Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
4944 commits
Select commit Hold shift + click to select a range
78e59ab
pmdomains: mediatek: Avoid setting RTFF's CLK_DIS before NRESTORE
Jul 16, 2026
b5060ff
mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
Aug 3, 2026
e5b5278
drm/connector/hdmi: Fix out of bounds memory read
Jul 23, 2026
8f7f7a6
mmc: loongson2: Fix sg iteration in data reorder functions
Aug 4, 2026
198b4a8
pmdomain: mediatek: Fix mt8183 hang on boot
Jul 29, 2026
7b90db6
drm/xe: Order ring writes before ring tail updates
Aug 7, 2026
3611148
drm/xe: Fix xe_device_probe() failure
Aug 10, 2026
31ef570
drm/radeon: fix autosuspend cleanup during teardown
Aug 8, 2026
0382ed4
eth: bnxt: always set the queue mgmt ops
Jan 22, 2026
45aa385
eth: bnxt: make sure we populate the qcfg defaults on old FW/HW
Jan 28, 2026
32e3d36
s390/vfio_ccw: Free all memory if cp_init() fails
Jul 28, 2026
06f4d6e
s390/vfio_ccw: Limit the number of channel program segments
Jul 28, 2026
b7ae0f7
s390/vfio_ccw: Cancel existing workqueues
Jul 28, 2026
649badf
s390/vfio_ccw: Ensure index for read/write regions are within range
Jul 28, 2026
08ef2a8
s390/vfio_ccw: Ensure first IDAW remains constant
Jul 28, 2026
4c2e1d3
s390/vfio_ccw: Fix out of bounds check on CCW array
Jul 28, 2026
af1759d
s390/vfio_ccw: Move cp cleanup out of not operational
Jul 28, 2026
b6aecea
s390/vfio_ccw: Selectively expand io_mutex
Jul 28, 2026
3b224d3
s390/vfio_ccw: Calculate idal length based on idaw type
Jul 28, 2026
7902be3
s390/vfio_ccw: Implement a crw lock
Jul 28, 2026
95c1de6
s390/zcrypt: Fix CPRB memory allocation in zcrypt misc code
Aug 3, 2026
5045fb4
drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_v…
Aug 7, 2026
cd99fa1
drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix
Aug 2, 2026
e3e6a63
drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE
Aug 2, 2026
e304c3e
drm/amdgpu: Reject UVD message with invalid number of h265 refs
Aug 11, 2026
916e8a1
drm/amdgpu: fix nbif 6.3.1 l1 low power not functional
Aug 10, 2026
a082bd7
drm/amdgpu: check ASPM on the dGPU host link
Aug 5, 2026
220aa25
drm/amdgpu: validate GEM_CREATE domain combinations
Jul 27, 2026
339deb7
drm/amdgpu: Reject UVD message with dimensions above 4096
Jul 30, 2026
86a5cb0
drm/amdgpu: Implement insert_end for VCE 3
Aug 10, 2026
c76e5cc
drm/amdgpu: Fix UVD min buffer sizes
Jul 30, 2026
38914cb
drm/amdgpu: Fix UVD dpb min size calculation for H264
Jul 30, 2026
25ee120
drm/amdgpu: Fix UVD decode image min size calculation
Jul 30, 2026
71aa45f
drm/amdgpu: disallow multiple FENCE chunks in one submit
Aug 6, 2026
ec19cea
xfs: propagate errors from xfs_rtginode_load
Jul 12, 2026
8a0ecae
xfs: fix off-by-one in rtrefcount btree root level validation
Jul 14, 2026
f828821
xfs: bounds-check buffer log item's dirty bitmap
Jul 15, 2026
aeadf3f
xfs: mark nonzero sb_gquotino as corrupt on metadir filesystems
Jul 21, 2026
069c0ea
xfs: clear zapped attr fork state when bmap repair finds no attr fork
Jul 16, 2026
90a49b8
xfs: check cowextsize in xrep_inode_cowextsize
Jul 21, 2026
a9114c6
xfs: fix transaction block reservation in xrep_rtbitmap
Jul 21, 2026
62c0b14
xfs: zero i_nlink before repair puts inode on unlinked list
Jul 21, 2026
983588e
xfs: only check mergeability of bnobt records
Jul 27, 2026
ce2a700
xfs: don't double-lock when deleting a self-referential directory
Jul 27, 2026
ab4e133
xfs: set the prev pointer when reinserting an inode on the unlinked list
Jul 27, 2026
7d1d82c
xfs: pass runtime errors from xrep_iunlink_mark_ondisk_rec up to callers
Jul 27, 2026
8b52fa8
xfs: nlink scrub must take IOLOCK before determining ILOCK state
Jul 27, 2026
9680b19
xfs: load next_agino from the correct xfarray in xrep_iunlink_relink_…
Jul 27, 2026
514a5d4
xfs: fix ilock leak on error in xfs_dq_get_next_id
Jul 27, 2026
73ffd26
xfs: don't zap the attr fork on repair when there are queued pptr upd…
Jul 27, 2026
c36d7f6
xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
Jul 27, 2026
fc7d8a5
xfs: fix allocated inodes that show up in the unlinked list
Jul 27, 2026
b6baf0d
xfs: fix another iunlink infinite loop bug in online fsck
Jul 27, 2026
e75150d
xfs: don't return EFSCORRUPTED when scrubbing corrupt parent pointers
Jul 27, 2026
cd1f876
xfs: avoid UAF on sc->tempip in xrep_tempfile_create
Jul 27, 2026
0f27b22
xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
Jul 28, 2026
38a4dbe
xfs: don't swallow dquot recovery verification errors
Jul 27, 2026
33b56c6
xfs: don't ignore runtime errors in xrep_iunlink_reload_next
Jul 27, 2026
04228b8
xfs: check xfarray iteration errors when committing unlinked inode lists
Jul 27, 2026
bb13785
xfs: check v5 superblock features early
Jul 29, 2026
79d95b4
ceph: avoid fs reclaim while using current->journal_info
Aug 7, 2026
a3bc6b3
ceph: fix hanging __ceph_get_caps() with stale mds_wanted
Aug 7, 2026
89a50fb
libceph: Amend checking to fix `make W=1` build breakage
Aug 7, 2026
590b07c
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
Aug 7, 2026
89df5d7
libceph: fix two unsafe bare decodes in decode_lockers()
Aug 8, 2026
8ddc2eb
net/sched: serialize qdisc_rtab_list against concurrent get/put
Aug 8, 2026
9d154c3
smb: move get_rfc1002_len() to common/smbglob.h
Aug 8, 2026
df3cf61
smb/server: rename include guard in smb_common.h
Aug 8, 2026
29dbb4e
ksmbd: Fix to handle removal of rfc1002 header from smb_hdr
Aug 8, 2026
5649004
ksmbd: rename smb2_get_msg to smb_get_msg
Aug 8, 2026
23d34ce
smb/server: fix minimum SMB1 PDU size
Aug 8, 2026
15a2fed
smb/server: fix minimum SMB2 PDU size
Aug 8, 2026
d9e9753
ksmbd: validate minimum PDU size for transform requests
Aug 8, 2026
58ae8b7
btrfs: remove fs_info argument from btrfs_zoned_activate_one_bg()
Aug 9, 2026
549148d
btrfs: zoned: fix missing chunk metadata reservation
Aug 9, 2026
54a0957
fs/proc/task_mmu: refactor pagemap_pmd_range()
Aug 10, 2026
ea563ed
mm: replace pmd_to_swp_entry() with softleaf_from_pmd()
Aug 10, 2026
ef60eca
userfaultfd: wait on source PMD during UFFDIO_MOVE
Aug 10, 2026
5f0a99e
KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs
Aug 10, 2026
db488d6
ASoC: tas2562: Validate values for volume writes
Aug 11, 2026
4c8d759
ata: libata-scsi: terminate deferred commands on time out
Aug 11, 2026
867aed6
binfmt_misc: don't leak the user namespace when the mount fails
Aug 11, 2026
562d4be
can: rcar_canfd: Invert reset assert order
Aug 12, 2026
f8c8c81
can: rcar_canfd: Invert global vs. channel teardown
Aug 12, 2026
e7a4ca9
can: rcar_canfd: Use devm_clk_get_optional() for RAM clk
Aug 12, 2026
45bf067
can: rcar_canfd: Extract rcar_canfd_global_{,de}init()
Aug 12, 2026
870f839
can: rcar_canfd: change the initializing flow for clocks and resets
Aug 12, 2026
4a7e941
futex: Fix race in futex_pivot_pending() during private hash resize
Aug 15, 2026
0907f81
sched_ext: Update p->scx.disallow warning in scx_init_task()
Aug 19, 2026
f786e66
sched_ext: Reorganize enable/disable path for multi-scheduler support
Aug 19, 2026
2ca6b43
sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
Aug 19, 2026
27d7fca
ring-buffer: Add helper functions for allocations
Aug 19, 2026
54fc675
ring-buffer: Store bpage pointers into subbuf_ids
Aug 19, 2026
4ae625d
ring-buffer: Prevent resizing of persistent ring buffer
Aug 19, 2026
7755be9
mm/page_table_check: skip special zero mappings
Aug 19, 2026
2895aeb
drm/amd/pm: adjust the visibility of pp_table sysfs node
Aug 12, 2026
8c685df
drm/amd/pm: fix pptable use-after-free
Aug 12, 2026
2a7d8fc
ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
Jul 30, 2026
08437c5
net: ntb_netdev: Introduce per-queue context
Mar 5, 2026
a4e3409
NTB: ntb_netdev: Preserve RX queue depth on allocation failure
Aug 6, 2026
d9ecc97
arm64: tegra: Add EL2 virtual timer interrupt for Tegra194
Jul 28, 2026
3e4bf50
crypto: ccm - Set rfc4309 maxauthsize from child
Jul 20, 2026
99a18e1
crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
Jul 20, 2026
a47a080
ovpn: fix NULL dereference when killing missing key
Jul 29, 2026
a3a6764
ovpn: finish crypto callback cleanup before peer release
Jul 29, 2026
6c85d16
riscv: ftrace: Fix ftrace_modify_call failure on kprobed functions
Aug 2, 2026
7a03413
perf: Reject exited events as group leaders
Aug 6, 2026
24d0f33
gpio: ml-ioh: share the register lock across channels
Aug 4, 2026
9e75e7d
ASoC: tas2781: fix clang build error for goto bypassing cleanup variable
Aug 7, 2026
cb20da3
netfilter: ipset: fix refcount race between list:set GC and swap
Jul 22, 2026
4a923fe
netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abo…
Aug 6, 2026
d9d3050
netfilter: flowtable: publish GC-visible tuple last
Aug 8, 2026
29c011b
netfilter: ipset: fix list type element drift bug
Aug 6, 2026
a26a1be
netfilter: ipset: let destroy callbacks adjust ext mem size
Aug 6, 2026
394f1b1
eth: bnxt: cancel IRQ notifier before freeing affinity mask
Aug 3, 2026
1072f0f
eth: bnxt: keep the aRFS rmap updated when TPH is enabled
Aug 3, 2026
5f33188
ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
Aug 6, 2026
96fa90b
macvlan: inherit needed_headroom and needed_tailroom from lowerdev
Aug 6, 2026
73f8dd2
veth: fix queue index used to wake the peer txq in veth_poll
Aug 6, 2026
17e3181
tcp: fix icsk_ack.ato bitfield overflow
Aug 7, 2026
0af3afd
net: phy: realtek: fix EEE advertisement write on the internal PHY MM…
Aug 6, 2026
f9297ab
net: packet: fix wrong transport_header when sending VLAN-tagged frame
Aug 7, 2026
5ffaa5d
net: tap: fix wrong transport_header when sending VLAN-tagged frame
Aug 7, 2026
cef4c5b
net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
Aug 7, 2026
82d9269
net/tls: Fail tls_sw_splice_read() after a failed async decrypt
Aug 7, 2026
f51a540
ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
Aug 6, 2026
37c5cca
regmap: sdw-mbq: Fix swap of timeout and retry times
Aug 11, 2026
98c5914
af_packet: Don't send zero-byte data in tpacket_snd().
Aug 10, 2026
abceabc
net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
Aug 9, 2026
31f26a9
net/sched: cls_u32: skip hash tables in u32_bind_class()
Aug 7, 2026
c27eed5
m68k: Define NR_CPUS to 1
Jul 31, 2026
6cf600b
regmap: sdw-mbq: don't call an unset readable_reg callback
Aug 11, 2026
72e4e3d
net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
Aug 7, 2026
1f493c4
accel/amdxdna: Skip unmapped range in aie2_populate_range()
Aug 12, 2026
adb3e7c
net/sched: cls_bpf: reject dev-bound programs bound to a different de…
Aug 9, 2026
384d9f0
firewire: ohci: split page allocation from dma mapping
Jan 10, 2026
ed54707
firewire: ohci: fix NULL pointer dereference in ar_context_release
Aug 7, 2026
948f346
drm/xe/oa: Fix sync entry leak on OA config emit failure
Jul 31, 2026
16a2716
drm/log: Fix out-of-bounds read on empty message length
Jul 29, 2026
841bc85
drm/client: Remove pitch from struct drm_client_buffer
Oct 27, 2025
60f1a2e
drm/client: Move dumb-buffer handling to drm_client_framebuffer_create()
Oct 27, 2025
0763282
drm/client: Inline drm_client_buffer_addfb() and _rmfb()
Oct 27, 2025
329731b
drm/client: Deprecate struct drm_client_buffer.gem
Oct 27, 2025
a6325e2
drm/client: Remove drm_client_framebuffer_delete()
Oct 27, 2025
a7d172b
drm/log: Fix infinite loop when scale is too large for display
Jul 29, 2026
67ac7e0
spi: virtio: mark device ready before registering the controller
Aug 13, 2026
7e35120
erofs: fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS on some UP platforms
Aug 12, 2026
e5e6ce7
drm/vmwgfx: Set surface-framebuffer GEM objects
Nov 4, 2025
192f445
firewire: ohci: initialize page array to use alloc_pages_bulk() corre…
Feb 28, 2026
b7ce4b3
ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r
Aug 8, 2026
1f99e9a
Linux 6.18.46
Aug 23, 2026
450fe8f
serial: sc16is7xx: rename EFR mutex with generic name
Aug 20, 2026
c5a1234
serial: sc16is7xx: use guards for simple mutex locks
Aug 20, 2026
755d0b7
serial: sc16is7xx: enable THRI before filling TX FIFO
Aug 20, 2026
00e2baf
xfs: add a xchk_ip_set_corrupt helper
Aug 24, 2026
8d678be
xfs: rtsummary scrub should treat rtbitmap corruption errors as an xr…
Aug 24, 2026
a05a1b6
xfs: hoist per-bucket unlinked list check to helper
Aug 24, 2026
159d162
xfs: don't livelock in scrub on a circular unlinked list
Aug 24, 2026
0c55707
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
Jul 9, 2026
d4b1a13
Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept
Aug 7, 2026
d2ab084
iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown
Jun 29, 2026
7596354
iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process …
Aug 6, 2026
65aceb4
ALSA: FCP: Use a private URB for the notification endpoint
Aug 9, 2026
4305e4b
ALSA: scarlett2: Use a private URB for the notification endpoint
Aug 9, 2026
e971d95
rndis_host: add overflow check in rndis_rx_fixup()
Jul 9, 2026
61dc1a3
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
Aug 4, 2026
3da64f2
io_uring/futex: don't mark futex wake requests as inflight
Jul 30, 2026
f20c2c3
ALSA: dummy: Check card index validity at probe
Aug 6, 2026
b6a768a
io_uring/cmd: fix iovec leak when the async cmd is not recycled
Aug 2, 2026
4074ae2
io_uring/io-wq: fix worker accounting when canceling creation callbacks
Aug 11, 2026
45c9451
io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()
Aug 2, 2026
15ccf53
io_uring/uring_cmd: don't skip completion for a synchronous multishot…
Aug 15, 2026
6176313
ocfs2: fix missing metadata reservation for large xattrs
Jul 24, 2026
164ca33
null_blk: fix UBSAN shift-out-of-bounds when zone_size is 0 or overflows
Aug 8, 2026
e11f5b4
kcov: fix data corruption and race conditions on PREEMPT_RT
Jul 15, 2026
4902a5c
ext4: stop retrying saturated xattr cache entries
Aug 2, 2026
e447f7e
nilfs2: reject invalid block index in GC ioctl
Jul 2, 2026
fb5980f
ext4: clear error before retrying inode xattr space fallback
Jul 8, 2026
5f46f08
ext4: avoid tail write_begin walk for uptodate folios
Jun 9, 2026
f3d2fa3
ext4: propagate errors from fast commit range replay
Jul 8, 2026
458776a
ext4: don't enable DAX on new encrypted files
Jul 30, 2026
e0e7f46
ext4: fix incorrect function call when initializing s_resgid
Jul 27, 2026
184c1a8
xfs: validate attr entry pointer before field access
Jul 28, 2026
cb8246e
libceph: fix OOB read in decode_watchers() via missing bounds check
Aug 24, 2026
a56773e
nfc: digital: clamp SENSF_RES length to the destination buffer
Jun 3, 2026
db7e464
nfc: fdp: bound the device-reported read length and fix an skb leak
Jun 17, 2026
d0902a7
nfc: microread: validate target discovery payload lengths
Jul 23, 2026
e87527b
nfc: llcp: bound the connect_sn TLV walk to the skb
Jul 9, 2026
2d23959
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers
Jun 22, 2026
e969e98
nfc: llcp: reject PDUs shorter than the LLCP header
Jul 14, 2026
2f5d093
nfc: pn533: purge fragmented skbs during cleanup
Jul 20, 2026
bfcca5f
nfc: st21nfca: validate ATR_REQ length against the received frame
Jul 11, 2026
9620a91
nfc: nci: add data_len bound checks to activation parameter extractors
Jun 12, 2026
2f08dbc
nfc: nci: fix out-of-bounds write in nci_target_auto_activated()
Jun 22, 2026
0d4b5cf
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers
Jun 26, 2026
20892d2
nfc: nci: free destination parameters when closing a connection
Jul 21, 2026
f034150
drm/xe: Fix DPT allocation paths.
Jun 30, 2026
d9d1a67
ipv4: reject undersized MTUs in ip_do_fragment()
Aug 13, 2026
3dc98e5
ipv6: fix use-after-free in ip6_finish_output2()
Aug 12, 2026
364edae
mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()
Jul 9, 2026
23a475f
dmaengine: fsl-edma: Add error handling for devm_kasprintf
Jul 6, 2026
b26189d
nvmet-auth: zero the AUTH_RECEIVE response buffer
Jul 2, 2026
8bce9cd
nvmet-fc: fix invalid free in LS IOD error path
Jul 29, 2026
6d27199
nvmet-tcp: bound SGL data length before allocating command buffers
Jul 9, 2026
9c95f7e
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations
Jul 27, 2026
20be486
nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()
Jul 30, 2026
f316502
nvmet: pci-epf: put CQ ref on create_cq mapping failure
Aug 4, 2026
defc59e
mptcp: pm: use for_each_subflow helper
Aug 24, 2026
714c6d1
mptcp: pm: rename add_entry structure to add_addr
Aug 24, 2026
6fa2064
mptcp: pm: uniform announced addresses helpers
Aug 24, 2026
9fe5eeb
mptcp: pm: fix memory leak from alloc-during-teardown race
Aug 24, 2026
b6baab7
ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
Aug 24, 2026
02a88f8
HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad U…
Jul 6, 2026
62ec3c5
HID: magicmouse: re-enable multitouch after reset-resume
Jul 25, 2026
15b60ad
HID: magicmouse: do not keep a stale msc->input if no input is claimed
Jul 29, 2026
ace7fc4
HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPOR…
Apr 16, 2026
9a1d7c5
HID: core: fix OOB read of field->usage in hid_set_field()
Jul 26, 2026
4529c03
HID: pidff: fix OOB write when hid->inputs is empty
Jul 26, 2026
39fc615
net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
Aug 13, 2026
0ea8f06
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Jun 27, 2026
936ea65
Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard
Aug 24, 2026
f303f6a
Input: atkbd - skip deactivate for HONOR ZQC-P
Aug 24, 2026
2b92e55
futex/pi: Reject cross-mm private futex owners
Aug 25, 2026
4da67de
futex: Sanitize and document task_struct::futex::state transitions
Aug 25, 2026
fdf538b
futex/pi: Plug private futex exec() race
Aug 25, 2026
86d12b3
futex: Fix race on the initial mm->futex.phash.ref allocation
Aug 25, 2026
942b89f
futex: Fix might_sleep() warning in futex_pivot_pending()
Aug 25, 2026
51cfd1a
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()
Jul 15, 2026
268679f
HID: nintendo: register input device after capabilities are set
Jul 30, 2026
5efcd7b
HID: nintendo: stop device IO before hid_hw_stop on probe failure
Jul 30, 2026
1fa1591
HID: core: fix number/pointer type confusion on long items
Jul 3, 2026
8406d4b
HID: sensor: custom: Fix use-after-free in enable_sensor
Jul 7, 2026
849e537
HID: uclogic: fix use-after-free of inrange_timer on remove
Jul 14, 2026
608f8fd
HID: hyperv: validate initial device info bounds
Jul 10, 2026
39a3afb
Bluetooth: hci_event: fix LE list UAF on reset
Jul 30, 2026
e3f82e8
Bluetooth: hci_event: validate LE Set CIG Parameters response
Aug 1, 2026
fe93a69
Bluetooth: hci_sync: Fix accept list UAF during suspend
Aug 1, 2026
753af97
Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync
Aug 7, 2026
1f6d1f2
Bluetooth: ISO: zero the sockaddr before returning it in getname
Aug 6, 2026
b7d9edc
Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255
Aug 6, 2026
e1534d4
Bluetooth: hci_aml: validate firmware segment lengths
Jul 30, 2026
dba60d2
futex: Avoid private hash use-after-free on final put
Aug 25, 2026
5b4f2be
ptp: vmclock: prevent read-only mappings from becoming writable
Aug 13, 2026
3ce832e
net: gro: properly validate BIG TCP aggregation criteria
Aug 27, 2026
7519e95
Linux 6.18.47
Aug 27, 2026
c49f04e
inet: frags: strip GSO state from fragments before reassembly
Aug 27, 2026
5bbb9c9
Linux 6.18.48
Aug 28, 2026
24ccab4
Record v6.18.46 as merged
Sep 1, 2026
9e67f04
Merge tag 'v6.18.48' into NAS-142951-26.0.0-RC.1
Sep 1, 2026
3973b55
Bump changelog for 6.18.48+truenas
Aug 31, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
VERSION = 6
PATCHLEVEL = 18
SUBLEVEL = 46
SUBLEVEL = 48
NAME = Baby Opossum Posse

ifndef EXTRAVERSION
Expand Down
10 changes: 8 additions & 2 deletions drivers/block/null_blk/zoned.c
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,8 @@ static inline sector_t mb_to_sects(unsigned long mb)

static inline unsigned int null_zone_no(struct nullb_device *dev, sector_t sect)
{
if (WARN_ON_ONCE(!dev->zone_size_sects))
return 0;
return sect >> ilog2(dev->zone_size_sects);
}

Expand Down Expand Up @@ -56,8 +58,8 @@ int null_init_zoned_dev(struct nullb_device *dev,
sector_t sector = 0;
unsigned int i;

if (!is_power_of_2(dev->zone_size)) {
pr_err("zone_size must be power-of-two\n");
if (!dev->zone_size || !is_power_of_2(dev->zone_size)) {
pr_err("zone_size must be non-zero power-of-two\n");
return -EINVAL;
}
if (dev->zone_size > dev->size) {
Expand Down Expand Up @@ -88,6 +90,10 @@ int null_init_zoned_dev(struct nullb_device *dev,
zone_capacity_sects = mb_to_sects(dev->zone_capacity);
dev_capacity_sects = mb_to_sects(dev->size);
dev->zone_size_sects = mb_to_sects(dev->zone_size);
if (!dev->zone_size_sects) {
pr_err("zone_size too large or too small, leads to zero sectors\n");
return -EINVAL;
}
dev->nr_zones = round_up(dev_capacity_sects, dev->zone_size_sects)
>> ilog2(dev->zone_size_sects);

Expand Down
18 changes: 16 additions & 2 deletions drivers/bluetooth/hci_aml.c
Original file line number Diff line number Diff line change
Expand Up @@ -247,7 +247,7 @@ static int aml_download_firmware(struct hci_dev *hdev, const char *fw_name)
struct hci_uart *hu = hci_get_drvdata(hdev);
struct aml_serdev *amldev = serdev_device_get_drvdata(hu->serdev);
const struct firmware *firmware = NULL;
struct aml_fw_len *fw_len = NULL;
const struct aml_fw_len *fw_len = NULL;
u8 *iccm_start = NULL, *dccm_start = NULL;
u32 iccm_len, dccm_len;
u32 value = 0;
Expand Down Expand Up @@ -281,7 +281,21 @@ static int aml_download_firmware(struct hci_dev *hdev, const char *fw_name)
goto exit;
}

fw_len = (struct aml_fw_len *)firmware->data;
if (firmware->size < sizeof(*fw_len)) {
bt_dev_err(hdev, "Firmware is too small for its header");
ret = -EINVAL;
goto exit;
}

fw_len = (const struct aml_fw_len *)firmware->data;
if (fw_len->iccm_len < amldev->aml_dev_data->iccm_offset ||
fw_len->iccm_len > firmware->size - sizeof(*fw_len) ||
fw_len->dccm_len > firmware->size - sizeof(*fw_len) -
fw_len->iccm_len) {
bt_dev_err(hdev, "Invalid firmware segment lengths");
ret = -EINVAL;
goto exit;
}

/* Download ICCM */
iccm_start = (u8 *)(firmware->data) + sizeof(struct aml_fw_len)
Expand Down
2 changes: 2 additions & 0 deletions drivers/dma/fsl-edma-main.c
Original file line number Diff line number Diff line change
Expand Up @@ -414,6 +414,8 @@ static int fsl_edma3_irq_init(struct platform_device *pdev, struct fsl_edma_engi

errirq_name = devm_kasprintf(&pdev->dev, GFP_KERNEL, "%s-err",
dev_name(&pdev->dev));
if (!errirq_name)
return -ENOMEM;

ret = devm_request_irq(&pdev->dev, fsl_edma->errirq, fsl_edma3_err_handler_shared,
0, errirq_name, fsl_edma);
Expand Down
32 changes: 8 additions & 24 deletions drivers/gpu/drm/xe/display/xe_fb_pin.c
Original file line number Diff line number Diff line change
Expand Up @@ -101,30 +101,14 @@ static int __xe_pin_fb_vma_dpt(const struct intel_framebuffer *fb,
dpt_size = ALIGN(intel_rotation_info_size(&view->rotated) * 8,
XE_PAGE_SIZE);

if (IS_DGFX(xe))
dpt = xe_bo_create_pin_map_at_novm(xe, tile0,
dpt_size, ~0ull,
ttm_bo_type_kernel,
XE_BO_FLAG_VRAM0 |
XE_BO_FLAG_GGTT |
XE_BO_FLAG_PAGETABLE,
alignment, false);
else
dpt = xe_bo_create_pin_map_at_novm(xe, tile0,
dpt_size, ~0ull,
ttm_bo_type_kernel,
XE_BO_FLAG_STOLEN |
XE_BO_FLAG_GGTT |
XE_BO_FLAG_PAGETABLE,
alignment, false);
if (IS_ERR(dpt))
dpt = xe_bo_create_pin_map_at_novm(xe, tile0,
dpt_size, ~0ull,
ttm_bo_type_kernel,
XE_BO_FLAG_SYSTEM |
XE_BO_FLAG_GGTT |
XE_BO_FLAG_PAGETABLE,
alignment, false);
dpt = xe_bo_create_pin_map_at_novm(xe, tile0,
dpt_size, ~0ull,
ttm_bo_type_kernel,
XE_BO_FLAG_VRAM_IF_DGFX(tile0) |
XE_BO_FLAG_GGTT |
XE_BO_FLAG_PAGETABLE |
XE_BO_FLAG_SCANOUT,
alignment, false);
if (IS_ERR(dpt))
return PTR_ERR(dpt);

Expand Down
11 changes: 9 additions & 2 deletions drivers/hid/hid-core.c
Original file line number Diff line number Diff line change
Expand Up @@ -379,6 +379,9 @@ static int hid_add_field(struct hid_parser *parser, unsigned report_type, unsign

static u32 item_udata(struct hid_item *item)
{
if (item->format != HID_ITEM_FORMAT_SHORT)
return 0;

switch (item->size) {
case 1: return item->data.u8;
case 2: return item->data.u16;
Expand All @@ -389,6 +392,9 @@ static u32 item_udata(struct hid_item *item)

static s32 item_sdata(struct hid_item *item)
{
if (item->format != HID_ITEM_FORMAT_SHORT)
return 0;

switch (item->size) {
case 1: return item->data.s8;
case 2: return item->data.s16;
Expand Down Expand Up @@ -1925,13 +1931,14 @@ int hid_set_field(struct hid_field *field, unsigned offset, __s32 value)

size = field->report_size;

hid_dump_input(field->report->device, field->usage + offset, value);

if (offset >= field->report_count) {
hid_err(field->report->device, "offset (%d) exceeds report_count (%d)\n",
offset, field->report_count);
return -1;
}

hid_dump_input(field->report->device, field->usage + offset, value);

if (field->logical_minimum < 0) {
if (value != snto32(s32ton(value, size), size)) {
hid_err(field->report->device, "value %d is out of range\n", value);
Expand Down
27 changes: 24 additions & 3 deletions drivers/hid/hid-hyperv.c
Original file line number Diff line number Diff line change
Expand Up @@ -171,18 +171,32 @@ static void mousevsc_free_device(struct mousevsc_dev *device)
}

static void mousevsc_on_receive_device_info(struct mousevsc_dev *input_device,
struct synthhid_device_info *device_info)
struct synthhid_device_info *device_info,
u32 device_info_size)
{
int ret = 0;
struct hid_descriptor *desc;
struct mousevsc_prt_msg ack;
size_t desc_offset;
size_t desc_size;

input_device->dev_info_status = -ENOMEM;

if (device_info_size < sizeof(*device_info)) {
input_device->dev_info_status = -EINVAL;
goto cleanup;
}

input_device->hid_dev_info = device_info->hid_dev_info;
desc = &device_info->hid_descriptor;
desc_offset = offsetof(struct synthhid_device_info, hid_descriptor);
desc_size = device_info_size - desc_offset;
if (desc->bLength == 0)
goto cleanup;
if (desc->bLength < sizeof(*desc) || desc->bLength > desc_size) {
input_device->dev_info_status = -EINVAL;
goto cleanup;
}

/* The pointer is not NULL when we resume from hibernation */
kfree(input_device->hid_desc);
Expand All @@ -197,6 +211,10 @@ static void mousevsc_on_receive_device_info(struct mousevsc_dev *input_device,
input_device->dev_info_status = -EINVAL;
goto cleanup;
}
if (input_device->report_desc_size > desc_size - desc->bLength) {
input_device->dev_info_status = -EINVAL;
goto cleanup;
}

/* The pointer is not NULL when we resume from hibernation */
kfree(input_device->report_desc);
Expand Down Expand Up @@ -273,14 +291,17 @@ static void mousevsc_on_receive(struct hv_device *device,
break;

case SYNTH_HID_INITIAL_DEVICE_INFO:
WARN_ON(pipe_msg->size < sizeof(struct hv_input_dev_info));
if (WARN_ON_ONCE(pipe_msg->size <
sizeof(struct synthhid_device_info)))
break;

/*
* Parse out the device info into device attr,
* hid desc and report desc
*/
mousevsc_on_receive_device_info(input_dev,
(struct synthhid_device_info *)pipe_msg->data);
(struct synthhid_device_info *)pipe_msg->data,
pipe_msg->size);
break;
case SYNTH_HID_INPUT_REPORT:
input_report =
Expand Down
3 changes: 3 additions & 0 deletions drivers/hid/hid-input.c
Original file line number Diff line number Diff line change
Expand Up @@ -374,6 +374,9 @@ static const struct hid_device_id hid_battery_quirks[] = {
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_APPLE,
USB_DEVICE_ID_APPLE_MAGICTRACKPAD),
HID_BATTERY_QUIRK_IGNORE },
{ HID_BLUETOOTH_DEVICE(BT_VENDOR_ID_APPLE,
USB_DEVICE_ID_APPLE_MAGICTRACKPAD2_USBC),
HID_BATTERY_QUIRK_AVOID_QUERY },
{ HID_BLUETOOTH_DEVICE(USB_VENDOR_ID_ELECOM,
USB_DEVICE_ID_ELECOM_BM084),
HID_BATTERY_QUIRK_IGNORE },
Expand Down
64 changes: 63 additions & 1 deletion drivers/hid/hid-magicmouse.c
Original file line number Diff line number Diff line change
Expand Up @@ -390,6 +390,10 @@ static int magicmouse_raw_event(struct hid_device *hdev,
struct input_dev *input = msc->input;
int x = 0, y = 0, ii, clicks = 0, npoints;

/* Protect against zero sized recursive calls from DOUBLE_REPORT_ID */
if (size < 1)
return 0;

switch (data[0]) {
case TRACKPAD_REPORT_ID:
case TRACKPAD2_BT_REPORT_ID:
Expand Down Expand Up @@ -490,6 +494,18 @@ static int magicmouse_raw_event(struct hid_device *hdev,
/* Sometimes the trackpad sends two touch reports in one
* packet.
*/

/* Ensure that we have at least 2 elements (report type and size) */
if (size < 2)
return 0;

if (size < data[1] + 2) {
hid_warn(hdev,
"received report length (%d) was smaller than specified (%d)",
size, data[1] + 2);
return 0;
}

magicmouse_raw_event(hdev, report, data + 2, data[1]);
magicmouse_raw_event(hdev, report, data + 2 + data[1],
size - 2 - data[1]);
Expand Down Expand Up @@ -812,6 +828,12 @@ static bool is_usb_magictrackpad2(__u32 vendor, __u32 product)
product == USB_DEVICE_ID_APPLE_MAGICTRACKPAD2_USBC;
}

static bool is_bt_magictrackpad2(__u32 vendor, __u32 product)
{
return vendor == BT_VENDOR_ID_APPLE &&
product == USB_DEVICE_ID_APPLE_MAGICTRACKPAD2_USBC;
}

static int magicmouse_fetch_battery(struct hid_device *hdev)
{
#ifdef CONFIG_HID_BATTERY_STRENGTH
Expand All @@ -820,7 +842,8 @@ static int magicmouse_fetch_battery(struct hid_device *hdev)

if (!hdev->battery ||
(!is_usb_magicmouse2(hdev->vendor, hdev->product) &&
!is_usb_magictrackpad2(hdev->vendor, hdev->product)))
!is_usb_magictrackpad2(hdev->vendor, hdev->product) &&
!is_bt_magictrackpad2(hdev->vendor, hdev->product)))
return -1;

report_enum = &hdev->report_enum[hdev->battery_report_type];
Expand Down Expand Up @@ -882,6 +905,16 @@ static int magicmouse_probe(struct hid_device *hdev,
return ret;
}

/*
* When hidinput_connect() fails it frees every input device it
* created, but that does not fail hid_hw_start(): the core simply
* does not claim an input. msc->input, cached in ->input_mapping
* while the report descriptor was parsed, would then be a dangling
* pointer that passes every NULL check. Trust the core's claim.
*/
if (!(hdev->claimed & HID_CLAIMED_INPUT))
msc->input = NULL;

if (is_usb_magicmouse2(id->vendor, id->product) ||
is_usb_magictrackpad2(id->vendor, id->product)) {
timer_setup(&msc->battery_timer, magicmouse_battery_timer_tick, 0);
Expand Down Expand Up @@ -953,6 +986,16 @@ static int magicmouse_probe(struct hid_device *hdev,
schedule_delayed_work(&msc->work, msecs_to_jiffies(500));
}

/*
* Query the Bluetooth Magic Trackpad USB-C battery as done for USB.
* Start io first: probe holds driver_input_lock and the synchronous
* GET_REPORT reply would otherwise be dropped.
*/
if (is_bt_magictrackpad2(id->vendor, id->product)) {
hid_device_io_start(hdev);
magicmouse_fetch_battery(hdev);
}

return 0;
err_stop_hw:
if (is_usb_magicmouse2(id->vendor, id->product) ||
Expand All @@ -977,6 +1020,22 @@ static void magicmouse_remove(struct hid_device *hdev)
hid_hw_stop(hdev);
}

#ifdef CONFIG_PM
static int magicmouse_reset_resume(struct hid_device *hdev)
{
struct magicmouse_sc *msc = hid_get_drvdata(hdev);

/* The device drops out of multitouch mode on resume; re-send the
* enable report. Only the HID_TYPE_USBMOUSE interface accepts it, and
* it must be deferred. Sending it inline here is too early.
*/
if (msc && hdev->type == HID_TYPE_USBMOUSE)
schedule_delayed_work(&msc->work, msecs_to_jiffies(500));

return 0;
}
#endif

static const __u8 *magicmouse_report_fixup(struct hid_device *hdev, __u8 *rdesc,
unsigned int *rsize)
{
Expand Down Expand Up @@ -1040,6 +1099,9 @@ static struct hid_driver magicmouse_driver = {
.event = magicmouse_event,
.input_mapping = magicmouse_input_mapping,
.input_configured = magicmouse_input_configured,
#ifdef CONFIG_PM
.reset_resume = magicmouse_reset_resume,
#endif
};
module_hid_driver(magicmouse_driver);

Expand Down
Loading