• Accepted linux-signed-amd64 6.1.123+1 (source) into proposed-updates (2

    From Debian FTP Masters@21:1/5 to All on Sun Jan 5 13:20:01 2025
    [continued from previous message]

    - btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in
    walk_down_proc()
    - drm/sti: avoid potential dereference of error pointers in
    sti_hqvdp_atomic_check
    - drm/sti: avoid potential dereference of error pointers in
    sti_gdp_atomic_check
    - drm/sti: avoid potential dereference of error pointers
    - [arm64,armhf] drm/etnaviv: flush shader L1 cache after user commandstream
    - drm/amd/pm: update current_socclk and current_uclk in gpu_metrics on smu
    v13.0.7
    - iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
    - watchdog: apple: Actually flush writes after requesting watchdog restart
    - watchdog: mediatek: Make sure system reset gets asserted in
    mtk_wdt_restart()
    - can: gs_usb: remove leading space from goto labels
    - can: gs_usb: gs_usb_probe(): align block comment
    - can: gs_usb: uniformly use "parent" as variable name for struct gs_usb
    - can: gs_usb: add VID/PID for Xylanta SAINT3 product family
    - can: gs_usb: add usb endpoint address detection at driver probe step
    - can: c_can: c_can_handle_bus_err(): update statistics if skb allocation
    fails
    - can: sun4i_can: sun4i_can_err(): call can_change_state() even if cf is
    NULL
    - can: hi311x: hi3110_can_ist(): fix potential use-after-free
    - can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors statistics
    - can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors statistics
    - can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics
    - can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics
    - can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
    - can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics
    - ipvs: fix UB due to uninitialized stack access in ip_vs_protocol_init()
    - netfilter: x_tables: fix LED ID check in led_tg_check()
    - netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level
    - ptp: convert remaining drivers to adjfine interface
    - ptp: Add error handling for adjfine callback in ptp_clock_adjtime
    - net/sched: tbf: correct backlog statistic for GSO packets
    - net: hsr: avoid potential out-of-bound access in fill_frame_info()
    - can: j1939: j1939_session_new(): fix skb reference counting
    - net-timestamp: make sk_tskey more predictable in error path
    - net/ipv6: release expired exception dst cached in socket
    - dccp: Fix memory leak in dccp_feat_change_recv
    - tipc: Fix use-after-free of kernel socket in cleanup_bearer().
    - net/smc: fix LGR and link use-after-free issue
    - net/qed: allow old cards not supporting "num_images" to work
    - ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5
    - ixgbe: downgrade logging of unsupported VF API version to debug
    - igb: Fix potential invalid memory access in igb_init_module()
    - net: sched: fix erspan_opt settings in cls_flower
    - netfilter: ipset: Hold module reference while requesting a module
    - netfilter: nft_set_hash: skip duplicated elements pending gc run
    - ethtool: Fix wrong mod state in case of verbose and no_mask bitset
    - geneve: do not assume mac header is set in geneve_xmit_skb()
    - net/mlx5e: Remove workaround to avoid syndrome for internal port
    - [arm64] KVM: arm64: Change kvm_handle_mmio_return() return polarity
    - [arm64] KVM: arm64: Don't retire aborted MMIO instruction
    - gpio: grgpio: use a helper variable to store the address of ofdev->dev
    - gpio: grgpio: Add NULL check in grgpio_probe
    - serial: amba-pl011: Use port lock wrappers
    - serial: amba-pl011: Fix RX stall when DMA is used
    - usb: dwc3: gadget: Rewrite endpoint allocation flow
    - usb: dwc3: ep0: Don't reset resource alloc flag (including ep0)
    - usb: dwc3: ep0: Don't clear ep0 DWC3_EP_TRANSFER_STARTED
    - [powerpc*] vdso: Skip objtool from running on VDSO files
    - [powerpc*] vdso: Remove unused '-s' flag from ASFLAGS
    - [powerpc*] vdso: Improve linker flags
    - [powerpc*] vdso: Remove an unsupported flag from vgettimeofday-32.o with
    clang
    - [powerpc*] vdso: Include CLANG_FLAGS explicitly in ldflags-y
    - [powerpc*] vdso: Refactor CFLAGS for CVDSO build
    - [powerpc*] vdso: Drop -mstack-protector-guard flags in 32-bit files with
    clang
    - ntp: Remove invalid cast in time offset math
    - driver core: fw_devlink: Improve logs for cycle detection
    - driver core: Add FWLINK_FLAG_IGNORE to completely ignore a fwnode link
    - driver core: fw_devlink: Stop trying to optimize cycle detection logic
    - i3c: Make i3c_master_unregister() return void
    - i3c: master: add enable(disable) hot join in sys entry
    - i3c: master: svc: add hot join support
    - i3c: master: fix kernel-doc check warning
    - i3c: master: support to adjust first broadcast address speed
    - i3c: master: svc: use slow speed for first broadcast address
    - i3c: master: svc: Modify enabled_events bit 7:0 to act as IBI enable
    counter
    - i3c: master: Replace hard code 2 with macro I3C_ADDR_SLOT_STATUS_BITS
    - i3c: master: Extend address status bit to 4 and add
    I3C_ADDR_SLOT_EXT_DESIRED
    - i3c: master: Fix dynamic address leak when 'assigned-address' is present
    - PCI: endpoint: Use a separate lock for protecting epc->pci_epf list
    - PCI: endpoint: Clear secondary (not primary) EPC in pci_epc_remove_epf()
    - device property: Constify device child node APIs
    - device property: Add cleanup.h based fwnode_handle_put() scope based
    cleanup.
    - device property: Introduce device_for_each_child_node_scoped()
    - leds: flash: mt6360: Fix device_for_each_child_node() refcounting in error
    paths
    - drm/bridge: it6505: update usleep_range for RC circuit charge time
    - drm/bridge: it6505: Fix inverted reset polarity
    - xsk: always clear DMA mapping information when unmapping the pool
    - bpftool: Remove asserts from JIT disassembler
    - bpftool: fix potential NULL pointer dereferencing in prog_dump()
    - drm/sti: Add __iomem for mixer_dbg_mxn's parameter
    - tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
    - ALSA: usb-audio: Notify xrun for low-latency mode
    - tools: Override makefile ARCH variable if defined, but empty
    - spi: mpc52xx: Add cancel_work_sync before module remove
    - scsi: scsi_debug: Fix hrtimer support for ndelay
    - [arm64] drm/v3d: Enable Performance Counters before clearing them
    - ocfs2: free inode when ocfs2_get_init_inode() fails
    - scatterlist: fix incorrect func name in kernel-doc
    - iio: magnetometer: yas530: use signed integer type for clamp limits
    - bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie
    - bpf: Remove unnecessary kfree(im_node) in lpm_trie_update_elem
    - bpf: Handle in-place update for full LPM trie correctly
    - bpf: Fix exact match conditions in trie_get_next_key()
    - mm: page_alloc: move mlocked flag clearance into free_pages_prepare()
    (CVE-2024-53105)
    - HID: wacom: fix when get product name maybe null pointer
    - ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read
    - ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write
    - watchdog: rti: of: honor timeout-sec property
    - can: dev: can_set_termination(): allow sleeping GPIOs
    - can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum DS80000789E
    6.
    - tracing: Fix cmp_entries_dup() to respect sort() comparison rules
    - [arm64] Ensure bits ASID[15:8] are masked out when the kernel uses 8-bit
    ASIDs
    - [arm64] ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL
    - ALSA: usb-audio: add mixer mapping for Corsair HS80
    - ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook 430 G8
    - ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360 (NP730QFG)
    - scsi: qla2xxx: Fix abort in bsg timeout
    - scsi: qla2xxx: Fix NVMe and NPIV connect issue
    - scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
    - scsi: qla2xxx: Fix use after free on unload
    - scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt
    - scsi: ufs: core: sysfs: Prevent div by zero
    - scsi: ufs: core: Add missing post notify for power mode change
    - nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry()
    - bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again
    - drm/dp_mst: Fix MST sideband message body length check
    - drm/dp_mst: Verify request type in the corresponding down message reply
    - drm/dp_mst: Fix resetting msg rx state after topology removal
    - drm/amdgpu/hdp5.2: do a posting read when flushing HDP
    - modpost: Add .irqentry.text to OTHER_SECTIONS
    - bpf: fix OOB devmap writes when deleting elements
    - dma-buf: fix dma_fence_array_signaled v4
    - dma-fence: Fix reference leak on fence merge failure path
    - dma-fence: Use kernel's sort for merging fences
    - xsk: fix OOB map writes when deleting elements
    - regmap: detach regmap from dev on regmap_exit
    - mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia Edu Atla 10
    tablet
    - mmc: core: Further prevent card detect during shutdown
    - ocfs2: update seq_file index in ocfs2_dlm_seq_next
    - lib: stackinit: hide never-taken branch from compiler
    - [arm64] iommu/arm-smmu: Defer probe of clients after smmu device bound
    - epoll: annotate racy check
    - [s390x] cpum_sf: Handle CPU hotplug remove during sampling
    - btrfs: avoid unnecessary device path update for the same device
    - btrfs: do not clear read-only when adding sprout device
    - [x86] perf/x86/amd: Warn only on new bits set
    - media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera
    - media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108
    - mmc: core: Add SD card quirk for broken poweroff notification
    - soc: imx8m: Probe the SoC driver as platform driver
    - HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support
    - [arm64,armhf] drm/vc4: hdmi: Avoid log spam for audio start failure
    - [arm64,armhf] drm/vc4: hvs: Set AXI panic modes for the HVS
    - drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
    - drm: panel-orientation-quirks: Add quirk for AYA NEO Founder edition
    - drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK
    - drm/bridge: it6505: Enable module autoloading
    - drm/mcde: Enable module autoloading
    - drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check()
    - drm/display: Fix building with GCC 15
    - r8169: don't apply UDP padding quirk on RTL8126A
    - net: fec_mpc52xx_phy: Use %pa to format resource_size_t
    - net: ethernet: fs_enet: Use %pa to format resource_size_t
    - net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
    - af_packet: avoid erroring out after sock_init_data() in packet_create()
    - Bluetooth: L2CAP: do not leave dangling sk pointer on error in
    l2cap_sock_create()
    - Bluetooth: RFCOMM: avoid leaving dangling sk pointer in
    rfcomm_sock_alloc()
    - net: af_can: do not leave a dangling sk pointer in can_create()
    - net: ieee802154: do not leave a dangling sk pointer in ieee802154_create()
    - net: inet: do not leave a dangling sk pointer in inet_create()
    - net: inet6: do not leave a dangling sk pointer in inet6_create()
    - wifi: ath5k: add PCI ID for SX76X
    - wifi: ath5k: add PCI ID for Arcadyan devices
    - drm/panel: simple: Add Microchip AC69T88A LVDS Display panel
    - net: sfp: change quirks for Alcatel Lucent G-010S-P
    - drm/sched: memset() 'job' in drm_sched_job_init()
    - drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih
    - drm/amdgpu: Dereference the ATCS ACPI buffer
    - drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr
    - dma-debug: fix a possible deadlock on radix_lock
    - jfs: array-index-out-of-bounds fix in dtReadFirst
    - jfs: fix shift-out-of-bounds in dbSplit
    - jfs: fix array-index-out-of-bounds in jfs_readdir
    - jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree
    - drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov
    - ALSA: usb-audio: Make mic volume workarounds globally applicable
    - drm/amdgpu: set the right AMDGPU sg segment limitation
    - wifi: ipw2x00: libipw_rx_any(): fix bad alignment
    - wifi: brcmfmac: Fix oops due to NULL pointer dereference in
    brcmf_sdiod_sglist_rw()
    - dsa: qca8k: Use nested lock to avoid splat
    - Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables
    - Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet
    - ASoC: hdmi-codec: reorder channel allocation list
    - rocker: fix link status detection in rocker_carrier_init()
    - net/neighbor: clear error in case strict check is not set
    - netpoll: Use rcu_access_pointer() in __netpoll_setup
    - pinctrl: freescale: fix COMPILE_TEST error with PINCTRL_IMX_SCU
    - tracing/ftrace: disable preemption in syscall probe
    - tracing: Use atomic64_inc_return() in trace_clock_counter()
    - tools/rtla: fix collision with glibc sched_attr/sched_set_attr
    - scsi: hisi_sas: Add cond_resched() for no forced preemption model
    - scsi: ufs: core: Make DMA mask configuration more flexible
    - leds: class: Protect brightness_show() with led_cdev->led_access mutex
    - scsi: st: Don't modify unknown block number in MTIOCGET
    - scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset
    - pinctrl: qcom-pmic-gpio: add support for PM8937
    - pinctrl: qcom: spmi-mpp: Add PM8937 compatible
    - nvdimm: rectify the illogical code within nd_dax_probe()
    - smb: client: memcpy() with surrounding object base address
    - verification/dot2: Improve dot parser robustness
    - f2fs: fix f2fs_bug_on when uninstalling filesystem call f2fs_evict_inode.
    - i3c: mipi-i3c-hci: Mask ring interrupts before ring stop request
    - PCI: Detect and trust built-in Thunderbolt chips
    - PCI: Add 'reset_subordinate' to reset hierarchy below bridge
    - PCI: Add ACS quirk for Wangxun FF5xxx NICs
    - i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to
    avoid deadlock
    - usb: chipidea: udc: handle USB Error Interrupt if IOC not set
    - iio: light: ltr501: Add LTER0303 to the supported devices
    - [x86] ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad T14s Gen
    6 21M1CTO1WW (Closes: #1087673)
    - [powerpc*] prom_init: Fixup missing powermac #size-cells
    - misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
    - rtc: cmos: avoid taking rtc_lock for extended period of time
    - serial: 8250_dw: Add Sophgo SG2044 quirk
    - io_uring/tctx: work around xa_store() allocation error issue
    - sched/core: Remove the unnecessary need_resched() check in nohz_csd_func()
    - sched/fair: Check idle_cpu() before need_resched() to detect ilb CPU
    turning busy
    - sched/core: Prevent wakeup of ksoftirqd during idle load balance
    - btrfs: fix missing snapshot drew unlock when root is dead during swap
    activation
    - tracing/eprobe: Fix to release eprobe when failed to add dyn_event
    - Revert "unicode: Don't special case ignorable code points"
    - vfio/mlx5: Align the page tracking max message size with the device
    capability
    - udf: Fold udf_getblk() into udf_bread()
    - [arm64] KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
    - [arm64] KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
    - [arm64] KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
    - [x86] KVM: x86/mmu: Ensure that kvm_release_pfn_clean() takes exact pfn
    from kvm_faultin_pfn()
    - jffs2: Prevent rtime decompress memory corruption
    - jffs2: Fix rtime decompressor
    - mm/damon/vaddr: fix issue in damon_va_evenly_split_region()
    - io_uring: wake up optimisations
    - xhci: dbc: Fix STALL transfer event handling
    - mmc: mtk-sd: Fix error handle of probe function
    - drm/amd/display: Check BIOS images before it is used (CVE-2024-46809)
    - ocfs2: Revert "ocfs2: fix the la space leak when unmounting an ocfs2
    volume"
    - Revert "drm/amdgpu: add missing size check in
    amdgpu_debugfs_gprwave_read()"
    - gve: Fixes for napi_poll when budget is 0
    - [arm64] sve: Discard stale CPU state when handling SVE traps
    (CVE-2024-50275)
    - [arm64] smccc: Remove broken support for SMCCCv1.3 SVE discard hint
    - [x86] ASoC: Intel: avs: Fix return status of avs_pcm_hw_constraints_init()
    - mm: call the security_mmap_file() LSM hook in remap_file_pages()
    - bpf: Fix helper writes to read-only maps (CVE-2024-49861)
    - net: Move {l,t,d}stats allocation to core and convert veth & vrf
    - bpf: Fix dev's rx stats for bpf_redirect_peer traffic
    - veth: Use tstats per-CPU traffic counters
    - drm/ttm: Make sure the mapped tt pages are decrypted when needed
    - drm/ttm: Print the memory decryption status just once
    - drm/amdgpu: rework resume handling for display (v2)
    - usb: dwc3: ep0: Don't reset resource alloc flag
    - serial: amba-pl011: fix build regression
    - i3c: master: Remove i3c_dev_disable_ibi_locked(olddev) on device hotjoin
    - i3c: master: svc: fix possible assignment of the same address to two
    devices
    - PM / devfreq: Fix build issues with devfreq disabled
    - [arm64] drm/msm: DEVFREQ_GOV_SIMPLE_ONDEMAND is no longer needed
    - fs/ntfs3: Sequential field availability check in mi_enum_attr()
    - i3c: master: svc: Fix use after free vulnerability in svc_i3c_master
    Driver Due to Race Condition
    - Bluetooth: MGMT: Fix possible deadlocks
    https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.121
    - bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors
    - ksmbd: fix racy issue from session lookup and expire
    - tcp: check space before adding MPTCP SYN options
    - blk-cgroup: Fix UAF in blkcg_unpin_online()
    - ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5
    - usb: host: max3421-hcd: Correctly abort a USB request.
    - ata: sata_highbank: fix OF node reference leak in
    highbank_initialize_phys()
    - usb: dwc2: Fix HCD resume
    - usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature
    - usb: dwc2: Fix HCD port connection race
    - usb: ehci-hcd: fix call balance of clocks handling routines
    - usb: typec: anx7411: fix fwnode_handle reference leak
    - usb: typec: anx7411: fix OF node reference leaks in
    anx7411_typec_switch_probe()
    - usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to
    accessing null pointer
    - usb: dwc3: xilinx: make sure pipe clock is deselected in usb2 only mode
    - [x86] drm/i915: Fix memory leak by correcting cache object name in error
    handler
    - xfs: update btree keys correctly when _insrec splits an inode root block
    - xfs: don't drop errno values when we fail to ficlone the entire range
    - xfs: return from xfs_symlink_verify early on V4 filesystems
    - xfs: fix scrub tracepoints when inode-rooted btrees are involved
    - xfs: only run precommits once per transaction object
    - bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog
    - bpf, sockmap: Fix update element with same
    - smb: client: fix UAF in smb2_reconnect_server() (CVE-2024-35870)
    (Closes: #1088733)
    - exfat: support dynamic allocate bh for exfat_entry_set_cache
    - exfat: fix potential deadlock on __exfat_get_dentry_set (CVE-2024-42315)
    - wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one
    - wifi: mac80211: clean up 'ret' in sta_link_apply_parameters()
    - wifi: mac80211: fix station NSS capability initialization order
    - acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl
    - amdgpu/uvd: get ring reference from rq scheduler
    - batman-adv: Do not send uninitialized TT changes
    - batman-adv: Remove uninitialized data in full table TT response
    - batman-adv: Do not let TT changes list grows indefinitely
    - tipc: fix NULL deref in cleanup_bearer()
    - net/mlx5: DR, prevent potential error pointer dereference
    - ptp: kvm: Use decrypted memory in confidential guest on x86
    - [x86] ptp: kvm: x86: Return EOPNOTSUPP instead of ENODEV from
    kvm_arch_ptp_init()
    - net: lapb: increase LAPB_HEADER_LEN
    - net: defer final 'struct net' free in netns dismantle
    - [arm64] net: mscc: ocelot: fix memory leak on
    ocelot_port_add_txtstamp_skb()
    - [arm64] net: mscc: ocelot: improve handling of TX timestamp for unknown
    skb
    - [arm64] net: mscc: ocelot: ocelot->ts_id_lock and
    ocelot_port->tx_skbs.lock are IRQ-safe
    - [arm64] net: mscc: ocelot: be resilient to loss of PTP packets during
    transmission
    - [arm64] net: mscc: ocelot: perform error cleanup in ocelot_hwstamp_set()
    - [armhf] spi: aspeed: Fix an error handling path in
    aspeed_spi_[read|write]_user()
    - net: sparx5: fix FDMA performance issue
    - net: sparx5: fix the maximum frame length register
    - ACPI: resource: Fix memory resource type union access
    - cxgb4: use port number to set mac addr
    - qca_spi: Fix clock speed for multiple QCA7000
    - qca_spi: Make driver probing reliable
    - ASoC: amd: yc: Fix the wrong return value
    - Documentation: PM: Clarify pm_runtime_resume_and_get() return value
    - net: dsa: felix: fix stuck CPU-injected packets with short taprio windows
    - net/sched: netem: account for backlog updates from child qdisc
    - bonding: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL
    - team: Fix feature propagation of NETIF_F_GSO_ENCAP_ALL
    - ACPICA: events/evxfregn: don't release the ContextMutex that was never
    acquired
    - Bluetooth: iso: Fix recursive locking warning
    - Bluetooth: SCO: Add support for 16 bits transparent voice setting
    - blk-iocost: Avoid using clamp() on inuse in __propagate_weights()
    - bpf: sync_linked_regs() must preserve subreg_def (CVE-2024-53125)
    - tracing/kprobes: Skip symbol counting logic for module symbols in
    create_local_trace_kprobe()
    - xen/netfront: fix crash when removing device (CVE-2024-53240)
    - [x86] make get_cpu_vendor() accessible from Xen code (CVE-2024-53241)
    - [x86] objtool/x86: allow syscall instruction (CVE-2024-53241)
    - [x86] static-call: provide a way to do very early static-call updates
    (CVE-2024-53241)
    - [x86] xen: don't do PV iret hypercall through hypercall page
    (CVE-2024-53241)
    - [x86] xen: add central hypercall functions (CVE-2024-53241)
    - [x86] xen: use new hypercall functions instead of hypercall page
    (CVE-2024-53241)
    - [x86] xen: remove hypercall page (CVE-2024-53241)
    - ALSA: usb-audio: Fix a DMA to stack memory bug
    - [x86] static-call: fix 32-bit build
    https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.122
    - net: sched: fix ordering of qlen adjustment (CVE-2024-53164)
    - PCI/AER: Disable AER service on suspend
    - PCI: Use preserve_config in place of pci_flags
    - PCI: vmd: Create domain symlink before pci_bus_add_devices()
    - usb: cdns3: Add quirk flag to enable suspend residency
    - [x86] ASoC: Intel: sof_sdw: fix jack detection on ADL-N variant RVP
    - [x86] ASoC: Intel: sof_sdw: add quirk for Dell SKU 0B8C
    - PCI: Add ACS quirk for Broadcom BCM5760X NIC
    - [arm64,armhf] usb: dwc2: gadget: Don't write invalid mapped sg entries
    into dma_desc with iommu enabled
    - PCI: Introduce pci_resource_n()
    - [x86] platform/x86: p2sb: Make p2sb_get_devfn() return void
    - [x86] p2sb: Factor out p2sb_read_from_cache()
    - [x86] p2sb: Introduce the global flag p2sb_hidden_by_bios
    - [x86] p2sb: Move P2SB hide and unhide code to p2sb_scan_and_cache()
    - [x86] p2sb: Do not scan and remove the P2SB device when it is unhidden
    - i2c: pnx: Fix timeout in wait functions
    - cxl/region: Fix region creation for greater than x2 switches
    - net/smc: protect link down work from execute after lgr freed
    (CVE-2024-56718)
    - net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll
    - net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal
    msg
    - net/smc: check smcd_v2_ext_offset when receiving proposal msg
    - net/smc: check return value of sock_recvmsg when draining clc data
    - [arm64] net: mscc: ocelot: fix incorrect IFH SRC_PORT field in
    ocelot_ifh_set_basic()
    - ionic: Fix netdev notifier unregister on failure (CVE-2024-56715)
    - ionic: use ee->offset when returning sprom data
    - net: hinic: Fix cleanup in create_rxqs/txqs()
    - net: ethernet: bgmac-platform: fix an OF node reference leak
    - netfilter: ipset: Fix for recursive locking warning
    - net: mdiobus: fix an OF node reference leak
    - [arm64,armhf] mmc: sdhci-tegra: Remove
    SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk
    - [x86] KVM: x86: Cache CPUID.0xD XSTATE offsets+sizes during module init
    - i2c: riic: Always round-up when calculating bus period
    - efivarfs: Fix error on non-existent file
    - USB: serial: option: add TCL IK512 MBIM & ECM
    - USB: serial: option: add MeiG Smart SLM770A
    - USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
    - USB: serial: option: add MediaTek T7XX compositions
    - USB: serial: option: add Telit FE910C04 rmnet compositions
    - [x86] thunderbolt: Improve redrive mode handling
    - drm/modes: Avoid divide by zero harder in drm_mode_vrefresh()
    - drm/panel: novatek-nt35950: fix return value check in nt35950_probe()
    - [x86] i915/guc: Reset engine utilization buffer before registration
    - [x86] i915/guc: Ensure busyness counter increases motonically
    - [x86] i915/guc: Accumulate active runtime on gt reset
    - drm/amdgpu: don't access invalid sched
    - hwmon: (tmp513) Don't use "proxy" headers
    - hwmon: (tmp513) Simplify with dev_err_probe()
    - hwmon: (tmp513) Use SI constants from units.h
    - hwmon: (tmp513) Fix interpretation of values of Shunt Voltage and Limit
    Registers
    - hwmon: (tmp513) Fix Current Register value interpretation
    - hwmon: (tmp513) Fix interpretation of values of Temperature Result and
    Limit Registers
    - zram: refuse to use zero sized block device as backing device
    - zram: fix uninitialized ZRAM not releasing backing device
    - btrfs: tree-checker: reject inline extent items with 0 ref count
    - Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
    - [x86] KVM: x86: Play nice with protected guests in
    complete_hypercall_exit()
    - tracing: Fix test_event_printk() to process entire print argument
    - tracing: Add missing helper functions in event pointer dereference check
    - tracing: Add "%s" check in test_event_printk()
    - io_uring: Fix registered ring file refcount leak
    - io_uring: check if iowq is killed before queuing (CVE-2024-56709)
    - NFS/pnfs: Fix a live lock between recalled layouts and layoutget
    - of/irq: Fix interrupt-map cell length check in of_irq_parse_imap_parent()
    - of/irq: Fix using uninitialized variable @addr_len in API
    of_irq_parse_one()
    - nilfs2: fix buffer head leaks in calls to truncate_inode_pages()
    - nilfs2: prevent use of deleted inode
    - of: Fix error path in of_parse_phandle_with_args_map()
    - of: Fix refcount leakage for OF node returned by __of_get_dma_parent()
    - ceph: validate snapdirname option length when mounting
    - udf: Fix directory iteration for longer tail extents (Closes: #1089698)
    - epoll: Add synchronous wakeup support for ep_poll_callback
    - io_uring/rw: split io_read() into a helper
    - io_uring/rw: treat -EOPNOTSUPP for IOCB_NOWAIT like -EAGAIN
    - io_uring/rw: avoid punting to io-wq directly
    - drm/amdgpu: Handle NULL bo->tbo.resource (again) in amdgpu_vm_bo_update
    https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.123
    - media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg
    - mm/vmstat: fix a W=1 clang compiler warning
    - tcp_bpf: Charge receive socket buffer in bpf_tcp_ingress()
    - tcp_bpf: Add sk_rmem_alloc related logic for tcp_bpf ingress redirection
    - bpf: Check negative offsets in __bpf_skb_min_len()
    - nfsd: restore callback functionality for NFSv4.0
    - mtd: diskonchip: Cast an operand to prevent potential overflow
    - [arm64] phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP
    - phy: core: Fix an OF node refcount leakage in _of_phy_get()
    - phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup()
    - phy: core: Fix that API devm_phy_put() fails to release the phy
    - phy: core: Fix that API devm_of_phy_provider_unregister() fails to
    unregister the phy provider
    - phy: core: Fix that API devm_phy_destroy() fails to destroy the phy
    - phy: usb: Toggle the PHY power during init
    - [arm64] phy: rockchip: naneng-combphy: fix phy reset
    - [arm*] dmaengine: mv_xor: fix child node refcount handling in early exit
    - [x86] dmaengine: dw: Select only supported masters for ACPI devices
    - [powerpc*] pseries/vas: Add close() callback in vas_vm_ops struct
    - stddef: make __struct_group() UAPI C++-friendly
    - tracing/kprobe: Make trace_kprobe's module callback called after
    jump_label update
    - watchdog: it87_wdt: add PWRGD enable quirk for Qotom QCML04
    - scsi: qla1280: Fix hw revision numbering for ISP1020/1040
    - scsi: megaraid_sas: Fix for a potential deadlock
    - ALSA: hda/conexant: fix Z60MR100 startup pop issue
    - smb: server: Fix building with GCC 15
    - regmap: Use correct format specifier for logging range errors
    - [x86] platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
    - scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set during driver
    load time
    - scsi: storvsc: Do not flag MAINTENANCE_IN return of
    SRB_STATUS_DATA_OVERRUN as an error
    - drm/dp_mst: Ensure mst_primary pointer is valid in
    drm_dp_mst_handle_up_req()
    - virtio-blk: don't keep queue frozen during system suspend
    - blk-mq: register cpuhp callback after hctx is added to xarray table
    - vmalloc: fix accounting with i915
    - [mips*] mipsregs: Set proper ISA level for virt extensions
    - net/mlx5e: Don't call cleanup on profile rollback failure (CVE-2024-50146)
    - bpf: Check validity of link->type in bpf_link_show_fdinfo()
    (CVE-2024-53099)
    - ALSA: hda/realtek: fix mute/micmute LEDs don't work for EliteBook X G1i
    - ALSA: hda/realtek: fix micmute LEDs don't work on HP Laptops
    - pmdomain: core: Add missing put_device()
    - sched/core: Report correct state for TASK_IDLE | TASK_FREEZABLE
    - freezer, sched: Report frozen tasks as 'D' instead of 'R'
    - tracing: Constify string literal data member in struct trace_event_call
    - tracing: Prevent bad count for tracing_cpumask_write
    - io_uring/sqpoll: fix sqpoll error handling races
    - i2c: microchip-core: actually use repeated sends
    - i2c: imx: add imx7d compatible string for applying erratum ERR007805
    - i2c: microchip-core: fix "ghost" detections
    - power: supply: gpio-charger: Fix set charge current limits
    - btrfs: avoid monopolizing a core when activating a swap file
    - btrfs: sysfs: fix direct super block member reads

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)