#1139686 Please enable CONFIG_NETFILTER_NETLINK_HOOK

Package:
src:linux
Source:
src:linux
Submitter:
Arturo Borrero Gonzalez
Date:
2026-07-11 11:05:03 UTC
Severity:
normal
Tags:
#1139686#5
Date:
2026-06-11 08:22:56 UTC
From:
To:
Dear maintainers,

thank you for your hard work with the linux kernel packages, it is really appreciated.

I'm missing this config option in the Debian default kernel:

  $ grep CONFIG_NETFILTER_NETLINK_HOOK /boot/config-6.12.90+deb13.1-amd64
  # CONFIG_NETFILTER_NETLINK_HOOK is not set

Please enable it, as it allows to complete certain operations, such as `nft list hooks`.

Thanks, regardss.

#1139686#10
Date:
2026-06-12 04:16:40 UTC
From:
To:
Control: tags -1 + patch
Control: forwarded -1 https://salsa.debian.org/kernel-team/linux/-/merge_requests/1976

I have created
https://salsa.debian.org/kernel-team/linux/-/merge_requests/1976 .
Let's see if there are any objections within the team for it.

Regards,
Salvatore

#1139686#21
Date:
2026-06-19 16:20:32 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139686@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 19 Jun 2026 18:00:30 +0200
Source: linux
Architecture: source
Version: 7.1.1-1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1138985 1139686
Changes:
 linux (7.1.1-1~exp1) experimental; urgency=medium
 .
   * New upstream release: https://kernelnewbies.org/Linux_7.1
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.1.1
     - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
     - driver core: faux: fix root device registration
     - driver core: reject devices with unregistered buses
     - [arm64] cputype: Add C1-Ultra definitions
     - [arm64] cputype: Add C1-Premium definitions
     - [arm64] errata: Mitigate TLBI errata on various Arm CPUs
     - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU
     - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
     - HID: Input: Add battery list cleanup with devm action
     - drm/amdgpu: drop retry loop in amdgpu_hmm_range_get_pages
 .
   [ Baoli Zhang ]
   * [amd64] Enable EDAC_IMH as module
   * [amd64] Enable VIDEO_LT6911UXE as module
   * [amd64] Enable MIPI_I3C_HCI as module
   * [amd64] Enable PPS_GENERATOR_TIO as module
 .
   [ Bastian Blank ]
   * Fix build failure over missing vdso debug files.
 .
   [ Aurelien Jarno ]
   * [riscv64] disable RISCV_USER_CFI
   * [riscv64] Backport SpacemiT K1 thermal sensor driver from 7.2
   * [riscv64] Backport SpacemiT K1 SD card driver from 7.2
 .
   [ Emanuele Rocca ]
   * [arm64] enable CONFIG_ARM64_MPAM
 .
   [ Salvatore Bonaccorso ]
   * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686)
 .
   [ Danny Trunk ]
   * [amd64] drivers/platform/x86: Enable OXP_EC as module (Closes: #1138985)
Checksums-Sha1:
 820d327d019260d0868bc37e3f7db9cf0e196ae0 183274 linux_7.1.1-1~exp1.dsc
 2601e3728cade0c10df96f24ca7510ab9d8d5163 161579668 linux_7.1.1.orig.tar.xz
 9f21235aaac300d16061bf795cc0c179f7c11ccd 1466668 linux_7.1.1-1~exp1.debian.tar.xz
 8cf1888e5c93a4831669480544741b70031de23e 6954 linux_7.1.1-1~exp1_source.buildinfo
Checksums-Sha256:
 13716a9f342ed3e24d5e5aa5c04a83b22c72e587494bca5cbfffea7d8558eba6 183274 linux_7.1.1-1~exp1.dsc
 8fc03ba2692ba33d169c7bb2a15f4e480533c5553f6a7038573c513672e3d48f 161579668 linux_7.1.1.orig.tar.xz
 3316ff4f2612a37c47cf15ea41ab8356223529d0f71185d1a74347d0831e3bab 1466668 linux_7.1.1-1~exp1.debian.tar.xz
 951d8c5fbe2c36f1638c737db7f37a600ce265ef14605f320f15a98b09b5ca5a 6954 linux_7.1.1-1~exp1_source.buildinfo
Files:
 8df61754d19812a73ca7890b507a14b9 183274 kernel optional linux_7.1.1-1~exp1.dsc
 3b7563c33f1920781ae139f726bc8ebc 161579668 kernel optional linux_7.1.1.orig.tar.xz
 5fcf05fcad436398125a8d856ce2420e 1466668 kernel optional linux_7.1.1-1~exp1.debian.tar.xz
 a267479006e12bacc58d0846443a0b74 6954 kernel optional linux_7.1.1-1~exp1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmo1aEFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EUcEP/28rXZe7Y0WDuHSyjaD0hQBSo20TeWJ7
DNs7HcIfSPFwccyNtzRLgt+r+iTYzPs09+9UNseeWFK2jCcSdGS4SwrYETW0ZLj1
MZNHAZM19J4SQMd3DLK9fzFR/8CwWdwB5YAvVXKNlMQgmlqxAvmPNxvCGrHE1L6x
KVSqD3ouPzwZevPqzUnW82g3DrPgq58V+CTwzLj1OifDMCazWESyJdB8n0KO709C
RHt3apShuuGjxzeo66aNI1nTGosEbhq4mpCHq12KRCeJZfWHppy2htm84nc+O9XO
4Qz5qrfru34hDJ/51uFqcm1pY3TTk2ivhlIdrDABvbOjXRMOfpO1U9bKIT/bvdvn
3g5C9kIAX/wo0XirZ9Fg9J9w71pc9EYTSy4v6/EK1VJi4INKomaWl8noE0HEMPkd
ibbFmTKFjg74eNPjML2lqlJpZftQKsBe90jFnNIadmOx46p1i1V581bpElrK5bVK
3HH/05jORI2gUyhd89y1UKwbFR+3E1NIse/HO8Uoau52dlzFmWXcatZ6GrKAQNdb
kgD7DARZXKBXLOSwXXeUgAKCrVX77sRFU4FgK00HAf5B0O8u87PfqwXasQRL9Wh6
YUvwloTb/BcaDipE7hcO4a8hjaAJj2euR+azn64Be6WvSl2J6en0aW1Q+v/4woNU
KiV0Ks4ecMcE
=8vVH
-----END PGP SIGNATURE-----

#1139686#26
Date:
2026-06-19 19:13:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139686@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 19 Jun 2026 19:39:07 +0200
Source: linux
Architecture: source
Version: 7.0.13-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1138985 1139686
Changes:
 linux (7.0.13-1) unstable; urgency=medium
 .
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.0.13
     - [arm64] KVM: arm64: Take the SRCU lock for page table walks in fault
       injection and AT emulation
     - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
     - Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer
     - ipv6: mcast: Fix use-after-free when processing MLD queries
     - net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
     - [arm64] tee: optee: prevent use-after-free when the client exits before
       the supplicant
     - [arm64] soc: qcom: ice: Allow explicit votes on 'iface' clock for ICE
     - [arm64] dts: qcom: x1-dell-thena: remove i2c20 (battery SMBus) and reserve
       its pins
     - [arm64] soc: qcom: ice: Return -ENODEV if the ICE platform device is not
       found
     - [arm64] tee: fix tee_ioctl_object_invoke_arg padding
     - [arm64] tee: qcomtee: add missing va_end in early return
       qcomtee_object_user_init()
     - [s390x] bug: Always emit format word in __BUG_ENTRY
     - erofs: fix use-after-free on sbi->sync_decompress
     - wifi: iwlwifi: mvm: don't support the reset handshake for old firmwares
     - ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
     - netfilter: xt_NFQUEUE: prefer raw_smp_processor_id
     - ipvs: clear the svc scheduler ptr early on edit
     - netfilter: synproxy: add mutex to guard hook reference counting
     - netfilter: conntrack_irc: fix possible out-of-bounds read
     - netfilter: nft_ct: bail out on template ct in get eval
     - netfilter: bridge: make ebt_snat ARP rewrite writable
     - dm cache policy smq: check allocation under invalidate lock
     - net/sched: act_api: use RCU with deferred freeing for action lifecycle
     - 6lowpan: fix off-by-one in multicast context address compression
     - l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
     - devlink: Release nested relation on devlink free
     - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c
     - wifi: mac80211: limit injected antenna index in
       ieee80211_parse_tx_radiotap
     - pcnet32: stop holding device spin lock during napi_complete_done
     - net: Annotate sk->sk_write_space() for UDP SOCKMAP.
     - tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
     - hsr: Remove WARN_ONCE() in hsr_addr_is_self().
     - net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
     - net: lan743x: permit VLAN-tagged packets up to configured MTU
     - net: fec: fix pinctrl default state restore order on resume
     - ipv6: anycast: insert aca into global hash under idev->lock
     - wifi: fix leak if split 6 GHz scanning fails
     - wifi: cfg80211: add support to handle incumbent signal detected event from
       mac80211/driver
     - wifi: nl80211: split out UHR operation information
     - wifi: cfg80211: enforce HE/EHT cap/oper consistency
     - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
     - Bluetooth: MGMT: validate advertising TLV before type checks
     - Bluetooth: RFCOMM: validate skb length in MCC handlers
     - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension
       handling
     - Bluetooth: bnep: reject short frames before parsing
     - Bluetooth: fix memory leak in error path of hci_alloc_dev()
     - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
     - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
     - Bluetooth: SCO: Fix data-race on sco_pi fields in sco_connect
     - Bluetooth: MGMT: Fix backward compatibility with userspace
     - xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
     - [arm64] octeontx2-pf: Fix NDC sync operation errors
     - [arm64] octeontx2-af: Fix initialization of mcam's entry2target_pffunc
       field
     - af_unix: Fix inq_len update problem in partial read
     - ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
     - ptp: vclock: Switch from RCU to SRCU
     - net: airoha: Fix use-after-free in metadata dst teardown
     - net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
     - geneve: fix length used in GRO hint UDP checksum adjustment
     - net/sched: fix pedit partial COW leading to page cache corruption
       (CVE-2026-46331)
     - sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
     - [arm64] octeontx2-af: npc: Fix CPT channel mask in npc_install_flow
     - vxlan: vnifilter: send notification on VNI add
     - vxlan: vnifilter: fix spurious notification on VNI update
     - ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
     - net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
     - bonding: annotate data-races arcound churn variables
     - sctp: purge outqueue on stale COOKIE-ECHO handling
     - fwctl/bnxt_en: Move common definitions to include/linux/bnxt/
     - fwctl/bnxt_en: Refactor aux bus functions to be more generic
     - Reapply "bnxt_en: bring back rtnl_lock() in the bnxt_open() path"
     - Drivers: hv: vmbus: Provide option to skip VMBus unload on panic
     - drm/hyperv: During panic do VMBus unload after frame buffer is flushed
     - signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
     - regulator: mt6363: select CONFIG_IRQ_DOMAIN
     - hyperv: Clean up and fix the guest ID comment in hvgdk.h
     - VFS: fix possible failure to unlock in nfsd4_create_file()
     - [s390x] crypto: s390 - add select CRYPTO_AEAD for aes
     - rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()
     - time: Fix off-by-one in settimeofday() usec validation
     - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked
       streams
     - ALSA: seq: dummy: fix UMP event stack overread
     - [amd64] x86/resctrl: Only check Intel systems for SNC
     - [amd64] cpufreq/amd-pstate: drop stale @epp_cached kdoc
     - rtla: Fix parsing of multi-character short options
     - [riscv64] ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI
     - [riscv64] cfi: reject unknown flags in PR_SET_CFI
     - xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
     - dma-mapping: direct: fix missing mapping for THRU_HOST_BRIDGE segments
     - dma-debug: fix physical address retrieval in debug_dma_sync_sg_for_device
     - xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
     - ice: fix missing priority callbacks for U.FL DPLL pins
     - [amd64,arm64] idpf: fix mailbox capability for set device clock time
     - net: ena: PHC: Add missing barrier
     - bnge: fix context mem iteration
     - netlabel: validate unlabeled address and mask attribute lengths
     - gpio: mvebu: fix NULL pointer dereference in suspend/resume
     - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls
     - tcp: restrict SO_ATTACH_FILTER to priv users
     - net: add pskb_may_pull() to skb_gro_receive_list()
     - net/mlx4: avoid GCC 10 __bad_copy_from() false positive
     - net: ibm: emac: Fix use-after-free during device removal
     - netdev: fix double-free in netdev_nl_bind_rx_doit()
     - net: phy: clean the sfp upstream if phy probing fails
     - net: phy: remove phy ports upon probe failure
     - net: phy: Clean the phy_ports after unregistering the downstream SFP bus
     - net: phy: don't try to setup PHY-driven SFP cages when using genphy
     - net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
     - net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
     - net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
     - net/mlx5: Use effective affinity mask for IRQ selection
     - ipv6: sit: reload inner IPv6 header after GSO offloads
     - net: openvswitch: fix possible kfree_skb of ERR_PTR
     - r8152: handle the return value of usb_reset_device()
     - gpio: zynq: fix runtime PM leak on remove
     - gpio: rockchip: fix generic IRQ chip leak on remove
     - net: mctp: usb: fix race between urb completion and rx_retry cancellation
     - net: mctp: usb: don't fail mctp_usb_rx_queue on a deferred submission
     - esp: fix page frag reference leak on skb_to_sgvec failure
     - [amd64] ASoC: SOF: amd: fix for ipc flags check
     - sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
     - ip6_vti: set netns_immutable on the fallback device. (CVE-2026-52909)
     - sctp: validate embedded INIT chunk and address list lengths in cookie
     - net: guard timestamp cmsgs to real error queue skbs
     - net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic
       completion
     - tun: zero the whole vnet header in tun_put_user()
     - ptp: ocp: fix resource freeing order
     - ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
     - rds: mark snapshot pages dirty in rds_info_getsockopt()
     - spi: rzv2h-rspi: Fix SPDR read access width for 16-bit RX
     - netfilter: revalidate bridge ports
     - netfilter: nf_conntrack: destroy stale expectfn expectations on unregister
     - netfilter: x_tables: avoid leaking percpu counter pointers
     - netfilter: nf_log: validate MAC header was set before dumping it
     - netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
     - [arm64,armhf] net: mvpp2: sync RX data at the hardware packet offset
     - [arm64,armhf] net: mvpp2: limit XDP frame size to the RX buffer
     - [arm64,armhf] net: mvpp2: refill RX buffers before XDP or skb use
     - [arm64,armhf] net: mvpp2: build skb from XDP-adjusted data on XDP_PASS
     - ipv6: Fix a potential NPD in cleanup_prefix_route()
     - [amd64] ASoC: SDCA: fix NULL pointer dereference in
       sdca_dev_unregister_functions
     - [arm64] clk: qcom: x1e80100-dispcc: Stop disp_cc_mdss_mdp_clk_src from
       getting parked
     - clk: samsung: gs101: Fix missing USI7_USI DIV clock in peric0_clk_regs
     - [arm64] clk: qcom: dispcc-sc8280xp: Don't park mdp_clk_src at registration
       time
     - [amd64] drm/i915/edp: Check supported link rates DPCD read
     - drm/virtio: Fix driver removal with disabled KMS
     - drm/vc4: fix krealloc() memory leak
     - drm/colorop: Remove read-only comments from interpolation fields
     - drm/colorop: make lut(1/3)d_interpolation props correctly behave as
       mutable
     - drm/atomic: track individual colorop updates
     - drm/amd/display: use plane color_mgmt_changed to track colorop changes
     - drm/xe: fix refcount leak in xe_range_fence_insert()
     - drm/xe: fix job timeout recovery for unstarted jobs and kernel queues
     - [amd64] accel/amdxdna: Fix mm_struct reference leak in
       aie2_populate_range()
     - namespace: restrict OPEN_TREE_NAMESPACE/FSMOUNT_NAMESPACE to directories
     - netfilter: nft_tunnel: fix use-after-free on object destroy
     - netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
     - [arm64] tee: shm: fix shm leak in register_shm_helper()
     - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
     - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
     - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get()
     - mm/memory-failure: fix hugetlb_lock AA deadlock in
       get_huge_page_for_hwpoison
     - Revert "drm/xe/nvls: Define GuC firmware for NVL-S"
     - [amd64] accel/ivpu: Add bounds check for firmware runtime memory
     - [amd64] accel/ivpu: Add bounds checks for firmware log indices
     - firmware: stratix10-svc: Don't fail probe when async ops unsupported
     - firmware: stratix10-svc: Return -EOPNOTSUPP when ATF async unsupported
     - firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe
     - [amd64] accel/ivpu: Add buffer overflow check in MS get_info_ioctl
     - [amd64] accel/ivpu: Fix signed integer truncation in IPC receive
     - tracing: Fix CFI violation in probestub being called by tprobes
     - tracing/probes: Point the error offset correctly for eprobe argument error
     - cgroup/cpuset: Use effective_xcpus in partcmd_update add/del mask
       calculation
     - Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during
       suspend"
     - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation
     - cfi: Include uaccess.h for get_kernel_nofault()
     - mshv: add a missing padding field
     - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
     - [amd64] KVM: SEV: Decouple the need to sync the GHCB SA from the need to
       free the SA
     - [arm64] KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX
     - [arm64] KVM: arm64: Correctly identify executable PTEs at stage-2
     - [arm64] KVM: arm64: Restore POR_EL0 access to host EL0
     - [amd64] drm/i915/gem: Fix phys BO pread/pwrite with offset
     - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
     - pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init
     - ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
     - xfrm: espintcp: do not reuse an in-progress partial send
     - xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
     - xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
     - USB: serial: io_ti: fix heap overflow in get_manuf_info()
     - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
     - USB: serial: option: add usb-id for Dell Wireless DW5826e-m
     - USB: serial: kl5kusb105: fix bulk-out buffer overflow
     - ALSA: timer: Forcibly close timer instances at closing
     - ALSA: timer: Fix UAF at snd_timer_user_params()
     - io_uring/wait: fix min_timeout behavior
     - io_uring/kbuf: don't truncate end buffer for bundles
     - io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
     - drm/virtio: fix dma_fence refcount leak on error in
       virtio_gpu_dma_fence_wait()
     - drm/amd/display: Reject gpio_bitshift >= 32 in
       bios_parser_get_gpio_pin_info()
     - mm/huge_memory: update file PMD counter before folio_put()
     - mm/damon/ops-common: call folio_test_lru() after folio_get()
     - mm/huge_memory: update file PUD counter before folio_put()
     - RDMA/core: Validate the passed in fops for ib_get_ucaps()
     - RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
     - RDMA/srp: bound SRP_RSP sense copy by the received length
     - zram: fix use-after-free in zram_bvec_write_partial()
     - udp: clear skb->dev before running a sockmap verdict
     - [arm64] mm: call pagetable dtor when freeing hot-removed page tables
     - mptcp: fix missing wakeups in edge scenarios
     - mptcp: fix retransmission loop when csum is enabled
     - mptcp: close TOCTOU race while computing rcv_wnd
     - mptcp: allow subflow rcv wnd to shrink
     - mptcp: pm: fix extra_subflows underflow on userspace PM subflow creation
     - mptcp: check desc->count in read_sock
     - mptcp: sockopt: check timestamping ret value
     - mptcp: sockopt: set sockopt on all subflows
     - mptcp: add-addr: always drop other suboptions
     - xfs: fix error returns in CoW fork repair
     - xfs: fix rtgroup cleanup in CoW fork repair
     - wifi: iwlwifi: pcie: simplify the resume flow if fast resume is not used
     - wifi: nl80211: reject oversized EMA RNR lists
     - vsock/vmci: fix sk_ack_backlog leak on failed handshake
     - timers/migration: Fix livelock in tmigr_handle_remote_up()
     - [arm64] spi: qcom-geni: Fix cs_change handling on the last transfer
     - staging: rtl8723bs: fix buffer over-read in rtw_update_protection
     - staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length
       subtraction
     - ASoC: fsl_sai: Fix 32 slots TDM broken by integer shift UB in xMR write
     - bnxt_en: Fix NULL pointer dereference
     - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
     - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
     - hv: utils: handle and propagate errors in kvp_register
     - IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
     - inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
     - ovl: keep err zero after successful ovl_cache_get()
     - pidfd: refuse access to tasks that have started exiting harder
     - [s390x] Remove GENERIC_LOCKBREAK Kconfig option
     - fs/qnx6: fix pointer arithmetic in directory iteration
     - fuse: reject fuse_notify() pagecache ops on directories
     - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
     - futex/requeue: Prevent NULL pointer dereference in remove_waiter() on
       self-deadlock
     - i2c: imx-lpi2c: fix resource leaks switching to devm_dma_request_chan()
     - i2c: imx: fix clock and pinctrl state inconsistency in runtime PM
     - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
     - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter
     - i2c: tegra: Fix NOIRQ suspend/resume
     - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK)
     - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard
     - iomap: avoid potential null folio->mapping deref during error reporting
     - iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
     - ipc/shm: serialize orphan cleanup with shm_nattch updates
     - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
     - memcg: use round-robin victim selection in refill_stock
     - memory: atmel-ebi: Allow deferred probing
     - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
     - misc: fastrpc: fix use-after-free race in fastrpc_map_create
     - misc: fastrpc: fix DMA address corruption due to find_vma misuse
     - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
     - firmware: samsung: acpm: Fix mailbox channel leak on probe error
     - net/mlx5: Reorder completion before putting command entry in
       cmd_work_handler
     - net: airoha: Add NULL check for of_reserved_mem_lookup() in
       airoha_qdma_init_hfwd_queues()
     - net: bonding: fix NULL pointer dereference in bond_do_ioctl()
     - net: mv643xx: fix OF node refcount
     - net: phonet: free phonet_device after RCU grace period
     - net: rds: clear i_sends on setup unwind
     - net: sfp: initialize i2c_block_size at adapter configure time
     - nvmem: core: fix use-after-free bugs in error paths
     - nvmem: layouts: onie-tlv: fix hang on unknown types
     - [arm64] octeontx2-af: fix memory leak in rvu_setup_hw_resources()
     - pinctrl: mcp23s08: Read spi-present-mask as u8 not u32
     - mm/cma: fix reserved page leak on activation failure
     - mm/cma_debug: fix invalid accesses for inactive CMA areas
     - mm/damon/lru_sort: handle ctx allocation failure
     - mm/damon/reclaim: handle ctx allocation failure
     - mm/huge_memory: use correct flags for device private PMD entry
     - mm/hugetlb: avoid false positive lockdep assertion
     - mm/hugetlb: restore reservation on error in hugetlb folio copy paths
     - mm/list_lru: drain before clearing xarray entry on reparent
     - mm/mincore: handle non-swap entries before !CONFIG_SWAP guard
     - mmc: core: Fix host controller programming for fixed driver type
     - mmc: dw_mmc-rockchip: Add missing private data for very old controllers
     - mmc: litex_mmc: Set mandatory idle clocks before CMD0
     - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC
     - mmc: sdhci-of-dwcmshc: Fix reset, clk, and SDIO support for Eswin EIC7700
     - mmc: sdhci: add signal voltage switch in sdhci_resume_host
     - pmdomain: imx: fix OF node refcount
     - pmdomain: ti_sci: add wakeup constraint to parent devices of wakeup source
     - rtase: Avoid sleeping in get_stats64()
     - rtase: Reset TX subqueue when clearing TX ring
     - rxrpc: Fix the ACK parser to extract the SACK table for parsing
     - sctp: diag: reject stale associations in dump_one path
     - sctp: stream: fully roll back denied add-stream state
     - [amd64] thunderbolt: Reject zero-length property entries in validator
     - [amd64] thunderbolt: Bound root directory content to block size
     - [amd64] thunderbolt: Clamp XDomain response data copy to allocation size
     - [amd64] thunderbolt: Validate XDomain request packet size before type cast
     - [amd64] thunderbolt: Limit XDomain response copy to actual frame size
     - [arm64] slimbus: qcom-ngd-ctrl: fix OF node refcount
     - [arm64] slimbus: qcom-ngd-ctrl: Fix up platform_driver registration
     - [arm64] slimbus: qcom-ngd-ctrl: Fix probe error path ordering
     - [arm64] slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
     - [arm64] slimbus: qcom-ngd-ctrl: Initialize controller resources in
       controller
     - [arm64] slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership
     - [arm64] slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD
     - [arm64] slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock
     - drm/gem: Try to fix change_handle ioctl, attempt 4
     - [amd64] drm/i915: Fix color blob reference handling in intel_plane_state
     - drm/amdkfd: fix NULL dereference in get_queue_ids()
     - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
     - drm/xe/display: fix oops in suspend/shutdown without display
     - drm/xe/multi_queue: skip submit when primary queue is suspended
     - drm/xe: Clear pending_disable before signaling suspend fence
     - [arm64] drm/v3d: Wait for pending L2T flush before cleaning caches
     - [arm64] drm/v3d: Fix global performance monitor reference counting
     - [arm64] drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
     - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups
     - drm/amdgpu: fix waiting for all submissions for userptrs
     - drm/amdgpu: restart the CS if some parts of the VM are still invalidated
     - drm/amdgpu: set noretry=1 as default for GFX 10.1.x (Navi10/12/14)
     - drm/amdgpu: Fix incorrect VRAM GART mappings on non-4K page size systems
     - drm/amd/pm: apply SMU 13.0.10 workaround during MP1 unload
     - drm/amd/pm: fix smu13 power limit default/cap calculation
     - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2
     - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in
       set_soft_freq_limited_range
     - drm/amd/display: Bound VBIOS record-chain walk loops
     - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
     - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
     - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs
     - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
     - drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()
     - drm/amd/display: Use krealloc_array() in dal_vector_reserve()
     - fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
     - driver core: faux: fix root device registration
     - driver core: reject devices with unregistered buses
     - RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
     - netfilter: nft_fib: fix stale stack leak via the OIFNAME register
     - sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()
     - wifi: mac80211: skip ieee80211_verify_sta_ht_mcs_support check in
       non-strict mode
     - wifi: mac80211: tests: mark HT check strict
     - RDMA/umem: fix kernel-doc warnings
     - RDMA: Move DMA block iterator logic into dedicated files
     - RDMA/umem: Fix truncation for block sizes >= 4G
     - vsock/virtio: fix potential unbounded skb queue
     - vsock/virtio: fix skb overhead accounting to preserve full buf_alloc
     - debugobjects: Do not fill_pool() if pi_blocked_on
     - debugobjects: Don't call fill_pool() in early boot hardirq context
     - [arm64] cputype: Add C1-Ultra definitions
     - [arm64] cputype: Add C1-Premium definitions
     - [arm64] errata: Mitigate TLBI errata on various Arm CPUs
     - [arm64] errata: Mitigate TLBI errata on NVIDIA Olympus CPU
     - [arm64] errata: Mitigate TLBI errata on Microsoft Azure Cobalt 100 CPU
     - vsock/virtio: fix skb overhead overflow on 32-bit builds
     - netfilter: require Ethernet MAC header before using eth_hdr()
     - drm/amdgpu: drop retry loop in amdgpu_hmm_range_get_pages
 .
   [ Salvatore Bonaccorso ]
   * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686)
 .
   [ Danny Trunk ]
   * [amd64] drivers/platform/x86: Enable OXP_EC as module (Closes: #1138985)
Checksums-Sha1:
 01058e774c4ccf45051e94043f350c8144c64f8e 196174 linux_7.0.13-1.dsc
 dcdcb3c1083a607c6d377628a9def1aa1f2c92f1 160427680 linux_7.0.13.orig.tar.xz
 9e29beb571997dd4bda0a60557c6463281b5629b 1507272 linux_7.0.13-1.debian.tar.xz
 66c7b82d18129c5a0cf91539c2a97ed1f15c8f4a 6938 linux_7.0.13-1_source.buildinfo
Checksums-Sha256:
 d0b0c17915b7dc4f1a14f195885cfb910e680be57c015c52940c2e4cf0abadf6 196174 linux_7.0.13-1.dsc
 a4bc45a075f9857bcfba83879d56cae0f6f0a9c50411b3a15297682ff0c1be10 160427680 linux_7.0.13.orig.tar.xz
 5b64df2822f9f7fc75189c7623bc5b309779c50a6ad8d32e6ac1325a1456908a 1507272 linux_7.0.13-1.debian.tar.xz
 ae6d4e107ce4fb5654cb1816cd0477b5872731d80a33335500e8b547c379cebe 6938 linux_7.0.13-1_source.buildinfo
Files:
 6a629bbdbfbce3455765ff4a2777d1d8 196174 kernel optional linux_7.0.13-1.dsc
 e06578f9fcd2862277e037f754f30fb6 160427680 kernel optional linux_7.0.13.orig.tar.xz
 d5b21c31b2bed8f29bbf3c02f220a620 1507272 kernel optional linux_7.0.13-1.debian.tar.xz
 69fa094b90637ce32757d9aab2140cf9 6938 kernel optional linux_7.0.13-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmo1f2VfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E+JIP+gIN5LQ/u60RWyI+k2ir3JUoKFAKNppF
bkG/cE2vnPNLPtTGsCA1tDte3Srh4GNaXOZCLJJiF2D6amUeo41wfUogebgidHJn
ifT9OWvOZ5dKBtlhCFdhTysiDwtrajW99fF89IER5IpRyt/bt/nr/+ZgGh9mtMjo
PQypssQOdOP6jBbjBsUxAVuoTe74Wz8OSrdimsfLH9WPPdYhT82Y+oqknYMxIVGS
2mI+AAr7R0PosCUMTBMSPEHhVUG3GRaTbDz7saOhxEIUXCe6UcII3i1+9x0JGqZj
RXXHajZaxKGhR6+lwRIuwGJBHilsyiJcNdmFB5DRSWUIoB+N6LcK3iaAMAXzMC8Z
MZrMctz0aMNKgKbFl0wHxNiUtcJfsPsxFRvMsOXPUnP4quDoY9wL4dQCMivgZ9CS
AHarwTBsMrlcuaUeGsrJuL/XPk4JpoM059zhoCKibxIeofeOdMNxwkGuvKprfK2h
HNezwHK+cl8T8cVAidN9sNTiCRXQikn219ULNR8Sq2a015ueFYKD4ayw3C0kkgqZ
oPCjSK7ghudTauZ4wixNaGTJoRqveAP80yF85KFg8nXtpXk5wcw8FIWyD0/dUfOj
/XBxTcbbNtKfCW5TTOuh0zCJzErNl9/nOpTWkcxp8HIjv/Y/RsJPd1GGUCQEkgRn
ox/4IdpjbpoQ
=e4lD
-----END PGP SIGNATURE-----

#1139686#31
Date:
2026-07-11 11:04:02 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139686@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 04 Jul 2026 20:24:27 +0200
Source: linux
Architecture: source
Version: 6.12.95-1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1136179 1139686
Changes:
 linux (6.12.95-1) trixie-security; urgency=high
 .
   * New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.95
     - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory
       domain
     - wifi: mt76: mt7921: fix a potential scan no APs
     - wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync
       (CVE-2026-53101)
     - fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (CVE-2026-53167)
     - gpiolib: Extract gpiochip_choose_fwnode() for wider use
     - gpiolib: Remove redundant assignment of return variable
     - gpio: Fix resource leaks on errors in gpiochip_add_data_with_key()
       (CVE-2026-31732)
     - io_uring/net: Avoid msghdr on op_connect/op_bind async data
     - drm/xe/display: fix oops in suspend/shutdown without display
       (CVE-2026-53142)
     - [arm64] drm/v3d: Store the active job inside the queue's state
     - [arm64] drm/v3d: Skip CSD when it has zeroed workgroups (CVE-2026-53139)
     - eventpoll: use hlist_is_singular_node() in __ep_remove()
     - eventpoll: split __ep_remove()
     - eventpoll: kill __ep_remove()
     - eventpoll: drop vestigial __ prefix from ep_remove_{file,epi}()
     - eventpoll: rename ep_remove_safe() back to ep_remove()
     - eventpoll: move epi_fget() up
     - eventpoll: fix ep_remove struct eventpoll / struct file UAF
       (CVE-2026-46242)
     - iio: light: bh1780: fix PM runtime leak on error path (CVE-2026-43355)
     - net: Drop the lock in skb_may_tx_timestamp() (CVE-2026-43216)
     - Reapply "selftest/ptp: update ptp selftest to exercise the gettimex
       options"
     - debugobjects: Allow to refill the pool before SYSTEM_SCHEDULING
     - debugobjects: Use LD_WAIT_CONFIG instead of LD_WAIT_SLEEP
     - debugobjects: Do not fill_pool() if pi_blocked_on
     - debugobjects: Dont call fill_pool() in early boot hardirq context
     - RDMA/bnxt_re: zero shared page before exposing to userspace
     - i2c: stub: Reject I2C block transfers with invalid length
     - [amd64] agp/amd64: Fix broken error propagation in agp_amd64_probe()
       (CVE-2026-53325)
     - bpf: Reject sleepable kprobe_multi programs at attach time
       (CVE-2026-43010)
     - ACPI: scan: Use async schedule function in acpi_scan_clear_dep_fn()
     - regulator: core: fix locking in regulator_resolve_supply() error path
     - dlm: prevent NPD when writing a positive value to event_done
       (CVE-2025-23131)
     - xfs: remove the expr argument to XFS_TEST_ERROR
     - xfs: fix error returns in CoW fork repair
     - Revert "net: bonding: fix use-after-free in bond_xmit_broadcast()"
     - net: bonding: add broadcast_neighbor option for 802.3ad
     - bonding: add support for per-port LACP actor priority
     - bonding: print churn state via netlink
     - bonding: 3ad: implement proper RCU rules for port->aggregator
       (CVE-2026-52975)
     - net: bonding: fix use-after-free in bond_xmit_broadcast() (CVE-2026-31419)
     - bonding: fix NULL pointer dereference in actor_port_prio setting
     - staging: rtl8723bs: fix buffer over-read in rtw_update_protection
       (CVE-2026-53179)
     - fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
       (CVE-2026-53341)
     - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs
     - hv: utils: handle and propagate errors in kvp_register
     - locking/mutex: Remove wakeups from under mutex::wait_lock
     - locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
     - phonet: Pass ifindex to fill_addr().
     - phonet: Pass net and ifindex to phonet_address_notify().
     - net: phonet: free phonet_device after RCU grace period (CVE-2026-53157)
     - rxrpc: Fix the ACK parser to extract the SACK table for parsing
       (CVE-2026-53151)
     - fuse: re-lock request before replacing page cache folio
     - ftrace: Update the mcount_loc check of skipped entries
     - ftrace: Have ftrace pages output reflect freed pages
     - ftrace: Do not over-allocate ftrace memory
     - ftrace: Test mcount_loc addr before calling ftrace_call_addr()
     - ftrace: Check against is_kernel_text() instead of kaslr_offset()
     - net: ipv6: Make udp_tunnel6_xmit_skb() void
     - sctp: disable BH before calling udp_tunnel_xmit_skb() (CVE-2026-53070)
     - iio: light: veml6075: add bounds check to veml6075_it_ms index
     - iio: adc: ti-ads1298: add bounds check to pga_settings index
     - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent
       vcs_write
     - [arm64] serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero
     - ksmbd: reject non-VALID session in compound request branch
     - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
     - virtiofs: fix UAF on submount umount
     - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected role
       (CVE-2026-53359)
     - [amd64] KVM: x86/mmu: Ensure hugepage is in by slot before checking max
       mapping level
     - Revert "PCI: qcom: Advertise Hotplug Slot Capability with no Command
       Completion support"
     - [amd64] KVM: SEV: Ignore MMIO requests of length '0'
     - [amd64] KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+
     - [amd64] KVM: SEV: Ignore Port I/O requests of length '0'
     - batman-adv: tp_meter: keep unacked list in ascending ordered
     - batman-adv: tp_meter: initialize dup_acks explicitly
     - batman-adv: tp_meter: initialize dec_cwnd explicitly
     - batman-adv: tp_meter: avoid window underflow
     - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
     - batman-adv: tp_meter: fix fast recovery precondition
     - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection
     - batman-adv: tp_meter: add only finished tp_vars to lists
     - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE
     - batman-adv: prevent ELP transmission interval underflow
     - batman-adv: tp_meter: initialize last_recv_time during init
     - batman-adv: ensure bcast is writable before modifying TTL
     - batman-adv: fix (m|b)cast csum after decrementing TTL
     - batman-adv: frag: ensure fragment is writable before modifying TTL
     - batman-adv: frag: avoid underflow of TTL
     - batman-adv: v: prevent OGM aggregation on disabled hardif
     - batman-adv: tp_meter: restrict number of unacked list entries
     - batman-adv: tp_meter: annotate last_recv_time access with READ/WRITE_ONCE
     - batman-adv: tp_meter: prevent parallel modifications of last_recv
     - batman-adv: tp_meter: handle overlapping packets
     - batman-adv: tt: don't merge change entries with different VIDs
     - batman-adv: tt: track roam count per VID
     - batman-adv: dat: prevent false sharing between VLANs
     - batman-adv: tvlv: enforce 2-byte alignment
     - batman-adv: tvlv: avoid race of cifsnotfound handler state
     - ipv6: account for fraggap on the paged allocation path (CVE-2026-53362)
     - fs: constify file ptr in backing_file accessor helpers
     - lsm: add backing_file LSM hooks
     - selinux: fix overlayfs mmap() and mprotect() access checks
     - inet: add indirect call wrapper for getfrag() calls
     - ipv4: account for fraggap on the paged allocation path
     - ntfs3: reject direct userspace writes to reserved $LX* xattrs
     - [amd64] KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb()
     - [amd64] KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free
     - af_unix: Set gc_in_progress to true in unix_gc(). (CVE-2026-53361)
     - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program
     - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g
     - mac802154: llsec: add skb_cow_data() before in-place crypto
     - net: skmsg: preserve sg.copy across SG transforms
     - net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
     - apparmor: mediate the implicit connect of TCP fast open sendmsg
     - apparmor: fix use-after-free in rawdata dedup loop
     - NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share
       BAR
     - fbdev: fix use-after-free in store_modes()
     - kernel/fork: clear PF_BLOCK_TS in copy_process()
     - block: invalidate cached plug timestamp after task switch
     - err.h: use __always_inline on all error pointer helpers
     - KEYS: fix overflow in keyctl_pkey_params_get_2()
     - keys: Pin request_key_auth payload in instantiate paths
     - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
     - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
     - wifi: ath11k: fix warning when unbinding
     - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
     - wifi: rtw88: increase TX report timeout to fix race condition
     - wifi: rtw88: usb: fix memory leaks on USB write failures
     - wifi: iwlwifi: mvm: fix race condition in PTP removal
     - f2fs: validate compress cache inode only when enabled
     - f2fs: fix to round down start offset of fallocate for pin file
     - f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
     - f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
     - f2fs: keep atomic write retry from zeroing original data
     - block: Avoid mounting the bdev pseudo-filesystem in userspace
     - bpf: use kvfree() for replaced sysctl write buffer
     - exfat: fix potential use-after-free in exfat_find_dir_entry()
     - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with
       get_unaligned()
     - gfs2: fix use-after-free in gfs2_qd_dealloc
     - [arm64] pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
     - hdlc_ppp: sync per-proto timers before freeing hdlc state
     - blk-cgroup: fix UAF in __blkcg_rstat_flush()
     - tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
     - pNFS: Fix use-after-free in pnfs_update_layout()
     - fpga: region: fix use-after-free in child_regions_with_firmware()
     - rpmsg: char: Fix use-after-free on probe error path
     - ocfs2: reject oversized group bitmap descriptors
     - 9p: avoid putting oldfid in p9_client_walk() error path
     - [amd64] KVM: x86: hyper-v: Bound the bank index when querying sparse banks
     - [amd64] KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
     - power: reset: linkstation-poweroff: fix use-after-free in the
       linkstation_poweroff_init()
     - [riscv64] mm: Extract helper mark_new_valid_map()
     - [riscv64] kfence: Call mark_new_valid_map() for kfence_unprotect()
     - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in
       fb_videomode_to_var
     - fbdev: modedb: fix a possible UAF in fb_find_mode()
     - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode
     - i2c: core: fix adapter registration race
     - NFSD: Fix SECINFO_NO_NAME decode error cleanup
     - nfsd: fix posix_acl leak on SETACL decode failure
     - nfsd: check get_user() return when reading princhashlen
     - nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
     - nfsd: reset write verifier on deferred writeback errors
     - NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
     - NFS: Prevent resource leak in nfs_alloc_server()
     - ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
     - serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
     - drivers/base/memory: set mem->altmap after successful device registration
     - Documentation: ioctl-number: Fix linuxppc-dev mailto link
     - Documentation: ioctl-number: Extend "Include File" column width
     - [amd64] crypto: qat - Replace kzalloc() + copy_from_user() with
       memdup_user()
     - [amd64] crypto: qat - Return pointer directly in adf_ctl_alloc_resources
     - [amd64] crypto: qat - remove unused character device and IOCTLs
     - net/tcp-ao: fix use-after-free of key in del_async path
     - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
     - net: bonding: update the slave array for broadcast mode
     - bonding: annotate data-races arcound churn variables
     - bonding: do not set usable_slaves for broadcast mode
 .
   [ Salvatore Bonaccorso ]
   * net/netfilter: Enable NETFILTER_NETLINK_HOOK as module (Closes: #1139686)
   * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse."
 .
   [ Uwe Kleine-König ]
   * [amd64] Enable CONFIG_PINCTRL_CS42L43 and CONFIG_SPI_CS42L43 explicitly
     (Closes: #1136179)
Checksums-Sha1:
 8953fd95787471d620486845dc1fbd1ecdd0904d 288306 linux_6.12.95-1.dsc
 d2ad53065f74afc1280d795570d8cc7258f909e1 151304520 linux_6.12.95.orig.tar.xz
 3382d41b1446bdcd76de6063e2ce8112fc723d04 1840680 linux_6.12.95-1.debian.tar.xz
 7c8044fab4add45fcf19e50fbc6c6aa5eb679ec1 6909 linux_6.12.95-1_source.buildinfo
Checksums-Sha256:
 ef7ffb480d44c4109efebc8d658fd0370adabb7dd4dfb0035ca9e1a7d23721cf 288306 linux_6.12.95-1.dsc
 82ee332c20307c8e75b59c2779f3d554c592f5efa454bacf1e58daced5199f89 151304520 linux_6.12.95.orig.tar.xz
 ee558061352ea28f1013ff968fe3a3055a07f0ee23297606893d5230dfa3f180 1840680 linux_6.12.95-1.debian.tar.xz
 e897969f2dd8bf9fb19421c8f81a8c70d5fe1214afe37fa611f9e22b61fe4e93 6909 linux_6.12.95-1_source.buildinfo
Files:
 4cb4a91a624e3f4abdbb92c5b7f5c3ba 288306 kernel optional linux_6.12.95-1.dsc
 356a3dc49c2e30eba307f5d64ccc1b16 151304520 kernel optional linux_6.12.95.orig.tar.xz
 733d3c8ec93a22c53b6ebad43ccf0152 1840680 kernel optional linux_6.12.95-1.debian.tar.xz
 5b370b91dcbd9736a5603282dab4cc3c 6909 kernel optional linux_6.12.95-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpJULBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89E1T8P/2yVUQXyOTTd5M5j7KtE62WOXJpNgKHw
Bj9FJk1o91mWN/ZZPAz2HovDnX2cPp5pcIDQHK+5zZDE6Aeo2FIdbXHVBfH0RSVY
Zy7t57/NPSOAiWJg2tqsjPfmw6/jQLDdZu4rZDADeHYnIiGTpHRcaPJxYpSVJMKz
0mSEjkfhQCfxIDUZO4KXk7BCFx8FBOacivVJ4zGnAh1uZKc37r2Ed7ZLl9zzSeDN
pwABQ/h5iC0GSrxx7GoSd+LCkIAlbNRtj3EyLtN0z1WCsCiA3L7Q8vFhE02VrX9k
Zb3czMs5T5G3yuIpxJbCoNrLnVWS6JUP6T30CPJRRFRNPrqqDVVxO9KuJ+mEjUBa
sNTjuTY6sD2DukNvC1x5LOKK9cytNpY3lPuiSWEWsas/E3zWngzNsEj6KcZ36ETr
h/bnn6rSHoO3yf/gPMKBBQXCDyI7wGbvfq/LG3Wm/KX6oHzGpjbpb2VJyBkRGzRm
Fx4RepZWOx/aGWE0Xv8Bpk0sGQblw2utPe/a8jtTXCtUJZ3rp3kAydPTAGnXfNxM
LTsE+Eq6rvfGMxqQm6VomfKs7GM3EqJI5aN0R9xacJeKuZ+4dfRJ9onXTIFNQRIE
YnPhq8tfXHilwGoNx20qWGMj0YW7T9KJM6I+e8oVIRY5oi3EO+2H2PGACmUBhvHi
iURJZ5b6wSao
=K2z6
-----END PGP SIGNATURE-----