-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 17 Feb 2026 06:47:26 +0100 Source: linux-signed-arm64 Architecture: source Version: 6.12.73+1 Distribution: trixie-security Urgency: high Maintainer: Debian Kernel Team Changed-By: Salvatore Bonaccorso Changes: linux-signed-arm64 (6.12.73+1) trixie-security; urgency=high . * Sign kernel from linux 6.12.73-1 . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.70 - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec - [amd64] x86/vmware: Fix hypercall clobbers - [amd64] x86/kfence: fix booting on 32bit non-PAE systems - [amd64] platform/x86: intel_telemetry: Fix swapped arrays in PSS output - ALSA: aloop: Fix racy access at PCM trigger - [arm64] pmdomain: qcom: rpmpd: fix off-by-one error in clamping to the highest state - [arm64] pmdomain: imx8mp-blk-ctrl: Keep gpc power domain on for system wakeup - [arm64,armhf] pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong adb400 reset - [arm64] pmdomain: imx8mp-blk-ctrl: Keep usb phy power domain on for system wakeup - [arm64] pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains - mm/slab: Add alloc_tagging_slab_free_hook for memcg_alloc_abort_single - ceph: fix NULL pointer dereference in ceph_mds_auth_match() (Closes: #1125405) - rbd: check for EOD after exclusive lock is ensured to be held - ceph: fix oops due to invalid pointer for kfree() in parse_longname() - gve: Fix stats report corruption on queue count change - gve: Correct ethtool rx_dropped calculation - mm, shmem: prevent infinite loop on truncate race - Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem" - KVM: Don't clobber irqfd routing type when deassigning irqfd - PCI/ERR: Ensure error recoverability at all times - ublk: fix deadlock when reading partition table (CVE-2025-68823) - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (CVE-2025-40082) - [arm*] binder: fix BR_FROZEN_REPLY error log - binderfs: fix ida_alloc_max() upper bound - procfs: avoid fetching build ID while holding VMA lock - tracing: Fix ftrace event field alignments - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined - wifi: wlcore: ensure skb headroom before skb_push - net: usb: sr9700: support devices with virtual driver CD - block,bfq: fix aux stat accumulation destination - smb/server: call ksmbd_session_rpc_close() on error path in create_smb2_pipe() - md: suspend array while updating raid_disks via sysfs - smb/server: fix refcount leak in smb2_open() - smb/server: fix refcount leak in parse_durable_handle_context() - [amd64] HID: intel-ish-hid: Update ishtp bus match to support device ID table - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL - btrfs: fix reservation leak in some error paths when inserting inline extent - [riscv64] Sanitize syscall table indexing under speculation - [amd64] HID: intel-ish-hid: Reset enum_devices_done before enumeration - HID: playstation: Center initial joystick axes to prevent spurious events - ALSA: hda/realtek: Add quirk for Acer Nitro AN517-55 - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk - [arm64] PCI: qcom: Remove ASPM L0s support for MSM8996 SoC - netfilter: replace -EEXIST with -EBUSY - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list - HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report() - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101) - drm/amd/pm: Disable MMIO access during SMU Mode 1 reset - ring-buffer: Avoid softlockup in ring_buffer_resize() during memory free - HID: logitech: add HID++ support for Logitech MX Anywhere 3S - wifi: mac80211: collect station statistics earlier when disconnect - ASoC: simple-card-utils: Check device node before overwrite direction - nvme-fc: release admin tagset if init fails - nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready() - [amd64] ASoC: amd: yc: Fix microphone on ASUS M6500RE - regmap: maple: free entry on mas_store_gfp() failure - wifi: cfg80211: Fix bitrate calculation overflow for HE rates - scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() - ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() - wifi: mac80211: correctly check if CSA is active - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice - btrfs: reject new transactions if the fs is fully read-only - ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Book 9i 13IRU8 audio - [amd64] platform/x86: toshiba_haps: Fix memory leaks in add/remove routines - [amd64] platform/x86: intel_telemetry: Fix PSS event register mask - [amd64] platform/x86: hp-bioscfg: Skip empty attribute names - [amd64] platform/x86/intel/tpmi/plr: Make the file domain/status writeable - smb/client: fix memory leak in smb2_open_file() - net: add skb_header_pointer_careful() helper - net/sched: cls_u32: use skb_header_pointer_careful() - net: liquidio: Initialize netdev pointer before queue setup - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup - net: phy: add phy_interface_weight() - net: phy: add phy_interface_copy() - net: sfp: pre-parse the module support - net: sfp: convert sfp quirks to modify struct sfp_module_support - net: sfp: Fix quirk for Ubiquiti U-Fiber Instant SFP module - macvlan: fix error recovery in macvlan_common_newlink() - net: usb: r8152: fix resume reset deadlock - net: don't touch dev->stats in BPF redirect paths - tipc: use kfree_sensitive() for session key material - drm/amd/display: fix wrong color value mapping on MCM shaper LUT - net: gro: fix outer network offset - [amd64] drm/mgag200: fix mgag200_bmc_stop_scanout() - drm/xe/query: Fix topology query pointer advance - drm/xe/pm: Also avoid missing outer rpm warning on system suspend - drm/xe/pm: Disable D3Cold for BMG only on specific platforms - [armhf] hwmon: (occ) Mark occ_init_attribute() as __printf - netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() - ipv6: Fix ECMP sibling count mismatch when clearing RTF_ADDRCONF - ALSA: usb-audio: fix broken logic in snd_audigy2nx_led_update() - [amd64] ASoC: amd: fix memory leak in acp3x pdm dma ops - [arm64] ipi: tegra: Fix a memory leak in tegra_slink_probe() - [arm64,armhf] spi: tegra114: Preserve SPI mode bits in def_command1_reg - ALSA: hda/realtek: Really fix headset mic for TongFang X6AR55xU. - gpiolib-acpi: Update file references in the Documentation and MAINTAINERS https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.71 - net: tunnel: make skb_vlan_inet_prepare() return drop reasons (Closes: #1127597) - io_uring/rw: recycle buffers manually for non-mshot reads https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.72 - smb: client: split cached_fid bitfields to avoid shared-byte RMW races - ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths - smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection() - driver core: enforce device_lock for driver_match_device() - Bluetooth: btusb: Add USB ID 7392:e611 for Edimax EW-7611UXB - [amd64] crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode - [armhf] crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly - crypto: virtio - Add spinlock protection with virtqueue notification - crypto: virtio - Remove duplicated virtqueue_kick in virtio_crypto_skcipher_crypt_req - nilfs2: Fix potential block overflow that cause system hang - wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() - scsi: qla2xxx: Validate sp before freeing associated memory - scsi: qla2xxx: Allow recovery for tape devices - scsi: qla2xxx: Delay module unload while fabric scan in progress - scsi: qla2xxx: Free sp in error path to fix system crash - scsi: qla2xxx: Query FW again before proceeding with login - bus: mhi: host: pci_generic: Add Telit FE990B40 modem support - mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() (CVE-2026-23169) - erofs: fix UAF issue for file-backed mounts w/ directio option - xfs: fix UAF in xchk_btree_check_block_owner - PCI: endpoint: Avoid creating sub-groups asynchronously - wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add - [armhf] gpio: omap: do not register driver in probe() https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.73 - Revert "driver core: enforce device_lock for driver_match_device()" Checksums-Sha1: ae364273e2c770963ea51d49c65fd93b69a7e945 9588 linux-signed-arm64_6.12.73+1.dsc eb956e4e6e2bb0eaabc77dec6ec032a84d070040 887088 linux-signed-arm64_6.12.73+1.tar.xz Checksums-Sha256: 4bcd558586a4594c46929dc3817ee77197797c67fdd82c3796a6541001f34983 9588 linux-signed-arm64_6.12.73+1.dsc 8bd84b84516d1d720011b4bbd055d72ec238239252a458a3c4a4d4f2b4aec9d2 887088 linux-signed-arm64_6.12.73+1.tar.xz Files: c58b80f1915ea6a8b9e8e31cfcdb6970 9588 kernel optional linux-signed-arm64_6.12.73+1.dsc d16d64f19128994660295f68bde43c41 887088 kernel optional linux-signed-arm64_6.12.73+1.tar.xz -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSInBJdRTWyTRy0ztFCTVFtUgONCgUCaZRS0QAKCRBCTVFtUgON Coy+AQCRXZ56wTREgX4s1RnPsHLKYmdhfGr85PB+wM472AYXUgD+MpLoqv+D3Nkr a45bQTHuaIVjbf126RLzO/yRCHrgrQc= =Ojw7 -----END PGP SIGNATURE-----