Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2686 http://linux.oracle.com/errata/ELSA-2025-2686.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libxml2-2.9.7-19.el8_10.i686.rpm libxml2-2.9.7-19.el8_10.x86_64.rpm libxml2-devel-2.9.7-19.el8_10.i686.rpm libxml2-devel-2.9.7-19.el8_10.x86_64.rpm python3-libxml2-2.9.7-19.el8_10.x86_64.rpm aarch64: libxml2-2.9.7-19.el8_10.aarch64.rpm libxml2-devel-2.9.7-19.el8_10.aarch64.rpm python3-libxml2-2.9.7-19.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//libxml2-2.9.7-19.el8_10.src.rpm Related CVEs: CVE-2024-56171 CVE-2025-24928 Description of changes: [2.9.7-19] - Fix CVE-2024-56171 (RHEL-80122) - Fix CVE-2025-24928 (RHEL-80137) [2.9.7.18.2] - Fix CVE-2022-49043 (RHEL-76289) [2.9.7-18.1] - Fix CVE-2024-25062 (RHEL-31056) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1736 http://linux.oracle.com/errata/ELSA-2025-1736.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.x86_64.rpm pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.x86_64.rpm postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.x86_64.rpm postgresql-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-contrib-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-docs-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-plperl-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-plpython3-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-pltcl-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-server-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-server-devel-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-static-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-test-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-test-rpm-macros-13.20-1.module+el8.10.0+90526+050ec11b.noarch.rpm postgresql-upgrade-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-upgrade-devel-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm aarch64: pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.aarch64.rpm pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.aarch64.rpm postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.aarch64.rpm postgresql-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-contrib-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-docs-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-plperl-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-plpython3-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-pltcl-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-server-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-server-devel-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-static-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-test-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-test-rpm-macros-13.20-1.module+el8.10.0+90526+050ec11b.noarch.rpm postgresql-upgrade-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-upgrade-devel-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgresql-13.20-1.module+el8.10.0+90526+050ec11b.src.rpm Related CVEs: CVE-2025-1094 Description of changes: pgaudit [1.5.0-1] - Update to version 1.5.0 Related: #1855776 pg_repack [1.4.6-3] - Release bump - enable gating postgres-decoderbufs [0.10.0-2] - Release bump for rebuild against libpq-12.1-3 postgresql [13.20-1] - Update to 13.20 - Fix CVE-2025-1094 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1673 http://linux.oracle.com/errata/ELSA-2025-1673.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-devel-0.996-2.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-ipadic-EUCJP-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-common-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-devel-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-errmsg-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-libs-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-server-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-test-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm aarch64: mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-devel-0.996-2.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-ipadic-EUCJP-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-common-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-devel-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-errmsg-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-libs-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-server-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-test-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.src.rpm RelatedCVEs: CVE-2024-5535 CVE-2024-7264 CVE-2024-11053 CVE-2024-21193 CVE-2024-21194 CVE-2024-21196 CVE-2024-21197 CVE-2024-21198 CVE-2024-21199 CVE-2024-21201 CVE-2024-21203 CVE-2024-21212 CVE-2024-21213 CVE-2024-21218 CVE-2024-21219 CVE-2024-21230 CVE-2024-21231 CVE-2024-21236 CVE-2024-21237 CVE-2024-21238 CVE-2024-21239 CVE-2024-21241 CVE-2024-21247 CVE-2024-37371 CVE-2025-21490 CVE-2025-21491 CVE-2025-21494 CVE-2025-21497 CVE-2025-21500 CVE-2025-21501 CVE-2025-21503 CVE-2025-21504 CVE-2025-21505 CVE-2025-21518 CVE-2025-21519 CVE-2025-21520 CVE-2025-21521 CVE-2025-21522 CVE-2025-21523 CVE-2025-21525 CVE-2025-21529 CVE-2025-21531 CVE-2025-21534 CVE-2025-21536 CVE-2025-21540 CVE-2025-21543 CVE-2025-21546 CVE-2025-21555 CVE-2025-21559 Description of changes: mecab [0.996-2.12] - Bump version for 'mysql' module rebuild We are moving the 'mecab-devel' RPM from the 'buildroot' repo to the 'AppStream' repo - Resolves: #2180411 mecab-ipadic [2.7.0.20070801-17.0.1] - Rename the LICENSE.Fedora to LICENSE.oracle [2.7.0.20070801-17] - Bump the release - Resolves: RHEL-24525 mysql [8.0.41-1] - Update to MySQL 8.0.41 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1372 http://linux.oracle.com/errata/ELSA-2025-1372.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.x86_64.rpm buildah-tests-1.33.12-1.module+el8.10.0+90509+b5e1e789.x86_64.rpm cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.x86_64.rpm container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.noarch.rpm crit-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-devel-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-libs-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-catatonit-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-docker-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.noarch.rpm podman-gvproxy-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-plugins-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-remote-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-tests-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm python3-criu-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm python3-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.noarch.rpm runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.x86_64.rpm skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.x86_64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90449+0b7c8529.x86_64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.noarch.rpm aarch64: aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.aarch64.rpm buildah-tests-1.33.12-1.module+el8.10.0+90509+b5e1e789.aarch64.rpm cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.aarch64.rpm container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.noarch.rpm crit-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-devel-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-libs-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-catatonit-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-docker-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.noarch.rpm podman-gvproxy-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-plugins-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-remote-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-tests-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm python3-criu-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm python3-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.noarch.rpm runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.aarch64.rpm skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.aarch64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90449+0b7c8529.aarch64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//criu-3.18-5.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.src.rpm Related CVEs: CVE-2024-11218 Description of changes: aardvark-dns buildah [2:1.33.12-1] -update to the latest content of https://github.com/containers/buildah/tree/release-1.33 (https://github.com/containers/buildah/commit/58af1cd) - Resolves: RHEL-67612 cockpit-podman conmon containernetworking-plugins containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - remove references to RedHat registry (Nikita Gerasimov) container-selinux criu crun fuse-overlayfs libslirp netavark oci-seccomp-bpf-hook podman [4.9.4-19.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-19] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/bfdd4c2) - Resolves: RHEL-67601 python-podman [4.9.0-3] - sync with release-4.9 branch - Resolves: RHEL-31069 runc [1:1.1.12-6] - Add CPU affinity feature from Kir Kolishkin - Resolves: RHEL-74865 skopeo slirp4netns udica _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0314 http://linux.oracle.com/errata/ELSA-2025-0314.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: raptor2-2.0.15-17.el8_10.i686.rpm raptor2-2.0.15-17.el8_10.x86_64.rpm raptor2-devel-2.0.15-17.el8_10.i686.rpm raptor2-devel-2.0.15-17.el8_10.x86_64.rpm aarch64: raptor2-2.0.15-17.el8_10.aarch64.rpm raptor2-devel-2.0.15-17.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//raptor2-2.0.15-17.el8_10.src.rpm Related CVEs: CVE-2024-57823 Description of changes: [2.0.15-17] - Resolves: CVE-2024-57823 integer underflow when normalizing a URI with the turtle parser _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20007 http://linux.oracle.com/errata/ELSA-2025-20007.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.93.1.el6uek.noarch.rpm kernel-uek-firmware-4.1.12-124.93.1.el6uek.noarch.rpm kernel-uek-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-devel-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-debug-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.93.1.el6uek.x86_64.rpm Related CVEs: CVE-2024-26840 Description of changes: [4.1.12-124.93.1.el6uek] - cachefiles: fix memory leak in cachefiles_add_cache() (Baokun Li) [Orabug: 36544657] {CVE-2024-26840} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12606 http://linux.oracle.com/errata/ELSA-2024-12606.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.89.4.el6uek.noarch.rpm kernel-uek-firmware-4.1.12-124.89.4.el6uek.noarch.rpm kernel-uek-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-devel-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-debug-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.89.4.el6uek.x86_64.rpm Related CVEs: CVE-2021-46939 CVE-2021-47118 CVE-2021-47153 CVE-2021-47171 CVE-2021-47236 CVE-2021-47284 CVE-2021-47310 CVE-2021-47353 CVE-2021-47356 CVE-2022-48627 CVE-2023-52445 CVE-2023-52477 CVE-2023-52574 CVE-2023-52594 CVE-2023-52615 CVE-2023-52620 CVE-2023-52628 CVE-2023-52703 CVE-2023-52809 CVE-2023-52881 CVE-2023-6040 CVE-2024-26635 CVE-2024-26651 CVE-2024-26675 CVE-2024-26679 CVE-2024-26704 CVE-2024-26772 CVE-2024-26778 CVE-2024-26801 CVE-2024-26805 CVE-2024-26816 CVE-2024-26859 CVE-2024-26880 CVE-2024-26903 CVE-2024-35922 CVE-2024-35944 CVE-2024-35978 CVE-2024-35982 CVE-2024-36016 CVE-2024-36883 CVE-2024-36919 CVE-2024-36950 CVE-2024-36960 Description of changes: [4.1.12-124.89.4.el6uek] - isdn: mISDN: netjet: Fix crash in nj_probe: (Zheyu Ma) [Orabug: 36940405] {CVE-2021-47284} - tracing: Restructure trace_clock_global() to never block (Steven Rostedt (VMware)) [Orabug: 36940388] {CVE-2021-46939} - udf: Fix NULL pointer dereference in udf_symlink function (Arturo Giusti) [Orabug: 36806640] {CVE-2021-47353} - media: pvrusb2: fix use after free on context disconnection (Ricardo B. Marliere) [Orabug: 36802294] {CVE-2023-52445} - vt: fix memory overlapping when deleting chars in the buffer (Yangxi Xiang) [Orabug: 36802212] {CVE-2022-48627} - tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (Daniel Starke) [Orabug: 36678070] {CVE-2024-36016} - netfilter: nftables: exthdr: fix 4-byte stack OOB write (Florian Westphal) [Orabug: 36654631] {CVE-2023-52628} - dm: call the resume method on internal suspend (Mikulas Patocka) [Orabug: 36544879] {CVE-2024-26880} - net/bnx2x: Prevent access to a freed page in page_pool (Thinh Tran) [Orabug: 36544783] {CVE-2024-26859} - x86, relocs: Ignore relocations in .notes section (Kees Cook) [Orabug: 36531115] {CVE-2024-26816} - netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter (Ryosuke Yasuoka) [Orabug: 36531057] {CVE-2024-26805} - fbdev: savage: Error out if pixclock equals zero (Fullway Wang) [Orabug: 36530913] {CVE-2024-26778} - ext4: fix double-free of blocks due to wrong extents moved_len (Baokun Li) [Orabug: 36530519] {CVE-2024-26704} - sr9800: Add check for usbnet_get_endpoints (Chen Ni) [Orabug: 36530183] {CVE-2024-26651} - llc: Drop support for ETH_P_TR_802_2. (Kuniyuki Iwashima) [Orabug: 36530047] {CVE-2024-26635} - netfilter: nf_tables: Reject tables of unsupported family (Phil Sutter) [Orabug: 36192155] {CVE-2023-6040} [4.1.12-124.89.3.el6uek] - wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() (Minsuk Kang) [Orabug: 36802321] {CVE-2023-52594} - batman-adv: Avoid infinite loop trying to resize local TT (Sven Eckelmann) [Orabug: 36643464] {CVE-2024-35982} - Bluetooth: Fix memory leak in hci_req_sync_complete() (Dmitry Antipov) [Orabug: 36643456] {CVE-2024-35978} - VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host() (Harshit Mogalapalli) [Orabug: 36643323] {CVE-2024-35944} - fbmon: prevent division by zero in fb_videomode_from_videomode() (Roman Smirnov) [Orabug: 36643194] {CVE-2024-35922} [4.1.12-124.89.2.el6uek] - scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() (Wenchao Hao) [Orabug: 36901390] {CVE-2023-52809} - net: usb: fix memory leak in smsc75xx_bind (Pavel Skripkin) [Orabug: 36802200] {CVE-2021-47171} - i2c: i801: Don't generate an interrupt on busreset (Jean Delvare) [Orabug: 36792714] {CVE-2021-47153} - pid: take a reference when initializing cad_pid (Mark Rutland) [Orabug: 36792687] {CVE-2021-47118} - drm/vmwgfx: Fix invalid reads in fence signaled events (Zack Rusin) [Orabug: 36691531] {CVE-2024-36960} - firewire: ohci: mask bus reset interrupts between ISR and bottom half (Adam Goldman) [Orabug: 36683507] {CVE-2024-36950} - scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload (Saurav Kashyap) [Orabug: 36683370] {CVE-2024-36919} - net: fix out-of-bounds access in ops_init (Thadeu Lima de Souza Cascardo) [Orabug: 36683115] {CVE-2024-36883} - netfilter: nf_tables: disallow timeout for anonymous sets (Pablo Neira Ayuso) [Orabug: 36654625] {CVE-2023-52620} - team: fix null-ptr-deref when team device type is changed (Ziyang Xuan) [Orabug: 36654606] {CVE-2023-52574} [4.1.12-124.89.1.el6uek] - tcp: do not accept ACK of bytes we never sent (Eric Dumazet) [Orabug: 36806731] {CVE-2023-52881} - net/usb: kalmia: Don't pass act_len in usb_bulk_msg error path (Miko Larsson) [Orabug: 36806698] {CVE-2023-52703} - hwrng: core - Fix page fault dead lock on mmap-ed hwrng (Herbert Xu) [Orabug: 36806668] {CVE-2023-52615} - mISDN: fix possible use-after-free in HFC_cleanup() (Zou Wei) [Orabug: 36806645] {CVE-2021-47356} - net: ti: fix UAF in tlan_remove_one (Pavel Skripkin) [Orabug: 36806628] {CVE-2021-47310} - net: cdc_eem: fix tx fixup skb leak (Linyu Yuan) [Orabug: 36806622] {CVE-2021-47236} - usb: hub: Guard against accesses to uninitialized BOS descriptors (Ricardo Cañuelo) [Orabug: 36802300] {CVE-2023-52477} - USB: add quirk for devices with broken LPM (Alan Stern) [Orabug: 36802300] {CVE-2023-52477} - Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security (Yuxuan Hu) [Orabug: 36544991] {CVE-2024-26903} - Bluetooth: Avoid potential use-after-free in hci_error_reset (Ying Hsu) [Orabug: 36531042] {CVE-2024-26801} - ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() (Baokun Li) [Orabug: 36530881] {CVE-2024-26772} - inet: read sk-> sk_family once in inet_recv_error() (Eric Dumazet) [Orabug: 36530348] {CVE-2024-26679} - ppp_async: limit MRU to 64K (Eric Dumazet) [Orabug: 36530335] {CVE-2024-26675} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12584 http://linux.oracle.com/errata/ELSA-2024-12584.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-container-5.4.17-2136.334.6.el8.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.334.6.el8.x86_64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//kernel-uek-container-5.4.17-2136.334.6.el8.src.rpm Related CVEs: CVE-2024-41090 CVE-2024-41091 CVE-2024-39503 CVE-2024-40916 CVE-2024-38661 CVE-2024-39276 CVE-2024-35976 CVE-2024-36971 CVE-2024-39480 CVE-2024-39301 CVE-2024-39471 CVE-2024-39467 CVE-2024-38583 CVE-2024-36288 CVE-2024-38618 CVE-2024-33621 CVE-2024-36270 CVE-2024-38659 CVE-2024-38780 CVE-2024-36286 CVE-2024-37353 CVE-2024-39488 CVE-2024-37356 CVE-2024-39489 CVE-2024-38621 CVE-2024-39292 CVE-2024-36015 CVE-2024-38627 CVE-2024-38633 CVE-2024-38634 CVE-2024-38635 CVE-2024-38637 CVE-2024-38589 CVE-2024-36014 CVE-2024-38549 CVE-2024-38552 CVE-2024-38612 CVE-2024-38558 CVE-2024-38596 CVE-2024-38613 CVE-2024-38559 CVE-2024-38560 CVE-2024-38565 CVE-2024-38567 CVE-2024-38615 CVE-2024-38598 CVE-2024-38599 CVE-2024-38578 CVE-2024-38579 CVE-2024-38582 CVE-2024-38601 CVE-2024-36016 Description of changes: [5.4.17-2136.334.6.el8] - loop: Fix a race between loop detach and loop open (Gulam Mohamed) [Orabug: 36197800] - x86/bhi: Do not enable unnecessary BHI mitigation in OCI and Exadata VMs (Alexandre Chartre) [Orabug: 36672495] - x86/bhi: Avoid warning in #DB handler due to BHI mitigation (Alexandre Chartre) [Orabug: 36642472] - wifi: wilc1000: fix ies_len type in connect path (Jozef Hopko) - net/mlx5e: drop shorter ethernet frames (Manjunath Patil) [Orabug: 36879157] {CVE-2024-41090} {CVE-2024-41091} [5.4.17-2136.334.5.el8] - Fix incorrect syntax in UEK6 OL8 kernel-uek.spec (Sherry Yang) [Orabug: 36847358] - rds/ib: decrement ib_rx_total_incs after releasing associated cache(Arumugam Kolappan) [Orabug: 36722026] [5.4.17-2136.334.4.el8] - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ (Luiz Augusto von Dentz) - netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type (Jozsef Kadlecsik) - drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found (Marek Szyprowski) [5.4.17-2136.334.3.el8] - rds/rdma: Send info to userspace, even if connnection is down. (Juan Garcia) [Orabug: 36529562] - pci: add hotplug patch support for SOLIDIGM Aura10 AIC 0x025e:0x0b60 (Alan Adamson) [Orabug: 36762919] [5.4.17-2136.334.2.el8] - LTS tag: v5.4.278 (Alok Tiwari) - x86/tsc: Trust initial offset in architectural TSC-adjust MSRs (Daniel J Blueman) - io_uring: fail NOP if non-zero op flags is passed in (Ming Lei) - nfs: fix undefined behavior in nfs_block_bits() (Sergey Shtylyov) - s390/ap: Fix crash in AP internal function modify_bitmap() (Harald Freudenberger) - ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() (Baokun Li) - sparc: move struct termio to asm/termios.h (Mike Gilbert) - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING (Eric Dumazet) - net: fix __dst_negative_advice() race (Eric Dumazet) - kdb: Use format-specifiers rather than memset() for padding in kdb_read() (Daniel Thompson) - kdb: Merge identical case statements in kdb_read() (Daniel Thompson) - kdb: Fix console handling when editing and tab-completing commands (Daniel Thompson) - kdb: Use format-strings rather than '\0' injection in kdb_read() (Daniel Thompson) - kdb: Fix buffer overflow during tab-complete (Daniel Thompson) - sparc64: Fix number of online CPUs (Sam Ravnborg) - intel_th: pci: Add Meteor Lake-S CPU support (Alexander Shishkin) - net/9p: fix uninit-value in p9_client_rpc() (Nikita Zhandarovich) - net/ipv6: Fix route deleting failure when metric equals 0 (xu xin) - crypto: ecrdsa - Fix module auto-load on add_key (Vitaly Chikunov) - KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode (Marc Zyngier) - media:v4l2-core: hold videodev_lock until dev reg, finishes (Hans Verkuil) - media: mxl5xx: Move xpt structures off stack (Nathan Chancellor) - media: mc: mark the media devnode as registered from the, start (Hans Verkuil) - arm64: dts: hi3798cv200: fix the size of GICR (Yang Xiwen) - wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU (Bitterblue Smith) - arm64: tegra: Correct Tegra132 I2C alias (Krzysztof Kozlowski) - ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx (Christoffer Sandberg) - ata: pata_legacy: make legacy_exit() work again (Sergey Shtylyov) - drm/amdgpu: add error handle to avoid out-of-bounds (Bob Zhou) - media: lgdt3306a: Add a check against null-pointer-def (Zheyu Ma) - f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() (Chao Yu) - x86/mm: Remove broken vsyscall emulation code from the page fault code (Linus Torvalds) - nilfs2: fix use-after-free of timer for log writer thread (Ryusuke Konishi) - afs: Don't cross .backup mountpoint from backup volume (Marc Dionne) - mmc: core: Do not force a retune before RPMB switch (Jorge Ramirez-Ortiz) - binder: fix max_thread type inconsistency (Carlos Llamas) - SUNRPC: Fix loop termination condition in gss_free_in_token_pages() (Chuck Lever) - ALSA: timer: Set lower bound of start tick time (Takashi Iwai) - ipvlan: Dont Use skb-> sk in ipvlan_process_v{4,6}_outbound (Yue Haibing) - spi: stm32: Don't warn about spurious interrupts (Uwe Kleine-König) - kconfig: fix comparison to constant symbols, 'm', 'n' (Masahiro Yamada) - netfilter: tproxy: bail out if IP has been disabled on the device (Florian Westphal) - net:fec: Add fec_enet_deinit() (Xiaolei Wang) - net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM (Parthiban Veerasooran) - smsc95xx: use usbnet-> driver_priv (Andre Edich) - smsc95xx: remove redundant function arguments (Andre Edich) - enic: Validate length of nl attributes in enic_set_vf_port (Roded Zats) - dma-buf/sw-sync: don't enable IRQ from sync_print_obj() (Tetsuo Handa) - net/mlx5e: Userx_missed_errors instead of rx_dropped for reporting buffer exhaustion (Carolina Jubran) - nvmet: fix ns enable/disable possible hang (Sagi Grimberg) - spi: Don't mark message DMA mapped when no transfer in it is (Andy Shevchenko) - netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() (Eric Dumazet) - net: fec: avoid lock evasion when reading pps_enable (Wei Fang) - virtio: delete vq in vp_find_vqs_msix() when request_irq() fails (Jiri Pirko) - arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY (Jiangfeng Xiao) - openvswitch: Set the skbuff pkt_type for proper pmtud support. (Aaron Conole) - tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). (Kuniyuki Iwashima) - params: lift param_set_uint_minmax to common code (Sagi Grimberg) - ipv6: sr: fix memleak in seg6_hmac_init_algo (Hangbin Liu) - sunrpc: fix NFSACL RPC retry on soft mount (Dan Aloni) - x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y (Masahiro Yamada) - null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION() (Zhu Yanjun) - media: cec: cec-api: add locking in cec_release() (Hans Verkuil) - media: cec: cec-adap: always cancel work in cec_transmit_msg_fh (Hans Verkuil) - um: Fix the -Wmissing-prototypes warning for __switch_mm (Tiwei Bie) - powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp (Shrikanth Hegde) - scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy() (Azeem Shaikh) - media: stk1160: fix bounds checking in stk1160_copy_video() (Dan Carpenter) - um: Add winch to winch_handlers before registering winch IRQ (Roberto Sassu) - um: Fix return value in ubd_init() (Duoming Zhou) - drm/msm/dpu: Always flush the slave INTF on the CTL (Marijn Suijten) - Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation (Fenglin Wu) - Input: ims-pcu - fix printf string overflow (Arnd Bergmann) - libsubcmd: Fix parse-options memory leak (Ian Rogers) - serial: sh-sci: protect invalidating RXDMA on shutdown (Wolfram Sang) - f2fs: fix to release node block countin error path of f2fs_new_node_page() (Chao Yu) - extcon: max8997: select IRQ_DOMAIN instead of depending on it (Randy Dunlap) - ppdev: Add an error check in register_device (Huai-Yuan Liu) - ppdev: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET) - stm class: Fix a double free in stm_register_device() (Dan Carpenter) - usb: gadget: u_audio: Clear uac pointer when freed. (Chris Wulff) - microblaze: Remove early printk call from cpuinfo-static.c (Michal Simek) - microblaze: Remove gcc flag for non existing early_printk.c file (Michal Simek) - iio: pressure: dps310: support negative temperature values (Thomas Haemmerle) - greybus: arche-ctrl: move device table to its right location (Arnd Bergmann) - serial: max3100: Fix bitwise types (Andy Shevchenko) - serial: max3100: Update uart_driver_registered on driver removal (Andy Shevchenko) - serial: max3100: Lock port-> lock when calling uart_handle_cts_change() (Andy Shevchenko) - firmware: dmi-id: add a release callback function (Arnd Bergmann) - dmaengine: idma64: Add check for dma_set_max_seg_size (Chen Ni) - soundwire: cadence: fix invalid PDI offset (Pierre-Louis Bossart) - soundwire: cadence_master: improve PDI allocation (Bard Liao) - soundwire: intel: don't filter out PDI0/1 (Pierre-Louis Bossart) - soundwire: cadence/intel: simplify PDI/port mapping (Pierre-Louis Bossart) - greybus: lights: check return of get_channel_from_mode (Rui Miguel Silva) - sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level (Vitalii Bursov) - af_packet: do not call packet_read_pending() from tpacket_destruct_skb() (Eric Dumazet) - netrom: fix possible dead-lock in nr_rt_ioctl() (Eric Dumazet) - RDMA/IPoIB: Fix format truncation compilation errors (Leon Romanovsky) - selftests/kcmp: remove unused open mode (Edward Liaw) - selftests/kcmp: Make the test output consistent and clear (Gautam Menghani) - SUNRPC: Fix gss_free_in_token_pages() (Chuck Lever) - sunrpc: removed redundant procp check (Aleksandr Aprelkov) - ext4: avoid excessivecredit estimate in ext4_tmpfile() (Jan Kara) - x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map (Adrian Hunter) - RDMA/hns: Use complete parentheses in macros (Chengchang Tang) - drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector (Marek Vasut) - ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value (Steven Rostedt) - drm/arm/malidp: fix a possible null pointer dereference (Huai-Yuan Liu) - fbdev: sh7760fb: allow modular build (Randy Dunlap) - platform/x86: wmi: Make two functions static (YueHaibing) - media: radio-shark2: Avoid led_names truncations (Ricardo Ribalda) - media: ngene: Add dvb_ca_en50221_init return value check (Aleksandr Burakov) - fbdev: sisfb: hide unused variables (Arnd Bergmann) - powerpc/fsl-soc: hide unused const variable (Arnd Bergmann) - drm/mediatek: Add 0 size check to mtk_drm_gem_obj (Justin Green) - fbdev: shmobile: fix snprintf truncation (Arnd Bergmann) - mtd: rawnand: hynix: fixed typo (Maxim Korotkov) - drm/amd/display: Fix potential index out of bounds in color transformation function (Srinivasan Shanmugam) - ipv6: sr: fix invalid unregister error path (Hangbin Liu) - ipv6: sr: add missing seg6_local_exit (Hangbin Liu) - net: openvswitch: fix overwriting ct original tuple for ICMPv6 (Ilya Maximets) - net: usb: smsc95xx: stop lying about skb-> truesize (Eric Dumazet) - af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg (Breno Leitao) - net: ethernet: cortina: Locking fixes (Linus Walleij) - m68k: mac: Fix reboot hang on Mac IIci (Finn Thain) - m68k: Fix spinlock race in kernel thread creation (Michael Schmitz) - net: usb: sr9700: stop lying about skb-> truesize (Eric Dumazet) - usb: aqc111: stop lying about skb-> truesize (Eric Dumazet) - wifi: mwl8k: initialize cmd-> addr[] properly (Dan Carpenter) - scsi: qedf: Ensure the copied buf is NUL terminated (Bui Quang Minh) - scsi: bfa: Ensure the copied buf is NUL terminated (Bui Quang Minh) - HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors (Chen Ni) - Revert "sh:Handle calling csum_partial with misaligned data" (Guenter Roeck) - sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe() (Geert Uytterhoeven) - wifi: ar5523: enable proper endpoint verification (Nikita Zhandarovich) - wifi: carl9170: add a proper sanity check for endpoints (Nikita Zhandarovich) - macintosh/via-macii: Fix "BUG: sleeping function called from invalid context" (Finn Thain) - tcp: avoid premature drops in tcp_add_backlog() (Eric Dumazet) - tcp: fix a signed-integer-overflow bug in tcp_add_backlog() (Lu Wei) - tcp: minor optimization in tcp_add_backlog() (Eric Dumazet) - wifi: ath10k: populate board data for WCN3990 (Dmitry Baryshkov) - wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger() (Su Hui) - x86/purgatory: Switch to the position-independent small code model (Ard Biesheuvel) - scsi: hpsa: Fix allocation size for Scsi_Host private data (Yuri Karpov) - scsi: libsas: Fix the failure of adding phy with zero-address to port (Xingui Yang) - cpufreq: exit() callback is optional (Viresh Kumar) - cpufreq: Rearrange locking in cpufreq_remove_dev() (Rafael J. Wysocki) - cpufreq: Split cpufreq_offline() (Rafael J. Wysocki) - cpufreq: Reorganize checks in cpufreq_offline() (Rafael J. Wysocki) - ACPI: disable -Wstringop-truncation (Arnd Bergmann) - irqchip/alpine-msi: Fix off-by-one in allocation error path (Zenghui Yu) - scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL (Andrew Halaney) - scsi: ufs: core: Perform read back after disabling interrupts (Andrew Halaney) - scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV (Andrew Halaney) - scsi: ufs: qcom: Perform read back after writing reset bit (Andrew Halaney) - qed: avoid truncating work queue length (Arnd Bergmann) - wifi: ath10k: poll service ready message before failing (Baochen Qiang) - md: fix resync softlockup when bitmap size is less than array size (Yu Kuai) - null_blk: Fix missing mutex_destroy() at module removal (Zhu Yanjun) - jffs2: prevent xattr node from overflowingthe eraseblock (Ilya Denisyev) - s390/cio: fix tracepoint subchannel type field (Peter Oberparleiter) - crypto: ccp - drop platform ifdef checks (Arnd Bergmann) - parisc: add missing export of __cmpxchg_u8() (Al Viro) - nilfs2: fix out-of-range warning (Arnd Bergmann) - ecryptfs: Fix buffer size for tag 66 packet (Brian Kubisiak) - firmware: raspberrypi: Use correct device for DMA mappings (Laurent Pinchart) - crypto: bcm - Fix pointer arithmetic (Aleksandr Mishin) - openpromfs: finish conversion to the new mount API (Eric Sandeen) - nvme: find numa distance only if controller has valid numa id (Nilay Shroff) - drm/amdkfd: Flush the process wq before creating a kfd_process (Lancelot SIX) - ASoC: da7219-aad: fix usage of device_get_named_child_node() (Pierre-Louis Bossart) - ASoC: dt-bindings: rt5645: add cbj sleeve gpio property (Derek Fang) - ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating (Derek Fang) - drm/amd/display: Set color_mgmt_changed to true on unsuspend (Joshua Ashton) - net: usb: qmi_wwan: add Telit FN920C04 compositions (Daniele Palmas) - wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class (Igor Artemiev) - nilfs2: fix potential hang in nilfs_detach_log_writer() (Ryusuke Konishi) - nilfs2: fix unexpected freezing of nilfs_segctor_sync() (Ryusuke Konishi) - net: smc91x: Fix m68k kernel compilation for ColdFire CPU (Thorsten Blum) - ring-buffer: Fix a race between readers and resize checks (Petr Pavlu) - tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (Daniel Starke) [5.4.17-2136.334.1.el8] - rds/rdma: Track rds_message in send, retrans and recv queue (Juan Garcia) [Orabug: 36529583] - xfs: make sure sb_fdblocks is non-negative (Wengang Wang) [Orabug: 36596998] - xfs: fix sb write verify for lazysbcount (Long Li) [Orabug: 36596998] - rds/rdma: Clear rds_info_socket before use (Juan Garcia) [Orabug: 36613125] _______________________________________________ El-errata mailinglist
Get the latest Linux and open source security news straight to your inbox.