{"id":"CLSA-2025-1746479711","summary":"kernel-uek: Fix of 218 CVEs","details":"- sctp: sysctl: auth_enable: avoid using current-\u003ensproxy\n- sctp: sysctl: cookie_hmac_alg: avoid using current-\u003ensproxy {CVE-2025-21640}\n- bpf: Use preempt_count() directly in bpf_send_signal_common()\n- Revert \"sctp: sysctl: cookie_hmac_alg: avoid using current-\u003ensproxy\"\n- jfs: fix slab-out-of-bounds read in ea_get()\n- serial: 8250_dma: terminate correct DMA in tx_dma_flush()\n- Revert \"sctp: sysctl: auth_enable: avoid using current-\u003ensproxy\"\n- net: usb: usbnet: restore usb%d name exception for local mac addresses\n- vlan: fix memory leak in vlan_newlink() {CVE-2022-49636}\n- rds: ib: Fix NULL ptr deref in rds_ib_cq_follow_affinity\n- LTS tag: v5.4.291\n- eeprom: digsy_mtc: Make GPIO lookup table match the device\n- slimbus: messaging: Free transaction ID in delayed interrupt scenario {CVE-2025-21914}\n- intel_th: pci: Add Panther Lake-P/U support\n- intel_th: pci: Add Panther Lake-H support\n- intel_th: pci: Add Arrow Lake support\n- Squashfs: check the inode number is not the invalid value of zero {CVE-2024-26982}\n- xhci: pci: Fix indentation in the PCI device ID definitions\n- usb: gadget: Check bmAttributes only if configuration is valid\n- usb: gadget: Fix setting self-powered state on suspend\n- usb: gadget: Set self-powered based on MaxPower and bmAttributes\n- usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix functionality\n- usb: typec: ucsi: increase timeout for PPM reset operations\n- usb: atm: cxacru: fix a flaw in existing endpoint checks {CVE-2025-21916}\n- usb: renesas_usbhs: Flush the notify_hotplug_work {CVE-2025-21917}\n- usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass Storage Card Reader\n- usb: renesas_usbhs: Use devm_usb_get_phy()\n- usb: renesas_usbhs: Call clk_put()\n- Revert \"drivers/card_reader/rtsx_usb: Restore interrupt based detection\"\n- gpio: rcar: Fix missing of_node_put() call\n- net: ipv6: fix missing dst ref drop in ila lwtunnel\n- net: ipv6: fix dst ref loop in ila lwtunnel\n- net-timestamp: support TCP GSO case for a few missing flags\n- vlan: enforce underlying device type {CVE-2025-21920}\n- ppp: Fix KMSAN uninit-value warning with bpf {CVE-2025-21922}\n- be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink\n- drm/sched: Fix preprocessor guard\n- hwmon: fix a NULL vs IS_ERR_OR_NULL() check in xgene_hwmon_probe()\n- llc: do not use skb_get() before dev_queue_xmit() {CVE-2025-21925}\n- hwmon: (ad7314) Validate leading zero bits and return error\n- hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table\n- hwmon: (pmbus) Initialise page count in pmbus_identify()\n- caif_virtio: fix wrong pointer check in cfv_probe() {CVE-2025-21904}\n- net: gso: fix ownership in __udp_gso_segment {CVE-2025-21926}\n- HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() {CVE-2025-21928}\n- HID: google: fix unused variable warning under !CONFIG_ACPI\n- wifi: iwlwifi: limit printed string from FW file {CVE-2025-21905}\n- mm/page_alloc: fix uninitialized variable\n- rapidio: fix an API misues when rio_add_net() fails {CVE-2025-21934}\n- rapidio: add check for rio_add_net() in rio_scan_alloc_net()\n- wifi: nl80211: reject cooked mode if it is set along with other flags {CVE-2025-21909}\n- wifi: cfg80211: regulatory: improve invalid hints checking {CVE-2025-21910}\n- x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63\n- x86/cpu: Validate CPUID leaf 0x2 EDX output\n- x86/cacheinfo: Validate CPUID leaf 0x2 EDX output\n- platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad X131e\n- drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress 200M\n- ALSA: hda/realtek: update ALC222 depop optimize\n- ALSA: hda: intel: Add Dell ALC3271 to power_save denylist\n- HID: appleir: Fix potential NULL dereference at raw event handle {CVE-2025-21948}\n- Revert \"of: reserved-memory: Fix using wrong number of cells to get property 'alignment'\"\n- drm/amdgpu: disable BAR resize on Dell G5 SE\n- drm/amdgpu: Check extended configuration space register when system uses large bar\n- drm/amdgpu: skip BAR resizing if the bios already did it\n- acct: perform last write from workqueue {CVE-2025-21846}\n- kernel/acct.c: use dedicated helper to access rlimit values\n- kernel/acct.c: use #elif instead of #end and #elif\n- drop_monitor: fix incorrect initialization order {CVE-2025-21862}\n- pfifo_tail_enqueue: Drop new packet when sch-\u003elimit == 0 {CVE-2025-21702}\n- sched/core: Prevent rescheduling when interrupts are disabled {CVE-2024-58090}\n- phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL masks in refclk\n- phy: tegra: xusb: reset VBUS & ID OVERRIDE\n- usbnet: gl620a: fix endpoint checking in genelink_bind() {CVE-2025-21877}\n- perf/core: Fix low freq setting via IOC_PERIOD\n- ftrace: Avoid potential division by zero in function_stat_show()\n- x86/CPU: Fix warm boot hang regression on AMD SC1100 SoC systems\n- net: mvpp2: cls: Fixed Non IP flow, with vlan tag flow defination.\n- ipvs: Always clear ipvs_property flag in skb_scrub_packet()\n- ASoC: es8328: fix route from DAC to output\n- net: cadence: macb: Synchronize stats calculations\n- sunrpc: suppress warnings for unused procfs functions\n- batman-adv: Drop unmanaged ELP metric worker {CVE-2025-21823}\n- batman-adv: Ignore neighbor throughput metrics in error case\n- acct: block access to kernel internal filesystems\n- ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED\n- nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() {CVE-2025-21848}\n- tee: optee: Fix supplicant wait loop {CVE-2025-21871}\n- power: supply: da9150-fg: fix potential overflow\n- flow_dissector: Fix port range key handling in BPF conversion\n- flow_dissector: Fix handling of mixed port and port-range keys\n- net: extract port range fields from fl_flow_key\n- geneve: Suppress list corruption splat in geneve_destroy_tunnels().\n- geneve: Fix use-after-free in geneve_find_dev(). {CVE-2025-21858}\n- powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_ALLOC\n- powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as static inline\n- powerpc/64s/mm: Move __real_pte stubs into hash-4k.h\n- USB: gadget: f_midi: f_midi_complete to call queue_work {CVE-2025-21859}\n- usb/gadget: f_midi: Replace tasklet with work\n- usb/gadget: f_midi: convert tasklets to use new tasklet_setup() API\n- usb: dwc3: Fix timeout issue during controller enter/exit from halt state\n- usb: dwc3: Increase DWC3 controller halt timeout\n- memcg: fix soft lockup in the OOM process {CVE-2024-57977}\n- mm: update mark_victim tracepoints fields\n- crypto: testmgr - some more fixes to RSA test vectors\n- crypto: testmgr - populate RSA CRT parameters in RSA test vectors\n- crypto: testmgr - fix version number of RSA tests\n- crypto: testmgr - Fix wrong test case of RSA\n- crypto: testmgr - fix wrong key length for pkcs1pad\n- driver core: bus: Fix double free in driver API bus_register() {CVE-2024-50055}\n- scsi: storvsc: Set correct data length for sending SCSI command without payload\n- vlan: move dev_put into vlan_dev_uninit\n- vlan: introduce vlan_dev_free_egress_priority\n- pps: Fix a use-after-free {CVE-2024-57979}\n- btrfs: avoid monopolizing a core when activating a swap file\n- x86/i8253: Disable PIT timer 0 when not in use\n- parport_pc: add support for ASIX AX99100\n- serial: 8250_pci: add support for ASIX AX99100\n- can: ems_pci: move ASIX AX99100 ids to pci_ids.h\n- nilfs2: protect access to buffers with no active references {CVE-2025-21811}\n- nilfs2: do not force clear folio if buffer is referenced {CVE-2025-21722}\n- nilfs2: do not output warnings when clearing dirty buffers\n- alpha: replace hardcoded stack offsets with autogenerated ones\n- ndisc: extend RCU protection in ndisc_send_skb() {CVE-2025-21760}\n- openvswitch: use RCU protection in ovs_vport_cmd_fill_info()\n- arp: use RCU protection in arp_xmit() {CVE-2025-21762}\n- neighbour: use RCU protection in __neigh_notify() {CVE-2025-21763}\n- neighbour: delete redundant judgment statements\n- ndisc: use RCU protection in ndisc_alloc_skb() {CVE-2025-21764}\n- ipv6: use RCU protection in ip6_default_advmss() {CVE-2025-21765}\n- ipv4: use RCU protection in inet_select_addr()\n- ipv4: use RCU protection in rt_is_expired()\n- net: add dev_net_rcu() helper\n- net: treat possible_net_t net pointer as an RCU one and add read_pnet_rcu()\n- regmap-irq: Add missing kfree()\n- partitions: mac: fix handling of bogus partition table {CVE-2025-21772}\n- gpio: stmpe: Check return value of stmpe_reg_read in stmpe_gpio_irq_sync_unlock\n- alpha: align stack for page fault and user unaligned trap handlers\n- serial: 8250: Fix fifo underflow on flush\n- alpha: make stack 16-byte aligned (most cases)\n- can: j1939: j1939_sk_send_loop(): fix unable to send messages with data length zero\n- can: c_can: fix unbalanced runtime PM disable in error path\n- USB: serial: option: drop MeiG Smart defines\n- USB: serial: option: fix Telit Cinterion FN990A name\n- USB: serial: option: add Telit Cinterion FN990B compositions\n- USB: serial: option: add MeiG Smart SLM828\n- usb: cdc-acm: Fix handling of oversized fragments\n- usb: cdc-acm: Check control transfer buffer size before access {CVE-2025-21704}\n- USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk\n- USB: hub: Ignore non-compliant devices with too many configs or interfaces {CVE-2025-21776}\n- usb: gadget: f_midi: fix MIDI Streaming descriptor lengths {CVE-2025-21835}\n- USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone\n- USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist\n- USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI\n- usb: dwc2: gadget: remove of_node reference upon udc_stop\n- usb: gadget: udc: renesas_usb3: Fix compiler warning\n- usb: roles: set switch registered flag early on\n- batman-adv: fix panic during interface removal {CVE-2025-21781}\n- ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet 5V\n- orangefs: fix a oob in orangefs_debug_write {CVE-2025-21782}\n- Grab mm lock before grabbing pt lock\n- vfio/pci: Enable iowrite64 and ioread64 for vfio pci\n- media: cxd2841er: fix 64-bit division on gcc-9\n- gpio: bcm-kona: Add missing newline to dev_err format string\n- gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting IRQ\n- gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0\n- arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array {CVE-2025-21785}\n- team: better TEAM_OPTION_TYPE_STRING validation {CVE-2025-21787}\n- vrf: use RCU protection in l3mdev_l3_out() {CVE-2025-21791}\n- ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()\n- HID: multitouch: Add NULL check in mt_input_configured\n- ocfs2: check dir i_size in ocfs2_find_entry\n- MIPS: ftrace: Declare ftrace_get_parent_ra_addr() as static\n- ptp: Ensure info-\u003eenable callback is always set {CVE-2025-21814}\n- net/ncsi: wait for the last response to Deselect Package before configuring channel\n- misc: fastrpc: Fix registered buffer page address\n- mtd: onenand: Fix uninitialized retlen in do_otp_read()\n- NFC: nci: Add bounds checking in nci_hci_create_pipe()\n- nilfs2: fix possible int overflows in nilfs_fiemap() {CVE-2025-21736}\n- ocfs2: handle a symlink read error correctly {CVE-2024-58001}\n- vfio/platform: check the bounds of read/write syscalls {CVE-2025-21687}\n- nvmem: core: improve range check for nvmem_cell_write()\n- crypto: qce - unregister previously registered algos in error path\n- crypto: qce - fix goto jump in error path\n- media: uvcvideo: Remove redundant NULL assignment\n- media: uvcvideo: Fix event flags in uvc_ctrl_send_events\n- media: ov5640: fix get_light_freq on auto\n- soc: qcom: smem_state: fix missing of_node_put in error path\n- kbuild: Move -Wenum-enum-conversion to W=2\n- powerpc/pseries/eeh: Fix get PE state translation\n- serial: sh-sci: Do not probe the serial port if its slot in sci_ports[] is in use\n- serial: sh-sci: Drop __initdata macro for port_cfg\n- soc: qcom: socinfo: Avoid out of bounds read of serial number {CVE-2024-58007}\n- usb: gadget: f_tcm: Don't prepare BOT write request twice\n- usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint\n- usb: gadget: f_tcm: Decrement command ref count on cleanup\n- usb: gadget: f_tcm: Translate error to sense\n- wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize() {CVE-2025-21744}\n- HID: hid-sensor-hub: don't use stale platform-data on remove\n- of: reserved-memory: Fix using wrong number of cells to get property 'alignment'\n- of: Fix of_find_node_opts_by_path() handling of alias+path+options\n- of: Correct child specifier used as input of the 2nd nexus node\n- perf bench: Fix undefined behavior in cmpworker()\n- clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate\n- clk: qcom: clk-alpha-pll: fix alpha mode configuration\n- drm/komeda: Add check for komeda_get_layer_fourcc_list()\n- KVM: s390: vsie: fix some corner-cases when grabbing vsie pages\n- KVM: Explicitly verify target vCPU is online in kvm_get_vcpu() {CVE-2024-58083}\n- arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma\n- binfmt_flat: Fix integer overflow bug on 32 bit systems {CVE-2024-58010}\n- m68k: vga: Fix I/O defines\n- s390/futex: Fix FUTEX_OP_ANDN implementation\n- leds: lp8860: Write full EEPROM, not only half of it\n- cpufreq: s3c64xx: Fix compilation warning\n- tun: revert fix group permission check\n- net: rose: lock the socket in rose_bind() {CVE-2025-21749}\n- udp: gso: do not drop small packets when PMTU reduces\n- tg3: Disable tg3 PCIe AER on system reboot\n- gpu: drm_dp_cec: fix broken CEC adapter properties check\n- firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry\n- nvme: handle connectivity loss in nvme_set_queue_count\n- usb: xhci: Fix NULL pointer dereference on certain command aborts {CVE-2024-57981}\n- usb: xhci: Add timeout argument in address_device USB HCD callback\n- net: usb: rtl8150: enable basic endpoint checking {CVE-2025-21708}\n- net: usb: rtl8150: use new tasklet API\n- tasklet: Introduce new initialization API\n- kbuild: userprogs: use correct lld when linking through clang\n- media: uvcvideo: Remove dangling pointers {CVE-2024-58002}\n- media: uvcvideo: Only save async fh if success\n- nilfs2: handle errors that nilfs_prepare_chunk() may return {CVE-2025-21721}\n- nilfs2: eliminate staggered calls to kunmap in nilfs_rename\n- nilfs2: move page release outside of nilfs_delete_entry and nilfs_set_link\n- spi-mxs: Fix chipselect glitch\n- x86/mm: Don't disable PCID when INVLPG has been fixed by microcode\n- APEI: GHES: Have GHES honor the panic= setting\n- HID: Wacom: Add PCI Wacom device support\n- mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id\n- tomoyo: don't emit warning in tomoyo_write_control() {CVE-2024-58085}\n- wifi: brcmsmac: add gain range check to wlc_phy_iqcal_gainparams_nphy()\n- mmc: core: Respect quirk_max_rate for non-UHS SDIO card\n- tun: fix group permission check\n- printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX {CVE-2024-58017}\n- x86/amd_nb: Restrict init function to AMD-based systems\n- sched: Don't try to catch up excess steal time.\n- btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error handling\n- btrfs: fix use-after-free when attempting to join an aborted transaction {CVE-2025-21753}\n- btrfs: output the reason for open_ctree() failure\n- usb: gadget: f_tcm: Don't free command immediately {CVE-2024-58055}\n- media: uvcvideo: Fix double free in error path {CVE-2024-57980}\n- HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections\n- usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to PD_T_SENDER_RESPONSE\n- drivers/card_reader/rtsx_usb: Restore interrupt based detection\n- ktest.pl: Check kernelrelease return in get_version\n- NFSD: Reset cb_seq_status after NFS4ERR_DELAY\n- hexagon: Fix unbalanced spinlock in die()\n- hexagon: fix using plain integer as NULL pointer warning in cmpxchg\n- genksyms: fix memory leak when the same symbol is read from *.symref file\n- genksyms: fix memory leak when the same symbol is added from source\n- net: sh_eth: Fix missing rtnl lock in suspend/resume path\n- vsock: Allow retrying on connect() failure\n- perf trace: Fix runtime error of index out of bounds\n- net: davicom: fix UAF in dm9000_drv_remove {CVE-2025-21715}\n- net: rose: fix timer races against user threads {CVE-2025-21718}\n- PM: hibernate: Add error handling for syscore_suspend()\n- ipmr: do not call mr_mfc_uses_dev() for unres entries {CVE-2025-21719}\n- net: fec: implement TSO descriptor cleanup\n- ubifs: skip dumping tnc tree when zroot is null {CVE-2024-58058}\n- rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read {CVE-2024-58069}\n- dmaengine: ti: edma: fix OF node reference leaks in edma_driver\n- module: Extend the preempt disabled section in dereference_symbol_descriptor().\n- ocfs2: mark dquot as inactive if failed to start trans while releasing dquot\n- scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails\n- scsi: mpt3sas: Set ioc-\u003emanu_pg11.EEDPTagMode directly to 1\n- staging: media: imx: fix OF node leak in imx_media_add_of_subdevs()\n- media: uvcvideo: Propagate buf-\u003eerror to userspace\n- media: camif-core: Add check for clk_enable()\n- media: mipi-csis: Add check for clk_enable()\n- PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()\n- media: lmedm04: Handle errors for lme2510_int_read\n- media: lmedm04: Use GFP_KERNEL for URB allocation/submission.\n- media: rc: iguanair: handle timeouts\n- fbdev: omapfb: Fix an OF node leak in dss_of_port_get_parent_device()\n- ARM: dts: mediatek: mt7623: fix IR nodename\n- arm64: dts: mediatek: mt8173-evb: Fix MT6397 PMIC sub-node names\n- arm64: dts: mediatek: mt8173-evb: Drop regulator-compatible property\n- rdma/cxgb4: Prevent potential integer overflow on 32bit {CVE-2024-57973}\n- RDMA/mlx4: Avoid false error about access to uninitialized gids array\n- bpf: Send signals asynchronously if !preemptible {CVE-2025-21728}\n- perf report: Fix misleading help message about --demangle\n- perf top: Don't complain about lack of vmlinux when not resolving some kernel samples\n- padata: fix sysfs store callback check\n- ktest.pl: Remove unused declarations in run_bisect_test function\n- perf header: Fix one memory leakage in process_bpf_prog_info()\n- perf header: Fix one memory leakage in process_bpf_btf()\n- ASoC: sun4i-spdif: Add clock multiplier settings\n- tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind\n- net: sched: Disallow replacing of child qdisc from one parent to another {CVE-2025-21700}\n- net/mlxfw: Drop hard coded max FW flash image size\n- net: let net.core.dev_weight always be non-zero {CVE-2025-21806}\n- clk: analogbits: Fix incorrect calculation of vco rate delta\n- selftests: harness: fix printing of mismatch values in __EXPECT()\n- selftests/harness: Display signed values correctly\n- wifi: wlcore: fix unbalanced pm_runtime calls\n- regulator: of: Implement the unwind path of of_regulator_match()\n- team: prevent adding a device which is already a team device lower {CVE-2024-58071}\n- cpupower: fix TSC MHz calculation\n- wifi: rtlwifi: pci: wait for firmware loading before releasing memory\n- wifi: rtlwifi: fix memory leaks and invalid access at probe error path {CVE-2024-58063}\n- wifi: rtlwifi: remove unused check_buddy_priv {CVE-2024-58072}\n- wifi: rtlwifi: remove unused dualmac control leftovers\n- wifi: rtlwifi: remove unused timer and related code\n- rtlwifi: replace usage of found with dedicated list iterator variable\n- dt-bindings: mmc: controller: clarify the address-cells description\n- wifi: rtlwifi: usb: fix workqueue leak when probe fails\n- wifi: rtlwifi: rtl8192se: rise completion of firmware loading as last step\n- rtlwifi: rtl8192se Rename RT_TRACE to rtl_dbg\n- wifi: rtlwifi: do not complete firmware loading needlessly\n- ipmi: ipmb: Add check devm_kasprintf() returned value {CVE-2024-58051}\n- drm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_table\n- drm/etnaviv: Fix page property being used for non writecombine buffers\n- partitions: ldm: remove the initial kernel-doc notation\n- nbd: don't allow reconnect after disconnect {CVE-2025-21731}\n- afs: Fix directory format encoding struct\n- overflow: Allow mixed type arguments\n- overflow: Correct check_shl_overflow() comment\n- overflow: Add __must_check attribute to check_*() helpers\n- rds: ib: Do not attempt to insert RDMA exthdr twice\n- net: mana: Fix TX CQE error handling {CVE-2023-52532}\n- net/mlx5: Stop waiting for PCI if pci channel is offline\n- rds: ib: Fix racy send affinity work cancellation\n- rds: ib: Make traffic_class visible to user-space\n- rds: ib: Remove incorrect update of the path record sl and qos_class fields\n- net: core: reject skb_copy(_expand) for fraglist GSO skbs {CVE-2024-36929}\n- udp: do not accept non-tunnel GSO skbs landing in a tunnel {CVE-2024-35884}\n- udp: never accept GSO_FRAGLIST packets\n- udp: initialize is_flist with 0 in udp_gro_receive\n- ima: Fix use-after-free on a dentry's dname.name {CVE-2024-39494}\n- sched: sch_cake: add bounds checks to host bulk flow fairness counts {CVE-2025-21647}\n- udf: Fix use of check_add_overflow() with mixed type arguments\n- x86/xen: allow larger contiguous memory regions in PV guests\n- xen: remove a confusing comment on auto-translated guest I/O\n- ALSA: hda/realtek: Fixup ALC225 depop procedure\n- ALSA: hda/realtek - Add type for ALC287\n- net: loopback: Avoid sending IP packets without an Ethernet header\n- netem: Update sch-\u003eq.qlen before qdisc_tree_reduce_backlog()\n- ocfs2: fix incorrect CPU endianness conversion causing mount failure\n- Revert \"btrfs: avoid monopolizing a core when activating a swap file\"\n- gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().\n- Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc {CVE-2024-58009}\n- rds: Make sure transmit path and connection tear-down does not run concurrently\n- NFSv4: Prevent NULL-pointer dereference in nfs42_complete_copies()\n- LTS tag: v5.4.290\n- Partial revert of xhci: use pm_ptr() instead #ifdef for CONFIG_PM conditionals\n- xhci: use pm_ptr() instead of #ifdef for CONFIG_PM conditionals\n- drm/v3d: Assign job pointer to NULL before signaling the fence {CVE-2025-21688}\n- Input: xpad - add support for wooting two he (arm)\n- Input: xpad - add unofficial Xbox 360 wireless receiver clone\n- Input: atkbd - map F23 key to support default copilot shortcut\n- Revert \"usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null\"\n- USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()\n- ext4: fix slab-use-after-free in ext4_split_extent_at()\n- ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path\n- vfio/platform: check the bounds of read/write syscalls {CVE-2025-21687}\n- net/xen-netback: prevent UAF in xenvif_flush_hash() {CVE-2024-49936}\n- net: xen-netback: hash.c: Use built-in RCU list checking\n- signal/m68k: Use force_sigsegv(SIGSEGV) in fpsp040_die\n- m68k: Add missing mmap_read_lock() to sys_cacheflush()\n- m68k: Update -\u003ethread.esp0 before calling syscall_trace() in ret_from_signal\n- gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag\n- irqchip/sunxi-nmi: Add missing SKIP_WAKE flag\n- scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request\n- ASoC: wm8994: Add depends on MFD core\n- net: fix data-races around sk-\u003esk_forward_alloc {CVE-2024-53124}\n- scsi: sg: Fix slab-use-after-free read in sg_release() {CVE-2024-56631}\n- ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev()\n- irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly\n- fs/proc: fix softlockup in __read_vmcore (part 2) {CVE-2025-21694}\n- net: ethernet: xgbe: re-add aneg to supported features in PHY quirks\n- nvmet: propagate npwg topology\n- poll_wait: add mb() to fix theoretical race between waitqueue_active() and .poll()\n- kheaders: Ignore silly-rename files\n- hfs: Sanity check the root record\n- mac802154: check local interfaces before deleting sdata list {CVE-2024-57948}\n- i2c: mux: demux-pinctrl: check initial mux selection, too\n- drm/v3d: Ensure job pointer is set to NULL after job completion {CVE-2025-21697}\n- nfp: bpf: prevent integer overflow in nfp_bpf_event_output()\n- gtp: Destroy device along with udp socket's netns dismantle. {CVE-2025-21678}\n- gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp().\n- gtp: use exit_batch_rtnl() method\n- net: add exit_batch_rtnl() method\n- net: net_namespace: Optimize the code\n- net: ethernet: ti: cpsw_ale: Fix cpsw_ale_get_field()\n- sctp: sysctl: rto_min/max: avoid using current-\u003ensproxy\n- ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv {CVE-2024-57892}\n- ocfs2: correct return value of ocfs2_local_free_info()\n- phy: core: Fix that API devm_of_phy_provider_unregister() fails to unregister the phy provider\n- phy: core: fix code style in devm_of_phy_provider_unregister\n- arm64: dts: rockchip: add hevc power domain clock to rk3328\n- arm64: dts: rockchip: add #power-domain-cells to power domain nodes\n- arm64: dts: rockchip: fix pd_tcpc0 and pd_tcpc1 node position on rk3399\n- arm64: dts: rockchip: fix defines in pd_vio node for rk3399\n- iio: inkern: call iio_device_put() only on mapped devices\n- iio: adc: at91: call input_free_device() on allocated iio_dev {CVE-2024-57904}\n- iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()\n- iio: gyro: fxas21002c: Fix missing data update in trigger handler\n- iio: adc: ti-ads8688: fix information leak in triggered buffer {CVE-2024-57906}\n- iio: imu: kmx61: fix information leak in triggered buffer {CVE-2024-57908}\n- iio: light: vcnl4035: fix information leak in triggered buffer {CVE-2024-57910}\n- iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer\n- iio: pressure: zpa2326: fix information leak in triggered buffer {CVE-2024-57912}\n- usb: gadget: f_fs: Remove WARN_ON in functionfs_bind {CVE-2024-57913}\n- usb: fix reference leak in usb_new_device()\n- USB: core: Disable LPM only for non-suspended ports\n- USB: usblp: return error when setting unsupported protocol\n- usb: gadget: u_serial: Disable ep before setting port to null to fix the crash caused by port being null\n- USB: serial: cp210x: add Phoenix Contact UPS Device\n- usb-storage: Add max sectors quirk for Nokia 208\n- staging: iio: ad9832: Correct phase range check\n- staging: iio: ad9834: Correct phase range check\n- USB: serial: option: add Neoway N723-EA support\n- USB: serial: option: add MeiG Smart SRM815\n- drm/amd/display: increase MAX_SURFACES to the value supported by hw\n- ACPI: resource: Add Asus Vivobook X1504VAP to irq1_level_low_skip_override[]\n- ACPI: resource: Add TongFang GM5HG0A to irq1_edge_low_force_override[]\n- drm/amd/display: Add check for granularity in dml ceil/floor helpers {CVE-2024-57922}\n- sctp: sysctl: auth_enable: avoid using current-\u003ensproxy\n- sctp: sysctl: cookie_hmac_alg: avoid using current-\u003ensproxy {CVE-2025-21640}\n- dm thin: make get_first_thin use rcu-safe list first function {CVE-2025-21664}\n- tls: Fix tls_sw_sendmsg error handling\n- net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute {CVE-2025-21653}\n- tcp/dccp: allow a connection when sk_max_ack_backlog is zero\n- tcp/dccp: complete lockless accesses to sk-\u003esk_max_ack_backlog\n- net: 802: LLC+SNAP OID:PID lookup on start of skb data\n- ieee802154: ca8210: Add missing check for kfifo_alloc() in ca8210_probe()\n- dm array: fix cursor index when skipping across block boundaries\n- dm array: fix unreleased btree blocks on closing a faulty array cursor\n- dm array: fix releasing a faulty array block twice in dm_array_cursor_end {CVE-2024-57929}\n- jbd2: flush filesystem device before updating tail sequence\n- Revert \"NFSD: Limit the number of concurrent async COPY operations\"\n- rds: ib: Avoid sleeping function inside RCU region by using sampled values instead\n- dm rq: don't queue request to blk-mq during DM suspend {CVE-2021-47498}\n- dm: rearrange core declarations for extended use from dm-zone.c\n- cgroup: Make operations on the cgroup root_list RCU safe\n- uek: kabi: Fix build error for HIDE_INCLUDE macro\n- oracleasm: Fix PI when use_logical_block_size is set\n- oracleasm: Add support for per-I/O block size selection\n- perf/x86/intel/uncore: Fix NULL pointer dereference issue in upi_fill_topology()\n- io_uring: fix possible deadlock in io_register_iowq_max_workers()\n- io_uring/rw: fix missing NOWAIT check for O_DIRECT start write {CVE-2024-53052}\n- io_uring: use kiocb_{start,end}_write() helpers\n- fs: create kiocb_{start,end}_write() helpers\n- io_uring: rename kiocb_end_write() local helper\n- io_uring/sqpoll: close race on waiting for sqring entries\n- io_uring/sqpoll: do not put cpumask on stack\n- io_uring/sqpoll: retain test for whether the CPU is valid\n- io_uring/sqpoll: do not allow pinning outside of cpuset\n- io_uring/io-wq: limit retrying worker initialisation\n- vfs: check dentry is still valid in get_link()\n- RDS: avoid queueing delayed work on an offlined cpu\n- NFSD: Limit the number of concurrent async COPY operations {CVE-2024-49974}\n- LTS tag: v5.4.289\n- mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim()\n- drm: adv7511: Drop dsi single lane support\n- net/sctp: Prevent autoclose integer overflow in sctp_association_init()\n- sky2: Add device ID 11ab:4373 for Marvell 88E8075\n- pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking {CVE-2024-57889}\n- RDMA/uverbs: Prevent integer overflow issue {CVE-2024-57890}\n- modpost: fix the missed iteration for the max bit in do_input()\n- modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on 32-bit host\n- ARC: build: Try to guess GCC variant of cross compiler\n- irqchip/gic: Correct declaration of *percpu_base pointer in union gic_base\n- net: usb: qmi_wwan: add Telit FE910C04 compositions\n- bpf: fix potential error return\n- sound: usb: format: don't warn that raw DSD is unsupported\n- wifi: mac80211: wake the queues in case of failure in resume\n- ila: serialize calls to nf_register_net_hooks() {CVE-2024-57900}\n- ALSA: usb-audio: US16x08: Initialize array before use\n- net: llc: reset skb-\u003etransport_header\n- netfilter: nft_set_hash: unaligned atomic read on struct nft_set_ext {CVE-2024-54031}\n- netfilter: Replace zero-length array with flexible-array member\n- netrom: check buffer length before accessing it {CVE-2024-57802}\n- drm/bridge: adv7511_audio: Update Audio InfoFrame properly\n- drm: bridge: adv7511: Enable SPDIF DAI\n- RDMA/bnxt_re: Fix max_qp_wrs reported\n- RDMA/bnxt_re: Fix reporting hw_ver in query_device\n- RDMA/bnxt_re: Add check for path mtu in modify_qp\n- RDMA/mlx5: Enforce same type port association for multiport RoCE\n- net/mlx5: Make API mlx5_core_is_ecpf accept const pointer\n- IB/mlx5: Introduce and use mlx5_core_is_vf()\n- Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet {CVE-2024-55916}\n- selinux: ignore unknown extended permissions {CVE-2024-57931}\n- ipv6: prevent possible UAF in ip6_xmit() {CVE-2024-44985}\n- skb_expand_head() adjust skb-\u003etruesize incorrectly\n- btrfs: avoid monopolizing a core when activating a swap file\n- tracing: Constify string literal data member in struct trace_event_call\n- bpf: fix recursive lock when verdict program return SK_PASS {CVE-2024-56694}\n- ipv6: fix possible UAF in ip6_finish_output2()\n- ipv6: use skb_expand_head in ip6_xmit\n- ipv6: use skb_expand_head in ip6_finish_output2\n- skbuff: introduce skb_expand_head()\n- MIPS: Probe toolchain support of -msym32\n- epoll: Add synchronous wakeup support for ep_poll_callback\n- virtio-blk: don't keep queue frozen during system suspend {CVE-2024-57946}\n- scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver load time\n- platform/x86: asus-nb-wmi: Ignore unknown event 0xCF\n- regmap: Use correct format specifier for logging range errors\n- scsi: megaraid_sas: Fix for a potential deadlock {CVE-2024-57807}\n- scsi: qla1280: Fix hw revision numbering for ISP1020/1040\n- tracing/kprobe: Make trace_kprobe's module callback called after jump_label update\n- dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset\n- dmaengine: mv_xor: fix child node refcount handling in early exit\n- phy: core: Fix that API devm_phy_destroy() fails to destroy the phy\n- phy: core: Fix that API devm_phy_put() fails to release the phy\n- phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()\n- phy: core: Fix an OF node refcount leakage in _of_phy_get()\n- mtd: diskonchip: Cast an operand to prevent potential overflow\n- bpf: Check negative offsets in __bpf_skb_min_len()\n- media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg {CVE-2024-56769}\n- of: Fix refcount leakage for OF node returned by __of_get_dma_parent()\n- of: Fix error path in of_parse_phandle_with_args_map()\n- udmabuf: also check for F_SEAL_FUTURE_WRITE\n- nilfs2: prevent use of deleted inode {CVE-2024-53690}\n- NFS/pnfs: Fix a live lock between recalled layouts and layoutget\n- btrfs: tree-checker: reject inline extent items with 0 ref count\n- zram: refuse to use zero sized block device as backing device\n- sh: clk: Fix clk_enable() to return 0 on NULL clk\n- USB: serial: option: add Telit FE910C04 rmnet compositions\n- USB: serial: option: add MediaTek T7XX compositions\n- USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready\n- USB: serial: option: add MeiG Smart SLM770A\n- USB: serial: option: add TCL IK512 MBIM & ECM\n- efivarfs: Fix error on non-existent file\n- i2c: riic: Always round-up when calculating bus period\n- chelsio/chtls: prevent potential integer overflow on 32bit\n- mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk\n- netfilter: ipset: Fix for recursive locking warning\n- net: ethernet: bgmac-platform: fix an OF node reference leak\n- net: hinic: Fix cleanup in create_rxqs/txqs()\n- ionic: use ee-\u003eoffset when returning sprom data\n- net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll\n- erofs: fix incorrect symlink detection in fast symlink\n- erofs: fix order \u003e= MAX_ORDER warning due to crafted negative i_size\n- drm/i915: Fix memory leak by correcting cache object name in error handler\n- PCI: Add ACS quirk for Broadcom BCM5760X NIC\n- ALSA: usb: Fix UBSAN warning in parse_audio_unit()\n- PCI/AER: Disable AER service on suspend\n- usb: dwc2: gadget: Don't write invalid mapped sg entries into dma_desc with iommu enabled\n- net: sched: fix ordering of qlen adjustment {CVE-2024-53164}\n- kpcimgr: fix flush_icache_range arguments\n- ftrace: use preempt_enable/disable notrace macros to avoid double fault\n- nfsd: restore callback functionality for NFSv4.0\n- i2c: pnx: Fix timeout in wait functions\n- of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one()\n- af_packet: fix vlan_get_tci() vs MSG_PEEK {CVE-2024-57902}\n- af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK {CVE-2024-57901}\n- mtd: rawnand: fix double free in atmel_pmecc_create_user()\n- Revert \"xen/swiotlb: add alignment check for dma buffers\"\n- vfio/iommu_type1: Fix some sanity checks in detach group\n- Revert \"vfio/iommu_type1: Fix some sanity checks in detach group\"\n- rds: ib: Avoid UAF on RDS Socket's rs_trans_lock\n- rds: ib: Fix blocked processes related to race in rds_rdma_free_dev_rs_worker()\n- rds: ib: Fix deterministic UAF in rds_rdma_free_dev_rs_worker()\n- Revert \"KVM: SVM: Add a module parameter to override iommu AVIC usage\"\n- LTS tag: v5.4.288\n- ALSA: usb-audio: Fix a DMA to stack memory bug\n- xen/netfront: fix crash when removing device {CVE-2024-53240}\n- KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow status\n- blk-iocost: Avoid using clamp() on inuse in __propagate_weights()\n- blk-iocost: fix weight updates of inner active iocgs\n- blk-iocost: clamp inuse and skip noops in __propagate_weights()\n- ACPICA: events/evxfregn: don't release the ContextMutex that was never acquired\n- net/sched: netem: account for backlog updates from child qdisc {CVE-2024-56770}\n- qca_spi: Make driver probing reliable\n- qca_spi: Fix clock speed for multiple QCA7000\n- ACPI: resource: Fix memory resource type union access\n- net: lapb: increase LAPB_HEADER_LEN {CVE-2024-56659}\n- tipc: fix NULL deref in cleanup_bearer() {CVE-2024-56661}\n- batman-adv: Do not let TT changes list grows indefinitely\n- batman-adv: Remove uninitialized data in full table TT response\n- batman-adv: Do not send uninitialized TT changes\n- bpf, sockmap: Fix update element with same\n- xfs: don't drop errno values when we fail to ficlone the entire range\n- usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer\n- usb: ehci-hcd: fix call balance of clocks handling routines\n- usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature\n- ata: sata_highbank: fix OF node reference leak in highbank_initialize_phys()\n- usb: host: max3421-hcd: Correctly abort a USB request.\n- LTS tag: v5.4.287\n- bpf, xdp: Update devmap comments to reflect napi/rcu usage\n- ALSA: usb-audio: Fix out of bounds reads when finding clock sources {CVE-2024-53150}\n- PCI: rockchip-ep: Fix address translation unit programming\n- Revert \"drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()\"\n- modpost: Add .irqentry.text to OTHER_SECTIONS\n- jffs2: Fix rtime decompressor\n- jffs2: Prevent rtime decompress memory corruption {CVE-2024-57850}\n- KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE\n- KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device\n- KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*\n- perf/x86/intel/pt: Fix buffer full but size is 0 case\n- bpf: fix OOB devmap writes when deleting elements {CVE-2024-56615}\n- xdp: Simplify devmap cleanup\n- misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle\n- powerpc/prom_init: Fixup missing powermac #size-cells {CVE-2024-56781}\n- usb: chipidea: udc: handle USB Error Interrupt if IOC not set\n- i3c: Use i3cdev-\u003edesc-\u003einfo instead of calling i3c_device_get_info() to avoid deadlock\n- PCI: Add ACS quirk for Wangxun FF5xxx NICs\n- PCI: Add 'reset_subordinate' to reset hierarchy below bridge\n- f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode. {CVE-2024-56586}\n- nvdimm: rectify the illogical code within nd_dax_probe()\n- pinctrl: qcom-pmic-gpio: add support for PM8937\n- scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset\n- scsi: st: Don't modify unknown block number in MTIOCGET\n- leds: class: Protect brightness_show() with led_cdev-\u003eled_access mutex\n- tracing: Use atomic64_inc_return() in trace_clock_counter()\n- netpoll: Use rcu_access_pointer() in __netpoll_setup\n- net/neighbor: clear error in case strict check is not set\n- rocker: fix link status detection in rocker_carrier_init()\n- ASoC: hdmi-codec: reorder channel allocation list\n- Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables\n- wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()\n- wifi: ipw2x00: libipw_rx_any(): fix bad alignment\n- drm/amdgpu: set the right AMDGPU sg segment limitation {CVE-2024-56594}\n- jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree {CVE-2024-56595}\n- jfs: fix array-index-out-of-bounds in jfs_readdir {CVE-2024-56596}\n- jfs: fix shift-out-of-bounds in dbSplit {CVE-2024-56597}\n- jfs: array-index-out-of-bounds fix in dtReadFirst {CVE-2024-56598}\n- wifi: ath5k: add PCI ID for Arcadyan devices\n- wifi: ath5k: add PCI ID for SX76X\n- net: inet6: do not leave a dangling sk pointer in inet6_create() {CVE-2024-40954}\n- net: inet: do not leave a dangling sk pointer in inet_create() {CVE-2024-40954}\n- net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() {CVE-2024-40954}\n- net: af_can: do not leave a dangling sk pointer in can_create() {CVE-2024-40954}\n- Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()\n- af_packet: avoid erroring out after sock_init_data() in packet_create() {CVE-2024-40954}\n- net/sched: cbs: Fix integer overflow in cbs_set_port_rate()\n- net: ethernet: fs_enet: Use %pa to format resource_size_t\n- net: fec_mpc52xx_phy: Use %pa to format resource_size_t\n- samples/bpf: Fix a resource leak\n- drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check()\n- drm/mcde: Enable module autoloading\n- drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model\n- media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108\n- media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera\n- s390/cpum_sf: Handle CPU hotplug remove during sampling {CVE-2024-57849}\n- mmc: core: Further prevent card detect during shutdown\n- regmap: detach regmap from dev on regmap_exit\n- dma-buf: fix dma_fence_array_signaled v4\n- bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again {CVE-2024-48881}\n- nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry() {CVE-2024-56619}\n- scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt\n- scsi: qla2xxx: Supported speed displayed incorrectly for VPorts\n- scsi: qla2xxx: Fix NVMe and NPIV connect issue\n- ocfs2: update seq_file index in ocfs2_dlm_seq_next\n- tracing: Fix cmp_entries_dup() to respect sort() comparison rules\n- HID: wacom: fix when get product name maybe null pointer {CVE-2024-56629}\n- bpf: Fix exact match conditions in trie_get_next_key()\n- bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie\n- ocfs2: free inode when ocfs2_get_init_inode() fails {CVE-2024-56630}\n- spi: mpc52xx: Add cancel_work_sync before module remove {CVE-2024-50051}\n- tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg {CVE-2024-56633}\n- drm/sti: Add __iomem for mixer_dbg_mxn's parameter\n- gpio: grgpio: Add NULL check in grgpio_probe {CVE-2024-56634}\n- gpio: grgpio: use a helper variable to store the address of ofdev-\u003edev\n- crypto: x86/aegis128 - access 32-bit arguments as 32-bit\n- x86/asm: Reorder early variables\n- xen: Fix the issue of resource not being properly released in xenbus_dev_probe()\n- xen/xenbus: fix locking\n- xenbus/backend: Protect xenbus callback with lock\n- xenbus/backend: Add memory pressure handler callback\n- xen/xenbus: reference count registered modules\n- netfilter: nft_set_hash: skip duplicated elements pending gc run\n- netfilter: ipset: Hold module reference while requesting a module {CVE-2024-56637}\n- igb: Fix potential invalid memory access in igb_init_module() {CVE-2024-52332}\n- net/qed: allow old cards not supporting \"num_images\" to work\n- tipc: Fix use-after-free of kernel socket in cleanup_bearer(). {CVE-2024-56642}\n- tipc: add new AEAD key structure for user API\n- tipc: enable creating a \"preliminary\" node\n- tipc: add reference counter to bearer\n- dccp: Fix memory leak in dccp_feat_change_recv {CVE-2024-56643}\n- can: j1939: j1939_session_new(): fix skb reference counting {CVE-2024-56645}\n- net/sched: tbf: correct backlog statistic for GSO packets\n- netfilter: x_tables: fix LED ID check in led_tg_check() {CVE-2024-56650}\n- ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init() {CVE-2024-53680}\n- can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics\n- can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is NULL\n- watchdog: mediatek: Make sure system reset gets asserted in mtk_wdt_restart()\n- iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call\n- drm/etnaviv: flush shader L1 cache after user commandstream\n- nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur {CVE-2024-56779}\n- nfsd: make sure exp active before svc_export_show {CVE-2024-56558}\n- dm thin: Add missing destroy_work_on_stack()\n- i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()\n- util_macros.h: fix/rework find_closest() macros\n- ad7780: fix division by zero in ad7780_write_raw() {CVE-2024-56567}\n- clk: qcom: gcc-qcs404: fix initial rate of GPLL3\n- ftrace: Fix regression with module command in stack_trace_filter {CVE-2024-56569}\n- ovl: Filter invalid inodes with missing lookup function {CVE-2024-56570}\n- media: platform: allegro-dvt: Fix possible memory leak in allocate_buffers_internal()\n- media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate()\n- media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled\n- media: ts2020: fix null-ptr-deref in ts2020_probe() {CVE-2024-56574}\n- media: i2c: tc358743: Fix crash in the probe error path when using polling\n- btrfs: ref-verify: fix use-after-free after invalid ref action {CVE-2024-56581}\n- quota: flush quota_release_work upon quota writeback {CVE-2024-56780}\n- ASoC: fsl_micfil: fix the naming style for mask definition\n- sh: intc: Fix use-after-free bug in register_intc_controller()\n- sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport {CVE-2024-56688}\n- SUNRPC: Replace internal use of SOCKWQ_ASYNC_NOSPACE\n- SUNRPC: correct error code comment in xs_tcp_setup_socket()\n- modpost: remove incorrect code in do_eisa_entry()\n- rtc: ab-eoz9: don't fail temperature reads on undervoltage notification\n- 9p/xen: fix release of IRQ {CVE-2024-56704}\n- 9p/xen: fix init sequence\n- block: return unsigned int from bdev_io_min\n- jffs2: fix use of uninitialized variable\n- ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit\n- ubi: fastmap: Fix duplicate slab cache names while attaching {CVE-2024-53172}\n- ubifs: Correct the total block count by deducting journal reservation\n- rtc: check if __rtc_read_time was successful in rtc_timer_do_work() {CVE-2024-56739}\n- rtc: abx80x: Fix WDT bit position of the status register\n- rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()\n- NFSv4.0: Fix a use-after-free problem in the asynchronous open()\n- um: Always dump trace for specified task in show_stack\n- um: Clean up stacktrace dump\n- um: add show_stack_loglvl()\n- um/sysrq: remove needless variable sp\n- um: Fix the return value of elf_core_copy_task_fpregs\n- um: Fix potential integer overflow during physmem setup {CVE-2024-53145}\n- rpmsg: glink: Propagate TX failures in intentless mode as well\n- SUNRPC: make sure cache entry active before cache_show {CVE-2024-53174}\n- NFSD: Prevent a potential integer overflow {CVE-2024-53146}\n- lib: string_helpers: silence snprintf() output truncation warning\n- usb: dwc3: gadget: Fix checking for number of TRBs left\n- ALSA: hda/realtek: Apply quirk for Medion E15433\n- ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max\n- ALSA: hda/realtek: Set PCBeep to default value for ALC274\n- ALSA: hda/realtek: Update ALC225 depop procedure\n- media: wl128x: Fix atomicity violation in fmc_send_cmd() {CVE-2024-56700}\n- HID: wacom: Interpret tilt data from Intuos Pro BT as signed values\n- block: fix ordering between checking BLK_MQ_S_STOPPED request adding\n- arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled\n- sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK\n- um: vector: Do not use drvdata in release {CVE-2024-53181}\n- serial: 8250: omap: Move pm_runtime_get_sync\n- um: net: Do not use drvdata in release {CVE-2024-53183}\n- um: ubd: Do not use drvdata in release {CVE-2024-53184}\n- ubi: wl: Put source PEB into correct list if trying locking LEB failed\n- spi: Fix acpi deferred irq probe\n- netfilter: ipset: add missing range check in bitmap_ip_uadt {CVE-2024-53141}\n- Revert \"serial: sh-sci: Clean sci_ports[0] after at earlycon exit\"\n- serial: sh-sci: Clean sci_ports[0] after at earlycon exit\n- Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()\n- tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler\n- comedi: Flush partial mappings in error case {CVE-2024-53148}\n- PCI: Fix use-after-free of slot-\u003ebus on hot remove {CVE-2024-53194}\n- ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()\n- jfs: xattr: check invalid xattr size more strictly\n- ext4: fix FS_IOC_GETFSMAP handling\n- ext4: supress data-race warnings in ext4_free_inodes_{count,set}()\n- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices\n- soc: qcom: socinfo: fix revision check in qcom_socinfo_probe()\n- usb: ehci-spear: fix call balance of sehci clk handling routines\n- apparmor: fix 'Do simple duplicate message elimination'\n- staging: greybus: uart: clean up TIOCGSERIAL\n- misc: apds990x: Fix missing pm_runtime_disable()\n- USB: chaoskey: Fix possible deadlock chaoskey_list_lock\n- USB: chaoskey: fail open after removal\n- usb: yurex: make waiting on yurex_write interruptible\n- usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()\n- ipmr: fix tables suspicious RCU usage\n- ipmr: convert /proc handlers to rcu_read_lock()\n- net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken\n- marvell: pxa168_eth: fix call balance of pep-\u003eclk handling routines\n- net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration\n- tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets\n- net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device\n- power: supply: core: Remove might_sleep() from power_supply_put()\n- vfio/pci: Properly hide first-in-list PCIe extended capability {CVE-2024-53214}\n- NFSD: Fix nfsd4_shutdown_copy()\n- NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()\n- NFSD: Prevent NULL dereference in nfsd4_process_cb_update()\n- rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length\n- rpmsg: glink: Fix GLINK command prefix\n- rpmsg: glink: Send READ_NOTIFY command in FIFO full case\n- rpmsg: glink: Add TX_DATA_CONT command while sending\n- perf trace: Avoid garbage when not printing a syscall's arguments\n- perf trace: Do not lose last events in a race\n- m68k: coldfire/device.c: only build FEC when HW macros are defined\n- m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x\n- PCI: cpqphp: Fix PCIBIOS_* return value confusion\n- PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads\n- perf probe: Correct demangled symbols in C++ program\n- perf cs-etm: Don't flush when packet_queue fills up\n- clk: clk-axi-clkgen: make sure to enable the AXI bus clock\n- clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand\n- dt-bindings: clock: axi-clkgen: include AXI clk\n- dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format\n- fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()\n- fbdev/sh7760fb: Alloc DMA memory from hardware device\n- powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static\n- ocfs2: fix uninitialized value in ocfs2_file_read_iter()\n- scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()\n- scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()\n- scsi: fusion: Remove unused variable 'rc'\n- scsi: bfa: Fix use-after-free in bfad_im_module_exit()\n- mfd: rt5033: Fix missing regmap_del_irq_chip()\n- mtd: rawnand: atmel: Fix possible memory leak\n- cpufreq: loongson2: Unregister platform_driver on failure\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices {CVE-2024-56723}\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device {CVE-2024-56724}\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device {CVE-2024-56691}\n- mfd: intel_soc_pmic_bxtwc: Use dev_err_probe()\n- mfd: da9052-spi: Change read-mask to write-mask\n- mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race\n- trace/trace_event_perf: remove duplicate samples on the first tracepoint event\n- netpoll: Use rcu_access_pointer() in netpoll_poll_lock\n- ALSA: 6fire: Release resources at card release {CVE-2024-53239}\n- ALSA: caiaq: Use snd_card_free_when_closed() at disconnection {CVE-2024-56531}\n- ALSA: us122l: Use snd_card_free_when_closed() at disconnection {CVE-2024-56532}\n- net: rfkill: gpio: Add check for clk_enable()\n- selftests: net: really check for bg process completion\n- bpf, sockmap: Fix sk_msg_reset_curr\n- bpf, sockmap: Several fixes to bpf_msg_pop_data {CVE-2024-56720}\n- bpf, sockmap: Several fixes to bpf_msg_push_data\n- drm/etnaviv: hold GPU lock across perfmon sampling\n- drm/etnaviv: fix power register offset on GC300\n- drm/etnaviv: dump: fix sparse warnings\n- drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()\n- drm/panfrost: Remove unused id_mask from struct panfrost_model\n- wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()\n- bpf: Fix the xdp_adjust_tail sample prog issue\n- ASoC: fsl_micfil: fix regmap_write_bits usage\n- ASoC: fsl_micfil: use GENMASK to define register bit fields\n- ASoC: fsl_micfil: do not define SHIFT/MASK for single bits\n- ASoC: fsl_micfil: Drop unnecessary register read\n- dt-bindings: vendor-prefixes: Add NeoFidelity, Inc\n- drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()\n- wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()\n- wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq()\n- drm/omap: Fix locking in omap_gem_new_dmabuf()\n- wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() {CVE-2024-53156}\n- drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused\n- firmware: arm_scpi: Check the DVFS OPP count returned by the firmware {CVE-2024-53157}\n- regmap: irq: Set lockdep class for hierarchical IRQ domains\n- ARM: dts: cubieboard4: Fix DCDC5 regulator constraints\n- tpm: fix signed/unsigned bug when checking event logs\n- efi/tpm: Pass correct address to memblock_reserve\n- mmc: mmc_spi: drop buggy snprintf()\n- soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()\n- soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()\n- time: Fix references to _msecs_to_jiffies() handling of values\n- crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()\n- crypto: bcm - add error check in the ahash_hmac_init function {CVE-2024-56681}\n- crypto: cavium - Fix the if condition to exit loop after timeout\n- crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY\n- EDAC/fsl_ddr: Fix bad bit shift operations\n- EDAC/bluefield: Fix potential integer overflow {CVE-2024-53161}\n- firmware: google: Unregister driver_info on failure\n- firmware: google: Unregister driver_info on failure and exit in gsmi\n- hfsplus: don't query the device logical block size multiple times {CVE-2024-56548}\n- s390/syscalls: Avoid creation of arch/arch/ directory\n- acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()\n- m68k: mvme147: Reinstate early console\n- m68k: mvme16x: Add and use \"mvme16x.h\"\n- m68k: mvme147: Fix SCSI controller IRQ numbers\n- nvme-pci: fix freeing of the HMB descriptor table {CVE-2024-56756}\n- initramfs: avoid filename buffer overrun {CVE-2024-53142}\n- mips: asm: fix warning when disabling MIPS_FP_SUPPORT\n- x86/xen/pvh: Annotate indirect branch as safe\n- nvme: fix metadata handling in nvme-passthrough\n- cifs: Fix buffer overflow when parsing NFS reparse points {CVE-2024-49996}\n- ipmr: Fix access to mfc_cache_list without lock held\n- proc/softirqs: replace seq_printf with seq_put_decimal_ull_width\n- ASoC: stm: Prevent potential division by zero in stm32_sai_get_clk_div()\n- ASoC: stm: Prevent potential division by zero in stm32_sai_mclk_round_rate()\n- regulator: rk808: Add apply_bit for BUCK3 on RK809\n- soc: qcom: Add check devm_kasprintf() returned value\n- net: usb: qmi_wwan: add Quectel RG650V\n- x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB\n- ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13\n- selftests/watchdog-test: Fix system accidentally reset after watchdog-test\n- mac80211: fix user-power when emulating chanctx\n- ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet\n- kbuild: Use uname for LINUX_COMPILE_HOST detection\n- media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set\n- nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint {CVE-2024-53130}\n- ocfs2: fix UBSAN warning in ocfs2_verify_volume()\n- nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint {CVE-2024-53131}\n- KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN\n- ocfs2: uncache inode which has failed entering the group {CVE-2024-53112}\n- net/mlx5e: kTLS, Fix incorrect page refcounting {CVE-2024-53138}\n- net/mlx5: fs, lock FTE when checking if active {CVE-2024-53121}\n- netlink: terminate outstanding dump on socket close {CVE-2024-53140}\n- LTS tag: v5.4.286\n- 9p: fix slab cache name creation for real\n- md/raid10: improve code of mrdev in raid10_sync_request\n- net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition\n- fs: Fix uninitialized value issue in from_kuid and from_kgid {CVE-2024-53101}\n- powerpc/powernv: Free name on error in opal_event_init()\n- sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML\n- bpf: use kvzmalloc to allocate BPF verifier environment\n- HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad\n- 9p: Avoid creating multiple slab caches with the same name\n- ALSA: usb-audio: Add endianness annotations\n- vsock/virtio: Initialization of the dangling pointer occurring in vsk-\u003etrans {CVE-2024-50264}\n- hv_sock: Initializing vsk-\u003etrans to NULL to prevent a dangling pointer {CVE-2024-53103}\n- ftrace: Fix possible use-after-free issue in ftrace_location() {CVE-2024-38588}\n- NFSD: Fix NFSv4's PUTPUBFH operation\n- ALSA: usb-audio: Add quirks for Dell WD19 dock\n- ALSA: usb-audio: Support jack detection on Dell dock\n- ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()\n- irqchip/gic-v3: Force propagation of the active state with a read-back\n- USB: serial: option: add Quectel RG650V\n- USB: serial: option: add Fibocom FG132 0x0112 composition\n- USB: serial: qcserial: add support for Sierra Wireless EM86xx\n- USB: serial: io_edgeport: fix use after free in debug printk {CVE-2024-50267}\n- usb: musb: sunxi: Fix accessing an released usb phy {CVE-2024-50269}\n- fs/proc: fix compile warning about variable 'vmcore_mmap_ops'\n- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format\n- net: bridge: xmit: make sure we have at least eth header len bytes {CVE-2024-38538}\n- spi: fix use-after-free of the add_lock mutex {CVE-2021-47195}\n- spi: Fix deadlock when adding SPI controllers on SPI buses {CVE-2021-47469}\n- mtd: rawnand: protect access to rawnand devices while in suspend\n- btrfs: reinitialize delayed ref list after deleting it from the list {CVE-2024-50273}\n- nfs: Fix KMSAN warning in decode_getfattr_attrs() {CVE-2024-53066}\n- dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow\n- dm cache: fix potential out-of-bounds access on the first resume {CVE-2024-50278}\n- dm cache: optimize dirty bit checking with find_next_bit when resizing\n- dm cache: fix out-of-bounds access to the dirty bitset when resizing {CVE-2024-50279}\n- dm cache: correct the number of origin blocks to match the target length\n- drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()\n- pwm: imx-tpm: Use correct MODULO value for EPWM mode\n- media: v4l2-tpg: prevent the risk of a division by zero {CVE-2024-50287}\n- media: cx24116: prevent overflows on SNR calculus {CVE-2024-50290}\n- media: s5p-jpeg: prevent buffer overflows {CVE-2024-53061}\n- ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()\n- media: adv7604: prevent underflow condition when reporting colorspace\n- media: dvb_frontend: don't play tricks with underflow values\n- media: dvbdev: prevent the risk of out of memory access {CVE-2024-53063}\n- media: stb0899_algo: initialize cfr before using it\n- net: hns3: fix kernel crash when uninstalling driver {CVE-2024-50296}\n- can: c_can: fix {rx,tx}_errors statistics\n- sctp: properly validate chunk size in sctp_sf_ootb() {CVE-2024-50299}\n- net: enetc: set MAC address to the VF net_device\n- enetc: simplify the return expression of enetc_vf_set_mac_addr()\n- security/keys: fix slab-out-of-bounds in key_task_permission\n- HID: core: zero-initialize the report buffer {CVE-2024-50302}\n- ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin\n- ARM: dts: rockchip: Fix the spi controller on rk3036\n- ARM: dts: rockchip: drop grf reference from rk3036 hdmi\n- ARM: dts: rockchip: fix rk3036 acodec node\n- arm64: dts: rockchip: Remove #cooling-cells from fan on Theobroma lion\n- arm64: dts: rockchip: Fix bluetooth properties on Rock960 boards\n- arm64: dts: rockchip: Remove hdmi's 2nd interrupt on rk3328\n- arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator\n- rds/ib: avoid scq/rcq polling during rds connection shutdown\n- RDMA/mlx5: Send UAR page index as ioctl attribute\n- RDMA: Pass entire uverbs attr bundle to create cq function\n- IB/uverbs: Enable CQ ioctl commands by default\n- tracing/kprobes: Skip symbol counting logic for module symbols in create_local_trace_kprobe()\n- RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey\n- Revert \"mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\" {CVE-2024-53127}\n- mm: revert \"mm: shmem: fix data-race in shmem_getattr()\"\n- net/ipv6: release expired exception dst cached in socket {CVE-2024-56644}\n- Revert \"unicode: Don't special case ignorable code points\"\n- powerpc/vdso: Flag VDSO64 entry points as functions\n- Revert \"usb: gadget: composite: fix OS descriptors w_value logic\"\n- rds: recv_payload_bad_checksum was not 0 after running rds-stress on UEK6\n- rds: If RDS Checksums are enabled for RDMA RDS operations, the extension headers will overflow causing incorrect operation\n- rds: rds_message_alloc() needlessly zeroes m_used_sgs\n- rds: tracepoint in rds_receive_csum_err() prints pointless information\n- rds: rds_inc_init() should initialize the inc-\u003ei_conn_path field\n- rds: Race condition in adding RDS payload checksum extension header may result in RDS header corruption\n- md/raid10: fix task hung in raid10d\n- md/raid10: factor out code from wait_barrier() to stop_waiting_barrier()\n- md/raid10: avoid deadlock on recovery.\n- arm64/cpu_errata: Spectre-BHB mitigation for AMPERE1 expects a loop of 11 iterations.\n- net/rds: report pending-messages count in RDS_INQ response\n- net/rds: Introduce RDS-INQ feature to RDS protocol\n- net/rds: Supporting SIOCOUTQ to read pending sends\n- mm/memory-failure: pass the folio and the page to collect_procs()\n- KVM: x86: Stop compiling vmenter.S with OBJECT_FILES_NON_STANDARD\n- KVM: SVM: Create a stack frame in __svm_vcpu_run() for unwinding\n- objtool: Default ignore INT3 for unreachable\n- x86/spec_ctrl: AMD AutoIBRS cannot be dynamically enabled or disabled\n- x86/msr: Add functions to set/clear the bit of an MSR on all cpus","modified":"2026-05-27T11:33:38.777874944Z","published":"2025-05-05T21:36:22Z","upstream":["CVE-2021-47195","CVE-2021-47469","CVE-2021-47498","CVE-2022-49636","CVE-2023-52532","CVE-2024-26982","CVE-2024-35884","CVE-2024-36929","CVE-2024-38538","CVE-2024-38588","CVE-2024-39494","CVE-2024-40954","CVE-2024-44985","CVE-2024-48881","CVE-2024-49936","CVE-2024-49974","CVE-2024-49996","CVE-2024-50051","CVE-2024-50055","CVE-2024-50264","CVE-2024-50267","CVE-2024-50269","CVE-2024-50273","CVE-2024-50278","CVE-2024-50279","CVE-2024-50287","CVE-2024-50290","CVE-2024-50296","CVE-2024-50299","CVE-2024-50302","CVE-2024-52332","CVE-2024-53052","CVE-2024-53061","CVE-2024-53063","CVE-2024-53066","CVE-2024-53101","CVE-2024-53103","CVE-2024-53112","CVE-2024-53121","CVE-2024-53124","CVE-2024-53127","CVE-2024-53130","CVE-2024-53131","CVE-2024-53138","CVE-2024-53140","CVE-2024-53141","CVE-2024-53142","CVE-2024-53145","CVE-2024-53146","CVE-2024-53148","CVE-2024-53150","CVE-2024-53156","CVE-2024-53157","CVE-2024-53161","CVE-2024-53164","CVE-2024-53172","CVE-2024-53174","CVE-2024-53181","CVE-2024-53183","CVE-2024-53184","CVE-2024-53194","CVE-2024-53214","CVE-2024-53239","CVE-2024-53240","CVE-2024-53680","CVE-2024-53690","CVE-2024-54031","CVE-2024-55916","CVE-2024-56531","CVE-2024-56532","CVE-2024-56548","CVE-2024-56558","CVE-2024-56567","CVE-2024-56569","CVE-2024-56570","CVE-2024-56574","CVE-2024-56581","CVE-2024-56586","CVE-2024-56594","CVE-2024-56595","CVE-2024-56596","CVE-2024-56597","CVE-2024-56598","CVE-2024-56615","CVE-2024-56619","CVE-2024-56629","CVE-2024-56630","CVE-2024-56631","CVE-2024-56633","CVE-2024-56634","CVE-2024-56637","CVE-2024-56642","CVE-2024-56643","CVE-2024-56644","CVE-2024-56645","CVE-2024-56650","CVE-2024-56659","CVE-2024-56661","CVE-2024-56681","CVE-2024-56688","CVE-2024-56691","CVE-2024-56694","CVE-2024-56700","CVE-2024-56704","CVE-2024-56720","CVE-2024-56723","CVE-2024-56724","CVE-2024-56739","CVE-2024-56756","CVE-2024-56769","CVE-2024-56770","CVE-2024-56779","CVE-2024-56780","CVE-2024-56781","CVE-2024-57802","CVE-2024-57807","CVE-2024-57849","CVE-2024-57850","CVE-2024-57889","CVE-2024-57890","CVE-2024-57892","CVE-2024-57900","CVE-2024-57901","CVE-2024-57902","CVE-2024-57904","CVE-2024-57906","CVE-2024-57908","CVE-2024-57910","CVE-2024-57912","CVE-2024-57913","CVE-2024-57922","CVE-2024-57929","CVE-2024-57931","CVE-2024-57946","CVE-2024-57948","CVE-2024-57973","CVE-2024-57977","CVE-2024-57979","CVE-2024-57980","CVE-2024-57981","CVE-2024-58001","CVE-2024-58002","CVE-2024-58007","CVE-2024-58009","CVE-2024-58010","CVE-2024-58017","CVE-2024-58051","CVE-2024-58055","CVE-2024-58058","CVE-2024-58063","CVE-2024-58069","CVE-2024-58071","CVE-2024-58072","CVE-2024-58083","CVE-2024-58085","CVE-2024-58090","CVE-2025-21640","CVE-2025-21647","CVE-2025-21653","CVE-2025-21664","CVE-2025-21678","CVE-2025-21687","CVE-2025-21688","CVE-2025-21694","CVE-2025-21697","CVE-2025-21700","CVE-2025-21702","CVE-2025-21704","CVE-2025-21708","CVE-2025-21715","CVE-2025-21718","CVE-2025-21719","CVE-2025-21721","CVE-2025-21722","CVE-2025-21728","CVE-2025-21731","CVE-2025-21736","CVE-2025-21744","CVE-2025-21749","CVE-2025-21753","CVE-2025-21760","CVE-2025-21762","CVE-2025-21763","CVE-2025-21764","CVE-2025-21765","CVE-2025-21772","CVE-2025-21776","CVE-2025-21781","CVE-2025-21782","CVE-2025-21785","CVE-2025-21787","CVE-2025-21791","CVE-2025-21806","CVE-2025-21811","CVE-2025-21814","CVE-2025-21823","CVE-2025-21835","CVE-2025-21846","CVE-2025-21848","CVE-2025-21858","CVE-2025-21859","CVE-2025-21862","CVE-2025-21871","CVE-2025-21877","CVE-2025-21904","CVE-2025-21905","CVE-2025-21909","CVE-2025-21910","CVE-2025-21914","CVE-2025-21916","CVE-2025-21917","CVE-2025-21920","CVE-2025-21922","CVE-2025-21925","CVE-2025-21926","CVE-2025-21928","CVE-2025-21934","CVE-2025-21948"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/oraclelinux7-els/CLSA-2025-1746479711.html"}],"affected":[{"package":{"name":"bpftool","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/bpftool?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-container","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-container?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-container-debug","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-container-debug?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-debug","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-debug?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-debug-devel","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-debug-devel?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-devel","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-devel?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-headers","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-headers?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"kernel-uek-tools","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/kernel-uek-tools?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"perf","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/perf?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}},{"package":{"name":"python-perf","ecosystem":"TuxCare:OracleLinux:7","purl":"pkg:rpm/tuxcare/python-perf?distro=oraclelinux-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.17-2136.338.4.2.el7uek.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/oraclelinux7els/CLSA-2025-1746479711.json"}}],"schema_version":"1.7.5"}