-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2026 11:52:56 +0200 Source: linux Binary: bpftool bpftool-dbgsym hyperv-daemons hyperv-daemons-dbgsym libcpupower-dev libcpupower1 libcpupower1-dbgsym linux-cpupower linux-cpupower-dbgsym linux-kbuild-6.12.88+deb13 linux-kbuild-6.12.88+deb13-dbgsym linux-perf linux-perf-dbgsym rtla rtla-dbgsym usbip usbip-dbgsym Architecture: i386 Version: 6.12.88-1 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Salvatore Bonaccorso Description: bpftool - Inspection and simple manipulation of BPF programs and maps hyperv-daemons - Support daemons for Linux running on Hyper-V libcpupower-dev - CPU frequency and voltage scaling tools for Linux (development fi libcpupower1 - CPU frequency and voltage scaling tools for Linux (libraries) linux-cpupower - CPU power management tools for Linux linux-kbuild-6.12.88+deb13 - Kbuild infrastructure for Linux 6.12.88+deb13 linux-perf - Performance analysis tools for Linux rtla - Real-Time Linux Analysis tools usbip - USB device sharing system over IP network Closes: 1119093 1131025 1135313 Changes: linux (6.12.88-1) trixie-security; urgency=high . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.87 https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.88 - scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() - ipmi: Add limits to event and receive message requests - ipmi: Check event message buffer response for bad data - ipmi:si: Return state to normal if message allocation fails - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free - ACPI: scan: Use acpi_dev_put() in object add error paths - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug - ACPI: video: force native backlight on HP OMEN 16 (8A44) - ASoC: SOF: Don't allow pointer operations on unconfigured streams - spi: rockchip: fix controller deregistration - ksmbd: rewrite stop_sessions() with restartable iteration - mm: convert mm_lock_seq to a proper seqcount - [amd64] x86: shadow stacks: proper error handling for mmap lock (CVE-2026-43109) - [amd64] x86/shstk: Prevent deadlock during shstk sigreturn - [amd64] KVM: x86: Fix shadow paging use-after-free due to unexpected GFN - [amd64] iommu/amd: Use atomic64_inc_return() in iommu.c - [amd64] iommu/amd: serialize sequence allocation under concurrent TLB invalidations (CVE-2026-43220) (Closes: #1135313) - flow_dissector: do not dissect PPPoE PFC frames - net: txgbe: fix RTNL assertion warning when remove module - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088) - [amd64] KVM: SVM: check validity of VMCB controls when returning from SMM - net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked - Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (CVE-2026-31499) - exit: prevent preemption of oopsing TASK_DEAD task - wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr - wifi: mt76: mt7925: fix incorrect length field in txpower command - wifi: mt76: mt7921: fix a potential clc buffer length underflow - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work - wifi: b43legacy: enforce bounds check on firmware key index in RX path - wifi: mac80211: drop stray 'static' from fast-RX rx_result - wifi: rsi: fix kthread lifetime race between self-exit and external-stop - wifi: mac80211: use safe list iteration in radar detect work - wifi: ath5k: do not access array OOB (Closes: #1119093) - wifi: mac80211: remove station if connection prep fails - wifi: b43: enforce bounds check on firmware key index in b43_rx() - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task - usb: usblp: fix heap leak in IEEE 1284 device ID via short response - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl - ALSA: usb-audio: midi2: Restart output URBs on resume - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() - ALSA: usb-audio: Fix UAC3 cluster descriptor size check - USB: omap_udc: DMA: Don't enable burst 4 mode - USB: serial: option: add Telit Cinterion LE910Cx compositions - usb: ulpi: fix memory leak on ulpi_register() error paths - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger - ALSA: firewire-tascam: Do not drop unread control events - xfrm: provide message size for XFRM_MSG_MAPPING - xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete - ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() - xfrm: ah: account for ESN high bits in async callbacks - selinux: don't reserve xattr slot when we won't fill it - selinux: shrink critical section in sel_write_load() - selinux: prune /sys/fs/selinux/disable - Bluetooth: virtio_bt: clamp rx length before skb_put - Bluetooth: virtio_bt: validate rx pkt_type header length - Bluetooth: btmtk: validate WMT event SKB length before struct access - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() - [armhf] spi: sun4i: fix controller deregistration - [armhf] spi: ti-qspi: fix controller deregistration - spi: sun6i: fix controller deregistration - fanotify: fix false positive on permission events - [arm64] KVM: arm64: Fix kvm_vcpu_initialized() macro parameter - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() - net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo - sound: ua101: fix division by zero at probe - net: libwx: fix VF illegal register access - ip6_gre: Use cached t->net in ip6erspan_changelink(). - net/rds: handle zerocopy send cleanup before the message is queued - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler - hwmon: (ltc2992) Clamp threshold writes to hardware range - hwmon: (ltc2992) Fix u32 overflow in power read path - clk: rk808: fix OF node reference imbalance - hwmon: (corsair-psu) Close HID device on probe errors - af_unix: Reject SIOCATMARK on non-stream sockets - block: add pgmap check to biovec_phys_mergeable - cifs: abort open_cached_dir if we don't request leases - cifs: change_conf needs to be called for session setup - extcon: ptn5150: handle pending IRQ events during system resume - gpio: of: clear OF_POPULATED on hog nodes in remove path - hv_sock: fix ARM64 support - ibmveth: Disable GSO for packets with small MSS - ice: fix double free in ice_sf_eth_activate() error path - spi: microchip-core-qspi: fix controller deregistration - udf: reject descriptors with oversized CRC length - thermal: core: Free thermal zone ID later during removal - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp - spi: topcliff-pch: fix controller deregistration - spi: topcliff-pch: fix use-after-free on unbind - clk: imx: imx8-acm: fix flags for acm clocks - clk: microchip: mpfs-ccc: fix out of bounds access during output registration - cpuidle: powerpc: avoid double clear when breaking snooze - [amd64] ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table - [arm64] ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop - [arm64] ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens - [arm64] ASoC: qcom: q6apm: remove child devices when apm is removed - btrfs: fix double free in create_space_info() error path - dm-thin: fix metadata refcount underflow - dm: don't report warning when doing deferred remove - dm: fix a buffer overflow in ioctl processing - eventfs: Hold eventfs_mutex and SRCU when remount walks events - dm-verity-fec: correctly reject too-small FEC devices - dm-verity-fec: correctly reject too-small hash devices - isofs: validate Rock Ridge CE continuation extent against volume size - isofs: validate block number from NFS file handle in isofs_export_iget - [arm64] iommu/arm-smmu-v3: Add a missing dma_wmb() for hitless STE update - lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() - lib/scatterlist: fix length calculations in extract_kvec_to_sg - lib/scatterlist: fix temp buffer in extract_user_to_sg() - libceph: Fix slab-out-of-bounds access in auth message processing - md/raid10: fix divide-by-zero in setup_geo() with zero far_copies - nvme-apple: drop invalid put of admin queue reference count - nvmet-tcp: fix race between ICReq handling and queue teardown - nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free - openvswitch: vport: fix self-deadlock on release of tunnel ports - pmdomain: core: Fix detach procedure for virtual devices in genpd - [arm64] RDMA/hns: Fix unlocked call to hns_roce_qp_remove() - [s390x] debug: Reject zero-length input in debug_input_flush_fn() - smb/client: fix out-of-bounds read in smb2_compound_op() - smb/client: fix out-of-bounds read in symlink_data() - smb: client: use kzalloc to zero-initialize security descriptor buffer - smb: client: validate dacloffset before building DACL pointers - [amd64] KVM: x86: check for nEPT/nNPT in slow flush hypercalls - mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock - PCI: Update saved_config_space upon resource assignment (Closes: #1131025) - PCI/AER: Clear only error bits in PCIe Device Status - PCI/AER: Stop ruling out unbound devices as error source - PCI/ASPM: Fix pci_clear_and_set_config_dword() usage - power: supply: max17042: avoid overflow when determining health - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() - RDMA/mana: Validate rx_hash_key_len - RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() - RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads - RDMA/rxe: Reject unknown opcodes before ICRC processing - RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path - mptcp: fastclose msk when linger time is 0 - mptcp: use MPJoinSynAckHMacFailure for SynAck HMAC failure - mptcp: use MPTCP_RST_EMPTCP for ACK HMAC validation failure - mptcp: sockopt: set timestamp flags on subflow socket, not msk - mptcp: fix scheduling with atomic in timestamp sockopt - f2fs: add READ_ONCE() for i_blocks in f2fs_update_inode() - f2fs: fix fiemap boundary handling when read extent cache is incomplete - f2fs: fix incorrect multidevice info in trace_f2fs_map_blocks() - f2fs: fix node_cnt race between extent node destroy and writeback - f2fs: fix uninitialized kobject put in f2fs_init_sysfs() - [arm64] KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value - [arm64] KVM: arm64: Fix initialisation order in __pkvm_init_finalise() - bpf: Fix use-after-free in arena_vm_close on fork - fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info - fs: prepare for adding LSM blob to backing_file - dma-mapping: drop unneeded includes from dma-mapping.h - dma-mapping: add __dma_from_device_group_begin()/end() - hwmon: (powerz) Avoid cacheline sharing for DMA buffer - mmc: core: Optimize time for secure erase/trim for some Kingston eMMCs - udf: fix partition descriptor append bookkeeping - mtd: spinand: winbond: Declare the QE bit on W25NxxJW - hfsplus: fix uninit-value by validating catalog record size - hfsplus: fix held lock freed on hfsplus_fill_super() - erofs: move {in,out}pages into struct z_erofs_decompress_req - erofs: tidy up z_erofs_lz4_handle_overlap() - erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() - gtp: disable BH before calling udp_tunnel_xmit_skb() - printk: add print_hex_dump_devel() - crypto: caam - guard HMAC key hex dumps in hash_digest_key - ALSA: aloop: Fix peer runtime UAF during format-change stop - net: stmmac: avoid shadowing global buf_sz - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() - net: stmmac: Prevent NULL deref when RX memory exhausted - wifi: mt76: mt7925: fix incorrect TLV length in CLC command - tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() - [arm64] KVM: arm64: Wake-up from WFI when iqrchip is in userspace - [amd64] x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache - ksmbd: validate inherited ACE SID length . [ Salvatore Bonaccorso ] * ptrace: slightly saner 'get_dumpable()' logic Checksums-Sha1: 57a1db89c84c19d2117e78dee6470adb491e9821 880728 bpftool-dbgsym_7.5.0+6.12.88-1_i386.deb 1dd7e5394ec03340abb3cba16723aec464bfaa0a 1563400 bpftool_7.5.0+6.12.88-1_i386.deb d6eed8cd0e9ed50b996bd61cddb0783bf5042479 42928 hyperv-daemons-dbgsym_6.12.88-1_i386.deb bdebdb663923b43c3dae22840571decf62c6d2c6 1273844 hyperv-daemons_6.12.88-1_i386.deb 052812c0e5071614cc60f4e1504e5f35f871fb6f 1257864 libcpupower-dev_6.12.88-1_i386.deb 29cf764f2ced037e8d4a1721bda19724d0545de4 28264 libcpupower1-dbgsym_6.12.88-1_i386.deb fdacc4e7d0a638725fb005f89b79614730aa4d59 1266284 libcpupower1_6.12.88-1_i386.deb 8317f2a9aba46875399507145274120c18125081 355772 linux-cpupower-dbgsym_6.12.88-1_i386.deb 589a992770296b73f73df9f5a44fcecf2d2cb56f 1440912 linux-cpupower_6.12.88-1_i386.deb 95a72949e0a5e0714465b0e5a33388698897b6c6 1802488 linux-kbuild-6.12.88+deb13-dbgsym_6.12.88-1_i386.deb d82648a719f1217388979920c1a4f7f9c5866153 1712276 linux-kbuild-6.12.88+deb13_6.12.88-1_i386.deb 5b8c5ab177edc94eaa6e35e1261d3a8e3321f7be 11539940 linux-perf-dbgsym_6.12.88-1_i386.deb 82a15167793173d814f8af3f2dba0fd21305aad5 4827312 linux-perf_6.12.88-1_i386.deb 63e39ef71710b4f0d7470acb744e193f61a9ed68 15354 linux_6.12.88-1_i386-buildd.buildinfo cfdfa75495a799ef55857bf1e4dc7e10654481dc 100484 rtla-dbgsym_6.12.88-1_i386.deb 5c82d83f8213ea5831e9b19dccf462381eae443a 1316128 rtla_6.12.88-1_i386.deb 0ea7c0f457955533f04b32b5c4159f0e210f2798 138084 usbip-dbgsym_2.0+6.12.88-1_i386.deb 6928db5319b1cbc266839917ec349ce46cc0246f 1293860 usbip_2.0+6.12.88-1_i386.deb Checksums-Sha256: 51db61e649e49347bc2371c1919a3a20059df0e2b92d96252b09ef042b95bde2 880728 bpftool-dbgsym_7.5.0+6.12.88-1_i386.deb a1568ba1ae043aa0486bac453a92b0c5940d88f5c908574eead8cd39f3add1f8 1563400 bpftool_7.5.0+6.12.88-1_i386.deb a153fa094e7471dbe2a2cbf4760cd5db32e53f52a1c54d50708d7c233361d646 42928 hyperv-daemons-dbgsym_6.12.88-1_i386.deb 470bd203e51b63fa174abf3dda6c44cd636894ce3fb7efddf2e6622ae1a7274e 1273844 hyperv-daemons_6.12.88-1_i386.deb af332c04fe62fb1b789935db2599c1d9b97ca238d7f7c8a86275eae45ffee7ec 1257864 libcpupower-dev_6.12.88-1_i386.deb 830e6139db43cbbe0e0a39a71e122020b9439cc05e4f4bace62029f9e14204a6 28264 libcpupower1-dbgsym_6.12.88-1_i386.deb ce1de40bd564bc4461944e10acd1cb37bfd2d7269fb2aea59abe5d2acdee271a 1266284 libcpupower1_6.12.88-1_i386.deb db59801554490ec2b3d933ba4d25f5b405efee03bbd0a029f79c05073c200e6f 355772 linux-cpupower-dbgsym_6.12.88-1_i386.deb 76ae6bb3a7e799ee70571850356759cd526acf150e223287cf41371c03ed5498 1440912 linux-cpupower_6.12.88-1_i386.deb 7e398b40949c4c90c8a87b792c62dbbb06ae647a08b84d7882247e7a38734d72 1802488 linux-kbuild-6.12.88+deb13-dbgsym_6.12.88-1_i386.deb b34e175562cf7e339565f4fd0d54104f1e5de2eb78ee6e1e3c9d621c0f9892e5 1712276 linux-kbuild-6.12.88+deb13_6.12.88-1_i386.deb 0a67d2a31a23c200b53204ae07a8a11c3b20866cff5dd0457a7173d7ccfbd561 11539940 linux-perf-dbgsym_6.12.88-1_i386.deb 65f3fd4e159e3224ffcb64cd0d65e94989ab246a7417c21c986b337ceb91d369 4827312 linux-perf_6.12.88-1_i386.deb 6341cee8ede8930a43b7ce7032b5fd5ffa2feb0e33600714769010fca2d794c1 15354 linux_6.12.88-1_i386-buildd.buildinfo 3b4d0deb006925099bb7ae7fdedbb60a1642469749d05f34adea6df737e68557 100484 rtla-dbgsym_6.12.88-1_i386.deb 2e1c2f88f7f029b7c30473a89b85da60615c71adea8d57a10f17a8eafb5f9388 1316128 rtla_6.12.88-1_i386.deb 2ce1b9b67c72daf5671c16e17a44921ebf0b1b7a9ef4fa5eaff316afff51e3bf 138084 usbip-dbgsym_2.0+6.12.88-1_i386.deb 1fb8e07b38c2b19570c4e40ba46560e3ebf2ef5cd1870d96c51a22bd586d7e62 1293860 usbip_2.0+6.12.88-1_i386.deb Files: 6779bc5f2f0b708cef8181ff2ea42c51 880728 debug optional bpftool-dbgsym_7.5.0+6.12.88-1_i386.deb b32350db17b725a49b8573d14a62fc76 1563400 devel optional bpftool_7.5.0+6.12.88-1_i386.deb 78c078b277f090ee227fb8b738ec1c88 42928 debug optional hyperv-daemons-dbgsym_6.12.88-1_i386.deb 5c78a10368693ab8d7cdb5fcbc463a32 1273844 admin optional hyperv-daemons_6.12.88-1_i386.deb cb4ebf329cbb68de127b8169242f308d 1257864 libdevel optional libcpupower-dev_6.12.88-1_i386.deb 11aea764d0587f06c88d59791a817e74 28264 debug optional libcpupower1-dbgsym_6.12.88-1_i386.deb 872593319b1c57d05dde713318eca240 1266284 libs optional libcpupower1_6.12.88-1_i386.deb a920c3365e4ba86af4b8a32f4c76d840 355772 debug optional linux-cpupower-dbgsym_6.12.88-1_i386.deb 14efaffb900968e758b48e19b8bf2095 1440912 admin optional linux-cpupower_6.12.88-1_i386.deb 79016c563183d47a36635f0c019aadc7 1802488 debug optional linux-kbuild-6.12.88+deb13-dbgsym_6.12.88-1_i386.deb 4bc907b1664336da370e395500bc6bee 1712276 kernel optional linux-kbuild-6.12.88+deb13_6.12.88-1_i386.deb 1a7da785f8b70f66e1e2f447ab1508ab 11539940 debug optional linux-perf-dbgsym_6.12.88-1_i386.deb 7d8c563499b0ebbcf932f7981c55f0fa 4827312 devel optional linux-perf_6.12.88-1_i386.deb 517335d667d2e7d2e6a5c5add2f1ae85 15354 kernel optional linux_6.12.88-1_i386-buildd.buildinfo a49e54bcd5e05a4a0f3ad20572855723 100484 debug optional rtla-dbgsym_6.12.88-1_i386.deb 766febb001ac337a10d2462c4cf8554b 1316128 devel optional rtla_6.12.88-1_i386.deb 2f965b20be680ca7bc473192198ea344 138084 debug optional usbip-dbgsym_2.0+6.12.88-1_i386.deb 23688ef2e1568d9556843183ee9cc12c 1293860 admin optional usbip_2.0+6.12.88-1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmoHCIwACgkQf2INRiCd aWLFLA/9HRLDTtrN6eFN+KCIlAJz1t0OCMzfU8fG5P2p1KqEstkdcZLohHpBZe0b elnsS784xkqPoFHMRcwxL2FjFuKScNCErRijWbrsZbOlmUvKPemPUYhA1/6GF/86 ld4NH/BE5/FGRrXZqo7HtB+t9UT5yTfAF1N02V+89qIA3D/XE/ALpbtqvK+2WjtM fIvZ6x3mVGTfWNS2PcppJKAMF8ZFnXYnhPIYGLiP8p9IKnzWOtgwuxFufywI1ITI kjz+miPRdcXPQZA6Iyh4tIhoQhE9GNr6Whr2OXiFYpDqSByaLmjTEXAH10jxVBpw /Q4pdZtgFvXPY/EaoAXLMJDaBTwwiShPnEI1dvrzkZ0qJgrnrs73mGs3Za0BffVt oFN+w6QsyI3MCXJVoTsvsysw6OnAFcHPuPP4qtLAXHa7DJ2I8dlzIpiHweO4Kci3 lQjykil5ZKciFTI4j/CP42wmW6U6AxUjzx+SjNvV6GY8M/md1xtAaWAYHhR9LHvW aFzTNvKTN7wZc0gUKAENtgv770dBMCcw3lceW7ISCdU9YMnRS9F0/a5rOEwsUpo8 7uHSA1RGNs0i2wBXKbhtnrsIcBrgEY+Sr5P00UTx4bBokcobrQUddo85apAAKRLM QyaP1CfLmoXpmI3FYinCerRs7eB1lRrbwEIs4c+pJnDCjWErF1w= =fAK6 -----END PGP SIGNATURE-----