TASK COMMIT
bugzilla: #IADG80:CVE-2022-48827 68f74c34ae8e NFSD: Fix the behavior of READ near OFFSET_MAX
bugzilla: #IAGEN5:CVE-2024-41027 de1b2a2023ce Fix userfaultfd_api to return EINVAL as expected
ab54dce92e6c mm/userfaultfd: fail uffd-wp registration if not supported
bugzilla: #IAGEP3:CVE-2024-42089 03d5d9595c8a ASoC: fsl-asoc-card: set priv->pdev before using it
bugzilla: #IAGENX:CVE-2024-41087 a071840d7f4d ata: libata-core: Fix double free on error
bugzilla: #IAGEML:CVE-2024-41073 3ff652bed313 nvme: avoid double free special payload
bugzilla: #IAGTIZ:CVE-2024-42155 cd075fde07c9 s390/pkey: Wipe copies of protected- and secure-keys
fe266c4b37ae Revert "s390/pkey: Wipe copies of protected- and secure-keys"
bugzilla: #IAI2U3:irqchip/mbigen: Fix mbigen node address layout 9d9238c4d938 irqchip/mbigen: Fix mbigen node address layout
bugzilla: #IAGEPB:CVE-2024-42093 3a0852b70f35 net/dpaa2: Avoid explicit cpumask var allocation on stack
bugzilla: #IAH97R:CVE-2023-52888 c6b688d749ee media: mediatek: vcodec: Only free buffer VA that is not NULL
bugzilla: #IAGS16:CVE-2024-42160 d7db19a77990 f2fs: Add inline to f2fs_build_fault_attr() stub
b4f357547fba f2fs: check validation of fault attrs in f2fs_build_fault_attr()
bugzilla: #IAGEOW:CVE-2024-42084 b95ecee30339 ftruncate: pass a signed offset
bugzilla: #IAGEMC:CVE-2024-41066 226f3b253286 ibmvnic: Add tx check to prevent skb leak
bugzilla: #IAGTJ2:CVE-2024-42124 96e3737c6cb7 scsi: qedf: Make qedf_execute_tmf() non-preemptible
bugzilla: #IAGRP3:CVE-2024-42161 f7cd46edd3ae bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD
bugzilla: #IAF0D0:【OLK-5.10】回合主线bugfix补丁 f11c7cf7e7e6 irqdomain: Fixed unbalanced fwnode get and put
bugzilla: #IAGS04:CVE-2024-42101 db6f5bf6df34 drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes
bugzilla: #IAGEMT:CVE-2024-41079 2f619916fe65 nvmet: always initialize cqe.result
bugzilla: #IAGEP9:CVE-2024-42094 0d8f5e00bbc6 net/iucv: Avoid explicit cpumask var allocation on stack
bugzilla: #IACS4Z:CVE-2024-39497 afe656d52a23 drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE)
bugzilla: #IAGRY7:CVE-2024-42162 d9561e71be39 gve: Account for stopped queues when reading NIC stats
bugzilla: #IAGRQD:CVE-2024-42137 479ffece662e Bluetooth: qca: Fix BT enable failure again for QCA6390 after warm reboot
bugzilla: #IAGS4V:CVE-2024-42129 9e437bc3582e leds: mlxreg: Use devm_mutex_init() for mutex initialization
87ac7d798f52 locking/mutex: Introduce devm_mutex_init()
bugzilla: #IA6SGI:CVE-2024-38546 14353e62ce90 drm: vc4: Fix possible null pointer dereference
bugzilla: #IA6S5U:CVE-2024-38594 cef3b30b448d net: stmmac: move the EST lock to struct stmmac_priv
bugzilla: #IAGEL6:CVE-2024-41055 5682f391cd3d mm: prevent derefencing NULL ptr in pfn_section_valid()
bugzilla: #IACZYN:CVE-2024-40910 ebfe8cc10206 ax25: Fix refcount imbalance on inbound connections
bugzilla: #IAGENQ:CVE-2024-42077 c6c647b79a76 ocfs2: fix DIO failure due to insufficient transaction credits
bugzilla: #IAGEP8:CVE-2024-42092 633debe8517a gpio: davinci: Validate the obtained number of IRQs
bugzilla: #IAGEOP:CVE-2024-42076 9d5c3c2e533c net: can: j1939: Initialize unused data in j1939_send_one()
bugzilla: #IAGEK1:CVE-2024-41062 f9b978222fb2 Bluetooth: L2CAP: Fix deadlock
dfaef6fe02c6 bluetooth/l2cap: sync sock recv cb and release
bugzilla: #IAG8QA:CVE-2024-41014 afcc9adf9a39 xfs: add bounds checking to xlog_recover_process_data
bugzilla: #IAG8UD:CVE-2024-41013 3b75a8a11645 xfs: don't walk off the end of a directory data block
bugzilla: #IAGEKF:CVE-2024-41070 6e8071349aed KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
bugzilla: #IAGEN4:CVE-2024-41023 836f84e5c827 sched/deadline: Fix task_struct reference leak
bugzilla: #IAGEP4:CVE-2024-42090 bf1e37a2f23a pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER
bugzilla: #IAGEOL:CVE-2024-41097 3a378778957c usb: atm: cxacru: fix endpoint checking in cxacru_bind()
bugzilla: #IAGPRU:CVE-2024-42106 fce8426355b1 inet_diag: Initialize pad field in struct inet_diag_req_v2
bugzilla: #IAGEOR:CVE-2024-42080 e7012de5d719 RDMA/restrack: Fix potential invalid address access
bugzilla: #IAGSOT:CVE-2024-42224 bc97a812c679 net: dsa: mv88e6xxx: Correct check for empty list
bugzilla: #IAGEON:CVE-2024-41089 534ddad2183f drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes
bugzilla: #IAGTIZ:CVE-2024-42155 956fdf4bd422 s390/pkey: Wipe copies of protected- and secure-keys
bugzilla: #IAGSG3:CVE-2024-42105 eb109da03304 nilfs2: fix inode number range checks
bugzilla: #IAGEN2:CVE-2024-41044 2af10338b715 ppp: reject claimed-as-LCP but actually malformed packets
bugzilla: #IAGELZ:CVE-2024-41072 0878a163412f wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
bugzilla: #IAGSPA:CVE-2024-42145 7bf1af9ef216 IB/core: Implement a limit on UMAD receive List
bugzilla: #IAGEM4:CVE-2024-41048 dcddbe19d126 skmsg: Skip zero length skb in sk_msg_recvmsg
bugzilla: #IAGENG:CVE-2024-42082 b978fa70335b xdp: xdp_mem_allocator can be NULL in trace_mem_connect().
43850d42a248 xdp: Remove WARN() from __xdp_reg_mem_model()
4bbdc8a473d0 xdp: Allow registering memory model without rxq reference
a4e933e8e1a8 xdp: Move the rxq_info.mem clearing to unreg_mem_model()
bugzilla: #IAGEKE:CVE-2024-41046 2a19dd705c77 net: ethernet: lantiq_etop: fix double free in detach
471c2b900c25 net: lantiq_etop: add blank line after declaration
bugzilla: #IAGEMQ:CVE-2024-41081 839b80e52991 ila: block BH in ila_output()
bugzilla: #IAH95F:CVE-2023-52887 1348b0012f94 net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new
bugzilla: #IAGEF4:CVE-2024-41020 dfbebb5dc268 filelock: Fix fcntl/close race recovery compat path
bugzilla: #IAG8ZG:CVE-2024-41090 d00ea5d79ed4 tap: add missing verification for short frame
bugzilla: #IAG8V2:CVE-2024-41091 c41870da8c0b tun: add missing verification for short frame
bugzilla: #IAD0KR:CVE-2024-40961 436e09de6657 ipv6: prevent possible NULL deref in fib6_nh_init()
bugzilla: #IAGEOM:CVE-2024-42068 a6da8e0bc283 bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
bugzilla: #IAGELJ:CVE-2024-41064 5ee1f01f962b powerpc/eeh: avoid possible crash when edev->pdev changes
bugzilla: #IAGEN8:CVE-2024-41063 250c4132a140 Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
bugzilla: #IA7D3T:CVE-2024-38627 615c6e82b0c3 stm class: Fix a double free in stm_register_device()
bugzilla: #IAGEP7:CVE-2024-42097 f4d2eb4f070d ALSA: emux: improve patch ioctl data validation
bugzilla: #IAGEMW:CVE-2024-41077 3db056389eac null_blk: fix validation of block size
bugzilla: #IAGS1R:CVE-2024-42115 4f84ace66042 jffs2: Fix potential illegal address access in jffs2_free_inode
bugzilla: #IAGEK8:CVE-2024-41080 542b8f05a1ac io_uring: fix possible deadlock in io_register_iowq_max_workers()
bugzilla: #IAG8RW:CVE-2024-41019 a765caed4372 fs/ntfs3: Validate ff offset
bugzilla: #IAGEKN:CVE-2024-41049 592950acac49 filelock: fix potential use-after-free in posix_lock_inode
bugzilla: #IAGEKL:CVE-2024-41041 35a53b24e3fe udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
bugzilla: #IAGSW7:CVE-2024-42228 2f007050989f drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc
bugzilla: #IAGOP2:Backport 5.10.212 LTS patches from upstream a719603ae50b mtd: spinand: gigadevice: fix Quad IO for GD5F1GQ5UExxG
81a271c12c6d gpio: fix resource unwinding order in error path
d66cff1dd8b0 gpiolib: Fix the error path order in gpiochip_add_data_with_key()
73412b7f8f5d gpio: 74x164: Enable output pins after registers are reset
172cfa0fa3cf ext4: avoid bb_free and bb_fragments inconsistency in mb_free_blocks()
b0a09b79ed44 mptcp: fix possible deadlock in subflow diag
e276b8bbf68b pmdomain: qcom: rpmhpd: Fix enabled_corner aggregation
a3fb32da7ced mmc: sdhci-xenon: fix PHY init clock stability
522b67596e69 mmc: sdhci-xenon: add timeout for PHY init complete
a6e935f7c4e9 mmc: core: Fix eMMC initialization with 1-bit bus connection
7089a93c3be5 dmaengine: fsl-qdma: fix SoC may hang on 16 byte unaligned read
174dad40484d wifi: nl80211: reject iftype change with mesh ID change
0749ab92b88c gtp: fix use-after-free and null-ptr-deref in gtp_newlink()
93a2696695e6 afs: Fix endless loop in directory parsing
bf313fff0439 ALSA: Drop leftover snd-rtctimer stuff from Makefile
82f2d2c10465 netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
21b14670f9b4 Bluetooth: Enforce validation on max value of connection interval
0d76938df211 Bluetooth: hci_event: Fix wrongly recorded wakeup BD_ADDR
7eb4c40c892a net: usb: dm9601: fix wrong return value in dm9601_mdio_read
f4000d6da3fe lan78xx: enable auto speed configuration for LAN7850 if no EEPROM is detected
7c2f666bde6a tun: Fix xdp_rxq_info's queue_index when detaching
f77b7ffc94bc mtd: spinand: gigadevice: Fix the get ecc status issue
072247592cde mtd: spinand: gigadevice: Support GD5F1GQ5UExxG
b5f0f9385b95 crypto: virtio/akcipher - Fix stack overflow on memcpy
a92ba1ae4e16 platform/x86: touchscreen_dmi: Allow partial (prefix) matches for ACPI names
bugzilla: #IAGEOZ:CVE-2024-42086 4c64e2fc6ba2 iio: chemical: bme680: Fix overflows in compensate() functions
bugzilla: #IACR1V:CVE-2024-40988 8aa834af496c drm/radeon: fix UBSAN warning in kv_dpm.c
bugzilla: #IA6SDW:CVE-2024-38561 9f00593328cf kunit: Fix kthread reference
c8dc8e53eb2e kunit: Fix kthread reference
bugzilla: #IAEDJI:【OLK-5.10】 FSC = 0x21: alignment fault 05e7a9d29a09 PCI/ROM: Fix PCI ROM header check bug
bugzilla: #IAD0D8:CVE-2024-40959 f9733ad206f5 xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
bugzilla: #IAGELE:CVE-2024-41069 6bf23b50cb34 ASoC: topology: Fix route memory corruption
b581981d567e ASoC: topology: Fix references to freed memory
bugzilla: #IACV6I:CVE-2024-40976 6c011a5c40ae drm/lima: mask irqs in timeout path before hard reset
c6f3eafd48bd drm/lima: add mask irq callback to gp and pp
bugzilla: #I9Q92E:CVE-2024-35825 4f4bab294a1f usb: gadget: ncm: Fix handling of zero block length packets
bugzilla: #IAD00R:CVE-2024-39509 937026844005 HID: core: remove unnecessary WARN_ON() in implement()
bugzilla: #I9R4P3:CVE-2021-47382 ffb1028a3bf1 s390/qeth: fix deadlock during failing recovery
bugzilla: #IAGEM2:CVE-2024-41040 10a53bc78e8b net/sched: Fix UAF when resolving a clash
bugzilla: #IAFYD8:[OLK5.10]如果RNIC支持rocev2,也可以使用smcrv1收发包 e3d017c15a55 net/smc: enable smcrv1 when RNIC supports rocev2
bugzilla: #IACS9I:CVE-2024-40999 8dd7071f1e98 net: ena: Add validation for completion descriptors consistency

| bugzilla: #IAGSC9:CVE-2024-42105 | eb109da033048734f9e927ccb899598d2205f1c0 nilfs2: fix inode number range checks |