-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 20 Jul 2026 09:13:07 +0200
Source: linux
Binary: bpftool bpftool-dbgsym hyperv-daemons hyperv-daemons-dbgsym libcpupower-dev libcpupower1 libcpupower1-dbgsym linux-cpupower linux-cpupower-dbgsym linux-kbuild-6.12.96+deb13 linux-kbuild-6.12.96+deb13-dbgsym linux-perf linux-perf-dbgsym rtla rtla-dbgsym usbip usbip-dbgsym
Architecture: i386
Version: 6.12.96-1
Distribution: trixie-security
Urgency: high
Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) <buildd_amd64-x86-ubc-02@buildd.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Description:
 bpftool    - Inspection and simple manipulation of BPF programs and maps
 hyperv-daemons - Support daemons for Linux running on Hyper-V
 libcpupower-dev - CPU frequency and voltage scaling tools for Linux (development fi
 libcpupower1 - CPU frequency and voltage scaling tools for Linux (libraries)
 linux-cpupower - CPU power management tools for Linux
 linux-kbuild-6.12.96+deb13 - Kbuild infrastructure for Linux 6.12.96+deb13
 linux-perf - Performance analysis tools for Linux
 rtla       - Real-Time Linux Analysis tools
 usbip      - USB device sharing system over IP network
Closes: 1140651
Changes:
 linux (6.12.96-1) trixie-security; urgency=high
 .
   * New upstream stable update:
     https://www.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.96
     - [arm64] bpf, arm64: Reject out-of-range B.cond targets
     - nfsd: fix file change detection in CB_GETATTR
     - nfsd: release layout stid on setlease failure
     - userfaultfd: gate must_wait writability check on pte_present()
     - perf: Fix dangling cgroup pointer in cpuctx backport
     - bcachefs: avoid truncating fiemap extent length
     - drm/amd: Fix set but not used warnings
     - gpio: rockchip: change the GPIO version judgment logic
     - gpio: rockchip: teardown bugs and resource leaks
     - gpio: rockchip: fix generic IRQ chip leak on remove (CVE-2026-53226)
     - mm/vmalloc: take vmap_purge_lock in shrinker (CVE-2026-46093)
     - device property: initialize the remaining fields of fwnode_handle in
       fwnode_init()
     - f2fs: validate orphan inode entry count
     - f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
     - f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
     - f2fs: fix potential deadlock in f2fs_balance_fs()
     - f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
     - f2fs: fix listxattr handling of corrupted xattr entries
     - fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
     - nfsd: add nfsd_file_{get,put} to 'nfs_to' nfsd_localio_operations
     - nfs_common: rename functions that invalidate LOCALIO nfs_clients
     - NFSv4/flexfiles: Remove cred local variable dependency
     - NFSv4/flexfiles: Add data structure support for striped layouts
     - NFSv4/flexfiles: reject zero filehandle version count
     - locking/rtmutex: Make sure we wake anything on the wake_q when we release
       the lock->wait_lock
     - apparmor: advertise the tcp fast open fix is applied
     - nfsd: move name lookup out of nfsd4_list_rec_dir()
     - nfsd: change nfs4_client_to_reclaim() to allocate data
     - bonding: fix xfrm offload feature setup on active-backup mode
     - block: add a store_limit operations for sysfs entries
     - block: fix queue freeze vs limits lock order in sysfs store methods
       (CVE-2025-21807)
     - mm/khugepaged: write all dirty file folios when collapsing
     - perf trace beauty fcntl: Fix build with older kernel headers
     - ACPI: CPPC: Suppress UBSAN warning caused by field misuse
     - ACPI: NFIT: core: Fix possible NULL pointer dereference
     - [amd64] platform/x86: intel-hid: Protect ACPI notify handler against
       recursion
     - perf/core: Detach event groups during remove_on_exec
     - [amd64] drm/i915: ensure segment offset never exceeds allowed max
     - usb: gadget: function: rndis: add length check to response query
     - usb: gadget: function: rndis: add length check for header
     - iio: accel: bmc150: clamp the device-reported FIFO frame count
     - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
     - iio: adc: lpc32xx: Initialize completion before requesting IRQ
     - iio: adc: spear: Initialize completion before requesting IRQ
     - iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
     - iio: adc: ti-ads124s08: Return reset GPIO lookup errors
     - iio: backend: fix uninitialized data in debugfs
     - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
     - iio: common: st_sensors: honour channel endianness in read_axis_data
     - iio: event: Fix event FIFO reset race
     - iio: gyro: bmg160: bail out when bandwidth/filter is not in table
     - iio: gyro: bmg160: wait full startup time after mode change at probe
     - iio: imu: adis: add IRQF_NO_THREAD to non-FIFO trigger IRQ
     - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ
     - iio: imu: inv_icm42600: fix timestamp clock period by using lower value
     - iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading
     - iio: imu: st_lsm6dsx: deselect shub page before reading whoami
     - iio: light: al3010: fix incorrect scale for the highest gain range
     - iio: light: gp2ap002: fix runtime PM leak on read error
     - iio: light: opt3001: fix missing state reset on timeout
     - iio: light: tsl2591: return actual error from probe IRQ failure
     - iio: light: veml6030: fix channel type when pushing events
     - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call
     - iio: resolver: ad2s1210: notify trigger and clear state on fault read
       error
     - iio: temperature: Build mlx90635 with CONFIG_MLX90635
     - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check
     - iio: temperature: ltc2983: Fix reinit_completion() called after conversion
       start
     - ALSA: virtio: Add missing 384 kHz PCM rate mapping
     - ALSA: virtio: Validate control metadata from the device
     - ALSA: ymfpci: check snd_ctl_new1() return value
     - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
     - ALSA: cmipci: check snd_ctl_new1() return value
     - ALSA: es1938: check snd_ctl_new1() return value
     - ALSA: firewire: isight: bound the sample count to the packet payload
     - ALSA: gus: check snd_ctl_new1() return value
     - ALSA: ice1712: check snd_ctl_new1() return value
     - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
     - ALSA: usb-audio: avoid kobject path lookup in DualSense match
     - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put()
     - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch
       put callbacks
     - ALSA: usb-audio: Roll back quirk control caches on write errors
     - ALSA: usb-audio: Update Babyface Pro control caches only after successful
       writes
     - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful
       writes
     - vfio/pci: Use a private flag to prevent power state change with VFs
     - vfio/pci: Latch disable_idle_d3 per device
     - vfio/pci: Release the VGA arbiter client on register_device() failure
     - vfio/pci: Fix racy bitfields and tighten struct layout
     - vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
     - vfio: Remove device debugfs before releasing devres
     - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB
     - Bluetooth: btusb: fix use-after-free on registration failure
     - Bluetooth: btusb: fix use-after-free on marvell probe failure
     - Bluetooth: btusb: fix wakeup source leak on probe failure
     - [arm*] binder: fix UAF in binder_thread_release()
     - [arm*] binder: fix UAF in binder_free_transaction()
     - usb: xhci: Fix sleep in atomic context in xhci_free_streams()
     - usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
     - PCI: host-common: Request bus reassignment when not probe-only
     - [arm*] PCI: imx6: Fix IMX6SX_GPR12_PCIE_TEST_POWERDOWN handling
     - mm/damon/ops-common: handle extreme intervals in damon_hot_score()
     - netfilter: ipset: fix race between dump and ip_set_list resize
     - virtio_pci: fix vq info pointer lookup via wrong index
     - virtio-mmio: fix device release warning on module unload
     - hwrng: virtio: clamp device-reported used.len at copy_data()
     - USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
     - usb: dwc3: run gadget disconnect from sleepable suspend context
     - 6lowpan: fix NHC entry use-after-free on error path
     - tipc: fix out-of-bounds read in broadcast Gap ACK blocks
     - staging: vme_user: bound slave read/write to the kern_buf size
     - smb: client: restrict implied bcc[0] exemption to responses without data
       area
     - staging: vme_user: fix location monitor leak in fake bridge
     - staging: vme_user: fix location monitor leak in tsi148 bridge
     - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe
     - staging: media: atomisp: reduce load_primary_binaries() stack usage
     - staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
     - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
     - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
     - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
     - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and
       join_cmd_hdl()
     - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
     - staging: rtl8723bs: fix OOB write in HT_caps_handler()
     - crypto: amlogic - avoid double cleanup in meson_crypto_probe()
     - ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then
       SMB2_CANCEL
     - net: af_key: initialize alg_key_len for IPComp states
     - audit: Fix data races of skb_queue_len() readers on audit_queue
     - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
     - coresight: etb10: restore atomic_t for shared reading state
     - debugobjects: Plug race against a concurrent OOM disable
     - fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
     - NTB: epf: Avoid calling pci_irq_vector() from hardirq context
     - gpio: eic-sprd: use raw_spinlock_t in the irq startup path
     - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
     - netpoll: fix a use-after-free on shutdown path
     - ipv4: igmp: remove multicast group from hash table on device destruction
     - net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
     - mfd: cros_ec: Delay dev_set_drvdata() until probe success
     - mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
     - mm: shrinker: fix shrinker_info teardown race with expansion
     - mm: shrinker: fix NULL pointer dereference in debugfs
     - mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent
       softlockup
     - netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump
     - netfilter: handle unreadable frags
     - netfilter: ebtables: module names must be null-terminated
     - netfilter: ebtables: terminate table name before find_table_lock()
     - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
     - Bluetooth: bnep: pin L2CAP connection during netdev registration
     - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in
       nxp_recv_fw_req_v3()
     - Bluetooth: fix UAF in bt_accept_dequeue()
     - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
     - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
     - Bluetooth: L2CAP: validate option length before reading conf opt value
     - fs/ntfs3: rename ni_readpage_cmpr into ni_read_folio_cmpr
     - fs/ntfs3: fsync files by syncing parent inodes
     - fs/ntfs3: zero-fill folios beyond i_valid in ntfs_read_folio()
     - fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
       (CVE-2026-53027)
     - coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
     - smb/client: Fix error code in smb2_aead_req_alloc()
     - ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
     - ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
     - ksmbd: serialize QUERY_DIRECTORY requests per file
     - ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
     - ksmbd: require source read access for duplicate extents
     - ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
     - ksmbd: run set info with opener credentials
     - ksmbd: enforce FILE_READ_ATTRIBUTES on SMB_FIND_FILE_POSIX_INFORMATION
     - ksmbd: add per-handle permission check to FILE_LINK_INFORMATION
     - ksmbd: use opener credentials for delete-on-close
     - ksmbd: use opener credentials for ADS I/O
     - smb: client: fix query directory replay double-free
     - smb: client: fix query_info() replay double-free
     - smb: client: fix double-free in SMB2_ioctl() replay
     - smb: client: fix change notify replay double-free
     - smb: client: fix double-free in SMB2_flush() replay
     - smb: client: fix double-free in SMB2_open() replay
     - smb: client: fix double-free in SMB2_close() replay
     - smb: client: Fix next buffer leak in receive_encrypted_standard()
     - smb: client: use unaligned reads in parse_posix_ctxt()
     - smb: client: harden POSIX SID length parsing
     - smb: client: fix atime clamp check in read completion
     - smb: client: mask server-provided mode to 07777 in modefromsid
     - writeback: fix race between cgroup_writeback_umount() and
       inode_switch_wbs()
     - cpufreq: qcom-cpufreq-hw: Fix possible double free
     - firmware_loader: fix device reference leak in firmware_upload_register()
     - [amd64] cpufreq: intel_pstate: Sync policy->cur during CPU offline
     - sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
     - cpufreq: Fix hotplug-suspend race during reboot
     - cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
     - posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
     - clocksource/drivers/timer-tegra186: Fix support for multiple watchdog
       instances
     - X.509: Fix validation of ASN.1 certificate header
     - mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
     - tools/mm/slabinfo: Fix trace disable logic inversion
     - tools/mm/slabinfo: fix total_objects attribute name
     - HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
     - HID: wacom: stop hardware after post-start probe failures
     - HID: letsketch: fix UAF on inrange_timer at driver unbind
     - HID: lg-g15: cancel pending work on remove to fix a use-after-free
     - HID: sensor-hub: Add sensor_hub_input_attr_read_values() for multi-byte
       reads
     - hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
     - nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
     - media: mtk-jpeg: cancel workqueue on release for supported platforms only
     - serial: 8250_mid: Disable DMA for selected platforms
     - xfs: use null daddr for unset first bad log block
     - xfs: release dquot buffer after dqflush failure
     - xfs: fix unreachable BIGTIME check in dquot flush validation
     - xfs: fix pointer arithmetic error on 32-bit systems
     - xfs: fix exchmaps reservation limit check
     - bpf: Reject fragmented frames in devmap
     - bpf: Restore sysctl new-value from 1 to 0
     - bpf: Validate BTF repeated field counts before expansion
     - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
     - usb: cdc_acm: Add quirk for Uniden BC125AT scanner
     - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
     - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub
     - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume()
     - usb: free iso schedules on failed submit
     - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
     - usb: gadget: udc: Fix use-after-free in gadget_match_driver
     - usb: gadget: f_printer: take kref only for successful open
     - USB: idmouse: fix use-after-free on disconnect race
     - USB: ldusb: fix use-after-free on disconnect race
     - USB: iowarrior: fix use-after-free on disconnect
     - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD
     - USB: legousbtower: fix use-after-free on disconnect race
     - usb: sl811-hcd: disable controller wakeup on remove
     - USB: storage: include US_FL_NO_SAME in quirks mask
     - USB: misc: uss720: unregister parport on probe failure
     - usb: mtu3: unmap request DMA on queue failure
     - USB: serial: keyspan_pda: fix information leak
     - USB: serial: option: add Telit Cinterion FE990D50 compositions
     - USB: serial: digi_acceleport: fix broken rx after throttle
     - USB: serial: digi_acceleport: fix hard lockup on disconnect
     - USB: serial: digi_acceleport: fix write buffer corruption
     - USB: ulpi: fix memory leak on registration failure
     - USB: usb-storage: ene_ub6250: restore media-ready check
     - usbip: tools: support SuperSpeedPlus devices
     - usbip: vudc: fix NULL deref in vep_dequeue()
     - usb: typec: anx7411: use devm_pm_runtime_enable()
     - usb: typec: class: drop PD lookup reference
     - usb: typec: tcpm: Fix VDM type for Enter Mode commands
     - usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
     - usb: typec: ucsi: Invert DisplayPort role assignment
     - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt
       mode
     - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
     - usb: typec: ucsi: cancel pending work on system suspend
     - usb: gadget: f_fs: Fix DMA fence leak
     - block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
     - [amd64] x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU
       when SNC enabled
     - PCI: Always lift 2.5GT/s restriction in PCIe failed link retraining
     - udf: validate free block extents against the partition length
     - udf: validate VAT header length against the VAT inode size
     - udf: validate sparing table length as an entry count, not a byte count
     - hwrng: jh7110 - fix refcount leak in starfive_trng_read()
     - nvme: target: rdma: fix ndev refcount leak on queue connect
     - dm-ioctl: report an error if a device has no table
     - nvme-multipath: set BIO_REMAPPED on bios remapped to per-path namespace
       disks
     - nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
     - nvmet-auth: validate reply message payload bounds against transfer length
     - btrfs: do not trim a device which is not writeable
     - partitions: aix: bound the pp_count scan to the ppe array
     - isofs: bound Rock Ridge symlink components to the SL record
     - crypto: af_alg - Remove zero-copy support from skcipher and aead
     - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps
     - [arm64] crypto: caam - use print_hex_dump_devel to guard key hex dumps
       again
     - crypto: ecc - Fix carry overflow in vli multiplication
     - crypto: pcrypt - restore callback for non-parallel fallback
     - [amd64] crypto: ccp - Do not initialize SNP for SEV ioctls
     - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
     - [amd64] crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
     - crypto: drbg - Fix returning success on failure in CTR_DRBG
     - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels
     - crypto: drbg - Fix the fips_enabled priority boost
     - [amd64] crypto: qat - keep VFs enabled during reset
     - [amd64] crypto: qat - notify fatal error before AER reset preparation
     - [amd64] crypto: qat - protect service table iterations with service_lock
     - [amd64] crypto: qat - validate RSA CRT component lengths
     - [arm64] fpsimd: Fix type mismatch in sme_{save,load}_state()
     - spi: fsl-lpspi: replace dmaengine_terminate_all() with
       dmaengine_terminate_sync()
     - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
     - EDAC/i10nm: Don't fail probing if ADXL is missing
     - watchdog: apple: Add "apple,t8103-wdt" compatible
     - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
     - i2c: core: fix hang on adapter registration failure
     - tracing: Prevent out-of-bounds read in glob matching
     - audit: fix potential integer overflow in audit_log_n_hex()
     - NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
     - module: decompress: check return value of module_extend_max_pages()
     - exfat: bound uniname advance in exfat_find_dir_entry()
     - NTB: epf: Fix request_irq() unwind in ntb_epf_init_isr()
     - riscv: mm: Unconditionally sfence.vma for spurious fault
     - mm: fix mmap errno value when MAP_DROPPABLE is not supported
     - mm: do file ownership checks with the proper mount idmap
     - [amd64] iommu/amd: Don't split flush for amd_iommu_domain_flush_all()
     - iommufd: Set upper bounds on cache invalidation entry_num and entry_len
     - [amd64] KVM: VMX: Refresh GUEST_PENDING_DBG_EXCEPTIONS.BS on all injected
       #DBs
     - [amd64] KVM: x86: Ensure vendor's exit handler runs before fastpath
       userspace exits
     - [amd64] KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in
       guest mode
     - udmabuf: fix DMA direction mismatch in release_udmabuf()
     - dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
     - i2c: core: fix irq domain leak on adapter registration failure
     - i2c: core: fix NULL-deref on adapter registration failure
     - i2c: core: fix adapter probe deferral loop
     - i2c: core: fix adapter debugfs creation
     - i2c: core: fix adapter deregistration race
     - i2c: mpc: Fix timeout calculations
     - i2c: stm32f7: truncate clock period instead of rounding it
     - Input: synaptics-rmi4 - unregister function handlers on physical driver
       registration failure
     - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
     - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
     - Input: elan_i2c - prevent division by zero and arithmetic underflow
     - Input: goodix - clamp the device-reported contact count
     - Input: iforce - bound the device-reported force-feedback effect index
     - Input: mms114 - fix touch indexing for MMS134S and MMS136
     - Input: touchwin - reset the packet index on every complete packet
     - Input: mms114 - reject an oversized device packet size
     - Input: maplemouse - fix NULL pointer dereference in open()
     - Input: mms114 - fix multi-touch slot corruption
     - Input: maple_keyb - set driver data before registering input device
     - Input: maplemouse - set driver data before registering input device
     - Input: maplecontrol - set driver data before registering input device
     - RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
     - RDMA/siw: bound Read Response placement to the RREAD length
     - fuse: fix device node leak in cuse_process_init_reply()
     - fuse: re-lock request before returning from fuse_ref_folio()
     - fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
     - usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction
       checks
     - smb: client: reject overlapping data areas in SMB2 responses
     - xfs: fix null pointer dereference in tracepoint
     - xfs: fail recovery on a committed log item with no regions
     - xfs: resample the data fork mapping after cycling ILOCK
     - xfs: don't wrap around quota ids in dqiterate
     - xfs: set xfarray killable sort correctly
     - xfs: clamp timestamp nanoseconds correctly
     - xfs: fully check the parent handle when it points to the rootdir
     - xfs: don't zap bmbt forks if they are MAXLEVELS tall
 .
   [ Han Gao ]
   * [riscv64] set NR_CPUS to 128 (Closes: #1140651)
 .
   [ Salvatore Bonaccorso ]
   * [rt] Refresh "locking/rt: Annotate unlock followed by lock for sparse."
     (context changes)
Checksums-Sha1:
 148568b8cd6e01888f37e161883ea10524c9068b 880736 bpftool-dbgsym_7.5.0+6.12.96-1_i386.deb
 e3053ec142afbb25eadf10cfb97e825f00c54398 1612268 bpftool_7.5.0+6.12.96-1_i386.deb
 5b098ebfdbfd66c95ad7c08141a7a9133612a617 42940 hyperv-daemons-dbgsym_6.12.96-1_i386.deb
 916cb249d4eb7e45b97cfab24f78cd49b7234fc2 1322040 hyperv-daemons_6.12.96-1_i386.deb
 b6edc97df9e8aef6d39f904a593ea22f6516b613 1306016 libcpupower-dev_6.12.96-1_i386.deb
 51185a4d23f2d4943b2f30193d38140649836769 28264 libcpupower1-dbgsym_6.12.96-1_i386.deb
 ec828c4691f0035a25eb1b02ef486b86a8a0e829 1314436 libcpupower1_6.12.96-1_i386.deb
 1a0bee948c29e1e12dde7463ab12310a04dae7aa 355760 linux-cpupower-dbgsym_6.12.96-1_i386.deb
 42386d75e0bc1e4548f5682f76aa1a35b9edb0d3 1489016 linux-cpupower_6.12.96-1_i386.deb
 41fc7c2dca5b06bb797a8e570b895d1d7a25357e 1801584 linux-kbuild-6.12.96+deb13-dbgsym_6.12.96-1_i386.deb
 e3674c0aa159945181dea732c14a2750033ec4a4 1761232 linux-kbuild-6.12.96+deb13_6.12.96-1_i386.deb
 b9e615c3925a718060f177a7fea0c1e5c6f390e8 11500036 linux-perf-dbgsym_6.12.96-1_i386.deb
 bb7cf63f74a98ca49d90a3f48d07457d6d8739ea 4875536 linux-perf_6.12.96-1_i386.deb
 2160ef391cf36f397227c7747efa6bfdea403281 15587 linux_6.12.96-1_i386-buildd.buildinfo
 38297a6d90882372f0f2081e624fc7ba850d3883 100496 rtla-dbgsym_6.12.96-1_i386.deb
 0fdb0524c5701afcbb30a56200a2028717252be4 1364284 rtla_6.12.96-1_i386.deb
 f39fab4bdd2e36adb6a7626557d6149321c80e2b 138040 usbip-dbgsym_2.0+6.12.96-1_i386.deb
 249b0ed57493e10ce68a64310f728152fe4dfeb5 1342856 usbip_2.0+6.12.96-1_i386.deb
Checksums-Sha256:
 ed5d197ad7c23548445c347b180b6994fc683cba8a8e6dd5f05f8634267063a9 880736 bpftool-dbgsym_7.5.0+6.12.96-1_i386.deb
 c0f16350d6e00bd44428c62d7b50ec7a594f15ec54ad1a46fc606424d7ea4cec 1612268 bpftool_7.5.0+6.12.96-1_i386.deb
 c03bc9b35a53a8e49f7e822c950e57748d1d1d1efd55322c273347f73b747830 42940 hyperv-daemons-dbgsym_6.12.96-1_i386.deb
 1314b13c5720b7c375181f063284414f9a16f287b247f462a58c488e18d1f698 1322040 hyperv-daemons_6.12.96-1_i386.deb
 3c6524ea7f95efabe233de33817a1233dd565b3aec9712df9bce35b01e71a431 1306016 libcpupower-dev_6.12.96-1_i386.deb
 6c91ccd0d29857290e42df9b1fa1f629fb0a1b84ec8ab655c0333af49fb2962f 28264 libcpupower1-dbgsym_6.12.96-1_i386.deb
 c0313713a9170b12c2ee4369ca20bc564b4c4c6488c69a24240971a8cd0346e3 1314436 libcpupower1_6.12.96-1_i386.deb
 0a3220cb0f338de6a3755835e947559e0db2feddf8e592558bcadb42865a3ef7 355760 linux-cpupower-dbgsym_6.12.96-1_i386.deb
 79d5d155b3379f0d17d28c9f9aae19c86d9f11093a9275ad07f785c962da72bf 1489016 linux-cpupower_6.12.96-1_i386.deb
 8e00d26839d7b3785eb36a1ba8fa18ad66c551d62d2a39126c13aeed57f97db3 1801584 linux-kbuild-6.12.96+deb13-dbgsym_6.12.96-1_i386.deb
 a389e82bc545ccf46ca652aa44ab54a823c14cb9311a4ebe29f7050d576c79a4 1761232 linux-kbuild-6.12.96+deb13_6.12.96-1_i386.deb
 224106620e1d7f9ac952a67c93c937e4bcfeb23362392b6273e2d35cfa4b956b 11500036 linux-perf-dbgsym_6.12.96-1_i386.deb
 67b010c7e95986f960007381648dccd3bbd59680193626677812181a2b561f4c 4875536 linux-perf_6.12.96-1_i386.deb
 053c3a527ac68c8e5707deab170600c859b378b6c26f9841f5f8e2c225bff1bf 15587 linux_6.12.96-1_i386-buildd.buildinfo
 f14347e06f94b0ead32ebd1a6387a8e9385c9be2c94e9364ed24e0aff4881658 100496 rtla-dbgsym_6.12.96-1_i386.deb
 b7f29d9f4731189a4fb6953575ac295ec43021968715d3aae7552bb4da3d121c 1364284 rtla_6.12.96-1_i386.deb
 953f07bc857faa538e08df3da99dcbbc784b3f8dc2334eb8bbf8453e508740cb 138040 usbip-dbgsym_2.0+6.12.96-1_i386.deb
 0f1e09782271c3c52fafbb8c914dde54e00b2e05a53c3cdd51233a0c4f34d804 1342856 usbip_2.0+6.12.96-1_i386.deb
Files:
 ef40f291018be1256e35a850f6bcf782 880736 debug optional bpftool-dbgsym_7.5.0+6.12.96-1_i386.deb
 2e07be593097990162a7d5cf5c9bdc5b 1612268 devel optional bpftool_7.5.0+6.12.96-1_i386.deb
 15d73325b0cf2a433445e71e71afbed9 42940 debug optional hyperv-daemons-dbgsym_6.12.96-1_i386.deb
 65aa1f3478b203dd5208c23e3f9c336a 1322040 admin optional hyperv-daemons_6.12.96-1_i386.deb
 9e3e4199e1a8048e47f87c525aee1ebe 1306016 libdevel optional libcpupower-dev_6.12.96-1_i386.deb
 d14600782b2029b29602200678258b73 28264 debug optional libcpupower1-dbgsym_6.12.96-1_i386.deb
 269538c3b1c30882036a5c733531ff29 1314436 libs optional libcpupower1_6.12.96-1_i386.deb
 eeb89766edeb3fa60d7adcdd10f444d8 355760 debug optional linux-cpupower-dbgsym_6.12.96-1_i386.deb
 8bec0b8d6b388d6b332a5ae5ef060112 1489016 admin optional linux-cpupower_6.12.96-1_i386.deb
 87541843d91cfa5768dd60877b701d19 1801584 debug optional linux-kbuild-6.12.96+deb13-dbgsym_6.12.96-1_i386.deb
 9586593cff80f1806a298e26d41d3e47 1761232 kernel optional linux-kbuild-6.12.96+deb13_6.12.96-1_i386.deb
 bdba0d136b1eb13a337d5581766c3167 11500036 debug optional linux-perf-dbgsym_6.12.96-1_i386.deb
 995a8839bb585f81ec3a034ec61055d5 4875536 devel optional linux-perf_6.12.96-1_i386.deb
 5e29e548552e787e8886cb24d7c3d6fd 15587 kernel optional linux_6.12.96-1_i386-buildd.buildinfo
 14b487d95acf7ce4b8197fc86600a3c4 100496 debug optional rtla-dbgsym_6.12.96-1_i386.deb
 dd5e57b0d3950d7498cbc4d30e7e0159 1364284 devel optional rtla_6.12.96-1_i386.deb
 c99bd26e00b07f67cfc70ebb3dd0f9ce 138040 debug optional usbip-dbgsym_2.0+6.12.96-1_i386.deb
 8ee518592eb393ba6fd83e054f0705e5 1342856 admin optional usbip_2.0+6.12.96-1_i386.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmpd3k4ACgkQbheoBegw
XLLqMQ//XplX6XS2ZuLHDYHVRkHuV0tG0grgssqepG7X659UikJ6ee/sE6Wv9xHG
naUF9gJMfbn3d/DYnxa9p/YuguWJUBzvk36+dMg4Ycp6ade5FVSg1NKf3KeH8Mrc
7PRyLQb6xwqxLjNd+4IE2vrqTV32X/S6q/z2BtpZZh4E/E8d18MfM5+yqdOJr5j4
2LVCYYauIuJpi28D+h0KiiCSY76wok2QAbbMW+4e77pcGoiefwSzEWY1ibJ60cv4
dxmn4WtEneqF5AbKhP2O9FCj9gT6UujcTgo15hLMw7kdMgnpdwiPmnumjvQQr6Nj
M+y5vYTYrqKcw0rWnueiu182Z4ItTiG3I6yE+Xz/38GQbb1R01kAOqSlimzeU1pz
aHPbBI7BUL+ehdf58YRRy+5VBSIZ2Dxpuz1icNdHgqSUhbR3Q4dqRjTZVirMLI5s
Ylxxnk8n1DprhwzbBKCYO5Z9pRjONRUGlDBjggQTtFWjxHktcdDtOJk12GtCh1Ps
43gI27CjjYzfjDHswrjkusIcpEG/T0x5RTlSdu+QuVPAIFsuNNFvZ7wggY3HN4d+
4XZ1hf0a/Bx+uihwCxi7OVLOAuIZXk+j3BUQy0F+WO+KoHvSc6BDQejJ/bO6Lhqb
9SbzjosP+EwrNBu9oHP7ppFuSA3sdf6y775m2FTn5+ayu1lVTj8=
=F5kV
-----END PGP SIGNATURE-----
