-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 15 Mar 2026 08:54:56 +0100 Source: linux-signed-arm64 Architecture: source Version: 6.19.8+1 Distribution: sid Urgency: medium Maintainer: Debian Kernel Team <[email protected]> Changed-By: Salvatore Bonaccorso <[email protected]> Changes: linux-signed-arm64 (6.19.8+1) unstable; urgency=medium . * Sign kernel from linux 6.19.8-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.19.7 - perf/core: Fix refcount bug and potential UAF in perf_mmap - drm/vmwgfx: Fix invalid kref_put callback in vmw_bo_dirty_release - drm/vmwgfx: Return the correct value in vmw_translate_ptr functions - debugobject: Make it work with deferred page initialization - again - [arm64] KVM: arm64: Hide S1POE from guests when not supported by the host - [arm64] KVM: arm64: Fix ID register initialization for non-protected pKVM guests - drm/fourcc: fix plane order for 10/12/16-bit YCbCr formats - drm/tiny: sharp-memory: fix pointer error dereference - [riscv64] irqchip/sifive-plic: Fix frozen interrupt due to affinity setting - scsi: lpfc: Properly set WC for DPP mapping - scsi: pm8001: Fix use-after-free in pm8001_queue_command() - [armhf] drm/imx: parallel-display: check return value of devm_drm_bridge_add() in imx_pd_probe() - drm/bridge: synopsys: dw-dp: Check return value of devm_drm_bridge_add() in dw_dp_bind() - ALSA: scarlett2: Fix DSP filter control array handling - ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite devices - ALSA: usb-audio: Add QUIRK_FLAG_SKIP_IFACE_SETUP - gpio: shared: fix memory leaks - [amd64] x86/fred: Correct speculative safety in fred_extint() - [amd64] x86/bug: Handle __WARN_printf() trap in early_fixup_exception() - [amd64] x86/cfi: Fix CFI rewrite for odd alignments - sched/fair: Rename cfs_rq::avg_load to cfs_rq::sum_weight - sched/fair: Rename cfs_rq::avg_vruntime to ::sum_w_vruntime, and helper functions - sched/fair: Introduce and use the vruntime_cmp() and vruntime_op() wrappers for wrapped-signed aritmetics - sched/fair: Fix zero_vruntime tracking - sched/fair: Only set slice protection at pick time - sched/eevdf: Update se->vprot in reweight_entity() - sched/fair: Fix lag clamp - rseq: Clarify rseq registration rseq_size bound check comment - perf/core: Fix invalid wait context in ctx_sched_in() - [amd64] accel/amdxdna: Remove buffer size check when creating command BO - [amd64] accel/amdxdna: Switch to always use chained command - [amd64] accel/amdxdna: Fix crash when destroying a suspended hardware context - [amd64] accel/amdxdna: Reduce log noise during process termination - [amd64] accel/amdxdna: Fix dead lock for suspend and resume - [amd64] accel/amdxdna: Fix suspend failure after enabling turbo mode - [amd64] accel/amdxdna: Fix command hang on suspended hardware context - [amd64] accel/amdxdna: Fix out-of-bounds memset in command slot handling - [amd64] accel/amdxdna: Prevent ubuf size overflow - [amd64] accel/amdxdna: Validate command buffer payload count - drm/xe/wa: Steer RMW of MCR registers while building default LRC - cgroup/cpuset: Fix incorrect change to effective_xcpus in partition_xcpus_del() - cgroup/cpuset: Fix incorrect use of cpuset_update_tasks_cpumask() in update_cpumasks_hier() - cxl: Move devm_cxl_add_nvdimm_bridge() to cxl_pmem.ko - cxl: Fix race of nvdimm_bus object when creating nvdimm objects - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() - scsi: ufs: core: Move link recovery for hibern8 exit failure to wl_resume - regulator: fp9931: Fix PM runtime reference leak in fp9931_hwmon_read() - regulator: bq257xx: Fix device node reference leak in bq257xx_reg_dt_parse_gpio() - irqchip/ls-extirq: Fix devm_of_iomap() error check - io_uring/cmd_net: use READ_ONCE() for ->addr3 read - zloop: advertise a volatile write cache - zloop: check for spurious options passed to remove - drm/client: Do not destroy NULL modes - ALSA: usb-audio: Cap the packet size pre-calculations - ALSA: usb-audio: Use inclusive terms - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race - [s390x] idle: Fix cpu idle exit cpu time accounting - [s390x] vtime: Fix virtual timer forwarding - [s390x] kexec: Disable stack protector in s390_reset_system() - [arm64] io: Rename ioremap_prot() to __ioremap_prot() - [arm64] io: Extract user memory type in ioremap_prot() - [arm64] PCI: dwc: ep: Refresh MSI Message Address cache on change - [arm64] PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry - drm/amdgpu/userq: Do not allow userspace to trivially triger kernel warnings - drm/amdgpu: Unlock a mutex before destroying it - drm/amdgpu: Fix locking bugs in error paths - drm/amdgpu: Fix error handling in slot reset - ALSA: hda: cs35l56: Fix signedness error in cs35l56_hda_posture_put() - btrfs: free pages on error in btrfs_uring_read_extent() - btrfs: fix error message order of parameters in btrfs_delete_delayed_dir_index() - btrfs: fix incorrect key offset in error message in check_dev_extent_item() - btrfs: fix objectid value in error message in check_extent_data_ref() - btrfs: fix warning in scrub_verify_one_metadata() - btrfs: print correct subvol num if active swapfile prevents deletion - btrfs: fix compat mask in error messages in btrfs_check_features() - ALSA: usb: qcom: Correct parameter comment for uaudio_transfer_buffer_setup() - mm/slab: pass __GFP_NOWARN to refill_sheaf() if fallback is available - [amd64] ASoC: SDCA: Fix comments for sdca_irq_request() - bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing - bpf: Fix stack-out-of-bounds write in devmap - sched_ext: Fix SCX_EFLAG_INITIALIZED being a no-op flag - [armhf] spi: stm32: fix missing pointer assignment in case of dma chaining - PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value - bpf: Fix race in cpumap on PREEMPT_RT - bpf: Fix race in devmap on PREEMPT_RT - bpf: Add bitwise tracking for BPF_END - bpf: Introduce tnum_step to step through tnum's members - bpf: Improve bounds when tnum has a single possible value - uaccess: Fix scoped_user_read_access() for 'pointer to const' - usb: gadget: u_ether: add gether_opts for config caching - usb: gadget: u_ether: Add auto-cleanup helper for freeing net_device - usb: gadget: f_ncm: align net_device lifecycle with bind/unbind - accel/rocket: fix unwinding in error path in rocket_core_init - accel/rocket: fix unwinding in error path in rocket_probe - [amd64] KVM: x86: Add x2APIC "features" to control EOI broadcast suppression - eventpoll: Fix integer overflow in ep_loop_check_proc() - namespace: fix proc mount iteration - media: dvb-core: fix wrong reinitialization of ringbuffer on reopen - nfc: pn533: properly drop the usb interface reference on disconnect - net: usb: kaweth: validate USB endpoints - net: usb: kalmia: validate USB endpoints - net: usb: pegasus: validate USB endpoints - can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message - can: usb: f81604: correctly anchor the urb in the read bulk callback - can: ucan: Fix infinite loop from zero-length messages - can: usb: etas_es58x: correctly anchor the urb in the read bulk callback - can: usb: f81604: handle short interrupt urb messages properly - can: usb: f81604: handle bulk write errors properly - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them - HID: pidff: Fix condition effect bit clearing - HID: multitouch: Keep latency normal on deactivate for reactivation gesture - [amd64] x86/efi: defer freeing of boot services memory - [amd64] perf/x86/intel/uncore: Add per-scheduler IMC CAS count events - [amd64] x86/boot: Handle relative CONFIG_EFI_SBAT_FILE file paths - [amd64] x86/sev: Allow IBPB-on-Entry feature for SNP guests - [amd64] x86/boot/sev: Move SEV decompressor variables into the .data section - [amd64] platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data - [amd64] platform/x86: alienware-wmi-wmax: Add G-Mode support to m18 laptops - [amd64] platform/x86: dell-wmi: Add audio/mic mute key codes - ALSA: hda/realtek: Add quirk for HP Pavilion 15-eh1xxx to enable mute LED - ALSA: doc: usb-audio: Add doc for QUIRK_FLAG_SKIP_IFACE_SETUP - ALSA: usb-audio: Use correct version for UAC3 header validation - ALSA: hda/intel: increase default bdl_pos_adj for Nvidia controllers - ALSA: hda/realtek: fix model name typo for Samsung Galaxy Book Flex (NT950QCG-X716) - ALSA: hda/realtek: Add quirk for Acer Aspire V3-572G - ALSA: hda/realtek: add quirk for Samsung Galaxy Book Flex (NT950QCT-A38A) - ALSA: hda/realtek: add quirk for Acer Nitro ANV15-51 - wifi: radiotap: reject radiotap with unknown bits - wifi: libertas: fix use-after-free in lbs_free_adapter() - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() - wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration - wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() - Bluetooth: purge error queues in socket destructors - gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL - net: phy: register phy led_triggers during probe to avoid AB-BA deadlock - IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() - RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() - RDMA/ionic: Fix kernel stack leak in ionic_create_cq() - ksmbd: Compare MACs in constant time - cpufreq: intel_pstate: Fix crash during turbo disable - [arm64] gcs: Do not set PTE_SHARED on GCS mappings if FEAT_LPA2 is enabled - net/sched: ets: fix divide by zero in the offload path - nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit(). - tracing: Fix WARN_ON in tracing_buffers_mmap_close - scsi: target: Fix recursive locking in __configfs_open_file() - mm: thp: deny THP for files on anonymous inodes - Squashfs: check metadata block offset is within range - drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() - drbd: fix null-pointer dereference on local read error - xfs: fix xfs_group release bug in xfs_dax_notify_dev_failure - xfs: Fix error pointer dereference - smb: client: fix cifs_pick_channel when channels are equally loaded - smb: client: fix broken multichannel with krb5+signing - smb: client: Don't log plaintext credentials in cifs_set_cifscreds - smb: client: fix oops due to uninitialised var in smb2_unlink() - scsi: core: Fix refcount leak for tagset_refcnt - scsi: ufs: core: Fix RPMB region size detection for UFS 2.2 - mptcp: pm: avoid sending RM_ADDR over same subflow - mptcp: pm: in-kernel: always mark signal+subflow endp as used - kbuild: Split .modinfo out from ELF_DETAILS - kbuild: Leave objtool binary around with 'make clean' - Revert "netfilter: nft_set_rbtree: validate open interval overlap" (Closes: #1129757) - [armhf] clean up the memset64() C wrapper - [amd64] platform/x86: hp-bioscfg: Support allocations of larger data (Closes: #1127612) - Bluetooth: Fix CIS host feature condition - ipmi: Fix use-after-free and list corruption on sender error - net: stmmac: remove support for lpi_intr_o - drm/amd/display: Use GFP_ATOMIC in dc_create_stream_for_sink - nvme: fix admin queue leak on controller reset - hwmon: (macsmc) Fix regressions in Apple Silicon SMC hwmon driver - hwmon: (macsmc) Fix overflows, underflows, and sign extension - hwmon: (aht10) Fix initialization commands for AHT20 - pinctrl: equilibrium: rename irq_chip function callbacks - pinctrl: equilibrium: fix warning trace on load - pinctrl: qcom: qcs615: Add missing dual edge GPIO IRQ errata flag - [amd64] platform/x86: thinkpad_acpi: Fix errors reading battery thresholds - module: Remove duplicate freeing of lockdep classes - HID: multitouch: new class MT_CLS_EGALAX_P80H84 - pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config() - pinctrl: generic: move function to amlogic-am4 driver - pinctrl: meson: amlogic-a4: Fix device node reference leak in aml_dt_node_to_map_pinmux() - pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() - hwmon: (it87) Check the it87_lock() return value - idpf: increment completion queue next_to_clean in sw marker wait routine - idpf: change IRQ naming to match netdev and ethtool queue numbering - idpf: Fix flow rule delete failure due to invalid validation - ice: recap the VSI and QoS info after rebuild - ice: fix crash in ethtool offline loopback test - i40e: Fix preempt count leak in napi poll tracepoint - e1000e: clear DPG_EN after reset to avoid autonomous power-gating - drm/solomon: Fix page start when updating rectangle in page addressing mode - netfs: Fix unbuffered/DIO writes to dispatch subrequests in strict sequence - nvmet-fcloop: Check remoteport port_state before calling done callback - net: annotate data-races around sk->sk_{data_ready,write_space} - bridge: Check relevant per-VLAN options in VLAN range grouping - net: ethernet: ti: am65-cpsw-nuss/cpsw-ale: Fix multicast entry handling in ALE table - nvme-multipath: fix leak on try_module_get failure - inet: annotate data-races around isk->inet_num - crypto: ccp - Fix use-after-free on error path - accel/amdxdna: Fill invalid payload for failed command - udp: Unhash auto-bound connected sk from 4-tuple hash table when disconnected. - tcp: give up on stronger sk_rcvbuf checks (for now) - xsk: Fix fragment node deletion to prevent buffer leak - xsk: Fix zero-copy AF_XDP fragment drop - dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler - atm: lec: fix null-ptr-deref in lec_arp_clear_vccs - net: ti: icssg-prueth: Fix ping failure after offload mode setup when link speed is not 1G - amd-xgbe: fix MAC_TCR_SS register width for 2.5G and 10M speeds - regulator: mt6363: Fix incorrect and redundant IRQ disposal in probe - can: bcm: fix locking for bcm_op runtime updates - can: dummy_can: dummy_can_init(): fix packet statistics - can: mcp251x: fix deadlock in error path of mcp251x_open - wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config - drm/syncobj: Fix handle <-> fd ioctls with dirty stack - drm/xe: Do not preempt fence signaling CS instructions - drm/xe/configfs: Free ctx_restore_mid_bb in release - drm/xe/queue: Call fini on exec queue creation fail - blktrace: fix __this_cpu_read/write in preemptible context - kunit: tool: copy caller args in run_kernel to prevent mutation - accel/amdxdna: Fix NULL pointer dereference of mgmt_chann - drm/amd/display: Use mpc.preblend flag to indicate 3D LUT - drm/amd/display: Enable DEGAMMA and reject COLOR_PIPELINE+DEGAMMA_LUT - net: dsa: realtek: rtl8365mb: fix rtl8365mb_phy_ocp_write return value - bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded - wifi: cw1200: Fix locking in error paths - wifi: wlcore: Fix a locking bug - wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() - wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() - wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() - indirect_call_wrapper: do not reevaluate function pointer - net/rds: Fix circular locking dependency in rds_tcp_tune - xen/acpi-processor: fix _CST detection using undersized evaluation buffer - [amd64] ASoC: SDCA: Add allocation failure check for Entity name - ice: fix adding AQ LLDP filter for VF - ice: Fix memory leak in ice_set_ringparam() - libie: don't unroll if fwlog isn't supported - iavf: fix netdev->max_mtu to respect actual hardware limit - igb: Fix trigger of incorrect irq in igb_xsk_wakeup - igc: Fix trigger of incorrect irq in igc_xsk_wakeup function - bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim - smb/client: fix buffer size for smb311_posix_qinfo in smb2_compound_op() - smb/client: fix buffer size for smb311_posix_qinfo in SMB311_posix_query_info() - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() - net: ipv4: fix ARM64 alignment fault in multipath hash seed - amd-xgbe: fix sleep while atomic on suspend/resume - drm/sched: Fix kernel-doc warning for drm_sched_job_done() - ata: libata: cancel pending work after clearing deferred_qc - i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus lock" - time/jiffies: Fix sysctl file error on configurations where USER_HZ < HZ - drm/xe/gsc: Fix GSC proxy cleanup on early initialization failure - drm/xe/reg_sr: Fix leak on xa_store failure - nvme: fix memory allocation in nvme_pr_read_keys() - [amd64] x86/numa: Store extra copy of numa_nodes_parsed - [amd64] x86/topo: Add topology_num_nodes_per_package() - [amd64] x86/topo: Replace x86_has_numa_in_package - [amd64] x86/topo: Fix SNC topology mess - sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting - timekeeping: Fix timex status validation for auxiliary clocks - hwmon: (max6639) fix inverted polarity - net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs - tcp: secure_seq: add back ports to TS offset - net: nfc: nci: Fix zero-length proprietary notifications - net_sched: sch_fq: clear q->band_pkt_count[] in fq_reset() - net: devmem: use READ_ONCE/WRITE_ONCE on binding->dev - nfc: nci: free skb on nci_transceive early error paths - nfc: nci: complete pending data exchange on device close - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback - nfc: rawsock: cancel tx_work before socket teardown - net: stmmac: Fix error handling in VLAN add and delete paths - net: stmmac: Improve double VLAN handling - net: stmmac: Fix VLAN HW state restore - net: stmmac: Defer VLAN HW configuration when interface is down - block: use trylock to avoid lockdep circular dependency in sysfs - net: Provide a PREEMPT_RT specific check for netdev_queue::_xmit_lock - netfilter: nf_tables: unconditionally bump set->nelems before insertion - netfilter: nf_tables: clone set on flush only - netfilter: nft_set_pipapo: split gc into unlink and reclaim phase - net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup() - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled - net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop - net/sched: act_ife: Fix metalist update behavior - xdp: use modulo operation to calculate XDP frag tailroom - xsk: introduce helper to determine rxq->frag_size - ice: fix rxq info registering in mbuf packets - ice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz - i40e: fix registering XDP RxQ info - i40e: use xdp.frame_sz as XDP RxQ info frag_size - net: enetc: use truesize as XDP RxQ info frag_size - xdp: produce a warning when calculated tailroom is negative - accel: ethosu: Fix job submit error clean-up refcount underflows - accel: ethosu: Fix NPU_OP_ELEMENTWISE validation with scalar - ata: libata-eh: Fix detection of deferred qc timeouts - tracing: Add NULL pointer check to trigger_data_free() - bpf: collect only live registers in linked regs https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.19.8 - net/sched: act_gate: snapshot parameters with RCU on replace - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks Checksums-Sha1: 1d27ebda80ac0edcb4454a3798b6e742bd568f5a 7106 linux-signed-arm64_6.19.8+1.dsc eea57feeafe9671d57a352d4cde83cfa0fa57c62 706088 linux-signed-arm64_6.19.8+1.tar.xz Checksums-Sha256: 1cad7d528eefea5d55d042ad564a6b8ef8042634a90c9a6b84859a7c6e0eef02 7106 linux-signed-arm64_6.19.8+1.dsc 71c838a2d75c8bf6cbd3d0b23b38338b3d9abe22edd043f0b43397a8b03a004e 706088 linux-signed-arm64_6.19.8+1.tar.xz Files: b06ca9cad133b3ef4d15df40bd91742d 7106 kernel optional linux-signed-arm64_6.19.8+1.dsc 32914110bf27dd18347b8bfcd9a639f8 706088 kernel optional linux-signed-arm64_6.19.8+1.tar.xz
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSInBJdRTWyTRy0ztFCTVFtUgONCgUCabbYHgAKCRBCTVFtUgON CremAP9IcXKA5MYLPlcSYmqP1+DT2uG5xOR3djLoRX+BK71lWwD+ORpModkPReS6 /VCnp5mpONIpV9sj9Fa7qzpHO2kDGg0= =J/xW -----END PGP SIGNATURE-----
pgp1qrdSUIICV.pgp
Description: PGP signature

