Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20270 http://linux.oracle.com/errata/ELSA-2025-20270.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-core-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-debug-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-debug-core-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-debug-devel-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-debug-modules-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-debug-modules-extra-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-devel-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-doc-5.15.0-307.178.5.el8uek.noarch.rpm kernel-uek-modules-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-modules-extra-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-container-5.15.0-307.178.5.el8uek.x86_64.rpm kernel-uek-container-debug-5.15.0-307.178.5.el8uek.x86_64.rpm aarch64: bpftool-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-core-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-debug-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-debug-core-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-devel-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-doc-5.15.0-307.178.5.el8uek.noarch.rpm kernel-uek-modules-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-container-5.15.0-307.178.5.el8uek.aarch64.rpm kernel-uek-container-debug-5.15.0-307.178.5.el8uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//kernel-uek-5.15.0-307.178.5.el8uek.src.rpm RelatedCVEs: CVE-2024-35972 CVE-2024-40919 CVE-2024-41079 CVE-2024-44984 CVE-2024-46842 CVE-2024-50155 CVE-2024-50215 CVE-2024-53209 CVE-2024-53213 CVE-2024-56656 CVE-2024-56660 CVE-2024-56760 Description of changes: [5.15.0-307.178.5.el8uek] - net/mlx5: DR, prevent potential error pointer dereference (Dan Carpenter) [Orabug: 37434242] {CVE-2024-56660} - uek-rpm: Set CONFIG_IP6_NF_IPTABLES for ol9/ol8 container kernels (Jonah Palmer) [Orabug: 37703179] - net: hsr: fix fill_frame_info() regression vs VLAN packets (Eric Dumazet) - f2fs: Introduce linear search for dentries (Daniel Lee) - tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for server bind (Marco Leogrande) - net: loopback: Avoid sending IP packets without an Ethernet header (Ido Schimmel) - x86/static-call: Remove early_boot_irqs_disabled check to fix Xen PVH dom0 (Andrew Cooper) - sched: sch_cake: add bounds checks to host bulk flow fairness counts (Toke Høiland-Jørgensen) - usb: atm: cxacru: fix a flaw in existing endpoint checks (Nikita Zhandarovich) - x86/xen: fix xen_hypercall_hvm() to not clobber %rbx (Juergen Gross) - x86/xen: add FRAME_END to xen_hypercall_hvm() (Juergen Gross) - ocfs2: fix incorrect CPU endianness conversion causing mount failure (Heming Zhao) - usb: dwc3: Set SUSPENDENABLE soon after phy init (Thinh Nguyen) - Revert "btrfs: avoid monopolizing a core when activating a swap file" (Koichiro Den) - Revert "media: uvcvideo: Require entities to have a non-zero unique ID" (Thadeu Lima de Souza Cascardo) - netem: Update sch-> q.qlen before qdisc_tree_reduce_backlog() (Cong Wang) [5.15.0-307.178.4.el8uek] - LTS version: v5.15.178 (Vijayendra Suman) - Input: xpad - add support for wooting two he (arm) (Jack Greiner) - Input: xpad - add unofficial Xbox 360 wireless receiver clone (Nilton Perim Neto) - Input: atkbd - map F23 key to support default copilot shortcut (Mark Pearson) - ALSA: usb-audio: Add delay quirk for USB Audio Device (Lianqin Hu) - USB: serial: quatech2: fix null-ptr-deref inqt2_process_read_urb() (Qasim Ijaz) - wifi: iwlwifi: add a few rate index validity checks (Anjaneyulu) - scsi: storvsc: Ratelimit warning logs to prevent VM denial of service (Easwar Hariharan) - ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find() (Ido Schimmel) - platform/chrome: cros_ec_typec: Check for EC driver (Akihiko Odaki) - fs/ntfs3: Additional check in ntfs_file_release (Konstantin Komarov) - Bluetooth: RFCOMM: Fix not validating setsockopt user input (Luiz Augusto von Dentz) - Bluetooth: SCO: Fix not validating setsockopt user input (Luiz Augusto von Dentz) - vfio/platform: check the bounds of read/write syscalls (Alex Williamson) - net: sched: fix ets qdisc OOB Indexing (Jamal Hadi Salim) - gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag (Andreas Gruenbacher) - mptcp: don't always assume copied data in mptcp_cleanup_rbuf() (Paolo Abeni) - regmap: detach regmap from dev on regmap_exit (Cosmin Tanislav) - ASoC: samsung: Add missing depends on I2C (Charles Keepax) - irqchip/sunxi-nmi: Add missing SKIP_WAKE flag (Philippe Simons) - scsi: iscsi: Fix redundant response for ISCSI_UEVENT_GET_HOST_STATS request (Xiang Zhang) - seccomp: Stub for !CONFIG_SECCOMP (Linus Walleij) - ASoC: samsung: Add missing selects for MFD_WM8994 (Charles Keepax) - ASoC: wm8994: Add depends on MFD core (Charles Keepax) [5.15.0-307.177.3.el8uek] - jbd2: increase maximum transaction size (Jan Kara) [Orabug: 37688920] - net/mlx5e: Avoid WARN_ON when configuring MQPRIO with HTB offload enabled (Carolina Jubran) [Orabug: 37534698] - net/mlx5e: Always start IPsec sequence number from 1 (Leon Romanovsky) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: Add support for clock_measure performance block (Shravan Kumar Ramani) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: Add support for monitoring cycle count (Shravan Kumar Ramani) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: incorrect type in assignment (Pei Xiao) [Orabug: 37534698] - net/mlx5e: Disable loopback self-test on multi-PFnetdev (Carolina Jubran) [Orabug: 37534698] - net/mlx5: Unregister notifier on eswitch init failure (Cosmin Ratiu) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: Prevent stale command interrupt handling (Michal Wilczynski) [Orabug: 37534698] - net/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice (Jianbo Liu) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: fix lockdep warning (Luiz Capitulino) [Orabug: 37534698] - net/mlx5: Fix bridge mode operations when there are no VFs (Benjamin Poirier) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: Add hw_reset() support for BlueField-3 SoC (Liming Sun) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: add dwcmshc_pltfm_data (Chen Wang) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: factor out code into dwcmshc_rk35xx_init (Chen Wang) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: factor out code for th1520_init() (Chen Wang) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: move two rk35xx functions (Chen Wang) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: add common bulk optional clocks support (Chen Wang) [Orabug: 37534698] - net/mlx5e: Take state lock during tx timeout reporter (Dragos Tatulea) [Orabug: 37534698] - net/mlx5: SD, Do not query MPIR register if no sd_group (Tariq Toukan) [Orabug: 37534698] - net/mlx5: Always drain health in shutdown callback (Shay Drory) [Orabug: 37534698] - mmc: dw_mmc-bluefield: Add support for eMMC HW reset (Liming Sun) [Orabug: 37534698] - mmc: dw_mmc: Add support for platform specific eMMC HW reset (Liming Sun) [Orabug: 37534698] - net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink (Dragos Tatulea) [Orabug: 37534698] - net/mlx5e: SHAMPO, Fix incorrect page release (Dragos Tatulea) [Orabug: 37534698] - net/mlx5: Do not query MPIR on embedded CPU function (Tariq Toukan) [Orabug: 37534698] - net/mlx5: Reload only IB representors upon lag disable/enable (Maher Sanalla) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: Add tuning support for Sophgo CV1800B and SG200X (Jisheng Zhang) [Orabug: 37534698] - macsec: Detect if Rx skb ismacsec-related for offloading devices that update md_dst (Rahul Rameshbabu) [Orabug: 37534698] - macsec: Enable devices to advertise whether they update sk_buff md_dst during offloads (Rahul Rameshbabu) [Orabug: 37534698] - net/mlx5e: Prevent deadlock while disabling aRFS (Carolina Jubran) [Orabug: 37534698] - net/mlx5e: Use channel mdev reference instead of global mdev instance for coalescing (Rahul Rameshbabu) [Orabug: 37534698] - net/mlx5: SD, Handle possible devcom ERR_PTR (Tariq Toukan) [Orabug: 37534698] - net/mlx5: Disallow SRIOV switchdev mode when in multi-PF netdev (Tariq Toukan) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: Implement SDHCI CQE support (Sergey Khimich) [Orabug: 37534698] - mmc: cqhci: Add cqhci set_tran_desc() callback (Sergey Khimich) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: fix signedness bugs (Dan Carpenter) [Orabug: 37534698] - net/mlx5e: Create EN core HW resources for all secondary devices (Tariq Toukan) [Orabug: 37534698] - net/mlx5e: Create single netdev per SD group (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Add debugfs (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Add informative prints in kernel log (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Implement steering for primary and secondaries (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Implement devcom communication and primary election (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Implement basic query and instantiation (Tariq Toukan) [Orabug: 37534698] - net/mlx5: SD, Introduce SD lib (Tariq Toukan) [Orabug: 37534698] - net/mlx5: Add MPIR bit in mcam_access_reg (Tariq Toukan) [Orabug: 37534698] - lib: memcpy_kunit: Fix an invalid format specifier in an assertion msg (David Gow) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: Ignore unsupported performance blocks (Luiz Capitulino) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: mlxbf_pmc_event_list(): make size ptr optional (Luiz Capitulino) [Orabug: 37534698] - mmc: sdhci-of-dwcmshc: Add support for Sophgo CV1800Band SG2002 (Jisheng Zhang) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: Cleanup signed/unsigned mix-up (Shravan Kumar Ramani) [Orabug: 37534698] - platform/mellanox: mlxbf-pmc: Replace uintN_t with kernel-style types (Shravan Kumar Ramani) [Orabug: 37534698] - net: macsec: revert the MAC address if mdo_upd_secy fails (Radu Pirea (NXP OSS)) [Orabug: 37534698] - net: macsec: documentation for macsec_context and macsec_ops (Radu Pirea (NXP OSS)) [Orabug: 37534698] - fortify: Do not cast to "unsigned char" (Kees Cook) [Orabug: 37534698] - fortify: Use SIZE_MAX instead of (size_t)-1 (Kees Cook) [Orabug: 37534698] - fortify: Fix __compiletime_strlen() under UBSAN_BOUNDS_LOCAL (Kees Cook) [Orabug: 37534698] - mmc: dw_mmc: Add driver callbacks for data read timeout (Mårten Lindahl) [Orabug: 37534698] - mmc: dw_mmc-exynos: Add support for ARTPEC-8 (Mårten Lindahl) [Orabug: 37534698] - mmc: dw_mmc: clean up a debug message (Dan Carpenter) [Orabug: 37534698] - mmc: dw_mmc: exynos: use common_caps (John Keeping) [Orabug: 37534698] - mmc: dw_mmc: add common capabilities to replace caps (John Keeping) [Orabug: 37534698] - mmc: dw_mmc: Allow lower TMOUT value than maximum (Mårten Lindahl) [Orabug: 37534698] - rds: Make sure transmit path and connection tear-down does not run concurrently (Håkon Bugge) [Orabug: 36441944] - ice: always add legacy 32byte RXDID in supported_rxdids (Michal Schmidt) [Orabug: 36252756] - ice: virtchnl rss hena support (Md Fahad Iqbal Polash) [Orabug: 36252756] - ice: Add support Flex RXD (Michal Jaron) [Orabug: 36252756] [5.15.0-307.177.2.el8uek] - uek-rpm: Enable CONFIG_MICROSOFT_MANA as module in aarch64 (Vijayendra Suman) [Orabug: 37647393] - rtc: add new RTC_FEATURE_ALARM_WAKEUP_ONLY feature (Alexandre Belloni) [Orabug: 37631796] - thermal: core: Drop excessive lockdep_assert_held() calls (Rafael J. Wysocki) [Orabug: 37631796] - thermal: core: Introduce thermal_cooling_device_update() (Rafael J. Wysocki) [Orabug: 37631796] - thermal: core: Introducethermal_cooling_device_present() (Rafael J. Wysocki) [Orabug: 37631796] - thermal: sysfs: Reuse cdev-> max_state (Viresh Kumar) [Orabug: 37631796] - rtc: efi: Enable SET/GET WAKEUP services as optional (Shanker Donthineni) [Orabug: 37631796] - rtc: efi: Add wakeup support (Riwen Lu) [Orabug: 37631796] - rtc: efi: switch to RTC_FEATURE_UPDATE_INTERRUPT (Alexandre Belloni) [Orabug: 37631796] - rtc: add BSM parameter (Alexandre Belloni) [Orabug: 37631796] - rtc: add correction parameter (Alexandre Belloni) [Orabug: 37631796] - rtc: add parameter ioctl (Alexandre Belloni) [Orabug: 37631796] - rtc: expose correction feature (Alexandre Belloni) [Orabug: 37631796] - rtc: add alarm related features (Alexandre Belloni) [Orabug: 37631796] - rtc: efi: switch to devm_rtc_allocate_device (Alexandre Belloni) [Orabug: 37631796] - cgroup: Make operations on the cgroup root_list RCU safe (Yafang Shao) [Orabug: 37621589] - rds: ib: Avoid sleeping function inside RCU region by using sampled values instead (Håkon Bugge) [Orabug: 37586089] - bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips (Michael Chan) [Orabug: 37434220] {CVE-2024-56656} - bnxt_en: Fix receive ring space parameters when XDP is active (Shravya KN) [Orabug: 37433562] {CVE-2024-53209} - bnxt_en: Adjust logging of firmware messages in case of released token in __hwrm_send() (Aleksandr Mishin) [Orabug: 37070333] {CVE-2024-40919} - bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() (Vikas Gupta) [Orabug: 37070270] {CVE-2024-35972} - bnxt_en: Fix double DMA unmapping for XDP_REDIRECT (Somnath Kotur) [Orabug: 37070266] {CVE-2024-44984} [5.15.0-307.177.1.el8uek] - nvmet: always initialize cqe.result (Daniel Wagner) [Orabug: 36897348] {CVE-2024-41079} - nvmet-auth: complete a request only after freeing the dhchap pointers (Maurizio Lombardi) [Orabug: 36897348] {CVE-2024-41079} - scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info (Justin Tee) [Orabug: 37116505] {CVE-2024-46842} - netdevsim: use cond_resched() innsim_dev_trap_report_work() (Eric Dumazet) [Orabug: 37264120] {CVE-2024-50155} - nvmet-auth: assign dh_key to NULL after kfree_sensitive (Vitaliy Shevtsov) [Orabug: 37268555] {CVE-2024-50215} - net: usb: lan78xx: Fix double free issue with interrupt buffer allocation (Oleksij Rempel) [Orabug: 37433573] {CVE-2024-53213} - PCI/MSI: Handle lack of irqdomain gracefully (Thomas Gleixner) [Orabug: 37452651] {CVE-2024-56760} - selftests: rtnetlink: update netdevsim ipsec output format (Hangbin Liu) [Orabug: 37547931] - netdevsim: print human readable IP address (Hangbin Liu) [Orabug: 37547931] - uek: kabi: Fix build error for HIDE_INCLUDE macro (Saeed Mirzamohammadi) [Orabug: 37619141] - Add __init annotation to pensando_efi_mem_reserve (Joseph Dobosenski) [Orabug: 37619785] _______________________________________________ El-errata mailing list
The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes. The following security bugs were fixed:. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2023:4882-1 Rating: important References: * bsc#1084909 * bsc#1208787 * bsc#1210780 * bsc#1216058 * bsc#1216259 * bsc#1216584 * bsc#1216965 * bsc#1216976 * jsc#PED-3184 * jsc#PED-5021 Cross-References: * CVE-2023-0461 * CVE-2023-31083 * CVE-2023-39197 * CVE-2023-39198 * CVE-2023-45863 * CVE-2023-45871 * CVE-2023-5717 CVSS scores: * CVE-2023-0461 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-0461 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-31083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-31083 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39197 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2023-39198 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-39198 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45863 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45871 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45871 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5717 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5717 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE CaaS Platform 4.0 * SUSE Linux Enterprise High Availability Extension 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Live Patching 15-SP1 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Serverfor SAP Applications 15 SP1 * SUSE Manager Proxy 4.0 * SUSE Manager Retail Branch Server 4.0 * SUSE Manager Server 4.0 An update that solves seven vulnerabilities, contains two features and has one security fix can now be installed. ## Description: The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208787). * CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976). * CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058). * CVE-2023-5717: Fixed a heap out-of-bounds write vulnerability in the Performance Events component (bsc#1216584). * CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may not be adequate for frames larger than the MTU (bsc#1216259). * CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965). * CVE-2023-31083: Fixed race condition in hci_uart_tty_ioctl (bsc#1210780). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4882=1 * SUSE Linux Enterprise Live Patching 15-SP1 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2023-4882=1 * SUSE Linux Enterprise High Availability Extension 15 SP1 zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2023-4882=1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4882=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4882=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP1-2023-4882=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. ## Package List: * openSUSE Leap 15.4 (nosrc) * kernel-default-4.12.14-150100.197.165.1 * kernel-kvmsmall-4.12.14-150100.197.165.1 * kernel-debug-4.12.14-150100.197.165.1 * kernel-zfcpdump-4.12.14-150100.197.165.1 * openSUSE Leap 15.4 (ppc64le x86_64) * kernel-debug-base-4.12.14-150100.197.165.1 * kernel-debug-base-debuginfo-4.12.14-150100.197.165.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * kernel-default-base-debuginfo-4.12.14-150100.197.165.1 * openSUSE Leap 15.4 (x86_64) * kernel-kvmsmall-base-debuginfo-4.12.14-150100.197.165.1 * kernel-kvmsmall-base-4.12.14-150100.197.165.1 * openSUSE Leap 15.4 (s390x) * kernel-default-man-4.12.14-150100.197.165.1 * kernel-zfcpdump-man-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Live Patching 15-SP1 (nosrc) * kernel-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Live Patching 15-SP1 (ppc64le x86_64) * kernel-livepatch-4_12_14-150100_197_165-default-1-150100.3.5.1 * kernel-default-debugsource-4.12.14-150100.197.165.1 * kernel-default-livepatch-4.12.14-150100.197.165.1 * kernel-default-debuginfo-4.12.14-150100.197.165.1 * kernel-default-livepatch-devel-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Availability Extension 15 SP1 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-4.12.14-150100.197.165.1 * ocfs2-kmp-default-4.12.14-150100.197.165.1 * dlm-kmp-default-4.12.14-150100.197.165.1 * kernel-default-debuginfo-4.12.14-150100.197.165.1 * ocfs2-kmp-default-debuginfo-4.12.14-150100.197.165.1 * gfs2-kmp-default-debuginfo-4.12.14-150100.197.165.1 * cluster-md-kmp-default-4.12.14-150100.197.165.1 * cluster-md-kmp-default-debuginfo-4.12.14-150100.197.165.1 * dlm-kmp-default-debuginfo-4.12.14-150100.197.165.1 *gfs2-kmp-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Availability Extension 15 SP1 (nosrc) * kernel-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 nosrc x86_64) * kernel-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * kernel-default-base-debuginfo-4.12.14-150100.197.165.1 * kernel-default-devel-4.12.14-150100.197.165.1 * kernel-default-debugsource-4.12.14-150100.197.165.1 * kernel-default-devel-debuginfo-4.12.14-150100.197.165.1 * kernel-default-debuginfo-4.12.14-150100.197.165.1 * kernel-obs-build-4.12.14-150100.197.165.1 * kernel-obs-build-debugsource-4.12.14-150100.197.165.1 * kernel-syms-4.12.14-150100.197.165.1 * kernel-default-base-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch) * kernel-devel-4.12.14-150100.197.165.1 * kernel-source-4.12.14-150100.197.165.1 * kernel-macros-4.12.14-150100.197.165.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch nosrc) * kernel-docs-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64 nosrc) * kernel-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * kernel-default-base-debuginfo-4.12.14-150100.197.165.1 * kernel-default-devel-4.12.14-150100.197.165.1 * kernel-default-debugsource-4.12.14-150100.197.165.1 * kernel-default-devel-debuginfo-4.12.14-150100.197.165.1 * reiserfs-kmp-default-4.12.14-150100.197.165.1 * kernel-default-debuginfo-4.12.14-150100.197.165.1 * kernel-obs-build-4.12.14-150100.197.165.1 * kernel-obs-build-debugsource-4.12.14-150100.197.165.1 * reiserfs-kmp-default-debuginfo-4.12.14-150100.197.165.1 * kernel-syms-4.12.14-150100.197.165.1 * kernel-default-base-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch) *kernel-devel-4.12.14-150100.197.165.1 * kernel-source-4.12.14-150100.197.165.1 * kernel-macros-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch nosrc) * kernel-docs-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (s390x) * kernel-zfcpdump-debugsource-4.12.14-150100.197.165.1 * kernel-zfcpdump-debuginfo-4.12.14-150100.197.165.1 * kernel-default-man-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (nosrc) * kernel-zfcpdump-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (nosrc ppc64le x86_64) * kernel-default-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * kernel-default-base-debuginfo-4.12.14-150100.197.165.1 * kernel-default-devel-4.12.14-150100.197.165.1 * kernel-default-debugsource-4.12.14-150100.197.165.1 * kernel-default-devel-debuginfo-4.12.14-150100.197.165.1 * reiserfs-kmp-default-4.12.14-150100.197.165.1 * kernel-default-debuginfo-4.12.14-150100.197.165.1 * kernel-obs-build-4.12.14-150100.197.165.1 * kernel-obs-build-debugsource-4.12.14-150100.197.165.1 * reiserfs-kmp-default-debuginfo-4.12.14-150100.197.165.1 * kernel-syms-4.12.14-150100.197.165.1 * kernel-default-base-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch) * kernel-devel-4.12.14-150100.197.165.1 * kernel-source-4.12.14-150100.197.165.1 * kernel-macros-4.12.14-150100.197.165.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch nosrc) * kernel-docs-4.12.14-150100.197.165.1 * SUSE CaaS Platform 4.0 (nosrc x86_64) * kernel-default-4.12.14-150100.197.165.1 * SUSE CaaS Platform 4.0 (x86_64) * kernel-default-base-debuginfo-4.12.14-150100.197.165.1 * kernel-default-devel-4.12.14-150100.197.165.1 * kernel-default-debugsource-4.12.14-150100.197.165.1 * kernel-default-devel-debuginfo-4.12.14-150100.197.165.1 * reiserfs-kmp-default-4.12.14-150100.197.165.1 *kernel-default-debuginfo-4.12.14-150100.197.165.1 * kernel-obs-build-4.12.14-150100.197.165.1 * kernel-obs-build-debugsource-4.12.14-150100.197.165.1 * reiserfs-kmp-default-debuginfo-4.12.14-150100.197.165.1 * kernel-syms-4.12.14-150100.197.165.1 * kernel-default-base-4.12.14-150100.197.165.1 * SUSE CaaS Platform 4.0 (noarch) * kernel-devel-4.12.14-150100.197.165.1 * kernel-source-4.12.14-150100.197.165.1 * kernel-macros-4.12.14-150100.197.165.1 * SUSE CaaS Platform 4.0 (noarch nosrc) * kernel-docs-4.12.14-150100.197.165.1 ## References: * https://www.suse.com/security/cve/CVE-2023-0461.html * https://www.suse.com/security/cve/CVE-2023-31083.html * https://www.suse.com/security/cve/CVE-2023-39197.html * https://www.suse.com/security/cve/CVE-2023-39198.html * https://www.suse.com/security/cve/CVE-2023-45863.html * https://www.suse.com/security/cve/CVE-2023-45871.html * https://www.suse.com/security/cve/CVE-2023-5717.html * https://bugzilla.suse.com/show_bug.cgi?id=1084909 * https://bugzilla.suse.com/show_bug.cgi?id=1208787 * https://bugzilla.suse.com/show_bug.cgi?id=1210780 * https://bugzilla.suse.com/show_bug.cgi?id=1216058 * https://bugzilla.suse.com/show_bug.cgi?id=1216259 * https://bugzilla.suse.com/show_bug.cgi?id=1216584 * https://bugzilla.suse.com/show_bug.cgi?id=1216965 * https://bugzilla.suse.com/show_bug.cgi?id=1216976 * * . Critical patch rolled out for openSUSE kernel, tackling various vulnerabilities and enhancing overall stability for improved efficiency.. Kernel Update, Security Issues, SUSE Linux, System Security. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6261-1 July 28, 2023 linux-iot vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-iot: Linux kernel for IoT platforms Details: It was discovered that the IP-VLAN network driver for the Linux kernel did not properly initialize memory in some situations, leading to an out-of- bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3090) Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-32629) It was discovered that the netfilter subsystem in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3390) Tanguy Dubroca discovered that the netfilter subsystem in the Linux kernel did not properly handle certain pointer data type, leading to an out-of- bounds write vulnerability. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35001) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1018-iot 5.4.0-1018.19 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI changethe kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6261-1 CVE-2023-3090, CVE-2023-32629, CVE-2023-3390, CVE-2023-35001 Package Information: https://launchpad.net/ubuntu/+source/linux-iot/5.4.0-1018.19 . Tackling essential security flaws in Linux IoT systems with guidelines for Ubuntu 20.04 LTS users. Safeguard your gadgets today.. Linux Kernel Security, IoT Threat Mitigation, Ubuntu Update Guide. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12018 https://linux.oracle.com/errata/ELSA-2023-12018.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-container-5.15.0-6.80.3.1.el8.x86_64.rpm kernel-uek-container-debug-5.15.0-6.80.3.1.el8.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-uek-container-5.15.0-6.80.3.1.el8.src.rpm Related CVEs: CVE-2022-4378 CVE-2022-42895 CVE-2022-42896 Description of changes: [5.15.0-6.80.3.1.el8] - Revert "rds: ib: Enable FC by default" (HÃ¥kon Bugge) [Orabug: 34964359] [5.15.0-6.80.3.el8] - net/mlx5: Suppress error logging on UCTX creation (Marina) [Orabug: 34888471] - rds: ib: Fix leaked MRs during kexec (HÃ¥kon Bugge) [Orabug: 34892082] - uek-rpm: Add ptp_kvm.ko to core rpm (Somasundaram Krishnasamy) [Orabug: 34901414] - Revert "tracing/ring-buffer: Have polling block on watermark" (Harshit Mogalapalli) [Orabug: 34890999] [5.15.0-6.80.2.el8] - scsi: mpi3mr: Remove unnecessary cast (Jules Irenge) [Orabug: 34640445] - scsi: mpi3mr: Update driver version to 8.2.0.3.0 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix scheduling while atomic type bug (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Scan the devices during resume time (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Free enclosure objects during driver unload (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Handle 0xF003 Fault Code (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Graceful handling of surprise removal of PCIe HBA (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Schedule IRQ kthreads only on non-RT kernels (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Support new power management framework (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update mpi3 header files (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix error code inmpi3mr_transport_smp_handler() (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Fix error codes in mpi3mr_report_manufacture() (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Block I/Os while refreshing target dev objects (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Refresh SAS ports during soft reset (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Support SAS transport class callbacks (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add framework to issue MPT transport cmds (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add SAS SATA end devices to STL (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Get target object based on rphy (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add expander devices to STL (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Enable STL on HBAs where multipath is disabled (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add helper functions to manage device's port (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add helper functions to retrieve device objects (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add framework to add phys to STL (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Enable Enclosure device add event (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add helper functions to retrieve config pages (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add framework to issue config requests (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add config and transport related debug flags (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Delete a stray tab (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Unlock on error path (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Reduce VD queue depth on detecting throttling (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Resource Based Metering (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Increase cmd_per_lun to 128 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Enable shared host tagset(Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix kernel-doc (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Rework mrioc-> bsg_device model to fix warnings (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Add target device related sysfs (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add shost related sysfs attributes (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Return error if dma_alloc_coherent() fails (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Fix a NULL vs IS_ERR() bug in mpi3mr_bsg_init() (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Return I/Os to an unrecoverable HBA with DID_ERROR (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Hidden drives not removed during soft reset (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Increase I/O timeout value to 60s (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update driver version to 8.0.0.69.0 (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Add support for NVMe passthrough (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Expose adapter state to sysfs (Chandrakanth patil) [Orabug: 34640445] - scsi: mpi3mr: Add support for PEL commands (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Add support for MPT commands (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Move data structures/definitions from MPI headers to uapi header (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Add support for driver commands (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Add bsg device support (Sumit Saxena) [Orabug: 34640445] - scsi: mpi3mr: Fix flushing !WQ_MEM_RECLAIM events warning (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Bump driver version to 8.0.0.68.0 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update the copyright year (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix cmnd getting marked as in use forever (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix hibernation issue (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update MPI3 headers(Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix printing of pending I/O count (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix deadlock while canceling the fw event (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fix formatting problems in some kernel-doc comments (Yang Li) [Orabug: 34640445] - scsi: mpi3mr: Fix some spelling mistakes (Colin Ian King) [Orabug: 34640445] - scsi: mpi3mr: Bump driver version to 8.0.0.61.0 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Enhanced Task Management Support Reply handling (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Use TM response codes from MPI3 headers (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add io_uring interface support in I/O-polled mode (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Print cable mngnt and temp threshold events (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Support Prepare for Reset event (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add Event acknowledgment logic (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Gracefully handle online FW update operation (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Detect async reset that occurred in firmware (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add IOC reinit function (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Handle offline FW activation in graceful manner (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Code refactor of IOC init - part2 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Code refactor of IOC init - part1 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Fault IOC when internal command gets timeout (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Display IOC firmware package version (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Handle unaligned PLL in unmap cmnds (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Increase internal cmnds timeout to 60s (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Do access status validation before addingdevices (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add support for PCIe Managed Switch SES device (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update MPI3 headers - part2 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Update MPI3 headers - part1 (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Don't reset IOC if cmnds flush with reset status (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Replace spin_lock() with spin_lock_irqsave() (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Add debug APIs based on logging_level bits (Sreekanth Reddy) [Orabug: 34640445] - scsi: mpi3mr: Use scnprintf() instead of snprintf() (Dan Carpenter) [Orabug: 34640445] - scsi: mpi3mr: Clean up mpi3mr_print_ioc_info() (Dan Carpenter) [Orabug: 34640445] - rds: ib: Remove unnecessary call to rds_ib_ring_unalloc (HÃ¥kon Bugge) [Orabug: 34768825] - rds: ib: Remove unnecessary i_flowctl term from conditions (HÃ¥kon Bugge) [Orabug: 34768825] - rds: ib: Remove unnesesarry variable initialization (HÃ¥kon Bugge) [Orabug: 34768825] - rds: ib: Make sure receives are posted before connection is up (HÃ¥kon Bugge) [Orabug: 34768825] - rds: ib: Fix the Retry counter dependency on RNR NAK Retry counter (HÃ¥kon Bugge) [Orabug: 34768825] - rds: Deduct one credit on the passive side (HÃ¥kon Bugge) [Orabug: 34768825] - rds: Use all eight bits for credit updates (HÃ¥kon Bugge) [Orabug: 34768825] - RDS/IB: Fix the misplaced counter update rdma dto path (Devesh Sharma) [Orabug: 34865847] - uek-rpm: Enable CONFIG_HP_ILO for aarch64 (Saeed Mirzamohammadi) [Orabug: 34869880] - uek-rpm: ol8: Choose right annobin plugin for UEK build (Somasundaram Krishnasamy) [Orabug: 34873882] - proc: proc_skip_spaces() shouldn't think it is working on C strings (Linus Torvalds) [Orabug: 34882775] {CVE-2022-4378} - proc: avoid integer type confusion in get_proc_long (Linus Torvalds) [Orabug: 34882775] {CVE-2022-4378} [5.15.0-6.80.1.el8] - LTS version: v5.15.80 (Jack Vogel) - ntfs: check overflow wheniterating ATTR_RECORDs (Hawkins Jiawei) - ntfs: fix out-of-bounds read in ntfs_attr_find() (Hawkins Jiawei) - ntfs: fix use-after-free in ntfs_attr_find() (Hawkins Jiawei) - net/9p: use a dedicated spinlock for trans_fd (Dominique Martinet) - mm: fs: initialize fsdata passed to write_begin/write_end interface (Alexander Potapenko) - wifi: wext: use flex array destination for memcpy() (Hawkins Jiawei) - 9p/trans_fd: always use O_NONBLOCK read/write (Tetsuo Handa) - gfs2: Switch from strlcpy to strscpy (Andreas Gruenbacher) - gfs2: Check sb_bsize_shift after reading superblock (Andrew Price) - 9p: trans_fd/p9_conn_cancel: drop client lock earlier (Dominique Martinet) - kcm: close race conditions on sk_receive_queue (Cong Wang) - kcm: avoid potential race in kcm_tx_work (Eric Dumazet) - tcp: cdg: allow tcp_cdg_release() to be called multiple times (Eric Dumazet) - macvlan: enforce a consistent minimal mtu (Eric Dumazet) - Input: i8042 - fix leaking of platform device on module removal (Chen Jun) - kprobes: Skip clearing aggrprobe's post_handler in kprobe-on-ftrace case (Li Huafei) - scsi: scsi_debug: Fix possible UAF in sdebug_add_host_helper() (Yuan Can) - scsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus() (Yang Yingliang) - net: use struct_group to copy ip/ipv6 header addresses (Hangbin Liu) - tracing: Fix warning on variable 'struct trace_array' (Aashish Sharma) - ring-buffer: Include dropped pages in counting dirty patches (Steven Rostedt (Google)) - perf: Improve missing SIGTRAP checking (Marco Elver) - serial: 8250_lpss: Use 16B DMA burst with Elkhart Lake (Ilpo Järvinen) - nvme: ensure subsystem reset is single threaded (Keith Busch) - nvme: restrict management ioctls to admin (Keith Busch) - perf/x86/intel/pt: Fix sampling using single range output (Adrian Hunter) - misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (Alexander Potapenko) - docs: update mediator contact information in CoC doc (Shuah Khan) - mmc: sdhci-pci: Fix possible memory leak caused by missingpci_dev_put() (Xiongfeng Wang) - mmc: sdhci-pci-o2micro: fix card detect fail issue caused by CD# debounce timeout (Chevron Li) - mmc: core: properly select voltage range without power cycle (Yann Gautier) - firmware: coreboot: Register bus in module init (Brian Norris) - iommu/vt-d: Set SRE bit only when hardware has SRS cap (Tina Zhang) - iommu/vt-d: Preset Access bit for IOVA in FL non-leaf paging entries (Tina Zhang) - scsi: zfcp: Fix double free of FSF request when qdio send fails (Benjamin Block) - net: phy: marvell: add sleep time after enabling the loopback bit (Aminuddin Jamaluddin) - maccess: Fix writing offset in case of fault in strncpy_from_kernel_nofault() (Alban Crequy) - Input: iforce - invert valid length check when fetching device IDs (Tetsuo Handa) - serial: 8250_lpss: Configure DMA also w/o DMA filter (Ilpo Järvinen) - serial: 8250: Flush DMA Rx on RLSI (Ilpo Järvinen) - serial: 8250: Fall back to non-DMA Rx if IIR_RDI occurs (Ilpo Järvinen) - dm ioctl: fix misbehavior if list_versions races with module loading (Mikulas Patocka) - iio: pressure: ms5611: changed hardcoded SPI speed to value limited (Mitja Spes) - iio: adc: mp2629: fix potential array out of bound access (Saravanan Sekar) - iio: adc: mp2629: fix wrong comparison of channel (Saravanan Sekar) - iio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init() (Yang Yingliang) - iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger() (Yang Yingliang) - usb: typec: mux: Enter safe mode only when pins need to be reconfigured (Rajat Khandelwal) - usb: cdns3: host: fix endless superspeed hub port reset (Li Jun) - usb: chipidea: fix deadlock in ci_otg_del_timer (Duoming Zhou) - usb: add NO_LPM quirk for Realforce 87U Keyboard (Nicolas Dumazet) - USB: serial: option: add Fibocom FM160 0x0111 composition (Reinhard Speyerer) - USB: serial: option: add u-blox LARA-L6 modem (Davide Tronchin) - USB: serial: option: add u-blox LARA-R6 00B modem (Davide Tronchin) - USB: serial: option: remove old LARA-R6 PID(Davide Tronchin) - USB: serial: option: add Sierra Wireless EM9191 (Benoît Monin) - USB: bcma: Make GPIO explicitly optional (Linus Walleij) - speakup: fix a segfault caused by switching consoles (Mushahid Hussain) - slimbus: stream: correct presence rate frequencies (Krzysztof Kozlowski) - slimbus: qcom-ngd: Fix build error when CONFIG_SLIM_QCOM_NGD_CTRL=y && CONFIG_QCOM_RPROC_COMMON=m (Zheng Bin) - Revert "usb: dwc3: disable USB core PHY management" (Johan Hovold) - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy Book Pro 360 (Takashi Iwai) - ALSA: hda/realtek: fix speakers for Samsung Galaxy Book Pro (Emil Flink) - ALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open() (Takashi Iwai) - drm/amd/display: Add HUBP surface flip interrupt handler (Rodrigo Siqueira) - tracing: kprobe: Fix potential null-ptr-deref on trace_array in kprobe_event_gen_test_exit() (Shang XiaoJing) - tracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit() (Shang XiaoJing) - tracing: Fix race where eprobes can be called before the event (Steven Rostedt (Google)) - tracing: Fix wild-memory-access in register_synth_event() (Shang XiaoJing) - tracing: Fix memory leak in test_gen_synth_cmd() and test_empty_synth_event() (Shang XiaoJing) - tracing/ring-buffer: Have polling block on watermark (Steven Rostedt (Google)) - tracing: Fix memory leak in tracing_read_pipe() (Wang Yufen) - ring_buffer: Do not deactivate non-existant pages (Daniil Tatianin) - ftrace: Fix null pointer dereference in ftrace_add_mod() (Xiu Jianfeng) - ftrace: Optimize the allocation for mcount entries (Wang Wensheng) - ftrace: Fix the possible incorrect kernel message (Wang Wensheng) - cifs: add check for returning value of SMB2_set_info_init (Anastasia Belova) - net: thunderbolt: Fix error handling in tbnet_init() (Yuan Can) - net: microchip: sparx5: Fix potential null-ptr-deref in sparx_stats_init() and sparx5_start() (Shang XiaoJing) - cifs: Fix wrong return value checking when GETFLAGS (ZhangXiaoxu) - net/x25: Fix skb leak in x25_lapb_receive_frame() (Wei Yongjun) - net: ag71xx: call phylink_disconnect_phy if ag71xx_hw_enable() fail in ag71xx_open() (Liu Jian) - cifs: add check for returning value of SMB2_close_init (Anastasia Belova) - platform/surface: aggregator: Do not check for repeated unsequenced packets (Maximilian Luz) - platform/x86/intel: pmc: Don't unconditionally attach Intel PMC when virtualized (Roger Pau Monné) - drbd: use after free in drbd_create_device() (Dan Carpenter) - bridge: switchdev: Fix memory leaks when changing VLAN protocol (Ido Schimmel) - net: hns3: fix setting incorrect phy link ksettings for firmware in resetting process (Guangbin Huang) - net: ena: Fix error handling in ena_init() (Yuan Can) - net: ionic: Fix error handling in ionic_init_module() (Yuan Can) - xen/pcpu: fix possible memory leak in register_pcpu() (Yang Yingliang) - net: dsa: make dsa_master_ioctl() see through port_hwtstamp_get() shims (Vladimir Oltean) - net: mhi: Fix memory leak in mhi_net_dellink() (Wei Yongjun) - bnxt_en: Remove debugfs when pci_register_driver failed (Gaosheng Cui) - net: caif: fix double disconnect client in chnl_net_open() (Zhengchao Shao) - net: macvlan: Use built-in RCU list checking (Chuang Wang) - mISDN: fix misuse of put_device() in mISDN_register_device() (Wang ShaoBo) - net: liquidio: release resources when liquidio driver open failed (Zhengchao Shao) - soc: imx8m: Enable OCOTP clock before reading the register (Xiaolei Wang) - net: stmmac: ensure tx function is not running in stmmac_xdp_release() (Mohd Faizal Abdul Rahim) - net: hinic: Fix error handling in hinic_module_init() (Yuan Can) - mISDN: fix possible memory leak in mISDN_dsp_element_register() (Yang Yingliang) - net: bgmac: Drop free_netdev() from bgmac_enet_remove() (Wei Yongjun) - bpf: Initialize same number of free nodes for each pcpu_freelist (Xu Kuohai) - MIPS: Loongson64: Add WARN_ON on kexec related kmalloc failed (Liao Chang) - MIPS: fix duplicate definitions for exported symbols (Rongwei Zhang) -nfp: change eeprom length to max length enumerators (Jaco Coetzee) - ata: libata-transport: fix error handling in ata_tdev_add() (Yang Yingliang) - ata: libata-transport: fix error handling in ata_tlink_add() (Yang Yingliang) - ata: libata-transport: fix error handling in ata_tport_add() (Yang Yingliang) - ata: libata-transport: fix double ata_host_put() in ata_tport_add() (Yang Yingliang) - arm64: dts: imx8mn: Fix NAND controller size-cells (Marek Vasut) - arm64: dts: imx8mm: Fix NAND controller size-cells (Marek Vasut) - ARM: dts: imx7: Fix NAND controller size-cells (Marek Vasut) - drm: Fix potential null-ptr-deref in drm_vblank_destroy_worker() (Shang XiaoJing) - drm/drv: Fix potential memory leak in drm_dev_init() (Shang XiaoJing) - drm/panel: simple: set bpc field for logic technologies displays (Aishwarya Kothari) - drm/vc4: kms: Fix IS_ERR() vs NULL check for vc4_kms (Gaosheng Cui) - pinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map (Zeng Heng) - parport_pc: Avoid FIFO port location truncation (Maciej W. Rozycki) - siox: fix possible memory leak in siox_device_add() (Yang Yingliang) - arm64: Fix bit-shifting UB in the MIDR_CPU_MODEL() macro (D Scott Phillips) - bpf: Fix memory leaks in __check_func_call (Wang Yufen) - block: sed-opal: kmalloc the cmd/resp buffers (Serge Semin) - scsi: scsi_transport_sas: Fix error handling in sas_phy_add() (Yang Yingliang) - pinctrl: rockchip: list all pins in a possible mux route for PX30 (Quentin Schulz) - ASoC: soc-utils: Remove __exit for snd_soc_util_exit() (Chen Zhongjin) - bpf, test_run: Fix alignment problem in bpf_prog_test_run_skb() (Baisong Zhong) - tty: n_gsm: fix sleep-in-atomic-context bug in gsm_control_send (Duoming Zhou) - serial: imx: Add missing .thaw_noirq hook (Shawn Guo) - serial: 8250: omap: Flush PM QOS work on remove (Tony Lindgren) - serial: 8250: omap: Fix unpaired pm_runtime_put_sync() in omap8250_remove() (Tony Lindgren) - serial: 8250_omap: remove wait loop from Errata i202 workaround (Matthias Schiffer) - serial:8250: omap: Fix missing PM runtime calls for omap8250_set_mctrl() (Tony Lindgren) - ARM: at91: pm: avoid soft resetting AC DLL (Claudiu Beznea) - ASoC: tas2764: Fix set_tdm_slot in case of single slot (Martin PoviÅ¡er) - ASoC: tas2770: Fix set_tdm_slot in case of single slot (Martin PoviÅ¡er) - ASoC: core: Fix use-after-free in snd_soc_exit() (Chen Zhongjin) - ARM: dts: at91: sama7g5: fix signal name of pin PB2 (Mihai Sain) - spi: stm32: Print summary 'callbacks suppressed' message (Marek Vasut) - arm64: dts: qcom: sm8350-hdk: Specify which LDO modes are allowed (Douglas Anderson) - arm64: dts: qcom: sm8250-xperia-edo: Specify which LDO modes are allowed (Douglas Anderson) - arm64: dts: qcom: sm8150-xperia-kumano: Specify which LDO modes are allowed (Douglas Anderson) - arm64: dts: qcom: sa8155p-adp: Specify which LDO modes are allowed (Douglas Anderson) - KVM: x86/pmu: Do not speculatively query Intel GP PMCs that don't exist yet (Like Xu) - spi: intel: Use correct mask for flash and protected regions (Mika Westerberg) - mtd: spi-nor: intel-spi: Disable write protection only if asked (Mika Westerberg) - ASoC: codecs: jz4725b: Fix spelling mistake "Sourc" -> "Source", "Routee" -> "Route" (Colin Ian King) - x86/cpu: Add several Intel server CPU model numbers (Tony Luck) - Bluetooth: L2CAP: Fix l2cap_global_chan_by_psm (Luiz Augusto von Dentz) - btrfs: remove pointless and double ulist frees in error paths of qgroup tests (Filipe Manana) - drm/imx: imx-tve: Fix return type of imx_tve_connector_mode_valid (Nathan Huckleberry) - i2c: i801: add lis3lv02d's I2C address for Vostro 5568 (Nam Cao) - i2c: tegra: Allocate DMA memory for DMA engine (Thierry Reding) - firmware: arm_scmi: Cleanup the core driver removal callback (Cristian Marussi) - ACPI: x86: Add another system to quirk list for forcing StorageD3Enable (Mario Limonciello) - NFSv4: Retry LOCK on OLD_STATEID during delegation return (Benjamin Coddington) - btrfs: raid56: properly handle the error when unable to find the missing stripe (Qu Wenruo) -RDMA/efa: Add EFA 0xefa2 PCI ID (Michael Margolin) - ACPI: scan: Add LATT2021 to acpi_ignore_dep_ids[] (Hans de Goede) - drm/amd/display: Remove wrong pipe control lock (Rodrigo Siqueira) - ASoC: rt1308-sdw: add the default value of some registers (Shuming Fan) - selftests/intel_pstate: fix build for ARCH=x86_64 (Ricardo Cañuelo) - selftests/futex: fix build for clang (Ricardo Cañuelo) - ASoC: Intel: sof_sdw: add quirk variant for LAPBC710 NUC15 (Pierre-Louis Bossart) - ASoC: codecs: jz4725b: fix capture selector naming (Siarhei Volkau) - ASoC: codecs: jz4725b: use right control for Capture Volume (Siarhei Volkau) - ASoC: codecs: jz4725b: fix reported volume for Master ctl (Siarhei Volkau) - ASoC: codecs: jz4725b: add missed Line In power control bit (Siarhei Volkau) - spi: intel: Fix the offset to get the 64K erase opcode (Mauro Lima) - ASoC: wm8962: Add an event handler for TEMP_HP and TEMP_SPK (Xiaolei Wang) - ASoC: rt1019: Fix the TDM settings (Derek Fang) - ASoC: mt6660: Keep the pm_runtime enables before component stuff in mt6660_i2c_probe (Zhang Qilong) - ASoC: wm8997: Revert "ASoC: wm8997: Fix PM disable depth imbalance in wm8997_probe" (Zhang Qilong) - ASoC: wm5110: Revert "ASoC: wm5110: Fix PM disable depth imbalance in wm5110_probe" (Zhang Qilong) - ASoC: wm5102: Revert "ASoC: wm5102: Fix PM disable depth imbalance in wm5102_probe" (Zhang Qilong) - LTS version: v5.15.79 (Jack Vogel) - x86/cpu: Restore AMD's DE_CFG MSR after resume (Borislav Petkov) - net: tun: call napi_schedule_prep() to ensure we own a napi (Eric Dumazet) - drm/amdkfd: Migrate in CPU page fault use current mm (Philip Yang) - marvell: octeontx2: build error: unknown type name 'u64' (Anders Roxell) - dmaengine: at_hdmac: Check return code of dma_async_device_register (Tudor Ambarus) - dmaengine: at_hdmac: Fix impossible condition (Tudor Ambarus) - dmaengine: at_hdmac: Don't allow CPU to reorder channel enable (Tudor Ambarus) - dmaengine: at_hdmac: Fix completion of unissued descriptor in case of errors (Tudor Ambarus) -dmaengine: at_hdmac: Fix descriptor handling when issuing it to hardware (Tudor Ambarus) - dmaengine: at_hdmac: Fix concurrency over the active list (Tudor Ambarus) - dmaengine: at_hdmac: Free the memset buf without holding the chan lock (Tudor Ambarus) - dmaengine: at_hdmac: Fix concurrency over descriptor (Tudor Ambarus) - dmaengine: at_hdmac: Fix concurrency problems by removing atc_complete_all() (Tudor Ambarus) - dmaengine: at_hdmac: Protect atchan-> status with the channel lock (Tudor Ambarus) - dmaengine: at_hdmac: Do not call the complete callback on device_terminate_all (Tudor Ambarus) - dmaengine: at_hdmac: Fix premature completion of desc in issue_pending (Tudor Ambarus) - dmaengine: at_hdmac: Start transfer for cyclic channels in issue_pending (Tudor Ambarus) - dmaengine: at_hdmac: Don't start transactions at tx_submit level (Tudor Ambarus) - dmaengine: at_hdmac: Fix at_lli struct definition (Tudor Ambarus) - cert host tools: Stop complaining about deprecated OpenSSL functions (Linus Torvalds) - can: j1939: j1939_send_one(): fix missing CAN header initialization (Oliver Hartkopp) - mm/shmem: use page_mapping() to detect page cache for uffd continue (Peter Xu) - mm/memremap.c: map FS_DAX device memory as decrypted (Pankaj Gupta) - mm/damon/dbgfs: check if rm_contexts input is for a real context (SeongJae Park) - udf: Fix a slab-out-of-bounds write bug in udf_find_entry() (ZhangPeng) - mms: sdhci-esdhc-imx: Fix SDHCI_RESET_ALL for CQHCI (Brian Norris) - btrfs: zoned: initialize device's zone info for seeding (Johannes Thumshirn) - btrfs: selftests: fix wrong error check in btrfs_free_dummy_root() (Zhang Xiaoxu) - btrfs: fix match incorrectly in dev_args_match_device (Liu Shixin) - wifi: ath11k: avoid deadlock during regulatory update in ath11k_regd_update() (Wen Gong) - platform/x86: hp_wmi: Fix rfkill causing soft blocked wifi (Jorge Lopez) - drm/amdgpu: disable BACO on special BEIGE_GOBY card (Guchun Chen) - drm/i915/dmabuf: fix sg_table handling in map_dma_buf (Matthew Auld) - nilfs2: fixuse-after-free bug of ns_writer on remount (Ryusuke Konishi) - nilfs2: fix deadlock in nilfs_count_free_blocks() (Ryusuke Konishi) - ata: libata-scsi: fix SYNCHRONIZE CACHE (16) command failure (Shin'ichiro Kawasaki) - vmlinux.lds.h: Fix placement of '.data..decrypted' section (Nathan Chancellor) - ALSA: usb-audio: Add DSD support for Accuphase DAC-60 (Jussi Laako) - ALSA: usb-audio: Add quirk entry for M-Audio Micro (Takashi Iwai) - ALSA: usb-audio: Yet more regression for for the delayed card registration (Takashi Iwai) - ALSA: hda/realtek: Add Positivo C6300 model quirk (Edson Juliano Drosdeck) - ALSA: hda: fix potential memleak in 'add_widget_node' (Ye Bin) - ALSA: hda/ca0132: add quirk for EVGA Z390 DARK (Xian Wang) - ALSA: hda/hdmi - enable runtime pm for more AMD display audio (Evan Quan) - mmc: sdhci-esdhc-imx: use the correct host caps for MMC_CAP_8_BIT_DATA (Haibo Chen) - mmc: sdhci-tegra: Fix SDHCI_RESET_ALL for CQHCI (Brian Norris) - mmc: sdhci_am654: Fix SDHCI_RESET_ALL for CQHCI (Brian Norris) - mmc: sdhci-of-arasan: Fix SDHCI_RESET_ALL for CQHCI (Brian Norris) - mmc: cqhci: Provide helper for resetting both SDHCI and CQHCI (Brian Norris) - MIPS: jump_label: Fix compat branch range check (Jiaxun Yang) - arm64: efi: Fix handling of misaligned runtime regions and drop warning (Ard Biesheuvel) - riscv: fix reserved memory setup (Conor Dooley) - riscv: vdso: fix build with llvm (Jisheng Zhang) - riscv: process: fix kernel info leakage (Jisheng Zhang) - net: macvlan: fix memory leaks of macvlan_common_newlink (Chuang Wang) - ethernet: tundra: free irq when alloc ring failed in tsi108_open() (Zhengchao Shao) - net: mv643xx_eth: disable napi when init rxq or txq failed in mv643xx_eth_open() (Zhengchao Shao) - ethernet: s2io: disable napi when start nic failed in s2io_card_up() (Zhengchao Shao) - net: atlantic: macsec: clear encryption keys from the stack (Antoine Tenart) - net: phy: mscc: macsec: clear encryption keys when freeing a flow (Antoine Tenart) - stmmac: dwmac-loongson: fix missing of_node_put()while module exiting (Yang Yingliang) - stmmac: dwmac-loongson: fix missing pci_disable_device() in loongson_dwmac_probe() (Yang Yingliang) - stmmac: dwmac-loongson: fix missing pci_disable_msi() while module exiting (Yang Yingliang) - cxgb4vf: shut down the adapter when t4vf_update_port_info() failed in cxgb4vf_open() (Zhengchao Shao) - mctp: Fix an error handling path in mctp_init() (Wei Yongjun) - stmmac: intel: Update PCH PTP clock rate from 200MHz to 204.8MHz (Tan, Tee Min) - stmmac: intel: Enable 2.5Gbps for Intel AlderLake-S (Wong Vee Khee) - net: cxgb3_main: disable napi when bind qsets failed in cxgb_up() (Zhengchao Shao) - net: cpsw: disable napi in cpsw_ndo_open() (Zhengchao Shao) - net/mlx5e: E-Switch, Fix comparing termination table instance (Roi Dayan) - net/mlx5: Allow async trigger completion execution on single CPU systems (Roy Novich) - net/mlx5: Bridge, verify LAG state when adding bond to bridge (Vlad Buslov) - net: wwan: iosm: fix memory leak in ipc_pcie_read_bios_cfg (M Chetan Kumar) - net: nixge: disable napi when enable interrupts failed in nixge_open() (Zhengchao Shao) - net: marvell: prestera: fix memory leak in prestera_rxtx_switch_init() (Zhengchao Shao) - netfilter: Cleanup nft_net-> module_list from nf_tables_exit_net() (Shigeru Yoshida) - netfilter: nfnetlink: fix potential dead lock in nfnetlink_rcv_msg() (Ziyang Xuan) - perf tools: Add the include/perf/ directory to .gitignore (Donglin Peng) - perf stat: Fix printing os-> prefix in CSV metrics output (Athira Rajeev) - drivers: net: xgene: disable napi when register irq failed in xgene_enet_open() (Zhengchao Shao) - net: lapbether: fix issue of invalid opcode in lapbeth_open() (Zhengchao Shao) - dmaengine: ti: k3-udma-glue: fix memory leak when register device fail (Yang Yingliang) - dmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove() (Christophe JAILLET) - dmaengine: pxa_dma: use platform_get_irq_optional (Doug Brown) - tipc: fix the msg-> req tlv len check in tipc_nl_compat_name_table_dump_header (Xin Long) - net:broadcom: Fix BCMGENET Kconfig (YueHaibing) - net: stmmac: dwmac-meson8b: fix meson8b_devm_clk_prepare_enable() (Rasmus Villemoes) - can: af_can: fix NULL pointer dereference in can_rx_register() (Zhengchao Shao) - ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network (Alexander Potapenko) - tcp: prohibit TCP_REPAIR_OPTIONS if data was already sent (Lu Wei) - drm/vc4: Fix missing platform_unregister_drivers() call in vc4_drm_register() (Yuan Can) - net: wwan: mhi: fix memory leak in mhi_mbim_dellink (HW He) - net: wwan: iosm: fix memory leak in ipc_wwan_dellink (HW He) - hamradio: fix issue of dev reference count leakage in bpq_device_event() (Zhengchao Shao) - net: lapbether: fix issue of dev reference count leakage in lapbeth_device_event() (Zhengchao Shao) - KVM: s390: pv: don't allow userspace to set the clock under PV (Nico Boehr) - phy: ralink: mt7621-pci: add sentinel to quirks table (John Thomson) - capabilities: fix undefined behavior in bit shift for CAP_TO_MASK (Gaosheng Cui) - net: fman: Unregister ethernet device on removal (Sean Anderson) - bnxt_en: fix potentially incorrect return value for ndo_rx_flow_steer (Alex Barba) - bnxt_en: Fix possible crash in bnxt_hwrm_set_coal() (Michael Chan) - net: tun: Fix memory leaks of napi_get_frags (Wang Yufen) - octeontx2-pf: NIX TX overwrites SQ_CTX_HW_S[SQ_INT] (Ratheesh Kannoth) - octeontx2-pf: Use hardware register for CQE count (Geetha sowjanya) - macsec: clear encryption keys from the stack after setting up offload (Sabrina Dubroca) - macsec: fix detection of RXSCs when toggling offloading (Sabrina Dubroca) - macsec: fix secy-> n_rx_sc accounting (Sabrina Dubroca) - macsec: delete new rxsc when offload fails (Sabrina Dubroca) - net: gso: fix panic on frag_list with mixed head alloc types (Jiri Benc) - bpf: Fix wrong reg type conversion in release_reference() (Youlin Li) - bpf: Add helper macro bpf_for_each_reg_in_vstate (Kumar Kartikeya Dwivedi) - bpf, sock_map: Move cancel_work_sync() out of sock lock (Cong Wang) - bpf: Fix sockmapcalling sleepable function in teardown path (John Fastabend) - bpf, sockmap: Fix sk-> sk_forward_alloc warn_on in sk_stream_kill_queues (Wang Yufen) - HID: hyperv: fix possible memory leak in mousevsc_probe() (Yang Yingliang) - bpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE (Pu Lehui) - wifi: mac80211: Set TWT Information Frame Disabled bit as 1 (Howard Hsu) - bpf, sockmap: Fix the sk-> sk_forward_alloc warning of sk_stream_kill_queues (Wang Yufen) - bpf, verifier: Fix memory leak in array reallocation for stack state (Kees Cook) - soundwire: qcom: check for outanding writes before doing a read (Srinivas Kandagatla) - soundwire: qcom: reinit broadcast completion (Srinivas Kandagatla) - wifi: cfg80211: fix memory leak in query_regdb_file() (Arend van Spriel) - wifi: cfg80211: silence a sparse RCU warning (Johannes Berg) - phy: stm32: fix an error code in probe (Dan Carpenter) - hwspinlock: qcom: correct MMIO max register for newer SoCs (Krzysztof Kozlowski) - drm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram() (Yang Li) - drm/amdkfd: handle CPU fault on COW mapping (Philip Yang) - drm/amdkfd: avoid recursive lock in migrations back to RAM (Alex Sierra) - fuse: fix readdir cache race (Miklos Szeredi) - thunderbolt: Add DP OUT resource when DP tunnel is discovered (Sanjay R Mehta) - thunderbolt: Tear down existing tunnels when resuming from hibernate (Mika Westerberg) - LTS version: v5.15.78 (Jack Vogel) - wifi: brcmfmac: Fix potential buffer overflow in brcmf_fweh_event_worker() (Dokyung Song) {CVE-2022-3628} - drm/i915/sdvo: Setup DDC fully before output init (Ville Syrjälä) - drm/i915/sdvo: Filter out invalid outputs more sensibly (Ville Syrjälä) - drm/rockchip: dsi: Force synchronous probe (Brian Norris) - drm/rockchip: dsi: Clean up 'usage_mode' when failing to attach (Brian Norris) - cifs: fix regression in very old smb1 mounts (Ronnie Sahlberg) - ext4,f2fs: fix readahead of verity data (Matthew Wilcox (Oracle)) - tee: Fix tee_shm_register() for kernelTEE drivers (Sumit Garg) - KVM: x86: emulator: update the emulation mode after CR0 write (Maxim Levitsky) - KVM: x86: emulator: update the emulation mode after rsm (Maxim Levitsky) - KVM: x86: emulator: introduce emulator_recalc_and_set_mode (Maxim Levitsky) - KVM: x86: emulator: em_sysexit should update ctxt-> mode (Maxim Levitsky) - KVM: arm64: Fix bad dereference on MTE-enabled systems (Ryan Roberts) - KVM: VMX: fully disable SGX if SECONDARY_EXEC_ENCLS_EXITING unavailable (Emanuele Giuseppe Esposito) - KVM: x86: Mask off reserved bits in CPUID.8000001FH (Jim Mattson) - KVM: x86: Mask off reserved bits in CPUID.80000001H (Jim Mattson) - KVM: x86: Mask off reserved bits in CPUID.80000008H (Jim Mattson) - KVM: x86: Mask off reserved bits in CPUID.8000001AH (Jim Mattson) - KVM: x86: Mask off reserved bits in CPUID.80000006H (Jim Mattson) - x86/syscall: Include asm/ptrace.h in syscall_wrapper header (Jiri Olsa) - ext4: fix BUG_ON() when directory entry has invalid rec_len (LuÃs Henriques) - ext4: fix warning in 'ext4_da_release_space' (Ye Bin) - parisc: Avoid printing the hardware path twice (Helge Deller) - parisc: Export iosapic_serial_irq() symbol for serial port driver (Helge Deller) - parisc: Make 8250_gsc driver dependend on CONFIG_PARISC (Helge Deller) - perf/x86/intel: Fix pebs event constraints for SPR (Kan Liang) - perf/x86/intel: Add Cooper Lake stepping to isolation_ucodes[] (Kan Liang) - perf/x86/intel: Fix pebs event constraints for ICL (Kan Liang) - arm64: entry: avoid kprobe recursion (Mark Rutland) - efi: random: Use 'ACPI reclaim' memory for random seed (Ard Biesheuvel) - efi: random: reduce seed size to 32 bytes (Ard Biesheuvel) - fuse: add file_modified() to fallocate (Miklos Szeredi) - capabilities: fix potential memleak on error path from vfs_getxattr_alloc() (Gaosheng Cui) - tracing/histogram: Update document for KEYS_MAX size (Zheng Yejian) - tools/nolibc/string: Fix memcmp() implementation (Rasmus Villemoes) - ring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters() (StevenRostedt (Google)) - kprobe: reverse kp-> flags when arm_kprobe failed (Li Qiang) - tracing: kprobe: Fix memory leak in test_gen_kprobe/kretprobe_cmd() (Shang XiaoJing) - tcp/udp: Make early_demux back namespacified. (Kuniyuki Iwashima) - ftrace: Fix use-after-free for dynamic ftrace_ops (Li Huafei) - btrfs: fix type of parameter generation in btrfs_get_dentry (David Sterba) - btrfs: fix tree mod log mishandling of reallocated nodes (Josef Bacik) - btrfs: fix lost file sync on direct IO write with nowait and dsync iocb (Filipe Manana) - fscrypt: fix keyring memory leak on mount failure (Eric Biggers) - fscrypt: stop using keyrings subsystem for fscrypt_master_key (Eric Biggers) - af_unix: Fix memory leaks of the whole sk due to OOB skb. (Kuniyuki Iwashima) - block, bfq: protect 'bfqd-> queued' by 'bfqd-> lock' (Yu Kuai) - Bluetooth: L2CAP: Fix attempting to access uninitialized memory (Luiz Augusto von Dentz) {CVE-2022-42895} - Bluetooth: L2CAP: Fix accepting connection request for invalid SPSM (Luiz Augusto von Dentz) {CVE-2022-42896} - i2c: piix4: Fix adapter not be removed in piix4_remove() (Chen Zhongjin) - arm64: dts: juno: Add thermal critical trip points (Cristian Marussi) - firmware: arm_scmi: Fix devres allocation device in virtio transport (Cristian Marussi) - firmware: arm_scmi: Make Rx chan_setup fail on memory errors (Cristian Marussi) - firmware: arm_scmi: Suppress the driver's bind attributes (Cristian Marussi) - block: Fix possible memory leak for rq_wb on add_disk failure (Chen Zhongjin) - arm64: dts: ls208xa: specify clock frequencies for the MDIO controllers (Ioana Ciornei) - arm64: dts: ls1088a: specify clock frequencies for the MDIO controllers (Ioana Ciornei) - arm64: dts: lx2160a: specify clock frequencies for the MDIO controllers (Ioana Ciornei) - arm64: dts: imx8: correct clock order (Peng Fan) - ARM: dts: imx6qdl-gw59{10,13}: fix user pushbutton GPIO offset (Tim Harvey) - clk: qcom: Update the force mem core bit for GPU clocks (Taniya Das) - efi/tpm: Pass correct address tomemblock_reserve (Jerry Snitselaar) - i2c: xiic: Add platform module alias (Martin Tůma) - drm/amdgpu: set vm_update_mode=0 as default for Sienna Cichlid in SRIOV case (Danijel Slivka) - HID: saitek: add madcatz variant of MMO7 mouse device ID (Samuel Bailey) - scsi: core: Restrict legal sdev_state transitions via sysfs (Uday Shankar) - ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() (Ashish Kalra) - media: v4l: subdev: Fail graciously when getting try data for NULL state (Sakari Ailus) - media: meson: vdec: fix possible refcount leak in vdec_probe() (Hangyu Hua) - media: dvb-frontends/drxk: initialize err to 0 (Hans Verkuil) - media: cros-ec-cec: limit msg.len to CEC_MAX_MSG_SIZE (Hans Verkuil) - media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE (Hans Verkuil) - media: rkisp1: Zero v4l2_subdev_format fields in when validating links (Laurent Pinchart) - media: rkisp1: Use correct macro for gradient registers (Laurent Pinchart) - media: rkisp1: Initialize color space on resizer sink and source pads (Laurent Pinchart) - media: rkisp1: Don't pass the quantization to rkisp1_csm_config() (Laurent Pinchart) - s390/cio: fix out-of-bounds access on cio_ignore free (Peter Oberparleiter) - s390/cio: derive cdev information only for IO-subchannels (Vineeth Vijayan) - s390/boot: add secure boot trailer (Peter Oberparleiter) - s390/uaccess: add missing EX_TABLE entries to __clear_user() (Heiko Carstens) - mtd: parsers: bcm47xxpart: Fix halfblock reads (Linus Walleij) - mtd: parsers: bcm47xxpart: print correct offset on read error (RafaÅ MiÅecki) - fbdev: stifb: Fall back to cfb_fillrect() on 32-bit HCRX cards (Helge Deller) - video/fbdev/stifb: Implement the stifb_fillrect() function (Helge Deller) - drm/msm/hdmi: fix IRQ lifetime (Johan Hovold) - drm/msm/hdmi: Remove spurious IRQF_ONESHOT flag (Daniel Thompson) - vsock: fix possible infinite sleep in vsock_connectible_wait_data() (Dexuan Cui) - ipv6: fix WARNING in ip6_route_net_exit_late() (Zhengchao Shao) - net, neigh: Fix null-ptr-deref inneigh_table_clear() (Chen Zhongjin) - net/smc: Fix possible leaked pernet namespace in smc_init() (Chen Zhongjin) - stmmac: dwmac-loongson: fix invalid mdio_node (Liu Peibao) - ibmvnic: Free rwi on reset success (Nick Child) - net: mdio: fix undefined behavior in bit shift for __mdiobus_register (Gaosheng Cui) - Bluetooth: L2CAP: Fix memory leak in vhci_write (Hawkins Jiawei) - Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() (Zhengchao Shao) - Bluetooth: virtio_bt: Use skb_put to set length (Soenke Huster) - Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Maxim Mikityanskiy) - netfilter: ipset: enforce documented limit to prevent allocating huge memory (Jozsef Kadlecsik) - btrfs: fix ulist leaks in error paths of qgroup self tests (Filipe Manana) - btrfs: fix inode list leak during backref walking at find_parent_nodes() (Filipe Manana) - btrfs: fix inode list leak during backref walking at resolve_indirect_refs() (Filipe Manana) - isdn: mISDN: netjet: fix wrong check of device registration (Yang Yingliang) - mISDN: fix possible memory leak in mISDN_register_device() (Yang Yingliang) - rose: Fix NULL pointer dereference in rose_send_frame() (Zhang Qilong) - ipvs: fix WARNING in ip_vs_app_net_cleanup() (Zhengchao Shao) - ipvs: fix WARNING in __ip_vs_cleanup_batch() (Zhengchao Shao) - ipvs: use explicitly signed chars (Jason A. Donenfeld) - netfilter: nf_tables: release flow rule object from commit path (Pablo Neira Ayuso) - netfilter: nf_tables: netlink notifier might race to release objects (Pablo Neira Ayuso) - net: tun: fix bugs for oversize packet when napi frags enabled (Ziyang Xuan) - net: sched: Fix use after free in red_enqueue() (Dan Carpenter) - ata: pata_legacy: fix pdc20230_set_piomode() (Sergey Shtylyov) - net: fec: fix improper use of NETDEV_TX_BUSY (Zhang Changzhong) - nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send() (Shang XiaoJing) - nfc: s3fwrn5: Fix potential memory leak in s3fwrn5_nci_send() (Shang XiaoJing) - nfc: nxp-nci: Fix potential memoryleak in nxp_nci_send() (Shang XiaoJing) - nfc: fdp: Fix potential memory leak in fdp_nci_send() (Shang XiaoJing) - net: dsa: fall back to default tagger if we can't load the one from DT (Vladimir Oltean) - RDMA/qedr: clean up work queue on failure in qedr_alloc_resources() (Dan Carpenter) - RDMA/core: Fix null-ptr-deref in ib_core_cleanup() (Chen Zhongjin) - net: dsa: Fix possible memory leaks in dsa_loop_init() (Chen Zhongjin) - nfs4: Fix kmemleak when allocate slot failed (Zhang Xiaoxu) - NFSv4.2: Fixup CLONE dest file size for zero-length count (Benjamin Coddington) - SUNRPC: Fix null-ptr-deref when xps sysfs alloc failed (Zhang Xiaoxu) - NFSv4.1: We must always send RECLAIM_COMPLETE after a reboot (Trond Myklebust) - NFSv4.1: Handle RECLAIM_COMPLETE trunking errors (Trond Myklebust) - NFSv4: Fix a potential state reclaim deadlock (Trond Myklebust) - RDMA/hns: Disable local invalidate operation (Yangyang Li) - RDMA/hns: Use hr_reg_xxx() instead of remaining roce_set_xxx() (Wenpeng Liang) - RDMA/hns: Remove magic number (Xinhao Liu) - IB/hfi1: Correctly move list in sc_disable() (Dean Luick) - KVM: x86: Add compat handler for KVM_X86_SET_MSR_FILTER (Alexander Graf) - KVM: x86: Copy filter arg outside kvm_vm_ioctl_set_msr_filter() (Alexander Graf) - KVM: x86: Protect the unused bits in MSR exiting flags (Aaron Lewis) - HID: playstation: add initial DualSense Edge controller support (Roderick Colenbrander) - mm/hugetlb: fix races when looking up a CONT-PTE/PMD size hugetlb page (Baolin Wang) - drm/amd/display: explicitly disable psr_feature_enable appropriately (Shirish S) - KVM: x86: Treat #DBs from the emulator as fault-like (code and DR7.GD=1) (Sean Christopherson) - serial: ar933x: Deassert Transmit Enable on -> rs485_config() (Lukas Wunner) - scsi: lpfc: Rework MIB Rx Monitor debug info logic (James Smart) - scsi: lpfc: Adjust CMF total bytes and rxmonitor (James Smart) - scsi: lpfc: Adjust bytes received vales during cmf timer interval (James Smart) - LTS version: v5.15.77 (Jack Vogel) - tcp/udp: Fixmemory leak in ipv6_renew_options(). (Kuniyuki Iwashima) - serial: Deassert Transmit Enable on probe in driver-specific way (Lukas Wunner) - serial: core: move RS485 configuration tasks from drivers into core (Lino Sanfilippo) - can: rcar_canfd: rcar_canfd_handle_global_receive(): fix IRQ storm on global FIFO receive (Biju Das) - can: rcar_canfd: fix channel specific IRQ handling for RZ/G2L (Biju Das) - scsi: sd: Revert "scsi: sd: Remove a local variable" (Yu Kuai) - arm64: Add AMPERE1 to the Spectre-BHB affected list (D Scott Phillips) - net: enetc: survive memory pressure without crashing (Vladimir Oltean) - kcm: do not sense pfmemalloc status in kcm_sendpage() (Eric Dumazet) - net: do not sense pfmemalloc status in skb_append_pagefrags() (Eric Dumazet) - net/mlx5: Fix crash during sync firmware reset (Suresh Devarakonda) - net/mlx5: Update fw fatal reporter state on PCI handlers successful recover (Roy Novich) - net/mlx5: Print more info on pci error handlers (Saeed Mahameed) - net/mlx5: Fix possible use-after-free in async command interface (Tariq Toukan) - net/mlx5e: Extend SKB room check to include PTP-SQ (Aya Levin) - net/mlx5e: Do not increment ESN when updating IPsec ESN state (Hyong Youb Kim) - netdevsim: remove dir in nsim_dev_debugfs_init() when creating ports dir failed (Zhengchao Shao) - net: broadcom: bcm4908_enet: update TX stats after actual transmission (RafaÅ MiÅecki) - net: broadcom: bcm4908enet: remove redundant variable bytes (Colin Ian King) - nh: fix scope used to find saddr when adding non gw nh (Nicolas Dichtel) - net: bcmsysport: Indicate MAC is in charge of PHY PM (Florian Fainelli) - net: ehea: fix possible memory leak in ehea_register_port() (Yang Yingliang) - openvswitch: switch from WARN to pr_warn (Aaron Conole) - ALSA: aoa: Fix I2S device accounting (Takashi Iwai) - ALSA: aoa: i2sbus: fix possible memory leak in i2sbus_add_dev() (Yang Yingliang) - net: ethernet: ave: Fix MAC to be in charge of PHY PM (Kunihiko Hayashi) - net: fec: limit register access on i.MX6UL (JuergenBorleis) - perf vendor events arm64: Fix incorrect Hisi hip08 L3 metrics (Shang XiaoJing) - PM: domains: Fix handling of unavailable/disabled idle states (Sudeep Holla) - net: ksz884x: fix missing pci_disable_device() on error in pcidev_init() (Yang Yingliang) - i40e: Fix flow-type by setting GL_HASH_INSET registers (Slawomir Laba) - i40e: Fix VF hang when reset is triggered on another VF (Sylwester Dziedziuch) - i40e: Fix ethtool rx-flow-hash setting for X722 (Slawomir Laba) - ipv6: ensure sane device mtu in tunnels (Eric Dumazet) - perf vendor events power10: Fix hv-24x7 metric events (Kajol Jain) - media: vivid: set num_in/outputs to 0 if not supported (Hans Verkuil) - media: videodev2.h: V4L2_DV_BT_BLANKING_HEIGHT should check 'interlaced' (Hans Verkuil) - media: v4l2-dv-timings: add sanity checks for blanking values (Hans Verkuil) - media: vivid: dev-> bitmap_cap wasn't freed in all cases (Hans Verkuil) - media: vivid: s_fbuf: add more sanity checks (Hans Verkuil) - PM: hibernate: Allow hybrid sleep to work with s2idle (Mario Limonciello) - can: mcp251x: mcp251x_can_probe(): add missing unregister_candev() in error path (Dongliang Mu) - can: mscan: mpc5xxx: mpc5xxx_can_probe(): add missing put_clock() in error path (Dongliang Mu) - drm/amdkfd: Fix memory leak in kfd_mem_dmamap_userptr() (Rafael Mendonca) - net-memcg: avoid stalls when under memory pressure (Jakub Kicinski) - tcp: fix indefinite deferral of RTO with SACK reneging (Neal Cardwell) - tcp: fix a signed-integer-overflow bug in tcp_add_backlog() (Lu Wei) - tcp: minor optimization in tcp_add_backlog() (Eric Dumazet) - net: lantiq_etop: don't free skb when returning NETDEV_TX_BUSY (Zhang Changzhong) - net: fix UAF issue in nfqnl_nf_hook_drop() when ops_init() failed (Zhengchao Shao) - kcm: annotate data-races around kcm-> rx_wait (Eric Dumazet) - kcm: annotate data-races around kcm-> rx_psock (Eric Dumazet) - atlantic: fix deadlock at aq_nic_stop (Ãñigo Huguet) - drm/i915/dp: Reset frl trained flag before restarting FRL training (AnkitNautiyal) - amd-xgbe: add the bit rate quirk for Molex cables (Raju Rangoju) - amd-xgbe: fix the SFP compliance codes check for DAC cables (Raju Rangoju) - x86/unwind/orc: Fix unreliable stack dump with gcov (Chen Zhongjin) - nfc: virtual_ncidev: Fix memory leak in virtual_nci_send() (Shang XiaoJing) - net: macb: Specify PHY PM management done by MAC (Sergiu Moga) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9012 https://linux.oracle.com/errata/ELSA-2022-9012.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: aarch64: kernel-uek-5.4.17-2136.302.7.2.el8uek.aarch64.rpm kernel-uek-debug-5.4.17-2136.302.7.2.el8uek.aarch64.rpm kernel-uek-debug-devel-5.4.17-2136.302.7.2.el8uek.aarch64.rpm kernel-uek-devel-5.4.17-2136.302.7.2.el8uek.aarch64.rpm kernel-uek-doc-5.4.17-2136.302.7.2.el8uek.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-uek-5.4.17-2136.302.7.2.el8uek.src.rpm Related CVEs: CVE-2021-0920 CVE-2021-4155 Description of changes: [5.4.17-2136.302.7.2.el8uek] - xfs: map unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (Darrick J. Wong) [Orabug: 33699625] {CVE-2021-4155} [5.4.17-2136.302.7.1.el8uek] - fget: check that the fd still exists after getting a ref to it (Linus Torvalds) [Orabug: 33691332] {CVE-2021-0920} [5.4.17-2136.302.7.el8uek] - rds: ib: Reduce the contention caused by the asynchronous workers to flush the mr pool (Praveen Kumar Kannoju) [Orabug: 33671425] - rds: ib: Ack seq not always received in monotonic increasing order (H=E5kon Bugge) [Orabug: 33671414] - net/rds: Don't pummel the subnet-manager (Gerd Rausch) [Orabug: 33671407] - EDAC/i10nm: Add detection of memory levels for ICX/SPR servers (Qiuxu Zhuo) [Orabug: 33601775] - EDAC/skx_common: Add new ADXL components for 2-level memory (Qiuxu Zhuo) [Orabug: 33601775] - EDAC, skx_common: Refactor so that we initialize "dev" in result of adxl decode. (Tony Luck) [Orabug: 33601775] - uek-rpm: Add ktime_get_coarse_ts64 to KABI (John Donnelly) [Orabug: 33671383] - cpufreq: intel_pstate: Add Icelake servers support in no-HWP mode (Giovanni Gherdovich) [Orabug: 33671378] - net: ipv6: Discard next-hop MTU less than minimum link MTU (Georg Kohmann) [Orabug: 33671371] - ocfs2: fix race betweensearching chunks and release journal_head from buffer_head (Gautham Ananthakrishna) [Orabug: 33671363] - rds/ib: Use both iova and key in free_mr socket call (aru kolappan) [Orabug: 33671236] _______________________________________________ El-errata mailing list
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2713-1 August 18, 2015 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's SCTP address configuration lists when using Address Configuration Change (ASCONF) options on a socket. An unprivileged local user could exploit this flaw to cause a denial of service (system crash). (CVE-2015-3212) A flaw was discovered in how the Linux kernel handles invalid UDP checksums. A remote attacker could exploit this flaw to cause a denial of service using a flood of UDP packets with invalid checksums. (CVE-2015-5364) A flaw was discovered in how the Linux kernel handles invalid UDP checksums. A remote attacker can cause a denial of service against applications that use epoll by injecting a single packet with an invalid checksum. (CVE-2015-5366) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: linux-image-3.2.0-89-generic 3.2.0-89.127 linux-image-3.2.0-89-generic-pae 3.2.0-89.127 linux-image-3.2.0-89-highbank 3.2.0-89.127 linux-image-3.2.0-89-omap 3.2.0-89.127 linux-image-3.2.0-89-powerpc-smp 3.2.0-89.127 linux-image-3.2.0-89-powerpc64-smp 3.2.0-89.127 linux-image-3.2.0-89-virtual 3.2.0-89.127 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed.If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-2713-1 CVE-2015-3212, CVE-2015-5364, CVE-2015-5366 Package Information: https://launchpad.net/ubuntu/+source/linux/3.2.0-89.127 . Linux 4.15 LTS resolves various kernel vulnerabilities with essential updates promoting system reliability and protection.. Ubuntu Kernel Security, Linux Kernel Patch, Kernel Mitigation, Denial of Service Threats. . Severity: Critical. LinuxSecurity.com Team
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-1919-1 July 29, 2013 linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux: Linux kernel Details: Kees Cook discovered a format string vulnerability in the Broadcom B43 wireless driver for the Linux kernel. A local user could exploit this flaw to gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: linux-image-3.8.0-27-generic 3.8.0-27.40 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-1919-1 CVE-2013-2852 Package Information: https://launchpad.net/ubuntu/+source/linux/3.8.0-27.40 . Critical notice for Ubuntu users addressing a Linux kernel flaw that could grant root-level privileges and lead to possible system failures.. Linux Kernel Threat, Ubuntu Update Guide, Admin Access Flaw, System Crash Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.