[5.15.0-310.184.5.2.el9uek] - sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (Jeff Layton) {CVE-2025-38089} - net_sched: sch_sfq: move the limit validation (Octavian Purdila) {CVE-2025-37752} - net_sched: sch_sfq: use a temporary work area for validating configuration (Octavian Purdila) - net_sched: sch_sfq: don't allow 1 packet limit (Octavian Purdila) - net_sched: sch_sfq: handle bigger packets (Eric Dumazet) - net_sched: sch_sfq: annotate data-races around q->perturb_period (Eric Dumazet) - block: assign bi_bdev for cloned bios in blk_rq_prep_clone (Christoph Hellwig) [Orabug: 37931495] - fs/proc: do_task_stat: use __for_each_thread() (Oleg Nesterov) [Orabug: 38081922] [5.15.0-310.184.5.1.el9uek] - Add Zen34 clients (Borislav Petkov (AMD)) [Orabug: 38023240] {CVE-2024-36350} {CVE-2024-36357} - x86/process: Move the buffer clearing before MONITOR (Kim Phillips) [Orabug: 38023240] {CVE-2024-36350} {CVE-2024-36357} - Add normal counters (Borislav...
Read the Full Advisory
http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-5.15.0-310.184.5.2.el9uek.src.rpm
bpftool-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-core-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-debug-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-debug-core-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-debug-devel-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-debug-modules-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-debug-modules-extra-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-devel-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-doc-5.15.0-310.184.5.2.el9uek.noarch.rpm kernel-uek-modules-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-modules-extra-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-container-5.15.0-310.184.5.2.el9uek.x86_64.rpm kernel-uek-container-debug-5.15.0-310.184.5.2.el9uek.x86_64.rpm
- x86/its: its_native_only bug is not correctly reported (Alexandre Chartre) [Orabug: 37960160] - RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad) [Orabug: 37358844] - amd_hsmp: Increase the SMU timeout to 500ms (Vijay Kumar) [Orabug: 37266677] - bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags (Alan Maguire) [Orabug: 36699198] [5.15.0-309.180.4.el9uek] - nvme: unblock ctrl state transition for firmware update (Daniel Wagner) - nfsd: decrease sc_count directly if fail to queue dl_recall (Li Lingfeng) [Orabug: 37938121] {CVE-2025-37871} - cpufreq/sched: Fix the usage of CPUFREQ_NEED_UPDATE_LIMITS (Rafael J. Wysocki) - ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr() (Luoxuanqiang) [Orabug: 37976780] {CVE-2025-37912} - usb: chipidea: ci_hdrc_imx: fix usbmisc handling (Fedor Pchelkin) [Orabug: 37938106] {CVE-2025-37811} - Revert "PCI: Avoid reset when disabled via sysfs" (Alex Williamson) - uek-rpm: CONFIG_PTP_1588_CLOCK_OCP enable for OCI (Vijayendra Suman) [Orabug: 37777354] - ptp: ocp: let ptp core report driver name instead of the drivers (Vijayendra Suman) [Orabug: 37777354] - ptp: ocp: Add .getmaxphase ptp_clock_info callback (Rahul Rameshbabu) [Orabug: 37777354] - ptp: ocp: remove flash image header check fallback (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: expose config and temperature for ART card (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: add serial port of mRO50 MAC on ART card (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: add Orolia timecard support (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: upgrade serial line information (Vadim Fedorenko) [Orabug: 37777354] - ] ptp: ocp: remove symlink for second GNSS (Vadim Fedorenko) [Orabug: 37777354] - ptp_ocp: use device_find_any_child() instead of custom approach (Andy Shevchenko) [Orabug: 37777354] - ptp_ocp: replace kzalloc(x*y) by kcalloc(y, x) (Andy Shevchenko) [Orabug: 37777354] - ptp_ocp: do not call pci_set_drvdata(pdev, NULL) (Andy Shevchenko) [Orabug: 37777354] - ptp_ocp: drop duplicate NULL check in ptp_ocp_detach() (Andy Shevchenko) [Orabug: 37777354] - ptp_ocp: use bits.h macros for all masks (Andy Shevchenko) [Orabug: 37777354] - ptp: ocp: Add firmware header checks (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: fix PPS source selector debugfs reporting (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: add .init function for sma_op vector (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: vectorize the sma accessor functions (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: constify selectors (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: parameterize input/output sma selectors (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: revise firmware display (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: add Celestica timecard PCI ids (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: Remove #ifdefs around PCI IDs (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: 32-bit fixups for pci start address (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: change sysfs attr group handling (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: have adjtime handle negative delta_ns correctly (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Use DIV64_U64_ROUND_UP for rounding. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: handle error from nvmem_device_find (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: use snprintf() in ptp_ocp_verify() (Dan Carpenter) [Orabug: 37777354] - ptp: ocp: Make debugfs variables the correct bitwidth (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Fix PTP_PF_* verification requests (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add 2 more timestampers (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add 4 frequency counters (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Program the signal generators via PTP_CLK_REQ_PEROUT (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add signal generators and update sysfs nodes (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add firmware capability bits for feature gating (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add GND and VCC output selectors (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Rename output selector 'GNSS' to 'GNSS1' (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add ability to disable input selectors. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add support for selectable SMA directions. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: add UPF_NO_THRE_TEST flag for serial ports (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Update devlink firmware display path. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: add nvmem interface for accessing eeprom (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: correct label for error path (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: off by in in ptp_ocp_tod_gnss_name() (Dan Carpenter) [Orabug: 37777354] - ptp: ocp: Add serial port information to the debug summary (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: adjust utc_tai_offset to TOD info (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: add tod_correction attribute (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: Expose clock status drift and offset (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: add TOD debug information (Vadim Fedorenko) [Orabug: 37777354] - ptp: ocp: Add ptp_ocp_adjtime_coarse for large adjustments (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Move devlink registration to be last devlink command (Leon Romanovsky) [Orabug: 37777354] - ptp: ocp: Avoid operator precedence warning in ptp_ocp_summary_show() (Nathan Chancellor) [Orabug: 37777354] - ptp: ocp: Add timestamp window adjustment (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Have FPGA fold in ns adjustment for adjtime. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Enable 4th timestamper / PPS generator (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add second GNSS device (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add NMEA output (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add debugfs entry for timecard (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Separate the init and info logic (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add sysfs attribute utc_tai_offset (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add IRIG-B output mode control (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add IRIG-B and DCF blocks (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add SMA selector and controls (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Add third timestamper (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Report error if resource registration fails. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Skip resources with out of range irqs (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Skip I2C flash read when there is no controller. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: Parameterize the TOD information display. (Jonathan Lemon) [Orabug: 37777354] - ptp: ocp: parameterize the i2c driver used (Jonathan Lemon) [Orabug: 37777354] - vhost-scsi: log event queue write descriptors (Dongli Zhang) [Orabug: 37884058] - vhost-scsi: log control queue write descriptors (Dongli Zhang) [Orabug: 37884058] - vhost-scsi: log I/O queue write descriptors (Dongli Zhang) [Orabug: 37884058] - vhost-scsi: adjust vhost_scsi_get_desc() to log vring descriptors (Dongli Zhang) [Orabug: 37884058] - vhost: modify vhost_log_write() for broader users (Dongli Zhang) [Orabug: 37884058] - mm: make page_mapped_in_vma() hugetlb walk aware (Jane Chu) [Orabug: 37956589] - mm/rmap: Fix handling of hugetlbfs pages in page_vma_mapped_walk (Zhenwei Pi) [Orabug: 37956589] - ext4: update the backup superblock's at the end of the online resize (Theodore Ts'O) [Orabug: 37356729] - gve: ignore nonrelevant GSO type bits when processing TSO headers (Joshua Washington) [Orabug: 37356729] - gve: update gve.rst (Rushil Gupta) [Orabug: 37356729] - gve: RX path for DQO-QPL (Rushil Gupta) [Orabug: 37356729] - gve: Tx path for DQO-QPL (Rushil Gupta) [Orabug: 37356729] - gve: Control path for DQO-QPL (Rushil Gupta) [Orabug: 37356729] - gve: Fix gve interrupt names (Praveen Kaligineedi) [Orabug: 37356729] - gve: Handle alternate miss completions (Jeroen de Borst) [Orabug: 37356729] - gve: Adding a new AdminQ command to verify driver (Jeroen de Borst) [Orabug: 37356729] - gve: Fix error return code in gve_prefill_rx_pages() (Yang Yingliang) [Orabug: 37356729] - gve: Reduce alloc and copy costs in the GQ rx path (Shailend Chand) [Orabug: 37356729] - google/gve:fix repeated words in comments (Jilin Yuan) [Orabug: 37356729] - gve: Fix spelling mistake "droping" -> "dropping" (Colin Ian King) [Orabug: 37356729] - gve: enhance no queue page list detection (Haiyue Wang) [Orabug: 37356729] - gve: Recording rx queue before sending to napi (Tao Liu) [Orabug: 37356729] - ext4: add ioctls to get/set the ext4 superblock uuid (Jeremy Bongio) [Orabug: 37356729] - ext4: implement support for get/set fs label (Lukas Czerner) [Orabug: 37356729] - gve: Add tx|rx-coalesce-usec for DQO (Tao Liu) [Orabug: 37356729] - gve: Add consumed counts to ethtool stats (Jordan Kim) [Orabug: 37356729] - gve: Implement suspend/resume/shutdown (Catherine Sullivan) [Orabug: 37356729] - gve: Add optional metadata descriptor type GVE_TXD_MTD (Willem de Bruijn) [Orabug: 37356729] - gve: remove memory barrier around seqno (Catherine Sullivan) [Orabug: 37356729] - gve: Update gve_free_queue_page_list signature (Catherine Sullivan) [Orabug: 37356729] - gve: Move the irq db indexes out of the ntfy block struct (Catherine Sullivan) [Orabug: 37356729] - gve: Correct order of processing device options (Jeroen de Borst) [Orabug: 37356729] - gve: fix for null pointer dereference. (Ameer Hamza) [Orabug: 37356729] - gve: fix unmatched u64_stats_update_end() (Dan Carpenter) [Orabug: 37356729] - gve: Add a jumbo-frame device option. (Shailend Chand) [Orabug: 37356729] - gve: Implement packet continuation for RX. (David Awogbemila) [Orabug: 37356729] - gve: Allow pageflips on larger pages (Jordan Kim) [Orabug: 37356729] - gve: Add netif_set_xps_queue call (Catherine Sullivan) [Orabug: 37356729] - gve: Do lazy cleanup in TX path (Tao Liu) [Orabug: 37356729] - gve: Add rx buffer pagecnt bias (Catherine Sullivan) [Orabug: 37356729] - gve: Switch to use napi_complete_done (Yanchun Fu) [Orabug: 37356729] - gve: Use kvcalloc() instead of kvzalloc() (Gustavo A R Silva) [Orabug: 37356729] - selftests/net: optmem_max became per netns (Eric Dumazet) [Orabug: 37356732] - tcp: derive delack_max with tcp_rto_min helper (Kevin Yang) [Orabug: 37356732] - tcp: derive delack_max from rto_min (Eric Dumazet) [Orabug: 37356732] - tcp: add sysctl_tcp_rto_min_us (Kevin Yang) [Orabug: 37356732] - tcp: constify tcp_rto_min() and tcp_rto_min_us() argument (Eric Dumazet) [Orabug: 37356732] - net: constify sk_dst_get() and __sk_dst_get() argument (Eric Dumazet) [Orabug: 37356732] - net: Namespace-ify sysctl_optmem_max (Eric Dumazet) [Orabug: 37356732] - net: increase optmem_max default value (Eric Dumazet) [Orabug: 37356732] - net: phy: dp83867: Fix SGMII FIFO depth for non OF devices (Michael Sit Wei Hong) [Orabug: 37670821] - net: phy: dp83867: fix get nvmem cell fail (Nikita Shubin) [Orabug: 37670821] - net: phy: dp83867: implement support for io_impedance_ctrl nvmem cell (Rasmus Villemoes) [Orabug: 37670821] - net: phy: constify netdev->dev_addr references (Jakub Kicinski) [Orabug: 37670821] - net: phy: dp83867: introduce critical chip default init for non-of platform (Lay, Kuan Loon) [Orabug: 37670821] - RDS: use pin_user_pages_fast() (Stephen Brennan) [Orabug: 37872748] - uek-rpm: Reduce the size of the Bluefield 3 kernel (Henry Willard) [Orabug: 37910874] - uek-rpm: Make sure dtb directory exists for emb3. (Henry Willard) [Orabug: 37910874] - uek-rpm: Move the gve kernel module from extra to kernel-uek-core (Samasth Norway Ananda) [Orabug: 37940898] - platform/mellanox: mlxbf-pmc: Support additional PMC blocks (Shravan Kumar Ramani) [Orabug: 37955981] - mlxbf-bootctl: use sysfs_emit_at() in secure_boot_fuse_state_show() (David Thompson) [Orabug: 37955981,37989158] {CVE-2025-37866} - mlxbf-bootctl: Support sysfs entries for RTC battery status (Xiangrong Li) [Orabug: 37955981] - platform/mellanox: mlxbf-bootctl: use sysfs_emit() instead of sprintf() (Ai Chao) [Orabug: 37955981] - drivers/platform/mellanox: Convert snprintf to sysfs_emit (Li Zhijian) [Orabug: 37955981] - certs: Add new Oracle Linux Driver Signing (key 1) certificate (Sherry Yang) [Orabug: 37967553] [5.15.0-309.180.3.el9uek] - net/mlx5: Reclaim max 50K pages at once (Anand Khoje) [Orabug: 36933755] - x86/sev: Fix position dependent variable references in startup code (Ard Biesheuvel) [Orabug: 37356711] - x86/PCI: Export find_cap() to be used in early PCI code (Rayan Dasoriya) [Orabug: 37356711] - x86/quirks: Scan all busses for early PCI quirks (Rayan Dasoriya) [Orabug: 37356711] - x86/quirks: Add parameter to clear MSIs early on boot (Rayan Dasoriya) [Orabug: 37356711] - iommu/amd: Add map/unmap_pages() iommu_domain_ops callback support (Vasant Hegde) [Orabug: 37356711] - iommu/amd/io-pgtable: Implement unmap_pages io_pgtable_ops callback (Vasant Hegde) [Orabug: 37356711] - iommu/amd/io-pgtable: Implement map_pages io_pgtable_ops callback (Vasant Hegde) [Orabug: 37356711] - iommu/amd: Use put_pages_list (Matthew Wilcox) [Orabug: 37356711] - x86/sev: Make enc_dec_hypercall() accept a size instead of npages (Steve Rutherford) [Orabug: 37356711] - iommu/amd: Simplify pagetable freeing (Robin Murphy) [Orabug: 37356711] - x86/kvm: Add kexec support for SEV Live Migration. (Ashish Kalra) [Orabug: 37356711] - nfsd: allow layout state to be admin-revoked. (Neil Brown) [Orabug: 37644985] - nfsd: allow delegation state ids to be revoked and then freed (Neil Brown) [Orabug: 37644985] - nfsd: allow open state ids to be revoked and then freed (Neil Brown) [Orabug: 37644985] - nfsd: allow lock state ids to be revoked and then freed (Neil Brown) [Orabug: 37644985] - nfsd: allow admin-revoked NFSv4.0 state to be freed. (Neil Brown) [Orabug: 37644985] - nfsd: report in /proc/fs/nfsd/clients/*/states when state is admin-revoke (Neil Brown) [Orabug: 37644985] - nfsd: allow state with no file to appear in /proc/fs/nfsd/clients/*/states (Neil Brown) [Orabug: 37644985] - nfsd: prepare for supporting admin-revocation of state (Neil Brown) [Orabug: 37644985] - nfsd: split sc_status out of sc_type (Neil Brown) [Orabug: 37644985] - nfsd: remove stale comment in nfs4_show_deleg() (Neil Brown) [Orabug: 37644985] - nfsd: avoid race after unhash_delegation_locked() (Neil Brown) [Orabug: 37644985] - nfsd: don't call functions with side-effecting inside WARN_ON() (Neil Brown) [Orabug: 37644985] - NFSD: Add nfsd_seq4_status trace event (Chuck Lever) [Orabug: 37644985] - NFSD: Clean up nfsd4_encode_layoutreturn() (Chuck Lever) [Orabug: 37644985] - NFSD: Make @lgp parameter of ->encode_layoutget a const pointer (Chuck Lever) [Orabug: 37644985] - NFSD: Clean up nfsd4_encode_stateid() (Chuck Lever) [Orabug: 37644985] - NFSD: Add simple u32, u64, and bool encoders (Chuck Lever) [Orabug: 37644985] - NFSD: Add encoders for NFSv4 clientids and verifiers (Chuck Lever) [Orabug: 37644985] - nfsd: add some kerneldoc comments for stateid preprocessing functions (Jeff Layton) [Orabug: 37644985] - nfsd: eliminate find_deleg_file_locked (Jeff Layton) [Orabug: 37644985] - nfsd: fix potential race in nfs4_find_file (Jeff Layton) [Orabug: 37644985] - vhost-scsi: Fix vhost_scsi_send_status() (Dongli Zhang) [Orabug: 37840544] - vhost-scsi: Fix vhost_scsi_send_bad_target() (Dongli Zhang) [Orabug: 37840544] - vhost-scsi: protect vq->log_used with vq->mutex (Dongli Zhang) [Orabug: 37840544,38095126] {CVE-2025-38074} - vhost-scsi: Reduce response iov mem use (Mike Christie) [Orabug: 37840544] - vhost-scsi: Allocate iov_iter used for unaligned copies when needed (Mike Christie) [Orabug: 37840544] - vhost-scsi: Stop duplicating se_cmd fields (Mike Christie) [Orabug: 37840544] - vhost-scsi: Dynamically allocate scatterlists (Mike Christie) [Orabug: 37840544] - vhost-scsi: Return queue full for page alloc failures during copy (Mike Christie) [Orabug: 37840544] - vhost-scsi: Add better resource allocation failure handling (Mike Christie) [Orabug: 37840544] - vhost-scsi: Allocate T10 PI structs only when enabled (Mike Christie) [Orabug: 37840544] - vhost-scsi: Reduce mem use by moving upages to per queue (Mike Christie) [Orabug: 37840544] - scsi: target: core: Use RCU helpers for INQUIRY t10_alua_tg_pt_gp (Mike Christie) [Orabug: 37840544] - scsi: target: Perform ALUA group changes in one step (Mike Christie) [Orabug: 37840544] - scsi: target: Replace lun_tg_pt_gp_lock with rcu in I/O path (Mike Christie) [Orabug: 37840544] - scsi: target: Fix write perf due to unneeded throttling (Mike Christie) [Orabug: 37840544] - vhost scsi: Allow user to control num virtqueues (Mike Christie) [Orabug: 37840544] - vhost-scsi: Rename vhost_scsi_iov_to_sgl (Mike Christie) [Orabug: 37840544] - vhost-scsi: unbreak any layout for response (Jason Wang) [Orabug: 37840544] - Revert "vhost-scsi: protect vq->log_base with vq->mutex" (Mike Christie) [Orabug: 37840544] - Revert "vhost_scsi: log write descriptors" (Mike Christie) [Orabug: 37840544] - x86/bugs: Enabling Retbleed and SRSO mitigation can taint the kernel (Alexandre Chartre) [Orabug: 37945824] - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (Pawan Gupta) [Orabug: 37945831] - x86/bpf: Add IBHF call at end of classic BPF (Daniel Sneddon) [Orabug: 37945831] - x86/bpf: Call branch history clearing sequence on exit (Daniel Sneddon) [Orabug: 37945831] - selftest/x86/bugs: Add selftests for ITS (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Align RETs in BHB clear sequence to avoid thunking (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Add "vmexit" option to skip mitigation on some CPUs (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Enable Indirect Target Selection mitigation (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Add support for ITS-safe return thunk (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Add support for ITS-safe indirect thunk (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/its: Enumerate Indirect Target Selection (ITS) bug (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - Documentation: x86/bugs/its: Add ITS documentation (Pawan Gupta) [Orabug: 37945842] {CVE-2024-28956} - x86/alternatives: Remove faulty optimization (Josh Poimboeuf) [Orabug: 37945842] {CVE-2024-28956} - x86/alternative: Optimize returns patching (Borislav Petkov) [Orabug: 37945842] {CVE-2024-28956}
Get the latest Linux and open source security news straight to your inbox.