SUSE-CU-2026:9301-1: Security update of bci/bci-sle15-kernel-module-devel

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 27 10:33:22 UTC 2026


SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9301-1
Container Tags        : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.47 , bci/bci-sle15-kernel-module-devel:latest
Container Release     : 60.47
Severity              : important
Type                  : security
References            : 1185845 1239511 1243603 1246182 1247455 1253262 1253674 1255357
                        1255703 1256675 1257815 1258718 1260347 1262573 1262632 1262633
                        1262635 1262636 1262638 1262745 1262771 1263010 1263068 1263440
                        1263718 1263788 1264007 1264013 1264053 1264076 1264089 1264090
                        1264184 1264319 1264333 1264418 1264422 1264452 1264532 1264534
                        1264537 1264539 1264543 1264558 1264601 1264712 1264779 1264793
                        1264795 1264827 1264832 1265009 1265141 1265308 1266238 1266685
                        1266695 1266710 1266715 1266758 1266813 1266850 1266869 1266876
                        1266880 1266890 1266891 1266896 1266900 1266904 1266913 1266918
                        1267025 1267203 1267210 1267375 1267384 1267439 1267570 1267584
                        1267596 1267656 1267662 1267678 1267682 1267689 1267714 1267715
                        1267943 1267986 1267995 1268029 1268307 1268412 1268648 1268659
                        1268966 1268967 1268983 1269003 1269024 1269027 1269094 1269104
                        1269112 1269115 1269117 1269118 1269119 1269132 1269134 1269138
                        1269154 1269181 1269185 1269186 1269229 1269233 1269240 1269270
                        1269272 1269289 1269290 1269307 1269318 1269362 1269376 1269383
                        1269512 1269513 1269577 1269633 1269643 1269658 1269659 1269660
                        1269672 1269688 1269689 1269694 1269697 1269714 1269724 1269734
                        1269773 1269797 1269808 1269810 1269819 1269964 1269981 1269990
                        1269991 1269994 1270000 1270102 1270113 1270132 1270230 1271250
                        1271283 1271285 1271291 1271349 1271368 1271402 1271526 1271717
                        1271731 1271813 1271818 1271825 1271826 1271827 1271831 1271832
                        1271833 1271834 1271858 1271866 1271869 1271870 1271899 1271904
                        1271908 1271912 1271937 1271955 1271964 1271967 1272146 1272149
                        1272176 1272180 1272183 1272187 1272194 1272197 1272204 1272207
                        1272211 1272242 1272246 1272263 1272268 1272282 1272296 1272325
                        1272360 1272361 1272362 1272373 1272374 1272380 1272384 1272387
                        1272389 1272406 1272434 1272466 1272467 1272468 1272470 1272472
                        1272474 1272478 1272480 1272482 1272483 1272489 1272492 1272494
                        1272499 1272500 1272501 1272513 1272517 1272522 1272523 1272573
                        1272578 1272591 1272600 1272607 1272614 1272617 1272620 1272642
                        1272646 1272659 1272664 1272665 1272668 1272670 1272671 1272678
                        1272681 1272685 1272686 1272689 1272690 1272691 1272693 1272694
                        1272706 1272781 1272785 1272787 1272797 1272800 1272807 1272836
                        1272843 1272850 1272853 1272855 1272863 1272865 1272871 1272891
                        1272892 1272897 1272903 1272904 1272907 1272918 1272920 1272973
                        1273004 1273023 1273035 1273044 1273117 1273231 1273550 1274072
                        CVE-2023-2058 CVE-2025-21845 CVE-2025-38250 CVE-2025-38469 CVE-2025-40213
                        CVE-2025-54518 CVE-2025-68223 CVE-2025-68741 CVE-2025-68818 CVE-2026-23097
                        CVE-2026-31431 CVE-2026-31482 CVE-2026-31483 CVE-2026-31542 CVE-2026-31598
                        CVE-2026-31628 CVE-2026-31759 CVE-2026-43016 CVE-2026-43033 CVE-2026-43046
                        CVE-2026-43056 CVE-2026-43059 CVE-2026-43114 CVE-2026-43130 CVE-2026-43161
                        CVE-2026-43168 CVE-2026-43170 CVE-2026-43172 CVE-2026-43216 CVE-2026-43230
                        CVE-2026-43262 CVE-2026-43266 CVE-2026-43276 CVE-2026-43281 CVE-2026-43308
                        CVE-2026-43309 CVE-2026-43328 CVE-2026-43352 CVE-2026-43439 CVE-2026-43440
                        CVE-2026-43451 CVE-2026-43475 CVE-2026-45860 CVE-2026-45873 CVE-2026-45904
                        CVE-2026-45905 CVE-2026-45913 CVE-2026-45915 CVE-2026-45917 CVE-2026-45944
                        CVE-2026-45973 CVE-2026-46003 CVE-2026-46015 CVE-2026-46026 CVE-2026-46038
                        CVE-2026-46080 CVE-2026-46084 CVE-2026-46109 CVE-2026-46117 CVE-2026-46126
                        CVE-2026-46137 CVE-2026-46144 CVE-2026-46145 CVE-2026-46147 CVE-2026-46158
                        CVE-2026-46168 CVE-2026-46170 CVE-2026-46174 CVE-2026-46180 CVE-2026-46189
                        CVE-2026-46193 CVE-2026-46234 CVE-2026-46243 CVE-2026-46245 CVE-2026-46265
                        CVE-2026-46292 CVE-2026-46306 CVE-2026-46323 CVE-2026-46324 CVE-2026-46333
                        CVE-2026-52910 CVE-2026-52921 CVE-2026-52927 CVE-2026-52930 CVE-2026-52937
                        CVE-2026-52941 CVE-2026-52942 CVE-2026-52947 CVE-2026-52967 CVE-2026-52970
                        CVE-2026-52974 CVE-2026-52984 CVE-2026-52986 CVE-2026-52988 CVE-2026-52991
                        CVE-2026-52998 CVE-2026-52999 CVE-2026-53000 CVE-2026-53002 CVE-2026-53006
                        CVE-2026-53011 CVE-2026-53012 CVE-2026-53032 CVE-2026-53062 CVE-2026-53063
                        CVE-2026-53064 CVE-2026-53069 CVE-2026-53074 CVE-2026-53083 CVE-2026-53088
                        CVE-2026-53106 CVE-2026-53107 CVE-2026-53123 CVE-2026-53129 CVE-2026-53131
                        CVE-2026-53132 CVE-2026-53134 CVE-2026-53175 CVE-2026-53177 CVE-2026-53183
                        CVE-2026-53184 CVE-2026-53185 CVE-2026-53189 CVE-2026-53212 CVE-2026-53221
                        CVE-2026-53230 CVE-2026-53236 CVE-2026-53250 CVE-2026-53252 CVE-2026-53262
                        CVE-2026-53265 CVE-2026-53267 CVE-2026-53270 CVE-2026-53275 CVE-2026-53289
                        CVE-2026-53291 CVE-2026-53297 CVE-2026-53321 CVE-2026-53324 CVE-2026-53331
                        CVE-2026-53332 CVE-2026-53345 CVE-2026-53354 CVE-2026-53369 CVE-2026-53374
                        CVE-2026-53375 CVE-2026-53376 CVE-2026-53379 CVE-2026-53382 CVE-2026-53385
                        CVE-2026-53388 CVE-2026-53391 CVE-2026-53392 CVE-2026-53393 CVE-2026-53397
                        CVE-2026-53398 CVE-2026-53399 CVE-2026-53402 CVE-2026-53403 CVE-2026-5545
                        CVE-2026-5773 CVE-2026-6253 CVE-2026-6276 CVE-2026-63794 CVE-2026-63795
                        CVE-2026-63802 CVE-2026-63806 CVE-2026-63807 CVE-2026-63809 CVE-2026-63821
                        CVE-2026-63822 CVE-2026-63824 CVE-2026-63826 CVE-2026-63829 CVE-2026-63836
                        CVE-2026-63843 CVE-2026-63844 CVE-2026-63845 CVE-2026-63846 CVE-2026-63847
                        CVE-2026-63848 CVE-2026-63851 CVE-2026-63852 CVE-2026-63853 CVE-2026-63854
                        CVE-2026-63855 CVE-2026-63856 CVE-2026-63861 CVE-2026-63862 CVE-2026-63869
                        CVE-2026-63882 CVE-2026-63884 CVE-2026-63892 CVE-2026-63893 CVE-2026-63895
                        CVE-2026-63896 CVE-2026-63897 CVE-2026-63899 CVE-2026-63900 CVE-2026-63901
                        CVE-2026-63902 CVE-2026-63903 CVE-2026-63904 CVE-2026-63905 CVE-2026-63908
                        CVE-2026-63912 CVE-2026-63915 CVE-2026-63916 CVE-2026-63917 CVE-2026-63919
                        CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63927 CVE-2026-63928
                        CVE-2026-63930 CVE-2026-63931 CVE-2026-63934 CVE-2026-63938 CVE-2026-63939
                        CVE-2026-63940 CVE-2026-63942 CVE-2026-63943 CVE-2026-63945 CVE-2026-63946
                        CVE-2026-63947 CVE-2026-63948 CVE-2026-63949 CVE-2026-63952 CVE-2026-63957
                        CVE-2026-63958 CVE-2026-63959 CVE-2026-63960 CVE-2026-63961 CVE-2026-63962
                        CVE-2026-63964 CVE-2026-63967 CVE-2026-63968 CVE-2026-63971 CVE-2026-63974
                        CVE-2026-63975 CVE-2026-63976 CVE-2026-63984 CVE-2026-63991 CVE-2026-63994
                        CVE-2026-64025 CVE-2026-64089 CVE-2026-64106 CVE-2026-64174 CVE-2026-64179
                        CVE-2026-64182 CVE-2026-64183 CVE-2026-64187 CVE-2026-64189 CVE-2026-64191
                        CVE-2026-64220 CVE-2026-64221 CVE-2026-64223 CVE-2026-64231 CVE-2026-64234
                        CVE-2026-64242 CVE-2026-6429 CVE-2026-64298 CVE-2026-64330 CVE-2026-64336
                        CVE-2026-64345 CVE-2026-64347 CVE-2026-64465 CVE-2026-64530 CVE-2026-64560
                        CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 CVE-2026-7168 CVE-2026-8926
-----------------------------------------------------------------

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3790-1
Released:    Tue Aug 25 14:24:18 2026
Summary:     Security update for the Linux Kernel
Type:        security
Severity:    important
References:  1185845,1239511,1243603,1246182,1247455,1253262,1253674,1255357,1255703,1256675,1257815,1258718,1260347,1262573,1262745,1262771,1263010,1263068,1263718,1263788,1264007,1264013,1264053,1264076,1264089,1264090,1264184,1264319,1264333,1264418,1264422,1264452,1264532,1264534,1264537,1264539,1264543,1264558,1264601,1264712,1264779,1264793,1264795,1264827,1264832,1265009,1265141,1265308,1266238,1266685,1266695,1266710,1266715,1266758,1266813,1266850,1266869,1266876,1266880,1266890,1266891,1266896,1266900,1266904,1266913,1266918,1267025,1267203,1267210,1267375,1267384,1267439,1267570,1267584,1267596,1267656,1267662,1267678,1267682,1267689,1267714,1267715,1267943,1267986,1267995,1268029,1268307,1268648,1268659,1268966,1268967,1268983,1269003,1269024,1269027,1269094,1269104,1269112,1269115,1269117,1269118,1269119,1269132,1269134,1269138,1269154,1269181,1269185,1269186,1269229,1269233,1269240,1269270,1269272,1269289,1269290,1269307,1269318,1269362,1269376,1269383,1269512,1269513,1
 269577,1269633,1269643,1269658,1269659,1269660,1269672,1269688,1269689,1269694,1269697,1269714,1269724,1269734,1269773,1269797,1269808,1269810,1269819,1269964,1269981,1269990,1269991,1269994,1270000,1270102,1270113,1270132,1270230,1271250,1271283,1271285,1271291,1271349,1271368,1271402,1271526,1271717,1271731,1271813,1271818,1271825,1271826,1271827,1271831,1271832,1271833,1271834,1271858,1271866,1271869,1271870,1271899,1271904,1271908,1271912,1271937,1271955,1271964,1271967,1272146,1272149,1272176,1272180,1272183,1272187,1272194,1272197,1272204,1272207,1272211,1272242,1272246,1272263,1272268,1272282,1272296,1272325,1272360,1272361,1272362,1272373,1272374,1272380,1272384,1272387,1272389,1272406,1272434,1272466,1272467,1272468,1272470,1272472,1272474,1272478,1272480,1272482,1272483,1272489,1272492,1272494,1272499,1272500,1272501,1272513,1272517,1272522,1272523,1272573,1272578,1272591,1272600,1272607,1272614,1272617,1272620,1272642,1272646,1272659,1272664,1272665,1272668,1272670,127267
 1,1272678,1272681,1272685,1272686,1272689,1272690,1272691,1272693,1272694,1272706,1272781,1272785,1272787,1272797,1272800,1272807,1272836,1272843,1272850,1272853,1272855,1272863,1272865,1272871,1272891,1272892,1272897,1272903,1272904,1272907,1272918,1272920,1272973,1273004,1273023,1273035,1273044,1273117,1273231,1273550,1274072,CVE-2023-2058,CVE-2025-21845,CVE-2025-38250,CVE-2025-38469,CVE-2025-40213,CVE-2025-54518,CVE-2025-68223,CVE-2025-68741,CVE-2025-68818,CVE-2026-23097,CVE-2026-31431,CVE-2026-31482,CVE-2026-31483,CVE-2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43016,CVE-2026-43033,CVE-2026-43046,CVE-2026-43056,CVE-2026-43059,CVE-2026-43114,CVE-2026-43130,CVE-2026-43161,CVE-2026-43168,CVE-2026-43170,CVE-2026-43172,CVE-2026-43216,CVE-2026-43230,CVE-2026-43262,CVE-2026-43266,CVE-2026-43276,CVE-2026-43281,CVE-2026-43308,CVE-2026-43309,CVE-2026-43328,CVE-2026-43352,CVE-2026-43439,CVE-2026-43440,CVE-2026-43451,CVE-2026-43475,CVE-2026-45860,CVE-2026-45873,CVE-2026
 -45904,CVE-2026-45905,CVE-2026-45913,CVE-2026-45915,CVE-2026-45917,CVE-2026-45944,CVE-2026-45973,CVE-2026-46003,CVE-2026-46015,CVE-2026-46026,CVE-2026-46038,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46137,CVE-2026-46144,CVE-2026-46145,CVE-2026-46147,CVE-2026-46158,CVE-2026-46168,CVE-2026-46170,CVE-2026-46174,CVE-2026-46180,CVE-2026-46189,CVE-2026-46193,CVE-2026-46234,CVE-2026-46243,CVE-2026-46245,CVE-2026-46265,CVE-2026-46292,CVE-2026-46306,CVE-2026-46323,CVE-2026-46324,CVE-2026-46333,CVE-2026-52910,CVE-2026-52921,CVE-2026-52927,CVE-2026-52930,CVE-2026-52937,CVE-2026-52941,CVE-2026-52942,CVE-2026-52947,CVE-2026-52967,CVE-2026-52970,CVE-2026-52974,CVE-2026-52984,CVE-2026-52986,CVE-2026-52988,CVE-2026-52991,CVE-2026-52998,CVE-2026-52999,CVE-2026-53000,CVE-2026-53002,CVE-2026-53006,CVE-2026-53011,CVE-2026-53012,CVE-2026-53032,CVE-2026-53062,CVE-2026-53063,CVE-2026-53064,CVE-2026-53069,CVE-2026-53074,CVE-2026-53083,CVE-2026-53088,CVE-2026-53106,
 CVE-2026-53107,CVE-2026-53123,CVE-2026-53129,CVE-2026-53131,CVE-2026-53132,CVE-2026-53134,CVE-2026-53175,CVE-2026-53177,CVE-2026-53183,CVE-2026-53184,CVE-2026-53185,CVE-2026-53189,CVE-2026-53212,CVE-2026-53221,CVE-2026-53230,CVE-2026-53236,CVE-2026-53250,CVE-2026-53252,CVE-2026-53262,CVE-2026-53265,CVE-2026-53267,CVE-2026-53270,CVE-2026-53275,CVE-2026-53289,CVE-2026-53291,CVE-2026-53297,CVE-2026-53321,CVE-2026-53324,CVE-2026-53331,CVE-2026-53332,CVE-2026-53345,CVE-2026-53354,CVE-2026-53369,CVE-2026-53374,CVE-2026-53375,CVE-2026-53376,CVE-2026-53379,CVE-2026-53382,CVE-2026-53385,CVE-2026-53388,CVE-2026-53391,CVE-2026-53392,CVE-2026-53393,CVE-2026-53397,CVE-2026-53398,CVE-2026-53399,CVE-2026-53402,CVE-2026-53403,CVE-2026-63794,CVE-2026-63795,CVE-2026-63802,CVE-2026-63806,CVE-2026-63807,CVE-2026-63809,CVE-2026-63821,CVE-2026-63822,CVE-2026-63824,CVE-2026-63826,CVE-2026-63829,CVE-2026-63836,CVE-2026-63843,CVE-2026-63844,CVE-2026-63845,CVE-2026-63846,CVE-2026-63847,CVE-2026-63848,CVE-202
 6-63851,CVE-2026-63852,CVE-2026-63853,CVE-2026-63854,CVE-2026-63855,CVE-2026-63856,CVE-2026-63861,CVE-2026-63862,CVE-2026-63869,CVE-2026-63882,CVE-2026-63884,CVE-2026-63892,CVE-2026-63893,CVE-2026-63895,CVE-2026-63896,CVE-2026-63897,CVE-2026-63899,CVE-2026-63900,CVE-2026-63901,CVE-2026-63902,CVE-2026-63903,CVE-2026-63904,CVE-2026-63905,CVE-2026-63908,CVE-2026-63912,CVE-2026-63915,CVE-2026-63916,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63927,CVE-2026-63928,CVE-2026-63930,CVE-2026-63931,CVE-2026-63934,CVE-2026-63938,CVE-2026-63939,CVE-2026-63940,CVE-2026-63942,CVE-2026-63943,CVE-2026-63945,CVE-2026-63946,CVE-2026-63947,CVE-2026-63948,CVE-2026-63949,CVE-2026-63952,CVE-2026-63957,CVE-2026-63958,CVE-2026-63959,CVE-2026-63960,CVE-2026-63961,CVE-2026-63962,CVE-2026-63964,CVE-2026-63967,CVE-2026-63968,CVE-2026-63971,CVE-2026-63974,CVE-2026-63975,CVE-2026-63976,CVE-2026-63984,CVE-2026-63991,CVE-2026-63994,CVE-2026-64025,CVE-2026-64089,CVE-2026-64106
 ,CVE-2026-64174,CVE-2026-64179,CVE-2026-64182,CVE-2026-64183,CVE-2026-64187,CVE-2026-64189,CVE-2026-64191,CVE-2026-64220,CVE-2026-64221,CVE-2026-64223,CVE-2026-64231,CVE-2026-64234,CVE-2026-64242,CVE-2026-64298,CVE-2026-64330,CVE-2026-64336,CVE-2026-64345,CVE-2026-64347,CVE-2026-64465,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600
The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues:

The following security issues were fixed:

- CVE-2025-68741: scsi: qla2xxx: Fix improper freeing of purex item (bsc#1255703).
- CVE-2025-68818: scsi: Revert 'scsi: qla2xxx: Perform lockless command completion in abort path' (bsc#1256675).
- CVE-2026-23097: migrate: correct lock ordering for hugetlb file folios (bsc#1257815).
- CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007).
- CVE-2026-43114: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (bsc#1264601).
- CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532).
- CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333).
- CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537).
- CVE-2026-43170: usb: dwc3: gadget: Move vbus draw to workqueue context (bsc#1264452).
- CVE-2026-43172: wifi: iwlwifi: fix 22000 series SMEM parsing (bsc#1264543).
- CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319).
- CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539).
- CVE-2026-43262: gfs2: fiemap page fault fix (bsc#1264422).
- CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418).
- CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534).
- CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712).
- CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827).
- CVE-2026-43328: cpufreq: governor: Free dbs_data directly when gov->init() fails (bsc#1264832).
- CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141).
- CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009).
- CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710).
- CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets (bsc#1266715).
- CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685).
- CVE-2026-45913: net: bridge: mcast: always update mdb_n_entries for vlan contexts (bsc#1266891).
- CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896).
- CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900).
- CVE-2026-45944: iommu/vt-d: Clear Present bit before tearing down context entry (bsc#1267203).
- CVE-2026-45973: RDMA/mlx5: Fix UMR hang in LAG error state unload (bsc#1267025).
- CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes (bsc#1267210).
- CVE-2026-46015: tcp: call sk_data_ready() after listener migration (bsc#1267439).
- CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups (bsc#1266876).
- CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye() (bsc#1266695).
- CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race (bsc#1267570).
- CVE-2026-46147: KVM: arm64: Factor out pKVM hyp vcpu creation to separate function (bsc#1267689).
- CVE-2026-46158: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (bsc#1266880).
- CVE-2026-46168: mptcp: sockopt: set timestamp flags on subflow socket, not msk (bsc#1266869).
- CVE-2026-46170: mptcp: pm: reuse ID 0 after delete and re-add (bsc#1267714).
- CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (bsc#1266813).
- CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918).
- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
- CVE-2026-46234: vsock: fix buffer size clamping order (bsc#1266904).
- CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678).
- CVE-2026-46265: RDMA/hns: Fix WQ_MEM_RECLAIM warning (bsc#1267662).
- CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd (bsc#1267943).
- CVE-2026-46306: flow_dissector: do not dissect PPPoE PFC frames (bsc#1267986).
- CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995).
- CVE-2026-52910: pf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
- CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end (bsc#1269024).
- CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027).
- CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003).
- CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR (bsc#1268983).
- CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint (bsc#1268966).
- CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967).
- CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (bsc#1269115).
- CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181).
- CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval (bsc#1269229).
- CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX setup failure (bsc#1269233).
- CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272).
- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).
- CVE-2026-52988: rculist: add list_splice_rcu() for private lists (bsc#1269362).
- CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134).
- CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118).
- CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (bsc#1269119).
- CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops (bsc#1269117).
- CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112).
- CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104).
- CVE-2026-53011: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (bsc#1269094).
- CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop (bsc#1269154).
- CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs (bsc#1269138).
- CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658).
- CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659).
- CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132).
- CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (bsc#1269186).
- CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (bsc#1269688).
- CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear() (bsc#1269964).
- CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (bsc#1269185).
- CVE-2026-53106: bpf: Do not allow deleting local storage in NMI (bsc#1269990).
- CVE-2026-53107: wifi: libertas: use USB anchors for tracking in-flight URBs (bsc#1269991).
- CVE-2026-53123: md: wake raid456 reshape waiters before suspend (bsc#1269643).
- CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633).
- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
- CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue (bsc#1269290).
- CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819).
- CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (bsc#1269714).
- CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink (bsc#1269376).
- CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict (bsc#1269689).
- CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial() (bsc#1269660).
- CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put() (bsc#1269797).
- CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy (bsc#1269672).
- CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (bsc#1269318).
- CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (bsc#1269270).
- CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994).
- CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808).
- CVE-2026-53252: adaption to srcu change of hci_dev in hci_sysfs (bsc#1269307).
- CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000).
- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
- CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240).
- CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810).
- CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs() (bsc#1269694).
- CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697).
- CVE-2026-53321: io_uring/napi: cap busy_poll_to 10 msec (bsc#1269724).
- CVE-2026-53345: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (bsc#1270132).
- CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230).    
- CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818).
- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).
- CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826).
- CVE-2026-53393: nfsd: Don't reset the write verifier on a commit EAGAIN (bsc#1271858).
- CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869).
- CVE-2026-53398: NFSD: Fix SECINFO_NO_NAME decode error cleanup (bsc#1271870).
- CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832).
- CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908).
- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).
- CVE-2026-63795: 9p: avoid putting oldfid in p9_client_walk() error path (bsc#1271955).
- CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282).
- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).
- CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263).
- CVE-2026-63809: bpf: NUL-terminate replaced sysctl value (bsc#1272296).
- CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180).
- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).
- CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501).
- CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836).
- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904).
- CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907).
- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918).
- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855).
- CVE-2026-63938: KVM: SEV: Check PSC request indices against the actual size of the buffer (bsc#1272620).
- CVE-2026-63939: KVM: SEV: Compute the correct max length of the in-GHCB scratch area (bsc#1272691).
- CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468).
- CVE-2026-63962: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (bsc#1272482).
- CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466).
- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678).
- CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865).
- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035).
- CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (bsc#1273117).
- CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242).
- CVE-2026-64187: xfs: fail recovery on a committed log item with no regions (bsc#1272204).
- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207).
- CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550).
- CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004).
- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231).
- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).

The following non security issues were fixed:

- accel/ivpu: Fix wrong register read in LNL failure diagnostics (git-fixes).
- accel/ivpu: Reject firmware log with size smaller than header (git-fixes).
- accel/qaic: use sizeof(*trans_hdr) for transaction length check (git-fixes).
- ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (git-fixes).
- ALSA: hda: cs35l41: validate and free ACPI mute object (git-fixes).
- ALSA: lx6464es: fix period byte count for 16-bit streams (git-fixes).
- ALSA: pcm: wake linked drain waiters on unlink (git-fixes).
- ALSA: seq: close a re-opened queue timer in the destructor (git-fixes).
- ALSA: ump: fix double free of out_cvts on rawmidi error (git-fixes).
- ALSA: usb-audio: Clamp frame size in implicit-feedback mode (git-fixes).
- ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (git-fixes).
- ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (git-fixes).
- ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (git-fixes).
- ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (git-fixes).
- ASoC: cs35l56: Fix potential probe() deadlock (git-fixes).
- ASoC: cs35l56: Use complete_all() to signal init_completion (git-fixes).
- ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (git-fixes).
- ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes).
- ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes).
- ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (stable-fixes).
- ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (stable-fixes).
- ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (stable-fixes).
- ASoC: tas2562: fix broken entries in the volume lookup table (git-fixes).
- ASoC: tas2562: fix DVC coefficient write order (git-fixes).
- ASoC: tas2781: bound firmware description string parsing (git-fixes).
- assoc_array: trim the final shortcut word using the current chunk end (git-fixes).
- batman-adv: dat: fix tie-break for candidate selection (git-fixes).
- batman-adv: fix VLAN priority offset (git-fixes).
- batman-adv: frag: fix primary_if leak on failed linearization (git-fixes).
- batman-adv: frag: free unfragmentable packet (git-fixes).
- batman-adv: tt: avoid request storms during pending request (git-fixes).
- batman-adv: tt: prevent TVLV OOB check overflow (git-fixes).
- bitops: make BYTES_TO_BITS() treewide-available (stable-fixes).
- Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (stable-fixes).
- Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (git-fixes).
- Bluetooth: btintel: Validate length before parsing diagnostics TLV (git-fixes).
- Bluetooth: btrtl: validate firmware patch bounds (git-fixes).
- Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (stable-fixes).
- Bluetooth: btusb: mediatek: remove the unnecessary goto tag (stable-fixes).
- Bluetooth: btusb: validate Realtek vendor event length (git-fixes).
- Bluetooth: hci_qca: Clear memdump state on invalid dump size (git-fixes).
- Bluetooth: hci_sync: Fix advertising data UAFs (git-fixes).
- Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks (git-fixes).
- Bluetooth: hci_sync: Protect UUID list traversal (git-fixes).
- Bluetooth: HIDP: reject frames without a transaction header (git-fixes).
- Bluetooth: HIDP: validate numbered report payloads (git-fixes).
- Bluetooth: ISO: clear iso_data always when detaching conn from hcon (git-fixes).
- Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (git-fixes).
- Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (git-fixes).
- Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (git-fixes).
- Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (git-fixes).
- Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes).
- Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (git-fixes).
- Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (git-fixes).
- Bluetooth: mgmt: Translate HCI reason in Device Disconnected event (git-fixes).
- Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes).
- Bluetooth: RFCOMM: Fix session UAF in set_termios (git-fixes).
- bus: sunxi-rsb: Always check register address validity (git-fixes).
- can: bcm: add missing rcu list annotations and operations (git-fixes).
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (git-fixes).
- can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (git-fixes).
- can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (git-fixes).
- can: ctucanfd: add missing MODULE_DEVICE_TABLE() (git-fixes).
- can: ctucanfd: handle bus error interrupts (git-fixes).
- can: ctucanfd: mark error-active controller status valid (git-fixes).
- can: ctucanfd: unmap BAR0 using base address (git-fixes).
- can: ctucanfd: use self-test mode for PRESUME_ACK (git-fixes).
- can: ems_usb: validate CPC message lengths (git-fixes).
- can: esd_usb: kill anchored URBs before freeing netdevs (git-fixes).
- can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (git-fixes).
- can: isotp: check register_netdevice_notifier() error in module init (git-fixes).
- can: isotp: use unconditional synchronize_rcu() in isotp_release() (git-fixes).
- can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (git-fixes).
- can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (git-fixes).
- can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (git-fixes).
- can: peak_usb: add bounds check for USB channel index (git-fixes).
- can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (git-fixes).
- can: peak_usb: validate uCAN receive record lengths (git-fixes).
- can: softing: fw_parse(): validate firmware record spans (git-fixes).
- cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (git-fixes).
- comedi: comedi_parport: deal with premature interrupt (git-fixes).
- dm cache policy smq: check allocation under invalidate lock (git-fixes).
- dm cache: fix missing return in invalidate_committed's error path (git-fixes).
- dmaengine: idxd: fix double free of wq, engine, and group structs (git-fixes).
- dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (git-fixes).
- dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (git-fixes).
- dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (git-fixes).
- driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (git-fixes).
- driver core: Guard deferred probe timeout extension with delayed_work_pending() (git-fixes).
- driver core: Use mod_delayed_work to prevent lost deferred probe work (git-fixes).
- Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes).
- drm/amd/display: dce100: skip non-DP stream encoders for DP MST (stable-fixes).
- drm/amd/display: set new_stream to NULL after release (git-fixes).
- drm/amd/display: use proper context for logging (git-fixes).
- drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (git-fixes).
- drm/amd/pm: fix smu14 power limit range calculation (stable-fixes).
- drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes).
- drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes).
- drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (stable-fixes).
- drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes).
- drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes).
- drm/amdgpu/vce: fix integer overflow in image size (stable-fixes).
- drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes).
- drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (git-fixes).
- drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes).
- drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes).
- drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (stable-fixes).
- drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes).
- drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes).
- drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes).
- drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (stable-fixes).
- drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (git-fixes).
- drm/amdkfd: free MQD managers on DQM init failures (git-fixes).
- drm/amdkfd: hold event_mutex while checkpointing CRIU events (git-fixes).
- drm/amdkfd: Use kvcalloc to allocate arrays (stable-fixes).
- drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (git-fixes).
- drm/i915/gt: use correct selftest config symbol (git-fixes).
- drm/i915/selftests: Fix GT PM sort comparators (git-fixes).
- drm/i915: ensure segment offset never exceeds allowed max (stable-fixes).
- drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (git-fixes).
- drm/mediatek: Check CRTC state before freeing (git-fixes).
- drm/mediatek: ovl_adaptor: balance component registrations (git-fixes).
- drm/panthor: reject firmware sections with oversized data (git-fixes).
- drm/panthor: return error on truncated firmware (git-fixes).
- drm/panthor: validate firmware interface structure sizes (git-fixes).
- drm/radeon: fix r100_copy_blit for large BOs (stable-fixes).
- drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (git-fixes).
- drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (stable-fixes).
- drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (git-fixes).
- drm/vc4: hvs/v3d: Fix null dereference in unbind (git-fixes).
- drm/vc4: Prevent shader BO mappings from becoming writable (git-fixes).
- drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (git-fixes).
- drm/vc4: Zero the tile state data array before each BIN job (git-fixes).
- drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (git-fixes).
- drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (git-fixes).
- drm/vmwgfx: bound DMA command body size against suffix pointer (git-fixes).
- drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (git-fixes).
- drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (git-fixes).
- drm/vmwgfx: reject DX_BIND_QUERY without a DX context (git-fixes).
- drm/vmwgfx: use check_add_overflow for shader size+offset bound (git-fixes).
- drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (git-fixes).
- drm/vmwgfx: validate external BO copy bounds for both stride paths (git-fixes).
- drm/vmwgfx: Validate vmw_surface_metadata::array_size (git-fixes).
- drm/xe/wopcm: fix WOPCM size for LNL+ (git-fixes).
- fbcon: fix NULL pointer dereference for a console without vc_data (stable-fixes).
- fbdev/efifb: Replace references to global screen_info by local pointer (stable-fixes).
- fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (git-fixes).
- fbdev: efifb: fix memory leak in efifb_probe() (git-fixes).
- firewire: net: Fix fragmented datagram reassembly (git-fixes).
- firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (git-fixes).
- firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes).
- firmware_loader: introduce __free() cleanup hanler (stable-fixes).
- gpio: eic-sprd: use raw_spinlock_t in the irq startup path (git-fixes).
- gpio: mlxbf3: fail probe if gpiochip registration fails (git-fixes).
- gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (git-fixes).
- gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes).
- gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes).
- HID: add haptics page defines (stable-fixes).
- HID: playstation: validate num_touch_reports in DualShock 4 reports (stable-fixes).
- hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
- hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (git-fixes).
- hwmon: (adt7470) Fix cache updated before hardware write on I2C error (git-fixes).
- hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (git-fixes).
- hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (git-fixes).
- hwmon: (adt7470) Fix PWM auto temp state array and bounds check (git-fixes).
- hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (git-fixes).
- hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (git-fixes).
- hwmon: (adt7470) Use cached PWM frequency value (git-fixes).
- hwmon: (asus-ec-sensors) add missed handle for ENOMEM (git-fixes).
- hwmon: (asus-ec-sensors) fix EC read intervals (git-fixes).
- hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (git-fixes).
- hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (git-fixes).
- hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (git-fixes).
- hwmon: (lm90) Only report alarms if driver is ready (git-fixes).
- hwmon: (nct6775-core) Prevent access to unsupported weight registers (git-fixes).
- hwmon: (npcm750-pwm-fan): stop fan timer on device detach (git-fixes).
- hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (git-fixes).
- hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (git-fixes).
- hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (git-fixes).
- hwmon: (w83627hf) remove VID sysfs files on error and remove (stable-fixes).
- hwmon: (w83793) remove vrm sysfs file on probe failure (stable-fixes).
- hwmon: occ: validate poll response sensor blocks (git-fixes).
- i2c: amd-mp2: Unregister callback on adapter add failure (git-fixes).
- i2c: imx: Cancel hrtimer before clearing slave pointer (git-fixes).
- i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes).
- i2c: imx: Fix slave registration race and error handling (git-fixes).
- i2c: imx: separate atomic, dma and non-dma use case (stable-fixes).
- i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (git-fixes).
- i2c: mediatek: fix WRRD for SoCs without auto_restart option (git-fixes).
- i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (git-fixes).
- ice: don't check has_ready_bitmap in E810 functions (bsc#1269981).
- ice: factor out ice_ptp_rebuild_owner() (bsc#1269981).
- ice: fix PTP Call Trace during PTP release (bsc#1269981).
- ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981).
- ice: introduce PTP state machine (bsc#1269981).
- ice: pass reset type to PTP reset functions (bsc#1269981).
- ice: rename ice_ptp_tx_cfg_intr (bsc#1269981).
- ice: rename verify_cached to has_ready_bitmap (bsc#1269981).
- ice: stop destroying and reinitalizing Tx tracker during reset (bsc#1269981).
- ieee802154: admin-gate legacy LLSEC dump operations (git-fixes).
- ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (git-fixes).
- ieee802154: ca8210: fix cas_ctl leak on spi_async failure (git-fixes).
- ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (git-fixes).
- ieee802154: fix kernel-infoleak in dgram_recvmsg() (git-fixes).
- ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (git-fixes).
- iio: common: st_sensors: honour channel endianness in read_axis_data (git-fixes).
- Input: atkbd - validate scancode in firmware keymap entries (git-fixes).
- Input: elan_i2c - prevent division by zero and arithmetic underflow (git-fixes).
- Input: goodix - clamp the device-reported contact count (git-fixes).
- Input: iforce - bound the device-reported force-feedback effect index (git-fixes).
- Input: ims-pcu - add response length checks (git-fixes).
- Input: ims-pcu - fix DMA mapping violation in line setup (git-fixes).
- Input: ims-pcu - fix firmware leak in async update (git-fixes).
- Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (git-fixes).
- Input: ims-pcu - fix logic error in packet reset (git-fixes).
- Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (git-fixes).
- Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (git-fixes).
- Input: ims-pcu - fix race condition in reset_device sysfs callback (git-fixes).
- Input: ims-pcu - fix type confusion in CDC union descriptor parsing (git-fixes).
- Input: ims-pcu - fix use-after-free and double-free in disconnect (git-fixes).
- Input: ims-pcu - release data interface on disconnect (git-fixes).
- Input: ims-pcu - validate control endpoint type (git-fixes).
- Input: maple_keyb - set driver data before registering input device (stable-fixes).
- Input: maplecontrol - set driver data before registering input device (stable-fixes).
- Input: maplemouse - set driver data before registering input device (stable-fixes).
- Input: rmi4 - fix bit count in bitmap_copy() (git-fixes).
- Input: rmi4 - fix limit in rmi_register_desc_has_subpacket() (git-fixes).
- Input: rmi4 - fix memory leak in rmi_set_attn_data() (git-fixes).
- Input: rmi4 - fix num_subpackets overflow in register descriptor (git-fixes).
- Input: rmi4 - fix register descriptor address calculation (git-fixes).
- Input: rmi4 - fix type overflow in register counts (git-fixes).
- Input: rmi4 - initialize attn_fifo properly (stable-fixes).
- Input: rmi4 - iterative IRQ handler (git-fixes).
- Input: rmi4 - refactor F12 probe function (stable-fixes).
- Input: rmi4 - refactor register descriptor parsing (git-fixes).
- Input: rmi4 - tolerate short register descriptor structure (git-fixes).
- Input: rmi4 - use local presence map in rmi_read_register_desc() (stable-fixes).
- Input: serio - define serio_pause_rx guard to pause and resume serio ports (stable-fixes).
- Input: synaptics-rmi4 - add support for querying DPM value (F12) (stable-fixes).
- Input: synaptics-rmi4 - fix crash when DPM query is not supported (git-fixes).
- Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (git-fixes).
- Input: touchwin - reset the packet index on every complete packet (git-fixes).
- intel_th: fix MSC output device reference leak (git-fixes).
- io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (bsc#1271283).
- io_uring/filetable: clamp alloc_hint to the configured alloc range (bsc#1271285).
- io_uring/timeout: add helper for parsing user time (bsc#1271291).
- io_uring/timeout: honour caller's time namespace for IORING_TIMEOUT_ABS (bsc#1271291).
- io_uring/timeout: migrate reqs from ts64 to ktime (bsc#1271291).
- io_uring/wait: honour caller's time namespace for IORING_ENTER_ABS_TIMER (bsc#1271291).
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (git-fixes).
- KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (git-fixes).
- KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes).
- KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes).
- KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (git-fixes).
- KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes).
- KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes).
- KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes).
- KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes).
- KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes).
- KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes).
- KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (git-fixes).
- KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes).
- KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes).
- KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (git-fixes).
- libbpf: Search /lib64 and /lib in resolve_full_path() (bsc#1271250).
- mac802154: hold an interface reference across the scan worker (git-fixes).
- mac802154: llsec: reject frames shorter than the authentication tag (git-fixes).
- media: airspy: Return queued buffers on start_streaming() failure (git-fixes).
- media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (git-fixes).
- media: cedrus: clean up media device on probe failure (git-fixes).
- media: cx231xx: fix devres lifetime (git-fixes).
- media: cx23885: add ioremap return check and cleanup (git-fixes).
- media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (git-fixes).
- media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes).
- media: msi2500: Return queued buffers on start_streaming() failure (git-fixes).
- media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes).
- media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes).
- media: nxp: imx8-isi: Convert to platform remove callback returning void (stable-fixes).
- media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes).
- media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes).
- media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes).
- media: nxp: imx8-isi: Fix use-after-free on remove (git-fixes).
- media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (stable-fixes).
- media: pwc: Drain fill_buf on start_streaming() failure (git-fixes).
- media: pwc: Return queued buffers on start_streaming() failure (git-fixes).
- media: qcom: venus: drop extra padding in NV12 raw size calculation (git-fixes).
- media: qcom: venus: relax encoder frame/blur dimension steps on v4 (git-fixes).
- media: qcom: venus: relax encoder frame/blur step size on v6 (git-fixes).
- media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes).
- media: rockchip: rga: fix too small buffer size (git-fixes).
- media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes).
- media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes).
- media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes).
- media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (git-fixes).
- media: stm32: dcmi: unregister notifier on probe failure (git-fixes).
- media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes).
- media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes).
- media: uvcvideo: Avoid partial metadata buffers (git-fixes).
- media: uvcvideo: Fix buffer sequence in frame gaps (git-fixes).
- media: uvcvideo: Fix sequence number when no EOF (git-fixes).
- media: v4l2-common: Add YUV24 format info (git-fixes).
- media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes).
- media: vivid: add vivid_update_reduced_fps() (git-fixes).
- media: vivid: check for vb2_is_busy() when toggling caps (git-fixes).
- mei: bus: access mei_device under device_lock on cleanup (git-fixes).
- memstick: ms_block: reject a card that reports too many blocks (git-fixes).
- mfd: cros_ec: Delay dev_set_drvdata() until probe success (git-fixes).
- mfd: sm501: Fix reference leak on failed device registration (git-fixes).
- mfd: tps6586x: Fix OF node refcount (git-fixes).
- mkspec-dtb: Skip missing DTBs.
- mm: convert pagecache_isize_extended to use a folio (bsc#1272920).
- mm: fix the inaccurate memory statistics issue for users (bsc#1268648).
- mm: list_lru: disable memcg_aware when cgroup.memory is set to 'nokmem' (bsc#1271402).
- mm: zero range of eof folio exposed by inode size extension (bsc#1272920).
- mmc: vub300: defer reset until cmd_mutex is unlocked (git-fixes).
- mtd: mchp23k256: use SPI match data for chip caps (git-fixes).
- mtd: mtdswap: remove debugfs stats file on teardown (git-fixes).
- mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes).
- mtd: onenand: samsung: report DMA completion timeouts (git-fixes).
- mtd: rawnand: Add a helper for calculating a page index (stable-fixes).
- mtd: rawnand: Ensure all continuous terms are always in sync (git-fixes).
- mtd: rawnand: fsl_ifc: return errors for failed page reads (git-fixes).
- mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (git-fixes).
- mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (git-fixes).
- mtd: rawnand: Pause continuous reads at block boundaries (git-fixes).
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866).
- net/x25: fix use-after-free in x25_kill_by_neigh() (git-fixes).
- net: mana: Add Interrupt Moderation support (bsc#1271368).
- net: mana: Return error code from mana_create_rxq() (git-fixes).
- net: thunderbolt: Fix frags overflow by bounding frame_count (git-fixes).
- net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (git-fixes).
- net: usb: lan78xx: move functions to avoid forward definitions (stable-fixes).
- net: wwan: t7xx: check skb_clone in control TX (git-fixes).
- net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (git-fixes).
- phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (git-fixes).
- phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (git-fixes).
- phy: zynqmp: use read-modify-write for SERDES scrambler bypass (git-fixes).
- pinctrl-amd: Don't clear S4 wake bits at probe (git-fixes).
- pinctrl: bm1880: add missing select GENERIC_PINCONF (git-fixes).
- pinctrl: devicetree: don't free uninitialized dev_name on error path (git-fixes).
- pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (git-fixes).
- pkspec-dtb: Fix dtb-al rename.
- platform/x86/amd/pmc: Add delay_suspend module parameter (stable-fixes).
- platform/x86/amd/pmc: Avoid logging '(null)' for DMI values (git-fixes).
- platform/x86/amd/pmc: Check for intermediate wakeup in function (stable-fixes).
- platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (stable-fixes).
- platform/x86/amd/pmc: Don't log during intermediate wakeups (stable-fixes).
- platform/x86: dell-smbios: Move request functions for reuse (stable-fixes).
- posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
- posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912).
- posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
- posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912).
- posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
- posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1271912).
- posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
- posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
- posix-timers: Add proper state tracking (bsc#1271912).
- posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
- posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
- posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
- posix-timers: Consolidate signal queueing (bsc#1271912).
- posix-timers: Consolidate timer setup (bsc#1271912).
- posix-timers: Cure si_sys_private race (bsc#1271912).
- posix-timers: Document common_clock_get() correctly (bsc#1271912).
- posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912).
- posix-timers: Polish coding style in a few places (bsc#1271912).
- posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912).
- power: supply: bq25890: fix the -10 C NTC lookup entry (git-fixes).
- RDMA/mana_ib: initialize err for empty send WR lists (git-fixes).
- regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (git-fixes).
- remoteproc: qcom: Fix leak when custom dump_segments addition fails (git-fixes).
- reset: sunxi: fix memory region leak on ioremap failure (git-fixes).
- Revert 'Input: rmi4 - fix register descriptor address calculation' (stable-fixes).
- sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134).
- sctp: validate embedded address parameter length (git-fixes).
- selftests: Disable dad for ipv6 in fcnal-test.sh (bsc#1272871).
- selftests: Replace sleep with slowwait (bsc#1272871).
- serial: 8250_mid: Disable DMA for selected platforms (git-fixes).
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (git-fixes).
- serial: 8250_mid: Remove 8250_pci usage (stable-fixes).
- serial: sc16is7xx: implement gpio get_direction() callback (git-fixes).
- series.conf: disable failing patch.
- slimbus: Convert to platform remove callback returning void (stable-fixes).
- slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes).
- slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes).
- slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes).
- slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes).
- slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes).
- slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git-fixes).
- slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git-fixes).
- staging: media: atomisp: reduce load_primary_binaries() stack usage (git-fixes).
- staging: rtl8723bs: core: move constants to right side in comparison (stable-fixes).
- staging: rtl8723bs: fix inverted HT40 secondary channel offset (git-fixes).
- task_work: Fix NMI race condition (git-fixes).
- time: Switch to hrtimer_setup() (bsc#1271912).
- uio_hv_generic: Bind to FCopy device by default (git-fixes).
- usb: cdc_acm: Add quirk for Uniden BC125AT scanner (stable-fixes).
- usb: chipidea: fix usage_count leak when autosuspend_delay is negative (git-fixes).
- USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (stable-fixes).
- usb: core: port: Deattach Type-C connector on component unbind (git-fixes).
- usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (git-fixes).
- usb: gadget: f_midi: cancel pending IN work before freeing the midi object (git-fixes).
- usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (git-fixes).
- USB: gadget: fsl-udc: fix dev_printk() device (git-fixes).
- USB: gadget: fsl-udc: fix device name leak on probe failure (git-fixes).
- usb: gadget: function: rndis: add length check for header (stable-fixes).
- usb: gadget: function: rndis: add length check to response query (stable-fixes).
- usb: gadget: printer: fix infinite loop in printer_read() (git-fixes).
- USB: gadget: snps-udc: fix device name leak on probe failure (git-fixes).
- usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (git-fixes).
- usb: gadget: udc: Fix use-after-free in gadget_match_driver (stable-fixes).
- usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (git-fixes).
- USB: iowarrior: fix use-after-free on disconnect race (git-fixes).
- usb: iowarrior: remove inherent race with minor number (stable-fixes).
- USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (stable-fixes).
- USB: serial: io_edgeport: cap received transmit credits (git-fixes).
- USB: serial: io_ti: reject oversized boot-mode firmware (git-fixes).
- USB: serial: keyspan_pda: fix data loss on receive throttling (git-fixes).
- USB: serial: mxuport: validate firmware header size (git-fixes).
- USB: serial: option: add Telit Cinterion FE990D50 compositions (stable-fixes).
- wan: wanxl: Only reset hardware after BAR mapping (git-fixes).
- watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (git-fixes).
- wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (git-fixes).
- wifi: ath6kl: fix OOB access from firmware ADDBA window size (git-fixes).
- wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (git-fixes).
- wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (git-fixes).
- wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (git-fixes).
- wifi: ath10k: fix skb leak on incomplete msdu during rx pop (git-fixes).
- wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (git-fixes).
- wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (git-fixes).
- wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes).
- wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes).
- wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (git-fixes).
- wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes).
- wifi: brcmfmac: make release_scratchbuffers idempotent (git-fixes).
- wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (git-fixes).
- wifi: carl9170: fix buffer overflow in rx_stream failover path (git-fixes).
- wifi: carl9170: fix OOB read from off-by-two in TX status handler (git-fixes).
- wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes).
- wifi: cfg80211: cancel sched scan results work on unregister (git-fixes).
- wifi: cfg80211: derive S1G beacon TSF from S1G fields (git-fixes).
- wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes).
- wifi: cfg80211: validate PMSR FTM preamble range (git-fixes).
- wifi: cfg80211: validate PMSR measurement type data (git-fixes).
- wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes).
- wifi: iwlwifi: mvm: fix flushing during quiet CSA (bsc#1272600).
- wifi: iwlwifi: mvm: fix read in wake packet notification handler (git-fixes).
- wifi: iwlwifi: mvm: validate SAR GEO response payload size (git-fixes).
- wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes).
- wifi: mac80211: fix fils_discovery double free on alloc failure (git-fixes).
- wifi: mac80211: fix memory leak in ieee80211_register_hw() (git-fixes).
- wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (git-fixes).
- wifi: mac80211: free ack status frame on TX header build failure (git-fixes).
- wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes).
- wifi: mac80211: recalculate TIM when a station enters power save (git-fixes).
- wifi: mac80211: tear down new links on vif update error path (git-fixes).
- wifi: mac80211: validate individual TWT params before driver setup (git-fixes).
- wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (git-fixes).
- wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (git-fixes).
- wifi: mt76: mt7915: guard HE capability lookups (git-fixes).
- wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (git-fixes).
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (git-fixes).
- wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (git-fixes).
- wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (git-fixes).
- wifi: mwifiex: bound uAP association event IEs to the event buffer (git-fixes).
- wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (git-fixes).
- wifi: mwifiex: fix permanently busy scans after multiple roam iterations (git-fixes).
- wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (git-fixes).
- wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes).
- wifi: nl80211: validate nested MBSSID IE blobs (git-fixes).
- wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes).
- wifi: rt2x00: avoid full teardown before work setup in probe (git-fixes).
- wifi: wilc1000: validate assoc response length before subtracting header (git-fixes).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3798-1
Released:    Tue Aug 25 14:40:59 2026
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1262632,1262633,1262635,1262636,1262638,1263440,1268412,CVE-2026-5545,CVE-2026-5773,CVE-2026-6253,CVE-2026-6276,CVE-2026-6429,CVE-2026-7168,CVE-2026-8926
This update for curl fixes the following issues:

- CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632).
- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635).
- CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636).
- CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).


The following package changes have been done:

- libcurl4-8.14.1-150700.7.23.1 updated
- kernel-macros-6.4.0-150700.53.78.1 updated
- kernel-devel-6.4.0-150700.53.78.1 updated
- kernel-default-devel-6.4.0-150700.53.78.1 updated
- kernel-syms-6.4.0-150700.53.78.1 updated
- container:registry.suse.com-bci-bci-base-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated


More information about the sle-container-updates mailing list