-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-9d4e48836d 2022-02-24 23:06:26.903827 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 35 Version : 5.16.10 Release : 200.fc35 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 5.16.10 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 16 2022 Justin M. Forbes[5.16.10-200] - New configs for 5.16.10 (Justin M. Forbes) * Wed Feb 16 2022 Justin M. Forbes [5.16.10-0] - Revert "x86/PCI: Ignore E820 reservations for bridge windows on newer systems" (Justin M. Forbes) - usb: gadget: clear related members when goto fail (Hangyu Hua) - usb: gadget: don't release an existing dev->buf (Hangyu Hua) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2053548 - CVE-2022-24958 kernel: use-after-free in dev->buf release in drivers/usb/gadget/legacy/inode.c https://bugzilla.redhat.com/show_bug.cgi?id=2053548 [ 2 ] Bug #2055502 - CVE-2022-25258 kernel: security issues in the OS descriptor handling section of composite_setup function (composite.c) https://bugzilla.redhat.com/show_bug.cgi?id=2055502 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-9d4e48836d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure