• linux-signed-i386_5.10.205+1_source.changes ACCEPTED into oldstable-pro

    From Debian FTP Masters@21:1/5 to All on Sun Jan 14 21:20:01 2024
    Thank you for your contribution to Debian.



    Accepted:

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Sat, 30 Dec 2023 10:41:34 +0100
    Source: linux-signed-i386
    Architecture: source
    Version: 5.10.205+1
    Distribution: bullseye-security
    Urgency: high
    Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
    Changed-By: Salvatore Bonaccorso <carnil@debian.org>
    Changes:
    linux-signed-i386 (5.10.205+1) bullseye-security; urgency=high
    .
    * Sign kernel from linux 5.10.205-1
    .
    * New upstream stable update:
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.198
    - NFS: Use the correct commit info in nfs_join_page_group()
    - NFS/pNFS: Report EINVAL errors from connect() to the server
    - SUNRPC: Mark the cred for revalidation if the server rejects it
    - tracing: Increase trace array ref count on enable and filter files
    - ata: ahci: Drop pointless VPRINTK() calls and convert the remaining ones
    - ata: libahci: clear pending interrupt status
    - ext4: remove the 'group' parameter of ext4_trim_extent
    - ext4: add new helper interface ext4_try_to_trim_range()
    - ext4: scope ret locally in ext4_try_to_trim_range()
    - ext4: change s_last_trim_minblks type to unsigned long
    - ext4: mark group as trimmed only if it was fully scanned
    - ext4: replace the traditional ternary conditional operator with with
    max()/min()
    - ext4: move setting of trimmed bit into ext4_try_to_trim_range()
    - ext4: do not let fstrim block system suspend
    - tracing: Have event inject files inc the trace array ref count
    - bpf: Avoid deadlock when using queue and stack maps from NMI
    - i40e: Fix VF VLAN offloading when port VLAN is configured
    - [powerpc*] perf/hv-24x7: Update domain value check
    - dccp: fix dccp_v4_err()/dccp_v6_err() again
    - [x86] platform/x86: intel_scu_ipc: Check status after timeout in
    busy_loop()
    - [x86] platform/x86: intel_scu_ipc: Check status upon timeout in
    ipc_wait_for_interrupt()
    - [x86] platform/x86: intel_scu_ipc: Don't override scu in
    intel_scu_ipc_dev_simple_command()
    - [x86] platform/x86: intel_scu_ipc: Fail IPC send if still busy
    - [x86] srso: Fix srso_show_state() side effect
    - [x86] srso: Fix SBPB enablement for spec_rstack_overflow=off
    - [arm64] net: hns3: only enable unicast promisc when mac table full
    - [arm64] net: hns3: add 5ms delay before clear firmware reset irq source
    - net: bridge: use DEV_STATS_INC()
    - team: fix null-ptr-deref when team device type is changed
    - seqlock: avoid -Wshadow warnings
    - seqlock: Rename __seqprop() users
    - seqlock: Prefix internal seqcount_t-only macros with a "do_"
    - locking/seqlock: Do the lockdep annotation before locking in
    do_write_seqcount_begin_nested()
    - bnxt_en: Flush XDP for bnxt_poll_nitroa0()'s NAPI
    - net: rds: Fix possible NULL-pointer dereference
    - gpio: tb10x: Fix an error handling path in tb10x_gpio_probe()
    - i2c: mux: demux-pinctrl: check the return value of devm_kstrdup()
    - Input: i8042 - rename i8042-x86ia64io.h to i8042-acpipnpio.h
    - Input: i8042 - add quirk for TUXEDO Gemini 17 Gen1/Clevo PD70PN
    - [arm64] media: venus: core: Add io base variables for each block
    - [arm64] media: venus: hfi,pm,firmware: Convert to block relative
    addressing
    - [arm64] media: venus: hfi: Define additional 6xx registers
    - [arm64] media: venus: core: Add differentiator IS_V6(core)
    - [arm64] media: venus: hfi: Add a 6xx boot logic
    - [arm64] media: venus: hfi_venus: Write to VIDC_CTRL_INIT after unmasking
    interrupts
    - netfilter: use actual socket sk for REJECT action
    - netfilter: nft_exthdr: Support SCTP chunks
    - netfilter: nf_tables: add and use nft_sk helper
    - netfilter: nf_tables: add and use nft_thoff helper
    - netfilter: nft_exthdr: break evaluation if setting TCP option fails
    - netfilter: exthdr: add support for tcp option removal
    - netfilter: nft_exthdr: Fix non-linear header modification
    - ata: libata: Rename link flag ATA_LFLAG_NO_DB_DELAY
    - ata: ahci: Add support for AMD A85 FCH (Hudson D4)
    - ata: ahci: Rename board_ahci_mobile
    - ata: ahci: Add Elkhart Lake AHCI controller
    - btrfs: reset destination buffer when read_extent_buffer() gets invalid
    range
    - [armhf] bus: ti-sysc: Use fsleep() instead of usleep_range() in
    sysc_reset()
    - [armhf] bus: ti-sysc: Fix missing AM35xx SoC matching
    - [armhf] ARM: dts: omap: correct indentation
    - [armhf] bus: ti-sysc: Fix SYSC_QUIRK_SWSUP_SIDLE_ACT handling for uart
    wake-up
    - gpio: pmic-eic-sprd: Add can_sleep flag for PMIC EIC chip
    - i2c: npcm7xx: Fix callback completion ordering
    - scsi: qedf: Add synchronization between I/O completions and abort
    - ring-buffer: Avoid softlockup in ring_buffer_resize()
    - ring-buffer: Do not attempt to read past "commit"
    - scsi: pm80xx: Use phy-specific SAS address when sending PHY_START command
    - scsi: pm80xx: Avoid leaking tags when processing
    OPC_INB_SET_CONTROLLER_CONFIG command
    - ata: libata-eh: do not clear ATA_PFLAG_EH_PENDING in ata_eh_reset()
    - bpf: Clarify error expectations from bpf_clone_redirect
    - media: vb2: frame_vector.c: replace WARN_ONCE with a comment
    - [powerpc*] watchpoints: Disable preemption in thread_change_pc()
    - [armhf] ncsi: Propagate carrier gain/loss events to the NCSI controller
    - sched/cpuacct: Fix user/system in shown cpuacct.usage*
    - sched/cpuacct: Fix charge percpu cpuusage
    - sched/cpuacct: Optimize away RCU read lock
    - cgroup: Fix suspicious rcu_dereference_check() usage warning
    - ACPI: Check StorageD3Enable _DSD property in ACPI code
    - nvme-pci: factor the iod mempool creation into a helper
    - nvme-pci: factor out a nvme_pci_alloc_dev helper
    - nvme-pci: do not set the NUMA node of device if it has none
    - watchdog: iTCO_wdt: No need to stop the timer in probe
    - watchdog: iTCO_wdt: Set NO_REBOOT if the watchdog is not already running
    - netfilter: nft_exthdr: Search chunks in SCTP packets only
    - netfilter: nft_exthdr: Fix for unsafe packet data read
    - nvme-pci: always return an ERR_PTR from nvme_pci_alloc_dev
    - Revert "tty: n_gsm: fix UAF in gsm_cleanup_mux"
    - serial: 8250_port: Check IRQ data before use
    - nilfs2: fix potential use after free in nilfs_gccache_submit_read_data()
    - netfilter: nf_tables: disallow rule removal from chain binding
    (CVE-2023-5197)
    - ALSA: hda: Disable power save for solving pop issue on Lenovo ThinkCentre
    M70q
    - ata: libata-scsi: ignore reserved bits for REPORT SUPPORTED OPERATION
    CODES
    - i2c: i801: unregister tco_pdev in i801_probe() error path
    - Revert "SUNRPC dont update timeout value on connection reset"
    - proc: nommu: /proc/<pid>/maps: release mmap read lock
    - ring-buffer: Update "shortest_full" in polling
    - btrfs: properly report 0 avail for very full file systems
    - bpf: Fix BTF_ID symbol generation collision
    - bpf: Fix BTF_ID symbol generation collision in tools/
    - net: thunderbolt: Fix TCPv6 GSO checksum calculation
    - ata: libata-core: Fix ata_port_request_pm() locking
    - ata: libata-core: Fix port and device removal
    - ata: libata-core: Do not register PM operations for SAS ports
    - ata: libata-sata: increase PMP SRST timeout to 10s
    - fs: binfmt_elf_efpic: fix personality for ELF-FDPIC
    - NFS: Cleanup unused rpc_clnt variable
    - NFS: rename nfs_client_kset to nfs_kset
    - NFSv4: Fix a state manager thread deadlock regression
    - ring-buffer: remove obsolete comment for free_buffer_page()
    - ring-buffer: Fix bytes info in per_cpu buffer stats
    - rbd: move rbd_dev_refresh() definition
    - rbd: decouple header read-in from updating rbd_dev->header
    - rbd: decouple parent info read-in from updating rbd_dev
    - rbd: take header_rwsem in rbd_dev_refresh() only when updating
    - block: fix use-after-free of q->q_usage_counter
    - Revert "clk: imx: pll14xx: dynamically configure PLL for
    393216000/361267200Hz"
    - Revert "PCI: qcom: Disable write access to read only registers for IP
    v2.3.3"
    - scsi: zfcp: Fix a double put in zfcp_port_enqueue()
    - wifi: mwifiex: Fix tlv_buf_left calculation
    - net: replace calls to sock->ops->connect() with kernel_connect()
    - net: prevent rewrite of msg_name in sock_sendmsg()
    - [arm64] Add Cortex-A520 CPU part definition
    - ubi: Refuse attaching if mtd's erasesize is 0
    - wifi: iwlwifi: dbg_ini: fix structure packing
    - wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet
    - bpf: Fix tr dereferencing
    - drivers/net: process the result of hdlc_open() and add call of
    hdlc_close() in uhdlc_close()
    - wifi: mt76: mt76x02: fix MT76x0 external LNA gain handling
    - regmap: rbtree: Fix wrong register marked as in-cache when creating new
    node
    - ima: Finish deprecation of IMA_TRUSTED_KEYRING Kconfig
    - scsi: target: core: Fix deadlock due to recursive locking
    - ima: rework CONFIG_IMA dependency block
    - NFSv4: Fix a nfs4_state_manager() race
    - modpost: add missing else to the "of" check
    - net: fix possible store tearing in neigh_periodic_work()
    - ipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data()
    - [arm64,armhf] net: dsa: mv88e6xxx: Avoid EEPROM timeout when EEPROM is
    absent
    - net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
    - net: nfc: llcp: Add lock when modifying device list
    - net: ethernet: ti: am65-cpsw: Fix error code in
    am65_cpsw_nuss_init_tx_chns()
    - netfilter: handle the connecting collision properly in
    nf_conntrack_proto_sctp
    - netfilter: nf_tables: nft_set_rbtree: fix spurious insertion failure
    - [armhf] net: stmmac: dwmac-stm32: fix resume on STM32 MCU
    - tipc: fix a potential deadlock on &tx->lock
    - tcp: fix quick-ack counting to count actual ACKs of new data
    - tcp: fix delayed ACKs for MSS boundary condition
    - sctp: update transport state when processing a dupcook packet
    - sctp: update hb timer immediately after users change hb_interval
    - cpupower: add Makefile dependencies for install targets
    - dm zoned: free dmz->ddev array in dmz_put_zoned_devices
    - RDMA/core: Require admin capabilities to set system parameters
    - of: dynamic: Fix potential memory leak in of_changeset_action()
    - IB/mlx4: Fix the size of a buffer in add_port_entries()
    - [armhf] gpio: aspeed: fix the GPIO number passed to
    pinctrl_gpio_set_config()
    - RDMA/cma: Initialize ib_sa_multicast structure to 0 when join
    - RDMA/cma: Fix truncation compilation warning in make_cma_ports
    - RDMA/uverbs: Fix typo of sizeof argument
    - RDMA/siw: Fix connection failure handling
    - RDMA/mlx5: Fix NULL string error
    - netfilter: nf_tables: fix kdoc warnings after gc rework
    - netfilter: nftables: exthdr: fix 4-byte stack OOB write
    - xen/events: replace evtchn_rwlock with RCU (CVE-2023-34324)
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.199
    - RDMA/srp: Make struct scsi_cmnd and struct srp_request adjacent
    - RDMA/srp: Do not call scsi_done() from srp_abort()
    - RDMA/cxgb4: Check skb value for failure to allocate
    - [arm64] perf/arm-cmn: Fix the unhandled overflow status of counter 4 to 7
    - HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
    - quota: Fix slow quotaoff
    - net: prevent address rewrite in kernel_bind()
    - [arm64] drm/msm/dp: do not reinitialize phy unless retry during link
    training
    - [arm64] drm/msm/dsi: skip the wait for video mode done if not applicable
    - [arm64] drm/msm/dpu: change _dpu_plane_calc_bw() to use u64 to avoid
    overflow
    - xen-netback: use default TX queue size for vifs
    - [x86] drm/vmwgfx: fix typo of sizeof argument
    - net: macsec: indicate next pn update when offloading
    - net: phy: mscc: macsec: reject PN update requests
    - ixgbe: fix crash with empty VF macvlan list
    - net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
    - nfc: nci: assert requested protocol is valid
    - workqueue: Override implicit ordered attribute in
    workqueue_apply_unbound_cpumask()
    - net: add sysctl accept_ra_min_rtr_lft
    - net: change accept_ra_min_rtr_lft to affect all RA lifetimes
    - net: release reference to inet6_dev pointer
    - [armhf] dmaengine: stm32-mdma: abort resume if no ongoing transfer
    - usb: xhci: xhci-ring: Use sysdev for mapping bounce buffer
    - net: usb: dm9601: fix uninitialized variable use in dm9601_mdio_read
    - [arm64,armhf] usb: dwc3: Soft reset phy on probe for host
    - usb: musb: Get the musb_qh poniter after musb_giveback
    - usb: musb: Modify the "HWVers" register address
    - iio: pressure: bmp280: Fix NULL pointer exception
    - iio: pressure: dps310: Adjust Timeout Settings
    - iio: pressure: ms5611: ms5611_prom_is_valid false negative bug
    - [x86] cpu: Fix AMD erratum #1485 on Zen4-based CPUs
    - mcb: remove is_added flag from mcb_device struct
    - [x86] thunderbolt: Check that lane 1 is in CL0 before enabling lane
    bonding
    - libceph: use kernel_connect()
    - ceph: fix incorrect revoked caps assert in ceph_fill_file_size()
    - ceph: fix type promotion bug on 32bit systems
    - Input: powermate - fix use-after-free in powermate_config_complete
    - Input: psmouse - fix fast_reconnect function for PS/2 mode
    - Input: xpad - add PXN V900 support
    - Input: i8042 - add Fujitsu Lifebook E5411 to i8042 quirk table
    - Input: goodix - ensure int GPIO is in input for gpio_count == 1 &&
    gpio_int_idx == 0 case
    - tee: amdtee: fix use-after-free vulnerability in amdtee_close_session
    - cgroup: Remove duplicates in cgroup v1 tasks file
    - pinctrl: avoid unsafe code pattern in find_pinctrl()
    - counter: microchip-tcb-capture: Fix the use of internal GCLK logic
    - usb: gadget: udc-xilinx: replace memcpy with memcpy_toio
    - usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call
    - [powerpc*] 8xx: Fix pte_access_permitted() for PAGE_NONE
    - [powerpc*] 64e: Fix wrong test in __ptep_test_and_clear_young()
    - [x86] alternatives: Disable KASAN in apply_alternatives()
    - [arm64] report EL1 UNDEFs better
    - [arm64] die(): pass 'err' as long
    - [arm64] consistently pass ESR_ELx to die()
    - [arm64] rework FPAC exception handling
    - [arm64] rework BTI exception handling
    - [arm64] allow kprobes on EL0 handlers
    - [arm64] split EL0/EL1 UNDEF handlers
    - [arm64] factor out EL1 SSBS emulation hook
    - [arm64] factor insn read out of call_undef_hook()
    - [arm64] rework EL0 MRS emulation
    - [arm64] armv8_deprecated: fold ops into insn_emulation
    - [arm64] armv8_deprecated move emulation functions
    - [arm64] armv8_deprecated: move aarch32 helper earlier
    - [arm64] armv8_deprecated: rework deprected instruction handling
    - [arm64] armv8_deprecated: fix unused-function error
    - RDMA/srp: Set scmnd->result only when scmnd is not NULL
    - RDMA/srp: Fix srp_abort()
    - ravb: Fix use-after-free issue in ravb_tx_timeout_work() (CVE-2023-35827)
    - dev_forward_skb: do not scrub skb mark within the same name space
    - lib/Kconfig.debug: do not enable DEBUG_PREEMPT by default
    - mm/memory_hotplug: rate limit page migration warnings
    - Documentation: sysctl: align cells in second content column
    - usb: hub: Guard against accesses to uninitialized BOS descriptors
    - Bluetooth: hci_event: Ignore NULL link key
    - Bluetooth: Reject connection with the device which has same BD_ADDR
    - Bluetooth: Fix a refcnt underflow problem for hci_conn
    - Bluetooth: vhci: Fix race when opening vhci device
    - Bluetooth: hci_event: Fix coding style
    - Bluetooth: avoid memcmp() out of bounds warning
    - ice: fix over-shifted variable
    - ice: reset first in crash dump kernels
    - nfc: nci: fix possible NULL pointer dereference in send_acknowledge()
    - regmap: fix NULL deref on lookup
    - [x86] KVM: x86: Mask LVTPC when handling a PMI
    - [x86] sev: Disable MMIO emulation from user mode (CVE-2023-46813)
    - [x86] sev: Check IOBM for IOIO exceptions from user-space (CVE-2023-46813)
    - [x86] sev: Check for user-space IOIO pointing to kernel space
    (CVE-2023-46813)
    - tcp: check mptcp-level constraints for backlog coalescing
    - netfilter: nft_payload: fix wrong mac header matching
    - nvmet-tcp: Fix a possible UAF in queue intialization setup (CVE-2023-5178)
    - [x86] drm/i915: Retry gtt fault when out of fence registers
    - qed: fix LL2 RX buffer allocation
    - xfrm: fix a data-race in xfrm_gen_index()
    - xfrm: interface: use DEV_STATS_INC()
    - net: ipv4: fix return value check in esp_remove_trailer
    - net: ipv6: fix return value check in esp_remove_trailer
    - net: rfkill: gpio: prevent value glitch during probe
    - tcp: fix excessive TLP and RACK timeouts from HZ rounding
    - tcp: tsq: relax tcp_small_queue_check() when rtx queue contains a single
    skb
    - tun: prevent negative ifindex
    - ipv4: fib: annotate races around nh->nh_saddr_genid and nh->nh_saddr
    - net: usb: smsc95xx: Fix an error code in smsc95xx_reset()
    - i40e: prevent crash on probe if hw registers have invalid values
    - net: dsa: bcm_sf2: Fix possible memory leak in bcm_sf2_mdio_register()
    - net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve
    - netfilter: nft_set_rbtree: .deactivate fails if element has expired
    - net: pktgen: Fix interface flags printing
    - [x86] thunderbolt: Workaround an IOMMU fault on certain systems with Intel
    Maple Ridge
    - resource: Add irqresource_disabled()
    - ACPI: Drop acpi_dev_irqresource_disabled()
    - ACPI: resources: Add DMI-based legacy IRQ override quirk
    - ACPI: resource: Skip IRQ override on Asus Vivobook K3402ZA/K3502ZA
    - ACPI: resource: Add ASUS model S5402ZA to quirks
    - ACPI: resource: Skip IRQ override on Asus Vivobook S5602ZA
    - ACPI: resource: Add Asus ExpertBook B2502 to Asus quirks
    - ACPI: resource: Skip IRQ override on Asus Expertbook B2402CBA
    - ACPI: resource: Skip IRQ override on ASUS ExpertBook B1502CBA
    - ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CBA
    - usb: core: Track SuperSpeed Plus GenXxY
    - xhci: cleanup xhci_hub_control port references
    - xhci: move port specific items such as state completions to port structure
    - xhci: rename resume_done to resume_timestamp
    - xhci: clear usb2 resume related variables in one place.
    - xhci: decouple usb2 port resume and get_port_status request handling
    - xhci: track port suspend state correctly in unsuccessful resume cases
    - serial: 8250: omap: Fix imprecise external abort for omap_8250_pm()
    - serial: 8250_omap: Fix errors with no_console_suspend
    - drm/amd/display: only check available pipe to disable vbios mode.
    - drm/amd/display: Don't set dpms_off for seamless boot
    - drm/connector: Give connector sysfs devices there own device_type
    - drm/connector: Add a fwnode pointer to drm_connector and register with
    ACPI (v2)
    - drm/connector: Add drm_connector_find_by_fwnode() function (v3)
    - drm/connector: Add support for out-of-band hotplug notification (v3)
    - usb: typec: altmodes/displayport: Notify drm subsys of hotplug events
    - usb: typec: altmodes/displayport: Signal hpd low when exiting mode
    - ARM: dts: ti: omap: Fix noisy serial with overrun-throttle-ms for mapphone
    - btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to
    1
    - btrfs: initialize start_slot in btrfs_log_prealloc_extents
    - i2c: mux: Avoid potential false error message in i2c_mux_add_adapter
    - overlayfs: set ctime when setting mtime and atime
    - gpio: timberdale: Fix potential deadlock on &tgpio->lock
    - ata: libata-eh: Fix compilation warning in ata_eh_link_report()
    - tracing: relax trace_event_eval_update() execution with cond_resched()
    - HID: holtek: fix slab-out-of-bounds Write in holtek_kbd_input_event
    - Bluetooth: Avoid redundant authentication
    - Bluetooth: hci_core: Fix build warnings
    - wifi: cfg80211: Fix 6GHz scan configuration
    - wifi: mac80211: allow transmitting EAPOL frames with tainted key
    - wifi: cfg80211: avoid leaking stack data into trace
    - regulator/core: Revert "fix kobject release warning and memory leak in
    regulator_register()"
    - sky2: Make sure there is at least one frag_addr available
    - ipv4/fib: send notify when delete source address routes
    - drm: panel-orientation-quirks: Add quirk for One Mix 2S
    - btrfs: fix some -Wmaybe-uninitialized warnings in ioctl.c
    - HID: multitouch: Add required quirk for Synaptics 0xcd7e device
    - [x86] platform/x86: touchscreen_dmi: Add info for the Positivo C4128B
    - net/mlx5: Handle fw tracer change ownership event based on MTRC
    - Bluetooth: hci_event: Fix using memcmp when comparing keys
    - mtd: physmap-core: Restore map_rom fallback
    - mmc: core: sdio: hold retuning if sdio in 1-bit mode
    - mmc: core: Capture correct oemid-bits for eMMC cards
    - Revert "pinctrl: avoid unsafe code pattern in find_pinctrl()"
    - pNFS: Fix a hang in nfs4_evict_inode()
    - ACPI: irq: Fix incorrect return value in acpi_register_gsi()
    - nvme-pci: add BOGUS_NID for Intel 0a54 device
    - nvme-rdma: do not try to stop unallocated queues
    - USB: serial: option: add Telit LE910C4-WWX 0x1035 composition
    - USB: serial: option: add entry for Sierra EM9191 with new firmware
    - USB: serial: option: add Fibocom to DELL custom modem FM101R-GL
    - perf: Disallow mis-matched inherited group reads (CVE-2023-5717)
    - [s390x] pci: fix iommu bitmap allocation
    - [x86] platform/x86: asus-wmi: Change ASUS_WMI_BRN_DOWN code from 0x20 to
    0x2e
    - [x86] platform/x86: asus-wmi: Map 0x2a code, Ignore 0x2b and 0x2c events
    - Bluetooth: hci_sock: fix slab oob read in create_monitor_event
    - Bluetooth: hci_sock: Correctly bounds check and pad HCI_MON_NEW_INDEX name
    - xfrm6: fix inet6_dev refcount underflow problem
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.200
    - virtio_balloon: Fix endless deflation and inflation on arm64
    - virtio-mmio: fix memory leak of vm_dev
    - mm/page_alloc: correct start page when guard page debug is enabled
    - drm/dp_mst: Fix NULL deref in get_mst_branch_device_by_guid_helper()
    - r8169: fix the KCSAN reported data-race in rtl_tx while reading
    TxDescArray[entry].opts1
    - r8169: fix the KCSAN reported data race in rtl_rx while reading
    desc->opts1
    - treewide: Spelling fix in comment
    - igb: Fix potential memory leak in igb_add_ethtool_nfc_entry
    - neighbour: fix various data-races
    - igc: Fix ambiguity in the ethtool advertising
    - net: ieee802154: adf7242: Fix some potential buffer overflow in
    adf7242_stats_show()
    - net: usb: smsc95xx: Fix uninit-value access in smsc95xx_read_reg
    - r8152: Increase USB control msg timeout to 5000ms as per spec
    - r8152: Run the unload routine if we have errors during probe
    - r8152: Cancel hw_phy_work if we have an error in probe
    - r8152: Release firmware if we have an error in probe
    - tcp: fix wrong RTO timeout when received SACK reneging
    - gtp: uapi: fix GTPA_MAX
    - gtp: fix fragmentation needed check with gso
    - i40e: Fix wrong check for I40E_TXR_FLAGS_WB_ON_ITR
    - [armhf] i2c: muxes: i2c-mux-pinctrl: Use of_get_i2c_adapter_by_node()
    - [armhf] i2c: stm32f7: Fix PEC handling in case of SMBUS transfers
    - [armhf] i2c: aspeed: Fix i2c bus hang in slave read
    - tracing/kprobes: Fix the description of variable length arguments
    - [arm64,armhf] nvmem: imx: correct nregs for i.MX6ULL
    - [arm64,armhf] nvmem: imx: correct nregs for i.MX6SLL
    - [arm64,armhf] nvmem: imx: correct nregs for i.MX6UL
    - perf/core: Fix potential NULL deref
    - clk: Sanitize possible_parent_show to Handle Return Value of
    of_clk_get_parent_name
    - [x86] i8259: Skip probing when ACPI/MADT advertises PCAT compatibility
    - kobject: Fix slab-out-of-bounds in fill_kobj_path() (CVE-2023-45863)
    - f2fs: fix to do sanity check on inode type during garbage collection
    (CVE-2021-44879)
    - [x86] mm: Simplify RESERVE_BRK()
    - [x86] mm: Fix RESERVE_BRK() for older binutils
    - ext4: add two helper functions extent_logical_end() and pa_logical_end()
    - ext4: fix BUG in ext4_mb_new_inode_pa() due to overflow
    - ext4: avoid overlapping preallocations due to overflow
    - [x86] objtool/x86: add missing embedded_insn check
    - driver: platform: Add helper for safer setting of driver_override
    - [arm64] rpmsg: Constify local variable in field store macro
    - rpmsg: Fix kfree() of static memory on setting driver_override
    - rpmsg: Fix calling device_lock() on non-initialized device
    - [arm64] rpmsg: glink: Release driver_override
    - [arm64] rpmsg: Fix possible refcount leak in
    rpmsg_register_device_override()
    - [x86] Fix .brk attribute in linker script
    - net: sched: cls_u32: Fix allocation size in u32_init()
    - [armhf] irqchip/stm32-exti: add missing DT IRQ flag translation
    - Input: synaptics-rmi4 - handle reset delay when using SMBus trsnsport
    - fbdev: atyfb: only use ioremap_uc() on i386 and ia64
    - netfilter: nfnetlink_log: silence bogus compiler warning
    - ASoC: rt5650: fix the wrong result of key button
    - [x86] fbdev: uvesafb: Call cn_del_callback() at the end of uvesafb_exit()
    - scsi: mpt3sas: Fix in error path
    - net: chelsio: cxgb4: add an error code check in t4_load_phy_fw
    - [powerpc*] mm: Fix boot crash with FLATMEM
    - can: isotp: change error format from decimal to symbolic error names
    - can: isotp: add symbolic error message to isotp_module_init()
    - can: isotp: Add error message if txqueuelen is too small
    - can: isotp: set max PDU size to 64 kByte
    - can: isotp: isotp_bind(): return -EINVAL on incorrect CAN ID formatting
    - can: isotp: check CAN address family in isotp_bind()
    - can: isotp: handle wait_event_interruptible() return values
    - can: isotp: add local echo tx processing and tx without FC
    - can: isotp: isotp_bind(): do not validate unused address information
    - can: isotp: isotp_sendmsg(): fix TX state detection and wait behavior
    - PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device
    - usb: storage: set 1.50 as the lower bcdDevice for older "Super Top"
    compatibility
    - usb: raw-gadget: properly handle interrupted requests
    - tty: 8250: Remove UC-257 and UC-431
    - tty: 8250: Add support for additional Brainboxes UC cards
    - tty: 8250: Add support for Brainboxes UP cards
    - tty: 8250: Add support for Intashield IS-100
    - ALSA: hda: intel-dsp-config: Fix JSL Chromebook quirk detection
    https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.201
    - [x86] iov_iter, x86: Be consistent about the __user tag on
    copy_mc_to_user()
    - sched/uclamp: Ignore (util == 0) optimization in feec() when p_util_max =
    0
    - vfs: fix readahead(2) on block devices
    - [x86] srso: Fix SBPB enablement for (possible) future fixed HW
    - futex: Don't include process MM in futex key on no-MMU
    - [x86] boot: Fix incorrect startup_gdt_descr.size
    - pstore/platform: Add check for kstrdup
    - genirq/matrix: Exclude managed interrupts in irq_matrix_allocated()
    - i40e: fix potential memory leaks in i40e_remove()
    - udp: add missing WRITE_ONCE() around up->encap_rcv
    - tcp: call tcp_try_undo_recovery when an RTOd TFO SYNACK is ACKed
    - overflow: Implement size_t saturating arithmetic helpers
    - gve: Use size_add() in call to struct_size()
    - tipc: Use size_add() in calls to struct_size()
    - wifi: rtw88: debug: Fix the NULL vs IS_ERR() bug for debugfs_create_file()
    - tcp_metrics: add missing barriers on delete
    - tcp_metrics: properly set tp->snd_ssthresh in tcp_init_metrics()
    - tcp_metrics: do not create an entry from tcp_init_metrics()
    - wifi: rtlwifi: fix EDCA limit set by BT coexistence
    - can: dev: can_restart(): don't crash kernel if carrier is OK
    - can: dev: can_restart(): fix race condition between controller restart and
    netif_carrier_on()
    - PM / devfreq: rockchip-dfi: Make pmu regmap mandatory
    - thermal: core: prevent potential string overflow
    - r8169: use tp_to_dev instead of open code
    - r8169: fix rare issue with broken rx after link-down on RTL8125
    - tcp: fix cookie_init_timestamp() overflows
    - ACPI: sysfs: Fix create_pnp_modalias() and create_of_modalias()
    - ipv6: avoid atomic fragment on GSO packets
    - net: add DEV_STATS_READ() helper
    - ipvlan: properly track tx_errors
    - regmap: debugfs: Fix a erroneous check after snprintf()
    - [arm64] clk: qcom: clk-rcg2: Fix clock rate overflow for high parent
    frequencies
    - [arm64] clk: qcom: mmcc-msm8998: Add hardware clockgating registers to
    some clks
    - [arm64] clk: qcom: mmcc-msm8998: Don't check halt bit on some branch clks
    - [arm64] clk: qcom: mmcc-msm8998: Set bimc_smmu_gdsc always on
    - [arm64] clk: qcom: mmcc-msm8998: Fix the SMMU GDSC
    - [arm64] clk: qcom: gcc-sm8150: use ARRAY_SIZE instead of specifying
    num_parents
    - [arm64] clk: qcom: gcc-sm8150: Fix gcc_sdcc2_apps_clk_src
    - [arm64] clk: imx: imx8mq: correct error handling path
    - clk: asm9260: use parent index to link the reference clock
    - clk: linux/clk-provider.h: fix kernel-doc warnings and typos
    - [arm64] spi: nxp-fspi: use the correct ioremap function
    - [armhf] clk: ti: Add ti_dt_clk_name() helper to use clock-output-names
    - [armhf] clk: ti: Update pll and clockdomain clocks to use ti_dt_clk_name()
    - [armhf] clk: ti: Update component clocks to use ti_dt_clk_name()
    - [armhf] clk: ti: change ti_clk_register[_omap_hw]() API
    - [armhf] clk: ti: fix double free in of_ti_divider_clk_setup()
    - [x86] platform/x86: wmi: Fix probe failure when failing to register WMI
    devices
    - [x86] platform/x86: wmi: remove unnecessary initializations
    - [x86] platform/x86: wmi: Fix opening of char device
    - hwmon: (coretemp) Fix potentially truncated sysfs attribute name
    - [arm64,armhf] drm/rockchip: vop: Fix reset of state in duplicate state
    crtc funcs
    - [arm64,armhf] drm/rockchip: vop: Fix call to crtc reset helper
    - drm/radeon: possible buffer overflow
    - [arm64] drm/rockchip: cdn-dp: Fix some error handling paths in
    cdn_dp_probe()
    - [arm64,armhf] drm/rockchip: Fix type promotion bug in
    rockchip_gem_iommu_map()
    - xen-pciback: Consider INTx disabled when MSI/MSI-X is enabled
    - [arm64] dts: qcom: msm8916: Fix iommu local address range
    - [arm64] dts: qcom: sdm845-mtp: fix WiFi configuration
    - [i386] hwrng: geode - fix accessing registers
    - libnvdimm/of_pmem: Use devm_kstrdup instead of kstrdup and check its
    return value
    - nd_btt: Make BTT lanes preemptible
    - [arm64] crypto: caam/qi2 - fix Chacha20 + Poly1305 self test failure

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)