CVE-2025-40175: idpf: cleanup remaining SKBs in PTP flows (bsc#1253426).
CVE-2025-40176: tls: wait for pending async decryptions if tls_strp_msg_hold fails (bsc#1253425).
CVE-2025-40178: pid: Add a judgment for ns null in pid_nr_ns (bsc#1253463).
CVE-2025-40185: ice: ice_adapter: release xa entry on adapter allocation failure (bsc#1253394).
CVE-2025-40201: kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths (bsc#1253455).
CVE-2025-40203: listmount: don't call path_put() under namespace semaphore (bsc#1253457).
The following non security issues were fixed:
ACPI: scan: Update honor list for RPMI System MSI (stable-fixes).
ACPICA: Update dsmethod.c to get rid of unused variable warning (stable-fixes).
Disable CONFIG_CPU5_WDT The cpu5wdt driver doesn't implement a
proper watchdog interface and has many code issues. It only handles
obscure and obsolete hardware. Stop building and supporting this driver
(jsc#PED-14062).
Fix "drm/xe: Don't allow evicting of BOs in same VM in array of VM binds" (bsc#1252923)
KVM: SVM: Delete IRTE link from previous vCPU before setting new IRTE (git-fixes).
KVM: SVM: Delete IRTE link from previous vCPU irrespective of new routing (git-fixes).
KVM: SVM: Mark VMCB_LBR dirty when MSR_IA32_DEBUGCTLMSR is updated (git-fixes).
KVM: s390: improve interrupt cpu for wakeup (bsc#1235463).
KVM: s390: kABI backport for 'last_sleep_cpu' (bsc#1252352).
KVM: x86/mmu: Return -EAGAIN if userspace deletes/moves memslot during prefault (git-fixes).
PCI/ERR: Update device error_state already after reset (stable-fixes).