{"schema_version":"1.7.5","id":"SUSE-SU-2026:21834-1","published":"2026-05-28T11:12:43Z","modified":"2026-07-09T18:24:07.906973973Z","related":["CVE-2023-2058","CVE-2024-14027","CVE-2025-40181","CVE-2025-40219","CVE-2025-68265","CVE-2025-68310","CVE-2025-71238","CVE-2025-71268","CVE-2025-71269","CVE-2025-71302","CVE-2026-23168","CVE-2026-23209","CVE-2026-23236","CVE-2026-23237","CVE-2026-23245","CVE-2026-23246","CVE-2026-23253","CVE-2026-23260","CVE-2026-23261","CVE-2026-23264","CVE-2026-23266","CVE-2026-23268","CVE-2026-23269","CVE-2026-23271","CVE-2026-23273","CVE-2026-23276","CVE-2026-23279","CVE-2026-23290","CVE-2026-23291","CVE-2026-23298","CVE-2026-23300","CVE-2026-23307","CVE-2026-23312","CVE-2026-23313","CVE-2026-23315","CVE-2026-23316","CVE-2026-23317","CVE-2026-23318","CVE-2026-23321","CVE-2026-23324","CVE-2026-23325","CVE-2026-23334","CVE-2026-23336","CVE-2026-23339","CVE-2026-23340","CVE-2026-23346","CVE-2026-23347","CVE-2026-23351","CVE-2026-23354","CVE-2026-23357","CVE-2026-23360","CVE-2026-23362","CVE-2026-23363","CVE-2026-23365","CVE-2026-23367","CVE-2026-23368","CVE-2026-23369","CVE-2026-23370","CVE-2026-23372","CVE-2026-23373","CVE-2026-23374","CVE-2026-23375","CVE-2026-23378","CVE-2026-23382","CVE-2026-23387","CVE-2026-23391","CVE-2026-23392","CVE-2026-23395","CVE-2026-23396","CVE-2026-23397","CVE-2026-23399","CVE-2026-23401","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23406","CVE-2026-23407","CVE-2026-23408","CVE-2026-23409","CVE-2026-23410","CVE-2026-23411","CVE-2026-23417","CVE-2026-23418","CVE-2026-23420","CVE-2026-23426","CVE-2026-23434","CVE-2026-23436","CVE-2026-23437","CVE-2026-23440","CVE-2026-23441","CVE-2026-23442","CVE-2026-23443","CVE-2026-23445","CVE-2026-23446","CVE-2026-23447","CVE-2026-23448","CVE-2026-23449","CVE-2026-23450","CVE-2026-23452","CVE-2026-23454","CVE-2026-23455","CVE-2026-23456","CVE-2026-23457","CVE-2026-23458","CVE-2026-23460","CVE-2026-23461","CVE-2026-23462","CVE-2026-23463","CVE-2026-23464","CVE-2026-23465","CVE-2026-23466","CVE-2026-23468","CVE-2026-23470","CVE-2026-23472","CVE-2026-23473","CVE-2026-23474","CVE-2026-23475","CVE-2026-31389","CVE-2026-31392","CVE-2026-31393","CVE-2026-31394","CVE-2026-31395","CVE-2026-31400","CVE-2026-31402","CVE-2026-31403","CVE-2026-31405","CVE-2026-31406","CVE-2026-31407","CVE-2026-31408","CVE-2026-31411","CVE-2026-31412","CVE-2026-31415","CVE-2026-31416","CVE-2026-31417","CVE-2026-31420","CVE-2026-31421","CVE-2026-31422","CVE-2026-31423","CVE-2026-31424","CVE-2026-31425","CVE-2026-31426","CVE-2026-31427","CVE-2026-31428","CVE-2026-31435","CVE-2026-31449","CVE-2026-31453","CVE-2026-31456","CVE-2026-31470","CVE-2026-31494","CVE-2026-31496","CVE-2026-31503","CVE-2026-31504","CVE-2026-31505","CVE-2026-31507","CVE-2026-31515","CVE-2026-31519","CVE-2026-31525","CVE-2026-31526","CVE-2026-31528","CVE-2026-31533","CVE-2026-31547","CVE-2026-31550","CVE-2026-31554","CVE-2026-31565","CVE-2026-31579","CVE-2026-31586","CVE-2026-31588","CVE-2026-31644","CVE-2026-31649","CVE-2026-31658","CVE-2026-31662","CVE-2026-31666","CVE-2026-31668","CVE-2026-31669","CVE-2026-31675","CVE-2026-31678","CVE-2026-31679","CVE-2026-31681","CVE-2026-31682","CVE-2026-31684","CVE-2026-31685","CVE-2026-31691","CVE-2026-31694","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43009","CVE-2026-43025","CVE-2026-43027","CVE-2026-43037","CVE-2026-43038","CVE-2026-43045","CVE-2026-43050","CVE-2026-43060","CVE-2026-43082","CVE-2026-43088","CVE-2026-43153","CVE-2026-43190","CVE-2026-43265","CVE-2026-43329","CVE-2026-43365","CVE-2026-43366","CVE-2026-43441","CVE-2026-43494","CVE-2026-43503","CVE-2026-46333"],"upstream":["CVE-2023-2058","CVE-2024-14027","CVE-2025-40181","CVE-2025-40219","CVE-2025-68265","CVE-2025-68310","CVE-2025-71238","CVE-2025-71268","CVE-2025-71269","CVE-2025-71302","CVE-2026-23168","CVE-2026-23209","CVE-2026-23236","CVE-2026-23237","CVE-2026-23245","CVE-2026-23246","CVE-2026-23253","CVE-2026-23260","CVE-2026-23261","CVE-2026-23264","CVE-2026-23266","CVE-2026-23268","CVE-2026-23269","CVE-2026-23271","CVE-2026-23273","CVE-2026-23276","CVE-2026-23279","CVE-2026-23290","CVE-2026-23291","CVE-2026-23298","CVE-2026-23300","CVE-2026-23307","CVE-2026-23312","CVE-2026-23313","CVE-2026-23315","CVE-2026-23316","CVE-2026-23317","CVE-2026-23318","CVE-2026-23321","CVE-2026-23324","CVE-2026-23325","CVE-2026-23334","CVE-2026-23336","CVE-2026-23339","CVE-2026-23340","CVE-2026-23346","CVE-2026-23347","CVE-2026-23351","CVE-2026-23354","CVE-2026-23357","CVE-2026-23360","CVE-2026-23362","CVE-2026-23363","CVE-2026-23365","CVE-2026-23367","CVE-2026-23368","CVE-2026-23369","CVE-2026-23370","CVE-2026-23372","CVE-2026-23373","CVE-2026-23374","CVE-2026-23375","CVE-2026-23378","CVE-2026-23382","CVE-2026-23387","CVE-2026-23391","CVE-2026-23392","CVE-2026-23395","CVE-2026-23396","CVE-2026-23397","CVE-2026-23399","CVE-2026-23401","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23406","CVE-2026-23407","CVE-2026-23408","CVE-2026-23409","CVE-2026-23410","CVE-2026-23411","CVE-2026-23417","CVE-2026-23418","CVE-2026-23420","CVE-2026-23426","CVE-2026-23434","CVE-2026-23436","CVE-2026-23437","CVE-2026-23440","CVE-2026-23441","CVE-2026-23442","CVE-2026-23443","CVE-2026-23445","CVE-2026-23446","CVE-2026-23447","CVE-2026-23448","CVE-2026-23449","CVE-2026-23450","CVE-2026-23452","CVE-2026-23454","CVE-2026-23455","CVE-2026-23456","CVE-2026-23457","CVE-2026-23458","CVE-2026-23460","CVE-2026-23461","CVE-2026-23462","CVE-2026-23463","CVE-2026-23464","CVE-2026-23465","CVE-2026-23466","CVE-2026-23468","CVE-2026-23470","CVE-2026-23472","CVE-2026-23473","CVE-2026-23474","CVE-2026-23475","CVE-2026-31389","CVE-2026-31392","CVE-2026-31393","CVE-2026-31394","CVE-2026-31395","CVE-2026-31400","CVE-2026-31402","CVE-2026-31403","CVE-2026-31405","CVE-2026-31406","CVE-2026-31407","CVE-2026-31408","CVE-2026-31411","CVE-2026-31412","CVE-2026-31415","CVE-2026-31416","CVE-2026-31417","CVE-2026-31420","CVE-2026-31421","CVE-2026-31422","CVE-2026-31423","CVE-2026-31424","CVE-2026-31425","CVE-2026-31426","CVE-2026-31427","CVE-2026-31428","CVE-2026-31435","CVE-2026-31449","CVE-2026-31453","CVE-2026-31456","CVE-2026-31470","CVE-2026-31494","CVE-2026-31496","CVE-2026-31503","CVE-2026-31504","CVE-2026-31505","CVE-2026-31507","CVE-2026-31515","CVE-2026-31519","CVE-2026-31525","CVE-2026-31526","CVE-2026-31528","CVE-2026-31533","CVE-2026-31547","CVE-2026-31550","CVE-2026-31554","CVE-2026-31565","CVE-2026-31579","CVE-2026-31586","CVE-2026-31588","CVE-2026-31644","CVE-2026-31649","CVE-2026-31658","CVE-2026-31662","CVE-2026-31666","CVE-2026-31668","CVE-2026-31669","CVE-2026-31675","CVE-2026-31678","CVE-2026-31679","CVE-2026-31681","CVE-2026-31682","CVE-2026-31684","CVE-2026-31685","CVE-2026-31691","CVE-2026-31694","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43009","CVE-2026-43025","CVE-2026-43027","CVE-2026-43037","CVE-2026-43038","CVE-2026-43045","CVE-2026-43050","CVE-2026-43060","CVE-2026-43082","CVE-2026-43088","CVE-2026-43153","CVE-2026-43190","CVE-2026-43265","CVE-2026-43329","CVE-2026-43365","CVE-2026-43366","CVE-2026-43441","CVE-2026-43494","CVE-2026-43503","CVE-2026-46333"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2023-2058: x86/CPU: Fix FPDSS on Zen1 (bsc#1243603).\n- CVE-2024-14027: xattr: switch to CLASS(fd) (bsc#1259420).\n- CVE-2025-40181: x86/kvm: Force legacy PCI hole to UC when overriding MTRRs for TDX/SNP (bsc#1253471).\n- CVE-2025-68265: nvme: fix admin request_queue lifetime (bsc#1255360).\n- CVE-2025-68310: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump (bsc#1255160).\n- CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837).\n- CVE-2026-23168: flex_proportions: make fprop_new_period() hardirq safe (bsc#1258826).\n- CVE-2026-23245: net/sched: act_gate: snapshot parameters with RCU on replace (bsc#1259799).\n- CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018).\n- CVE-2026-23276: net: add xmit recursion limit to tunnel xmit functions (bsc#1260012).\n- CVE-2026-23300: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (bsc#1260538).\n- CVE-2026-23313: i40e: Fix preempt count leak in napi poll tracepoint (bsc#1260555).\n- CVE-2026-23316: net: ipv4: fix ARM64 alignment fault in multipath hash seed (bsc#1260573).\n- CVE-2026-23321: mptcp: pm: in-kernel: always mark signal+subflow endp as used (bsc#1260505).\n- CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523).\n- CVE-2026-23346: arm64: io: Rename ioremap_prot() to __ioremap_prot() (bsc#1260529).\n- CVE-2026-23351: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (bsc#1260526).\n- CVE-2026-23354: x86/fred: Correct speculative safety in fred_extint() (bsc#1260801).\n- CVE-2026-23368: net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (bsc#1260530).\n- CVE-2026-23374: blktrace: fix __this_cpu_read/write in preemptible context (bsc#1260811).\n- CVE-2026-23375: mm: thp: deny THP for files on anonymous inodes (bsc#1260576).\n- CVE-2026-23378: net/sched: act_ife: Fix metalist update behavior (bsc#1260546).\n- CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566).\n- CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).\n- CVE-2026-23397: nfnetlink_osf: validate individual option lengths in fingerprints (bsc#1260728).\n- CVE-2026-23399: nf_tables: nft_dynset: fix possible stateful expression memleak in error path (bsc#1261020).\n- CVE-2026-23417: bpf: Fix constant blinding for PROBE_MEM32 stores (bsc#1261410).\n- CVE-2026-23436: net: add helpers for lookup and walking netdevs under netdev_lock() (bsc#1261617).\n- CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261635).\n- CVE-2026-23440: net/mlx5e: Fix race condition during IPSec ESN update (bsc#1261641).\n- CVE-2026-23441: net/mlx5e: Prevent concurrent access to IPSec ASO context (bsc#1261768).\n- CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581).\n- CVE-2026-23445: igc: fix page fault in XDP TX timestamps handling (bsc#1261702).\n- CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779).\n- CVE-2026-23450: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() (bsc#1261584).\n- CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687).\n- CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703).\n- CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686).\n- CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781).\n- CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692).\n- CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636).\n- CVE-2026-23473: io_uring/poll: fix multishot recv missing EOF on wakeup race (bsc#1261694).\n- CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788).\n- CVE-2026-31395: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler (bsc#1261786).\n- CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645).\n- CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638).\n- CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796).\n- CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261629).\n- CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632).\n- CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752).\n- CVE-2026-31415: ipv6: avoid overflows in ip6_datagram_send_ctl() (bsc#1262099).\n- CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100).\n- CVE-2026-31420: bridge: mrp: reject zero test interval to avoid OOM panic (bsc#1262055).\n- CVE-2026-31421: net/sched: cls_fw: fix NULL pointer dereference on shared blocks (bsc#1262061).\n- CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054).\n- CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063).\n- CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053).\n- CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074).\n- CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086).\n- CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087).\n- CVE-2026-31435: netfs: Fix read abandonment during retry (bsc#1262601).\n- CVE-2026-31449: ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616).\n- CVE-2026-31453: xfs: avoid dereferencing log items after push callbacks (bsc#1262617).\n- CVE-2026-31456: mm/pagewalk: fix race between concurrent split and refault (bsc#1262627).\n- CVE-2026-31494: net: cadence: macb: Synchronize stats calculations (bsc#1262671).\n- CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673).\n- CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077).\n- CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085).\n- CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263093).\n- CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095).\n- CVE-2026-31515: af_key: validate families in pfkey_send_migrate() (bsc#1262752).\n- CVE-2026-31519: btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (bsc#1263012).\n- CVE-2026-31525: bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (bsc#1262725).\n- CVE-2026-31526: bpf: Fix exception exit lock checking for subprogs (bsc#1262662).\n- CVE-2026-31528: perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001).\n- CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262758).\n- CVE-2026-31547: drm/xe: Fix missing runtime PM reference in ccs_mode_store (bsc#1263018).\n- CVE-2026-31550: pmdomain: bcm: bcm2835-power: Increase ASB control timeout (bsc#1263104).\n- CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263107).\n- CVE-2026-31565: RDMA/irdma: Fix deadlock during netdev reset with active connections (bsc#1263064).\n- CVE-2026-31579: wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (bsc#1263074).\n- CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176).\n- CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165).\n- CVE-2026-31644: net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (bsc#1263048).\n- CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582).\n- CVE-2026-31658: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (bsc#1263052).\n- CVE-2026-31662: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (bsc#1263131).\n- CVE-2026-31666: btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (bsc#1263138).\n- CVE-2026-31668: seg6: separate dst_cache for input and output paths in seg6 lwtunnel (bsc#1263140).\n- CVE-2026-31669: mptcp: fix slab-use-after-free in __inet_lookup_established (bsc#1263141).\n- CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556).\n- CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562).\n- CVE-2026-31679: openvswitch: validate MPLS set/set_masked payload length (bsc#1263592).\n- CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593).\n- CVE-2026-31682: bridge: br_nd_send: linearize skb before parsing ND options (bsc#1263595).\n- CVE-2026-31684: net: sched: act_csum: validate nested VLAN headers (bsc#1263596).\n- CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668).\n- CVE-2026-31691: igb: remove napi_synchronize() in igb_down() (bsc#1263604).\n- CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263901).\n- CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882).\n- CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059).\n- CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181).\n- CVE-2026-43009: bpf: Fix incorrect pruning due to atomic fetch precision tracking (bsc#1264014).\n- CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931).\n- CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1263933).\n- CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995).\n- CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097).\n- CVE-2026-43045: mshv: Refactor and rename memory region handling functions (bsc#1263942).\n- CVE-2026-43050: atm: lec: fix use-after-free in sock_def_readable() (bsc#1264082).\n- CVE-2026-43060: netfilter: nft_ct: drop pending enqueued packets on removal (bsc#1264183).\n- CVE-2026-43082: net: txgbe: leave space for null terminators on property_entry (bsc#1264233).\n- CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469).\n- CVE-2026-43153: xfs: remove xfs_attr_leaf_hasname (bsc#1264586).\n- CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848).\n- CVE-2026-43265: KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (bsc#1264427).\n- CVE-2026-43329: netfilter: flowtable: strictly check for maximum number of actions (bsc#1265085).\n- CVE-2026-43365: xfs: fix undersized l_iclog_roundoff values (bsc#1265119).\n- CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265116).\n- CVE-2026-43441: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1264674).\n- CVE-2026-43494: net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626).\n- CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960).\n\nThe following non security issues were fixed:\n\n- accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes).\n- ACPI: AGDI: fix missing newline in error message (git-fixes).\n- ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes).\n- ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes).\n- ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes).\n- ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes).\n- ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes).\n- ALSA: 6fire: Fix input volume change detection (git-fixes).\n- ALSA: 6fire: fix use-after-free on disconnect (git-fixes).\n- ALSA: aoa: i2sbus: clear stale prepared state (git-fixes).\n- ALSA: aoa: i2sbus: fix OF node lifetime handling (git-fixes).\n- ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes).\n- ALSA: aoa: Use guard() for mutex locks (stable-fixes).\n- ALSA: asihpi: avoid write overflow check warning (stable-fixes).\n- ALSA: caiaq: Don't abort when no input device is available (git-fixes).\n- ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes).\n- ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes).\n- ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes).\n- ALSA: caiaq: Handle probe errors properly (git-fixes).\n- ALSA: caiaq: take a reference on the USB device in create_card() (git-fixes).\n- ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (git-fixes).\n- ALSA: core: Fix potential data race at fasync handling (git-fixes).\n- ALSA: core: Serialize deferred fasync state checks (git-fixes).\n- ALSA: core: Validate compress device numbers without dynamic minors (git-fixes).\n- ALSA: ctxfi: Add fallback to default RSR for S/PDIF (git-fixes).\n- ALSA: ctxfi: Fix missing SPDIFI1 index handling (stable-fixes).\n- ALSA: ctxfi: Limit PTP to a single page (git-fixes).\n- ALSA: firewire-tascam: Do not drop unread control events (git-fixes).\n- ALSA: fireworks: bound device-supplied status before string array lookup (git-fixes).\n- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes).\n- ALSA: hda/realtek - fixed speaker no sound update (git-fixes).\n- ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes).\n- ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes).\n- ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes).\n- ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes).\n- ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes).\n- ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (git-fixes).\n- ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes).\n- ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes).\n- ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes).\n- ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes).\n- ALSA: misc: Use guard() for spin locks (stable-fixes).\n- ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes).\n- ALSA: pcmtest: fix reference leak on failed device registration (git-fixes).\n- ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes).\n- ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes).\n- ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes).\n- ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes).\n- ALSA: scarlett2: Add missing sentinel initializer field (git-fixes).\n- ALSA: seq: Notify client and port info changes (stable-fixes).\n- ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes).\n- ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes).\n- ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes).\n- ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes).\n- ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes).\n- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes).\n- ALSA: usb-audio: Evaluate packsize caps at the right place (git-fixes).\n- ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes).\n- ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes).\n- ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes).\n- ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes).\n- ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes).\n- ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes).\n- ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes).\n- amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes).\n- ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes).\n- ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes).\n- ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes).\n- ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes).\n- ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes).\n- ASoC: codecs: ab8500: Fix casting of private data (git-fixes).\n- ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes).\n- ASoC: cs35l56: Don't use devres to unregister component (git-fixes).\n- ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes).\n- ASoC: fsl_easrc: Change the type for iec958 channel status controls (git-fixes).\n- ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (git-fixes).\n- ASoC: fsl_easrc: fix comment typo (git-fixes).\n- ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (git-fixes).\n- ASoC: fsl_micfil: Add access property for \"VAD Detected\" (git-fixes).\n- ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() (git-fixes).\n- ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() (git-fixes).\n- ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() (git-fixes).\n- ASoC: fsl_micfil: Fix event generation in micfil_quality_set() (git-fixes).\n- ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes).\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (git-fixes).\n- ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (git-fixes).\n- ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes).\n- ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop (git-fixes).\n- ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens (git-fixes).\n- ASoC: qcom: q6apm: move component registration to unmanaged version (git-fixes).\n- ASoC: qcom: q6apm: remove child devices when apm is removed (git-fixes).\n- ASoC: qcom: qdsp6: topology: check widget type before accessing data (git-fixes).\n- ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes).\n- ASoC: SOF: compress: return the configured codec from get_params (git-fixes).\n- ASoC: SOF: Don't allow pointer operations on unconfigured streams (git-fixes).\n- ASoC: SOF: Intel: hda: Place check before dereference (git-fixes).\n- ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes).\n- ASoC: sti: Return errors from regmap_field_alloc() (git-fixes).\n- ASoC: sti: use managed regmap_field allocations (git-fixes).\n- ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes).\n- ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes).\n- backlight: sky81452-backlight: Check return value of devm_gpiod_get_optional() in sky81452_bl_parse_dt() (git-fixes).\n- batman-adv: bla: only purge non-released claims (git-fixes).\n- batman-adv: bla: prevent use-after-free when deleting claims (git-fixes).\n- batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes).\n- batman-adv: fix integer overflow on buff_pos (git-fixes).\n- batman-adv: hold claim backbone gateways by reference (git-fixes).\n- batman-adv: reject new tp_meter sessions during teardown (git-fixes).\n- batman-adv: reject oversized global TT response buffers (git-fixes).\n- batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes).\n- bitfield: Add FIELD_MODIFY() helper (jsc#PED-14238).\n- Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes).\n- Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes).\n- Bluetooth: btusb: Check for unexpected bytes when defragmenting HCI frames (bsc#1260996).\n- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (git-fixes).\n- Bluetooth: hci_event: fix memset typo (git-fixes).\n- Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes).\n- Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (git-fixes).\n- Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (git-fixes).\n- Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes).\n- Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes).\n- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (git-fixes).\n- Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes).\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes).\n- Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes).\n- Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (git-fixes).\n- Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes).\n- Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec (git-fixes).\n- Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes).\n- Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes).\n- Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes).\n- Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes).\n- bpf: Add third round of bounds deduction (git-fixes).\n- bpf: Fix u32/s32 bounds when ranges cross min/max boundary (git-fixes).\n- bpf: Improve bounds when s64 crosses sign boundary (git-fixes).\n- bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes).\n- btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933).\n- btrfs: reject root items with drop_progress and zero drop_level (git-fixes).\n- btrfs: replace BUG() with error handling in __btrfs_balance() (git-fixes).\n- bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes).\n- bus: rifsc: fix RIF configuration check for peripherals (git-fixes).\n- can: mcp251x: add error handling for power enable in open and resume (stable-fixes).\n- can: raw: fix ro->uniq use-after-free in raw_rcv() (git-fixes).\n- can: ucan: fix devres lifetime (git-fixes).\n- cdc-acm: new quirk for EPSON HMD (stable-fixes).\n- check-for-config-changes: Exclude CC_MS_EXTENSIONS.\n- check-for-config-changes: Exclude HAVE_CFI_ICALL_NORMALIZE_INTEGERS{,_RUSTC}.\n- comedi: dt2815: add hardware detection to prevent crash (stable-fixes).\n- cpufreq: intel_pstate: Drop Arrow Lake from \"scaling factor\" list (bsc#1249104).\n- crypto: af_alg - limit RX SG extraction by receive buffer budget (git-fixes).\n- crypto: algif_aead - Fix minimum RX size check for decryption (git-fixes).\n- crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (git-fixes).\n- crypto: atmel-ecc - Release client on allocation failure (git-fixes).\n- crypto: atmel-sha204a - Fix error codes in OTP reads (git-fixes).\n- crypto: atmel-sha204a - Fix OTP sysfs read and error handling (git-fixes).\n- crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path (git-fixes).\n- crypto: atmel-sha204a - Fix uninitialized data access on OTP read error (git-fixes).\n- crypto: atmel-tdes - fix DMA sync direction (git-fixes).\n- crypto: ccp - copy IV using skcipher ivsize (git-fixes).\n- crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (git-fixes).\n- crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (git-fixes).\n- crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (git-fixes).\n- crypto: ccree - fix a memory leak in cc_mac_digest() (git-fixes).\n- crypto: drivers - Switch back to struct platform_driver::remove() (jsc#PED-14238).\n- crypto: drivers - Use str_enable_disable-like helpers (jsc#PED-14238).\n- crypto: hisilicon - Fix dma_unmap_single() direction (git-fixes).\n- crypto: iaa - Adjust workqueue allocation type (jsc#PED-14238).\n- crypto: iaa - fix per-node CPU counter reset in rebalance_wq_table() (git-fixes).\n- crypto: iaa - Move compression CRC into request object (jsc#PED-14238).\n- crypto: iaa - Optimize rebalance_wq_table() (jsc#PED-14238).\n- crypto: iaa - Remove potential infinite loop in check_completion() (jsc#PED-14238).\n- crypto: iaa - Remove unreachable pr_debug from iaa_crypto_cleanup_module (jsc#PED-14238).\n- crypto: iaa - Remove unused disable_async argument from iaa_decompress (jsc#PED-14238).\n- crypto: iaa - Replace sprintf with sysfs_emit in sysfs show functions (jsc#PED-14238).\n- crypto: iaa - Simplify init_iaa_device() (jsc#PED-14238).\n- crypto: jitterentropy - replace long-held spinlock with mutex (git-fixes).\n- crypto: nx - Fix packed layout in struct nx842_crypto_header (git-fixes).\n- crypto: pcrypt - Fix handling of MAY_BACKLOG requests (git-fixes).\n- crypto: qat - #undef field_get() before local definition (jsc#PED-14238).\n- crypto: qat - add adf_rl_get_num_svc_aes() in rate limiting (jsc#PED-14238).\n- crypto: qat - add bank state save and restore for qat_420xx (jsc#PED-14238).\n- crypto: qat - add command queue telemetry counters for GEN6 (jsc#PED-14238).\n- crypto: qat - add compression slice count for rate limiting (jsc#PED-14238).\n- crypto: qat - add decompression service for rate limiting (jsc#PED-14238).\n- crypto: qat - add decompression service to telemetry (jsc#PED-14238).\n- crypto: qat - add firmware headers for GEN6 devices (jsc#PED-14238).\n- crypto: qat - add GEN6 firmware loader (jsc#PED-14238).\n- crypto: qat - add get_svc_slice_cnt() in device data structure (jsc#PED-14238).\n- crypto: qat - add live migration enablers for GEN6 devices (jsc#PED-14238).\n- crypto: qat - add macro to write 64-bit values to registers (jsc#PED-14238).\n- crypto: qat - add missing header inclusion (jsc#PED-14238).\n- crypto: qat - add qat_6xxx driver (jsc#PED-14238).\n- crypto: qat - add ring buffer idle telemetry counter for GEN6 (jsc#PED-14238).\n- crypto: qat - add support for decompression service to GEN6 devices (jsc#PED-14238).\n- crypto: qat - consolidate service enums (jsc#PED-14238).\n- crypto: qat - Constify struct pm_status_row (jsc#PED-14238).\n- crypto: qat - disable 4xxx AE cluster when lead engine is fused off (git-fixes).\n- crypto: qat - disable 420xx AE cluster when lead engine is fused off (git-fixes).\n- crypto: qat - do not export adf_cfg_services (jsc#PED-14238).\n- crypto: qat - enable power management debugfs for GEN6 devices (jsc#PED-14238).\n- crypto: qat - enable RAS support for GEN6 devices (jsc#PED-14238).\n- crypto: qat - enable rate limiting feature for GEN6 devices (jsc#PED-14238).\n- crypto: qat - enable reporting of error counters for GEN6 devices (jsc#PED-14238).\n- crypto: qat - enable telemetry for GEN6 devices (jsc#PED-14238).\n- crypto: qat - export adf_get_service_mask() (jsc#PED-14238).\n- crypto: qat - export adf_init_admin_pm() (jsc#PED-14238).\n- crypto: qat - expose configuration functions (jsc#PED-14238).\n- crypto: qat - fix compression instance leak (git-fixes).\n- crypto: qat - fix IRQ cleanup on 6xxx probe failure (git-fixes).\n- crypto: qat - fix object goals in Makefiles (jsc#PED-14238.\n- crypto: qat - fix type mismatch in RAS sysfs show functions (git-fixes).\n- crypto: qat - Fix typo \"accelaration\" (jsc#PED-14238).\n- crypto: qat - fix virtual channel configuration for GEN6 devices (jsc#PED-14238).\n- crypto: qat - include qat_common in top Makefile (jsc#PED-14238).\n- crypto: qat - introduce fuse array (jsc#PED-14238).\n- crypto: qat - make adf_dev_autoreset() static (jsc#PED-14238).\n- crypto: qat - optimize allocations for fw authentication (jsc#PED-14238).\n- crypto: qat - refactor compression template logic (jsc#PED-14238).\n- crypto: qat - refactor FW signing algorithm (jsc#PED-14238).\n- crypto: qat - refactor ring-related debug functions (jsc#PED-14238).\n- crypto: qat - refactor service parsing logic (jsc#PED-14238).\n- crypto: qat - relocate and rename bank state structure definition (jsc#PED-14238).\n- crypto: qat - relocate bank state helper functions (jsc#PED-14238).\n- crypto: qat - relocate power management debugfs helper APIs (jsc#PED-14238).\n- crypto: qat - relocate service related functions (jsc#PED-14238).\n- crypto: qat - remove BITS_IN_DWORD() (jsc#PED-14238).\n- crypto: qat - Remove dst_null support (jsc#PED-14238).\n- crypto: qat - remove duplicate masking for GEN6 devices (jsc#PED-14238).\n- crypto: qat - remove initialization in device class (jsc#PED-14238).\n- crypto: qat - remove redundant FW image size check (jsc#PED-14238).\n- crypto: qat - remove unused adf_devmgr_get_first (jsc#PED-14238).\n- crypto: qat - remove unused members in suof structure (jsc#PED-14238).\n- crypto: qat - rename and relocate timer logic (jsc#PED-14238).\n- crypto: qat - reorder objects in qat_common Makefile (jsc#PED-14238).\n- crypto: qat - replace CHECK_STAT macro with static inline function (jsc#PED-14238).\n- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (jsc#PED-14238).\n- crypto: qat - restore ASYM service support for GEN6 devices (jsc#PED-14238).\n- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (jsc#PED-14238).\n- crypto: qat - set command ids as reserved (jsc#PED-14238).\n- crypto: qat - switch to standard pattern for PCI IDs (jsc#PED-14238).\n- crypto: qat - update firmware api (jsc#PED-14238).\n- crypto: qat - use pr_fmt() in adf_gen4_hw_data.c (jsc#PED-14238).\n- crypto: qat - use pr_fmt() in qat uclo.c (jsc#PED-14238).\n- crypto: qat - use simple_strtoull to improve qat_uclo_parse_num (jsc#PED-14238).\n- crypto: qat - use swab32 macro (git-fixes).\n- crypto: qat - validate service in rate limiting sysfs api (jsc#PED-14238).\n- crypto: qat/qat_6xxx - Fix NULL vs IS_ERR() check in adf_probe() (jsc#PED-14238).\n- crypto: sa2ul - Fix AEAD fallback algorithm names (git-fixes).\n- crypto: simd - reject compat registrations without __ prefixes (git-fixes).\n- crypto: talitos - fix SEC1 32k ahash request limitation (git-fixes).\n- crypto: tegra - Disable softirqs before finalizing request (git-fixes).\n- devres: fix missing node debug info in devm_krealloc() (git-fixes).\n- dmaengine: dw-axi-dmac: fix Alignment should match open parenthesis (git-fixes).\n- dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (git-fixes).\n- dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (git-fixes).\n- dpll: zl3073x: Add support to adjust phase (bsc#1255752).\n- dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752).\n- dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752).\n- dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752).\n- drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes).\n- drm/amd/display: Add NULL check for integrated_info in clk_mgr_construct (git-fixes).\n- drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes).\n- drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths (git-fixes).\n- drm/amd/display: Change dither policy for 10 bpc output back to dithering (git-fixes).\n- drm/amd/display: Correct logic check error for fastboot (git-fixes).\n- drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes).\n- drm/amd/display: Disable fastboot on DCE 6 too (stable-fixes).\n- drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes).\n- drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (git-fixes).\n- drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (git-fixes).\n- drm/amd/pm/ci: Fill DW8 fields from SMC (git-fixes).\n- drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (git-fixes).\n- drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (git-fixes).\n- drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (git-fixes).\n- drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (git-fixes).\n- drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes).\n- drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes).\n- drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes).\n- drm/amdgpu/gfx10: look at the right prop for gfx queue priority (git-fixes).\n- drm/amdgpu/gfx11: look at the right prop for gfx queue priority (git-fixes).\n- drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes).\n- drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes).\n- drm/amdgpu/pm: add missing revision check for CI (git-fixes).\n- drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes).\n- drm/amdgpu/pm: drop SMU driver if version not matched messages (stable-fixes).\n- drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes).\n- drm/amdgpu/vce: Prevent partial address patches (stable-fixes).\n- drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes).\n- drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes).\n- drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes).\n- drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes).\n- drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes).\n- drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes).\n- drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes).\n- drm/amdgpu: Add default case in DVI mode validation (git-fixes).\n- drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes).\n- drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes).\n- drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes).\n- drm/amdgpu: replace PASID IDR with XArray (git-fixes).\n- drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes).\n- drm/amdgpu: zero-initialize GART table on allocation (stable-fixes).\n- drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes).\n- drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes).\n- drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes).\n- drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes).\n- drm/arcpgu: fix device node leak (git-fixes).\n- drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs (git-fixes).\n- drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check (git-fixes).\n- drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() (git-fixes).\n- drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes).\n- drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes).\n- drm/exynos: remove bridge when component_add fails (git-fixes).\n- drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes).\n- drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes).\n- drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes).\n- drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes).\n- drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes).\n- drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes).\n- drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (git-fixes).\n- drm/i915/wm: Verify the correct plane DDB entry (git-fixes).\n- drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes).\n- drm/imagination: Switch reset_reason fields from enum to u32 (git-fixes).\n- drm/komeda: fix integer overflow in AFBC framebuffer size check (git-fixes).\n- drm/loongson: Use managed KMS polling (git-fixes).\n- drm/msm/a6xx: Fix dumping A650+ debugbus blocks (git-fixes).\n- drm/msm/a6xx: Fix HLSQ register dumping (git-fixes).\n- drm/msm/a6xx: Use barriers while updating HFI Q headers (git-fixes).\n- drm/msm/dpu: fix mismatch between power and frequency (git-fixes).\n- drm/msm/dsi: add the missing parameter description (git-fixes).\n- drm/msm/dsi: fix bits_per_pclk (git-fixes).\n- drm/msm/dsi: fix hdisplay calculation for CMD mode panel (git-fixes).\n- drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (git-fixes).\n- drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() (git-fixes).\n- drm/msm/shrinker: Fix can_block() logic (git-fixes).\n- drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes).\n- drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes).\n- drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes).\n- drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes).\n- drm/panel: sharp-ls043t1le01: make use of prepare_prev_first (git-fixes).\n- drm/panel: simple: Correct G190EAN01 prepare timing (git-fixes).\n- drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes).\n- drm/panthor: Fix outdated function documentation (git-fixes).\n- drm/radeon: add missing revision check for CI (git-fixes).\n- drm/sun4i: backend: fix error pointer dereference (git-fixes).\n- drm/sun4i: Fix resource leaks (git-fixes).\n- drm/v3d: Handle error from drm_sched_entity_init() (git-fixes).\n- drm/vc4: Fix a memory leak in hang state error path (git-fixes).\n- drm/vc4: Fix memory leak of BO array in hang state (git-fixes).\n- drm/vc4: platform_get_irq_byname() returns an int (stable-fixes).\n- drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (git-fixes).\n- drm/vc4: Release runtime PM reference after binding V3D (git-fixes).\n- drm/vram: remove DRM_VRAM_MM_FILE_OPERATIONS from docs (git-fixes).\n- drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes).\n- drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes).\n- drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes).\n- drm/xe/dma-buf: handle empty bo and UAF races (git-fixes).\n- drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes).\n- drm/xe/uapi: update used tracking kernel-doc (git-fixes).\n- drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes).\n- drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes).\n- dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes).\n- efi/capsule-loader: fix incorrect sizeof in phys array reallocation (git-fixes).\n- efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes).\n- erofs: add GFP_NOIO in the bio completion if needed (git-fixes).\n- ext4: fix fsync(2) for nojournal mode (git-fixes).\n- ext4: make recently_deleted() properly work with lazy itable initialization (git-fixes).\n- ext4: reject mount if bigalloc with s_first_data_block != 0 (git-fixes).\n- extcon: Fixed sysfs duplicate filename issue (git-fixes).\n- extcon: ptn5150: handle pending IRQ events during system resume (git-fixes).\n- fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (git-fixes).\n- fbdev: offb: fix PCI device reference leak on probe failure (git-fixes).\n- fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes).\n- fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes).\n- firmware: arm_ffa: Use the correct buffer size during RXTX_MAP (git-fixes).\n- firmware: dmi: Correct an indexing error in dmi.h (git-fixes).\n- firmware: google: framebuffer: Do not mark framebuffer as busy (git-fixes).\n- firmware: google: framebuffer: Do not unregister platform device (git-fixes).\n- gpio: of: clear OF_POPULATED on hog nodes in remove path (git-fixes).\n- gpio: tegra: fix irq_release_resources calling enable instead of disable (git-fixes).\n- gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes).\n- HID: alps: fix NULL pointer dereference in alps_raw_event() (git-fixes).\n- HID: amd_sfh: don't log error when device discovery fails with -EOPNOTSUPP (git-fixes).\n- HID: apple: ensure the keyboard backlight is off if suspending (git-fixes).\n- HID: asus: do not abort probe when not necessary (git-fixes).\n- HID: asus: make asus_resume adhere to linux kernel coding standards (git-fixes).\n- HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes).\n- HID: logitech-hidpp: Enable MX Master 4 over bluetooth (stable-fixes).\n- HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (stable-fixes).\n- HID: multitouch: Check to ensure report responses match the request (stable-fixes).\n- HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes).\n- HID: roccat: fix use-after-free in roccat_report_event (stable-fixes).\n- HID: usbhid: fix deadlock in hid_post_reset() (git-fixes).\n- HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (stable-fixes).\n- hisi_acc_vfio_pci: add eq and aeq interruption restore (git-fixes).\n- hisi_acc_vfio_pci: bugfix cache write-back issue (git-fixes).\n- hisi_acc_vfio_pci: bugfix the problem of uninstalling driver (git-fixes).\n- hv_sock: fix ARM64 support (git-fixes).\n- hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes).\n- hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes).\n- hwmon: (corsair-psu) Close HID device on probe errors (git-fixes).\n- hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes).\n- hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes).\n- hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes).\n- hwmon: (ltc4286) Add missing MODULE_IMPORT_NS(\"PMBUS\") (git-fixes).\n- hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt (git-fixes).\n- hwmon: (powerz) Fix use-after-free on USB disconnect (git-fixes).\n- hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data() (git-fixes).\n- i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes).\n- i2c: smbus: reject oversized block transfers in the common path (git-fixes).\n- i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes).\n- i2c: stub: Reject I2C block transfers with invalid length (git-fixes).\n- i2c: tegra: Add HS mode support (bsc#1261550).\n- i2c: tegra: Add Tegra256 support (bsc#1261550).\n- i2c: tegra: Do not configure DMA if not supported (bsc#1261550).\n- i2c: tegra: Don't mark devices with pins as IRQ safe (stable-fixes).\n- i2c: tegra: Update Tegra256 timing parameters (bsc#1261550).\n- i2c: tegra: Use separate variables for fast and fastplus (bsc#1261550).\n- i3c: dw: Fix memory leak in dw_i3c_master_i3c_xfers() (git-fixes).\n- i3c: master: Fix error codes at send_ccc_cmd (git-fixes).\n- i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (git-fixes).\n- ibmveth: Disable GSO for packets with small MSS (bsc#1265144).\n- iio: adc: ad7192: Revert \"properly check spi_get_device_match_data()\" (stable-fixes).\n- iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes).\n- iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes).\n- iio: frequency: admv1013: add dev variable (stable-fixes).\n- iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes).\n- Input: bcm5974 - recover from failed mode switch (stable-fixes).\n- Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table (stable-fixes).\n- Input: uinput - fix circular locking dependency with ff-core (git-fixes).\n- Input: uinput - take event lock when submitting FF request \"event\" (stable-fixes).\n- Input: xpad - add support for BETOP BTP-KP50B/C controller's wireless mode (stable-fixes).\n- Input: xpad - add support for Razer Wolverine V3 Pro (stable-fixes).\n- interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes).\n- io_uring/timeout: check unused sqe fields (git-fixes).\n- iommu/amd: move wait_on_sem() out of spinlock (git-fixes bsc#1260593).\n- iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes bsc#1260593).\n- iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113).\n- ipmi: Add limits to event and receive message requests (git-fixes).\n- ipmi: Check event message buffer response for bad data (git-fixes).\n- ipmi: ssif_bmc: change log level to dbg in irq callback (git-fixes).\n- ipmi: ssif_bmc: fix message desynchronization after truncated response (git-fixes).\n- ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure (git-fixes).\n- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes).\n- KVM: arm64: Allow cacheable stage 2 mapping using VMA flags (git-fixes).\n- KVM: arm64: Assume non-PFNMAP/MIXEDMAP VMAs can be mapped cacheable (git-fixes).\n- KVM: arm64: Block cacheable PFNMAP mapping (git-fixes).\n- KVM: arm64: Consolidate idreg callbacks (git-fixes).\n- KVM: arm64: Discard PC update state on vcpu reset (git-fixes).\n- KVM: arm64: Finalize ID registers only once per VM (git-fixes).\n- KVM: arm64: Fix MTE flag initialization for protected VMs (git-fixes).\n- KVM: arm64: Fix page leak in user_mem_abort() (git-fixes).\n- KVM: arm64: Fix Trace Buffer trap polarity for protected VMs (git-fixes).\n- KVM: arm64: Fix Trace Buffer trapping for protected VMs (git-fixes).\n- KVM: arm64: Fix vma_shift staleness on nested hwpoison path (git-fixes).\n- KVM: arm64: Hide S1POE from guests when not supported by the host (git-fixes).\n- KVM: arm64: Limit clearing of ID_{AA64PFR0,PFR1}_EL1.GIC to userspace irqchip (git-fixes).\n- KVM: arm64: Make all 32bit ID registers fully writable (git-fixes).\n- KVM: arm64: nv: Add trap config for DBGWCR<15>_EL1 (git-fixes).\n- KVM: arm64: nv: Return correct RES0 bits for FGT registers (git-fixes).\n- KVM: arm64: pkvm: Fallback to level-3 mapping on host stage-2 fault (git-fixes).\n- KVM: arm64: Read PMUVer as unsigned (git-fixes).\n- KVM: arm64: Rename the device variable to s2_force_noncacheable (git-fixes).\n- KVM: arm64: Return early from trace helpers when KVM isn't available (git-fixes).\n- KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes).\n- KVM: arm64: vgic-v3: Release reserved slot outside of lpi_xa's lock (git-fixes).\n- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).\n- KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git-fixes).\n- KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes).\n- KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes).\n- KVM: SEV: Disallow LAUNCH_FINISH if vCPUs are actively being created (git-fixes).\n- KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (git-fixes).\n- KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish (git-fixes).\n- KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (git-fixes).\n- KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (git-fixes).\n- KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes).\n- KVM: SVM: Fix a missing kunmap_local() in sev_gmem_post_populate() (git-fixes).\n- KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes).\n- KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes).\n- KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes).\n- KVM: SVM: Properly check RAX in the emulator for SVM instructions (git-fixes).\n- KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (git-fixes).\n- KVM: TDX: Explicitly set user-return MSRs that *may* be clobbered by the TDX-Module (git-fixes).\n- KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes).\n- KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes).\n- KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2() (git-fixes).\n- KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes).\n- KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes).\n- KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes).\n- KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes).\n- KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes).\n- KVM: x86: Ignore cpuid faulting in SMM (git-fixes).\n- leds: lgm-sso: Remove duplicate assignments for priv->mmap (git-fixes).\n- leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes).\n- lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (git-fixes).\n- md/raid1: fix the comparing region of interval tree (bsc#1261555).\n- md/raid1: serialize overlap io for writemostly disk (bsc#1261555).\n- media: amphion: Fix race between m2m job_abort and device_run (git-fixes).\n- media: as102: fix to not free memory after the device is registered in as102_usb_probe() (git-fixes).\n- media: chips-media: wave5: add missing spinlock protection for handle_dynamic_resolution_change() (git-fixes).\n- media: chips-media: wave5: add missing spinlock protection for send_eos_event() (git-fixes).\n- media: chips-media: wave5: fix a potential memory leak in wave5_vdi_init() (git-fixes).\n- media: dib8000: avoid division by 0 in dib8000_set_dds() (git-fixes).\n- media: em28xx: fix use-after-free in em28xx_v4l2_open() (git-fixes).\n- media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (git-fixes).\n- media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (git-fixes).\n- media: i2c: imx283: Enter full standby when stopping streaming (git-fixes).\n- media: i2c: imx283: Fix hang when going from large to small resolution (git-fixes).\n- media: i2c: imx412: Assert reset GPIO during probe (git-fixes).\n- media: i2c: ov08d10: fix image vertical start setting (git-fixes).\n- media: i2c: ov8856: free control handler on error in ov8856_init_controls() (git-fixes).\n- media: intel/ipu6: fix error pointer dereference (git-fixes).\n- media: mtk-jpeg: fix use-after-free in release path due to uncancelled work (git-fixes).\n- media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0 (git-fixes).\n- media: omap3isp: drop the use count of v4l2 pipeline (git-fixes).\n- media: pci: zoran: fix potential memory leak in zoran_probe() (git-fixes).\n- media: rc: streamzap: Error handling in probe (git-fixes).\n- media: rc: xbox_remote: heed DMA restrictions (git-fixes).\n- media: saa7164: add ioremap return checks and cleanups (git-fixes).\n- media: staging: imx: configure src_mux in csi_start (git-fixes).\n- media: staging: imx: request mbus_config in csi_start (git-fixes).\n- media: uvcvideo: Enable VB2_DMABUF for metadata stream (git-fixes).\n- media: videobuf2: Set vma_flags in vb2_dma_sg_mmap (git-fixes).\n- media: vidtv: fix nfeeds state corruption on start_streaming failure (git-fixes).\n- media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (git-fixes).\n- media: vidtv: fix pass-by-value structs causing MSAN warnings (git-fixes).\n- memory: tegra30-emc: Fix dll_change check (git-fixes).\n- memory: tegra124-emc: Fix dll_change check (git-fixes).\n- mfd: core: Preserve OF node when ACPI handle is present (git-fixes).\n- mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (git-fixes).\n- mfd: stpmic1: Attempt system shutdown twice in case PMIC is confused (git-fixes).\n- mkspec: Add signature to source list only when it exists.\n- mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (git-fixes).\n- mmc: vub300: fix NULL-deref on disconnect (git-fixes).\n- modpost: Amend ppc64 save/restfpr symnames for -Os build (bsc#1215199).\n- mtd: docg3: fix use-after-free in docg3_release() (git-fixes).\n- mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (git-fixes).\n- mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (git-fixes).\n- mtd: physmap_of_gemini: Fix disabled pinctrl state check (git-fixes).\n- mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (git-fixes).\n- mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (git-fixes).\n- mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes).\n- mtd: spi-nor: sst: Fix write enable before AAI sequence (git-fixes).\n- mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (git-fixes).\n- net-shapers: don't free reply skb after genlmsg_reply() (git-fixes).\n- net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes).\n- net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626).\n- net/sched: cls_fw: fix NULL dereference of \"old\" filters before change() (git-fixes).\n- net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421).\n- net: gro: don't merge zcopy skbs (git-fixes).\n- net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf (git-fixes).\n- net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes).\n- net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes).\n- net: mana: Don't overwrite port probe error with add_adev result (git-fixes).\n- net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (bsc#1265846).\n- net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes).\n- net: mana: Fix RX skb truesize accounting (bsc#1248754).\n- net: mana: Guard mana_remove against double invocation (git-fixes).\n- net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes).\n- net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes).\n- net: mana: Init gf_stats_work before potential error paths in probe (git-fixes).\n- net: mana: Init link_change_work before potential error paths in probe (git-fixes).\n- net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes).\n- net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes).\n- net: mana: Set default number of queues to 16 (bsc#1261648).\n- net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes).\n- net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes).\n- net: mana: Use pci_name() for debugfs directory naming (git-fixes).\n- net: phy: broadcom: Save PHY counters during suspend (git-fixes).\n- net: phy: DP83TC811: add reading of abilities (git-fixes).\n- net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes).\n- net: phy: fix a return path in get_phy_c45_ids() (git-fixes).\n- net: phy: qcom: at803x: Use the correct bit to disable extended next page (git-fixes).\n- net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes).\n- net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes).\n- net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (git-fixes).\n- net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes).\n- net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes).\n- net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes).\n- net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes).\n- net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes).\n- net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes).\n- NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (git-fixes).\n- nfc: llcp: add missing return after LLCP_CLOSED checks (git-fixes).\n- nfc: pn533: allocate rx skb before consuming bytes (git-fixes).\n- nfc: s3fwrn5: allocate rx skb before consuming bytes (git-fixes).\n- NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes).\n- nvme-apple: drop invalid put of admin queue reference count (git-fixes).\n- nvme-auth: Include SC_C in RVAL controller hash (bsc#1260428).\n- nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709).\n- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes).\n- nvme: Allow reauth from sysfs (bsc#1259672).\n- nvme: Expose the tls_configured sysfs for secure concat connections (bsc#1259672).\n- nvme: expose TLS mode (bsc#1259672).\n- nvme: fix admin queue leak on controller reset (git-fixes).\n- nvme: fix PCIe subsystem reset controller state transition (bsc#1261738).\n- nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes).\n- ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718).\n- ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).\n- openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes).\n- panic/printk: replace other_cpu_in_panic() with panic_on_other_cpu() (bsc#1261149).\n- panic/printk: replace this_cpu_in_panic() with panic_on_this_cpu() (bsc#1261149).\n- panic: introduce helper functions for panic state (bsc#1261149).\n- panic: use angle-bracket include for panic.h (bsc#1261149).\n- PCI/AER: Clear only error bits in PCIe Device Status (git-fixes).\n- PCI/AER: Stop ruling out unbound devices as error source (git-fixes).\n- PCI/ASPM: Fix pci_clear_and_set_config_dword() usage (git-fixes).\n- PCI/NPEM: Set LED_HW_PLUGGABLE for hotplug-capable ports (git-fixes).\n- PCI/TPH: Allow TPH enable for RCiEPs (git-fixes).\n- PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well (git-fixes).\n- PCI: dwc: rcar-gen4: Change EPC BAR alignment to 4K as per the documentation (git-fixes).\n- PCI: Enable AtomicOps only if Root Port supports them (git-fixes).\n- PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (git-fixes).\n- PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup (git-fixes).\n- PCI: epf-mhi: Return 0, not remaining timeout, when eDMA ops complete (git-fixes).\n- PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648).\n- PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found (git-fixes).\n- PCI: qcom: Advertise Hotplug Slot Capability with no Command Completion support (git-fixes).\n- PCI: tegra194: Allow system suspend when the Endpoint link is not up (git-fixes).\n- PCI: tegra194: Disable direct speed change for Endpoint mode (git-fixes).\n- PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (git-fixes).\n- PCI: tegra194: Disable PERST# IRQ only in Endpoint mode (git-fixes).\n- PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on (git-fixes).\n- PCI: tegra194: Fix polling delay for L2 state (git-fixes).\n- PCI: tegra194: Free up Endpoint resources during remove() (git-fixes).\n- PCI: tegra194: Increase LTSSM poll time on surprise link down (git-fixes).\n- PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode (git-fixes).\n- PCI: tegra194: Use devm_gpiod_get_optional() to parse \"nvidia,refclk-select\" (git-fixes).\n- PCI: tegra194: Use DWC IP core version (git-fixes).\n- pinctrl: abx500: Fix type of 'argument' variable (git-fixes).\n- pinctrl: Fix spelling problem (git-fixes).\n- pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes).\n- pinctrl: pic32: change all cases of bare 'unsigned' to 'unsigned int' (git-fixes).\n- pinctrl: pic32: use consistent spacing around '+' (git-fixes).\n- pinctrl: pinctrl-pic32: Fix resource leak (git-fixes).\n- pinctrl: realtek: Fix function signature for config argument (git-fixes).\n- pinctrl: renesas: rzg2l: Fix save/restore of {IOLH,IEN,PUPD,SMT} registers (git-fixes).\n- platform/chrome: chromeos_tbmc: Drop wakeup source on remove (git-fixes).\n- platform/surface: surfacepro3_button: Drop wakeup source on remove (git-fixes).\n- platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes).\n- platform/x86/intel-uncore-freq: Handle autonomous UFS status bit (git-fixes).\n- platform/x86: asus-wmi: adjust screenpad power/brightness handling (git-fixes).\n- platform/x86: asus-wmi: fix screenpad brightness range (git-fixes).\n- platform/x86: dell-wmi-sysman: bound enumeration string aggregation (git-fixes).\n- platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (git-fixes).\n- platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes).\n- platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (git-fixes).\n- power: supply: axp288_charger: Do not cancel work before initializing it (git-fixes).\n- power: supply: max17042: avoid overflow when determining health (git-fixes).\n- powerpc/crash: fix backup region offset update to elfcorehdr (bsc#1259535).\n- powerpc/crash: Update backup region offset in elfcorehdr on memory hotplug (bsc#1259535).\n- printk/nbcon/panic: Allow printk kthread to sleep when the system is in panic (bsc#1261149).\n- printk/nbcon: Block printk kthreads when any CPU is in an emergency context (bsc#1261149).\n- printk/nbcon: Release nbcon consoles ownership in atomic flush after each emitted record (bsc#1261149).\n- printk/nbcon: Restore IRQ in atomic flush after each emitted record (bsc#1261149).\n- printk/nbcon: use panic_on_this_cpu() helper (bsc#1261149).\n- printk: Allow printk_trigger_flush() to flush all types (bsc#1262750).\n- printk: Allow to use the printk kthread immediately even for 1st nbcon (jsc#PED-7912).\n- printk: Avoid irq_work for printk_deferred() on suspend (bsc#1262750).\n- printk: Avoid scheduling irq_work on suspend (bsc#1262750).\n- printk: console_flush_one_record() code cleanup (bsc#1261149).\n- printk: Introduce console_flush_one_record (bsc#1261149).\n- printk: Use console_flush_one_record for legacy printer kthread (bsc#1261149).\n- pwm: imx-tpm: Count the number of enabled channels in probe (git-fixes).\n- qat: don't mess with ->d_name (jsc#PED-14238).\n- r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes).\n- RDMA/irdma: Fix double free related to rereg_user_mr (git-fixes).\n- RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes).\n- RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes).\n- RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes).\n- RDMA/mana: Validate rx_hash_key_len (git-fixes).\n- RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes).\n- RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes).\n- RDMA/mana_ib: Support memory windows (git-fixes).\n- regulator: act8945a: fix OF node reference imbalance (git-fixes).\n- regulator: bd9571mwv: fix OF node reference imbalance (git-fixes).\n- regulator: max77650: fix OF node reference imbalance (git-fixes).\n- regulator: mt6357: fix OF node reference imbalance (git-fixes).\n- regulator: rk808: fix OF node reference imbalance (git-fixes).\n- remoteproc: xlnx: Fix sram property parsing (git-fixes).\n- remoteproc: xlnx: Only access buffer information if IPI is buffered (git-fixes).\n- Revert \"ALSA: usb: Increase volume range that triggers a warning\" (git-fixes).\n- Revert \"serial: 8250: Revert \"drop lockdep annotation from serial8250_clear_IER()\"\" (bsc#1262480).\n- Revert \"serial: 8250: Switch to nbcon console\" (bsc#1262480).\n- rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes).\n- rtc: ntxec: fix OF node reference imbalance (git-fixes).\n- s390/dasd: Copy detected format information to secondary device (bsc#1259994).\n- s390/dasd: Fix gendisk parent after copy pair swap (bsc#1259994).\n- s390/dasd: Move quiesce state with pprc swap (bsc#1259994).\n- sched/fair: Change likelyhood of nohz.nr_cpus (bsc#1234634 bsc#1258961).\n- sched/fair: Move checking for nohz cpus after time check (bsc#1234634 bsc#1258961).\n- sched/fair: Remove nohz.nr_cpus and use weight of cpumask instead (bsc#1234634 bsc#1258961).\n- scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019).\n- scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019).\n- scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019).\n- scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019).\n- scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019).\n- scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019).\n- scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019).\n- scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019).\n- scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019).\n- scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019).\n- scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019).\n- scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019).\n- scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019).\n- scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019).\n- scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019).\n- scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019).\n- scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019).\n- scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019).\n- scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019).\n- scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019).\n- scsi: lpfc: Update copyright year string for 2026 (bsc#1262019).\n- scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019).\n- scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019).\n- scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019).\n- scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019).\n- scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019).\n- scsi: lpfc: Use the crc32c() function (bsc#1262019).\n- scsi: mpi3mr: Add NULL checks when resetting request and reply queues (git-fixes).\n- scsi: ses: Fix devices attaching to different hosts (git-fixes).\n- scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes).\n- scsi: target: iscsi: validate CHAP_R length before base64 decode (bsc#1265449).\n- scsi: ufs: ufs-pci: Add support for Intel Wildcat Lake (jsc#PED-13771).\n- selftests/bpf: Test cross-sign 64bits range refinement (git-fixes).\n- selftests/bpf: Test invariants on JSLT crossing sign (git-fixes).\n- selftests/bpf: test refining u32/s32 bounds when ranges cross min/max boundary (git-fixes).\n- selftests: net: build net/lib dependency in all target (bsc#1262245).\n- selinux: don't reserve xattr slot when we won't fill it (stable-fixes).\n- selinux: prune /sys/fs/selinux/disable (stable-fixes).\n- selinux: shrink critical section in sel_write_load() (stable-fixes).\n- serial: 8250: Add serial8250_handle_irq_locked() (bsc#1262480).\n- serial: 8250: Protect LCR write in shutdown (bsc#1262480).\n- serial: 8250_dw: Avoid unnecessary LCR writes (bsc#1262480).\n- serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480).\n- serial: 8250_dw: Rework dw8250_handle_irq() locking and IIR handling (bsc#1262480).\n- serial: 8250_dw: Rework IIR_NO_INT handling to stop interrupt storm (bsc#1262480).\n- Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044).\n- soc/tegra: cbb: Set ERD on resume for err interrupt (git-fixes).\n- soc: qcom: aoss: compare against normalized cooling state (git-fixes).\n- soc: qcom: llcc: fix v1 SB syndrome register offset (git-fixes).\n- soc: qcom: ocmem: make the core clock optional (git-fixes).\n- soc: qcom: ocmem: register reasons for probe deferrals (git-fixes).\n- soc: qcom: ocmem: return -EPROBE_DEFER is ocmem is not available (git-fixes).\n- sound: ua101: fix division by zero at probe (git-fixes).\n- soundwire: bus: demote UNATTACHED state warnings to dev_dbg() (git-fixes).\n- soundwire: cadence: Clear message complete before signaling waiting thread (git-fixes).\n- soundwire: debugfs: initialize firmware_file to empty string (git-fixes).\n- spi: aspeed-smc: fix controller deregistration (git-fixes).\n- spi: at91-usart: fix controller deregistration (git-fixes).\n- spi: atmel: fix controller deregistration (git-fixes).\n- spi: bcm63xx: fix controller deregistration (git-fixes).\n- spi: bcmbca-hsspi: fix controller deregistration (git-fixes).\n- spi: cadence: fix controller deregistration (git-fixes).\n- spi: cadence: fix unclocked access on unbind (git-fixes).\n- spi: ch341: fix memory leaks on probe failures (git-fixes).\n- spi: coldfire-qspi: fix controller deregistration (git-fixes).\n- spi: dln2: fix controller deregistration (git-fixes).\n- spi: fix controller cleanup() documentation (git-fixes).\n- spi: fix misleading controller deregistration kernel-doc (git-fixes).\n- spi: fix misleading controller registration kernel-doc (git-fixes).\n- spi: fsl-espi: fix controller deregistration (git-fixes).\n- spi: fsl-qspi: Use reinit_completion() for repeated operations (git-fixes).\n- spi: fsl: fix controller deregistration (git-fixes).\n- spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (git-fixes).\n- spi: img-spfi: fix controller deregistration (git-fixes).\n- spi: imx: fix runtime pm leak on probe deferral (git-fixes).\n- spi: imx: fix use-after-free on unbind (git-fixes).\n- spi: lantiq-ssc: fix controller deregistration (git-fixes).\n- spi: meson-spicc: fix controller deregistration (git-fixes).\n- spi: microchip-core-qspi: fix controller deregistration (git-fixes).\n- spi: mpc52xx: fix controller deregistration (git-fixes).\n- spi: mpc52xx: fix use-after-free on registration failure (git-fixes).\n- spi: mpc52xx: fix use-after-free on unbind (git-fixes).\n- spi: mtk-nor: fix controller deregistration (git-fixes).\n- spi: mtk-snfi: fix memory leak in probe (git-fixes).\n- spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback (git-fixes).\n- spi: mxic: fix controller deregistration (git-fixes).\n- spi: mxs: fix controller deregistration (git-fixes).\n- spi: npcm-pspi: fix controller deregistration (git-fixes).\n- spi: omap2-mcspi: fix controller deregistration (git-fixes).\n- spi: orion: fix clock imbalance on registration failure (git-fixes).\n- spi: orion: fix controller deregistration (git-fixes).\n- spi: orion: fix runtime pm leak on unbind (git-fixes).\n- spi: pic32-sqi: fix controller deregistration (git-fixes).\n- spi: pic32: fix controller deregistration (git-fixes).\n- spi: pl022: fix controller deregistration (git-fixes).\n- spi: qup: fix controller deregistration (git-fixes).\n- spi: rockchip: fix controller deregistration (git-fixes).\n- spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes).\n- spi: rspi: fix controller deregistration (git-fixes).\n- spi: s3c64xx: fix controller deregistration (git-fixes).\n- spi: s3c64xx: fix NULL-deref on driver unbind (git-fixes).\n- spi: sh-hspi: fix controller deregistration (git-fixes).\n- spi: sprd: fix controller deregistration (git-fixes).\n- spi: st-ssc4: fix controller deregistration (git-fixes).\n- spi: sun4i: fix controller deregistration (git-fixes).\n- spi: sun6i: fix controller deregistration (git-fixes).\n- spi: syncuacer: fix controller deregistration (git-fixes).\n- spi: ti-qspi: fix controller deregistration (git-fixes).\n- spi: topcliff-pch: fix controller deregistration (git-fixes).\n- spi: topcliff-pch: fix use-after-free on unbind (git-fixes).\n- spi: uniphier: fix controller deregistration (git-fixes).\n- spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes).\n- spi: zynq-qspi: fix controller deregistration (git-fixes).\n- spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes).\n- spi: zynqmp-gqspi: fix controller deregistration (git-fixes).\n- staging: media: atomisp: Disallow all private IOCTLs (git-fixes).\n- staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (git-fixes).\n- staging: sm750fb: fix division by zero in ps_to_hz() (git-fixes).\n- staging: vme_user: fix root device leak on init failure (git-fixes).\n- tg3: replace placeholder MAC address with device property (git-fixes).\n- thermal/drivers/spear: Fix error condition for reading st,thermal-flags (git-fixes).\n- thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (git-fixes).\n- thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (git-fixes).\n- tools/power/turbostat: Fix microcode patch level output for AMD/Hygon (git-fixes).\n- tools: hv: Fix cross-compilation (git-fixes).\n- tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes).\n- tpm: avoid -Wunused-but-set-variable (git-fixes).\n- tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes).\n- tpm: tpm_tis: add error logging for data transfer (git-fixes).\n- tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes).\n- tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes).\n- tty: serial: ip22zilog: Fix section mispatch warning (git-fixes).\n- udp: Force compute_score to always inline (bsc#1241259).\n- unshare: fix unshare_fs() handling (git-fixes).\n- USB: cdc-acm: Add quirks for Yoga Book 9 14IAH10 INGENIC touchscreen (git-fixes).\n- usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (git-fixes).\n- usb: chipidea: otg: not wait vbus drop if use role_switch (git-fixes).\n- USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam (stable-fixes).\n- usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer (stable-fixes).\n- usb: gadget: f_hid: Add missing error code (git-fixes).\n- usb: gadget: f_hid: don't call cdev_init while cdev in use (git-fixes).\n- usb: gadget: f_hid: move list and spinlock inits from bind to alloc (stable-fixes).\n- usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (git-fixes).\n- usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (git-fixes).\n- usb: gadget: f_uac1_legacy: validate control request size (stable-fixes).\n- usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (git-fixes).\n- usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes).\n- USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes).\n- usb: port: add delay after usb_hub_set_port_power() (git-fixes).\n- usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive (stable-fixes).\n- USB: serial: io_edgeport: add support for Blackbox IC135A (stable-fixes).\n- USB: serial: option: add MeiG Smart SRM825WN (stable-fixes).\n- USB: serial: option: add support for Rolling Wireless RW135R-GL (stable-fixes).\n- USB: serial: option: add Telit Cinterion FN990A MBIM composition (git-fixes).\n- USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes).\n- usb: storage: Expand range of matched versions for VL817 quirks entry (git-fixes).\n- usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes).\n- usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes).\n- usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes).\n- usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes).\n- usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (git-fixes).\n- usbip: validate number_of_packets in usbip_pack_ret_submit() (git-fixes).\n- vfio/pci: Lock upstream bridge for vfio_pci_core_disable() (git-fixes).\n- vfio/pds: Fix memory leak in pds_vfio_dirty_enable() (git-fixes).\n- vfio/pds: Fix missing detach_ioas op (git-fixes).\n- vfio/pds: replace bitmap_free with vfree (git-fixes).\n- vfio/type1: Fix error unwind in migration dirty bitmap allocation (git-fixes).\n- vfio: Fix unbalanced vfio_df_close call in no-iommu mode (git-fixes).\n- vfio: Prevent open_count decrement to negative (git-fixes).\n- virt: arm-cca-guest: fix error check for RSI_INCOMPLETE (git-fixes).\n- virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes).\n- virt: tdx-guest: Fix handling of host controlled 'quote' buffer length (git-fixes).\n- virt: tdx-guest: Return error for GetQuote failures (git-fixes).\n- wifi: ath5k: do not access array OOB (git-fixes).\n- wifi: ath9k: Fix typo (git-fixes).\n- wifi: ath10k: fix station lookup failure during disconnect (git-fixes).\n- wifi: ath11k: fix memory leaks in beacon template setup (git-fixes).\n- wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes).\n- wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes).\n- wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes).\n- wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes).\n- wifi: brcmfmac: Fix error pointer dereference (git-fixes).\n- wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes).\n- wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes).\n- wifi: brcmsmac: Fix dma_free_coherent() size (git-fixes).\n- wifi: cw1200: Revert \"Fix locking in error paths\" (git-fixes).\n- wifi: libertas: notify firmware load wait on disconnect (git-fixes).\n- wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes).\n- wifi: mac80211: check tdls flag in ieee80211_tdls_oper (stable-fixes).\n- wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes).\n- wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() (git-fixes).\n- wifi: mac80211: remove station if connection prep fails (git-fixes).\n- wifi: mac80211: use safe list iteration in radar detect work (git-fixes).\n- wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req() (git-fixes).\n- wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes).\n- wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes).\n- wifi: mt76: mt7615: fix use_cts_prot support (git-fixes).\n- wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() (git-fixes).\n- wifi: mt76: mt7915: fix use_cts_prot support (git-fixes).\n- wifi: mt76: mt7921: fix 6GHz regulatory update on connection (git-fixes).\n- wifi: mt76: mt7921: fix a potential clc buffer length underflow (git-fixes).\n- wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work (git-fixes).\n- wifi: mt76: mt7921: Place upper limit on station AID (git-fixes).\n- wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() (git-fixes).\n- wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr (git-fixes).\n- wifi: mt76: mt7925: fix incorrect length field in txpower command (git-fixes).\n- wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control (git-fixes).\n- wifi: mt76: mt7925: fix incorrect TLV length in CLC command (git-fixes).\n- wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr() (git-fixes).\n- wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi (git-fixes).\n- wifi: mt76: mt7996: fix FCS error flag check in RX descriptor (git-fixes).\n- wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event (git-fixes).\n- wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() (git-fixes).\n- wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (git-fixes).\n- wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes).\n- wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes).\n- wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes).\n- wifi: rt2x00usb: fix devres lifetime (git-fixes).\n- wifi: rtl8xxxu: fix potential use of uninitialized value (git-fixes).\n- wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (git-fixes).\n- wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135).\n- wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135).\n- wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135).\n- wifi: rtw88: check for PCI upstream bridge existence (git-fixes).\n- wifi: rtw88: fix device leak on probe failure (git-fixes).\n- wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135).\n- wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() (git-fixes).\n- wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes).\n- x86/acpi/boot: Correct acpi_is_processor_usable() check again (git-fixes).\n- x86/boot/sev: Avoid shared GHCB page for early memory acceptance (git-fixes).\n- x86/boot/sev: Support memory acceptance in the EFI stub under SVSM (git-fixes).\n- x86/boot: Fix page table access in 5-level to 4-level paging transition (git-fixes).\n- x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255).\n- x86/cpufeatures: Free up unused feature bits (bsc#1263255).\n- x86/fred: Fix early boot failures on SEV-ES/SNP guests (git-fixes).\n- x86/mtrr: Check if fixed-range MTRRs exist in mtrr_save_fixed_ranges() (git-fixes).\n- x86/sev: Add missing RIP_REL_REF() invocations during sme_enable() (git-fixes).\n- x86/sev: Do not touch VMSA pages during SNP guest memory kdump (git-fixes).\n- x86/sev: Ensure SVSM reserved fields in a page validation entry are initialized to zero (git-fixes).\n- x86/sev: Fix operator precedence in GHCB_MSR_VMPL_REQ_LEVEL macro (git-fixes).\n- x86/sev: Improve handling of writes to intercepted TSC MSRs (git-fixes).\n- x86/sev: Make sure pages are not skipped during kdump (git-fixes).\n- x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1250951 bsc#1263044).\n- x86/tsx: Make tsx_ctrl_state static (bsc#1250951 bsc#1263044).\n- x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes).\n- X.509: Fix out-of-bounds access when parsing extensions (git-fixes).\n- Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815).\n","affected":[{"package":{"name":"kernel-obs-build","ecosystem":"SUSE:Linux Micro Extras 6.2","purl":"pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Micro%20Extras%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.0-160000.33.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-obs-build":"6.12.0-160000.33.1","kernel-syms":"6.12.0-160000.33.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21834-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Micro Extras 6.2","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Micro%20Extras%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.0-160000.33.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-obs-build":"6.12.0-160000.33.1","kernel-syms":"6.12.0-160000.33.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21834-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621834-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241259"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248754"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249104"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250951"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255160"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255360"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255459"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256867"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258854"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258856"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258961"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259186"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259461"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259535"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259806"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259868"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259869"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259871"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259889"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259994"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260018"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260468"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260483"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260523"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260526"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260528"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260530"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260532"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260533"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260536"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260537"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260538"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260541"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260549"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260551"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260552"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260566"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260571"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260573"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260580"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260613"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260728"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260800"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260801"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260807"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260811"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260996"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261020"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261295"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261348"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261503"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261550"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261582"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261585"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261592"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261601"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261602"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261632"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261635"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261636"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261637"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261641"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261645"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261648"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261685"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261694"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261702"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261713"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261714"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261738"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261768"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261778"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261779"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261780"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261781"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261786"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261789"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261797"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261896"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262019"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262055"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262061"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262063"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262074"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262078"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262086"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262087"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262099"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262101"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262179"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262181"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262245"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262480"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262601"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262616"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262627"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262662"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262665"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262671"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262709"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262725"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262758"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263018"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263064"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263074"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263077"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263095"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263104"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263131"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263135"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263138"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263140"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263141"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263556"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263582"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263592"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263596"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263604"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263815"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263931"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264014"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264183"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264233"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264469"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264586"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264674"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264837"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265116"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265308"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265456"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265626"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265846"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-14027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-40181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-40219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68265"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71302"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23168"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23237"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23245"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23246"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23260"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23261"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23264"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23273"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23279"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23290"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23298"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23300"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23307"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23321"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23336"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23339"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23367"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23370"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23387"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23397"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23417"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23418"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23426"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23436"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23440"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23445"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23452"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23460"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23474"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31389"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31394"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31400"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31415"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31417"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31421"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31424"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31426"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31427"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31428"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31435"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31505"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31515"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31547"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31550"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31554"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31565"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31579"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31644"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31658"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31666"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31682"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31738"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43153"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43265"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46333"}]}