• Bug#1022126: marked as done (mpt3sas broken with xen dom0) (4/5)

    From Debian Bug Tracking System@21:1/5 to All on Fri Apr 21 16:50:03 2023
    [continued from previous message]

    - scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
    - scsi: qla2xxx: Fix erroneous link down
    - scsi: ses: Don't attach if enclosure has no components
    - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
    - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses
    - scsi: ses: Fix possible desc_ptr out-of-bounds accesses
    - scsi: ses: Fix slab-out-of-bounds in ses_intf_remove()
    - PCI/PM: Observe reset delay irrespective of bridge_d3
    - PCI: hotplug: Allow marking devices as disconnected during bind/unbind
    - PCI: Avoid FLR for AMD FCH AHCI adapters
    - vfio/type1: prevent underflow of locked_vm via exec()
    - [x86] drm/i915/quirks: Add inverted backlight quirk for HP 14-r206nv
    - drm/radeon: Fix eDP for single-display iMac11,2
    - drm/edid: fix AVI infoframe aspect ratio handling
    - wifi: ath9k: use proper statements in conditionals
    - [arm64,armhf] pinctrl: rockchip: fix mux route data for rk3568
    - [arm64,armhf] pinctrl: rockchip: fix reading pull type on rk3568
    - net/sched: Retire tcindex classifier (CVE-2023-1829)
    - fs/jfs: fix shift exponent db_agl2size negative
    - objtool: Fix memory leak in create_static_call_sections()
    - [armhf] pwm: stm32-lp: fix the check on arr and cmp registers update
    - f2fs: use memcpy_{to,from}_page() where possible
    - fs: f2fs: initialize fsdata in pagecache_write()
    - ubi: ensure that VID header offset + VID header size <= alloc, size
    - ubifs: Fix build errors as symbol undefined
    - ubifs: Rectify space budget for ubifs_symlink() if symlink is encrypted
    - ubifs: Rectify space budget for ubifs_xrename()
    - ubifs: Fix wrong dirty space budget for dirty inode
    - ubifs: do_rename: Fix wrong space budget when target inode's nlink > 1
    - ubifs: Reserve one leb for each journal head while doing budget
    - ubi: Fix use-after-free when volume resizing failed
    - ubi: Fix unreferenced object reported by kmemleak in ubi_resize_volume()
    - ubifs: Fix memory leak in alloc_wbufs()
    - ubi: Fix possible null-ptr-deref in ubi_free_volume()
    - ubifs: Re-statistic cleaned znode count if commit failed
    - ubifs: dirty_cow_znode: Fix memleak in error handling path
    - ubifs: ubifs_writepage: Mark page dirty after writing inode failed
    - ubi: fastmap: Fix missed fm_anchor PEB in wear-leveling after disabling
    fastmap
    - ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()
    - ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed
    - [x86] um: vdso: Add '%rcx' and '%r11' to the syscall clobber list
    - watchdog: Fix kmemleak in watchdog_cdev_register
    - watchdog: pcwd_usb: Fix attempting to access uninitialized memory
    - netfilter: ctnetlink: fix possible refcount leak in
    ctnetlink_create_conntrack()
    - netfilter: ebtables: fix table blob use-after-free
    - ipv6: Add lwtunnel encap size of all siblings in nexthop calculation
    - sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop
    - net: fix __dev_kfree_skb_any() vs drop monitor
    - 9p/xen: fix version parsing
    - 9p/xen: fix connection sequence
    - 9p/rdma: unmap receive dma buffer in rdma_request()/post_recv()
    - net/mlx5: Geneve, Fix handling of Geneve object id as error code
    - nfc: fix memory leak of se_io context in nfc_genl_se_io
    - net/sched: act_sample: fix action bind logic
    - tcp: tcp_check_req() can be called from process context
    - vc_screen: modify vcs_size() handling in vcs_read()
    - [arm64,armhf] rtc: sun6i: Always export the internal oscillator
    - scsi: ipr: Work around fortify-string warning
    - loop: loop_set_status_from_info() check before assignment
    - tracing: Add NULL checks for buffer in ring_buffer_free_read_page()
    - [x86] firmware/efi sysfb_efi: Add quirk for Lenovo IdeaPad Duet 3
    - bootconfig: Increase max nodes of bootconfig from 1024 to 8192 for DCC
    support
    - [amd64] IB/hfi1: Update RMT size calculation
    - media: uvcvideo: Handle cameras with invalid descriptors
    - media: uvcvideo: Handle errors from calls to usb_string
    - media: uvcvideo: Quirk for autosuspend in Logitech B910 and C910
    - media: uvcvideo: Silence memcpy() run-time false positive warnings
    - tty: fix out-of-bounds access in tty_driver_lookup_tty()
    - tty: serial: fsl_lpuart: disable the CTS when send break signal
    - [x86] mei: bus-fixup:upon error print return values of send and receive
    - iio: accel: mma9551_core: Prevent uninitialized variable in
    mma9551_read_status_word()
    - iio: accel: mma9551_core: Prevent uninitialized variable in
    mma9551_read_config_word()
    - [arm64,armhf] usb: host: xhci: mvebu: Iterate over array indexes instead
    of using pointer math
    - USB: ene_usb6250: Allocate enough memory for full object
    - usb: uvc: Enumerate valid values for color matching
    - usb: gadget: uvc: Make bSourceID read/write
    - PCI: Align extra resources for hotplug bridges properly
    - PCI: Take other bus devices into account when distributing resources
    - kernel/fail_function: fix memory leak with using debugfs_lookup()
    - PCI: Add ACS quirk for Wangxun NICs
    - [arm64] phy: rockchip-typec: Fix unsigned comparison with less than zero
    - soundwire: cadence: Remove wasted space in response_buf
    - soundwire: cadence: Drain the RX FIFO after an IO timeout
    - [x86] resctrl: Apply READ_ONCE/WRITE_ONCE to task_struct.{rmid,closid}
    - [x86] resctl: fix scheduler confusion with 'current'
    - drm/display/dp_mst: Fix down/up message handling after sink disconnect
    - drm/display/dp_mst: Fix down message handling after a packet reception
    error
    - Bluetooth: hci_sock: purge socket queues in the destruct() callback
    - tcp: Fix listen() regression in 5.10.163
    - drm/virtio: Fix error code in virtio_gpu_object_shmem_init()
    - media: uvcvideo: Provide sync and async uvc_ctrl_status_event
    - media: uvcvideo: Fix race condition with usb_kill_urb
    - Revert "scsi: mpt3sas: Fix return value check of dma_get_required_mask()"
    - scsi: mpt3sas: Don't change DMA mask while reallocating pools
    - scsi: mpt3sas: re-do lost mpt3sas DMA mask fix
    - scsi: mpt3sas: Remove usage of dma_get_required_mask() API
    (Closes: #1022126)
    - malidp: Fix NULL vs IS_ERR() checking (CVE-2023-23004)
    - usb: gadget: uvc: fix missing mutex_unlock() if kstrtou8() fails
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.174
    - wifi: cfg80211: Partial revert "wifi: cfg80211: Fix use after free for
    wext"
    - [x86] staging: rtl8192e: Remove function ..dm_check_ac_dc_power calling a
    script
    - [x86] staging: rtl8192e: Remove call_usermodehelper starting RadioPower.sh
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.175
    - fs: prevent out-of-bounds array speculation when closing a file descriptor
    - fork: allow CLONE_NEWTIME in clone3 flags
    - [x86] CPU/AMD: Disable XSAVES on AMD family 0x17
    - drm/amdgpu: fix error checking in amdgpu_read_mm_registers for soc15
    - drm/connector: print max_requested_bpc in state debugfs
    - ext4: fix cgroup writeback accounting with fs-layer encryption
    - ext4: fix RENAME_WHITEOUT handling for inline directories
    - ext4: fix another off-by-one fsmap error on 1k block filesystems
    - ext4: move where set the MAY_INLINE_DATA flag is set
    - ext4: fix WARNING in ext4_update_inline_data
    - ext4: zero i_disksize when initializing the bootloader inode
    - nfc: change order inside nfc_se_io error path
    - udf: Fix off-by-one error when discarding preallocation
    - irq: Fix typos in comments
    - irqdomain: Look for existing mapping only once
    - irqdomain: Refactor __irq_domain_alloc_irqs()
    - irqdomain: Fix mapping-creation race
    - irqdomain: Change the type of 'size' in __irq_domain_add() to be
    consistent
    - irqdomain: Fix domain registration race
    - [amd64] iommu/vt-d: Fix lockdep splat in intel_pasid_get_entry()
    - [amd64] iommu/vt-d: Fix PASID directory pointer coherency
    - [arm64] efi: Make efi_rt_lock a raw_spinlock
    - scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
    - ext4: Fix possible corruption when moving a directory
    - drm/nouveau/kms/nv50-: remove unused functions
    - drm/nouveau/kms/nv50: fix nv50_wndw_new_ prototype
    - [arm64] drm/msm: Fix potential invalid ptr free
    - [arm64] drm/msm/a5xx: fix setting of the CP_PREEMPT_ENABLE_LOCAL register
    - [arm64] drm/msm: Document and rename preempt_lock
    - [arm64] drm/msm/a5xx: fix the emptyness check in the preempt code
    - [arm64] drm/msm/a5xx: fix context faults during ring switch
    - ila: do not generate empty messages in ila_xlat_nl_cmd_get_mapping()
    - net: usb: lan78xx: Remove lots of set but unused 'ret' variables
    - net: lan78xx: fix accessing the LAN7800's internal phy specific registers
    from the MAC driver
    - net: stmmac: add to set device wake up flag when stmmac init phy
    - net: phylib: get rid of unnecessary locking
    - bnxt_en: Avoid order-5 memory allocation for TPA data
    - netfilter: ctnetlink: revert to dumping mark regardless of event type
    - netfilter: tproxy: fix deadlock due to missing BH disable
    - btf: fix resolving BTF_KIND_VAR after ARRAY, STRUCT, UNION, PTR
    - scsi: megaraid_sas: Update max supported LD IDs to 240
    - net/smc: fix fallback failed while sendmsg with fastopen
    - SUNRPC: Fix a server shutdown leak
    - ext4: Fix deadlock during directory rename
    - [amd64] iommu/amd: Add a length limitation for the ivrs_acpihid
    command-line parameter
    - watch_queue: fix IOC_WATCH_QUEUE_SET_SIZE alloc error paths
    - tpm/eventlog: Don't abort tpm_read_log on faulty ACPI address
    - block, bfq: fix possible uaf for 'bfqq->bic'
    - block, bfq: fix uaf for bfqq in bfq_exit_icq_bfqq
    - block/bfq-iosched.c: use "false" rather than "BLK_RW_ASYNC"
    - block, bfq: replace 0/1 with false/true in bic apis
    - block, bfq: fix uaf for bfqq in bic_set_bfqq()
    - PCI: Add SolidRun vendor ID
    - [armhf] media: rc: gpio-ir-recv: add remove function
    - ipmi/watchdog: replace atomic_add() and atomic_sub()
    - ipmi:watchdog: Set panic count to proper value on a panic
    - skbuff: Fix nfct leak on napi stolen
    - [x86] drm/i915: Don't use BAR mappings for ring buffers with LLC
    - ext4: refactor ext4_free_blocks() to pull out ext4_mb_clear_bb()
    - ext4: add ext4_sb_block_valid() refactored out of ext4_inode_block_valid()
    - ext4: add strict range checks while freeing blocks
    - ext4: block range must be validated before use in ext4_mb_clear_bb()
    - arch: fix broken BuildID for arm64 and riscv
    - [powerpc*] vmlinux.lds: Define RUNTIME_DISCARD_EXIT
    - [powerpc*] vmlinux.lds: Don't discard .rela* for relocatable builds
    - [s390x] define RUNTIME_DISCARD_EXIT to fix link error with GNU ld < 2.36
    - [x86] KVM: nVMX: Don't use Enlightened MSR Bitmap for L3
    - [x86] KVM: VMX: Introduce vmx_msr_bitmap_l01_changed() helper
    - [x86] KVM: VMX: Fix crash due to uninitialized current_vmcs
    - [s390x] dasd: add missing discipline function
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.176
    - xfrm: Allow transport-mode states with AF_UNSPEC selector
    - [arm64,armhf] drm/panfrost: Don't sync rpm suspension after mmu flushing
    - cifs: Move the in_send statistic to __smb_send_rqst()
    - [arm64] drm/meson: fix 1px pink line on GXM when scaling video overlay
    - docs: Correct missing "d_" prefix for dentry_operations member
    d_weak_revalidate
    - scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add()
    - ALSA: hda: Match only Intel devices with CONTROLLER_IN_GPU()
    - netfilter: nft_nat: correct length for loading protocol registers
    - netfilter: nft_masq: correct length for loading protocol registers
    - netfilter: nft_redir: correct length for loading protocol registers
    - netfilter: nft_redir: correct value of inet type `.maxattrs`
    - scsi: core: Fix a comment in function scsi_host_dev_release()
    - scsi: core: Fix a procfs host directory removal regression
    - tcp: tcp_make_synack() can be called from process context
    - nfc: pn533: initialize struct pn533_out_arg properly
    - ipvlan: Make skb->skb_iif track skb->dev for l3s mode
    - i40e: Fix kernel crash during reboot when adapter is in recovery mode
    - net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler()
    - qed/qed_dev: guard against a possible division by zero
    - net: tunnels: annotate lockless accesses to dev->needed_headroom
    - net: phy: smsc: bail out in lan87xx_read_status if genphy_read_status
    fails
    - net/smc: fix deadlock triggered by cancel_delayed_work_syn()
    - net: usb: smsc75xx: Limit packet length to skb->len
    - drm/bridge: Fix returned array size name for atomic_get_input_bus_fmts
    kdoc
    - nvme: fix handling single range discard request
    - nvmet: avoid potential UAF in nvmet_req_complete()
    - ice: xsk: disable txq irq before flushing hw
    - net: dsa: mv88e6xxx: fix max_mtu of 1492 on 6165, 6191, 6220, 6250, 6290
    - ipv4: Fix incorrect table ID in IOCTL path
    - net: usb: smsc75xx: Move packet length check to prevent kernel panic in
    skb_pull
    - [s390x] net/iucv: Fix size of interrupt data
    - qed/qed_mng_tlv: correctly zero out ->min instead of ->hour
    - hwmon: (adt7475) Display smoothing attributes in correct order
    - hwmon: (adt7475) Fix masking of hysteresis registers
    - [arm64] hwmon: (xgene) Fix use after free bug in xgene_hwmon_remove due to
    race condition (CVE-2023-1855)
    - jffs2: correct logic when creating a hole in jffs2_write_begin
    - ext4: fail ext4_iget if special inode unallocated
    - ext4: fix task hung in ext4_xattr_delete_inode
    - drm/amd/display: fix shift-out-of-bounds in CalculateVMAndRowBytes
    - ext4: fix possible double unlock when moving a directory
    - [arm64] tty: serial: fsl_lpuart: skip waiting for transmission complete
    when UARTCTRL_SBK is asserted
    - [arm64] firmware: xilinx: don't make a sleepable memory allocation from an
    atomic context
    - tracing: Make splice_read available again
    - tracing: Check field value in hist_field_name()
    - tracing: Make tracepoint lockdep check actually test something
    - cifs: Fix smb2_set_path_size()
    - [x86] KVM: nVMX: add missing consistency checks for CR0 and CR4
    (CVE-2023-30456)
    - ALSA: hda: intel-dsp-config: add MTL PCI id
    - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy Book2 Pro
    - drm/shmem-helper: Remove another errant put in error path
    - ftrace: Fix invalid address access in lookup_rec() when index is 0
    - mm/userfaultfd: propagate uffd-wp bit when PTE-mapping the huge zeropage
    - [x86] mce: Make sure logged MCEs are processed after sysfs update
    - [x86] mm: Fix use of uninitialized buffer in sme_enable()
    - [x86] drm/i915: Don't use stolen memory for ring buffers with LLC
    - [x86] drm/i915/active: Fix misuse of non-idle barriers as fence trackers
    - io_uring: avoid null-ptr-deref in io_arm_poll_handler
    - [s390x] ipl: add missing intersection check to ipl_report handling
    - PCI: Unify delay handling for reset and resume
    - PCI/DPC: Await readiness of secondary bus after reset
    - xfs: don't assert fail on perag references on teardown
    - xfs: purge dquots after inode walk fails during quotacheck
    - xfs: don't leak btree cursor when insrec fails after a split
    - xfs: remove XFS_PREALLOC_SYNC
    - xfs: fallocate() should call file_modified()
    - xfs: set prealloc flag in xfs_alloc_file_space()
    - xfs: use setattr_copy to set vfs inode attributes
    - fs: add mode_strip_sgid() helper
    - fs: move S_ISGID stripping into the vfs_*() helpers
    - attr: add in_group_or_capable()
    - fs: move should_remove_suid()
    - attr: add setattr_should_drop_sgid()
    - attr: use consistent sgid stripping checks
    - fs: use consistent setgid checks in is_sxid()
    - xfs: remove xfs_setattr_time() declaration
    - HID: core: Provide new max_buffer_size attribute to over-ride the default
    - HID: uhid: Over-ride the default maximum data buffer value with our own
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.177
    - perf/core: Fix perf_output_begin parameter is incorrectly invoked in
    perf_event_bpf_output
    - perf: fix perf_event_context->time
    - ipmi:ssif: make ssif_i2c_send() void
    - ipmi:ssif: Increase the message retry time
    - ipmi:ssif: resend_msg() cannot fail
    - ipmi:ssif: Add a timer between request retries
    - KVM: Clean up benign vcpu->cpu data races when kicking vCPUs
    - KVM: KVM: Use cpumask_available() to check for NULL cpumask when kicking
    vCPUs
    - KVM: Optimize kvm_make_vcpus_request_mask() a bit
    - KVM: Pre-allocate cpumasks for kvm_make_all_cpus_request_except()
    - KVM: Register /dev/kvm as the _very_ last thing during initialization
    - [arm64] serial: fsl_lpuart: Fix comment typo
    - [arm64] tty: serial: fsl_lpuart: fix race on RX DMA shutdown
    - [arm64,armhf] drm/sun4i: fix missing component unbind on bind errors
    - net: tls: fix possible race condition between do_tls_getsockopt_conf() and
    do_tls_setsockopt_conf() (CVE-2023-28466)
    - [x86] power: supply: bq24190_charger: using pm_runtime_resume_and_get
    instead of pm_runtime_get_sync
    - [x86] power: supply: bq24190: Fix use after free bug in bq24190_remove due
    to race condition
    - [armhf] dts: imx6sl: tolino-shine2hd: fix usbotg1 pinctrl
    - xsk: Add missing overflow check in xdp_umem_reg
    - iavf: fix inverted Rx hash condition leading to disabled hash
    - iavf: fix non-tunneled IPv6 UDP packet type and hashing
    - intel/igbvf: free irq on the error path in igbvf_request_msix()
    - igbvf: Regard vf reset nack as success
    - igc: fix the validation logic for taprio's gate list
    - scsi: scsi_dh_alua: Fix memleak for 'qdata' in alua_activate()
    - net: usb: smsc95xx: Limit packet length to skb->len
    - qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
    - [x86] xirc2ps_cs: Fix use after free bug in xirc2ps_detach (CVE-2023-1670)
    - net: phy: Ensure state transitions are processed from phy_stop()
    - net: mdio: fix owner field for mdio buses registered using device-tree
    - [arm64] net: qcom/emac: Fix use after free bug in emac_remove due to race
    condition
    - keys: Do not cache key in task struct if key is requested from kernel
    thread
    - bpf: Adjust insufficient default bpf_jit_limit
    - net/mlx5: Fix steering rules cleanup
    - net/mlx5: Read the TC mapping of all priorities on ETS query
    - net/mlx5: E-Switch, Fix an Oops in error handling code
    - atm: idt77252: fix kmemleak when rmmod idt77252
    - erspan: do not use skb_mac_header() in ndo_start_xmit()
    - nvme-tcp: fix nvme_tcp_term_pdu to match spec
    - [amd64,arm64] gve: Cache link_speed value from device
    - [arm64] net: mdio: thunder: Add missing fwnode_handle_put()
    - [arm64] Bluetooth: btqcomsmd: Fix command timeout after setting BD address
    - Bluetooth: L2CAP: Fix not checking for maximum number of DCID
    - Bluetooth: L2CAP: Fix responding with wrong PDU type
    - Bluetooth: btsdio: fix use after free bug in btsdio_remove due to
    unfinished work (CVE-2023-1989)
    - [arm64] platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl
    - hwmon: fix potential sensor registration fail if of_node is missing
    - [x86] hwmon (it87): Fix voltage scaling for chips with 10.9mV ADCs
    - scsi: qla2xxx: Perform lockless command completion in abort path
    - [x86] thunderbolt: Use scale field when allocating USB3 bandwidth
    - [x86] thunderbolt: Use const qualifier for `ring_interrupt_index`
    - HID: cp2112: Fix driver not registering GPIO IRQ chip as threaded
    - scsi: target: iscsi: Fix an error message in iscsi_check_key()
    - [arm64] scsi: hisi_sas: Check devm_add_action() return value
    - scsi: ufs: core: Add soft dependency on governor_simpleondemand
    - scsi: lpfc: Avoid usage of list iterator variable after loop
    - [x86] scsi: storvsc: Handle BlockSize change in Hyper-V VHD/VHDX file
    - net: usb: cdc_mbim: avoid altsetting toggling for Telit FE990
    - net: usb: qmi_wwan: add Telit 0x1080 composition
    - cifs: empty interface list when server doesn't support query interfaces
    - scsi: core: Add BLIST_SKIP_VPD_PAGES for SKhynix H28U74301AMR
    - [arm*] usb: dwc2: fix a devres leak in hw_enable upon suspend resume
    - usb: gadget: u_audio: don't let userspace block driver unbind
    - fsverity: Remove WQ_UNBOUND from fsverity read workqueue
    - igb: revert rtnl_lock() that causes deadlock
    - dm thin: fix deadlock when swapping to thin device
    - [arm64,armhf] usb: chipdea: core: fix return -EINVAL if request role is
    the same with current role
    - [arm64,armhf] usb: chipidea: core: fix possible concurrent when switch
    role
    - usb: ucsi: Fix NULL pointer deref in ucsi_connector_change()
    - wifi: mac80211: fix qos on mesh interfaces
    - nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_copy()
    - [x86] drm/i915/active: Fix missing debug object activation
    - [x86] drm/i915: Preserve crtc_state->inherited during state clearing
    - [arm64] i2c: xgene-slimpro: Fix out-of-bounds bug in
    xgene_slimpro_i2c_xfer() (CVE-2023-2194)
    - dm stats: check for and propagate alloc_percpu failure
    - dm crypt: add cond_resched() to dmcrypt_write()
    - sched/fair: sanitize vruntime of entity being placed
    - sched/fair: Sanitize vruntime of entity being migrated
    - ocfs2: fix data corruption after failed write
    - xfs: shut down the filesystem if we screw up quota reservation
    - xfs: don't reuse busy extents on extent trim
    - KVM: fix memoryleak in kvm_init()
    - NFSD: fix use-after-free in __nfs42_ssc_open() (CVE-2022-4379)
    - [arm64,armhf] usb: dwc3: gadget: move cmd_endtransfer to extra function
    - [arm64,armhf] usb: dwc3: gadget: Add 1ms delay after end transfer command
    without IOC
    - [arm64] drm/meson: Fix error handling when afbcd.ops->init fails
    - [arm64] drm/meson: fix missing component unbind on bind errors
    - dm crypt: avoid accessing uninitialized tasklet
    - fsverity: don't drop pagecache at end of FS_IOC_ENABLE_VERITY
    - md: avoid signed overflow in slot_store()
    - [x86] ALSA: asihpi: check pao in control_message()
    - ALSA: hda/ca0132: fixup buffer overrun at tuning_ctl_set()
    - sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
    - tracing: Fix wrong return in kprobe_event_gen_test.c
    - sfc: ef10: don't overwrite offload features at NIC reset
    - scsi: megaraid_sas: Fix crash after a double completion
    - [arm64] ptp_qoriq: fix memory leak in probe()
    - r8169: fix RTL8168H and RTL8107E rx crc error
    - [arm*] regulator: Handle deferred clk
    - net/net_failover: fix txq exceeding warning
    - net: stmmac: don't reject VLANs when IFF_PROMISC is set
    - ALSA: ymfpci: Fix assignment in if condition
    - ALSA: ymfpci: Fix BUG_ON in probe function
    - i40e: fix registers dump after run ethtool adapter self test
    - bnxt_en: Fix typo in PCI id to device description string mapping
    - bnxt_en: Add missing 200G link speed reporting
    - [arm64,armhf] net: dsa: mv88e6xxx: Enable IGMP snooping on user ports only
    - Input: alps - fix compatibility with -funsigned-char
    - Input: focaltech - use explicitly signed char type
    - cifs: prevent infinite recursion in CIFSGetDFSRefer()
    - cifs: fix DFS traversal oops without CONFIG_CIFS_DFS_UPCALL
    - Input: goodix - add Lenovo Yoga Book X90F to nine_bytes_report DMI table
    - btrfs: fix race between quota disable and quota assign ioctls
    (CVE-2023-1611)
    - xen/netback: don't do grant copy across page boundary
    - pinctrl: amd: Disable and mask interrupts on resume
    - [powerpc*] Don't try to copy PPR for task with NULL pt_regs
    - NFSv4: Fix hangs when recovering open state after a server reboot
    - ALSA: hda/conexant: Partial revert of a quirk for Lenovo
    - ALSA: usb-audio: Fix regression on detection of Roland VS-100
    - ALSA: hda/realtek: Add quirk for Lenovo ZhaoYang CF4620Z
    - rcu: Fix rcu_torture_read ftrace event
    - [armhf] drm/etnaviv: fix reference leak when mmaping imported buffer
    - drm/amd/display: Add DSC Support for Synaptics Cascaded MST Hub
    - [s390x] uaccess: add missing earlyclobber annotations to __clear_user()
    - btrfs: scan device in non-exclusive mode
    - zonefs: Fix error message in zonefs_file_dio_append()
    - ext4: fix kernel BUG in 'ext4_write_inline_data_end()'
    - gfs2: Always check inode size of inline inodes
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.178
    - [x86] Drivers: vmbus: Check for channel allocation before looking up
    relids
    - [arm64] pwm: cros-ec: Explicitly set .polarity in .get_state()
    - [s390x] KVM: s390: pv: fix external interruption loop not always detected
    - wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded
    sta
    - icmp: guard against too small mtu
    - net: don't let netpoll invoke NAPI if in xmit context
    - sctp: check send stream number after wait_for_sndbuf
    - ipv6: Fix an uninit variable access bug in __ip6_make_skb()
    - net: stmmac: fix up RX flow hash indirection table when setting channels
    - sunrpc: only free unix grouplist after RCU settles
    - NFSD: callback request does not use correct credential for AUTH_SYS
    - [arm64,armhf] usb: xhci: tegra: fix sleep in atomic call
    - xhci: also avoid the XHCI_ZERO_64B_REGS quirk with a passthrough iommu
    - USB: serial: cp210x: add Silicon Labs IFS-USB-DATACABLE IDs
    - usb: typec: altmodes/displayport: Fix configure initial pin assignment
    - USB: serial: option: add Telit FE990 compositions
    - USB: serial: option: add Quectel RM500U-CN modem
    - iio: adc: ti-ads7950: Set `can_sleep` flag for GPIO chip
    - iio: light: cm32181: Unregister second I2C client if present
    - [arm64] tty: serial: fsl_lpuart: avoid checking for transfer complete when
    UARTCTRL_SBK is asserted in lpuart32_tx_empty
    - nilfs2: fix potential UAF of struct nilfs_sc_info in
    nilfs_segctor_thread()
    - nilfs2: fix sysfs interface lifetime
    - dt-bindings: serial: renesas,scif: Fix 4th IRQ for 4-IRQ SCIFs
    - ALSA: hda/realtek: Add quirk for Clevo X370SNW
    - iio: adc: ad7791: fix IRQ flags
    - scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()
    - perf/core: Fix the same task check in perf_event_set_output
    - ftrace: Mark get_lock_parent_ip() __always_inline
    - ftrace: Fix issue that 'direct->addr' not restored in
    modify_ftrace_direct()
    - can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access
    - can: isotp: isotp_ops: fix poll() to not report false EPOLLOUT events
    - tracing: Free error logs of tracing instances
    - ASoC: hdac_hdmi: use set_stream() instead of set_tdm_slots()
    - [arm64,armhf] drm/panfrost: Fix the panfrost_mmu_map_fault_addr() error
    path
    - drm/nouveau/disp: Support more modes by checking with lower bpc
    - ring-buffer: Fix race while reader and writer are on the same page
    - mm/swap: fix swap_info_struct race between swapoff and get_swap_pages()
    - ocfs2: fix freeing uninitialized resource on ocfs2_dlm_shutdown
    - bpftool: Print newline before '}' for struct with padding only fields
    - Revert "pinctrl: amd: Disable and mask interrupts on resume"
    - ALSA: emu10k1: fix capture interrupt handler unlinking
    - ALSA: hda/sigmatel: add pin overrides for Intel DP45SG motherboard
    - ALSA: i2c/cs8427: fix iec958 mixer control deactivation
    - ALSA: firewire-tascam: add missing unwind goto in
    snd_tscm_stream_start_duplex()
    - ALSA: hda/sigmatel: fix S/PDIF out on Intel D*45* motherboards
    - Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
    - Bluetooth: Fix race condition in hidp_session_thread
    - btrfs: print checksum type and implementation at mount time
    - btrfs: fix fast csum implementation detection
    - fbmem: Reject FB_ACTIVATE_KD_TEXT from userspace
    - mtdblock: tolerate corrected bit-flips
    - [armhf] mtd: rawnand: stm32_fmc2: remove unsupported EDO mode
    - [armhf] mtd: rawnand: stm32_fmc2: use timings.mode instead of checking
    tRC_min
    - IB/mlx5: Add support for NDR link speed
    - IB/mlx5: Add support for 400G_8X lane speed
    - RDMA/cma: Allow UD qp_type to join multicast only
    - 9p/xen : Fix use after free bug in xen_9pfs_front_remove due to race
    condition (CVE-2023-1859)
    - niu: Fix missing unwind goto in niu_alloc_channels()
    - sysctl: add proc_dou8vec_minmax()
    - ipv4: shrink netns_ipv4 with sysctl conversions
    - tcp: convert elligible sysctls to u8
    - tcp: restrict net.ipv4.tcp_app_win
    - [armhf] drm/armada: Fix a potential double free in an error handling path
    - qlcnic: check pci_reset_function result
    - sctp: fix a potential overflow in sctp_ifwdtsn_skip
    - RDMA/core: Fix GID entry ref leak when create_ah fails
    - udp6: fix potential access to stale information
    - [arm64] net: macb: fix a memory corruption in extended buffer descriptor
    mode
    - [arm64] power: supply: cros_usbpd: reclassify "default case!" as debug
    - wifi: mwifiex: mark OF related data as maybe unused
    - [x86] efi: sysfb_efi: Add quirk for Lenovo Yoga Book X91F/L
    - drm: panel-orientation-quirks: Add quirk for Lenovo Yoga Book X90F
    - [amd64] verify_pefile: relax wrapper length check
    - asymmetric_keys: log on fatal failures in PE/pkcs7
    - net: sfp: initialize sfp->i2c_block_size at sfp allocation
    - scsi: ses: Handle enclosure with just a primary component gracefully
    - [x86] PCI: Add quirk for AMD XHCI controller that loses MSI-X state in
    D3hot
    - cgroup/cpuset: Wake up cpuset_attach_wq tasks in cpuset_cancel_attach()
    - ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size
    - mtd: ubi: wl: Fix a couple of kernel-doc issues
    - ubi: Fix deadlock caused by recursively holding work_sem
    - [powerpc*] pseries: rename min_common_depth to primary_domain_index
    - [powerpc*] pseries: Rename TYPE1_AFFINITY to FORM1_AFFINITY
    - [powerpc*] pseries: Consolidate different NUMA distance update code paths
    - [powerpc*] pseries: Add a helper for form1 cpu distance
    - [powerpc*] pseries: Add support for FORM2 associativity
    - [powerpc*] papr_scm: Update the NUMA distance table for the target node
    - sched/fair: Move calculate of avg_load to a better location
    - sched/fair: Fix imbalance overflow
    - [x86] rtc: Remove __init for runtime functions
    - i2c: ocores: generate stop condition after timeout in polling mode
    - [arm64] watchdog: sbsa_wdog: Make sure the timeout programming is within
    the limits
    - kbuild: check the minimum assembler version in Kconfig
    - kbuild: Switch to 'f' variants of integrated assembler flag
    - kexec: move locking into do_kexec_load
    - kexec: turn all kexec_mutex acquisitions into trylocks

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)