Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
217

Oracle Linux 7 ELSA-2024-4564 Moderate: Java Security Fixes for aarch64

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4564 http://linux.oracle.com/errata/ELSA-2024-4564.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: java-11-openjdk-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-devel-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-headless-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-demo-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-javadoc-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-javadoc-zip-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-jmods-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm java-11-openjdk-src-11.0.23.0.9-2.0.3.el7_9.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//java-11-openjdk-11.0.23.0.9-2.0.3.el7_9.src.rpm Related CVEs: CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 Description of changes: [1:11.0.23.0.9-2.0.3] - Fixes below CVE's - CVE-2024-21131 Improve-UTF8-String-supports - CVE-2024-21138 Better-symbol-storage - Fixes malformed control flow openjdk bug8303466 - CVE-2024-21140 Improved-loop-handling - CVE-2024-21144 Enhance-Pack-200-loading - CVE-2024-21145 Improve-2D-image-handling - CVE-2024-21147 Improve-array-management _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 7 ELSA-2024-7890 releases tackle vital python vulnerabilities, improving overall system resilience and functionality.. Oracle Linux, Java Updates, Security Advisory, OpenJDK Fixes, aarch64 Enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 10, 2024 Important Oracle
89

Fedora 40: Wireshark 4.2.5 Critical: Network Issues Fixes

New version 4.2.5. Includes fixes for CVE-2024-4853, CVE-2024-4854, CVE-2024-4855.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-cd1f01e5d9 2024-05-31 01:15:54.301433 -------------------------------------------------------------------------------- Name : wireshark Product : Fedora 40 Version : 4.2.5 Release : 1.fc40 URL : http://www.wireshark.org/ Summary : Network traffic analyzer Description : Wireshark allows you to examine protocol data stored in files or as it is captured from wired or wireless (WiFi or Bluetooth) networks, USB devices, and many other sources. It supports dozens of protocol capture file formats and understands more than a thousand protocols. It has many powerful features including a rich display filter language and the ability to reassemble multiple protocol packets in order to, for example, view a complete TCP stream, save the contents of a file which was transferred over HTTP or CIFS, or play back an RTP audio stream. -------------------------------------------------------------------------------- Update Information: New version 4.2.5. Includes fixes for CVE-2024-4853, CVE-2024-4854, CVE-2024-4855. -------------------------------------------------------------------------------- ChangeLog: * Wed May 22 2024 Michal Ruprich - 1:4.2.5-1 - New version 4.2.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2280712 - CVE-2024-4855 wireshark: Editcap byte chopping crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280712 [ 2 ] Bug #2280716 - CVE-2024-4854 wireshark: dissector infinite loop [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280716 [ 3 ] Bug #2280719 - CVE-2024-4853 wireshark: Editcap byte chopping crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280719 [ 4 ] Bug #2282006 - wireshark-4.2.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2282006 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-cd1f01e5d9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40 enhances Wireshark to version 4.2.5, implementing essential security patches that resolve various vulnerabilities. Discover more details today!. Wireshark Security Fixes,Fedora 40 Updates,Network Traffic Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 31, 2024 Critical Fedora
100

openSUSE 5.3, 5.4 Kernel Update: Critical Issues Resolved

* bsc#1084909 * bsc#1189998 * bsc#1210447 * bsc#1214286 * bsc#1214976 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2023:4731-1 Rating: important References: * bsc#1084909 * bsc#1189998 * bsc#1210447 * bsc#1214286 * bsc#1214976 * bsc#1215124 * bsc#1215292 * bsc#1215420 * bsc#1215458 * bsc#1215710 * bsc#1216058 * bsc#1216105 * bsc#1216259 * bsc#1216584 * bsc#1216693 * bsc#1216759 * bsc#1216761 * bsc#1216844 * bsc#1216861 * bsc#1216909 * bsc#1216959 * bsc#1216965 * bsc#1216976 * bsc#1217036 * bsc#1217068 * bsc#1217086 * bsc#1217124 * bsc#1217140 * bsc#1217195 * bsc#1217200 * bsc#1217205 * bsc#1217332 * bsc#1217366 * bsc#1217515 * bsc#1217598 * bsc#1217599 * bsc#1217609 * bsc#1217687 * bsc#1217731 * bsc#1217780 * jsc#PED-3184 * jsc#PED-5021 * jsc#PED-7237 Cross-References: * CVE-2023-2006 * CVE-2023-25775 * CVE-2023-39197 * CVE-2023-39198 * CVE-2023-4244 * CVE-2023-45863 * CVE-2023-45871 * CVE-2023-46862 * CVE-2023-5158 * CVE-2023-5717 * CVE-2023-6039 * CVE-2023-6176 CVSS scores: * CVE-2023-2006 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2006 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-25775 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-25775 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-39197 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2023-39198 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-39198 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-4244 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-4244 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45871 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45871 ( NVD ): 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-46862 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-46862 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-5158 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2023-5158 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2023-5717 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5717 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6039 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6039 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-6176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Real Time Module 15-SP4 An update that solves 12 vulnerabilities, contains three features and has 28 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-6176: Fixed a denial of service in the cryptographic algorithm scatterwalk functionality (bsc#1217332). * CVE-2023-2006: Fixed a race condition in the RxRPC network protocol (bsc#1210447). * CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976). * CVE-2023-4244: Fixed a use-after-free in the nf_tables component, which could be exploited to achieve local privilege escalation(bsc#1215420). * CVE-2023-6039: Fixed a use-after-free in lan78xx_disconnect in drivers/net/usb/lan78xx.c (bsc#1217068). * CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058). * CVE-2023-5158: Fixed a denial of service in vringh_kiov_advance() in drivers/vhost/vringh.c in the host side of a virtio ring (bsc#1215710). * CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may not be adequate for frames larger than the MTU (bsc#1216259). * CVE-2023-5717: Fixed a heap out-of-bounds write vulnerability in the Performance Events component (bsc#1216584). * CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965). * CVE-2023-25775: Fixed improper access control in the Intel Ethernet Controller RDMA driver (bsc#1216959). * CVE-2023-46862: Fixed a NULL pointer dereference in io_uring_show_fdinfo() (bsc#1216693). The following non-security bugs were fixed: * ACPI: FPDT: properly handle invalid FPDT subtables (git-fixes). * ACPI: resource: Do IRQ override on TongFang GMxXGxx (git-fixes). * ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CVA (git-fixes). * ACPI: sysfs: Fix create_pnp_modalias() and create_of_modalias() (git-fixes). * ALSA: hda/realtek - Add Dell ALC295 to pin fall back table (git-fixes). * ALSA: hda/realtek - Enable internal speaker of ASUS K6500ZC (git-fixes). * ALSA: hda/realtek: Add quirks for HP Laptops (git-fixes). * ALSA: hda/realtek: Enable Mute LED on HP 255 G10 (git-fixes). * ALSA: hda/realtek: Enable Mute LED on HP 255 G8 (git-fixes). * ALSA: hda: Disable power-save on KONTRON SinglePC (bsc#1217140). * ALSA: hda: Fix possible null-ptr-deref when assigning a stream (git-fixes). * ALSA: hda: cs35l41: Fix unbalanced pm_runtime_get() (git-fixes). * ALSA: hda: cs35l41: Undo runtime PM changes at driver exit time (git-fixes). * ALSA: hda: intel-dsp-config: Fix JSL Chromebook quirk detection (git-fixes). * ALSA: info: Fix potential deadlock at disconnection (git-fixes). * ARM: 9321/1: memset: cast the constant byte to unsigned char (git-fixes). * ASoC: Intel: Skylake: Fix mem leak when parsing UUIDs fails (git-fixes). * ASoC: ams-delta.c: use component after check (git-fixes). * ASoC: codecs: wsa-macro: fix uninitialized stack variables with name prefix (git-fixes). * ASoC: cs35l41: Undo runtime PM changes at driver exit time (git-fixes). * ASoC: cs35l41: Verify PM runtime resume errors in IRQ handler (git-fixes). * ASoC: fsl: Fix PM disable depth imbalance in fsl_easrc_probe (git-fixes). * ASoC: fsl: mpc5200_dma.c: Fix warning of Function parameter or member not described (git-fixes). * ASoC: hdmi-codec: register hpd callback on component probe (git-fixes). * ASoC: rt5650: fix the wrong result of key button (git-fixes). * ASoC: simple-card: fixup asoc_simple_probe() error handling (git-fixes). * ASoC: ti: omap-mcbsp: Fix runtime PM underflow warnings (git-fixes). * Bluetooth: btusb: Add 0bda:b85b for Fn-Link RTL8852BE (git-fixes). * Bluetooth: btusb: Add RTW8852BE device 13d3:3570 to device tables (git- fixes). * Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0cb8:0xc559 (git- fixes). * Bluetooth: btusb: Add date-> evt_skb is NULL check (git-fixes). * Disable Loongson drivers Loongson is a mips architecture, it does not make sense to build Loongson drivers on other architectures. * Documentation: networking: correct possessive "its" (bsc#1215458). * Drivers: hv: vmbus: Remove unused extern declaration vmbus_ontimer() (git- fixes). * Ensure ia32_emulation is always enabled for kernel-obs-build If ia32_emulation is disabled by default, ensure it is enabled back for OBS kernel to allow building 32bit binaries (jsc#PED-3184) [ms: Always pass the parameter, no need to grep through the config which may not be very reliable] * Fix termination state for idr_for_each_entry_ul() (git-fixes). * HID: Add quirk for Dell Pro Wireless Keyboard and Mouse KM5221W (git-fixes). * HID: hyperv: Replace one-element array with flexible-array member (git- fixes). * HID: hyperv: avoid struct memcpy overrun warning (git-fixes). * HID: hyperv: remove unused struct synthhid_msg (git-fixes). * HID: lenovo: Detect quirk-free fw on cptkbd and stop applying workaround (git-fixes). * HID: logitech-hidpp: Do not restart IO, instead defer hid_connect() only (git-fixes). * HID: logitech-hidpp: Move get_wireless_feature_index() check to hidpp_connect_event() (git-fixes). * HID: logitech-hidpp: Remove HIDPP_QUIRK_NO_HIDINPUT quirk (git-fixes). * HID: logitech-hidpp: Revert "Do not restart communication if not necessary" (git-fixes). * Input: synaptics-rmi4 - fix use after free in rmi_unregister_function() (git-fixes). * Input: synaptics-rmi4 - handle reset delay when using SMBus trsnsport (git- fixes). * Input: xpad - add VID for Turtle Beach controllers (git-fixes). * PCI/ASPM: Fix L1 substate handling in aspm_attr_store_common() (git-fixes). * PCI/sysfs: Protect driver's D3cold preference from user space (git-fixes). * PCI: Disable ATS for specific Intel IPU E2000 devices (bsc#1215458). * PCI: Extract ATS disabling to a helper function (bsc#1215458). * PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device (git- fixes). * PCI: Use FIELD_GET() in Sapphire RX 5600 XT Pulse quirk (git-fixes). * PCI: Use FIELD_GET() to extract Link Width (git-fixes). * PCI: exynos: Do not discard.remove() callback (git-fixes). * PCI: keystone: Do not discard.probe() callback (git-fixes). * PCI: keystone: Do not discard.remove() callback (git-fixes). * PCI: tegra194: Use FIELD_GET()/FIELD_PREP() with Link Width fields (git- fixes). * PM / devfreq: rockchip-dfi: Make pmu regmap mandatory (git-fixes). * PM: hibernate: Use __get_safe_page() rather than touching the list (git- fixes). * USB: dwc2: write HCINT with INTMASK applied (bsc#1214286). * USB: dwc3: qcom: fix ACPI platform device leak (git-fixes). * USB: dwc3: qcom: fix resource leaks on probe deferral (git-fixes). * USB: dwc3: qcom: fix software node leak on probe errors (git-fixes). * USB:dwc3: qcom: fix wakeup after probe deferral (git-fixes). * USB: serial: option: add Fibocom L7xx modules (git-fixes). * USB: serial: option: add Luat Air72*U series products (git-fixes). * USB: serial: option: do not claim interface 4 for ZTE MF290 (git-fixes). * USB: serial: option: fix FM101R-GL defines (git-fixes). * USB: usbip: fix stub_dev hub disconnect (git-fixes). * arm/xen: fix xen_vcpu_info allocation alignment (git-fixes). * arm64: Add Cortex-A520 CPU part definition (git-fixes) * arm64: allow kprobes on EL0 handlers (git-fixes) * arm64: armv8_deprecated move emulation functions (git-fixes) * arm64: armv8_deprecated: fix unused-function error (git-fixes) * arm64: armv8_deprecated: fold ops into insn_emulation (git-fixes) * arm64: armv8_deprecated: move aarch32 helper earlier (git-fixes) * arm64: armv8_deprecated: rework deprected instruction handling (git-fixes) * arm64: consistently pass ESR_ELx to die() (git-fixes) * arm64: die(): pass 'err' as long (git-fixes) * arm64: factor insn read out of call_undef_hook() (git-fixes) * arm64: factor out EL1 SSBS emulation hook (git-fixes) * arm64: report EL1 UNDEFs better (git-fixes) * arm64: rework BTI exception handling (git-fixes) * arm64: rework EL0 MRS emulation (git-fixes) * arm64: rework FPAC exception handling (git-fixes) * arm64: split EL0/EL1 UNDEF handlers (git-fixes) * ata: pata_isapnp: Add missing error check for devm_ioport_map() (git-fixes). * atl1c: Work around the DMA RX overflow issue (git-fixes). * atm: iphase: Do PCI error checks on own line (git-fixes). * blk-mq: Do not clear driver tags own mapping (bsc#1217366). * blk-mq: fix null pointer dereference in blk_mq_clear_rq_mapping() (bsc#1217366). * bluetooth: Add device 0bda:887b to device tables (git-fixes). * bluetooth: Add device 13d3:3571 to device tables (git-fixes). * can: dev: can_put_echo_skb(): do not crash kernel if can_priv::echo_skb is accessed out of bounds (git-fixes). * can: dev: can_restart(): do not crash kernel if carrier is OK(git-fixes). * can: dev: can_restart(): fix race condition between controller restart and netif_carrier_on() (git-fixes). * can: isotp: add local echo tx processing for consecutive frames (git-fixes). * can: isotp: fix race between isotp_sendsmg() and isotp_release() (git- fixes). * can: isotp: fix tx state handling for echo tx processing (git-fixes). * can: isotp: handle wait_event_interruptible() return values (git-fixes). * can: isotp: isotp_bind(): return -EINVAL on incorrect CAN ID formatting (git-fixes). * can: isotp: isotp_sendmsg(): fix TX state detection and wait behavior (git- fixes). * can: isotp: remove re-binding of bound socket (git-fixes). * can: isotp: sanitize CAN ID checks in isotp_bind() (git-fixes). * can: isotp: set max PDU size to 64 kByte (git-fixes). * can: isotp: split tx timer into transmission and timeout (git-fixes). * can: sja1000: Fix comment (git-fixes). * clk: Sanitize possible_parent_show to Handle Return Value of of_clk_get_parent_name (git-fixes). * clk: imx: Select MXC_CLK for CLK_IMX8QXP (git-fixes). * clk: imx: imx8mq: correct error handling path (git-fixes). * clk: imx: imx8qxp: Fix elcdif_pll clock (git-fixes). * clk: keystone: pll: fix a couple NULL vs IS_ERR() checks (git-fixes). * clk: mediatek: clk-mt2701: Add check for mtk_alloc_clk_data (git-fixes). * clk: mediatek: clk-mt6765: Add check for mtk_alloc_clk_data (git-fixes). * clk: mediatek: clk-mt6779: Add check for mtk_alloc_clk_data (git-fixes). * clk: mediatek: clk-mt6797: Add check for mtk_alloc_clk_data (git-fixes). * clk: mediatek: clk-mt7629-eth: Add check for mtk_alloc_clk_data (git-fixes). * clk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_data (git-fixes). * clk: npcm7xx: Fix incorrect kfree (git-fixes). * clk: qcom: clk-rcg2: Fix clock rate overflow for high parent frequencies (git-fixes). * clk: qcom: config IPQ_APSS_6018 should depend on QCOM_SMEM (git-fixes). * clk: qcom: gcc-sm8150: Fix gcc_sdcc2_apps_clk_src (git-fixes). * clk: qcom: ipq6018: drop theCLK_SET_RATE_PARENT flag from PLL clocks (git- fixes). * clk: qcom: mmcc-msm8998: Do not check halt bit on some branch clks (git- fixes). * clk: qcom: mmcc-msm8998: Fix the SMMU GDSC (git-fixes). * clk: scmi: Free scmi_clk allocated when the clocks with invalid info are skipped (git-fixes). * clk: ti: Add ti_dt_clk_name() helper to use clock-output-names (git-fixes). * clk: ti: Update component clocks to use ti_dt_clk_name() (git-fixes). * clk: ti: Update pll and clockdomain clocks to use ti_dt_clk_name() (git- fixes). * clk: ti: change ti_clk_register_omap_hw API (git-fixes). * clk: ti: fix double free in of_ti_divider_clk_setup() (git-fixes). * crypto: caam/jr - fix Chacha20 + Poly1305 self test failure (git-fixes). * crypto: caam/qi2 - fix Chacha20 + Poly1305 self test failure (git-fixes). * crypto: hisilicon/hpre - Fix a erroneous check after snprintf() (git-fixes). * dmaengine: pxa_dma: Remove an erroneous BUG_ON() in pxad_free_desc() (git- fixes). * dmaengine: ste_dma40: Fix PM disable depth imbalance in d40_probe (git- fixes). * dmaengine: stm32-mdma: correct desc prep when channel running (git-fixes). * dmaengine: ti: edma: handle irq_of_parse_and_map() errors (git-fixes). * docs: net: move the probe and open/close sections of driver.rst up (bsc#1215458). * docs: net: reformat driver.rst from a list to sections (bsc#1215458). * docs: net: use C syntax highlight in driver.rst (bsc#1215458). * drm/amd/display: Avoid NULL dereference of timing generator (git-fixes). * drm/amd/display: Change the DMCUB mailbox memory location from FB to inbox (git-fixes). * drm/amd/display: remove useless check in should_enable_fbc() (git-fixes). * drm/amd/display: use full update for clip size increase of large plane source (git-fixes). * drm/amd/pm: Handle non-terminated overdrive commands (git-fixes). * drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga (git- fixes). * drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 (git-fixes). * drm/amdgpu: Fix a null pointeraccess when the smc_rreg pointer is NULL (git-fixes). * drm/amdgpu: Fix potential null pointer derefernce (git-fixes). * drm/amdgpu: do not use ATRM for external devices (git-fixes). * drm/amdgpu: fix error handling in amdgpu_bo_list_get() (git-fixes). * drm/amdgpu: fix software pci_unplug on some chips (git-fixes). * drm/amdkfd: Fix a race condition of vram buffer unref in svm code (git- fixes). * drm/amdkfd: Fix shift out-of-bounds issue (git-fixes). * drm/amdkfd: fix some race conditions in vram buffer alloc/free of svm code (git-fixes). * drm/bridge: Fix kernel-doc typo in desc of output_bus_cfg in drm_bridge_state (git-fixes). * drm/bridge: lt8912b: Add missing drm_bridge_attach call (git-fixes). * drm/bridge: lt8912b: Fix bridge_detach (git-fixes). * drm/bridge: lt8912b: Fix crash on bridge detach (git-fixes). * drm/bridge: lt8912b: Manually disable HPD only if it was enabled (git- fixes). * drm/bridge: lt8912b: Register and attach our DSI device at probe (git- fixes). * drm/bridge: lt8912b: Switch to devm MIPI-DSI helpers (git-fixes). * drm/bridge: lt9611uxc: Register and attach our DSI device at probe (git- fixes). * drm/bridge: lt9611uxc: Switch to devm MIPI-DSI helpers (git-fixes). * drm/bridge: lt9611uxc: fix the race in the error path (git-fixes). * drm/bridge: tc358768: Disable non-continuous clock mode (git-fixes). * drm/bridge: tc358768: Fix bit updates (git-fixes). * drm/bridge: tc358768: Fix use of uninitialized variable (git-fixes). * drm/gud: Use size_add() in call to struct_size() (git-fixes). * drm/i915/pmu: Check if pmu is closed before stopping event (git-fixes). * drm/i915: Fix potential spectre vulnerability (git-fixes). * drm/komeda: drop all currently held locks if deadlock happens (git-fixes). * drm/mediatek: Fix iommu fault by swapping FBs after updating plane state (git-fixes). * drm/mediatek: Fix iommu fault during crtc enabling (git-fixes). * drm/mipi-dsi: Create devm device attachment (git-fixes). * drm/mipi-dsi: Create devm device registration(git-fixes). * drm/msm/dp: skip validity check for DP CTS EDID checksum (git-fixes). * drm/panel/panel-tpo-tpg110: fix a possible null pointer dereference (git- fixes). * drm/panel: fix a possible null pointer dereference (git-fixes). * drm/panel: simple: Fix Innolux G101ICE-L01 bus flags (git-fixes). * drm/panel: simple: Fix Innolux G101ICE-L01 timings (git-fixes). * drm/panel: st7703: Pick different reset sequence (git-fixes). * drm/qxl: prevent memory leak (git-fixes). * drm/radeon: possible buffer overflow (git-fixes). * drm/rockchip: Fix type promotion bug in rockchip_gem_iommu_map() (git- fixes). * drm/rockchip: cdn-dp: Fix some error handling paths in cdn_dp_probe() (git- fixes). * drm/rockchip: vop: Fix call to crtc reset helper (git-fixes). * drm/rockchip: vop: Fix color for RGB888/BGR888 format on VOP full (git- fixes). * drm/rockchip: vop: Fix reset of state in duplicate state crtc funcs (git- fixes). * drm/syncobj: fix DRM_SYNCOBJ_WAIT_FLAGS_WAIT_AVAILABLE (git-fixes). * drm/vc4: fix typo (git-fixes). * drm: vmwgfx_surface.c: copy user-array safely (git-fixes). * dt-bindings: usb: hcd: add missing phy name to example (git-fixes). * dt-bindings: usb: qcom,dwc3: fix example wakeup interrupt types (git-fixes). * fbdev: fsl-diu-fb: mark wr_reg_wa() static (git-fixes). * fbdev: imsttfb: Fix error path of imsttfb_probe() (git-fixes). * fbdev: imsttfb: Release framebuffer and dealloc cmap on error path (git- fixes). * fbdev: imsttfb: fix a resource leak in probe (git-fixes). * fbdev: imsttfb: fix double free in probe() (git-fixes). * fbdev: omapfb: Drop unused remove function (git-fixes). * firewire: core: fix possible memory leak in create_units() (git-fixes). * firmware/imx-dsp: Fix use_after_free in imx_dsp_setup_channels() (git- fixes). * gpio: mockup: fix kerneldoc (git-fixes). * gpio: mockup: remove unused field (git-fixes). * hid: cp2112: Fix duplicate workqueue initialization (git-fixes). * hv: simplify sysctl registration (git-fixes). * hv_netvsc: Fix race ofregister_netdevice_notifier and VF register (git- fixes). * hv_netvsc: Mark VF as slave before exposing it to user-mode (git-fixes). * hv_netvsc: fix netvsc_send_completion to avoid multiple message length checks (git-fixes). * hv_netvsc: fix race of netvsc and VF register_netdevice (git-fixes). * hwmon: (coretemp) Fix potentially truncated sysfs attribute name (git- fixes). * i2c: aspeed: Fix i2c bus hang in slave read (git-fixes). * i2c: core: Run atomic i2c xfer when!preemptible (git-fixes). * i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (git-fixes). * i2c: dev: copy userspace array safely (git-fixes). * i2c: i801: fix potential race in i801_block_transaction_byte_by_byte (git- fixes). * i2c: iproc: handle invalid slave state (git-fixes). * i2c: muxes: i2c-demux-pinctrl: Use of_get_i2c_adapter_by_node() (git-fixes). * i2c: muxes: i2c-mux-gpmux: Use of_get_i2c_adapter_by_node() (git-fixes). * i2c: muxes: i2c-mux-pinctrl: Use of_get_i2c_adapter_by_node() (git-fixes). * i2c: stm32f7: Fix PEC handling in case of SMBUS transfers (git-fixes). * i2c: sun6i-p2wi: Prevent potential division by zero (git-fixes). * i3c: Fix potential refcount leak in i3c_master_register_new_i3c_devs (git- fixes). * i3c: master: cdns: Fix reading status register (git-fixes). * i3c: master: mipi-i3c-hci: Fix a kernel panic for accessing DAT_data (git- fixes). * i3c: master: svc: fix SDA keep low when polling IBIWON timeout happen (git- fixes). * i3c: master: svc: fix check wrong status register in irq handler (git- fixes). * i3c: master: svc: fix ibi may not return mandatory data byte (git-fixes). * i3c: master: svc: fix race condition in ibi work thread (git-fixes). * i3c: master: svc: fix wrong data return when IBI happen during start frame (git-fixes). * i3c: mipi-i3c-hci: Fix out of bounds access in hci_dma_irq_handler (git- fixes). * i915/perf: Fix NULL deref bugs with drm_dbg() calls (git-fixes). * idpf: add RX splitq napi poll support (bsc#1215458). * idpf: addSRIOV support and other ndo_ops (bsc#1215458). * idpf: add TX splitq napi poll support (bsc#1215458). * idpf: add controlq init and reset checks (bsc#1215458). * idpf: add core init and interrupt request (bsc#1215458). * idpf: add create vport and netdev configuration (bsc#1215458). * idpf: add ethtool callbacks (bsc#1215458). * idpf: add module register and probe functionality (bsc#1215458). * idpf: add ptypes and MAC filter support (bsc#1215458). * idpf: add singleq start_xmit and napi poll (bsc#1215458). * idpf: add splitq start_xmit (bsc#1215458). * idpf: cancel mailbox work in error path (bsc#1215458). * idpf: configure resources for RX queues (bsc#1215458). * idpf: configure resources for TX queues (bsc#1215458). * idpf: fix potential use-after-free in idpf_tso() (bsc#1215458). * idpf: initialize interrupts and enable vport (bsc#1215458). * idpf: set scheduling mode for completion queue (bsc#1215458). * iio: adc: xilinx-xadc: Correct temperature offset/scale for UltraScale (git- fixes). * iio: adc: xilinx-xadc: Do not clobber preset voltage/temperature thresholds (git-fixes). * iio: exynos-adc: request second interupt only when touchscreen mode is used (git-fixes). * irqchip/stm32-exti: add missing DT IRQ flag translation (git-fixes). * kabi/severities: ignore kabi in rxrpc (bsc#1210447) The rxrpc module is built since SLE15-SP3 but it is not shipped as part of any SLE product, only in Leap (in kernel-*-optional). * kernel-binary: suse-module-tools is also required when installed Requires(pre) adds dependency for the specific sciptlet. However, suse- module-tools also ships modprobe.d files which may be needed at posttrans time or any time the kernel is on the system for generating ramdisk. Add plain Requires as well. * kernel-source: Move provides after sources * kernel/fork: beware of __put_task_struct() calling context (bsc#1189998 (PREEMPT_RT prerequisite backports)). * kernel/fork: beware of __put_task_struct() calling context (bsc#1216761). * leds: pwm: Do notdisable the PWM when the LED should be off (git-fixes). * leds: trigger: ledtrig-cpu:: Fix 'output may be truncated' issue for 'cpu' (git-fixes). * leds: turris-omnia: Do not use SMBUS calls (git-fixes). * lsm: fix default return value for inode_getsecctx (git-fixes). * lsm: fix default return value for vm_enough_memory (git-fixes). * media: bttv: fix use after free error due to btv-> timeout timer (git-fixes). * media: ccs: Correctly initialise try compose rectangle (git-fixes). * media: ccs: Fix driver quirk struct documentation (git-fixes). * media: cedrus: Fix clock/reset sequence (git-fixes). * media: cobalt: Use FIELD_GET() to extract Link Width (git-fixes). * media: gspca: cpia1: shift-out-of-bounds in set_flicker (git-fixes). * media: i2c: max9286: Fix some redundant of_node_put() calls (git-fixes). * media: imon: fix access to invalid resource for the second interface (git- fixes). * media: lirc: drop trailing space from scancode transmit (git-fixes). * media: qcom: camss: Fix VFE-17x vfe_disable_output() (git-fixes). * media: qcom: camss: Fix missing vfe_lite clocks check (git-fixes). * media: qcom: camss: Fix pm_domain_on sequence in probe (git-fixes). * media: qcom: camss: Fix vfe_get() error jump (git-fixes). * media: sharp: fix sharp encoding (git-fixes). * media: siano: Drop unnecessary error check for debugfs_create_dir/file() (git-fixes). * media: venus: hfi: add checks to handle capabilities from firmware (git- fixes). * media: venus: hfi: add checks to perform sanity on queue pointers (git- fixes). * media: venus: hfi: fix the check to handle session buffer requirement (git- fixes). * media: venus: hfi_parser: Add check to keep the number of codecs within range (git-fixes). * media: vidtv: mux: Add check and kfree for kstrdup (git-fixes). * media: vidtv: psi: Add check for kstrdup (git-fixes). * media: vivid: avoid integer overflow (git-fixes). * mfd: arizona-spi: Set pdata.hpdet_channel for ACPI enumerated devs (git- fixes). * mfd: core: Ensure disableddevices are skipped without aborting (git-fixes). * mfd: dln2: Fix double put in dln2_probe (git-fixes). * misc: fastrpc: Clean buffers on remote invocation failures (git-fixes). * misc: pci_endpoint_test: Add Device ID for R-Car S4-8 PCIe controller (git- fixes). * mm/hmm: fault non-owner device private entries (bsc#1216844, jsc#PED-7237, git-fixes). * mmc: block: Be sure to wait while busy in CQE error recovery (git-fixes). * mmc: block: Do not lose cache flush during CQE error recovery (git-fixes). * mmc: block: Retry commands in CQE error recovery (git-fixes). * mmc: cqhci: Fix task clearing in CQE error recovery (git-fixes). * mmc: cqhci: Increase recovery halt timeout (git-fixes). * mmc: cqhci: Warn of halt or task clear failure (git-fixes). * mmc: meson-gx: Remove setting of CMD_CFG_ERROR (git-fixes). * mmc: sdhci-pci-gli: A workaround to allow GL9750 to enter ASPM L1.2 (git- fixes). * mmc: sdhci-pci-gli: GL9750: Mask the replay timer timeout of AER (git- fixes). * mmc: sdhci_am654: fix start loop index for TAP value parsing (git-fixes). * mmc: vub300: fix an error code (git-fixes). * modpost: fix tee MODULE_DEVICE_TABLE built on big-endian host (git-fixes). * mt76: dma: use kzalloc instead of devm_kzalloc for txwi (git-fixes). * mtd: cfi_cmdset_0001: Byte swap OTP info (git-fixes). * mtd: rawnand: arasan: Include ECC syndrome along with in-band data while checking for ECC failure (git-fixes). * net-memcg: Fix scope of sockmem pressure indicators (bsc#1216759). * net: Avoid address overwrite in kernel_connect (bsc#1216861). * net: add macro netif_subqueue_completed_wake (bsc#1215458). * net: fix use-after-free in tw_timer_handler (bsc#1217195). * net: ieee802154: adf7242: Fix some potential buffer overflow in adf7242_stats_show() (git-fixes). * net: mana: Fix return type of mana_start_xmit() (git-fixes). * net: piggy back on the memory barrier in bql when waking queues (bsc#1215458). * net: provide macros for commonly copied lockless queue stop/wake code (bsc#1215458). * net: usb: ax88179_178a: fix failed operations during ax88179_reset (git- fixes). * net: usb: smsc95xx: Fix uninit-value access in smsc95xx_read_reg (git- fixes). * nvme: update firmware version after commit (bsc#1215292). * pcmcia: cs: fix possible hung task and memory leak pccardd() (git-fixes). * pcmcia: ds: fix possible name leak in error path in pcmcia_device_add() (git-fixes). * pcmcia: ds: fix refcount leak in pcmcia_device_add() (git-fixes). * pinctrl: avoid reload of p state in list iteration (git-fixes). * platform/x86: thinkpad_acpi: Add battery quirk for Thinkpad X120e (git- fixes). * platform/x86: wmi: Fix opening of char device (git-fixes). * platform/x86: wmi: Fix probe failure when failing to register WMI devices (git-fixes). * platform/x86: wmi: remove unnecessary initializations (git-fixes). * powerpc: Do not clobber f0/vs0 during fp|altivec register save (bsc#1217780). * pwm: Fix double shift bug (git-fixes). * pwm: brcmstb: Utilize appropriate clock APIs in suspend/resume (git-fixes). * pwm: sti: Reduce number of allocations and drop usage of chip_data (git- fixes). * r8152: Cancel hw_phy_work if we have an error in probe (git-fixes). * r8152: Check for unplug in r8153b_ups_en() / r8153c_ups_en() (git-fixes). * r8152: Check for unplug in rtl_phy_patch_request() (git-fixes). * r8152: Increase USB control msg timeout to 5000ms as per spec (git-fixes). * r8152: Release firmware if we have an error in probe (git-fixes). * r8152: Run the unload routine if we have errors during probe (git-fixes). * regmap: Ensure range selector registers are updated after cache sync (git- fixes). * regmap: debugfs: Fix a erroneous check after snprintf() (git-fixes). * regmap: prevent noinc writes from clobbering cache (git-fixes). * s390/ap: fix AP bus crash on early config change callback invocation (git- fixes bsc#1217687). * s390/cio: unregister device when the only path is gone (git-fixes bsc#1217609). * s390/cmma: fix detection of DAT pages (LTC#203997 bsc#1217086). *s390/cmma: fix handling of swapper_pg_dir and invalid_pg_dir (LTC#203997 bsc#1217086). * s390/cmma: fix initial kernel address space page table walk (LTC#203997 bsc#1217086). * s390/crashdump: fix TOD programmable field size (git-fixes bsc#1217205). * s390/dasd: fix hanging device after request requeue (git-fixes LTC#203629 bsc#1215124). * s390/dasd: protect device queue against concurrent access (git-fixes bsc#1217515). * s390/dasd: use correct number of retries for ERP requests (git-fixes bsc#1217598). * s390/ipl: add missing secure/has_secure file to ipl type 'unknown' (bsc#1214976 git-fixes). * s390/mm: add missing arch_set_page_dat() call to gmap allocations (LTC#203997 bsc#1217086). * s390/mm: add missing arch_set_page_dat() call to vmem_crst_alloc() (LTC#203997 bsc#1217086). * s390/pkey: fix/harmonize internal keyblob headers (git-fixes bsc#1217200). * s390/ptrace: fix PTRACE_GET_LAST_BREAK error handling (git-fixes bsc#1217599). * sbsa_gwdt: Calculate timeout with 64-bit math (git-fixes). * scsi: lpfc: Copyright updates for 14.2.0.16 patches (bsc#1217731). * scsi: lpfc: Correct maximum PCI function value for RAS fw logging (bsc#1217731). * scsi: lpfc: Eliminate unnecessary relocking in lpfc_check_nlp_post_devloss() (bsc#1217731). * scsi: lpfc: Enhance driver logging for selected discovery events (bsc#1217731). * scsi: lpfc: Fix list_entry null check warning in lpfc_cmpl_els_plogi() (bsc#1217731). * scsi: lpfc: Fix possible file string name overflow when updating firmware (bsc#1217731). * scsi: lpfc: Introduce LOG_NODE_VERBOSE messaging flag (bsc#1217124). * scsi: lpfc: Refactor and clean up mailbox command memory free (bsc#1217731). * scsi: lpfc: Reject received PRLIs with only initiator fcn role for NPIV ports (bsc#1217124). * scsi: lpfc: Remove unnecessary zero return code assignment in lpfc_sli4_hba_setup (bsc#1217124). * scsi: lpfc: Return early in lpfc_poll_eratt() when the driver is unloading (bsc#1217731). * scsi: lpfc: Treat IOERR_SLI_DOWN I/O completionstatus the same as pci offline (bsc#1217124). * scsi: lpfc: Update lpfc version to 14.2.0.15 (bsc#1217124). * scsi: lpfc: Update lpfc version to 14.2.0.16 (bsc#1217731). * scsi: lpfc: Validate ELS LS_ACC completion payload (bsc#1217124). * scsi: qla2xxx: Fix double free of dsd_list during driver load (git-fixes). * scsi: qla2xxx: Use FIELD_GET() to extract PCIe capability fields (git- fixes). * selftests/efivarfs: create-read: fix a resource leak (git-fixes). * selftests/pidfd: Fix ksft print formats (git-fixes). * selftests/resctrl: Ensure the benchmark commands fits to its array (git- fixes). * selftests/resctrl: Reduce failures due to outliers in MBA/MBM tests (git- fixes). * selftests/resctrl: Remove duplicate feature check from CMT test (git-fixes). * seq_buf: fix a misleading comment (git-fixes). * serial: exar: Revert "serial: exar: Add support for Sealevel 7xxxC serial cards" (git-fixes). * serial: meson: Use platform_get_irq() to get the interrupt (git-fixes). * soc: qcom: llcc: Handle a second device without data corruption (git-fixes). * spi: nxp-fspi: use the correct ioremap function (git-fixes). * spi: spi-zynq-qspi: add spi-mem to driver kconfig dependencies (git-fixes). * spi: tegra: Fix missing IRQ check in tegra_slink_probe() (git-fixes). * staging: media: ipu3: remove ftrace-like logging (git-fixes). * string.h: add array-wrappers for (v)memdup_user() (git-fixes). * supported.conf: marked idpf supported * thermal: core: prevent potential string overflow (git-fixes). * treewide: Spelling fix in comment (git-fixes). * tty/sysrq: replace smp_processor_id() with get_cpu() (git-fixes). * tty: 8250: Add Brainboxes Oxford Semiconductor-based quirks (git-fixes). * tty: 8250: Add support for Brainboxes UP cards (git-fixes). * tty: 8250: Add support for Intashield IS-100 (git-fixes). * tty: 8250: Add support for Intashield IX cards (git-fixes). * tty: 8250: Add support for additional Brainboxes PX cards (git-fixes). * tty: 8250: Add support for additional Brainboxes UCcards (git-fixes). * tty: 8250: Fix port count of PX-257 (git-fixes). * tty: 8250: Fix up PX-803/PX-857 (git-fixes). * tty: 8250: Remove UC-257 and UC-431 (git-fixes). * tty: Fix uninit-value access in ppp_sync_receive() (git-fixes). * tty: n_gsm: fix race condition in status line change on dead connections (git-fixes). * tty: serial: meson: fix hard LOCKUP on crtscts mode (git-fixes). * tty: tty_jobctrl: fix pid memleak in disassociate_ctty() (git-fixes). * tty: vcc: Add check for kstrdup() in vcc_probe() (git-fixes). * usb: cdnsp: Fix deadlock issue during using NCM gadget (git-fixes). * usb: chipidea: Fix DMA overwrite for Tegra (git-fixes). * usb: chipidea: Simplify Tegra DMA alignment code (git-fixes). * usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency (git-fixes). * usb: dwc3: Fix default mode initialization (git-fixes). * usb: dwc3: set the dma max_seg_size (git-fixes). * usb: gadget: f_ncm: Always set current gadget in ncm_bind() (git-fixes). * usb: raw-gadget: properly handle interrupted requests (git-fixes). * usb: storage: set 1.50 as the lower bcdDevice for older "Super Top" compatibility (git-fixes). * usb: typec: tcpm: Fix NULL pointer dereference in tcpm_pd_svdm() (git- fixes). * usb: typec: tcpm: Skip hard reset when in error recovery (git-fixes). * virtchnl: add virtchnl version 2 ops (bsc#1215458). * wifi: ath10k: Do not touch the CE interrupt registers after power up (git- fixes). * wifi: ath10k: fix clang-specific fortify warning (git-fixes). * wifi: ath11k: debugfs: fix to work with multiple PCI devices (git-fixes). * wifi: ath11k: fix dfs radar event locking (git-fixes). * wifi: ath11k: fix htt pktlog locking (git-fixes). * wifi: ath11k: fix temperature event locking (git-fixes). * wifi: ath9k: fix clang-specific fortify warnings (git-fixes). * wifi: iwlwifi: Use FW rate for non-data frames (git-fixes). * wifi: iwlwifi: call napi_synchronize() before freeing rx/tx queues (git- fixes). * wifi: iwlwifi: empty overflow queueduring flush (git-fixes). * wifi: iwlwifi: honor the enable_ini value (git-fixes). * wifi: iwlwifi: pcie: synchronize IRQs before NAPI (git-fixes). * wifi: mac80211: do not return unset power in ieee80211_get_tx_power() (git- fixes). * wifi: mac80211: fix # of MSDU in A-MSDU calculation (git-fixes). * wifi: mt76: mt7603: rework/fix rx pse hang check (git-fixes). * wifi: rtlwifi: fix EDCA limit set by BT coexistence (git-fixes). * wifi: rtw88: debug: Fix the NULL vs IS_ERR() bug for debugfs_create_file() (git-fixes). * x86/alternative: Add a __alt_reloc_selftest() prototype (git-fixes). * x86/cpu: Fix AMD erratum #1485 on Zen4-based CPUs (git-fixes). * x86/fpu: Set X86_FEATURE_OSXSAVE feature after enabling OSXSAVE in CR4 (git- fixes). * x86/hyperv: Add HV_EXPOSE_INVARIANT_TSC define (git-fixes). * x86/hyperv: Improve code for referencing hyperv_pcpu_input_arg (git-fixes). * x86/hyperv: Make hv_get_nmi_reason public (git-fixes). * x86/hyperv: fix a warning in mshyperv.h (git-fixes). * x86/sev: Do not try to parse for the CC blob on non-AMD hardware (git- fixes). * x86/sev: Fix calculation of end address based on number of pages (git- fixes). * x86/sev: Use the GHCB protocol when available for SNP CPUID requests (git- fixes). * x86: Move gds_ucode_mitigated() declaration to header (git-fixes). * xfs: add attr state machine tracepoints (git-fixes). * xfs: can't use kmem_zalloc() for attribute buffers (bsc#1216909). * xfs: constify btree function parameters that are not modified (git-fixes). * xfs: convert AGF log flags to unsigned (git-fixes). * xfs: convert AGI log flags to unsigned (git-fixes). * xfs: convert attr type flags to unsigned (git-fixes). * xfs: convert bmap extent type flags to unsigned (git-fixes). * xfs: convert bmapi flags to unsigned (git-fixes). * xfs: convert btree buffer log flags to unsigned (git-fixes). * xfs: convert buffer flags to unsigned (git-fixes). * xfs: convert buffer log item flags to unsigned (git-fixes). * xfs: convert da btree operations flagsto unsigned (git-fixes). * xfs: convert dquot flags to unsigned (git-fixes). * xfs: convert inode lock flags to unsigned (git-fixes). * xfs: convert log item tracepoint flags to unsigned (git-fixes). * xfs: convert log ticket and iclog flags to unsigned (git-fixes). * xfs: convert quota options flags to unsigned (git-fixes). * xfs: convert scrub type flags to unsigned (git-fixes). * xfs: disambiguate units for ftrace fields tagged "blkno", "block", or "bno" (git-fixes). * xfs: disambiguate units for ftrace fields tagged "count" (git-fixes). * xfs: disambiguate units for ftrace fields tagged "len" (git-fixes). * xfs: disambiguate units for ftrace fields tagged "offset" (git-fixes). * xfs: make the key parameters to all btree key comparison functions const (git-fixes). * xfs: make the key parameters to all btree query range functions const (git- fixes). * xfs: make the keys and records passed to btree inorder functions const (git- fixes). * xfs: make the pointer passed to btree set_root functions const (git-fixes). * xfs: make the start pointer passed to btree alloc_block functions const (git-fixes). * xfs: make the start pointer passed to btree update_lastrec functions const (git-fixes). * xfs: mark the record passed into btree init_key functions as const (git- fixes). * xfs: mark the record passed into xchk_btree functions as const (git-fixes). * xfs: remove xfs_btree_cur_t typedef (git-fixes). * xfs: rename i_disk_size fields in ftrace output (git-fixes). * xfs: resolve fork names in trace output (git-fixes). * xfs: standardize AG block number formatting in ftrace output (git-fixes). * xfs: standardize AG number formatting in ftrace output (git-fixes). * xfs: standardize daddr formatting in ftrace output (git-fixes). * xfs: standardize inode generation formatting in ftrace output (git-fixes). * xfs: standardize inode number formatting in ftrace output (git-fixes). * xfs: standardize remaining xfs_buf length tracepoints (git-fixes). * xfs: standardize rmap owner numberformatting in ftrace output (git-fixes). * xhci: Enable RPM on controllers that support low-power states (git-fixes). * xhci: Loosen RPM as default policy to cover for AMD xHC 1.1 (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-4731=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4731=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4731=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4731=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4731=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4731=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4731=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-4731=1 * SUSE Real Time Module 15-SP4 zypper in -t patch SUSE-SLE-Module-RT-15-SP4-2023-4731=1 ## Package List: * openSUSE Leap Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * openSUSE Leap Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * openSUSE Leap Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * openSUSE Leap Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * openSUSE Leap 15.4 (x86_64) * cluster-md-kmp-rt-5.14.21-150400.15.62.1 * dlm-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * ocfs2-kmp-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-debuginfo-5.14.21-150400.15.62.1 *kernel-rt-debugsource-5.14.21-150400.15.62.1 * kernel-syms-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150400.15.62.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * gfs2-kmp-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-debugsource-5.14.21-150400.15.62.1 * kernel-rt-devel-5.14.21-150400.15.62.1 * kernel-rt_debug-devel-5.14.21-150400.15.62.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-devel-debuginfo-5.14.21-150400.15.62.1 * dlm-kmp-rt-5.14.21-150400.15.62.1 * gfs2-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * openSUSE Leap 15.4 (noarch) * kernel-source-rt-5.14.21-150400.15.62.1 * kernel-devel-rt-5.14.21-150400.15.62.1 * openSUSE Leap 15.4 (nosrc x86_64) * kernel-rt_debug-5.14.21-150400.15.62.1 * kernel-rt-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * SUSE Linux Enterprise Live Patching 15-SP4 (x86_64) * kernel-livepatch-5_14_21-150400_15_62-rt-1-150400.1.3.1 * kernel-livepatch-5_14_21-150400_15_62-rt-debuginfo-1-150400.1.3.1 * kernel-livepatch-SLE15-SP4-RT_Update_16-debugsource-1-150400.1.3.1 * SUSE Real Time Module 15-SP4 (x86_64) *cluster-md-kmp-rt-5.14.21-150400.15.62.1 * dlm-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debuginfo-5.14.21-150400.15.62.1 * ocfs2-kmp-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-debugsource-5.14.21-150400.15.62.1 * kernel-syms-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150400.15.62.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * gfs2-kmp-rt-5.14.21-150400.15.62.1 * kernel-rt_debug-debugsource-5.14.21-150400.15.62.1 * kernel-rt-devel-5.14.21-150400.15.62.1 * kernel-rt_debug-devel-5.14.21-150400.15.62.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * kernel-rt-devel-debuginfo-5.14.21-150400.15.62.1 * dlm-kmp-rt-5.14.21-150400.15.62.1 * gfs2-kmp-rt-debuginfo-5.14.21-150400.15.62.1 * SUSE Real Time Module 15-SP4 (noarch) * kernel-source-rt-5.14.21-150400.15.62.1 * kernel-devel-rt-5.14.21-150400.15.62.1 * SUSE Real Time Module 15-SP4 (nosrc x86_64) * kernel-rt_debug-5.14.21-150400.15.62.1 * kernel-rt-5.14.21-150400.15.62.1 ## References: * https://www.suse.com/security/cve/CVE-2023-2006.html * https://www.suse.com/security/cve/CVE-2023-25775.html * https://www.suse.com/security/cve/CVE-2023-39197.html * https://www.suse.com/security/cve/CVE-2023-39198.html * https://www.suse.com/security/cve/CVE-2023-4244.html * https://www.suse.com/security/cve/CVE-2023-45863.html * https://www.suse.com/security/cve/CVE-2023-45871.html * https://www.suse.com/security/cve/CVE-2023-46862.html * https://www.suse.com/security/cve/CVE-2023-5158.html * https://www.suse.com/security/cve/CVE-2023-5717.html * https://www.suse.com/security/cve/CVE-2023-6039.html * https://www.suse.com/security/cve/CVE-2023-6176.html * https://bugzilla.suse.com/show_bug.cgi?id=1084909 * https://bugzilla.suse.com/show_bug.cgi?id=1189998 * https://bugzilla.suse.com/show_bug.cgi?id=1210447 * https://bugzilla.suse.com/show_bug.cgi?id=1214286 * https://bugzilla.suse.com/show_bug.cgi?id=1214976 *https://bugzilla.suse.com/show_bug.cgi?id=1215124 * https://bugzilla.suse.com/show_bug.cgi?id=1215292 * https://bugzilla.suse.com/show_bug.cgi?id=1215420 * https://bugzilla.suse.com/show_bug.cgi?id=1215458 * https://bugzilla.suse.com/show_bug.cgi?id=1215710 * https://bugzilla.suse.com/show_bug.cgi?id=1216058 * https://bugzilla.suse.com/show_bug.cgi?id=1216105 * https://bugzilla.suse.com/show_bug.cgi?id=1216259 * https://bugzilla.suse.com/show_bug.cgi?id=1216584 * https://bugzilla.suse.com/show_bug.cgi?id=1216693 * https://bugzilla.suse.com/show_bug.cgi?id=1216759 * https://bugzilla.suse.com/show_bug.cgi?id=1216761 * https://bugzilla.suse.com/show_bug.cgi?id=1216844 * https://bugzilla.suse.com/show_bug.cgi?id=1216861 * https://bugzilla.suse.com/show_bug.cgi?id=1216909 * https://bugzilla.suse.com/show_bug.cgi?id=1216959 * https://bugzilla.suse.com/show_bug.cgi?id=1216965 * https://bugzilla.suse.com/show_bug.cgi?id=1216976 * https://bugzilla.suse.com/show_bug.cgi?id=1217036 * https://bugzilla.suse.com/show_bug.cgi?id=1217068 * https://bugzilla.suse.com/show_bug.cgi?id=1217086 * https://bugzilla.suse.com/show_bug.cgi?id=1217124 * https://bugzilla.suse.com/show_bug.cgi?id=1217140 * https://bugzilla.suse.com/show_bug.cgi?id=1217195 * https://bugzilla.suse.com/show_bug.cgi?id=1217200 * https://bugzilla.suse.com/show_bug.cgi?id=1217205 * https://bugzilla.suse.com/show_bug.cgi?id=1217332 * https://bugzilla.suse.com/show_bug.cgi?id=1217366 * https://bugzilla.suse.com/show_bug.cgi?id=1217515 * https://bugzilla.suse.com/show_bug.cgi?id=1217598 * https://bugzilla.suse.com/show_bug.cgi?id=1217599 * https://bugzilla.suse.com/show_bug.cgi?id=1217609 * https://bugzilla.suse.com/show_bug.cgi?id=1217687 * https://bugzilla.suse.com/show_bug.cgi?id=1217731 * https://bugzilla.suse.com/show_bug.cgi?id=1217780 * * * . SUSE's latest kernel update fixes critical issues including denial of service and privilege escalation vulnerabilities.. SUSE Security Advisory, Linux Kernel Updates, Critical KernelFixes, Security Patches, Important Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 14, 2023 Important SuSE
100

SUSE 15 SP2: 2023:4784-2 Critical: Kernel Memory Management Bugs

* bsc#1084909 * bsc#1210780 * bsc#1214037 * bsc#1214344 * bsc#1214764 . # Security update for the Linux Kernel Announcement ID: SUSE-SU-2023:4783-1 Rating: important References: * bsc#1084909 * bsc#1210780 * bsc#1214037 * bsc#1214344 * bsc#1214764 * bsc#1216058 * bsc#1216259 * bsc#1216584 * bsc#1216965 * bsc#1216976 * bsc#1217332 * bsc#1217780 * jsc#PED-3184 * jsc#PED-5021 Cross-References: * CVE-2023-31083 * CVE-2023-39197 * CVE-2023-39198 * CVE-2023-45863 * CVE-2023-45871 * CVE-2023-5717 * CVE-2023-6176 CVSS scores: * CVE-2023-31083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-31083 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39197 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2023-39198 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-39198 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45871 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45871 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5717 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5717 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Live Patching 15-SP2 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 Business Critical Linux 15-SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Manager Proxy4.1 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Server 4.1 An update that solves seven vulnerabilities, contains two features and has five security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976). * CVE-2023-6176: Fixed a denial of service in the cryptographic algorithm scatterwalk functionality (bsc#1217332). * CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058). * CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may not be adequate for frames larger than the MTU (bsc#1216259). * CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965). * CVE-2023-31083: Fixed race condition in hci_uart_tty_ioctl (bsc#1210780). * CVE-2023-5717: Fixed a heap out-of-bounds write vulnerability in the Performance Events component (bsc#1216584). The following non-security bugs were fixed: * net: mana: Configure hwc timeout from hardware (bsc#1214037). * net: mana: Fix MANA VF unload when hardware is unresponsive (bsc#1214764). * powerpc: Do not clobber f0/vs0 during fp|altivec register save (bsc#1217780). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP2 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2023-4783=1 * SUSE Linux Enterprise High Availability Extension 15 SP2 zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2023-4783=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4783=1 * SUSE LinuxEnterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4783=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4783=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP2 (nosrc) * kernel-default-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Live Patching 15-SP2 (ppc64le s390x x86_64) * kernel-default-livepatch-5.3.18-150200.24.172.1 * kernel-default-livepatch-devel-5.3.18-150200.24.172.1 * kernel-livepatch-SLE15-SP2_Update_43-debugsource-1-150200.5.3.1 * kernel-default-debuginfo-5.3.18-150200.24.172.1 * kernel-livepatch-5_3_18-150200_24_172-default-debuginfo-1-150200.5.3.1 * kernel-livepatch-5_3_18-150200_24_172-default-1-150200.5.3.1 * kernel-default-debugsource-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Availability Extension 15 SP2 (aarch64 ppc64le s390x x86_64) * ocfs2-kmp-default-debuginfo-5.3.18-150200.24.172.1 * ocfs2-kmp-default-5.3.18-150200.24.172.1 * dlm-kmp-default-5.3.18-150200.24.172.1 * cluster-md-kmp-default-5.3.18-150200.24.172.1 * kernel-default-debuginfo-5.3.18-150200.24.172.1 * cluster-md-kmp-default-debuginfo-5.3.18-150200.24.172.1 * gfs2-kmp-default-debuginfo-5.3.18-150200.24.172.1 * gfs2-kmp-default-5.3.18-150200.24.172.1 * dlm-kmp-default-debuginfo-5.3.18-150200.24.172.1 * kernel-default-debugsource-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Availability Extension 15 SP2 (nosrc) * kernel-default-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 nosrc x86_64) * kernel-default-5.3.18-150200.24.172.1 * kernel-preempt-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * kernel-default-base-5.3.18-150200.24.172.1.150200.9.87.1 * kernel-preempt-debuginfo-5.3.18-150200.24.172.1 * kernel-obs-build-debugsource-5.3.18-150200.24.172.1 * kernel-preempt-debugsource-5.3.18-150200.24.172.1 *kernel-default-debuginfo-5.3.18-150200.24.172.1 * kernel-default-devel-debuginfo-5.3.18-150200.24.172.1 * kernel-syms-5.3.18-150200.24.172.1 * kernel-obs-build-5.3.18-150200.24.172.1 * kernel-preempt-devel-5.3.18-150200.24.172.1 * kernel-default-devel-5.3.18-150200.24.172.1 * kernel-default-debugsource-5.3.18-150200.24.172.1 * kernel-preempt-devel-debuginfo-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * kernel-source-5.3.18-150200.24.172.1 * kernel-devel-5.3.18-150200.24.172.1 * kernel-macros-5.3.18-150200.24.172.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch nosrc) * kernel-docs-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * kernel-default-base-5.3.18-150200.24.172.1.150200.9.87.1 * kernel-obs-build-debugsource-5.3.18-150200.24.172.1 * kernel-default-debuginfo-5.3.18-150200.24.172.1 * kernel-default-devel-debuginfo-5.3.18-150200.24.172.1 * kernel-syms-5.3.18-150200.24.172.1 * kernel-obs-build-5.3.18-150200.24.172.1 * reiserfs-kmp-default-debuginfo-5.3.18-150200.24.172.1 * reiserfs-kmp-default-5.3.18-150200.24.172.1 * kernel-default-devel-5.3.18-150200.24.172.1 * kernel-default-debugsource-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * kernel-source-5.3.18-150200.24.172.1 * kernel-devel-5.3.18-150200.24.172.1 * kernel-macros-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch nosrc) * kernel-docs-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 nosrc x86_64) * kernel-preempt-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * kernel-preempt-debuginfo-5.3.18-150200.24.172.1 * kernel-preempt-devel-5.3.18-150200.24.172.1 *kernel-preempt-debugsource-5.3.18-150200.24.172.1 * kernel-preempt-devel-debuginfo-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (nosrc ppc64le x86_64) * kernel-default-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * kernel-default-base-5.3.18-150200.24.172.1.150200.9.87.1 * kernel-obs-build-debugsource-5.3.18-150200.24.172.1 * kernel-default-debuginfo-5.3.18-150200.24.172.1 * kernel-default-devel-debuginfo-5.3.18-150200.24.172.1 * kernel-syms-5.3.18-150200.24.172.1 * kernel-obs-build-5.3.18-150200.24.172.1 * reiserfs-kmp-default-debuginfo-5.3.18-150200.24.172.1 * reiserfs-kmp-default-5.3.18-150200.24.172.1 * kernel-default-devel-5.3.18-150200.24.172.1 * kernel-default-debugsource-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * kernel-source-5.3.18-150200.24.172.1 * kernel-devel-5.3.18-150200.24.172.1 * kernel-macros-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch nosrc) * kernel-docs-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (nosrc x86_64) * kernel-preempt-5.3.18-150200.24.172.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (x86_64) * kernel-preempt-debuginfo-5.3.18-150200.24.172.1 * kernel-preempt-devel-5.3.18-150200.24.172.1 * kernel-preempt-debugsource-5.3.18-150200.24.172.1 * kernel-preempt-devel-debuginfo-5.3.18-150200.24.172.1 ## References: * https://www.suse.com/security/cve/CVE-2023-31083.html * https://www.suse.com/security/cve/CVE-2023-39197.html * https://www.suse.com/security/cve/CVE-2023-39198.html * https://www.suse.com/security/cve/CVE-2023-45863.html * https://www.suse.com/security/cve/CVE-2023-45871.html * https://www.suse.com/security/cve/CVE-2023-5717.html * https://www.suse.com/security/cve/CVE-2023-6176.html * https://bugzilla.suse.com/show_bug.cgi?id=1084909 * https://bugzilla.suse.com/show_bug.cgi?id=1210780 *https://bugzilla.suse.com/show_bug.cgi?id=1214037 * https://bugzilla.suse.com/show_bug.cgi?id=1214344 * https://bugzilla.suse.com/show_bug.cgi?id=1214764 * https://bugzilla.suse.com/show_bug.cgi?id=1216058 * https://bugzilla.suse.com/show_bug.cgi?id=1216259 * https://bugzilla.suse.com/show_bug.cgi?id=1216584 * https://bugzilla.suse.com/show_bug.cgi?id=1216965 * https://bugzilla.suse.com/show_bug.cgi?id=1216976 * https://bugzilla.suse.com/show_bug.cgi?id=1217332 * https://bugzilla.suse.com/show_bug.cgi?id=1217780 * * . Discover the latest SUSE Linux Kernel patch designed to combat significant security threats while enhancing system reliability and integrity for sensitive data protection. SUSE Linux Kernel Update, Kernel Security Patches, System Security Enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 13, 2023 Important SuSE
89

Fedora 38 FEDORA-2023-15deb2e32a critical kernel update overview of fixes

The 6.6.3 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-15deb2e32a 2023-12-04 01:50:38.988373 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.6.3 Release : 100.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.6.3 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 28 2023 Justin M. Forbes [6.6.3-0] - Add BugsFixed for 6.6.3 (Justin M. Forbes) - Update BugsFixed (Justin M. Forbes) - Turn on USB_DWC3 for Fedora (rhbz 2250955) (Justin M. Forbes) - Revert "netfilter: nf_tables: remove catchall element in GC sync path" (Justin M. Forbes) - More BugsFixed (Justin M. Forbes) - netfilter: nf_tables: remove catchall element in GC sync path (Pablo Neira Ayuso) - frop the build number back to 200 for fedora-srpm.sh (Justin M. Forbes) - ACPI: video: Use acpi_device_fix_up_power_children() (Hans de Goede) - ACPI: PM: Add acpi_device_fix_up_power_children() function (Hans de Goede) - Linux v6.6.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250105 - CVE-2023-6111 kernel: netfilter: use-after-free when removing catchall element in GC sync path https://bugzilla.redhat.com/show_bug.cgi?id=2250105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-15deb2e32a' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A crucial kernel update for Fedora 38 brings critical fixes ensuring system stability and performance enhancements.. Fedora Kernel Update, Kernel Fixes, System Stability, Software Improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2023 Critical Fedora
89

Fedora 37: 2023-50bd7c9c12 Critical: Kernel 6.5.6 Update

The 6.5.6 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-50bd7c9c12 2023-10-10 01:32:45.619518 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 37 Version : 6.5.6 Release : 100.fc37 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.5.6 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 6 2023 Augusto Caringi [6.5.6-0] - power: supply: core: Use blocking_notifier_call_chain to avoid RCU complaint (Kai-Heng Feng) - Revert "Add linux-next specific files for 20231004" (Justin M. Forbes) - redhat/configs: enable missing Kconfig options for Qualcomm RideSX4 (Brian Masney) - add a couple of CVEs to BugsFixed (Justin M. Forbes) - Add another F39 FE bug to BugsFixed (Justin M. Forbes) - Add linux-next specific files for 20231004 (Stephen Rothwell) - common: aarch64: enable NXP Flex SPI (Peter Robinson) - fedora: Switch TI_SCI_CLK and TI_SCI_PM_DOMAINS symbols to built-in (Javier Martinez Canillas) - Add bug for amdgpu to BugsFixed for 6.5.6 (Justin M. Forbes) - drm/amdgpu: set completion status as preempted for the resubmission (Jiadong Zhu) - Add CVE-2023-42756 to BugsFixed for 6.5.6 (Justin M. Forbes) - Linux v6.5.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2239845 - CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() https://bugzilla.redhat.com/show_bug.cgi?id=2239845 [ 2 ] Bug #2239848 - CVE-2023-42756 kernel: netfilter: race condition betweenIPSET_CMD_ADD and IPSET_CMD_SWAP https://bugzilla.redhat.com/show_bug.cgi?id=2239848 [ 3 ] Bug #2242172 - CVE-2023-5345 kernel: use-after-free vulnerability in the smb client component https://bugzilla.redhat.com/show_bug.cgi?id=2242172 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-50bd7c9c12' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent update for Fedora 37 with kernel 6.5.6 introduces essential patches that resolve various identified vulnerabilities.. kernel update,Fedora 37,security updates,system stability,critical fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 10, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-da8b7c1ca3 Critical Kernel Update

The 6.4.13 stable kernel updates contain a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-da8b7c1ca3 2023-09-03 01:15:04.283867 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.4.13 Release : 200.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.4.13 stable kernel updates contain a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 30 2023 Justin M. Forbes [6.4.13-0] - Add CVE-2023-4563 bugs to BugsFixed (Justin M. Forbes) - Linux v6.4.13 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2235306 - CVE-2023-4563 kernel: Use-after-free in nft_verdict_dump due to a race between set GC and transaction https://bugzilla.redhat.com/show_bug.cgi?id=2235306 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-da8b7c1ca3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. FedoraCode of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Kernel release 6.4.13 for Fedora 38 introduces key enhancements and crucial bug resolutions.. Fedora Kernel Updates,Fedora 38 Kernel Fixes,Kernel Security Updates,Linux Kernel Improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 03, 2023 Critical Fedora
202

openSUSE: 2023:3182-1 Important Kernel Security Threats Addressed

The SUSE Linux Enterprise 15 SP4 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed:. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2023:3182-1 Rating: important References: * #1150305 * #1193629 * #1194869 * #1207894 * #1208788 * #1210565 * #1210584 * #1210853 * #1211243 * #1211811 * #1211867 * #1212301 * #1212846 * #1212905 * #1213010 * #1213011 * #1213012 * #1213013 * #1213014 * #1213015 * #1213016 * #1213017 * #1213018 * #1213019 * #1213020 * #1213021 * #1213024 * #1213025 * #1213032 * #1213034 * #1213035 * #1213036 * #1213037 * #1213038 * #1213039 * #1213040 * #1213041 * #1213059 * #1213061 * #1213087 * #1213088 * #1213089 * #1213090 * #1213092 * #1213093 * #1213094 * #1213095 * #1213096 * #1213098 * #1213099 * #1213100 * #1213102 * #1213103 * #1213104 * #1213105 * #1213106 * #1213107 * #1213108 * #1213109 * #1213110 * #1213111 * #1213112 * #1213113 * #1213114 * #1213134 * #1213245 * #1213247 * #1213252 * #1213258 * #1213259 * #1213263 * #1213264 * #1213286 * #1213523 * #1213524 * #1213543 * #1213585 * #1213586 * #1213705 Cross-References: * CVE-2023-20593 * CVE-2023-2985 * CVE-2023-3117 * CVE-2023-31248 * CVE-2023-3390 * CVE-2023-35001 * CVE-2023-3609 * CVE-2023-3611 * CVE-2023-3812 CVSS scores: * CVE-2023-20593 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-20593 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-2985 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-3117 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3117 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-31248 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-31248 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3390 ( SUSE ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3390 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3609 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3609 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3611 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3611 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3812 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3812 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves nine vulnerabilities, contains one feature and has 70 fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-3609: Fixed an use-after-free vulnerability in net/sched (bsc#1213586). * CVE-2023-3611: Fixed an out-of-bounds write vulnerability in net/sched (bsc#1213585). * CVE-2023-3812: Fixed an out-of-bounds memory access flaw in the TUN/TAP device driver functionality that could allow a local user to crash or potentially escalate their privileges on the system (bsc#1213543). * CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213059). * CVE-2023-31248: Fixed an use-after-free vulnerability in nft_chain_lookup_byid that could allow a local attacker to escalate their privilege (bsc#1213061). * CVE-2023-3390: Fixedan use-after-free vulnerability in the netfilter subsystem in net/netfilter/nf_tables_api.c that could allow a local attacker with user access to cause a privilege escalation issue (bsc#1212846). * CVE-2023-3117: Fixed an use-after-free vulnerability in the netfilter subsystem when processing named and anonymous sets in batch requests that could allow a local user with CAP_NET_ADMIN capability to crash or potentially escalate their privileges on the system (bsc#1213245). * CVE-2023-20593: Fixed a ZenBleed issue in "Zen 2" CPUs that could allow an attacker to potentially access sensitive information (bsc#1213286). * CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in fs/hfsplus/super.c that could allow a local user to cause a denial of service (bsc#1211867). The following non-security bugs were fixed: * Add MODULE_FIRMWARE() for FIRMWARE_TG357766 (git-fixes). * Drop patch that caused issues with k3s (bsc#1213705). * Enable NXP SNVS RTC driver for i.MX 8MQ/8MP (jsc#PED-4758) * Fix documentation of panic_on_warn (git-fixes). * Fixed launch issue on 15-SP5 (git-fixes, bsc#1210853). * Revert "arm64: dts: zynqmp: Add address-cells property to interrupt (git- fixes) * Revert "drm/amd/display: edp do not add non-edid timings" (git-fixes). * acpi: utils: Fix acpi_evaluate_dsm_typed() redefinition error (git-fixes). * alsa: fireface: make read-only const array for model names static (git- fixes). * alsa: hda/realtek - remove 3k pull low procedure (git-fixes). * alsa: hda/realtek: Add quirk for ASUS ROG G614Jx (git-fixes). * alsa: hda/realtek: Add quirk for ASUS ROG GA402X (git-fixes). * alsa: hda/realtek: Add quirk for ASUS ROG GX650P (git-fixes). * alsa: hda/realtek: Add quirk for ASUS ROG GZ301V (git-fixes). * alsa: hda/realtek: Add quirk for Clevo NPx0SNx (git-fixes). * alsa: hda/realtek: Add quirk for Clevo NS70AU (git-fixes). * alsa: hda/realtek: Add quirks for Unis H3C Desktop B760 & Q760 (git-fixes). * alsa: hda/realtek: Add support for DELL Oasis 13/14/16laptops (git-fixes). * alsa: hda/realtek: Amend G634 quirk to enable rear speakers (git-fixes). * alsa: hda/realtek: Enable Mute LED on HP Laptop 15s-eq2xxx (git-fixes). * alsa: hda/realtek: Fix generic fixup definition for cs35l41 amp (git-fixes). * alsa: hda/realtek: Whitespace fix (git-fixes). * alsa: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() (git-fixes). * alsa: oxfw: make read-only const array models static (git-fixes). * alsa: pcm: Fix potential data race at PCM memory allocation helpers (git- fixes). * apparmor: fix missing error check for rhashtable_insert_fast (git-fixes). * arm64/mm: mark private VM_FAULT_X defines as vm_fault_t (git-fixes) * arm64: dts: microchip: sparx5: do not use PSCI on reference boards (git- fixes) * arm64: vdso: Pass (void *) to virt_to_page() (git-fixes) * arm64: xor-neon: mark xor_arm64_neon_*() static (git-fixes) * asoc: codecs: wcd-mbhc-v2: fix resource leaks on component remove (git- fixes). * asoc: codecs: wcd934x: fix resource leaks on component remove (git-fixes). * asoc: codecs: wcd938x: fix codec initialisation race (git-fixes). * asoc: codecs: wcd938x: fix dB range for HPHL and HPHR (git-fixes). * asoc: codecs: wcd938x: fix missing clsh ctrl error handling (git-fixes). * asoc: codecs: wcd938x: fix soundwire initialisation race (git-fixes). * asoc: tegra: Fix ADX byte map (git-fixes). * asoc: tegra: Fix AMX byte map (git-fixes). * can: bcm: Fix UAF in bcm_proc_show() (git-fixes). * cifs: add a warning when the in-flight count goes negative (bsc#1193629). * cifs: address unused variable warning (bsc#1193629). * cifs: do all necessary checks for credits within or before locking (bsc#1193629). * cifs: fix lease break oops in xfstest generic/098 (bsc#1193629). * cifs: fix max_credits implementation (bsc#1193629). * cifs: fix session state check in reconnect to avoid use-after-free issue (bsc#1193629). * cifs: fix session state check in smb2_find_smb_ses (bsc#1193629). * cifs: fix session statetransition to avoid use-after-free issue (bsc#1193629). * cifs: fix sockaddr comparison in iface_cmp (bsc#1193629). * cifs: fix status checks in cifs_tree_connect (bsc#1193629). * cifs: log session id when a matching ses is not found (bsc#1193629). * cifs: new dynamic tracepoint to track ses not found errors (bsc#1193629). * cifs: prevent use-after-free by freeing the cfile later (bsc#1193629). * cifs: print all credit counters in DebugData (bsc#1193629). * cifs: print client_guid in DebugData (bsc#1193629). * cifs: print more detail when invalidate_inode_mapping fails (bsc#1193629). * cifs: print nosharesock value while dumping mount options (bsc#1193629). * clk: qcom: camcc-sc7180: Add parent dependency to all camera GDSCs (git- fixes). * clk: qcom: gcc-ipq6018: Use floor ops for sdcc clocks (git-fixes). * codel: fix kernel-doc notation warnings (git-fixes). * crypto: kpp - Add helper to set reqsize (git-fixes). * crypto: qat - Use helper to set reqsize (git-fixes). * devlink: fix kernel-doc notation warnings (git-fixes). * docs: networking: Update codeaurora references for rmnet (git-fixes). * documentation: bonding: fix the doc of peer_notif_delay (git-fixes). * documentation: timers: hrtimers: Make hybrid union historical (git-fixes). * drm/amd/display: Correct `DMUB_FW_VERSION` macro (git-fixes). * drm/amdgpu: Set vmbo destroy after pt bo is created (git-fixes). * drm/amdgpu: Validate VM ioctl flags (git-fixes). * drm/amdgpu: avoid restore process run into dead loop (git-fixes). * drm/amdgpu: fix clearing mappings for BOs that are always valid in VM (git- fixes). * drm/atomic: Allow vblank-enabled + self-refresh "disable" (git-fixes). * drm/atomic: Fix potential use-after-free in nonblocking commits (git-fixes). * drm/bridge: tc358768: Add atomic_get_input_bus_fmts() implementation (git- fixes). * drm/bridge: tc358768: fix TCLK_TRAILCNT computation (git-fixes). * drm/bridge: tc358768: fix THS_TRAILCNT computation (git-fixes). * drm/bridge: tc358768: fix THS_ZEROCNTcomputation (git-fixes). * drm/client: Fix memory leak in drm_client_target_cloned (git-fixes). * drm/i915/psr: Use hw.adjusted mode when calculating io/fast wake times (git- fixes). * drm/i915: Fix one wrong caching mode enum usage (git-fixes). * drm/msm/disp/dpu: get timing engine status from intf status register (git- fixes). * drm/msm/dpu: Set DPU_DATA_HCTL_EN for in INTF_SC7180_MASK (git-fixes). * drm/panel: simple: Add Powertip PH800480T013 drm_display_mode flags (git- fixes). * drm/panel: simple: Add connector_type for innolux_at043tn24 (git-fixes). * drm/ttm: Do not leak a resource on swapout move error (git-fixes). * dt-bindings: phy: brcm,brcmstb-usb-phy: Fix error in "compatible" conditional schema (git-fixes). * ext4: Fix reusing stale buffer heads from last failed mounting (bsc#1213020). * ext4: add EA_INODE checking to ext4_iget() (bsc#1213106). * ext4: add ext4_sb_block_valid() refactored out of ext4_inode_block_valid() (bsc#1213088). * ext4: add lockdep annotations for i_data_sem for ea_inode's (bsc#1213109). * ext4: add strict range checks while freeing blocks (bsc#1213089). * ext4: avoid deadlock in fs reclaim with page writeback (bsc#1213016). * ext4: bail out of ext4_xattr_ibody_get() fails for any reason (bsc#1213018). * ext4: block range must be validated before use in ext4_mb_clear_bb() (bsc#1213090). * ext4: check iomap type only if ext4_iomap_begin() does not fail (bsc#1213103). * ext4: disallow ea_inodes with extended attributes (bsc#1213108). * ext4: fail ext4_iget if special inode unallocated (bsc#1213010). * ext4: fix WARNING in ext4_update_inline_data (bsc#1213012). * ext4: fix WARNING in mb_find_extent (bsc#1213099). * ext4: fix bug_on in __es_tree_search caused by bad quota inode (bsc#1213111). * ext4: fix data races when using cached status extents (bsc#1213102). * ext4: fix deadlock when converting an inline directory in nojournal mode (bsc#1213105). * ext4: fix i_disksize exceeding i_size problem in paritally written case (bsc#1213015). *ext4: fix lockdep warning when enabling MMP (bsc#1213100). * ext4: fix task hung in ext4_xattr_delete_inode (bsc#1213096). * ext4: fix to check return value of freeze_bdev() in ext4_shutdown() (bsc#1213021). * ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline (bsc#1213098). * ext4: improve error handling from ext4_dirhash() (bsc#1213104). * ext4: improve error recovery code paths in __ext4_remount() (bsc#1213017). * ext4: move where set the MAY_INLINE_DATA flag is set (bsc#1213011). * ext4: only update i_reserved_data_blocks on successful block allocation (bsc#1213019). * ext4: refactor ext4_free_blocks() to pull out ext4_mb_clear_bb() (bsc#1213087). * ext4: refuse to create ea block when umounted (bsc#1213093). * ext4: set lockdep subclass for the ea_inode in ext4_xattr_inode_cache_find() (bsc#1213107). * ext4: turn quotas off if mount failed after enabling quotas (bsc#1213110). * ext4: update s_journal_inum if it changes after journal replay (bsc#1213094). * ext4: use ext4_fc_tl_mem in fast-commit replay path (bsc#1213092). * ext4: zero i_disksize when initializing the bootloader inode (bsc#1213013). * fbdev: au1200fb: Fix missing IRQ check in au1200fb_drv_probe (git-fixes). * fbdev: imxfb: warn about invalid left/right margin (git-fixes). * fuse: ioctl: translate ENOSYS in outarg (bsc#1213524). * fuse: revalidate: do not invalidate if interrupted (bsc#1213523). * hvcs: Fix hvcs port reference counting (bsc#1213134 ltc#202861). * hvcs: Get reference to tty in remove (bsc#1213134 ltc#202861). * hvcs: Synchronize hotplug remove with port free (bsc#1213134 ltc#202861). * hvcs: Use dev_groups to manage hvcs device attributes (bsc#1213134 ltc#202861). * hvcs: Use driver groups to manage driver attributes (bsc#1213134 ltc#202861). * hvcs: Use vhangup in hotplug remove (bsc#1213134 ltc#202861). * hwmon: (adm1275) Allow setting sample averaging (git-fixes). * hwmon: (pmbus/adm1275) Fix problems with temperature monitoring on ADM1272 (git-fixes). * i2c: xiic:Defer xiic_wakeup() and __xiic_start_xfer() in xiic_process() (git-fixes). * i2c: xiic: Do not try to handle more interrupt events after error (git- fixes). * ib/hfi1: Use bitmap_zalloc() when applicable (git-fixes) * inotify: Avoid reporting event with invalid wd (bsc#1213025). * jbd2: fix data missing when reusing bh which is ready to be checkpointed (bsc#1213095). * jdb2: Do not refuse invalidation of already invalidated buffers (bsc#1213014). * kABI: do not check external trampolines for signature (kabi bsc#1207894 bsc#1211243). * kabi/severities: Add VAS symbols changed due to recent fix VAS accelerators are directly tied to the architecture, there is no reason to have out-of- tree production drivers * kselftest: vDSO: Fix accumulation of uninitialized ret when CLOCK_REALTIME is undefined (git-fixes). * leds: trigger: netdev: Recheck NETDEV_LED_MODE_LINKUP on dev rename (git- fixes). * media: atomisp: gmin_platform: fix out_len in gmin_get_config_dsm_var() (git-fixes). * media: cec: i2c: ch7322: also select REGMAP (git-fixes). * media: i2c: Correct format propagation for st-mipid02 (git-fixes). * media: usb: Check az6007_read() return value (git-fixes). * media: usb: siano: Fix warning due to null work_func_t function pointer (git-fixes). * media: venus: helpers: Fix ALIGN() of non power of two (git-fixes). * media: videodev2.h: Fix struct v4l2_input tuner index comment (git-fixes). * memcg: drop kmem.limit_in_bytes (bsc#1208788, bsc#1212905). * mmc: core: disable TRIM on Kingston EMMC04G-M627 (git-fixes). * mmc: sdhci: fix DMA configure compatibility issue when 64bit DMA mode is used (git-fixes). * net/sched: sch_qfq: refactor parsing of netlink parameters (bsc#1213585). * net/sched: sch_qfq: reintroduce lmax bound check for MTU (bsc#1213585). * net: mana: Add support for vlan tagging (bsc#1212301). * net: phy: prevent stale pointer dereference in phy_init() (git-fixes). * ntb: amd: Fix error handling in amd_ntb_pci_driver_init() (git-fixes). * ntb: idt: Fix errorhandling in idt_pci_driver_init() (git-fixes). * ntb: intel: Fix error handling in intel_ntb_pci_driver_init() (git-fixes). * ntb: ntb_tool: Add check for devm_kcalloc (git-fixes). * ntb: ntb_transport: fix possible memory leak while device_register() fails (git-fixes). * nvme-multipath: support io stats on the mpath device (bsc#1210565). * nvme: introduce nvme_start_request (bsc#1210565). * ocfs2: Switch to security_inode_init_security() (git-fixes). * ocfs2: check new file size on fallocate call (git-fixes). * ocfs2: fix use-after-free when unmounting read-only filesystem (git-fixes). * opp: Fix use-after-free in lazy_opp_tables after probe deferral (git-fixes). * pci/pm: Avoid putting EloPOS E2/S2/H2 PCIe Ports in D3cold (git-fixes). * pci: Add function 1 DMA alias quirk for Marvell 88SE9235 (git-fixes). * phy: Revert "phy: Remove SOC_EXYNOS4212 dep. from PHY_EXYNOS4X12_USB" (git- fixes). * phy: tegra: xusb: Clear the driver reference in usb-phy dev (git-fixes). * phy: tegra: xusb: check return value of devm_kzalloc() (git-fixes). * pie: fix kernel-doc notation warning (git-fixes). * pinctrl: amd: Detect internal GPIO0 debounce handling (git-fixes). * pinctrl: amd: Fix mistake in handling clearing pins at startup (git-fixes). * pinctrl: amd: Only use special debounce behavior for GPIO 0 (git-fixes). * powerpc/64: Only WARN if __pa()/__va() called with bad addresses (bsc#1194869). * powerpc/64s: Fix VAS mm use after free (bsc#1194869). * powerpc/book3s64/mm: Fix DirectMap stats in /proc/meminfo (bsc#1194869). * powerpc/bpf: Fix use of user_pt_regs in uapi (bsc#1194869). * powerpc/ftrace: Remove ftrace init tramp once kernel init is complete (bsc#1194869). * powerpc/interrupt: Do not read MSR from interrupt_exit_kernel_prepare() (bsc#1194869). * powerpc/mm/dax: Fix the condition when checking if altmap vmemap can cross- boundary (bsc#1150305 ltc#176097 git-fixes). * powerpc/mm: Switch obsolete dssall to.long (bsc#1194869). * powerpc/powernv/sriov: perform null check on iovbefore dereferencing iov (bsc#1194869). * powerpc/powernv/vas: Assign real address to rx_fifo in vas_rx_win_attr (bsc#1194869). * powerpc/prom_init: Fix kernel config grep (bsc#1194869). * powerpc/secvar: fix refcount leak in format_show() (bsc#1194869). * powerpc/xics: fix refcount leak in icp_opal_init() (bsc#1194869). * powerpc: clean vdso32 and vdso64 directories (bsc#1194869). * powerpc: define get_cycles macro for arch-override (bsc#1194869). * powerpc: update ppc_save_regs to save current r1 in pt_regs (bsc#1194869). * pwm: ab8500: Fix error code in probe() (git-fixes). * pwm: imx-tpm: force 'real_period' to be zero in suspend (git-fixes). * pwm: sysfs: Do not apply state to already disabled PWMs (git-fixes). * rdma/rxe: Fix access checks in rxe_check_bind_mw (git-fixes) * rpm/check-for-config-changes: ignore also RISCV_ISA_ _and DYNAMIC_SIGFRAME They depend on CONFIG_TOOLCHAIN_HAS__. * rsi: remove kernel-doc comment marker (git-fixes). * s390/ap: fix status returned by ap_aqic() (git-fixes bsc#1213259). * s390/ap: fix status returned by ap_qact() (git-fixes bsc#1213258). * s390/debug: add _ASM_S390_ prefix to header guard (git-fixes bsc#1213263). * s390/percpu: add READ_ONCE() to arch_this_cpu_to_op_simple() (git-fixes bsc#1213252). * s390: define RUNTIME_DISCARD_EXIT to fix link error with GNU ld < 2.36 (git-fixes bsc#1213264). * s390: discard.interp section (git-fixes bsc#1213247). * sched/debug: fix dentry leak in update_sched_domain_debugfs (git-fixes) * sched: Fix DEBUG &&!SCHEDSTATS warn (git-fixes) * security: keys: Modify mismatched function name (git-fixes). * selftests: mptcp: depend on SYN_COOKIES (git-fixes). * selftests: mptcp: sockopt: return error if wrong mark (git-fixes). * selftests: rtnetlink: remove netdevsim device after ipsec offload test (git- fixes). * selftests: tc: add 'ct' action kconfig dep (git-fixes). * selftests: tc: add ConnTrack procfs kconfig (git-fixes). * selftests: tc: set timeout to 15 minutes (git-fixes). * signal/powerpc: Onswapcontext failure force SIGSEGV (bsc#1194869). * signal: Replace force_sigsegv(SIGSEGV) with force_fatal_sig(SIGSEGV) (bsc#1194869). * smb3: do not reserve too many oplock credits (bsc#1193629). * smb3: missing null check in SMB2_change_notify (bsc#1193629). * smb: client: fix broken file attrs with nodfs mounts (bsc#1193629). * smb: client: fix missed ses refcounting (git-fixes). * smb: client: fix parsing of source mount option (bsc#1193629). * smb: client: fix shared DFS root mounts with different prefixes (bsc#1193629). * smb: client: fix warning in CIFSFindFirst() (bsc#1193629). * smb: client: fix warning in CIFSFindNext() (bsc#1193629). * smb: client: fix warning in cifs_match_super() (bsc#1193629). * smb: client: fix warning in cifs_smb3_do_mount() (bsc#1193629). * smb: client: fix warning in generic_ip_connect() (bsc#1193629). * smb: client: improve DFS mount check (bsc#1193629). * smb: client: remove redundant pointer 'server' (bsc#1193629). * smb: delete an unnecessary statement (bsc#1193629). * smb: move client and server files to common directory fs/smb (bsc#1193629). * smb: remove obsolete comment (bsc#1193629). * soundwire: qcom: fix storing port config out-of-bounds (git-fixes). * spi: bcm-qspi: return error if neither hif_mspi nor mspi is available (git- fixes). * spi: bcm63xx: fix max prepend length (git-fixes). * tpm: tpm_vtpm_proxy: fix a race condition in /dev/vtpmx creation (git- fixes). * tty: serial: fsl_lpuart: add earlycon for imx8ulp platform (git-fixes). * ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size (bsc#1210584). * ubi: ensure that VID header offset + VID header size

Calendar%202 Aug 03, 2023 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200