Thank you for your contribution to Debian.
Accepted: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 03 Sep 2026 10:34:10 +0200 Source: linux Architecture: source Version: 7.1.13-1 Distribution: unstable Urgency: medium Maintainer: Debian Kernel Team <[email protected]> Changed-By: Salvatore Bonaccorso <[email protected]> Changes: linux (7.1.13-1) unstable; urgency=medium . * New upstream stable update: https://www.kernel.org/pub/linux/kernel/v7.x/ChangeLog-7.1.13 - bpf: reject overlarge global subprog argument sizes - RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp - RDMA/rxe: Fix OOB in free_rd_atomic_resources() - [amd64] KVM: x86/mmu: Check write tracking in all address spaces - nvme-tcp: fix usage of page_frag_cache - Revert "selinux: reject a permission value exceeding the class permission count" - selinux: use u16 for security classes - selinux: more strict policy parsing - selinux: reject a permission value exceeding the class permission count - selinux: require a class's permission values to cover its permission count - selinux: switch two allocations to use kzalloc_objs() - ext4: export converted block count from ext4_convert_unwritten_extents() - ext4: protect WRITE_ZEROES written extents with orphan list - ext4: move partial block zeroing earlier in ext4_zero_range() - ext4: write back partial-zeroed edges in WRITE_ZEROES - ext4: track partial-zero outcome per edge in ext4_zero_partial_blocks() - ext4: zero out whole block for clean edges in WRITE_ZEROES - fpga: dfl: fme: add error handling - accessibility: speakup: unregister tty ldisc on later init failures - usb: xhci: Handle bogus TRB pointers in Missed Service Error events - usb: xhci: Handle USB3 port events when there is one roothub - usb: xhci: bail out of setup if the controller is inaccessible - xhci: dbgtty: Fix unregister on tty_register_driver() failure - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure - fuse: fix invalidate lock leak on setattr writeback failure - fuse: fix invalidate lock leak on open O_TRUNC DAX failure - usb: usbtest: disable dynamic ID support - usb: gadget: f_tcm: keep port count until LUN teardown completes - [amd64] KVM: SEV: Drop FOLL_WRITE for encrypted region registration - [amd64] KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests - [amd64] KVM: SEV: Extract loading of guest-provided VMSA to a separate helper - [amd64] KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable - [amd64] KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y - tls: device: fix out-of-bounds write in tls_append_frag() - gtp: serialize PDP context updates - net/tcp: fix TCP-AO key deletion in VRFs - tcp: fix AO info use-after-free in tcp_ao_connect_init() - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer - net: advertise TCP MSS from the configured MTU, not the learned PMTU - xfrm: espintcp: fix UAF during close - tcp: clamp route advmss to TCP_MIN_MSS - xfrm: drop ESP-in-TCP packets with no ingress device - xfrm: avoid lock inversion in nat keepalive work - xfrm: ah6: validate routing header segments_left - xfrm: fix xfrm_state_construct() auth-trunc leak - xfrm: bound nat keepalive state collection - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context - net/packet: defer vmalloc TX_RING free until skbs finish - ipv6: seg6: clear IPv4 control block on IPIP decapsulation - batman-adv: reject unrepresentable multicast TVLV offsets - vxlan: keep the last remote linked during FDB flush - netfilter: nft_set_pipapo_avx2: add missing vzeroupper - netfilter: nf_tables: don't queue packet path object notifications - mm/swap: reject swapon() on filesystem-level encrypted files - kunit: irq: Continue increasing hrtimer interval for longer - crypto: virtio - bound the akcipher result length - crypto: qcom-rng - Enable clock in hwrng case - crypto: qcom-rng - Remove crypto_rng interface - crypto: qcom-rng - Allow zero as a random number - crypto: atmel-tdes - use scatterlist length before DMA mapping - crypto: krb5 - use kfree_sensitive() for derived key buffers - crypto: qce - fix CCM AAD buffer underallocation - crypto: iaa - fall back to software for multi-entry scatterlists - crypto: mxs-dcp - fix source scatterlist length access - crypto: qce - Remove unsafe/deprecated algorithms - [s390x] KVM: s390: vsie: zero stale crypto bits - usb: core: Add lock to usb_wakeup_notification() - usb: core: Strengthen error handling in hub_hub_status() - ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() - ALSA: usb-audio: Complete cleanup after system-resume errors - USB: serial: option: fix slab OOB read in interrupt URB callback - USB: serial: spcp8x5: drop broken carrier detect support - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb - usb: usbfs: fix use-after-free of usb_device in usbdev_release() Checksums-Sha1: fc68743f587bb8664eccc4906aa19ec3ec5d3974 196174 linux_7.1.13-1.dsc 086cfdbe786073fd2b2c5a92cb63c7349f732243 161695252 linux_7.1.13.orig.tar.xz 911de27b633f9409313069b8091a053b8c86ca7f 1541736 linux_7.1.13-1.debian.tar.xz 5f8124bb07b63be7718ce22f46a28feeb42a1abd 6913 linux_7.1.13-1_source.buildinfo Checksums-Sha256: f20cc891957963f4bf2285a90c8b478b4c8aa8ab6765f06bcdf50dfb8a0b6f80 196174 linux_7.1.13-1.dsc 25f65727fb83a4fa90d18ec1449bd99db93ad54faceacab821c38f19431940c2 161695252 linux_7.1.13.orig.tar.xz 4d28914071c65882c46bdc0a0cf90ace5ee2f8dcba3c397ad7c9cee5084f0483 1541736 linux_7.1.13-1.debian.tar.xz 64c8bae3863bc74cc040e484885f026b8a454cd94f27e8ae591c74a0ccd1b440 6913 linux_7.1.13-1_source.buildinfo Files: 6f0a0808fce4dd3962e6561b0295a10f 196174 kernel optional linux_7.1.13-1.dsc 306f73a9eb0bc18451db439264cc9d8d 161695252 kernel optional linux_7.1.13.orig.tar.xz ab87703c8f89a213873cab656ec0ee67 1541736 kernel optional linux_7.1.13-1.debian.tar.xz adef7d09b669072ab47190667d236a75 6913 kernel optional linux_7.1.13-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqZM9dfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EtEcQAJOtkfW524zUuPBHGcmiYIyGQdgOgz5f 7H8KxJGK0RyaijunN4hb0JxGap/h4hRVQm1S5gmV5yIC6j5RYrXEknDTn6yP3w5a ZsdfZ44SRVRkEB1RzPKmeBwqKkjBnYys9UUnDbIcmJfkqx6VRVRjMUfxMK193Qxm 778yyz5EqPJiNe+Jhkh2LMniwF+I4h/b0pMQNtL1Jd2k5pJ549uVlpq3myMtzAI9 gybqZvphAxQrzXpjOUB05WnxlPOAOgLLgsmMgOy6b+OSYjEF/dtA1omifhee7a1+ KwEN8Rltxrnn01Tvmt+uJAG78wc4op6LM9oPmWLssR61hbb2ZBq7sRAWz47zAW2S VuPBYzNKHWYrVcFB+dzHYmd/945LXgcCiABySFqJCQkK4DZHEbw4SjHFVB/jrVWA t3xL0tMJ0yuWfhL2ZV3krpPEV2co5ybyWeI7idCZC7fgdaHCBYqxabRZRNQjP+6R 1dYMYwCJPj5FdQOsmPw3oWO7XbynOgPkOrOs1SlasyJ2OFWW917iem4ZdYecFMB7 /miNsMYRQvp2hcaaIp2jwYv0l65uDkp3bJTd9+iBvvG8iow7YYNd41ggqLEZOdeB W+PxKAnEoBq6F/vIUbugny3HEUtN46rZxcCmBXB201KzEC9VrHCYebPxdSOF/RcW BNKVePJqGqGV =ZkYp -----END PGP SIGNATURE-----
pgpeb3wOfRp6W.pgp
Description: PGP signature

