-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 25 Apr 2025 21:51:43 +0200 Source: linux Binary: bpftool bpftool-dbgsym hyperv-daemons hyperv-daemons-dbgsym libcpupower-dev libcpupower1 libcpupower1-dbgsym linux-compiler-gcc-12-x86 linux-config-6.1 linux-cpupower linux-cpupower-dbgsym linux-headers-6.1.0-34-amd64 linux-headers-6.1.0-34-cloud-amd64 linux-headers-6.1.0-34-rt-amd64 linux-image-6.1.0-34-amd64-dbg linux-image-6.1.0-34-amd64-unsigned linux-image-6.1.0-34-cloud-amd64-dbg linux-image-6.1.0-34-cloud-amd64-unsigned linux-image-6.1.0-34-rt-amd64-dbg linux-image-6.1.0-34-rt-amd64-unsigned linux-image-amd64-dbg linux-image-amd64-signed-template linux-image-cloud-amd64-dbg linux-image-rt-amd64-dbg linux-kbuild-6.1 linux-kbuild-6.1-dbgsym linux-libc-dev linux-perf linux-perf-dbgsym rtla usbip usbip-dbgsym Architecture: amd64 Version: 6.1.135-1 Distribution: bookworm-security Urgency: high Maintainer: amd64 Build Daemon (x86-grnet-01) Changed-By: Salvatore Bonaccorso Description: bpftool - Inspection and simple manipulation of BPF programs and maps hyperv-daemons - Support daemons for Linux running on Hyper-V libcpupower-dev - CPU frequency and voltage scaling tools for Linux (development fi libcpupower1 - CPU frequency and voltage scaling tools for Linux (libraries) linux-compiler-gcc-12-x86 - Compiler for Linux on x86 (meta-package) linux-config-6.1 - Debian kernel configurations for Linux 6.1 linux-cpupower - CPU power management tools for Linux linux-headers-6.1.0-34-amd64 - Header files for Linux 6.1.0-34-amd64 linux-headers-6.1.0-34-cloud-amd64 - Header files for Linux 6.1.0-34-cloud-amd64 linux-headers-6.1.0-34-rt-amd64 - Header files for Linux 6.1.0-34-rt-amd64 linux-image-6.1.0-34-amd64-dbg - Debug symbols for linux-image-6.1.0-34-amd64 linux-image-6.1.0-34-amd64-unsigned - Linux 6.1 for 64-bit PCs linux-image-6.1.0-34-cloud-amd64-dbg - Debug symbols for linux-image-6.1.0-34-cloud-amd64 linux-image-6.1.0-34-cloud-amd64-unsigned - Linux 6.1 for x86-64 cloud linux-image-6.1.0-34-rt-amd64-dbg - Debug symbols for linux-image-6.1.0-34-rt-amd64 linux-image-6.1.0-34-rt-amd64-unsigned - Linux 6.1 for 64-bit PCs, PREEMPT_RT linux-image-amd64-dbg - Debugging symbols for Linux amd64 configuration (meta-package) linux-image-amd64-signed-template - Template for signed linux-image packages for amd64 linux-image-cloud-amd64-dbg - Debugging symbols for Linux cloud-amd64 configuration (meta-packa linux-image-rt-amd64-dbg - Debugging symbols for Linux rt-amd64 configuration (meta-package) linux-kbuild-6.1 - Kbuild infrastructure for Linux 6.1 linux-libc-dev - Linux support headers for userspace development linux-perf - Performance analysis tools for Linux rtla - Real-Time Linux Analysis tools usbip - USB device sharing system over IP network Closes: 1086175 1102914 Changes: linux (6.1.135-1) bookworm-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.134 - watch_queue: fix pipe accounting mismatch - [x86] mm/pat: cpa-test: fix length for CPA_ARRAY test - cpufreq: scpi: compare kHz instead of Hz - cpufreq: governor: Fix negative 'idle_time' handling in dbs_update() - [x86] fpu: Fix guest FPU state buffer allocation size - [x86] fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct() - [x86] platform: Only allow CONFIG_EISA for 32-bit - [x86] sev: Add missing RIP_REL_REF() invocations during sme_enable() - lockdep/mm: Fix might_fault() lockdep check of current->mm->mmap_lock - PM: sleep: Adjust check before setting power.must_resume - selinux: Chain up tool resolving errors in install_policy.sh - [x86] EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer - [x86] EDAC/ie31200: Fix the DIMM size mask for several SoCs - [x86] EDAC/ie31200: Fix the error path order of ie31200_init() - thermal: int340x: Add NULL check for adev - PM: sleep: Fix handling devices with direct_complete set on errors - lockdep: Don't disable interrupts on RT in disable_irq_nosync_lockdep.*() - perf/ring_buffer: Allow the EPOLLRDNORM flag for poll - [x86] fpu/xstate: Fix inconsistencies in guest FPU xfeatures - [arm64,armhf] media: verisilicon: HEVC: Initialize start_bit field - [x86] ASoC: cs35l41: check the return value from spi_setup() - HID: remove superfluous (and wrong) Makefile entry for CONFIG_INTEL_ISH_FIRMWARE_DOWNLOADER - ALSA: hda/realtek: Always honor no_shutup_pins - [arm64] drm/bridge: ti-sn65dsi86: Fix multiple instances - drm/dp_mst: Fix drm RAD print - PCI: Use downstream bridges for distributing resources - PCI/ASPM: Fix link state exit during switch upstream function removal - [arm64] drm/msm/dsi: Set PHY usescase (and mode) before registering DSI host - [arm64] PCI: cadence-ep: Fix the driver to send MSG TLP for INTx without data payload - [arm64] PCI: brcmstb: Use internal register to change link capability - [arm64] PCI: brcmstb: Fix error path after a call to regulator_bulk_get() - [arm64] PCI: brcmstb: Fix potential premature regulator disabling - PCI/portdrv: Only disable pciehp interrupts early when needed - PCI: Avoid reset when disabled via sysfs - drm/amd/display: fix type mismatch in CalculateDynamicMetadataParameters() - PCI: Remove stray put_device() in pci_register_host_bridge() - drm/amd/display: avoid NPD when ASIC does not support DMUB - PCI: pciehp: Don't enable HPIE when resuming in poll mode - [mips*] fbdev: sm501fb: Add some geometry checks. - [arm64] clk: amlogic: gxbb: drop incorrect flag on 32k clock - [arm64,armhf] remoteproc: core: Clear table_sz when rproc_shutdown - bpf: Use preempt_count() directly in bpf_send_signal_common() - lib: 842: Improve error handling in sw842_compress() - [arm64] clk: rockchip: rk3328: fix wrong clk_ref_usb3otg parent - RDMA/core: Don't expose hw_counters outside of init net namespace - RDMA/mlx5: Fix calculation of total invalidated pages - RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() - IB/mad: Check available slots before posting receive WRs - [arm64,armhf] pinctrl: tegra: Set SFIO mode to Mux Register - [arm64] clk: amlogic: g12b: fix cluster A parent data - [arm64] clk: amlogic: gxbb: drop non existing 32k clock parent - [arm64] clk: amlogic: g12a: fix mmc A peripheral clock - [x86] entry: Fix ORC unwinder for PUSH_REGS with save_ret=1 - power: supply: max77693: Fix wrong conversion of charge input threshold value - [powerpc*] crypto: nx - Fix uninitialised hv_nxc on error - RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow - [mips*] mfd: sm501: Switch to BIT() to mitigate integer overflows - [x86] dumpstack: Fix inaccurate unwinding from exception stacks due to misplaced assignment - isofs: fix KMSAN uninit-value bug in do_isofs_readdir() - soundwire: slave: fix an OF node reference leak in soundwire slave device - [arm64] coresight-etm4x: add isb() before reading the TRCSTATR - iio: accel: mma8452: Ensure error return on failure to matching oversampling ratio - iio: accel: msa311: Fix failure to release runtime pm if direct mode claim fails. - usb: xhci: correct debug message page size calculation - iio: adc: ad7124: Fix comparison of channel configs - perf evlist: Add success path to evlist__create_syswide_maps - perf units: Fix insufficient array space - kexec: initialize ELF lowest address to ULONG_MAX - ocfs2: validate l_tree_depth to avoid out-of-bounds access - NFSv4: Don't trigger uneccessary scans for return-on-close delegations - fuse: fix dax truncate/punch_hole fault path - i3c: master: svc: Fix missing the IBI rules - perf python: Fixup description of sample.id event member - perf python: Decrement the refcount of just created event on failure - perf python: Don't keep a raw_data pointer to consumed ring buffer space - perf python: Check if there is space to copy all the event - fs/procfs: fix the comment above proc_pid_wchan() - perf tools: annotate asm_pure_loop.S - objtool, media: dib8000: Prevent divide-by-zero in dib8000_set_dds() - exfat: fix the infinite loop in exfat_find_last_cluster() - rtnetlink: Allocate vfinfo size for VF GUIDs when supported - rndis_host: Flag RNDIS modems as WWAN devices - ksmbd: use aead_request_free to match aead_request_alloc - ksmbd: fix multichannel connection failure - net/mlx5e: SHAMPO, Make reserved size independent of page size - ring-buffer: Fix bytes_dropped calculation issue - ACPI: processor: idle: Return an error if both P_LVL{2,3} idle states are invalid - sched/smt: Always inline sched_smt_active() - context_tracking: Always inline ct_{nmi,irq}_{enter,exit}() - rcu-tasks: Always inline rcu_irq_work_resched() - wifi: iwlwifi: fw: allocate chained SG tables for dump - wifi: iwlwifi: mvm: use the right version of the rate API - nvme-tcp: fix possible UAF in nvme_tcp_poll - nvme-pci: clean up CMBMSC when registering CMB fails - nvme-pci: skip CMB blocks incompatible with PCI P2P DMA - wifi: brcmfmac: keep power during suspend if board requires it - affs: generate OFS sequence numbers starting at 1 - affs: don't write overlarge OFS data block size fields - ALSA: hda/realtek: Fix Asus Z13 2025 audio - ALSA: hda: Fix speakers on ASUS EXPERTBOOK P5405CSA 1.0 - [x86] platform/x86: intel-hid: fix volume buttons on Microsoft Surface Go 4 tablet - HID: i2c-hid: improve i2c_hid_get_report error message - ALSA: hda/realtek: Add support for ASUS ROG Strix G614 Laptops using CS35L41 HDA - ALSA: hda/realtek: Add support for ASUS Zenbook UM3406KA Laptops using CS35L41 HDA - sched/deadline: Use online cpus for validating runtime - locking/semaphore: Use wake_q to wake up processes outside lock critical section - [x86] sgx: Warn explicitly if X86_FEATURE_SGX_LC is not enabled - drm/amd: Keep display off while going into S4 - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion x360 14-dy1xxx - can: statistics: use atomic access in hot path - memory: omap-gpmc: drop no compatible check - hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9} - spufs: fix a leak on spufs_new_file() failure - spufs: fix gang directory lifetimes - spufs: fix a leak in spufs_create_context() - ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans - ntb: intel: Fix using link status DB's - netfilter: nft_set_hash: GC reaps elements with conncount for dynamic sets only - netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets - net_sched: skbprio: Remove overly strict queue assertions - [arm64,armhf] net: mvpp2: Prevent parser TCAM memory corruption - udp: Fix memory accounting leak. - vsock: avoid timeout during connect() if the socket is closing - tunnels: Accept PACKET_HOST in skb_tunnel_check_pmtu(). - netfilter: nft_tunnel: fix geneve_opt type confusion addition - ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS - net: dsa: mv88e6xxx: propperly shutdown PPU re-enable timer on destroy - net: fix geneve_opt length integer overflow - ipv6: Start path selection from the first nexthop - ipv6: Do not consider link down nexthops in path selection - arcnet: Add NULL check in com20020pci_probe() - io_uring/filetable: ensure node switch is always done, if needed - drm/amdgpu/gfx11: fix num_mec - tty: serial: fsl_lpuart: use UARTMODIR register bits for lpuart32 platform - tty: serial: fsl_lpuart: disable transmitter before changing RS485 related registers - usbnet:fix NPE during rx_complete - [x86] platform/x86: ISST: Correct command storage data length - ntb_perf: Delete duplicate dmaengine_unmap_put() call in perf_copy_chunk() - [x86] perf/x86/intel: Apply static call for drain_pebs - [x86] perf/x86/intel: Avoid disable PMU if !cpuc->enabled in sample read - kunit/overflow: Fix UB in overflow_allocation_test (CVE-2024-46823) - btrfs: handle errors from btrfs_dec_ref() properly (CVE-2024-46753) - [x86] tsc: Always save/restore TSC sched_clock() on suspend/resume - [x86] mm: Fix flush_tlb_range() when used for zapping normal PMDs - acpi: nfit: fix narrowing conversion in acpi_nfit_ctl - ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP - mmc: sdhci-pxav3: set NEED_RSP_BUSY capability - mmc: sdhci-omap: Disable MMC_CAP_AGGRESSIVE_PM for eMMC/SD - ksmbd: add bounds check for create lease context - ksmbd: fix use-after-free in ksmbd_sessions_deregister() - ksmbd: fix session use-after-free in multichannel connection - ksmbd: validate zero num_subauth before sub_auth is accessed - tracing: Fix use-after-free in print_graph_function_flags during tracer switching - tracing: Ensure module defining synth event cannot be unloaded while tracing - tracing: Fix synth event printk format for str fields - tracing/osnoise: Fix possible recursive locking for cpus_read_lock() - [arm64] Don't call NULL in do_compat_alignment_fixup() - ext4: don't over-report free space or inodes in statvfs - ext4: fix OOB read when checking dotdot dir - jfs: fix slab-out-of-bounds read in ea_get() - jfs: add index corruption check to DT_GETPAGE() - media: streamzap: fix race between device disconnection and urb callback - nfsd: put dl_stid if fail to queue dl_recall - NFSD: Skip sending CB_RECALL_ANY when the backchannel isn't up - tracing: Do not use PERF enums when perf is not defined https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.135 - tipc: fix memory leak in tipc_link_xmit - codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() - net: tls: explicitly disallow disconnect - rtnl: add helper to check if rtnl group has listeners - rtnl: add helper to check if a notification is needed - net/sched: cls_api: conditional notification of events - tc: Ensure we have enough buffer space when sending filter netlink notifications - net: ethtool: Don't call .cleanup_data when prepare_data fails - ata: sata_sx4: Add error handling in pdc20621_i2c_read() - nvmet-fcloop: swap list_add_tail arguments - net_sched: sch_sfq: use a temporary work area for validating configuration - net_sched: sch_sfq: move the limit validation - ipv6: Align behavior across nexthops during path selection - net: ppp: Add bound checking for skb data on ppp_sync_txmung - nft_set_pipapo: fix incorrect avx2 match of 5th field octet - fs: consistently deref the files table with rcu_dereference_raw() - umount: Allow superblock owners to force umount - pm: cpupower: bench: Prevent NULL dereference on malloc failure - [x86] cpu: Don't clear X86_FEATURE_LAHF_LM flag in init_amd_k8() on AMD when running in a virtual machine - [arm*] perf: arm_pmu: Don't disable counter in armpmu_add() - [arm64] cputype: Add QCOM_CPU_PART_KRYO_3XX_GOLD - xen/mcelog: Add __nonstring annotations for unterminated strings - HID: pidff: Convert infinite length from Linux API to PID standard - HID: pidff: Do not send effect envelope if it's empty - HID: pidff: Fix null pointer dereference in pidff_find_fields - ALSA: hda: intel: Fix Optimus when GPU has no sound - ALSA: hda: intel: Add Lenovo IdeaPad Z570 to probe denylist - [arm64] ASoC: fsl_audmix: register card device depends on 'dais' property - [arm64,armhf] mmc: dw_mmc: add a quirk for accessing 64-bit FIFOs in two halves - ALSA: usb-audio: Fix CME quirk for UF series keyboards - [x86] ASoC: amd: Add DMI quirk for ACP6X mic support - f2fs: don't retry IO for corrupted data scenario - page_pool: avoid infinite loop to schedule delayed worker - jfs: Fix uninit-value access of imap allocated in the diMount() function - fs/jfs: cast inactags to s64 to prevent potential overflow - fs/jfs: Prevent integer overflow in AG size calculation - jfs: Prevent copying of nlink with value 0 from disk inode - jfs: add sanity check for agwidth in dbMount - ata: libata-eh: Do not use ATAPI DMA for a device limited to PIO mode - f2fs: fix to avoid out-of-bounds access in f2fs_truncate_inode_blocks() - ahci: add PCI ID for Marvell 88SE9215 SATA Controller - ext4: protect ext4_release_dquot against freezing - ext4: ignore xattrs past end - scsi: st: Fix array overflow in st_setup() - wifi: mt76: mt76x2u: add TP-Link TL-WDN6200 ID to device table - net: vlan: don't propagate flags on open - tracing: fix return value in __ftrace_event_enable_disable for TRACE_REG_UNREGISTER - Bluetooth: hci_uart: fix race during initialization - Bluetooth: qca: simplify WCN399x NVM loading - drm: allow encoder mode_set even when connectors change for crtc - drm/amd/display: Update Cursor request mode to the beginning prefetch always - drm: panel-orientation-quirks: Add support for AYANEO 2S - drm: panel-orientation-quirks: Add quirks for AYA NEO Flip DS and KB - drm: panel-orientation-quirks: Add quirk for AYA NEO Slide - drm: panel-orientation-quirks: Add new quirk for GPD Win 2 - drm: panel-orientation-quirks: Add quirk for OneXPlayer Mini (Intel) - drm/bridge: panel: forbid initializing a panel with unknown connector type - drivers: base: devres: Allow to release group on device release - drm/amdkfd: clamp queue size to minimum - drm/amdkfd: Fix mode1 reset crash issue - drm/amdkfd: Fix pqm_destroy_queue race with GPU reset - drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() - [amd64] PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type - drm/amdgpu: grab an additional reference on the gang fence v2 - tpm, tpm_tis: Workaround failed command reception on Infineon devices - bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags - ext4: don't treat fhandle lookup of ea_inode as FS corruption - xenfs/xensyms: respect hypervisor's "next" indication - [arm64] cputype: Add MIDR_CORTEX_A76AE - [arm64] errata: Add QCOM_KRYO_4XX_GOLD to the spectre_bhb_k24_list - [arm64] errata: Assume that unknown CPUs _are_ vulnerable to Spectre BHB - [arm64] errata: Add KRYO 2XX/3XX/4XX silver cores to Spectre BHB safe list - [arm64] KVM: arm64: Tear down vGIC on failed vCPU creation - spi: cadence-qspi: Fix probe on AM62A LP SK - tpm, tpm_tis: Fix timeout handling when waiting for TPM status - media: streamzap: prevent processing IR data on URB failure - media: platform: stm32: Add check for clk_enable() - media: v4l2-dv-timings: prevent possible overflow in v4l2_detect_gtf() - media: i2c: ccs: Set the device's runtime PM status correctly in remove - media: i2c: ccs: Set the device's runtime PM status correctly in probe - media: i2c: ov7251: Set enable GPIO low in probe - media: i2c: ov7251: Introduce 1 ms delay between regulators and en GPIO - mptcp: sockopt: fix getting IPV6_V6ONLY - mtd: Add check for devm_kcalloc() - [arm64,armhf] net: dsa: mv88e6xxx: workaround RGMII transmit delay erratum for 6320 family - wifi: mt76: Add check for devm_kstrdup() - wifi: mac80211: fix integer overflow in hwmp_route_info_get() - io_uring/kbuf: reject zero sized provided buffers - bus: mhi: host: Fix race between unprepare and queue_buf - ext4: fix off-by-one error in do_split - [armhf] soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() - smb311 client: fix missing tcon check when mounting with linux/posix extensions - i3c: master: svc: Use readsb helper for reading MDB - i3c: Add NULL pointer check in i3c_master_queue_ibi() - jbd2: remove wrong sb->s_sequence check - [armhf] mfd: ene-kb3930: Fix a potential NULL pointer dereference - locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class() - lib: scatterlist: fix sg_split_phys to preserve original scatterlist offsets - mptcp: fix NULL pointer in can_accept_new_subflow - mptcp: only inc MPJoinAckHMacFailure for HMAC failures - mtd: inftlcore: Add error check for inftl_read_oob() - mtd: rawnand: Add status chack in r852_ready() - [arm64] mm: Correct the update of max_pfn - [arm64] dts: mediatek: mt8173: Fix disp-pwm compatible string - btrfs: fix non-empty delayed iputs list on unmount due to compressed write workers - mm/rmap: reject hugetlb folios in folio_make_device_exclusive() - mm: add missing release barrier on PGDAT_RECLAIM_LOCKED unlock - mm/hwpoison: do not send SIGBUS to processes with recovered clean pages - sctp: detect and prevent references to a freed transport in sendmsg - thermal/drivers/rockchip: Add missing rk3328 mapping entry - cifs: avoid NULL pointer dereference in dbg call - cifs: fix integer overflow in match_server() - [arm64] clk: qcom: gdsc: Release pm subdomains in reverse add order - [arm64] clk: qcom: gdsc: Capture pm_genpd_add_subdomain result code - [arm64] clk: qcom: gdsc: Set retain_ff before moving to HW CTRL - [x86] crypto: ccp - Fix check for the primary ASP device - dm-integrity: set ti->error on memory allocation failure - dm-verity: fix prefetch-vs-suspend race - ftrace: Add cond_resched() to ftrace_graph_set_hash() - [arm64] gpio: zynq: Fix wakeup source leaks on device unbind - gve: handle overflow when reporting TX consumed descriptors - [x86] KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses - of/irq: Fix device node refcount leakage in API of_irq_parse_one() - of/irq: Fix device node refcount leakage in API of_irq_parse_raw() - of/irq: Fix device node refcount leakages in of_irq_count() - of/irq: Fix device node refcount leakage in API irq_of_parse_and_map() - of/irq: Fix device node refcount leakages in of_irq_init() - PCI: brcmstb: Fix missing of_node_put() in brcm_pcie_probe() - PCI: Fix reference leak in pci_alloc_child_bus() - [arm64] pinctrl: qcom: Clear latched interrupt status when changing IRQ type - [arm64] errata: Add newer ARM cores to the spectre_bhb_loop_affected() lists - [x86] ACPI: platform-profile: Fix CFI violation when accessing sysfs files - [x86] e820: Fix handling of subpage regions when calculating nosave ranges in e820__register_nosave_regions() - Bluetooth: hci_uart: Fix another race during initialization - [armhf] HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition (CVE-2025-37838) - [arm64] scsi: hisi_sas: Enable force phy when SATA disk directly connected - wifi: at76c50x: fix use after free access in at76_disconnect - wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue() - wifi: mac80211: Purge vif txq in ieee80211_do_stop() - wifi: wl1251: fix memory leak in wl1251_tx_work - scsi: iscsi: Fix missing scsi_host_put() in error path - md/raid10: fix missing discard IO accounting - md/md-bitmap: fix stats collection for external bitmaps - [amd64] RDMA/usnic: Fix passing zero to PTR_ERR in usnic_ib_pci_probe() - [arm64] RDMA/hns: Fix wrong maximum DMA segment size - RDMA/core: Silence oversized kvmalloc() warning - Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for invalid address - Bluetooth: btrtl: Prevent potential NULL dereference - Bluetooth: l2cap: Check encryption key size on incoming connection - Revert "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()" - igc: fix PTM cycle trigger logic - igc: move ktime snapshot into PTM retry loop - igc: handle the IGC_PTP_ENABLED flag correctly - igc: cleanup PTP module if probe fails - net: mctp: Set SOCK_RCU_FREE - net: openvswitch: fix nested key length validation in the set() action - cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error path - net: b53: enable BPDU reception for management port - net: bridge: switchdev: do not notify new brentries as changed - [arm64,armhf] net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered - [arm64,armhf] net: dsa: mv88e6xxx: fix -ENOENT when deleting VLANs and MST is unsupported - [arm64,armhf] net: dsa: avoid refcount warnings when ds->ops->tag_8021q_vlan_del() fails - ptp: ocp: fix start time alignment in ptp_ocp_signal_set - cpufreq/sched: Fix the usage of CPUFREQ_NEED_UPDATE_LIMITS - writeback: fix false warning in inode_to_wb() - Revert "PCI: Avoid reset when disabled via sysfs" - [x86] asus-laptop: Fix an uninitialized variable - nfs: move nfs_fhandle_hash to common include file - nfs: add missing selections of CONFIG_CRC32 - nfsd: decrease sc_count directly if fail to queue dl_recall - btrfs: correctly escape subvol in btrfs_show_options() - hfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key - i2c: cros-ec-tunnel: defer probe if parent EC is not present - isofs: Prevent the use of too small fid - loop: properly send KOBJ_CHANGED uevent for disk device - loop: LOOP_SET_FD: send uevents for partitions - mm/gup: fix wrongly calculated returned value in fault_in_safe_writeable() - mm: fix filemap_get_folios_contig returning batches of identical folios - ksmbd: Fix dangling pointer in krb_authenticate - ksmbd: Prevent integer overflow in calculation of deadtime - ksmbd: fix the warning from __kernel_write_iter - smb3 client: fix open hardlink on deferred close file error - string: Add load_unaligned_zeropad() code path to sized_strscpy() - tracing: Fix filter string testing - virtiofs: add filesystem context source name check - scsi: megaraid_sas: Block zero-length ATA VPD inquiry - scsi: ufs: exynos: Ensure consistent phy reference counts - [x86] perf/x86/intel: Allow to update user space GPRs from PEBS records - [x86] perf/x86/intel/uncore: Fix the scale of IIO free running counters on SNR - [x86] perf/x86/intel/uncore: Fix the scale of IIO free running counters on ICX - [x86] perf/x86/intel/uncore: Fix the scale of IIO free running counters on SPR - [arm64] drm/msm/a6xx: Fix stale rpmh votes from GPU - drm/amd: Handle being compiled without SI or CIK support better - drm/amd/pm: Prevent division by zero - drm/amd/pm/powerplay: Prevent division by zero - drm/amd/pm/smu11: Prevent division by zero - drm/amd/pm/powerplay/hwmgr/smu7_thermal: Prevent division by zero - drm/amd/pm/swsmu/smu13/smu_v13_0: Prevent division by zero - drm/amd/pm/powerplay/hwmgr/vega20_thermal: Prevent division by zero - drm/amdgpu/dma_buf: fix page_link check - drm/nouveau: prime: fix ttm_bo_delayed_delete oops - [x86] drm/i915/gvt: fix unterminated-string-initialization warning - io_uring/net: fix accept multishot handling - [arm64] KVM: arm64: Discard any SVE state when entering KVM guests - [arm64] fpsimd: Track the saved FPSIMD state type separately to TIF_SVE - [arm64] fpsimd: Have KVM explicitly say which FP registers to save - [arm64] fpsimd: Stop using TIF_SVE to manage register saving in KVM - [arm64] KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state - [arm64] KVM: arm64: Remove host FPSIMD saving for non-protected KVM - [arm64] KVM: arm64: Remove VHE host restore of CPACR_EL1.ZEN - [arm64] KVM: arm64: Remove VHE host restore of CPACR_EL1.SMEN - [arm64] KVM: arm64: Refactor exit handlers - [arm64] KVM: arm64: Mark some header functions as inline - [arm64] KVM: arm64: Calculate cptr_el2 traps on activating traps - [arm64] KVM: arm64: Eagerly switch ZCR_EL{1,2} - cpufreq: Reference count policy in cpufreq_update_limits() - kbuild: Add '-fno-builtin-wcslen' - mptcp: sockopt: fix getting freebind & transparent - mm: Fix is_zero_page() usage in try_grab_page() (Closes: #1102914) - [x86] split_lock: Fix the delayed detection logic - [x86] pvh: Call C code via the kernel virtual mapping - [powerpc*] rtas: Prevent Spectre v1 gadget construction in sys_rtas() (CVE-2024-46774) - btrfs: fix qgroup reserve leaks in cow_file_range (CVE-2024-46733) - btrfs: zoned: fix zone activation with missing devices - btrfs: zoned: fix zone finishing with missing devices - Revert "Xen/swiotlb: mark xen_swiotlb_fixup() __init" - drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (CVE-2024-46816) - landlock: Add the errata interface - nvmet-fc: Remove unused functions - smb/server: fix potential null-ptr-deref of lease_ctx_info in smb2_open() (CVE-2024-46742) - cifs: use origin fullpath for automounts - btrfs: fix the length of reserved qgroup to free - bpf: avoid holding freeze_mutex during mmap operation (CVE-2025-21853) - bpf: Prevent tail call between progs attached to different hooks (CVE-2024-50063) - blk-cgroup: support to track if policy is online - blk-iocost: do not WARN if iocg was already offlined (CVE-2024-36908) - mm: fix apply_to_existing_page_range() - sign-file,extract-cert: move common SSL helper functions to a header - sign-file,extract-cert: avoid using deprecated ERR_get_error_line() - sign-file,extract-cert: use pkcs11 provider for OPENSSL MAJOR >= 3 - [mips*] ds1287: Match ds1287_set_base_clock() function types - md: factor out a helper from mddev_put() - md: fix mddev uaf while iterating all_mddevs list (CVE-2025-22126) (Closes: #1086175) . [ Salvatore Bonaccorso ] * Bump ABI to 34 . [ Ben Hutchings ] * d/rules.d/certs: Add newly required include directory to CPPFLAGS Checksums-Sha1: 0643ddf1f991db911511891c1a69c8f5513a285c 833980 bpftool-dbgsym_7.1.0+6.1.135-1_amd64.deb 35f59756f3842b511dce8407691495c95d040c58 1240724 bpftool_7.1.0+6.1.135-1_amd64.deb e1ee3e715f23931cc30c5d6111a6e2489735e3af 48660 hyperv-daemons-dbgsym_6.1.135-1_amd64.deb 9bcf61978c3d6712786c54f69adb5bcfb67729e0 1006844 hyperv-daemons_6.1.135-1_amd64.deb 3d2754d346419a4bc1a453036bc4f59c6fb6ff1b 991188 libcpupower-dev_6.1.135-1_amd64.deb 2e971bf4be1dbac445ea6994552154e90653e542 25052 libcpupower1-dbgsym_6.1.135-1_amd64.deb 3d79b839d5fd6412aeabcb302b9e93c55a08a3e0 997296 libcpupower1_6.1.135-1_amd64.deb f1387ca71cc025799d66cc086bfd79d2fdd3b1ed 989264 linux-compiler-gcc-12-x86_6.1.135-1_amd64.deb f397a255fafb166b7157509701c4dbdfbf937ac5 1123260 linux-config-6.1_6.1.135-1_amd64.deb b8ea6a96faa6c98469ab256a6beeaf7563146a25 211500 linux-cpupower-dbgsym_6.1.135-1_amd64.deb e301e8a8e68dfe16f742feb7cbf64471fd2f5aa1 1100756 linux-cpupower_6.1.135-1_amd64.deb 2c39c8bf54a053b6e8a2dcfdec84ff613246ede1 1520264 linux-headers-6.1.0-34-amd64_6.1.135-1_amd64.deb 24acfb66c668165ac6bd9ebc3452864d57f6513b 1272036 linux-headers-6.1.0-34-cloud-amd64_6.1.135-1_amd64.deb 615aa1112ea20ef00ca0146ec7f021697891ce2f 1520004 linux-headers-6.1.0-34-rt-amd64_6.1.135-1_amd64.deb 6f99b164ef8d5931ee1427ee80706039088719d6 854259744 linux-image-6.1.0-34-amd64-dbg_6.1.135-1_amd64.deb 093e3cdbb8f8990257fec235f22db1f02683ed8e 67953192 linux-image-6.1.0-34-amd64-unsigned_6.1.135-1_amd64.deb fa39f63bc8ae824a7167babf31c8d7fae39a40cf 280914988 linux-image-6.1.0-34-cloud-amd64-dbg_6.1.135-1_amd64.deb 59eaae4c0e8a5bbdd070a40291b60fe810d9e80f 25649192 linux-image-6.1.0-34-cloud-amd64-unsigned_6.1.135-1_amd64.deb 47622405a2dadd78c1f595750863c8b5f308c81e 856544696 linux-image-6.1.0-34-rt-amd64-dbg_6.1.135-1_amd64.deb ed27401ec8cf2f47dd89409f8710cf721779e953 67917036 linux-image-6.1.0-34-rt-amd64-unsigned_6.1.135-1_amd64.deb 5572a0792c2c0dd041d459b1d2d340542425bb66 1296 linux-image-amd64-dbg_6.1.135-1_amd64.deb cb0d8e30811814065bb780613c816949ddaad3bb 1767660 linux-image-amd64-signed-template_6.1.135-1_amd64.deb 4e10794b144aa53cdb7f7dbbb05927a7e70e4308 1320 linux-image-cloud-amd64-dbg_6.1.135-1_amd64.deb 2fbdec1c3259bb0fb4fdc6c335892a3a08fa9387 1316 linux-image-rt-amd64-dbg_6.1.135-1_amd64.deb b22b5436b3d5ee8d8fa6622ad047894e2298052d 1029412 linux-kbuild-6.1-dbgsym_6.1.135-1_amd64.deb 155ca51a015f5f120fbcb12a1a50a9585ddaf2dd 1247488 linux-kbuild-6.1_6.1.135-1_amd64.deb 9f9a684869eb4fb2ad559d95250151f6539de3ff 2135840 linux-libc-dev_6.1.135-1_amd64.deb f36267b2cb777ca62e2d1a36b499363686278c2c 8118300 linux-perf-dbgsym_6.1.135-1_amd64.deb 3b744694d089f3860315801af966a77344dd8bef 3109488 linux-perf_6.1.135-1_amd64.deb 60d09fa04d4964f5e5be12dcd2264f0422a11376 20444 linux_6.1.135-1_amd64-buildd.buildinfo 899ebe47aa81bfb392a7c510e5dae0ac4763deba 1027160 rtla_6.1.135-1_amd64.deb a75dda1dd8755790542ea5daedec9329cfa2c24a 145308 usbip-dbgsym_2.0+6.1.135-1_amd64.deb fc394f8c3d2aef1e1c3ce1ab4bb54ef6ee918356 1032160 usbip_2.0+6.1.135-1_amd64.deb Checksums-Sha256: 5224e865c09c2dc1f586b0e8a133d7dc3eef6630b893dba2fd2f5175866eb203 833980 bpftool-dbgsym_7.1.0+6.1.135-1_amd64.deb 17082fb9f877ef4cc44b79c4d041034d4c996da88e52e0d55cb87044bd85fb9e 1240724 bpftool_7.1.0+6.1.135-1_amd64.deb 9cf72e5300a9e1014e781ca7f6687eb39bfc4a1f5c0e94d5034d3813d074cd53 48660 hyperv-daemons-dbgsym_6.1.135-1_amd64.deb 8113766f279dd24da64a422724bab2c98c710fba9483c8cdce02a459903343d2 1006844 hyperv-daemons_6.1.135-1_amd64.deb 360542673074f254aa2f8b92d7c11c42305acd3c3d2e9c057b6fd2bc0b405ed5 991188 libcpupower-dev_6.1.135-1_amd64.deb 001f43aa4bae6a61809ce9067e03007275967ca560415e2257396f3a4938d558 25052 libcpupower1-dbgsym_6.1.135-1_amd64.deb 812db9715f754f164d17ec27faf743d58dd821ef4af20a34fc06f3bbc73d5fea 997296 libcpupower1_6.1.135-1_amd64.deb 07b1602eba05ce33fcd3c0ba6ea15b62cfd64b6fbd5985309a0f721a264835ea 989264 linux-compiler-gcc-12-x86_6.1.135-1_amd64.deb 251ac93043936a591070274f2330f486216f951842e5db48a20c69dbe19303c1 1123260 linux-config-6.1_6.1.135-1_amd64.deb 2aed2665384ce9bbd8d6caa224c462c366c629ea524c04c84bc5c2edba1fef45 211500 linux-cpupower-dbgsym_6.1.135-1_amd64.deb e84d4b989c30f24b93b06e5d3db15f4a0b84a701cf864a97d08c490efe1d706e 1100756 linux-cpupower_6.1.135-1_amd64.deb 8ecc898ee1fd2d40422498ba4d1472bb87b47d3203d1ff870301df7ba864a6d1 1520264 linux-headers-6.1.0-34-amd64_6.1.135-1_amd64.deb 86dd8dbe3f9391ff454d5a5ed30f5afc3dc8c0173f5d1f8046aacc4d270ef253 1272036 linux-headers-6.1.0-34-cloud-amd64_6.1.135-1_amd64.deb 8e0f5f84570dafbf1dc541395e55d7b314d894b19f3270fed8119760da115900 1520004 linux-headers-6.1.0-34-rt-amd64_6.1.135-1_amd64.deb e93e53f862adea00e944026744890acc229cd7d33fc01bce7bbe00418fd7dd3c 854259744 linux-image-6.1.0-34-amd64-dbg_6.1.135-1_amd64.deb 46775cd49aff73955d6ab20abbccccc4677b91033eac0f2b9febd9e615bd8fdc 67953192 linux-image-6.1.0-34-amd64-unsigned_6.1.135-1_amd64.deb 0c84c55c512a2f9d4be6f7e4568da665c9a402ae8033e68a51d5efcbe13b5b90 280914988 linux-image-6.1.0-34-cloud-amd64-dbg_6.1.135-1_amd64.deb 84a31ecc368a0514bee8ebee86bdc303fe032b55f258ab3e2d658524adb092ca 25649192 linux-image-6.1.0-34-cloud-amd64-unsigned_6.1.135-1_amd64.deb 45a9b21e3cdea2b5c7f4492828639024fe3375fa9efe430ba1f9e3e199524d04 856544696 linux-image-6.1.0-34-rt-amd64-dbg_6.1.135-1_amd64.deb 80f0f8af26c45b69d223497f5e0a7ad25d69965e4125b4752cf242c8f81da4bc 67917036 linux-image-6.1.0-34-rt-amd64-unsigned_6.1.135-1_amd64.deb 6b9486d8ebe3fa7733460f0297a139bebde5f6fb0baef3f217a86a8f82c4fe4f 1296 linux-image-amd64-dbg_6.1.135-1_amd64.deb 9fe473178aff492c25962ddee5eeaf560f94d151aa2f175e95e78752ba98c016 1767660 linux-image-amd64-signed-template_6.1.135-1_amd64.deb e6f644eef61c625e6b6fec14f93ba01e1413dab3811fd042c4ac3fe58969c537 1320 linux-image-cloud-amd64-dbg_6.1.135-1_amd64.deb ef21db03b332d095f76ea612bddc58628c13fe58e838c7b4c2fd51fba4b82596 1316 linux-image-rt-amd64-dbg_6.1.135-1_amd64.deb 6c790bcae24b5ebb64055562ad30979807d0f999580f0e8e80be4c5713e92a8b 1029412 linux-kbuild-6.1-dbgsym_6.1.135-1_amd64.deb c46acf191fe9ad8b03f0c9207f94864e245cb8a3175f7cf17174442afd34b7a2 1247488 linux-kbuild-6.1_6.1.135-1_amd64.deb 5de010105a38035e96eb39344dd848fcc85da97b676bceef4706db5ae622bba4 2135840 linux-libc-dev_6.1.135-1_amd64.deb bee439d7173f575fac06a0a471852f60ab5d3c3b626b98d672c2b6b9e201404d 8118300 linux-perf-dbgsym_6.1.135-1_amd64.deb 163f5cfa475ab096caa583e9c8271c6a0b835cc8d920a2a1acc0891dc405dcca 3109488 linux-perf_6.1.135-1_amd64.deb 1df9df8264512dda11a678cc5ceacd0bad640603a0f839d1e2fd8183f5616249 20444 linux_6.1.135-1_amd64-buildd.buildinfo 194bf66a5472485e4c5bc2dbb168c3e8cac3fee85bad87af0a5d5d827ddefda2 1027160 rtla_6.1.135-1_amd64.deb af35b43a3e0cdc74bebcff4f14bb328789c75d1b95b60920490dddccb07dd2d1 145308 usbip-dbgsym_2.0+6.1.135-1_amd64.deb 3a5d3cd94c960864dcd82d4f97e8dbe821b8ae06914a4336e0b30152c07f1266 1032160 usbip_2.0+6.1.135-1_amd64.deb Files: e405ff9446cca4075a2f73eef3e1f50f 833980 debug optional bpftool-dbgsym_7.1.0+6.1.135-1_amd64.deb 9254c3833cc4ef7e820f79656f95b617 1240724 devel optional bpftool_7.1.0+6.1.135-1_amd64.deb c4dac2a76801cef87fabf5fea8fb866b 48660 debug optional hyperv-daemons-dbgsym_6.1.135-1_amd64.deb 360b2b5d2ee63b7c5b5cb70952f429e1 1006844 admin optional hyperv-daemons_6.1.135-1_amd64.deb 874e1b61e8c049cb2ff34ef7df8534eb 991188 libdevel optional libcpupower-dev_6.1.135-1_amd64.deb 8438fd98731d4126588451cf85dc1aa9 25052 debug optional libcpupower1-dbgsym_6.1.135-1_amd64.deb a1fa4e4a729d48d85acffb31e58f3835 997296 libs optional libcpupower1_6.1.135-1_amd64.deb 2ea45a27b077d937ffc1882ff2733de7 989264 kernel optional linux-compiler-gcc-12-x86_6.1.135-1_amd64.deb 9c58f641620c12afce9ec4e5e50c2ce3 1123260 kernel optional linux-config-6.1_6.1.135-1_amd64.deb 890539574ba9ba651f2afa8c2c371024 211500 debug optional linux-cpupower-dbgsym_6.1.135-1_amd64.deb 8eafc619e4677892e67bf9ae159cfd02 1100756 admin optional linux-cpupower_6.1.135-1_amd64.deb febba4b2cee91b94b6265e868efd0e2c 1520264 kernel optional linux-headers-6.1.0-34-amd64_6.1.135-1_amd64.deb cec624dd0fa9fe592f5f4064b29843d4 1272036 kernel optional linux-headers-6.1.0-34-cloud-amd64_6.1.135-1_amd64.deb 890ef49a12f8671b1aa7d45d9c5ef46e 1520004 kernel optional linux-headers-6.1.0-34-rt-amd64_6.1.135-1_amd64.deb 0d5a58e7dacfaea33db8c2c6deaf5eba 854259744 debug optional linux-image-6.1.0-34-amd64-dbg_6.1.135-1_amd64.deb 6b7ab2697cc3c943a8ac2e346a8b54ba 67953192 kernel optional linux-image-6.1.0-34-amd64-unsigned_6.1.135-1_amd64.deb 476b5ac9ab7054181ee0fb567e40293a 280914988 debug optional linux-image-6.1.0-34-cloud-amd64-dbg_6.1.135-1_amd64.deb efb7e8e827285b2cdf6c79aef148d63c 25649192 kernel optional linux-image-6.1.0-34-cloud-amd64-unsigned_6.1.135-1_amd64.deb 3f5a6c6638b5cbeebba4a79cd8903b76 856544696 debug optional linux-image-6.1.0-34-rt-amd64-dbg_6.1.135-1_amd64.deb 648914cea6368eb1cfc73df80b061e5d 67917036 kernel optional linux-image-6.1.0-34-rt-amd64-unsigned_6.1.135-1_amd64.deb 6000958bc3501c71b09406749d37a191 1296 kernel optional linux-image-amd64-dbg_6.1.135-1_amd64.deb 47de81d30b9c253af84a3b1b0634ac05 1767660 kernel optional linux-image-amd64-signed-template_6.1.135-1_amd64.deb d534b5906238b7e1eef259332a29b343 1320 kernel optional linux-image-cloud-amd64-dbg_6.1.135-1_amd64.deb 9d61cfb08c8c3c27a284cbe79af7310e 1316 kernel optional linux-image-rt-amd64-dbg_6.1.135-1_amd64.deb 83857687a237c94ef8595a465232a27f 1029412 debug optional linux-kbuild-6.1-dbgsym_6.1.135-1_amd64.deb ad5ed9e8b7f0296478cc9c8a4a68b6b2 1247488 kernel optional linux-kbuild-6.1_6.1.135-1_amd64.deb be73e76b371409f49d55e5c93e664cc9 2135840 devel optional linux-libc-dev_6.1.135-1_amd64.deb 5c50b3461340bf0f5ff743b2606c34d8 8118300 debug optional linux-perf-dbgsym_6.1.135-1_amd64.deb fd07adb7f58bb0d5f31cbca3f8310d36 3109488 devel optional linux-perf_6.1.135-1_amd64.deb 4df624beb605725e004582b82f73d9bc 20444 kernel optional linux_6.1.135-1_amd64-buildd.buildinfo 52211287627ad2aac5b02b4ed8397c22 1027160 devel optional rtla_6.1.135-1_amd64.deb fef9cc94dce01468d77c972790d644b2 145308 debug optional usbip-dbgsym_2.0+6.1.135-1_amd64.deb 8e98dbf36d7dc88ab7b354c9e7163614 1032160 admin optional usbip_2.0+6.1.135-1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEv2qEY4xQXyY/2dWIvGw9w6VrLCcFAmgMO84ACgkQvGw9w6Vr LCdijhAAmqoLYKxbLIrcY1W6V0EbqZ0eriUP7HMHjC3Jmor3v9lbPLcp4o4ILmr+ tsG7+kjLr3OrMZTnm+Mw83jwOEVysOqFLbSzscyxd78FrtltCK+81qMbnrJwuCSr 8SgjzMUyzYvQUgdIdx2CJlUgy2U+jZJgSNPvKFADpg+1j814m9elYhMLFj63j7/z Pgx9SpehQ7luLGlcfdZ2yyp8RePYPGp9tirnMXBz+ZbUB7g7vouVKTRl/ms0aUPh mnHQCVS7VRt/PxLIIDGSEh9DsDQHtTYs4AbXfj9kBK4hrrFv8MOaO654XOmyBDGk UqIAI+1EIMly5qPGWikUvIgmIuGW15ZojdJg03CZFVuQj1V0U/3uUe6WvOFruv6e Nj5lAYTR3mVzoaIqsqkcUsWdadMpNw28isq0/aL9KM0euwSzXdYi65Kf9SkjHhDa zMYzcVi3xlbWaSi0sKalhY5nVb10YYQSWdOVMr0V9MfAwkAGZEnNnpvX12iS9rq9 YQYp/WV8OfFWcvbsrtRX4ZfzSZ2U/gY+/wETr1x2Rmq11hQmMfCo4rCogaR2OKDu eSnZhEieFXT4J9Jgu1guqI62AAAyV+TJqQkkYcFC3tO995gp/SiszOybGrDnEZyV yP/EexLG7QHzWvukPbWjKI0QBPP3ciNcl1iGmLJ0Mwg89FTNbxs= =Adbg -----END PGP SIGNATURE-----