CVE-2025-71149: io_uring/poll: correctly handle io_poll_add() return value on update (bsc#1257164).
CVE-2026-22976: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset (bsc#1257035).
CVE-2026-22977: net: sock: fix hardened usercopy panic in sock_recv_errqueue (bsc#1257053).
CVE-2026-22984: libceph: prevent potential out-of-bounds reads in handle_auth_done() (bsc#1257217).
CVE-2026-22990: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (bsc#1257221).
CVE-2026-22991: libceph: make free_choose_arg_map() resilient to partial allocation (bsc#1257220).
CVE-2026-22992: libceph: return the handler error from mon_handle_auth_done() (bsc#1257218).
CVE-2026-22993: idpf: Fix RSS LUT NULL pointer crash on early ethtool operations (bsc#1257180).
CVE-2026-22996: net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv.
CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257236).
CVE-2026-23000: net/mlx5e: Fix crash on profile change rollback failure (bsc#1257234).
CVE-2026-23001: macvlan: fix possible UAF in macvlan_forward_source() (bsc#1257232).
CVE-2026-23005: x86/fpu: Clear XSTATE_BV in guest XSAVE state whenever XFD[i]=1 (bsc#1257245).
CVE-2026-23010: ipv6: Fix use-after-free in inet6_addr_del() (bsc#1257332).
CVE-2026-23011: ipv4: ip_gre: make ipgre_header() robust (bsc#1257207).
The following non security issues were fixed:
ALSA: usb-audio: Update for native DSD support quirks (stable-fixes).
Disable CONFIG_CPU5_WDT The cpu5wdt driver doesn't implement a
proper watchdog interface and has many code issues. It only handles
obscure and obsolete hardware. Stop building and supporting this driver
(jsc#PED-14062).