Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
608 commits
Select commit Hold shift + click to select a range
6e175c0
cpufreq: Fix hotplug-suspend race during reboot
Apr 8, 2026
6ba6f67
cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
Uuuuuuho Apr 16, 2026
7776f92
posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
ISCAS-Vulab Jun 11, 2026
cd25e98
time/jiffies: Register jiffies clocksource before usage
Jun 9, 2026
2421a7b
clocksource/drivers/timer-tegra186: Fix support for multiple watchdog…
May 7, 2026
be79d28
s390: Revert support for DCACHE_WORD_ACCESS
hcahca Jun 11, 2026
2839091
perf/arm-cmn: Fix DVM node events
rmurphy-arm May 29, 2026
18d90dc
X.509: Fix validation of ASN.1 certificate header
l1k May 14, 2026
2382971
mm/slab: do not limit zeroing to orig_size when only red zoning is en…
Jun 10, 2026
e0eec74
tools/mm/slabinfo: Fix trace disable logic inversion
May 18, 2026
abf07f5
tools/mm/slabinfo: fix total_objects attribute name
chenyichong1 Jun 12, 2026
dae1d00
HID: hid-goodix-spi: validate report size to prevent stack buffer ove…
tcchen2026 May 29, 2026
7ce2c7d
HID: uhid: convert to hid_safe_input_report()
Jun 6, 2026
416095e
HID: wacom: stop hardware after post-start probe failures
testacegi Jun 4, 2026
cb90a01
HID: pidff: Use correct effect type in effect update
JacKeTUs Jun 9, 2026
ca899a9
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
omnij May 28, 2026
bbe1e55
HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
omnij Jun 1, 2026
3eca1a8
HID: letsketch: fix UAF on inrange_timer at driver unbind
unamem May 15, 2026
37daa8c
HID: multitouch: fix out-of-bounds bit access on mt_io_flags
everping Jul 1, 2026
b363d96
HID: appleir: fix UAF on pending key_up_timer in remove()
unamem May 15, 2026
4d0d51b
HID: lg-g15: cancel pending work on remove to fix a use-after-free
maoyixie Jun 18, 2026
c63bc63
HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-by…
spandruvada Jun 10, 2026
f3461b8
hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
May 5, 2026
223463c
nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
deepanshu406 May 3, 2026
973408c
media: mtk-jpeg: cancel workqueue on release for supported platforms …
laeyraud Apr 1, 2026
1cd54e2
serial: 8250_mid: Disable DMA for selected platforms
andy-shev Jun 26, 2026
200794d
xfs: use null daddr for unset first bad log block
Yousef13710 Jun 30, 2026
9366186
xfs: release dquot buffer after dqflush failure
Ink-Paper2 Jun 25, 2026
dd8d066
xfs: fix unreachable BIGTIME check in dquot flush validation
Jun 3, 2026
55e4d84
xfs: fix pointer arithmetic error on 32-bit systems
Jun 10, 2026
a62ef2d
xfs: fix exchmaps reservation limit check
Ink-Paper2 Jun 4, 2026
c3d3d22
xfs: fix memory leak in xfs_dqinode_metadir_create()
Jun 27, 2026
a9bb2d9
bpf: Reject fragmented frames in devmap
zzhan461 Jun 2, 2026
d94ab0e
bpf: Restore sysctl new-value from 1 to 0
Jun 3, 2026
cd407de
bpf: Validate BTF repeated field counts before expansion
jopamo Jun 5, 2026
e24eb27
net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
maoyixie Jun 22, 2026
e22f044
usb: cdc_acm: Add quirk for Uniden BC125AT scanner
jrb May 30, 2026
c00826e
usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
Jun 22, 2026
4b07792
USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
Jun 3, 2026
0bbab88
usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
ISCAS-Vulab Jun 11, 2026
6bc17a7
usb: free iso schedules on failed submit
Jun 30, 2026
01feaf0
usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
maoyixie May 27, 2026
b52476a
usb: gadget: udc: Fix use-after-free in gadget_match_driver
Jun 25, 2026
8a5eba9
usb: gadget: f_printer: take kref only for successful open
Jun 26, 2026
54c2b73
USB: idmouse: fix use-after-free on disconnect race
jhovold Jun 22, 2026
2107a4f
USB: ldusb: fix use-after-free on disconnect race
jhovold Jun 22, 2026
b748f97
USB: iowarrior: fix use-after-free on disconnect
jhovold May 23, 2026
6af2834
USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
compholio Jun 2, 2026
766738e
USB: legousbtower: fix use-after-free on disconnect race
jhovold Jun 22, 2026
e088677
usb: sl811-hcd: disable controller wakeup on remove
testacegi Jul 1, 2026
964d572
USB: storage: include US_FL_NO_SAME in quirks mask
Jun 2, 2026
48394f9
usb: misc: usbio: bound bulk IN response length to the received transfer
hewei-gikaku Jun 24, 2026
729b68a
USB: misc: uss720: unregister parport on probe failure
testacegi Jul 6, 2026
8c29d9c
usb: mtu3: unmap request DMA on queue failure
Jun 23, 2026
cf6ca0a
USB: serial: keyspan_pda: fix information leak
jhovold Jun 29, 2026
4b147eb
USB: serial: option: add Telit Cinterion FE990D50 compositions
fabio-porcedda Jun 12, 2026
eab3947
USB: serial: digi_acceleport: fix broken rx after throttle
jhovold Jun 23, 2026
2b7dc48
USB: serial: digi_acceleport: fix hard lockup on disconnect
jhovold Jun 23, 2026
1243f12
USB: serial: digi_acceleport: fix write buffer corruption
jhovold Jun 23, 2026
1967a7f
USB: ulpi: fix memory leak on registration failure
jhovold Jun 8, 2026
2d84c83
USB: usb-storage: ene_ub6250: restore media-ready check
Jun 26, 2026
6c7e8e2
usbip: tools: support SuperSpeedPlus devices
chenyichong1 Jun 17, 2026
347b59e
usbip: vudc: fix NULL deref in vep_dequeue()
samcday Jun 26, 2026
1126f11
usb: typec: anx7411: use devm_pm_runtime_enable()
testacegi Jul 1, 2026
bf6aa6c
usb: typec: class: drop PD lookup reference
shuangpeng-kernel Jul 2, 2026
0bc1778
usb: typec: tcpm: Fix VDM type for Enter Mode commands
andyshrk Jun 4, 2026
3e1b1ac
usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
Jun 22, 2026
8c00aec
usb: typec: ucsi: Invert DisplayPort role assignment
Jun 1, 2026
b1dfdff
usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP a…
madhum031 Jun 19, 2026
f5c772b
usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
Jun 16, 2026
b45be66
usb: typec: ucsi: cancel pending work on system suspend
paulmenzel Jul 3, 2026
e086c16
usb: gadget: f_fs: Fix DMA fence leak
pcercuei Jun 9, 2026
9818bca
block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
ChaoShi001 May 22, 2026
b7b2d2c
mm: shmem: fix potential livelock issue for shmem direct swapin
Jul 10, 2026
be15679
x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when…
rchatre Jul 13, 2026
e504952
rust_binder: introduce TransactionInfo
Darksonn Jul 14, 2026
bd818dc
rust_binder: fix BINDER_GET_EXTENDED_ERROR
Darksonn Jul 14, 2026
8ff183e
bpf: Support for hardening against JIT spraying
pa1gupta Jul 14, 2026
8a4c8af
x86/bugs: Enable IBPB flush on BPF JIT allocation
pa1gupta Jul 14, 2026
666fc2e
bpf: Restrict JIT predictor flush to cBPF
pa1gupta Jul 14, 2026
f1f36bf
bpf: Skip redundant IBPB in pack allocator
pa1gupta Jul 14, 2026
0229944
bpf: Prefer packs that won't trigger an IBPB flush on allocation
pa1gupta Jul 14, 2026
d944b8a
bpf: Prefer dirty packs for eBPF allocations
pa1gupta Jul 14, 2026
335202a
udf: validate free block extents against the partition length
mjbommar May 15, 2026
e610fb1
udf: validate VAT header length against the VAT inode size
bryamzxz Jun 12, 2026
04f4599
udf: validate sparing table length as an entry count, not a byte count
bryamzxz Jun 12, 2026
c60932d
hwrng: jh7110 - fix refcount leak in starfive_trng_read()
ISCAS-Vulab Jun 3, 2026
d161d47
crypto: atmel-sha204a - drop hwrng quality reduction for ATSHA204A
toblux Apr 28, 2026
a8803c4
nvme: target: rdma: fix ndev refcount leak on queue connect
ISCAS-Vulab May 27, 2026
427c824
block: partitions: fix of_node refcount leak in of_partition()
ISCAS-Vulab May 26, 2026
13f2f5d
dm-ioctl: report an error if a device has no table
May 11, 2026
7a69463
nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespa…
May 28, 2026
56c021a
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
bryamzxz May 27, 2026
6d7649c
nvmet-auth: validate reply message payload bounds against transfer le…
tcchen2026 May 29, 2026
0912b98
btrfs: check and set EXTENT_DELALLOC_NEW before clearing EXTENT_DELALLOC
adam900710 Apr 20, 2026
7a64521
btrfs: do not trim a device which is not writeable
adam900710 Jun 2, 2026
ce93228
partitions: aix: bound the pp_count scan to the ppe array
bryamzxz Jun 7, 2026
b569964
isofs: bound Rock Ridge symlink components to the SL record
bryamzxz Jun 7, 2026
7465ed1
crypto: af_alg - Remove zero-copy support from skcipher and aead
May 4, 2026
6f7b8e0
crypto: caam - use print_hex_dump_devel to guard key hex dumps
toblux Apr 27, 2026
d0b8caf
crypto: caam - use print_hex_dump_devel to guard key hex dumps again
toblux Apr 27, 2026
0016d3c
crypto: chacha20poly1305 - validate poly1305 template argument
sisyphus311 May 26, 2026
ac667f9
crypto: crypto4xx - Remove insecure and unused rng_alg
May 29, 2026
774dddd
crypto: ecc - Fix carry overflow in vli multiplication
sv3iry May 13, 2026
ee6a2a2
crypto: hisi-trng - Remove crypto_rng interface
May 30, 2026
c4bd2f4
crypto: pcrypt - restore callback for non-parallel fallback
ruijieli51 May 25, 2026
cc4e42b
crypto: tegra - fix refcount leak in tegra_se_host1x_submit()
ISCAS-Vulab Jun 4, 2026
53b8fb8
crypto: loongson - Select CRYPTO_RNG
May 22, 2026
9e983d0
crypto: ccp - Do not initialize SNP for SEV ioctls
tych0 May 4, 2026
7a361c7
crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
tych0 May 4, 2026
92567ed
crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
tych0 May 4, 2026
441ea32
crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
tych0 May 4, 2026
23b8b18
crypto: drbg - Fix returning success on failure in CTR_DRBG
Apr 20, 2026
53d38b9
crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
Apr 20, 2026
5337b5c
crypto: drbg - Fix the fips_enabled priority boost
Apr 20, 2026
050bded
crypto: qat - centralize bus master enable
Ahsan-Atta May 13, 2026
33cfc0c
crypto: qat - handle sysfs-triggered reset callbacks
Ahsan-Atta May 13, 2026
45b65a2
crypto: qat - keep VFs enabled during reset
Ahsan-Atta May 13, 2026
e310e8d
crypto: qat - notify fatal error before AER reset preparation
Ahsan-Atta May 13, 2026
c3c5925
crypto: qat - protect service table iterations with service_lock
Ahsan-Atta May 20, 2026
fabf364
crypto: qat - skip restart for down devices
Ahsan-Atta May 13, 2026
6fb62b7
crypto: qat - validate RSA CRT component lengths
gcabiddu May 28, 2026
7584c92
crypto: qat - factor out AER reset helpers
Ahsan-Atta May 13, 2026
f52aa95
crypto: talitos - use dma_sync_single_for_cpu() before reading descri…
noctuelles May 7, 2026
664e7f1
crypto: talitos - add chaining of arbitrary number of descriptor for …
noctuelles May 7, 2026
3fa1846
crypto: talitos - move dma unmapping code in flush_channel() into a s…
noctuelles May 7, 2026
aea8cfb
crypto: talitos - move dma mapping code in talitos_submit() into a st…
noctuelles May 7, 2026
a8decb8
crypto: talitos - move code in current_desc_hdr() into a standalone f…
noctuelles May 7, 2026
40a2e90
crypto: talitos/hash - prepare SEC1 descriptor chaining, remove addit…
noctuelles May 7, 2026
0427302
crypto: talitos/hash - use descriptor chaining for SEC1 instead of wo…
noctuelles May 7, 2026
b960edc
crypto: talitos/hash - drop workqueue mechanism for SEC1
noctuelles May 7, 2026
99cc3f5
crypto: talitos/hash - rename first_desc/last_desc to first_request/l…
noctuelles May 7, 2026
fda9cb9
crypto: talitos/hash - remove useless wrapper
noctuelles May 7, 2026
93f000e
crypto: talitos/hash - fix SEC2 64k - 1 ahash request limitation
noctuelles May 7, 2026
75422f5
arm64: fpsimd: Fix type mismatch in sme_{save,load}_state()
mrutland-arm Jun 3, 2026
18d6048
spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_term…
NXP-CarlosSong May 25, 2026
808033d
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
NXP-CarlosSong May 25, 2026
add1e41
x86/mm: Fix freeing of PMD-sized vmemmap pages
davidhildenbrand Apr 29, 2026
f4dd562
EDAC/i10nm: Don't fail probing if ADXL is missing
vasilykh-arista Apr 14, 2026
6b01ed1
watchdog: apple: Add "apple,t8103-wdt" compatible
jannau Dec 31, 2025
22cb337
regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
ISCAS-Vulab May 27, 2026
af6048e
i2c: core: fix hang on adapter registration failure
jhovold May 11, 2026
c8b7e11
perf/aux: Fix page UAF in map_range()
Jul 9, 2026
2dad64a
tracing: Prevent out-of-bounds read in glob matching
huanghuihui0904 Jul 1, 2026
75ca998
audit: fix potential integer overflow in audit_log_n_hex()
rprobaina Jul 2, 2026
a937e92
NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
Jun 11, 2026
b883733
rqspinlock: Fix order in raw_res_spin_(un)lock_irq to allow schedule
glemco Jun 10, 2026
a82e170
module: decompress: check return value of module_extend_max_pages()
Ne02ni May 18, 2026
33c0b96
exfat: bound uniname advance in exfat_find_dir_entry()
bryamzxz Jun 12, 2026
1c8889e
NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
Mar 4, 2026
90405c8
riscv: mm: Define DIRECT_MAP_PHYSMEM_END
dramforever Jun 7, 2026
4d730ca
riscv: mm: Unconditionally sfence.vma for spurious fault
dramforever Mar 3, 2026
279c2fa
mm: fix mmap errno value when MAP_DROPPABLE is not supported
Apr 16, 2026
785ebd4
selftests: mm: fix and speedup "droppable" test
davidhildenbrand Jun 11, 2026
8dcaa0f
mm: page_ext: add count limit to page_ext_iter_next to prevent invali…
Jun 22, 2026
5c942ad
mm: do file ownership checks with the proper mount idmap
heatd Jun 25, 2026
6bbe200
selftests/mm: pagemap_ioctl: use the correct page size for transact_t…
Jun 28, 2026
037ec83
crypto: loongson - Remove broken and unused loongson-rng
May 29, 2026
bb35438
iommu/vt-d: Avoid WARNING in sva unbind path
LuBaolu Jun 4, 2026
50612ce
iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
May 28, 2026
04a177f
iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
IzenJ Apr 30, 2026
5c5f1b5
iommufd: Fix data_len byte-count vs element-count mismatch
nicolinc May 22, 2026
f565297
iommufd: Set veventq_depth upper bound
nicolinc May 22, 2026
6401139
iommufd: Rewind header length in done if iommufd_veventq_fops_read() …
nicolinc Jun 1, 2026
f549a74
iommufd: Reject invalid read count in iommufd_veventq_fops_read()
nicolinc Jun 1, 2026
f2dbe1d
iommufd: Reject invalid read count in iommufd_fault_fops_read()
nicolinc Jun 1, 2026
5539da1
iommufd: Break the loop on failure in iommufd_fault_fops_read()
nicolinc Jun 1, 2026
67daea4
iommufd: Avoid partial fault group delivery in iommufd_fault_fops_read()
nicolinc Jun 1, 2026
32ca4ae
iommufd: Set upper bounds on cache invalidation entry_num and entry_len
nicolinc Jun 3, 2026
e4427c1
audit: fix removal of dangling executable rules
rprobaina May 13, 2026
859fef2
landlock: Set audit_net.sk for socket access checks
l0kod Jun 12, 2026
b51a743
selftests/landlock: Filter dealloc records in audit_count_records()
l0kod May 13, 2026
7c73a26
KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
Jun 7, 2026
2d710d4
LoongArch: KVM: Add missing slots_lock for device register/unregister
Jun 11, 2026
6bea2f8
KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
V4bel Jun 6, 2026
4b200e0
KVM: x86: Add dedicated API for getting mask of accelerated x2APIC MSRs
sean-jc May 14, 2026
7949aa3
KVM: SVM: Disable x2AVIC RDMSR interception for MSRs KVM actually sup…
sean-jc May 14, 2026
35f3ea7
KVM: SVM: Only disable x2AVIC WRMSR interception for MSRs that are ac…
sean-jc May 14, 2026
eeb456e
KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected #DBs
sean-jc May 15, 2026
ab253cf
KVM: VMX: Handle bad values on proxied writes to LBR MSRs
Xuanqing-Shi May 27, 2026
4ad73ef
KVM: x86: Ensure vendor's exit handler runs before fastpath userspace…
sean-jc Apr 23, 2026
0c93681
KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
Jun 2, 2026
f8e1dc7
udmabuf: fix DMA direction mismatch in release_udmabuf()
NTMan Mar 14, 2026
3469656
dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
NTMan Mar 31, 2026
5907004
fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
Sebasteuo May 18, 2026
9ec02cc
i2c: core: fix irq domain leak on adapter registration failure
jhovold May 11, 2026
3351c5e
i2c: core: fix NULL-deref on adapter registration failure
jhovold May 11, 2026
0345994
i2c: core: fix adapter probe deferral loop
jhovold May 11, 2026
71b7da9
i2c: core: fix adapter debugfs creation
jhovold May 11, 2026
b6d2af6
i2c: core: fix adapter deregistration race
jhovold May 11, 2026
5694587
i2c: mpc: Fix timeout calculations
andy-shev Jun 18, 2026
b65667e
i2c: davinci: Unregister cpufreq notifier on probe failure
Jun 10, 2026
369635f
i2c: stm32f7: truncate clock period instead of rounding it
guillerodriguez Jun 11, 2026
b2523f2
i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
NXP-CarlosSong May 25, 2026
bb5133a
i2c: i801: fix hardware state machine corruption in error path
Wmingyu May 12, 2026
11f275f
Input: synaptics-rmi4 - unregister function handlers on physical driv…
Jun 10, 2026
8db211a
Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
bryamzxz Jun 14, 2026
e849c6f
Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
bryamzxz Jun 14, 2026
01e0317
Input: elan_i2c - prevent division by zero and arithmetic underflow
Jun 23, 2026
3b32303
Input: goodix - clamp the device-reported contact count
bryamzxz Jun 13, 2026
7001977
Input: iforce - bound the device-reported force-feedback effect index
bryamzxz Jun 23, 2026
75b1287
Input: mms114 - fix touch indexing for MMS134S and MMS136
dtor Jun 23, 2026
05dee40
Input: ads7846 - don't use scratch for tx_buf when clearing register
ts-kris May 7, 2026
3e6f007
Input: touchwin - reset the packet index on every complete packet
bryamzxz Jun 14, 2026
8301c33
Input: mms114 - reject an oversized device packet size
bryamzxz Jun 14, 2026
37fbe63
Input: gscps2 - advance receive buffer write index
Jun 24, 2026
1b4cb75
Input: maplemouse - fix NULL pointer dereference in open()
foxdrodd Jun 30, 2026
d7f66fb
Input: mms114 - fix multi-touch slot corruption
dtor Jul 4, 2026
699e3ab
Input: maple_keyb - set driver data before registering input device
dtor Jun 30, 2026
9376c74
Input: maplemouse - set driver data before registering input device
dtor Jun 30, 2026
95de76f
Input: maplecontrol - set driver data before registering input device
dtor Jun 30, 2026
5a45d0a
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Jun 11, 2026
ab45808
RDMA/core: Fix broadcast address falsely detected as local
msanalla Jun 9, 2026
423a78f
RDMA/siw: bound Read Response placement to the RREAD length
mjbommar Jun 2, 2026
69cfae5
fuse: back uncached readdir buffers with pages
nvmochs May 26, 2026
6e2d84f
fuse: avoid 32-bit prune notification count wrap
smoelius Jun 10, 2026
e662020
fuse: fix device node leak in cuse_process_init_reply()
Apr 8, 2026
be353ca
fuse: re-lock request before returning from fuse_ref_folio()
joannekoong May 19, 2026
096cb2e
fuse: fix io-uring background queue dispatch on request completion
joannekoong Apr 8, 2026
7366e6f
fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
AlexNova-ops Jun 9, 2026
0483fff
fuse-uring: fix EFAULT clobber in fuse_uring_commit
masoncl Jun 5, 2026
b156bb9
fuse-uring: fix data races on ring->ready
masoncl Jun 5, 2026
50f3e03
fuse-uring: fix moving cancelled entry to ent_in_userspace list
joannekoong Jun 8, 2026
bb476ef
fuse-uring: end fuse_req on io-uring cancel task work
masoncl Jun 9, 2026
23a356e
fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
bsbernd Jun 8, 2026
39c8e92
fuse-uring: Avoid queue->stopped races and set/read that value under …
bsbernd Jun 8, 2026
e171147
fuse-uring: make a fuse_req on SQE commit only findable after memcpy
bsbernd Jun 8, 2026
0b466cf
fuse-uring: remove request-less entries from ent_w_req_queue to fix N…
joannekoong Jun 9, 2026
75e1d27
sched/fair: Only update stats for allowed CPUs when looking for dst g…
Oct 11, 2025
9e04055
usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direct…
nkapron Jun 19, 2026
e697df3
timekeeping: Register default clocksource before taking tk_core.lock
NTMan Jun 16, 2026
1c56c46
Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote n…
Vudentz Jun 12, 2026
1991d49
Revert "f2fs: remove non-uptodate folio from the page cache in move_d…
Jun 8, 2026
fdafa1e
smb: client: reject overlapping data areas in SMB2 responses
Jul 11, 2026
dca861f
xfs: fix null pointer dereference in tracepoint
alberand Jul 9, 2026
d98f22d
xfs: fail recovery on a committed log item with no regions
winmin Jul 2, 2026
206c09b
xfs: resample the data fork mapping after cycling ILOCK
Jul 14, 2026
d1c4c40
xfs: don't wrap around quota ids in dqiterate
Jul 14, 2026
1045844
xfs: grab rtrmap btree when checking rgsuper
Jul 14, 2026
08b191a
xfs: use the rt version of the cow staging checker
Jul 14, 2026
d399b02
xfs: set xfarray killable sort correctly
Jul 14, 2026
424be21
xfs: handle non-inode owners for rtrmap record checking
Jul 14, 2026
c9662ff
xfs: clamp timestamp nanoseconds correctly
Jul 14, 2026
1ea0868
xfs: fully check the parent handle when it points to the rootdir
Jul 14, 2026
6403ef9
xfs: don't zap bmbt forks if they are MAXLEVELS tall
Jul 14, 2026
e696ef0
xfs: fix off-by-one error when calling xchk_xref_has_rt_owner
Jul 14, 2026
457a93a
xfs: write the rg superblock when fixing it
Jul 14, 2026
06b1729
xfs: use rtrefcount btree cursor in xchk_xref_is_rt_cow_staging
Jul 14, 2026
f89c296
Linux 6.18.39
gregkh Jul 18, 2026
6c7703f
Merge tag 'v6.18.39' into qcom-6.18.y
nsiddams Jul 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
31 changes: 4 additions & 27 deletions Documentation/crypto/userspace-if.rst
Original file line number Diff line number Diff line change
Expand Up @@ -328,33 +328,10 @@ CRYPTO_USER_API_RNG_CAVP option:
Zero-Copy Interface
-------------------

In addition to the send/write/read/recv system call family, the AF_ALG
interface can be accessed with the zero-copy interface of
splice/vmsplice. As the name indicates, the kernel tries to avoid a copy
operation into kernel space.

The zero-copy operation requires data to be aligned at the page
boundary. Non-aligned data can be used as well, but may require more
operations of the kernel which would defeat the speed gains obtained
from the zero-copy interface.

The system-inherent limit for the size of one zero-copy operation is 16
pages. If more data is to be sent to AF_ALG, user space must slice the
input into segments with a maximum size of 16 pages.

Zero-copy can be used with the following code example (a complete
working example is provided with libkcapi):

::

int pipes[2];

pipe(pipes);
/* input data in iov */
vmsplice(pipes[1], iov, iovlen, SPLICE_F_GIFT);
/* opfd is the file descriptor returned from accept() system call */
splice(pipes[0], NULL, opfd, NULL, ret, 0);
read(opfd, out, outlen);
AF_ALG used to have zero-copy support, but it was removed due to it being a
frequent source of vulnerabilities. For backwards compatibility the splice()
and sendfile() system calls are still supported, but the kernel will make an
internal copy of the data before passing it to the crypto code.


Setsockopt Interface
Expand Down
7 changes: 7 additions & 0 deletions Documentation/process/deprecated.rst
Original file line number Diff line number Diff line change
Expand Up @@ -387,6 +387,7 @@ allocations. For example, these open coded assignments::
ptr = kzalloc(sizeof(*ptr), gfp);
ptr = kmalloc_array(count, sizeof(*ptr), gfp);
ptr = kcalloc(count, sizeof(*ptr), gfp);
ptr = kmalloc(struct_size(ptr, flex_member, count), gfp);
ptr = kmalloc(sizeof(struct foo, gfp);

become, respectively::
Expand All @@ -395,4 +396,10 @@ become, respectively::
ptr = kzalloc_obj(*ptr, gfp);
ptr = kmalloc_objs(*ptr, count, gfp);
ptr = kzalloc_objs(*ptr, count, gfp);
ptr = kmalloc_flex(*ptr, flex_member, count, gfp);
__auto_type ptr = kmalloc_obj(struct foo, gfp);

If `ptr->flex_member` is annotated with __counted_by(), the allocation
will automatically fail if `count` is larger than the maximum
representable value that can be stored in the counter member associated
with `flex_member`.
1 change: 0 additions & 1 deletion MAINTAINERS
Original file line number Diff line number Diff line change
Expand Up @@ -14637,7 +14637,6 @@ M: Qunqin Zhao <zhaoqunqin@loongson.cn>
L: linux-crypto@vger.kernel.org
S: Maintained
F: drivers/char/tpm/tpm_loongson.c
F: drivers/crypto/loongson/
F: drivers/mfd/loongson-se.c
F: include/linux/mfd/loongson-se.h

Expand Down
32 changes: 25 additions & 7 deletions Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 6
PATCHLEVEL = 18
SUBLEVEL = 37
SUBLEVEL = 39
EXTRAVERSION =
NAME = Baby Opossum Posse

Expand Down Expand Up @@ -806,12 +806,6 @@ endif # KBUILD_EXTMOD
# Defaults to vmlinux, but the arch makefile usually adds further targets
all: vmlinux

CFLAGS_GCOV := -fprofile-arcs -ftest-coverage
ifdef CONFIG_CC_IS_GCC
CFLAGS_GCOV += -fno-tree-loop-im
endif
export CFLAGS_GCOV

# The arch Makefiles can override CC_FLAGS_FTRACE. We may also append it later.
ifdef CONFIG_FUNCTION_TRACER
CC_FLAGS_FTRACE := -pg
Expand Down Expand Up @@ -911,6 +905,9 @@ KBUILD_CFLAGS += $(stackp-flags-y)
ifdef CONFIG_FRAME_POINTER
KBUILD_CFLAGS += -fno-omit-frame-pointer -fno-optimize-sibling-calls
KBUILD_RUSTFLAGS += -Cforce-frame-pointers=y
# Work around rustc bug on compilers without
# https://github.com/rust-lang/rust/pull/156980.
KBUILD_RUSTFLAGS += $(if $(call rustc-min-version,109800),,-Zllvm_module_flag=frame-pointer:u32:2:max)
else
# Some targets (ARM with Thumb2, for example), can't be built with frame
# pointers. For those, we don't have FUNCTION_TRACER automatically
Expand Down Expand Up @@ -1082,6 +1079,27 @@ endif
# Ensure compilers do not transform certain loops into calls to wcslen()
KBUILD_CFLAGS += -fno-builtin-wcslen

CFLAGS_GCOV := -fprofile-arcs -ftest-coverage
ifdef CONFIG_CC_IS_GCC
CFLAGS_GCOV += -fno-tree-loop-im
# Use atomic counter updates to avoid concurrent-access crashes in GCOV.
# Only enable if -fprofile-update=prefer-atomic does not introduce new
# undefined symbols (e.g. libatomic calls that the kernel cannot link).
CFLAGS_GCOV += $(call try-run,\
echo 'long long x; void f(void){x++;}' | \
$(CC) $(KBUILD_CPPFLAGS) $(KBUILD_CFLAGS) -w -fprofile-arcs \
-ftest-coverage -x c - -c -o "$$TMP.base" && \
echo 'long long x; void f(void){x++;}' | \
$(CC) $(KBUILD_CPPFLAGS) $(KBUILD_CFLAGS) -w -fprofile-arcs \
-ftest-coverage -fprofile-update=prefer-atomic \
-x c - -c -o "$$TMP" && \
$(NM) "$$TMP.base" | grep ' U ' > "$$TMP.ubase" || true ; \
$(NM) "$$TMP" | grep ' U ' > "$$TMP.utest" || true ; \
cmp -s "$$TMP.ubase" "$$TMP.utest",\
-fprofile-update=prefer-atomic)
endif
export CFLAGS_GCOV

# change __FILE__ to the relative path to the source directory
ifdef building_out_of_srctree
KBUILD_CPPFLAGS += $(call cc-option,-fmacro-prefix-map=$(srcroot)/=)
Expand Down
8 changes: 4 additions & 4 deletions arch/arm64/kernel/entry-fpsimd.S
Original file line number Diff line number Diff line change
Expand Up @@ -103,13 +103,13 @@ SYM_FUNC_END(sme_set_vq)
* Save the ZA and ZT state
*
* x0 - pointer to buffer for state
* x1 - number of ZT registers to save
* w1 - number of ZT registers to save
*/
SYM_FUNC_START(sme_save_state)
_sme_rdsvl 2, 1 // x2 = VL/8
sme_save_za 0, x2, 12 // Leaves x0 pointing to the end of ZA

cbz x1, 1f
cbz w1, 1f
_str_zt 0
1:
ret
Expand All @@ -119,13 +119,13 @@ SYM_FUNC_END(sme_save_state)
* Load the ZA and ZT state
*
* x0 - pointer to buffer for state
* x1 - number of ZT registers to save
* w1 - number of ZT registers to save
*/
SYM_FUNC_START(sme_load_state)
_sme_rdsvl 2, 1 // x2 = VL/8
sme_load_za 0, x2, 12 // Leaves x0 pointing to the end of ZA

cbz x1, 1f
cbz w1, 1f
_ldr_zt 0
1:
ret
Expand Down
3 changes: 3 additions & 0 deletions arch/arm64/kvm/hyp/nvhe/hyp-main.c
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,9 @@ static void flush_hyp_vcpu(struct pkvm_hyp_vcpu *hyp_vcpu)

hyp_vcpu->vcpu.arch.ctxt = host_vcpu->arch.ctxt;

/* __hyp_running_vcpu must be NULL in a guest context. */
hyp_vcpu->vcpu.arch.ctxt.__hyp_running_vcpu = NULL;

hyp_vcpu->vcpu.arch.mdcr_el2 = host_vcpu->arch.mdcr_el2;
hyp_vcpu->vcpu.arch.hcr_el2 &= ~(HCR_TWI | HCR_TWE);
hyp_vcpu->vcpu.arch.hcr_el2 |= READ_ONCE(host_vcpu->arch.hcr_el2) &
Expand Down
5 changes: 5 additions & 0 deletions arch/arm64/kvm/mmu.c
Original file line number Diff line number Diff line change
Expand Up @@ -1444,6 +1444,11 @@ static void sanitise_mte_tags(struct kvm *kvm, kvm_pfn_t pfn,
if (!kvm_has_mte(kvm))
return;

if (is_zero_pfn(pfn)) {
WARN_ON_ONCE(nr_pages != 1);
return;
}

if (folio_test_hugetlb(folio)) {
/* Hugetlb has MTE flags set on head page only */
if (folio_try_hugetlb_mte_tagging(folio)) {
Expand Down
40 changes: 18 additions & 22 deletions arch/arm64/kvm/nested.c
Original file line number Diff line number Diff line change
Expand Up @@ -824,34 +824,31 @@ static void invalidate_vncr(struct vncr_tlb *vt)
clear_fixmap(vncr_fixmap(vt->cpu));
}

/*
* VNCR TLB invalidation occurs from MMU notifiers or TLBI instructions, and
* either can race against a vcpu not being onlined yet (no pseudo-TLB
* allocated). Similarly, the TLB might be invalid. Skip those, as they
* obviously don't participate in the invalidation at this stage.
*/
#define kvm_for_each_vncr_tlb(idx, vcpup, tlbp, kvm) \
kvm_for_each_vcpu(idx, vcpup, kvm) \
if (((tlbp) = vcpup->arch.vncr_tlb) && \
(tlbp)->valid)

static void kvm_invalidate_vncr_ipa(struct kvm *kvm, u64 start, u64 end)
{
struct kvm_vcpu *vcpu;
struct vncr_tlb *vt;
unsigned long i;

lockdep_assert_held_write(&kvm->mmu_lock);

if (!kvm_has_feat(kvm, ID_AA64MMFR4_EL1, NV_frac, NV2_ONLY))
return;

kvm_for_each_vcpu(i, vcpu, kvm) {
struct vncr_tlb *vt = vcpu->arch.vncr_tlb;
kvm_for_each_vncr_tlb(i, vcpu, vt, kvm) {
u64 ipa_start, ipa_end, ipa_size;

/*
* Careful here: We end-up here from an MMU notifier,
* and this can race against a vcpu not being onlined
* yet, without the pseudo-TLB being allocated.
*
* Skip those, as they obviously don't participate in
* the invalidation at this stage.
*/
if (!vt)
continue;

if (!vt->valid)
continue;

ipa_size = ttl_to_size(pgshift_level_to_ttl(vt->wi.pgshift,
vt->wr.level));
ipa_start = vt->wr.pa & ~(ipa_size - 1);
Expand Down Expand Up @@ -881,17 +878,14 @@ static void invalidate_vncr_va(struct kvm *kvm,
struct s1e2_tlbi_scope *scope)
{
struct kvm_vcpu *vcpu;
struct vncr_tlb *vt;
unsigned long i;

lockdep_assert_held_write(&kvm->mmu_lock);

kvm_for_each_vcpu(i, vcpu, kvm) {
struct vncr_tlb *vt = vcpu->arch.vncr_tlb;
kvm_for_each_vncr_tlb(i, vcpu, vt, kvm) {
u64 va_start, va_end, va_size;

if (!vt->valid)
continue;

va_size = ttl_to_size(pgshift_level_to_ttl(vt->wi.pgshift,
vt->wr.level));
va_start = vt->gva & ~(va_size - 1);
Expand Down Expand Up @@ -1244,8 +1238,10 @@ static int kvm_translate_vncr(struct kvm_vcpu *vcpu, bool *is_gmem)
}

scoped_guard(write_lock, &vcpu->kvm->mmu_lock) {
if (mmu_invalidate_retry(vcpu->kvm, mmu_seq))
if (mmu_invalidate_retry(vcpu->kvm, mmu_seq)) {
kvm_release_faultin_page(vcpu->kvm, page, true, false);
return -EAGAIN;
}

vt->gva = va;
vt->hpa = pfn << PAGE_SHIFT;
Expand Down
2 changes: 2 additions & 0 deletions arch/arm64/lib/insn.c
Original file line number Diff line number Diff line change
Expand Up @@ -338,6 +338,8 @@ u32 aarch64_insn_gen_cond_branch_imm(unsigned long pc, unsigned long addr,
long offset;

offset = label_imm_common(pc, addr, SZ_1M);
if (offset >= SZ_1M)
return AARCH64_BREAK_FAULT;

insn = aarch64_insn_get_bcond_value();

Expand Down
4 changes: 2 additions & 2 deletions arch/arm64/net/bpf_jit_comp.c
Original file line number Diff line number Diff line change
Expand Up @@ -2117,7 +2117,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_prog *prog)
image_size = extable_offset + extable_size;
ro_header = bpf_jit_binary_pack_alloc(image_size, &ro_image_ptr,
sizeof(u64), &header, &image_ptr,
jit_fill_hole);
jit_fill_hole, was_classic);
if (!ro_header) {
prog = orig_prog;
goto out_off;
Expand Down Expand Up @@ -2754,7 +2754,7 @@ int arch_bpf_trampoline_size(const struct btf_func_model *m, u32 flags,

void *arch_alloc_bpf_trampoline(unsigned int size)
{
return bpf_prog_pack_alloc(size, jit_fill_hole);
return bpf_prog_pack_alloc(size, jit_fill_hole, false);
}

void arch_free_bpf_trampoline(void *image, unsigned int size)
Expand Down
2 changes: 2 additions & 0 deletions arch/loongarch/include/asm/acpi.h
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,8 @@ static inline bool acpi_has_cpu_in_madt(void)
extern struct list_head acpi_wakeup_device_list;
extern struct acpi_madt_core_pic acpi_core_pic[MAX_CORE_PIC];

extern void acpi_add_early_pio(void);
extern void acpi_remove_early_pio(void);
extern int __init parse_acpi_topology(void);

static inline u32 get_acpi_id_for_cpu(unsigned int cpu)
Expand Down
28 changes: 28 additions & 0 deletions arch/loongarch/kernel/acpi.c
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@
#include <linux/memblock.h>
#include <linux/of_fdt.h>
#include <linux/serial_core.h>
#include <linux/vmalloc.h>
#include <asm/io.h>
#include <asm/numa.h>
#include <asm/loongson.h>
Expand Down Expand Up @@ -59,6 +60,33 @@ void __iomem *acpi_os_ioremap(acpi_physical_address phys, acpi_size size)
return ioremap_cache(phys, size);
}

#define PIO_BASE (unsigned long)PCI_IOBASE
#define PIO_SIZE ALIGN(ISA_IOSIZE, PAGE_SIZE)

static bool acpi_pio;

/* Add PIO for early access */
void acpi_add_early_pio(void)
{
if (!acpi_disabled) {
acpi_pio = true;
vmap_page_range(PIO_BASE, PIO_BASE + PIO_SIZE,
LOONGSON_LIO_BASE, pgprot_device(PAGE_KERNEL));
}
}

/* Remove PIO for PCI register */
void acpi_remove_early_pio(void)
{
if (!acpi_pio)
return;

if (!acpi_disabled) {
acpi_pio = false;
vunmap_range(PIO_BASE, PIO_BASE + PIO_SIZE);
}
}

#ifdef CONFIG_SMP
static int set_processor_mask(u32 id, u32 pass)
{
Expand Down
2 changes: 2 additions & 0 deletions arch/loongarch/kernel/setup.c
Original file line number Diff line number Diff line change
Expand Up @@ -510,6 +510,8 @@ static __init int arch_reserve_pio_range(void)
{
struct device_node *np;

acpi_add_early_pio();

for_each_node_by_name(np, "isa") {
struct of_range range;
struct of_range_parser parser;
Expand Down
1 change: 1 addition & 0 deletions arch/loongarch/kernel/smp.c
Original file line number Diff line number Diff line change
Expand Up @@ -688,6 +688,7 @@ static void stop_this_cpu(void *dummy)
set_cpu_online(smp_processor_id(), false);
calculate_cpu_foreign_map();
local_irq_disable();
rcutree_report_cpu_dead();
while (true);
}

Expand Down
6 changes: 6 additions & 0 deletions arch/loongarch/kvm/intc/eiointc.c
Original file line number Diff line number Diff line change
Expand Up @@ -654,10 +654,14 @@ static int kvm_eiointc_create(struct kvm_device *dev, u32 type)

device = &s->device_vext;
kvm_iodevice_init(device, &kvm_eiointc_virt_ops);
mutex_lock(&kvm->slots_lock);
ret = kvm_io_bus_register_dev(kvm, KVM_IOCSR_BUS,
EIOINTC_VIRT_BASE, EIOINTC_VIRT_SIZE, device);
mutex_unlock(&kvm->slots_lock);
if (ret < 0) {
mutex_lock(&kvm->slots_lock);
kvm_io_bus_unregister_dev(kvm, KVM_IOCSR_BUS, &s->device);
mutex_unlock(&kvm->slots_lock);
kfree(s);
return ret;
}
Expand All @@ -676,8 +680,10 @@ static void kvm_eiointc_destroy(struct kvm_device *dev)

kvm = dev->kvm;
eiointc = kvm->arch.eiointc;
mutex_lock(&kvm->slots_lock);
kvm_io_bus_unregister_dev(kvm, KVM_IOCSR_BUS, &eiointc->device);
kvm_io_bus_unregister_dev(kvm, KVM_IOCSR_BUS, &eiointc->device_vext);
mutex_unlock(&kvm->slots_lock);
kfree(eiointc);
kfree(dev);
}
Expand Down
2 changes: 2 additions & 0 deletions arch/loongarch/kvm/intc/ipi.c
Original file line number Diff line number Diff line change
Expand Up @@ -457,7 +457,9 @@ static void kvm_ipi_destroy(struct kvm_device *dev)

kvm = dev->kvm;
ipi = kvm->arch.ipi;
mutex_lock(&kvm->slots_lock);
kvm_io_bus_unregister_dev(kvm, KVM_IOCSR_BUS, &ipi->device);
mutex_unlock(&kvm->slots_lock);
kfree(ipi);
kfree(dev);
}
Expand Down
2 changes: 2 additions & 0 deletions arch/loongarch/kvm/intc/pch_pic.c
Original file line number Diff line number Diff line change
Expand Up @@ -473,7 +473,9 @@ static void kvm_pch_pic_destroy(struct kvm_device *dev)
kvm = dev->kvm;
s = kvm->arch.pch_pic;
/* unregister pch pic device and free it's memory */
mutex_lock(&kvm->slots_lock);
kvm_io_bus_unregister_dev(kvm, KVM_MMIO_BUS, &s->device);
mutex_unlock(&kvm->slots_lock);
kfree(s);
kfree(dev);
}
Expand Down
Loading