#1136179 Regression: no sound on Lunar Lake laptops due to missing spi-cs42l43 module

Package:
src:linux
Source:
src:linux
Submitter:
Lennart Ackermans
Date:
2026-07-11 11:05:03 UTC
Severity:
normal
Tags:
#1136179#5
Date:
2026-05-10 15:11:35 UTC
From:
To:
Dear Maintainer,

Since updating from 6.19.11 to (I believe) 6.19.12 I have had no audio
on my laptop, Dell Pro 14 PA14250.

Previously the kernel included the module spi-cs42l43. I believe the
cause of the regression is that the module is no longer automatically
selected in the upstream Kconfig:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e920c36f2073d533bdf19ba6ab690432c8173b63

This fix is to set CONFIG_SPI_CS42L43 explicitly.

Diagnostics:

$ aplay -l
aplay: device_list:279: no soundcards found...
$ ls /sys/bus/spi/devices/
$ modprobe spi-cs42l43
modprobe: FATAL: Module spi-cs42l43 not found in directory /lib/modules/7.0.4+deb14-amd64
$ grep CS42L43 /boot/config-7.0.4+deb14-amd64
# CONFIG_PINCTRL_CS42L43 is not set
CONFIG_MFD_CS42L43=m
# CONFIG_MFD_CS42L43_I2C is not set
CONFIG_MFD_CS42L43_SDW=m
CONFIG_SND_SOC_CS42L43=m
CONFIG_SND_SOC_CS42L43_SDW=m
$ dmesg | grep -E 'cs42l43|sof_sdw'
[    5.951190] cs42l43 sdw:0:0:01fa:4243:01: supply vdd-p not found, using dummy regulator
[    5.951231] cs42l43 sdw:0:0:01fa:4243:01: supply vdd-d not found, using dummy regulator
[    5.951236] cs42l43 sdw:0:0:01fa:4243:01: supply vdd-a not found, using dummy regulator
[    5.951243] cs42l43 sdw:0:0:01fa:4243:01: supply vdd-io not found, using dummy regulator
[    5.951248] cs42l43 sdw:0:0:01fa:4243:01: supply vdd-cp not found, using dummy regulator
[    5.954422] cs42l43 sdw:0:0:01fa:4243:01: devid: 0x042a43, rev: 0xa1, otp: 0x03
[    5.992265] cs42l43 sdw:0:0:01fa:4243:01: Slave 6 state check1: UNATTACHED, status was 1
[   16.395497] platform sof_sdw: deferred probe pending: sof_sdw: snd_soc_register_card failed -517
$ lspci -v -s 00:1f.3
00:1f.3 Audio device: Intel Corporation Lunar Lake-M HD Audio Controller (rev 10) (prog-if 80 [HDA compatible with vendor specific extensions])
	Subsystem: Dell Device 0ce4
	Flags: bus master, fast devsel, latency 64, IRQ 194, IOMMU group 19
	Memory at 3015200000 (64-bit, non-prefetchable) [size=512K]
	Memory at 3015000000 (64-bit, non-prefetchable) [size=2M]
	Capabilities: [50] Power Management version 3
	Capabilities: [c0] Vendor Specific Information: Intel <unknown>
	Capabilities: [60] MSI: Enable+ Count=1/1 Maskable- 64bit+
	Kernel driver in use: sof-audio-pci-intel-lnl
	Kernel modules: snd_sof_pci_intel_lnl, snd_hda_intel

#1136179#16
Date:
2026-05-17 12:14:17 UTC
From:
To:
Hello,
dependency on PINCTRL")) was backported to v6.19.12~236 = de7076a98502
and also to v6.12.81~176 = 8b079642413d. Older kernels that are relevant
for Debian are not affected, as the commit that introduced the issue is
only in 6.11-rc1 (i.e. v6.11-rc1~108^2~6^2~75^2 = c073f0757663).

(Though our 6.1 kernel has SND_SOC_INTEL_SOUNDWIRE_SOF_MACH=m but the
two CS42L43 not enabled. I didn't research if these exist there already
and are needed, too. Might be worth a look from someone with that
hardware.)

I created a MR for this at
https://salsa.debian.org/kernel-team/linux/-/merge_requests/1942

Best regards
Uwe

#1136179#23
Date:
2026-05-19 15:05:47 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1136179@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 19 May 2026 16:46:44 +0200
Source: linux
Architecture: source
Version: 7.1~rc4-1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1135359 1136132 1136179
Changes:
 linux (7.1~rc4-1~exp1) experimental; urgency=medium
 .
   * New upstream release candidate.
 .
   [ Salvatore Bonaccorso ]
   * [amd64] Enable INTEL_MEI_LB as module (Closes: #1136132)
 .
   [ Yunseong Kim ]
   * Enable SND_SOC_SDCA_CLASS as modules SND_SOC_SDCA_FDL, SND_SOC_SDCA_HID,
     SND_SOC_SDCA_IRQ as built-in for Panther Lake audio support.
     (Closes: #1135359)
 .
   [ Uwe Kleine-König ]
   * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly
     (Closes: #1136179)
 .
   [ Agathe Porte ]
   * [arm64] Enable PCI M.2 power sequencing driver as module
Checksums-Sha1:
 f05313849ec6c8e5112c0ceb632e1a1a0d15ecbb 183288 linux_7.1~rc4-1~exp1.dsc
 89e979f46aa10e692254e58c84071d503338fd58 161515620 linux_7.1~rc4.orig.tar.xz
 957d075fda52582ff8fc60bd1d69c81fda302e04 1455188 linux_7.1~rc4-1~exp1.debian.tar.xz
 405966abac57434f0e5bd1a1a2c3012c7923b6ea 6899 linux_7.1~rc4-1~exp1_source.buildinfo
Checksums-Sha256:
 a78acfcbe04d82d65a7951c3114092ec8e408c39b9e4199b9386e4d77cc00fda 183288 linux_7.1~rc4-1~exp1.dsc
 deb1a86ab7b6b1edd0e512f0d0424767c807efde7228d3bdce16d3d66b95dc6c 161515620 linux_7.1~rc4.orig.tar.xz
 bf34d4b88546950e1e24f83435d995357cc931c492bafc17fa28ad25fb7d907b 1455188 linux_7.1~rc4-1~exp1.debian.tar.xz
 7f9a50e8ef8f0cf332e253bfc6f5b56fa400067b55bd93137d5d1495e1768949 6899 linux_7.1~rc4-1~exp1_source.buildinfo
Files:
 8fab9c28e640f845e63c8aad144905f5 183288 kernel optional linux_7.1~rc4-1~exp1.dsc
 a292295314faf8c6137556da04727105 161515620 kernel optional linux_7.1~rc4.orig.tar.xz
 d45c47529bce5a5e851bf7f884da7ddd 1455188 kernel optional linux_7.1~rc4-1~exp1.debian.tar.xz
 e9fdc41e9612b1fd35f4ba7f660ae282 6899 kernel optional linux_7.1~rc4-1~exp1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoMeRFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E6IUP/0fBjqv6JtTIAOm+Gc1qu6S02G5dRgau
yRUzfcyLDD2YgVN8svnFoMSGHt+xsaEj6nVtQddpW0FweG6viDlEq7QdX7nIEOK1
EOiv1nGBQp3607dhJAha7qQIr53/M5lAUZ9hsNr0KYC9NPEa9f7kPfBjIMSGguZ5
+/BfkaU+w+ndi5qDRKi6eaCRw26XcVkLyhDwtzo0sJlNpXw6FZMASJ/tyygk9XiB
4jjyh2r+7YBgtB7VaIextpnGiXYyy++c2dSM3+Tsq4oY5LPL6A9pzKEL3PD8gw4O
W2DGxm33dsRIcAxBK4KaBf0w4aSrjvEFKImzLg0R8/fY/kNzL6NI63sPki+BwpYh
e6NiDAITKU/zCAli4jWVJjPhwAquri78btqjDXpuffovYpBksOJyyTGejxlnW0VA
YybZQxHQV5HFEQffJ01bweWGjtSIKMqvk8fdFo2Gru6BNAE8FUcR/L3Ay97QvzaG
nNOx4VdURP4KdzN68HnpJnBLu2OViIPTh/gTiX+qMjnU50sMxeFK/9fS/2MV32jH
vA8Xamo13Nx/TjrDhvVoH7vpScw00Zkr2lUl7w1XEGeS3MbjOGXcRqFI9YSotUOT
Y8Ehub+B4JcTQ9zaKdQislXzV5qBMrPKtv6fYGfuohraJbiULhso+uib9ZFw2d9o
PNp0+KnpEtAR
=2UyC
-----END PGP SIGNATURE-----

#1136179#34
Date:
2026-06-09 22:13:15 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1136179@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 09 Jun 2026 21:49:08 +0200
Source: linux
Architecture: source
Version: 7.0.12-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1136179
Changes:
 linux (7.0.12-1) unstable; urgency=medium
 .
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.11
     - [amd64] iommu/amd: Fix illegal cap/mmio access in IOMMU debugfs
     - [amd64] iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs
     - ksmbd: close durable scavenger races against m_fp_list lookups
     - ata: libata-scsi: improve readability of ata_scsi_qc_issue()
     - ata: libata-scsi: do not use the deferred QC feature for ATA_DEFER_PORT
     - ata: libata-scsi: do not use the deferred QC feature on PMPs with CBS
     - ata: libata-scsi: do not needlessly defer commands when using PMP with FBS
     - sysfs: don't remove existing directory on update failure
     - mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
     - ksmbd: fix null pointer dereference in compare_guid_key()
     - ksmbd: fix null pointer dereference in proc_show_files()
     - ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
     - ksmbd: validate SID in parent security descriptor during ACL inheritance
     - regulator: tps65219: fix irq_data.rdev not being assigned
     - [amd64] x86/mm: Disable broadcast TLB flush when PCID is disabled
     - smb: client: require net admin for CIFS SWN netlink
     - smb: client: protect tc_count increment in
       smb2_find_smb_sess_tcon_unlocked()
     - smb: client: use data_len for SMB2 READ encrypted folioq copy
     - smb/server: promote S_DEL_ON_CLS to S_DEL_PENDING when close
     - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
     - ALSA: ua101: Reject too-short USB descriptors
     - ALSA: pcm: Don't setup bogus iov_iter for silencing
     - ALSA: asihpi: Fix potential OOB array access at reading cache
     - ALSA: scarlett2: Allow flash writes ending at segment boundary
     - ACPI: battery: Fix system wakeup on critical battery status
     - efi: Allocate runtime workqueue before ACPI init
     - spi: amd: Set correct bus number in ACPI probe path
     - io_uring/waitid: clear waitid info before copying it to userspace
     - drivers/base/memory: fix memory block reference leak in poison accounting
     - ipv6: ioam: refresh hdr pointer before ioam6_event()
     - mm/memory: fix spurious warning when unmapping device-private/exclusive
       pages
     - mm: fix __vm_normal_page() to handle missing support for
       pmd_special()/pud_special()
     - mm/memory_hotplug: fix memory block reference leak on remove
     - mm/page_alloc: fix initialization of tags of the huge zero folio with
       init_on_free
     - mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page
     - mm/damon: fix damos_stat tracepoint format for sz_applied
     - net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
     - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
     - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
     - Bluetooth: bnep: Fix UAF read of dev->name
     - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
     - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
     - Bluetooth: hci_qca: Convert timeout from jiffies to ms
     - Bluetooth: MGMT: validate Add Extended Advertising Data length
     - Bluetooth: serialize accept_q access
     - phonet/pep: disable BH around forwarded sk_receive_skb()
     - net: bcmgenet: keep RBUF EEE/PM disabled
     - net: devmem: reject dma-buf bind with non-page-aligned size or SG length
     - net: phy: skip EEE advertisement write when autoneg is disabled
     - net: hsr: defer node table free until after RCU readers
     - net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
     - net: ifb: report ethtool stats over num_tx_queues
     - net: pse-pd: fix sign on -ENOENT check in of_load_pse_pis()
     - netfilter: ip6t_hbh: reject oversized option lists
     - netfilter: nf_queue: hold bridge skb->dev while queued
     - netfilter: ipset: stop hash:* range iteration at end
     - netfilter: nft_inner: Fix IPv6 inner_thoff desync
     - net: ethtool: fix NULL pointer dereference in phy_reply_size
     - net: ethtool: phy: avoid NULL deref when PHY driver is unbound
     - ACPI: driver: Check ACPI_COMPANION() against NULL during probe
     - sched_ext: Fix missing warning in scx_set_task_state() default case
     - sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
     - l2tp: use list_del_rcu in l2tp_session_unhash
     - qed: fix double free in qed_cxt_tables_alloc()
     - ring-buffer: Fix reporting of missed events in iterator
     - ring-buffer: Flush and stop persistent ring buffer on panic
     - wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
     - ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
     - mptcp: pm: fix ADD_ADDR timer infinite retry on option space insufficient
     - vsock/vmci: fix UAF when peer resets connection during handshake
     - vsock/virtio: reset connection on receiving queue overflow
     - ice: fix VF queue configuration with low MTU values
     - wifi: ath11k: clear shared SRNG pointer state on restart
     - wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
     - wifi: iwlwifi: mld: stop TX during firmware restart
     - ipv4: raw: reject IP_HDRINCL packets with ihl < 5
     - ixgbevf: fix use-after-free in VEPA multicast source pruning
     - rbd: eliminate a race in lock_dwork draining on unmap
     - mptcp: do not drop partial packets
     - mptcp: reset rcv wnd on disconnect
     - lsm: hold cred_guard_mutex for lsm_set_self_attr()
     - [arm64] octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
     - [arm64] octeontx2-pf: fix double free in rvu_rep_rsrc_init()
     - igc: fix potential skb leak in igc_fpe_xmit_smd_frame()
     - ice: fix locking around wait_event_interruptible_locked_irq
     - ice: fix setting promisc mode while adding VID filter
     - ice: restore PTP Rx timestamp config after ethtool set-channels
     - wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
     - af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
     - wifi: mac80211: consume only present negotiated TTLM maps
     - [arm64] octeontx2-pf: avoid double free of pool->stack on AQ init failure
     - cifs: Fix busy dentry used after unmounting
     - tracing: Do not call map->ops->elt_free() if elt_alloc() fails
     - ASoC: codecs: pcm512x: fix null-ptr dereference in
       pcm512x_overclock_xxx_put()
     - [arm64] probes: Handle probes on hinted conditional branch instructions
     - [arm64] KVM: arm64: vgic-its: Reject restored DTE with out-of-range
       num_eventid_bits
     - [arm64] KVM: arm64: vgic: Free private_irqs when init fails after
       allocation
     - [amd64] KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h
       (erratum #1235)
     - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_snapshot_set_shmem() when
       OOM
     - [riscv64] kvm: return SBI_ERR_FAILURE for pmu_event_info() when OOM
     - virt: sev-guest: Explicitly leak pages in unknown state
     - [arm64,armhf] i2c: tegra: fix pm_runtime leak on mutex_lock failure
     - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe
     - spi: qup: fix error pointer deref after DMA setup failure
     - [arm64,armhf] phy: exynos5-usbdrd: fix USB 2.0 HS PHY tuning values for
       Exynos7870
     - [arm64] phy: qcom-qmp-ufs: Fix kaanapali PHY PLL lock failure after SM8650
       G4 fix
     - [arm64] phy: qcom: edp: Unify generic DP/eDP swing and pre-emphasis tables
     - [arm64] phy: qcom: edp: Add eDP/DP mode switch support
     - [arm64] phy: qcom: edp: Fix AUX_CFG8 programming for DP mode
     - scsi: isci: Fix use-after-free in device removal path
     - spi: ep93xx: fix error pointer deref after DMA setup failure
     - spi: sprd: fix error pointer deref after DMA setup failure
     - spi: ti-qspi: fix use-after-free after DMA setup failure
     - mm/slub: hold cpus_read_lock around flush_rcu_sheaves_on_cache()
     - RDMA/siw: Reject MPA FPDU length underflow before signed receive math
     - [s390x] cio: Restore GFP_DMA for CHSC allocation
     - [s390x] pai: Disable duplicate read of kernel PAI counter value
     - [s390x] pai: Fix missing PAI counter increments under heavy load
     - fwctl: pds: Validate RPC input size before parsing
     - [loong64] LoongArch: kprobes: Use larch_insn_text_copy() to patch
       instructions
     - [loong64] LoongArch: Remove unused code to avoid build warning
     - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E
     - device property: set fwnode->secondary to NULL in fwnode_init()
     - [amd64] drm/i915/display: Copy color pipeline from plane in the primary
       joiner pipe
     - [arm64] drm/msm: Fix shrinker deadlock
     - drm/v3d: Fix use-after-free of CPU job query arrays on error path
     - drm/v3d: Release indirect CSD GEM reference on CPU job free
     - drm/virtio: use uninterruptible resv lock for plane updates
     - drm/xe/multi_queue: Fix secondary queue error case
     - drm/amdgpu/vpe: Force collaborate sync after TRAP
     - drm/bridge: it66121: acquire reset GPIO in probe
     - drm/bridge: megachips: remove bridge when irq request fails
     - drm/amd/display: Fix integer overflow in bios_get_image()
     - drm/amd/display: Validate GPIO pin LUT table size before iterating
     - drm/amd/display: Validate payload length and link_index in
       dc_process_dmub_aux_transfer_async
     - batman-adv: v: stop OGMv2 on disabled interface
     - batman-adv: tvlv: abort OGM send on tvlv append failure
     - batman-adv: tvlv: reject oversized TVLV packets
     - batman-adv: iv: recover OGM scheduling after forward packet error
     - batman-adv: mcast: fix use-after-free in orig_node RCU release
     - batman-adv: clear current gateway during teardown
     - batman-adv: dat: handle forward allocation error
     - batman-adv: fix fragment reassembly length accounting
     - batman-adv: fix tp_meter counter underflow during shutdown
     - batman-adv: frag: disallow unicast fragment in fragment
     - batman-adv: bla: fix report_work leak on backbone_gw purge
     - batman-adv: bla: avoid double decrement of bla.num_requests
     - batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
     - batman-adv: tp_meter: avoid use of uninit sender vars
     - batman-adv: tp_meter: directly shut down timer on cleanup
     - batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
     - batman-adv: tp_meter: fix race condition in send error reporting
     - batman-adv: tp_meter: avoid role confusion in tp_list
     - batman-adv: tt: fix TOCTOU race for reported vlans
     - batman-adv: tt: reject oversized local TVLV buffers
     - batman-adv: tt: avoid empty VLAN responses
     - batman-adv: tt: fix negative last_changeset_len
     - batman-adv: tt: fix negative tt_buff_len
     - batman-adv: tt: prevent TVLV entry number overflow
     - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock
     - hwmon: (pmbus/adm1266) reject implausible blackbox record_count
     - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
     - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized
       buffer
     - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
     - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in
       get_multiple
     - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe()
     - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe()
     - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO
       accessors
     - [arm64] pinctrl: mediatek: moore: implement gpio_chip::get_direction()
     - [arm64] dts: renesas: r8a78000: Fix SCIF brg_int clocks
     - [arm64] pinctrl: renesas: rzg2l: Fix incorrect PUPD register offset for
       high pins during suspend/resume
     - [arm64] pinctrl: renesas: rzg2l: Fix SMT register cache handling
     - [arm64] pinctrl: meson: amlogic-a4: fix deadlock issue
     - [arm64] pinctrl: qcom: Fix GPIO to PDC wake irq map for qcs615
     - kho: skip KHO for crash kernel
     - mm/memfd_luo: report error when restoring a folio fails mid-loop
     - HID: intel-thc-hid: Intel-quickspi: Fix some error codes
     - HID: uclogic: Fix regression of input name assignment
     - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
     - [arm64] firmware: arm_ffa: Skip free_pages on RX buffer alloc failure
     - [arm64] firmware: arm_ffa: Fix per-vcpu self notifications handling in
       workqueue
     - [arm64] firmware: arm_ffa: Unregister bus notifier on teardown for FF-A
       v1.0
     - [riscv64] errata: Fix bitwise vs logical AND in MIPS errata patching
     - [riscv64] Fix register corruption from uninitialized cregs on error
     - [riscv64] mm: Fixup no5lvl failure when vaddr is invalid
     - [arm64] pinctrl: qcom: Fix wakeirq map by removing disconnected irqs for
       sm8150
     - [arm64] firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies
     - [arm64] firmware: arm_ffa: Keep framework RX release under lock
     - [arm64] firmware: arm_ffa: Validate framework notification message layout
     - [arm64] firmware: arm_ffa: Align RxTx buffer size before mapping
     - [arm64] firmware: arm_ffa: Snapshot notifier callbacks under lock
     - [arm64] firmware: arm_ffa: Fix sched-recv callback partition lookup
     - ALSA: hda: cs35l56: Put ACPI device after setting companion
     - ALSA: hda: cs35l41: Put ACPI device on missing physical node
     - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
     - netfilter: x_tables: allow initial table replace without emitting audit
       log message
     - netfilter: x_tables: allocate hook ops while under mutex
     - netfilter: x_tables: unregister the templates first
     - netfilter: x_tables: add and use xt_unregister_table_pre_exit
     - netfilter: x_tables: add and use xtables_unregister_table_exit
     - netfilter: ebtables: move to two-stage removal scheme
     - netfilter: ebtables: close dangling table module init race
     - netfilter: x_tables: close dangling table module init race
     - netfilter: bridge: eb_tables: close module init race
     - netfilter: nf_conntrack_expect: restore helper propagation via expectation
     - kprobes: skip non-symbol addresses in kprobe_add_ksym_blacklist()
     - tcp: Fix imbalanced icsk_accept_queue count.
     - net: napi: Avoid gro timer misfiring at end of busypoll
     - net: shaper: Reject reparenting of existing nodes
     - idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
     - ice: fix setting RSS VSI hash for E830
     - ice: fix locking in ice_dcb_rebuild()
     - ice: dpll: fix rclk pin state get for E810
     - ice: dpll: fix misplaced header macros
     - net: lan966x: avoid unregistering netdev on register failure
     - net: ti: icssm-prueth: fix eth_ports_node leak in probe
     - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register
       access
     - phy: spacemit: Remove incorrect clk_disable() in spacemit_usb2phy_init()
     - NFSD: Fix infinite loop in layout state revocation
     - ASoC: sdw_utils: Add quirk to ignore RT712 CODEC_MIC
     - ASoC: sdw_utils: Add quirk to ignore RT721 CODEC_MIC
     - fprobe: Fix unregister_fprobe() to wait for RCU grace period
     - fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
     - fs: Fix return in jfs_mkdir and orangefs_mkdir
     - irqchip/ath79-cpu: Remove unused function
     - fs: fix forced iversion increment on lazytime timestamp updates
     - ublk: reject max_sectors smaller than PAGE_SECTORS in parameter validation
     - nsfs: fix wrong error code returned for pidns ioctls
     - irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
     - nvme: fix bio leak on mapping failure
     - nvme-pci: fix use-after-free in nvme_free_host_mem()
     - zonefs: handle integer overflow in zonefs_fname_to_fno
     - tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().
     - [amd64] ASoC: SOF: amd: Fix error code handling in psp_send_cmd()
     - [powerpc*] 82xx: fix uninitialized pointers with free attribute
     - [powerpc*] fix dead default for GUEST_STATE_BUFFER_TEST
     - [powerpc*] hv-gpci: fix preempt count leak in sysfs show paths
     - netfs: Fix cancellation of a DIO and single read subrequests
     - netfs: Fix missing locking around retry adding new subreqs
     - netfs: Fix missing barriers when accessing stream->subrequests locklessly
     - netfs: Fix netfs_read_to_pagecache() to pause on subreq failure
     - netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
     - netfs: Fix zeropoint update where i_size > remote_i_size
     - netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call
     - netfs: Fix overrun check in netfs_extract_user_iter()
     - netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone
     - netfs: Defer the emission of trace_netfs_folio()
     - netfs: Fix streaming write being overwritten
     - netfs: Fix potential deadlock in write-through mode
     - netfs: Fix read-gaps to remove netfs_folio from filled folio
     - netfs: Fix write streaming disablement if fd open O_RDWR
     - netfs: Fix early put of sink folio in netfs_read_gaps()
     - netfs: Fix leak of request in netfs_write_begin() error handling
     - netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
     - netfs: Fix partial invalidation of streaming-write folio
     - netfs: Fix folio->private handling in netfs_perform_write()
     - netfs: Fix netfs_read_folio() to wait on writeback
     - netfs, afs: Fix write skipping in dir/link writepages
     - afs: Fix the locking used by afs_get_link()
     - net: ethernet: cortina: Make RX SKB per-port
     - net: ethernet: cortina: Drop half-assembled SKB
     - net: ethernet: cortina: Carry over frag counter
     - net: ethernet: cs89x0: remove stale CONFIG_MACH_MX31ADS reference
     - wifi: ath11k: fix error path leaks in some WMI WOW calls
     - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
     - wifi: ath10k: skip WMI and beacon transmission when device is wedged
     - net: shaper: flip the polarity of the valid flag
     - net: shaper: fix trivial ordering issue in net_shaper_commit()
     - net: shaper: reject duplicate leaves in GROUP request
     - net: shaper: set ret to -ENOMEM when genlmsg_new() fails in group_doit
     - net: shaper: fix undersized reply skb allocation in GROUP command
     - net: shaper: enforce singleton NETDEV scope with id 0
     - net: shaper: reject QUEUE scope handle with missing id
     - block: don't overwrite bip_vcnt in bio_integrity_copy_user()
     - block: recompute nr_integrity_segments in blk_insert_cloned_request
     - HID: quirks: really enable the intended work around for appledisplay
     - block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
     - accel/qaic: Add overflow check to remap_pfn_range during mmap
     - net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
     - ethtool: fix ethnl_bitmap32_not_zero() bit interval semantics
     - [arm64] drm/msm/dpu: fix UV scanlines calculation for YUV UBWC formats
     - [arm64] drm/msm/dpu: Fix Kaanapali CWB register configuration
     - [arm64] drm/msm/dsi: don't dump registers past the mapped region
     - [arm64] drm/msm/dpu: don't mix devm and drmm functions
     - block: rename struct gendisk zone_wplugs_lock field
     - block: allow submitting all zone writes from a single context
     - block: fix handling of dead zone write plugs
     - [amd64] x86/mce: Restore MCA polling interval halving
     - Documentation: intel_pstate: Fix description of asymmetric packing with
       SMT
     - [arm64] drm/msm: Fix GMEM_BASE for A650
     - [arm64] drm/msm/a6xx: Add soft fuse detection support
     - [arm64] drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
     - [arm64] drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx
     - [arm64] drm/msm/a6xx: Restore sysprof_active
     - [arm64] drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
     - [arm64] drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table
     - [amd64] ASoC: intel: sof_sdw: Prepare for configuration without a jack
     - [amd64] ASoC: sdw_utils: cs42l43: allow spk component names to be combined
     - [amd64] ASoC: sdw_utils: Check speaker component string allocation
     - [riscv64] Docs: fix unmatched quote warning
     - [powerpc*] time: Remove redundant preempt_disable|enable() calls from
       arch_irq_work_raise()
     - net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
     - net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
     - net: tls: prevent chain-after-chain in plain text SG
     - net: phy: DP83TC811: add reading of abilities
     - ovpn: tcp - use cached peer pointer in ovpn_tcp_close()
     - ovpn: respect peer refcount in CMD_NEW_PEER error path
     - ovpn: fix race between deleting interface and adding new peer
     - cifs: client: stage smb3_reconfigure() updates and restore ctx on failure
     - phy: apple: atc: Fix typec switch/mux leak on unbind
     - gcc-plugins: Always define CONST_CAST_GIMPLE and CONST_CAST_TREE
     - [amd64] x86/xen: Fix xen_e820_swap_entry_with_ram()
     - vfio/pci: Check BAR resources before exporting a DMABUF
     - ovpn: disable BHs when updating device stats
     - tls: Preserve sk_err across recvmsg() when data has been copied
     - net/mlx5: Do not restore destination-less TC rules
     - net/mlx5: Skip disabled vports when setting max TX speed
     - scsi: sd: Fix return code handling in sd_spinup_disk()
     - ASoC: codecs: fs210x: fix possible buffer overflow
     - iommupt: Directly call iommupt's unmap_range()
     - iommupt: Avoid rewalking during map
     - iommu: Fix loss of errno on map failure for classic ops
     - iommu: Fix up map/unmap debugging for iommupt domains
     - iommu: Handle unmap error when iommu_debug is enabled
     - iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap
     - iommupt: Fix the end_index calculation in __map_range_leaf()
     - ALSA: scarlett2: Add missing error check when initialise Autogain Status
     - ALSA: hda/ca0132: Disable auto-detect on manual output select
     - cachefiles: Fix error return when vfs_mkdir() fails
     - io_uring/net: punt IORING_OP_BIND async if it needs file create
     - vsock/virtio: fix zerocopy completion for multi-skb sends
     - btrfs: check for subvolume before deleting squota qgroup
     - btrfs: fix squota accounting during enable generation
     - [amd64] ASoC: amd: acp-sdw-legacy: check CPU DAI name before logging
     - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache()
     - netfilter: nft_inner: release local_lock before re-enabling softirqs
     - ALSA: hda/realtek: Use ALC287_FIXUP_TXNW2781_I2C for ASUS Strix Gxx5
     - drm/msm/snapshot: fix dumping of the unaligned regions
     - hwmon: (lm90) Stop work before releasing hwmon device
     - hwmon: (lm90) Add lock protection to lm90_alert
     - wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
     - wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
     - dma-mapping: move dma_map_resource() sanity check into debug code
     - drm/gem: Make the GEM LRU lock part of drm_device
     - drm/xe/gsc: Fix double-free of managed BO in error path
     - drm/xe/vf: Fix signature of print functions
     - drm/xe/pf: Fix CFI failure in debugfs access
     - drm/xe: Consolidate workaround entries for Wa_14019988906
     - drm/xe: Consolidate workaround entries for Wa_18033852989
     - drm/xe: Define and use MCR version of COMMON_SLICE_CHICKEN1
     - drm/xe/tuning: Apply windower hardware filtering setting on Xe3 and Xe3p
     - drm/xe: Define and use MCR version of COMMON_SLICE_CHICKEN4
     - wifi: ath11k: fix peer resolution on rx path when peer_id=0
     - wifi: ath12k: fix EHT TX MCS limitation due to wrong 20 MHz-only parsing
     - io_uring: propagate array_index_nospec opcode into req->opcode
     - srcu: Don't queue workqueue handlers to never-online CPUs
     - cgroup/rstat: validate cpu before css_rstat_cpu() access
     - net/mlx5e: xsk: Fix unlocked writing to ICOSQ
     - cifs: Fix undefined variables
     - ice: ptp: serialize E825 PHY timer start with PTP lock
     - ice: ptp: use primary NAC semaphore on E825
     - igc: set tx buffer type for SMD frames
     - [amd64] drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP
     - [arm64] phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing
       config
     - kbuild: pacman-pkg: make "rc" releases adhere to pacman versioning scheme
     - [arm64] net: dsa: mt7530: fix FDB entries not aging out with short timeout
     - [arm64] net: dsa: mt7530: preserve VLAN tags on trapped link-local frames
     - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
     - platform/surface: aggregator_registry: omit battery & AC nodes on Surface
       Laptop 7
     - [amd64] platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL
     - [amd64] platform/x86: hp_accel: Check ACPI_COMPANION() against NULL
     - [amd64] platform/x86: intel-hid: Check ACPI_HANDLE() against NULL
     - [amd64] platform/x86: intel_sar: Check ACPI_HANDLE() against NULL
     - [amd64] platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL
     - [amd64] platform/x86: uniwill-laptop: Properly initialize charging
       threshold
     - [amd64] platform/x86: uniwill-laptop: Accept charging threshold of 0
     - [amd64] platform/x86: uniwill-laptop: Fix behavior of "force" module param
     - [amd64] platform/x86: asus-armoury: fix mini-LED mode get/set on MODE2
       devices
     - ASoC: soc-utils: Add missing va_end in snd_soc_ret()
     - drm/amdgpu: Align amdgpu_gtt_mgr entries to TLB size on Tahiti (v2)
     - drm/amdgpu/vce1: Check that the GPU address is < 128 MiB
     - drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets
     - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port
     - RDMA/rtrs: Fix use-after-free in path file creation cleanup
     - bridge: mcast: Fix a possible use-after-free when removing a bridge port
     - net: phy: honor eee_disabled_modes in phy_support_eee()
     - net: phy: honor eee_disabled_modes in phy_advertise_eee_all()
     - net: airoha: Fix NPU RX DMA descriptor bits
     - pds_core: fix error handling in pdsc_devcmd_wait
     - pds_core: fix debugfs_lookup dentry leak and error handling
     - erofs: fix managed cache race for unaligned extents
     - erofs: harden h_shared_count in erofs_init_inode_xattrs()
     - erofs: fix metabuf leak in inode xattr initialization
     - wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
     - wifi: mac80211: fix MLE defragmentation
     - wifi: mac80211: fix multi-link element inheritance
     - wifi: wilc1000: fix dma_buffer leak on bus acquire failure
     - ALSA: seq: Serialize UMP output teardown with event_input
     - cgroup: rstat: relax NMI guard after switch to try_cmpxchg
     - tracing: Avoid NULL return from hist_field_name() on truncation
     - Bluetooth: hci_sync: Fix not setting mask for
       HCI_EVT_LE_ALL_REMOTE_FEATURES_COMPLETE
     - Bluetooth: btintel_pcie: Fix incorrect MAC access programming
     - Bluetooth: btmtk: fix urb->setup_packet leak in error paths
     - udp: gso: Fix handling checksum in __udp_gso_segment
     - udp: Fix UDP length on last GSO_PARTIAL segment
     - net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
     - net: shaper: annotate the data races
     - net: shaper: rework the VALID marking (again)
     - crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
     - rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
     - net: ag71xx: check error for platform_get_irq
     - bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
     - tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
     - [riscv64] net: stmmac: eswin: fix HSP CSR init ordering after clock enable
     - [riscv64] net: stmmac: eswin: clear TXD and RXD delay registers during
       initialization
     - [riscv64] net: stmmac: eswin: correct RGMII delay granularity to 20 ps
     - [riscv64] net: stmmac: eswin: validate RGMII delay values
     - gpio: cdev: check if uAPI v2 config attributes are correctly zeroed
     - gpio: aggregator: fix a potential use-after-free
     - gpio: aggregator: stop using dev-sync-probe
     - gpio: aggregator: remove the software node when deactivating the
       aggregator
     - gpio: aggregator: lock device when calling device_is_bound()
     - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove()
     - drm/xe/oa: Fix exec_queue leak on width check in stream open
     - ASoC: cs-amp-lib: Fix wrong sizeof() in _cs_amp_set_efi_calibration_data()
     - ASoC: cs-amp-lib: Fix missing dput() after debugfs_lookup()
     - nvme-pci: fix dma_vecs leak on p2p memory
     - nvme-pci: fix dma mapping leak on data setup error
     - [arm64] octeontx2-af: npc: Fix allmulticast skip logic for LBK and SDP VFs
     - net: mana: validate rx_req_idx to prevent out-of-bounds array access
     - tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
     - net: airoha: Disable GDM2 forwarding before configuring GDM2 loopback
     - pds_core: ensure null-termination for firmware version strings
     - net: gro: don't merge zcopy skbs
     - net: enetc: fix missing error code when pf->vf_state allocation fails
     - io_uring/nop: pass all errors to userspace
     - blk-mq: pop cached request if it is usable
     - ksmbd: fix durable reconnect error path file lifetime
     - [loong64] LoongArch: kprobes: Fix handling of fatal unrecoverable
       recursions
     - block: avoid use-after-free in disk_free_zone_resources()
     - Documentation: laptops: Update documentation for uniwill laptops
     - [amd64] platform/x86: uniwill-laptop: Do not enable the charging limit
       even when forced
     - [arm64] drm/msm: Restore second parameter name in purge() and evict()
     - security/keys: fix missed RCU read section on lookup
https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.12
     - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
     - ACPI: button: Fix ACPI GPE handler leak during removal
     - ACPI: button: Enable wakeup GPEs for ACPI buttons at probe time
     - xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
     - net/sched: sch_sfb: Replace direct dequeue call with peek and
       qdisc_dequeue_peeked
     - bcache: fix uninitialized closure object
     - nfc: llcp: Fix use-after-free in llcp_sock_release()
     - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
     - xfrm: Check for underflow in xfrm_state_mtu
     - nfc: nxp-nci: i2c: use rising-edge IRQ on ACPI systems
     - HID: remove duplicate hid_warn_ratelimited definition
     - netfilter: synproxy: refresh tcphdr after skb_ensure_writable
     - netfilter: xt_cpu: prefer raw_smp_processor_id
     - netfilter: ebtables: fix OOB read in compat_mtw_from_user
     - netfilter: nf_tables: fix dst corruption in same register operation
     - tun: free page on short-frame rejection in tun_xdp_one() (CVE-2026-46321)
     - tap: free page on error paths in tap_get_user_xdp() (CVE-2026-46320)
     - tun: free page on build_skb failure in tun_xdp_one() (CVE-2026-46322)
     - vsock: keep poll shutdown state consistent
     - net: netlink: fix sending unassigned nsid after assigned one
     - net: netlink: don't set nsid on local notifications
     - net/smc: Do not re-initialize smc hashtables
     - [s390x] net/iucv: fix locking in .getsockopt
     - scsi: core: Run queues for all non-SDEV_DEL devices from
       scsi_run_host_queues
     - scsi: scsi_debug: Add missing newline in scsi_debug_device_reset()
     - ipv4: free net->ipv4.sysctl_local_reserved_ports after
       unregister_net_sysctl_table()
     - ALSA: hda: cs35l56: Fix system name string leaks
     - ALSA: pcm: oss: Fix setup list UAF on proc write error
     - [amd64] ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors
     - net/mlx5: HWS: Reject unsupported remove-header action
     - net: hsr: fix potential OOB access in supervision frame handling
     - [amd64] accel/ivpu: prevent uninitialized data bug in debugfs
     - gpio: mxc: fix irq_high handling
     - [amd64] drm/i915/aux: use polling when irqs are unavailable
     - net: Avoid checksumming unreadable skb tail on trim
     - ethtool: rss: avoid modifying the RSS context response
     - ethtool: rss: add missing errno on RSS context delete
     - ethtool: rss: fix falsely ignoring indir table updates
     - ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
     - ethtool: rss: fix hkey leak when indir_size is 0
     - ethtool: rss: avoid device context leak on reply-build failure
     - ethtool: module: call ethnl_ops_complete() on module flash errors
     - ethtool: module: avoid leaking a netdev ref on module flash errors
     - ethtool: module: avoid racy updates to dev->ethtool bitfield
     - ethtool: module: check fw_flash_in_progress under rtnl_lock
     - ethtool: module: fix cleanup if socket used for flashing multiple devices
     - ethtool: cmis: require exact CDB reply length
     - ethtool: cmis: fix u16-to-u8 truncation of msleep_pre_rpl
     - ethtool: cmis: validate start_cmd_payload_size from module
     - ethtool: cmis: validate fw->size against start_cmd_payload_size
     - blk-mq: reinsert cached request to the list
     - tunnels: load network headers after skb_cow() in
       iptunnel_pmtud_build_icmp[v6]()
     - vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
     - tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
     - ksmbd: fix FSCTL permission bypass by adding a permission check for
       FSCTL_SET_SPARSE
     - drm/xe: Restore IDLEDLY regiter on engine reset
     - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
     - bonding: refuse to enslave CAN devices
     - bridge: Fix sleep in atomic context in netlink path
     - bridge: Fix sleep in atomic context in sysfs path
     - ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
     - ethtool: tsconfig: fix reply error handling
     - ethtool: linkstate: fix unbalanced ethnl_ops_complete() on PHY lookup
       error
     - ethtool: pse-pd: fix missing ethnl_ops_complete()
     - ethtool: tsconfig: fix missing ethnl_ops_complete()
     - ethtool: tsinfo: fix uninitialized stats on the by-PHC path
     - ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
     - ethtool: strset: fix header attribute index in ethnl_req_get_phydev()
     - ethtool: eeprom: add missing ethnl_ops_begin() / _complete() during
       fallback
     - ethtool: eeprom: add more safeties to EEPROM Netlink fallback
     - ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
     - net/sched: Revert "net/sched: Restrict conditions for adding duplicating
       netems to qdisc tree"
     - net/sched: fix packet loop on netem when duplicate is on
     - net: Introduce skb tc depth field to track packet loops
     - net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop
     - net/sched: act_mirred: Fix blockcast recursion bypass leading to stack
       overflow
     - net/sched: act_mirred: Fix return code in early mirred redirect error
       paths
     - net: hibmcge: disable Relaxed Ordering to fix RX packet corruption
     - net: hibmcge: move dma_rmb() after dma_sync_single_for_cpu() in RX path
     - net/handshake: Use spin_lock_bh for hn_lock
     - nvme-tcp: store negative errno in queue->tls_err
     - net/handshake: Pass negative errno through handshake_complete()
     - net/handshake: hand off the pinned file reference to accept_doit
     - net/handshake: Take a long-lived file reference at submit
     - net/handshake: Drain pending requests at net namespace exit
     - dpll: zl3073x: detect DPLL channel count from chip ID at runtime
     - dpll: zl3073x: add die temperature reporting for supported chips
     - dpll: export __dpll_device_change_ntf() for use under dpll_lock
     - dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work
     - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
     - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
     - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
     - Bluetooth: hci_sync: Reset device counters in hci_dev_close_sync()
     - gpio: adnp: fix flow control regression caused by scoped_guard()
     - gpio: virtuser: Fix uninitialized data bug in
       gpio_virtuser_direction_do_write()
     - [arm64,armhf] gpio: rockchip: convert bank->clk to devm_clk_get_enabled()
     - [arm64,armhf] gpio: rockchip: teardown bugs and resource leaks
     - [amd64,arm64] net: mana: Add NULL guards in teardown path to prevent panic
       on attach failure
     - [amd64,arm64] net: mana: Skip redundant detach on already-detached port
     - sctp: fix race between sctp_wait_for_connect and peeloff
     - net: pcs: pcs-mtk-lynxi: fix bpi-r3 serdes configuration
     - vsock/virtio: bind uarg before filling zerocopy skb
     - ipv6: fix possible infinite loop in rt6_fill_node()
     - ipv6: fix possible infinite loop in fib6_select_path()
     - net: skbuff: fix pskb_carve leaking zcopy pages
     - Revert "ipv6: preserve insertion order for same-scope addresses"
     - [amd64] Revert "x86/fpu: Refine and simplify the magic number check during
       signal return"
     - [amd64] drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD
       register
     - [amd64] drm/i915/psr: Read Intel DPCD workaround register
     - [amd64] drm/i915/psr: Apply Intel DPCD workaround when SDP on prior line
       used
     - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
     - iio: imu: adis16550: fix stack leak in trigger handler
     - iio: pressure: bmp280: fix stack leak in bmp580 trigger handler
     - usb: typec: ucsi: ccg: reject firmware images without a ':' record header
     - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
     - usb: typec: tcpm: bound altmode_desc[] per iteration in
       svdm_consume_modes()
     - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO
     - usb: typec: altmodes/displayport: validate count before reading Status
       Update VDO
     - usb: typec: wcove: don't write past struct pd_message in
       wcove_read_rx_buffer()
     - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
     - usb: typec: ucsi: validate connector number in ucsi_connector_change()
     - USB: serial: safe_serial: fix memory corruption with small endpoint
     - media: rc: igorplugusb: fix control request setup packet
     - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free()
     - USB: serial: cypress_m8: fix memory corruption with small endpoint
     - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse
     - Bluetooth: btusb: Allow firmware re-download when version matches
     - mm/vmalloc: do not trigger BUG() on BH disabled context
     - hpfs: fix a crash if hpfs_map_dnode_bitmap fails
     - mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
     - ipc: limit next_id allocation to the valid ID range
     - mm: memcontrol: propagate NMI slab stats to memcg vmstats
     - mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page
     - memfd: deny writeable mappings when implying SEAL_WRITE
     - zram: fix use-after-free in zram_writeback_endio
     - mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
     - auxdisplay: line-display: fix OOB read on zero-length message_store()
     - smb: client: fix uninitialized variable in smb2_writev_callback
     - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
     - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
     - Bluetooth: HIDP: fix missing length checks in hidp_input_report()
     - Bluetooth: ISO: fix UAF in iso_recv_frame
     - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
     - Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
     - Bluetooth: hci_qca: Use 100 ms SSR delay for rampatch and NVM loading
     - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
     - Input: xpad - fix out-of-bounds access for Share button
     - rust_binder: Avoid holding lock when dropping delivered_death
     - rust_binder: avoid calling pending_oneway_finished() on TF_UPDATE_TXN
     - USB: cdc-acm: Fix bit overlap and move quirk definitions to header
     - [arm64] KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor
     - [arm64] KVM: arm64: PMU: Preserve AArch32 counter low bits
     - [amd64] KVM: SVM: Flush the current TLB when transitioning from xAVIC =>
       x2AVIC
     - [amd64] KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
     - [amd64] KVM: SEV: Ignore Port I/O requests of length '0'
     - [amd64] KVM: SEV: Use the size of the PSC header as the minimum size for
       PSC requests
     - [amd64] KVM: SEV: WARN if KVM attempts to setup scratch area with
       min_len==0
     - [amd64] KVM: SEV: Compute the correct max length of the in-GHCB scratch
       area
     - [amd64] KVM: SEV: Check PSC request indices against the actual size of the
       buffer
     - [amd64] KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC
       buffer
     - [amd64] KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc()
     - gpio: shared: undo the vote of the proxy on GPIO free
     - gpio: shared: fix deadlock on shared proxy's parent removal
     - gpio: shared: fix lockdep false positive by removing unneeded lock
     - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux
     - iio: adc: npcm: fix unbalanced clk_disable_unprepare()
     - iio: dac: ad3530r: Fix AD3531/AD3531R powerdown mode strings
     - iio: dac: max5821: fix return value check in powerdown sync
     - iio: dac: ad5686: fix ref bit initialization for single-channel parts
     - iio: dac: ad5686: fix input raw value check
     - iio: dac: ad5686: acquire lock when doing powerdown control
     - iio: dac: ad5686: fix powerdown control on dual-channel devices
     - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp
     - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw
     - iio: adc: ad4695: Fix call ordering in offload buffer postenable
     - iio: adc: nxp-sar-adc: fix division by zero in write_raw
     - iio: adc: nxp-sar-adc: Avoid division by zero
     - iio: adc: nxp-sar-adc: zero-initialize dma_slave_config
     - iio: gyro: itg3200: fix i2c read into the wrong stack location
     - iio: gyro: adis16260: fix division by zero in write_raw
     - iio: ssp_sensors: cancel delayed work_refresh on remove
     - iio: temperature: tsys01: fix broken PROM checksum validation
     - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL
     - iio: light: veml6070: Fix resource leak in probe error path
     - iio: Fix iio_multiply_value use in iio_read_channel_processed_scale
     - iio: chemical: mhz19b: reject oversized serial replies
     - iio: chemical: scd30: fix division by zero in write_raw
     - iio: light: cm3323: fix reg_conf not being initialized correctly
     - iio: buffer: hw-consumer: fix use-after-free in error path
     - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()
     - USB: serial: omninet: fix memory corruption with small endpoint
     - usb: cdns3: gadget: fix request skipping after clearing halt
     - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy
       acquisition failure
     - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently
       leaks the runtime PM usage counter across bind/unbind cycles
     - usb: dwc2: Fix use after free in debug code
     - Input: elan_i2c - validate firmware size before use
     - i2c: davinci: fix division by zero on missing clock-frequency
     - [amd64] x86/ftrace: Relocate %rip-relative percpu refs in dynamic
       trampolines
     - wireguard: send: append trailer after expanding head
     - bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
     - macsec: fix replay protection at XPN lower-PN wrap
     - ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
     - [arm64] ASoC: qcom: q6asm-dai: fix error handling in prepare and
       set_params
     - [arm64] octeontx2-af: validate body pcifunc in
       rvu_mbox_handler_rep_event_notify
     - ipv6: exthdrs: refresh nh after handling HAO option
     - ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
     - ipv6: validate extension header length before copying to cmsg
     - xfrm: input: hold netns during deferred transport reinjection
     - l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname
     - ip6: vti: Use ip6_tnl.net in vti6_changelink().
     - net: skbuff: fix missing zerocopy reference in pskb_carve helpers
     - spi: spi-mem: avoid mutating op template in spi_mem_supports_op()
     - HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
     - nfc: hci: fix out-of-bounds read in HCP header parsing
     - xfrm: route MIGRATE notifications to caller's netns
     - xfrm: ipcomp: Free destination pages on acomp errors
     - xfrm: ah: use skb_to_full_sk in async output callbacks
     - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417
     - ALSA: firewire-motu: Protect register DSP event queue positions
     - netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without
       direction check
     - [arm64] ASoC: qcom: q6asm-dai: close stream only when running
     - [arm64] ASoC: qcom: q6asm-dai: do not set stream state in event and
       trigger callbacks
     - xfrm: esp: restore combined single-frag length gate
     - ALSA: hda/realtek: Fix speaker output on ASUS ROG Strix G615LP
     - xfrm: iptfs: reset runtime state when cloning SAs
     - dma-buf: fix UAF in dma_buf_fd() tracepoint
     - Input: xpad - add "Nova 2 Lite" from GameSir
     - Input: xpad - add support for ASUS ROG RAIKIRI II
     - ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
     - misc: rp1: Send IACK on IRQ activate to fix kdump/kexec
     - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
     - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490
     - dt-bindings: usb: Fix EIC7700 USB reset's issue
     - counter: Fix refcount leak in counter_alloc() error path
     - tty: serial: pch_uart: add check for dma_alloc_coherent()
     - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
     - uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory
     - usb: chipidea: core: convert ci_role_switch to local variable
     - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval
     - usb: dwc3: xilinx: fix error handling in zynqmp init error paths
     - usb: musb: omap2430: Fix use-after-free in omap2430_probe()
     - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub
       controllers
     - usb: storage: Add quirks for PNY Elite Portable SSD
     - usbip: vudc: Fix use after free bug in vudc_remove due to race condition
     - usb: usbtmc: check URB actual_length for interrupt-IN notifications
     - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize
     - usb: typec: tipd: Fix error code in tps6598x_probe()
     - usb: typec: tcpm: improve handling of DISCOVER_MODES failures
     - usb: typec: ucsi: Check if power role change actually happened before
       handling
     - usb: typec: ucsi: Don't update power_supply on power role change if not
       connected
     - USB: serial: option: add MeiG SRM813Q
     - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL
     - USB: serial: belkin_sa: validate interrupt status length
     - USB: serial: cypress_m8: validate interrupt packet headers
     - USB: serial: digi_acceleport: fix memory corruption with small endpoints
     - USB: serial: keyspan: fix missing indat transfer sanity check
     - USB: serial: mxuport: fix memory corruption with small endpoint
     - USB: serial: mct_u232: fix memory corruption with small endpoint
     - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
     - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
     - usb: gadget: net2280: Fix double free in probe error path
     - usb: gadget: f_hid: fix device reference leak in hidg_alloc()
     - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
     - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports
     - usb: gadget: f_fs: copy only received bytes on short ep0 read
     - usb: gadget: f_fs: serialize DMABUF cancel against request completion
     - [amd64] thunderbolt: property: Reject u32 wrap in
       tb_property_entry_valid()
     - [amd64] thunderbolt: property: Reject dir_len < 4 to prevent size_t
       underflow
     - [amd64] thunderbolt: property: Cap recursion depth in
       __tb_property_parse_dir()
     - scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
     - scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
     - scsi: target: iscsi: Fix CRC overread and double-free in
       iscsit_handle_text_cmd()
     - scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
     - scsi: target: iscsi: Validate CHAP_R length before base64 decode
     - drm/hyperv: validate resolution_count and fix WIN8 fallback
     - drm/hyperv: validate VMBus packet size in receive callback
     - drm/gem: fix race between change_handle and handle_delete
     - [amd64] drm/i915/color: Fix HDR pre-CSC LUT programming loop
     - [amd64] drm/i915/psr: Block DC states on vblank enable when Panel Replay
       supported
     - [amd64] drm/i915/psr: Use DC_OFF wake reference to block DC6 on vblank
       enable
     - [amd64] drm/i915: Fix potential UAF in TTM object purge
     - drm/amd/pm/si: Disregard vblank time when no displays are connected
     - serial: altera_jtaguart: handle uart_add_one_port() failures
     - serial: qcom-geni: fix UART_RX_PAR_EN bit position
     - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion
       IRQ
     - serial: sh-sci: fix memory region release in error path
     - serial: zs: Fix swapped RI/DSR modem line transition counting
     - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma
     - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
     - drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
     - drm/amdkfd: Check for pdd drm file first in CRIU restore path
     - drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO
     - drm/amdgpu: fix calling VM invalidation in amdgpu_hmm_invalidate_gfx
     - drm/amdgpu: fix amdgpu_hmm_range_get_pages
     - drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO
     - serial: dz: Fix bootconsole message clobbering at chip reset
     - serial: dz: Fix bootconsole handover lockup
     - serial: dz: Convert to use a platform device
     - serial: zs: Fix bootconsole handover lockup
     - serial: zs: Switch to using channel reset
     - serial: zs: Convert to use a platform device
     - serial: core: introduce guard(uart_port_lock_check_sysrq_irqsave)
     - serial: 8250: dispatch SysRq character in serial8250_handle_irq()
     - serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq()
     - Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare"
       (CVE-2026-46318)
     - [amd64] platform/x86/intel/vsec: Refactor base_addr handling
     - [amd64] platform/x86/intel/vsec: Make driver_data info const
     - [amd64] platform/x86/intel/vsec: Fix enable_cnt imbalance on PCIe error
       recovery
     - rxrpc: Fix RESPONSE packet verification to extract skb to a linear buffer
     - ALSA: hda/realtek: Fix mute and mic-mute LEDs for HP Envy X360 15-fh0xxx
     - ALSA: hda/realtek: Fix mute and mic-mute LEDs for HP 16 Piston OmniBook X
     - [arm64] tlb: Flush walk cache when unsharing PMD tables
     - [amd64,armhf] i2c: tegra: make tegra_i2c_mutex_unlock() return void
     - hwmon: (pmbus) Add support for guarded PMBus lock
     - hwmon: (pmbus/adm1266) serialize sequencer_state debugfs read with
       pmbus_lock
     - hwmon: (pmbus/adm1266) serialize GPIO PMBus accesses with pmbus_lock
     - net: phy: micrel: fix LAN8814 QSGMII soft reset
     - [arm64,armhf] xhci: tegra: Fix ghost USB device on dual-role port unplug
     - mailbox: Fix NULL message support in mbox_send_message()
     - usb: core: Fix SuperSpeed root hub wMaxPacketSize
     - [arm64] KVM: arm64: vgic-its: Drop the translation cache reference only
       for the erased entry (CVE-2026-46316)
     - [arm64] KVM: arm64: Reassign nested_mmus array behind mmu_lock
       (CVE-2026-46317)
 .
   [ Uwe Kleine-König ]
   * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly
     (Closes: #1136179)
Checksums-Sha1:
 526bef2d592b204d2e3527b70c1ea57654e7133e 196174 linux_7.0.12-1.dsc
 37f0aa242699bd500fb12c597edf9a1369bfe049 160420472 linux_7.0.12.orig.tar.xz
 1719b314827a09c4afa7ad5ef73dde746146651c 1501020 linux_7.0.12-1.debian.tar.xz
 0fe2d82a324cc962c45e4cdbdb3eb6e08da37b35 6868 linux_7.0.12-1_source.buildinfo
Checksums-Sha256:
 660c82edb07c382146a50cbeecd916533d8002b3e29f0a39c7c7a63c4899d9cc 196174 linux_7.0.12-1.dsc
 261d9a82461c6350f8722633fa3df3f64340dd47430ef188653def6ea6ca0bf7 160420472 linux_7.0.12.orig.tar.xz
 21949e9b9dfa368e4d1f092d6ec27f3380d6f80e022a34803c288f7c2b62749a 1501020 linux_7.0.12-1.debian.tar.xz
 4e0c7b10067354ef09708e4cf68715caba948224e5430d06343808c24f8d3fa3 6868 linux_7.0.12-1_source.buildinfo
Files:
 704e9bdc48355495bf8a59447890e521 196174 kernel optional linux_7.0.12-1.dsc
 ce723a58f4c1c7fd68d46cb72b98906f 160420472 kernel optional linux_7.0.12.orig.tar.xz
 d5b259a450faf952ce33f49fe2812fe2 1501020 kernel optional linux_7.0.12-1.debian.tar.xz
 8827664d373d9a71c35a2b3ed6429010 6868 kernel optional linux_7.0.12-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoobqNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E2yEP/3nDDoWSac5TycaEG7cM7Zf0n4axhc77
gmkcRfGD78TGtD5EEGsMBCl932h0xxRQ3dqesa/edgmr8+mzuHOFVppziV+PuQYL
tdmYeQpPpqfBhHPljpoafqcqvNIEDOMClf4EpficDNy9xs0wWs1hitb1E7dzlcOf
DmQs5phXFZZKp+wv/cKvx12giNCiIuUX1nfGpDPxd2mnFpiPEBh8O7s5QfrYOQja
/2eRb0WYfAMIIC4yv3oA3TRvPGzy8ivoVipzPYxbySUCovl51lGKzw08KIzQa7fv
/U1gVxV2Y1iNN/vBe2PA0Ild2Px/YHtdZwmf/4VDopak/5oAFA0jz9twGN+n8tSr
+8yjV2SyXV5kYmih99UNsSt49enszRQNbXJJp+IbVXA1y8Fl3DnPL/fqPXlLpSr2
yQGP8colf5kAtluZFXgMmOERRP+Ivn6fj3VRzXzT/9lSextveDQNtSIpZnvnANRA
AK8Wqa3b/I/tqm7inss82K40gimrFmWquWnXWB+b+YZR3SWplme6UJaTZvfpxLQo
OoWzsF0Ow43IuunD/UZBrLlAazSS5NhyQbUy2dG3TC1akJFl3sMp4TWPocznFhWW
Ei0RB07ThcOP0R5rL8m80gA/6BpPgEivgZTufta2L7sgtGlyrBnT2IZ145pmZpwy
AXuotS8jJBGF
=+M4n
-----END PGP SIGNATURE-----

#1136179#45
Date:
2026-07-11 11:04:02 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1136179@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 04 Jul 2026 20:24:27 +0200
Source: linux
Architecture: source
Version: 6.12.95-1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1136179 1139686
Changes:
 linux (6.12.95-1) trixie-security; urgency=high
 .
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95
     - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory
       domain
     - wifi: mt76: mt7921: fix a potential scan no APs
     - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync
       (CVE-2026-53101)
     - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167)
     - gpiolib: Extract gpiochip_choose_fwnode() for wider use
     - gpiolib: Remove redundant assignment of return variable
     - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key()
       (CVE-2026-31732)
     - io_uring/net: Avoid msghdr on op_connect/op_bind async data
     - drm/xe/display: fix oops in suspend/shutdown without display
       (CVE-2026-53142)
     - [arm64] drm/v3d: Store the active job inside the queue's state
     - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139)
     - eventpoll: use hlist_is_singular_node() in __ep_remove()
     - eventpoll: split __ep_remove()
     - eventpoll: kill __ep_remove()
     - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}()
     - eventpoll: rename ep_remove_safe() back to ep_remove()
     - eventpoll: move epi_fget() up
     - eventpoll: fix ep_remove struct eventpoll / struct file UAF
       (CVE-2026-46242)
     - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355)
     - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216)
     - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex
       options"
     - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
     - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
     - debugobjects: Do not fill_pool() if pi_blocked_on
     - debugobjects: Dont call fill_pool() in early boot hardirq context
     - RDMA/bnxt_re: zero shared page before exposing to userspace
     - i2c: stub: Reject I2C block transfers with invalid length
     - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe()
       (CVE-2026-53325)
     - bpf: Reject sleepable kprobe_multi programs at attach time
       (CVE-2026-43010)
     - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
     - regulator: core: fix locking in regulator_resolve_supply() error path
     - dlm: prevent NPD when writing a positive value to event_done
       (CVE-2025-23131)
     - xfs: remove the expr argument to XFS_TEST_ERROR
     - xfs: fix error returns in CoW fork repair
     - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()"
     - net: bonding: add broadcast_neighbor option for 802.3ad
     - bonding: add support for per-port LACP actor priority
     - bonding: print churn state via netlink
     - bonding: 3ad: implement proper RCU rules for port->aggregator
       (CVE-2026-52975)
     - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419)
     - bonding: fix NULL pointer dereference in actor_port_prio setting
     - staging: rtl8723bs: fix buffer over-read in rtw_update_protection
       (CVE-2026-53179)
     - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
       (CVE-2026-53341)
     - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
     - hv: utils: handle and propagate errors in kvp_register
     - locking/mutex: Remove wakeups from under mutex::wait_lock
     - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
     - phonet: Pass ifindex to fill_addr().
     - phonet: Pass net and ifindex to phonet_address_notify().
     - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157)
     - rxrpc: Fix the ACK parser to extract the SACK table for parsing
       (CVE-2026-53151)
     - fuse: re-lock request before replacing page cache folio
     - ftrace: Update the mcount_loc check of skipped entries
     - ftrace: Have ftrace pages output reflect freed pages
     - ftrace: Do not over-allocate ftrace memory
     - ftrace: Test mcount_loc addr before calling ftrace_call_addr()
     - ftrace: Check against is_kernel_text() instead of kaslr_offset()
     - net: ipv6: Make udp_tunnel6_xmit_skb() void
     - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070)
     - iio: light: veml6075: add bounds check to veml6075_it_ms index
     - iio: adc: ti-ads1298: add bounds check to pga_settings index
     - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent
       vcs_write
     - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
     - ksmbd: reject non-VALID session in compound request branch
     - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
     - virtiofs: fix UAF on submount umount
     - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role
       (CVE-2026-53359)
     - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max
       mapping level
     - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command
       Completion support"
     - [amd64] KVM: SEV: Ignore MMIO requests of length '0'
     - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+
     - [amd64] KVM: SEV: Ignore Port I/O requests of length '0'
     - batman-adv: tp_meter: keep unacked list in ascending ordered
     - batman-adv: tp_meter: initialize dup_acks explicitly
     - batman-adv: tp_meter: initialize dec_cwnd explicitly
     - batman-adv: tp_meter: avoid window underflow
     - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
     - batman-adv: tp_meter: fix fast recovery precondition
     - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
     - batman-adv: tp_meter: add only finished tp_vars to lists
     - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
     - batman-adv: prevent ELP transmission interval underflow
     - batman-adv: tp_meter: initialize last_recv_time during init
     - batman-adv: ensure bcast is writable before modifying TTL
     - batman-adv: fix (m|b)cast csum after decrementing TTL
     - batman-adv: frag: ensure fragment is writable before modifying TTL
     - batman-adv: frag: avoid underflow of TTL
     - batman-adv: v: prevent OGM aggregation on disabled hardif
     - batman-adv: tp_meter: restrict number of unacked list entries
     - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
     - batman-adv: tp_meter: prevent parallel modifications of last_recv
     - batman-adv: tp_meter: handle overlapping packets
     - batman-adv: tt: don't merge change entries with different VIDs
     - batman-adv: tt: track roam count per VID
     - batman-adv: dat: prevent false sharing between VLANs
     - batman-adv: tvlv: enforce 2-byte alignment
     - batman-adv: tvlv: avoid race of cifsnotfound handler state
     - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362)
     - fs: constify file ptr in backing_file accessor helpers
     - lsm: add backing_file LSM hooks
     - selinux: fix overlayfs mmap() and mprotect() access checks
     - inet: add indirect call wrapper for getfrag() calls
     - ipv4: account for fraggap on the paged allocation path
     - ntfs3: reject direct userspace writes to reserved $LX* xattrs
     - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb()
     - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free
     - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361)
     - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program
     - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g
     - mac802154: llsec: add skb_cow_data() before in-place crypto
     - net: skmsg: preserve sg.copy across SG transforms
     - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
     - apparmor: mediate the implicit connect of TCP fast open sendmsg
     - apparmor: fix use-after-free in rawdata dedup loop
     - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share
       BAR
     - fbdev: fix use-after-free in store_modes()
     - kernel/fork: clear PF_BLOCK_TS in copy_process()
     - block: invalidate cached plug timestamp after task switch
     - err.h: use __always_inline on all error pointer helpers
     - KEYS: fix overflow in keyctl_pkey_params_get_2()
     - keys: Pin request_key_auth payload in instantiate paths
     - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
     - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
     - wifi: ath11k: fix warning when unbinding
     - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
     - wifi: rtw88: increase TX report timeout to fix race condition
     - wifi: rtw88: usb: fix memory leaks on USB write failures
     - wifi: iwlwifi: mvm: fix race condition in PTP removal
     - f2fs: validate compress cache inode only when enabled
     - f2fs: fix to round down start offset of fallocate for pin file
     - f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
     - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
     - f2fs: keep atomic write retry from zeroing original data
     - block: Avoid mounting the bdev pseudo-filesystem in userspace
     - bpf: use kvfree() for replaced sysctl write buffer
     - exfat: fix potential use-after-free in exfat_find_dir_entry()
     - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
       get_unaligned()
     - gfs2: fix use-after-free in gfs2_qd_dealloc
     - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
     - hdlc_ppp: sync per-proto timers before freeing hdlc state
     - blk-cgroup: fix UAF in __blkcg_rstat_flush()
     - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
     - pNFS: Fix use-after-free in pnfs_update_layout()
     - fpga: region: fix use-after-free in child_regions_with_firmware()
     - rpmsg: char: Fix use-after-free on probe error path
     - ocfs2: reject oversized group bitmap descriptors
     - 9p: avoid putting oldfid in p9_client_walk() error path
     - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks
     - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
     - power: reset: linkstation-poweroff: fix use-after-free in the
       linkstation_poweroff_init()
     - [riscv64] mm: Extract helper mark_new_valid_map()
     - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect()
     - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in
       fb_videomode_to_var
     - fbdev: modedb: fix a possible UAF in fb_find_mode()
     - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
     - i2c: core: fix adapter registration race
     - NFSD: Fix SECINFO_NO_NAME decode error cleanup
     - nfsd: fix posix_acl leak on SETACL decode failure
     - nfsd: check get_user() return when reading princhashlen
     - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
     - nfsd: reset write verifier on deferred writeback errors
     - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
     - NFS: Prevent resource leak in nfs_alloc_server()
     - ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
     - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
     - drivers/base/memory: set mem->altmap after successful device registration
     - Documentation: ioctl-number: Fix linuxppc-dev mailto link
     - Documentation: ioctl-number: Extend "Include File" column width
     - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with
       memdup_user()
     - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources
     - [amd64] crypto: qat - remove unused character device and IOCTLs
     - net/tcp-ao: fix use-after-free of key in del_async path
     - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
     - net: bonding: update the slave array for broadcast mode
     - bonding: annotate data-races arcound churn variables
     - bonding: do not set usable_slaves for broadcast mode
 .
   [ Salvatore Bonaccorso ]
   * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686)
   * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse."
 .
   [ Uwe Kleine-König ]
   * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly
     (Closes: #1136179)
Checksums-Sha1:
 8953fd95787471d620486845dc1fbd1ecdd0904d 288306 linux_6.12.95-1.dsc
 d2ad53065f74afc1280d795570d8cc7258f909e1 151304520 linux_6.12.95.orig.tar.xz
 3382d41b1446bdcd76de6063e2ce8112fc723d04 1840680 linux_6.12.95-1.debian.tar.xz
 7c8044fab4add45fcf19e50fbc6c6aa5eb679ec1 6909 linux_6.12.95-1_source.buildinfo
Checksums-Sha256:
 ef7ffb480d44c4109efebc8d658fd0370adabb7dd4dfb0035ca9e1a7d23721cf 288306 linux_6.12.95-1.dsc
 82ee332c20307c8e75b59c2779f3d554c592f5efa454bacf1e58daced5199f89 151304520 linux_6.12.95.orig.tar.xz
 ee558061352ea28f1013ff968fe3a3055a07f0ee23297606893d5230dfa3f180 1840680 linux_6.12.95-1.debian.tar.xz
 e897969f2dd8bf9fb19421c8f81a8c70d5fe1214afe37fa611f9e22b61fe4e93 6909 linux_6.12.95-1_source.buildinfo
Files:
 4cb4a91a624e3f4abdbb92c5b7f5c3ba 288306 kernel optional linux_6.12.95-1.dsc
 356a3dc49c2e30eba307f5d64ccc1b16 151304520 kernel optional linux_6.12.95.orig.tar.xz
 733d3c8ec93a22c53b6ebad43ccf0152 1840680 kernel optional linux_6.12.95-1.debian.tar.xz
 5b370b91dcbd9736a5603282dab4cc3c 6909 kernel optional linux_6.12.95-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpJULBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E1T8P/2yVUQXyOTTd5M5j7KtE62WOXJpNgKHw
Bj9FJk1o91mWN/ZZPAz2HovDnX2cPp5pcIDQHK+5zZDE6Aeo2FIdbXHVBfH0RSVY
Zy7t57/NPSOAiWJg2tqsjPfmw6/jQLDdZu4rZDADeHYnIiGTpHRcaPJxYpSVJMKz
0mSEjkfhQCfxIDUZO4KXk7BCFx8FBOacivVJ4zGnAh1uZKc37r2Ed7ZLl9zzSeDN
pwABQ/h5iC0GSrxx7GoSd+LCkIAlbNRtj3EyLtN0z1WCsCiA3L7Q8vFhE02VrX9k
Zb3czMs5T5G3yuIpxJbCoNrLnVWS6JUP6T30CPJRRFRNPrqqDVVxO9KuJ+mEjUBa
sNTjuTY6sD2DukNvC1x5LOKK9cytNpY3lPuiSWEWsas/E3zWngzNsEj6KcZ36ETr
h/bnn6rSHoO3yf/gPMKBBQXCDyI7wGbvfq/LG3Wm/KX6oHzGpjbpb2VJyBkRGzRm
Fx4RepZWOx/aGWE0Xv8Bpk0sGQblw2utPe/a8jtTXCtUJZ3rp3kAydPTAGnXfNxM
LTsE+Eq6rvfGMxqQm6VomfKs7GM3EqJI5aN0R9xacJeKuZ+4dfRJ9onXTIFNQRIE
YnPhq8tfXHilwGoNx20qWGMj0YW7T9KJM6I+e8oVIRY5oi3EO+2H2PGACmUBhvHi
iURJZ5b6wSao
=K2z6
-----END PGP SIGNATURE-----