--- /dev/null
+From fe89277c9ceb0d6af0aa665bcf24a41d8b1b79cd Mon Sep 17 00:00:00 2001
+From: Guanghui Feng <guanghuifeng@linux.alibaba.com>
+Date: Mon, 16 Mar 2026 15:16:39 +0800
+Subject: iommu/vt-d: Fix intel iommu iotlb sync hardlockup and retry
+
+From: Guanghui Feng <guanghuifeng@linux.alibaba.com>
+
+commit fe89277c9ceb0d6af0aa665bcf24a41d8b1b79cd upstream.
+
+During the qi_check_fault process after an IOMMU ITE event, requests at
+odd-numbered positions in the queue are set to QI_ABORT, only satisfying
+single-request submissions. However, qi_submit_sync now supports multiple
+simultaneous submissions, and can't guarantee that the wait_desc will be
+at an odd-numbered position. Therefore, if an item times out, IOMMU can't
+re-initiate the request, resulting in an infinite polling wait.
+
+This modifies the process by setting the status of all requests already
+fetched by IOMMU and recorded as QI_IN_USE status (including wait_desc
+requests) to QI_ABORT, thus enabling multiple requests to be resubmitted.
+
+Fixes: 8a1d82462540 ("iommu/vt-d: Multiple descriptors per qi_submit_sync()")
+Cc: stable@vger.kernel.org
+Signed-off-by: Guanghui Feng <guanghuifeng@linux.alibaba.com>
+Tested-by: Shuai Xue <xueshuai@linux.alibaba.com>
+Reviewed-by: Shuai Xue <xueshuai@linux.alibaba.com>
+Reviewed-by: Samiullah Khawaja <skhawaja@google.com>
+Link: https://lore.kernel.org/r/20260306101516.3885775-1-guanghuifeng@linux.alibaba.com
+Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
+Fixes: 8a1d82462540 ("iommu/vt-d: Multiple descriptors per qi_submit_sync()")
+Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/iommu/intel/dmar.c | 3 +--
+ 1 file changed, 1 insertion(+), 2 deletions(-)
+
+--- a/drivers/iommu/intel/dmar.c
++++ b/drivers/iommu/intel/dmar.c
+@@ -1282,7 +1282,6 @@ static int qi_check_fault(struct intel_i
+ if (fault & DMA_FSTS_ITE) {
+ head = readl(iommu->reg + DMAR_IQH_REG);
+ head = ((head >> shift) - 1 + QI_LENGTH) % QI_LENGTH;
+- head |= 1;
+ tail = readl(iommu->reg + DMAR_IQT_REG);
+ tail = ((tail >> shift) - 1 + QI_LENGTH) % QI_LENGTH;
+
+@@ -1292,7 +1291,7 @@ static int qi_check_fault(struct intel_i
+ do {
+ if (qi->desc_status[head] == QI_IN_USE)
+ qi->desc_status[head] = QI_ABORT;
+- head = (head - 2 + QI_LENGTH) % QI_LENGTH;
++ head = (head - 1 + QI_LENGTH) % QI_LENGTH;
+ } while (head != tail);
+
+ if (qi->desc_status[wait_index] == QI_ABORT)
--- /dev/null
+From 5e3486e64094c28a526543f1e8aa0d5964b7f02d Mon Sep 17 00:00:00 2001
+From: Luke Wang <ziniu.wang_1@nxp.com>
+Date: Wed, 11 Mar 2026 17:50:06 +0800
+Subject: mmc: sdhci: fix timing selection for 1-bit bus width
+
+From: Luke Wang <ziniu.wang_1@nxp.com>
+
+commit 5e3486e64094c28a526543f1e8aa0d5964b7f02d upstream.
+
+When 1-bit bus width is used with HS200/HS400 capabilities set,
+mmc_select_hs200() returns 0 without actually switching. This
+causes mmc_select_timing() to skip mmc_select_hs(), leaving eMMC
+in legacy mode (26MHz) instead of High Speed SDR (52MHz).
+
+Per JEDEC eMMC spec section 5.3.2, 1-bit mode supports High Speed
+SDR. Drop incompatible HS200/HS400/UHS/DDR caps early so timing
+selection falls through to mmc_select_hs() correctly.
+
+Fixes: f2119df6b764 ("mmc: sd: add support for signal voltage switch procedure")
+Signed-off-by: Luke Wang <ziniu.wang_1@nxp.com>
+Acked-by: Adrian Hunter <adrian.hunter@intel.com>
+Cc: stable@vger.kernel.org
+Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/mmc/host/sdhci.c | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+--- a/drivers/mmc/host/sdhci.c
++++ b/drivers/mmc/host/sdhci.c
+@@ -4523,8 +4523,15 @@ int sdhci_setup_host(struct sdhci_host *
+ * their platform code before calling sdhci_add_host(), and we
+ * won't assume 8-bit width for hosts without that CAP.
+ */
+- if (!(host->quirks & SDHCI_QUIRK_FORCE_1_BIT_DATA))
++ if (host->quirks & SDHCI_QUIRK_FORCE_1_BIT_DATA) {
++ host->caps1 &= ~(SDHCI_SUPPORT_SDR104 | SDHCI_SUPPORT_SDR50 | SDHCI_SUPPORT_DDR50);
++ if (host->quirks2 & SDHCI_QUIRK2_CAPS_BIT63_FOR_HS400)
++ host->caps1 &= ~SDHCI_SUPPORT_HS400;
++ mmc->caps2 &= ~(MMC_CAP2_HS200 | MMC_CAP2_HS400 | MMC_CAP2_HS400_ES);
++ mmc->caps &= ~(MMC_CAP_DDR | MMC_CAP_UHS);
++ } else {
+ mmc->caps |= MMC_CAP_4_BIT_DATA;
++ }
+
+ if (host->quirks2 & SDHCI_QUIRK2_HOST_NO_CMD23)
+ mmc->caps &= ~MMC_CAP_CMD23;
--- /dev/null
+From 2b76e0cc7803e5ab561c875edaba7f6bbd87fbb0 Mon Sep 17 00:00:00 2001
+From: Matthew Schwartz <matthew.schwartz@linux.dev>
+Date: Mon, 2 Mar 2026 13:07:17 -0800
+Subject: mmc: sdhci-pci-gli: fix GL9750 DMA write corruption
+
+From: Matthew Schwartz <matthew.schwartz@linux.dev>
+
+commit 2b76e0cc7803e5ab561c875edaba7f6bbd87fbb0 upstream.
+
+The GL9750 SD host controller has intermittent data corruption during
+DMA write operations. The GM_BURST register's R_OSRC_Lmt field
+(bits 17:16), which limits outstanding DMA read requests from system
+memory, is not being cleared during initialization. The Windows driver
+sets R_OSRC_Lmt to zero, limiting requests to the smallest unit.
+
+Clear R_OSRC_Lmt to match the Windows driver behavior. This eliminates
+write corruption verified with f3write/f3read tests while maintaining
+DMA performance.
+
+Cc: stable@vger.kernel.org
+Fixes: e51df6ce668a ("mmc: host: sdhci-pci: Add Genesys Logic GL975x support")
+Closes: https://lore.kernel.org/linux-mmc/33d12807-5c72-41ce-8679-57aa11831fad@linux.dev/
+Acked-by: Adrian Hunter <adrian.hunter@intel.com>
+Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
+Reviewed-by: Ben Chuang <ben.chuang@genesyslogic.com.tw>
+Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/mmc/host/sdhci-pci-gli.c | 9 +++++++++
+ 1 file changed, 9 insertions(+)
+
+--- a/drivers/mmc/host/sdhci-pci-gli.c
++++ b/drivers/mmc/host/sdhci-pci-gli.c
+@@ -70,6 +70,9 @@
+ #define GLI_9750_MISC_TX1_DLY_VALUE 0x5
+ #define SDHCI_GLI_9750_MISC_SSC_OFF BIT(26)
+
++#define SDHCI_GLI_9750_GM_BURST_SIZE 0x510
++#define SDHCI_GLI_9750_GM_BURST_SIZE_R_OSRC_LMT GENMASK(17, 16)
++
+ #define SDHCI_GLI_9750_TUNING_CONTROL 0x540
+ #define SDHCI_GLI_9750_TUNING_CONTROL_EN BIT(4)
+ #define GLI_9750_TUNING_CONTROL_EN_ON 0x1
+@@ -212,10 +215,16 @@ static void gli_set_9750(struct sdhci_ho
+ u32 misc_value;
+ u32 parameter_value;
+ u32 control_value;
++ u32 burst_value;
+ u16 ctrl2;
+
+ gl9750_wt_on(host);
+
++ /* clear R_OSRC_Lmt to avoid DMA write corruption */
++ burst_value = sdhci_readl(host, SDHCI_GLI_9750_GM_BURST_SIZE);
++ burst_value &= ~SDHCI_GLI_9750_GM_BURST_SIZE_R_OSRC_LMT;
++ sdhci_writel(host, burst_value, SDHCI_GLI_9750_GM_BURST_SIZE);
++
+ driving_value = sdhci_readl(host, SDHCI_GLI_9750_DRIVING);
+ pll_value = sdhci_readl(host, SDHCI_GLI_9750_PLL);
+ sw_ctrl_value = sdhci_readl(host, SDHCI_GLI_9750_SW_CTRL);
--- /dev/null
+From 8e2f8020270af7777d49c2e7132260983e4fc566 Mon Sep 17 00:00:00 2001
+From: Finn Thain <fthain@linux-m68k.org>
+Date: Mon, 16 Feb 2026 18:01:30 +1100
+Subject: mtd: Avoid boot crash in RedBoot partition table parser
+
+From: Finn Thain <fthain@linux-m68k.org>
+
+commit 8e2f8020270af7777d49c2e7132260983e4fc566 upstream.
+
+Given CONFIG_FORTIFY_SOURCE=y and a recent compiler,
+commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when
+available") produces the warning below and an oops.
+
+ Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000
+ ------------[ cut here ]------------
+ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1
+ memcmp: detected buffer overflow: 15 byte read of buffer size 14
+ Modules linked in:
+ CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE
+
+As Kees said, "'names' is pointing to the final 'namelen' many bytes
+of the allocation ... 'namelen' could be basically any length at all.
+This fortify warning looks legit to me -- this code used to be reading
+beyond the end of the allocation."
+
+Since the size of the dynamic allocation is calculated with strlen()
+we can use strcmp() instead of memcmp() and remain within bounds.
+
+Cc: Kees Cook <kees@kernel.org>
+Cc: stable@vger.kernel.org
+Cc: linux-hardening@vger.kernel.org
+Link: https://lore.kernel.org/all/202602151911.AD092DFFCD@keescook/
+Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
+Suggested-by: Kees Cook <kees@kernel.org>
+Signed-off-by: Finn Thain <fthain@linux-m68k.org>
+Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/mtd/parsers/redboot.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+--- a/drivers/mtd/parsers/redboot.c
++++ b/drivers/mtd/parsers/redboot.c
+@@ -270,9 +270,9 @@ nogood:
+
+ strcpy(names, fl->img->name);
+ #ifdef CONFIG_MTD_REDBOOT_PARTS_READONLY
+- if (!memcmp(names, "RedBoot", 8) ||
+- !memcmp(names, "RedBoot config", 15) ||
+- !memcmp(names, "FIS directory", 14)) {
++ if (!strcmp(names, "RedBoot") ||
++ !strcmp(names, "RedBoot config") ||
++ !strcmp(names, "FIS directory")) {
+ parts[i].mask_flags = MTD_WRITEABLE;
+ }
+ #endif
--- /dev/null
+From 0410e1a4c545c769c59c6eda897ad5d574d0c865 Mon Sep 17 00:00:00 2001
+From: Chen Ni <nichen@iscas.ac.cn>
+Date: Mon, 9 Feb 2026 15:56:18 +0800
+Subject: mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init()
+
+From: Chen Ni <nichen@iscas.ac.cn>
+
+commit 0410e1a4c545c769c59c6eda897ad5d574d0c865 upstream.
+
+Fix wrong variable used for error checking after dma_alloc_coherent()
+call. The function checks cdns_ctrl->dma_cdma_desc instead of
+cdns_ctrl->cdma_desc, which could lead to incorrect error handling.
+
+Fixes: ec4ba01e894d ("mtd: rawnand: Add new Cadence NAND driver to MTD subsystem")
+Cc: stable@vger.kernel.org
+Signed-off-by: Chen Ni <nichen@iscas.ac.cn>
+Reviewed-by: Alok Tiwari <alok.a.tiwari@oracle.com>
+Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/mtd/nand/raw/cadence-nand-controller.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+--- a/drivers/mtd/nand/raw/cadence-nand-controller.c
++++ b/drivers/mtd/nand/raw/cadence-nand-controller.c
+@@ -2837,7 +2837,7 @@ static int cadence_nand_init(struct cdns
+ sizeof(*cdns_ctrl->cdma_desc),
+ &cdns_ctrl->dma_cdma_desc,
+ GFP_KERNEL);
+- if (!cdns_ctrl->dma_cdma_desc)
++ if (!cdns_ctrl->cdma_desc)
+ return -ENOMEM;
+
+ cdns_ctrl->buf_size = SZ_16K;
--- /dev/null
+From b9465b04de4b90228de03db9a1e0d56b00814366 Mon Sep 17 00:00:00 2001
+From: Olivier Sobrie <olivier@sobrie.be>
+Date: Tue, 17 Mar 2026 18:18:07 +0100
+Subject: mtd: rawnand: pl353: make sure optimal timings are applied
+
+From: Olivier Sobrie <olivier@sobrie.be>
+
+commit b9465b04de4b90228de03db9a1e0d56b00814366 upstream.
+
+Timings of the nand are adjusted by pl35x_nfc_setup_interface() but
+actually applied by the pl35x_nand_select_target() function.
+If there is only one nand chip, the pl35x_nand_select_target() will only
+apply the timings once since the test at its beginning will always be true
+after the first call to this function. As a result, the hardware will
+keep using the default timings set at boot to detect the nand chip, not
+the optimal ones.
+
+With this patch, we program directly the new timings when
+pl35x_nfc_setup_interface() is called.
+
+Fixes: 08d8c62164a3 ("mtd: rawnand: pl353: Add support for the ARM PL353 SMC NAND controller")
+Signed-off-by: Olivier Sobrie <olivier@sobrie.be>
+Cc: stable@vger.kernel.org
+Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/mtd/nand/raw/pl35x-nand-controller.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+--- a/drivers/mtd/nand/raw/pl35x-nand-controller.c
++++ b/drivers/mtd/nand/raw/pl35x-nand-controller.c
+@@ -864,6 +864,9 @@ static int pl35x_nfc_setup_interface(str
+ PL35X_SMC_NAND_TAR_CYCLES(tmgs.t_ar) |
+ PL35X_SMC_NAND_TRR_CYCLES(tmgs.t_rr);
+
++ writel(plnand->timings, nfc->conf_regs + PL35X_SMC_CYCLES);
++ pl35x_smc_update_regs(nfc);
++
+ return 0;
+ }
+
bluetooth-l2cap-validate-l2cap_info_rsp-payload-length-before-access.patch
smb-client-fix-krb5-mount-with-username-option.patch
ksmbd-unset-conn-binding-on-failed-binding-request.patch
+mmc-sdhci-pci-gli-fix-gl9750-dma-write-corruption.patch
+mmc-sdhci-fix-timing-selection-for-1-bit-bus-width.patch
+spi-fix-use-after-free-on-controller-registration-failure.patch
+spi-fix-statistics-allocation.patch
+mtd-rawnand-pl353-make-sure-optimal-timings-are-applied.patch
+mtd-rawnand-cadence-fix-error-check-for-dma_alloc_coherent-in-cadence_nand_init.patch
+mtd-avoid-boot-crash-in-redboot-partition-table-parser.patch
+iommu-vt-d-fix-intel-iommu-iotlb-sync-hardlockup-and-retry.patch
--- /dev/null
+From dee0774bbb2abb172e9069ce5ffef579b12b3ae9 Mon Sep 17 00:00:00 2001
+From: Johan Hovold <johan@kernel.org>
+Date: Thu, 12 Mar 2026 16:18:14 +0100
+Subject: spi: fix statistics allocation
+
+From: Johan Hovold <johan@kernel.org>
+
+commit dee0774bbb2abb172e9069ce5ffef579b12b3ae9 upstream.
+
+The controller per-cpu statistics is not allocated until after the
+controller has been registered with driver core, which leaves a window
+where accessing the sysfs attributes can trigger a NULL-pointer
+dereference.
+
+Fix this by moving the statistics allocation to controller allocation
+while tying its lifetime to that of the controller (rather than using
+implicit devres).
+
+Fixes: 6598b91b5ac3 ("spi: spi.c: Convert statistics to per-cpu u64_stats_t")
+Cc: stable@vger.kernel.org # 6.0
+Cc: David Jander <david@protonic.nl>
+Signed-off-by: Johan Hovold <johan@kernel.org>
+Link: https://patch.msgid.link/20260312151817.32100-3-johan@kernel.org
+Signed-off-by: Mark Brown <broonie@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/spi/spi.c | 17 ++++++++---------
+ 1 file changed, 8 insertions(+), 9 deletions(-)
+
+--- a/drivers/spi/spi.c
++++ b/drivers/spi/spi.c
+@@ -2768,6 +2768,8 @@ static void spi_controller_release(struc
+ struct spi_controller *ctlr;
+
+ ctlr = container_of(dev, struct spi_controller, dev);
++
++ free_percpu(ctlr->pcpu_statistics);
+ kfree(ctlr);
+ }
+
+@@ -2922,6 +2924,12 @@ struct spi_controller *__spi_alloc_contr
+ if (!ctlr)
+ return NULL;
+
++ ctlr->pcpu_statistics = spi_alloc_pcpu_stats(NULL);
++ if (!ctlr->pcpu_statistics) {
++ kfree(ctlr);
++ return NULL;
++ }
++
+ device_initialize(&ctlr->dev);
+ INIT_LIST_HEAD(&ctlr->queue);
+ spin_lock_init(&ctlr->queue_lock);
+@@ -3215,13 +3223,6 @@ int spi_register_controller(struct spi_c
+ if (status)
+ goto del_ctrl;
+ }
+- /* Add statistics */
+- ctlr->pcpu_statistics = spi_alloc_pcpu_stats(dev);
+- if (!ctlr->pcpu_statistics) {
+- dev_err(dev, "Error allocating per-cpu statistics\n");
+- status = -ENOMEM;
+- goto destroy_queue;
+- }
+
+ mutex_lock(&board_lock);
+ list_add_tail(&ctlr->list, &spi_controller_list);
+@@ -3234,8 +3235,6 @@ int spi_register_controller(struct spi_c
+ acpi_register_spi_devices(ctlr);
+ return status;
+
+-destroy_queue:
+- spi_destroy_queue(ctlr);
+ del_ctrl:
+ device_del(&ctlr->dev);
+ free_bus_id:
--- /dev/null
+From 8634e05b08ead636e926022f4a98416e13440df9 Mon Sep 17 00:00:00 2001
+From: Johan Hovold <johan@kernel.org>
+Date: Thu, 12 Mar 2026 16:18:13 +0100
+Subject: spi: fix use-after-free on controller registration failure
+
+From: Johan Hovold <johan@kernel.org>
+
+commit 8634e05b08ead636e926022f4a98416e13440df9 upstream.
+
+Make sure to deregister from driver core also in the unlikely event that
+per-cpu statistics allocation fails during controller registration to
+avoid use-after-free (of driver resources) and unclocked register
+accesses.
+
+Fixes: 6598b91b5ac3 ("spi: spi.c: Convert statistics to per-cpu u64_stats_t")
+Cc: stable@vger.kernel.org # 6.0
+Cc: David Jander <david@protonic.nl>
+Signed-off-by: Johan Hovold <johan@kernel.org>
+Link: https://patch.msgid.link/20260312151817.32100-2-johan@kernel.org
+Signed-off-by: Mark Brown <broonie@kernel.org>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ drivers/spi/spi.c | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+--- a/drivers/spi/spi.c
++++ b/drivers/spi/spi.c
+@@ -3212,10 +3212,8 @@ int spi_register_controller(struct spi_c
+ dev_info(dev, "controller is unqueued, this is deprecated\n");
+ } else if (ctlr->transfer_one || ctlr->transfer_one_message) {
+ status = spi_controller_initialize_queue(ctlr);
+- if (status) {
+- device_del(&ctlr->dev);
+- goto free_bus_id;
+- }
++ if (status)
++ goto del_ctrl;
+ }
+ /* Add statistics */
+ ctlr->pcpu_statistics = spi_alloc_pcpu_stats(dev);
+@@ -3238,6 +3236,8 @@ int spi_register_controller(struct spi_c
+
+ destroy_queue:
+ spi_destroy_queue(ctlr);
++del_ctrl:
++ device_del(&ctlr->dev);
+ free_bus_id:
+ mutex_lock(&board_lock);
+ idr_remove(&spi_master_idr, ctlr->bus_num);