This bug was fixed in the package linux-hwe-6.2 - 6.2.0-32.32~22.04.1 --------------- linux-hwe-6.2 (6.2.0-32.32~22.04.1) jammy; urgency=medium
* jammy/linux-hwe-6.2: 6.2.0-32.32~22.04.1 -proposed tracker (LP: #2030380) [ Ubuntu: 6.2.0-32.32 ] * lunar/linux: 6.2.0-32.32 -proposed tracker (LP: #2031134) * libgnutls report "trap invalid opcode" when trying to install packages over https (LP: #2031093) - [Config]: disable CONFIG_GDS_FORCE_MITIGATION [ Ubuntu: 6.2.0-30.30 ] * lunar/linux: 6.2.0-30.30 -proposed tracker (LP: #2030381) * CVE-2022-40982 - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - ARM: cpu: Switch to arch_cpu_finalize_init() - ia64/cpu: Switch to arch_cpu_finalize_init() - m68k/cpu: Switch to arch_cpu_finalize_init() - mips/cpu: Switch to arch_cpu_finalize_init() - sh/cpu: Switch to arch_cpu_finalize_init() - sparc/cpu: Switch to arch_cpu_finalize_init() - um/cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - init: Invoke arch_cpu_finalize_init() earlier - init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init() - x86/init: Initialize signal frame size late - x86/fpu: Remove cpuinfo argument from init functions - x86/fpu: Mark init functions __init - x86/fpu: Move FPU initialization into arch_cpu_finalize_init() - x86/mem_encrypt: Unbreak the AMD_MEM_ENCRYPT=n build - x86/xen: Fix secondary processors' FPU initialization - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM - Documentation/x86: Fix backwards on/off logic about YMM support - [Config]: Enable CONFIG_ARCH_HAS_CPU_FINALIZE_INIT and CONFIG_GDS_FORCE_MITIGATION * CVE-2023-4015 - netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain - netfilter: nf_tables: unbind non-anonymous set if rule construction fails - netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR * CVE-2023-3995 - netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID * CVE-2023-3777 - netfilter: nf_tables: skip bound chain on rule flush * CVE-2023-3609 - net/sched: cls_u32: Fix reference counter leak leading to overflow * NULL pointer dereference on CS35L41 HDA AMP (LP: #2029199) - ASoC: cs35l41: Refactor error release code - ALSA: cs35l41: Add shared boost feature - ASoC: dt-bindings: cirrus, cs35l41: Document CS35l41 shared boost - ALSA: hda: cs35l41: Ensure firmware/tuning pairs are always loaded - ALSA: hda: cs35l41: Enable Amp High Pass Filter - ALSA: cs35l41: Use mbox command to enable speaker output for external boost - ALSA: cs35l41: Poll for Power Up/Down rather than waiting a fixed delay - ALSA: hda: cs35l41: Check mailbox status of pause command after firmware load - ALSA: hda: cs35l41: Ensure we correctly re-sync regmap before system suspending. - ALSA: hda: cs35l41: Ensure we pass up any errors during system suspend. - ALSA: hda: cs35l41: Move Play and Pause into separate functions - ALSA: hda: hda_component: Add pre and post playback hooks to hda_component - ALSA: hda: cs35l41: Use pre and post playback hooks - ALSA: hda: cs35l41: Rework System Suspend to ensure correct call separation - ALSA: hda: cs35l41: Add device_link between HDA and cs35l41_hda - ALSA: hda: cs35l41: Ensure amp is only unmuted during playback * Reboot command powers off the system (LP: #2029332) - x86/smp: Make stop_other_cpus() more robust - x86/smp: Dont access non-existing CPUID leaf * losetup with mknod fails on jammy with kernel 5.15.0-69-generic (LP: #2015400) - loop: deprecate autoloading callback loop_probe() - loop: do not enforce max_loop hard limit by (new) default * Fix UBSAN in Intel EDAC driver (LP: #2028746) - EDAC/skx_common: Enable EDAC support for the "near" memory - EDAC/skx_common: Delete duplicated and unreachable code - EDAC/i10nm: Add Intel Emerald Rapids server support - EDAC/i10nm: Make more configurations CPU model specific - EDAC/i10nm: Add Intel Granite Rapids server support - EDAC/i10nm: Skip the absent memory controllers * Make TTY switching possible for NVIDIA when it's boot VGA (LP: #2028749) - drm/gma500: Use drm_aperture_remove_conflicting_pci_framebuffers - video/aperture: use generic code to figure out the vga default device - drm/aperture: Remove primary argument - video/aperture: Only kick vgacon when the pdev is decoding vga - video/aperture: Move vga handling to pci function - video/aperture: Drop primary argument - video/aperture: Only remove sysfb on the default vga pci device - fbdev: Simplify fb_is_primary_device for x86 - video/aperture: Provide a VGA helper for gma500 and internal use * Fix AMD gpu hang when screen off/on (LP: #2028740) - drm/amd/display: Keep PHY active for dp config * Various backlight issues with the 6.0/6.1 kernel (LP: #2023638) - ACPI: video: Stop trying to use vendor backlight control on laptops from after ~2012 * FM350(mtk_t7xx) failed to suspend, or early wake while suspending (LP: #2020743) - net: wwan: t7xx: Ensure init is completed before system sleep * Include the MAC address pass through function on RTL8153DD-CG (LP: #2020295) - r8152: add USB device driver for config selection * CVE-2023-20593 - x86/cpu/amd: Move the errata checking functionality up - x86/cpu/amd: Add a Zenbleed fix * CVE-2023-4004 - netfilter: nft_set_pipapo: fix improper element removal * CVE-2023-3611 - net/sched: sch_qfq: refactor parsing of netlink parameters - net/sched: sch_qfq: account for stab overhead in qfq_enqueue * CVE-2023-3610 - netfilter: nf_tables: fix chain binding transaction logic * CVE-2023-2898 - f2fs: fix to avoid NULL pointer dereference f2fs_write_end_io() * Fix speaker volume too low on HP G10 laptops (LP: #2023197) - ALSA: hda/realtek: Enable 4 amplifiers instead of 2 on a HP platform * stacked overlay file system mounts that have chroot() called against them appear to be getting locked (by the kernel most likely?) (LP: #2016398) - SAUCE: overlayfs: fix reference count mismatch * arm64+ast2600: No Output from BMC's VGA port (LP: #2026776) - drm/ast: Fix ARM compatibility * Fix eDP only displays 3/4 area after switching to mirror mode with external HDMI 4K monitor (LP: #2024273) - drm/i915: Allow arbitrary refresh rates with VRR eDP panels * Fix AMDGPU: the screen freeze with W7500 (LP: #2027957) - drm/amd/pm: share the code around SMU13 pcie parameters update - drm/amd/pm: conditionally disable pcie lane/speed switching for SMU13 - drm/amd: Move helper for dynamic speed switch check out of smu13 - drm/amd: Align SMU11 SMU_MSG_OverridePcieParameters implementation with SMU13 * UBSAN: shift-out-of-bounds in amd_sfh (LP: #2027773) - HID: amd_sfh: Rename the float32 variable - HID: amd_sfh: Fix for shift-out-of-bounds * cifs: fix mid leak during reconnection after timeout threshold (LP: #2029138) - cifs: fix mid leak during reconnection after timeout threshold * Lunar update: upstream stable patchset 2023-07-28 (LP: #2028979) - usb: dwc3: fix gadget mode suspend interrupt handler issue - tpm, tpm_tis: Avoid cache incoherency in test for interrupts - tpm, tpm_tis: Only handle supported interrupts - tpm_tis: Use tpm_chip_{start,stop} decoration inside tpm_tis_resume - tpm, tpm_tis: startup chip before testing for interrupts - tpm: Re-enable TPM chip boostrapping non-tpm_tis TPM drivers - tpm: Prevent hwrng from activating during resume - watchdog: sp5100_tco: Immediately trigger upon starting. - drm/amd/display: hpd rx irq not working with eDP interface - ocfs2: Switch to security_inode_init_security() - platform/x86/intel/ifs: Annotate work queue on stack so object debug does not complain - ALSA: hda/ca0132: add quirk for EVGA X299 DARK - ALSA: hda: Fix unhandled register update during auto-suspend period - ALSA: hda/realtek: Enable headset onLenovo M70/M90 - SUNRPC: Don't change task->tk_status after the call to rpc_exit_task - mmc: sdhci-esdhc-imx: make "no-mmc-hs400" works - mmc: block: ensure error propagation for non-blk - power: supply: axp288_fuel_gauge: Fix external_power_changed race - power: supply: bq25890: Fix external_power_changed race - ASoC: rt5682: Disable jack detection interrupt during suspend - net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize - m68k: Move signal frame following exception on 68020/030 - xtensa: fix signal delivery to FDPIC process - xtensa: add __bswap{si,di}2 helpers - parisc: Use num_present_cpus() in alternative patching code - parisc: Handle kgdb breakpoints only in kernel context - parisc: Fix flush_dcache_page() for usage from irq context - parisc: Allow to reboot machine after system halt - parisc: Enable LOCKDEP support - parisc: Handle kprobes breakpoints only in kernel context - gpio: mockup: Fix mode of debugfs files - btrfs: use nofs when cleaning up aborted transactions - dt-binding: cdns,usb3: Fix cdns,on-chip-buff-size type - drm/mgag200: Fix gamma lut not initialized. - drm/radeon: reintroduce radeon_dp_work_func content - drm/amd/pm: add missing NotifyPowerSource message mapping for SMU13.0.7 - drm/amd/pm: Fix output of pp_od_clk_voltage - Revert "binder_alloc: add missing mmap_lock calls when using the VMA" - Revert "android: binder: stop saving a pointer to the VMA" - binder: add lockless binder_alloc_(set|get)_vma() - binder: fix UAF caused by faulty buffer cleanup - binder: fix UAF of alloc->vma in race with munmap() - selftests/memfd: Fix unknown type name build failure - drm/amd/amdgpu: limit one queue per gang - perf/x86/uncore: Correct the number of CHAs on SPR - x86/topology: Fix erroneous smp_num_siblings on Intel Hybrid platforms - irqchip/mips-gic: Don't touch vl_map if a local interrupt is not routable - irqchip/mips-gic: Use raw spinlock for gic_lock - debugobjects: Don't wake up kswapd from fill_pool() - fbdev: udlfb: Fix endpoint check - net: fix stack overflow when LRO is disabled for virtual interfaces - udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). - USB: core: Add routines for endpoint checks in old drivers - USB: sisusbvga: Add endpoint checks - media: radio-shark: Add endpoint checks - ASoC: lpass: Fix for KASAN use_after_free out of bounds - net: fix skb leak in __skb_tstamp_tx() - drm: fix drmm_mutex_init() - selftests: fib_tests: mute cleanup error message - octeontx2-pf: Fix TSOv6 offload - bpf: Fix mask generation for 32-bit narrow loads of 64-bit fields - bpf: fix a memory leak in the LRU and LRU_PERCPU hash maps - lan966x: Fix unloading/loading of the driver - ipv6: Fix out-of-bounds access in ipv6_find_tlv() - cifs: mapchars mount option ignored - power: supply: leds: Fix blink to LED on transition - power: supply: mt6360: add a check of devm_work_autocancel in mt6360_charger_probe - power: supply: bq27xxx: Fix bq27xxx_battery_update() race condition - power: supply: bq27xxx: Fix I2C IRQ race on remove - power: supply: bq27xxx: Fix poll_interval handling and races on remove - power: supply: bq27xxx: Add cache parameter to bq27xxx_battery_current_and_status() - power: supply: bq27xxx: Move bq27xxx_battery_update() down - power: supply: bq27xxx: Ensure power_supply_changed() is called on current sign changes - power: supply: bq27xxx: After charger plug in/out wait 0.5s for things to stabilize - power: supply: bq25890: Call power_supply_changed() after updating input current or voltage - power: supply: bq24190: Call power_supply_changed() after updating input current - power: supply: sbs-charger: Fix INHIBITED bit for Status reg - optee: fix uninited async notif value - firmware: arm_ffa: Check if ffa_driver remove is present before executing - firmware: arm_ffa: Fix FFA device names for logical partitions - fs: fix undefined behavior in bit shift for SB_NOUSER - regulator: pca9450: Fix BUCK2 enable_mask - platform/x86: ISST: Remove 8 socket limit - coresight: Fix signedness bug in tmc_etr_buf_insert_barrier_packet() - ARM: dts: imx6qdl-mba6: Add missing pvcie-supply regulator - xen/pvcalls-back: fix double frees with pvcalls_new_active_socket() - x86/show_trace_log_lvl: Ensure stack pointer is aligned, again - ASoC: Intel: Skylake: Fix declaration of enum skl_ch_cfg - ASoC: Intel: avs: Fix declaration of enum avs_channel_config - ASoC: Intel: avs: Access path components under lock - cxl: Wait Memory_Info_Valid before access memory related info - sctp: fix an issue that plpmtu can never go to complete state - forcedeth: Fix an error handling path in nv_probe() - platform/mellanox: mlxbf-pmc: fix sscanf() error checking - net/mlx5e: Fix SQ wake logic in ptp napi_poll context - net/mlx5e: Fix deadlock in tc route query code - net/mlx5e: Use correct encap attribute during invalidation - net/mlx5e: do as little as possible in napi poll when budget is 0 - net/mlx5: DR, Fix crc32 calculation to work on big-endian (BE) CPUs - net/mlx5: Handle pairing of E-switch via uplink un/load APIs - net/mlx5: DR, Check force-loopback RC QP capability independently from RoCE - net/mlx5: Fix error message when failing to allocate device memory - net/mlx5: Collect command failures data only for known commands - net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device - net/mlx5: Devcom, serialize devcom registration - arm64: dts: imx8mn-var-som: fix PHY detection bug by adding deassert delay - firmware: arm_ffa: Set reserved/MBZ fields to zero in the memory descriptors - regulator: mt6359: add read check for PMIC MT6359 - net/smc: Reset connection when trying to use SMCRv2 fails. - 3c589_cs: Fix an error handling path in tc589_probe() - net: phy: mscc: add VSC8502 to MODULE_DEVICE_TABLE - wifi: rtw89: 8852b: adjust quota to avoid SER L1 caused by access null page - zsmalloc: move LRU update from zs_map_object() to zs_malloc() - mm/vmemmap/devdax: fix kernel crash when probing devdax devices - cifs: fix smb1 mount regression - cxl: Move cxl_await_media_ready() to before capacity info retrieval - net: ethernet: mtk_eth_soc: fix QoS on DSA MAC on non MTK_NETSYS_V2 SoCs - Upstream stable to v6.1.31, v6.3.5 - inet: Add IP_LOCAL_PORT_RANGE socket option - ipv{4,6}/raw: fix output xfrm lookup wrt protocol - firmware: arm_ffa: Fix usage of partition info get count flag - selftests/bpf: Fix pkg-config call building sign-file - platform/x86/amd/pmf: Fix CnQF and auto-mode after resume - tls: rx: device: fix checking decryption status - tls: rx: strp: set the skb->len of detached / CoW'ed skbs - tls: rx: strp: fix determining record length in copy mode - tls: rx: strp: force mixed decrypted records into copy mode - tls: rx: strp: factor out copying skb data - tls: rx: strp: preserve decryption status of skbs when needed - net/mlx5: E-switch, Devcom, sync devcom events and devcom comp register - gpio-f7188x: fix chip name and pin count on Nuvoton chip - bpf, sockmap: Pass skb ownership through read_skb - bpf, sockmap: Convert schedule_work into delayed_work - bpf, sockmap: Reschedule is now done through backlog - bpf, sockmap: Improved check for empty queue - bpf, sockmap: Handle fin correctly - bpf, sockmap: TCP data stall on recv before accept - bpf, sockmap: Wake up polling after data copy - bpf, sockmap: Incorrectly handling copied_seq - blk-mq: fix race condition in active queue accounting - vfio/type1: check pfn valid before converting to struct page - net: page_pool: use in_softirq() instead - page_pool: fix inconsistency for page_pool_ring_[un]lock() - net: phy: mscc: enable VSC8501/2 RGMII RX clock - wifi: iwlwifi: mvm: support wowlan info notification version 2 - drm/amd: Don't allow s0ix on APUs older than Raven - bluetooth: Add cmd validity checks at the start of hci_sock_ioctl() - Revert "thermal/drivers/mellanox: Use generic thermal_zone_get_trip() function" - block: fix bio-cache for passthru IO - cpufreq: amd-pstate: Update policy->cur in amd_pstate_adjust_perf() - cpufreq: amd-pstate: Add ->fast_switch() callback - netfilter: ctnetlink: Support offloaded conntrack entry deletion - tools headers UAPI: Sync the linux/in.h with the kernel sources - gpiolib: fix allocation of mixed dynamic/static GPIOs - net: fec: add dma_wmb to ensure correct descriptor values - cxl/port: Fix NULL pointer access in devm_cxl_add_port() - blk-wbt: fix that wbt can't be disabled by default - Upstream stable to v6.1.32, v6.3.6 * sysfs msi_irqs directory empty with kernel-5.19 when being a xen guest (LP: #2022354) // Lunar update: upstream stable patchset 2023-07-28 (LP: #2028979) - x86/pci/xen: populate MSI sysfs entries * Lunar update: upstream stable patchset 2023-07-26 (LP: #2028808) - drm/fbdev-generic: prohibit potential out-of-bounds access - drm/mipi-dsi: Set the fwnode for mipi_dsi_device - ARM: 9296/1: HP Jornada 7XX: fix kernel-doc warnings - net: skb_partial_csum_set() fix against transport header magic value - net: mdio: mvusb: Fix an error handling path in mvusb_mdio_probe() - scsi: ufs: core: Fix I/O hang that occurs when BKOPS fails in W-LUN suspend - tick/broadcast: Make broadcast device replacement work correctly - linux/dim: Do nothing if no time delta between samples - net: stmmac: Initialize MAC_ONEUS_TIC_COUNTER register - net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). - net: phy: bcm7xx: Correct read from expansion register - netfilter: nf_tables: always release netdev hooks from notifier - netfilter: conntrack: fix possible bug_on with enable_hooks=1 - bonding: fix send_peer_notif overflow - netlink: annotate accesses to nlk->cb_running - net: annotate sk->sk_err write from do_recvmmsg() - net: deal with most data-races in sk_wait_event() - net: add vlan_get_protocol_and_depth() helper - tcp: add annotations around sk->sk_shutdown accesses - gve: Remove the code of clearing PBA bit - net: mscc: ocelot: fix stat counter register values - net: datagram: fix data-races in datagram_poll() - af_unix: Fix a data race of sk->sk_receive_queue->qlen. - af_unix: Fix data races around sk->sk_shutdown. - drm/i915/guc: Don't capture Gen8 regs on Xe devices - drm/i915: Fix NULL ptr deref by checking new_crtc_state - drm/i915/dp: prevent potential div-by-zero - drm/i915: Expand force_probe to block probe of devices as well. - drm/i915: taint kernel when force probing unsupported devices - fbdev: arcfb: Fix error handling in arcfb_probe() - ext4: reflect error codes from ext4_multi_mount_protect() to its callers - ext4: allow to find by goal if EXT4_MB_HINT_GOAL_ONLY is set - ext4: allow ext4_get_group_info() to fail - refscale: Move shutdown from wait_event() to wait_event_idle() - selftests: cgroup: Add 'malloc' failures checks in test_memcontrol - rcu: Protect rcu_print_task_exp_stall() ->exp_tasks access - open: return EINVAL for O_DIRECTORY | O_CREAT - fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() - drm/displayid: add displayid_get_header() and check bounds better - drm/amd/display: populate subvp cmd info only for the top pipe - drm/amd/display: Correct DML calculation to align HW formula - platform/x86: x86-android-tablets: Add Acer Iconia One 7 B1-750 data - drm/amd/display: Enable HostVM based on rIOMMU active - drm/amd/display: Use DC_LOG_DC in the trasform pixel function - regmap: cache: Return error in cache sync operations for REGCACHE_NONE - remoteproc: imx_dsp_rproc: Add custom memory copy implementation for i.MX DSP Cores - arm64: dts: qcom: msm8996: Add missing DWC3 quirks - media: cx23885: Fix a null-ptr-deref bug in buffer_prepare() and buffer_finish() - media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish - media: pvrusb2: VIDEO_PVRUSB2 depends on DVB_CORE to use dvb_* symbols - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() - drm/rockchip: dw_hdmi: cleanup drm encoder during unbind - arm64: dts: imx8mq-librem5: Remove dis_u3_susphy_quirk from usb_dwc3_0 - firmware: arm_sdei: Fix sleep from invalid context BUG - ACPI: EC: Fix oops when removing custom query handlers - drm/amd/display: fixed dcn30+ underflow issue - remoteproc: stm32_rproc: Add mutex protection for workqueue - drm/tegra: Avoid potential 32-bit integer overflow - drm/msm/dp: Clean up handling of DP AUX interrupts - ACPICA: Avoid undefined behavior: applying zero offset to null pointer - ACPICA: ACPICA: check null return of ACPI_ALLOCATE_ZEROED in acpi_db_display_objects - arm64: dts: qcom: sdm845-polaris: Drop inexistent properties - irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 - ACPI: video: Remove desktops without backlight DMI quirks - drm/amd/display: Correct DML calculation to follow HW SPEC - drm/amd: Fix an out of bounds error in BIOS parser - drm/amdgpu: Fix sdma v4 sw fini error - media: Prefer designated initializers over memset for subdev pad ops - media: mediatek: vcodec: Fix potential array out-of-bounds in decoder queue_setup - wifi: ath: Silence memcpy run-time false positive warning - bpf: Annotate data races in bpf_local_storage - wifi: brcmfmac: pcie: Provide a buffer of random bytes to the device - wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex - ext2: Check block size validity during mount - scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow - scsi: lpfc: Correct used_rpi count when devloss tmo fires with no recovery - bnxt: avoid overflow in bnxt_get_nvram_directory() - net: pasemi: Fix return type of pasemi_mac_start_tx() - net: Catch invalid index in XPS mapping - netdev: Enforce index cap in netdev_get_tx_queue - scsi: target: iscsit: Free cmds before session free - lib: cpu_rmap: Avoid use after free on rmap->obj array entries - scsi: message: mptlan: Fix use after free bug in mptlan_remove() due to race condition - gfs2: Fix inode height consistency check - scsi: ufs: ufs-pci: Add support for Intel Lunar Lake - ext4: set goal start correctly in ext4_mb_normalize_request - ext4: Fix best extent lstart adjustment logic in ext4_mb_new_inode_pa() - crypto: jitter - permanent and intermittent health errors - f2fs: Fix system crash due to lack of free space in LFS - f2fs: fix to drop all dirty pages during umount() if cp_error is set - f2fs: fix to check readonly condition correctly - samples/bpf: Fix fout leak in hbm's run_bpf_prog - bpf: Add preempt_count_{sub,add} into btf id deny list - md: fix soft lockup in status_resync - wifi: iwlwifi: pcie: fix possible NULL pointer dereference - wifi: iwlwifi: add a new PCI device ID for BZ device - wifi: iwlwifi: pcie: Fix integer overflow in iwl_write_to_user_buf - wifi: iwlwifi: mvm: fix ptk_pn memory leak - block, bfq: Fix division by zero error on zero wsum - wifi: ath11k: Ignore frags from uninitialized peer in dp. - wifi: iwlwifi: fix iwl_mvm_max_amsdu_size() for MLO - null_blk: Always check queue mode setting from configfs - wifi: iwlwifi: dvm: Fix memcpy: detected field-spanning write backtrace - wifi: ath11k: Fix SKB corruption in REO destination ring - nbd: fix incomplete validation of ioctl arg - ipvs: Update width of source for ip_vs_sync_conn_options - Bluetooth: btusb: Add new PID/VID 04ca:3801 for MT7663 - Bluetooth: Add new quirk for broken local ext features page 2 - Bluetooth: btrtl: add support for the RTL8723CS - Bluetooth: Improve support for Actions Semi ATS2851 based devices - Bluetooth: btrtl: check for NULL in btrtl_set_quirks() - Bluetooth: btintel: Add LE States quirk support - Bluetooth: hci_bcm: Fall back to getting bdaddr from EFI if not set - Bluetooth: Add new quirk for broken set random RPA timeout for ATS2851 - Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp - Bluetooth: btrtl: Add the support for RTL8851B - HID: apple: Set the tilde quirk flag on the Geyser 4 and later - staging: axis-fifo: initialize timeouts in init only - ASoC: amd: yc: Add DMI entries to support HP OMEN 16-n0xxx (8A42) - HID: logitech-hidpp: Don't use the USB serial for USB devices - HID: logitech-hidpp: Reconcile USB and Unifying serials - spi: spi-imx: fix MX51_ECSPI_* macros when cs > 3 - usb: typec: ucsi: acpi: add quirk for ASUS Zenbook UM325 - ALSA: hda: LNL: add HD Audio PCI ID - ASoC: amd: Add Dell G15 5525 to quirks list - ASoC: amd: yc: Add ThinkBook 14 G5+ ARP to quirks list for acp6x - HID: apple: Set the tilde quirk flag on the Geyser 3 - HID: Ignore battery for ELAN touchscreen on ROG Flow X13 GV301RA - HID: wacom: generic: Set battery quirk only when we see battery data - usb: typec: tcpm: fix multiple times discover svids error - serial: 8250: Reinit port->pm on port specific driver unbind - mcb-pci: Reallocate memory region to avoid memory overlapping - sched: Fix KCSAN noinstr violation - lkdtm/stackleak: Fix noinstr violation - recordmcount: Fix memory leaks in the uwrite function - soundwire: dmi-quirks: add remapping for Intel 'Rooks County' NUC M15 - phy: st: miphy28lp: use _poll_timeout functions for waits - soundwire: qcom: gracefully handle too many ports in DT - soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow - mfd: intel_soc_pmic_chtwc: Add Lenovo Yoga Book X90F to intel_cht_wc_models - mfd: dln2: Fix memory leak in dln2_probe() - mfd: intel-lpss: Add Intel Meteor Lake PCH-S LPSS PCI IDs - parisc: Replace regular spinlock with spin_trylock on panic path - drm/amdgpu: drop gfx_v11_0_cp_ecc_error_irq_funcs - xfrm: don't check the default policy if the policy allows the packet - Revert "Fix XFRM-I support for nested ESP tunnels" - drm/msm/dp: unregister audio driver during unbind - drm/msm/dpu: Assign missing writeback log_mask - drm/msm/dpu: Move non-MDP_TOP INTF_INTR offsets out of hwio header - drm/msm/dpu: Remove duplicate register defines from INTF - dt-bindings: display/msm: dsi-controller-main: Document qcom, master-dsi and qcom, sync-dual-dsi - ASoC: fsl_micfil: Fix error handler with pm_runtime_enable - cpupower: Make TSC read per CPU for Mperf monitor - xfrm: Reject optional tunnel/BEET mode templates in outbound policies - af_key: Reject optional tunnel/BEET mode templates in outbound policies - drm/msm: Fix submit error-path leaks - selftests: seg6: disable DAD on IPv6 router cfg for srv6_end_dt4_l3vpn_test - selftets: seg6: disable rp_filter by default in srv6_end_dt4_l3vpn_test - net: fec: Better handle pm_runtime_get() failing in .remove() - net: phy: dp83867: add w/a for packet errors seen with short cables - ALSA: firewire-digi00x: prevent potential use after free - wifi: mt76: connac: fix stats->tx_bytes calculation - ALSA: hda/realtek: Apply HP B&O top speaker profile to Pavilion 15 - sfc: disable RXFCS and RXALL features by default - vsock: avoid to close connected socket after the timeout - tcp: fix possible sk_priority leak in tcp_v4_send_reset() - serial: arc_uart: fix of_iomap leak in `arc_serial_probe` - serial: 8250_bcm7271: balance clk_enable calls - serial: 8250_bcm7271: fix leak in `brcmuart_probe` - erspan: get the proto with the md version for collect_md - net: dsa: rzn1-a5psw: enable management frames for CPU port - net: dsa: rzn1-a5psw: fix STP states handling - net: dsa: rzn1-a5psw: disable learning for standalone ports - net: hns3: fix output information incomplete for dumping tx queue info with debugfs - net: hns3: fix sending pfc frames after reset issue - net: hns3: fix reset delay time to avoid configuration timeout - net: hns3: fix reset timeout when enable full VF - media: netup_unidvb: fix use-after-free at del_timer() - SUNRPC: double free xprt_ctxt while still in use - SUNRPC: always free ctxt when freeing deferred request - SUNRPC: Fix trace_svc_register() call site - ASoC: mediatek: mt8186: Fix use-after-free in driver remove path - ASoC: SOF: topology: Fix logic for copying tuples - drm/exynos: fix g2d_open/close helper function definitions - net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() - virtio-net: Maintain reverse cleanup order - virtio_net: Fix error unwinding of XDP initialization - tipc: add tipc_bearer_min_mtu to calculate min mtu - tipc: do not update mtu if msg_max is too small in mtu negotiation - tipc: check the bearer min mtu properly when setting it by netlink - s390/cio: include subchannels without devices also for evaluation - can: dev: fix missing CAN XL support in can_put_echo_skb() - net: bcmgenet: Remove phy_stop() from bcmgenet_netif_stop() - net: bcmgenet: Restore phy_stop() depending upon suspend/close - ice: introduce clear_reset_state operation - ice: Fix ice VF reset during iavf initialization - wifi: cfg80211: Drop entries with invalid BSSIDs in RNR - wifi: mac80211: fortify the spinlock against deadlock by interrupt - wifi: mac80211: fix min center freq offset tracing - wifi: mac80211: Abort running color change when stopping the AP - wifi: iwlwifi: mvm: fix cancel_delayed_work_sync() deadlock - wifi: iwlwifi: fw: fix DBGI dump - wifi: iwlwifi: fix OEM's name in the ppag approved list - wifi: iwlwifi: mvm: fix OEM's name in the tas approved list - wifi: iwlwifi: mvm: don't trust firmware n_channels - scsi: storvsc: Don't pass unused PFNs to Hyper-V host - tun: Fix memory leak for detached NAPI queue. - cassini: Fix a memory leak in the error handling path of cas_init_one() - net: dsa: mv88e6xxx: Fix mv88e6393x EPC write command offset - igb: fix bit_shift to be in [1..8] range - vlan: fix a potential uninit-value in vlan_dev_hard_start_xmit() - net: wwan: iosm: fix NULL pointer dereference when removing device - net: pcs: xpcs: fix C73 AN not getting enabled - net: selftests: Fix optstring - netfilter: nf_tables: fix nft_trans type confusion - netfilter: nft_set_rbtree: fix null deref on element insertion - bridge: always declare tunnel functions - ALSA: usb-audio: Add a sample rate workaround for Line6 Pod Go - USB: usbtmc: Fix direction for 0-length ioctl control messages - usb-storage: fix deadlock when a scsi command timeouts more than once - USB: UHCI: adjust zhaoxin UHCI controllers OverCurrent bit value - usb: dwc3: gadget: Improve dwc3_gadget_suspend() and dwc3_gadget_resume() - usb: dwc3: debugfs: Resume dwc3 before accessing registers - usb: gadget: u_ether: Fix host MAC address case - usb: typec: altmodes/displayport: fix pin_assignment_show - Revert "usb: gadget: udc: core: Prevent redundant calls to pullup" - Revert "usb: gadget: udc: core: Invoke usb_gadget_connect only when started" - xhci-pci: Only run d3cold avoidance quirk for s2idle - xhci: Fix incorrect tracking of free space on transfer rings - ALSA: hda: Fix Oops by 9.1 surround channel names - ALSA: hda/realtek: Add quirk for Clevo L140AU - ALSA: hda/realtek: Add a quirk for HP EliteDesk 805 - ALSA: hda/realtek: Add quirk for 2nd ASUS GU603 - ALSA: hda/realtek: Add quirk for HP EliteBook G10 laptops - can: j1939: recvmsg(): allow MSG_CMSG_COMPAT flag - can: isotp: recvmsg(): allow MSG_CMSG_COMPAT flag - can: kvaser_pciefd: Set CAN_STATE_STOPPED in kvaser_pciefd_stop() - can: kvaser_pciefd: Call request_irq() before enabling interrupts - can: kvaser_pciefd: Empty SRB buffer in probe - can: kvaser_pciefd: Clear listen-only bit if not explicitly requested - can: kvaser_pciefd: Do not send EFLUSH command on TFD interrupt - can: kvaser_pciefd: Disable interrupts in probe error path - wifi: rtw88: use work to update rate to avoid RCU warning - SMB3: Close all deferred handles of inode in case of handle lease break - SMB3: drop reference to cfile before sending oplock break - ksmbd: smb2: Allow messages padded to 8byte boundary - ksmbd: allocate one more byte for implied bcc[0] - ksmbd: fix wrong UserName check in session_user - ksmbd: fix global-out-of-bounds in smb2_find_context_vals - KVM: Fix vcpu_array[0] races - statfs: enforce statfs[64] structure initialization - maple_tree: make maple state reusable after mas_empty_area() - mm: fix zswap writeback race condition - serial: Add support for Advantech PCI-1611U card - serial: 8250_exar: Add support for USR298x PCI Modems - serial: qcom-geni: fix enabling deactivated interrupt - thunderbolt: Clear registers properly when auto clear isn't in use - vc_screen: reload load of struct vc_data pointer in vcs_write() to avoid UAF - ceph: force updating the msg pointer in non-split case - drm/amd/pm: fix possible power mode mismatch between driver and PMFW - drm/amdgpu/gmc11: implement get_vbios_fb_size() - drm/amdgpu/gfx10: Disable gfxoff before disabling powergating. - drm/amdgpu/gfx11: Adjust gfxoff before powergating on gfx11 as well - dt-bindings: ata: ahci-ceva: Cover all 4 iommus entries - powerpc/iommu: DMA address offset is incorrectly calculated with 2MB TCEs - powerpc/iommu: Incorrect DDW Table is referenced for SR-IOV device - tpm/tpm_tis: Disable interrupts for more Lenovo devices - powerpc/64s/radix: Fix soft dirty tracking - nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode() - s390/dasd: fix command reject error on ESE devices - s390/crypto: use vector instructions only if available for ChaCha20 - s390/qdio: fix do_sqbs() inline assembly constraint - arm64: mte: Do not set PG_mte_tagged if tags were not initialized - rethook: use preempt_{disable, enable}_notrace in rethook_trampoline_handler - rethook, fprobe: do not trace rethook related functions - remoteproc: imx_dsp_rproc: Fix kernel test robot sparse warning - drm/amd/amdgpu: introduce gc_*_mes_2.bin v2 - drm/amdgpu: reserve the old gc_11_0_*_mes.bin - drm/nouveau/disp: More DP_RECEIVER_CAP_SIZE array fixes - xfrm: release all offloaded policy memory - xfrm: Fix leak of dev tracker - media: pvrusb2: fix DVB_CORE dependency - net: fec: remove the xdp_return_frame when lack of tx BDs - iavf: send VLAN offloading caps once after VFR - wifi: brcmfmac: Check for probe() id argument being NULL - wifi: rtw88: correct qsel_to_ep[] type as int - KVM: arm64: Infer the PA offset from IPA in stage-2 map walker - perf script: Skip aggregation for stat events - iommu/arm-smmu-qcom: Fix missing adreno_smmu's - arm64: Also reset KASAN tag if page is not PG_mte_tagged - Upstream stable to v6.1.30, v6.3.4 * Lunar update: v6.2.16 upstream stable release (LP: #2028580) - USB: dwc3: gadget: drop dead hibernation code - usb: dwc3: gadget: Execute gadget stop after halting the controller - crypto: ccp - Clear PSP interrupt status register before calling handler - ASoC: codecs: constify static sdw_slave_ops struct - ASoC: codecs: wcd938x: fix accessing regmap on unattached devices - mtd: spi-nor: Add a RWW flag - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s28hx SEMPER flash - qcom: llcc/edac: Support polling mode for ECC handling - soc: qcom: llcc: Do not create EDAC platform device on SDM845 - mailbox: zynq: Switch to flexible array to simplify code - mailbox: zynqmp: Fix counts of child nodes - mtd: spi-nor: spansion: Enable JFFS2 write buffer for Infineon s25hx SEMPER flash - fs/ntfs3: Fix null-ptr-deref on inode->i_op in ntfs_lookup() - drm/amd/display: Ext displays with dock can't recognized after resume - KVM: x86/mmu: Avoid indirect call for get_cr3 - KVM: x86: Do not unload MMU roots when only toggling CR0.WP with TDP enabled - KVM: x86: Make use of kvm_read_cr*_bits() when testing bits - KVM: VMX: Make CR0.WP a guest owned bit - KVM: x86/mmu: Refresh CR0.WP prior to checking for emulated permission faults - RDMA/rxe: Remove rxe_alloc() - RDMA/rxe: Change rxe_dbg to rxe_dbg_dev - RDMA/rxe: Extend dbg log messages to err and info - ASoC: Intel: soc-acpi-byt: Fix "WM510205" match no longer working - scsi: qedi: Fix use after free bug in qedi_remove() - drm/amd/display: Add missing WA and MCLK validation - drm/amd/display: Return error code on DSC atomic check failure - drm/amd/display: Fixes for dcn32_clk_mgr implementation - drm/amd/display: Reset OUTBOX0 r/w pointer on DMUB reset - drm/amd/display: Do not clear GPINT register when releasing DMUB from reset - drm/amd/display: Update bounding box values for DCN321 - rxrpc: Fix potential data race in rxrpc_wait_to_be_connected() - ixgbe: Fix panic during XDP_TX with > 64 CPUs - octeonxt2-af: mcs: Fix per port bypass config - octeontx2-af: mcs: Write TCAM_DATA and TCAM_MASK registers at once - octeontx2-af: mcs: Config parser to skip 8B header - octeontx2-af: mcs: Fix MCS block interrupt - octeontx2-pf: mcs: Fix NULL pointer dereferences - octeontx2-pf: mcs: Match macsec ethertype along with DMAC - octeontx2-pf: mcs: Clear stats before freeing resource - octeontx2-pf: mcs: Fix shared counters logic - octeontx2-pf: mcs: Do not reset PN while updating secy - net/ncsi: clear Tx enable mode when handling a Config required AEN - tcp: fix skb_copy_ubufs() vs BIG TCP - net/sched: cls_api: remove block_cb from driver_list before freeing - sit: update dev->needed_headroom in ipip6_tunnel_bind_dev() - selftests: srv6: make srv6_end_dt46_l3vpn_test more robust - net: ipv6: fix skb hash for some RST packets - net: dsa: mv88e6xxx: add mv88e6321 rsvd2cpu - writeback: fix call of incorrect macro - block: Skip destroyed blkg when restart in blkg_destroy_all() - watchdog: dw_wdt: Fix the error handling path of dw_wdt_drv_probe() - RISC-V: mm: Enable huge page support to kernel_page_present() function - i2c: tegra: Fix PEC support for SMBUS block read - net/sched: act_mirred: Add carrier check - r8152: fix flow control issue of RTL8156A - r8152: fix the poor throughput for 2.5G devices - r8152: move setting r8153b_rx_agg_chg_indicate() - sfc: Fix module EEPROM reporting for QSFP modules - rxrpc: Fix hard call timeout units - rxrpc: Make it so that a waiting process can be aborted - rxrpc: Fix timeout of a call that hasn't yet been granted a channel - riscv: compat_syscall_table: Fixup compile warning - net: ethernet: mtk_eth_soc: drop generic vlan rx offload, only use DSA untagging - drm/i915/mtl: Add the missing CPU transcoder mask in intel_device_info - selftests: netfilter: fix libmnl pkg-config usage - octeontx2-af: Secure APR table update with the lock - octeontx2-af: Fix start and end bit for scan config - octeontx2-af: Fix depth of cam and mem table. - octeontx2-pf: Increase the size of dmac filter flows - octeontx2-af: Add validation for lmac type - octeontx2-af: Update correct mask to filter IPv4 fragments - octeontx2-af: Update/Fix NPC field hash extract feature - octeontx2-af: Fix issues with NPC field hash extract - octeontx2-af: Skip PFs if not enabled - octeontx2-pf: Disable packet I/O for graceful exit - octeontx2-vf: Detach LF resources on probe cleanup - ionic: remove noise from ethtool rxnfc error msg - ethtool: Fix uninitialized number of lanes - ionic: catch failure from devlink_alloc - af_packet: Don't send zero-byte data in packet_sendmsg_spkt(). - drm/amdgpu: add a missing lock for AMDGPU_SCHED - ALSA: caiaq: input: Add error handling for unsupported input methods in `snd_usb_caiaq_input_init` - KVM: s390: pv: fix asynchronous teardown for small VMs - KVM: s390: fix race in gmap_make_secure() - net: dsa: mt7530: fix corrupt frames using trgmii on 40 MHz XTAL MT7621 - net: dsa: mt7530: split-off common parts from mt7531_setup - net: dsa: mt7530: fix network connectivity with multiple CPU ports - ice: block LAN in case of VF to VF offload - virtio_net: suppress cpu stall when free_unused_bufs - net: enetc: check the index of the SFI rather than the handle - net: fec: correct the counting of XDP sent frames - perf record: Fix "read LOST count failed" msg with sample read - perf build: Support python/perf.so testing - perf scripts intel-pt-events.py: Fix IPC output for Python 2 - perf script: Fix Python support when no libtraceevent - perf hist: Improve srcfile sort key performance (really) - perf vendor events s390: Remove UTF-8 characters from JSON file - perf tests record_offcpu.sh: Fix redirection of stderr to stdin - perf ftrace: Make system wide the default target for latency subcommand - perf vendor events power9: Remove UTF-8 characters from JSON files - perf pmu: zfree() expects a pointer to a pointer to zero it after freeing its contents - perf map: Delete two variable initialisations before null pointer checks in sort__sym_from_cmp() - perf cs-etm: Fix timeless decode mode detection - crypto: sun8i-ss - Fix a test in sun8i_ss_setup_ivs() - crypto: api - Add scaffolding to change completion function signature - crypto: engine - Use crypto_request_complete - crypto: engine - fix crypto_queue backlog handling - perf symbols: Fix return incorrect build_id size in elf_read_build_id() - perf tracepoint: Fix memory leak in is_valid_tracepoint() - perf stat: Separate bperf from bpf_profiler - KVM: x86/mmu: Change tdp_mmu to a read-only parameter - KVM: x86/mmu: Move TDP MMU VM init/uninit behind tdp_mmu_enabled - KVM: x86/mmu: Replace open coded usage of tdp_mmu_page with is_tdp_mmu_page() - KVM: x86: Preserve TDP MMU roots until they are explicitly invalidated - ksmbd: Implements sess->ksmbd_chann_list as xarray - ksmbd: fix racy issue from session setup and logoff - ksmbd: block asynchronous requests when making a delay on session setup - ksmbd: destroy expired sessions - ksmbd: fix racy issue from smb2 close and logoff with multichannel - wifi: iwlwifi: mvm: fix potential memory leak - cifs: check only tcon status on tcon related functions - cifs: avoid potential races when handling multiple dfs tcons - netfilter: nf_tables: extended netlink error reporting for netdevice - netfilter: nf_tables: rename function to destroy hook list - netfilter: nf_tables: hit ENOENT on unexisting chain/flowtable update with missing attributes - x86/retbleed: Fix return thunk alignment - btrfs: fix btrfs_prev_leaf() to not return the same key twice - btrfs: zoned: fix wrong use of bitops API in btrfs_ensure_empty_zones - btrfs: properly reject clear_cache and v1 cache for block-group-tree - btrfs: fix assertion of exclop condition when starting balance - btrfs: fix encoded write i_size corruption with no-holes - btrfs: don't free qgroup space unless specified - btrfs: zero the buffer before marking it dirty in btrfs_redirty_list_add - btrfs: make clear_cache mount option to rebuild FST without disabling it - btrfs: print-tree: parent bytenr must be aligned to sector size - btrfs: fix space cache inconsistency after error loading it from disk - btrfs: zoned: zone finish data relocation BG with last IO - btrfs: zoned: fix full zone super block reading on ZNS - btrfs: fix backref walking not returning all inode refs - cifs: fix pcchunk length type in smb2_copychunk_range - cifs: release leases for deferred close handles when freezing - platform/x86/intel-uncore-freq: Return error on write frequency - platform/x86: touchscreen_dmi: Add upside-down quirk for GDIX1002 ts on the Juno Tablet - platform/x86: thinkpad_acpi: Fix platform profiles on T490 - platform/x86: hp-wmi: add micmute to hp_wmi_keymap struct - platform/x86: touchscreen_dmi: Add info for the Dexp Ursus KX210i - platform/x86: thinkpad_acpi: Add profile force ability - inotify: Avoid reporting event with invalid wd - smb3: fix problem remounting a share after shutdown - SMB3: force unmount was failing to close deferred close files - sh: math-emu: fix macro redefined warning - sh: mcount.S: fix build error when PRINTK is not enabled - sh: init: use OF_EARLY_FLATTREE for early init - sh: nmi_debug: fix return value of __setup handler - proc_sysctl: update docs for __register_sysctl_table() - proc_sysctl: enhance documentation - remoteproc: stm32: Call of_node_put() on iteration error - remoteproc: st: Call of_node_put() on iteration error - remoteproc: imx_dsp_rproc: Call of_node_put() on iteration error - remoteproc: imx_rproc: Call of_node_put() on iteration error - remoteproc: rcar_rproc: Call of_node_put() on iteration error - sysctl: clarify register_sysctl_init() base directory order - ARM: dts: aspeed: asrock: Correct firmware flash SPI clocks - ARM: dts: exynos: fix WM8960 clock name in Itop Elite - ARM: dts: s5pv210: correct MIPI CSIS clock name - ARM: dts: aspeed: romed8hm3: Fix GPIO polarity of system-fault LED - drm/msm/adreno: fix runtime PM imbalance at gpu load - drm/bridge: lt8912b: Fix DSI Video Mode - drm/i915/color: Fix typo for Plane CSC indexes - drm/msm: fix NULL-deref on snapshot tear down - drm/msm: fix NULL-deref on irq uninstall - drm/msm: fix drm device leak on bind errors - drm/msm: fix vram leak on bind errors - drm/msm: fix missing wq allocation error handling - drm/msm: fix workqueue leak on bind errors - drm/i915/dsi: Use unconditional msleep() instead of intel_dsi_msleep() - f2fs: factor out victim_entry usage from general rb_tree use - f2fs: fix null pointer panic in tracepoint in __replace_atomic_write_block - f2fs: fix potential corruption when moving a directory - irqchip/loongson-pch-pic: Fix pch_pic_acpi_init calling - irqchip/loongson-pch-pic: Fix registration of syscore_ops - irqchip/loongson-eiointc: Fix returned value on parsing MADT - irqchip/loongson-eiointc: Fix incorrect use of acpi_get_vec_parent - irqchip/loongson-eiointc: Fix registration of syscore_ops - drm/panel: otm8009a: Set backlight parent to panel device - drm/amd/display: Add NULL plane_state check for cursor disable logic - drm/amd/display: Fix 4to1 MPC black screen with DPP RCO - drm/amd/display: filter out invalid bits in pipe_fuses - drm/amd/display: fix flickering caused by S/G mode - drm/amdgpu: drop redundant sched job cleanup when cs is aborted - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v10_0_hw_fini - drm/amdgpu: fix an amdgpu_irq_put() issue in gmc_v9_0_hw_fini() - drm/amdgpu: fix amdgpu_irq_put call trace in gmc_v11_0_hw_fini - drm/amdgpu/gfx: disable gfx9 cp_ecc_error_irq only when enabling legacy gfx ras - drm/amdgpu/jpeg: Remove harvest checking for JPEG3 - drm/amdgpu: change gfx 11.0.4 external_id range - drm/amdgpu: Fix vram recover doesn't work after whole GPU reset (v2) - drm/amd/display: Enforce 60us prefetch for 200Mhz DCFCLK modes - drm/amd/pm: parse pp_handle under appropriate conditions - drm/amdgpu: disable sdma ecc irq only when sdma RAS is enabled in suspend - drm/amd/pm: avoid potential UBSAN issue on legacy asics - drm/amd: Load MES microcode during early_init - drm/amd: Add a new helper for loading/validating microcode - drm/amd: Use `amdgpu_ucode_*` helpers for MES - HID: wacom: Set a default resolution for older tablets - HID: wacom: insert timestamp to packed Bluetooth (BT) events - fs/ntfs3: Refactoring of various minor issues - drm/msm/adreno: adreno_gpu: Use suspend() instead of idle() on load error - drm/i915/mtl: Add workarounds Wa_14017066071 and Wa_14017654203 - drm/i915/mtl: Add Wa_14017856879 - drm/i915: disable sampler indirect state in bindless heap - drm/i915/mtl: update scaler source and destination limits for MTL - drm/i915: Check pipe source size when using skl+ scalers - drm/amd/display: Fix Z8 support configurations - drm/amd/display: Add minimum Z8 residency debug option - drm/amd/display: Update minimum stutter residency for DCN314 Z8 - drm/amd/display: Lowering min Z8 residency time - drm/amd/display: Update Z8 SR exit/enter latencies - drm/amd/display: Change default Z8 watermark values - drm: Add missing DP DSC extended capability definitions. - drm/dsc: fix drm_edp_dsc_sink_output_bpp() DPCD high byte usage - locking/rwsem: Add __always_inline annotation to __down_read_common() and inlined callers - ext4: fix WARNING in mb_find_extent - ext4: avoid a potential slab-out-of-bounds in ext4_group_desc_csum - ext4: fix data races when using cached status extents - ext4: avoid deadlock in fs reclaim with page writeback - ext4: check iomap type only if ext4_iomap_begin() does not fail - ext4: improve error recovery code paths in __ext4_remount() - ext4: improve error handling from ext4_dirhash() - ext4: fix deadlock when converting an inline directory in nojournal mode - ext4: add bounds checking in get_max_inline_xattr_value_size() - ext4: bail out of ext4_xattr_ibody_get() fails for any reason - ext4: fix lockdep warning when enabling MMP - ext4: remove a BUG_ON in ext4_mb_release_group_pa() - ext4: fix invalid free tracking in ext4_xattr_move_to_block() - drm/dsc: fix DP_DSC_MAX_BPP_DELTA_* macro values - x86/amd_nb: Add PCI ID for family 19h model 78h - x86: fix clear_user_rep_good() exception handling annotation - spi: fsl-spi: Re-organise transfer bits_per_word adaptation - spi: fsl-cpm: Use 16 bit mode for large transfers with even size - drm/amd/display: Fix hang when skipping modeset - Linux 6.2.16 * CVE-2023-31084 // CVE-2023-31084 was assigned to this bug. - media: dvb-core: Fix kernel WARNING for blocking operation in wait_event*() * CVE-2023-3776 - net/sched: cls_fw: Fix improper refcount update leads to use-after-free * Packaging resync (LP: #1786013) - [Packaging] resync update-dkms-versions helper - [Packaging] resync getabis -- Stefan Bader <stefan.ba...@canonical.com> Fri, 18 Aug 2023 11:38:55 +0200 ** Changed in: linux-hwe-6.2 (Ubuntu Jammy) Status: Fix Committed => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-40982 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20593 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-2898 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-31084 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3609 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3610 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3611 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3776 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3777 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-3995 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-4004 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-4015 -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-hwe-6.2 in Ubuntu. https://bugs.launchpad.net/bugs/2029332 Title: Reboot command powers off the system Status in linux package in Ubuntu: Confirmed Status in linux-hwe-6.2 package in Ubuntu: Confirmed Status in linux-hwe-6.2 source package in Jammy: Fix Released Status in linux source package in Lunar: Fix Committed Bug description: [Impact] Issue: When a reboot (or init 6) command is issued the server shuts down instead. Expected behaviour: To reboot and NOT shutdown Impacted HW: HPE DL 380 OR Synergy 480 Gen 10 Plus Server 2P core count greater than 16 (like 24,28 or 32) Impacted OS: Ubuntu 22.04.2 kernel higher than 15.17.15 When the CPU count is 1, issue is not observed. When core count is less than 24 (like 16) issue not observed. [Fix] Problem introduced in v5.18 with commit: 08f253ec3767 x86/cpu: Clear SME feature flag when not in use Fixes for the above:0 9b040453d444 x86/smp: Dont access non-existing CPUID leaf 1f5e7eb7868e x86/smp: Make stop_other_cpus() more robust [Test Case] $ sudo reboot Server should reboot and not power off. [Where Problems Could Occur] The fixes modify x86 stop-CPU code so reboot/poweroff of x86 machines could be affected. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2029332/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp