SUSE-SU-2023:0146-1: important: Security update for the Linux Kernel

sle-security-updates at sle-security-updates at
Thu Jan 26 11:22:45 UTC 2023

   SUSE Security Update: Security update for the Linux Kernel

Announcement ID:    SUSE-SU-2023:0146-1
Rating:             important
References:         #1065729 #1187428 #1188605 #1190969 #1191259 
                    #1193629 #1199294 #1201068 #1203219 #1203740 
                    #1203829 #1204614 #1204652 #1204760 #1204911 
                    #1204989 #1205257 #1205263 #1205485 #1205496 
                    #1205601 #1205695 #1206073 #1206098 #1206101 
                    #1206188 #1206209 #1206344 #1206389 #1206390 
                    #1206391 #1206393 #1206394 #1206395 #1206396 
                    #1206397 #1206398 #1206399 #1206456 #1206468 
                    #1206515 #1206536 #1206554 #1206602 #1206619 
                    #1206664 #1206703 #1206794 #1206896 #1206912 
                    #1207016 PED-1445 PED-568 
Cross-References:   CVE-2022-3104 CVE-2022-3105 CVE-2022-3106
                    CVE-2022-3107 CVE-2022-3108 CVE-2022-3111
                    CVE-2022-3112 CVE-2022-3113 CVE-2022-3114
                    CVE-2022-3115 CVE-2022-3344 CVE-2022-3564
                    CVE-2022-4379 CVE-2022-4662 CVE-2022-47520
CVSS scores:
                    CVE-2022-3104 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3104 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3105 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3105 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3106 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3106 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3107 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3107 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3108 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3108 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3111 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3111 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3112 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3112 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3113 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3113 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3114 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3114 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3115 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3115 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3344 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-3344 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
                    CVE-2022-3564 (NVD) : 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
                    CVE-2022-3564 (SUSE): 8 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
                    CVE-2022-4379 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-4379 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
                    CVE-2022-4662 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-4662 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2022-47520 (NVD) : 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
                    CVE-2022-47520 (SUSE): 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Affected Products:
                    SUSE Linux Enterprise High Performance Computing 15-SP4
                    SUSE Linux Enterprise Module for Public Cloud 15-SP4
                    SUSE Linux Enterprise Server 15-SP4
                    SUSE Linux Enterprise Server for SAP Applications 15-SP4
                    SUSE Manager Proxy 4.3
                    SUSE Manager Retail Branch Server 4.3
                    SUSE Manager Server 4.3
                    openSUSE Leap 15.4

   An update that solves 15 vulnerabilities, contains two
   features and has 36 fixes is now available.


   The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various
   security and bugfixes.

   The following security bugs were fixed:

   - CVE-2022-3344: Fixed a flaw found in the KVM's AMD nested virtualization
     (SVM). A malicious L1 guest could purposely fail to intercept the
     shutdown of a cooperative nested guest (L2), possibly leading to a page
     fault and kernel panic in the host (L0). (bsc#1204652)
   - CVE-2022-4662: Fixed a recursive locking violation in usb-storage that
     can cause the kernel to deadlock. (bsc#1206664)
   - CVE-2022-3115: Fixed a null pointer dereference in malidp_crtc.c caused
     by a lack of checks of the return value of kzalloc. (bsc#1206393)
   - CVE-2022-47520: Fixed an out-of-bounds read when parsing a Robust
     Security Network (RSN) information element from a Netlink packet.
   - CVE-2022-3112: Fixed a null pointer dereference caused by a missing
     check of the return value of kzalloc() in
     vdec_helpers.c:amvdec_set_canvases. (bsc#1206399)
   - CVE-2022-3564: Fixed a bug which could lead to use after free, it was
     found in the function l2cap_reassemble_sdu of the file
     net/bluetooth/l2cap_core.c of the component Bluetooth. (bsc#1206073)
   - CVE-2022-4379: Fixed a use-after-free vulnerability in
     nfs4file.c:__nfs42_ssc_open. (bsc#1206209)
   - CVE-2022-3108: Fixed a bug in kfd_parse_subtype_iolink in
     drivers/gpu/drm/amd/amdkfd/kfd_crat.c where a lack of check of the
     return value of kmemdup() could lead to a NULL pointer dereference.
   - CVE-2022-3104: Fixed a  null pointer dereference caused by caused by a
     missing check of the return value of kzalloc() in
     bugs.c:lkdtm_ARRAY_BOUNDS. (bsc#1206396)
   - CVE-2022-3113: Fixed a null pointer dereference caused by a missing
     check of the return value of devm_kzalloc. (bsc#1206390)
   - CVE-2022-3107: Fixed a null pointer dereference caused by a missing
     check of the return value of kvmalloc_array. (bsc#1206395)
   - CVE-2022-3114: Fixed a null pointer dereference caused by a missing
     check of the return value of kcalloc. (bsc#1206391)
   - CVE-2022-3111: Fixed a missing release of resource after effective
     lifetime bug caused by a missing free of the WM8350_IRQ_CHG_FAST_RDY in
     wm8350_init_charger. (bsc#1206394)
   - CVE-2022-3105: Fixed a null pointer dereference caused by a missing
     check of the return value of kmalloc_array. (bsc#1206398)
   - CVE-2022-3106: Fixed a null pointer dereference caused by a missing
     check of the return value of kmalloc. (bsc#1206397)

   The following non-security bugs were fixed:

   - acct: fix potential integer overflow in encode_comp_t() (git-fixes).
   - ACPI: resource: Skip IRQ override on Asus Vivobook K3402ZA/K3502ZA
   - ACPICA: Fix error code path in acpi_ds_call_control_method() (git-fixes).
   - ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage()
   - ALSA: asihpi: fix missing pci_disable_device() (git-fixes).
   - ALSA: hda/hdmi: Add HP Device 0x8711 to force connect list (git-fixes).
   - ALSA: hda/realtek: Add quirk for Lenovo TianYi510Pro-14IOB (git-fixes).
   - ALSA: hda/realtek: Apply dual codec fixup for Dell Latitude laptops
   - ALSA: line6: correct midi status byte when receiving data from podxt
   - ALSA: line6: fix stack overflow in line6_midi_transmit (git-fixes).
   - ALSA: mts64: fix possible null-ptr-defer in snd_mts64_interrupt
   - ALSA: patch_realtek: Fix Dell Inspiron Plus 16 (git-fixes).
   - ALSA: pcm: fix undefined behavior in bit shift for SNDRV_PCM_RATE_KNOT
   - ALSA: pcm: Set missing stop_operating flag at undoing trigger start
   - ALSA: seq: Fix function prototype mismatch in snd_seq_expand_var_event
   - ALSA: seq: fix undefined behavior in bit shift for
     SNDRV_SEQ_FILTER_USE_EVENT (git-fixes).
   - ALSA: usb-audio: add the quirk for KT0206 device (git-fixes).
   - amdgpu/pm: prevent array underflow in vega20_odn_edit_dpm_table()
   - apparmor: fix a memleak in multi_transaction_new() (git-fixes).
   - apparmor: Fix abi check to include v8 abi (git-fixes).
   - apparmor: fix lockdep warning when removing a namespace (git-fixes).
   - apparmor: Fix memleak in alloc_ns() (git-fixes).
   - apparmor: Use pointer to struct aa_label for lbs_cred (git-fixes).
   - ARM: 9251/1: perf: Fix stacktraces for tracepoint events in THUMB2
     kernels (git-fixes).
   - ARM: 9256/1: NWFPE: avoid compiler-generated __aeabi_uldivmod
   - ARM: dts: armada-370: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: armada-375: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: armada-38x: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: armada-38x: Fix compatible string for gpios (git-fixes).
   - ARM: dts: armada-39x: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: armada-39x: Fix compatible string for gpios (git-fixes).
   - ARM: dts: armada-xp: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: dove: Fix assigned-addresses for every PCIe Root Port
   - ARM: dts: nuvoton: Remove bogus unit addresses from fixed-partition
     nodes (git-fixes).
   - ARM: dts: qcom: apq8064: fix coresight compatible (git-fixes).
   - ARM: dts: rockchip: disable arm_global_timer on rk3066 and rk3188
   - ARM: dts: rockchip: fix ir-receiver node names (git-fixes).
   - ARM: dts: rockchip: fix node name for hym8563 rtc (git-fixes).
   - ARM: dts: rockchip: remove clock-frequency from rtc (git-fixes).
   - ARM: dts: rockchip: rk3188: fix lcdc1-rgb24 node name (git-fixes).
   - ARM: dts: spear600: Fix clcd interrupt (git-fixes).
   - ARM: dts: stm32: Drop stm32mp15xc.dtsi from Avenger96 (git-fixes).
   - ARM: dts: stm32: Fix AV96 WLAN regulator gpio property (git-fixes).
   - ARM: dts: turris-omnia: Add ethernet aliases (git-fixes).
   - ARM: dts: turris-omnia: Add switch port 6 node (git-fixes).
   - ARM: mmp: fix timer_read delay (git-fixes).
   - ARM: ux500: do not directly dereference __iomem (git-fixes).
   - arm64: Avoid repeated AA64MMFR1_EL1 register read on pagefault path
     (performance bsc#1203219).
   - arm64: dts: armada-3720-turris-mox: Add missing interrupt for RTC
   - arm64: dts: mediatek: mt6797: Fix 26M oscillator unit name (git-fixes).
   - arm64: dts: mediatek: pumpkin-common: Fix devicetree warnings
   - arm64: dts: mt2712-evb: Fix usb vbus regulators unit names (git-fixes).
   - arm64: dts: mt2712-evb: Fix vproc fixed regulators unit names
   - arm64: dts: mt2712e: Fix unit address for pinctrl node (git-fixes).
   - arm64: dts: mt2712e: Fix unit_address_vs_reg warning for oscillators
   - arm64: dts: mt6779: Fix devicetree build warnings (git-fixes).
   - arm64: dts: mt7622: drop r_smpl property from mmc node (git-fixes).
   - arm64: dts: mt8183: drop drv-type from mmc-node (git-fixes).
   - arm64: dts: mt8183: Fix Mali GPU clock (git-fixes).
   - arm64: dts: qcom: ipq6018-cp01-c1: use BLSPI1 pins (git-fixes).
   - arm64: dts: qcom: msm8916: Drop MSS fallback compatible (git-fixes).
   - arm64: dts: qcom: msm8996: Add MSM8996 Pro support (git-fixes).
   - arm64: dts: qcom: msm8996: fix GPU OPP table (git-fixes).
   - arm64: dts: qcom: msm8996: fix supported-hw in cpufreq OPP tables
   - arm64: dts: qcom: sdm630: fix UART1 pin bias (git-fixes).
   - arm64: dts: qcom: sdm845-cheza: fix AP suspend pin bias (git-fixes).
   - arm64: dts: qcom: sdm845-db845c: correct SPI2 pins drive strength
   - arm64: dts: qcom: sdm850-lenovo-yoga-c630: correct I2C12 pins drive
     strength (git-fixes).
   - arm64: dts: qcom: sm8250-sony-xperia-edo: fix touchscreen bias-disable
   - arm64: dts: qcom: sm8250: correct LPASS pin pull down (git-fixes).
   - arm64: dts: qcom: sm8250: drop bogus DP PHY clock (git-fixes).
   - arm64: dts: qcom: sm8250: fix USB-DP PHY registers (git-fixes).
   - arm64: dts: rockchip: fix ir-receiver node names (git-fixes).
   - arm64: dts: rockchip: keep I2S1 disabled for GPIO function on ROCK Pi 4
     series (git-fixes).
   - arm64: dts: ti: k3-am65-main: Drop dma-coherent in crypto node
   - arm64: dts: ti: k3-j721e-main: Drop dma-coherent in crypto node
   - ASoC: audio-graph-card: fix refcount leak of cpu_ep in
     __graph_for_each_link() (git-fixes).
   - ASoC: codecs: rt298: Add quirk for KBL-R RVP platform (git-fixes).
   - ASoC: cs42l51: Correct PGA Volume minimum value (git-fixes).
   - ASoC: dt-bindings: wcd9335: fix reset line polarity in example
   - ASoC: fsl_micfil: explicitly clear CHnF flags (git-fixes).
   - ASoC: fsl_micfil: explicitly clear software reset bit (git-fixes).
   - ASoC: Intel: bytcr_rt5640: Add quirk for the Advantech MICA-071 tablet
   - ASoC: jz4740-i2s: Handle independent FIFO flush bits (git-fixes).
   - ASoC: mediatek: mt8173-rt5650-rt5514: fix refcount leak in
     mt8173_rt5650_rt5514_dev_probe() (git-fixes).
   - ASoC: mediatek: mt8173: Enable IRQ when pdata is ready (git-fixes).
   - ASoC: mediatek: mt8183: fix refcount leak in
     mt8183_mt6358_ts3a227_max98357_dev_probe() (git-fixes).
   - ASoC: mediatek: mtk-btcvsd: Add checks for write and read of
     mtk_btcvsd_snd (git-fixes).
   - ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
   - ASoC: ops: Correct bounds check for second channel on SX controls
   - ASoC: pcm512x: Fix PM disable depth imbalance in pcm512x_probe
   - ASoC: pxa: fix null-pointer dereference in filter() (git-fixes).
   - ASoC: qcom: Add checks for devm_kcalloc (git-fixes).
   - ASoC: rockchip: pdm: Add missing clk_disable_unprepare() in
     rockchip_pdm_runtime_resume() (git-fixes).
   - ASoC: rockchip: spdif: Add missing clk_disable_unprepare() in
     rk_spdif_runtime_resume() (git-fixes).
   - ASoC: rt5670: Remove unbalanced pm_runtime_put() (git-fixes).
   - ASoC: rt711-sdca: fix the latency time of clock stop prepare state
     machine transitions (git-fixes).
   - ASoC: soc-pcm: Add NULL check in BE reparenting (git-fixes).
   - ASoC: wm8962: Wait for updated value of WM8962_CLOCKING1 register
   - ASoC: wm8994: Fix potential deadlock (git-fixes).
   - ata: ahci: Fix PCS quirk application for suspend (git-fixes).
   - binfmt_elf: fix documented return value for load_elf_phdrs() (git-fixes).
   - binfmt_misc: fix shift-out-of-bounds in check_special_flags (git-fixes).
   - binfmt: Fix error return code in load_elf_fdpic_binary() (git-fixes).
   - block: Do not reread partition table on exclusively open device
   - Bluetooth: btintel: Fix missing free skb in btintel_setup_combined()
   - Bluetooth: btusb: Add debug message for CSR controllers (git-fixes).
   - Bluetooth: btusb: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: hci_bcsp: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: hci_core: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: hci_h5: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: hci_ll: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: hci_qca: do not call kfree_skb() under spin_lock_irqsave()
   - Bluetooth: MGMT: Fix error report for ADD_EXT_ADV_PARAMS (git-fixes).
   - Bluetooth: RFCOMM: do not call kfree_skb() under spin_lock_irqsave()
   - brcmfmac: return error when getting invalid max_flowrings from dongle
   - caif: fix memory leak in cfctrl_linkup_request() (git-fixes).
   - can: do not increase rx statistics when generating a CAN rx error
     message frame (git-fixes).
   - can: do not increase rx_bytes statistics for RTR frames (git-fixes).
   - can: kvaser_usb_leaf: Fix bogus restart events (git-fixes).
   - can: kvaser_usb_leaf: Fix wrong CAN state after stopping (git-fixes).
   - can: kvaser_usb_leaf: Set Warning state even without bus errors
   - can: kvaser_usb: do not increase tx statistics when sending error
     message frames (git-fixes).
   - can: kvaser_usb: kvaser_usb_leaf: fix bittiming limits (git-fixes).
   - can: kvaser_usb: make use of units.h in assignment of frequency
   - can: m_can: fix typo prescalar -> prescaler (git-fixes).
   - can: m_can: is_lec_err(): clean up LEC error handling (git-fixes).
   - can: mcba_usb: Fix termination command argument (git-fixes).
   - can: sja1000: fix size of OCR_MODE_MASK define (git-fixes).
   - can: tcan4x5x: Remove invalid write in clear_interrupts (git-fixes).
   - chardev: fix error handling in cdev_device_add() (git-fixes).
   - cifs: Add "extbuf" and "extbuflen" args to smb2_compound_op()
   - cifs: do not block in dfs_cache_noreq_update_tgthint() (bsc#1193629).
   - cifs: do not leak -ENOMEM in smb2_open_file() (bsc#1193629).
   - cifs: do not refresh cached referrals from unactive mounts (bsc#1193629).
   - cifs: fix confusing debug message (bsc#1193629).
   - cifs: Fix kmap_local_page() unmapping (git-fixes).
   - cifs: fix missing display of three mount options (bsc#1193629).
   - cifs: fix oops during encryption (bsc#1199294).
   - cifs: fix refresh of cached referrals (bsc#1193629).
   - cifs: fix source pathname comparison of dfs supers (bsc#1193629).
   - cifs: fix various whitespace errors in headers (bsc#1193629).
   - cifs: get rid of mount options string parsing (bsc#1193629).
   - cifs: minor cleanup of some headers (bsc#1193629).
   - cifs: optimize reconnect of nested links (bsc#1193629).
   - cifs: Parse owner/group for stat in smb311 posix extensions
   - cifs: print warning when conflicting soft vs. hard mount options
     specified (bsc#1193629).
   - cifs: reduce roundtrips on create/qinfo requests (bsc#1193629).
   - cifs: refresh root referrals (bsc#1193629).
   - cifs: Remove duplicated include in cifsglob.h (bsc#1193629).
   - cifs: remove unused smb3_fs_context::mount_options (bsc#1193629).
   - cifs: set correct ipc status after initial tree connect (bsc#1193629).
   - cifs: set correct status of tcon ipc when reconnecting (bsc#1193629).
   - cifs: set correct tcon status after initial tree connect (bsc#1193629).
   - cifs: set resolved ip in sockaddr (bsc#1193629).
   - cifs: share dfs connections and supers (bsc#1193629).
   - cifs: skip alloc when request has no pages (bsc#1193629).
   - cifs: split out ses and tcon retrieval from mount_get_conns()
   - cifs: update internal module number (bsc#1193629).
   - cifs: use fs_context for automounts (bsc#1193629).
   - cifs: use origin fullpath for automounts (bsc#1193629).
   - class: fix possible memory leak in __class_register() (git-fixes).
   - clk: Fix pointer casting to prevent oops in devm_clk_release()
   - clk: generalize devm_clk_get() a bit (git-fixes).
   - clk: imx: imx8mp: add shared clk gate for usb suspend clk (git-fixes).
   - clk: imx: replace osc_hdmi with dummy (git-fixes).
   - clk: nomadik: correct struct name kernel-doc warning (git-fixes).
   - clk: Provide new devm_clk helpers for prepared and enabled clocks
   - clk: qcom: clk-krait: fix wrong div2 functions (git-fixes).
   - clk: qcom: gcc-sm8250: Use retention mode for USB GDSCs (git-fixes).
   - clk: qcom: lpass-sc7180: Fix pm_runtime usage (git-fixes).
   - clk: renesas: r9a06g032: Repair grave increment error (git-fixes).
   - clk: rockchip: Fix memory leak in rockchip_clk_register_pll()
   - clk: samsung: Fix memory leak in _samsung_clk_register_pll() (git-fixes).
   - clk: socfpga: Fix memory leak in socfpga_gate_init() (git-fixes).
   - clk: st: Fix memory leak in st_of_quadfs_setup() (git-fixes).
   - clk: sunxi-ng: v3s: Correct the header guard of ccu-sun8i-v3s.h
   - clocksource/drivers/sh_cmt: Access registers according to spec
   - clocksource/drivers/timer-ti-dm: Fix missing clk_disable_unprepare in
     dmtimer_systimer_init_clock() (git-fixes).
   - cpufreq: ACPI: Defer setting boost MSRs (bsc#1205485).
   - cpufreq: ACPI: Only set boost MSRs on supported CPUs (bsc#1205485).
   - cpufreq: ACPI: Remove unused variables 'acpi_cpufreq_online' and 'ret'
   - cpufreq: intel_pstate: Add Sapphire Rapids support in no-HWP mode
   - crypto: ccree - Make cc_debugfs_global_fini() available for module init
     function (git-fixes).
   - crypto: ccree - Remove debugfs when platform_driver_register failed
   - crypto: cryptd - Use request context instead of stack for sub-request
   - crypto: hisilicon/qm - fix missing destroy qp_idr (git-fixes).
   - crypto: img-hash - Fix variable dereferenced before check 'hdev->req'
   - crypto: n2 - add missing hash statesize (git-fixes).
   - crypto: nitrox - avoid double free on error path in nitrox_sriov_init()
   - crypto: omap-sham - Use pm_runtime_resume_and_get() in omap_sham_probe()
   - crypto: rockchip - add fallback for ahash (git-fixes).
   - crypto: rockchip - add fallback for cipher (git-fixes).
   - crypto: rockchip - better handle cipher key (git-fixes).
   - crypto: rockchip - do not do custom power management (git-fixes).
   - crypto: rockchip - do not store mode globally (git-fixes).
   - crypto: rockchip - remove non-aligned handling (git-fixes).
   - crypto: rockchip - rework by using crypto_engine (git-fixes).
   - crypto: sun8i-ss - use dma_addr instead u32 (git-fixes).
   - crypto: tcrypt - Fix multibuffer skcipher speed test mem leak
   - device property: Fix documentation for fwnode_get_next_parent()
   - dmaengine: idxd: Fix crc_val field for completion record (git-fixes).
   - docs/zh_CN: Fix '.. only::' directive's expression (git-fixes).
   - Documentation: bonding: update miimon default to 100 (git-fixes).
   - Documentation: devres: add missing devm_acpi_dma_controller_free()
     helper (git-fixes).
   - Documentation: devres: add missing MEM helper (git-fixes).
   - Documentation: devres: add missing PHY helpers (git-fixes).
   - Documentation: devres: add missing PWM helper (git-fixes).
   - Documentation/ Only sed the beginning "arch" of
     ARCH_DIR (git-fixes).
   - drbd: destroy workqueue when drbd device was freed (git-fixes).
   - drbd: remove call to memset before free device/resource/connection
   - drbd: remove usage of list iterator variable after loop (git-fixes).
   - drbd: set QUEUE_FLAG_STABLE_WRITES (git-fixes).
   - drbd: use after free in drbd_create_device() (git-fixes).
   - driver core: Fix bus_type.match() error handling in __driver_attach()
   - drivers: dio: fix possible memory leak in dio_init() (git-fixes).
   - drivers: soc: ti: knav_qmss_queue: Mark knav_acc_firmwares as static
   - drm: bridge: dw_hdmi: fix preference of RGB modes over YUV420
   - drm/amd/display: fix array index out of bound error in bios parser
   - drm/amd/display: Manually adjust strobe for DCN303 (git-fixes).
   - drm/amd/display: prevent memory leak (git-fixes).
   - drm/amd/display: Use the largest vready_offset in pipe group (git-fixes).
   - drm/amd/pm/smu11: BACO is supported when it's in BACO state (git-fixes).
   - drm/amdgpu: fix pci device refcount leak (git-fixes).
   - drm/amdgpu: Fix PCI device refcount leak in amdgpu_atrm_get_bios()
   - drm/amdgpu: Fix type of second parameter in odn_edit_dpm_table()
     callback (git-fixes).
   - drm/amdgpu: Fix type of second parameter in trans_msg() callback
   - drm/amdgpu: handle polaris10/11 overlap asics (v2) (git-fixes).
   - drm/amdgpu: make display pinning more flexible (v2) (git-fixes).
   - drm/amdgpu/powerplay/psm: Fix memory leak in power state init
   - drm/amdgpu/sdma_v4_0: turn off SDMA ring buffer in the s2idle suspend
   - drm/amdkfd: Fix memory leakage (git-fixes).
   - drm/bridge: adv7533: remove dynamic lane switching from adv7533 bridge
   - drm/bridge: anx7625: Fix edid_read break case in sp_tx_edid_read()
   - drm/bridge: ti-sn65dsi86: Fix output polarity setting bug (git-fixes).
   - drm/connector: send hotplug uevent on connector cleanup (git-fixes).
   - drm/edid: Fix minimum bpc supported with DSC1.2 for HDMI sink
   - drm/etnaviv: add missing quirks for GC300 (git-fixes).
   - drm/etnaviv: do not truncate physical page address (git-fixes).
   - drm/fourcc: Add packed 10bit YUV 4:2:0 format (git-fixes).
   - drm/fourcc: Fix vsub/hsub for Q410 and Q401 (git-fixes).
   - drm/fsl-dcu: Fix return type of fsl_dcu_drm_connector_mode_valid()
   - drm/i915: Fix documentation for intel_uncore_forcewake_put__locked
   - drm/i915: remove circ_buf.h includes (git-fixes).
   - drm/i915: unpin on error in intel_vgpu_shadow_mm_pin() (git-fixes).
   - drm/i915/display: Do not disable DDI/Transcoder when setting phy test
     pattern (git-fixes).
   - drm/i915/dsi: fix VBT send packet port selection for dual link DSI
   - drm/i915/gvt: fix gvt debugfs destroy (git-fixes).
   - drm/i915/gvt: fix vgpu debugfs clean in remove (git-fixes).
   - drm/i915/migrate: do not check the scratch page (git-fixes).
   - drm/i915/migrate: fix length calculation (git-fixes).
   - drm/i915/migrate: fix offset calculation (git-fixes).
   - drm/i915/ttm: never purge busy objects (git-fixes).
   - drm/imx: ipuv3-plane: Fix overlay plane width (git-fixes).
   - drm/ingenic: Fix missing platform_driver_unregister() call in
     ingenic_drm_init() (git-fixes).
   - drm/mediatek: Fix return type of mtk_hdmi_bridge_mode_valid()
   - drm/mediatek: Modify dpi power on/off sequence (git-fixes).
   - drm/meson: Reduce the FIFO lines held when AFBC is not used (git-fixes).
   - drm/msm: Use drm_mode_copy() (git-fixes).
   - drm/panel/panel-sitronix-st7701: Remove panel on DSI attach failure
   - drm/panfrost: Fix GEM handle creation ref-counting (git-fixes).
   - drm/radeon: Add the missed acpi_put_table() to fix memory leak
   - drm/radeon: Fix PCI device refcount leak in radeon_atrm_get_bios()
   - drm/rockchip: lvds: fix PM usage counter unbalance in poweron
   - drm/rockchip: Use drm_mode_copy() (git-fixes).
   - drm/shmem-helper: Avoid vm_open error paths (git-fixes).
   - drm/shmem-helper: Remove errant put in error path (git-fixes).
   - drm/sti: Fix return type of sti_{dvo,hda,hdmi}_connector_mode_valid()
   - drm/sti: Use drm_mode_copy() (git-fixes).
   - drm/tegra: Add missing clk_disable_unprepare() in tegra_dc_probe()
   - drm/vmwgfx: Do not use screen objects when SEV is active (git-fixes).
   - drm/vmwgfx: Fix a sparse warning in kernel docs (git-fixes).
   - drm/vmwgfx: Validate the box size for the snooped cursor (git-fixes).
   - Drop FIPS mode DRBG->getrandom(2) wire-up (bsc#1191259)
   - dt-bindings: clock: qcom,aoncc-sm8250: fix compatible (git-fixes).
   - dt-bindings: clocks: imx8mp: Add ID for usb suspend clock (git-fixes).
   - dt-bindings: display: sun6i-dsi: Fix clock conditional (git-fixes).
   - dt-bindings: gpio: gpio-davinci: Increase maxItems in gpio-line-names
   - dt-bindings: net: sun8i-emac: Add phy-supply property (git-fixes).
   - EDAC/mc_sysfs: Increase legacy channel support to 12 (bsc#1205263).
   - efi: Add iMac Pro 2017 to uefi skip cert quirk (git-fixes).
   - ext4: avoid BUG_ON when creating xattrs (bsc#1205496).
   - extcon: usbc-tusb320: Add support for mode setting and reset (git-fixes).
   - extcon: usbc-tusb320: Add support for TUSB320L (git-fixes).
   - extcon: usbc-tusb320: Factor out extcon into dedicated functions
   - fbcon: Use kzalloc() in fbcon_prepare_logo() (git-fixes).
   - fbdev: fbcon: release buffer when fbcon_do_set_font() failed (git-fixes).
   - fbdev: geode: do not build on UML (git-fixes).
   - fbdev: matroxfb: G200eW: Increase max memory from 1 MB to 16 MB
   - fbdev: pm2fb: fix missing pci_disable_device() (git-fixes).
   - fbdev: ssd1307fb: Drop optional dependency (git-fixes).
   - fbdev: uvesafb: do not build on UML (git-fixes).
   - fbdev: uvesafb: Fixes an error handling path in uvesafb_probe()
   - fbdev: vermilion: decrease reference count in error path (git-fixes).
   - fbdev: via: Fix error in via_core_init() (git-fixes).
   - firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe()
   - floppy: Fix memory leak in do_floppy_init() (git-fixes).
   - gpio: sifive: Fix refcount leak in sifive_gpio_probe (git-fixes).
   - gpiolib: cdev: fix NULL-pointer dereferences (git-fixes).
   - gpiolib: check the 'ngpios' property in core gpiolib code (git-fixes).
   - gpiolib: fix memory leak in gpiochip_setup_dev() (git-fixes).
   - gpiolib: Get rid of redundant 'else' (git-fixes).
   - gpiolib: improve coding style for local variables (git-fixes).
   - gpiolib: make struct comments into real kernel docs (git-fixes).
   - hamradio: baycom_epp: Fix return type of baycom_send_packet()
   - hamradio: do not call dev_kfree_skb() under spin_lock_irqsave()
   - HID: hid-sensor-custom: set fixed size for custom attributes (git-fixes).
   - HID: ite: Enable QUIRK_TOUCHPAD_ON_OFF_REPORT on Acer Aspire Switch V 10
   - HID: mcp2221: do not connect hidraw (git-fixes).
   - HID: multitouch: fix Asus ExpertBook P2 P2451FA trackpoint (git-fixes).
   - HID: plantronics: Additional PIDs for double volume key presses quirk
   - HID: uclogic: Add HID_QUIRK_HIDINPUT_FORCE quirk (git-fixes).
   - HID: usbhid: Add ALWAYS_POLL quirk for some mice (git-fixes).
   - HID: wacom: Ensure bootloader PID is usable in hidraw mode (git-fixes).
   - HSI: omap_ssi_core: Fix error handling in ssi_init() (git-fixes).
   - HSI: omap_ssi_core: fix possible memory leak in ssi_probe() (git-fixes).
   - HSI: omap_ssi_core: fix unbalanced pm_runtime_disable() (git-fixes).
   - hwmon: (jc42) Convert register access and caching to regmap/regcache
   - hwmon: (jc42) Fix missing unlock on error in jc42_write() (git-fixes).
   - hwmon: (jc42) Restore the min/max/critical temperatures on resume
   - hwrng: amd - Fix PCI device refcount leak (git-fixes).
   - i2c: ismt: Fix an out-of-bounds bug in ismt_access() (git-fixes).
   - i2c: mux: reg: check return value after calling platform_get_resource()
   - i2c: pxa-pci: fix missing pci_disable_device() on error in
     ce4100_i2c_probe (git-fixes).
   - IB/IPoIB: Fix queue count inconsistency for PKEY child interfaces
   - ibmveth: Always stop tx queues during close (bsc#1065729).
   - iio: adc: ad_sigma_delta: do not use internal iio_dev lock (git-fixes).
   - iio: adc128s052: add proper .data members in adc128_of_match table
   - iio: fix memory leak in iio_device_register_eventset() (git-fixes).
   - iio: temperature: ltc2983: make bulk write buffer DMA-safe (git-fixes).
   - ima: Fix a potential NULL pointer access in ima_restore_measurement_list
   - Input: elants_i2c - properly handle the reset GPIO when power is off
   - Input: joystick - fix Kconfig warning for JOYSTICK_ADC (git-fixes).
   - Input: wistron_btns - disable on UML (git-fixes).
   - integrity: Fix memory leakage in keyring allocation error path
   - ipmi: fix long wait in unload when IPMI disconnect (git-fixes).
   - ipmi: fix memleak when unload ipmi driver (git-fixes).
   - ipmi: fix use after free in _ipmi_destroy_user() (git-fixes).
   - ipmi: kcs: Poll OBF briefly to reduce OBE latency (git-fixes).
   - ipu3-imgu: Fix NULL pointer dereference in imgu_subdev_set_selection()
   - kABI: reintroduce a non-inline usleep_range (git-fixes).
   - lib/debugobjects: fix stat count and optimize debug_objects_mem_init
   - lib/fonts: fix undefined behavior in bit shift for get_default_font
   - mailbox: arm_mhuv2: Fix return value check in mhuv2_probe() (git-fixes).
   - mailbox: mpfs: read the system controller's status (git-fixes).
   - mailbox: zynq-ipi: fix error handling while device_register() fails
   - media: adv748x: afe: Select input port when initializing AFE (git-fixes).
   - media: camss: Clean up received buffers on failed start of streaming
   - media: dvb-core: Fix double free in dvb_register_device() (git-fixes).
   - media: dvb-core: Fix ignored return value in dvb_register_frontend()
   - media: dvb-frontends: fix leak of memory fw (git-fixes).
   - media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()
   - media: dvb-usb: fix memory leak in dvb_usb_adapter_init() (git-fixes).
   - media: i2c: ad5820: Fix error path (git-fixes).
   - media: imon: fix a race condition in send_packet() (git-fixes).
   - media: saa7164: fix missing pci_disable_device() (git-fixes).
   - media: si470x: Fix use-after-free in si470x_int_in_callback()
   - media: solo6x10: fix possible memory leak in solo_sysfs_init()
   - media: stv0288: use explicitly signed char (git-fixes).
   - media: v4l2-ctrls: Fix off-by-one error in integer menu control check
   - media: v4l2-dv-timings.c: fix too strict blanking sanity checks
   - media: videobuf-dma-contig: use dma_mmap_coherent (git-fixes).
   - media: vidtv: Fix use-after-free in vidtv_bridge_dvb_init() (git-fixes).
   - media: vimc: Fix wrong function called when vimc_init() fails
   - media: vivid: fix compose size exceed boundary (git-fixes).
   - memcg, kmem: further deprecate kmem.limit_in_bytes (bsc#1206896).
   - memcg: Fix possible use-after-free in memcg_write_event_control()
   - mfd: bd957x: Fix Kconfig dependency on REGMAP_IRQ (git-fixes).
   - mfd: mt6360: Add bounds checking in Regmap read/write call-backs
   - mfd: pm8008: Fix return value check in pm8008_probe() (git-fixes).
   - mfd: pm8008: Remove driver data structure pm8008_data (git-fixes).
   - mfd: qcom_rpm: Fix an error handling path in qcom_rpm_probe()
   - mfd: qcom_rpm: Use devm_of_platform_populate() to simplify code
   - misc: ocxl: fix possible name leak in ocxl_file_register_afu()
   - misc: tifm: fix possible memory leak in tifm_7xx1_switch_media()
   - mISDN: hfcmulti: do not call dev_kfree_skb/kfree_skb() under
     spin_lock_irqsave() (git-fixes).
   - mISDN: hfcpci: do not call dev_kfree_skb/kfree_skb() under
     spin_lock_irqsave() (git-fixes).
   - mISDN: hfcsusb: do not call dev_kfree_skb/kfree_skb() under
     spin_lock_irqsave() (git-fixes).
   - mm: fix race between MADV_FREE reclaim and blkdev direct IO read
   - mm/mempolicy: fix memory leak in set_mempolicy_home_node system call
   - mmc: alcor: fix return value check of mmc_add_host() (git-fixes).
   - mmc: atmel-mci: fix return value check of mmc_add_host() (git-fixes).
   - mmc: core: Normalize the error handling branch in sd_read_ext_regs()
   - mmc: f-sdh30: Add quirks for broken timeout clock capability (git-fixes).
   - mmc: meson-gx: fix return value check of mmc_add_host() (git-fixes).
   - mmc: mmci: fix return value check of mmc_add_host() (git-fixes).
   - mmc: moxart: fix return value check of mmc_add_host() (git-fixes).
   - mmc: mtk-sd: Fix missing clk_disable_unprepare in msdc_of_clock_parse()
   - mmc: mxcmmc: fix return value check of mmc_add_host() (git-fixes).
   - mmc: omap_hsmmc: fix return value check of mmc_add_host() (git-fixes).
   - mmc: pxamci: fix return value check of mmc_add_host() (git-fixes).
   - mmc: renesas_sdhi: alway populate SCC pointer (git-fixes).
   - mmc: renesas_sdhi: better reset from HS400 mode (git-fixes).
   - mmc: rtsx_pci: fix return value check of mmc_add_host() (git-fixes).
   - mmc: rtsx_usb_sdmmc: fix return value check of mmc_add_host()
   - mmc: sdhci-sprd: Disable CLK_AUTO when the clock is less than 400K
   - mmc: toshsd: fix return value check of mmc_add_host() (git-fixes).
   - mmc: via-sdmmc: fix return value check of mmc_add_host() (git-fixes).
   - mmc: vub300: fix return value check of mmc_add_host() (git-fixes).
   - mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING
   - mmc: wbsd: fix return value check of mmc_add_host() (git-fixes).
   - mmc: wmt-sdmmc: fix return value check of mmc_add_host() (git-fixes).
   - module: change to print useful messages from elf_validity_check()
   - module: fix [e_shstrndx].sh_size=0 OOB access (git-fixes).
   - mt76: stop the radar detector after leaving dfs channel (git-fixes).
   - mtd: Fix device name leak when register device failed in
     add_mtd_device() (git-fixes).
   - mtd: lpddr2_nvm: Fix possible null-ptr-deref (git-fixes).
   - mtd: maps: pxa2xx-flash: fix memory leak in probe (git-fixes).
   - mtd: spi-nor: Check for zero erase size in
     spi_nor_find_best_erase_type() (git-fixes).
   - mtd: spi-nor: Fix the number of bytes for the dummy cycles (git-fixes).
   - mtd: spi-nor: hide jedec_id sysfs attribute if not present (git-fixes).
   - net: allow retransmitting a TCP packet if original is still in queue
     (bsc#1188605 bsc#1187428 bsc#1206619).
   - net: mana: Fix race on per-CQ variable napi work_done (git-fixes).
   - net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe
   - net: usb: qmi_wwan: add u-blox 0x1342 composition (git-fixes).
   - net: usb: smsc95xx: fix external PHY reset (git-fixes).
   - net/mlx5: Fix mlx5_get_next_dev() peer device matching (bsc#1206536).
   - net/mlx5: Lag, filter non compatible devices (bsc#1206536).
   - netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find()
   - nfc: Fix potential resource leaks (git-fixes).
   - nfc: pn533: Clear nfc_target before being used (git-fixes).
   - nfc: pn533: Wait for out_urb's completion in pn533_usb_send_frame()
   - NFS: Handle missing attributes in OPEN reply (bsc#1203740).
   - nilfs2: fix shift-out-of-bounds due to too large exponent of block size
   - nilfs2: fix shift-out-of-bounds/overflow in nilfs_sb2_bad_offset()
   - octeontx2-af: Add PTP PPS Errata workaround on CN10K silicon
   - octeontx2-af: Allow mkex profile without DMAC and add L2M/L2B header
     extraction support (jsc#SLE-24682).
   - octeontx2-af: Do not reset previous pfc config (jsc#SLE-24682).
   - octeontx2-af: fix operand size in bitwise operation (jsc#SLE-24682).
   - octeontx2-af: Initialize PTP_SEC_ROLLOVER register properly
   - octeontx2-af: Limit link bringup time at firmware (jsc#SLE-24682).
   - octeontx2-af: return correct ptp timestamp for CN10K silicon
   - octeontx2-af: Set NIX link credits based on max LMAC (jsc#SLE-24682).
   - octeontx2-af: Skip CGX/RPM probe incase of zero lmac count
   - octeontx2-pf: Add egress PFC support (jsc#SLE-24682).
   - octeontx2-pf: Add support for ptp 1-step mode on CN10K silicon
   - octeontx2-pf: Fix lmtst ID used in aura free (jsc#SLE-24682).
   - octeontx2-pf: Fix pfc_alloc_status array overflow (jsc#SLE-24682).
   - octeontx2-pf: Fix SQE threshold checking (jsc#SLE-24682).
   - octeontx2-pf: Fix unused variable build error (jsc#SLE-24682).
   - octeontx2-pf: NIX TX overwrites SQ_CTX_HW_S[SQ_INT] (jsc#SLE-24682).
   - octeontx2-pf: Reduce minimum mtu size to 60 (jsc#SLE-24682).
   - octeontx2: Modify mbox request and response structures (jsc#SLE-24682).
   - padata: Fix list iterator in padata_do_serial() (git-fixes).
   - PCI: Check for alloc failure in pci_request_irq() (git-fixes).
   - PCI: dwc: Fix n_fts[] array overrun (git-fixes).
   - PCI: Fix pci_device_is_present() for VFs by checking PF (git-fixes).
   - PCI: pci-epf-test: Register notifier if only core_init_notifier is
     enabled (git-fixes).
   - PCI: vmd: Disable MSI remapping after suspend (git-fixes).
   - PCI/sysfs: Fix double free in error path (git-fixes).
   - phy: usb: s2 WoL wakeup_count not incremented for USB->Eth devices
   - pinctrl: k210: call of_node_put() (git-fixes).
   - pinctrl: meditatek: Startup with the IRQs disabled (git-fixes).
   - pinctrl: pinconf-generic: add missing of_node_put() (git-fixes).
   - platform/chrome: cros_ec_typec: Cleanup switch handle return paths
   - platform/chrome: cros_usbpd_notify: Fix error handling in
     cros_usbpd_notify_init() (git-fixes).
   - platform/mellanox: mlxbf-pmc: Fix event typo (git-fixes).
   - platform/x86: huawei-wmi: fix return value calculation (git-fixes).
   - platform/x86: intel_scu_ipc: fix possible name leak in
     __intel_scu_ipc_register() (git-fixes).
   - platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
   - PM: hibernate: Fix mistake in kerneldoc comment (git-fixes).
   - PM: runtime: Do not call __rpm_callback() from rpm_idle() (git-fixes).
   - PNP: fix name memory leak in pnp_alloc_dev() (git-fixes).
   - power: supply: ab8500: Fix error handling in ab8500_charger_init()
   - power: supply: fix null pointer dereferencing in
     power_supply_get_battery_info (git-fixes).
   - power: supply: fix residue sysfs file in error handle route of
     __power_supply_register() (git-fixes).
   - power: supply: z2_battery: Fix possible memleak in z2_batt_probe()
   - powerpc: export the CPU node count (bsc#1207016 ltc#201108).
   - powerpc: Take in account addition CPU node when building kexec FDT
     (bsc#1207016 ltc#201108).
   - powerpc/64: Init jump labels before parse_early_param() (bsc#1065729).
   - powerpc/pci: Fix get_phb_number() locking (bsc#1065729).
   - powerpc/perf: callchain validate kernel stack pointer bounds
   - powerpc/powernv: add missing of_node_put (bsc#1065729).
   - powerpc/pseries: unregister VPA when hot unplugging a CPU (bsc#1205695
   - powerpc/pseries/eeh: use correct API for error log size (bsc#1065729).
   - powerpc/rtas: avoid device tree lookups in rtas_os_term() (bsc#1065729).
   - powerpc/rtas: avoid scheduling in rtas_os_term() (bsc#1065729).
   - powerpc/xive: add missing iounmap() in error path in
     xive_spapr_populate_irq_data() (git-fixes).
   - powerpc/xive/spapr: correct bitmap allocation size (git-fixes).
   - proc: fixup uptime selftest (git-fixes).
   - pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP (git-fixes).
   - pstore: Make sure CONFIG_PSTORE_PMSG selects CONFIG_RT_MUTEXES
   - pstore: Properly assign mem_type property (git-fixes).
   - pstore: Switch pmsg_lock to an rt_mutex to avoid priority inversion
   - pstore/ram: Fix error return code in ramoops_probe() (git-fixes).
   - pstore/zone: Use GFP_ATOMIC to allocate zone buffer (git-fixes).
   - pwm: lpc18xx-sct: Fix a comment to match code (git-fixes).
   - pwm: mediatek: always use bus clock for PWM on MT7622 (git-fixes).
   - pwm: sifive: Call pwm_sifive_update_clock() while mutex is held
   - pwm: tegra: Improve required rate calculation (git-fixes).
   - r6040: Fix kmemleak in probe and remove (git-fixes).
   - random: allow partial reads if later user copies fail (bsc#1204911).
   - random: check for signals every PAGE_SIZE chunk of /dev/random
   - random: convert to using fops->read_iter() (bsc#1204911).
   - random: convert to using fops->write_iter() (bsc#1204911).
   - random: remove outdated INT_MAX >> 6 check in urandom_read()
   - random: zero buffer after reading entropy from userspace (bsc#1204911).
   - RDMA: Disable IB HW for UML (git-fixes)
   - RDMA/core: Fix order of nldev_exit call (git-fixes)
   - RDMA/core: Make sure "ib_port" is valid when access sysfs node
   - RDMA/efa: Add EFA 0xefa2 PCI ID (git-fixes)
   - RDMA/hfi: Decrease PCI device reference count in error path (git-fixes)
   - RDMA/hfi1: Fix error return code in parse_platform_config() (git-fixes)
   - RDMA/hns: Fix AH attr queried by query_qp (git-fixes)
   - RDMA/hns: Fix error code of CMD (git-fixes)
   - RDMA/hns: Fix ext_sge num error when post send (git-fixes)
   - RDMA/hns: fix memory leak in hns_roce_alloc_mr() (git-fixes)
   - RDMA/hns: Fix page size cap from firmware (git-fixes)
   - RDMA/hns: Fix PBL page MTR find (git-fixes)
   - RDMA/hns: Fix XRC caps on HIP08 (git-fixes)
   - RDMA/hns: Repacing 'dseg_len' by macros in fill_ext_sge_inl_data()
   - RDMA/irdma: Do not request 2-level PBLEs for CQ alloc (git-fixes)
   - RDMA/irdma: Initialize net_type before checking it (git-fixes)
   - RDMA/irdma: Report the correct link speed (git-fixes)
   - RDMA/nldev: Add checks for nla_nest_start() in fill_stat_counter_qps()
   - RDMA/nldev: Fix failure to send large messages (git-fixes)
   - RDMA/nldev: Return "-EAGAIN" if the cm_id isn't from expected port
   - RDMA/restrack: Release MR restrack when delete (git-fixes)
   - RDMA/rxe: Fix NULL-ptr-deref in rxe_qp_do_cleanup() when socket create
     failed (git-fixes)
   - RDMA/siw: Fix immediate work request flush to completion queue
   - RDMA/siw: Fix pointer cast warning (git-fixes)
   - RDMA/siw: Set defined status for work completion with undefined status
   - RDMA/srp: Fix error return code in srp_parse_options() (git-fixes)
   - regulator: bd718x7: Drop unnecessary info print (git-fixes).
   - regulator: core: fix deadlock on regulator enable (git-fixes).
   - regulator: core: fix module refcount leak in set_supply() (git-fixes).
   - regulator: core: fix resource leak in regulator_register() (git-fixes).
   - regulator: core: fix unbalanced of node refcount in
     regulator_dev_lookup() (git-fixes).
   - regulator: core: fix use_count leakage when handling boot-on (git-fixes).
   - regulator: core: use kfree_const() to free space conditionally
   - regulator: qcom-labibb: Fix missing of_node_put() in
     qcom_labibb_regulator_probe() (git-fixes).
   - regulator: qcom-rpmh: Fix PMR735a S3 regulator spec (git-fixes).
   - regulator: slg51000: Wait after asserting CS pin (git-fixes).
   - regulator: twl6030: fix get status of twl6032 regulators (git-fixes).
   - remoteproc: core: Do pm_relax when in RPROC_OFFLINE state (git-fixes).
   - remoteproc: qcom_q6v5_pas: detach power domains on remove (git-fixes).
   - remoteproc: qcom_q6v5_pas: disable wakeup on probe fail or remove
   - remoteproc: qcom_q6v5_pas: Fix missing of_node_put() in
     adsp_alloc_memory_region() (git-fixes).
   - remoteproc: qcom: q6v5: Fix missing clk_disable_unprepare() in
     q6v5_wcss_qcs404_power_on() (git-fixes).
   - remoteproc: qcom: q6v5: Fix potential null-ptr-deref in
     q6v5_wcss_init_mmio() (git-fixes).
   - remoteproc: sysmon: fix memory leak in qcom_add_sysmon_subdev()
   - restore m_can_lec_type (git-fixes).
   - rtc: cmos: fix build on non-ACPI platforms (git-fixes).
   - rtc: cmos: Fix event handler registration ordering issue (git-fixes).
   - rtc: cmos: Fix wake alarm breakage (git-fixes).
   - rtc: ds1347: fix value written to century register (git-fixes).
   - rtc: mxc_v2: Add missing clk_disable_unprepare() (git-fixes).
   - rtc: pcf85063: fix pcf85063_clkout_control (gut-fixes).
   - rtc: pcf85063: Fix reading alarm (git-fixes).
   - rtc: pic32: Move devm_rtc_allocate_device earlier in pic32_rtc_probe()
   - rtc: rtc-cmos: Do not check ACPI_FADT_LOW_POWER_S0 (git-fixes).
   - rtc: snvs: Allow a time difference on clock register read (git-fixes).
   - rtc: st-lpc: Add missing clk_disable_unprepare in st_rtc_probe()
   - rtmutex: Add acquire semantics for rtmutex lock acquisition slow path
   - s390/boot: add secure boot trailer (bsc#1205257 LTC#200451).
   - sbitmap: fix lockup while swapping (bsc#1206602).
   - sched/core: Fix comparison in sched_group_cookie_match() (git-fixes)
   - sched/core: Fix the bug that task won't enqueue into core (git-fixes)
   - sched/topology: Remove redundant variable and fix incorrect (git-fixes)
   - sched/uclamp: Fix relationship between uclamp and migration (git-fixes)
   - sched/uclamp: Make task_fits_capacity() use util_fits_cpu() (git-fixes)
   - scsi: 3w-9xxx: Avoid disabling device if failing to enable it
   - scsi: advansys: Fix kernel pointer leak (git-fixes).
   - scsi: aha152x: Fix aha152x_setup() __setup handler return value
   - scsi: bfa: Replace snprintf() with sysfs_emit() (git-fixes).
   - scsi: core: Fix sbitmap depth in scsi_realloc_sdev_budget_map()
   - scsi: core: Fix scsi_mode_sense() buffer length handling (git-fixes).
   - scsi: core: Reallocate device's budget map on queue depth change
   - scsi: core: Restrict legal sdev_state transitions via sysfs (git-fixes).
   - scsi: hisi_sas: Free irq vectors in order for v3 HW (git-fixes).
   - scsi: hisi_sas: Limit max hw sectors for v3 HW (git-fixes).
   - scsi: hisi_sas: Use managed PCI functions (git-fixes).
   - scsi: ipr: Fix missing/incorrect resource cleanup in error case
   - scsi: iscsi: Add recv workqueue helpers (git-fixes).
   - scsi: iscsi: Fix harmless double shift bug (git-fixes).
   - scsi: iscsi: Fix possible memory leak when device_register() failed
   - scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername()
   - scsi: iscsi: kabi: add iscsi_conn_queue_work back (git-fixes).
   - scsi: iscsi: kabi: fix libiscsi new field (git-fixes).
   - scsi: iscsi: Merge suspend fields (git-fixes).
   - scsi: iscsi: Rename iscsi_conn_queue_work() (git-fixes).
   - scsi: iscsi: Run recv path from workqueue (git-fixes).
   - scsi: iscsi: Unblock session then wake up error handler (git-fixes).
   - scsi: libfc: Fix use after free in fc_exch_abts_resp() (git-fixes).
   - scsi: libiscsi: Fix UAF in iscsi_conn_get_param()/iscsi_conn_teardown()
   - scsi: lpfc: Correct bandwidth logging during receipt of congestion sync
     WCQE (jsc#PED-1445).
   - scsi: lpfc: Fix crash involving race between FLOGI timeout and devloss
     handler (jsc#PED-1445).
   - scsi: lpfc: Fix MI capability display in cmf_info sysfs attribute
   - scsi: lpfc: Fix WQ|CQ|EQ resource check (jsc#PED-1445).
   - scsi: lpfc: Remove linux/msi.h include (jsc#PED-1445).
   - scsi: lpfc: Remove redundant pointer 'lp' (jsc#PED-1445).
   - scsi: lpfc: Update lpfc version to (jsc#PED-1445).
   - scsi: lpfc: Use memset_startat() helper (jsc#PED-1445).
   - scsi: megaraid_sas: Fix double kfree() (git-fixes).
   - scsi: megaraid_sas: Target with invalid LUN ID is deleted during scan
   - scsi: megaraid: Fix error check return value of register_chrdev()
   - scsi: mpi3mr: Fix memory leaks (git-fixes).
   - scsi: mpi3mr: Fix reporting of actual data transfer size (git-fixes).
   - scsi: mpi3mr: Fixes around reply request queues (git-fixes).
   - scsi: mpt3sas: Do not change DMA mask while reallocating pools
   - scsi: mpt3sas: Fail reset operation if config request timed out
   - scsi: mpt3sas: Fix out-of-bounds compiler warning (git-fixes).
   - scsi: mpt3sas: re-do lost mpt3sas DMA mask fix (bsc#1206912,bsc#1206098).
   - scsi: mpt3sas: Remove usage of dma_get_required_mask() API
   - scsi: mvsas: Add PCI ID of RocketRaid 2640 (git-fixes).
   - scsi: mvsas: Replace snprintf() with sysfs_emit() (git-fixes).
   - scsi: myrb: Fix up null pointer access on myrb_cleanup() (git-fixes).
   - scsi: myrs: Fix crash in error case (git-fixes).
   - scsi: ncr53c8xx: Remove unused retrieve_from_waiting_list() function
   - scsi: pm8001: Fix bogus FW crash for maxcpus=1 (git-fixes).
   - scsi: pm8001: Fix memory leak in pm8001_chip_fw_flash_update_req()
   - scsi: pm8001: Fix pm8001_mpi_task_abort_resp() (git-fixes).
   - scsi: pm8001: Fix pm80xx_pci_mem_copy() interface (git-fixes).
   - scsi: pm8001: Fix tag leaks on error (git-fixes).
   - scsi: pm8001: Fix task leak in pm8001_send_abort_all() (git-fixes).
   - scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
   - scsi: pm8001: Fix use-after-free for aborted TMF sas_task (git-fixes).
   - scsi: pm80xx: Fix double completion for SATA devices (git-fixes).
   - scsi: pm80xx: Fix memory leak during rmmod (git-fixes).
   - scsi: pmcraid: Fix missing resource cleanup in error case (git-fixes).
   - scsi: qedf: Add stag_work to all the vports (git-fixes).
   - scsi: qedf: Change context reset messages to ratelimited (git-fixes).
   - scsi: qedf: Fix a UAF bug in __qedf_probe() (git-fixes).
   - scsi: qedf: Fix refcount issue when LOGO is received during TMF
   - scsi: qla2xxx: Fix crash when I/O abort times out (jsc#PED-568).
   - scsi: qla2xxx: Fix set-but-not-used variable warnings (jsc#PED-568).
   - scsi: qla2xxx: Initialize vha->unknown_atio_[list, work] for NPIV hosts
   - scsi: qla2xxx: Remove duplicate of vha->iocb_work initialization
   - scsi: qla2xxx: Remove unused variable 'found_devs' (jsc#PED-568).
   - scsi: scsi_debug: Fix out-of-bound read in resp_readcap16() (git-fixes).
   - scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs()
   - scsi: scsi_debug: Fix possible UAF in sdebug_add_host_helper()
   - scsi: scsi_debug: Make the READ CAPACITY response compliant with ZBC
   - scsi: scsi_dh_alua: Properly handle the ALUA transitioning state
   - scsi: smartpqi: Fix kdump issue when controller is locked up (git-fixes).
   - scsi: sr: Do not use GFP_DMA (git-fixes).
   - scsi: ufs: core: Fix ufshcd_probe_hba() prototype to match the
     definition (git-fixes).
   - scsi: ufs: Fix a kernel crash during shutdown (git-fixes).
   - scsi: ufs: Treat link loss as fatal error (git-fixes).
   - scsi: ufs: ufshcd-pltfrm: Check the return value of devm_kstrdup()
   - scsi: ufs: Use generic error code in ufshcd_set_dev_pwr_mode()
   - scsi: ufs: Use pm_runtime_resume_and_get() instead of
     pm_runtime_get_sync() (git-fixes).
   - scsi: vmw_pvscsi: Expand vcpuHint to 16 bits (git-fixes).
   - sctp: sysctl: make extra pointers netns aware (bsc#1204760).
   - selftests: devlink: fix the fd redirect in dummy_reporter_test
   - selftests: set the BUILD variable to absolute path (git-fixes).
   - selftests: Use optional USERCFLAGS and USERLDFLAGS (git-fixes).
   - selftests/efivarfs: Add checking of the test return value (git-fixes).
   - selftests/ftrace: event_triggers: wait longer for test_event_enable
   - selftests/powerpc: Fix resource leaks (git-fixes).
   - serial: 8250_bcm7271: Fix error handling in brcmuart_init() (git-fixes).
   - serial: amba-pl011: avoid SBSA UART accessing DMACR register (git-fixes).
   - serial: pch: Fix PCI device refcount leak in pch_request_dma()
   - serial: pl011: Do not clear RX FIFO & RX interrupt in unthrottle
   - serial: stm32: move dma_request_chan() before clk_prepare_enable()
   - serial: sunsab: Fix error handling in sunsab_init() (git-fixes).
   - serial: tegra: Read DMA status before terminating (git-fixes).
   - soc: mediatek: pm-domains: Fix the power glitch issue (git-fixes).
   - soc: qcom: llcc: make irq truly optional (git-fixes).
   - soc: qcom: Select REMAP_MMIO for LLCC driver (git-fixes).
   - soc: ti: knav_qmss_queue: Fix PM disable depth imbalance in
     knav_queue_probe (git-fixes).
   - soc: ti: knav_qmss_queue: Use pm_runtime_resume_and_get instead of
     pm_runtime_get_sync (git-fixes).
   - soc: ti: smartreflex: Fix PM disable depth imbalance in omap_sr_probe
   - soundwire: dmi-quirks: add quirk variant for LAPBC710 NUC15 (git-fixes).
   - spi: spi-gpio: Do not set MOSI as an input if not 3WIRE mode (git-fixes).
   - spi: spidev: mask SPI_CS_HIGH in SPI_IOC_RD_MODE (git-fixes).
   - spi: Update reference to struct spi_controller (git-fixes).
   - staging: media: tegra-video: fix chan->mipi value on error (git-fixes).
   - staging: media: tegra-video: fix device_node use after free (git-fixes).
   - staging: rtl8192e: Fix potential use-after-free in rtllib_rx_Monitor()
   - staging: rtl8192u: Fix use after free in ieee80211_rx() (git-fixes).
   - string.h: Introduce memset_startat() for wiping trailing members and
     padding (jsc#PED-1445).
   - test_firmware: fix memory leak in test_firmware_init() (git-fixes).
   - thermal: core: fix some possible name leaks in error paths (git-fixes).
   - thermal: int340x: Add missing attribute for data rate base (git-fixes).
   - thermal/drivers/imx8mm_thermal: Validate temperature range (git-fixes).
   - thermal/drivers/qcom/temp-alarm: Fix inaccurate warning for gen2
   - timers: implement usleep_idle_range() (git-fixes).
   - tpm: acpi: Call acpi_put_table() to fix memory leak (git-fixes).
   - tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak
   - tpm: tpm_tis: Add the missed acpi_put_table() to fix memory leak
   - tpm/tpm_crb: Fix error message in __crb_relinquish_locality()
   - tpm/tpm_ftpm_tee: Fix error handling in ftpm_mod_init() (git-fixes).
   - tracing: Add tracing_reset_all_online_cpus_unlocked() function
   - tracing: Free buffers when a used dynamic event is removed (git-fixes).
   - tracing/doc: Fix typos on the timerlat tracer documentation (git-fixes).
   - tracing/osnoise: Fix duration type (git-fixes).
   - tty: serial: altera_uart_{r,t}x_chars() need only uart_port (git-fixes).
   - tty: serial: clean up stop-tx part in altera_uart_tx_chars() (git-fixes).
   - uio: uio_dmem_genirq: Fix deadlock between irq config and handling
   - uio: uio_dmem_genirq: Fix missing unlock in irq configuration
   - units: Add SI metric prefix definitions (git-fixes).
   - units: add the HZ macros (git-fixes).
   - usb: cdnsp: fix lack of ZLP for ep0 (git-fixes).
   - usb: dwc3: core: defer probe on ulpi_read_id timeout (git-fixes).
   - usb: dwc3: fix PHY disable sequence (git-fixes).
   - usb: dwc3: Fix race between dwc3_set_mode and __dwc3_set_mode
   - usb: dwc3: gadget: Disable GUSB2PHYCFG.SUSPHY for End Transfer
   - usb: dwc3: pci: Update PCIe device ID for USB3 controller on CPU
     sub-system for Raptor Lake (git-fixes).
   - usb: dwc3: qcom: fix runtime PM wakeup (git-fixes).
   - usb: gadget: uvc: Prevent buffer overflow in setup handler (git-fixes).
   - usb: gadget: uvc: Rename bmInterfaceFlags -> bmInterlaceFlags
   - usb: rndis_host: Secure rndis_query check against int overflow
   - usb: roles: fix of node refcount leak in usb_role_switch_is_parent()
   - usb: serial: cp210x: add Kamstrup RF sniffer PIDs (git-fixes).
   - usb: serial: f81232: fix division by zero on line-speed change
   - usb: serial: f81534: fix division by zero on line-speed change
   - usb: serial: option: add Quectel EM05-G modem (git-fixes).
   - usb: storage: Add check for kcalloc (git-fixes).
   - usb: typec: Check for ops->exit instead of ops->enter in altmode_exit
   - usb: typec: Factor out non-PD fwnode properties (git-fixes).
   - usb: typec: tcpci: fix of node refcount leak in tcpci_register_port()
   - usb: typec: tipd: Cleanup resources if devm_tps6598_psy_register fails
   - usb: typec: tipd: Fix spurious fwnode_handle_put in error path
   - usb: ulpi: defer ulpi_register on ulpi_read_id timeout (git-fixes).
   - usb: xhci-mtk: fix leakage of shared hcd when fail to set wakeup irq
   - vdpa_sim: fix possible memory leak in vdpasim_net_init() and
     vdpasim_blk_init() (git-fixes).
   - vdpa_sim: fix vringh initialization in vdpasim_queue_ready() (git-fixes).
   - vfio: platform: Do not pass return buffer to ACPI _RST method
   - vhost: fix range used in translate_desc() (git-fixes).
   - vhost/vsock: Fix error handling in vhost_vsock_init() (git-fixes).
   - vmxnet3: correctly report csum_level for encapsulated packet (git-fixes).
   - vringh: fix range used in iotlb_translate() (git-fixes).
   - vsock: Enable y2038 safe timeval for timeout (bsc#1206101).
   - vsock: Refactor vsock_*_getsockopt to resemble sock_getsockopt
   - wifi: ar5523: Fix use-after-free on ar5523_cmd() timed out (git-fixes).
   - wifi: ath10k: Fix return value in ath10k_pci_init() (git-fixes).
   - wifi: ath9k: hif_usb: fix memory leak of urbs in
     ath9k_hif_usb_dealloc_tx_urbs() (git-fixes).
   - wifi: ath9k: hif_usb: Fix use-after-free in ath9k_hif_usb_reg_in_cb()
   - wifi: ath9k: verify the expected usb_endpoints are present (git-fixes).
   - wifi: brcmfmac: Fix error return code in brcmf_sdio_download_firmware()
   - wifi: brcmfmac: Fix potential shift-out-of-bounds in
     brcmf_fw_alloc_request() (git-fixes).
   - wifi: cfg80211: Fix not unregister reg_pdev when
     load_builtin_regdb_keys() fails (git-fixes).
   - wifi: iwlwifi: mvm: fix double free on tx path (git-fixes).
   - wifi: mac80211: fix memory leak in ieee80211_if_add() (git-fixes).
   - wifi: mt76: do not run mt76u_status_worker if the device is not running
   - wifi: mt76: fix coverity overrun-call in mt76_get_txpower() (git-fixes).
   - wifi: rsi: Fix handling of 802.3 EAPOL frames sent via control port
   - wifi: rtl8xxxu: Add __packed to struct rtl8723bu_c2h (git-fixes).
   - wifi: rtl8xxxu: Fix the channel width reporting (git-fixes).
   - wifi: rtl8xxxu: gen2: Turn on the rate control (git-fixes).
   - wifi: rtw89: fix physts IE page check (git-fixes).
   - wifi: rtw89: Fix some error handling path in rtw89_core_sta_assoc()
   - wifi: rtw89: use u32_encode_bits() to fill MAC quota value (git-fixes).
   - wifi: wilc1000: sdio: fix module autoloading (git-fixes).
   - xfrm: Fix oops in __xfrm_state_delete() (bsc#1206794).
   - xhci: Apply XHCI_RESET_TO_DEFAULT quirk to ADL-N (git-fixes).

Special Instructions and Notes:

   Please reboot the system after installing this update.

Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Leap 15.4:

      zypper in -t patch openSUSE-SLE-15.4-2023-146=1

   - SUSE Linux Enterprise Module for Public Cloud 15-SP4:

      zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2023-146=1

Package List:

   - openSUSE Leap 15.4 (aarch64 x86_64):


   - openSUSE Leap 15.4 (noarch):


   - SUSE Linux Enterprise Module for Public Cloud 15-SP4 (aarch64 x86_64):


   - SUSE Linux Enterprise Module for Public Cloud 15-SP4 (noarch):



More information about the sle-security-updates mailing list