{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* Bump kernel ABI to 28: ship the ELS kernel as linux-image-4.19.0-28-*,\n     distinct from Debian stock 4.19.0-27.\n   * Backport security fixes for CVE-2026-31431 (af_alg / AEAD):\n     - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec\n     - crypto: scatterwalk - Backport memcpy_sglist()\n     - crypto: authencesn - Do not place hiseq at end of dst for out-of-place\n       decryption\n     - crypto: authencesn - Fix src offset when decrypting in-place\n     - crypto: algif_aead - use memcpy_sglist() instead of null skcipher\n     - crypto: algif_aead - Revert to operating out-of-place\n     - crypto: algif_aead - snapshot IV for async AEAD requests\n     - crypto: authenc - use memcpy_sglist() instead of null skcipher\n     - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl\n     - crypto: algif_aead - Fix minimum RX size check for decryption\n   * Backport security fixes for CVE-2026-53043 (ocfs2/dlm out-of-bounds):\n     - ocfs2/dlm: validate qr_numregions in dlm_match_regions()\n     - ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison\n   * New upstream stable update:\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.317\n     - wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects\n     - wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()\n     - wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64\n     - wifi: iwlwifi: mvm: don't read past the mfuart notifcation\n     - ipv6: sr: block BH in seg6_output_core() and seg6_input_core()\n     - vxlan: Fix regression when dropping packets due to invalid src addresses\n     - tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB\n     - ptp: Fix error message on failed pin verification\n     - af_unix: Annotate data-race of sk->sk_state in unix_inq_len().\n     - af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll().\n     - af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg().\n     - af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG.\n     - af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen.\n     - af_unix: Use unix_recvq_full_lockless() in unix_stream_connect().\n     - af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen().\n     - af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill().\n     - usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete\n     - drm/amd/display: Handle Y carry-over in VCP X.Y calculation\n     - serial: sc16is7xx: replace hardcoded divisor value with BIT() macro\n     - serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler\n     - media: mc: mark the media devnode as registered from the, start\n     - selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages\n     - selftests/mm: conform test to TAP format output\n     - selftests/mm: compaction_test: fix bogus test success on Aarch64\n     - nilfs2: Remove check for PageError\n     - nilfs2: return the mapped address from nilfs_get_page()\n     - nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors\n     - USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages\n     - mei: me: release irq in mei_me_pci_resume error path\n     - jfs: xattr: fix buffer overflow for invalid xattr\n     - xhci: Apply reset resume quirk to Etron EJ188 xHCI host\n     - xhci: Apply broken streams quirk to Etron EJ188 xHCI host\n     - Input: try trimming too long modalias strings\n     - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING\n     - HID: core: remove unnecessary WARN_ON() in implement()\n     - iommu/amd: Fix sysfs leak in iommu init\n     - liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet\n     - drm/bridge/panel: Fix runtime warning on panel bridge release\n     - tcp: fix race in tcp_v6_syn_recv_sock()\n     - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ\n     - ipv6/route: Add a missing check on proc_dointvec\n     - net/ipv6: Fix the RT cache flush via sysctl using a previous delay\n     - drivers: core: synchronize really_probe() and dev_uevent()\n     - drm/exynos/vidi: fix memory leak in .get_modes()\n     - vmci: prevent speculation leaks by sanitizing event in event_deliver()\n     - fs/proc: fix softlockup in __read_vmcore\n     - ocfs2: use coarse time for new created files\n     - ocfs2: fix races between hole punching and AIO+DIO\n     - PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id\n     - dmaengine: axi-dmac: fix possible race in remove()\n     - intel_th: pci: Add Granite Rapids support\n     - intel_th: pci: Add Granite Rapids SOC support\n     - intel_th: pci: Add Sapphire Rapids SOC support\n     - intel_th: pci: Add Meteor Lake-S support\n     - intel_th: pci: Add Lunar Lake support\n     - nilfs2: fix potential kernel bug due to lack of writeback flag waiting\n     - hv_utils: drain the timesync packets on onchannelcallback\n     - hugetlb_encode.h: fix undefined behaviour (34 << 26)\n     - usb-storage: alauda: Check whether the media is initialized\n     - rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment\n     - batman-adv: bypass empty buckets in batadv_purge_orig_ref()\n     - scsi: qedi: Fix crash while reading debugfs attribute\n     - powerpc/pseries: Enforce hcall result buffer validity and size\n     - powerpc/io: Avoid clang null pointer arithmetic warnings\n     - usb: misc: uss720: check for incompatible versions of the Belkin F5U002\n     - udf: udftime: prevent overflow in udf_disk_stamp_to_time()\n     - PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports\n     - MIPS: Octeon: Add PCIe link status check\n     - MIPS: Routerboard 532: Fix vendor retry check code\n     - cipso: fix total option length computation\n     - netrom: Fix a memory leak in nr_heartbeat_expiry()\n     - ipv6: prevent possible NULL dereference in rt6_probe()\n     - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()\n     - virtio_net: checksum offloading handling fix\n     - net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings\n     - regulator: core: Fix modpost error \"regulator_get_regmap\" undefined\n     - dmaengine: ioatdma: Fix missing kmem_cache_destroy()\n     - ACPICA: Revert \"ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine.\"\n     - drm/radeon: fix UBSAN warning in kv_dpm.c\n     - gcov: add support for GCC 14\n     - ARM: dts: samsung: smdkv310: fix keypad no-autorepeat\n     - ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat\n     - ARM: dts: samsung: smdk4412: fix keypad no-autorepeat\n     - selftests/ftrace: Fix checkbashisms errors\n     - tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test\n     - perf/core: Fix missing wakeup when waiting for context reference\n     - PCI: Add PCI_ERROR_RESPONSE and related definitions\n     - x86/amd_nb: Check for invalid SMN reads\n     - iio: dac: ad5592r-base: Replace indio_dev->mlock with own device lock\n     - iio: dac: ad5592r: un-indent code-block for scale read\n     - iio: dac: ad5592r: fix temperature channel scaling value\n     - scsi: mpt3sas: Add ioc_<level> logging macros\n     - scsi: mpt3sas: Gracefully handle online firmware update\n     - scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory\n     - xhci: Use soft retry to recover faster from transaction errors\n     - xhci: Set correct transferred length for cancelled bulk transfers\n     - usb: xhci: do not perform Soft Retry for some xHCI hosts\n     - pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER\n     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins\n     - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins\n     - pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set\n     - drm/amdgpu: fix UBSAN warning in kv_dpm.c\n     - netfilter: nf_tables: validate family when identifying table via handle\n     - ASoC: fsl-asoc-card: set priv->pdev before using it\n     - netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers\n     - drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep\n     - net/iucv: Avoid explicit cpumask var allocation on stack\n     - ALSA: emux: improve patch ioctl data validation\n     - media: dvbdev: Initialize sbuf\n     - soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message\n     - nvme: fixup comment for nvme RDMA Provider Type\n     - gpio: davinci: Validate the obtained number of IRQs\n     - i2c: ocores: stop transfer on timeout\n     - i2c: ocores: set IACK bit after core is enabled\n     - x86: stop playing stack games in profile_pc()\n     - mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos\n     - iio: adc: ad7266: Fix variable checking bug\n     - iio: chemical: bme680: Fix pressure value output\n     - iio: chemical: bme680: Fix calibration data variable\n     - iio: chemical: bme680: Fix overflows in compensate() functions\n     - iio: chemical: bme680: Fix sensor data read operation\n     - net: usb: ax88179_178a: improve link status logs\n     - usb: gadget: printer: SS+ support\n     - usb: musb: da8xx: fix a resource leak in probe()\n     - usb: atm: cxacru: fix endpoint checking in cxacru_bind()\n     - tty: mcf: MCF54418 has 10 UARTS\n     - hexagon: fix fadvise64_64 calling conventions\n     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes\n     - drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes\n     - batman-adv: Don't accept TT entries for out-of-spec VIDs\n     - ata: libata-core: Fix double free on error\n     - ftruncate: pass a signed offset\n     - pwm: stm32: Refuse too small period requests\n     - ipv6: annotate some data-races around sk->sk_prot\n     - ipv6: Fix data races around sk->sk_prot.\n     - tcp: Fix data races around icsk->icsk_af_ops.\n     - arm64: dts: rockchip: Add sound-dai-cells for RK3368\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.318\n     - asm-generic: Move common compat types to asm-generic/compat.h\n     - media: dvb: as102-fe: Fix as10x_register_addr packing\n     - media: dvb-usb: dib0700_devices: Add missing release_firmware()\n     - IB/core: Implement a limit on UMAD receive List\n     - drm/amd/display: Skip finding free audio for unknown engine_id\n     - media: dw2102: Don't translate i2c read into write\n     - sctp: prefer struct_size over open coded arithmetic\n     - firmware: dmi: Stop decoding on broken entry\n     - Input: ff-core - prefer struct_size over open coded arithmetic\n     - net: dsa: mv88e6xxx: Correct check for empty list\n     - media: dvb-frontends: tda18271c2dd: Remove casting during div\n     - media: s2255: Use refcount_t instead of atomic_t for num_channels\n     - media: dvb-frontends: tda10048: Fix integer overflow\n     - i2c: i801: Annotate apanel_addr as __ro_after_init\n     - powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n\n     - orangefs: fix out-of-bounds fsid access\n     - powerpc/xmon: Check cpu id in commands \"c#\", \"dp#\" and \"dx#\"\n     - jffs2: Fix potential illegal address access in jffs2_free_inode\n     - s390/pkey: Wipe sensitive data on failure\n     - tcp: take care of compressed acks in tcp_add_reno_sack()\n     - tcp: tcp_mark_head_lost is only valid for sack-tcp\n     - tcp: add ece_ack flag to reno sack functions\n     - net: tcp better handling of reordering then loss cases\n     - UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open()\n     - tcp_metrics: validate source addr length\n     - bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set()\n     - selftests: fix OOM in msg_zerocopy selftest\n     - selftests: make order checking verbose in msg_zerocopy selftest\n     - inet_diag: Initialize pad field in struct inet_diag_req_v2\n     - nilfs2: fix inode number range checks\n     - nilfs2: add missing check for inode numbers on directory entries\n     - mm: optimize the redundant loop of mm_update_owner_next()\n     - Bluetooth: Fix incorrect pointer arithmatic in ext_adv_report_evt\n     - can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct\n     - fsnotify: Do not generate events for O_PATH file descriptors\n     - Revert \"mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again\"\n     - drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes\n     - drm/amdgpu/atomfirmware: silence UBSAN warning\n     - bnx2x: Fix multiple UBSAN array-index-out-of-bounds\n     - media: dw2102: fix a potential buffer overflow\n     - i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr\n     - nilfs2: fix incorrect inode allocation from reserved inodes\n     - drm/i915: make find_fw_domain work on intel_uncore\n     - tcp: fix incorrect undo caused by DSACK of TLP retransmit\n     - net: lantiq_etop: add blank line after declaration\n     - net: ethernet: lantiq_etop: fix double free in detach\n     - ppp: reject claimed-as-LCP but actually malformed packets\n     - ARM: davinci: Convert comma to semicolon\n     - USB: serial: option: add Telit generic core-dump composition\n     - USB: serial: option: add Telit FN912 rmnet compositions\n     - USB: serial: option: add Fibocom FM350-GL\n     - USB: serial: option: add support for Foxconn T99W651\n     - USB: serial: option: add Netprisma LCUK54 series modules\n     - USB: serial: option: add Rolling RW350-GL variants\n     - USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k\n     - usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()\n     - USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor\n     - hpet: Support 32-bit userspace\n     - libceph: fix race between delayed_work() and ceph_monc_stop()\n     - tcp: refactor tcp_retransmit_timer()\n     - net: tcp: fix unexcepted socket die when snd_wnd is 0\n     - tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()\n     - tcp: avoid too many retransmit packets\n     - SUNRPC: Fix RPC client cleaned up the freed pipefs dentries\n     - nilfs2: fix kernel bug on rename operation of broken directory\n     - i2c: rcar: bring hardware to known state when probing\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.319\n     - gcc-plugins: Rename last_stmt() for GCC 14+\n     - scsi: qedf: Set qed_slowpath_params to zero before use\n     - ACPI: EC: Abort address space access upon error\n     - ACPI: EC: Avoid returning AE_OK on errors in address space handler\n     - wifi: mac80211: mesh: init nonpeer_pm to active by default in mesh sdata\n     - wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()\n     - Input: silead - Always support 10 fingers\n     - ila: block BH in ila_output()\n     - kconfig: gconf: give a proper initial state to the Save button\n     - kconfig: remove wrong expr_trans_bool()\n     - fs/file: fix the check in find_next_fd()\n     - mei: demote client disconnect warning on suspend to debug\n     - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check\n     - Input: elantech - fix touchpad state on resume for Lenovo N24\n     - bytcr_rt5640 : inverse jack detect for Archos 101 cesium\n     - can: kvaser_usb: fix return value for hif_usb_send_regout\n     - s390/sclp: Fix sclp_init() cleanup on failure\n     - ALSA: dmaengine_pcm: terminate dmaengine before synchronize\n     - net: usb: qmi_wwan: add Telit FN912 compositions\n     - net: mac802154: Fix racy device stats updates by DEV_STATS_INC() and DEV_STATS_ADD()\n     - Bluetooth: hci_core: cancel all works upon hci_unregister_dev()\n     - fs: better handle deep ancestor chains in is_subdir()\n     - spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices\n     - selftests/vDSO: fix clang build errors and warnings\n     - hfsplus: fix uninit-value in copy_name\n     - filelock: Remove locks reliably when fcntl/close race is detected\n     - ARM: 9324/1: fix get_user() broken with veneer\n     - ACPI: processor_idle: Fix invalid comparison with insertion sort for latency\n     - net: relax socket state check at accept time.\n     - ocfs2: add bounds checking to ocfs2_check_dir_entry()\n     - jfs: don't walk off the end of ealist\n     - filelock: Fix fcntl/close race recovery compat path\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.320\n     - platform/chrome: cros_ec_debugfs: fix wrong EC message version\n     - hfsplus: fix to avoid false alarm of circular locking\n     - x86/of: Return consistent error type from x86_of_pci_irq_enable()\n     - x86/pci/intel_mid_pci: Fix PCIBIOS_* return code handling\n     - x86/pci/xen: Fix PCIBIOS_* return code handling\n     - x86/platform/iosf_mbi: Convert PCIBIOS_* return codes to errnos\n     - hwmon: (adt7475) Fix default duty on fan is disabled\n     - pwm: stm32: Always do lazy disabling\n     - hwmon: (max6697) Fix underflow when writing limit attributes\n     - hwmon: Introduce SENSOR_DEVICE_ATTR_{RO, RW, WO} and variants\n     - hwmon: (max6697) Auto-convert to use SENSOR_DEVICE_ATTR_{RO, RW, WO}\n     - hwmon: (max6697) Fix swapped temp{1,8} critical alarms\n     - arm64: dts: rockchip: Increase VOP clk rate on RK3328\n     - m68k: atari: Fix TT bootup freeze / unexpected (SCU) interrupt messages\n     - x86/xen: Convert comma to semicolon\n     - m68k: cmpxchg: Fix return value for default case in __arch_xchg()\n     - wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device\n     - net/smc: Allow SMC-D 1MB DMB allocations\n     - net/smc: set rmb's SG_MAX_SINGLE_ALLOC limitation only when CONFIG_ARCH_NO_SG_CHAIN is defined\n     - selftests/bpf: Check length of recv in test_sockmap\n     - wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()\n     - wifi: cfg80211: handle 2x996 RU allocation in cfg80211_calculate_bitrate_he()\n     - net: fec: Refactor: #define magic constants\n     - net: fec: Fix FEC_ECR_EN1588 being cleared on link-down\n     - ipvs: Avoid unnecessary calls to skb_is_gso_sctp\n     - perf: Fix perf_aux_size() for greater-than 32-bit size\n     - perf: Prevent passing zero nr_pages to rb_alloc_aux()\n     - bna: adjust 'name' buf size of bna_tcb and bna_ccb structures\n     - selftests: forwarding: devlink_lib: Wait for udev events after reloading\n     - media: imon: Fix race getting ictx->lock\n     - saa7134: Unchecked i2c_transfer function result fixed\n     - media: uvcvideo: Allow entity-defined get_info and get_cur\n     - media: uvcvideo: Override default flags\n     - media: renesas: vsp1: Fix _irqsave and _irq mix\n     - media: renesas: vsp1: Store RPF partition configuration per RPF instance\n     - leds: trigger: Unregister sysfs attributes before calling deactivate()\n     - perf report: Fix condition in sort__sym_cmp()\n     - drm/etnaviv: fix DMA direction handling for cached RW buffers\n     - mfd: omap-usb-tll: Use struct_size to allocate tll\n     - ext4: avoid writing unitialized memory to disk in EA inodes\n     - sparc64: Fix incorrect function signature and add prototype for prom_cif_init\n     - PCI: Equalize hotplug memory and io for occupied and empty slots\n     - PCI: Fix resource double counting on remove & rescan\n     - RDMA/mlx4: Fix truncated output warning in mad.c\n     - RDMA/mlx4: Fix truncated output warning in alias_GUID.c\n     - RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs\n     - mtd: make mtd_test.c a separate module\n     - Input: elan_i2c - do not leave interrupt disabled on suspend failure\n     - MIPS: Octeron: remove source file executable bit\n     - powerpc/xmon: Fix disassembly CPU feature checks\n     - macintosh/therm_windtunnel: fix module unload.\n     - bnxt_re: Fix imm_data endianness\n     - ice: Rework flex descriptor programming\n     - netfilter: ctnetlink: use helper function to calculate expect ID\n     - pinctrl: core: fix possible memory leak when pinctrl_enable() fails\n     - pinctrl: single: fix possible memory leak when pinctrl_enable() fails\n     - pinctrl: ti: ti-iodelay: Drop if block with always false condition\n     - pinctrl: ti: ti-iodelay: fix possible memory leak when pinctrl_enable() fails\n     - pinctrl: freescale: mxs: Fix refcount of child\n     - fs/nilfs2: remove some unused macros to tame gcc\n     - nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro\n     - tick/broadcast: Make takeover of broadcast hrtimer reliable\n     - net: netconsole: Disable target before netpoll cleanup\n     - af_packet: Handle outgoing VLAN packets without hardware offloading\n     - ipv6: take care of scope when choosing the src addr\n     - char: tpm: Fix possible memory leak in tpm_bios_measurements_open()\n     - media: venus: fix use after free in vdec_close\n     - hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode()\n     - drm/gma500: fix null pointer dereference in cdv_intel_lvds_get_modes\n     - drm/gma500: fix null pointer dereference in psb_intel_lvds_get_modes\n     - m68k: amiga: Turn off Warp1260 interrupts during boot\n     - ext4: check dot and dotdot of dx_root before making dir indexed\n     - ext4: make sure the first directory block is not a hole\n     - wifi: mwifiex: Fix interface type change\n     - leds: ss4200: Convert PCIBIOS_* return codes to errnos\n     - tools/memory-model: Fix bug in lock.cat\n     - hwrng: amd - Convert PCIBIOS_* return codes to errnos\n     - PCI: hv: Return zero, not garbage, when reading PCI_INTERRUPT_PIN\n     - binder: fix hang of unregistered readers\n     - scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for ELS cmds\n     - f2fs: fix to don't dirty inode for readonly filesystem\n     - clk: davinci: da8xx-cfgchip: Initialize clk_init_data before use\n     - ubi: eba: properly rollback inside self_check_eba\n     - decompress_bunzip2: fix rare decompression failure\n     - kobject_uevent: Fix OOB access within zap_modalias_env()\n     - rtc: cmos: Fix return value of nvmem callbacks\n     - scsi: qla2xxx: During vport delete send async logout explicitly\n     - scsi: qla2xxx: validate nvme_local_port correctly\n     - perf/x86/intel/pt: Fix topa_entry base length\n     - watchdog/perf: properly initialize the turbo mode timestamp and rearm counter\n     - platform: mips: cpu_hwmon: Disable driver on unsupported hardware\n     - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs\n     - selftests/sigaltstack: Fix ppc64 GCC build\n     - nilfs2: handle inconsistent state in nilfs_btnode_create_block()\n     - kdb: Fix bound check compiler warning\n     - kdb: address -Wformat-security warnings\n     - kdb: Use the passed prompt in kdb_position_cursor()\n     - jfs: Fix array-index-out-of-bounds in diFree\n     - dma: fix call order in dmam_free_coherent\n     - MIPS: SMP-CPS: Fix address for GCR_ACCESS register for CM3 and later\n     - net: ip_rt_get_source() - use new style struct initializer instead of memset\n     - ipv4: Fix incorrect source address in Record Route option\n     - net: bonding: correctly annotate RCU in bond_should_notify_peers()\n     - tipc: Return non-zero value from tipc_udp_addr2str() on error\n     - mISDN: Fix a use after free in hfcmulti_tx()\n     - mm: avoid overflows in dirty throttling logic\n     - PCI: rockchip: Make 'ep-gpios' DT property optional\n     - PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio\n     - parport: parport_pc: Mark expected switch fall-through\n     - parport: Convert printk(KERN_<LEVEL> to pr_<level>(\n     - parport: Standardize use of printmode\n     - dev/parport: fix the array out-of-bounds risk\n     - driver core: Cast to (void *) with __force for __percpu pointer\n     - devres: Fix memory leakage caused by driver API devm_free_percpu()\n     - perf/x86/intel/pt: Export pt_cap_get()\n     - perf/x86/intel/pt: Use helpers to obtain ToPA entry size\n     - perf/x86/intel/pt: Use pointer arithmetics instead in ToPA entry calculation\n     - perf/x86/intel/pt: Split ToPA metadata and page layout\n     - perf/x86/intel/pt: Fix a topa_entry base address calculation\n     - remoteproc: imx_rproc: ignore mapping vdev regions\n     - remoteproc: imx_rproc: Fix ignoring mapping vdev regions\n     - remoteproc: imx_rproc: Skip over memory region when node value is NULL\n     - drm/vmwgfx: Fix overlay when using Screen Targets\n     - net/iucv: fix use after free in iucv_sock_close()\n     - ipv6: fix ndisc_is_useropt() handling for PIO\n     - protect the fetch of ->fd[fd] in do_dup2() from mispredictions\n     - ALSA: usb-audio: Correct surround channels in UAC1 channel map\n     - net: usb: sr9700: fix uninitialized variable use in sr_mdio_read\n     - irqchip/mbigen: Fix mbigen node address layout\n     - x86/mm: Fix pti_clone_pgtable() alignment assumption\n     - net: usb: qmi_wwan: fix memory leak for not ip packets\n     - net: linkwatch: use system_unbound_wq\n     - Bluetooth: l2cap: always unlock channel in l2cap_conless_channel()\n     - net: fec: Stop PPS on driver remove\n     - md/raid5: avoid BUG_ON() while continue reshape after reassembling\n     - clocksource/drivers/sh_cmt: Address race condition for clock events\n     - PCI: Add Edimax Vendor ID to pci_ids.h\n     - udf: prevent integer overflow in udf_bitmap_free_blocks()\n     - wifi: nl80211: don't give key data to userspace\n     - btrfs: fix bitmap leak when loading free space cache on duplicate entry\n     - media: uvcvideo: Ignore empty TS packets\n     - media: uvcvideo: Fix the bandwdith quirk on USB 3.x\n     - jbd2: avoid memleak in jbd2_journal_write_metadata_buffer\n     - s390/sclp: Prevent release of buffer in I/O\n     - SUNRPC: Fix a race to wake a sync task\n     - ext4: fix wrong unit use in ext4_mb_find_by_goal\n     - arm64: Add support for SB barrier and patch in over DSB; ISB sequences\n     - arm64: cpufeature: Force HWCAP to be based on the sysreg visible to user-space\n     - arm64: Add Neoverse-V2 part\n     - arm64: cputype: Add Cortex-X4 definitions\n     - arm64: cputype: Add Neoverse-V3 definitions\n     - arm64: errata: Add workaround for Arm errata 3194386 and 3312417\n     - arm64: cputype: Add Cortex-X3 definitions\n     - arm64: cputype: Add Cortex-A720 definitions\n     - arm64: cputype: Add Cortex-X925 definitions\n     - arm64: errata: Unify speculative SSBS errata logic\n     - arm64: errata: Expand speculative SSBS workaround\n     - arm64: cputype: Add Cortex-X1C definitions\n     - arm64: cputype: Add Cortex-A725 definitions\n     - arm64: errata: Expand speculative SSBS workaround (again)\n     - i2c: smbus: Don't filter out duplicate alerts\n     - i2c: smbus: Improve handling of stuck alerts\n     - i2c: smbus: Send alert notifications to all devices if source not found\n     - bpf: kprobe: remove unused declaring of bpf_kprobe_override\n     - spi: lpspi: Replace all \"master\" with \"controller\"\n     - spi: lpspi: Add slave mode support\n     - spi: lpspi: Let watermark change with send data length\n     - spi: lpspi: Add i.MX8 boards support for lpspi\n     - spi: lpspi: add the error info of transfer speed setting\n     - spi: fsl-lpspi: remove unneeded array\n     - spi: spi-fsl-lpspi: Fix scldiv calculation\n     - ALSA: line6: Fix racy access to midibuf\n     - usb: vhci-hcd: Do not drop references before new references are gained\n     - USB: serial: debug: do not echo input by default\n     - usb: gadget: core: Check for unset descriptor\n     - scsi: ufs: core: Fix hba->last_dme_cmd_tstamp timestamp updating logic\n     - tick/broadcast: Move per CPU pointer access into the atomic section\n     - ntp: Clamp maxerror and esterror to operating range\n     - driver core: Fix uevent_show() vs driver detach race\n     - ntp: Safeguard against time_constant overflow\n     - serial: core: check uartclk for zero to avoid divide by zero\n     - power: supply: axp288_charger: Fix constant_charge_voltage writes\n     - power: supply: axp288_charger: Round constant_charge_voltage writes down\n     - tracing: Fix overflow in get_free_elt()\n     - x86/mtrr: Check if fixed MTRRs exist before saving them\n     - drm/bridge: analogix_dp: properly handle zero sized AUX transactions\n     - drm/mgag200: Set DDC timeout in milliseconds\n     - kbuild: Fix '-S -c' in x86 stack protector scripts\n     - netfilter: nf_tables: set element extended ACK reporting support\n     - netfilter: nf_tables: use timestamp to check for set element timeout\n     - netfilter: nf_tables: prefer nft_chain_validate\n     - arm64: cpufeature: Fix the visibility of compat hwcaps\n     - media: uvcvideo: Use entity get_cur in uvc_ctrl_set\n     - drm/i915/gem: Fix Virtual Memory mapping boundaries calculation\n     - exec: Fix ToCToU between perm check and set-uid/gid usage\n     - nvme/pci: Add APST quirk for Lenovo N60z laptop\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.321\n     - fuse: Initialize beyond-EOF page contents before setting uptodate\n     - ALSA: usb-audio: Support Yamaha P-125 quirk entry\n     - xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration\n     - arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to NUMA_NO_NODE\n     - dm resume: don't return EINVAL when signalled\n     - dm persistent data: fix memory allocation failure\n     - bitmap: introduce generic optimized bitmap_size()\n     - fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE\n     - selinux: fix potential counting error in avc_add_xperms_decision()\n     - drm/amdgpu: Actually check flags for all context ops.\n     - memcg_write_event_control(): fix a user-triggerable oops\n     - s390/cio: rename bitmap_size() -> idset_bitmap_size()\n     - overflow.h: Add flex_array_size() helper\n     - overflow: Implement size_t saturating arithmetic helpers\n     - btrfs: rename bitmap_set_bits() -> btrfs_bitmap_set_bits()\n     - net/mlx5e: Correctly report errors for ethtool rx flows\n     - atm: idt77252: prevent use after free in dequeue_rx()\n     - net: dsa: vsc73xx: pass value in phy_write operation\n     - ssb: Fix division by zero issue in ssb_calc_clock_rate\n     - wifi: cw1200: Avoid processing an invalid TIM IE\n     - i2c: riic: avoid potential division by zero\n     - staging: ks7010: disable bh on tx_dev_lock\n     - binfmt_misc: cleanup on filesystem umount\n     - scsi: spi: Fix sshdr use\n     - gfs2: setattr_chown: Add missing initialization\n     - wifi: iwlwifi: abort scan when rfkill on but device enabled\n     - powerpc/xics: Check return value of kasprintf in icp_native_map_one_cpu\n     - ext4: do not trim the group with corrupted block bitmap\n     - quota: Remove BUG_ON from dqget()\n     - media: pci: cx23885: check cx23885_vdev_init() return\n     - fs: binfmt_elf_efpic: don't use missing interpreter's properties\n     - scsi: lpfc: Initialize status local variable in lpfc_sli4_repost_sgl_list()\n     - net/sun3_82586: Avoid reading past buffer in debug output\n     - md: clean up invalid BUG_ON in md_ioctl\n     - parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367\n     - powerpc/boot: Handle allocation failure in simple_realloc()\n     - powerpc/boot: Only free if realloc() succeeds\n     - btrfs: change BUG_ON to assertion when checking for delayed_node root\n     - btrfs: handle invalid root reference found in may_destroy_subvol()\n     - btrfs: send: handle unexpected data in header buffer in begin_cmd()\n     - btrfs: delete pointless BUG_ON check on quota root in btrfs_qgroup_account_extent()\n     - f2fs: fix to do sanity check in update_sit_entry\n     - usb: gadget: fsl: Increase size of name buffer for endpoints\n     - Bluetooth: bnep: Fix out-of-bound access\n     - NFS: avoid infinite loop in pnfs_update_layout.\n     - openrisc: Call setup_memory() earlier in the init sequence\n     - s390/iucv: fix receive buffer virtual vs physical address confusion\n     - usb: dwc3: core: Skip setting event buffers for host only controllers\n     - irqchip/gic-v3-its: Remove BUG_ON in its_vpe_irq_domain_alloc\n     - ext4: set the type of max_zeroout to unsigned int to avoid overflow\n     - nvmet-rdma: fix possible bad dereference when freeing rsps\n     - hrtimer: Prevent queuing of hrtimer without a function callback\n     - gtp: pull network headers in gtp_dev_xmit()\n     - block: use \"unsigned long\" for blk_validate_block_size().\n     - Bluetooth: Make use of __check_timeout on hci_sched_le\n     - Bluetooth: hci_core: Fix not handling link timeouts propertly\n     - Bluetooth: hci_core: Fix LE quote calculation\n     - kcm: Serialise kcm_sendmsg() for the same socket.\n     - netfilter: nft_counter: Synchronize nft_counter_reset() against reader.\n     - ipv6: prevent UAF in ip6_send_skb()\n     - net: xilinx: axienet: Always disable promiscuous mode\n     - drm/msm: use drm_debug_enabled() to check for debug categories\n     - drm/msm/dpu: don't play tricks with debug macros\n     - mmc: mmc_test: Fix NULL dereference on allocation failure\n     - Bluetooth: MGMT: Add error handling to pair_device()\n     - HID: wacom: Defer calculation of resolution until resolution_code is known\n     - cxgb4: add forgotten u64 ivlan cast before shift\n     - mmc: dw_mmc: allow biu and ciu clocks to defer\n     - ALSA: timer: Relax start tick time check for slave timer elements\n     - Bluetooth: hci_ldisc: check HCI_UART_PROTO_READY flag in HCIUARTGETPROTO\n     - Input: MT - limit max slots\n     - tools: move alignment-related macros to new <linux/align.h>\n     - drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc\n     - pinctrl: single: fix potential NULL dereference in pcs_get_function()\n     - wifi: mwifiex: duplicate static structs used in driver instances\n     - dm suspend: return -ERESTARTSYS instead of -EINTR\n     - scsi: mpt3sas: Avoid IOMMU page faults on REPORT ZONES\n     - filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64\n     - media: uvcvideo: Fix integer overflow calculating timestamp\n     - ata: libata-core: Fix null pointer dereference on error\n     - cgroup/cpuset: Prevent UAF in proc_cpuset_show()\n     - memcg: enable accounting of ipc resources\n     - fbcon: Prevent that screen size is smaller than font size\n     - fbmem: Check virtual screen sizes in fb_set_var()\n     - net:rds: Fix possible deadlock in rds_message_put\n     - ida: Fix crash in ida_free when the bitmap is empty\n     - net: prevent mss overflow in skb_segment()\n     - soundwire: stream: fix programming slave ports for non-continous port maps\n     - gtp: fix a potential NULL pointer dereference\n     - net: busy-poll: use ktime_get_ns() instead of local_clock()\n     - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller\n     - USB: serial: option: add MeiG Smart SRM825L\n     - usb: dwc3: omap: add missing depopulate in probe error path\n     - usb: dwc3: core: Prevent USB core invalid event buffer address access\n     - usb: dwc3: st: fix probed platform device ref count on probe error path\n     - usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in remove_power_attributes()\n     - scsi: aacraid: Fix double-free on probe failure\n     - ipc: remove memcg accounting for sops objects in do_semtimedop()\n     - drm/fb-helper: set x/yres_virtual in drm_fb_helper_check_var\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.322\n     - net: usb: qmi_wwan: add MeiG Smart SRM825L\n     - usb: dwc3: st: Add of_node_put() before return in probe function\n     - usb: dwc3: st: add missing depopulate in probe error path\n     - drm/amdgpu: Fix uninitialized variable warning in amdgpu_afmt_acr\n     - drm/amdgpu: fix overflowed array index read warning\n     - drm/amdgpu: fix ucode out-of-bounds read warning\n     - drm/amdgpu: fix mc_data out-of-bounds read warning\n     - drm/amdkfd: Reconcile the definition and use of oem_id in struct kfd_topology_device\n     - apparmor: fix possible NULL pointer dereference\n     - usbip: Don't submit special requests twice\n     - smack: tcp: ipv4, fix incorrect labeling\n     - media: uvcvideo: Enforce alignment of frame and interval\n     - block: initialize integrity buffer to zero before writing it to media\n     - virtio_net: Fix napi_skb_cache_put warning\n     - udf: Limit file size to 4TB\n     - ALSA: usb-audio: Sanity checks for each pipe and EP types\n     - ALSA: usb-audio: Fix gpf in snd_usb_pipe_sanity_check\n     - sch/netem: fix use after free in netem_dequeue\n     - ALSA: hda/conexant: Add pincfg quirk to enable top speakers on Sirius devices\n     - ata: libata: Fix memory leak for error path in ata_host_alloc()\n     - mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\n     - fuse: use unsigned type for getxattr/listxattr size truncation\n     - clk: qcom: clk-alpha-pll: Fix the pll post div mask\n     - nilfs2: fix missing cleanup on rollforward recovery error\n     - nilfs2: fix state management in error path of log writing function\n     - ALSA: hda: Add input value sanity checks to HDMI channel map controls\n     - smack: unix sockets: fix accept()ed socket label\n     - irqchip/armada-370-xp: Do not allow mapping IRQ 0 and 1\n     - af_unix: Remove put_pid()/put_cred() in copy_peercred().\n     - netfilter: nf_conncount: fix wrong variable type\n     - udf: Avoid excessive partition lengths\n     - wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3\n     - media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse\n     - pcmcia: Use resource_size function on resource object\n     - can: bcm: Remove proc entry when dev is unregistered.\n     - igb: Fix not clearing TimeSync interrupts for 82580\n     - platform/x86: dell-smbios: Fix error path in dell_smbios_init()\n     - cx82310_eth: re-enable ethernet mode after router reboot\n     - drivers/net/usb: Remove all strcpy() uses\n     - net: usb: don't write directly to netdev->dev_addr\n     - usbnet: modern method to get random MAC\n     - rfkill: fix spelling mistake contidion to condition\n     - net: bridge: add support for sticky fdb entries\n     - bridge: switchdev: Allow clearing FDB entry offload indication\n     - net: bridge: fdb: convert is_local to bitops\n     - net: bridge: fdb: convert is_static to bitops\n     - net: bridge: fdb: convert is_sticky to bitops\n     - net: bridge: fdb: convert added_by_user to bitops\n     - net: bridge: fdb: convert added_by_external_learn to use bitops\n     - net: bridge: br_fdb_external_learn_add(): always set EXT_LEARN\n     - net: dsa: vsc73xx: fix possible subblocks range of CAPT block\n     - iommu/vt-d: Handle volatile descriptor status read\n     - cgroup: Protect css->cgroup write under css_set_lock\n     - um: line: always fill *error_out in setup_one_line()\n     - devres: Initialize an uninitialized struct member\n     - pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv\n     - hwmon: (adc128d818) Fix underflows seen when writing limit attributes\n     - hwmon: (lm95234) Fix underflows seen when writing limit attributes\n     - hwmon: (nct6775-core) Fix underflows seen when writing limit attributes\n     - hwmon: (w83627ehf) Fix underflows seen when writing limit attributes\n     - wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()\n     - smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()\n     - btrfs: replace BUG_ON with ASSERT in walk_down_proc()\n     - btrfs: clean up our handling of refs == 0 in snapshot delete\n     - PCI: Add missing bridge lock to pci_bus_lock()\n     - btrfs: initialize location to fix -Wmaybe-uninitialized in btrfs_lookup_dentry()\n     - HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup\n     - Input: uinput - reject requests with unreasonable number of slots\n     - usbnet: ipheth: race between ipheth_close and error handling\n     - Squashfs: sanity check symbolic link size\n     - of/irq: Prevent device address out-of-bounds read in interrupt map walk\n     - ata: pata_macio: Use WARN instead of BUG\n     - iio: buffer-dmaengine: fix releasing dma channel on error\n     - iio: fix scale application in iio_convert_raw_to_processed_unlocked\n     - nvmem: Fix return type of devm_nvmem_device_get() in kerneldoc\n     - uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind\n     - Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic\n     - VMCI: Fix use-after-free when removing resource in vmci_resource_remove()\n     - clocksource/drivers/imx-tpm: Fix return -ETIME when delta exceeds INT_MAX\n     - clocksource/drivers/imx-tpm: Fix next event not taking effect sometime\n     - uprobes: Use kzalloc to allocate xol area\n     - ring-buffer: Rename ring_buffer_read() to read_buffer_iter_advance()\n     - tracing: Avoid possible softlockup in tracing_iter_reset()\n     - nilfs2: replace snprintf in show functions with sysfs_emit\n     - nilfs2: protect references to superblock parameters exposed in sysfs\n     - netns: add pre_exit method to struct pernet_operations\n     - ila: call nf_unregister_net_hooks() sooner\n     - ACPI: processor: Return an error if acpi_processor_get_info() fails in processor_add()\n     - ACPI: processor: Fix memory leaks in error paths of processor_add()\n     - drm/i915/fence: Mark debug_fence_init_onstack() with __maybe_unused\n     - drm/i915/fence: Mark debug_fence_free() with __maybe_unused\n     - rtmutex: Drop rt_mutex::wait_lock before scheduling\n     - net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket\n     - cx82310_eth: fix error return code in cx82310_bind()\n     - netns: restore ops before calling ops_exit_list\n     - Revert \"parisc: Use irq_enter_rcu() to fix warning at kernel/context_tracking.c:367\"\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.323\n     - staging: iio: frequency: ad9833: Get frequency value statically\n     - staging: iio: frequency: ad9833: Load clock using clock framework\n     - staging: iio: frequency: ad9834: Validate frequency parameter value\n     - usbnet: ipheth: fix carrier detection in modes 1 and 4\n     - net: ethernet: use ip_hdrlen() instead of bit shift\n     - net: phy: vitesse: repair vsc73xx autonegotiation\n     - scripts: kconfig: merge_config: config files: add a trailing newline\n     - arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO hog on RK3399 Puma\n     - net/mlx5: Update the list of the PCI supported devices\n     - net: ftgmac100: Enable TX interrupt to avoid TX timeout\n     - net: dpaa: Pad packets to ETH_ZLEN\n     - soundwire: stream: Revert \"soundwire: stream: fix programming slave ports for non-continous port maps\"\n     - selftests/vm: remove call to ksft_set_plan()\n     - selftests/kcmp: remove call to ksft_set_plan()\n     - ASoC: allow module autoloading for table db1200_pids\n     - pinctrl: at91: make it work with current gpiolib\n     - microblaze: don't treat zero reserved memory regions as error\n     - net: ftgmac100: Ensure tx descriptor updates are visible\n     - wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()\n     - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead\n     - ASoC: tda7419: fix module autoloading\n     - spi: bcm63xx: Enable module autoloading\n     - x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides frequency\n     - ocfs2: add bounds checking to ocfs2_xattr_find_entry()\n     - ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry()\n     - gpio: prevent potential speculation leaks in gpio_device_get_desc()\n     - USB: serial: pl2303: add device id for Macrosilicon MS3020\n     - ACPI: PMIC: Remove unneeded check in tps68470_pmic_opregion_probe()\n     - wifi: ath9k: fix parameter check in ath9k_init_debug()\n     - wifi: ath9k: Remove error checks when creating debugfs entries\n     - netfilter: nf_tables: elements with timeout below CONFIG_HZ never expire\n     - wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()\n     - wifi: cfg80211: fix two more possible UBSAN-detected off-by-one errors\n     - wifi: mac80211: use two-phase skb reclamation in ieee80211_do_stop()\n     - can: bcm: Clear bo->bcm_proc_read after remove_proc_entry().\n     - Bluetooth: btusb: Fix not handling ZPL/short-transfer\n     - block, bfq: fix possible UAF for bfqq->bic with merge chain\n     - block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator()\n     - block, bfq: don't break merge chain in bfq_split_bfqq()\n     - spi: ppc4xx: handle irq_of_parse_and_map() errors\n     - spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ\n     - ARM: versatile: fix OF node leak in CPUs prepare\n     - reset: berlin: fix OF node leak in probe() error path\n     - clocksource/drivers/qcom: Add missing iounmap() on errors in msm_dt_timer_init()\n     - hwmon: (max16065) Fix overflows seen when writing limits\n     - mtd: slram: insert break after errors in parsing the map\n     - hwmon: (ntc_thermistor) fix module autoloading\n     - power: supply: max17042_battery: Fix SOC threshold calc w/ no current sense\n     - fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()\n     - drm/stm: Fix an error handling path in stm_drm_platform_probe()\n     - drm/amd: fix typo\n     - drm/amdgpu: Replace one-element array with flexible-array member\n     - drm/amdgpu: properly handle vbios fake edid sizing\n     - drm/radeon: Replace one-element array with flexible-array member\n     - drm/radeon: properly handle vbios fake edid sizing\n     - drm/rockchip: vop: Allow 4096px width scaling\n     - drm/radeon/evergreen_cs: fix int overflow errors in cs track offsets\n     - jfs: fix out-of-bounds in dbNextAG() and diAlloc()\n     - drm/msm/a5xx: properly clear preemption records on resume\n     - drm/msm/a5xx: fix races in preemption evaluation stage\n     - ipmi: docs: don't advertise deprecated sysfs entries\n     - drm/msm: fix %s null argument error\n     - xen: use correct end address of kernel for conflict checking\n     - xen/swiotlb: simplify range_straddles_page_boundary()\n     - xen/swiotlb: add alignment check for dma buffers\n     - selftests/bpf: Fix error compiling test_lru_map.c\n     - xz: cleanup CRC32 edits from 2018\n     - kthread: add kthread_work tracepoints\n     - kthread: fix task state in kthread worker if being frozen\n     - jbd2: introduce/export functions jbd2_journal_submit|finish_inode_data_buffers()\n     - ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard\n     - smackfs: Use rcu_assign_pointer() to ensure safe assignment in smk_set_cipso\n     - ext4: avoid negative min_clusters in find_group_orlov()\n     - ext4: return error on ext4_find_inline_entry\n     - ext4: avoid OOB when system.data xattr changes underneath the filesystem\n     - nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()\n     - nilfs2: determine empty node blocks as corrupted\n     - nilfs2: fix potential oob read in nilfs_btree_check_delete()\n     - perf sched timehist: Fix missing free of session in perf_sched__timehist()\n     - perf sched timehist: Fixed timestamp error when unable to confirm event sched_in time\n     - perf time-utils: Fix 32-bit nsec parsing\n     - clk: rockchip: Set parent rate for DCLK_VOP clock on RK3228\n     - drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds write error\n     - drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds write error\n     - PCI: xilinx-nwl: Fix register misspelling\n     - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency\n     - pinctrl: single: fix missing error code in pcs_probe()\n     - clk: ti: dra7-atl: Fix leak of of_nodes\n     - pinctrl: mvebu: Fix devinit_dove_pinctrl_probe function\n     - RDMA/cxgb4: Added NULL check for lookup_atid\n     - ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir()\n     - nfsd: call cache_put if xdr_reserve_space returns NULL\n     - f2fs: enhance to update i_mode and acl atomically in f2fs_setattr()\n     - f2fs: fix typo\n     - f2fs: fix to update i_ctime in __f2fs_setxattr()\n     - f2fs: remove unneeded check condition in __f2fs_setxattr()\n     - f2fs: reduce expensive checkpoint trigger frequency\n     - coresight: tmc: sg: Do not leak sg_table\n     - netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()\n     - net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition\n     - tcp: introduce tcp_skb_timestamp_us() helper\n     - tcp: check skb is non-NULL in tcp_rto_delta_us()\n     - net: qrtr: Update packets cloning when broadcasting\n     - netfilter: ctnetlink: compile ctnetlink_label_size with CONFIG_NF_CONNTRACK_EVENTS\n     - crypto: aead,cipher - zeroize key buffer after use\n     - Remove *.orig pattern from .gitignore\n     - soc: versatile: integrator: fix OF node leak in probe() error path\n     - USB: appledisplay: close race between probe and completion handler\n     - USB: misc: cypress_cy7c63: check for short transfer\n     - firmware_loader: Block path traversal\n     - tty: rp2: Fix reset with non forgiving PCIe host bridges\n     - drbd: Fix atomicity violation in drbd_uuid_set_bm()\n     - drbd: Add NULL check for net_conf to prevent dereference in state validation\n     - ACPI: sysfs: validate return type of _STR method\n     - f2fs: prevent possible int overflow in dir_block_index()\n     - f2fs: avoid potential int overflow in sanity_check_area_boundary()\n     - vfs: fix race between evice_inodes() and find_inode()&iput()\n     - fs: Fix file_set_fowner LSM hook inconsistencies\n     - nfs: fix memory leak in error path of nfs4_do_reclaim\n     - PCI: xilinx-nwl: Use irq_data_get_irq_chip_data()\n     - PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler\n     - soc: versatile: realview: fix memory leak during device remove\n     - soc: versatile: realview: fix soc_dev leak during device remove\n     - usb: yurex: Replace snprintf() with the safer scnprintf() variant\n     - USB: misc: yurex: fix race between read and write\n     - pps: remove usage of the deprecated ida_simple_xx() API\n     - pps: add an error check in parport_attach\n     - i2c: aspeed: Update the stop sw state when the bus recovery occurs\n     - i2c: isch: Add missed 'else'\n     - usb: yurex: Fix inconsistent locking bug in yurex_read()\n     - mailbox: rockchip: fix a typo in module autoloading\n     - mailbox: bcm2835: Fix timeout during suspend mode\n     - ceph: remove the incorrect Fw reference check when dirtying pages\n     - netfilter: uapi: NFTA_FLOWTABLE_HOOK is NLA_NESTED\n     - netfilter: nf_tables: prevent nf_skb_duplicated corruption\n     - r8152: Factor out OOB link list waits\n     - net: ethernet: lantiq_etop: fix memory disclosure\n     - net: avoid potential underflow in qdisc_pkt_len_init() with UFO\n     - net: add more sanity checks to qdisc_pkt_len_init()\n     - ipv4: ip_gre: Fix drops of small packets in ipgre_xmit\n     - sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start\n     - ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs\n     - ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin\n     - f2fs: Require FMODE_WRITE for atomic write ioctls\n     - wifi: ath9k: fix possible integer overflow in ath9k_get_et_stats()\n     - wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit\n     - net: hisilicon: hip04: fix OF node leak in probe()\n     - net: hisilicon: hns_dsaf_mac: fix OF node leak in hns_mac_get_info()\n     - net: hisilicon: hns_mdio: fix OF node leak in probe()\n     - ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails\n     - ACPICA: Fix memory leak if acpi_ps_get_next_field() fails\n     - ACPI: EC: Do not release locks during operation region accesses\n     - ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()\n     - tipc: guard against string buffer overrun\n     - net: mvpp2: Increase size of queue_name buffer\n     - ipv4: Check !in_dev earlier for ioctl(SIOCSIFADDR).\n     - ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family\n     - tcp: avoid reusing FIN_WAIT2 when trying to find port in connect() process\n     - ACPICA: iasl: handle empty connection_node\n     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()\n     - signal: Replace BUG_ON()s\n     - ALSA: asihpi: Fix potential OOB array access\n     - ALSA: hdsp: Break infinite MIDI input flush loop\n     - fbdev: pxafb: Fix possible use after free in pxafb_task()\n     - power: reset: brcmstb: Do not go into infinite loop if reset fails\n     - ata: sata_sil: Rename sil_blacklist to sil_quirks\n     - jfs: UBSAN: shift-out-of-bounds in dbFindBits\n     - jfs: Fix uaf in dbFreeBits\n     - jfs: check if leafidx greater than num leaves per dmap tree\n     - jfs: Fix uninit-value access of new_ea in ea_buffer\n     - drm/amd/display: Check stream before comparing them\n     - drm/amd/display: Fix index out of bounds in degamma hardware format translation\n     - drm/printer: Allow NULL data in devcoredump printer\n     - scsi: aacraid: Rearrange order of struct aac_srb_unit\n     - drm/radeon/r100: Handle unknown family in r100_cp_init_microcode()\n     - of/irq: Refer to actual buffer size in of_irq_parse_one()\n     - ext4: ext4_search_dir should return a proper error\n     - ext4: fix i_data_sem unlock order in ext4_ind_migrate()\n     - spi: s3c64xx: fix timeout counters in flush_fifo\n     - selftests: breakpoints: use remaining time to check if suspend succeed\n     - selftests: vDSO: fix vDSO symbols lookup for powerpc64\n     - i2c: xiic: Wait for TX empty to avoid missed TX NAKs\n     - spi: bcm63xx: Fix module autoloading\n     - perf/core: Fix small negative period being ignored\n     - parisc: Fix itlb miss handler for 64-bit programs\n     - ALSA: core: add isascii() check to card ID generator\n     - ext4: no need to continue when the number of entries is 1\n     - ext4: propagate errors from ext4_find_extent() in ext4_insert_range()\n     - ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space()\n     - ext4: aovid use-after-free in ext4_ext_insert_extent()\n     - ext4: fix double brelse() the buffer of the extents path\n     - ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit()\n     - parisc: Fix 64-bit userspace syscall path\n     - of/irq: Support #msi-cells=<0> in of_msi_get_domain\n     - jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error\n     - ocfs2: fix the la space leak when unmounting an ocfs2 volume\n     - ocfs2: fix uninit-value in ocfs2_get_block()\n     - ocfs2: reserve space for inline xattr before attaching reflink tree\n     - ocfs2: cancel dqi_sync_work before freeing oinfo\n     - ocfs2: remove unreasonable unlock in ocfs2_read_blocks\n     - ocfs2: fix null-ptr-deref when journal load failed.\n     - ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate\n     - riscv: define ILLEGAL_POINTER_VALUE for 64bit\n     - aoe: fix the potential use-after-free problem in more places\n     - clk: rockchip: fix error for unknown clocks\n     - media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags\n     - media: venus: fix use after free bug in venus_remove due to race condition\n     - iio: magnetometer: ak8975: Fix reading for ak099xx sensors\n     - tomoyo: fallback to realpath if symlink's pathname does not exist\n     - Input: adp5589-keys - fix adp5589_gpio_get_value()\n     - btrfs: wait for fixup workers before stopping cleaner kthread during umount\n     - gpio: davinci: fix lazy disable\n     - ext4: avoid ext4_error()'s caused by ENOMEM in the truncate path\n     - ext4: fix slab-use-after-free in ext4_split_extent_at()\n     - ext4: update orig_path in ext4_find_extent()\n     - arm64: Add Cortex-715 CPU part definition\n     - arm64: cputype: Add Neoverse-N3 definitions\n     - arm64: errata: Expand speculative SSBS workaround once more\n     - uprobes: fix kernel info leak via \"[uprobes]\" vma\n     - nfsd: use ktime_get_seconds() for timestamps\n     - nfsd: fix delegation_blocked() to block correctly for at least 30 seconds\n     - rtc: at91sam9: drop platform_data support\n     - rtc: at91sam9: fix OF node leak in probe() error path\n     - ACPI: battery: Simplify battery hook locking\n     - ACPI: battery: Fix possible crash when unregistering a battery hook\n     - ext4: fix inode tree inconsistency caused by ENOMEM\n     - net: ethernet: cortina: Drop TSO support\n     - tracing: Remove precision vsnprintf() check from print event\n     - drm: Move drm_mode_setcrtc() local re-init to failure path\n     - drm/crtc: fix uninitialized variable use even harder\n     - virtio_console: fix misc probe bugs\n     - Input: synaptics-rmi4 - fix UAF of IRQ domain on driver removal\n     - bpf: Check percpu map value size first\n     - s390/facility: Disable compile time optimization for decompressor code\n     - s390/mm: Add cond_resched() to cmm_alloc/free_pages()\n     - ext4: nested locking for xattr inode\n     - s390/cpum_sf: Remove WARN_ON_ONCE statements\n     - ktest.pl: Avoid false positives with grub2 skip regex\n     - clk: bcm: bcm53573: fix OF node leak in init\n     - i2c: i801: Use a different adapter-name for IDF adapters\n     - PCI: Mark Creative Labs EMU20k2 INTx masking as broken\n     - media: videobuf2-core: clear memory related fields in __vb2_plane_dmabuf_put()\n     - usb: chipidea: udc: enable suspend interrupt after usb reset\n     - tools/iio: Add memory allocation failure check for trigger_name\n     - driver core: bus: Return -EIO instead of 0 when show/store invalid bus attribute\n     - fbdev: sisfb: Fix strbuf array overflow\n     - NFS: Remove print_overflow_msg()\n     - SUNRPC: Fix integer overflow in decode_rc_list()\n     - tcp: fix tcp_enter_recovery() to zero retrans_stamp when it's safe\n     - netfilter: br_netfilter: fix panic with metadata_dst skb\n     - Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change\n     - gpio: aspeed: Add the flush write to ensure the write complete.\n     - clk: Add (devm_)clk_get_optional() functions\n     - clk: generalize devm_clk_get() a bit\n     - clk: Provide new devm_clk helpers for prepared and enabled clocks\n     - gpio: aspeed: Use devm_clk api to manage clock source\n     - igb: Do not bring the device up after non-fatal error\n     - net: ibm: emac: mal: fix wrong goto\n     - ppp: fix ppp_async_encode() illegal access\n     - net: ipv6: ensure we call ipv6_mc_down() at most once\n     - CDC-NCM: avoid overflow in sanity checking\n     - HID: plantronics: Workaround for an unexcepted opposite volume key\n     - Revert \"usb: yurex: Replace snprintf() with the safer scnprintf() variant\"\n     - usb: xhci: Fix problem with xhci resume from suspend\n     - usb: storage: ignore bogus device raised by JieLi BR21 USB sound chip\n     - net: Fix an unsafe loop on the list\n     - posix-clock: Fix missing timespec64 check in pc_clock_settime()\n     - arm64: probes: Remove broken LDR (literal) uprobe support\n     - arm64: probes: Fix simulate_ldr*_literal()\n     - PCI: Add function 0 DMA alias quirk for Glenfly Arise chip\n     - fat: fix uninitialized variable\n     - KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()\n     - net: dsa: mv88e6xxx: Fix out-of-bound access\n     - s390/sclp_vt220: Convert newlines to CRLF instead of LFCR\n     - KVM: s390: Change virtual to physical address access in diag 0x258 handler\n     - x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET\n     - drm/vmwgfx: Handle surface check failure correctly\n     - iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in Kconfig\n     - iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER in Kconfig\n     - iio: hid-sensors: Fix an error handling path in _hid_sensor_set_report_latency()\n     - iio: light: opt3001: add missing full-scale range value\n     - Bluetooth: Remove debugfs directory on module init failure\n     - Bluetooth: btusb: Fix regression with fake CSR controllers 0a12:0001\n     - xhci: Fix incorrect stream context type macro\n     - USB: serial: option: add support for Quectel EG916Q-GL\n     - USB: serial: option: add Telit FN920C04 MBIM compositions\n     - parport: Proper fix for array out-of-bounds access\n     - x86/apic: Always explicitly disarm TSC-deadline timer\n     - nilfs2: propagate directory read errors from nilfs_find_entry()\n     - clk: Fix pointer casting to prevent oops in devm_clk_release()\n     - clk: Fix slab-out-of-bounds error in devm_clk_release()\n     - RDMA/bnxt_re: Fix incorrect AVID type in WQE structure\n     - RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP\n     - RDMA/bnxt_re: Return more meaningful error\n     - drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate calculation\n     - macsec: don't increment counters for an unrelated SA\n     - net: ethernet: aeroflex: fix potential memory leak in greth_start_xmit_gbit()\n     - net: systemport: fix potential memory leak in bcm_sysport_xmit()\n     - usb: typec: altmode should keep reference to parent\n     - Bluetooth: bnep: fix wild-memory-access in proto_unregister\n     - arm64:uprobe fix the uprobe SWBP_INSN in big-endian\n     - arm64: probes: Fix uprobes for big-endian kernels\n     - KVM: s390: gaccess: Refactor gpa and length calculation\n     - KVM: s390: gaccess: Refactor access address range check\n     - KVM: s390: gaccess: Cleanup access to guest pages\n     - KVM: s390: gaccess: Check if guest address is in memslot\n     - udf: fix uninit-value use in udf_get_fileshortad\n     - jfs: Fix sanity check in dbMount\n     - net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()\n     - be2net: fix potential memory leak in be_xmit()\n     - net: usb: usbnet: fix name regression\n     - posix-clock: posix-clock: Fix unbalanced locking in pc_clock_settime()\n     - ALSA: hda/realtek: Update default depop procedure\n     - drm/amd: Guard against bad data for ATIF ACPI method\n     - ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix initial lid detection issue\n     - nilfs2: fix kernel bug due to missing clearing of buffer delay flag\n     - hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event\n     - selinux: improve error checking in sel_write_load()\n     - arm64/uprobes: change the uprobe_opcode_t typedef to fix the sparse warning\n     - xfrm: validate new SA's prefixlen using SA family when sel.family is unset\n     - usb: dwc3: remove generic PHY calibrate() calls\n     - usb: dwc3: Add splitdisable quirk for Hisilicon Kirin Soc\n     - usb: dwc3: core: Stop processing of pending events if controller is halted\n     - cgroup: Fix potential overflow issue when checking max_depth\n     - wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys\n     - gtp: simplify error handling code in 'gtp_encap_enable()'\n     - gtp: allow -1 to be specified as file description from userspace\n     - net/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOT\n     - bpf: Fix out-of-bounds write in trie_get_next_key()\n     - net: support ip generic csum processing in skb_csum_hwoffload_help\n     - net: skip offload for NETIF_F_IPV6_CSUM if ipv6 header contains extension\n     - netfilter: nft_payload: sanitize offset and length before calling skb_checksum()\n     - firmware: arm_sdei: Fix the input parameter of cpuhp_remove_state()\n     - net: amd: mvme147: Fix probe banner message\n     - misc: sgi-gru: Don't disable preemption in GRU driver\n     - usbip: tools: Fix detach_port() invalid port error path\n     - usb: phy: Fix API devm_usb_put_phy() can not release the phy\n     - xhci: Fix Link TRB DMA in command ring stopped completion event\n     - Revert \"driver core: Fix uevent_show() vs driver detach race\"\n     - wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower\n     - wifi: ath10k: Fix memory leak in management tx\n     - wifi: iwlegacy: Clear stale interrupts before resuming device\n     - nilfs2: fix potential deadlock with newly created symlinks\n     - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow\n     - nilfs2: fix kernel bug due to missing clearing of checked flag\n     - mm: shmem: fix data-race in shmem_getattr()\n     - vt: prevent kernel-infoleak in con_font_get()\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.324\n     - arm64: dts: rockchip: Fix rt5651 compatible value on rk3399-sapphire-excavator\n     - ARM: dts: rockchip: fix rk3036 acodec node\n     - ARM: dts: rockchip: drop grf reference from rk3036 hdmi\n     - ARM: dts: rockchip: Fix the realtek audio codec on rk3036-kylin\n     - HID: core: zero-initialize the report buffer\n     - security/keys: fix slab-out-of-bounds in key_task_permission\n     - sctp: properly validate chunk size in sctp_sf_ootb()\n     - can: c_can: fix {rx,tx}_errors statistics\n     - net: hns3: fix kernel crash when uninstalling driver\n     - media: stb0899_algo: initialize cfr before using it\n     - media: dvbdev: prevent the risk of out of memory access\n     - media: dvb_frontend: don't play tricks with underflow values\n     - media: adv7604: prevent underflow condition when reporting colorspace\n     - ALSA: firewire-lib: fix return value on fail in amdtp_tscm_init()\n     - media: s5p-jpeg: prevent buffer overflows\n     - media: cx24116: prevent overflows on SNR calculus\n     - media: v4l2-tpg: prevent the risk of a division by zero\n     - drm/amdgpu: add missing size check in amdgpu_debugfs_gprwave_read()\n     - drm/amdgpu: prevent NULL pointer dereference if ATIF is not supported\n     - dm cache: correct the number of origin blocks to match the target length\n     - dm cache: fix out-of-bounds access to the dirty bitset when resizing\n     - dm cache: optimize dirty bit checking with find_next_bit when resizing\n     - dm cache: fix potential out-of-bounds access on the first resume\n     - dm-unstriped: cast an operand to sector_t to prevent potential uint32_t overflow\n     - nfs: Fix KMSAN warning in decode_getfattr_attrs()\n     - btrfs: reinitialize delayed ref list after deleting it from the list\n     - bonding (gcc13): synchronize bond_{a,t}lb_xmit() types\n     - net: bridge: xmit: make sure we have at least eth header len bytes\n     - media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format\n     - fs/proc: fix compile warning about variable 'vmcore_mmap_ops'\n     - usb: musb: sunxi: Fix accessing an released usb phy\n     - USB: serial: io_edgeport: fix use after free in debug printk\n     - USB: serial: qcserial: add support for Sierra Wireless EM86xx\n     - USB: serial: option: add Fibocom FG132 0x0112 composition\n     - USB: serial: option: add Quectel RG650V\n     - irqchip/gic-v3: Force propagation of the active state with a read-back\n     - ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()\n     - ALSA: pcm: Return 0 when size < start_threshold in capture\n     - ALSA: usb-audio: Add custom mixer status quirks for RME CC devices\n     - ALSA: usb-audio: Support jack detection on Dell dock\n     - ALSA: usb-audio: Add quirks for Dell WD19 dock\n     - hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer\n     - vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans\n     - ALSA: usb-audio: Add endianness annotations\n     - 9p: Avoid creating multiple slab caches with the same name\n     - HID: multitouch: Add quirk for HONOR MagicBook Art 14 touchpad\n     - bpf: use kvzmalloc to allocate BPF verifier environment\n     - sound: Make CONFIG_SND depend on INDIRECT_IOMEM instead of UML\n     - powerpc/powernv: Free name on error in opal_event_init()\n     - fs: Fix uninitialized value issue in from_kuid and from_kgid\n     - net: usb: qmi_wwan: add Fibocom FG132 0x0112 composition\n     - 9p: fix slab cache name creation for real\n     https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.325\n     - netlink: terminate outstanding dump on socket close\n     - ocfs2: uncache inode which has failed entering the group\n     - nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint\n     - ocfs2: fix UBSAN warning in ocfs2_verify_volume()\n     - nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint\n     - Revert \"mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\"\n     - media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set\n     - kbuild: Use uname for LINUX_COMPILE_HOST detection\n     - mm: revert \"mm: shmem: fix data-race in shmem_getattr()\"\n     - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla 10 tablet\n     - mac80211: fix user-power when emulating chanctx\n     - selftests/watchdog-test: Fix system accidentally reset after watchdog-test\n     - x86/amd_nb: Fix compile-testing without CONFIG_AMD_NB\n     - net: usb: qmi_wwan: add Quectel RG650V\n     - proc/softirqs: replace seq_printf with seq_put_decimal_ull_width\n     - nvme: fix metadata handling in nvme-passthrough\n     - initramfs: avoid filename buffer overrun\n     - m68k: mvme147: Fix SCSI controller IRQ numbers\n     - m68k: mvme16x: Add and use \"mvme16x.h\"\n     - m68k: mvme147: Reinstate early console\n     - acpi/arm64: Adjust error handling procedure in gtdt_parse_timer_block()\n     - s390/syscalls: Avoid creation of arch/arch/ directory\n     - hfsplus: don't query the device logical block size multiple times\n     - EDAC/fsl_ddr: Fix bad bit shift operations\n     - crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY\n     - crypto: cavium - Fix the if condition to exit loop after timeout\n     - crypto: bcm - add error check in the ahash_hmac_init function\n     - crypto: cavium - Fix an error handling path in cpt_ucode_load_fw()\n     - time: Fix references to _msecs_to_jiffies() handling of values\n     - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()\n     - mmc: mmc_spi: drop buggy snprintf()\n     - ARM: dts: cubieboard4: Fix DCDC5 regulator constraints\n     - regmap: irq: Set lockdep class for hierarchical IRQ domains\n     - firmware: arm_scpi: Check the DVFS OPP count returned by the firmware\n     - drm/mm: Mark drm_mm_interval_tree*() functions with __maybe_unused\n     - wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()\n     - drm/omap: Fix locking in omap_gem_new_dmabuf()\n     - bpf: Fix the xdp_adjust_tail sample prog issue\n     - wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()\n     - drm/etnaviv: consolidate hardware fence handling in etnaviv_gpu\n     - drm/etnaviv: dump: fix sparse warnings\n     - drm/etnaviv: fix power register offset on GC300\n     - drm/etnaviv: hold GPU lock across perfmon sampling\n     - net: rfkill: gpio: Add check for clk_enable()\n     - ALSA: us122l: Use snd_card_free_when_closed() at disconnection\n     - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection\n     - ALSA: 6fire: Release resources at card release\n     - netpoll: Use rcu_access_pointer() in netpoll_poll_lock\n     - trace/trace_event_perf: remove duplicate samples on the first tracepoint event\n     - powerpc/vdso: Flag VDSO64 entry points as functions\n     - mfd: da9052-spi: Change read-mask to write-mask\n     - cpufreq: loongson2: Unregister platform_driver on failure\n     - mtd: rawnand: atmel: Fix possible memory leak\n     - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey\n     - mfd: rt5033: Fix missing regmap_del_irq_chip()\n     - scsi: bfa: Fix use-after-free in bfad_im_module_exit()\n     - scsi: fusion: Remove unused variable 'rc'\n     - scsi: qedi: Fix a possible memory leak in qedi_alloc_and_init_sb()\n     - ocfs2: fix uninitialized value in ocfs2_file_read_iter()\n     - powerpc/sstep: make emulate_vsx_load and emulate_vsx_store static\n     - fbdev/sh7760fb: Alloc DMA memory from hardware device\n     - fbdev: sh7760fb: Fix a possible memory leak in sh7760fb_alloc_mem()\n     - dt-bindings: clock: adi,axi-clkgen: convert old binding to yaml format\n     - dt-bindings: clock: axi-clkgen: include AXI clk\n     - clk: axi-clkgen: use devm_platform_ioremap_resource() short-hand\n     - clk: clk-axi-clkgen: make sure to enable the AXI bus clock\n     - perf probe: Correct demangled symbols in C++ program\n     - PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads\n     - PCI: cpqphp: Fix PCIBIOS_* return value confusion\n     - m68k: mcfgpio: Fix incorrect register offset for CONFIG_M5441x\n     - m68k: coldfire/device.c: only build FEC when HW macros are defined\n     - rpmsg: glink: Add TX_DATA_CONT command while sending\n     - rpmsg: glink: Send READ_NOTIFY command in FIFO full case\n     - rpmsg: glink: Fix GLINK command prefix\n     - rpmsg: glink: use only lower 16-bits of param2 for CMD_OPEN name length\n     - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()\n     - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()\n     - vfio/pci: Properly hide first-in-list PCIe extended capability\n     - power: supply: core: Remove might_sleep() from power_supply_put()\n     - net: usb: lan78xx: Fix memory leak on device unplug by freeing PHY device\n     - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets\n     - net: usb: lan78xx: Fix refcounting and autosuspend on invalid WoL configuration\n     - marvell: pxa168_eth: fix call balance of pep->clk handling routines\n     - net: stmmac: dwmac-socfpga: Set RX watchdog interrupt as broken\n     - usb: using mutex lock and supporting O_NONBLOCK flag in iowarrior_read()\n     - USB: chaoskey: fail open after removal\n     - USB: chaoskey: Fix possible deadlock chaoskey_list_lock\n     - misc: apds990x: Fix missing pm_runtime_disable()\n     - apparmor: fix 'Do simple duplicate message elimination'\n     - usb: ehci-spear: fix call balance of sehci clk handling routines\n     - ext4: supress data-race warnings in ext4_free_inodes_{count,set}()\n     - ext4: fix FS_IOC_GETFSMAP handling\n     - jfs: xattr: check invalid xattr size more strictly\n     - ASoC: codecs: Fix atomicity violation in snd_soc_component_get_drvdata()\n     - PCI: Fix use-after-free of slot->bus on hot remove\n     - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler\n     - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()\n     - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices\n     - Revert \"usb: gadget: composite: fix OS descriptors w_value logic\"\n     - serial: sh-sci: Clean sci_ports[0] after at earlycon exit\n     - Revert \"serial: sh-sci: Clean sci_ports[0] after at earlycon exit\"\n     - netfilter: ipset: add missing range check in bitmap_ip_uadt\n     - spi: Fix acpi deferred irq probe\n     - ubi: wl: Put source PEB into correct list if trying locking LEB failed\n     - um: ubd: Do not use drvdata in release\n     - um: net: Do not use drvdata in release\n     - serial: 8250: omap: Move pm_runtime_get_sync\n     - um: vector: Do not use drvdata in release\n     - sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK\n     - arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled\n     - block: fix ordering between checking BLK_MQ_S_STOPPED request adding\n     - HID: wacom: Interpret tilt data from Intuos Pro BT as signed values\n     - media: wl128x: Fix atomicity violation in fmc_send_cmd()\n     - usb: dwc3: gadget: Fix checking for number of TRBs left\n     - lib: string_helpers: silence snprintf() output truncation warning\n     - NFSD: Prevent a potential integer overflow\n     - rpmsg: glink: Propagate TX failures in intentless mode as well\n     - um: Fix the return value of elf_core_copy_task_fpregs\n     - NFSv4.0: Fix a use-after-free problem in the asynchronous open()\n     - rtc: check if __rtc_read_time was successful in rtc_timer_do_work()\n     - ubifs: Correct the total block count by deducting journal reservation\n     - ubi: fastmap: Fix duplicate slab cache names while attaching\n     - jffs2: fix use of uninitialized variable\n     - block: return unsigned int from bdev_io_min\n     - 9p/xen: fix init sequence\n     - 9p/xen: fix release of IRQ\n     - modpost: remove incorrect code in do_eisa_entry()\n     - sh: intc: Fix use-after-free bug in register_intc_controller()",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/advisories/2026/clsa-2026_1787656450.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-27T15:49:59Z",
      "generator": {
        "date": "2026-08-27T15:49:59Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787656450",
      "initial_release_date": "2026-08-25T11:14:13Z",
      "revision_history": [
        {
          "date": "2026-08-25T11:14:13Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-27T15:49:59Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Fix CVE(s): CVE-2023-6270, CVE-2026-31431, CVE-2026-53043"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-headers-4.19.0-28-all-amd64@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-libc-dev@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libcpupower1@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libcpupower-dev@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libbpf-dev@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-perf-4.19@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-config-4.19@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-kbuild-4.19@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libbpf4.19@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-compiler-gcc-8-x86@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-headers-4.19.0-28-all@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-image-amd64-signed-template@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-cpupower@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-headers-4.19.0-28-amd64@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/hyperv-daemons@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
                "product": {
                  "name": "linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_id": "linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-image-4.19.0-28-amd64-unsigned@4.19.325-1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
                "product": {
                  "name": "linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
                  "product_id": "linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-doc-4.19@4.19.325-1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all",
                "product": {
                  "name": "linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all",
                  "product_id": "linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-support-4.19.0-28@4.19.325-1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
                "product": {
                  "name": "linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
                  "product_id": "linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-source-4.19@4.19.325-1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
                "product": {
                  "name": "linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
                  "product_id": "linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/linux-headers-4.19.0-28-common@4.19.325-1%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcpupower1-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all"
        },
        "product_reference": "linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
        },
        "product_reference": "linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-source-4.19-0:4.19.325-1+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all"
        },
        "product_reference": "linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all as a component of Debian 10",
          "product_id": "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all"
        },
        "product_reference": "linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64"
        },
        "product_reference": "linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53043",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2/dlm: validate qr_numregions in dlm_match_regions()\n\nPatch series \"ocfs2/dlm: fix two bugs in dlm_match_regions()\".\n\nIn dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION\nnetwork message is used to drive loops over the qr_regions buffer without\nsufficient validation.  This series fixes two issues:\n\n- Patch 1 adds a bounds check to reject messages where qr_numregions\n  exceeds O2NM_MAX_REGIONS. The o2net layer only validates message\n  byte length; it does not constrain field values, so a crafted message\n  can set qr_numregions up to 255 and trigger out-of-bounds reads past\n  the 1024-byte qr_regions buffer.\n\n- Patch 2 fixes an off-by-one in the local-vs-remote comparison loop,\n  which uses '<=' instead of '<', reading one entry past the valid range\n  even when qr_numregions is within bounds.\n\n\nThis patch (of 2):\n\nThe qr_numregions field from a DLM_QUERY_REGION network message is used\ndirectly as loop bounds in dlm_match_regions() without checking against\nO2NM_MAX_REGIONS.  Since qr_regions is sized for at most O2NM_MAX_REGIONS\n(32) entries, a crafted message with qr_numregions > 32 causes\nout-of-bounds reads past the qr_regions buffer.\n\nAdd a bounds check for qr_numregions before entering the loops.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53043"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/1f8b91275912cd428289c1fb424bebd7ff5302bd",
          "url": "https://git.kernel.org/stable/c/1f8b91275912cd428289c1fb424bebd7ff5302bd"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21",
          "url": "https://git.kernel.org/stable/c/3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/3f474c33ebc2e2ca3fcb587d7de4375348f13373",
          "url": "https://git.kernel.org/stable/c/3f474c33ebc2e2ca3fcb587d7de4375348f13373"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/6c6e8fc3c007319981647b410c29bb5775048551",
          "url": "https://git.kernel.org/stable/c/6c6e8fc3c007319981647b410c29bb5775048551"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/7ab3fbb01bc6d79091bc375e5235d360cd9b78be",
          "url": "https://git.kernel.org/stable/c/7ab3fbb01bc6d79091bc375e5235d360cd9b78be"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/d3d5efade0c79dac1cac98c0cb1115432f804439",
          "url": "https://git.kernel.org/stable/c/d3d5efade0c79dac1cac98c0cb1115432f804439"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/f37de46149db49abd2b24f4f0c5a88cf4dfb5f47",
          "url": "https://git.kernel.org/stable/c/f37de46149db49abd2b24f4f0c5a88cf4dfb5f47"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/f69551139caf6d24242a0ad049ee46b264e3aee0",
          "url": "https://git.kernel.org/stable/c/f69551139caf6d24242a0ad049ee46b264e3aee0"
        }
      ],
      "release_date": "2026-06-24T16:29:49Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T11:14:13.407522Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450",
          "product_ids": [
            "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-6270",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-6270"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2023-6270",
          "url": "https://access.redhat.com/security/cve/CVE-2023-6270"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2256786",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256786"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
        }
      ],
      "release_date": "2024-01-04T17:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T11:14:13.407522Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450",
          "product_ids": [
            "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-31431",
      "cwe": {
        "id": "CWE-669",
        "name": "Incorrect Resource Transfer Between Spheres"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
          "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
          "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-31431"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c",
          "url": "https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc",
          "url": "https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667",
          "url": "https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82",
          "url": "https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b",
          "url": "https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5",
          "url": "https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237",
          "url": "https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237"
        },
        {
          "category": "external",
          "summary": "https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8",
          "url": "https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/29/23",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/23"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/29/25",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/25"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/29/26",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/29/26"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/10"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/11",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/11"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/12",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/14",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/14"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/15",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/15"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/16",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/16"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/17",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/17"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/18",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/18"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/20",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/20"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/5",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/5"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/30/6",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/30/6"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/10"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/12",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/15",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/15"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/16",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/16"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/17",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/17"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/18",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/18"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/22",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/22"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/23",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/23"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/24",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/24"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/01/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/01/3"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/14",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/14"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/15",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/15"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/16",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/16"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/17",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/17"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/18",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/18"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/19",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/19"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/20",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/20"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/21",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/21"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/23",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/23"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/24",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/24"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/25",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/25"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/4",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/4"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/5",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/5"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/6",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/6"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/7",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/7"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/02/8",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/02/8"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/10"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/12",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/13",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/13"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/3"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/4",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/4"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/5",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/5"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/03/6",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/03/6"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/1",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/1"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/10"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/11",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/11"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/12",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/13",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/13"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/14",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/14"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/24",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/24"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/27",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/27"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/28",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/28"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/29",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/29"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/31",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/31"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/8",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/8"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/04/9",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/04/9"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/06/5",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/06/5"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/07/12",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/07/12"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/07/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/07/2"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/08/13",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/08/13"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/05/18/3",
          "url": "http://www.openwall.com/lists/oss-security/2026/05/18/3"
        },
        {
          "category": "external",
          "summary": "https://copy.fail",
          "url": "https://copy.fail/"
        },
        {
          "category": "external",
          "summary": "https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170",
          "url": "https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/260001",
          "url": "https://www.kb.cert.org/vuls/id/260001"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13565",
          "url": "https://access.redhat.com/errata/RHSA-2026:13565"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13566",
          "url": "https://access.redhat.com/errata/RHSA-2026:13566"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13577",
          "url": "https://access.redhat.com/errata/RHSA-2026:13577"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13578",
          "url": "https://access.redhat.com/errata/RHSA-2026:13578"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13681",
          "url": "https://access.redhat.com/errata/RHSA-2026:13681"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13690",
          "url": "https://access.redhat.com/errata/RHSA-2026:13690"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13727",
          "url": "https://access.redhat.com/errata/RHSA-2026:13727"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13729",
          "url": "https://access.redhat.com/errata/RHSA-2026:13729"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13734",
          "url": "https://access.redhat.com/errata/RHSA-2026:13734"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13811",
          "url": "https://access.redhat.com/errata/RHSA-2026:13811"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13862",
          "url": "https://access.redhat.com/errata/RHSA-2026:13862"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13885",
          "url": "https://access.redhat.com/errata/RHSA-2026:13885"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13887",
          "url": "https://access.redhat.com/errata/RHSA-2026:13887"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13932",
          "url": "https://access.redhat.com/errata/RHSA-2026:13932"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13936",
          "url": "https://access.redhat.com/errata/RHSA-2026:13936"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14097",
          "url": "https://access.redhat.com/errata/RHSA-2026:14097"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14112",
          "url": "https://access.redhat.com/errata/RHSA-2026:14112"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14137",
          "url": "https://access.redhat.com/errata/RHSA-2026:14137"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14165",
          "url": "https://access.redhat.com/errata/RHSA-2026:14165"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14230",
          "url": "https://access.redhat.com/errata/RHSA-2026:14230"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14301",
          "url": "https://access.redhat.com/errata/RHSA-2026:14301"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14339",
          "url": "https://access.redhat.com/errata/RHSA-2026:14339"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14773",
          "url": "https://access.redhat.com/errata/RHSA-2026:14773"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14926",
          "url": "https://access.redhat.com/errata/RHSA-2026:14926"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:15087",
          "url": "https://access.redhat.com/errata/RHSA-2026:15087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:15976",
          "url": "https://access.redhat.com/errata/RHSA-2026:15976"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:15978",
          "url": "https://access.redhat.com/errata/RHSA-2026:15978"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16018",
          "url": "https://access.redhat.com/errata/RHSA-2026:16018"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16063",
          "url": "https://access.redhat.com/errata/RHSA-2026:16063"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16111",
          "url": "https://access.redhat.com/errata/RHSA-2026:16111"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16208",
          "url": "https://access.redhat.com/errata/RHSA-2026:16208"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16209",
          "url": "https://access.redhat.com/errata/RHSA-2026:16209"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16210",
          "url": "https://access.redhat.com/errata/RHSA-2026:16210"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19074",
          "url": "https://access.redhat.com/errata/RHSA-2026:19074"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19225",
          "url": "https://access.redhat.com/errata/RHSA-2026:19225"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:33486",
          "url": "https://access.redhat.com/errata/RHSA-2026:33486"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-31431",
          "url": "https://access.redhat.com/security/cve/CVE-2026-31431"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation",
          "url": "https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2460538",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460538"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
        },
        {
          "category": "external",
          "summary": "https://github.com/theori-io/copy-fail-CVE-2026-31431",
          "url": "https://github.com/theori-io/copy-fail-CVE-2026-31431"
        },
        {
          "category": "external",
          "summary": "https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/",
          "url": "https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.json"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431"
        },
        {
          "category": "external",
          "summary": "https://xint.io/blog/copy-fail-linux-distributions#the-fix-6",
          "url": "https://xint.io/blog/copy-fail-linux-distributions#the-fix-6"
        }
      ],
      "release_date": "2026-04-22T08:15:10Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-25T11:14:13.407522Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450",
          "product_ids": [
            "Debian-10:hyperv-daemons-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libbpf4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:libcpupower1-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-compiler-gcc-8-x86-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-config-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-cpupower-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-doc-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-headers-4.19.0-28-all-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-all-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-amd64-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-headers-4.19.0-28-common-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-image-4.19.0-28-amd64-unsigned-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-image-amd64-signed-template-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-kbuild-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-libc-dev-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-perf-4.19-0:4.19.325-1+tuxcare.els1.amd64",
            "Debian-10:linux-source-4.19-0:4.19.325-1+tuxcare.els1.all",
            "Debian-10:linux-support-4.19.0-28-0:4.19.325-1+tuxcare.els1.all"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787656450"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}