-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 12 Aug 2025 05:28:04 +0200 Source: linux Architecture: source Version: 6.12.41-1 Distribution: trixie-security Urgency: high Maintainer: Debian Kernel Team Changed-By: Salvatore Bonaccorso Closes: 1088522 1108430 1109344 1109676 1109734 1109799 Changes: linux (6.12.41-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.39 - eventpoll: don't decrement ep refcount while still holding the ep mutex (CVE-2025-38349) - drm/amdgpu/discovery: use specific ip_discovery.bin for legacy asics - drm/amdgpu/ip_discovery: add missing ip_discovery fw - [s390x] crypto: s390/sha - Fix uninitialized variable in SHA-1 and SHA-2 - drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV (CVE-2025-38104) - [amd64] ASoC: Intel: SND_SOC_INTEL_SOF_BOARD_HELPERS select SND_SOC_ACPI_INTEL_MATCH - [amd64] ASoC: Intel: soc-acpi: arl: Correct naming of a cs35l56 address struct - [amd64] ASoC: Intel: soc-acpi: arl: Add match entries for new cs42l43 laptops - [amd64] ASoC: soc-acpi: add get_function_tplg_files ops - [amd64] ASoC: Intel: add sof_sdw_get_tplg_files ops - [amd64] ASoC: Intel: soc-acpi-intel-arl-match: set get_function_tplg_files ops - [amd64] ASoC: Intel: soc-acpi: arl: Correct order of cs42l43 matches - perf/core: Fix the WARN_ON_ONCE is out of lock protected region - irqchip/irq-msi-lib: Select CONFIG_GENERIC_MSI_IRQ - sched/core: Fix migrate_swap() vs. hotplug - perf: Revert to requiring CAP_SYS_ADMIN for uprobes - ASoC: cs35l56: probe() should fail if the device ID is not recognized - Bluetooth: hci_sync: Fix not disabling advertising instance - Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as connected - pinctrl: amd: Clear GPIO debounce for suspend - fix proc_sys_compare() handling of in-lookup dentries - sched/deadline: Fix dl_server runtime calculation formula - bnxt_en: eliminate the compile warning in bnxt_request_irq due to CONFIG_RFS_ACCEL - [arm64] poe: Handle spurious Overlay faults - [arm64] net: phy: qcom: move the WoL function to shared library - [arm64] net: phy: qcom: qca808x: Fix WoL issue by utilizing at8031_set_wol() - netlink: Fix wraparounds of sk->sk_rmem_alloc. - vsock: fix `vsock_proto` declaration - tipc: Fix use-after-free in tipc_conn_close(). - tcp: Correct signedness in skb remaining space calculation - vsock: Fix transport_{g2h,h2g} TOCTOU - vsock: Fix transport_* TOCTOU - vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also `transport_local` - net: stmmac: Fix interrupt handling for level-triggered mode in DWC_XGMAC2 - net: phy: smsc: Fix Auto-MDIX configuration when disabled by strap - net: phy: smsc: Force predictable MDI-X state on LAN87xx - net: phy: smsc: Fix link failure in forced mode with Auto-MDIX - atm: clip: Fix potential null-ptr-deref in to_atmarpd(). - atm: clip: Fix memory leak of struct clip_vcc. - atm: clip: Fix infinite recursive call of clip_push(). - atm: clip: Fix NULL pointer dereference in vcc_sendmsg() - [arm64] net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info - net/sched: Abort __tc_modify_qdisc if parent class does not exist - rxrpc: Fix bug due to prealloc collision - rxrpc: Fix oops due to non-existence of prealloc backlog struct - ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() - [amd64] x86/mce/amd: Add default names for MCA banks and blocks - [amd64] x86/mce/amd: Fix threshold limit reset - [amd64] x86/mce: Don't remove sysfs if thresholding sysfs init fails - [amd64] x86/mce: Ensure user polling settings are honored when restarting timer - [amd64] x86/mce: Make sure CMCI banks are cleared during shutdown on Intel - [amd64] KVM: x86/xen: Allow 'out of range' event channel ports in IRQ routing table. - [amd64] KVM: SVM: Add missing member in SNP_LAUNCH_START command structure - [amd64] KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight - KVM: Allow CPU to reschedule while setting per-page memory attributes - ASoC: fsl_sai: Force a software reset when starting in consumer mode - gre: Fix IPv6 multicast route creation. (Closes: #1108430) - md/md-bitmap: fix GPF in bitmap_get_stats() (Closes: #1109734) - [arm64] pinctrl: qcom: msm: mark certain pins as invalid for interrupts - pwm: Fix invalid state detection - pwm: mediatek: Ensure to disable clocks in error path - wifi: prevent A-MSDU attacks in mesh networks (CVE-2025-27558) - wifi: mwifiex: discard erroneous disassoc frames on STA interface - wifi: mt76: mt7921: prevent decap offload config before STA initialization - wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_sta_set_decap_offload() - wifi: mt76: mt7925: fix the wrong config for tx interrupt - wifi: mt76: mt7925: fix invalid array index in ssid assignment during hw scan - drm/imagination: Fix kernel crash when hard resetting the GPU - drm/amdkfd: Don't call mmput from MMU notifier callback - drm/gem: Acquire references on GEM handles for framebuffers - drm/sched: Increment job count before swapping tail spsc queue - drm/ttm: fix error handling in ttm_buffer_object_transfer - drm/gem: Fix race in drm_gem_handle_create_tail() - drm/xe/bmg: fix compressed VRAM handling - Revert "drm/xe/xe2: Enable Indirect Ring State support for Xe2" - usb: gadget: u_serial: Fix race condition in TTY wakeup - Revert "usb: gadget: u_serial: Add null pointer check in gs_start_io" - drm/framebuffer: Acquire internal references on GEM handles - drm/xe: Allocate PF queue size on pow2 boundary - Revert "ACPI: battery: negate current when discharging" (Closes: #1109344) - Revert "PCI/ACPI: Fix allocated memory release on error in pci_acpi_scan_root()" - kallsyms: fix build without execinfo - maple_tree: fix mt_destroy_walk() on root leaf node - mm: fix the inaccurate memory statistics issue for users - mm/vmalloc: leave lazy MMU mode on PTE mapping error - lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() - [amd64] x86/rdrand: Disable RDSEED on AMD Cyan Skillfish - [amd64] x86/mm: Disable hugetlb page table sharing on 32-bit - [arm64] clk: scmi: Handle case where child clocks are initialized before their parents - smb: server: make use of rdma_destroy_qp() - ksmbd: fix a mount write count leak in ksmbd_vfs_kern_path_locked() - erofs: fix to add missing tracepoint in erofs_read_folio() - erofs: address D-cache aliasing - [amd64] ASoC: Intel: sof-function-topology-lib: Print out the unsupported dmic count - netlink: Fix rmem check in netlink_broadcast_deliver(). - netlink: make sure we allow at least one dump skb - netfs: Fix ref leak on inserted extra subreq in write retry - wifi: cfg80211: fix S1G beacon head validation in nl80211 - wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() - drm/tegra: nvdec: Fix dma_alloc_coherent error check - md/raid1: Fix stack memory use after return in raid1_reshape - raid10: cleanup memleak at raid10_make_request - wifi: mac80211: correctly identify S1G short beacon - wifi: mac80211: fix non-transmitted BSSID profile search - wifi: rt2x00: fix remove callback type mismatch - drm/nouveau/gsp: fix potential leak of memory used during acpi init - wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() - nbd: fix uaf in nbd_genl_connect() error path - drm/xe/pf: Clear all LMTT pages on alloc - erofs: free pclusters if no cached folio is attached - erofs: get rid of `z_erofs_next_pcluster_t` - erofs: tidy up zdata.c - erofs: refine readahead tracepoint - erofs: fix to add missing tracepoint in erofs_readahead() - netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() - net: appletalk: Fix device refcount leak in atrtr_create() - ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic sizeof - net: phy: microchip: Use genphy_soft_reset() to purge stale LPA bits - net: phy: microchip: limit 100M workaround to link-down events on LAN88xx - drm/xe/pm: Correct comment of xe_pm_set_vram_threshold() - can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level - net/mlx5e: Fix race between DIM disable and net_dim() - net/mlx5e: Add new prio for promiscuous mode - net: ll_temac: Fix missing tx_pending check in ethtools_set_ringparam() - bnxt_en: Fix DCB ETS validation - bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT - ublk: sanity check add_dev input for underflow - atm: idt77252: Add missing `dma_map_error()` - ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak. - [amd64] ALSA: hda/realtek: Add mic-mute LED setup for ASUS UM5606 - io_uring: make fallocate be hashed work - [amd64] ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic - ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop 15-eg100 - ALSA: hda/realtek: Add quirks for some Clevo laptops - net: usb: qmi_wwan: add SIMCom 8230C composition - driver: bluetooth: hci_qca:fix unable to load the BT driver - HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard Gen2 - net: mana: Record doorbell physical address in PF mode - btrfs: fix assertion when building free space tree - vt: add missing notification when switching back to text mode - bpf: Adjust free target to avoid global starvation of LRU map - [riscv64] vdso: Exclude .rodata from the PT_DYNAMIC segment - HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY - HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras - HID: nintendo: avoid bluetooth suspend/resume stalls - erofs: fix rare pcluster memory leak after unmounting - net: wangxun: revert the adjustment of the IRQ vector sequence - kasan: remove kasan_find_vm_area() to prevent possible deadlock - ksmbd: fix potential use-after-free in oplock/lease break ack - [arm64] Filter out SME hwcaps when FEAT_SME isn't implemented - crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() (CVE-2025-37984) - rseq: Fix segfault on registration when rseq_cs is non-zero (CVE-2025-38067) - [amd64] KVM: SVM: Set synthesized TSA CPUID flags https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.40 - USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition - USB: serial: option: add Foxconn T99W640 - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI - usb: musb: fix gadget state on disconnect - [arm*] usb: dwc2: gadget: Fix enter to hibernation for UTMI+ PHY - usb: gadget: configfs: Fix OOB read on empty string write - [armhf] i2c: stm32: fix the device used for the DMA map - [armhf] i2c: stm32f7: unmap DMA mapped buffer - [amd64] thunderbolt: Fix wake on connect at runtime - [amd64] thunderbolt: Fix bit masking in tb_dp_port_set_hops() - Revert "staging: vchiq_arm: Create keep-alive thread during probe" - nvmem: imx-ocotp: fix MAC address byte length - nvmem: layouts: u-boot-env: remove crc32 endianness conversion - Input: xpad - set correct controller type for Acer NGR200 - pch_uart: Fix dma_sync_sg_for_device() nents value - spi: Add check for 8-bit transfer with 8 IO mode support - dm-bufio: fix sched in atomic context - HID: core: ensure the allocated report buffer can contain the reserved report ID - HID: core: ensure __hid_request reserves the report ID as the first byte - HID: core: do not bypass hid_hw_raw_request - tracing/probes: Avoid using params uninitialized in parse_btf_arg() - tracing: Add down_write(trace_event_sem) when adding trace event - tracing/osnoise: Fix crash in timerlat_dump_stack() - drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume - drm/amdgpu: Increase reset counter only on success - drm/amd/display: Disable CRTC degamma LUT for DCN401 - drm/amd/display: Free memory allocation - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx - ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS - io_uring/poll: fix POLLERR handling - mptcp: make fallback action and fallback decision atomic - mptcp: plug races between subflow fail and subflow creation - mptcp: reset fallback status gracefully at disconnect() time - phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() - net/mlx5: Update the list of the PCI supported devices - [arm64] dts: imx8mp-venice-gw74xx: fix TPM SPI frequency - [arm64] dts: add big-endian property back into watchdog node - [arm64] dts: freescale: imx8mm-verdin: Keep LDO5 always on - [arm64] dts: imx8mp-venice-gw71xx: fix TPM SPI frequency - [arm64] dts: imx8mp-venice-gw72xx: fix TPM SPI frequency - [arm64] dts: imx8mp-venice-gw73xx: fix TPM SPI frequency - [arm64] dts: rockchip: use cs-gpios for spi1 on ringneck - af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() - af_packet: fix soft lockup issue caused by tpacket_snd() - Bluetooth: btintel: Check if controller is ISO capable on btintel_classify_pkt_type - cpuidle: psci: Fix cpuhotplug routine with PREEMPT_RT=y - isofs: Verify inode mode when loading from disk - memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() - [arm*] mmc: bcm2835: Fix dma_unmap_sg() nents value - mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models - [arm64] mmc: sdhci_am654: Workaround for Errata i2312 - [amd64] net: stmmac: intel: populate entire system_counterval_t in get_time_fn() callback - pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov - [s390x] bpf: Fix bpf_arch_text_poke() with new_addr == NULL again - smb: client: fix use-after-free in crypt_message when using async crypto - [armhf] soc: aspeed: lpc-snoop: Cleanup resources in stack-order - [armhf] soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled - iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush - iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] - iio: adc: max1363: Reorder mode_list[] entries - iio: adc: stm32-adc: Fix race in installing chained IRQ handler - iio: backend: fix out-of-bound write - iio: common: st_sensors: Fix use of uninitialize device structs - [arm64] dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5 - [arm64] dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B - [arm64] dts: imx95: Correct the DMA interrupter number of pcie0_ep - bpf: Reject %p% format string in bprintf-like helpers - cachefiles: Fix the incorrect return value in __cachefiles_write() - block: fix kobject leak in blk_unregister_queue - net/sched: sch_qfq: Fix race condition on qfq_aggregate - rpl: Fix use-after-free in rpl_do_srh_inline(). - smb: client: fix use-after-free in cifs_oplock_break - fix a leak in fcntl_dirnotify() - nvme: fix inconsistent RCU list manipulation in nvme_ns_add_to_ctrl_list() - nvme: fix endianness of command word prints in nvme_log_err_passthru() - smc: Fix various oops due to inet_sock type confusion. - net: phy: Don't register LEDs for genphy - nvme: fix misaccounting of nvme-mpath inflight I/O - nvmet-tcp: fix callback lock for TLS handshake - wifi: cfg80211: remove scan request n_channels counted_by - [amd64] hwmon: (corsair-cpro) Validate the size of the received input buffer - ice: add NULL check in eswitch lag check - ice: check correct pointer in fwlog debugfs - usb: net: sierra: check for no status endpoint - loop: use kiocb helpers to fix lockdep warning - [riscv64] Enable interrupt during exception handling - [riscv64] traps_misaligned: properly sign extend value in misaligned load handler - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() - Bluetooth: hci_sync: fix connectable extended advertising when using static random address - Bluetooth: SMP: If an unallowed command is received consider it a failure - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout - Bluetooth: hci_core: add missing braces when using macro parameters - Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855 GF variant without board ID - net/mlx5: Correctly set gso_size when LRO is used - ipv6: mcast: Delay put pmc->idev in mld_del_delrec() - net: fix segmentation after TCP/UDP fraglist GRO - netfilter: nf_conntrack: fix crash due to removal of uninitialised entry - drm/xe/pf: Sanitize VF scratch registers on FLR - drm/xe/pf: Move VFs reprovisioning to worker - drm/xe/pf: Prepare to stop SR-IOV support prior GT reset - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU - [amd64,arm64] hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open to prevent IPv6 addrconf - virtio-net: fix recursived rtnl_lock() during probe() - tls: always refresh the queue when reading sock - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime - net: bridge: Do not offload IGMP/MLD messages - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree - rxrpc: Fix recv-recv race of completed call - rxrpc: Fix transmission of an abort in response to an abort - Revert "cgroup_freezer: cgroup_freezing: Check if not frozen" - drm/mediatek: Add wait_event_timeout when disabling plane - drm/mediatek: only announce AFBC if really supported - libbpf: Fix handling of BPF arena relocations - efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths - sched: Change nr_uninterruptible type to unsigned long - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns - btrfs: fix block group refcount race in btrfs_create_pending_block_groups() (CVE-2025-22115) - usb: hub: fix detection of high tier USB3 devices behind suspended hubs - usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm - usb: hub: Fix flushing of delayed work used for post resume purposes - usb: hub: Don't try to recover devices lost during warm reset. - [arm64] usb: dwc3: qcom: Don't leave BCR asserted - [arm64,armhf] i2c: omap: Add support for setting mux - [arm64,armhf] i2c: omap: Fix an error handling path in omap_i2c_probe() - [arm64,armhf] i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe() - [arm64,armhf] i2c: omap: fix deprecated of_property_read_bool() use - sched,freezer: Remove unnecessary warning in __thaw_task - drm/xe/mocs: Initialize MOCS index early - drm/xe: Move page fault init after topology init - smb: client: let smbd_post_send_iter() respect the peers max_send_size and transmit all data - [amd64] iommu/vt-d: Fix misplaced domain_attached assignment (Closes: #1109676) - [amd64] KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.41 - [amd64] x86/traps: Initialize DR7 by writing its architectural reset value - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT (CVE-2025-38335) - virtio_net: Enforce minimum TX ring size for reliability - virtio_ring: Fix error reporting in virtqueue_resize - regulator: core: fix NULL dereference on unbind due to stale coupling data - [amd64] platform/x86: asus-nb-wmi: add DMI quirk for ASUS Zenbook Duo UX8406CA - RDMA/core: Rate limit GID cache warning messages - [arm64] interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1 node - iio: adc: ad7949: use spi_is_bpw_supported() - regmap: fix potential memory leak of regmap_bus - [amd64] x86/hyperv: Fix usage of cpu_online_mask to get valid cpu - [amd64] platform/x86: Fix initialization order for firmware_attributes_class - [arm*] staging: vchiq_arm: Make vchiq_shutdown never fail - xfrm: state: initialize state_ptrs earlier in xfrm_state_find - xfrm: state: use a consistent pcpu_id in xfrm_state_find - xfrm: Set transport header to fix UDP GRO handling - xfrm: interface: fix use-after-free after changing collect_md xfrm interface - [arm64] net: ti: icssg-prueth: Fix buffer allocation for ICSSG - net/mlx5: Fix memory leak in cmd_exec() - net/mlx5: E-Switch, Fix peer miss rules to use peer eswitch - i40e: report VF tx_dropped with tx_errors instead of tx_discards - i40e: When removing VF MAC filters, only check PF-set MAC - net: appletalk: Fix use-after-free in AARP proxy probe - net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class - can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode - [arm64] drm/bridge: ti-sn65dsi86: Remove extra semicolon in ti_sn_bridge_probe() - ALSA: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop - [s390x] ism: fix concurrency management in ism_cmd() - [arm64] net: hns3: fix concurrent setting vlan filter issue - [arm64] net: hns3: disable interrupt when ptp init failed - [arm64] net: hns3: fixed vf get max channels bug - [arm64] net: hns3: default enable tx bounce buffer when smmu enabled - [amd64] platform/x86: ideapad-laptop: Fix FnLock not remembered among boots - [amd64] platform/x86: ideapad-laptop: Fix kbd backlight not remembered among boots - drm/amdgpu: Reset the clear flag in buddy during resume - drm/sched: Remove optimization that causes hang when killing dependent jobs - mm/ksm: fix -Wsometimes-uninitialized from clang-21 in advisor_mode_show() - timekeeping: Zero initialize system_counterval when querying time from phc drivers - [arm64] i2c: qup: jump out of the loop in case of timeout - [arm64,armhf] i2c: tegra: Fix reset error handling with ACPI - i2c: virtio: Avoid hang by using interruptible completion wait - bus: fsl-mc: Fix potential double device reference in fsl_mc_get_endpoint() - sprintf.h requires stdarg.h - ALSA: hda/realtek - Add mute LED support for HP Pavilion 15-eg0xxx - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fa0xxx - [arm64] entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() - [arm64] dpaa2-eth: Fix device reference count leak in MAC endpoint handling - e1000e: disregard NVM checksum on tgp when valid checksum bit is not set - e1000e: ignore uninitialized checksum word on tgp - gve: Fix stuck TX queue for DQ queue format - ice: Fix a null pointer dereference in ice_copy_and_init_pkg() - nilfs2: reject invalid file types when reading inodes - resource: fix false warning in __request_region() - mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list - mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n - [amd64,arm64] usb: typec: tcpm: allow to use sink in accessory mode - [amd64,arm64] usb: typec: tcpm: allow switching to mode accessory to mux properly - [amd64,arm64] usb: typec: tcpm: apply vbus before data bringup in tcpm_src_attach - spi: cadence-quadspi: fix cleanup of rx_chan on failure paths - [amd64] x86/bugs: Fix use of possibly uninit value in amd_check_tsa_microcode() - jfs: reject on-disk inodes of an unsupported type (CVE-2025-37925) - [amd64] comedi: comedi_test: Fix possible deletion of uninitialized timers - [arm64] dts: qcom: x1e78100-t14s: mark l12b and l15b always-on - erofs: simplify z_erofs_load_compact_lcluster() - erofs: refine z_erofs_get_extent_compressedlen() - erofs: use Z_EROFS_LCLUSTER_TYPE_MAX to simplify switches - erofs: simplify tail inline pcluster handling - erofs: clean up header parsing for ztailpacking and fragments - erofs: fix large fragment handling - ext4: don't explicit update times in ext4_fallocate() - ext4: refactor ext4_punch_hole() - ext4: refactor ext4_zero_range() - ext4: refactor ext4_collapse_range() - ext4: refactor ext4_insert_range() - ext4: factor out ext4_do_fallocate() - ext4: move out inode_lock into ext4_fallocate() - ext4: move out common parts into ext4_fallocate() - ext4: fix incorrect punch max_end - ext4: correct the error handle in ext4_fallocate() - ext4: fix out of bounds punch offset - [amd64] KVM: x86: drop x86.h include from cpuid.h - [amd64] KVM: x86: Route non-canonical checks in emulator through emulate_ops - [amd64] KVM: x86: Add X86EMUL_F_MSR and X86EMUL_F_DT_LOAD to aid canonical checks - [amd64] KVM: x86: model canonical checks more precisely - [amd64] KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (CVE-2025-38351) - [amd64] x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap() - [arm64] dts: qcom: x1-crd: Fix vreg_l2j_1p2 voltage - Revert "wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba for MLO" - wifi: mt76: mt7925: adjust rm BSS flow to prevent next connection failure - iio: hid-sensor-prox: Restore lost scale assignments - iio: hid-sensor-prox: Fix incorrect OFFSET calculation - [amd64,arm64] Drivers: hv: Make the sysfs node size for the ring buffer dynamic - ALSA: hda/tegra: Add Tegra264 support - ALSA: hda: Add missing NVIDIA HDA codec IDs - [amd64] drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x - Revert "drm/xe/gt: Update handling of xe_force_wake_get return" (Closes: #1109799) - Revert "drm/xe/tests/mocs: Update xe_force_wake_get() return handling" - Revert "drm/xe/devcoredump: Update handling of xe_force_wake_get return" - Revert "drm/xe/forcewake: Add a helper xe_force_wake_ref_has_domain()" - [amd64] KVM: x86: Free vCPUs before freeing VM state - mm: khugepaged: fix call hpage_collapse_scan_file() for anonymous vma . [ Bastian Blank ] * Store build time signing key encrypted. * Enable CRYPTO_ECDSA. . [ Aurelien Jarno ] * Fix installation of DTB files . [ Tj ] * drivers/gpu/drm/nouveau: Enable DRM_NOUVEAU_GSP_DEFAULT (Closes: #1088522) . [ Uwe Kleine-König ] * [armhf] Add phy-gmii-sel module to nic-shared-modules udeb for ti/omap/am335x based machines (e.g. BeagleBone black). . [ Salvatore Bonaccorso ] * d/salsa-ci.yml: Update for trixie: Set RELEASE to trixie Checksums-Sha1: 4c27cc03165101daa02730a246b5db5edfd2578e 219407 linux_6.12.41-1.dsc accbbe886f7ee7058c827f6ea981e6c57fca8285 151148292 linux_6.12.41.orig.tar.xz 9580fbacfe8e5e345f4770237739808dfcc6af45 1672664 linux_6.12.41-1.debian.tar.xz fba82022a1f26b217e65612bfc2686a3fe0ec4c4 6694 linux_6.12.41-1_source.buildinfo Checksums-Sha256: 65bbf4e35635465326c9470605da1886ce3d3cf7e2a6d93392c4c6245d895b34 219407 linux_6.12.41-1.dsc 78afa637ca891174c22b332e4c1f87cf6aaa81861a6cca3b529e861843fa2fd3 151148292 linux_6.12.41.orig.tar.xz b62680107fc155ad3d2c421ba0af1d5848812674fe767fcd40ba81a414e4ce2a 1672664 linux_6.12.41-1.debian.tar.xz 59c0b9af69e550237710e6c56c67f7d9f62f35283af553196a4d0a1ec1ced78c 6694 linux_6.12.41-1_source.buildinfo Files: 26aa7b0334cd1d40085838b157601a02 219407 kernel optional linux_6.12.41-1.dsc a005fb8810c0ef34fc27bc5edf92d128 151148292 kernel optional linux_6.12.41.orig.tar.xz fa713a42314b7a9d99fb1e053e9fc824 1672664 kernel optional linux_6.12.41-1.debian.tar.xz 1ae397aa6aee8bfccf80d08c11fd330b 6694 kernel optional linux_6.12.41-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmiatddfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EqiUP/RMw7zcTvXowime5vF7mRR9pK5UWBUtT RwIKg8OtrO7GYc22RJUTZrBeAH0YS7vN5/89h38i0EUElv02S0YgRSxZJ8rYmNnF yhaskB+OZ/uu5AOMHukBO7CTxu8eTlEWfZ5x47xfl9Dm5EgCzD+Sy+KK72A8ORe9 6se6QjUlpY6+LfcMjWjdojAmAdFDR49AT63yWQAyD7PcE42puh/1CPNB64XB/DCL Q8zGC8VtOAa/VWb7Fxi0HVA1tBwQWXyYZNl+ssrqlxPpO3zKZsrS/hxYgo1G/1QL 22Hu5ljImERn/m9uooqX32+btycv8xuH0lFkprKUpbLmoJmwEto6tfkb//S6xwLw m8Qg6r2gPTphQv/be3zA2pSJYFEd5+altLqOXrZjV0X/xIm+dKN5ksCh1UOMOQ6j wkfBl2DHKd4Q+gmEdrMhiZ/aERjQwmngiImhlOvCSkHRFdKZg2p1o9EHoGUt2RPN t6ygp4H/cLKHkwBJsmlx4UW5MtnhB+7ZjMMjyqgHeMkTxkhW8slDEhmW6dVQAuvY e5H45fFoS+dpDDhtJU22UghalXV9KX3icyvrerAOtcORVR43ZXQSNZAFqfWxyEmw 8AnweMKUWLJ5QidZedu7ELlMD2I6qUpKyAJyEN5LGB9/AYSjcIROEnpJThJvomK4 7VbBVT3mM5dF =LGVy -----END PGP SIGNATURE-----