• Accepted linux-signed-i386 6.1.123+1 (source) into proposed-updates (1/

    From Debian FTP Masters@21:1/5 to All on Sat Jan 4 18:50:02 2025
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Thu, 02 Jan 2025 14:31:22 +0100
    Source: linux-signed-i386
    Architecture: source
    Version: 6.1.123+1
    Distribution: bookworm-proposed-updates
    Urgency: medium
    Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
    Changed-By: Salvatore Bonaccorso <carnil@debian.org>
    Changes:
    linux-signed-i386 (6.1.123+1) bookworm; urgency=medium
    .
    * Sign kernel from linux 6.1.123-1
    .
    * New upstream stable update:
    https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.120
    - [x86] ASoC: Intel: bytcr_rt5640: Add support for non ACPI instantiated
    codec
    - [x86] ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10
    tablet
    - [x86] ASoC: Intel: sst: Support LPE0F28 ACPI HID
    - wifi: iwlwifi: mvm: Use the sync timepoint API in suspend
    - mac80211: fix user-power when emulating chanctx
    - usb: add support for new USB device ID 0x17EF:0x3098 for the r8152 driver
    - ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
    - bpf: fix filed access without lock
    - net: usb: qmi_wwan: add Quectel RG650V
    - soc: qcom: Add check devm_kasprintf() returned value
    - regulator: rk808: Add apply_bit for BUCK3 on RK809
    - [x86] platform/x86: dell-smbios-base: Extends support to Alienware
    products
    - [x86] platform/x86: dell-wmi-base: Handle META key Lock/Unlock events
    - tools/lib/thermal: Remove the thermal.h soft link when doing make clean
    - can: j1939: fix error in J1939 documentation.
    - [x86] platform/x86: thinkpad_acpi: Fix for ThinkPad's with ECFW showing
    incorrect fan speed
    - [x86] ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad E14
    Gen 6
    - [armhf] ASoC: stm: Prevent potential division by zero in
    stm32_sai_mclk_round_rate()
    - [armhf] ASoC: stm: Prevent potential division by zero in
    stm32_sai_get_clk_div()
    - drm: panel-orientation-quirks: Make Lenovo Yoga Tab 3 X90F DMI match less
    strict
    - proc/softirqs: replace seq_printf with seq_put_decimal_ull_width
    - ASoC: audio-graph-card2: Purge absent supplies for device tree nodes
    - ALSA: usb-audio: Fix Yamaha P-125 Quirk Entry
    - [armel,armhf] 9420/1: smp: Fix SMP for xip kernels
    - ipmr: Fix access to mfc_cache_list without lock held
    - closures: Change BUG_ON() to WARN_ON() (CVE-2024-42252)
    - net: fix crash when config small gso_max_size/gso_ipv4_max_size
    (CVE-2024-50258)
    - serial: sc16is7xx: fix invalid FIFO access with special register set
    (CVE-2024-44950)
    - cifs: Fix buffer overflow when parsing NFS reparse points (CVE-2024-49996)
    - fpga: bridge: add owner module and take its refcount (CVE-2024-36479)
    - fpga: manager: add owner module and take its refcount (CVE-2024-37021)
    - drm/amd/display: Add NULL check for function pointer in
    dcn32_set_output_transfer_func (CVE-2024-49909)
    - drm/amd/display: Check null-initialized variables (CVE-2024-49898)
    - Bluetooth: hci_sync: Add helper functions to manipulate cmd_sync queue
    - Bluetooth: MGMT: Fix possible crash on mgmt_index_removed (CVE-2024-49951)
    - fbdev: efifb: Register sysfs groups through driver core (CVE-2024-49925)
    - mptcp: fix possible integer overflow in mptcp_reset_tout_timer
    - wifi: rtw89: avoid to add interface to list twice when SER
    (CVE-2024-49939)
    - drm/amd/display: Initialize denominators' default to 1 (CVE-2024-49899)
    - fs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name
    - [x86] barrier: Do not serialize MSR accesses on AMD
    - [s390x] cio: Do not unregister the subchannel based on DNV
    - brd: defer automatic disk creation until module initialization succeeds
    - ext4: make 'abort' mount option handling standard
    - ext4: avoid remount errors with 'abort' mount option
    - [mips*] asm: fix warning when disabling MIPS_FP_SUPPORT
    - initramfs: avoid filename buffer overrun (CVE-2024-53142)
    - nvme-pci: fix freeing of the HMB descriptor table
    - [arm64] acpi/arm64: Adjust error handling procedure in
    gtdt_parse_timer_block()
    - cachefiles: Fix missing pos updates in cachefiles_ondemand_fd_write_iter()
    - netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING
    - block: fix bio_split_rw_at to take zone_write_granularity into account
    - [s390x] syscalls: Avoid creation of arch/arch/ directory
    - hfsplus: don't query the device logical block size multiple times
    - nvme-pci: reverse request order in nvme_queue_rqs
    - virtio_blk: reverse request order in virtio_queue_rqs
    - crypto: caam - Fix the pointer passed to caam_qi_shutdown()
    - firmware: google: Unregister driver_info on failure
    - EDAC/bluefield: Fix potential integer overflow
    - [x86] crypto: qat - remove faulty arbiter config reset
    - thermal: core: Initialize thermal zones before registering them
    - EDAC/fsl_ddr: Fix bad bit shift operations
    - crypto: pcrypt - Call crypto layer directly when padata_do_parallel()
    return -EBUSY
    - crypto: cavium - Fix the if condition to exit loop after timeout
    - crypto: hisilicon/qm - disable same error report before resetting
    - EDAC/igen6: Avoid segmentation fault on module unload
    - crypto: inside-secure - Fix the return value of
    safexcel_xcbcmac_cra_init()
    - doc: rcu: update printed dynticks counter bits
    - hwmon: (nct6775-core) Fix overflows seen when writing limit attributes
    - ACPI: CPPC: Fix _CPC register setting issue
    - crypto: caam - add error check to caam_rsa_set_priv_key_form
    - crypto: bcm - add error check in the ahash_hmac_init function
    - crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()
    - tools/lib/thermal: Make more generic the command encoding function
    - thermal/lib: Fix memory leak on error in thermal_genl_auto()
    - time: Fix references to _msecs_to_jiffies() handling of values
    - seqlock/latch: Provide raw_read_seqcount_latch_retry()
    - clocksource/drivers:sp804: Make user selectable
    - clocksource/drivers/timer-ti-dm: Fix child node refcount handling
    - spi: spi-fsl-lpspi: downgrade log level for pio mode
    - spi: spi-fsl-lpspi: Use IRQF_NO_AUTOEN flag in request_irq()
    - drivers: soc: xilinx: add the missing kfree in xlnx_add_cb_for_suspend()
    - microblaze: Export xmb_manager functions
    - [arm64] dts: mt8195: Fix dtbs_check error for infracfg_ao node
    - soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
    - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
    - mmc: mmc_spi: drop buggy snprintf()
    - tpm: fix signed/unsigned bug when checking event logs
    - [arm64] dts: mt8183: krane: Fix the address of eeprom at i2c4
    - [arm64] dts: mt8183: kukui: Fix the address of eeprom at i2c4
    - [arm64] dts: mediatek: mt8173-elm-hana: Add vdd-supply to second source
    trackpad
    - Revert "cgroup: Fix memory leak caused by missing cgroup_bpf_offline"
    - cgroup/bpf: only cgroup v2 can be attached by bpf programs
    - [arm64] dts: mt8183: fennel: add i2c2's i2c-scl-internal-delay-ns
    - [arm64] dts: mt8183: burnet: add i2c2's i2c-scl-internal-delay-ns
    - [arm64] dts: mt8183: cozmo: add i2c2's i2c-scl-internal-delay-ns
    - [arm64] dts: mt8183: Damu: add i2c2's i2c-scl-internal-delay-ns
    - pwm: imx27: Workaround of the pwm output bug when decrease the duty cycle
    - [armhf] dts: cubieboard4: Fix DCDC5 regulator constraints
    - pmdomain: ti-sci: Add missing of_node_put() for args.np
    - regmap: irq: Set lockdep class for hierarchical IRQ domains
    - [arm64] dts: mt8183: jacuzzi: Move panel under aux-bus
    - [arm64] dts: mediatek: mt8183-kukui-jacuzzi: Fix DP bridge supply names
    - [arm64] dts: mediatek: mt8183-kukui-jacuzzi: Add supplies for fixed
    regulators
    - [arm64] firmware: arm_scpi: Check the DVFS OPP count returned by the
    firmware
    - venus: venc: add handling for VIDIOC_ENCODER_CMD
    - media: venus: provide ctx queue lock for ioctl synchronization
    - media: atomisp: Add check for rgby_data memory allocation failure
    - [x86] platform/x86: panasonic-laptop: Return errno correctly in show
    callback
    - drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused
    - [arm64,armhf] drm/vc4: hvs: Don't write gamma luts on 2711
    - [arm64,armhf] drm/vc4: hdmi: Avoid hang with debug registers when
    suspended
    - [arm64,armhf] drm/vc4: hvs: Fix dlist debug not resetting the next entry
    pointer
    - [arm64,armhf] drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs
    function
    - [arm64,armhf] drm/vc4: hvs: Correct logic on stopping an HVS channel
    - wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()
    - drm/omap: Fix possible NULL dereference
    - drm/omap: Fix locking in omap_gem_new_dmabuf()
    - wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq()
    - wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
    - [arm64] drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq()
    - [arm64] drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
    - [arm64] drm/v3d: Address race-condition in MMU flush
    - wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss1
    - wifi: ath10k: fix invalid VHT parameters in supported_vht_mcs_rate_nss2
    - dt-bindings: vendor-prefixes: Add NeoFidelity, Inc
    - ASoC: fsl_micfil: fix regmap_write_bits usage
    - ASoC: dt-bindings: mt6359: Update generic node name and dmic-mode
    - drm/bridge: anx7625: Drop EDID cache on bridge power off
    - libbpf: Fix output .symtab byte-order during linking
    - bpf: Fix the xdp_adjust_tail sample prog issue
    - libbpf: fix sym_is_subprog() logic for weak global subprogs
    - libbpf: never interpret subprogs in .text as entry programs
    - netdevsim: copy addresses for both in and out paths
    - drm/bridge: tc358767: Fix link properties discovery
    - wifi: mwifiex: Fix memcpy() field-spanning write warning in
    mwifiex_config_scan()
    - drm: fsl-dcu: enable PIXCLK on LS1021A
    - [arm64,armhf] drm/panfrost: Remove unused id_mask from struct
    panfrost_model
    - [arm64] bpf, arm64: Remove garbage frame for struct_ops trampoline
    - [arm64] drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
    - [arm64] drm/msm/gpu: Add devfreq tuning debugfs
    - [arm64] drm/msm/gpu: Bypass PM QoS constraint for idle clamp
    - [arm64] drm/msm/gpu: Check the status of registration to PM QoS
    - [arm64,armhf] drm/etnaviv: Request pages from DMA32 zone on
    addressing_limited
    - [arm64,armhf] drm/etnaviv: fix power register offset on GC300
    - [arm64,armhf] drm/etnaviv: hold GPU lock across perfmon sampling
    - wifi: wfx: Fix error handling in wfx_core_init()
    - [arm64] drm/msm/dpu: cast crtc_clk calculation to u64 in
    _dpu_core_perf_calc_clk()
    - netfilter: nf_tables: skip transaction if update object is not implemented
    - netfilter: nf_tables: must hold rcu read lock while iterating object type
    list
    - netlink: typographical error in nlmsg_type constants definition
    - bpf, sockmap: Several fixes to bpf_msg_push_data
    - bpf, sockmap: Several fixes to bpf_msg_pop_data
    - bpf, sockmap: Fix sk_msg_reset_curr
    - sock_diag: add module pointer to "struct sock_diag_handler"
    - sock_diag: allow concurrent operations
    - sock_diag: allow concurrent operation in sock_diag_rcv_msg()
    - net: use unrcu_pointer() helper
    - ipv6: release nexthop on device removal
    - net: rfkill: gpio: Add check for clk_enable()
    - ALSA: usx2y: Use snd_card_free_when_closed() at disconnection
    - ALSA: us122l: Use snd_card_free_when_closed() at disconnection
    - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
    - ALSA: 6fire: Release resources at card release
    - Bluetooth: fix use-after-free in device_for_each_child()
    - netpoll: Use rcu_access_pointer() in netpoll_poll_lock
    - wireguard: selftests: load nf_conntrack if not present
    - bpf: fix recursive lock when verdict program return SK_PASS
    - unicode: Fix utf8_load() error path
    - trace/trace_event_perf: remove duplicate samples on the first tracepoint
    event
    - pinctrl: zynqmp: drop excess struct member description
    - [powerpc*] vdso: Flag VDSO64 entry points as functions
    - mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to fix race
    - mfd: da9052-spi: Change read-mask to write-mask
    - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
    - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
    - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
    - cpufreq: loongson2: Unregister platform_driver on failure
    - [powerpc*] fadump: Refactor and prepare fadump_cma_init for late init
    - [powerpc*] fadump: Move fadump_cma_init to setup_arch() after
    initmem_init()
    - memory: renesas-rpc-if: Improve Runtime PM handling
    - memory: renesas-rpc-if: Pass device instead of rpcif to rpcif_*()
    - memory: renesas-rpc-if: Remove Runtime PM wrappers
    - mtd: hyperbus: rpc-if: Convert to platform remove callback returning void
    - mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE
    - mtd: rawnand: atmel: Fix possible memory leak
    - [powerpc*] mm/fault: Fix kfence page fault reporting
    - [powerpc*] pseries: Fix dtl_access_lock to be a rw_semaphore
    - cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw()
    - cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()
    - [arm64] RDMA/hns: Fix an AEQE overflow error caused by untimely update of
    eq_db_ci
    - [arm64] RDMA/hns: Add clear_hem return value to log
    - [arm64] RDMA/hns: Use dev_* printings in hem code instead of ibdev_*
    - [arm64] RDMA/hns: Remove unnecessary QP type checks
    - [arm64] RDMA/hns: Fix cpu stuck caused by printings during reset
    - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey
    - clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset
    - clk: renesas: rzg2l: Fix FOUTPOSTDIV clk
    - clk: imx: lpcg-scu: SW workaround for errata (e10858)
    - clk: imx: fracn-gppll: correct PLL initialization flow
    - clk: imx: fracn-gppll: fix pll power up
    - clk: imx: clk-scu: fix clk enable state save and restore
    - [amd64] iommu/vt-d: Fix checks and print in dmar_fault_dump_ptes()
    - [amd64] iommu/vt-d: Fix checks and print in pgtable_walk()
    - mfd: rt5033: Fix missing regmap_del_irq_chip()
    - fs/proc/kcore.c: fix coccinelle reported ERROR instances
    - scsi: bfa: Fix use-after-free in bfad_im_module_exit()
    - scsi: fusion: Remove unused variable 'rc'
    - scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()
    - scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()
    - [arm64] RDMA/hns: Fix out-of-order issue of requester when setting FENCE
    - [arm64] RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg()
    - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost()
    - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power()
    - ocfs2: fix uninitialized value in ocfs2_file_read_iter()
    - dax: delete a stale directory pmem
    - KVM: PPC: Book3S HV: Stop using vc->dpdes for nested KVM guests
    - KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on pending
    doorbells
    - [powerpc*] sstep: make emulate_vsx_load and emulate_vsx_store static
    - [powerpc*] kexec: Fix return of uninitialized variable
    - fbdev/sh7760fb: Alloc DMA memory from hardware device
    - fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()
    - clk: clk-apple-nco: Add NULL check in applnco_probe
    - dt-bindings: clock: axi-clkgen: include AXI clk
    - clk: clk-axi-clkgen: make sure to enable the AXI bus clock
    - pinctrl: k210: Undef K210_PC_DEFAULT
    - smb: cached directories can be more than root file handle
    - mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb()
    - perf cs-etm: Don't flush when packet_queue fills up
    - PCI: Fix reset_method_store() memory leak
    - perf stat: Close cork_fd when create_perf_stat_counter() failed
    - perf stat: Fix affinity memory leaks on error path
    - f2fs: compress: fix inconsistent update of i_blocks in
    release_compress_blocks and reserve_compress_blocks
    - f2fs: fix to account dirty data in __get_secs_required()
    - perf probe: Fix libdw memory leak
    - perf probe: Correct demangled symbols in C++ program
    - PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads
    - PCI: cpqphp: Fix PCIBIOS_* return value confusion
    - perf ftrace latency: Fix unit on histogram first entry when using
    --use-nsec
    - f2fs: fix the wrong f2fs_bug_on condition in f2fs_do_replace_block
    - f2fs: remove struct segment_allocation default_salloc_ops
    - f2fs: open code allocate_segment_by_default
    - f2fs: remove the unused flush argument to change_curseg
    - f2fs: check curseg->inited before write_sum_page in change_curseg
    - f2fs: fix to avoid use GC_AT when setting gc_mode as GC_URGENT_LOW or
    GC_URGENT_MID
    - f2fs: fix to avoid forcing direct write to use buffered IO on inline_data
    inode
    - perf trace: avoid garbage when not printing a trace event's arguments
    - svcrdma: Address an integer overflow
    - perf trace: Do not lose last events in a race
    - perf trace: Avoid garbage when not printing a syscall's arguments
    - remoteproc: qcom: q6v5: Use _clk_get_optional for aggre2_clk
    - remoteproc: qcom: pas: add minidump_id to SM8350 resources
    - rpmsg: glink: Fix GLINK command prefix
    - rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length
    - remoteproc: qcom_q6v5_mss: Re-order writes to the IMEM region
    - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
    - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
    - sunrpc: simplify two-level sysctl registration for svcrdma_parm_table
    - svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()
    - NFSD: Fix nfsd4_shutdown_copy()
    - hwmon: (tps23861) Fix reporting of negative temperatures
    - vdpa/mlx5: Fix suboptimal range on iotlb iteration
    - vfio/pci: Properly hide first-in-list PCIe extended capability
    - fs_parser: update mount_api doc to match function signature
    - power: supply: core: Remove might_sleep() from power_supply_put()
    - power: supply: bq27xxx: Fix registers of bq27426
    - net: usb: lan78xx: Fix double free issue with interrupt buffer allocation
    - net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device
    - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
    - net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL
    configuration
    - [s390x] iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()
    - net/ipv6: delete temporary address if mngtmpaddr is removed or unmanaged
    - net: mdio-ipq4019: add missing error check
    - marvell: pxa168_eth: fix call balance of pep->clk handling routines
    - net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken
    - spi: atmel-quadspi: Fix register name in verbose logging function
    - net: hsr: fix hsr_init_sk() vs network/transport headers.
    - bnxt_en: Reserve rings after PCIe AER recovery if NIC interface is down
    - Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync
    - crypto: api - Add crypto_tfm_get
    - crypto: api - Add crypto_clone_tfm
    - llc: Improve setsockopt() handling of malformed user input
    - rxrpc: Improve setsockopt() handling of malformed user input
    - tcp: Fix use-after-free of nreq in reqsk_timer_handler().
    - ip6mr: fix tables suspicious RCU usage
    - ipmr: fix tables suspicious RCU usage
    - iio: light: al3010: Fix an error handling path in al3010_probe()
    - usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()
    - usb: yurex: make waiting on yurex_write interruptible
    - USB: chaoskey: fail open after removal
    - USB: chaoskey: Fix possible deadlock chaoskey_list_lock
    - misc: apds990x: Fix missing pm_runtime_disable()
    - counter: stm32-timer-cnt: Add check for clk_enable()
    - counter: ti-ecap-capture: Add check for clk_enable()
    - ALSA: hda/realtek: Update ALC256 depop procedure
    - apparmor: fix 'Do simple duplicate message elimination'
    - [x86] ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry
    - mailbox: mtk-cmdq: Move devm_mbox_controller_register() after
    devm_pm_runtime_enable()
    - fs/ntfs3: Fixed overflow check in mi_enum_attr() (CVE-2024-27407)
    - ntfs3: Add bounds checking to mi_enum_attr() (CVE-2024-50248)
    - scsi: lpfc: Validate hdwq pointers before dereferencing in reset/errata
    paths (CVE-2024-49891)
    - xfs: add bounds checking to xlog_recover_process_data (CVE-2024-41014)
    - xen: Fix the issue of resource not being properly released in
    xenbus_dev_probe()
    - ALSA: usb-audio: Fix out of bounds reads when finding clock sources
    - usb: ehci-spear: fix call balance of sehci clk handling routines
    - media: aspeed: Fix memory overwrite if timing is 1600x900 (CVE-2023-52916)
    - wifi: iwlwifi: mvm: avoid NULL pointer dereference (CVE-2024-49929)
    - drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in
    dcn30_init_hw (CVE-2024-49917)
    - drm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw
    (CVE-2024-49915)
    - drm/amd/display: Add NULL check for function pointer in
    dcn20_set_output_transfer_func (CVE-2024-49911)
    - drm/amd/display: Check phantom_stream before it is used (CVE-2024-49897)
    - rcu-tasks: Fix access non-existent percpu rtpcp variable in
    rcu_tasks_need_gpcb()
    - btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations
    (CVE-2024-35956)
    - [x86] perf/x86/intel: Hide Topdown metrics events if the feature is not
    enumerated
    - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox
    devices
    - Revert "arm64: dts: mediatek: mt8195-cherry: Mark USB 3.0 on xhci1 as
    disabled"
    - [arm64] dts: mediatek: mt8195-cherry: Mark USB 3.0 on xhci1 as disabled
    - mm/slab: decouple ARCH_KMALLOC_MINALIGN from ARCH_DMA_MINALIGN
    - [powerpc*] move the ARCH_DMA_MINALIGN definition to asm/cache.h
    - dma: allow dma_get_cache_alignment() to be overridden by the arch code
    - [x86] ASoC: Intel: sst: Fix used of uninitialized ctx to log an error
    - soc: qcom: socinfo: fix revision check in qcom_socinfo_probe()
    - ext4: supress data-race warnings in ext4_free_inodes_{count,set}()
    - ext4: fix FS_IOC_GETFSMAP handling
    - jfs: xattr: check invalid xattr size more strictly
    - [x86] ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad P14s Gen
    5 21MES00B00
    - ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()
    - [x86] perf/x86/intel/pt: Fix buffer full but size is 0 case
    - crypto: x86/aegis128 - access 32-bit arguments as 32-bit
    - [x86] KVM: x86/mmu: Skip the "try unsync" path iff the old SPTE was a leaf
    SPTE
    - [powerpc*] pseries: Fix KVM guest detection for disabling hardlockup
    detector
    - [arm64] KVM: arm64: vgic-v3: Sanitise guest writes to GICR_INVLPIR
    - [arm64] KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow
    status
    - PCI: Fix use-after-free of slot->bus on hot remove
    - fsnotify: fix sending inotify event with unexpected filename
    - comedi: Flush partial mappings in error case
    - apparmor: test: Fix memory leak for aa_unpack_strdup()
    - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
    - locking/lockdep: Avoid creating new name string literals in
    lockdep_set_subclass()
    - pinctrl: qcom: spmi: fix debugfs drive strength
    - dt-bindings: iio: dac: ad3552r: fix maximum spi speed
    - exfat: fix uninit-value in __exfat_get_dentry_set
    - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
    - usb: xhci: Fix TD invalidation under pending Set TR Dequeue
    - driver core: bus: Fix double free in driver API bus_register()
    (CVE-2024-50055)
    - wifi: rtlwifi: Drastically reduce the attempts to read efuse in case of
    failures
    - wifi: brcmfmac: release 'root' node in all execution paths
    - Revert "usb: gadget: composite: fix OS descriptors w_value logic"
    - serial: sh-sci: Clean sci_ports[0] after at earlycon exit
    - Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon exit"
    - gpio: exar: set value when external pull-up or pull-down is present
    - netfilter: ipset: add missing range check in bitmap_ip_uadt
    (CVE-2024-53141)
    - spi: Fix acpi deferred irq probe
    - mtd: spi-nor: core: replace dummy buswidth from addr to data
    - cpufreq: mediatek-hw: Fix wrong return value in
    mtk_cpufreq_get_cpu_power()
    - platform/chrome: cros_ec_typec: fix missing fwnode reference decrement
    - ubi: wl: Put source PEB into correct list if trying locking LEB failed
    - dt-bindings: serial: rs485: Fix rs485-rts-delay property
    - serial: 8250_fintek: Add support for F81216E
    - serial: 8250: omap: Move pm_runtime_get_sync
    - ublk: fix ublk_ch_mmap() for 64K page size
    - [arm64] tls: Fix context-switching of tpidrro_el0 when kpti is enabled
    - block: fix ordering between checking BLK_MQ_S_STOPPED request adding
    - HID: wacom: Interpret tilt data from Intuos Pro BT as signed values
    - media: wl128x: Fix atomicity violation in fmc_send_cmd()
    - soc: fsl: rcpm: fix missing of_node_put() in copy_ippdexpcr1_setting()
    - media: v4l2-core: v4l2-dv-timings: check cvt/gtf result
    - ALSA: pcm: Add sanity NULL check for the default mmap fault handler
    - ALSA: hda/realtek: Update ALC225 depop procedure
    - ALSA: hda/realtek: Set PCBeep to default value for ALC274
    - ALSA: hda/realtek: Fix Internal Speaker and Mic boost of Infinix Y4 Max
    - ALSA: hda/realtek: Apply quirk for Medion E15433
    - smb3: request handle caching when caching directories
    - usb: musb: Fix hardware lockup on first Rx endpoint request
    - usb: dwc3: gadget: Fix checking for number of TRBs left
    - usb: dwc3: gadget: Fix looping of queued SG entries
    - ublk: fix error code for unsupported command
    - lib: string_helpers: silence snprintf() output truncation warning
    - ipc: fix memleak if msg_init_ns failed in create_ipc_ns
    - NFSD: Prevent a potential integer overflow
    - SUNRPC: make sure cache entry active before cache_show
    - NFSv4.0: Fix a use-after-free problem in the asynchronous open()
    - rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
    - rtc: abx80x: Fix WDT bit position of the status register
    - rtc: check if __rtc_read_time was successful in rtc_timer_do_work()
    - ubi: fastmap: wl: Schedule fm_work if wear-leveling pool is empty
    - ubifs: Correct the total block count by deducting journal reservation
    - ubi: fastmap: Fix duplicate slab cache names while attaching
    - ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit
    - jffs2: fix use of uninitialized variable
    - rtc: rzn1: fix BCD to rtc_time conversion errors
    - block: return unsigned int from bdev_io_min
    - 9p/xen: fix init sequence
    - 9p/xen: fix release of IRQ
    - [arm64] perf/arm-smmuv3: Fix lockdep assert in ->event_init()
    - [arm64] perf/arm-cmn: Ensure port and device id bits are set properly
    - rtc: ab-eoz9: don't fail temperature reads on undervoltage notification
    - modpost: remove incorrect code in do_eisa_entry()
    - nfs: ignore SB_RDONLY when mounting nfs
    - sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
    - xfs: remove unknown compat feature check in superblock write validation
    - quota: flush quota_release_work upon quota writeback
    - btrfs: don't loop for nowait writes when checking for cross references
    - btrfs: add might_sleep() annotations
    - btrfs: add a sanity check for btrfs root in btrfs_search_slot()
    - btrfs: ref-verify: fix use-after-free after invalid ref action
    - [arm64] dts: allwinner: pinephone: Add mount matrix to accelerometer
    - [arm64] dts: freescale: imx8mm-verdin: Fix SD regulator startup delay
    - media: amphion: Set video drvdata before register video device
    - media: imx-jpeg: Set video drvdata before register video device
    - media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime pm enabled
    - [arm64] dts: freescale: imx8mp-verdin: Fix SD regulator startup delay
    - media: i2c: tc358743: Fix crash in the probe error path when using polling
    - media: imx-jpeg: Ensure power suppliers be suspended before detach them
    - media: ts2020: fix null-ptr-deref in ts2020_probe()
    - media: platform: exynos4-is: Fix an OF node reference leak in
    fimc_md_is_isp_available
    - media: amphion: Fix pm_runtime_set_suspended() with runtime pm enabled
    - media: venus: Fix pm_runtime_set_suspended() with runtime pm enabled
    - media: gspca: ov534-ov772x: Fix off-by-one error in set_frame_rate()
    - media: platform: allegro-dvt: Fix possible memory leak in
    allocate_buffers_internal()
    - media: uvcvideo: Stop stream during unregister
    - media: uvcvideo: Require entities to have a non-zero unique ID
    - ovl: Filter invalid inodes with missing lookup function
    - maple_tree: refine mas_store_root() on storing NULL
    - ftrace: Fix regression with module command in stack_trace_filter
    - vmstat: call fold_vm_zone_numa_events() before show per zone NUMA event
    - [arm64,armhf] iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated
    tables
    - leds: lp55xx: Remove redundant test for invalid channel number
    - clk: qcom: gcc-qcs404: fix initial rate of GPLL3
    - ad7780: fix division by zero in ad7780_write_raw()
    - [armel,armhf] 9429/1: ioremap: Sync PGDs for VMALLOC shadow
    - [s390x] entry: Mark IRQ entries to fix stack depot warnings
    - [armel,armhf] 9430/1: entry: Do a dummy read from VMAP shadow
    - [armel,armhf] 9431/1: mm: Pair atomic_set_release() with _read_acquire()
    - ceph: extract entity name from device id
    - util_macros.h: fix/rework find_closest() macros
    - scsi: ufs: exynos: Fix hibern8 notify callbacks
    - i3c: master: svc: Fix pm_runtime_set_suspended() with runtime pm enabled
    - i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()
    - PCI: keystone: Set mode as Root Complex for "ti,keystone-pcie" compatible
    - PCI: keystone: Add link up check to ks_pcie_other_map_bus()
    - fs/proc/kcore.c: Clear ret value in read_kcore_iter after successful
    iov_iter_zero
    - thermal: int3400: Fix reading of current_uuid for active policy
    - ovl: properly handle large files in ovl_security_fileattr
    - dm thin: Add missing destroy_work_on_stack()
    - PCI: rockchip-ep: Fix address translation unit programming
    - nfsd: make sure exp active before svc_export_show
    - nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
    - iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name()
    - iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
    - [powerpc*] Fix stack protector Kconfig test for clang
    - [powerpc*] Adjust adding stack protector flags to KBUILD_CLAGS for clang

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)