Merge tag 'for-7.3-rc3-tag' of git://git.kernel.org/pub/scm/linux/kernel/git/kdave/linux
Pull btrfs fixes from David Sterba:
"Among the regular fixes, there are two that were reported recently and
have user impact:
- filesystem id is now stable again on the default and common case
(it broke openconnect key derivation, while this is not secure,
it's still in use), the intention was to change id for the
temp_fsid use case
- fix detection of /dev/root and rename it after device scan, this
broke booting of initramdisk-less system with grub2 as the probe
needs the real device
Regular fixes:
- don't store compressed inline extent if the size is larger than
uncompressed
[29 lines not shown]
Merge tag 'drm-fixes-2026-09-19' of https://gitlab.freedesktop.org/drm/kernel
Pull drm fixes from Dave Airlie:
"Things have picked back up a bit this week, mostly amdgpu, xe and msm
this time. There are a bunch of scattered changes across the rest of
drivers and core stuff, nouveau, i915.
core:
- fix vblank pending event leak
ttm:
- swapout fixes
dma-buf:
- scattergather fixes
- enable dma-buf debug on debug kernels
dma-fence:
- fix signaling bit checks
[85 lines not shown]
Merge tag 'drm-misc-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/misc/kernel into drm-fixes
Two ttm fixes for ttm_tt_swapout(), one page-alignment and one overflow
fix for dma-buf, a drm_pending_vblank_event leak fix for drm,
suspend/resume fixes for nouveau, one out-of-bounds access fix for gud,
a use-after-free fix for vc4, a fence signaling fix, a race condition
fix for sched, planes formats fixes for verisilicon, and add the blend
mode property for loongson
Signed-off-by: Dave Airlie <airlied at redhat.com>
From: Maxime Ripard <self at mripard.dev>
Link: https://patch.msgid.link/aqvVENQ4ksJEIcdb@houat
Merge tag 'cifs-fixes-7.3-rc4' of https://git.manguebit.org/linux
Pull smb client fixes from Paulo Alcantara:
"A batch of bug fixes for the smb client:
- Fix multiple out-of-bounds reads and use-after-frees in the SMB2/3
receive path that are reachable from a malicious or compromised
server: a stale next_buffer pointer and an integer overflow in
compound encrypted frame handling, missing minimum-PDU-size and
per-sub-PDU length validation before parsing command-specific
response fields, missing bounds checks in DFS referral, server
interface list, EA list, POSIX SID, snapshot enumeration and SMB1
reparse point parsing
- Fix use-after-frees and races in multichannel and connection
teardown, including an interface freed while still in use when
adding channels, a server used after its channel reference was
dropped, a reconnect work item left queued after the server is
freed and an uninitialized reconnect list node
[38 lines not shown]
Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi
Pull SCSI fixes from James Bottomley:
"Four driver fixes, three of which are minor and one of which (fnic)
tries to add some logic to try to avoid MSI-X being ineffective if
hyperthreading is disabled.
The core fix adds validation to mode sense buffer sizes because it is
used by ATA and could, theoretically, be exploited by a specially
crafted USB device that can simply be plugged in to any laptop or
server"
* tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:
scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
scsi: ibmvfc: Add Kconfig dependency to fix link failure when NVME_FC=m
scsi: qla2xxx: Fix the ql2xfc2target parameter description
scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions
Merge tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci
Pull PCI fix from Bjorn Helgaas:
- Enable clock after core reset is asserted to fix enumeration
regression on i.MX6Q Apalis platforms with ASM1061/ASM1062 SATA
controllers (Richard Zhu)
* tag 'pci-v7.3-fixes-1' of git://git.kernel.org/pub/scm/linux/kernel/git/pci/pci:
PCI: imx6: Move clock enable after core reset assertion
Merge tag 'ksmbd-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/smb
Pull smb server fixes from Namjae Jeon:
- Fix session expiration so that valid sessions are no longer removed
after ten seconds of inactivity when a new session setup request is
received.
Sessions now expire only after credential expiration, while stale
unauthenticated sessions are cleaned up after a 45-second timeout.
- Keep earlier responses in compound requests when Query Info fails
because the output buffer is too small. The error response is
appended without truncating preceding responses.
- Return STATUS_BUFFER_OVERFLOW for partial
FILE_NORMALIZED_NAME_INFORMATION responses instead of incorrectly
returning STATUS_INFO_LENGTH_MISMATCH.
[4 lines not shown]
Merge tag 'ntfs-for-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/linkinjeon/ntfs
Pull ntfs fixes from Namjae Jeon:
- Make MFT extension work on existing Windows-created volumes by
dynamically reserving MFT tail records, accounting for records added
during allocation, and avoiding false -ENOSPC failures
- Repack non-resident $MFT/$ATTRIBUTE_LIST when its mapping pairs no
longer fit in the base MFT record, while propagating allocation and
writeback errors
- Serialize runlist updates with the runlist lock and restore both the
in-memory runlist and on-disk mapping pairs when allocation rollback
is required
- Propagate folio errors and harden inode failure handling by treating
interrupted reads as transient failures and discarding and unhashing
inodes whose initialization fails
[15 lines not shown]
Merge tag 'mmc-v7.3-rc1' of git://git.kernel.org/pub/scm/linux/kernel/git/ulfh/mmc
Pull MMC/MEMSTICK fixes from Ulf Hansson:
"MMC core:
- Prevent potential use-after-free for SDIO IRQ work
- Fix OF node reference leak on card add failure
- Fix memory lea when the port table is full for sdio_uart
MMC host:
- hsq: Fix use-after-free in retry work
- mmci: Fix use-after-free in busy-timeout work
- mmc_spi: Reset bytes_xfered before retrying CRC failures
- mxcmmc: Cancel data work and watchdog on remove
- rtsx_pci_sdmmc: Ignore broken write-protect on ThinkPad X260
- sdhci_am654: A couple of fixes for the tuning sequence
- sdhci-of-aspeed: Remove children before releasing SDC resources
- sh_mmcif: Initialize IRQ-thread mutex before requesting interrupt
MEMSTICK:
[18 lines not shown]
Merge tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux
Pull ata fixes from Niklas Cassel:
- Explicitly clear upper address bits on quirked AHCI controllers
AHCI controllers that claim to support 64-bit DMA, but which have
been quirked to only do 32-bit DMA, could start the DMA engine with a
non-zero value in the upper address bits registers (me)
- Fix a resource leak in ahci_platform_get_resources() (Wentao)
- Fix invalid kernel-doc formatting for ata_dsm_trim_pages() (me)
* tag 'ata-7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/libata/linux:
ata: libata-scsi: fix ata_dsm_trim_pages() kernel-doc
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
Merge tag 'hwmon-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging
Pull hwmon fixes from Guenter Roeck:
- Add missing sensors, and fix current sensors ID lookup (cgbc-hwmon)
- Return IRQ_HANDLED from the shared alarm IRQ handler to fix possible
interrupt storm (gpioufan)
- Improve raw WMI string handling, and fix UaF in show function
(hp-wmi-sensors)
- Fix k10temp model id range of Zen5 Turin to stop reporting
temperature data for non-existing CCDs
- pmbus:
- Increase number of phases to fix UaF problems
- Fix TPS53676 phase page decoding, and select page 0 for
single-page applications
[20 lines not shown]
Merge tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging
Pull watchdog fixes from Guenter Roeck:
- Fix suspend/resume handling of HW_RUNNING watchdog (da9062, da9063)
- Avoid division by zero if clock rate is 0 (digicolor, rtd119x, and
rzv2h)
- Fix premature reset during timeout update, and propagate error code
in msc313e resume()
- Fix pci_dev reference leak in sp5100_tco_init()
- Fix runtime PM leak in starfive_wdt_pm_start()
* tag 'watchdog-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/groeck/linux-staging:
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
[7 lines not shown]
Merge tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6
Pull crypto fix from Herbert Xu:
"Fix a regression in caam"
* tag 'v7.3-p4' of git://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6:
crypto: caam - map job ring registers without claiming region
Merge tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc
Pull SoC fixes from Arnd Bergmann:
"The driver fixes are all for simple mistakes: a use-after-free bug on
Samsung Exynos, error handling and reference counting on Arm SCMI
firmware and a problem dealing with inconsistent firmware information.
The rest are devicetree fixes for arm64 platforms from Altera, Renesas
and Amlogic. On the Renesas platform, one patch addresses a boot time
regression, the rest address minor performance and correctness issues"
* tag 'soc-fixes-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/soc/soc: (21 commits)
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
arm64: dts: renesas: r8a779f0: Set UFS lane count
firmware: arm_scmi: Fix typo "upto" in comment
arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR
arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR
arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
[14 lines not shown]
Merge tag 'arm64-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux
Pull arm64 fixes from Will Deacon:
"In this batch we've got a couple of hibernation fixes, a couple of
minor MTE fixes, some per-cpu codegen fixes (which were found as part
of Mark's series adding preemptible this_cpu_*() operations) and a fix
for the Arm CMN PMU driver.
Summary:
- Fix hypercall arguments when resetting EL2 vectors during
hibernation
- Fix hibernation with 52-bit capable kernels on machines without
52-bit addressing, similarly to the recent kexec fix
- Fix a bunch of clumsy codegen issues with our per-cpu accessors
- Fix MTE ptrace documentation to reflect the de-facto ABI behaviour
[14 lines not shown]
Merge tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux
Pull MIPS fixes from Thomas Bogendoerfer:
- Fix kconfig dependencies for ECONET
- Enable weak reordering for EYEQ
- Include USB FDT fixup for Octeon even when USB is modular
* tag 'mips-fixes_7.3_1' of git://git.kernel.org/pub/scm/linux/kernel/git/mips/linux:
MIPS: Octeon: apply USB FDT fixups also when USB is modular
mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
MIPS: config: Add EcoNet EN751221 defconfig
mips: econet: fix unmet dependencies for ECONET
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes: a7ceca4398bc8 ("watchdog: da9063: optionally disable watchdog during suspend")
Cc: stable at vger.kernel.org
Signed-off-by: Li Jun <lijun01 at kylinos.cn>
Link: https://patch.msgid.link/20260917013710.2754679-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux at roeck-us.net>
Merge tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel into arm/fixes
Renesas fixes for v7.3 (take two)
- Fix UFS regression on R-Car S4.
* tag 'renesas-fixes-for-v7.3-tag2' of git://git.kernel.org/pub/scm/linux/kernel/git/geert/renesas-devel:
arm64: dts: renesas: r8a779f0: Set UFS lane count
Signed-off-by: Arnd Bergmann <arnd at arndb.de>
Merge tag 'drm-xe-fixes-2026-09-17' of https://gitlab.freedesktop.org/drm/xe/kernel into drm-fixes
Couple shrinker related fixes plus a series of patches fixing several
xe_mmio_gem issues around fault handler and destroy path.
Signed-off-by: Dave Airlie <airlied at redhat.com>
From: Rodrigo Vivi <rodrigo.vivi at intel.com>
Link: https://patch.msgid.link/aqvoKaPuLLPBGayA@intel.com
Merge tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd
Pull key fixes from Jarkko Sakkinen.
* tag 'for-next-keys-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/jarkko/linux-tpmdd:
KEYS: encrypted: fix integer overflow of datablob_len
KEYS: trusted: Fix tpm2_load_cmd() boundary check
keys: translate request_key_auth pid for the reading procfs instance
keys: fix lost wakeup when reaping a dead key type
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes: f591062bdbf4 ("cifs: handle servers that still advertise multichannel after disabling")
Cc: stable at vger.kernel.org
Signed-off-by: Wentao Liang <vulab at iscas.ac.cn>
Signed-off-by: Paulo Alcantara <pc at manguebit.org>
PCI: imx6: Move clock enable after core reset assertion
Commit 610fa91d9863 ("PCI: imx6: Assert PERST# before enabling regulators")
inadvertently moved clock enablement before core reset assertion, breaking
PCI device initialization on i.MX6Q Apalis platforms with
ASM1061/ASM1062 SATA controllers connected:
imx6q-pcie 1ffc000.pcie: host bridge /soc/pcie at 1ffc000 ranges:
imx6q-pcie 1ffc000.pcie: IO 0x0001f80000..0x0001f8ffff -> 0x0000000000
imx6q-pcie 1ffc000.pcie: MEM 0x0001000000..0x0001efffff -> 0x0001000000
imx6q-pcie 1ffc000.pcie: config reg[1] 0x01f00000 == cpu 0x01f00000
imx6q-pcie 1ffc000.pcie: iATU: unroll F, 4 ob, 4 ib, align 64K, limit 4G
imx6q-pcie 1ffc000.pcie: Link: Only Gen1 is enabled
imx6q-pcie 1ffc000.pcie: Link failed to come up. LTSSM: POLL_CONFIG
imx6q-pcie 1ffc000.pcie: probe with driver imx6q-pcie failed with error -110
NOTE: It is not 100% clear if the issue is specific to the ASM1061/ASM1062
device or on the specific power-up sequence (reset vs cold-power-on).
[14 lines not shown]
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes: 56e84c64fc25 ("cifs: Fix validation of SMB1 query reparse point response")
Cc: stable at vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson at redhat.com>
Reviewed-by: David Howells <dhowells at redhat.com>
Signed-off-by: Paulo Alcantara <pc at manguebit.org>
smb: client: fix potential OOB read in smb3_enum_snapshots()
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
[6 lines not shown]
smb: client: fix missing iov bounds check in parse_posix_sids()
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable at vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson at redhat.com>
Reviewed-by: David Howells <dhowells at redhat.com>
Signed-off-by: Paulo Alcantara <pc at manguebit.org>
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src_size is too small to contain a complete smb2_ea_info structure.
Consequently, reads of ea_name_length and ea_value_length can occur
out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next_entry_offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
[5 lines not shown]
smb: client: reject short Next offsets in parse_server_interfaces()
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable at vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson at redhat.com>
Reviewed-by: David Howells <dhowells at redhat.com>
Signed-off-by: Paulo Alcantara <pc at manguebit.org>