--- /dev/null
+From 289a2ca0c9b7eae74f93fc213b0b971669b8683d Mon Sep 17 00:00:00 2001
+From: Junrui Luo <moonafterrain@outlook.com>
+Date: Wed, 13 May 2026 17:28:40 +0800
+Subject: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
+
+From: Junrui Luo <moonafterrain@outlook.com>
+
+commit 289a2ca0c9b7eae74f93fc213b0b971669b8683d upstream.
+
+jbd2_journal_initialize_fast_commit() validates journal capacity by
+checking (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS).
+Both j_last and num_fc_blks are unsigned, so when num_fc_blks exceeds
+j_last the subtraction wraps to a large value, bypassing the bounds
+check.
+
+The resulting underflow corrupts j_last, j_fc_first, and j_free,
+leading to journal abort.
+
+Fix by checking num_fc_blks against j_last before the subtraction,
+returning -EFSCORRUPTED.
+
+Fixes: 6866d7b3f2bb ("ext4 / jbd2: add fast commit initialization")
+Reported-by: Yuhao Jiang <danisjiang@gmail.com>
+Cc: stable@vger.kernel.org
+Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
+Fixes: e029c5f27987 ("ext4: make num of fast commit blocks configurable")
+Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
+Fixes: e029c5f279872 ("ext4: make num of fast commit blocks configurable")
+Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
+Reviewed-by: Jan Kara <jack@suse.cz>
+Link: https://patch.msgid.link/SYBPR01MB7881663C927DE9D7BBF4D1DFAF062@SYBPR01MB7881.ausprd01.prod.outlook.com
+Signed-off-by: Theodore Ts'o <tytso@mit.edu>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/jbd2/journal.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+--- a/fs/jbd2/journal.c
++++ b/fs/jbd2/journal.c
+@@ -2286,6 +2286,8 @@ jbd2_journal_initialize_fast_commit(jour
+ unsigned long long num_fc_blks;
+
+ num_fc_blks = jbd2_journal_get_num_fc_blks(sb);
++ if (num_fc_blks > journal->j_last)
++ return -EFSCORRUPTED;
+ if (journal->j_last - num_fc_blks < JBD2_MIN_JOURNAL_BLOCKS)
+ return -ENOSPC;
+
--- /dev/null
+From f16a1513452edb532fec81e591c64c320866719c Mon Sep 17 00:00:00 2001
+From: Chuck Lever <chuck.lever@oracle.com>
+Date: Thu, 14 May 2026 16:56:04 -0400
+Subject: lockd: Plug nlm_file leak when nlm_do_fopen() fails
+
+From: Chuck Lever <chuck.lever@oracle.com>
+
+commit f16a1513452edb532fec81e591c64c320866719c upstream.
+
+A client can repeatedly drive nlm_do_fopen() failures by presenting
+file handles that the underlying export rejects. After kzalloc_obj()
+succeeds in nlm_lookup_file(), the freshly allocated nlm_file is not
+yet inserted into nlm_files[]. The nlm_do_fopen() failure path jumps
+to out_unlock, which releases nlm_file_mutex and returns without
+freeing the allocation, so each failure leaks one nlm_file.
+
+Route the failure through out_free so kfree() runs before the
+function returns.
+
+Fixes: 7f024fcd5c97 ("Keep read and write fds with each nlm_file")
+Cc: stable@vger.kernel.org
+Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/lockd/svcsubs.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/fs/lockd/svcsubs.c
++++ b/fs/lockd/svcsubs.c
+@@ -139,7 +139,7 @@ nlm_lookup_file(struct svc_rqst *rqstp,
+
+ nfserr = nlm_do_fopen(rqstp, file, mode);
+ if (nfserr)
+- goto out_unlock;
++ goto out_free;
+
+ hlist_add_head(&file->f_list, &nlm_files[hash]);
+
--- /dev/null
+From 70a38f87bed7f0694fd07988b47b2db1e10d8df3 Mon Sep 17 00:00:00 2001
+From: Chuck Lever <chuck.lever@oracle.com>
+Date: Thu, 14 May 2026 16:56:06 -0400
+Subject: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
+
+From: Chuck Lever <chuck.lever@oracle.com>
+
+commit 70a38f87bed7f0694fd07988b47b2db1e10d8df3 upstream.
+
+The cached-file path in nlm_lookup_file() reaches the found: label
+unconditionally, even when nlm_do_fopen() fails. At that label
+*result and file->f_count are updated before the error is returned.
+The wrappers nlm3svc_lookup_file() and nlm4svc_lookup_file() then
+bail out of their switch without copying *result back to their
+caller, so the proc handler's local nlm_file pointer remains NULL
+and the cleanup path skips nlm_release_file(). The f_count
+increment is never released, and nlm_traverse_files() can no
+longer reap the file because its refcount never returns to zero
+between requests.
+
+Short-circuit the cached path so neither *result nor f_count is
+touched when nlm_do_fopen() fails on a hashed nlm_file.
+
+Fixes: 7f024fcd5c97 ("Keep read and write fds with each nlm_file")
+Cc: stable@vger.kernel.org
+Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ fs/lockd/svcsubs.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+--- a/fs/lockd/svcsubs.c
++++ b/fs/lockd/svcsubs.c
+@@ -123,6 +123,8 @@ nlm_lookup_file(struct svc_rqst *rqstp,
+ mutex_lock(&file->f_mutex);
+ nfserr = nlm_do_fopen(rqstp, file, mode);
+ mutex_unlock(&file->f_mutex);
++ if (nfserr)
++ goto out_unlock;
+ goto found;
+ }
+ nlm_debug_print_fh("creating file for", &lock->fh);
--- /dev/null
+From 13fe4cd9ddd0aacb7777812328be525a11ea3fea Mon Sep 17 00:00:00 2001
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Date: Tue, 19 May 2026 11:20:12 +0530
+Subject: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path
+
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+
+commit 13fe4cd9ddd0aacb7777812328be525a11ea3fea upstream.
+
+Memory allocated by btt_freelist_init(), btt_rtt_init(), and
+btt_maplocks_init() is not freed on some discover_arenas() error
+paths. This leaks memory when arena discovery fails.
+
+Add the missing kfree() calls to release the allocations before
+returning an error.
+
+[ as: commit message and log edits ]
+
+Fixes: 5212e11fde4d ("nd_btt: atomic sector updates")
+Cc: stable@vger.kernel.org
+Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Reviewed-by: Alison Schofield <alison.schofield@intel.com>
+Link: https://patch.msgid.link/20260519-nvdimmleaks-v1-1-592300fb7a43@cse.iitm.ac.in
+Signed-off-by: Alison Schofield <alison.schofield@intel.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/nvdimm/btt.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/nvdimm/btt.c
++++ b/drivers/nvdimm/btt.c
+@@ -924,6 +924,9 @@ static int discover_arenas(struct btt *b
+ return ret;
+
+ out:
++ kfree(arena->freelist);
++ kfree(arena->rtt);
++ kfree(arena->map_locks);
+ kfree(arena);
+ free_arenas(btt);
+ out_super:
--- /dev/null
+From 1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57 Mon Sep 17 00:00:00 2001
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Date: Tue, 19 May 2026 11:20:13 +0530
+Subject: nvdimm/btt: Free arenas on btt_init() error paths
+
+From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+
+commit 1a6b6442a982d0ca5fb6a1a39b6f6dfd760eda57 upstream.
+
+The arenas allocated by discover_arenas() or create_arenas() are not
+freed on some error paths in btt_init(). This leaks memory when BTT
+initialization fails.
+
+Call free_arenas() from the affected error paths to release the
+allocations.
+
+[ as: commit message and log edits ]
+
+Fixes: 5212e11fde4d ("nd_btt: atomic sector updates")
+Cc: stable@vger.kernel.org
+Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
+Reviewed-by: Alison Schofield <alison.schofield@intel.com>
+Link: https://patch.msgid.link/20260519-nvdimmleaks-v1-2-592300fb7a43@cse.iitm.ac.in
+Signed-off-by: Alison Schofield <alison.schofield@intel.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/nvdimm/btt.c | 11 +++++++----
+ 1 file changed, 7 insertions(+), 4 deletions(-)
+
+--- a/drivers/nvdimm/btt.c
++++ b/drivers/nvdimm/btt.c
+@@ -1604,7 +1604,7 @@ static struct btt *btt_init(struct nd_bt
+ if (btt->init_state != INIT_READY && nd_region->ro) {
+ dev_warn(dev, "%s is read-only, unable to init btt metadata\n",
+ dev_name(&nd_region->dev));
+- return NULL;
++ goto err;
+ } else if (btt->init_state != INIT_READY) {
+ btt->num_arenas = (rawsize / ARENA_MAX_SIZE) +
+ ((rawsize % ARENA_MAX_SIZE) ? 1 : 0);
+@@ -1614,25 +1614,28 @@ static struct btt *btt_init(struct nd_bt
+ ret = create_arenas(btt);
+ if (ret) {
+ dev_info(dev, "init: create_arenas: %d\n", ret);
+- return NULL;
++ goto err;
+ }
+
+ ret = btt_meta_init(btt);
+ if (ret) {
+ dev_err(dev, "init: error in meta_init: %d\n", ret);
+- return NULL;
++ goto err;
+ }
+ }
+
+ ret = btt_blk_init(btt);
+ if (ret) {
+ dev_err(dev, "init: error in blk_init: %d\n", ret);
+- return NULL;
++ goto err;
+ }
+
+ btt_debugfs_init(btt);
+
+ return btt;
++err:
++ free_arenas(btt);
++ return NULL;
+ }
+
+ /**
mfd-tps6586x-fix-of-node-refcount.patch
bluetooth-sco-fix-sleeping-under-spinlock-in-sco_conn_ready.patch
bluetooth-sco-hold-sk-properly-in-sco_conn_ready.patch
+jbd2-fix-integer-underflow-in-jbd2_journal_initialize_fast_commit.patch
+nvdimm-btt-free-arenas-on-btt_init-error-paths.patch
+nvdimm-btt-free-arena-sub-allocations-on-discover_arenas-error-path.patch
+lockd-plug-nlm_file-leak-when-nlm_do_fopen-fails.patch
+lockd-plug-nlm_file-refcount-leak-on-cached-nlm_do_fopen-failure.patch