Your message dated Fri, 02 Jan 2026 10:47:16 +0000
with message-id <[email protected]>
and subject line Bug#1106411: fixed in linux 6.1.159-1
has caused the Debian Bug report #1106411,
regarding linux-image-6.12.27-amd64: kernel NULL pointer dereference in
bmc150_accel_core
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1106411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1106411
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: src:linux
Version: 6.12.27-1
Severity: important
X-Debbugs-Cc: [email protected]
User: [email protected]
Usertags: amd64
Dear Maintainer,
I noticed a kernel BUG line in the logs.
> BUG: kernel NULL pointer dereference, address: 0000000000000001
-- Package-specific info:
** Version:
Linux version 6.12.27-amd64 ([email protected])
(x86_64-linux-gnu-gcc-14 (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for
Debian) 2.44) #1 SMP PREEMPT_DYNAMIC Debian 6.12.27-1 (2025-05-06)
** Command line:
BOOT_IMAGE=/vmlinuz-6.12.27-amd64 root=/dev/mapper/spisula--vg-root ro quiet
** Tainted: D (128)
* kernel died recently, i.e. there was an OOPS or BUG
** Kernel log:
[ 15.089146] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
[ 15.089148] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
[ 15.089149] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
[ 15.089151] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
[ 15.089153] FS: 00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000)
knlGS:0000000000000000
[ 15.089155] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 15.089157] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
[ 15.089159] Call Trace:
[ 15.089163] <TASK>
[ 15.089167] bmc150_accel_buffer_postenable+0x5d/0x90 [bmc150_accel_core]
[ 15.089173] __iio_update_buffers+0x731/0xb20 [industrialio]
[ 15.089198] enable_store+0x84/0xe0 [industrialio]
[ 15.089214] kernfs_fop_write_iter+0x13b/0x1f0
[ 15.089222] vfs_write+0x28d/0x450
[ 15.089230] ksys_write+0x6d/0xf0
[ 15.089235] do_syscall_64+0x82/0x190
[ 15.089241] ? syscall_exit_to_user_mode+0x4d/0x210
[ 15.089245] ? do_syscall_64+0x8e/0x190
[ 15.089248] ? __memcg_slab_free_hook+0xf7/0x140
[ 15.089253] ? __x64_sys_close+0x3c/0x80
[ 15.089255] ? kmem_cache_free+0x3ee/0x440
[ 15.089260] ? syscall_exit_to_user_mode+0x4d/0x210
[ 15.089263] ? do_syscall_64+0x8e/0x190
[ 15.089265] ? kernfs_fop_write_iter+0x9d/0x1f0
[ 15.089268] ? vfs_write+0x28d/0x450
[ 15.089272] ? syscall_exit_to_user_mode+0x4d/0x210
[ 15.089275] ? clear_bhb_loop+0x25/0x80
[ 15.089279] ? clear_bhb_loop+0x25/0x80
[ 15.089281] ? clear_bhb_loop+0x25/0x80
[ 15.089284] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[ 15.089288] RIP: 0033:0x7f10b31369ee
[ 15.089319] Code: 08 0f 85 f5 4b ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce
4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e
0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
[ 15.089321] RSP: 002b:00007ffc6dbe57d8 EFLAGS: 00000246 ORIG_RAX:
0000000000000001
[ 15.089324] RAX: ffffffffffffffda RBX: 00007f10b2d30940 RCX: 00007f10b31369ee
[ 15.089325] RDX: 0000000000000001 RSI: 00007ffc6dbe5980 RDI: 0000000000000009
[ 15.089327] RBP: 00007ffc6dbe5980 R08: 0000000000000000 R09: 0000000000000000
[ 15.089328] R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
[ 15.089329] R13: 0000559ac7f662a0 R14: 00007f10b3281e80 R15: 0000000000000001
[ 15.089333] </TASK>
[ 15.089333] Modules linked in: snd_hda_ext_core snd_soc_core snd_compress
snd_pcm_dmaengine overlay bnep zram processor_thermal_device_pci_legacy
snd_hda_intel lz4hc_compress snd_intel_dspcfg lz4_compress i915(+)
processor_thermal_device x86_pkg_temp_thermal uvcvideo intel_powerclamp
snd_intel_sdw_acpi processor_thermal_wt_hint coretemp videobuf2_vmalloc iwlmvm
btusb snd_hda_codec binfmt_misc processor_thermal_rfim drm_buddy kvm_intel uvc
drm_display_helper btrtl snd_hda_core mac80211 intel_rapl_msr
processor_thermal_rapl videobuf2_memops nls_ascii btintel snd_hwdep cec
intel_rapl_common kvm libarc4 bmc150_accel_i2c videobuf2_v4l2 nls_cp437 btbcm
snd_pcm acer_wmi rc_core processor_thermal_wt_req bmc150_accel_core iwlwifi
irqbypass videodev vfat btmtk intel_pmc_core snd_timer mei_hdcp mei_pxp
sparse_keymap ttm processor_thermal_power_floor industrialio_triggered_buffer
rapl fat videobuf2_common rtsx_usb_ms cfg80211 intel_vsec snd bluetooth
platform_profile mei_me drm_kms_helper processor_thermal_mbox kfifo_buf
[ 15.089389] intel_cstate pcspkr mc wmi_bmof memstick pmt_telemetry
soundcore rfkill mei i2c_algo_bit intel_soc_dts_iosf industrialio
int3400_thermal ac acer_wireless int3403_thermal pmt_class soc_button_array
button acpi_thermal_rel int340x_thermal_zone joydev evdev msr parport_pc ppdev
lp parport efi_pstore configfs nfnetlink efivarfs ip_tables x_tables autofs4
ext4 crc16 mbcache jbd2 crc32c_generic rtsx_usb_sdmmc rtsx_usb dm_crypt dm_mod
crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel hid_multitouch
sha512_ssse3 hid_generic sha256_ssse3 xhci_pci sha1_ssse3 r8169 i2c_hid_acpi
sdhci_pci xhci_hcd aesni_intel nvme realtek i2c_hid intel_lpss_pci cqhci
usbcore gf128mul nvme_core mdio_devres hid intel_lpss sdhci i2c_i801 wdat_wdt
crypto_simd cryptd watchdog serio_raw video i2c_smbus lpc_ich libphy mmc_core
usb_common idma64 drm nvme_auth battery wmi
[ 15.089449] CR2: 0000000000000001
[ 15.089451] ---[ end trace 0000000000000000 ]---
[ 15.207536] RIP: 0010:bmc150_accel_set_interrupt+0x68/0x120
[bmc150_accel_core]
[ 15.207561] Code: 84 86 00 00 00 ba 01 00 00 00 f0 0f c1 10 83 c2 01 83 fa
01 7f 64 49 8b 3c 24 be 01 00 00 00 e8 5e fc ff ff 89 c3 85 c0 75 52 <41> 0f b6
55 01 41 0f b6 75 00 45 31 c9 45 31 c0 49 8b 3c 24 6a 00
[ 15.207563] RSP: 0018:ffffb83f40d27ab0 EFLAGS: 00010246
[ 15.207567] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00000000ffffff01
[ 15.207569] RDX: ffffffff83326d30 RSI: 0000000000000202 RDI: ffff9a9190947504
[ 15.207571] RBP: ffff9a9190947420 R08: ffff9a919c498be8 R09: 0000000000000000
[ 15.207572] R10: ffffb83f40d27ac8 R11: 0000000000000009 R12: ffff9a919c498d50
[ 15.207574] R13: 0000000000000000 R14: 0000000000000001 R15: ffff9a919c498b30
[ 15.207575] FS: 00007f10b2d30940(0000) GS:ffff9a91fbd00000(0000)
knlGS:0000000000000000
[ 15.207577] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 15.207579] CR2: 0000000000000001 CR3: 000000011c33c000 CR4: 0000000000352ef0
[ 15.207582] note: iio-sensor-prox[804] exited with irqs disabled
[ 15.281160] Generic FE-GE Realtek PHY r8169-0-200:00: attached PHY driver
(mii_bus:phy_addr=r8169-0-200:00, irq=MAC)
[ 15.300168] snd_hda_codec_realtek hdaudioC0D0: autoconfig for ALC256:
line_outs=1 (0x14/0x0/0x0/0x0/0x0) type:speaker
[ 15.300176] snd_hda_codec_realtek hdaudioC0D0: speaker_outs=0
(0x0/0x0/0x0/0x0/0x0)
[ 15.300179] snd_hda_codec_realtek hdaudioC0D0: hp_outs=1
(0x21/0x0/0x0/0x0/0x0)
[ 15.300181] snd_hda_codec_realtek hdaudioC0D0: mono: mono_out=0x0
[ 15.300182] snd_hda_codec_realtek hdaudioC0D0: inputs:
[ 15.300184] snd_hda_codec_realtek hdaudioC0D0: Internal Mic=0x12
[ 15.300186] snd_hda_codec_realtek hdaudioC0D0: Headset Mic=0x19
[ 15.461236] r8169 0000:02:00.0 enp2s0: Link is Down
[ 15.666827] iwlwifi 0000:00:0c.0: Registered PHC clock: iwlwifi-PTP, with
index: 0
[ 15.749241] Bluetooth: hci0: Waiting for firmware download to complete
[ 15.749426] Bluetooth: hci0: Firmware loaded in 1795145 usecs
[ 15.749520] Bluetooth: hci0: Waiting for device to boot
[ 15.753647] input: HDA Digital PCBeep as
/devices/pci0000:00/0000:00:0e.0/sound/card0/input23
[ 15.753728] input: HDA Intel PCH Front Headphone as
/devices/pci0000:00/0000:00:0e.0/sound/card0/input24
[ 15.753797] input: HDA Intel PCH HDMI/DP,pcm=3 as
/devices/pci0000:00/0000:00:0e.0/sound/card0/input25
[ 15.753859] input: HDA Intel PCH HDMI/DP,pcm=7 as
/devices/pci0000:00/0000:00:0e.0/sound/card0/input26
[ 15.753929] input: HDA Intel PCH HDMI/DP,pcm=8 as
/devices/pci0000:00/0000:00:0e.0/sound/card0/input27
[ 15.763426] Bluetooth: hci0: Device booted in 13644 usecs
[ 15.764861] Bluetooth: hci0: Found Intel DDC parameters:
intel/ibt-17-16-1.ddc
[ 15.766480] Bluetooth: hci0: Applying Intel DDC parameters completed
[ 15.767483] Bluetooth: hci0: Firmware revision 0.1 build 201 week 12 2024
[ 15.769492] Bluetooth: hci0: HCI LE Coded PHY feature bit is set, but its
usage is not supported.
[ 15.825248] Bluetooth: MGMT ver 1.23
[ 15.862572] NET: Registered PF_ALG protocol family
[ 16.107882] Console: switching to colour frame buffer device 170x48
[ 16.186327] i915 0000:00:02.0: [drm] fb0: i915drmfb frame buffer device
[ 16.188401] Bluetooth: RFCOMM TTY layer initialized
[ 16.189294] Bluetooth: RFCOMM socket layer initialized
[ 16.190089] Bluetooth: RFCOMM ver 1.11
[ 18.899809] wlp0s12f0: authenticate with 14:91:82:2e:1c:5b (local
address=f4:b3:01:63:29:78)
[ 18.900292] wlp0s12f0: send auth to 14:91:82:2e:1c:5b (try 1/3)
[ 18.939856] wlp0s12f0: authenticated
[ 18.941129] wlp0s12f0: associate with 14:91:82:2e:1c:5b (try 1/3)
[ 18.960084] wlp0s12f0: RX AssocResp from 14:91:82:2e:1c:5b (capab=0x11
status=0 aid=2)
[ 18.963364] wlp0s12f0: associated
[ 19.726378] Lockdown: systemd-logind: hibernation is restricted; see man
kernel_lockdown.7
[ 20.032936] rfkill: input handler disabled
[ 56.015476] systemd-journald[486]: File
/var/log/journal/1ee1fc9b6cdc4cf895119313e2529972/user-1000.journal corrupted
or uncleanly shut down, renaming and replacing.
[ 56.441048] rfkill: input handler enabled
[ 57.651916] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching
to polling mode: last cmd=0x20bf8100
[ 58.655918] snd_hda_intel 0000:00:0e.0: No response from codec, disabling
MSI: last cmd=0x20bf8100
[ 59.663910] snd_hda_intel 0000:00:0e.0: azx_get_response timeout, switching
to single_cmd mode: last cmd=0x20bf8100
[ 59.664135] azx_single_wait_for_response: 119 callbacks suppressed
[ 71.688065] azx_single_send_cmd: 161 callbacks suppressed
** Model information
sys_vendor: Acer
product_name: TravelMate Spin B311R-31
product_version: V1.18
chassis_vendor: Acer
chassis_version: Chassis Version
bios_vendor: Insyde Corp.
bios_version: V1.18
board_vendor: GLK
board_name: Maracas_GL
board_version: V1.18
** Configuration for modprobe:
blacklist arkfb
blacklist aty128fb
blacklist atyfb
blacklist radeonfb
blacklist cirrusfb
blacklist cyber2000fb
blacklist kyrofb
blacklist matroxfb_base
blacklist mb862xxfb
blacklist neofb
blacklist pm2fb
blacklist pm3fb
blacklist s3fb
blacklist savagefb
blacklist sisfb
blacklist tdfxfb
blacklist tridentfb
blacklist vt8623fb
blacklist microcode
options snd_pcsp index=-2
options cx88_alsa index=-2
options snd_atiixp_modem index=-2
options snd_intel8x0m index=-2
options snd_via82xx_modem index=-2
options bonding max_bonds=0
options dummy numdummies=0
options ifb numifbs=0
** Loaded modules:
ccm
snd_seq_dummy
snd_hrtimer
snd_seq
snd_seq_device
snd_sof_pci_intel_apl
snd_sof_intel_hda_generic
rfcomm
soundwire_intel
cmac
soundwire_generic_allocation
algif_hash
soundwire_cadence
algif_skcipher
snd_sof_intel_hda_common
af_alg
snd_soc_hdac_hda
snd_sof_intel_hda_mlink
snd_sof_intel_hda
snd_hda_codec_hdmi
snd_sof_pci
snd_sof_xtensa_dsp
snd_sof
snd_sof_utils
snd_soc_acpi_intel_match
snd_soc_acpi
soundwire_bus
snd_hda_codec_realtek
snd_soc_avs
snd_hda_codec_generic
snd_soc_hda_codec
snd_hda_scodec_component
snd_hda_ext_core
snd_soc_core
snd_compress
snd_pcm_dmaengine
overlay
bnep
zram
processor_thermal_device_pci_legacy
snd_hda_intel
lz4hc_compress
snd_intel_dspcfg
lz4_compress
i915
processor_thermal_device
x86_pkg_temp_thermal
uvcvideo
intel_powerclamp
snd_intel_sdw_acpi
processor_thermal_wt_hint
coretemp
videobuf2_vmalloc
iwlmvm
btusb
snd_hda_codec
binfmt_misc
processor_thermal_rfim
drm_buddy
kvm_intel
uvc
drm_display_helper
btrtl
snd_hda_core
mac80211
intel_rapl_msr
processor_thermal_rapl
videobuf2_memops
nls_ascii
btintel
snd_hwdep
cec
intel_rapl_common
kvm
libarc4
bmc150_accel_i2c
videobuf2_v4l2
nls_cp437
btbcm
snd_pcm
acer_wmi
rc_core
processor_thermal_wt_req
bmc150_accel_core
iwlwifi
irqbypass
videodev
vfat
btmtk
intel_pmc_core
snd_timer
mei_hdcp
mei_pxp
sparse_keymap
ttm
processor_thermal_power_floor
industrialio_triggered_buffer
rapl
fat
videobuf2_common
rtsx_usb_ms
cfg80211
intel_vsec
snd
bluetooth
platform_profile
mei_me
drm_kms_helper
processor_thermal_mbox
kfifo_buf
intel_cstate
pcspkr
mc
wmi_bmof
memstick
pmt_telemetry
soundcore
rfkill
mei
i2c_algo_bit
intel_soc_dts_iosf
industrialio
int3400_thermal
ac
acer_wireless
int3403_thermal
pmt_class
soc_button_array
button
acpi_thermal_rel
int340x_thermal_zone
joydev
evdev
msr
parport_pc
ppdev
lp
parport
efi_pstore
configfs
nfnetlink
efivarfs
ip_tables
x_tables
autofs4
ext4
crc16
mbcache
jbd2
crc32c_generic
rtsx_usb_sdmmc
rtsx_usb
dm_crypt
dm_mod
crct10dif_pclmul
crc32_pclmul
crc32c_intel
ghash_clmulni_intel
hid_multitouch
sha512_ssse3
hid_generic
sha256_ssse3
xhci_pci
sha1_ssse3
r8169
i2c_hid_acpi
sdhci_pci
xhci_hcd
aesni_intel
nvme
realtek
i2c_hid
intel_lpss_pci
cqhci
usbcore
gf128mul
nvme_core
mdio_devres
hid
intel_lpss
sdhci
i2c_i801
wdat_wdt
crypto_simd
cryptd
watchdog
serio_raw
video
i2c_smbus
lpc_ich
libphy
mmc_core
usb_common
idma64
drm
nvme_auth
battery
wmi
** PCI devices:
00:00.0 Host bridge [0600]: Intel Corporation Gemini Lake Host Bridge
[8086:31f0] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0
IOMMU group: 1
00:00.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor Dynamic Platform and Thermal Framework Processor Participant
[8086:318c] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx+
Latency: 0
Interrupt: pin B routed to IRQ 24
IOMMU group: 1
Region 0: Memory at 80000000 (64-bit, non-prefetchable) [size=32K]
Capabilities: <access denied>
Kernel driver in use: proc_thermal
Kernel modules: processor_thermal_device_pci_legacy
00:00.3 System peripheral [0880]: Intel Corporation Celeron/Pentium Silver
Processor Gaussian Mixture Model [8086:3190] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 23
IOMMU group: 1
Region 0: Memory at a1318000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
00:02.0 VGA compatible controller [0300]: Intel Corporation GeminiLake [UHD
Graphics 600] [8086:3185] (rev 06) (prog-if 00 [VGA controller])
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 139
IOMMU group: 0
Region 0: Memory at a0000000 (64-bit, non-prefetchable) [size=16M]
Region 2: Memory at 90000000 (64-bit, prefetchable) [size=256M]
Region 4: I/O ports at 2000 [size=64]
Expansion ROM at 000c0000 [virtual] [disabled] [size=128K]
Capabilities: <access denied>
Kernel driver in use: i915
Kernel modules: i915
00:0c.0 Network controller [0280]: Intel Corporation Gemini Lake PCH CNVi WiFi
[8086:31dc] (rev 06)
Subsystem: Intel Corporation Wireless-AC 9560 [8086:0034]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 138
IOMMU group: 2
Region 0: Memory at a1310000 (64-bit, non-prefetchable) [size=16K]
Capabilities: <access denied>
Kernel driver in use: iwlwifi
Kernel modules: iwlwifi
00:0e.0 Audio device [0403]: Intel Corporation Celeron/Pentium Silver Processor
High Definition Audio [8086:3198] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 25
IOMMU group: 3
Region 0: Memory at a1314000 (64-bit, non-prefetchable) [size=16K]
Region 4: Memory at a1000000 (64-bit, non-prefetchable) [size=1M]
Capabilities: <access denied>
Kernel driver in use: snd_hda_intel
Kernel modules: snd_hda_intel, snd_soc_avs, snd_sof_pci_intel_apl
00:0f.0 Communication controller [0780]: Intel Corporation Celeron/Pentium
Silver Processor Trusted Execution Engine Interface [8086:319a] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 137
IOMMU group: 4
Region 0: Memory at a1319000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: mei_me
Kernel modules: mei_me
00:13.0 PCI bridge [0604]: Intel Corporation Gemini Lake PCI Express Root Port
[8086:31d8] (rev f6) (prog-if 00 [Normal decode])
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 122
IOMMU group: 5
Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
I/O behind bridge: [disabled] [16-bit]
Memory behind bridge: a1200000-a12fffff [size=1M] [32-bit]
Prefetchable memory behind bridge: [disabled] [64-bit]
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16- MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
00:14.0 PCI bridge [0604]: Intel Corporation Gemini Lake PCI Express Root Port
[8086:31d6] (rev f6) (prog-if 00 [Normal decode])
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 123
IOMMU group: 6
Bus: primary=00, secondary=02, subordinate=02, sec-latency=0
I/O behind bridge: 1000-1fff [size=4K] [16-bit]
Memory behind bridge: a1100000-a11fffff [size=1M] [32-bit]
Prefetchable memory behind bridge: [disabled] [64-bit]
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16- MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
00:15.0 USB controller [0c03]: Intel Corporation Celeron/Pentium Silver
Processor USB 3.0 xHCI Controller [8086:31a8] (rev 06) (prog-if 30 [XHCI])
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort-
<TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 132
IOMMU group: 7
Region 0: Memory at a1300000 (64-bit, non-prefetchable) [size=64K]
Capabilities: <access denied>
Kernel driver in use: xhci_hcd
Kernel modules: xhci_pci
00:16.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor I2C 0 [8086:31ac] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 27
IOMMU group: 8
Region 0: Memory at a131a000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a131b000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:16.3 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor I2C 3 [8086:31b2] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin D routed to IRQ 30
IOMMU group: 8
Region 0: Memory at a131c000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a131d000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:17.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor I2C 4 [8086:31b4] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 31
IOMMU group: 9
Region 0: Memory at a131e000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a131f000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:17.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor I2C 5 [8086:31b6] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin B routed to IRQ 32
IOMMU group: 9
Region 0: Memory at a1320000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a1321000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:17.2 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor I2C 6 [8086:31b8] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin C routed to IRQ 33
IOMMU group: 9
Region 0: Memory at a1322000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a1323000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:18.0 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor Serial IO UART Host Controller [8086:31bc] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 4
IOMMU group: 10
Region 0: Memory at a1324000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a1325000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:18.1 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor Serial IO UART Host Controller [8086:31be] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin B routed to IRQ 5
IOMMU group: 10
Region 0: Memory at a1326000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a1327000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:18.3 Signal processing controller [1180]: Intel Corporation Celeron/Pentium
Silver Processor Serial IO UART Host Controller [8086:31ee] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin D routed to IRQ 7
IOMMU group: 10
Region 0: Memory at a1328000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a1329000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
Kernel modules: intel_lpss_pci
00:1c.0 SD Host controller [0805]: Intel Corporation Celeron/Pentium Silver
Processor SDA Standard Compliant SD Host Controller [8086:31cc] (rev 06)
(prog-if 01)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 39
IOMMU group: 11
Region 0: Memory at a132a000 (64-bit, non-prefetchable) [size=4K]
Region 2: Memory at a132b000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: sdhci-pci
Kernel modules: sdhci_pci
00:1f.0 ISA bridge [0601]: Intel Corporation Celeron/Pentium Silver Processor
LPC Controller [8086:31e8] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=medium >TAbort-
<TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
IOMMU group: 12
Kernel modules: lpc_ich
00:1f.1 SMBus [0c05]: Intel Corporation Celeron/Pentium Silver Processor
Gaussian Mixture Model [8086:31d4] (rev 06)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx-
Status: Cap- 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort-
<TAbort- <MAbort- >SERR- <PERR- INTx-
Interrupt: pin A routed to IRQ 20
IOMMU group: 12
Region 0: Memory at a132c000 (64-bit, non-prefetchable) [size=256]
Region 4: I/O ports at 2040 [size=32]
Kernel driver in use: i801_smbus
Kernel modules: i2c_i801
01:00.0 Non-Volatile memory controller [0108]: Kingston Technology Company,
Inc. OM3PDP3 NVMe SSD [2646:500d] (rev 01) (prog-if 02 [NVM Express])
Subsystem: Kingston Technology Company, Inc. OM3PDP3 NVMe SSD
[2646:500d]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 22
IOMMU group: 13
Region 0: Memory at a1200000 (64-bit, non-prefetchable) [size=16K]
Capabilities: <access denied>
Kernel driver in use: nvme
Kernel modules: nvme
02:00.0 Ethernet controller [0200]: Realtek Semiconductor Co., Ltd.
RTL8111/8168/8211/8411 PCI Express Gigabit Ethernet Controller [10ec:8168] (rev
15)
Subsystem: Acer Incorporated [ALI] Device [1025:1430]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr-
Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort-
<MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 64 bytes
Interrupt: pin A routed to IRQ 22
IOMMU group: 14
Region 0: I/O ports at 1000 [size=256]
Region 2: Memory at a1104000 (64-bit, non-prefetchable) [size=4K]
Region 4: Memory at a1100000 (64-bit, non-prefetchable) [size=16K]
Capabilities: <access denied>
Kernel driver in use: r8169
Kernel modules: r8169
** USB devices:
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 001 Device 002: ID 04f2:b6db Chicony Electronics Co., Ltd 5MP World Facing
Bus 001 Device 003: ID 0408:a061 Quanta Computer, Inc. HD User Facing
Bus 001 Device 004: ID 0bda:0129 Realtek Semiconductor Corp. RTS5129 Card
Reader Controller
Bus 001 Device 005: ID 8087:0aaa Intel Corp. Bluetooth 9460/9560 Jefferson Peak
(JfP)
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
-- System Information:
Debian Release: 13.0
APT prefers testing
APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 6.12.27-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_DIE
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages linux-image-6.12.27-amd64 depends on:
ii initramfs-tools [linux-initramfs-tool] 0.147
ii kmod 34.2-2
ii linux-base 4.11
Versions of packages linux-image-6.12.27-amd64 recommends:
ii apparmor 4.1.0-1
Versions of packages linux-image-6.12.27-amd64 suggests:
pn debian-kernel-handbook <none>
ii firmware-linux-free 20241210-2
ii grub-efi-amd64 2.12-7
pn linux-doc-6.12 <none>
Versions of packages linux-image-6.12.27-amd64 is related to:
ii firmware-amd-graphics 20250410-2
pn firmware-atheros <none>
pn firmware-bnx2 <none>
pn firmware-bnx2x <none>
pn firmware-brcm80211 <none>
pn firmware-cavium <none>
pn firmware-cirrus <none>
pn firmware-intel-graphics <none>
pn firmware-intel-misc <none>
pn firmware-intel-sound <none>
pn firmware-ipw2x00 <none>
pn firmware-ivtv <none>
ii firmware-iwlwifi 20250410-2
pn firmware-libertas <none>
pn firmware-marvell-prestera <none>
pn firmware-mediatek <none>
ii firmware-misc-nonfree 20250410-2
pn firmware-myricom <none>
pn firmware-netronome <none>
pn firmware-netxen <none>
pn firmware-nvidia-graphics <none>
pn firmware-qcom-soc <none>
pn firmware-qlogic <none>
ii firmware-realtek 20250410-2
pn firmware-samsung <none>
pn firmware-siano <none>
pn firmware-ti-connectivity <none>
pn xen-hypervisor <none>
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: linux
Source-Version: 6.1.159-1
Done: Salvatore Bonaccorso <[email protected]>
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated linux package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 30 Dec 2025 23:20:29 +0100
Source: linux
Architecture: source
Version: 6.1.159-1
Distribution: bookworm
Urgency: medium
Maintainer: Debian Kernel Team <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 919350 1106411 1114557 1119232 1120602 1120680
Changes:
linux (6.1.159-1) bookworm; urgency=medium
.
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.159
- net/sched: sch_qfq: Fix null-deref in agg_dequeue (CVE-2025-40083)
- perf: Have get_perf_callchain() return NULL if crosstask and user are set
- [x86] bugs: Fix reporting of LFENCE retpoline
- EDAC/mc_sysfs: Increase legacy channel support to 16
- btrfs: zoned: refine extent allocator hint selection
- btrfs: scrub: replace max_t()/min_t() with clamp() in
scrub_throttle_dev_io()
- btrfs: always drop log root tree reference in btrfs_replay_log()
- btrfs: use smp_mb__after_atomic() when forcing COW in
create_pending_snapshot()
- arch: Add the macro COMPILE_OFFSETS to all the asm-offsets.c
- mptcp: pm: in-kernel: C-flag: handle late ADD_ADDR
- dt-bindings: usb: dwc3-imx8mp: dma-range is required only for imx8mp
- xhci: dbc: Provide sysfs option to configure dbc descriptors
- xhci: dbc: poll at different rate depending on data transfer activity
- xhci: dbc: Allow users to modify DbC poll interval via sysfs
- xhci: dbc: Improve performance by removing delay in transfer event
polling.
- xhci: dbc: Avoid event polling busyloop if pending rx transfers are
inactive.
- xhci: dbc: fix bogus 1024 byte prefix if ttyDBC read races with stall
event
- NFSD: Fix crash in nfsd4_read_release() (CVE-2025-40324)
- net: usb: asix_devices: Check return value of usbnet_get_endpoints
- fbcon: Set fb_display[i]->mode to NULL when the mode is released
- fbdev: atyfb: Check if pll_ops->init_pll failed
- ACPI: video: Fix use-after-free in acpi_video_switch_brightness()
(CVE-2025-40211)
- fbdev: bitblit: bound-check glyph index in bit_putcs* (CVE-2025-40322)*
- wifi: brcmfmac: fix crash while sending Action Frames in standalone AP
Mode (CVE-2025-40321)
- fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS
- fbdev: valkyriefb: Fix reference count leak in valkyriefb_init
- mptcp: restore window probe
- [x86] fpu: Ensure XFD state on signal delivery
- wifi: ath10k: Fix memory leak on unsupported WMI command
- [arm64] drm/msm/a6xx: Fix GMU firmware parser
- ALSA: usb-audio: fix control pipe direction
- bpf: Sync pending IRQ work before freeing ring buffer (CVE-2025-40319)
- scsi: ufs: core: Initialize value of an attribute returned by uic cmd
- bpf: Do not audit capability check in do_jit()
- [arm64] ASoC: fsl_sai: fix bit order for DSD format
- libbpf: Fix powerpc's stack register definition in bpf_tracing.h
- usbnet: Prevents free active kevent
- Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
(CVE-2025-40318)
- Bluetooth: btmtksdio: Add pmctrl handling for BT closed state during
reset
- Bluetooth: HCI: Fix tracking of advertisement set/instance 0x00
- Bluetooth: ISO: Add support for periodic adv reports processing
- Bluetooth: ISO: Fix another instance of dst_type handling
- [arm64,armhf] drm/etnaviv: fix flush sequence logic
- [arm64] net: hns3: return error code when function fails
- drm/amd/pm: fix smu table id bound check issue in smu_cmn_update_table()
- drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on Fiji
- drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on Iceland
- block: fix op_is_zone_mgmt() to handle REQ_OP_ZONE_RESET_ALL
- block: make REQ_OP_ZONE_OPEN a write operation
- regmap: slimbus: fix bus_context pointer in regmap init calls
(CVE-2025-40317)
- Reapply "Revert drm/amd/display: Enable Freesync Video Mode by default"
(Closes: #1119232)
- [s390x] pci: Restore IRQ unconditionally for the zPCI device
- net: phy: dp83867: Disable EEE support as not implemented
- mptcp: change 'first' as a parameter
- mptcp: drop bogus optimization in __mptcp_check_push()
- can: gs_usb: increase max interface to U8_MAX
- cacheinfo: Return error code in init_of_cache_level()
- cacheinfo: Check 'cache-unified' property to count cache leaves
- ACPI: PPTT: Remove acpi_find_cache_levels()
- ACPI: PPTT: Update acpi_find_last_cache_level() to acpi_get_cache_info()
- arch_topology: Build cacheinfo from primary CPU
- cacheinfo: Initialize variables in fetch_cache_info()
- cacheinfo: Fix LLC is not exported through sysfs
- drivers: base: cacheinfo: Update cpu_map_populated during CPU Hotplug
- [arm64] tegra: Update cache properties
- filemap: add a kiocb_invalidate_pages helper
- filemap: add a kiocb_invalidate_post_direct_write helper
- filemap: update ki_pos in generic_perform_write
- fs: factor out a direct_write_fallback helper
- direct_write_fallback(): on error revert the ->ki_pos update from
buffered
write
- block: open code __generic_file_write_iter for blkdev writes
- block: fix race between set_blocksize and read paths (CVE-2025-38073)
- nilfs2: fix deadlock warnings caused by lock dependency in init_nilfs()
- usb: gadget: f_fs: Fix epfile null pointer access after ep enable.
(CVE-2025-40315)
- drm/sysfb: Do not dereference NULL pointer in plane reset
- drm/sched: Fix race in drm_sched_entity_select_rq()
- [s390x] pci: Avoid deadlock between PCI error recovery and mlx5 crdump
- [armhf] soc: aspeed: socinfo: Add AST27xx silicon IDs
- bpf: Don't use %pK through printk
- pinctrl: single: fix bias pull up/down handling in pin_config_set
- [arm64] mmc: host: renesas_sdhi: Fix the actual clock
- memstick: Add timeout to prevent indefinite waiting
- cpufreq/longhaul: handle NULL policy in longhaul_exit
- [arm64,armhf] irqchip/gic-v2m: Handle Multiple MSI base IRQ Alignment
- ACPI: PRM: Skip handlers with NULL handler_address or NULL VA
- ACPI: scan: Add Intel CVS ACPI HIDs to acpi_ignore_dep_ids[]
- hwmon: (sbtsi_temp) AMD CPU extended temperature range support
- power: supply: sbs-charger: Support multiple devices
- [arm64] mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card
- ACPICA: dispatcher: Use acpi_ds_clear_operands() in
acpi_ds_call_control_method()
- [arm64] tee: allow a driver to allocate a tee_device without a pool
- nvmet-fc: avoid scheduling association deletion twice (CVE-2025-40343)
- nvme-fc: use lock accessing port_state and rport state (CVE-2025-40342)
- [arm64] video: backlight: lp855x_bl: Set correct EPROM start for LP8556
- tools/cpupower: fix error return value in cpupower_write_sysfs()
- cpuidle: Fail cpuidle device registration if there is one already
- futex: Don't leak robust_list pointer on exec race (CVE-2025-40341)
- bpf: Clear pfmemalloc flag when freeing all fragments
- nvme: Use non zero KATO for persistent discovery connections
- uprobe: Do not emulate/sstep original instruction when ip is changed
- [x86] hwmon: (asus-ec-sensors) increase timeout for locking ACPI mutex
- [x86] hwmon: (dell-smm) Add support for Dell OptiPlex 7040
- [x86] tools/cpupower: Fix incorrect size in cpuidle_state_disable()
- [x86] tools/power x86_energy_perf_policy: Fix incorrect fopen mode usage
- [x86] tools/power x86_energy_perf_policy: Enhance HWP enable
- [x86] tools/power x86_energy_perf_policy: Prefer driver HWP limits
- [armhf] mfd: stmpe: Remove IRQ domain upon removal
- [armhf] mfd: stmpe-i2c: Add missing MODULE_LICENSE
- drm/amd/display: add more cyan skillfish devices
- drm/amd/pm: Use cached metrics data on aldebaran
- drm/amd/pm: Use cached metrics data on arcturus
- drm/amdgpu/jpeg: Hold pg_lock before jpeg poweroff
- drm/nouveau: replace snprintf() with scnprintf() in nvkm_snprintbf()
- PCI: Disable MSI on RDC PCI to PCIe bridges
- drm/amdkfd: return -ENOTTY for unsupported IOCTLs
- media: pci: ivtv: Don't create fake v4l2_fh
- [x86] vsyscall: Do not require X86_PF_INSTR to emulate vsyscall
- net: stmmac: Check stmmac_hw_setup() in stmmac_resume()
- ice: Don't use %pK through printk or tracepoints
- thunderbolt: Use is_pciehp instead of is_hotplug_bridge
- [powerpc*] eeh: Use result of error_detected() in uevent
- [s390x] pci: Use pci_uevent_ers() in PCI recovery
- bridge: Redirect to backup port when port is administratively down
- net: ipv6: fix field-spanning memcpy warning in AH output
- media: imon: make send_packet() more robust
- drm/bridge: display-connector: don't set OP_DETECT for DisplayPorts
- usb: gadget: f_ncm: Fix MAC assignment NCM ethernet
- char: misc: Does not request module for miscdevice with dynamic minor
- net: When removing nexthops, don't call synchronize_net if it is not
necessary
- net: Call trace_sock_exceed_buf_limit() for memcg failure with
SK_MEM_RECV.
- PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call
- ALSA: usb-audio: Add validation of UAC2/UAC3 effect units
- rds: Fix endianness annotation for RDS_MPATH_HASH
- scsi: mpi3mr: Fix controller init failure on fault during queue creation
- scsi: pm80xx: Fix race condition caused by static variables
- extcon: adc-jack: Fix wakeup source leaks on device unbind
- net: phy: fixed_phy: let fixed_phy_unregister free the phy_device
- drm/amdkfd: fix vram allocation failure for a special case
- drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption
- media: fix uninitialized symbol warnings
- drm/amdgpu: Respect max pixel clock for HDMI and DVI-D (v2)
- scsi: pm8001: Use int instead of u32 to store error codes
- ptp: Limit time setting of PTP clocks
- dmaengine: sh: setup_xref error handling
- dmaengine: mv_xor: match alloc_wc and free_wc
- dmaengine: dw-edma: Set status for callback_result
- [arm64] drm/msm/dsi/phy: Toggle back buffer resync after preparing PLL
- [arm64] drm/msm/dsi/phy_7nm: Fix missing initial VCO rate
- drm/amdgpu: Allow kfd CRIU with no buffer objects
- ipv6: Add sanity checks on ipv6_devconf.rpl_seg_enabled
- net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms
- [arm64,armhf] media: verisilicon: Explicitly disable selection api ioctls
for decoders
- ALSA: usb-audio: apply quirk for MOONDROP Quark2
- net: call cond_resched() less often in __release_sock()
- smsc911x: add second read of EEPROM mac when possible corruption seen
- [amd64] iommu/amd: Skip enabling command/event buffers for kdump
- drm/amd: add more cyan skillfish PCI ids
- drm/amdgpu: don't enable SMU on cyan skillfish
- drm/amdgpu: add support for cyan skillfish gpu_info
- usb: gadget: f_hid: Fix zero length packet transfer
- usb: cdns3: gadget: Use-after-free during failed initialization and exit
of cdnsp gadget (CVE-2025-40314)
- [arm64] drm/msm: make sure to not queue up recovery more than once
- media: i2c: og01a1b: Specify monochrome media bus format instead of Bayer
- net: phy: marvell: Fix 88e1510 downshift counter errata
- wifi: mac80211: Fix HE capabilities element check
- [arm64] phy: rockchip: phy-rockchip-inno-csidphy: allow writes to grf
register 0
- net: sh_eth: Disable WoL if system can not suspend
- media: redrat3: use int type to store negative error codes
- netfilter: nf_reject: don't reply to icmp error messages
- [x86] kvm: Prefer native qspinlock for dedicated vCPUs irrespective of
PV_UNHALT
- udp_tunnel: use netdev_warn() instead of netdev_WARN()
- watchdog: s3c2410_wdt: Fix max_timeout being calculated larger
- net/cls_cgroup: Fix task_get_classid() during qdisc run
- wifi: mt76: mt7921: Add 160MHz beamformee capability for mt7922 device
- ALSA: serial-generic: remove shared static buffer
- drm/amdgpu: Use memdup_array_user in amdgpu_cs_wait_fences_ioctl
- drm/amd: Avoid evicting resources at S5
- page_pool: always add GFP_NOWARN for ATOMIC allocations
- ethernet: Extend device_get_mac_address() to use NVMEM
- drm/amdgpu: reject gang submissions under SRIOV
- scsi: lpfc: Check return status of lpfc_reset_flush_io_context during
TGT_RESET
- scsi: lpfc: Remove ndlp kref decrement clause for F_Port_Ctrl in
lpfc_cleanup
- scsi: lpfc: Define size of debugfs entry for xri rebalancing
- allow finish_no_open(file, ERR_PTR(-E...))
- usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs
- [arm64,armhf] usb: xhci: plat: Facilitate using autosuspend for xhci plat
devices
- ipv6: np->rxpmtu race annotation
- jfs: Verify inode mode when loading from disk (CVE-2025-40312)
- jfs: fix uninitialized waitqueue in transaction manager
- [amd64] iommu/vt-d: Replace snprintf with scnprintf in
dmar_latency_snapshot()
- wifi: ath10k: Fix connection after GTK rekeying
- net: intel: fm10k: Fix parameter idx set but not used
- r8169: set EEE speed down ratio to 1
- [arm64] PCI: cadence: Check for the existence of cdns_pcie::ops before
using it
- vfio: return -ENOTTY for unsupported device feature
- PCI/PM: Skip resuming to D0 if device is disconnected
- NFSv4: handle ERR_GRACE on delegation recalls
- NFSv4.1: fix mount hang after CREATE_SESSION failure
- nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode
dereferencing
- net: bridge: Install FDB for bridge MAC on VLAN 0
- scsi: libfc: Fix potential buffer overflow in fc_ct_ms_fill()
- scsi: mpt3sas: Add support for 22.5 Gbps SAS link rate
- fs: ext4: change GFP_KERNEL to GFP_NOFS to avoid deadlock
- ext4: increase IO priority of fastcommit
- net/mlx5e: Don't query FEC statistics when FEC is disabled
- net: macb: avoid dealing with endianness in macb_set_hwaddr()
- Bluetooth: btusb: Check for unexpected bytes when defragmenting HCI
frames
- Bluetooth: SCO: Fix UAF on sco_conn_free (CVE-2025-40309)
- Bluetooth: bcsp: receive data only if registered (CVE-2025-40308)
- ALSA: usb-audio: add mono main switch to Presonus S1824c
- exfat: limit log print for IO error
- 6pack: drop redundant locking and refcounting
- page_pool: Clamp pool size to max 16K pages
- orangefs: fix xattr related buffer overflow... (CVE-2025-40306)
- ftrace: Fix softlockup in ftrace_module_enable
- ksmbd: use sock_create_kern interface to create kernel socket
- smb: client: transport: avoid reconnects triggered by pending task work
- ACPICA: Update dsmethod.c to get rid of unused variable warning
- RDMA/irdma: Fix SD index calculation
- RDMA/irdma: Remove unused struct irdma_cq fields
- RDMA/irdma: Set irdma_cq cq_num field during CQ create
- [arm64] RDMA/hns: Fix the modification of max_send_sge
- [arm64] RDMA/hns: Fix wrong WQE data when QP wraps around
- btrfs: mark dirty extent range for out of bound prealloc extents
- fs/hpfs: Fix error code for new_inode() failure in
mkdir/create/mknod/symlink
- [arm64] rtc: pcf2127: clear minute/second interrupt
- [armhf] clk: ti: am33xx: keep WKUP_DEBUGSS_CLKCTRL enabled
- NTB: epf: Allow arbitrary BAR mapping
- 9p: fix /sys/fs/9p/caches overwriting itself
- 9p: sysfs_init: don't hardcode error to ENOMEM
- scsi: ufs: core: Include UTP error in INT_FATAL_ERRORS
- ACPI: property: Return present device nodes only on fwnode interface
- tools bitmap: Add missing asm-generic/bitsperlong.h include
- tools: lib: thermal: don't preserve owner in install
- tools: lib: thermal: use pkg-config to locate libnl3
- fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds
(CVE-2025-40304)
- kbuild: uapi: Strip comments before size type check
- [arm64,armhf] ASoC: meson: aiu-encoder-i2s: fix bit clock polarity
- ceph: add checking of wait_for_completion_killable() return value
- ALSA: hda/realtek: Audio disappears on HP 15-fc000 after warm boot again
- Revert "wifi: ath10k: avoid unnecessary wait for service ready message"
(Closes: #1120680)
- Bluetooth: hci_event: validate skb length for unknown CC opcode
(CVE-2025-40301)
- [armhf] net: dsa: tag_brcm: legacy: fix untagged rx on unbridged ports
for
bcm63xx
- net: vlan: sync VLAN features with lower device
- [armhf] net: dsa: b53: fix resetting speed and pause on forced link
- [armhf] net: dsa: b53: fix enabling ip multicast
- [armhf] net: dsa: b53: stop reading ARL entries if search is done
- sctp: Hold RCU read lock while iterating over address list
- sctp: Prevent TOCTOU out-of-bounds write (CVE-2025-40331)
- sctp: Hold sock lock while iterating over address list
- net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup
- bnxt_en: Fix a possible memory leak in bnxt_ptp_init
- net/mlx5e: SHAMPO, Fix skb size check for 64K pages
- net: bridge: fix use-after-free due to MST port state bypass
(CVE-2025-40297)
- net: bridge: fix MST static key usage
- tracing: Fix memory leaks in create_field_var()
- Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
(CVE-2025-40294)
- rtc: rx8025: fix incorrect register reference
- smb: client: validate change notify buffer before copy
- lib/crypto: curve25519-hacl64: Fix older clang KASAN workaround for GCC
- scsi: ufs: ufs-pci: Fix S0ix/S3 for Intel controllers
- PM: suspend: Fix pm_suspend_target_state handling for !CONFIG_PM
- extcon: adc-jack: Cleanup wakeup source only if it was enabled
- drm/amdgpu: Fix function header names in amdgpu_connectors.c
- [x86] drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD
- [x86] drm/i915: Fix conversion between clock ticks and nanoseconds
- smb: client: fix refcount leak in smb2_set_path_attr
- drm/amd: Fix suspend failure with secure display TA
- compiler_types: Move unused static inline functions warning to W=2
- drm/amd/pm: Disable MCLK switching on SI at high pixel clocks
- drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices
(CVE-2025-40288)
- NFS4: Fix state renewals missing after boot
- HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
- NFS: check if suid/sgid was cleared after a write as needed
- smb/server: fix possible memory leak in smb2_read() (CVE-2025-40286)
- smb/server: fix possible refcount leak in smb2_sess_setup()
(CVE-2025-40285)
- ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
- wifi: ath11k: Add tx ack signal support for management packets
- wifi: ath11k: zero init info->status in wmi_process_mgmt_tx_comp()
- net: fec: correct rx_bytes statistic for the case SHIFT16 is set
- Bluetooth: MGMT: cancel mesh send timer when hdev removed
(CVE-2025-40284)
- Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
(CVE-2025-40283)
- Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
(CVE-2025-40282)
- Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion
- Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
- sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
(CVE-2025-40281)
- net/smc: fix mismatch between CLC header and proposal
- tipc: Fix use-after-free in tipc_mon_reinit_self(). (CVE-2025-40280)).
- net: mdio: fix resource leak in mdiobus_register_device()
- wifi: mac80211: skip rate verification for not captured PSDUs
- af_unix: Initialise scc_index in unix_add_edge(). (CVE-2025-40214)).
- net/sched: act_connmark: transition to percpu stats and rcu
- net_sched: act_connmark: use RCU in tcf_connmark_dump()
- net: sched: act_connmark: initialize struct tc_ife to fix kernel leak
(CVE-2025-40279)
- net: sched: act_ife: initialize struct tc_ife to fix KMSAN
kernel-infoleak
(CVE-2025-40278)
- net/mlx5e: Fix maxrate wraparound in threshold between units
- net/mlx5e: Fix wraparound in rate limiting for values above 255 Gbps
- net/mlx5: Expose shared buffer registers bits and structs
- net/mlx5e: Add API to query/modify SBPR and SBCM registers
- net/mlx5e: Update shared buffer along with device buffer changes
- net/mlx5e: Consider internal buffers size in port buffer calculations
- net/mlx5e: Remove mlx5e_dbg() and msglvl support
- net/mlx5e: Fix potentially misleading debug message
- net_sched: limit try_bulk_dequeue_skb() batches
- hsr: Fix supervision frame sending on HSRv0
- ACPI: CPPC: Check _CPC validity for only the online CPUs
- ACPI: CPPC: Perform fast check switch only for online CPUs
- ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs
- Bluetooth: L2CAP: export l2cap_chan_hold for modules
- acpi,srat: Fix incorrect device handle check for Generic Initiator
- regulator: fixed: fix GPIO descriptor leak on register failure
- drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
(CVE-2025-40277)
- NFSv4: Fix an incorrect parameter when calling nfs4_call_sync()
- ALSA: usb-audio: Fix NULL pointer dereference in
snd_usb_mixer_controls_badd (CVE-2025-40275)
- bpf: Add bpf_prog_run_data_pointers()
- softirq: Add trace points for tasklet entry/exit
- Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
- espintcp: fix skb leaks (CVE-2025-38057)
- lib/crypto: arm/curve25519: Disable on CPU_BIG_ENDIAN
- asm-generic: Unify uapi bitsperlong.h for arm64, riscv and loongarch
- netfilter: nf_tables: reject duplicate device on updates (CVE-2025-38678)
- HID: hid-ntrig: Prevent memory leak in ntrig_report_version()
- NFSD: free copynotify stateid in nfs4_free_ol_stateid() (CVE-2025-40273)
- ksmbd: close accepted socket when per-IP limit rejects connection
- strparser: Fix signed/unsigned mismatch bug
- dma-mapping: benchmark: Restore padding to ensure uABI remained
consistent
- ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe
- wifi: mac80211: reject address change while connecting
- fs/proc: fix uaf in proc_readdir_de() (CVE-2025-40271)
- [arm64] mmc: sdhci-of-dwcmshc: Change DLL_STRBIN_TAPNUM_DEFAULT to 0x4
- ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
(CVE-2025-40269)
- ALSA: usb-audio: Fix missing unlock at error path of maxpacksize check
- spi: Try to get ACPI GPIO IRQ earlier
- btrfs: do not update last_log_commit when logging inode due to a new name
- virtio-net: fix received length check in big packets (CVE-2025-40292)
- scsi: ufs: core: Add a quirk to suppress link_startup_again
- scsi: ufs: ufs-pci: Set UFSHCD_QUIRK_PERFORM_LINK_STARTUP_ONCE for Intel
ADL
- iommufd: Don't overflow during division for dirty tracking
(CVE-2025-40293)
- [x86] KVM: SVM: Mark VMCB_LBR dirty when MSR_IA32_DEBUGCTLMSR is updated
- net: netpoll: fix incorrect refcount handling causing incorrect cleanup
- eventpoll: Replace rwlock with spinlock
- mm, percpu: do not consider sleepable allocations atomic
- isdn: mISDN: hfcsusb: fix memory leak in hfcsusb_probe()
- asm-generic: partially revert "Unify uapi bitsperlong.h for arm64, riscv
and loongarch"
- net/mlx5: Fix memory leak in error flow of port set buffer
- net/sched: act_connmark: handle errno on tcf_idr_check_alloc
- net/mlx5e: Do not update SBCM when prio2buffer command is invalid
- net/mlx5e: Preserve shared buffer capacity during headroom updates
- timers: Fix NULL function pointer race in timer_shutdown_sync()
- HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
(Closes: #1114557)
- mtdchar: fix integer overflow in read/write ioctls
- exfat: check return value of sb_min_blocksize in exfat_read_boot_sector
- mptcp: Disallow MPTCP subflows from sockmap
- ata: libata-scsi: Add missing scsi_device_put() in ata_scsi_dev_rescan()
- be2net: pass wrb_params in case of OS2BMC (CVE-2025-40264)
- Input: cros_ec_keyb - fix an invalid memory access (CVE-2025-40263)
- Input: imx_sc_key - fix memory corruption on unload (CVE-2025-40262)
- Input: pegasus-notetaker - fix potential out-of-bounds access
- nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()
(CVE-2025-40261)
- scsi: sg: Do not sleep in atomic context (CVE-2025-40259)
- scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()
- mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)
- mptcp: fix ack generation for fallback msk
- mptcp: fix premature close in case of fallback
- mptcp: avoid unneeded subflow-level drops
- mptcp: do not fallback when OoO is present
- [arm64,armhf] drm/tegra: dc: Fix reference leak in tegra_dc_couple()
- drm/amdgpu: Skip emit de meta data on gfx11 with rs64 enabled
- xfrm: Determine inner GSO type from packet inner protocol
- [arm64,armhf] gpu: host1x: Select context device based on attached IOMMU
- [arm64,armhf] drm/tegra: Add call to put_pid()
- net: openvswitch: remove never-working support for setting nsh fields
(CVE-2025-40254)
- nvme-multipath: fix lockdep WARN due to partition scan work
- [s390x] ctcm: Fix double-kfree (CVE-2025-40253)
- [x86] platform/x86/intel/speed_select_if: Convert PCIBIOS_* return codes
to errnos
- kernel.h: Move ARRAY_SIZE() to a separate header
- net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and
qede_tpa_end()
- vsock: Ignore signal/timeout on connect() if already established
- bcma: don't register devices disabled in OF
- cifs: fix typo in enable_gcm_256 module parameter
- scsi: core: Fix a regression triggered by scsi_host_busy()
- net: tls: Cancel RX async resync request on rcd_delta overflow
- mm/secretmem: fix use-after-free race in fault handler (CVE-2025-40272)
- mm/mm_init: fix hash table order logging in alloc_large_system_hash()
- ALSA: usb-audio: fix uac2 clock source at terminal parser
- tracing/tools: Fix incorrcet short option in usage text for --threads
- uio_hv_generic: Set event for all channels on the device
(Closes: #1120602)
- mm/truncate: unmap large folio on split failure
- maple_tree: fix tracepoint string pointers
- mptcp: decouple mptcp fastclose from tcp close
- mptcp: fix a race in mptcp_pm_del_add_timer() (CVE-2025-40257)
- mm/mempool: replace kmap_atomic() with kmap_local_page()
- mm/mempool: fix poisoning order>0 pages with HIGHMEM
- dt-bindings: pinctrl: toshiba,visconti: Fix number of items in groups
- ata: libata-scsi: Fix system suspend for a security locked drive
- HID: amd_sfh: Stop sensor before starting
- [armhf] pmdomain: samsung: plug potential memleak during probe
- [arm64] pmdomain: arm: scmi: Fix genpd leak on provider registration
failure
- [armhf] pmdomain: imx: Fix reference count leak in imx_gpc_remove
- filemap: cap PTE range to be created to allowed zero fill in
folio_map_range()
- can: kvaser_usb: leaf: Fix potential infinite loop in command parsers
- can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted
URBs
- can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before
accessing header
- Bluetooth: SMP: Fix not generating mackey and ltk when repairing
- [x86] platform/x86: intel: punit_ipc: fix memory corruption
- net: aquantia: Add missing descriptor cache invalidation on ATL2
- net/mlx5e: Fix validation logic in rate limiting
- net: sxgbe: fix potential NULL dereference in sxgbe_rx()
- drm/amdgpu: fix cyan_skillfish2 gpu info fw handling
- net: atlantic: fix fragment overflow handling in RX path
- mailbox: Allow direct registration to a channel
- [amd64,arm64] mailbox: pcc: Use mbox_bind_client
- [amd64,arm64] mailbox: pcc: Add support for platform notification
handling
- [amd64,arm64] mailbox: pcc: Support shared interrupt for multiple
subspaces
- ACPI: PCC: Add PCC shared memory region command and status bitfields
- [amd64,arm64] mailbox: pcc: Check before sending MCTP PCC response ACK
- [amd64,arm64] mailbox: pcc: Refactor error handling in irq handler into
separate function
- [amd64,arm64] mailbox: pcc: don't zero error register
- [x86] Revert "perf/x86: Always store regs->ip in perf_callchain_kernel()"
- iio: imu: st_lsm6dsx: fix array size for st_lsm6dsx_settings fields
- iio:common:ssp_sensors: Fix an error handling path ssp_probe()
- iio: accel: bmc150: Fix irq assumption regression (Closes: #1106411)
- iio: accel: fix ADXL355 startup race condition
- iio: adc: ad7280a: fix ad7280_store_balance_timer()
- [mips*] mm: Prevent a TLB shutdown on initial uniquification
- [mips*] mm: kmalloc tlb_vpn array to avoid stack overflow
- ALSA: usb-audio: Add DSD quirk for LEAK Stereo 230
- atm/fore200e: Fix possible data race in fore200e_open()
- can: sja1000: fix max irq loop handling
- [armhf] can: sun4i_can: sun4i_can_interrupt(): fix max irq loop handling
- dm-verity: fix unreliable memory allocation
- [arm64,armhf] drivers/usb/dwc3: fix PCI parent check
- smb: client: fix memory leak in cifs_construct_tcon()
- [x86] thunderbolt: Add support for Intel Wildcat Lake
- firmware: stratix10-svc: fix bug in saving controller data
- [arm64,armhf] serial: amba-pl011: prefer dma_mapping_error() over
explicit
address checking
- usb: cdns3: Fix double resource release in cdns3_pci_probe
- usb: gadget: f_eem: Fix memory leak in eem_unwrap
- usb: storage: Fix memory leak in USB bulk transport
- USB: storage: Remove subclass and protocol overrides from Novatek quirk
- usb: storage: sddr55: Reject out-of-bound new_pba
- usb: uas: fix urb unmapping issue when the uas device is remove during
ongoing data transfer
- [arm64,armhf] usb: dwc3: Fix race condition between concurrent
dwc3_remove_requests() call paths
- USB: serial: ftdi_sio: add support for u-blox EVK-M101
- USB: serial: option: add support for Rolling RW101R-GL
- drm/amd/display: Check NULL before accessing
- libceph: fix potential use-after-free in have_mon_and_osd_map()
- libceph: prevent potential out-of-bounds writes in
handle_auth_session_key()
- libceph: replace BUG_ON with bounds check for map->max_osd
- nfsd: Replace clamp_t in nfsd4_get_drc_mem()
- net: macb: fix unregister_netdev call order in macb_remove()
(CVE-2025-39805)
- mptcp: fix duplicate reset on fastclose
- mptcp: Fix proto fallback detection with BPF
- staging: rtl8712: Remove driver using deprecated API wext
- ksmbd: fix use-after-free in session logoff (CVE-2025-37899)
- usb: typec: ucsi: psy: Set max current to zero when disconnected
- usb: udc: Add trace event for usb_gadget_set_state
- usb: gadget: udc: fix use-after-free in usb_gadget_state_work
- scsi: pm80xx: Set phy->enable_completion only when we
- [arm64] i2c: xgene-slimpro: Migrate to use generic PCC shmem related
macros
- HID: core: Harden s32ton() against conversion to 0 bits
.
[ Ben Hutchings ]
* tools/hv: Make the sample hv_get_dhcp_info script more useful
* hyperv-daemons: Install the sample network info scripts (Closes: #919350)
Checksums-Sha1:
161f0656ed2c7f92b563735a2967d6ed50221f6b 399396 linux_6.1.159-1.dsc
3e7703e23b0cb5b5348d2ce4493d5f10bcc50eeb 137840844 linux_6.1.159.orig.tar.xz
2c3e54f10a8e865584f1e1bc05209d187f6312d7 1797540 linux_6.1.159-1.debian.tar.xz
ff2f23c6adf24cc835a3282d1c35fa2ac87caaa5 6981 linux_6.1.159-1_source.buildinfo
Checksums-Sha256:
2e05b8b357b6810c021b4a0a6ae89c2845976bf6e3461602ad1d136b0a822557 399396
linux_6.1.159-1.dsc
aee9073581b7b34d516ca28ec2a8473dccb9d169118b587dcbfea5deb269a711 137840844
linux_6.1.159.orig.tar.xz
1b360e038ac5fc42fd258e64c3fff5bb8ccfb1516feb1d69f17c2eb239ec113e 1797540
linux_6.1.159-1.debian.tar.xz
46f1183f9ce2c05a2e6ab2ec52e16d70f5cea2b9e13dd693c655b3f47ab934df 6981
linux_6.1.159-1_source.buildinfo
Files:
040127ad5e817478bf88f0bec1cbfde7 399396 kernel optional linux_6.1.159-1.dsc
56f4d3508b28a951aac494238160ae5a 137840844 kernel optional
linux_6.1.159.orig.tar.xz
7646e9613291ea5c1eea79529e26de17 1797540 kernel optional
linux_6.1.159-1.debian.tar.xz
f910377786a2eaecb5c6558ee55c5c90 6981 kernel optional
linux_6.1.159-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmlUUR9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EqacQAIpkdq6VviUnKoPAyN4Ka8TwBDktk+Hg
Ip/UM6qoCqc6o/lfZ3RvTfphNAHoaM9g8ivy+2mCLv9C2R2iyWHZ+hyvVXlOpH0c
aJzn4qiHOpP2aN+NyuOmaqXQZ3juct1ONadCoJrVfPTW4H8mtzvxiolwyAfpdNzA
O/8MpTbQf/tvEpLRvZAxIZ2e/72AWzG1WfCoLY+1XEo7JdsThTYE6u+8XoDxfOoQ
r6V5HUcPiwfcNZ7Lrz6N3gj7kKx6Ph9JAlm1qo3xcMz+8X7uVgRoixTXMs25zNI/
N+ShqRjxWdN3QR3aE1QD+5ceNwQkCjaHRm0F/aJoMJ3XrW+NAzD2k265ynLp6YeY
4/j4qw4+rBdOO7B2K8SO56LkXYyeTGbwbpphMlmCZVvwjV/xqukqNgt9WzYehZYU
KYiAZY/2QVxOKUbvJMhzipXOcg9NeonrMPMCj0yMQQsv+UltXrCE8rzpA246uEna
5xLDAJyhB0JsAgJSUMcU1uE/QFC57gqpBdwNgKJvU0gw3MsdiI7j6J88hiEN9BN6
bd3ZR7GxIj0/FH0pAuAq4kimwtQo7hCncQJSR/UOMxrgc8X423cnSXaoPQNPVv/9
0VQUZlU4E0RapdZXpZFFvzG+HEiZQ0/rwGzvdsb7l+OEFies0xJ/zPpBiXqzAMSG
0tnsmBHTBkez
=sqhs
-----END PGP SIGNATURE-----
pgpSxo9s86HPr.pgp
Description: PGP signature
--- End Message ---