78213 Commits

Author SHA1 Message Date
Bruce Ashfield
2b12a5e03f linux-yocto/6.12: update CVE exclusions (6.12.42)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 2 changes (2 new | 0 updated): - 2 new CVEs: CVE-2025-47184, CVE-2025-9300 - 0 updated CVEs:
        Date: Thu, 21 Aug 2025 13:06:23 +0000

    ]

(From OE-Core rev: 95ed346fa1e5174fb02180eaf4e1bddfeee8636e)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit eacbb65bcf73540c7ea07cc4b9513cde898368c8)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
b9c058128b linux-yocto/6.12: update to v6.12.42
Updating linux-yocto/6.12 to the latest korg -stable release that comprises
the following commits:

no ids found, dumping:
    880e4ff5d6c8 Linux 6.12.42
    5f06ee9f9a36 usb: gadget : fix use-after-free in composite_dev_cleanup()
    0ab3ae768c48 USB: gadget: f_hid: Fix memory leak in hidg_bind error path
    ba08cc6801ec HID: apple: validate feature-report field count to prevent NULL pointer dereference
    68e5579f4de1 media: ti: j721e-csi2rx: fix list_del corruption
    efee62c5fc8c perf/arm-ni: Set initial IRQ affinity
    91b370800b3f mm: swap: fix potential buffer overflow in setup_clusters()
    f7c75406b7e6 mm: swap: correctly use maxpages in swapon syscall to avoid potential deadloop
    b85fe4c7403f mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery
    1beca07bd954 MIPS: mm: tlb-r4k: Uniquify TLB entries on init
    082a639b1c67 s390/mm: Remove possible false-positive warning in pte_free_defer()
    296742ab73c2 x86/fpu: Delay instruction pointer fixup until after warning
    860d93bd6a21 platform/x86/intel/pmt: fix a crashlog NULL pointer access
    76563060ec75 ALSA: hda/realtek - Fix mute LED for HP Victus 16-d1xxx (MB 8A26)
    9fb7f010eb2e ALSA: hda/realtek - Fix mute LED for HP Victus 16-s0xxx
    0e1c67e9b8bb ALSA: hda/realtek - Fix mute LED for HP Victus 16-r1xxx
    e1c508818cba ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx()
    0f158abad0ce ALSA: intel_hdmi: Fix off-by-one error in __hdmi_lpe_audio_probe()
    aed15fc08f15 x86/sev: Evict cache lines during SNP memory validation
    c884cab3bb60 net: usbnet: Fix the wrong netif_carrier_on() call
    d68a867d7401 net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
    8c2b840c5443 Bluetooth: btusb: Add USB ID 3625:010b for TP-LINK Archer TX10UB Nano
    1331e908f2f4 PCI/ASPM: Fix L1SS saving
    78b3007eb08b PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    8d2026704a79 USB: serial: option: add Foxconn T99W709
    f54eef9be3cf smb: server: Fix extension string in ksmbd_extract_shortname()
    7e5d91d3e6c6 ksmbd: limit repeated connections from clients with the same IP
    68300f2738e0 ksmbd: fix corrupted mtime and ctime in smb2_open
    edeecc7871e8 ksmbd: fix Preauh_HashValue race condition
    2a30ed6428ce ksmbd: fix null pointer dereference error in generate_encryptionkey
    7384e0637fa8 drm/i915/ddi: only call shutdown hooks for valid encoders
    4a764acf4ab3 drm/i915/display: add intel_encoder_is_hdmi()
    428434769e45 drm/i915/ddi: gracefully handle errors from intel_ddi_init_hdmi_connector()
    743de353a434 drm/i915/hdmi: add error handling in g4x_hdmi_init()
    7edff90dc154 drm/i915/hdmi: propagate errors from intel_hdmi_init_connector()
    5913410e4962 drm/i915/ddi: change intel_ddi_init_{dp, hdmi}_connector() return type
    acd6f757f66c selftests/bpf: Fix build error with llvm 19
    01d1f298ba86 selftests/bpf: Add a test for arena range tree algorithm
    22d89925e37e ice/ptp: fix crosstimestamp reporting
    43a27836ac98 Revert "bcache: remove heap-related macros and switch to generic min_heap"
    be8a5602b05b accel/ivpu: Fix reset_engine debugfs file logic
    32950b190791 vsock: Do not allow binding to VMADDR_PORT_ANY
    f2e8fcfd2b1b net/packet: fix a race in packet_set_ring() and packet_notifier()
    15a77e9cb924 selftests/perf_events: Add a mmap() correctness test
    e529888b7e80 perf/core: Prevent VMA split of buffer mappings
    92043120a2e9 perf/core: Exit early on perf_mmap() fail
    8c67899a5295 perf/core: Don't leak AUX buffer refcount on allocation failure
    25bb3647d30a sunrpc: fix handling of server side tls alerts
    39f8e0cf1798 smb: client: return an error if rdma_connect does not return within 5 seconds
    8cb7f685af10 pptp: fix pptp_xmit() error path
    7d0f3072f999 nvmet: exit debugfs after discovery subsystem exits
    8c221b55d0c2 smb: client: let recv_done() avoid touching data_transfer after cleanup/move
    c5b3ce5cc7f6 smb: client: let recv_done() cleanup before notifying the callers.
    501eed35cac6 smb: client: make sure we call ib_dma_unmap_single() only if we called ib_dma_map_single already
    d6917b434919 smb: client: remove separate empty_packet_queue
    0d6d86b0a575 smb: server: let recv_done() avoid touching data_transfer after cleanup/move
    3d970a2f2472 smb: server: let recv_done() consistently call put_recvmsg/smb_direct_disconnect_rdma_connection
    896af4c26100 smb: server: make sure we call ib_dma_unmap_single() only if we called ib_dma_map_single already
    17d675f6390b smb: server: remove separate empty_recvmsg_queue
    b9a8a3f60b9c ALSA: hda/ca0132: Fix missing error handling in ca0132_alt_select_out()
    02541f9d5c58 irqchip: Build IMX_MU_MSI only on ARM
    04d5f4dbef26 eth: fbnic: remove the debugging trick of super high page bias
    9432bcabeeee s390/mm: Allocate page table with PAGE_SIZE granularity
    d00e4125680f net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing
    0ddfe8b127ef benet: fix BUG when creating VFs
    788c5e28cf48 x86/irq: Plug vector setup race
    c36b2fbd60e8 sunrpc: fix client side handling of tls alerts
    034d210f9d56 net/sched: taprio: enforce minimum value for picos_per_byte
    c0ec2e47f1e9 net: drop UFO packets in udp_rcv_segment()
    714b84653841 net: mdio: mdio-bcm-unimac: Correct rate fallback logic
    5489e7fc6f8b ipv6: reject malicious packets in ipv6_gso_segment()
    15c0847df624 net/mlx5: Correctly set gso_segs when LRO is used
    674328102baa spi: cs42l43: Property entry should be a null-terminated array
    e1e15033dfba ASoC: tas2781: Fix the wrong step for TLV on tas2781
    0257dc08a404 block: ensure discard_granularity is zero when discard is not supported
    3ff8fe9194a7 block: Fix default IO priority if there is no IO context
    495cb1e8ec8a netlink: specs: ethtool: fix module EEPROM input/output arguments
    7175bf8a2af5 s390/ap: Unmask SLCF bit in card and queue ap functions sysfs
    929aa980dacf nvmet: initialize discovery subsys after debugfs is initialized
    ea99b88b1999 pptp: ensure minimal skb length in pptp_xmit()
    39468480b321 net: ipa: add IPA v5.1 and v5.5 to ipa_version_string()
    e56e1842289d phy: mscc: Fix parsing of unicast frames
    75b59af723c4 netpoll: prevent hanging NAPI when netcons gets enabled
    1f3a7f53874a md/md-cluster: handle REMOVE message earlier
    b6f47385e457 NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY
    d4ebe94673b3 NFSv4.2: another fix for listxattr
    2ad40b7992aa NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
    bb96d6dbd005 NFS: Fix wakeup of __nfs_lookup_revalidate() in unblock_revalidate()
    ac9a6b863827 sched: Add test_and_clear_wake_up_bit() and atomic_dec_and_wake_up()
    531914fd74e8 pNFS/flexfiles: don't attempt pnfs on fatal DS errors
    48c6935a3498 PCI: pnv_php: Fix surprise plug detection and recovery
    d2c60a8a387e powerpc/eeh: Make EEH driver device hotplug safe
    5ea0d23aa954 powerpc/eeh: Export eeh_unfreeze_pe()
    11fa01706a4f PCI: pnv_php: Work around switches with broken presence detection
    28aa3cfce124 PCI: pnv_php: Clean up allocated IRQs on unplug
    3df959fd51d6 sched/psi: Fix psi_seq initialization
    c4a0d62bbe99 kconfig: qconf: fix ConfigList::updateListAllforAll()
    74b3fedc57d1 scsi: sd: Make sd shutdown issue START STOP UNIT appropriately
    d710ed68c54a scsi: ufs: core: Use link recovery when h8 exit fails during runtime resume
    13a501f95e22 scsi: Revert "scsi: iscsi: Fix HW conn removal use after free"
    13510a36a22f scsi: mpt3sas: Fix a fw_event memory leak
    fa1607f943f4 vfio/pci: Separate SR-IOV VF dev_set
    1df8150ab4cc vfio/pds: Fix missing detach_ioas op
    12964e77c8c1 vfio: Prevent open_count decrement to negative
    7b2db63ad836 vfio: Fix unbalanced vfio_df_close call in no-iommu mode
    89efd90ec672 i2c: muxes: mule: Fix an error handling path in mule_i2c_mux_probe()
    6038537c4a26 exfat: fdatasync flag should be same like generic_write_sync()
    82765ce5c7a5 f2fs: fix to trigger foreground gc during f2fs_map_blocks() in lfs mode
    4b069ec86c33 f2fs: fix to calculate dirty data during has_not_enough_free_secs()
    3908f15df598 f2fs: fix to update upper_p in __get_secs_required() correctly
    0fe7976b6254 f2fs: vm_unmap_ram() may be called from an invalid context
    70849d33130a f2fs: fix to avoid out-of-boundary access in devs.path
    97df495d7541 f2fs: fix to avoid panic in f2fs_evict_inode
    dea243f58a83 f2fs: fix to avoid UAF in f2fs_sync_inode_meta()
    09a8915e0fcc f2fs: doc: fix wrong quota mount option description
    ca525a64bb92 f2fs: fix to check upper boundary for gc_no_zoned_gc_percent
    1f1efc11132a f2fs: fix to check upper boundary for gc_valid_thresh_ratio
    46f24b1fbf6b f2fs: fix to check upper boundary for value of gc_boost_zoned_gc_percent
    44a79437309e f2fs: fix KMSAN uninit-value in extent_info usage
    334afc40c41c f2fs: fix bio memleak when committing super block
    8b1f1f83e377 f2fs: turn off one_time when forcibly set to foreground GC
    b0002acbec11 rtc: rv3028: fix incorrect maximum clock rate handling
    b6612b05de8e rtc: pcf8563: fix incorrect maximum clock rate handling
    b82c5074f6fc rtc: pcf85063: fix incorrect maximum clock rate handling
    e57edc34bcf7 rtc: nct3018y: fix incorrect maximum clock rate handling
    189ddb44f88c rtc: hym8563: fix incorrect maximum clock rate handling
    6ccd7f451e0e rtc: ds1307: fix incorrect maximum clock rate handling
    a721da19eac7 ucount: fix atomic_long_inc_below() argument type
    db38ade47be4 module: Restore the moduleparam prefix length check
    ff24854e8547 apparmor: Fix unaligned memory accesses in KUnit test
    277bb68f6576 apparmor: fix loop detection used in conflicting attachment resolution
    991a32f71538 apparmor: ensure WB_HISTORY_SIZE value is a power of 2
    258d42024fad bpf: Check netfilter ctx accesses are aligned
    eb2035c1adeb bpf: Check flow_dissector ctx accesses are aligned
    b2a3018e8325 vhost: Reintroduce kthread API and add mode selection
    3c8a15f2229d vdpa: Fix IDR memory leak in VDUSE module exit
    37f26b9013b4 vdpa/mlx5: Fix release of uninitialized resources on error path
    8ed657604bfd vhost-scsi: Fix log flooding with target does not exist errors
    65c9eeff9308 vdpa/mlx5: Fix needs_teardown flag calculation
    966460bace9e perf record: Cache build-ID of hit DSOs only
    0a98771d1e50 selftests: ALSA: fix memory leak in utimer test
    6f7ac9c5ad75 drm/xe/vf: Disable CSC support on VF
    81b117f4a5a3 mtd: rawnand: atmel: set pmecc data setup time
    2529fc0a1873 mtd: rawnand: rockchip: Add missing check after DMA map
    3e2d8d39a328 mtd: rawnand: atmel: Fix dma_mapping_error() address
    3406bd02dee3 jfs: fix metapage reference count leak in dbAllocCtl
    40f0a51f6c54 fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
    a434ce6643de crypto: qat - fix seq_file position update in adf_ring_next()
    71c31562d23b crypto: qat - fix DMA direction for compression on GEN2 devices
    309b23f7b5bc perf tools: Remove libtraceevent in .gitignore
    112ed94f2a45 sh: Do not use hyphen in exported variable name
    32b106dc4622 ASoC: fsl_xcvr: get channel status data when PHY is not exists
    a5f147a934ef dmaengine: nbpfaxi: Add missing check after DMA map
    2c0b57e55d89 dmaengine: mv_xor: Fix missing check after DMA map and missing unmap
    39c4454ed669 fs/orangefs: Allow 2 more characters in do_c_string()
    e3d729db128d remoteproc: xlnx: Disable unsupported features
    c1dead8bb303 clk: imx95-blk-ctl: Fix synchronous abort
    875bdd2f9bbc PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem attribute
    9cf0d1dbfa44 soundwire: stream: restore params when prepare ports fail
    a510a9869d21 crypto: qat - disable ZUC-256 capability for QAT GEN5
    bcd9cdc74974 crypto: img-hash - Fix dma_unmap_sg() nents value
    44b07ee87c4f crypto: keembay - Fix dma_unmap_sg() nents value
    f63bd615e58f hwrng: mtk - handle devm_pm_runtime_enable errors
    1a43f53b0e9e clk: at91: sam9x7: update pll clk ranges
    b2e294216bf1 ext4: Make sure BH_New bit is cleared in ->write_end handler
    0a844a32e07a watchdog: ziirave_wdt: check record length in ziirave_firm_verify()
    7aa077df2357 scsi: isci: Fix dma_unmap_sg() nents value
    ef42bea6c105 scsi: mvsas: Fix dma_unmap_sg() nents value
    ad1fbfab0dcf scsi: elx: efct: Fix dma_unmap_sg() nents value
    6a9f573ebdb6 scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value
    49a6266113f0 clk: sunxi-ng: v3s: Fix de clock definition
    ea11b0d213cc clk: thead: th1520-ap: Correctly refer the parent of osc_12m
    87be3d8ca00b RDMA/mana_ib: Fix DSCP value in modify QP
    c149e3475cac perf tests bp_account: Fix leaked file descriptor
    9ea3f6b9a67b pinmux: fix race causing mux_owner NULL with active mux_usecount
    fc1072d934f6 proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al
    ec437d015968 kernel: trace: preemptirq_delay_test: use offstack cpu mask
    5f3c0301540b RDMA/hns: Fix -Wframe-larger-than issue
    81c0bdb09cfa RDMA/hns: Drop GFP_NOWARN
    bb8899d40600 RDMA/hns: Fix accessing uninitialized resources
    1209e33fe3af RDMA/hns: Get message length of ack_req from FW
    9dea08eac4f6 crypto: ccp - Fix crash when rebind ccp device for ccp.ko
    c88a902cc5d3 crypto: inside-secure - Fix `dma_unmap_sg()` nents value
    155c1d4c4907 crypto: ccp - Fix locking on alloc failure handling
    88d4191073a5 RDMA/hns: Fix HW configurations not cleared in error flow
    dab173bae330 RDMA/hns: Fix double destruction of rsv_qp
    ffc3c00a0e83 perf sched: Fix memory leaks in 'perf sched latency'
    f7786e6a4f9c perf sched: Use RC_CHK_EQUAL() to compare pointers
    f34d54d2c276 perf sched: Fix memory leaks for evsel->priv in timehist
    31a549b3a294 perf sched: Fix memory leaks in 'perf sched map'
    4b3ab5f3639e perf sched: Free thread->priv using priv_destructor
    5c42686e56fc perf sched: Make sure it frees the usage string
    c2e061c2a5ec mtd: spi-nor: spansion: Fixup params->set_4byte_addr_mode for SEMPER
    ea90bb43be7c perf dso: Add missed dso__put to dso__load_kcore
    e9136a4afe3b perf tools: Fix use-after-free in help_unknown_cmd()
    16ab43828c48 Fix dma_unmap_sg() nents value
    40fd96ce4e60 clk: clk-axi-clkgen: fix fpfd_max frequency for zynq
    de07e1183139 fanotify: sanitize handle_type values when reporting fid
    faa05c6d5ae1 phy: qualcomm: phy-qcom-eusb2-repeater: Don't zero-out registers
    e7d11d7da5e0 dmaengine: mmp: Fix again Wvoid-pointer-to-enum-cast warning
    b2b740a884eb pinctrl: berlin: fix memory leak in berlin_pinctrl_build_state()
    230b23da10d5 pinctrl: sunxi: Fix memory leak on krealloc failure
    c63ca4d3870c PCI: endpoint: pci-epf-vntb: Return -ENOENT if pci_epc_get_next_free_bar() fails
    0e29430d700a crypto: arm/aes-neonbs - work around gcc-15 warning
    99490f243390 power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set
    f642500aa7ed power: supply: cpcap-charger: Fix null check for power_supply_get_by_name
    f1a1be99d5ae clk: xilinx: vcu: unregister pll_post only if registered correctly
    1ff541ea9e0c media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check
    7943ed1f05f5 clk: davinci: Add NULL check in davinci_lpsc_clk_register()
    a508da16feac mtd: fix possible integer overflow in erase_xfer()
    55ece6d9c370 crypto: qat - fix state restore for banks with exceptions
    a32cd73f66b7 crypto: qat - allow enabling VFs in the absence of IOMMU
    bfd78c42f0d7 crypto: marvell/cesa - Fix engine load inaccuracy
    e555e28232b3 crypto: qat - use unmanaged allocation for dc_data
    beea9197b2e9 crypto: sun8i-ce - fix nents passed to dma_unmap_sg()
    e3992ee81eba clk: renesas: rzv2h: Fix missing CLK_SET_RATE_PARENT flag for ddiv clocks
    a0acd38f75de PCI: rockchip-host: Fix "Unexpected Completion" log message
    5f176b9ea18c fortify: Fix incorrect reporting of read buffer size
    3d672fe065aa staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()
    0dbef493cae7 bpf, arm64: Fix fp initialization for exception boundary
    87b34d935109 bpf/preload: Don't select USERMODE_DRIVER
    0c58f74f8aa9 ipv6: annotate data-races around rt->fib6_nsiblings
    db65739d406c ipv6: fix possible infinite loop in fib6_info_uses_dev()
    cd8d8bbd9ced ipv6: prevent infinite loop in rt6_nlmsg_size()
    c2241478d248 vrf: Drop existing dst reference in vrf_ip6_input_dst
    f4f5a1a751aa selftests: rtnetlink.sh: remove esp4_offload after test
    77b05e7a2d66 stmmac: xsk: fix negative overflow of budget in zerocopy mode
    5d761dc79f4a net: dsa: microchip: Fix wrong rx drop MIB counter for KSZ8863
    781a0bbf3774 net/mlx5e: Remove skb secpath if xfrm state is not found
    c04bc84aa5e9 net/mlx5e: Clear Read-Only port buffer size in PBMC before update
    7c1ae471da69 netfilter: xt_nfacct: don't assume acct name is null-terminated
    bd5908c1f60d can: kvaser_usb: Assign netdev.dev_port based on device channel index
    4bee385bc330 can: kvaser_pciefd: Store device channel index
    f2880c9cf1ed can: peak_usb: fix USB FD devices potential malfunction
    176784dc75ae selftests: drv-net: Fix remote command checking in require_cmd()
    208040490a4f tools/rv: Do not skip idle in trace
    62f6175d145e bpf: Disable migration in nf_hook_run_bpf().
    cca34a0a767f Bluetooth: hci_event: Mask data status from LE ext adv reports
    16852eccbdfa Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
    f15d94491094 memcg_slabinfo: Fix use of PG_slab
    1e30043ee358 kcsan: test: Initialize dummy variable
    5763daf5ca4f ring-buffer: Remove ring_buffer_read_prepare_sync()
    24bf1d10a04a wifi: nl80211: Set num_sub_specs before looping through sub_specs
    471a7904f82f wifi: mac80211: Write cnt before copying in ieee80211_copy_rnr_beacon()
    27244ed7403c wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE
    0c5c0c898314 wifi: ath12k: fix endianness handling while accessing wmi service bit
    f0a0bc39fc52 Reapply "wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()"
    01aa86f93e70 wifi: mac80211: Check 802.11 encaps offloading in ieee80211_tx_h_select_key()
    f92ad4f8ecb9 wifi: mac80211: Don't call fq_flow_idx() for management frames
    eadf83a687fd wifi: mac80211: Do not schedule stopped TXQs
    ad1c484f1b81 wifi: plfxlc: Fix error handling in usb driver probe
    af72badd5ee4 wifi: mac80211: reject TDLS operations when station is not associated
    c200ecdd820f rcu: Fix delayed execution of hurry callbacks
    f14341cf874e iommu/amd: Fix geometry.aperture_end for V2 tables
    39dfbf77c6e4 drm/amdgpu/gfx10: fix kiq locking in KCQ reset
    6db9f958b43f drm/amdgpu/gfx9.4.3: fix kiq locking in KCQ reset
    b9f5d112e5e3 drm/amdgpu/gfx9: fix kiq locking in KCQ reset
    9c0e3144924c wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
    da4d3fd5920a mwl8k: Add missing check after DMA map
    4db9ac2246a7 wifi: rtw88: Fix macid assigned to TDLS station
    2bc4c07394cb wifi: rtl8xxxu: Fix RX skb size for aggregation disabled
    e9c3ae88e4f4 tcp: call tcp_measure_rcv_mss() for ooo packets
    81990ac1d1f0 xen/gntdev: remove struct gntdev_copy_batch from stack
    e59078852604 xen: fix UAF in dmabuf_exp_from_pages()
    19c262401e12 RDMA/mlx5: Fix UMR modifying of mkey page size
    bdb956891c9c net_sched: act_ctinfo: use atomic64_t for three counters
    795cb393e389 net/sched: Restrict conditions for adding duplicating netems to qdisc tree
    6aa95f56a6a7 iommu/amd: Enable PASID and ATS capabilities in the correct order
    67925d8b0d63 um: rtc: Avoid shadowing err in uml_rtc_start()
    fe6345dbae40 arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX
    a9ca56ca4f19 netfilter: nf_tables: adjust lockdep assertions handling
    765eeb44b1a3 netfilter: nf_tables: Drop dead code from fill_*_info routines
    69be0a3c4e5b fbcon: Fix outdated registered_fb reference in comment
    c1cbee3aae2a sched/psi: Optimize psi_group_change() cpu_clock() usage
    82f2cd70222c drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value
    08cfbe7acac0 refscale: Check that nreaders and loops multiplication doesn't overflow
    ac984f610628 m68k: Don't unregister boot console needlessly
    d89943d1e3a0 drm/msm/dpu: Fill in min_prefill_lines for SC8180X
    6434ca4429eb bpf: Ensure RCU lock is held around bpf_prog_ksym_find
    7989a6056c7e kselftest/arm64: Fix check for setting new VLs in sve-ptrace
    939135ddeae2 net: dst: annotate data-races around dst->output
    002bb5722d7e net: dst: annotate data-races around dst->input
    4249f1307932 net/mlx5: Check device memory pointer before usage
    bfb595e79319 tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range
    72a48be1f539 wifi: ath11k: clear initialized flag for deinit-ed srng lists
    7dd6350307af iwlwifi: Add missing check for alloc_ordered_workqueue
    a84858649b32 wifi: iwlwifi: Fix memory leak in iwl_mvm_init()
    7858a95566f4 wifi: rtl818x: Kill URBs before clearing tx status queue
    77a7a48f87d6 wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band
    1b8397c2d14e caif: reduce stack size, again
    3f91bec30811 powerpc/pseries/dlpar: Search DRC index from ibm,drc-indexes for IO add
    c9c7b91bc1a0 bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure
    bcdd7499bdef drm/amdgpu: Remove nbiov7.9 replay count reporting
    b56acee24e33 drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel
    94927ae3d5c1 net: ipv6: ip6mr: Fix in/out netdev to pass to the FORWARD chain
    443430e67868 selftests/bpf: Fix unintentional switch case fall through
    274bf55fcd3f selftests/bpf: fix signedness bug in redir_partial()
    ee03766d79de bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
    538b19886ca0 bpf, sockmap: Fix psock incorrectly pointing to sk
    66d64d42d297 drm/panthor: Add missing explicit padding in drm_panthor_gpu_info
    de7834d100f2 drm/panfrost: Fix panfrost device variable name in devfreq
    439b30af0ea9 drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed
    33cb946a8c73 selftests/tracing: Fix false failure of subsystem event test
    e7d59358a7e3 staging: nvec: Fix incorrect null termination of battery manufacturer
    c458492e2ab8 bus: mhi: host: pci_generic: Fix the modem name of Foxconn T99W640
    7d4f49b9141a interconnect: qcom: sc8180x: specify num_nodes
    3f693357f551 interconnect: qcom: sc8280xp: specify num_links for qnm_a1noc_cfg
    8eaeb8df9159 soc: qcom: pmic_glink: fix OF node leak
    4c80835f6af4 samples: mei: Fix building on musl libc
    c2f05fc69f4a staging: greybus: gbphy: fix up const issue with the match callback
    8e4b38710dd4 cpufreq: Init policy->rwsem before it may be possibly used
    494c213792f3 cpufreq: Initialize cpufreq-based frequency-invariance later
    667eb5aeecd2 cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive mode
    7db3a7b2e413 PM / devfreq: Fix a index typo in trans_stat
    d5632359dbc4 PM / devfreq: Check governor before using governor->name
    a7d23e71a66e arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed
    6e6c9e2d29b5 arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed
    6d5a85e3bb67 ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface
    11be9a6e3483 selftests: breakpoints: use suspend_stats to reliably check suspend success
    bed9fa51068f arm64: dts: st: fix timer used for ticks
    e2a57054e999 soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS
    bf8d808f77b9 arm: dts: ti: omap: Fixup pinheader typo
    cd865df971c6 usb: early: xhci-dbc: Fix early_ioremap leak
    8374ac7d69a5 powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw()
    3e3ebf358cda Revert "vmci: Prevent the dispatching of uninitialized payloads"
    576fc220fb6c selftests: vDSO: chacha: Correctly skip test if necessary
    6ee761012d1a pps: fix poll support
    87f8f8654e55 vmci: Prevent the dispatching of uninitialized payloads
    a3177955f8da staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc()
    a7645815edf4 spi: stm32: Check for cfg availability in stm32_spi_probe
    5786ccbd317c mei: vsc: Unset the event callback on remove and probe errors
    173a7f17103c mei: vsc: Event notifier fixes
    4a958702b7cc mei: vsc: Destroy mutex after freeing the IRQ
    ae77ebdc4822 usb: typec: ucsi: yoga-c630: fix error and remove paths
    7101b26f7e96 firmware: arm_scmi: Fix up turbo frequencies selection
    e579ab62fefd cpufreq: armada-8k: make both cpu masks static
    1de0e54aaf49 arm64: dts: ti: k3-am62p-j722s: fix pinctrl-single size
    ac0f8fca09f2 arm64: dts: ti: k3-am642-phyboard-electra: Fix PRU-ICSSG Ethernet ports
    8209fc45b04e usb: misc: apple-mfi-fastcharge: Make power supply names unique
    1d88e8e66b68 usb: host: xhci-plat: fix incorrect type for of_match variable in xhci_plat_probe()
    d9632823a400 ARM: dts: vfxxx: Correctly use two tuples for timer address
    e7e370264098 arm64: dts: qcom: msm8976: Make blsp_dma controlled-remotely
    cac895bcbcf2 arm64: dts: qcom: sa8775p: Correct the interrupt for remoteproc
    0f35f4df0590 arm64: dts: exynos: gs101: Add 'local-timer-stop' to cpuidle nodes
    72ee9c7b7c61 arm64: dts: qcom: sc7180: Expand IMEM region
    db9d963622d9 arm64: dts: qcom: sdm845: Expand IMEM region
    04e7717dddc0 soc: qcom: QMI encoding/decoding for big endian
    90040a48030e selftests: Fix errno checking in syscall_user_dispatch test
    c814023c82ae arm64: dts: freescale: imx93-tqma9352: Limit BUCK2 to 600mV
    3b13b5a4f29e ASoC: mediatek: use reserved memory or enable buffer pre-allocation
    a9d00b7f374b ASoC: ops: dynamically allocate struct snd_ctl_elem_value
    2d9ee65b6d84 ASoC: soc-dai: tidyup return value of snd_soc_xlate_tdm_slot_mask()
    cd89d86dd1d5 io_uring: fix breakage in EXPERT menu
    f5426ffbec97 gfs2: No more self recovery
    b356ee013a79 Revert "fs/ntfs3: Replace inode_trylock with inode_lock"
    5055b7db9411 hfsplus: remove mutex_lock check in hfsplus_free_extents
    b53a10073f28 hfs: make splice write available again
    248d605319fe hfsplus: make splice write available again
    0e5c17c2376b ublk: use vmalloc for ublk_device's __queues
    3ed2cc6a6e93 fs/ntfs3: cancle set bad inode after removing name fails
    47706f9acfee fs_context: fix parameter name in infofc() macro
    bb80f7618832 parse_longname(): strrchr() expects NUL-terminated string
    2f6c33b9fab0 audit,module: restore audit logging in load failure case
    6b4b30b863ee ASoC: amd: yc: add DMI quirk for ASUS M6501RM
    362ea99022c9 ASoC: Intel: fix SND_SOC_SOF dependencies
    9b25e1643cc7 ALSA: hda/cs35l56: Workaround bad dev-index on Lenovo Yoga Book 9i GenX
    bf0d05941955 ASoC: amd: yc: Add DMI entries to support HP 15-fb1xxx
    f13486ac6b5b ethernet: intel: fix building with large NR_CPUS
    60291de0c56c ASoC: amd: yc: Add DMI quirk for HP Laptop 17 cp-2033dx

(From OE-Core rev: 5199b8677f4964d6a4ec4f5c1fac3eacd3b1a489)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 940556e3d828e80af9b9cc8c56357c6bf0adfc83)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
7c1dcdd88f linux-yocto/6.12: update CVE exclusions (6.12.41)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 3 changes (2 new | 1 updated): - 2 new CVEs: CVE-2025-8707, CVE-2025-8708 - 1 updated CVEs: CVE-2025-2586
        Date: Fri, 8 Aug 2025 02:36:59 +0000

    ]

(From OE-Core rev: 3733cf3b8e020c334e4c9f46fbb0bd954a9c05f5)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 08be226ec7d26018f8ca0240a7c3a98f201b94d7)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
270669b4ec linux-yocto/6.12: update to v6.12.41
Updating linux-yocto/6.12 to the latest korg -stable release that comprises
the following commits:

no ids found, dumping:
    8f5ff9784f32 Linux 6.12.41
    c0c21293d0c2 mm: khugepaged: fix call hpage_collapse_scan_file() for anonymous vma
    c60f5156e62d KVM: x86: Free vCPUs before freeing VM state
    d8b3dfd4d36c Revert "drm/xe/forcewake: Add a helper xe_force_wake_ref_has_domain()"
    ffbedb4ad984 Revert "drm/xe/devcoredump: Update handling of xe_force_wake_get return"
    5a276d341c8e Revert "drm/xe/tests/mocs: Update xe_force_wake_get() return handling"
    c72303e7eb49 Revert "drm/xe/gt: Update handling of xe_force_wake_get return"
    69fbb3f1740b drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x
    bc9abdf6bce8 ALSA: hda: Add missing NVIDIA HDA codec IDs
    beb314a55e1e ALSA: hda/tegra: Add Tegra264 support
    c7f864d34529 Drivers: hv: Make the sysfs node size for the ring buffer dynamic
    beddf74e4064 ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS
    90d5cd64f46d iio: hid-sensor-prox: Fix incorrect OFFSET calculation
    05847477ff8a iio: hid-sensor-prox: Restore lost scale assignments
    86dca1cb4804 wifi: mt76: mt7925: adjust rm BSS flow to prevent next connection failure
    b63eb95856c0 Revert "wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba for MLO"
    98937588ff9c arm64: dts: qcom: x1-crd: Fix vreg_l2j_1p2 voltage
    3d12349ade54 x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap()
    f1b3ad11ec11 KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush
    d483bf624f22 KVM: x86: model canonical checks more precisely
    c0c82c2adc22 KVM: x86: Add X86EMUL_F_MSR and X86EMUL_F_DT_LOAD to aid canonical checks
    62dd9132a458 KVM: x86: Route non-canonical checks in emulator through emulate_ops
    94620f95f6cd KVM: x86: drop x86.h include from cpuid.h
    a4d60ba277ec ext4: fix out of bounds punch offset
    51492e99894a ext4: correct the error handle in ext4_fallocate()
    85defb9933f6 ext4: fix incorrect punch max_end
    35bd33e3ef09 ext4: move out common parts into ext4_fallocate()
    8a98313caa3a ext4: move out inode_lock into ext4_fallocate()
    1697ca500a84 ext4: factor out ext4_do_fallocate()
    2cbc4d640d40 ext4: refactor ext4_insert_range()
    8bb93d988212 ext4: refactor ext4_collapse_range()
    db1fcf7fd51c ext4: refactor ext4_zero_range()
    33f61ecabb10 ext4: refactor ext4_punch_hole()
    d9116d28538a ext4: don't explicit update times in ext4_fallocate()
    a5ae7fa30cd9 erofs: fix large fragment handling
    41485d7c637b erofs: clean up header parsing for ztailpacking and fragments
    f9b2cb6fff33 erofs: simplify tail inline pcluster handling
    516fabf34173 erofs: use Z_EROFS_LCLUSTER_TYPE_MAX to simplify switches
    9a84e212e334 erofs: refine z_erofs_get_extent_compressedlen()
    4d0f12dc8335 erofs: simplify z_erofs_load_compact_lcluster()
    1e5a88732ace arm64: dts: qcom: x1e78100-t14s: mark l12b and l15b always-on
    4a7b64ba0cca mtd: rawnand: qcom: Fix last codeword read in qcom_param_page_type_exec()
    a1bc9a394a27 crypto: powerpc/poly1305 - add depends on BROKEN for now
    b49b543f4e0b comedi: comedi_test: Fix possible deletion of uninitialized timers
    28419a4f3a1e jfs: reject on-disk inodes of an unsupported type
    3ad50c7c66cc x86/bugs: Fix use of possibly uninit value in amd_check_tsa_microcode()
    b85815675fc5 spi: cadence-quadspi: fix cleanup of rx_chan on failure paths
    a7c6de9f8467 usb: typec: tcpm: apply vbus before data bringup in tcpm_src_attach
    27e423886a7a usb: typec: tcpm: allow switching to mode accessory to mux properly
    a9a1eb410f35 usb: typec: tcpm: allow to use sink in accessory mode
    77a4a907cc53 selftests/bpf: Add tests with stack ptr register in conditional jmp
    bafb375c4606 rust: give Clippy the minimum supported Rust version
    4c8f15e770fb mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n
    656eaddbc952 mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list
    140edd5adf6d selftests: mptcp: connect: also cover checksum
    219c4eb6c3f0 selftests: mptcp: connect: also cover alt modes
    1bff28ea4b11 resource: fix false warning in __request_region()
    79663a15a1c7 nilfs2: reject invalid file types when reading inodes
    27e740614df8 kasan: use vmalloc_dump_obj() for vmalloc error reports
    0fde7dccbf4c ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
    44af78621c09 gve: Fix stuck TX queue for DQ queue format
    50c61f55b6b9 e1000e: ignore uninitialized checksum word on tgp
    78328fad6c49 e1000e: disregard NVM checksum on tgp when valid checksum bit is not set
    a3bba0205830 dpaa2-switch: Fix device reference count leak in MAC endpoint handling
    4dd56cabfbe5 dpaa2-eth: Fix device reference count leak in MAC endpoint handling
    708fd522b86d arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack()
    060a28e39053 ALSA: hda/realtek - Add mute LED support for HP Victus 15-fa0xxx
    d3f60054b6a0 ALSA: hda/realtek - Add mute LED support for HP Pavilion 15-eg0xxx
    ba8e8a8a2e19 sprintf.h requires stdarg.h
    cf8e62f6e1b2 bus: fsl-mc: Fix potential double device reference in fsl_mc_get_endpoint()
    5b8d6cb9a03d i2c: virtio: Avoid hang by using interruptible completion wait
    5622108c3041 i2c: tegra: Fix reset error handling with ACPI
    42c4471b30fa i2c: qup: jump out of the loop in case of timeout
    9ea8a9ebbea8 timekeeping: Zero initialize system_counterval when querying time from phc drivers
    6ed79cf1183a ARM: 9450/1: Fix allowing linker DCE with binutils < 2.36
    f7ff03247600 mm/ksm: fix -Wsometimes-uninitialized from clang-21 in advisor_mode_show()
    f5ee8a39f03e drm/sched: Remove optimization that causes hang when killing dependent jobs
    198604687f19 drm/amdgpu: Reset the clear flag in buddy during resume
    d2a6a3543fd2 platform/x86: ideapad-laptop: Fix kbd backlight not remembered among boots
    616ca3c4d11e platform/x86: ideapad-laptop: Fix FnLock not remembered among boots
    4de81eb46284 net: hns3: default enable tx bounce buffer when smmu enabled
    68494b2ca295 net: hns3: fixed vf get max channels bug
    952cd60f695b net: hns3: disable interrupt when ptp init failed
    7676d652801c net: hns3: fix concurrent setting vlan filter issue
    1194ad0d44d6 s390/ism: fix concurrency management in ism_cmd()
    de5aaea0384c selftests: drv-net: wait for iperf client to stop sending
    61baf2a43d45 ALSA: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop
    5c25b4f2769e drm/bridge: ti-sn65dsi86: Remove extra semicolon in ti_sn_bridge_probe()
    0ca816a96fdc can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode
    11a2eadf0bd2 net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class
    5f02ea0f63dd net: appletalk: Fix use-after-free in AARP proxy probe
    18617f4063e5 i40e: When removing VF MAC filters, only check PF-set MAC
    dc08e1772566 i40e: report VF tx_dropped with tx_errors instead of tx_discards
    ebd24581e055 net/mlx5: E-Switch, Fix peer miss rules to use peer eswitch
    6b1f7194d02c net/mlx5: Fix memory leak in cmd_exec()
    07759e28a3b5 net: ti: icssg-prueth: Fix buffer allocation for ICSSG
    1dc0ed16cfbc ASoC: mediatek: mt8365-dai-i2s: pass correct size to mt8365_dai_set_priv
    5918c3f4800a xfrm: interface: fix use-after-free after changing collect_md xfrm interface
    07ab45902446 xfrm: Set transport header to fix UDP GRO handling
    085f24f0be55 xfrm: state: use a consistent pcpu_id in xfrm_state_find
    6bf2daafc51b xfrm: state: initialize state_ptrs earlier in xfrm_state_find
    80d66be8a04f staging: vchiq_arm: Make vchiq_shutdown never fail
    0fb8478fb0ea platform/x86: Fix initialization order for firmware_attributes_class
    9128b2dbe510 x86/hyperv: Fix usage of cpu_online_mask to get valid cpu
    ef3bee8d1da1 tools/hv: fcopy: Fix incorrect file path conversion
    8a1fbb642b74 platform/mellanox: mlxbf-pmc: Use kstrtobool() to check 0/1 input
    d38e1e0a64a9 platform/mellanox: mlxbf-pmc: Validate event/enable input
    f0580af3d3ec platform/mellanox: mlxbf-pmc: Remove newline char from event name input
    1b102d2cc4bc regmap: fix potential memory leak of regmap_bus
    be4f30f7c178 iio: adc: ad7949: use spi_is_bpw_supported()
    5aa9a2d57899 interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1 node
    3fd782ceabea RDMA/core: Rate limit GID cache warning messages
    96876f6e859e platform/x86: asus-nb-wmi: add DMI quirk for ASUS Zenbook Duo UX8406CA
    5d4261dbb333 regulator: core: fix NULL dereference on unbind due to stale coupling data
    bf812206f2d0 virtio_ring: Fix error reporting in virtqueue_resize
    30ce52f1616e virtio_net: Enforce minimum TX ring size for reliability
    a7b79db25846 Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT
    2bf554c820f1 x86/traps: Initialize DR7 by writing its architectural reset value

(From OE-Core rev: 8f1e1b571dac3bf16147b3e2283d22cae4ab9431)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 97e62663b3f94fbe6429ce6f40a84974aac81471)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
bc47b236c4 linux-yocto/6.12: update CVE exclusions (6.12.40)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 4 changes (1 new | 3 updated): - 1 new CVEs: CVE-2025-8126 - 3 updated CVEs: CVE-2025-31952, CVE-2025-31953, CVE-2025-31955
        Date: Fri, 25 Jul 2025 02:18:30 +0000

    ]

(From OE-Core rev: 3dfad0c48a5b60bc9dd7c96c07ed914b020c463e)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit e504bd7a9e908be0937d6fc9f6b9699b0acdc2aa)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
487e8c7de1 linux-yocto/6.12: update to v6.12.40
Updating linux-yocto/6.12 to the latest korg -stable release that comprises
the following commits:

    d90ecb2b1308 Linux 6.12.40
    fd627ac8a5cf KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls
    ff7ccaadb0bf iommu/vt-d: Fix misplaced domain_attached assignment
    e82d8825f712 smb: client: let smbd_post_send_iter() respect the peers max_send_size and transmit all data
    11f430b8f5fc drm/xe: Move page fault init after topology init
    ce7585324b20 drm/xe/mocs: Initialize MOCS index early
    8fc25d3055ba sched,freezer: Remove unnecessary warning in __thaw_task
    7258b437d55d i2c: omap: fix deprecated of_property_read_bool() use
    f701716812cb i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe()
    ba35cc0598f3 i2c: omap: Fix an error handling path in omap_i2c_probe()
    c1a786faa6ec i2c: omap: Add support for setting mux
    35fdf1093109 selftests/bpf: Set test path for token/obj_priv_implicit_token_envvar
    d9ebd928288b rust: use `#[used(compiler)]` to fix build and `modpost` with Rust >= 1.89.0
    affb46db59f9 net: libwx: fix multicast packets received count
    75747e25beca usb: dwc3: qcom: Don't leave BCR asserted
    c45b48b4f4c0 usb: hub: Don't try to recover devices lost during warm reset.
    bf71baa3cfe7 usb: hub: Fix flushing of delayed work used for post resume purposes
    e11359640090 usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm
    aec11e5f9c45 usb: hub: fix detection of high tier USB3 devices behind suspended hubs
    ee56da95f896 btrfs: fix block group refcount race in btrfs_create_pending_block_groups()
    e77078e52fbf clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
    7fc808d98215 sched: Change nr_uninterruptible type to unsigned long
    816d36973467 efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths
    44e73241b8be libbpf: Fix handling of BPF arena relocations
    f0de9702f9b2 drm/mediatek: only announce AFBC if really supported
    40b5b4ba8ed8 drm/mediatek: Add wait_event_timeout when disabling plane
    b04fb2628b28 Revert "cgroup_freezer: cgroup_freezing: Check if not frozen"
    d7c1098787a6 rxrpc: Fix transmission of an abort in response to an abort
    839fe96c1520 rxrpc: Fix recv-recv race of completed call
    e5c480dc62a3 net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree
    71f435f846b0 net: bridge: Do not offload IGMP/MLD messages
    8984bcbd1edf net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime
    cdb767915fc9 tls: always refresh the queue when reading sock
    4e7c46362550 virtio-net: fix recursived rtnl_lock() during probe()
    1a71bf5c91ab hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open to prevent IPv6 addrconf
    5db93cbd7d50 Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
    1259b780e7b9 drm/xe/pf: Prepare to stop SR-IOV support prior GT reset
    be77ce6b3a6b drm/xe/pf: Move VFs reprovisioning to worker
    abe59c53b626 drm/xe/pf: Sanitize VF scratch registers on FLR
    fc38c249c622 netfilter: nf_conntrack: fix crash due to removal of uninitialised entry
    7c532f222361 net: fix segmentation after TCP/UDP fraglist GRO
    7929d27c747e ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
    35b501a2393a net/mlx5: Correctly set gso_size when LRO is used
    f47400547a95 Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855 GF variant without board ID
    f5a40e54cd6c Bluetooth: hci_core: add missing braces when using macro parameters
    db386fc5fa65 Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
    6c586fcb880a Bluetooth: SMP: If an unallowed command is received consider it a failure
    05ab8da312ec Bluetooth: hci_sync: fix connectable extended advertising when using static random address
    b97be7ee8a1c Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
    95a13b0a6b04 riscv: traps_misaligned: properly sign extend value in misaligned load handler
    32b14e757404 riscv: Enable interrupt during exception handling
    efad4e2a0fa7 loop: use kiocb helpers to fix lockdep warning
    65c666aff44e usb: net: sierra: check for no status endpoint
    cd469b173d14 ice: check correct pointer in fwlog debugfs
    5a5d64f0eec8 ice: add NULL check in eswitch lag check
    3c4bdc8a852e hwmon: (corsair-cpro) Validate the size of the received input buffer
    dcf0f03d7f74 selftests: net: increase inter-packet timeout in udpgro.sh
    33711db90bd5 can: tcan4x5x: fix reset gpio usage during probe
    d587e6929b7c can: tcan4x5x: add option for selecting nWKRQ voltage
    d57dda2056fa wifi: cfg80211: remove scan request n_channels counted_by
    6a466ac72fd4 nvmet-tcp: fix callback lock for TLS handshake
    f9a90478207a nvme: fix misaccounting of nvme-mpath inflight I/O
    fd6493533af9 net: phy: Don't register LEDs for genphy
    5b02e397929e smc: Fix various oops due to inet_sock type confusion.
    124765c20603 nvme: fix endianness of command word prints in nvme_log_err_passthru()
    8184ee3c667d nvme: fix inconsistent RCU list manipulation in nvme_ns_add_to_ctrl_list()
    9a7de97b915a fix a leak in fcntl_dirnotify()
    09bce2138a30 smb: client: fix use-after-free in cifs_oplock_break
    06ec83b6c792 rpl: Fix use-after-free in rpl_do_srh_inline().
    a6d735100f60 net/sched: sch_qfq: Fix race condition on qfq_aggregate
    e8767b89cd82 block: fix kobject leak in blk_unregister_queue
    20648ff4a203 net: emaclite: Fix missing pointer increment in aligned_read()
    894780d6dd3e cachefiles: Fix the incorrect return value in __cachefiles_write()
    dc05051dd10d selftests/sched_ext: Fix exit selftest hang on UP
    6952aeace93f bpf: Reject %p% format string in bprintf-like helpers
    e80692789679 arm64: dts: imx95: Correct the DMA interrupter number of pcie0_ep
    6353bf36f56b soundwire: amd: fix for clearing command status register
    a6e232ee0f86 soundwire: amd: fix for handling slave alerts after link is down
    8814cbbddcaf arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B
    6cb38e5d359a arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5
    c42116dc70af comedi: Fix initialization of data for instructions that write to subdevice
    2af1e7d389c2 comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
    8c20a5cb9879 comedi: Fix some signed shift left operations
    992d600f284e comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
    3eab654f5d19 comedi: das6402: Fix bit shift out of bounds
    076b13ee60eb comedi: das16m1: Fix bit shift out of bounds
    e0f3c0867d7d comedi: aio_iiro_16: Fix bit shift out of bounds
    a27e27eee313 comedi: pcl812: Fix bit shift out of bounds
    610615c96680 iio: common: st_sensors: Fix use of uninitialize device structs
    6eea9f7648dd iio: backend: fix out-of-bound write
    404b1d0fe0c6 iio: adc: stm32-adc: Fix race in installing chained IRQ handler
    07c9a0617d9a iio: adc: max1363: Reorder mode_list[] entries
    0ceb2893d360 iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
    086a76474121 iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps
    bfcda3e10157 iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush
    b361598b7352 soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled
    855d4da5f270 soc: aspeed: lpc-snoop: Cleanup resources in stack-order
    2a76bc2b24ed smb: client: fix use-after-free in crypt_message when using async crypto
    d5629d1af060 s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again
    11c19d42d3a7 pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov
    10e27b2a6ebe net: libwx: properly reset Rx ring descriptor
    ba7c793f96c1 net: libwx: fix the using of Rx buffer DMA
    08d18bda0d03 net: libwx: remove duplicate page_pool_put_full_page()
    74cb0f102d4b net: stmmac: intel: populate entire system_counterval_t in get_time_fn() callback
    516cd0943a22 mmc: sdhci_am654: Workaround for Errata i2312
    5280e0b8bc69 mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models
    6198bfe1af77 mmc: bcm2835: Fix dma_unmap_sg() nents value
    a25ebc337022 memstick: core: Zero initialize id_reg in h_memstick_read_dev_id()
    2594d5ffc081 isofs: Verify inode mode when loading from disk
    122160289adf dmaengine: nbpfaxi: Fix memory corruption in probe()
    573f1e59024c cpuidle: psci: Fix cpuhotplug routine with PREEMPT_RT=y
    9e11e0db4e27 Bluetooth: btintel: Check if controller is ISO capable on btintel_classify_pkt_type
    1ddedbd8087d af_packet: fix soft lockup issue caused by tpacket_snd()
    fa0796cd62c2 af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd()
    0e9c4b36ad0c arm64: dts: rockchip: use cs-gpios for spi1 on ringneck
    b0c7f2984356 arm64: dts: imx8mp-venice-gw73xx: fix TPM SPI frequency
    9650e49db619 arm64: dts: imx8mp-venice-gw72xx: fix TPM SPI frequency
    a3964e87cf15 arm64: dts: imx8mp-venice-gw71xx: fix TPM SPI frequency
    1a54317f3868 arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on
    a86ea423dc13 arm64: dts: add big-endian property back into watchdog node
    c70000779432 arm64: dts: imx8mp-venice-gw74xx: fix TPM SPI frequency
    5419adaef571 net/mlx5: Update the list of the PCI supported devices
    837a9631f180 phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept()
    938126995e64 mptcp: reset fallback status gracefully at disconnect() time
    f81b6fbe13c7 mptcp: plug races between subflow fail and subflow creation
    54999dea879f mptcp: make fallback action and fallback decision atomic
    f28044a60506 io_uring/poll: fix POLLERR handling
    134ec1ed468f ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS
    61e867574444 ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx
    084eb54b820f drm/amd/display: Free memory allocation
    74162dda80e7 drm/amd/display: Disable CRTC degamma LUT for DCN401
    62f2a58a4cb0 drm/amdgpu: Increase reset counter only on success
    228ad2ab5b33 drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume
    21e649b0bd1a objtool/rust: add one more `noreturn` Rust function for Rust 1.89.0
    7bb9ea515cda tracing/osnoise: Fix crash in timerlat_dump_stack()
    33e20747b47d tracing: Add down_write(trace_event_sem) when adding trace event
    692cfff241f1 tracing/probes: Avoid using params uninitialized in parse_btf_arg()
    d18f63e84884 HID: core: do not bypass hid_hw_raw_request
    953af3c0814a HID: core: ensure __hid_request reserves the report ID as the first byte
    a262370f385e HID: core: ensure the allocated report buffer can contain the reserved report ID
    68860d1ade38 dm-bufio: fix sched in atomic context
    0758f7ef402b spi: Add check for 8-bit transfer with 8 IO mode support
    40f79e2bf6a4 pch_uart: Fix dma_sync_sg_for_device() nents value
    9ecfed987bc8 Input: xpad - set correct controller type for Acer NGR200
    c29a2328af96 nvmem: layouts: u-boot-env: remove crc32 endianness conversion
    c85295f624db nvmem: imx-ocotp: fix MAC address byte length
    ff628593ba7c Revert "staging: vchiq_arm: Create keep-alive thread during probe"
    970635ed63da thunderbolt: Fix bit masking in tb_dp_port_set_hops()
    17a6ea23890e thunderbolt: Fix wake on connect at runtime
    1a1190b4ba7b i2c: stm32f7: unmap DMA mapped buffer
    79b63523bfdc i2c: stm32: fix the device used for the DMA map
    783ea37b237a usb: gadget: configfs: Fix OOB read on empty string write
    032f22962bfc usb: dwc2: gadget: Fix enter to hibernation for UTMI+ PHY
    231bf7e839a8 usb: musb: fix gadget state on disconnect
    951dd99ac05a USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
    8b8cb0c34c66 USB: serial: option: add Foxconn T99W640
    ba1d8dc87ae7 USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition
    248ba00d13ff phy: tegra: xusb: Disable periodic tracking on Tegra234
    2f2a375304b0 phy: tegra: xusb: Decouple CYA_TRK_CODE_UPDATE_ON_IDLE from trk_hw_mode
    ec7f98ff05f0 phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode

(From OE-Core rev: 842e271dcfaa2abaa5e2bd4fd474efd8bd0d204a)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a4a28bbc46597c95f76972d68b39591da77b1b59)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
22b561673c linux-yocto/6.12: update CVE exclusions (6.12.39)
Data pulled from: https://github.com/CVEProject/cvelistV5

    1/1 [
        Author: cvelistV5 Github Action
        Email: github_action@example.com
        Subject: 4 changes (1 new | 3 updated): - 1 new CVEs: CVE-2025-46002 - 3 updated CVEs: CVE-2025-5752, CVE-2025-6717, CVE-2025-7397
        Date: Fri, 18 Jul 2025 14:11:28 +0000

    ]

(From OE-Core rev: 6cc4b2e6ded0a717a060a9101baf9b8bdf6dc3e0)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit a58b2c6f20ad6257036e144bee2eec1375e1a799)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Bruce Ashfield
6694328818 linux-yocto/6.12: update to v6.12.39
Updating linux-yocto/6.12 to the latest korg -stable release that comprises
the following commits:

    cdf264c0a590 Linux 6.12.39
    f3f9deccfc68 KVM: SVM: Set synthesized TSA CPUID flags
    f004f58d18a2 rseq: Fix segfault on registration when rseq_cs is non-zero
    f2133b849ff2 crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP()
    59923d508bd2 arm64: Filter out SME hwcaps when FEAT_SME isn't implemented
    815f1161d6db ksmbd: fix potential use-after-free in oplock/lease break ack
    2d89dab1ea60 kasan: remove kasan_find_vm_area() to prevent possible deadlock
    e1aec954583f net: wangxun: revert the adjustment of the IRQ vector sequence
    5244536e650c erofs: fix rare pcluster memory leak after unmounting
    5ea53aa71c2c selftests/bpf: adapt one more case in test_lru_map to the new target_free
    7b4a02631352 HID: nintendo: avoid bluetooth suspend/resume stalls
    c72536350e82 HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
    716a0c8dedc6 HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY
    70685fb6216f riscv: vdso: Exclude .rodata from the PT_DYNAMIC segment
    9ef5d4748dfe bpf: Adjust free target to avoid global starvation of LRU map
    c23e0792b77d vt: add missing notification when switching back to text mode
    0bcc14f36c7a btrfs: fix assertion when building free space tree
    589b290d0935 net: mana: Record doorbell physical address in PF mode
    921fffa1d8bc HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard Gen2
    e46cf2943f91 driver: bluetooth: hci_qca:fix unable to load the BT driver
    a9c357b08672 net: usb: qmi_wwan: add SIMCom 8230C composition
    e55b2126961b ALSA: hda/realtek: Add quirks for some Clevo laptops
    01b0312a4a3a ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop 15-eg100
    72aad5cf5790 ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic
    383b2399d586 io_uring: make fallocate be hashed work
    67be7e6c55a9 ALSA: hda/realtek: Add mic-mute LED setup for ASUS UM5606
    68397fda2caa ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak.
    dd072fa64715 um: vector: Reduce stack usage in vector_eth_configure()
    7df2295c036b atm: idt77252: Add missing `dma_map_error()`
    25cab1b83d66 ublk: sanity check add_dev input for underflow
    f154e41e1d9d bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT
    b4e7e3f4e9d2 bnxt_en: Fix DCB ETS validation
    948ab36ed249 net: ll_temac: Fix missing tx_pending check in ethtools_set_ringparam()
    bbd385b65f9e net/mlx5e: Add new prio for promiscuous mode
    7581afc05154 net/mlx5e: Fix race between DIM disable and net_dim()
    c4270235db92 can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level
    90d0d5a439f5 drm/xe/pm: Correct comment of xe_pm_set_vram_threshold()
    ec4014566377 selftests: net: lib: fix shift count out of range
    182c9f38c367 selftests: net: lib: Move logging from forwarding/lib.sh here
    e3647c40bea2 net: phy: microchip: limit 100M workaround to link-down events on LAN88xx
    b215e916336f net: phy: microchip: Use genphy_soft_reset() to purge stale LPA bits
    4c934e0cac61 ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic sizeof
    473f3eadfc73 net: appletalk: Fix device refcount leak in atrtr_create()
    e0dd2e972966 netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto()
    fd67f52eea80 erofs: fix to add missing tracepoint in erofs_readahead()
    ea2350dfa378 erofs: refine readahead tracepoint
    9493b5f9ad07 erofs: tidy up zdata.c
    71e4f033a90d erofs: get rid of `z_erofs_next_pcluster_t`
    16396885c26a erofs: free pclusters if no cached folio is attached
    ff4b8c9ade1b drm/xe/pf: Clear all LMTT pages on alloc
    8586552df591 nbd: fix uaf in nbd_genl_connect() error path
    1bbdf4213711 wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init()
    fa7e9a15460a drm/nouveau/gsp: fix potential leak of memory used during acpi init
    06c566371f8a wifi: rt2x00: fix remove callback type mismatch
    d21eeb050599 wifi: mac80211: fix non-transmitted BSSID profile search
    d4a7056ca9ab wifi: mac80211: correctly identify S1G short beacon
    2941155d9a5a raid10: cleanup memleak at raid10_make_request
    776e6186dc9e md/raid1: Fix stack memory use after return in raid1_reshape
    a560de522374 drm/tegra: nvdec: Fix dma_alloc_coherent error check
    fcd9c923b58e wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()
    c6625c21ea66 wifi: cfg80211: fix S1G beacon head validation in nl80211
    8d4d00ea6038 netfs: Fix ref leak on inserted extra subreq in write retry
    42baf997722c netlink: make sure we allow at least one dump skb
    f98c4cec7504 netlink: Fix rmem check in netlink_broadcast_deliver().
    cecc9146d244 ASoC: Intel: sof-function-topology-lib: Print out the unsupported dmic count
    19ff875dc516 erofs: address D-cache aliasing
    4745bfd34ae7 erofs: fix to add missing tracepoint in erofs_read_folio()
    3b16c9b8ba71 ksmbd: fix a mount write count leak in ksmbd_vfs_kern_path_locked()
    92c2c005a8ba smb: server: make use of rdma_destroy_qp()
    1d219778281e clk: scmi: Handle case where child clocks are initialized before their parents
    971da696abf0 x86/mm: Disable hugetlb page table sharing on 32-bit
    a68b85855732 x86/rdrand: Disable RDSEED on AMD Cyan Skillfish
    fcee75daecc5 clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data
    5d2d34f36724 rust: init: allow `dead_code` warnings for Rust >= 1.89.0
    febc0b5dbabd lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users()
    4c39dfd13beb mm/vmalloc: leave lazy MMU mode on PTE mapping error
    92ed107cd26d scripts/gdb: fix interrupts.py after maple tree conversion
    62720dc3cfd9 scripts/gdb: de-reference per-CPU MCE interrupts
    cb89f9bf6c3a scripts/gdb: fix interrupts display after MCP on x86
    ee6c677ef318 mm: fix the inaccurate memory statistics issue for users
    839d8682732e maple_tree: fix mt_destroy_walk() on root leaf node
    92db42e201f4 kallsyms: fix build without execinfo
    7dccd5eb5343 Revert "PCI/ACPI: Fix allocated memory release on error in pci_acpi_scan_root()"
    e4172522d594 Revert "ACPI: battery: negate current when discharging"
    ee6f6138d5f2 drm/xe: Allocate PF queue size on pow2 boundary
    065bd940ee0a drm/framebuffer: Acquire internal references on GEM handles
    9e4af87bd08d Revert "usb: gadget: u_serial: Add null pointer check in gs_start_io"
    abf3620cba68 usb: gadget: u_serial: Fix race condition in TTY wakeup
    48007d6e7bdb Revert "drm/xe/xe2: Enable Indirect Ring State support for Xe2"
    57b7c27ef5e7 drm/xe/bmg: fix compressed VRAM handling
    2d2f07a99487 drm/gem: Fix race in drm_gem_handle_create_tail()
    38df1a5053bc drm/ttm: fix error handling in ttm_buffer_object_transfer
    e2d6547dc8b9 drm/sched: Increment job count before swapping tail spsc queue
    08480e285c6a drm/gem: Acquire references on GEM handles for framebuffers
    e90ee15ce28c drm/amdkfd: Don't call mmput from MMU notifier callback
    9f852d301f64 drm/imagination: Fix kernel crash when hard resetting the GPU
    a7b2f250ffcd wifi: mt76: mt7925: fix invalid array index in ssid assignment during hw scan
    fad0f6fcdae0 wifi: mt76: mt7925: fix the wrong config for tx interrupt
    9b50874f297f wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_sta_set_decap_offload()
    9639e54025f1 wifi: mt76: mt7921: prevent decap offload config before STA initialization
    a963819a121f wifi: mwifiex: discard erroneous disassoc frames on STA interface
    e01851f6e9a6 wifi: prevent A-MSDU attacks in mesh networks
    373caeec3651 pwm: mediatek: Ensure to disable clocks in error path
    d526e11ab274 pwm: Fix invalid state detection
    275605a8b480 pinctrl: qcom: msm: mark certain pins as invalid for interrupts
    3e0542701b37 md/md-bitmap: fix GPF in bitmap_get_stats()
    9f260e16b297 net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe()
    8f65277317a8 gre: Fix IPv6 multicast route creation.
    199af064babb ASoC: fsl_sai: Force a software reset when starting in consumer mode
    e14bffc90866 ALSA: ad1816a: Fix potential NULL pointer deref in snd_card_ad1816a_pnp()
    d9bd1163c8d8 KVM: Allow CPU to reschedule while setting per-page memory attributes
    fd044c99d831 KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight
    5cb498b20bff KVM: SVM: Add missing member in SNP_LAUNCH_START command structure
    55f568521e0b KVM: x86/xen: Allow 'out of range' event channel ports in IRQ routing table.
    291eff10b197 x86/mce: Make sure CMCI banks are cleared during shutdown on Intel
    8ed7f3de93e1 x86/mce: Ensure user polling settings are honored when restarting timer
    55ea884c0dce x86/mce: Don't remove sysfs if thresholding sysfs init fails
    afcf4f4e7062 x86/mce/amd: Fix threshold limit reset
    e01d5e33645d x86/mce/amd: Add default names for MCA banks and blocks
    9e0d33e75c16 ipmi:msghandler: Fix potential memory corruption in ipmi_create_user()
    d1ff5f9d2c54 rxrpc: Fix oops due to non-existence of prealloc backlog struct
    5385ad53793d rxrpc: Fix bug due to prealloc collision
    8ecd651ef24a net/sched: Abort __tc_modify_qdisc if parent class does not exist
    fc2fffa2faca net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info
    34a09d6240a2 atm: clip: Fix NULL pointer dereference in vcc_sendmsg()
    024876b247a8 atm: clip: Fix infinite recursive call of clip_push().
    9f771816f14d atm: clip: Fix memory leak of struct clip_vcc.
    36caab990b69 atm: clip: Fix potential null-ptr-deref in to_atmarpd().
    4d5476fa3931 net: phy: smsc: Fix link failure in forced mode with Auto-MDIX
    6fb4cd247cda net: phy: smsc: Force predictable MDI-X state on LAN87xx
    850812bd2a15 net: phy: smsc: Fix Auto-MDIX configuration when disabled by strap
    be8792c6702b net: stmmac: Fix interrupt handling for level-triggered mode in DWC_XGMAC2
    41a741c476e1 vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also `transport_local`
    ae2c712ba39c vsock: Fix transport_* TOCTOU
    3734d78210cc vsock: Fix transport_{g2h,h2g} TOCTOU
    62e6160cfb55 tcp: Correct signedness in skb remaining space calculation
    50aa2d121bc2 tipc: Fix use-after-free in tipc_conn_close().
    8fb2802a1654 vsock: fix `vsock_proto` declaration
    4b8e18af7bea netlink: Fix wraparounds of sk->sk_rmem_alloc.
    b90129445f50 net: phy: qcom: qca808x: Fix WoL issue by utilizing at8031_set_wol()
    31db4223db33 net: phy: qcom: move the WoL function to shared library
    778f4e173020 arm64: poe: Handle spurious Overlay faults
    2e0cb0c74d96 bnxt_en: eliminate the compile warning in bnxt_request_irq due to CONFIG_RFS_ACCEL
    0caba66f0073 sched/deadline: Fix dl_server runtime calculation formula
    35bda158da39 fix proc_sys_compare() handling of in-lookup dentries
    df1d6801f16a pinctrl: amd: Clear GPIO debounce for suspend
    cdbcde935e72 Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as connected
    32fa1f92a40e Bluetooth: hci_sync: Fix not disabling advertising instance
    0cd863ab4204 ASoC: cs35l56: probe() should fail if the device ID is not recognized
    a0a8009083e5 perf: Revert to requiring CAP_SYS_ADMIN for uprobes
    f7fe33f629bb sched/core: Fix migrate_swap() vs. hotplug
    1207f57be07f irqchip/irq-msi-lib: Select CONFIG_GENERIC_MSI_IRQ
    bc179aa79a20 perf/core: Fix the WARN_ON_ONCE is out of lock protected region
    8f4c7131721a ASoC: Intel: soc-acpi: arl: Correct order of cs42l43 matches
    cca47e6e1f78 ASoC: Intel: soc-acpi-intel-arl-match: set get_function_tplg_files ops
    fc3a8a5e8f8e ASoC: Intel: add sof_sdw_get_tplg_files ops
    36536435849b ASoC: soc-acpi: add get_function_tplg_files ops
    06e0b070eb97 ASoC: Intel: soc-acpi: arl: Add match entries for new cs42l43 laptops
    97d14c04610c ASoC: Intel: soc-acpi: arl: Correct naming of a cs35l56 address struct
    724b93a6a694 ASoC: Intel: SND_SOC_INTEL_SOF_BOARD_HELPERS select SND_SOC_ACPI_INTEL_MATCH
    d4f6a267cc07 ASoC: fsl_asrc: use internal measured ratio for non-ideal ratio mode
    07ed75bfa7ed drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to avoid Priority Inversion in SRIOV
    56ea7746045a crypto: s390/sha - Fix uninitialized variable in SHA-1 and SHA-2
    04513cf1581b drm/amdgpu/ip_discovery: add missing ip_discovery fw
    39d6a607d531 drm/amdgpu/discovery: use specific ip_discovery.bin for legacy asics
    e9d9b25f3767 drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
    6dee745bd0ae eventpoll: don't decrement ep refcount while still holding the ep mutex

(From OE-Core rev: 7e6c84ab74dd8adf162ab998380829ee2319f749)

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 25fd1e5999398cc81201379b51d676356e4d102b)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-22 12:21:23 -07:00
Lee Chee Yang
7e03dda118 migration-guides: add release notes for 5.0.12
(From yocto-docs rev: 29330751c8a2b82b4bd80659d2a0a8bac51afca5)

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit e77139b5c616e6e5ad436eb91416fd804389425f)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Lee Chee Yang
c9578ff805 migration-guides: add release notes for 5.2.3
(From yocto-docs rev: 46b642658ce3fcf9402a1330c308e42f988ddd7e)

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 3a73f28b3fffaa7abbb68dd164fa8615efbfece5)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Joao Marcos Costa
8b9ff99208 ref-manual/variables.rst: expand IMAGE_OVERHEAD_FACTOR glossary entry
There's a (second) overhead factor applied in images generated with Wic,
and this is already documented in the .wks reference. However, the
IMAGE_OVERHEAD_FACTOR entry does not mention it, and by looking at the
partition sizes (e.g. with parted) one may find it confusing that they
don't match with the expected rootfs size (e.g. in a scenario where the
extra space is "0" and IMAGE_OVERHEAD_FACTOR="1.0").

This second overhead is already documented, though:
https://docs.yoctoproject.org/ref-manual/kickstart.html#command-part-or-partition

Mention the '--overhead-factor' option in the glossary entry and add a
reference to the wks documentation.

(From yocto-docs rev: 987929b349a927d6b243d351aebebfd160d1b097)

Signed-off-by: Joao Marcos Costa <joaomarcos.costa@bootlin.com>
Reviewed-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit b9040e20b015e9b02683ec3014e4ade5eb59d41a)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Antonin Godard
26c602f913 dev-manual/security-subjects.rst: update mailing lists
Update mailing lists following changes by Michael Halstead
(https://lists.yoctoproject.org/g/yocto-security/message/1478).

Also fix formatting/spacing.

(From yocto-docs rev: cad5770b123a2e763b4026e4c6a5991286ba7fa0)

Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 8066aa92a1acae6c99fbee92d24ee1feea65d974)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Jan Vermaete
627f697dac sdk: The main in the C example should return an int
see C17 (ISO/IEC 9899:2018)

(From yocto-docs rev: 9b7a4b503f6d0f2cd8b209ba9348a067a3846260)

Signed-off-by: Jan Vermaete <jan.vermaete@gmail.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit 1ebaed299f7ef80a49b68608f45bf25884900d13)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Peter Marko
7ec60228eb vulnerabilities: update nvdcve file name
The filename is outdated as its version was already bumped and there are
also different files for different feed choices.
Use glob to match any available file.

Also the directory changed to CVE_CHECK2 meanwhile, so Update it, too.

(From yocto-docs rev: 1b4d559ad5489a34cec26f9aad2687d2cb3ecc0a)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit a2f18cb23183401d9d8e2fd4499d164ef8d86e44)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Lee Chee Yang
8150b2ba7c migration-guides: add release notes for 4.0.29
(From yocto-docs rev: eca0629b779c2b96c812b68c42b83ed3589a6d87)

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
(cherry picked from commit d3bbfed9cad4cda0960ee0623c728ea2a18e1b29)
Signed-off-by: Antonin Godard <antonin.godard@bootlin.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Martin Jansa
831fd471f1 bitbake: bitbake: Bump version to 2.12.1
To indicate compatibility with python 3.14

[YOCTO #15858]

(Bitbake rev: aab6b5ab43d6589f0a8ccacd0832a45eb0aa0fd0)

Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Joshua Watt
ec065ce64c bitbake: Use a "fork" multiprocessing context
Python 3.14 changes the default multiprocessing context from "fork" to
"forkserver"; however bitbake heavily relies on "fork" to efficiently
pass data to the child processes. As such, make "fork" context in the bb
namespace and use it in place of the normal multiprocessing module.

Note that multiprocessing contexts were added in Python 3.4, so this
should be safe to use even before Python 3.14

[YOCTO #15858]

(Bitbake rev: 0d9d8d0863e82e986c33c08064ce9a99224a06d5)

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-17 15:32:27 -07:00
Per x Johansson
5495d8b6ff rust-target-config: Add has-thread-local option
The "has-elf-tls" option was removed by the commit
8e1614a906086fb46c5dd7b7f2dffab91194165c. However is should have been
renamed to "has-thread-local", since it was renamed and not removed in
rust by this commit.
391332c5d9

(From OE-Core rev: 575a4316f661392eb73d1d97300511e2bca24ada)

Signed-off-by: Per x Johansson <perxjoh@axis.com>
Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Kyungjik Min
f6534ab04f pulseaudio: Add audio group explicitly
Since pulseaudio-server requires the audio group, we explicitly add it.

When use useradd-staticids or do not use the default group in
base-passwd, an error will occur because the audio group is not defined.

NOTE: pulseaudio: Performing useradd with [--root
TOPDIR/tmp/work/cortexa72-poky-linux/pulseaudio/17.0/recipe-sysroot
--home-dir /var/run/pulse --gid 998 --groups audio,pulse
--no-create-home --system --shell /bin/false --uid 998 pulse]
useradd: group 'audio' does not exist
ERROR: pulseaudio: useradd command did not succeed.

(From OE-Core rev: 4fc918da4667eebbbdae3def8c38209a3d650f97)

Signed-off-by: Kyungjik Min <dpmin7@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Deepak Rathore
199b076727 default-distrovars.inc: Fix CONNECTIVITY_CHECK_URIS redirect issue
The default CONNECTIVITY_CHECK_URIS uses "https://yoctoproject.org/connectivity.html"
which redirect to "https://www.yoctoproject.org/connectivity.html".

Some network configurations with proxies or restricted internet access
don't handle HTTP redirects properly during the sanity check phase,
causing build failures with:

ERROR:  OE-core's config sanity checker detected a potential misconfiguration.
Either fix the cause of this error or at your own risk disable the checker (see sanity.conf).
Following is the list of potential problems / advisories:

Fetcher failure for URL: 'https://yoctoproject.org/connectivity.html'. URL doesn't work.

Updated the default URL to use the final destination directly to avoid
redirect-related connectivity check failures.

Also updated SDK test cases in https.py to use the corrected URL for
consistency.

(From OE-Core rev: 894648f4173a8a0e489e720e2b543cd22e39a878)

Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 60cdf960a3560f391babd559737f1afb31fb2c5c)
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Yogita Urade
ebbcc0a3c6 tiff: fix CVE-2025-8534
A vulnerability classified as problematic was found in libtiff
4.6.0. This vulnerability affects the function PS_Lvl2page of
the file tools/tiff2ps.c of the component tiff2ps. The
manipulation leads to null pointer dereference. It is possible
to launch the attack on the local host. The complexity of an
attack is rather high. The exploitation appears to be difficult.
The exploit has been disclosed to the public and may be used.
The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b.
It is recommended to apply a patch to fix this issue. One of the
maintainers explains, that "[t]his error only occurs if
DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD")
option is used."

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-8534

Upstream patch:
6ba36f159f

(From OE-Core rev: 6db99609f8aeca660fa01fc9e32008a2e37aae03)

Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Siddharth Doshi
d5ed259e92 tiff: Security fix for CVE-2024-13978, CVE-2025-8176, CVE-2025-8177
Upstream-Status: Backport from [7be20ccaab, 2ebfffb0e8, 3994cf3b3b, ce46f002ec, ecc4ddbf1f, 75d8eca6f1, e8c9d6c616]

CVE's Fixed:
CVE-2024-13978 libtiff: LibTIFF Null Pointer Dereference
CVE-2025-8176 libtiff: LibTIFF Use-After-Free Vulnerability
CVE-2025-8177 libtiff: LibTIFF Buffer Overflow

(From OE-Core rev: 16d8a873c57b174e4d6581b58d890f2157aa2f2c)

(From OE-Core rev: f52df68fc89f0da9ea8ea8197462c9f55d0de46c)

Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Peter Marko
6f906dc9cf binutils: patch CVE-2025-8225
Pick commit [1] mentioned in [2].

[1] e51fdff7d2
[2] https://nvd.nist.gov/vuln/detail/CVE-2025-8225

Testsuite did not show any changes in results:

 === binutils Summary ===

 # of expected passes           310
 # of unexpected failures       1
 # of untested testcases        1
 # of unsupported tests         9

(From OE-Core rev: 3d79514f90a6f731a5333417641500b8e52e410a)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-09 09:30:07 -07:00
Steve Sakoman
343adc0de0 Revert "linux-yocto/6.12: riscv: Enable TUNE_FEATURES based KERNEL_FEATURES"
This reverts commit 9296d038106aebfb66e3a76c4444597e2e1a2263.

Since this patch, it looks like qemuriscv64 doesn't boot in Walnascar.

(From OE-Core rev: 49f47169953b807d430461ca33f3a2b076119712)

Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-09-02 09:44:27 -07:00
Michael Halstead
36326e581e yocto-uninative: Update to 4.9 for glibc 2.42
(From OE-Core rev: adbb7737cbfbe241df514704b9bb237e41505310)

Signed-off-by: Michael Halstead <mhalstead@linuxfoundation.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Michael Halstead
e5a9adf1a5 yocto-uninative: Update to 4.8 for GCC 15.1
(From OE-Core rev: ea3a60aabab3b7b456bd086f9e59b42d9ba62ce3)

Signed-off-by: Michael Halstead <mhalstead@linuxfoundation.org>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
54986335f9 gstreamer1.0: upgrade 1.24.12 -> 1.24.13
Below list of CVEs are addressed in this release
CVE-2025-47183
CVE-2025-47219
CVE-2025-47806
CVE-2025-47807
CVE-2025-47808

(From OE-Core rev: 340b182d5fc972175f1d2a89127f807073c10255)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
f699ff2f0c gstreamer1.0-vaapi: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: 5b918f7a9002472c271f412bec19c6ef9eaf6098)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
3b0107f1d2 gstreamer1.0-rtsp-server: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: fb4f3b3d2ee5d6098993cf59337b5d982be74b19)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
90b3c9c0f3 gstreamer1.0-python: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: c5742f1c6037c588e91011883b8cf5af6bd360a5)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
0e895d96c2 gstreamer1.0-plugins-ugly: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: fac2cdbd50d7e1e74910cc4c035471305372d5d7)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
33ef432073 gstreamer1.0-plugins-good: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: 01d4f52c290dc4acc7dd6e129db5470a626bfa90)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
b8ad59f27e gstreamer1.0-plugins-base: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: 7b024f5983e83fbde68aaaeaeeff4997d22ba825)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
d4485baac0 gstreamer1.0-plugins-bad: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: b819ceba86919df9b99533825dff2efe14164d74)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
224dc049d4 gstreamer1.0-libav: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: d40b0da3070dcd42bed756a47f98b09f04632cab)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Archana Polampalli
ea258f1f85 gst-devtools: upgrade 1.24.12 -> 1.24.13
(From OE-Core rev: 294522f993b5246ff4a4bf35d1f8fa66c29d1a63)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
4011ae9f22 vim: upgrade 9.1.1198 -> 9.1.1652
Handles CVE-2025-53905, CVE-2025-53906, CVE-2025-55157, CVE-2025-55158.

Changes between 9.1.1198 -> 9.1.1652
====================================
https://github.com/vim/vim/compare/v9.1.1198...v9.1.1652

Refresh patches.

Disable newly introduced wayland support (in patch version 1485).
To this belongs also adding recursion in delete command for dir auto
which was newly failing as there is wayland directory inside now.
If someone is interested, this can be probably enabled, but without
additional work it results in compilation error due to function
redefinition conflicts.

(From OE-Core rev: e87d427d928234ef0441f9ce1fe8631fbe471094)

(From OE-Core rev: 99e24ba524157ed70ad05b0b1a14fcca8df52246)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
390a774854 cve-update-db-native: fix fetcher for CVEs missing nodes
As of now, update of CVE DB from FKIE source (which is the defailt)
fails with following error:

File: '<build>/poky/meta/recipes-core/meta/cve-update-db-native.bb', lineno: 393, function: update_db_fkie
     0389:                [cveId, cveDesc, cvssv2, cvssv3, cvssv4, date, accessVector, vectorString]).close()
     0390:
     0391:        for config in elt['configurations']:
     0392:            # This is suboptimal as it doesn't handle AND/OR and negate, but is better than nothing
 *** 0393:            for node in config["nodes"]:
     0394:                parse_node_and_insert(conn, node, cveId, False)
     0395:
     0396:def update_db(d, conn, jsondata):
     0397:    if (d.getVar("NVD_DB_VERSION") == "FKIE"):
Exception: KeyError: 'nodes'

Entry for new CVE-2025-32915 is broken.

(From OE-Core rev: 5bc27449381d2a53588dc7ad1fe2b78783d5c240)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
c0192e2543 binutils: set status for CVE-2025-8224
Commit mentioned in CVE report is already included in current hash.
Can be verified by trying to cherry-pick.

(From OE-Core rev: c7297f46efa410a9204d3d386d307deada967bb6)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
1828ecc19f libarchive: patch CVE-2025-5918
Pick commits per [1]

Additionally pick a commit needed to apply these cleanly.

[1] https://security-tracker.debian.org/tracker/CVE-2025-5918

(From OE-Core rev: 20687d6eed86003eacd5c91ebfd1101f6413ee3f)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
3c89580ab0 libarchive: patch CVE-2025-5917
Pick commit per [1]

[1] https://security-tracker.debian.org/tracker/CVE-2025-5917

(From OE-Core rev: 59b3c2f9dcf523a441bdaeac52c590d469b0b8ac)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
7570380173 libarchive: patch CVE-2025-5916
Pick commit per [1]

[1] https://security-tracker.debian.org/tracker/CVE-2025-5916

(From OE-Core rev: aa9adf9b4d5b0169dfe44503c247d48538d16929)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Peter Marko
1685873075 gnutls: mark CVE-2025-32989 and CVE-2025-32990 as fixed
This is mentioned in [1].
NVD tracks this as version-less CVE.

[1] https://gitlab.com/gnutls/gnutls/-/blob/3.8.10/NEWS?ref_type=tags#L8

(From OE-Core rev: 0c84e464d67df1111e62edc5d4f9ad398e19e40a)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-29 10:02:59 -07:00
Patryk Seregiet
f0c015b3f1 linux-firmware: fix FILES to drop RDEPENDS on full package
linux-firmware-rtl8723 and linux-firmware-adsp-sst
contain symlinks to files that were previously
packaged only in the main linux-firmware package.
This caused both subpackages to inherit an unintended
RDEPENDS on the full package. This change resolves the
issue by ensuring all required files are correctly
included in their respective subpackages.

Thanks to Peter Kjellerstedt for figuring out the rootcause.

(From OE-Core rev: cf27c7d040e7a5f1bbc60fb36c98686704bd7dc5)

(From OE-Core rev: 4b785d2d416944a78bf4c09e85a508ae80e35ca4)

Signed-off-by: Patryk Seregiet <patryk.seregiet@gmail.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

(master rev: cf27c7d040e7a5f1bbc60fb36c98686704bd7dc5)

Signed-off-by: Robert Yang <liezhi.yang@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Martin Jansa
9fc83a3343 bash: use -std=gnu17 also for native CFLAGS
* fixes builds on host with gcc-15:
  http://errors.yoctoproject.org/Errors/Details/853016/

../../bash-5.2.37/builtins/mkbuiltins.c:268:29: error: too many arguments to function ‘xmalloc’; expected 0, have 1
  268 |           error_directory = xmalloc (2 + strlen (argv[arg_index]));
      |                             ^~~~~~~  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~

(From OE-Core rev: 0c09f4a449fc03e6f5dfb6e5961c0a0471a7816d)

Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Martin Jansa
49a42f23d1 pkgconfig: fix build with gcc-15
* on hosts with gcc-15 or whenever glib PACKAGECONFIG isn't enabled
  and pkgconfig uses own old bundled glib

* fixes:
  http://errors.yoctoproject.org/Errors/Details/853015/
../../../git/glib/glib/goption.c:169:14: error: two or more data types in declaration specifiers
  169 |     gboolean bool;
      |              ^~~~
../../../git/glib/glib/goption.c:169:18: warning: declaration does not declare anything
  169 |     gboolean bool;
      |                  ^

(From OE-Core rev: 092ee1703d81b8aaed452189dd329320483087d3)

Signed-off-by: Martin Jansa <martin.jansa@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Harish Sadineni
5d2bdb56f8 binutils: Fix gprofng broken symbolic link with gp-*
In binutils 2.44, application names were changed from the gp- prefix
(e.g., gp-display-text, gp-archive) to the gprofng- prefix
(e.g., gprofng-display-text, gprofng-archive). Temporary gp-*
symlinks were added to maintain compatibility with the older
gprofng-gui.

However, these compatibility symlinks did not support cross-platform
toolchain prefixes, which resulted in broken gp-* symbolic links.

Support for cross-platform prefixes are added upstream in binutils 2.45,
so this change backports that fix to resolve broken symlinks issue.

Upstream-Status: Backport [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=90803ffdcc4d8c3d17566bf8dccadbad312f07a9]

(From OE-Core rev: 55684a63904365d8a6ab2a8ce9e091f29b0b7df5)

Signed-off-by: Harish Sadineni <Harish.Sadineni@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Peter Marko
62d813527d go: upgrade 1.24.5 -> 1.24.6
Upgrade to latest 1.24.x release [1]:

$ git --no-pager log --oneline go1.24.5..go1.24.6
7f36edc26d [release-branch.go1.24] go1.24.6
83b4a5db24 [release-branch.go1.24] database/sql: avoid closing Rows while scan is in progress
0f5133b742 [release-branch.go1.24] os/exec: fix incorrect expansion of "", "." and ".." in LookPath
6e1c4529e4 [release-branch.go1.24] cmd/compile: for arm64 epilog, do SP increment with a single instruction
731de13dc3 [release-branch.go1.24] os/user: user random name for the test user account
390ffce7d6 [release-branch.go1.24] runtime: prevent unnecessary zeroing of large objects with pointers
b454859a8a [release-branch.go1.24] runtime: stash allpSnapshot on the M

Fixes CVE-2025-47906 and CVE-2025-47907 [2].

[1] https://github.com/golang/go/compare/go1.24.5...go1.24.6
[2] https://groups.google.com/g/golang-announce/c/x5MKroML2yM

(From OE-Core rev: a348c04d449c0ba36b2ef278bea08919f0e6d19f)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
(cherry picked from commit f3072c210ac0a1e4d8046d920c3ebc29f9916b72)
Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Peter Marko
c00fb3ce44 glib-2.0: patch CVE-2025-6052
Backport commits from [1] which references this CVE.

[1] https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4681

(From OE-Core rev: a96c84cb861cb550ddcabd2396a74b00f0035ba4)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00
Peter Marko
d2cf21799c glib-2.0: update 2.84.2 -> 2.84.4
Overview of changes in GLib 2.84.4, 2025-08-08
==============================================
* Bugs fixed:
  - #3716 (CVE-2025-7039) (#YWH-PGM9867-104) Buffer Under-read on GLib through
    glib/gfileutils.c via get_tmp_file() (Michael Catanzaro)
  - #3721 GFile leak in g_local_file_set_display_name during error handling
    (Philip Withnall, Michael Catanzaro)
  - !4668 Backport !4667 “Incorrect output parameter handling in closure helper
    of g_settings_bind_with_mapping_closures” to glib-2-84
  - !4675 Backport !4674 “gfileutils: fix computation of temporary file name” to
    glib-2-84
  - !4679 Backport !4677 and !4678 “Fix GFile leak in
    g_local_file_set_display_name()” to glib-2-84
  - !4697 Backport !4696 “gthreadpool: Catch pool_spawner creation failure” to
    glib-2-84
  - !4705 Backport !4702 “gio/filenamecompleter: Fix leaks” to glib-2-84
  - !4711 Backport !4708 “gfilenamecompleter: Fix g_object_unref() of undefined
    value” to glib-2-84

Overview of changes in GLib 2.84.3, 2025-06-13
==============================================
* Bugs fixed:
  - !4656 Backport !4655 “gstring: Fix overflow check when expanding the string”
    to glib-2-84

!4656 solves first half of CVE-2025-6052

(From OE-Core rev: 8d5df566ef2c3d342ca0eb2421b4a583b02969da)

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-08-26 06:33:14 -07:00