setting IRQ_DISABLE_UNLAZY flag - iio: dac: mcp4725: Fix i2c_master_send() return value handling - iio: adc: ad7192: Change "shorted" channels to differential - net: usb: qmi_wwan: Set DTR quirk for BroadMobi BM818 - usb: gadget: f_fs: Add unbind event before functionfs_unbind - md/raid5: fix miscalculation of 'end_sector' in raid5_read_one_chunk() - ata: libata-scsi: Use correct device no in ata_find_dev() - drm/amdgpu: enable tmz by default for GC 11.0.1 - drm/amd/pm: reverse mclk and fclk clocks levels for SMU v13.0.4 - drm/amd/pm: reverse mclk and fclk clocks levels for vangogh - drm/amd/pm: resolve reboot exception for si oland - drm/amd/pm: reverse mclk clocks levels for SMU v13.0.5 - drm/amd/pm: reverse mclk and fclk clocks levels for yellow carp - drm/amd/pm: reverse mclk and fclk clocks levels for renoir - [x86] mtrr: Revert 90b926e68f50 ("x86/pat: Fix pat_x_mtrr_type() for MTRR disabled case") - mmc: vub300: fix invalid response handling - [armhf] mmc: pwrseq: sd8787: Fix WILC CHIP_EN and RESETN toggling order - [arm64] tty: serial: fsl_lpuart: use UARTCTRL_TXINV to send break instead of UARTCTRL_SBK - btrfs: fix csum_tree_block page iteration to avoid tripping on -Werror=array-bounds - [arm64] phy: qcom-qmp-combo: fix init-count imbalance - [arm64] phy: qcom-qmp-pcie-msm8996: fix init-count imbalance - block: fix revalidate performance regression - [powerpc*] iommu: Limit number of TCEs to 512 for H_STUFF_TCE hcall - [amd64] iommu/amd: Fix domain flush size when syncing iotlb - tpm, tpm_tis: correct tpm_tis_flags enumeration values - io_uring: undeprecate epoll_ctl support - mtdchar: mark bits of ioctl handler noinline - [rt] tracing/timerlat: Always wakeup the timerlat thread - tracing/histograms: Allow variables to have some modifiers - tracing/probe: trace_probe_primary_from_call(): checked list_first_entry - mptcp: fix connect timeout handling - mptcp: fix active subflow finalization - ext4: add EA_INODE checking to ext4_iget() - ext4: disallow ea_inodes with extended attributes - fbcon: Fix null-ptr-deref in soft_cursor - [arm64,armhf] serial: 8250_tegra: Fix an error handling path in tegra_uart_probe() - [powerpc*] xmon: Use KSYM_NAME_LEN in array size - [arm64] KVM: arm64: Populate fault info for watchpoint - [x86] KVM: x86: Account fastpath-only VM-Exits in vCPU stats - ksmbd: fix credit count leakage - ksmbd: fix UAF issue from opinfo->conn - ksmbd: fix incorrect AllocationSize set in smb2_get_info - ksmbd: fix slab-out-of-bounds read in smb2_handle_negotiate - ksmbd: fix multiple out-of-bounds read during context decoding - KEYS: asymmetric: Copy sig and digest in public_key_verify_signature() - fs/ntfs3: Validate MFT flags before replaying logs (CVE-2022-48425) - regmap: Account for register length when chunking - tpm, tpm_tis: Request threaded interrupt handler - [amd64] iommu/amd/pgtbl_v2: Fix domain max address - drm/amd/display: Have Payload Properly Created After Resume - xfs: verify buffer contents when we skip log replay (CVE-2023-2124) - tls: rx: strp: don't use GFP_KERNEL in softirq context - [arm64] efi: Use SMBIOS processor version to key off Ampere quirk - ext4: enable the lazy init thread when remounting read/write https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.34 - scsi: megaraid_sas: Add flexible array member for SGLs - net: sfp: fix state loss when updating state_hw_mask - [x86] platform/surface: aggregator: Allow completion work-items to be executed in parallel - [x86] platform/surface: aggregator_tabletsw: Add support for book mode in KIP subsystem - [arm64] spi: qup: Request DMA before enabling clocks - afs: Fix setting of mtime when creating a file/dir/symlink - wifi: mt76: mt7615: fix possible race in mt7615_mac_sta_poll - bpf, sockmap: Avoid potential NULL dereference in sk_psock_verdict_data_ready() - neighbour: fix unaligned access to pneigh_entry - net/ipv4: ping_group_range: allow GID from 2147483648 to 4294967294 - bpf: Fix UAF in task local storage - bpf: Fix elem_size not being set for inner maps - net/ipv6: fix bool/int mismatch for skip_notify_on_dev_down - net/smc: Avoid to access invalid RMBs' MRs in SMCRv1 ADD LINK CONT - [arm64] net: enetc: correct the statistics of rx bytes - [arm64] net: enetc: correct rx_bytes statistics of XDP - net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values - [x86] drm/i915: Explain the magic numbers for AUX SYNC/precharge length - [x86] drm/i915: Use 18 fast wake AUX sync len - Bluetooth: hci_sync: add lock to protect HCI_UNREGISTER - Bluetooth: Fix l2cap_disconnect_req deadlock - Bluetooth: ISO: don't try to remove CIG if there are bound CIS left - Bluetooth: L2CAP: Add missing checks for invalid DCID - wifi: mac80211: use correct iftype HE cap - wifi: cfg80211: reject bad AP MLD address - wifi: mac80211: mlme: fix non-inheritence element - wifi: mac80211: don't translate beacon/presp addrs - qed/qede: Fix scheduling while atomic - wifi: cfg80211: fix locking in sched scan stop work - netfilter: nft_bitwise: fix register tracking - netfilter: conntrack: fix NULL pointer dereference in nf_confirm_cthelper - netfilter: ipset: Add schedule point in call_ad(). - netfilter: nf_tables: out-of-bound check in chain blob - ipv6: rpl: Fix Route of Death. (CVE-2023-2156) - tcp: gso: really support BIG TCP - rfs: annotate lockless accesses to sk->sk_rxhash - rfs: annotate lockless accesses to RFS sock flow table - net: sched: add rcu annotations around qdisc->qdisc_sleeping - net: sched: move rtm_tca_policy declaration to include file - net: sched: act_police: fix sparse errors in tcf_police_dump() - net: sched: fix possible refcount leak in tc_chain_tmplt_add() - bpf: Add extra path pointer check to d_path helper - drm/amdgpu: fix Null pointer dereference error in amdgpu_device_recover_vram - lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release() - [arm64] net: bcmgenet: Fix EEE implementation - bnxt_en: Don't issue AP reset during ethtool's reset operation - bnxt_en: Query default VLAN before VNIC setup on a VF - bnxt_en: Skip firmware fatal error recovery if chip is not accessible - bnxt_en: Prevent kernel panic when receiving unexpected PHC_UPDATE event - bnxt_en: Implement .set_port / .unset_port UDP tunnel callbacks - batman-adv: Broken sync while rescheduling delayed work - Input: xpad - delete a Razer DeathAdder mouse VID/PID entry - Input: psmouse - fix OOB access in Elantech protocol - Input: fix open count when closing inhibited device - ALSA: hda: Fix kctl->id initialization - ALSA: ymfpci: Fix kctl->id initialization - [i386] ALSA: gus: Fix kctl->id initialization - ALSA: cmipci: Fix kctl->id initialization - [x86] ALSA: hda/realtek: Add quirk for Clevo NS50AU - ALSA: ice1712,ice1724: fix the kcontrol->id initialization - [x86] ALSA: hda/realtek: Add a quirk for HP Slim Desktop S01 - [x86] ALSA: hda/realtek: Add Lenovo P3 Tower platform - [x86] ALSA: hda/realtek: Add quirks for Asus ROG 2024 laptops using CS35L41 - [x86] drm/i915/gt: Use the correct error value when kernel_context() fails - drm/amd/pm: conditionally disable pcie lane switching for some sienna_cichlid SKUs - drm/amdgpu: fix xclk freq on CHIP_STONEY - drm/amdgpu: change reserved vram info print - drm/amd/pm: Fix power context allocation in SMU13 - drm/amd/display: Reduce sdp bw after urgent to 90% - wifi: iwlwifi: mvm: Fix -Warray-bounds bug in iwl_mvm_wait_d3_notif() - can: j1939: j1939_sk_send_loop_abort(): improved error queue handling in J1939 Socket - can: j1939: change j1939_netdev_lock type to mutex - can: j1939: avoid possible use-after-free when j1939_can_rx_register fails - mptcp: only send RM_ADDR in nl_cmd_remove - mptcp: add address into userspace pm list - mptcp: update userspace pm infos - ceph: fix use-after-free bug for inodes when flushing capsnaps - [s390x] dasd: Use correct lock while counting channel queue length - Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk - Bluetooth: fix debugfs registration - Bluetooth: hci_qca: fix debugfs registration - rbd: move RBD_OBJ_FLAG_COPYUP_ENABLED flag setting - rbd: get snapshot context after exclusive lock is ensured to be held - virtio_net: use control_buf for coalesce params - [arm64] pinctrl: meson-axg: add missing GPIOA_18 gpio group - usb: usbfs: Enforce page requirements for mmap - usb: usbfs: Use consistent mmap functions - [arm64] dts: imx8qm-mek: correct GPIOs for USDHC2 CD and WP signals - [arm*] ASoC: simple-card-utils: fix PCM constraint error check - blk-mq: fix blk_mq_hw_ctx active request accounting - [arm64] dts: imx8mn-beacon: Fix SPI CS pinmux - [arm*] i2c: mv64xxx: Fix reading invalid status value in atomic mode - soundwire: stream: Add missing clear of alloc_slave_rt - vhost: support PACKED when setting-getting vring_base - ksmbd: fix out-of-bound read in deassemble_neg_contexts() - ksmbd: fix out-of-bound read in parse_lease_state() - ksmbd: check the validation of pdu_size in ksmbd_conn_handler_loop - ext4: only check dquot_initialize_needed() when debugging - wifi: rtw89: correct PS calculation for SUPPORTS_DYNAMIC_PS - wifi: rtw88: correct PS calculation for SUPPORTS_DYNAMIC_PS https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.35 - [amd64] x86/head/64: Switch to KERNEL_CS as soon as new GDT is installed - cgroup: bpf: use cgroup_lock()/cgroup_unlock() wrappers - cgroup: always put cset in cgroup_css_set_put_fork - cgroup: fix missing cpus_read_{lock,unlock}() in cgroup_transfer_tasks() - EDAC/qcom: Get rid of hardcoded register offsets - ksmbd: validate smb request protocol id - of: overlay: Fix missing of_node_put() in error case of init_overlay_changeset() - power: supply: bq27xxx: Use mod_delayed_work() instead of cancel() + schedule() - [armhf] dts: vexpress: add missing cache properties - power: supply: Ratelimit no data debug output - PCI/DPC: Quirk PIO log size for Intel Ice Lake Root Ports - [x86] platform/x86: asus-wmi: Ignore WMI events with codes 0x7B, 0xC0 - regulator: Fix error checking for debugfs_create_dir - [arm64,armhf] irqchip/gic-v3: Disable pseudo NMIs on Mediatek devices w/ firmware issues - [arm64,armhf] irqchip/meson-gpio: Mark OF related data as maybe unused - power: supply: Fix logic checking if system is running from battery - drm: panel-orientation-quirks: Change Air's quirk to support Air Plus - btrfs: scrub: try harder to mark RAID56 block groups read-only - btrfs: handle memory allocation failure in btrfs_csum_one_bio - ASoC: soc-pcm: test if a BE can be prepared - [mips*] unhide PATA_PLATFORM - [mips*] Restore Au1300 support - [mips*] Move initrd_start check after initrd address sanitisation. - ASoC: cs35l41: Fix default regmap values for some registers - ASoC: dwc: move DMA init to snd_soc_dai_driver probe() - xen/blkfront: Only check REQ_FUA for writes - drm:amd:amdgpu: Fix missing buffer object unlock in failure path - io_uring: unlock sqd->lock before sq thread release CPU - NVMe: Add MAXIO 1602 to bogus nid list. - [arm64,armhf] irqchip/gic: Correctly validate OF quirk descriptors - wifi: cfg80211: fix locking in regulatory disconnect - wifi: cfg80211: fix double lock bug in reg_wdev_chan_valid() - epoll: ep_autoremove_wake_function should use list_del_init_careful - ocfs2: fix use-after-free when unmounting read-only filesystem - ocfs2: check new file size on fallocate call - zswap: do not shrink if cgroup may not zswap - nilfs2: fix incomplete buffer cleanup in nilfs_btnode_abort_change_key() - nilfs2: fix possible out-of-bounds segment allocation in resize ioctl - nilfs2: reject devices with insufficient block count - io_uring/net: save msghdr->msg_control for retries - kexec: support purgatories with .text.hot sections - [x86] purgatory: remove PGO flags - [powerpc*] purgatory: remove PGO flags - btrfs: do not ASSERT() on duplicated global roots - btrfs: fix iomap_begin length for nocow writes - btrfs: can_nocow_file_extent should pass down args->strict from callers - ALSA: usb-audio: Fix broken resume due to UAC3 power state - ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback - dm thin metadata: check fail_io before using data_sm - dm thin: fix issue_discard to pass GFP_NOIO to __blkdev_issue_discard - net: ethernet: stmicro: stmmac: fix possible memory leak in __stmmac_open - nouveau: fix client work fence deletion race - RDMA/uverbs: Restrict usage of privileged QKEYs - drm/amdgpu: vcn_4_0 set instance 0 init sched score to 1 - net: usb: qmi_wwan: add support for Compal RXM-G1 - drm/amd/display: edp do not add non-edid timings - drm/amd: Make sure image is written to trigger VBIOS image update flow - drm/amd: Tighten permissions on VBIOS flashing attributes - drm/amd/pm: workaround for compute workload type on some skus - drm/amdgpu: add missing radeon secondary PCI ID - ALSA: hda/realtek: Add a quirk for Compaq N14JP6 - [x86] thunderbolt: Do not touch CL state configuration during discovery - [x86] thunderbolt: dma_test: Use correct value for absent rings when creating paths - [x86] thunderbolt: Mask ring interrupt on Intel hardware as well - USB: serial: option: add Quectel EM061KGL series - usb: typec: ucsi: Fix command cancellation - usb: typec: Fix fast_role_swap_current show function - usb: gadget: udc: core: Offload usb_udc_vbus_handler processing - usb: gadget: udc: core: Prevent soft_connect_store() race - [arm64] USB: dwc3: qcom: fix NULL-deref on suspend - [arm64,armhf] USB: dwc3: fix use-after-free on core driver unbind - [arm64,armhf] usb: dwc3: gadget: Reset num TRBs before giving back the request - RDMA/rxe: Fix packet length checks - RDMA/rxe: Fix ref count error in check_rkey() - spi: cadence-quadspi: Add missing check for dma_set_mask - [arm64] spi: fsl-dspi: avoid SCK glitches with continuous transfers - netfilter: nf_tables: integrate pipapo into commit protocol - netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM - ice: Fix XDP memory leak when NIC is brought up and down - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE (CVE-2023-3390) - [arm64] net: enetc: correct the indexes of highest and 2nd highest TCs - ping6: Fix send to link-local addresses with VRF. - igb: Fix extts capture value format for 82580/i354/i350 - net/sched: simplify tcf_pedit_act - net/sched: act_pedit: remove extra check for key type - net/sched: act_pedit: Parse L3 Header for L4 offset - net/sched: cls_u32: Fix reference counter leak leading to overflow - wifi: mac80211: fix link activation settings order - wifi: cfg80211: fix link del callback to call correct handler - wifi: mac80211: take lock before setting vif links - RDMA/rxe: Removed unused name from rxe_task struct - RDMA/rxe: Fix the use-before-initialization error of resp_pkts - iavf: remove mask from iavf_irq_enable_queues() - RDMA/mlx5: Initiate dropless RQ for RAW Ethernet functions - RDMA/mlx5: Create an indirect flow table for steering anchor - RDMA/cma: Always set static rate to 0 for RoCE - IB/uverbs: Fix to consider event queue closing also upon non-blocking mode - RDMA/mlx5: Fix affinity assignment - IB/isert: Fix dead lock in ib_isert - IB/isert: Fix possible list corruption in CMA handler - IB/isert: Fix incorrect release of isert connection - net: ethtool: correct MAX attribute value for stats - ipvlan: fix bound dev checking for IPv6 l3s mode - sctp: fix an error code in sctp_sf_eat_auth() - igc: Clean the TX buffer and TX descriptor ring - igc: Fix possible system crash when loading module - igb: fix nvm.ops.read() error handling - net: phylink: report correct max speed for QUSGMII - net: phylink: use a dedicated helper to parse usgmii control word - drm/nouveau: don't detect DSM for non-NVIDIA device - [arm64] drm/bridge: ti-sn65dsi86: Avoid possible buffer overflow - drm/nouveau/dp: check for NULL nv_connector->native_mode - drm/nouveau: add nv_encoder pointer check for NULL - sched: add new attr TCA_EXT_WARN_MSG to report tc extact message - net/sched: Refactor qdisc_graft() for ingress and clsact Qdiscs - net/sched: qdisc_destroy() old ingress and clsact Qdiscs before grafting - cifs: fix lease break oops in xfstest generic/098 - ext4: drop the call to ext4_error() from ext4_get_group_info() - net/sched: cls_api: Fix lockup on flushing explicitly created chain - [arm64] net: dsa: felix: fix taprio guard band overflow at 10Mbps with jumbo frames - net: macsec: fix double free of percpu stats - sfc: fix XDP queues mode with legacy IRQ - dm: don't lock fs when the map is NULL during suspend or resume - net: tipc: resize nlattr array to correct size - afs: Fix vlserver probe RTT handling - rcu/kvfree: Avoid freeing new kfree_rcu() memory after old grace period - drm/amdgpu: Don't set struct drm_driver.output_poll_changed - net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy - Revert "net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy" - net/sched: act_api: add specific EXT_WARN_MSG for tc action - neighbour: delete neigh_lookup_nodev as not used - scsi: target: core: Fix error path in target_setup_session() - [mips*] Move '-Wa,-msoft-float' check from as-option to cc-option - [mips*] Prefer cc-option for additions to cflags - kbuild: Update assembler calls to use proper flags and language target https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.36 - drm/amd/display: Use dc_update_planes_and_stream - drm/amd/display: Add wrapper to call planes and stream update - drm/amd/display: fix the system hang while disable PSR - [arm64] tty: serial: fsl_lpuart: make rx_watermark configurable for different platforms - [arm64] tty: serial: fsl_lpuart: reduce RX watermark to 0 on LS1028A - ata: libata-scsi: Avoid deadlock on rescan after device resume - mm: Fix copy_from_user_nofault(). (Closes: #1033398) - tpm, tpm_tis: Claim locality in interrupt handler - tpm_crb: Add support for CRB devices based on Pluton - ksmbd: validate command payload size - ksmbd: fix out-of-bound read in smb2_write - ksmbd: validate session id and tree id in the compound request - tick/common: Align tick period during sched_timer setup (Closes: #1038754) - writeback: fix dereferencing NULL mapping->host on writeback_page_template - nilfs2: fix buffer corruption due to concurrent device reads - [x86] ACPI: sleep: Avoid breaking S3 wakeup due to might_sleep() - KVM: Avoid illegal stage2 mapping on invalid memory slot - Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails - Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs - PCI: hv: Fix a race condition bug in hv_pci_query_relations() - Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally" - PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev - PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic - PCI: hv: Add a per-bus mutex state_lock - io_uring/net: clear msg_controllen on partial sendmsg retry - io_uring/net: disable partial retries for recvmsg with cmsg - mptcp: handle correctly disconnect() failures - mptcp: fix possible divide by zero in recvmsg() - mptcp: fix possible list corruption on passive MPJ - mptcp: consolidate fallback and non fallback state machine - cgroup: Do not corrupt task iteration when rebinding subsystem - cgroup,freezer: hold cpu_hotplug_lock before freezer_mutex in freezer_css_{online,offline}() - [arm64] mmc: sdhci-msm: Disable broken 64-bit DMA on MSM8916 - [arm64] mmc: meson-gx: remove redundant mmc_request_done() call from irq context - [arm64,armhf] mmc: mmci: stm32: fix max busy timeout calculation - [arm64,armhf] mmc: bcm2835: fix deferred probing - [arm64,armhf] mmc: sunxi: fix deferred probing - bpf: ensure main program has an extable - wifi: iwlwifi: pcie: Handle SO-F device for PCI id 0x7AF0 - io_uring/poll: serialize poll linked timer start with poll removal - nilfs2: prevent general protection fault in nilfs_clear_dirty_page() - [x86] mm: Avoid using set_pgd() outside of real PGD pages - memfd: check for non-NULL file_seals in memfd_create() syscall - [arm64] mmc: meson-gx: fix deferred probing - ieee802154: hwsim: Fix possible memory leaks - xfrm: Treat already-verified secpath entries as optional - xfrm: interface: rename xfrm_interface.c to xfrm_interface_core.c - xfrm: Ensure policies always checked on XFRM-I input path - [arm64] KVM: arm64: PMU: Restore the host's PMUSERENR_EL0 - bpf: track immediate values written to stack by BPF_ST instruction - bpf: Fix verifier id tracking of scalars on spill - xfrm: fix inbound ipv4/udp/esp packets to UDPv6 dualstack sockets - bpf: Fix a bpf_jit_dump issue for x86_64 with sysctl bpf_jit_enable. - xfrm: Linearize the skb after offloading if needed. - net/mlx5: DR, Fix wrong action data allocation in decap action - sfc: use budget for TX completions - [armel,armhf] mmc: mvsdio: fix deferred probing - [armhf] mmc: omap: fix deferred probing - [armhf] mmc: omap_hsmmc: fix deferred probing - mmc: sdhci-acpi: fix deferred probing - ipvs: align inner_mac_header for encapsulation - be2net: Extend xmit workaround to BE3 chip - netfilter: nf_tables: fix chain binding transaction logic - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: drop map element references from preparation phase - netfilter: nft_set_pipapo: .walk does not deal with generations - netfilter: nf_tables: disallow element updates of bound anonymous sets - netfilter: nf_tables: reject unbound anonymous set before commit phase - netfilter: nf_tables: reject unbound chain set before commit phase - netfilter: nf_tables: disallow updates of anonymous sets - netfilter: nfnetlink_osf: fix module autoload - Revert "net: phy: dp83867: perform soft reset and retain established link" - bpf/btf: Accept function names that contain dots - bpf: Force kprobe multi expected_attach_type for kprobe_multi link - io_uring/net: use the correct msghdr union member in io_sendmsg_copy_hdr - sch_netem: acquire qdisc lock in netem_change() - revert "net: align SO_RCVMARK required privileges with SO_MARK" - [arm64] dts: rockchip: fix nEXTRST on SOQuartz - gpiolib: Fix GPIO chip IRQ initialization restriction - gpiolib: Fix irq_domain resource tracking for gpiochip_irqchip_add_domain() - scsi: target: iscsi: Prevent login threads from racing between each other - HID: wacom: Add error check to wacom_parse_and_register() - smb3: missing null check in SMB2_change_notify - media: cec: core: disable adapter in cec_devnode_unregister - media: cec: core: don't set last_initiator if tx in progress - nfcsim.c: Fix error checking for debugfs_create_dir - btrfs: fix an uninitialized variable warning in btrfs_log_inode - [i386] usb: gadget: udc: fix NULL dereference in remove() - nvme: double KA polling frequency to avoid KATO with TBKAS on - nvme: check IO start time when deciding to defer KA - nvme: improve handling of long keep alives - [x86] Input: soc_button_array - add invalid acpi_index DMI quirk handling - [s390x] cio: unregister device when the only path is gone - [arm*] ASoC: simple-card: Add missing of_node_put() in case of error - soundwire: dmi-quirks: add new mapping for HP Spectre x360 - soundwire: qcom: add proper error paths in qcom_swrm_startup() - [x86] ASoC: nau8824: Add quirk to active-high jack-detect - [x86] ASoC: amd: yc: Add Thinkpad Neo14 to quirks list for acp6x - gfs2: Don't get stuck writing page onto itself under direct I/O - [arm64] ASoC: fsl_sai: Enable BCI bit if SAI works on synchronous mode with BYP asserted - ALSA: hda/realtek: Add "Intel Reference board" and "NUC 13" SSID in the ALC256 - i2c: mchp-pci1xxxx: Avoid cast to incompatible function type - null_blk: Fix: memory release when memory_backed=1 - drm/radeon: fix race condition UAF in radeon_gem_set_domain_ioctl - vhost_net: revert upend_idx only on retriable error - [arm64] KVM: arm64: Restore GICv2-on-GICv3 functionality - [x86] apic: Fix kernel panic when booting with intremap=off and x2apic_phys - [arm64] i2c: imx-lpi2c: fix type char overflow issue when calculating the clock cycle - smb: move client and server files to common directory fs/smb https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.37 - mm/mmap: Fix error path in do_vmi_align_munmap() - mm/mmap: Fix error return in do_vmi_align_munmap() - mptcp: ensure listener is unhashed before updating the sk status - mm, hwpoison: try to recover from copy-on write faults - mm, hwpoison: when copy-on-write hits poison, take page offline - [x86] microcode/AMD: Load late on both threads too - [x86] smp: Make stop_other_cpus() more robust - [x86] smp: Dont access non-existing CPUID leaf - [x86] smp: Remove pointless wmb()s from native_stop_other_cpus() - [x86] smp: Use dedicated cache-line for mwait_play_dead() - [x86] smp: Cure kexec() vs. mwait_play_dead() breakage - can: isotp: isotp_sendmsg(): fix return error fix on TX path - maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() - mm: introduce new 'lock_mm_and_find_vma()' page fault helper - mm: make the page fault mmap locking killable - [arm64] mm: Convert to using lock_mm_and_find_vma() - [powerpc*] mm: Convert to using lock_mm_and_find_vma() - [mips*] mm: Convert to using lock_mm_and_find_vma() - [armhf] mm: Convert to using lock_mm_and_find_vma() - mm/fault: convert remaining simple cases to lock_mm_and_find_vma() - [powerpc*] mm: convert coprocessor fault to lock_mm_and_find_vma() - mm: make find_extend_vma() fail if write lock not held - execve: expand new process stack manually ahead of time - mm: always expand the stack with the mmap write lock held - fbdev: fix potential OOB read in fast_imageblit() - HID: hidraw: fix data race on device refcount - HID: wacom: Use ktime_t rather than int when dealing with timestamps - HID: logitech-hidpp: add HIDPP_QUIRK_DELAYED_INIT for the T651. (Closes: #1038271) . [ Salvatore Bonaccorso ] * d/salsa-ci.yml: Update for bookworm: Set RELEASE to bookworm * d/rules.real: Fix typo in setup_image target. * [amd64,arm64] drivers/virtio: Enable VIRTIO_MEM as module (Closes: #1038665) * Bump ABI to 10 * [rt] Update to 6.1.33-rt11 * Revert "drm/amd/display: edp do not add non-edid timings" . [ Cyril Brulebois ] * udeb: Add r8188eu to nic-wireless-modules (Closes: #1035824) . [ Ben Hutchings ] * Add pkg.linux.mintools profile for building minimal userland tools * d/b/test-patches: Build linux-{kbuild,bootwrapper} packages (Closes: #871216, #1035359) linux-signed-i386 (6.1.38+1) bookworm; urgency=medium . * Sign kernel from linux 6.1.38-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.38 - drm/amd/display: Remove optimization for VRR updates - drm/amd/display: Do not update DRR while BW optimizations pending - PCI/ACPI: Validate acpi_pci_set_power_state() parameter - PCI/ACPI: Call _REG when transitioning D-states - execve: always mark stack as growing down during early stack setup - perf symbols: Symbol lookup with kcore can fail if multiple segments match stext - scripts/tags.sh: Resolve gtags empty index generation - drm/amdgpu: Validate VM ioctl flags. - drm/amd/display: Ensure vmin and vmax adjust for DCE . [ Salvatore Bonaccorso ] * drm: use mgr->dev in drm_dbg_kms in drm_dp_add_payload_part2 * mm/mmap: Fix VM_LOCKED check in do_vmi_align_munmap() * netfilter: nf_tables: do not ignore genmask when looking up chain by id (CVE-2023-31248) * netfilter: nf_tables: prevent OOB access in nft_byteorder_eval (CVE-2023-35001) linux-signed-i386 (6.1.37+1) bookworm-security; urgency=high . * Sign kernel from linux 6.1.37-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.28 - [x86] ASOC: Intel: sof_sdw: add quirk for Intel 'Rooks County' NUC M15 - [x86] ASoC: Intel: soc-acpi: add table for Intel 'Rooks County' NUC M15 - ASoC: soc-pcm: fix hw->formats cleared by soc_pcm_hw_init() for dpcm - [x86] hyperv: Block root partition functionality in a Confidential VM - [x86] ASoC: amd: yc: Add DMI entries to support Victus by HP Laptop 16-e1xxx (8A22) - [x86] ASoC: Intel: bytcr_rt5640: Add quirk for the Acer Iconia One 7 B1-750 - [x86] ASoC: da7213.c: add missing pm_runtime_disable() - scsi: mpi3mr: Handle soft reset in progress fault code (0xF002) - net: sfp: add quirk enabling 2500Base-x for HG MXPD-483II - [x86] platform/x86: thinkpad_acpi: Add missing T14s Gen1 type to s2idle quirk list - wifi: ath11k: reduce the MHI timeout to 20s - tracing: Error if a trace event has an array for a __field() - [x86] cpu: Add model number for Intel Arrow Lake processor - wireguard: timers: cast enum limits members to int in prints - wifi: mt76: mt7921e: Set memory space enable in PCI_COMMAND if unset - [arm64] Always load shadow stack pointer directly from the task struct - [arm64] Stash shadow stack pointer in the task struct on interrupt - PCI: pciehp: Fix AB-BA deadlock between reset_lock and device_lock - [arm64] PCI: qcom: Fix the incorrect register usage in v2.7.0 config - [arm64] phy: qcom-qmp-pcie: sc8180x PCIe PHY has 2 lanes - [arm64,armhf] usb: dwc3: gadget: Stall and restart EP0 if host is unresponsive - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on probe errors - [arm64,armhf] USB: dwc3: fix runtime pm imbalance on unbind - [x86] hwmon: (k10temp) Check range scale when CUR_TEMP register is read-write - hwmon: (adt7475) Use device_property APIs when configuring polarity - tpm: Add !tpm_amd_is_rng_defective() to the hwrng_unregister() call site - posix-cpu-timers: Implement the missing timer_wait_running callback - blk-stat: fix QUEUE_FLAG_STATS clear - blk-crypto: don't use struct request_queue for public interfaces - blk-crypto: add a blk_crypto_config_supported_natively helper - blk-crypto: move internal only declarations to blk-crypto-internal.h - blk-crypto: Add a missing include directive - blk-mq: release crypto keyslot before reporting I/O complete - blk-crypto: make blk_crypto_evict_key() return void - blk-crypto: make blk_crypto_evict_key() more robust - tty: Prevent writing chars during tcsetattr TCSADRAIN/FLUSH - xhci: fix debugfs register accesses while suspended - serial: fix TIOCSRS485 locking - serial: 8250: Fix serial8250_tx_empty() race with DMA Tx - tick/nohz: Fix cpu_is_hotpluggable() by checking with nohz subsystem - fs: fix sysctls.c built - [mips*] fw: Allow firmware to pass a empty env - ipmi:ssif: Add send_retries increment - ipmi: fix SSIF not responding under certain cond. - wifi: mt76: add missing locking to protect against concurrent rx/status calls - [arm64,armhf] pwm: meson: Fix axg ao mux parents - [arm64,armhf] pwm: meson: Fix g12a ao clk81 name - soundwire: qcom: correct setting ignore bit on v1.5.1 - ring-buffer: Ensure proper resetting of atomic variables in ring_buffer_reset_online_cpus - ring-buffer: Sync IRQ works before buffer destruction - crypto: api - Demote BUG_ON() in crypto_unregister_alg() to a WARN_ON() - [arm64] crypto: safexcel - Cleanup ring IRQ workqueues on load failure - [x86] crypto: ccp - Don't initialize CCP for PSP 0x1649 - rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed - reiserfs: Add security prefix to xattr name in reiserfs_security_write() - [x86] KVM: nVMX: Emulate NOPs in L2, and PAUSE if it's not intercepted - [arm64] KVM: arm64: Avoid vcpu->mutex v. kvm->lock inversion in CPU_ON - [arm64] KVM: arm64: Avoid lock inversion when setting the VM register width - [arm64] KVM: arm64: Use config_lock to protect data ordered against KVM_RUN - [arm64] KVM: arm64: Use config_lock to protect vgic state - [arm64] KVM: arm64: vgic: Don't acquire its_lock before config_lock - relayfs: fix out-of-bounds access in relay_file_read (CVE-2023-3268) - drm/amd/display: Remove stutter only configurations - drm/amd/display: limit timing for single dimm memory - drm/amd/display: fix PSR-SU/DSC interoperability support - drm/amd/display: fix a divided-by-zero error - ksmbd: fix racy issue under cocurrent smb2 tree disconnect (CVE-2023-32254) - ksmbd: call rcu_barrier() in ksmbd_server_exit() - ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem() - ksmbd: fix memleak in session setup - ksmbd: not allow guest user on multichannel - ksmbd: fix deadlock in ksmbd_find_crypto_ctx() - [x86] ACPI: video: Remove acpi_backlight=video quirk for Lenovo ThinkPad W530 - [arm64,armhf] i2c: omap: Fix standard mode false ACK readings - tracing: Fix permissions for the buffer_percent file - swsmu/amdgpu_smu: Fix the wrong if-condition - drm/amd/pm: re-enable the gfx imu when smu resume - [amd64] iommu/amd: Fix "Guest Virtual APIC Table Root Pointer" configuration in IRTE - Revert "ubifs: dirty_cow_znode: Fix memleak in error handling path" - ubifs: Fix memleak when insert_old_idx() failed - ubi: Fix return value overwrite issue in try_write_vid_and_data() - ubifs: Free memory for tmpfile name - ubifs: Fix memory leak in do_rename - ceph: fix potential use-after-free bug when trimming caps - xfs: don't consider future format versions valid - cxl/hdm: Fail upon detecting 0-sized decoders - bus: mhi: host: Remove duplicate ee check for syserr - bus: mhi: host: Use mhi_tryset_pm_state() for setting fw error state - bus: mhi: host: Range check CHDBOFF and ERDBOFF - rcu: Fix missing TICK_DEP_MASK_RCU_EXP dependency check - tpm, tpm_tis: Do not skip reset of original interrupt vector - tpm, tpm_tis: Claim locality before writing TPM_INT_ENABLE register - tpm, tpm_tis: Disable interrupts if tpm_tis_probe_irq() failed - tpm, tpm_tis: Claim locality before writing interrupt registers - tpm, tpm: Implement usage counter for locality - tpm, tpm_tis: Claim locality when interrupts are reenabled on resume - erofs: stop parsing non-compact HEAD index if clusterofs is invalid - erofs: initialize packed inode after root inode is assigned - erofs: fix potential overflow calculating xattr_isize - [arm64,armhf] drm/rockchip: Drop unbalanced obj unref - [x86] drm/i915/dg2: Drop one PCI ID - drm/vgem: add missing mutex_destroy - drm/probe-helper: Cancel previous job before starting new one - drm/amdgpu: register a vga_switcheroo client for MacBooks with apple-gmux - [arm64] dts: ti: k3-am62-main: Fix GPIO numbers in DT - [arm64] drm/msm/disp/dpu: check for crtc enable rather than crtc active to release shared resources - [amd64] EDAC/skx: Fix overflows on the DRAM row address mapping arrays - regulator: core: Shorten off-on-delay-us for always-on/boot-on by time since booted - [arm64] dts: ti: k3-am62a7-sk: Fix DDR size to full 4GB - [arm64] dts: qcom: msm8998: Fix stm-stimulus-base reg name - [arm64] dts: qcom: sdm845: correct dynamic power coefficients - [x86] MCE/AMD: Use an u64 for bank_map - [arm64] firmware: qcom_scm: Clear download bit during reboot - [arm64] drm/bridge: adv7533: Fix adv7533_mode_valid for adv7533 and adv7535 - [arm64] drm/msm/adreno: drop bogus pm_runtime_set_active() - [arm64] drm: msm: adreno: Disable preemption on Adreno 510 - [amd64] virt/coco/sev-guest: Double-buffer messages - [arm64] dts: qcom: sm8350-microsoft-surface: fix USB dual-role mode property - [x86] ACPI: processor: Fix evaluating _PDC method when running as Xen dom0 - [arm64] mmc: sdhci-of-esdhc: fix quirk to ignore command inhibit for data - [armhf] dts: gta04: fix excess dma channel usage - [arm64] firmware: arm_scmi: Fix xfers allocation on Rx channel - [arm64] perf/arm-cmn: Move overlapping wp_combine field - [armhf] dts: stm32: fix spi1 pin assignment on stm32mp15 - [arm64] cpufreq: qcom-cpufreq-hw: Revert adding cpufreq qos - [arm64,armhf] drm/lima/lima_drv: Add missing unwind goto in lima_pdev_probe() - [arm64,armhf] gpu: host1x: Fix potential double free if IOMMU is disabled - [arm64,armhf] gpu: host1x: Fix memory leak of device names - drm/ttm: optimize pool allocations a bit v2 - drm/ttm/pool: Fix ttm_pool_alloc error path - regulator: core: Consistently set mutex_owner when using ww_mutex_lock_slow() - regulator: core: Avoid lockdep reports when resolving supplies - [x86] apic: Fix atomic update of offset in reserve_eilvt_offset() - [arm64] dts: qcom: msm8994-angler: Fix cont_splash_mem mapping - [arm64] dts: qcom: msm8994-angler: removed clash with smem_region - [arm64,armhf] media: cedrus: fix use after free bug in cedrus_remove due to race condition (CVE-2023-35826) - [arm64] media: rkvdec: fix use after free bug in rkvdec_remove (CVE-2023-35829) - [amd64] platform/x86/amd: pmc: Don't try to read SMU version on Picasso - [amd64] platform/x86/amd: pmc: Hide SMU version and program attributes for Picasso - [amd64] platform/x86/amd: pmc: Don't dump data after resume from s0i3 on picasso - [amd64] platform/x86/amd: pmc: Move idlemask check into `amd_pmc_idlemask_read` - [amd64] platform/x86/amd: pmc: Utilize SMN index 0 for driver probe - [amd64] platform/x86/amd: pmc: Move out of BIOS SMN pair for STB init - media: dm1105: Fix use after free bug in dm1105_remove due to race condition (CVE-2023-35824) - media: saa7134: fix use after free bug in saa7134_finidev due to race condition (CVE-2023-35823) - media: v4l: async: Return async sub-devices to subnotifier list - drm/amd/display: Fix potential null dereference - [arm64,armhf] media: rc: gpio-ir-recv: Fix support for wake-up - [arm64] media: venus: dec: Fix handling of the start cmd - [arm64] media: venus: dec: Fix capture formats enumeration order - [armhf] regulator: stm32-pwr: fix of_iomap leak - [x86] ioapic: Don't return 0 from arch_dynirq_lower_bound() - [arm64] kgdb: Set PSTATE.SS to 1 to re-enable single-step - [arm64] perf/arm-cmn: Fix port detection for CMN-700 - [x86] drm/i915: Make intel_get_crtc_new_encoder() less oopsy - tick/common: Align tick period with the HZ tick. - ACPI: bus: Ensure that notify handlers are not running after removal - cpufreq: use correct unit when verify cur freq - [arm64] rpmsg: glink: Propagate TX failures in intentless mode as well - platform/chrome: cros_typec_switch: Add missing fwnode_handle_put() - wifi: ath6kl: minor fix for allocation size - wifi: ath9k: hif_usb: fix memory leak of remain_skbs - wifi: ath11k: Use platform_get_irq() to get the interrupt - wifi: ath5k: Use platform_get_irq() to get the interrupt - wifi: ath5k: fix an off by one check in ath5k_eeprom_read_freq_list() - wifi: ath11k: fix SAC bug on peer addition with sta band migration - wifi: brcmfmac: support CQM RSSI notification with older firmware - wifi: ath6kl: reduce WARN to dev_dbg() in callback - tools: bpftool: Remove invalid \' json escape - wifi: rtw88: mac: Return the original error from rtw_pwr_seq_parser() - wifi: rtw88: mac: Return the original error from rtw_mac_power_switch() - bpf: take into account liveness when propagating precision - bpf: fix precision propagation verbose logging - [x86] crypto: qat - fix concurrency issue when device state changes - scm: fix MSG_CTRUNC setting condition for SO_PASSSEC - wifi: ath11k: fix deinitialization of firmware resources - bpf: Remove misleading spec_v1 check on var-offset stack read - net: pcs: xpcs: remove double-read of link state when using AN - vlan: partially enable SIOCSHWTSTAMP in container - net/packet: annotate accesses to po->xmit - net/packet: convert po->origdev to an atomic flag - net/packet: convert po->auxdata to an atomic flag - libbpf: Fix ld_imm64 copy logic for ksym in light skeleton. - netfilter: keep conntrack reference until IPsecv6 policy checks are done - bpf: Fix __reg_bound_offset 64->32 var_off subreg propagation - scsi: target: core: Change the way target_xcopy_do_work() sets restiction on max I/O - scsi: target: Move sess cmd counter to new struct - scsi: target: Move cmd counter allocation - scsi: target: Pass in cmd counter to use during cmd setup - scsi: target: iscsit: isert: Alloc per conn cmd counter - scsi: target: iscsit: Stop/wait on cmds during conn close - scsi: target: Fix multiple LUN_RESET handling - scsi: target: iscsit: Fix TAS handling during conn cleanup - scsi: megaraid: Fix mega_cmd_done() CMDID_INT_CMDS - net: sunhme: Fix uninitialized return code - f2fs: handle dqget error in f2fs_transfer_project_quota() - f2fs: fix uninitialized skipped_gc_rwsem - f2fs: apply zone capacity to all zone type - f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() - f2fs: fix scheduling while atomic in decompression path - [arm64,armhf] crypto: caam - Clear some memory in instantiate_rng - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_rfreg() - wifi: rtlwifi: fix incorrect error codes in rtl_debugfs_set_write_reg() - scsi: libsas: Add sas_ata_device_link_abort() - [arm64] scsi: hisi_sas: Handle NCQ error when IPTT is valid - wifi: rt2x00: Fix memory leak when handling surveys - f2fs: fix iostat lock protection - net: qrtr: correct types of trace event parameters - bpftool: Fix bug for long instructions in program CFG dumps - crypto: drbg - Only fail when jent is unavailable in FIPS mode - xsk: Fix unaligned descriptor validation - f2fs: fix to avoid use-after-free for cached IPU bio - wifi: iwlwifi: fix duplicate entry in iwl_dev_info_table - bpf/btf: Fix is_int_ptr() - scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: rework optional clock handling - [arm64,armhf] net: ethernet: stmmac: dwmac-rk: fix optional phy regulator handling - wifi: ath11k: fix writing to unintended memory region - bpf, sockmap: fix deadlocks in the sockhash and sockmap - nvmet: fix error handling in nvmet_execute_identify_cns_cs_ns() - nvmet: fix Identify Namespace handling - nvmet: fix Identify Controller handling - nvmet: fix Identify Active Namespace ID list handling - nvmet: fix I/O Command Set specific Identify Controller - nvme: fix async event trace event - blk-mq: don't plug for head insertions in blk_execute_rq_nowait - wifi: iwlwifi: debug: fix crash in __iwl_err() - wifi: iwlwifi: trans: don't trigger d3 interrupt twice - wifi: iwlwifi: mvm: don't set CHECKSUM_COMPLETE for unsupported protocols - bpf, sockmap: Revert buggy deadlock fix in the sockhash and sockmap - f2fs: fix to check return value of f2fs_do_truncate_blocks() - f2fs: fix to check return value of inc_valid_block_count() - md/raid10: fix task hung in raid10d - md/raid10: fix leak of 'r10bio->remaining' for recovery - md/raid10: fix memleak for 'conf->bio_split' - md/raid10: fix memleak of md thread - md/raid10: don't call bio_start_io_acct twice for bio which experienced read error - wifi: iwlwifi: mvm: don't drop unencrypted MCAST frames - wifi: iwlwifi: yoyo: skip dump correctly on hw error - wifi: iwlwifi: yoyo: Fix possible division by zero - wifi: iwlwifi: mvm: initialize seq variable - wifi: iwlwifi: fw: move memset before early return - jdb2: Don't refuse invalidation of already invalidated buffers - io_uring/rsrc: use nospec'ed indexes - wifi: iwlwifi: make the loop for card preparation effective - wifi: mt76: handle failure of vzalloc in mt7615_coredump_work - wifi: mt76: add flexible polling wait-interval support - wifi: mt76: mt7921e: fix probe timeout after reboot - wifi: mt76: fix 6GHz high channel not be scanned - mt76: mt7921: fix kernel panic by accessing unallocated eeprom.data - wifi: mt76: mt7921: fix missing unwind goto in `mt7921u_probe` - wifi: mt76: mt7921e: improve reliability of dma reset - wifi: mt76: mt7921e: stop chip reset worker in unregister hook - wifi: mt76: connac: fix txd multicast rate setting - wifi: iwlwifi: mvm: check firmware response size - netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert() - netfilter: conntrack: fix wrong ct->timeout value - wifi: iwlwifi: fw: fix memory leak in debugfs - ixgbe: Allow flow hash to be set via ethtool - ixgbe: Enable setting RSS table to default values - net/mlx5e: Don't clone flow post action attributes second time - net/mlx5: E-switch, Create per vport table based on devlink encap mode - net/mlx5: E-switch, Don't destroy indirect table in split rule - net/mlx5e: Fix error flow in representor failing to add vport rx rule - net/mlx5: Suspend auxiliary devices only in case of PCI device suspend - net/mlx5: Use recovery timeout on sync reset flow - net/mlx5e: Nullify table pointer when failing to create - net: stmmac:fix system hang when setting up tag_8021q VLAN for DSA ports - bpf: Fix race between btf_put and btf_idr walk. - bpf: Don't EFAULT for getsockopt with optval=NULL - netfilter: nf_tables: don't write table validation state without mutex - net/sched: sch_fq: fix integer overflow of "credit" - ipv4: Fix potential uninit variable access bug in __ip_make_skb() - Revert "Bluetooth: btsdio: fix use after free bug in btsdio_remove due to unfinished work" - netlink: Use copy_to_user() for optval in netlink_getsockopt(). - [x86] net: amd: Fix link leak when verifying config failed - tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp. - [x86] ASoC: cs35l41: Only disable internal boost - drivers: staging: rtl8723bs: Fix locking in _rtw_join_timeout_handler() - drivers: staging: rtl8723bs: Fix locking in rtw_scan_timeout_handler() - [arm64] usb: host: xhci-rcar: remove leftover quirk handling - [arm64,armhf] usb: dwc3: gadget: Change condition for processing suspend event - [armhf] serial: stm32: Re-assert RTS/DE GPIO in RS485 mode only if more data are transmitted - iio: light: max44009: add missing OF device matching - [arm64,armhf] spi: imx: Don't skip cleanup in remove's error path - [x86] ASoC: soc-compress: Inherit atomicity from DAI link for Compress FE - [arm64,armhf] PCI: imx6: Install the fault handler only on compatible match - ASoC: es8316: Handle optional IRQ assignment - [arm64] spi: qup: Don't skip cleanup in remove's error path - [x86] vmci_host: fix a race condition in vmci_host_poll() causing GPF - of: Fix modalias string generation - [amd64] HID: amd_sfh: Correct the structure fields - [amd64] HID: amd_sfh: Correct the sensor enable and disable command - [amd64] HID: amd_sfh: Fix illuminance value - [amd64] HID: amd_sfh: Add support for shutdown operation - [amd64] HID: amd_sfh: Correct the stop all command - [amd64] HID: amd_sfh: Increase sensor command timeout for SFH1.1 - [amd64] HID: amd_sfh: Handle "no sensors" enabled for SFH1.1 - cacheinfo: Check sib_leaf in cache_leaves_are_shared() - [arm64] coresight: etm_pmu: Set the module field - PCI/PM: Extend D3hot delay for NVIDIA HDA controllers - spi: cadence-quadspi: fix suspend-resume implementations - [arm64,armhf] usb: chipidea: fix missing goto in `ci_hdrc_probe` - [arm64] tty: serial: fsl_lpuart: adjust buffer length to the intended size - serial: 8250: Add missing wakeup event reporting - spi: cadence-quadspi: use macro DEFINE_SIMPLE_DEV_PM_OPS - [x86] staging: rtl8192e: Fix W_DISABLE# does not work after stop/start - [arm64] spmi: Add a check for remove callback when removing a SPMI driver - virtio_ring: don't update event idx on get_buf - [powerpc*] rtas: use memmove for potentially overlapping buffer copy - sched/fair: Fix inaccurate tally of ttwu_move_affine - perf/core: Fix hardlockup failure caused by perf throttle - Revert "objtool: Support addition to set CFA base" - sched/rt: Fix bad task migration for rt tasks - tracing/user_events: Ensure write index cannot be negative - [amd64] IB/hifi1: add a null check of kzalloc_node in hfi1_ipoib_txreq_init - [amd64] RDMA/rdmavt: Delete unnecessary NULL check - workqueue: Fix hung time report of worker pools - [armhf] rtc: omap: include header for omap_rtc_power_off_program prototype - RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() - [arm64,armhf] rtc: meson-vrtc: Use ktime_get_real_ts64() to get the current time - clk: add missing of_node_put() in "assigned-clocks" property parsing - [arm64] power: supply: rk817: Fix low SOC bugs - RDMA/cm: Trace icm_send_rej event before the cm state is reset - RDMA/srpt: Add a check for valid 'mad_agent' pointer - [amd64] IB/hfi1: Fix SDMA mmu_rb_node not being evicted in LRU order - [amd64] IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests - [arm64,armhf] clk: imx: fracn-gppll: fix the rate table - [arm64,armhf] clk: imx: fracn-gppll: disable hardware select control - NFSv4.1: Always send a RECLAIM_COMPLETE after establishing lease - [amd64] iommu/amd: Set page size bitmap during V2 domain allocation - [arm64] Input: raspberrypi-ts - fix refcount leak in rpi_ts_probe - swiotlb: relocate PageHighMem test away from rmem_swiotlb_setup - swiotlb: fix debugfs reporting of reserved memory pools - RDMA/mlx5: Check pcie_relaxed_ordering_enabled() in UMR - RDMA/mlx5: Fix flow counter query via DEVX - SUNRPC: remove the maximum number of retries in call_bind_status - RDMA/mlx5: Use correct device num_ports when modify DC - timekeeping: Fix references to nonexistent ktime_get_fast_ns() - SMB3: Add missing locks to protect deferred close file list - SMB3: Close deferred file handles in case of handle lease break - ext4: fix i_disksize exceeding i_size problem in paritally written case - ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline - [arm64] dmaengine: mv_xor_v2: Fix an error code. - [armhf] leds: tca6507: Fix error handling of using fwnode_property_read_string - soundwire: cadence: rename sdw_cdns_dai_dma_data as sdw_cdns_dai_runtime - [x86] soundwire: intel: don't save hw_params for use in prepare - [arm64,armhf] phy: tegra: xusb: Add missing tegra_xusb_port_unregister for usb2_port and ulpi_port - [arm64,armhf] pinctrl-bcm2835.c: fix race condition when setting gpio dir - [x86] ACPI: PM: Do not turn of unused power resources on the Toshiba Click Mini - PM: hibernate: Turn snapshot_test into global variable - PM: hibernate: Do not get block device exclusively in test_resume mode - afs: Fix updating of i_size with dv jump from server - afs: Fix getattr to report server i_size on dirs, not local size - afs: Avoid endless loop if file is larger than expected - ALSA: usb-audio: Add quirk for Pioneer DDJ-800 - [x86] ALSA: hda/realtek: Add quirk for ThinkPad P1 Gen 6 - [x86] ALSA: hda/realtek: Add quirk for ASUS UM3402YAR using CS35L41 - [x86] ALSA: hda/realtek: support HP Pavilion Aero 13-be0xxx Mute LED - [x86] ALSA: hda/realtek: Fix mute and micmute LEDs for an HP laptop - nilfs2: do not write dirty data after degenerating to read-only - nilfs2: fix infinite loop in nilfs_mdt_get_block() - mm: do not reclaim private data from pinned page - drbd: correctly submit flush bio on barrier - md/raid10: fix null-ptr-deref in raid10_sync_request - md/raid5: Improve performance for sequential IO - mtd: core: provide unique name for nvmem device, take two - mtd: core: fix nvmem error reporting - mtd: core: fix error path for nvmem provider - mtd: spi-nor: core: Update flash's current address mode when changing address mode - [arm64] mailbox: zynqmp: Fix IPI isr handling - [arm64] mailbox: zynqmp: Fix typo in IPI documentation - wifi: rtl8xxxu: RTL8192EU always needs full init - wifi: rtw89: fix potential race condition between napi_init and napi_enable - [arm64] clk: rockchip: rk3399: allow clk_cifout to force clk_cifout_src to reparent - btrfs: scrub: reject unsupported scrub flags - [s390x] dasd: fix hanging blockdevice after request requeue - mm/mempolicy: correctly update prev when policy is equal on mbind - dm verity: fix error handling for check_at_most_once on FEC - dm integrity: call kmem_cache_destroy() in dm_integrity_init() error path - dm flakey: fix a crash with invalid table line - dm ioctl: fix nested locking in table_clear() to remove deadlock concern (CVE-2023-2269) - dm: don't lock fs when the map is NULL in process of resume - blk-iocost: avoid 64-bit division in ioc_timer_fn - cifs: fix potential use-after-free bugs in TCP_Server_Info::hostname - cifs: protect session status check in smb2_reconnect() - [x86] thunderbolt: Use correct type in tb_port_is_clx_enabled() prototype - wifi: ath11k: synchronize ath11k_mac_he_gi_to_nl80211_he_gi()'s return type - [x86] perf auxtrace: Fix address filter entire kernel size - [x86] perf intel-pt: Fix CYC timestamps after standalone CBR - i40e: Remove unused i40e status codes - i40e: Remove string printing for i40e_status - i40e: use int for i40e_status - scsi: libsas: Grab the ATA port lock in sas_ata_device_link_abort() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.29 - [arm64,armhf] USB: dwc3: gadget: drop dead hibernation code - [arm64,armhf] usb: dwc3: gadget: Execute gadget stop after halting the controller - drm/vmwgfx: Remove explicit and broken vblank handling - drm/vmwgfx: Fix Legacy Display Unit atomic drm support - [amd64] crypto: ccp - Clear PSP interrupt status register before calling handler - [x86] perf/x86/core: Zero @lbr instead of returning -1 in x86_perf_get_lbr() stub - [x86] KVM: x86: Track supported PERF_CAPABILITIES in kvm_caps - [x86] KVM: x86/pmu: Disallow legacy LBRs if architectural LBRs are available - mtd: spi-nor: spansion: Remove NO_SFDP_FLAGS from s28hs512t info - mtd: spi-nor: add SFDP fixups for Quad Page Program - mtd: spi-nor: Add a RWW flag - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s28hx SEMPER flash - [arm64] mailbox: zynq: Switch to flexible array to simplify code - [arm64] mailbox: zynqmp: Fix counts of child nodes - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s25hx SEMPER flash - drm/amd/display: Ext displays with dock can't recognized after resume - [x86] KVM: x86/mmu: Avoid indirect call for get_cr3 - [x86] KVM: x86: Do not unload MMU roots when only toggling CR0.WP with TDP enabled - [x86] KVM: x86: Make use of kvm_read_cr*_bits() when testing bits - [x86] KVM: VMX: Make CR0.WP a guest owned bit - [x86] KVM: x86/mmu: Refresh CR0.WP prior to checking for emulated permission faults - [x86] ASoC: Intel: soc-acpi-byt: Fix "WM510205" match no longer working - scsi: qedi: Fix use after free bug in qedi_remove() - drm/amd/display: Remove FPU guards from the DML folder - drm/amd/display: Add missing WA and MCLK validation - drm/amd/display: Return error code on DSC atomic check failure - drm/amd/display: Fixes for dcn32_clk_mgr implementation - drm/amd/display: Reset OUTBOX0 r/w pointer on DMUB reset - drm/amd/display: Do not clear GPINT register when releasing DMUB from reset - drm/amd/display: Update bounding box values for DCN321 - ixgbe: Fix panic during XDP_TX with > 64 CPUs - [armhf] net/ncsi: clear Tx enable mode when handling a Config required AEN - tcp: fix skb_copy_ubufs() vs BIG TCP - net/sched: cls_api: remove block_cb from driver_list before freeing - sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() - net: ipv6: fix skb hash for some RST packets - [arm64,armhf] net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu - writeback: fix call of incorrect macro - block: Skip destroyed blkg when restart in blkg_destroy_all() - [arm64,armhf] watchdog: dw_wdt: Fix the error handling path of dw_wdt_drv_probe() - [arm64,armhf] i2c: tegra: Fix PEC support for SMBUS block read - net/sched: act_mirred: Add carrier check - r8152: fix flow control issue of RTL8156A - r8152: fix the poor throughput for 2.5G devices - r8152: move setting r8153b_rx_agg_chg_indicate() - sfc: Fix module EEPROM reporting for QSFP modules - rxrpc: Fix hard call timeout units - [x86] drm/i915/mtl: Add the missing CPU transcoder mask in intel_device_info - ethtool: Fix uninitialized number of lanes - af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). - drm/amdgpu: add a missing lock for AMDGPU_SCHED - ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` - [s390x] KVM: s390: fix race in gmap_make_secure() - ice: block LAN in case of VF to VF offload - virtio_net: suppress cpu stall when free_unused_bufs - [arm64] net: enetc: check the index of the SFI rather than the handle - perf record: Fix "read LOST count failed" msg with sample read - perf scripts intel-pt-events.py: Fix IPC output for Python 2 - perf vendor events s390: Remove UTF-8 characters from JSON file - perf tests record_offcpu.sh: Fix redirection of stderr to stdin - perf ftrace: Make system wide the default target for latency subcommand - perf vendor events power9: Remove UTF-8 characters from JSON files - perf pmu: zfree() expects a pointer to a pointer to zero it after freeing its contents - perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() - perf cs-etm: Fix timeless decode mode detection - crypto: api - Add scaffolding to change completion function signature - crypto: engine - Use crypto_request_complete - crypto: engine - fix crypto_queue backlog handling - perf symbols: Fix return incorrect build_id size in elf_read_build_id() - perf tracepoint: Fix memory leak in is_valid_tracepoint() - perf stat: Separate bperf from bpf_profiler - [x86] retbleed: Fix return thunk alignment - btrfs: fix btrfs_prev_leaf() to not return the same key twice - btrfs: zoned: fix wrong use of bitops API in btrfs_ensure_empty_zones - btrfs: properly reject clear_cache and v1 cache for block-group-tree - btrfs: fix assertion of exclop condition when starting balance - btrfs: fix encoded write i_size corruption with no-holes - btrfs: don't free qgroup space unless specified - btrfs: zero the buffer before marking it dirty in btrfs_redirty_list_add - btrfs: make clear_cache mount option to rebuild FST without disabling it - btrfs: print-tree: parent bytenr must be aligned to sector size - btrfs: fix space cache inconsistency after error loading it from disk - btrfs: zoned: zone finish data relocation BG with last IO - btrfs: zoned: fix full zone super block reading on ZNS - cifs: fix pcchunk length type in smb2_copychunk_range - cifs: release leases for deferred close handles when freezing - [amd64] platform/x86/intel-uncore-freq: Return error on write frequency - [x86] platform/x86: touchscreen_dmi: Add upside-down quirk for GDIX1002 ts on the Juno Tablet - [x86] platform/x86: thinkpad_acpi: Fix platform profiles on T490 - [x86] platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i - [x86] platform/x86: thinkpad_acpi: Add profile force ability - inotify: Avoid reporting event with invalid wd - smb3: fix problem remounting a share after shutdown - SMB3: force unmount was failing to close deferred close files - [armhf] remoteproc: stm32: Call of_node_put() on iteration error - sysctl: clarify register_sysctl_init() base directory order - [armhf] ARM: dts: aspeed: asrock: Correct firmware flash SPI clocks - [armhf] ARM: dts: exynos: fix WM8960 clock name in Itop Elite - [armhf] ARM: dts: aspeed: romed8hm3: Fix GPIO polarity of system-fault LED - [arm64] drm/msm/adreno: fix runtime PM imbalance at gpu load - [x86] drm/i915/color: Fix typo for Plane CSC indexes - [arm64] drm/msm: fix NULL-deref on snapshot tear down - [arm64] drm/msm: fix NULL-deref on irq uninstall - [arm64] drm/msm: fix drm device leak on bind errors - [arm64] drm/msm: fix vram leak on bind errors - [arm64] drm/msm: fix workqueue leak on bind errors - [x86] drm/i915/dsi: Use unconditional msleep() instead of intel_dsi_msleep() - f2fs: fix null pointer panic in tracepoint in __replace_atomic_write_block - f2fs: fix potential corruption when moving a directory - [armhf] drm/panel: otm8009a: Set backlight parent to panel device - drm/amd/display: Add NULL plane_state check for cursor disable logic - drm/amd/display: Fix 4to1 MPC black screen with DPP RCO - drm/amd/display: filter out invalid bits in pipe_fuses - drm/amd/display: fix flickering caused by S/G mode - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v10_0_hw_fini - drm/amdgpu: fix an amdgpu_irq_put() issue in gmc_v9_0_hw_fini() - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_fini - drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras - drm/amdgpu/jpeg: Remove harvest checking for JPEG3 - drm/amdgpu: change gfx 11.0.4 external_id range - drm/amdgpu: Fix vram recover doesn't work after whole GPU reset (v2) - drm/amd/display: Enforce 60us prefetch for 200Mhz DCFCLK modes - drm/amd/pm: parse pp_handle under appropriate conditions - drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend - drm/amd/pm: avoid potential UBSAN issue on legacy asics - drm/amdgpu: remove deprecated MES version vars - drm/amd: Load MES microcode during early_init - drm/amd: Add a new helper for loading/validating microcode - drm/amd: Use `amdgpu_ucode_*` helpers for MES - HID: wacom: Set a default resolution for older tablets - HID: wacom: insert timestamp to packed Bluetooth (BT) events - [arm64] drm/msm/adreno: adreno_gpu: Use suspend() instead of idle() on load error - f2fs: specify extent cache for read explicitly - f2fs: move internal functions into extent_cache.c - f2fs: remove unnecessary __init_extent_tree - f2fs: refactor extent_cache to support for read and more - f2fs: allocate the extent_cache by default - f2fs: factor out victim_entry usage from general rb_tree use - [arm64] drm/msm/adreno: Simplify read64/write64 helpers - [arm64] drm/msm: Hangcheck progress detection - [arm64] drm/msm: fix missing wq allocation error handling - wifi: rtw88: rtw8821c: Fix rfe_option field width - [x86] drm/i915/mtl: update scaler source and destination limits for MTL - [x86] drm/i915: Check pipe source size when using skl+ scalers - drm/amd/display: Refactor eDP PSR codes - drm/amd/display: Add Z8 allow states to z-state support list - drm/amd/display: Add debug option to skip PSR CRTC disable - drm/amd/display: Fix Z8 support configurations - drm/amd/display: Add minimum Z8 residency debug option - drm/amd/display: Update minimum stutter residency for DCN314 Z8 - drm/amd/display: Lowering min Z8 residency time - [x86] ASoC: codecs: constify static sdw_slave_ops struct - drm/amd/display: Update Z8 watermarks for DCN314 - drm/amd/display: Update Z8 SR exit/enter latencies - drm/amd/display: Change default Z8 watermark values - ksmbd: Implements sess->ksmbd_chann_list as xarray - ksmbd: fix racy issue from session setup and logoff (CVE-2023-32250) - ksmbd: destroy expired sessions - ksmbd: block asynchronous requests when making a delay on session setup - ksmbd: fix racy issue from smb2 close and logoff with multichannel - drm: Add missing DP DSC extended capability definitions. - drm/dsc: fix drm_edp_dsc_sink_output_bpp() DPCD high byte usage - locking/rwsem: Add __always_inline annotation to __down_read_common() and inlined callers - ext4: fix WARNING in mb_find_extent - ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum (CVE-2023-34256) - ext4: fix data races when using cached status extents - ext4: check iomap type only if ext4_iomap_begin() does not fail - ext4: improve error recovery code paths in __ext4_remount() - ext4: improve error handling from ext4_dirhash() - ext4: fix deadlock when converting an inline directory in nojournal mode - ext4: add bounds checking in get_max_inline_xattr_value_size() - ext4: bail out of ext4_xattr_ibody_get() fails for any reason - ext4: fix lockdep warning when enabling MMP - ext4: remove a BUG_ON in ext4_mb_release_group_pa() - ext4: fix invalid free tracking in ext4_xattr_move_to_block() - drm/dsc: fix DP_DSC_MAX_BPP_DELTA_* macro values - f2fs: fix to do sanity check on extent cache correctly - f2fs: inode: fix to do sanity check on extent cache correctly - [x86] amd_nb: Add PCI ID for family 19h model 78h - [x86] fix clear_user_rep_good() exception handling annotation - drm/amd/display: Fix hang when skipping modeset https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.30 - drm/fbdev-generic: prohibit potential out-of-bounds access - drm/mipi-dsi: Set the fwnode for mipi_dsi_device - net: skb_partial_csum_set() fix against transport header magic value - scsi: ufs: core: Fix I/O hang that occurs when BKOPS fails in W-LUN suspend - tick/broadcast: Make broadcast device replacement work correctly - linux/dim: Do nothing if no time delta between samples - net: stmmac: Initialize MAC_ONEUS_TIC_COUNTER register - net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). - [arm64,armhf] net: phy: bcm7xx: Correct read from expansion register - netfilter: nf_tables: always release netdev hooks from notifier - netfilter: conntrack: fix possible bug_on with enable_hooks=1 - bonding: fix send_peer_notif overflow - netlink: annotate accesses to nlk->cb_running - net: annotate sk->sk_err write from do_recvmmsg() - net: deal with most data-races in sk_wait_event() - net: add vlan_get_protocol_and_depth() helper - tcp: add annotations around sk->sk_shutdown accesses - [amd64,arm64] gve: Remove the code of clearing PBA bit - ipvlan:Fix out-of-bounds caused by unclear skb->cb (CVE-2023-3090) - [arm64] net: mscc: ocelot: fix stat counter register values - net: datagram: fix data-races in datagram_poll() - af_unix: Fix a data race of sk->sk_receive_queue->qlen. - af_unix: Fix data races around sk->sk_shutdown. - [x86] drm/i915/guc: Don't capture Gen8 regs on Xe devices - [x86] drm/i915: Fix NULL ptr deref by checking new_crtc_state - [x86] drm/i915/dp: prevent potential div-by-zero - [x86] drm/i915: Expand force_probe to block probe of devices as well. - [x86] drm/i915: taint kernel when force probing unsupported devices - [x86] fbdev: arcfb: Fix error handling in arcfb_probe() - ext4: reflect error codes from ext4_multi_mount_protect() to its callers - ext4: allow to find by goal if EXT4_MB_HINT_GOAL_ONLY is set - ext4: allow ext4_get_group_info() to fail - rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access - open: return EINVAL for O_DIRECTORY | O_CREAT - fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() - drm/displayid: add displayid_get_header() and check bounds better - drm/amd/display: populate subvp cmd info only for the top pipe - drm/amd/display: Correct DML calculation to align HW formula - [x86] platform/x86: x86-android-tablets: Add Acer Iconia One 7 B1-750 data - drm/amd/display: Enable HostVM based on rIOMMU active - drm/amd/display: Use DC_LOG_DC in the trasform pixel function - regmap: cache: Return error in cache sync operations for REGCACHE_NONE - [arm64] dts: qcom: msm8996: Add missing DWC3 quirks - media: cx23885: Fix a null-ptr-deref bug in buffer_prepare() and buffer_finish() - media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() - [arm64,armhf] drm/rockchip: dw_hdmi: cleanup drm encoder during unbind - memstick: r592: Fix UAF bug in r592_remove due to race condition (CVE-2023-3141) - ACPI: EC: Fix oops when removing custom query handlers - drm/amd/display: fixed dcn30+ underflow issue - [armhf] remoteproc: stm32_rproc: Add mutex protection for workqueue - [arm64,armhf] drm/tegra: Avoid potential 32-bit integer overflow - [arm64] drm/msm/dp: Clean up handling of DP AUX interrupts - ACPICA: Avoid undefined behavior: applying zero offset to null pointer - ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects - [arm64] dts: qcom: sdm845-polaris: Drop inexistent properties - [arm64,armhf] irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 - ACPI: video: Remove desktops without backlight DMI quirks - drm/amd/display: Correct DML calculation to follow HW SPEC - drm/amd: Fix an out of bounds error in BIOS parser - drm/amdgpu: Fix sdma v4 sw fini error - [armhf] media: Prefer designated initializers over memset for subdev pad ops - wifi: ath: Silence memcpy run-time false positive warning - bpf: Annotate data races in bpf_local_storage - wifi: brcmfmac: pcie: Provide a buffer of random bytes to the device - wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex - scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow - scsi: lpfc: Correct used_rpi count when devloss tmo fires with no recovery - bnxt: avoid overflow in bnxt_get_nvram_directory() - net: Catch invalid index in XPS mapping - netdev: Enforce index cap in netdev_get_tx_queue - scsi: target: iscsit: Free cmds before session free - lib: cpu_rmap: Avoid use after free on rmap->obj array entries - scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition - gfs2: Fix inode height consistency check - [x86] scsi: ufs: ufs-pci: Add support for Intel Lunar Lake - ext4: set goal start correctly in ext4_mb_normalize_request - ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() - crypto: jitter - permanent and intermittent health errors - f2fs: Fix system crash due to lack of free space in LFS - f2fs: fix to drop all dirty pages during umount() if cp_error is set - f2fs: fix to check readonly condition correctly - bpf: Add preempt_count_{sub,add} into btf id deny list - md: fix soft lockup in status_resync - wifi: iwlwifi: pcie: fix possible NULL pointer dereference - wifi: iwlwifi: add a new PCI device ID for BZ device - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf - wifi: iwlwifi: mvm: fix ptk_pn memory leak - block, bfq: Fix division by zero error on zero wsum - wifi: ath11k: Ignore frags from uninitialized peer in dp. - wifi: iwlwifi: fix iwl_mvm_max_amsdu_size() for MLO - null_blk: Always check queue mode setting from configfs - wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace - wifi: ath11k: Fix SKB corruption in REO destination ring - nbd: fix incomplete validation of ioctl arg - ipvs: Update width of source for ip_vs_sync_conn_options - Bluetooth: btusb: Add new PID/VID 04ca:3801 for MT7663 - Bluetooth: Add new quirk for broken local ext features page 2 - Bluetooth: btrtl: add support for the RTL8723CS - Bluetooth: Improve support for Actions Semi ATS2851 based devices - Bluetooth: btrtl: check for NULL in btrtl_set_quirks() - Bluetooth: btintel: Add LE States quirk support - Bluetooth: hci_bcm: Fall back to getting bdaddr from EFI if not set - Bluetooth: Add new quirk for broken set random RPA timeout for ATS2851 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp - Bluetooth: btrtl: Add the support for RTL8851B - HID: apple: Set the tilde quirk flag on the Geyser 4 and later - [x86] ASoC: amd: yc: Add DMI entries to support HP OMEN 16-n0xxx (8A42) - HID: logitech-hidpp: Don't use the USB serial for USB devices - HID: logitech-hidpp: Reconcile USB and Unifying serials - [arm64,armhf] spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 - [x86] usb: typec: ucsi: acpi: add quirk for ASUS Zenbook UM325 - ALSA: hda: LNL: add HD Audio PCI ID - [x86] ASoC: amd: Add Dell G15 5525 to quirks list - [x86] ASoC: amd: yc: Add ThinkBook 14 G5+ ARP to quirks list for acp6x - [x86] HID: apple: Set the tilde quirk flag on the Geyser 3 - [x86] HID: Ignore battery for ELAN touchscreen on ROG Flow X13 GV301RA - HID: wacom: generic: Set battery quirk only when we see battery data - usb: typec: tcpm: fix multiple times discover svids error - serial: 8250: Reinit port->pm on port specific driver unbind - [x86] soundwire: dmi-quirks: add remapping for Intel 'Rooks County' NUC M15 - soundwire: qcom: gracefully handle too many ports in DT - soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow - [x86] mfd: intel_soc_pmic_chtwc: Add Lenovo Yoga Book X90F to intel_cht_wc_models - [x86] mfd: intel-lpss: Add Intel Meteor Lake PCH-S LPSS PCI IDs - [x86] platform/x86: Move existing HP drivers to a new hp subdir - [x86] hp-wmi: add micmute to hp_wmi_keymap struct - drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs - xfrm: don't check the default policy if the policy allows the packet - Revert "Fix XFRM-I support for nested ESP tunnels" - [arm64] drm/msm/dp: unregister audio driver during unbind - [arm64] drm/msm/dpu: Assign missing writeback log_mask - [arm64] drm/msm/dpu: Move non-MDP_TOP INTF_INTR offsets out of hwio header - [arm64] drm/msm/dpu: Remove duplicate register defines from INTF - platform: Provide a remove callback that returns no value - [arm64] ASoC: fsl_micfil: Fix error handler with pm_runtime_enable - cpupower: Make TSC read per CPU for Mperf monitor - xfrm: Reject optional tunnel/BEET mode templates in outbound policies - af_key: Reject optional tunnel/BEET mode templates in outbound policies - [arm64] drm/msm: Fix submit error-path leaks - [arm64,armhf] net: fec: Better handle pm_runtime_get() failing in .remove() - net: phy: dp83867: add w/a for packet errors seen with short cables - ALSA: firewire-digi00x: prevent potential use after free - wifi: mt76: connac: fix stats->tx_bytes calculation - [x86] ALSA: hda/realtek: Apply HP B&O top speaker profile to Pavilion 15 - sfc: disable RXFCS and RXALL features by default - vsock: avoid to close connected socket after the timeout - tcp: fix possible sk_priority leak in tcp_v4_send_reset() - [armhf] serial: arc_uart: fix of_iomap leak in `arc_serial_probe` - erspan: get the proto with the md version for collect_md - [arm64] net: hns3: fix output information incomplete for dumping tx queue info with debugfs - [arm64] net: hns3: fix sending pfc frames after reset issue - [arm64] net: hns3: fix reset delay time to avoid configuration timeout - [arm64] net: hns3: fix reset timeout when enable full VF - media: netup_unidvb: fix use-after-free at del_timer() - SUNRPC: double free xprt_ctxt while still in use - SUNRPC: always free ctxt when freeing deferred request - SUNRPC: Fix trace_svc_register() call site - [x86] ASoC: SOF: topology: Fix logic for copying tuples - net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() - virtio-net: Maintain reverse cleanup order - virtio_net: Fix error unwinding of XDP initialization - tipc: add tipc_bearer_min_mtu to calculate min mtu - tipc: do not update mtu if msg_max is too small in mtu negotiation - tipc: check the bearer min mtu properly when setting it by netlink - [s390x] cio: include subchannels without devices also for evaluation - can: dev: fix missing CAN XL support in can_put_echo_skb() - [arm64] net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() - [arm64] net: bcmgenet: Restore phy_stop() depending upon suspend/close - ice: introduce clear_reset_state operation - ice: Fix ice VF reset during iavf initialization - wifi: cfg80211: Drop entries with invalid BSSIDs in RNR - wifi: mac80211: fortify the spinlock against deadlock by interrupt - wifi: mac80211: fix min center freq offset tracing - wifi: mac80211: Abort running color change when stopping the AP - wifi: iwlwifi: mvm: fix cancel_delayed_work_sync() deadlock - wifi: iwlwifi: fw: fix DBGI dump - wifi: iwlwifi: fix OEM's name in the ppag approved list - wifi: iwlwifi: mvm: fix OEM's name in the tas approved list - wifi: iwlwifi: mvm: don't trust firmware n_channels - scsi: storvsc: Don't pass unused PFNs to Hyper-V host - net: tun: rebuild error handling in tun_get_user - tun: Fix memory leak for detached NAPI queue. - cassini: Fix a memory leak in the error handling path of cas_init_one() - [arm64,armhf] net: dsa: mv88e6xxx: Fix mv88e6393x EPC write command offset - igb: fix bit_shift to be in [1..8] range - vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() - net: wwan: iosm: fix NULL pointer dereference when removing device - net: pcs: xpcs: fix C73 AN not getting enabled - netfilter: nf_tables: fix nft_trans type confusion - netfilter: nft_set_rbtree: fix null deref on element insertion - ALSA: usb-audio: Add a sample rate workaround for Line6 Pod Go - USB: usbtmc: Fix direction for 0-length ioctl control messages - usb-storage: fix deadlock when a scsi command timeouts more than once - USB: UHCI: adjust zhaoxin UHCI controllers OverCurrent bit value - [arm64,armhf] usb: dwc3: gadget: Improve dwc3_gadget_suspend() and dwc3_gadget_resume() - [arm64,armhf] usb: dwc3: debugfs: Resume dwc3 before accessing registers - usb: gadget: u_ether: Fix host MAC address case - usb: typec: altmodes/displayport: fix pin_assignment_show - xhci-pci: Only run d3cold avoidance quirk for s2idle - xhci: Fix incorrect tracking of free space on transfer rings - ALSA: hda: Fix Oops by 9.1 surround channel names - ALSA: hda: Add NVIDIA codec IDs a3 through a7 to patch table - [x86] ALSA: hda/realtek: Add quirk for Clevo L140AU - [x86] ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 - [x86] ALSA: hda/realtek: Add quirk for 2nd ASUS GU603 - [x86] ALSA: hda/realtek: Add quirk for HP EliteBook G10 laptops - ALSA: hda/realtek: Fix mute and micmute LEDs for yet another HP laptop - can: j1939: recvmsg(): allow MSG_CMSG_COMPAT flag - can: isotp: recvmsg(): allow MSG_CMSG_COMPAT flag - wifi: rtw88: use work to update rate to avoid RCU warning - SMB3: Close all deferred handles of inode in case of handle lease break - SMB3: drop reference to cfile before sending oplock break - ksmbd: smb2: Allow messages padded to 8byte boundary - ksmbd: allocate one more byte for implied bcc[0] - ksmbd: fix wrong UserName check in session_user - ksmbd: fix global-out-of-bounds in smb2_find_context_vals - KVM: Fix vcpu_array[0] races - statfs: enforce statfs[64] structure initialization - maple_tree: make maple state reusable after mas_empty_area() (Closes: #1036755) - mm: fix zswap writeback race condition - serial: Add support for Advantech PCI-1611U card - serial: 8250_exar: Add support for USR298x PCI Modems - [arm64] serial: qcom-geni: fix enabling deactivated interrupt - [x86] thunderbolt: Clear registers properly when auto clear isn't in use - vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF - ceph: force updating the msg pointer in non-split case - drm/amd/pm: fix possible power mode mismatch between driver and PMFW - drm/amdgpu/gmc11: implement get_vbios_fb_size() - drm/amdgpu/gfx10: Disable gfxoff before disabling powergating. - drm/amdgpu/gfx11: Adjust gfxoff before powergating on gfx11 as well - drm/amdgpu: refine get gpu clock counter method - drm/amdgpu/gfx11: update gpu_clock_counter logic - [powerpc*] iommu: DMA address offset is incorrectly calculated with 2MB TCEs - [powerpc*] iommu: Incorrect DDW Table is referenced for SR-IOV device - tpm/tpm_tis: Disable interrupts for more Lenovo devices - [powerpc*] 64s/radix: Fix soft dirty tracking - nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() - [s390x] dasd: fix command reject error on ESE devices - [s390x] crypto: use vector instructions only if available for ChaCha20 - [s390x] qdio: fix do_sqbs() inline assembly constraint - [arm64] mte: Do not set PG_mte_tagged if tags were not initialized - [x86] rethook: use preempt_{disable, enable}_notrace in rethook_trampoline_handler - [x86] rethook, fprobe: do not trace rethook related functions - crypto: testmgr - fix RNG performance in fuzz tests - drm/amdgpu: declare firmware for new MES 11.0.4 - drm/amd/amdgpu: introduce gc_*_mes_2.bin v2 - drm/amdgpu: reserve the old gc_11_0_*_mes.bin https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.31 - [arm64,armhf] usb: dwc3: fix gadget mode suspend interrupt handler issue - tpm, tpm_tis: Avoid cache incoherency in test for interrupts - tpm, tpm_tis: Only handle supported interrupts - tpm_tis: Use tpm_chip_{start,stop} decoration inside tpm_tis_resume - tpm, tpm_tis: startup chip before testing for interrupts - tpm: Re-enable TPM chip boostrapping non-tpm_tis TPM drivers - tpm: Prevent hwrng from activating during resume - [x86] watchdog: sp5100_tco: Immediately trigger upon starting. - drm/amd/amdgpu: update mes11 api def - drm/amdgpu/mes11: enable reg active poll - skbuff: Proactively round up to kmalloc bucket size - [arm64,armhf] net: dsa: mv88e6xxx: Add RGMII delay to 88E6320 - drm/amd/display: hpd rx irq not working with eDP interface - ocfs2: Switch to security_inode_init_security() - [x86] mm: Avoid incomplete Global INVLPG flushes - [x86] ALSA: hda/ca0132: add quirk for EVGA X299 DARK - ALSA: hda: Fix unhandled register update during auto-suspend period - [x86] ALSA: hda/realtek: Enable headset onLenovo M70/M90 - SUNRPC: Don't change task->tk_status after the call to rpc_exit_task - [arm64,armhf] imc: sdhci-esdhc-imx: make "no-mmc-hs400" works - mmc: block: ensure error propagation for non-blk - [x86] power: supply: axp288_fuel_gauge: Fix external_power_changed race - [arm64] power: supply: bq25890: Fix external_power_changed race - ASoC: rt5682: Disable jack detection interrupt during suspend - net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize - btrfs: use nofs when cleaning up aborted transactions - [x86] drm/mgag200: Fix gamma lut not initialized. - drm/radeon: reintroduce radeon_dp_work_func content - drm/amd/pm: add missing NotifyPowerSource message mapping for SMU13.0.7 - drm/amd/pm: Fix output of pp_od_clk_voltage - Revert "binder_alloc: add missing mmap_lock calls when using the VMA" - Revert "android: binder: stop saving a pointer to the VMA" - binder: add lockless binder_alloc_(set|get)_vma() - binder: fix UAF caused by faulty buffer cleanup - binder: fix UAF of alloc->vma in race with munmap() - drm/amd/amdgpu: limit one queue per gang - [x86] perf/x86/uncore: Correct the number of CHAs on SPR - [x86] topology: Fix erroneous smp_num_siblings on Intel Hybrid platforms - [mips*] irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable - [mips*] irqchip/mips-gic: Use raw spinlock for gic_lock - debugobjects: Don't wake up kswapd from fill_pool() - fbdev: udlfb: Fix endpoint check - net: fix stack overflow when LRO is disabled for virtual interfaces - udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). - USB: core: Add routines for endpoint checks in old drivers - USB: sisusbvga: Add endpoint checks - media: radio-shark: Add endpoint checks - net: fix skb leak in __skb_tstamp_tx() - drm: fix drmm_mutex_init() - bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields - bpf: fix a memory leak in the LRU and LRU_PERCPU hash maps - ipv6: Fix out-of-bounds access in ipv6_find_tlv() - cifs: mapchars mount option ignored - power: supply: leds: Fix blink to LED on transition - power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition - power: supply: bq27xxx: Fix I2C IRQ race on remove - power: supply: bq27xxx: Fix poll_interval handling and races on remove - power: supply: bq27xxx: Add cache parameter to bq27xxx_battery_current_and_status() - power: supply: bq27xxx: Move bq27xxx_battery_update() down - power: supply: bq27xxx: Ensure power_supply_changed() is called on current sign changes - power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize - [arm64] power: supply: bq25890: Call power_supply_changed() after updating input current or voltage - [x86] power: supply: bq24190: Call power_supply_changed() after updating input current - [arm64] optee: fix uninited async notif value - fs: fix undefined behavior in bit shift for SB_NOUSER - [arm64] regulator: pca9450: Fix BUCK2 enable_mask - [x86] platform/x86: ISST: Remove 8 socket limit - [armhf] dts: imx6qdl-mba6: Add missing pvcie-supply regulator - [x86] pci/xen: populate MSI sysfs entries - [x86] show_trace_log_lvl: Ensure stack pointer is aligned, again - [x86] ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg - cxl: Wait Memory_Info_Valid before access memory related info - sctp: fix an issue that plpmtu can never go to complete state - [x86] forcedeth: Fix an error handling path in nv_probe() - net/mlx5e: Fix SQ wake logic in ptp napi_poll context - net/mlx5e: Fix deadlock in tc route query code - net/mlx5e: Use correct encap attribute during invalidation - net/mlx5e: do as little as possible in napi poll when budget is 0 - [s390x] net/mlx5: DR, Fix crc32 calculation to work on big-endian (BE) CPUs - net/mlx5: Handle pairing of E-switch via uplink un/load APIs - net/mlx5: DR, Check force-loopback RC QP capability independently from RoCE - net/mlx5: Fix error message when failing to allocate device memory - net/mlx5: Collect command failures data only for known commands - net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device - net/mlx5: Devcom, serialize devcom registration - [arm64] dts: imx8mn-var-som: fix PHY detection bug by adding deassert delay - net/smc: Reset connection when trying to use SMCRv2 fails. - [x86] 3c589_cs: Fix an error handling path in tc589_probe() - net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.32 - inet: Add IP_LOCAL_PORT_RANGE socket option - ipv{4,6}/raw: fix output xfrm lookup wrt protocol - tls: rx: device: fix checking decryption status - tls: rx: strp: set the skb->len of detached / CoW'ed skbs - tls: rx: strp: fix determining record length in copy mode - tls: rx: strp: force mixed decrypted records into copy mode - tls: rx: strp: factor out copying skb data - tls: rx: strp: preserve decryption status of skbs when needed - net/mlx5: E-switch, Devcom, sync devcom events and devcom comp register - [x86] gpio-f7188x: fix chip name and pin count on Nuvoton chip - bpf, sockmap: Pass skb ownership through read_skb - bpf, sockmap: Convert schedule_work into delayed_work - bpf, sockmap: Reschedule is now done through backlog - bpf, sockmap: Improved check for empty queue - bpf, sockmap: Handle fin correctly - bpf, sockmap: TCP data stall on recv before accept - bpf, sockmap: Wake up polling after data copy - bpf, sockmap: Incorrectly handling copied_seq - blk-mq: fix race condition in active queue accounting - vfio/type1: check pfn valid before converting to struct page - net: page_pool: use in_softirq() instead - page_pool: fix inconsistency for page_pool_ring_[un]lock() - net: phy: mscc: enable VSC8501/2 RGMII RX clock - wifi: iwlwifi: mvm: support wowlan info notification version 2 - wifi: iwlwifi: mvm: fix potential memory leak - RDMA/rxe: Fix the error "trying to register non-static key in rxe_cleanup_task" - drm/amd: Don't allow s0ix on APUs older than Raven - bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() - block: fix bio-cache for passthru IO - [x86] cpufreq: amd-pstate: Update policy->cur in amd_pstate_adjust_perf() - [x86] cpufreq: amd-pstate: Add ->fast_switch() callback - netfilter: ctnetlink: Support offloaded conntrack entry deletion https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.33 - [arm64,armhf] phy: amlogic: phy-meson-g12a-mipi-dphy-analog: fix CNTL2_DIF_TX_CTL0 value - [arm64] RDMA/hns: Fix timeout attr in query qp for HIP08 - [arm64] RDMA/hns: Fix base address table allocation - [arm64] RDMA/hns: Modify the value of long message loopback slice - [arm64,armhf] iommu/rockchip: Fix unwind goto issue - [amd64] iommu/amd: Don't block updates to GATag if guest mode is on - [amd64] iommu/amd: Handle GALog overflows - [amd64] iommu/amd: Fix up merge conflict resolution - nfsd: make a copy of struct iattr before calling notify_change - net/mlx5: Drain health before unregistering devlink - net/mlx5: SF, Drain health before removing device - net/mlx5: fw_tracer, Fix event handling - net/mlx5e: Don't attach netdev profile while handling internal error - netrom: fix info-leak in nr_write_internal() - af_packet: Fix data-races of pkt_sk(sk)->num. - tls: improve lockless access safety of tls_err_abort() - [amd64,arm64] amd-xgbe: fix the false linkup in xgbe_phy_status - perf ftrace latency: Remove unnecessary "--" from --use-nsec option - RDMA/irdma: Prevent QP use after free - RDMA/irdma: Fix Local Invalidate fencing - af_packet: do not use READ_ONCE() in packet_bind() - tcp: deny tcp_disconnect() when threads are waiting - tcp: Return user_mss for TCP_MAXSEG in CLOSE/LISTEN state if user_mss set - net/smc: Scan from current RMB list when no position specified - net/smc: Don't use RMBs not mapped to new link in SMCRv2 ADD LINK - net/sched: sch_ingress: Only create under TC_H_INGRESS - net/sched: sch_clsact: Only create under TC_H_CLSACT - net/sched: Reserve TC_H_INGRESS (TC_H_CLSACT) for ingress (clsact) Qdiscs - net/sched: Prohibit regrafting ingress or clsact Qdiscs - net: sched: fix NULL pointer dereference in mq_attach - net/netlink: fix NETLINK_LIST_MEMBERSHIPS length report - udp6: Fix race condition in udp6_sendmsg & connect - nfsd: fix double fget() bug in __write_ports_addfd() - nvme: fix the name of Zone Append for verbose logging - net/mlx5e: Fix error handling in mlx5e_refresh_tirs - net/mlx5: Read embedded cpu after init bit cleared - net/sched: flower: fix possible OOB write in fl_set_geneve_opt() (CVE-2023-35788) - tcp: fix mishandling when the sack compression is deferred. - [arm64,armhf] net: dsa: mv88e6xxx: Increase wait after reset deactivation - [armhf] mtd: rawnand: marvell: ensure timing values are written - [armhf] mtd: rawnand: marvell: don't set the NAND frequency select - rtnetlink: call validate_linkmsg in rtnl_create_link - mptcp: avoid unneeded __mptcp_nmpc_socket() usage - mptcp: add annotations around msk->subflow accesses - mptcp: avoid unneeded address copy - mptcp: simplify subflow_syn_recv_sock() - mptcp: consolidate passive msk socket initialization - mptcp: fix data race around msk->first access - mptcp: add annotations around sk->sk_shutdown accesses - drm/amdgpu: release gpu full access after "amdgpu_device_ip_late_init" - ALSA: hda: Glenfly: add HD Audio PCI IDs and HDMI Codec Vendor IDs. - [x86] ASoC: Intel: soc-acpi-cht: Add quirk for Nextbook Ares 8A tablet - drm/amdgpu: Use the default reset when loading or reloading the driver - [arm64] drm/ast: Fix ARM compatibility - btrfs: abort transaction when sibling keys check fails for leaves - [armel,armhf] ARM: 9295/1: unwind:fix unwind abort for uleb128 case - [x86] hwmon: (k10temp) Add PCI ID for family 19, model 78h - gfs2: Don't deref jdesc in evict (CVE-2023-3212) - drm/amdgpu: set gfx9 onwards APU atomics support to be true - fbdev: modedb: Add 1920x1080 at 60 Hz video mode - nbd: Fix debugfs_create_dir error checking - nvme-pci: add NVME_QUIRK_BOGUS_NID for HS-SSD-FUTURE 2048G - nvme-pci: add quirk for missing secondary temperature thresholds - [x86] ASoC: amd: yc: Add DMI entry to support System76 Pangolin 12 - xfrm: Check if_id in inbound policy/secpath match - [x86] ALSA: hda/realtek: Add quirks for ASUS GU604V and GU603V - media: dvb_demux: fix a bug for the continuity counter - media: dvb-usb: az6027: fix three null-ptr-deref in az6027_i2c_xfer() - media: dvb-usb-v2: ec168: fix null-ptr-deref in ec168_i2c_xfer() - media: dvb-usb-v2: ce6230: fix null-ptr-deref in ce6230_i2c_master_xfer() - media: dvb-usb-v2: rtl28xxu: fix null-ptr-deref in rtl28xxu_i2c_xfer - media: dvb-usb: digitv: fix null-ptr-deref in digitv_i2c_xfer() - media: dvb-usb: dw2102: fix uninit-value in su3000_read_mac_address - media: netup_unidvb: fix irq init by register it at the end of probe - media: dvb_ca_en50221: fix a size write bug - media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb() - media: dvb-core: Fix use-after-free due on race condition at dvb_net - media: dvb-core: Fix use-after-free due to race at dvb_register_device() - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() (CVE-2023-31084) - media: dvb-core: Fix use-after-free due to race condition at dvb_ca_en50221 - [x86] ASoC: SOF: debug: conditionally bump runtime_pm counter on exceptions - [x86] ASoC: SOF: pcm: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: sof-client-probes: fix pm_runtime imbalance in error handling - [x86] ASoC: SOF: pm: save io region state in case of errors in resume - [s390x] topology: honour nr_cpu_ids when adding CPUs - ACPI: resource: Add IRQ override quirk for LG UltraPC 17U70P - wifi: rtl8xxxu: fix authentication timeout due to incorrect RCR value - [arm64] mm: mark private VM_FAULT_X defines as vm_fault_t - [arm64] vdso: Pass (void *) to virt_to_page() - wifi: mac80211: simplify chanctx allocation - wifi: mac80211: consider reserved chanctx for mindef - wifi: mac80211: recalc chanctx mindef before assigning - wifi: iwlwifi: mvm: Add locking to the rate read flow - scsi: core: Decrease scsi_device's iorequest_cnt if dispatch failed - nvme-multipath: don't call blk_mark_disk_dead in nvme_mpath_remove_disk - nvme: do not let the user delete a ctrl before a complete initialization - [arm64] drm/msm: Be more shouty if per-process pgtables aren't working - ceph: silence smatch warning in reconnect_caps_cb() - drm/amdgpu: skip disabling fence driver src_irqs when device is unplugged - nvme-pci: Add quirk for Teamgroup MP33 SSD - block: Deny writable memory mapping if block is read-only - [arm64] KVM: arm64: vgic: Fix a circular locking issue - [arm64] KVM: arm64: vgic: Wrap vgic_its_create() with config_lock - [arm64] KVM: arm64: vgic: Fix locking comment - drivers: base: cacheinfo: Fix shared_cpu_map changes in event of CPU hotplug - media: uvcvideo: Don't expose unsupported formats to userspace - iio: accel: st_accel: Fix invalid mount_matrix on devices without ACPI _ONT method - HID: google: add jewel USB id - HID: wacom: avoid integer overflow in wacom_intuos_inout() - iio: imu: inv_icm42600: fix timestamp reset - iio: light: vcnl4035: fixed chip ID check - iio: adc: ad_sigma_delta: Fix IRQ issue by setting IRQ_DISABLE_UNLAZY flag - iio: dac: mcp4725: Fix i2c_master_send() return value handling - iio: adc: ad7192: Change "shorted" channels to differential - net: usb: qmi_wwan: Set DTR quirk for BroadMobi BM818 - usb: gadget: f_fs: Add unbind event before functionfs_unbind - md/raid5: fix miscalculation of 'end_sector' in raid5_read_one_chunk() - ata: libata-scsi: Use correct device no in ata_find_dev() - drm/amdgpu: enable tmz by default for GC 11.0.1 - drm/amd/pm: reverse mclk and fclk clocks levels for SMU v13.0.4 - drm/amd/pm: reverse mclk and fclk clocks levels for vangogh - drm/amd/pm: resolve reboot exception for si oland - drm/amd/pm: reverse mclk clocks levels for SMU v13.0.5 - drm/amd/pm: reverse mclk and fclk clocks levels for yellow carp - drm/amd/pm: reverse mclk and fclk clocks levels for renoir - [x86] mtrr: Revert 90b926e68f50 ("x86/pat: Fix pat_x_mtrr_type() for MTRR disabled case") - mmc: vub300: fix invalid response handling - [armhf] mmc: pwrseq: sd8787: Fix WILC CHIP_EN and RESETN toggling order - [arm64] tty: serial: fsl_lpuart: use UARTCTRL_TXINV to send break instead of UARTCTRL_SBK - btrfs: fix csum_tree_block page iteration to avoid tripping on -Werror=array-bounds - [arm64] phy: qcom-qmp-combo: fix init-count imbalance - [arm64] phy: qcom-qmp-pcie-msm8996: fix init-count imbalance - block: fix revalidate performance regression - [powerpc*] iommu: Limit number of TCEs to 512 for H_STUFF_TCE hcall - [amd64] iommu/amd: Fix domain flush size when syncing iotlb - tpm, tpm_tis: correct tpm_tis_flags enumeration values - io_uring: undeprecate epoll_ctl support - mtdchar: mark bits of ioctl handler noinline - [rt] tracing/timerlat: Always wakeup the timerlat thread - tracing/histograms: Allow variables to have some modifiers - tracing/probe: trace_probe_primary_from_call(): checked list_first_entry - mptcp: fix connect timeout handling - mptcp: fix active subflow finalization - ext4: add EA_INODE checking to ext4_iget() - ext4: disallow ea_inodes with extended attributes - fbcon: Fix null-ptr-deref in soft_cursor - [arm64,armhf] serial: 8250_tegra: Fix an error handling path in tegra_uart_probe() - [powerpc*] xmon: Use KSYM_NAME_LEN in array size - [arm64] KVM: arm64: Populate fault info for watchpoint - [x86] KVM: x86: Account fastpath-only VM-Exits in vCPU stats - ksmbd: fix credit count leakage - ksmbd: fix UAF issue from opinfo->conn - ksmbd: fix incorrect AllocationSize set in smb2_get_info - ksmbd: fix slab-out-of-bounds read in smb2_handle_negotiate - ksmbd: fix multiple out-of-bounds read during context decoding - KEYS: asymmetric: Copy sig and digest in public_key_verify_signature() - fs/ntfs3: Validate MFT flags before replaying logs (CVE-2022-48425) - regmap: Account for register length when chunking - tpm, tpm_tis: Request threaded interrupt handler - [amd64] iommu/amd/pgtbl_v2: Fix domain max address - drm/amd/display: Have Payload Properly Created After Resume - xfs: verify buffer contents when we skip log replay (CVE-2023-2124) - tls: rx: strp: don't use GFP_KERNEL in softirq context - [arm64] efi: Use SMBIOS processor version to key off Ampere quirk - ext4: enable the lazy init thread when remounting read/write https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.34 - scsi: megaraid_sas: Add flexible array member for SGLs - net: sfp: fix state loss when updating state_hw_mask - [x86] platform/surface: aggregator: Allow completion work-items to be executed in parallel - [x86] platform/surface: aggregator_tabletsw: Add support for book mode in KIP subsystem - [arm64] spi: qup: Request DMA before enabling clocks - afs: Fix setting of mtime when creating a file/dir/symlink - wifi: mt76: mt7615: fix possible race in mt7615_mac_sta_poll - bpf, sockmap: Avoid potential NULL dereference in sk_psock_verdict_data_ready() - neighbour: fix unaligned access to pneigh_entry - net/ipv4: ping_group_range: allow GID from 2147483648 to 4294967294 - bpf: Fix UAF in task local storage - bpf: Fix elem_size not being set for inner maps - net/ipv6: fix bool/int mismatch for skip_notify_on_dev_down - net/smc: Avoid to access invalid RMBs' MRs in SMCRv1 ADD LINK CONT - [arm64] net: enetc: correct the statistics of rx bytes - [arm64] net: enetc: correct rx_bytes statistics of XDP - net/sched: fq_pie: ensure reasonable TCA_FQ_PIE_QUANTUM values - [x86] drm/i915: Explain the magic numbers for AUX SYNC/precharge length - [x86] drm/i915: Use 18 fast wake AUX sync len - Bluetooth: hci_sync: add lock to protect HCI_UNREGISTER - Bluetooth: Fix l2cap_disconnect_req deadlock - Bluetooth: ISO: don't try to remove CIG if there are bound CIS left - Bluetooth: L2CAP: Add missing checks for invalid DCID - wifi: mac80211: use correct iftype HE cap - wifi: cfg80211: reject bad AP MLD address - wifi: mac80211: mlme: fix non-inheritence element - wifi: mac80211: don't translate beacon/presp addrs - qed/qede: Fix scheduling while atomic - wifi: cfg80211: fix locking in sched scan stop work - netfilter: nft_bitwise: fix register tracking - netfilter: conntrack: fix NULL pointer dereference in nf_confirm_cthelper - netfilter: ipset: Add schedule point in call_ad(). - netfilter: nf_tables: out-of-bound check in chain blob - ipv6: rpl: Fix Route of Death. (CVE-2023-2156) - tcp: gso: really support BIG TCP - rfs: annotate lockless accesses to sk->sk_rxhash - rfs: annotate lockless accesses to RFS sock flow table - net: sched: add rcu annotations around qdisc->qdisc_sleeping - net: sched: move rtm_tca_policy declaration to include file - net: sched: act_police: fix sparse errors in tcf_police_dump() - net: sched: fix possible refcount leak in tc_chain_tmplt_add() - bpf: Add extra path pointer check to d_path helper - drm/amdgpu: fix Null pointer dereference error in amdgpu_device_recover_vram - lib: cpu_rmap: Fix potential use-after-free in irq_cpu_rmap_release() - [arm64] net: bcmgenet: Fix EEE implementation - bnxt_en: Don't issue AP reset during ethtool's reset operation - bnxt_en: Query default VLAN before VNIC setup on a VF - bnxt_en: Skip firmware fatal error recovery if chip is not accessible - bnxt_en: Prevent kernel panic when receiving unexpected PHC_UPDATE event - bnxt_en: Implement .set_port / .unset_port UDP tunnel callbacks - batman-adv: Broken sync while rescheduling delayed work - Input: xpad - delete a Razer DeathAdder mouse VID/PID entry - Input: psmouse - fix OOB access in Elantech protocol - Input: fix open count when closing inhibited device - ALSA: hda: Fix kctl->id initialization - ALSA: ymfpci: Fix kctl->id initialization - [i386] ALSA: gus: Fix kctl->id initialization - ALSA: cmipci: Fix kctl->id initialization - [x86] ALSA: hda/realtek: Add quirk for Clevo NS50AU - ALSA: ice1712,ice1724: fix the kcontrol->id initialization - [x86] ALSA: hda/realtek: Add a quirk for HP Slim Desktop S01 - [x86] ALSA: hda/realtek: Add Lenovo P3 Tower platform - [x86] ALSA: hda/realtek: Add quirks for Asus ROG 2024 laptops using CS35L41 - [x86] drm/i915/gt: Use the correct error value when kernel_context() fails - drm/amd/pm: conditionally disable pcie lane switching for some sienna_cichlid SKUs - drm/amdgpu: fix xclk freq on CHIP_STONEY - drm/amdgpu: change reserved vram info print - drm/amd/pm: Fix power context allocation in SMU13 - drm/amd/display: Reduce sdp bw after urgent to 90% - wifi: iwlwifi: mvm: Fix -Warray-bounds bug in iwl_mvm_wait_d3_notif() - can: j1939: j1939_sk_send_loop_abort(): improved error queue handling in J1939 Socket - can: j1939: change j1939_netdev_lock type to mutex - can: j1939: avoid possible use-after-free when j1939_can_rx_register fails - mptcp: only send RM_ADDR in nl_cmd_remove - mptcp: add address into userspace pm list - mptcp: update userspace pm infos - ceph: fix use-after-free bug for inodes when flushing capsnaps - [s390x] dasd: Use correct lock while counting channel queue length - Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk - Bluetooth: fix debugfs registration - Bluetooth: hci_qca: fix debugfs registration - rbd: move RBD_OBJ_FLAG_COPYUP_ENABLED flag setting - rbd: get snapshot context after exclusive lock is ensured to be held - virtio_net: use control_buf for coalesce params - [arm64] pinctrl: meson-axg: add missing GPIOA_18 gpio group - usb: usbfs: Enforce page requirements for mmap - usb: usbfs: Use consistent mmap functions - [arm64] dts: imx8qm-mek: correct GPIOs for USDHC2 CD and WP signals - [arm*] ASoC: simple-card-utils: fix PCM constraint error check - blk-mq: fix blk_mq_hw_ctx active request accounting - [arm64] dts: imx8mn-beacon: Fix SPI CS pinmux - [arm*] i2c: mv64xxx: Fix reading invalid status value in atomic mode - soundwire: stream: Add missing clear of alloc_slave_rt - vhost: support PACKED when setting-getting vring_base - ksmbd: fix out-of-bound read in deassemble_neg_contexts() - ksmbd: fix out-of-bound read in parse_lease_state() - ksmbd: check the validation of pdu_size in ksmbd_conn_handler_loop - ext4: only check dquot_initialize_needed() when debugging - wifi: rtw89: correct PS calculation for SUPPORTS_DYNAMIC_PS - wifi: rtw88: correct PS calculation for SUPPORTS_DYNAMIC_PS https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.35 - [amd64] x86/head/64: Switch to KERNEL_CS as soon as new GDT is installed - cgroup: bpf: use cgroup_lock()/cgroup_unlock() wrappers - cgroup: always put cset in cgroup_css_set_put_fork - cgroup: fix missing cpus_read_{lock,unlock}() in cgroup_transfer_tasks() - EDAC/qcom: Get rid of hardcoded register offsets - ksmbd: validate smb request protocol id - of: overlay: Fix missing of_node_put() in error case of init_overlay_changeset() - power: supply: bq27xxx: Use mod_delayed_work() instead of cancel() + schedule() - [armhf] dts: vexpress: add missing cache properties - power: supply: Ratelimit no data debug output - PCI/DPC: Quirk PIO log size for Intel Ice Lake Root Ports - [x86] platform/x86: asus-wmi: Ignore WMI events with codes 0x7B, 0xC0 - regulator: Fix error checking for debugfs_create_dir - [arm64,armhf] irqchip/gic-v3: Disable pseudo NMIs on Mediatek devices w/ firmware issues - [arm64,armhf] irqchip/meson-gpio: Mark OF related data as maybe unused - power: supply: Fix logic checking if system is running from battery - drm: panel-orientation-quirks: Change Air's quirk to support Air Plus - btrfs: scrub: try harder to mark RAID56 block groups read-only - btrfs: handle memory allocation failure in btrfs_csum_one_bio - ASoC: soc-pcm: test if a BE can be prepared - [mips*] unhide PATA_PLATFORM - [mips*] Restore Au1300 support - [mips*] Move initrd_start check after initrd address sanitisation. - ASoC: cs35l41: Fix default regmap values for some registers - ASoC: dwc: move DMA init to snd_soc_dai_driver probe() - xen/blkfront: Only check REQ_FUA for writes - drm:amd:amdgpu: Fix missing buffer object unlock in failure path - io_uring: unlock sqd->lock before sq thread release CPU - NVMe: Add MAXIO 1602 to bogus nid list. - [arm64,armhf] irqchip/gic: Correctly validate OF quirk descriptors - wifi: cfg80211: fix locking in regulatory disconnect - wifi: cfg80211: fix double lock bug in reg_wdev_chan_valid() - epoll: ep_autoremove_wake_function should use list_del_init_careful - ocfs2: fix use-after-free when unmounting read-only filesystem - ocfs2: check new file size on fallocate call - zswap: do not shrink if cgroup may not zswap - nilfs2: fix incomplete buffer cleanup in nilfs_btnode_abort_change_key() - nilfs2: fix possible out-of-bounds segment allocation in resize ioctl - nilfs2: reject devices with insufficient block count - io_uring/net: save msghdr->msg_control for retries - kexec: support purgatories with .text.hot sections - [x86] purgatory: remove PGO flags - [powerpc*] purgatory: remove PGO flags - btrfs: do not ASSERT() on duplicated global roots - btrfs: fix iomap_begin length for nocow writes - btrfs: can_nocow_file_extent should pass down args->strict from callers - ALSA: usb-audio: Fix broken resume due to UAC3 power state - ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback - dm thin metadata: check fail_io before using data_sm - dm thin: fix issue_discard to pass GFP_NOIO to __blkdev_issue_discard - net: ethernet: stmicro: stmmac: fix possible memory leak in __stmmac_open - nouveau: fix client work fence deletion race - RDMA/uverbs: Restrict usage of privileged QKEYs - drm/amdgpu: vcn_4_0 set instance 0 init sched score to 1 - net: usb: qmi_wwan: add support for Compal RXM-G1 - drm/amd/display: edp do not add non-edid timings - drm/amd: Make sure image is written to trigger VBIOS image update flow - drm/amd: Tighten permissions on VBIOS flashing attributes - drm/amd/pm: workaround for compute workload type on some skus - drm/amdgpu: add missing radeon secondary PCI ID - ALSA: hda/realtek: Add a quirk for Compaq N14JP6 - [x86] thunderbolt: Do not touch CL state configuration during discovery - [x86] thunderbolt: dma_test: Use correct value for absent rings when creating paths - [x86] thunderbolt: Mask ring interrupt on Intel hardware as well - USB: serial: option: add Quectel EM061KGL series - usb: typec: ucsi: Fix command cancellation - usb: typec: Fix fast_role_swap_current show function - usb: gadget: udc: core: Offload usb_udc_vbus_handler processing - usb: gadget: udc: core: Prevent soft_connect_store() race - [arm64] USB: dwc3: qcom: fix NULL-deref on suspend - [arm64,armhf] USB: dwc3: fix use-after-free on core driver unbind - [arm64,armhf] usb: dwc3: gadget: Reset num TRBs before giving back the request - RDMA/rxe: Fix packet length checks - RDMA/rxe: Fix ref count error in check_rkey() - spi: cadence-quadspi: Add missing check for dma_set_mask - [arm64] spi: fsl-dspi: avoid SCK glitches with continuous transfers - netfilter: nf_tables: integrate pipapo into commit protocol - netfilter: nfnetlink: skip error delivery on batch in case of ENOMEM - ice: Fix XDP memory leak when NIC is brought up and down - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE (CVE-2023-3390) - [arm64] net: enetc: correct the indexes of highest and 2nd highest TCs - ping6: Fix send to link-local addresses with VRF. - igb: Fix extts capture value format for 82580/i354/i350 - net/sched: simplify tcf_pedit_act - net/sched: act_pedit: remove extra check for key type - net/sched: act_pedit: Parse L3 Header for L4 offset - net/sched: cls_u32: Fix reference counter leak leading to overflow - wifi: mac80211: fix link activation settings order - wifi: cfg80211: fix link del callback to call correct handler - wifi: mac80211: take lock before setting vif links - RDMA/rxe: Removed unused name from rxe_task struct - RDMA/rxe: Fix the use-before-initialization error of resp_pkts - iavf: remove mask from iavf_irq_enable_queues() - RDMA/mlx5: Initiate dropless RQ for RAW Ethernet functions - RDMA/mlx5: Create an indirect flow table for steering anchor - RDMA/cma: Always set static rate to 0 for RoCE - IB/uverbs: Fix to consider event queue closing also upon non-blocking mode - RDMA/mlx5: Fix affinity assignment - IB/isert: Fix dead lock in ib_isert - IB/isert: Fix possible list corruption in CMA handler - IB/isert: Fix incorrect release of isert connection - net: ethtool: correct MAX attribute value for stats - ipvlan: fix bound dev checking for IPv6 l3s mode - sctp: fix an error code in sctp_sf_eat_auth() - igc: Clean the TX buffer and TX descriptor ring - igc: Fix possible system crash when loading module - igb: fix nvm.ops.read() error handling - net: phylink: report correct max speed for QUSGMII - net: phylink: use a dedicated helper to parse usgmii control word - drm/nouveau: don't detect DSM for non-NVIDIA device - [arm64] drm/bridge: ti-sn65dsi86: Avoid possible buffer overflow - drm/nouveau/dp: check for NULL nv_connector->native_mode - drm/nouveau: add nv_encoder pointer check for NULL - sched: add new attr TCA_EXT_WARN_MSG to report tc extact message - net/sched: Refactor qdisc_graft() for ingress and clsact Qdiscs - net/sched: qdisc_destroy() old ingress and clsact Qdiscs before grafting - cifs: fix lease break oops in xfstest generic/098 - ext4: drop the call to ext4_error() from ext4_get_group_info() - net/sched: cls_api: Fix lockup on flushing explicitly created chain - [arm64] net: dsa: felix: fix taprio guard band overflow at 10Mbps with jumbo frames - net: macsec: fix double free of percpu stats - sfc: fix XDP queues mode with legacy IRQ - dm: don't lock fs when the map is NULL during suspend or resume - net: tipc: resize nlattr array to correct size - afs: Fix vlserver probe RTT handling - rcu/kvfree: Avoid freeing new kfree_rcu() memory after old grace period - drm/amdgpu: Don't set struct drm_driver.output_poll_changed - net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy - Revert "net/sched: act_api: move TCA_EXT_WARN_MSG to the correct hierarchy" - net/sched: act_api: add specific EXT_WARN_MSG for tc action - neighbour: delete neigh_lookup_nodev as not used - scsi: target: core: Fix error path in target_setup_session() - [mips*] Move '-Wa,-msoft-float' check from as-option to cc-option - [mips*] Prefer cc-option for additions to cflags - kbuild: Update assembler calls to use proper flags and language target https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.36 - drm/amd/display: Use dc_update_planes_and_stream - drm/amd/display: Add wrapper to call planes and stream update - drm/amd/display: fix the system hang while disable PSR - [arm64] tty: serial: fsl_lpuart: make rx_watermark configurable for different platforms - [arm64] tty: serial: fsl_lpuart: reduce RX watermark to 0 on LS1028A - ata: libata-scsi: Avoid deadlock on rescan after device resume - mm: Fix copy_from_user_nofault(). (Closes: #1033398) - tpm, tpm_tis: Claim locality in interrupt handler - tpm_crb: Add support for CRB devices based on Pluton - ksmbd: validate command payload size - ksmbd: fix out-of-bound read in smb2_write - ksmbd: validate session id and tree id in the compound request - tick/common: Align tick period during sched_timer setup (Closes: #1038754) - writeback: fix dereferencing NULL mapping->host on writeback_page_template - nilfs2: fix buffer corruption due to concurrent device reads - [x86] ACPI: sleep: Avoid breaking S3 wakeup due to might_sleep() - KVM: Avoid illegal stage2 mapping on invalid memory slot - Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails - Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs - PCI: hv: Fix a race condition bug in hv_pci_query_relations() - Revert "PCI: hv: Fix a timing issue which causes kdump to fail occasionally" - PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev - PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic - PCI: hv: Add a per-bus mutex state_lock - io_uring/net: clear msg_controllen on partial sendmsg retry - io_uring/net: disable partial retries for recvmsg with cmsg - mptcp: handle correctly disconnect() failures - mptcp: fix possible divide by zero in recvmsg() - mptcp: fix possible list corruption on passive MPJ - mptcp: consolidate fallback and non fallback state machine - cgroup: Do not corrupt task iteration when rebinding subsystem - cgroup,freezer: hold cpu_hotplug_lock before freezer_mutex in freezer_css_{online,offline}() - [arm64] mmc: sdhci-msm: Disable broken 64-bit DMA on MSM8916 - [arm64] mmc: meson-gx: remove redundant mmc_request_done() call from irq context - [arm64,armhf] mmc: mmci: stm32: fix max busy timeout calculation - [arm64,armhf] mmc: bcm2835: fix deferred probing - [arm64,armhf] mmc: sunxi: fix deferred probing - bpf: ensure main program has an extable - wifi: iwlwifi: pcie: Handle SO-F device for PCI id 0x7AF0 - io_uring/poll: serialize poll linked timer start with poll removal - nilfs2: prevent general protection fault in nilfs_clear_dirty_page() - [x86] mm: Avoid using set_pgd() outside of real PGD pages - memfd: check for non-NULL file_seals in memfd_create() syscall - [arm64] mmc: meson-gx: fix deferred probing - ieee802154: hwsim: Fix possible memory leaks - xfrm: Treat already-verified secpath entries as optional - xfrm: interface: rename xfrm_interface.c to xfrm_interface_core.c - xfrm: Ensure policies always checked on XFRM-I input path - [arm64] KVM: arm64: PMU: Restore the host's PMUSERENR_EL0 - bpf: track immediate values written to stack by BPF_ST instruction - bpf: Fix verifier id tracking of scalars on spill - xfrm: fix inbound ipv4/udp/esp packets to UDPv6 dualstack sockets - bpf: Fix a bpf_jit_dump issue for x86_64 with sysctl bpf_jit_enable. - xfrm: Linearize the skb after offloading if needed. - net/mlx5: DR, Fix wrong action data allocation in decap action - sfc: use budget for TX completions - [armel,armhf] mmc: mvsdio: fix deferred probing - [armhf] mmc: omap: fix deferred probing - [armhf] mmc: omap_hsmmc: fix deferred probing - mmc: sdhci-acpi: fix deferred probing - ipvs: align inner_mac_header for encapsulation - be2net: Extend xmit workaround to BE3 chip - netfilter: nf_tables: fix chain binding transaction logic - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: drop map element references from preparation phase - netfilter: nft_set_pipapo: .walk does not deal with generations - netfilter: nf_tables: disallow element updates of bound anonymous sets - netfilter: nf_tables: reject unbound anonymous set before commit phase - netfilter: nf_tables: reject unbound chain set before commit phase - netfilter: nf_tables: disallow updates of anonymous sets - netfilter: nfnetlink_osf: fix module autoload - Revert "net: phy: dp83867: perform soft reset and retain established link" - bpf/btf: Accept function names that contain dots - bpf: Force kprobe multi expected_attach_type for kprobe_multi link - io_uring/net: use the correct msghdr union member in io_sendmsg_copy_hdr - sch_netem: acquire qdisc lock in netem_change() - revert "net: align SO_RCVMARK required privileges with SO_MARK" - [arm64] dts: rockchip: fix nEXTRST on SOQuartz - gpiolib: Fix GPIO chip IRQ initialization restriction - gpiolib: Fix irq_domain resource tracking for gpiochip_irqchip_add_domain() - scsi: target: iscsi: Prevent login threads from racing between each other - HID: wacom: Add error check to wacom_parse_and_register() - smb3: missing null check in SMB2_change_notify - media: cec: core: disable adapter in cec_devnode_unregister - media: cec: core: don't set last_initiator if tx in progress - nfcsim.c: Fix error checking for debugfs_create_dir - btrfs: fix an uninitialized variable warning in btrfs_log_inode - [i386] usb: gadget: udc: fix NULL dereference in remove() - nvme: double KA polling frequency to avoid KATO with TBKAS on - nvme: check IO start time when deciding to defer KA - nvme: improve handling of long keep alives - [x86] Input: soc_button_array - add invalid acpi_index DMI quirk handling - [s390x] cio: unregister device when the only path is gone - [arm*] ASoC: simple-card: Add missing of_node_put() in case of error - soundwire: dmi-quirks: add new mapping for HP Spectre x360 - soundwire: qcom: add proper error paths in qcom_swrm_startup() - [x86] ASoC: nau8824: Add quirk to active-high jack-detect - [x86] ASoC: amd: yc: Add Thinkpad Neo14 to quirks list for acp6x - gfs2: Don't get stuck writing page onto itself under direct I/O - [arm64] ASoC: fsl_sai: Enable BCI bit if SAI works on synchronous mode with BYP asserted - ALSA: hda/realtek: Add "Intel Reference board" and "NUC 13" SSID in the ALC256 - i2c: mchp-pci1xxxx: Avoid cast to incompatible function type - null_blk: Fix: memory release when memory_backed=1 - drm/radeon: fix race condition UAF in radeon_gem_set_domain_ioctl - vhost_net: revert upend_idx only on retriable error - [arm64] KVM: arm64: Restore GICv2-on-GICv3 functionality - [x86] apic: Fix kernel panic when booting with intremap=off and x2apic_phys - [arm64] i2c: imx-lpi2c: fix type char overflow issue when calculating the clock cycle - smb: move client and server files to common directory fs/smb https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.37 - mm/mmap: Fix error path in do_vmi_align_munmap() - mm/mmap: Fix error return in do_vmi_align_munmap() - mptcp: ensure listener is unhashed before updating the sk status - mm, hwpoison: try to recover from copy-on write faults - mm, hwpoison: when copy-on-write hits poison, take page offline - [x86] microcode/AMD: Load late on both threads too - [x86] smp: Make stop_other_cpus() more robust - [x86] smp: Dont access non-existing CPUID leaf - [x86] smp: Remove pointless wmb()s from native_stop_other_cpus() - [x86] smp: Use dedicated cache-line for mwait_play_dead() - [x86] smp: Cure kexec() vs. mwait_play_dead() breakage - can: isotp: isotp_sendmsg(): fix return error fix on TX path - maple_tree: fix potential out-of-bounds access in mas_wr_end_piv() - mm: introduce new 'lock_mm_and_find_vma()' page fault helper - mm: make the page fault mmap locking killable - [arm64] mm: Convert to using lock_mm_and_find_vma() - [powerpc*] mm: Convert to using lock_mm_and_find_vma() - [mips*] mm: Convert to using lock_mm_and_find_vma() - [armhf] mm: Convert to using lock_mm_and_find_vma() - mm/fault: convert remaining simple cases to lock_mm_and_find_vma() - [powerpc*] mm: convert coprocessor fault to lock_mm_and_find_vma() - mm: make find_extend_vma() fail if write lock not held - execve: expand new process stack manually ahead of time - mm: always expand the stack with the mmap write lock held - fbdev: fix potential OOB read in fast_imageblit() - HID: hidraw: fix data race on device refcount - HID: wacom: Use ktime_t rather than int when dealing with timestamps - HID: logitech-hidpp: add HIDPP_QUIRK_DELAYED_INIT for the T651. (Closes: #1038271) . [ Salvatore Bonaccorso ] * d/salsa-ci.yml: Update for bookworm: Set RELEASE to bookworm * d/rules.real: Fix typo in setup_image target. * [amd64,arm64] drivers/virtio: Enable VIRTIO_MEM as module (Closes: #1038665) * Bump ABI to 10 * [rt] Update to 6.1.33-rt11 * Revert "drm/amd/display: edp do not add non-edid timings" . [ Cyril Brulebois ] * udeb: Add r8188eu to nic-wireless-modules (Closes: #1035824) . [ Ben Hutchings ] * Add pkg.linux.mintools profile for building minimal userland tools * d/b/test-patches: Build linux-{kbuild,bootwrapper} packages (Closes: #871216, #1035359) mailman3 (3.3.8-2~deb12u1) bookworm; urgency=medium . * Bookworm-pu of 4 bug fixes marco (1.26.1-3+deb12u1) bookworm; urgency=medium . * debian/patches: + Add 0004_show-correct-window-title-when-owned-by-superuser.patch. Fix window titles sometimes shown incorrectly when owned as root. This affects mostly KDE apps if they are run on MATE. (Closes: #1040752). mate-control-center (1.26.0-2+deb12u1) bookworm; urgency=medium . [ Martin Wimpress ] * debian/patches: + Add 2002-remove_obsolete_lock_button.patch (LP: #1955339) . [ Mike Gabriel ] * debian/patches: + Add various memleak fix patches (0007, 0008, 0009, 0010, 0011, 0013, 0014, + 0016 and 0017). Cherry-picked from 1.26.1 upstream release. (Closes: #1040019). mate-power-manager (1.26.0-2+deb12u1) bookworm; urgency=medium . * debian/patches: + Add 0002_gpm-statistics-fix-memory-leak.patch (gpm-prefs: fix memory leak) and 0003_gpm-prefs-fix-memory-leak.patch (gpm-statistics: fix memory leak). Cherry-picked and simplified from v1.26.1. (Closes: #1038444). + Document simplification in patch 0002_gpm-statistics-fix-memory- leak.patch. + Trivial rebase of 0001_add-gaming-input-devices.patch. mate-session-manager (1.26.0-1+deb12u1) bookworm; urgency=medium . * debian/patches: + Add 0007_Fix-memory-leaks-284.patch and 0008_mate-session-fix-memory- leak.patch. Fix various memory leaks. (Closes: #1038638). + Cherry-pick 0009_main-fix-double-free-on-gl_renderer.patch from upstream's 1.26 branch. Regression fix for 0008_mate-session-fix-memory-leak.patch. * debian/default-settings/X11/Xsession.d/99mate-environment: + Allow clutter backends other than x11 (while preferring x11). (Closes: #954783). mediawiki (1:1.39.4-1~deb12u1) bookworm-security; urgency=medium . [ Taavi Väänänen ] * New upstream version 1.39.4, fixing CVE-2023-29141, CVE-2023-36674 and CVE-2023-36675. * The bundled guzzlehttp/guzzle library was updated to 2.4.5 to fix CVE-2023-29197. * Update config for the bookworm branch. . [ Kunal Mehta ] * Set Breaks/Replaces for mediawiki-extensions-math (Closes: #1039075) minidlna (1.3.0+dfsg-2.2+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * upnphttp: Fix chunk length parsing (CVE-2023-33476) (Closes: #1037052) multipath-tools (0.9.4-3+deb12u1) bookworm; urgency=medium . * [cfa5138] Re-add dm-multipath module loading to ExecStartPre (Closes: #1037292) * [1289691] Fail package build if udev rules are missing * [2e45796] Install udev mulitpath.rules again. Thanks to Joshua Huber (Closes: #1037539) * [6b05510] debian/gbp.conf: update branch for bookworm mutter (43.6-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm . mutter (43.6-1) unstable; urgency=medium . * New upstream stable release 43.5 - Always update surfaces belonging to a window that is being recorded or included in a screencast, even if the window is not visible on a local display (mutter#2538, mutter!2789) - Export previously-private meta_window_has_pointer(), needed by screenshot UI fixes in gnome-shell 43.5 (mutter!2928) + d/libmutter-11-0.symbols: Update to add that symbol - All other changes were already present in 43.4-2 * New upstream stable release 43.6 - Fix a resource leak when a compositor view is destroyed (mutter!2991) - Fix a crash when headless gdm greeter via gnome-remote-desktop attempts to blank the screen (mutter#2841) * d/patches: Drop patches that were applied upstream * d/p/wayland-outputs-Fix-potential-crash-when-output-has-no-mo.patch: Backport patch from 44~beta to fix a crash during suspend/resume on some systems (mutter#2570, Closes: #1036268) network-manager-strongswan (1.6.0-1+deb12u1) bookworm; urgency=medium . [ Harald Dunkel ] * Build editor component with GTK 4, too (fix provided by Moritz Schlarb) (Closes: #1020495, #1036607) nfdump (1.7.1-2+deb12u1) bookworm; urgency=medium . * [8554dec3] Fix init script to return success when process has started. Thanks to Yury Shevchuk * [c9d7e789] Fix segfault in getopt parsing for -R (Closes: #1038644) * [eb140f97] d/gbp.conf: set debian branch nftables (1.0.6-2+deb12u1) bookworm; urgency=medium . * [7edf72e] d/patches: add 0001-debian-bug-1038724.patch (Closes: #1038724) This patch fixes a Debian 11 Bullseye -> Debian 12 Bookworm regression in set listing format, and makes the output consistent and predictable, bringing back the Debian Bullseye behavior. node-openpgp-seek-bzip (1.0.5-2+deb12u1) bookworm; urgency=medium . * Team upload * Fix seek-bzip install (Closes: #1040584) node-tough-cookie (4.0.0-2+deb12u1) bookworm; urgency=medium . * Team upload * Fix prototype pollution (Closes: CVE-2023-26136) node-undici (5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1) bookworm; urgency=medium . * Fix security issues (Closes: #1031418): - Protect "Host" HTTP header from CLRF injection (Closes: CVE-2023-23936) - Fix potential ReDoS on Headers.set and Headers.append (Closes: CVE-2023-24807) * Increase httpbin.org test timeout node-webpack (5.75.0+dfsg+~cs17.16.14-1+deb12u1) bookworm; urgency=medium . * Team upload * Avoid cross-realm objects (Closes: #1032904, CVE-2023-28154) nvidia-cuda-toolkit (11.8.0-5~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-cuda-toolkit (11.8.0-5) unstable; urgency=medium . * Fix nvidia-fs kernel module build for Linux 6.4. * Use a snapshot of openjdk-8-jre (8u372-ga-1). nvidia-graphics-drivers (525.125.06-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-graphics-drivers (525.125.06-1) unstable; urgency=medium . * New upstream production branch release 525.125.06 (2023-05-09). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039678) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 - Fixed a bug which prevented running a Wayland compositor in headless mode on GPUs without display hardware. . [ Andreas Beckmann ] * Update nv-readme.ids. . nvidia-graphics-drivers (525.116.04-1) unstable; urgency=medium . * New upstream production branch release 525.116.04 (2023-05-09). * New upstream production branch release 525.116.03 (2023-04-25). - Fixed a regression in Luxmark performance between 525.89.02 and 525.105.17. - Fixed a bug that could cause an unexpected VK_ERROR_NATIVE_WINDOW_IN_USE_KHR error in certain circumstances when recreating Vulkan surfaces. - Fixed a regression that caused brightness control to not vary smoothly across the range of values. * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. * Update nv-readme.ids. . nvidia-graphics-drivers (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-graphics-drivers (525.116.04-1) unstable; urgency=medium . * New upstream production branch release 525.116.04 (2023-05-09). * New upstream production branch release 525.116.03 (2023-04-25). - Fixed a regression in Luxmark performance between 525.89.02 and 525.105.17. - Fixed a bug that could cause an unexpected VK_ERROR_NATIVE_WINDOW_IN_USE_KHR error in certain circumstances when recreating Vulkan surfaces. - Fixed a regression that caused brightness control to not vary smoothly across the range of values. . [ Andreas Beckmann ] * Refresh patches. * Update nv-readme.ids. nvidia-graphics-drivers (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-graphics-drivers-tesla (525.125.06-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-graphics-drivers-tesla (525.125.06-1) unstable; urgency=medium . * New upstream production branch release 525.125.06 (2023-05-09). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039685) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 - Fixed a bug which prevented running a Wayland compositor in headless mode on GPUs without display hardware. . [ Andreas Beckmann ] * Update nv-readme.ids. . nvidia-graphics-drivers (525.125.06-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-graphics-drivers (525.125.06-1) unstable; urgency=medium . * New upstream production branch release 525.125.06 (2023-05-09). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039678) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 - Fixed a bug which prevented running a Wayland compositor in headless mode on GPUs without display hardware. . [ Andreas Beckmann ] * Update nv-readme.ids. . nvidia-graphics-drivers (525.116.04-1) unstable; urgency=medium . * New upstream production branch release 525.116.04 (2023-05-09). * New upstream production branch release 525.116.03 (2023-04-25). - Fixed a regression in Luxmark performance between 525.89.02 and 525.105.17. - Fixed a bug that could cause an unexpected VK_ERROR_NATIVE_WINDOW_IN_USE_KHR error in certain circumstances when recreating Vulkan surfaces. - Fixed a regression that caused brightness control to not vary smoothly across the range of values. * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. * Update nv-readme.ids. . nvidia-graphics-drivers-tesla (525.105.17-2) unstable; urgency=medium . * Rebuild as Tesla driver. . nvidia-graphics-drivers (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-graphics-drivers-tesla (525.105.17-2) unstable; urgency=medium . * Rebuild as Tesla driver. . nvidia-graphics-drivers (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-graphics-drivers-tesla-470 (470.199.02-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-graphics-drivers-tesla-470 (470.199.02-1) unstable; urgency=medium . * New upstream production branch release 470.199.02 (2023-06-26). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039684) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. . nvidia-graphics-drivers (470.199.02-1) bullseye; urgency=medium . * New upstream production branch release 470.199.02 (2023-06-26). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039678) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. * Upload to bullseye. . nvidia-graphics-drivers-tesla-470 (470.182.03-2) unstable; urgency=medium . * Backport vm_area_struct_has_const_vm_flags changes from 470.199.02 to fix kernel module build for Linux 6.3. (Closes: #1038004) * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. . nvidia-graphics-drivers-tesla-470 (470.182.03-1~deb11u1) bullseye; urgency=medium . * Rebuild for bullseye. nvidia-graphics-drivers-tesla-470 (470.199.02-1~deb11u1) bullseye; urgency=medium . * Rebuild for bullseye. . nvidia-graphics-drivers-tesla-470 (470.199.02-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-graphics-drivers-tesla-470 (470.199.02-1) unstable; urgency=medium . * New upstream production branch release 470.199.02 (2023-06-26). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039684) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. . nvidia-graphics-drivers (470.199.02-1) bullseye; urgency=medium . * New upstream production branch release 470.199.02 (2023-06-26). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039678) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 * Improved compatibility with recent Linux kernels. . [ Andreas Beckmann ] * Refresh patches. * Upload to bullseye. . nvidia-graphics-drivers-tesla-470 (470.182.03-2) unstable; urgency=medium . * Backport vm_area_struct_has_const_vm_flags changes from 470.199.02 to fix kernel module build for Linux 6.3. (Closes: #1038004) * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-graphics-drivers-tesla-470 (470.182.03-2) unstable; urgency=medium . * Backport vm_area_struct_has_const_vm_flags changes from 525.105.17 to fix kernel module build for Linux 6.3. (Closes: #1038004) * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-modprobe (535.54.03-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-modprobe (535.54.03-1) unstable; urgency=medium . * New upstream release. nvidia-open-gpu-kernel-modules (525.125.06-1~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-open-gpu-kernel-modules (525.125.06-1) unstable; urgency=medium . * New upstream production branch release 525.125.06 (2023-06-26). * Fixed CVE-2023-25515, CVE-2023-25516. (Closes: #1039686) https://nvidia.custhelp.com/app/answers/detail/a_id/5468 . nvidia-open-gpu-kernel-modules (525.116.04-1) unstable; urgency=medium . * New upstream production branch release 525.116.04 (2023-05-09). * New upstream production branch release 525.116.03 (2023-04-25). * Refresh patches. . nvidia-open-gpu-kernel-modules (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-open-gpu-kernel-modules (525.116.04-1) unstable; urgency=medium . * New upstream production branch release 525.116.04 (2023-05-09). * New upstream production branch release 525.116.03 (2023-04-25). * Refresh patches. nvidia-open-gpu-kernel-modules (525.105.17-2) unstable; urgency=medium . * Backport drm_driver_has_dumb_destroy changes from 525.116.03 to fix kernel module build for Linux 6.4. nvidia-support (20220217+3~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. . nvidia-support (20220217+3) unstable; urgency=medium . * nvidia-installer-cleanup: Add Breaks against obsolete nvidia-*-dkms packages from bullseye that are incompatible with the bookworm kernel. onionshare (2.6-5~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. openjdk-17 (17.0.7+7-1~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm openjdk-17 (17.0.7+7-1~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye openvpn (2.6.3-1+deb12u1) bookworm; urgency=medium . * Cherry-pick two bugfix commits from upstream - Memory leak in dco_get_peer_stats_multi for Linux - dangling pointer passed to pkcs11-helper * d/gbp.conf: set branch to bookworm pacemaker (2.1.5-1+deb12u1) bookworm; urgency=medium . * [0c22be8] New patches fixing migration regression. Backport of https://github.com/ClusterLabs/pacemaker/pull/3020/ to Pacemaker 2.1.5 (without the CTS changes, which we don't ship): 5754a2af9 Refactor: scheduler: improve xpath efficiency when unpacking 3f6f524f1 Low: scheduler: unknown_on_node() should ignore pending actions ad9fd9548 Fix: scheduler: handle cleaned migrate_from history correctly The starting refactor is required by the other two patches, but the third patch still needed backporting. Thanks to Ken Gaillot (Closes: #1040165) php8.2 (8.2.7-1~deb12u1) bookworm-security; urgency=high . * No change upload to bookworm-security postfix (3.7.6-0+deb12u2) bookworm; urgency=medium . * Correct regression that caused postfix set-permissions to fail (Closes: #1040329) - Restore and update debian/patches/05_debian_manpage_differences.diff - Restore and update debian/patches/05_debian_readme_differences.diff * Update autopkgtest to test postfix set-permissions postfix (3.7.6-0+deb12u1) bookworm; urgency=medium . [Scott Kitterman] . * Refresh patches . [Wietse Venema] . * 3.7.6 - Bugfix (defect introduced: Postfix 1.0): the command "postconf .. name=v1 .. name=v2 .." (multiple instances of the same parameter name) created multiple name=value entries with the same parameter name. It now logs a warning and skips the earlier update. Found during code maintenance. File: postconf/postconf_edit.c . - Bugfix (defect introduced: Postfix 3.3): the command "postconf -M name1/type1='name2 type2 ...'" died with a segmentation violation when the request matched multiple master.cf entries. The master.cf file was not damaged. Problem reported by SATOH Fumiyasu. File: postconf/postconf_master.c. . - Bugfix (defect introduced: Postfix 2.11): the command "postconf -M name1/type1='name2 type2 ...'" could add a service definition to master.cf that conflicted with an already existing service definition. It now replaces all existing service definitions that match the service pattern 'name1/type1' or the service name and type in 'name2 type2 ...' with a single service definition 'name2 type2 ...'. Problem reported by SATOH Fumiyasu. File: postconf/postconf_edit.c. . - Bitrot: preliminary support for OpenSSL configuration files, primarily OpenSSL 1.1.1b and later. This introduces new parameters "tls_config_file" and "tls_config_name", which can be used to limit collateral damage from OS distributions that crank up security to 11, increasing the number of plaintext email deliveries. Details are in the postconf(5) manpage under "tls_config_file" and "tls_config_name". Viktor Dukhovni. Files: mantools/postlink, proto/postconf.proto, global/mail_params.h, posttls-finger/posttls-finger.c, smtp/smtp.c, smtp/smtp_proto.c, tls/tls_client.c, tls/tls.h, tls/tls_misc.c, tls/tls_proxy_client_print.c, tls/tls_proxy_client_scan.c, tls/tls_proxy.h, tls/tls_server.c, tlsproxy/tlsproxy.c. . - Cleanup: use TLS_CLIENT_PARAMS to pass the OpensSSL 'init' configurations. This information is independent from the client or server TLS context, and therefore does not belong in tls_*_init() or tls_*_start() calls. The tlsproxy(8) server uses TLS_CLIENT_PARAMS to report differences between its own global TLS settings, and those from its clients. Files: posttls-finger/posttls-finger.c, smtp/smtp.c, smtp/smtp_proto.c, tls/tls.h, tls/tls_proxy_client_misc.c, tls/tls_proxy_client_print.c, tls/tls_proxy_client_scan.c, tls/tls_proxy.h, tlsproxy/tlsproxy.c. . - Cleanup: reverted cosmetic-only changes to minimize the patch footprint for OpenSSL INI file support; updated daemon manpages with the new tls_config_file and tls_config_name configuration parameters. Files: smtp/smtp.c, smtpd/smtpd.c, tls/tls_client.c, tls/tls.h, tls/tls_server.c, tlsproxy/tlsproxy.c, . - Cleanup: made OpenSSL 'default' INI file support error handling consistent with OpenSSL default behavior. Viktor Dukhovni. Files: proto/postconf.proto, tls/tls_misc.c. . - Backwards compatibility for stable releases that originally had no OpenSSL INI support. Skip the new OpenSSL INI support code, unless the Postfix configuration actually specifies non-default tls_config_xxx settings. File: tls/tls_misc.c. . - Cleanup: added a multiple initialization guard in the tls_library_init() function, and made an initialization error sticky. File: tls/tls_misc.c. . - Security: new parameter smtpd_forbid_unauth_pipelining (default: no) to disconnect remote SMTP clients that violate RFC 2920 (or 5321) command pipelining constraints. Files: global/mail_params.h, smtpd/smtpd.c, proto/postconf.proto. proftpd-dfsg (1.3.8+dfsg-4+deb12u1) bookworm; urgency=medium . * Now do not enable proftpd.socket to avoid conflicts at boot time. (Closes: #1038416) * Introduced a new prerm script to manage stop of service/socket before remove. * Added an entry to NEWS file to explain the change in unit files and how to deal with changes. * Revised README.Debian to reflect changes in unit file management. qemu (1:7.2+dfsg-7+deb12u1) bookworm; urgency=medium . * d/rules: add the forgotten --enable-libusb for the xen build. This makes usb devices available for xen hvm domUs again, as it has always been before. Closes: #1037341 * update to upstream 7.2.3 stable/bugfix release, v7.2.3.diff, https://gitlab.com/qemu-project/qemu/-/commits/v7.2.3 : - vnc: avoid underflow when accessing user-provided address - target/i386: Change wrong XFRM value in SGX CPUID leaf (was in debian already) - acpi: pcihp: allow repeating hot-unplug requests - qemu-options: finesse the recommendations around -blockdev - docs/about/deprecated.rst: Add "since 7.1" tag to dtb-kaslr-seed deprecation - target/arm: Initialize debug capabilities only once - hw/net/msf2-emac: Don't modify descriptor in-place in emac_store_desc() - hw/arm/boot: Make write_bootloader() public as arm_write_bootloader() - hw/arm/aspeed: Use arm_write_bootloader() to write the bootloader - hw/arm/raspi: Use arm_write_bootloader() to write boot code - hw/intc/allwinner-a10-pic: Don't use set_bit()/clear_bit() - target/arm: Define and use new load_cpu_field_low32() - hw/sd/allwinner-sdhost: Correctly byteswap descriptor fields - hw/net/allwinner-sun8i-emac: Correctly byteswap descriptor fields - softfloat: Fix the incorrect computation in float32_exp2 - meson: leave unnecessary modules out of the build - block: Fix use after free in blockdev_mark_auto_del() - target/riscv: Fix itrigger when icount is used - accel/tcg: Fix atomic_mmu_lookup for reads - ui: Fix pixel colour channel order for PNG screenshots - async: Suppress GCC13 false positive in aio_bh_poll() - tcg: ppc64: Fix mask generation for vextractdm - hw/virtio/vhost-user: avoid using uninitialized errp - virtio: fix reachable assertion due to stale value of cached region size - block/monitor: Fix crash when executing HMP commit - target/s390x: Fix EXECUTE of relative branches - s390x/tcg: Fix LDER instruction format - 9pfs/xen: Fix segfault on shutdown - xen/pt: reserve PCI slot 2 for Intel igd-passthru - Revert "vhost-user: Monitor slave channel in vhost_user_read()" - Revert "vhost-user: Introduce nested event loop in vhost_user_read()" - target/ppc: Fix helper_pminsn() prototype - tests/docker: bump the xtensa base to debian:11-slim - linux-user: Fix mips fp64 executables loading - linux-user: fix getgroups/setgroups allocations (was in debian already) - migration: Handle block device inactivation failures better - migration: Minor control flow simplification - migration: Attempt disk reactivation in more failure scenarios - target/arm: Fix vd == vm overlap in sve_ldff1_z - scsi-generic: fix buffer overflow on block limits inquiry - target/i386: fix operand size for VCOMI/VUCOMI instructions - target/i386: fix avx2 instructions vzeroall and vpermdq - vhost: fix possible wrap in SVQ descriptor ring - virtio-net: not enable vq reset feature unconditionally - virtio-crypto: fix NULL pointer dereference in virtio_crypto_free_request - e1000: Count CRC in Tx statistics - e1000e: Fix tx/rx counters - rtl8139: fix large_send_mss divide-by-zero (was in debian already) - util/vfio-helpers: Use g_file_read_link() - usb/ohci: Set pad to 0 after frame update - hw/scsi/lsi53c895a: Fix reentrancy issues in the LSI controller (Closes: #1029155, CVE-2023-0330) - machine: do not crash if default RAM backend name has been stolen - Update version for 7.2.3 release * update to upstream 7.2.4 stable/bugfix release, v7.2.4.diff, https://gitlab.com/qemu-project/qemu/-/commits/v7.2.4 : - gitlab-ci: Avoid to re-run "configure" in the device-crash-test jobs - scripts/device-crash-test: Add a parameter to run with TCG only - hw/ppc/prep: Fix wiring of PIC -> CPU interrupt - ui/gtk: fix passing y0_top parameter to scanout - ui/gtk: use widget size for cursor motion event - ui/gtk-egl: fix scaling for cursor position in scanout mode - ui/sdl2: fix surface_gl_update_texture: Assertion 'gls' failed - ui/sdl2: Grab Alt+Tab also in fullscreen mode - ui/sdl2: Grab Alt+F4 also under Windows - ui/sdl2: disable SDL_HINT_GRAB_KEYBOARD on Windows - hw/dma/xilinx_axidma: Check DMASR.HALTED to prevent infinite loop. - hw/arm/xlnx-zynqmp: fix unsigned error when checking the RPUs number - target/arm: Explicitly select short-format FSR for M-profile - target/s390x: Fix LCBB overwriting the top 32 bits - tests/tcg/s390x: Test LCBB - target/s390x: Fix LOCFHR taking the wrong half of R2 - tests/tcg/s390x: Test LOCFHR - linux-user/s390x: Fix single-stepping SVC - tests/tcg/s390x: Test single-stepping SVC - s390x/tcg: Fix CPU address returned by STIDP - docs: fix multi-process QEMU documentation - qga: Fix suspend on Linux guests without systemd - 9pfs: prevent opening special files (CVE-2023-2861) - hw/remote: Fix vfu_cfg trace offset format - vnc: move assert in vnc_worker_thread_loop - target/ppc: Fix lqarx to set cpu_reserve - target/ppc: Fix nested-hv HEAI delivery - target/ppc: Fix PMU hflags calculation - hw/riscv: qemu crash when NUMA nodes exceed available CPUs - aspeed/hace: Initialize g_autofree pointer - target/arm: Fix return value from LDSMIN/LDSMAX 8/16 bit atomics - target/arm: Return correct result for LDG when ATA=0 - hw/intc/allwinner-a10-pic: Handle IRQ levels other than 0 or 1 - hw/timer/nrf51_timer: Don't lose time when timer is queried in tight loop - host-utils: Avoid using __builtin_subcll on buggy versions of Apple Clang - pc-bios/keymaps: Use the official xkb name for Arabic layout, not the legacy synonym - target/hppa: Fix OS reboot issues - target/hppa: Provide qemu version via fw_cfg to firmware - target/hppa: New SeaBIOS-hppa version 7 (minus the binary pc-bios/hppa-firmware.img changes) - target/hppa: Update to SeaBIOS-hppa version 8 (minus the binary pc-bios/hppa-firmware.img changes) - vhost: release memory_listener object in error path - vdpa: fix not using CVQ buffer in case of error - vhost-vdpa: do not cleanup the vdpa/vhost-net structures if peer nic is present - virtio-gpu: Make non-gl display updates work again when blob=true - icount: don't adjust virtual time backwards after warp - vdpa: mask _F_CTRL_GUEST_OFFLOADS for vhost vdpa devices - target/ppc: Fix decrementer time underflow and infinite timer loop - vfio/pci: Fix a segfault in vfio_realize - vfio/pci: Call vfio_prepare_kvm_msi_virq_batch() in MSI retry path - ui/gtk: set the area of the scanout texture correctly - Update version for 7.2.4 release * remove patches included in v7.2.4: - linux-user-fix-getgroups-setgroups-allocations.patch - rtl8139-fix-large_send_mss-divide-by-zero.patch - target_i386-Change-wrong-XFRM-value.patch request-tracker5 (5.0.3+dfsg-3~deb12u1) bookworm; urgency=medium . * Rebuild for bookworm. rime-cantonese (0.0~git20230209.e0295fa-2~deb12u1) bookworm; urgency=medium . * Upload fix to Debian Bookworm. rime-luna-pinyin (0.0~git20230204.79aeae2-3~deb12u1) bookworm; urgency=medium . * Upload to Debian Bookworm. samba (2:4.17.9+dfsg-0+deb12u3) bookworm; urgency=medium . * +fix-unsupported-netr_LogonGetCapabilities-l2.patch Fix windows logon/trust issues with 2023-07 windows updates: https://bugzilla.samba.org/show_bug.cgi?id=15418 samba (2:4.17.9+dfsg-0+deb12u3~bpo11+1) bullseye-backports; urgency=medium . * Rebuild for bullseye-backports. samba (2:4.17.9+dfsg-0+deb12u2) bookworm; urgency=medium . * link with -latomic explicitly on a few architectures where gcc misses it (notable armel & mipsel), to fix FTBFS there, - the same as on sid. https://gcc.gnu.org/bugzilla/show_bug.cgi?id=81358 samba (2:4.17.9+dfsg-0+deb12u1) bookworm-proposed-updates; urgency=medium . * d/copyright: filter out autogenerated manpages from the upstream source when dfsg-repacking. The manpages are generated during build if not up to date, and changes significantly in every upstream release since the version number and the release date are included in every manpage. * new upstream stable/bugfix release, with the following fixes: * https://bugzilla.samba.org/show_bug.cgi?id=14030 named crashes on DLZ zone update (this was in debian in previous upload) * https://bugzilla.samba.org/show_bug.cgi?id=15275 smbd_scavenger crashes when service smbd is stopped * https://bugzilla.samba.org/show_bug.cgi?id=15361 winbind recurses into itself via rpcd_lsad * https://bugzilla.samba.org/show_bug.cgi?id=15374 aes256 smb3 encryption algorithms are not allowed in smb3_sid_parse() * https://bugzilla.samba.org/show_bug.cgi?id=15378 vfs_fruit might cause a failing open for delete * https://bugzilla.samba.org/show_bug.cgi?id=15382 cli_list loops 100% CPU against pre-lanman2 servers * https://bugzilla.samba.org/show_bug.cgi?id=15391 smbclient leaks fds with showacls * https://bugzilla.samba.org/show_bug.cgi?id=15403 smbget memory leak if failed to download files recursively * https://bugzilla.samba.org/show_bug.cgi?id=15404 Backport --pidl-developer fixes * https://bugzilla.samba.org/show_bug.cgi?id=15413 winbindd gets stuck on NT_STATUS_RPC_SEC_PKG_ERROR * remove dnsserver-rename-dns_name_equal.patch (included upstream) * heimdal-to-support-KEYRING-ccache.patch: enable KEYRING in heimdal (ability to store kerberos tickets in kernel keyring) (Closes: #1023609) * d/control: build-depend on libkeyutils-dev (it is pulled by some other dep, but better to be safe) schleuder-cli (0.1.0-4+deb12u1) bookworm; urgency=medium . * debian/patches: - Pull in upstream patch to fix escaping values in Ruby 3. (Closes: #1040257) smarty4 (4.3.0-1+deb12u1) bookworm; urgency=medium . * debian/patches: + Add CVE-2023-28447.patch. Prohibit execution of arbitrary JavaScript code in the context of the user's browser session. (Closes: #1033965, CVE-2023-28447). spip (4.1.9+dfsg-1+deb12u2) bookworm; urgency=medium . * Backport security fix from 4.1.11 - use an auth_desensibiliser_session() function to centralize extended authentification data filtering. spip (4.1.9+dfsg-1+deb12u1) bookworm; urgency=medium . [ David Prévot ] * Add CVE to previous changelog entry * Update documented branch * Backport security fixes from 4.1.10 - Limit recursion depth in protege_champ() function - Avoid unserialize use in security screen - Properly block hidden files in provided htaccess - Update security screen to 1.5.3 . [ RealET ] * mutualisation: PHP 8.1 compatibility fixes #2 sra-sdk (3.0.3+dfsg-6~deb12u1) bookworm; urgency=medium . * Reupload to bookworm (stable). . sra-sdk (3.0.3+dfsg-6) unstable; urgency=high . * debian/rules: Expand $(DEB_HOST_MULTIARCH) in libngs-java.links.in. (Closes: #1039621.) sudo (1.9.13p3-1+deb12u1) bookworm; urgency=medium . * add upstream patch to fix event log format. Thanks to Kimmo Suominen (Closes: #1039557) systemd (252.12-1~deb12u1) bookworm; urgency=medium . * New upstream version 252.12 * Refresh patches for v252.12 systemd (252.11-1) unstable; urgency=medium . * New upstream version 252.11 * Refresh patches systemd (252.11-1~deb12u1) bookworm; urgency=medium . * Upload to bookworm. . systemd (252.11-1) unstable; urgency=medium . * New upstream version 252.11 * Refresh patches tang (11-2+deb12u1) bookworm; urgency=medium . * Fix CVE-2023-1672. Closes: #1038119 - Cherry-pick "Fix race condition when creating/rotating keys" - Assert restrictive permissions on tang's key directory texlive-bin (2022.20220321.62855-5.1+deb12u1) bookworm; urgency=medium . * Stop building *jit* binaries on i386 based arches to make TL installable on computers not supporting sse2 (Closes: #1035461). * Add patch for CVE-2023-32668: disable socket in luatex by default (Closes: #1036470). thunderbird (1:102.13.0-1~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm-security (Closes: #971790, #1006432) thunderbird (1:102.13.0-1~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye-security (Closes: #971790, #1006432) thunderbird (1:102.12.0-1) unstable; urgency=medium . * [a285966] New upstream version 102.12.0 (Upstream has published a MFSA yet.) * [73c48d4] d/control: Add libotr5 to Depends thunderbird (1:102.12.0-1~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm-security thunderbird (1:102.12.0-1~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye-security trafficserver (9.2.0+ds-2+deb12u1) bookworm-security; urgency=medium . * Fix version number (Closes: #1038860) unixodbc (2.3.11-2+deb12u1) bookworm; urgency=medium . * unixodbc-common, odbcinst: Add Breaks+Replaces against odbcinst1debian1 (Closes: #1037172). usb.ids (2023.05.17-0+deb12u1) bookworm; urgency=medium . * Upload to bookworm. vm (8.2.0b-8+deb12u1) bookworm; urgency=medium . * Avoid byte compilation to work around trouble with emacs 28 Closes: #1039105. [Report from and patch via Dirk Eddelbuettel (Fix cherry picked from e8779ea20768ad08 in 8.2.0b-9.).) vte2.91 (0.70.6-1~deb12u1) bookworm; urgency=medium . * Team upload * Rebuild for bookworm (Closes: #1037919, LP: #2022019) * d/gbp.conf, d/control.in: Use debian/bookworm packaging branch . vte2.91 (0.70.6-1) unstable; urgency=medium . * Team upload * New upstream release - Functionally equivalent to 0.70.5-2, but the fix for #1037919 is incorporated upstream instead of as a patch * Add Debian and Ubuntu bug numbers to 0.70.5-2 changelog entry * Fix a typo in revised 0.70.5-1 changelog entry * d/gbp.conf, d/control.in: Use debian/trixie branch for packaging . vte2.91 (0.70.5-2) unstable; urgency=high . * Team upload * This version is functionally equivalent to 0.70.6 upstream, but 0.70.6 tarballs are not yet available * d/p/emulation-Fix-infinite-loop-on-non-number-OSC-104-param.patch: Add patch from upstream to fix an infinite loop processing OSC 104. A malicious program accessed via ssh, telnet or similar protocols could use this as a denial of service. (Closes: #1037919, LP: #2022019; vte#2631 upstream) * Add more details of the bugs fixed in the previous changelog entry . vte2.91 (0.70.5-1) unstable; urgency=medium . * New upstream bugfix release 0.70.4 - Fix an invalid memory access which can cause a terminal freeze or crash, for example when pasting emojis (vte#2606, vte#2620 upstream) * New upstream bugfix release 0.70.5 - Fix seconds vs milliseconds confusion so that the cursor stops blinking as intended when a focused window becomes idle (vte#2622 upstream) - Produce correct coordinates when mouse wheel scrolling on the left edge of a terminal (vte#2621 upstream) * d/gbp.conf, d/watch: Branch for 0.70.x and bookworm vte2.91 (0.70.5-2) unstable; urgency=high . * Team upload * This version is functionally equivalent to 0.70.6 upstream, but 0.70.6 tarballs are not yet available * d/p/emulation-Fix-infinite-loop-on-non-number-OSC-104-param.patch: Add patch from upstream to fix an infinite loop processing OSC 104. A malicious program accessed via ssh, telnet or similar protocols could use this as a denial of service. (vte#2631 upstream) * Add more details of the bugs fixed in the previous changelog entry vte2.91 (0.70.5-1) unstable; urgency=medium . * New upstream bugfix release webkit2gtk (2.40.3-2~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm-security. - Fixes CVE-2023-32439. webkit2gtk (2.40.3-2~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye-security. * gcc 10 segfaults when building webkit in amd64 (see #1008098) so use clang instead. Keep using gcc in other architectures because clang has problems in at least i386, arm64 and mipsel (see #1010329 and #1016811). - debian/rules: Tell CMake to use clang. - debian/control.in: Build depend on clang. * Build libsoup2 packages only. - debian/rules: Set ENABLE_SOUP3=NO, ENABLE_GTK4=NO and USE_PREBUILT_DOCS=YES. - debian/control.in: Remove build dependency on ccache. * debian/rules: - Disable USE_AVI, USE_GBM and USE_GSTREAMER_TRANSCODER due to missing or additional build dependencies. - Set Build-Depends-Indep to jdupes when USE_PREBUILT_DOCS is set. * debian/control: - Don't require version 1.20.0 of libgstreamer-plugins-bad1.0-dev. webkit2gtk (2.40.3-1) unstable; urgency=high . * New upstream release (Closes: #1036946). * debian/control.in: - Enable the bubblewrap sandbox in riscv64. * debian/copyright: - Update copyright information of all files. * debian/patches/fix-jsc-timestamp.patch: - Ensure reproducibility of __TIMESTAMP__ in JSCBytecodeCacheVersion.cpp. webkit2gtk (2.40.2-1) unstable; urgency=high . * New upstream release. * debian/rules: - Pass -VNone to dh_makeshlibs for javascriptcore to keep the behavior of the debhelper compat level 11 and earlier. webkit2gtk (2.40.2-1~deb12u1) bookworm-security; urgency=medium . * Rebuild for bookworm-security. * The WebKitGTK security advisory WSA-2023-0004 lists the following security fixes in the latest versions of WebKitGTK: - CVE-2023-28204 and CVE-2023-32373 (fixed in 2.40.2). webkit2gtk (2.40.2-1~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye-security. * gcc 10 segfaults when building webkit in amd64 (see #1008098) so use clang instead. Keep using gcc in other architectures because clang has problems in at least i386, arm64 and mipsel (see #1010329 and #1016811). - debian/rules: Tell CMake to use clang. - debian/control.in: Build depend on clang. * Build libsoup2 packages only. - debian/rules: Set ENABLE_SOUP3=NO, ENABLE_GTK4=NO and USE_PREBUILT_DOCS=YES. - debian/control.in: Remove build dependency on ccache. * debian/rules: - Disable USE_AVI, USE_GBM and USE_GSTREAMER_TRANSCODER due to missing or additional build dependencies. * debian/control: - Don't require version 1.20.0 of libgstreamer-plugins-bad1.0-dev. * debian/patches/g-spawn-check-wait-status.patch: - Fix build with older versions of GLib. wireshark (4.0.6-1~deb12u1) bookworm-security; urgency=medium . * Upload to bookworm-security . wireshark (4.0.6-1) unstable; urgency=medium . * Upload to unstable . wireshark (4.0.6-1~exp1) experimental; urgency=medium . * New upstream version 4.0.6 - security fixes: - Candump log file parser crash (CVE-2023-2855) - BLF file parser crash (CVE-2023-2857) - GDSDB dissector infinite loop - NetScaler file parser crash (CVE-2023-2858) - VMS TCPIPtrace file parser crash (CVE-2023-2856) - BLF file parser crash (CVE-2023-2854) - RTPS dissector crash (CVE-2023-0666) - IEEE C37.118 Synchrophasor dissector crash (CVE-2023-0668) - XRA dissector infinite loop * Fix mismatched Lintian overrides . wireshark (4.0.5-1~exp1) experimental; urgency=medium . [ Balint Reczey ] * New upstream version 4.0.4 - security fixes: - ISO 15765 and ISO 10681 dissector crash (CVE-2023-1161) (Closes: #1033756) * Drop 0001-tests-Get-tests-working-with-Python-3.11-except-with.patch integrated to the new upstream release. * New upstream version 4.0.5 - security fixes (Closes: #1034721): - RPCoRDMA dissector crash (CVE-2023-1992) - LISP dissector large loop (CVE-2023-1993) - GQUIC dissector crash (CVE-2023-1994) . [ Remus-Gabriel Chelu ] * Adding Romanian debconf templates translation (Closes: #1033792) wireshark (4.0.5-1~exp1) experimental; urgency=medium . [ Balint Reczey ] * New upstream version 4.0.4 - security fixes: - ISO 15765 and ISO 10681 dissector crash (CVE-2023-1161) (Closes: #1033756) * Drop 0001-tests-Get-tests-working-with-Python-3.11-except-with.patch integrated to the new upstream release. * New upstream version 4.0.5 - security fixes (Closes: #1034721): - RPCoRDMA dissector crash (CVE-2023-1992) - LISP dissector large loop (CVE-2023-1993) - GQUIC dissector crash (CVE-2023-1994) . [ Remus-Gabriel Chelu ] * Adding Romanian debconf templates translation (Closes: #1033792) xerial-sqlite-jdbc (3.40.1.0+dfsg-1+deb12u1) bookworm; urgency=medium . * Using a random UUID for the connection (Fixes CVE-2023-32697 in Bookworm, Closes: #1036706) xmltooling (3.2.3-1+deb12u1) bookworm-security; urgency=high . * [9e43891] New patch: CPPXT-157 - Install blocking URI resolver into Santuario. Fix a denial of service vulnerability: Parsing of KeyInfo elements can cause remote resource access. Including certain legal but "malicious in intent" content in the KeyInfo element defined by the XML Signature standard will result in attempts by the SP's shibd process to dereference untrusted URLs. While the content of the URL must be supplied within the message and does not include any SP internal state or dynamic content, there is at minimum a risk of denial of service, and the attack could be combined with others to create more serious vulnerabilities in the future. Thanks to Scott Cantor for the fix. (Closes: #1037948) yajl (2.1.0-3+deb12u2) bookworm; urgency=medium . [Tobias Frost] * Non-maintainer upload. * Cherry pick John's CVE fixes from 2.1.0-4 and 2.1.0-5 . [John Stamp] * Patch CVE-2017-16516 and CVE-2022-24795 (Closes: #1040036) * The patch for CVE-2023-33460 turned out to be incomplete. Fix that. (Closes: #1039984) yajl (2.1.0-3+deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Import upstream patch for CVE-2023-33460. (Closes: #1039984) * Fix d/control Homepage field (Closes: #1040034) yajl (2.1.0-3+deb11u1) bullseye; urgency=medium . * Non-maintainer upload. * Import upstream patch for CVE-2023-33460. (Closes: #1039984) ========================================= Sat, 10 Jun 2023 - Debian 12.0 released =========================================