Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6724-1 April 09, 2024 linux, linux-aws, linux-azure, linux-azure-6.5, linux-gcp, linux-gcp-6.5, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-starfive, linux-starfive-6.5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-laptop: Linux kernel for Lenovo X13s ARM laptops - linux-lowlatency: Linux low latency kernel - linux-oracle: Linux kernel for Oracle Cloud systems - linux-starfive: Linux kernel for StarFive processors - linux-azure-6.5: Linux kernel for Microsoft Azure cloud systems - linux-gcp-6.5: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-6.5: Linux hardware enablement (HWE) kernel - linux-lowlatency-hwe-6.5: Linux low latency kernel - linux-oem-6.5: Linux kernel for OEM systems - linux-oracle-6.5: Linux kernel for Oracle Cloud systems - linux-starfive-6.5: Linux kernel for StarFive processors Details: Pratyush Yadav discovered that the Xen network backend implementation in the Linux kernel did not properly handle zero length data request, leading to a null pointer dereference vulnerability. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2023-46838) It was discovered that the Habana's AI Processors driver in the Linux kernel did not properly initialize certain data structures beforepassing them to user space. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2023-50431) It was discovered that the device mapper driver in the Linux kernel did not properly validate target size during certain memory allocations. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-52429, CVE-2024-23851) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate certain SMB messages, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6610) Yang Chaoming discovered that the KSMBD implementation in the Linux kernel did not properly validate request buffer sizes, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2024-22705) Chenyuan Yang discovered that the btrfs file system in the Linux kernel did not properly handle read operations on newly created subvolumes in certain conditions. A local attacker could use this to cause a denial of service (system crash). (CVE-2024-23850) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Android drivers; - Userspace I/O drivers; - F2FS file system; - SMB network file system; - Networking core; (CVE-2023-52434, CVE-2023-52436, CVE-2023-52435, CVE-2023-52439, CVE-2023-52438) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: linux-image-6.5.0-1011-starfive 6.5.0-1011.12 linux-image-6.5.0-1013-laptop 6.5.0-1013.16 linux-image-6.5.0-1017-aws 6.5.0-1017.17 linux-image-6.5.0-1017-gcp 6.5.0-1017.17 linux-image-6.5.0-1018-azure 6.5.0-1018.19 linux-image-6.5.0-1018-azure-fde 6.5.0-1018.19 linux-image-6.5.0-1020-oracle 6.5.0-1020.20 linux-image-6.5.0-1020-oracle-64k 6.5.0-1020.20 linux-image-6.5.0-27-generic 6.5.0-27.28 linux-image-6.5.0-27-generic-64k 6.5.0-27.28 linux-image-6.5.0-27-lowlatency 6.5.0-27.28.1 linux-image-6.5.0-27-lowlatency-64k 6.5.0-27.28.1 linux-image-aws 6.5.0.1017.17 linux-image-azure 6.5.0.1018.22 linux-image-azure-fde 6.5.0.1018.22 linux-image-gcp 6.5.0.1017.17 linux-image-generic 6.5.0.27.27 linux-image-generic-64k 6.5.0.27.27 linux-image-generic-lpae 6.5.0.27.27 linux-image-kvm 6.5.0.27.27 linux-image-laptop-23.10 6.5.0.1013.16 linux-image-lowlatency 6.5.0.27.28.18 linux-image-lowlatency-64k 6.5.0.27.28.18 linux-image-oracle 6.5.0.1020.22 linux-image-oracle-64k 6.5.0.1020.22 linux-image-starfive 6.5.0.1011.13 linux-image-virtual 6.5.0.27.27 Ubuntu 22.04 LTS: linux-image-6.5.0-1011-starfive 6.5.0-1011.12~22.04.1 linux-image-6.5.0-1017-gcp 6.5.0-1017.17~22.04.1 linux-image-6.5.0-1018-azure 6.5.0-1018.19~22.04.2 linux-image-6.5.0-1018-azure-fde 6.5.0-1018.19~22.04.2 linux-image-6.5.0-1019-oem 6.5.0-1019.20 linux-image-6.5.0-1020-oracle 6.5.0-1020.20~22.04.1 linux-image-6.5.0-1020-oracle-64k 6.5.0-1020.20~22.04.1 linux-image-6.5.0-27-generic 6.5.0-27.28~22.04.1 linux-image-6.5.0-27-generic-64k 6.5.0-27.28~22.04.1 linux-image-6.5.0-27-lowlatency 6.5.0-27.28.1~22.04.1 linux-image-6.5.0-27-lowlatency-64k 6.5.0-27.28.1~22.04.1 linux-image-azure 6.5.0.1018.19~22.04.2 linux-image-azure-fde 6.5.0.1018.19~22.04.2 linux-image-gcp 6.5.0.1017.17~22.04.1 linux-image-generic-64k-hwe-22.04 6.5.0.27.28~22.04.1 linux-image-generic-hwe-22.04 6.5.0.27.28~22.04.1 linux-image-lowlatency-64k-hwe-22.04 6.5.0.27.28.1~22.04.1 linux-image-lowlatency-hwe-22.04 6.5.0.27.28.1~22.04.1 linux-image-oem-22.04 6.5.0.1019.21 linux-image-oem-22.04a 6.5.0.1019.21 linux-image-oem-22.04b 6.5.0.1019.21 linux-image-oem-22.04c 6.5.0.1019.21 linux-image-oem-22.04d 6.5.0.1019.21 linux-image-oracle 6.5.0.1020.20~22.04.1 linux-image-oracle-64k 6.5.0.1020.20~22.04.1 linux-image-starfive 6.5.0.1011.12~22.04.1 linux-image-virtual-hwe-22.04 6.5.0.27.28~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6724-1 CVE-2023-46838, CVE-2023-50431, CVE-2023-52429, CVE-2023-52434, CVE-2023-52435, CVE-2023-52436, CVE-2023-52438, CVE-2023-52439, CVE-2023-6610, CVE-2024-22705, CVE-2024-23850, CVE-2024-23851 Package Information: https://launchpad.net/ubuntu/+source/linux/6.5.0-27.28 https://launchpad.net/ubuntu/+source/linux-aws/6.5.0-1017.17 https://launchpad.net/ubuntu/+source/linux-azure/6.5.0-1018.19 https://launchpad.net/ubuntu/+source/linux-gcp/6.5.0-1017.17 https://launchpad.net/ubuntu/+source/linux-laptop/6.5.0-1013.16 https://launchpad.net/ubuntu/+source/linux-lowlatency/6.5.0-27.28.1 https://launchpad.net/ubuntu/+source/linux-oracle/6.5.0-1020.20 https://launchpad.net/ubuntu/+source/linux-starfive/6.5.0-1011.12 https://launchpad.net/ubuntu/+source/linux-azure-6.5/6.5.0-1018.19~22.04.2 https://launchpad.net/ubuntu/+source/linux-gcp-6.5/6.5.0-1017.17~22.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-6.5/6.5.0-27.28~22.04.1 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-6.5/6.5.0-27.28.1~22.04.1 https://launchpad.net/ubuntu/+source/linux-oem-6.5/6.5.0-1019.20 https://launchpad.net/ubuntu/+source/linux-oracle-6.5/6.5.0-1020.20~22.04.1 https://launchpad.net/ubuntu/+source/linux-starfive-6.5/6.5.0-1011.12~22.04.1 . Numerous vital vulnerabilities resolved in the most recent Ubuntu kernel releases, improving overall system defenses.. Kernel Security, System Update, Denial Of Service, Local Exploits, Ubuntu Security. . Severity: Critical. LinuxSecurity.com Team
An update that solves 10 vulnerabilities and has 61 fixes is now available. . SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0427-1 Rating: important References: #1065600 #1149032 #1152472 #1152489 #1153274 #1154353 #1155518 #1163930 #1165545 #1167773 #1172355 #1175389 #1176395 #1176831 #1176846 #1178142 #1178372 #1178631 #1178684 #1178995 #1179142 #1179396 #1179508 #1179509 #1179567 #1179572 #1179575 #1179878 #1180008 #1180130 #1180264 #1180412 #1180676 #1180759 #1180765 #1180773 #1180809 #1180812 #1180848 #1180859 #1180889 #1180891 #1180964 #1180971 #1181014 #1181018 #1181077 #1181104 #1181148 #1181158 #1181161 #1181169 #1181203 #1181217 #1181218 #1181219 #1181220 #1181237 #1181318 #1181335 #1181346 #1181349 #1181425 #1181494 #1181504 #1181511 #1181538 #1181544 #1181553 #1181584 #1181645 Cross-References: CVE-2020-25211 CVE-2020-25639 CVE-2020-27835 CVE-2020-28374 CVE-2020-29568 CVE-2020-29569 CVE-2021-0342 CVE-2021-20177 CVE-2021-3347 CVE-2021-3348 CVSS scores: CVE-2020-25211 (NVD) : 6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVE-2020-25211 (SUSE): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVE-2020-25639 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2020-27835 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2020-28374 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-28374 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-29568 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2020-29568 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2020-29569 (NVD) : 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2020-29569 (SUSE): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2021-0342 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0342 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-20177 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVE-2021-3347 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3347 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-3348 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-3348 (SUSE): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Module for Realtime 15-SP2 ______________________________________________________________________________ An update that solves 10 vulnerabilities and has 61 fixes is now available. Description: The SUSE Linux Enterprise 15 SP2 realtime kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-3347: A use-after-free was discovered in the PI futexes during fault handling, allowing local users to execute code in the kernel (bnc#1181349). - CVE-2021-3348: Fixed a use-after-free in nbd_add_socket that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup (bnc#1181504). - CVE-2021-20177: Fixed a kernel panic related to iptables string matching rules. A privileged user could insert a rule which could lead to denial of service (bnc#1180765). - CVE-2021-0342: In tun_get_user of tun.c, there ispossible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. (bnc#1180812) - CVE-2020-27835: A use-after-free in the infiniband hfi1 driver was found, specifically in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system (bnc#1179878). - CVE-2020-25639: Fixed a NULL pointer dereference via nouveau ioctl (bnc#1176846). - CVE-2020-29569: Fixed a potential privilege escalation and information leaks related to the PV block backend, as used by Xen (bnc#1179509). - CVE-2020-29568: Fixed a denial of service issue, related to processing watch events (bnc#1179508). - CVE-2020-25211: Fixed a flaw where a local attacker was able to inject conntrack netlink configuration that could cause a denial of service or trigger the use of incorrect protocol numbers in ctnetlink_parse_tuple_filter (bnc#1176395). - CVE-2020-28374: Fixed a Linux SCSI target issue (bsc#1178372). The following non-security bugs were fixed: - ACPI/IORT: Do not blindly trust DMA masks from firmware (git-fixes). - ACPI: scan: Harden acpi_device_add() against device ID overflows (git-fixes). - ACPI: scan: Make acpi_bus_get_device() clear return pointer on error (git-fixes). - ACPI: scan: add stub acpi_create_platform_device() for !CONFIG_ACPI (git-fixes). - ACPI: sysfs: Prefer "compatible" modalias (git-fixes). - ALSA: doc: Fix reference to mixart.rst (git-fixes). - ALSA: fireface: Fix integer overflow in transmit_midi_msg() (git-fixes). - ALSA: firewire-tascam: Fix integer overflow in midi_port_work() (git-fixes). - ALSA: hda/conexant: add a new hda codec CX11970 (git-fixes). - ALSA: hda/hdmi - enable runtime pm for CI AMD display audio (git-fixes). - ALSA: hda/realtek - Fix speaker volume control on Lenovo C940 (git-fixes). - ALSA: hda/realtek - Limit int mic boost on Acer Aspire E5-575T (git-fixes). - ALSA: hda/realtek - Modify Dell platform name (git-fixes). - ALSA: hda/realtek - Supported Dell fixed type headset (git-fixes). - ALSA: hda/realtek: Add mute LED quirk for more HP laptops (git-fixes). - ALSA: hda/realtek: Add two "Intel Reference board" SSID in the ALC256 (git-fixes). - ALSA: hda/realtek: Enable headset of ASUS B1400CEPE with ALC256 (git-fixes). - ALSA: hda/realtek: Enable mute and micmute LED on HP EliteBook 850 G7 (git-fixes). - ALSA: hda/realtek: Remove dummy lineout on Acer TravelMate P648/P658 (git-fixes). - ALSA: hda/realtek: fix right sounds and mute/micmute LEDs for HP machines (git-fixes). - ALSA: hda/tegra: fix tegra-hda on tegra30 soc (git-fixes). - ALSA: hda/via: Add minimum mute flag (git-fixes). - ALSA: hda/via: Apply the workaround generically for Clevo machines (git-fixes). - ALSA: hda/via: Fix runtime PM for Clevo W35xSS (git-fixes). - ALSA: hda: Add Cometlake-R PCI ID (git-fixes). - ALSA: pcm: Clear the full allocated memory at hw_params (git-fixes). - ALSA: pcm: One more dependency for hw constraints (bsc#1181014). - ALSA: pcm: fix hw_rule deps kABI (bsc#1181014). - ALSA: seq: oss: Fix missing error check in snd_seq_oss_synth_make_info() (git-fixes). - ALSA: usb-audio: Add quirk for BOSS AD-10 (git-fixes). - ALSA: usb-audio: Add quirk for RC-505 (git-fixes). - ALSA: usb-audio: Always apply the hw constraints for implicit fb sync (bsc#1181014). - ALSA: usb-audio: Annotate the endpoint index in audioformat (git-fixes). - ALSA: usb-audio: Avoid implicit feedback on Pioneer devices (bsc#1181014). - ALSA: usb-audio: Avoid unnecessary interface re-setup (git-fixes). - ALSA: usb-audio: Choose audioformat of a counter-part substream (git-fixes). - ALSA: usb-audio: Fix UAC1 rate setup for secondary endpoints (bsc#1181014). - ALSA: usb-audio: Fix UBSAN warnings for MIDI jacks (git-fixes). - ALSA: usb-audio: Fix hw constraintsdependencies (bsc#1181014). - ALSA: usb-audio: Fix implicit feedback sync setup for Pioneer devices (git-fixes). - ALSA: usb-audio: Fix the missing endpoints creations for quirks (git-fixes). - ALSA: usb-audio: Set sample rate for all sharing EPs on UAC1 (bsc#1181014). - ASoC: Intel: fix error code cnl_set_dsp_D0() (git-fixes). - ASoC: ak4458: correct reset polarity (git-fixes). - ASoC: dapm: remove widget from dirty list on free (git-fixes). - ASoC: meson: axg-tdm-interface: fix loopback (git-fixes). - Bluetooth: hci_h5: close serdev device and free hu in h5_close (git-fixes). - Bluetooth: revert: hci_h5: close serdev device and free hu in h5_close (git-fixes). - CDC-NCM: remove "connected" log message (git-fixes). - EDAC/amd64: Fix PCI component registration (bsc#1152489). - HID: Ignore battery for Elan touchscreen on ASUS UX550 (git-fixes). - HID: logitech-dj: add the G602 receiver (git-fixes). - HID: multitouch: Apply MT_QUIRK_CONFIDENCE quirk for multi-input devices (git-fixes). - HID: multitouch: Enable multi-input for Synaptics pointstick/touchpad device (git-fixes). - HID: multitouch: Remove MT_CLS_WIN_8_DUAL (git-fixes). - HID: multitouch: do not filter mice nodes (git-fixes). - HID: wacom: Constify attribute_groups (git-fixes). - HID: wacom: Correct NULL dereference on AES pen proximity (git-fixes). - HID: wacom: Fix memory leakage caused by kfifo_alloc (git-fixes). - HID: wacom: do not call hid_set_drvdata(hdev, NULL) (git-fixes). - IB/hfi1: Remove kobj from hfi1_devdata (bsc#1179878). - IB/hfi1: Remove module parameter for KDETH qpns (bsc#1179878). - KVM: SVM: Initialize prev_ga_tag before use (bsc#1180809). - KVM: SVM: Update cr3_lm_rsvd_bits for AMD SEV guests (bsc#1178995). - KVM: nVMX: Reload vmcs01 if getting vmcs12's pages fails (bsc#1181218). - KVM: s390: pv: Mark mm as protected after the set secure parameters and improve cleanup (jsc#SLE-7512 bsc#1165545). - KVM: x86:Introduce cr3_lm_rsvd_bits in kvm_vcpu_arch (bsc#1178995). - NFC: fix possible resource leak (git-fixes). - NFC: fix resource leak when target index is invalid (git-fixes). - NFS/pNFS: Fix a leak of the layout 'plh_outstanding' counter (for-next). - NFS/pNFS: Fix a typo in ff_layout_resend_pnfs_read() (for-next). - NFS4: Fix use-after-free in trace_event_raw_event_nfs4_set_lock (for-next). - NFS: nfs_delegation_find_inode_server must first reference the superblock (for-next). - NFS: nfs_igrab_and_active must first reference the superblock (for-next). - NFS: switch nfsiod to be an UNBOUND workqueue (for-next). - NFSv4.2: condition READDIR's mask for security label based on LSM state (for-next). - NFSv4: Fix the alignment of page data in the getdeviceinfo reply (for-next). - PM: hibernate: flush swap writer after marking (git-fixes). - Revert "nfsd4: support change_attr_type attribute" (for-next). - Revive usb-audio Keep Interface mixer (bsc#1181014). - SUNRPC: Clean up the handling of page padding in rpc_prepare_reply_pages() (for-next). - SUNRPC: rpc_wake_up() should wake up tasks in the correct order (for-next). - USB: cdc-acm: blacklist another IR Droid device (git-fixes). - USB: cdc-wdm: Fix use after free in service_outstanding_interrupt() (git-fixes). - USB: dummy-hcd: Fix uninitialized array use in init() (git-fixes). - USB: ehci: fix an interrupt calltrace error (git-fixes). - USB: gadget: legacy: fix return error code in acm_ms_bind() (git-fixes). - USB: serial: iuu_phoenix: fix DMA from stack (git-fixes). - USB: serial: option: add LongSung M5710 module support (git-fixes). - USB: serial: option: add Quectel EM160R-GL (git-fixes). - USB: usblp: fix DMA to stack (git-fixes). - USB: xhci: fix U1/U2 handling for hardware with XHCI_INTEL_HOST quirk set (git-fixes). - USB: yurex: fix control-URB timeout handling (git-fixes). - arch/x86/lib/usercopy_64.c: fix __copy_user_flushcache() cachewriteback (bsc#1152489). - arm64: mm: Fix ARCH_LOW_ADDRESS_LIMIT when !CONFIG_ZONE_DMA (git-fixes). - arm64: pgtable: Ensure dirty bit is preserved across pte_wrprotect() (bsc#1180130). - arm64: pgtable: Fix pte_accessible() (bsc#1180130). - bitmap: remove unused function declaration (git-fixes). - bnxt_en: Fix AER recovery (jsc#SLE-8371 bsc#1153274). - bpf: Do not leak memory in bpf getsockopt when optlen == 0 (bsc#1155518). - bpf: Fix helper bpf_map_peek_elem_proto pointing to wrong callback (bsc#1155518). - btrfs: fix missing delalloc new bit for new delalloc ranges (bsc#1180773). - btrfs: make btrfs_dirty_pages take btrfs_inode (bsc#1180773). - btrfs: make btrfs_set_extent_delalloc take btrfs_inode (bsc#1180773). - btrfs: send: fix invalid clone operations when cloning from the same file and root (bsc#1181511). - btrfs: send: fix wrong file path when there is an inode with a pending rmdir (bsc#1181237). - bus/fsl_mc: Do not rely on caller to provide non NULL mc_io (git-fixes). - cachefiles: Drop superfluous readpages aops NULL check (git-fixes). - can: dev: prevent potential information leak in can_fill_info() (git-fixes). - can: vxcan: vxcan_xmit: fix use after free bug (git-fixes). - clk: tegra30: Add hda clock default rates to clock driver (git-fixes). - crypto: asym_tpm: correct zero out potential secrets (git-fixes). - crypto: ecdh - avoid buffer overflow in ecdh_set_secret() (git-fixes). - dmaengine: at_hdmac: Substitute kzalloc with kmalloc (git-fixes). - dmaengine: at_hdmac: add missing kfree() call in at_dma_xlate() (git-fixes). - dmaengine: at_hdmac: add missing put_device() call in at_dma_xlate() (git-fixes). - dmaengine: dw-edma: Fix use after free in dw_edma_alloc_chunk() (git-fixes). - dmaengine: mediatek: mtk-hsdma: Fix a resource leak in the error handling path of the probe function (git-fixes). - dmaengine: xilinx_dma: check dma_async_device_register return value (git-fixes). - dmaengine: xilinx_dma: fix incompatible param warning in _child_probe() (git-fixes). - dmaengine: xilinx_dma: fix mixed_enum_type coverity warning (git-fixes). - drivers/base/memory.c: indicate all memory blocks as removable (bsc#1180264). - drivers/perf: Fix kernel panic when rmmod PMU modules during perf sampling (bsc#1180848). - drivers/perf: hisi: Permit modular builds of HiSilicon uncore drivers (bsc#1180848). - Update config files. - supported.conf: - drivers: soc: atmel: Avoid calling at91_soc_init on non AT91 SoCs (git-fixes). - drivers: soc: atmel: add null entry at the end of at91_soc_allowed_list[] (git-fixes). - drm/amd/display: Add missing pflip irq for dcn2.0 (git-fixes). - drm/amd/display: Avoid MST manager resource leak (git-fixes). - drm/amd/display: Do not double-buffer DTO adjustments (git-fixes). - drm/amd/display: Do not invoke kgdb_breakpoint() unconditionally (git-fixes). - drm/amd/display: Fix memleak in amdgpu_dm_mode_config_init (git-fixes). - drm/amd/display: Free gamma after calculating legacy transfer function (git-fixes). - drm/amd/display: HDMI remote sink need mode validation for Linux (git-fixes). - drm/amd/display: Increase timeout for DP Disable (git-fixes). - drm/amd/display: Reject overlay plane configurations in multi-display scenarios (git-fixes). - drm/amd/display: Retry AUX write when fail occurs (git-fixes). - drm/amd/display: Stop if retimer is not available (git-fixes). - drm/amd/display: dal_ddc_i2c_payloads_create can fail causing panic (git-fixes). - drm/amd/display: dchubbub p-state warning during surface planes switch (git-fixes). - drm/amd/display: remove useless if/else (git-fixes). - drm/amd/display: update nv1x stutter latencies (git-fixes). - drm/amd/pm: avoid false alarm due to confusing softwareshutdowntemp setting (git-fixes). - drm/amdgpu/dc: Require primary plane to be enabled whenever the CRTC is (git-fixes). - drm/amdgpu/powerplay/smu7: fix AVFS handling with custom powerplay table (git-fixes). - drm/amdgpu/powerplay: fix AVFS handling with custom powerplay table (git-fixes). - drm/amdgpu/psp: fix psp gfx ctrl cmds (git-fixes). - drm/amdgpu/sriov add amdgpu_amdkfd_pre_reset in gpu reset (git-fixes). - drm/amdgpu: Fix bug in reporting voltage for CIK (git-fixes). - drm/amdgpu: Fix bug where DPM is not enabled after hibernate and resume (git-fixes). - drm/amdgpu: add DID for navi10 blockchain SKU (git-fixes). - drm/amdgpu: correct the gpu reset handling for job != NULL case (git-fixes). - drm/amdgpu: do not map BO in reserved region (git-fixes). - drm/amdgpu: fix a GPU hang issue when remove device (git-fixes). - drm/amdgpu: fix build_coefficients() argument (git-fixes). - drm/amdgpu: fix calltrace during kmd unload(v3) (git-fixes). - drm/amdgpu: increase atombios cmd timeout (git-fixes). - drm/amdgpu: increase the reserved VM size to 2MB (git-fixes). - drm/amdgpu: perform srbm soft reset always on SDMA resume (git-fixes). - drm/amdgpu: prevent double kfree ttm-> sg (git-fixes). - drm/amdkfd: Fix leak in dmabuf import (git-fixes). - drm/amdkfd: Use same SQ prefetch setting as amdgpu (git-fixes). - drm/amdkfd: fix a memory leak issue (git-fixes). - drm/amdkfd: fix restore worker race condition (git-fixes). - drm/aspeed: Fix Kconfig warning & subsequent build errors (bsc#1152472) - drm/aspeed: Fix Kconfig warning & subsequent build errors (git-fixes). - drm/atomic: put state on error path (git-fixes). - drm/bridge/synopsys: dsi: add support for non-continuous HS clock (git-fixes). - drm/brige/megachips: Add checking if ge_b850v3_lvds_init() is working correctly (git-fixes). - drm/dp_aux_dev: check aux_dev before use in (bsc#1152472) - drm/dp_aux_dev: check aux_dev before use in drm_dp_aux_dev_get_by_minor() (git-fixes). - drm/etnaviv: always start/stop scheduler in timeout processing (git-fixes). - drm/exynos: dsi: Remove bridge node reference in error handling path in probe function (git-fixes). - drm/gma500: Fix out-of-bounds access to struct drm_device.vblank[] (git-fixes). - drm/gma500: fix double free of gma_connector (bsc#1152472) - drm/gma500: fix double free of gma_connector (git-fixes). - drm/i915/display/dp: Compute the correct slice count for VDSC on DP (git-fixes). - drm/i915/dsi: Use unconditional msleep for the panel_on_delay when there is no reset-deassert MIPI-sequence (git-fixes). - drm/i915/gt: Declare gen9 has 64 mocs entries! (git-fixes). - drm/i915/gt: Delay execlist processing for tgl (git-fixes). - drm/i915/gt: Free stale request on destroying the virtual engine (git-fixes). - drm/i915/gt: Prevent use of engine-> wa_ctx after error (git-fixes). - drm/i915/gt: Program mocs:63 for cache eviction on gen9 (git-fixes). - drm/i915/gvt: Set ENHANCED_FRAME_CAP bit (git-fixes). - drm/i915/gvt: return error when failing to take the module reference (git-fixes). - drm/i915/selftests: Avoid passing a random 0 into ilog2 (git-fixes). - drm/i915: Avoid memory leak with more than 16 workarounds on a list (git-fixes). - drm/i915: Break up error capture compression loops with cond_resched() (git-fixes). - drm/i915: Check for all subplatform bits (git-fixes). - drm/i915: Correctly set SFC capability for video engines (bsc#1152489) - drm/i915: Drop runtime-pm assert from vgpu io accessors (git-fixes). - drm/i915: Filter wake_flags passed to default_wake_function (git-fixes). - drm/i915: Fix mismatch between misplaced vma check and vma insert (git-fixes). - drm/i915: Force VT'd workarounds when running as a guest OS (git-fixes). - drm/i915: Handle max_bpc==16 (git-fixes). - drm/i915: clear the gpu reloc batch (git-fixes). - drm/mcde: Fix handling of platform_get_irq() error (bsc#1152472) - drm/mcde: Fix handling of platform_get_irq() error (git-fixes). - drm/meson:dw-hdmi: Register a callback to disable the regulator (git-fixes). - drm/msm/a5xx: Always set an OPP supported hardware value (git-fixes). - drm/msm/a6xx: fix a potential overflow issue (git-fixes). - drm/msm/a6xx: fix gmu start on newer firmware (git-fixes). - drm/msm/dpu: Add newline to printks (git-fixes). - drm/msm/dpu: Fix scale params in plane validation (git-fixes). - drm/msm/dsi_phy_10nm: implement PHY disabling (git-fixes). - drm/msm/dsi_pll_10nm: restore VCO rate during restore_state (git-fixes). - drm/msm: Disable preemption on all 5xx targets (git-fixes). - drm/msm: add shutdown support for display platform_driver (git-fixes). - drm/msm: fix leaks if initialization fails (git-fixes). - drm/nouveau/bios: fix issue shadowing expansion ROMs (git-fixes). - drm/nouveau/debugfs: fix runtime pm imbalance on error (git-fixes). - drm/nouveau/dispnv50: fix runtime pm imbalance on error (git-fixes). - drm/nouveau/i2c/gm200: increase width of aux semaphore owner fields (git-fixes). - drm/nouveau/kms/nv50-: fix case where notifier buffer is at offset 0 (git-fixes). - drm/nouveau/mem: guard against NULL pointer access in mem_del (git-fixes). - drm/nouveau/mmu: fix vram heap sizing (git-fixes). - drm/nouveau/nouveau: fix the start/end range for migration (git-fixes). - drm/nouveau/privring: ack interrupts the same way as RM (git-fixes). - drm/nouveau/svm: fail NOUVEAU_SVM_INIT ioctl on unsupported devices (git-fixes). - drm/nouveau: fix runtime pm imbalance on error (git-fixes). - drm/omap: dmm_tiler: fix return error code in omap_dmm_probe() (git-fixes). - drm/omap: dss: Cleanup DSS ports on initialisation failure (git-fixes). - drm/omap: fix incorrect lock state (git-fixes). - drm/omap: fix possible object reference leak (git-fixes). - drm/panfrost: add amlogic reset quirk callback (git-fixes). - drm/rockchip: Avoid uninitialized use of endpoint id in LVDS (bsc#1152472) - drm/rockchip: Avoiduninitialized use of endpoint id in LVDS (git-fixes). - drm/scheduler: Avoid accessing freed bad job (git-fixes). - drm/sun4i: dw-hdmi: fix error return code in sun8i_dw_hdmi_bind() (bsc#1152472) - drm/sun4i: frontend: Fix the scaler phase on A33 (git-fixes). - drm/sun4i: frontend: Reuse the ch0 phase for RGB formats (git-fixes). - drm/sun4i: frontend: Rework a bit the phase data (git-fixes). - drm/sun4i: mixer: Extend regmap max_register (git-fixes). - drm/syncobj: Fix use-after-free (git-fixes). - drm/tegra: replace idr_init() by idr_init_base() (git-fixes). - drm/tegra: sor: Disable clocks on error in tegra_sor_init() (git-fixes). - drm/ttm: fix eviction valuable range check (git-fixes). - drm/tve200: Fix handling of platform_get_irq() error (bsc#1152472) - drm/tve200: Fix handling of platform_get_irq() error (git-fixes). - drm/tve200: Stabilize enable/disable (git-fixes). - drm/vc4: drv: Add error handding for bind (git-fixes). - drm: Added orientation quirk for ASUS tablet model T103HAF (git-fixes). - drm: bridge: dw-hdmi: Avoid resetting force in the detect function (bsc#1152472) - drm: rcar-du: Set primary plane zpos immutably at initializing (git-fixes). - e1000e: bump up timeout to wait when ME un-configures ULP mode (jsc#SLE-8100). - ehci: fix EHCI host controller initialization sequence (git-fixes). - ethernet: ucc_geth: fix use-after-free in ucc_geth_remove() (git-fixes). - exec: Always set cap_ambient in cap_bprm_set_creds (git-fixes). - exfat: Avoid allocating upcase table using kcalloc() (git-fixes). - firmware: imx: select SOC_BUS to fix firmware build (git-fixes). - floppy: reintroduce O_NDELAY fix (boo#1181018). - futex: Ensure the correct return value from futex_lock_pi() (bsc#1181349 bsc#1149032). - futex: Handle faults correctly for PI futexes (bsc#1181349 bsc#1149032). - futex: Provide and use pi_state_update_owner() (bsc#1181349 bsc#1149032). - futex: Remove needless goto's(bsc#1149032). - futex: Remove unused empty compat_exit_robust_list() (bsc#1149032). - futex: Replace pointless printk in fixup_owner() (bsc#1181349 bsc#1149032). - futex: Simplify fixup_pi_state_owner() (bsc#1181349 bsc#1149032). - futex: Use pi_state_update_owner() in put_pi_state() (bsc#1181349 bsc#1149032). - hwmon: (pwm-fan) Ensure that calculation does not discard big period values (git-fixes). - i2c: bpmp-tegra: Ignore unknown I2C_M flags (git-fixes). - i2c: i801: Fix the i2c-mux gpiod_lookup_table not being properly terminated (git-fixes). - i2c: octeon: check correct size of maximum RECV_LEN packet (git-fixes). - i2c: sprd: use a specific timeout to avoid system hang up issue (git-fixes). - i3c master: fix missing destroy_workqueue() on error in i3c_master_register (git-fixes). - ice, xsk: clear the status bits for the next_to_use descriptor (jsc#SLE-7926). - ice: avoid premature Rx buffer reuse (jsc#SLE-7926). - iio: ad5504: Fix setting power-down state (git-fixes). - iomap: fix WARN_ON_ONCE() from unprivileged users (bsc#1181494). - iommu/vt-d: Fix a bug for PDP check in prq_event_thread (bsc#1181217). - ionic: account for vlan tag len in rx buffer len (bsc#1167773). - iwlwifi: pcie: reschedule in long-running memory reads (git-fixes). - iwlwifi: pcie: use jiffies for memory read spin time limit (git-fixes). - kABI fixup for dwc3 introduction of DWC_usb32 (git-fixes). - kABI: Fix kABI after AMD SEV PCID fixes (bsc#1178995). - kdb: Fix pager search for multi-line strings (git-fixes). - kgdb: Drop malformed kernel doc comment (git-fixes). - kprobes: tracing/kprobes: Fix to kill kprobes on initmem after boot (git fixes (kernel/kprobe)). - leds: trigger: fix potential deadlock with libata (git-fixes). - lib/genalloc: fix the overflow when size is too big (git-fixes). - lib/string: remove unnecessary #undefs (git-fixes). - lockd: do not use interval-based rebinding over TCP (for-next). - mac80211: check if atf has been disabled in __ieee80211_schedule_txq (git-fixes). - mac80211: do not drop tx nulldata packets on encrypted links (git-fixes). - mac80211: pause TX while changing interface type (git-fixes). - md: fix a warning caused by a race between concurrent md_ioctl()s (for-next). - media: dvb-usb: Fix memory leak at error in dvb_usb_device_init() (bsc#1181104). - media: dvb-usb: Fix use-after-free access (bsc#1181104). - media: gp8psk: initialize stats at power control logic (git-fixes). - media: rc: ensure that uevent can be read directly after rc device register (git-fixes). - misc: vmw_vmci: fix kernel info-leak by initializing dbells in vmci_ctx_get_chkpt_doorbells() (git-fixes). - misdn: dsp: select CONFIG_BITREVERSE (git-fixes). - mm/vmalloc: Fix unlock order in s_stop() (git fixes (mm/vmalloc)). - mm: memcontrol: fix missing wakeup polling thread (bsc#1181584). - mmc: core: do not initialize block size from ext_csd if not present (git-fixes). - mmc: sdhci-xenon: fix 1.8v regulator stabilization (git-fixes). - module: delay kobject uevent until after module init call (bsc#1178631). - mt7601u: fix kernel crash unplugging the device (git-fixes). - mt7601u: fix rx buffer refcounting (git-fixes). - net/af_iucv: fix null pointer dereference on shutdown (bsc#1179567 LTC#190111). - net/af_iucv: set correct sk_protocol for child sockets (git-fixes). - net/mlx5e: ethtool, Fix restriction of autoneg with 56G (jsc#SLE-8464). - net/smc: cancel event worker during device removal (git-fixes). - net/smc: check for valid ib_client_data (git-fixes). - net/smc: fix cleanup for linkgroup setup failures (git-fixes). - net/smc: fix direct access to ib_gid_addr-> ndev in smc_ib_determine_gid() (git-fixes). - net/smc: fix dmb buffer shortage (git-fixes). - net/smc: fix sleep bug in smc_pnet_find_roce_resource() (git-fixes). - net/smc: fix sock refcounting in case of termination(git-fixes). - net/smc: fix valid DMBE buffer sizes (git-fixes). - net/smc: no peer ID in CLC decline for SMCD (git-fixes). - net/smc: remove freed buffer from list (git-fixes). - net/smc: reset sndbuf_desc if freed (git-fixes). - net/smc: set rx_off for SMCR explicitly (git-fixes). - net/smc: switch smcd_dev_list spinlock to mutex (git-fixes). - net/smc: transfer fasync_list in case of fallback (git-fixes). - net: fix proc_fs init handling in af_packet and tls (bsc#1154353). - net: hns3: fix a phy loopback fail issue (bsc#1154353). - net: hns3: remove a misused pragma packed (bsc#1154353). - net: mscc: ocelot: allow offloading of bridge on top of LAG (git-fixes). - net: sunrpc: Fix 'snprintf' return value check in 'do_xprt_debugfs' (for-next). - net: sunrpc: interpret the return value of kstrtou32 correctly (for-next). - net: usb: qmi_wwan: add Quectel EM160R-GL (git-fixes). - net: usb: qmi_wwan: added support for Thales Cinterion PLSx3 modem family (git-fixes). - net: vlan: avoid leaks on register_vlan_dev() failures (bsc#1154353). - nfs_common: need lock during iterate through the list (for-next). - nfsd4: readdirplus shouldn't return parent of export (git-fixes). - nfsd: Fix message level for normal termination (for-next). - nvme-multipath: Early exit if no path is available (bsc#1180964). - nvme-multipath: fix bogus request queue reference put (bsc#1175389). - nvme-rdma: avoid request double completion for concurrent nvme_rdma_timeout (bsc#1181161). - nvme-tcp: avoid request double completion for concurrent nvme_tcp_timeout (bsc#1181161). - pNFS: Mark layout for return if return-on-close was not sent (git-fixes). - platform/x86: i2c-multi-instantiate: Do not create platform device for INT3515 ACPI nodes (git-fixes). - platform/x86: ideapad-laptop: Disable touchpad_switch for ELAN0634 (git-fixes). - platform/x86: intel-vbtn: Drop HP Stream x360 Convertible PC 11 from allow-list(git-fixes). - platform/x86: intel-vbtn: Fix SW_TABLET_MODE always reporting 1 on some HP x360 models (git-fixes). - power: vexpress: add suppress_bind_attrs to true (git-fixes). - powerpc/mm/pkeys: Make pkey access check work on execute_only_key (bsc#1181544 ltc#191080 git-fixes). - powerpc/paravirt: Use is_kvm_guest() in vcpu_is_preempted() (bsc#1181148 ltc#190702). - powerpc/pkeys: Avoid using lockless page table walk (bsc#1181544 ltc#191080). - powerpc/pkeys: Check vma before returning key fault error to the user (bsc#1181544 ltc#191080). - powerpc: Fix build error in paravirt.h (bsc#1181148 ltc#190702). - powerpc: Refactor is_kvm_guest() declaration to new header (bsc#1181148 ltc#190702). - powerpc: Reintroduce is_kvm_guest() as a fast-path check (bsc#1181148 ltc#190702). - powerpc: Rename is_kvm_guest() to check_kvm_guest() (bsc#1181148 ltc#190702). - prom_init: enable verbose prints (bsc#1178142 bsc#1180759). - ptrace: Set PF_SUPERPRIV when checking capability (bsc#1163930). - ptrace: reintroduce usage of subjective credentials in ptrace_has_cap() (bsc#1163930). - r8152: Add Lenovo Powered USB-C Travel Hub (git-fixes). - r8169: fix WoL on shutdown if CONFIG_DEBUG_SHIRQ is set (git-fixes). - r8169: work around power-saving bug on some chip versions (git-fixes). - regmap: debugfs: Fix a memory leak when calling regmap_attach_dev (git-fixes). - regmap: debugfs: Fix a reversed if statement in regmap_debugfs_init() (git-fixes). - rtc: pl031: fix resource leak in pl031_probe (git-fixes). - rtc: sun6i: Fix memleak in sun6i_rtc_clk_init (git-fixes). - rtmutex: Remove unused argument from rt_mutex_proxy_unlock() (bsc#1181349 bsc#1149032). - s390/cio: fix use-after-free in ccw_device_destroy_console (git-fixes). - s390/dasd: fix hanging device offline processing (bsc#1181169 LTC#190914). - s390/dasd: fix list corruption of lcu list (git-fixes). - s390/dasd: fix list corruptionof pavgroup group list (git-fixes). - s390/dasd: prevent inconsistent LCU device data (git-fixes). - s390/kexec_file: fix diag308 subcode when loading crash kernel (git-fixes). - s390/qeth: consolidate online/offline code (git-fixes). - s390/qeth: do not raise NETDEV_REBOOT event from L3 offline path (git-fixes). - s390/qeth: fix L2 header access in qeth_l3_osa_features_check() (git-fixes). - s390/qeth: fix deadlock during recovery (git-fixes). - s390/qeth: fix locking for discipline setup / removal (git-fixes). - s390/smp: perform initial CPU reset also for SMT siblings (git-fixes). - s390/vfio-ap: No need to disable IRQ after queue reset (git-fixes). - s390/vfio-ap: clean up vfio_ap resources when KVM pointer invalidated (git-fixes). - sched/fair: Check for idle core in wake_affine (git fixes (sched)). - scsi: ibmvfc: Set default timeout to avoid crash during migration (bsc#1181425 ltc#188252). - scsi: lpfc: Enhancements to LOG_TRACE_EVENT for better readability (bsc#1180891). - scsi: lpfc: Fix FW reset action if I/Os are outstanding (bsc#1180891). - scsi: lpfc: Fix NVMe recovery after mailbox timeout (bsc#1180891). - scsi: lpfc: Fix PLOGI S_ID of 0 on pt2pt config (bsc#1180891). - scsi: lpfc: Fix auto sli_mode and its effect on CONFIG_PORT for SLI3 (bsc#1180891). - scsi: lpfc: Fix crash when a fabric node is released prematurely (bsc#1180891). - scsi: lpfc: Fix crash when nvmet transport calls host_release (bsc#1180891). - scsi: lpfc: Fix error log messages being logged following SCSI task mgnt (bsc#1180891). - scsi: lpfc: Fix target reset failing (bsc#1180891). - scsi: lpfc: Fix vport create logging (bsc#1180891). - scsi: lpfc: Implement health checking when aborting I/O (bsc#1180891). - scsi: lpfc: Prevent duplicate requests to unregister with cpuhp framework (bsc#1180891). - scsi: lpfc: Refresh ndlp when a new PRLI is received in the PRLI issue state (bsc#1180891). -scsi: lpfc: Simplify bool comparison (bsc#1180891). - scsi: lpfc: Update lpfc version to 12.8.0.7 (bsc#1180891). - scsi: lpfc: Use the nvme-fc transport supplied timeout for LS requests (bsc#1180891). - scsi: qla2xxx: Fix description for parameter ql2xenforce_iocb_limit (bsc#1179142). - scsi: scsi_transport_srp: Do not block target in failfast state (bsc#1172355). - selftests/ftrace: Select an existing function in kprobe_eventname test (bsc#1179396 ltc#185738). - selftests/powerpc: Add a test of bad (out-of-range) accesses (bsc#1181158 ltc#190851). - selftests/powerpc: Add a test of spectre_v2 mitigations (bsc#1181158 ltc#190851). - selftests/powerpc: Ignore generated files (bsc#1181158 ltc#190851). - selftests/powerpc: Move Hash MMU check to utilities (bsc#1181158 ltc#190851). - selftests/powerpc: Move set_dscr() into rfi_flush.c (bsc#1181158 ltc#190851). - selftests/powerpc: Only test lwm/stmw on big endian (bsc#1180412 ltc#190579). - selftests/powerpc: spectre_v2 test must be built 64-bit (bsc#1181158 ltc#190851). - selftests: net: fib_tests: remove duplicate log test (git-fixes). - serial: mvebu-uart: fix tx lost characters at power off (git-fixes). - spi: cadence: cache reference clock rate during probe (git-fixes). - spi: stm32: FIFO threshold level - fix align packet size (git-fixes). - staging: mt7621-dma: Fix a resource leak in an error handling path (git-fixes). - staging: wlan-ng: fix out of bounds read in prism2sta_probe_usb() (git-fixes). - sunrpc: fix xs_read_xdr_buf for partial pages receive (for-next). - swiotlb: fix "x86: Do not panic if can not alloc buffer for swiotlb" (git-fixes). - swiotlb: using SIZE_MAX needs limits.h included (git-fixes). - timers: Preserve higher bits of expiration on index calculation (bsc#1181318). - timers: Use only bucket expiry for base-> next_expiry value (bsc#1181318). - udp: Prevent reuseport_select_sock from readinguninitialized socks (git-fixes). - usb: chipidea: ci_hdrc_imx: add missing put_device() call in usbmisc_get_init_data() (git-fixes). - usb: dwc3: Add support for DWC_usb32 IP (git-fixes). - usb: dwc3: Update soft-reset wait polling rate (git-fixes). - usb: dwc3: core: Properly default unspecified speed (git-fixes). - usb: dwc3: ulpi: Use VStsDone to detect PHY regs access completion (git-fixes). - usb: gadget: Fix spinlock lockup on usb_function_deactivate (git-fixes). - usb: gadget: aspeed: fix stop dma register setting (git-fixes). - usb: gadget: configfs: Fix use-after-free issue with udc_name (git-fixes). - usb: gadget: configfs: Preserve function ordering after bind failure (git-fixes). - usb: gadget: enable super speed plus (git-fixes). - usb: gadget: f_uac2: reset wMaxPacketSize (git-fixes). - usb: gadget: function: printer: Fix a memory leak for interface descriptor (git-fixes). - usb: gadget: select CONFIG_CRC32 (git-fixes). - usb: gadget: u_ether: Fix MTU size mismatch with RX packet size (git-fixes). - usb: typec: Fix copy paste error for NVIDIA alt-mode description (git-fixes). - usb: uas: Add PNY USB Portable SSD to unusual_uas (git-fixes). - usb: udc: core: Use lock when write to soft_connect (git-fixes). - usb: usbip: vhci_hcd: protect shift size (git-fixes). - vfio iommu: Add dma available capability (bsc#1179572 LTC#190110). - vfio-pci: Use io_remap_pfn_range() for PCI IO memory (bsc#1181220). - vfio/pci: Implement ioeventfd thread handler for contended memory lock (bsc#1181219). - video: fbdev: atmel_lcdfb: fix return error code in atmel_lcdfb_of_init() (git-fixes). - video: fbdev: fix OOB read in vga_8planes_imageblit() (git-fixes). - video: fbdev: pvr2fb: initialize variables (git-fixes). - video: fbdev: vga16fb: fix setting of pixclock because a pass-by-value error (git-fixes). - wan: ds26522: select CONFIG_BITREVERSE (git-fixes). - wext: fixNULL-ptr-dereference with cfg80211's lack of commit() (git-fixes). - wil6210: select CONFIG_CRC32 (git-fixes). - x86/apic: Fix x2apic enablement without interrupt remapping (bsc#1152489). - x86/cpu/amd: Call init_amd_zn() om Family 19h processors too (bsc#1181077). - x86/cpu/amd: Set __max_die_per_package on AMD (bsc#1152489). - x86/hyperv: Fix kexec panic/hang issues (bsc#1176831). - x86/kprobes: Restore BTF if the single-stepping is cancelled (bsc#1152489). - x86/mm/numa: Remove uninitialized_var() usage (bsc#1152489). - x86/mm: Fix leak of pmd ptlock (bsc#1152489). - x86/mtrr: Correct the range check before performing MTRR type lookups (bsc#1152489). - x86/resctrl: Do not move a task to the same resource group (bsc#1152489). - x86/resctrl: Use an IPI instead of task_work_add() to update PQR_ASSOC MSR (bsc#1152489). - x86/topology: Make __max_die_per_package available unconditionally (bsc#1152489). - x86/xen: avoid warning in Xen pv guest with CONFIG_AMD_MEM_ENCRYPT enabled (bsc#1181335). - xen-blkfront: allow discard-* nodes to be optional (bsc#1181346). - xen/privcmd: allow fetching resource sizes (bsc#1065600). - xfs: show the proper user quota options (bsc#1181538). - xhci: Give USB2 ports time to enter U3 in bus suspend (git-fixes). - xhci: make sure TRB is fully written before giving it to the controller (git-fixes). - xhci: tegra: Delay for disabling LFPS detector (git-fixes). Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Realtime 15-SP2: zypper in -t patch SUSE-SLE-Module-RT-15-SP2-2021-427=1 Package List: - SUSE Linux Enterprise Module for Realtime 15-SP2 (noarch): kernel-devel-rt-5.3.18-25.1 kernel-source-rt-5.3.18-25.1 - SUSE Linux Enterprise Module for Realtime 15-SP2 (x86_64): cluster-md-kmp-rt-5.3.18-25.1 cluster-md-kmp-rt-debuginfo-5.3.18-25.1 dlm-kmp-rt-5.3.18-25.1 dlm-kmp-rt-debuginfo-5.3.18-25.1 gfs2-kmp-rt-5.3.18-25.1 gfs2-kmp-rt-debuginfo-5.3.18-25.1 kernel-rt-5.3.18-25.1 kernel-rt-debuginfo-5.3.18-25.1 kernel-rt-debugsource-5.3.18-25.1 kernel-rt-devel-5.3.18-25.1 kernel-rt-devel-debuginfo-5.3.18-25.1 kernel-rt_debug-debuginfo-5.3.18-25.1 kernel-rt_debug-debugsource-5.3.18-25.1 kernel-rt_debug-devel-5.3.18-25.1 kernel-rt_debug-devel-debuginfo-5.3.18-25.1 kernel-syms-rt-5.3.18-25.1 ocfs2-kmp-rt-5.3.18-25.1 ocfs2-kmp-rt-debuginfo-5.3.18-25.1 References: https://www.suse.com/security/cve/CVE-2020-25211.html https://www.suse.com/security/cve/CVE-2020-25639.html https://www.suse.com/security/cve/CVE-2020-27835.html https://www.suse.com/security/cve/CVE-2020-28374.html https://www.suse.com/security/cve/CVE-2020-29568.html https://www.suse.com/security/cve/CVE-2020-29569.html https://www.suse.com/security/cve/CVE-2021-0342.html https://www.suse.com/security/cve/CVE-2021-20177.html https://www.suse.com/security/cve/CVE-2021-3347.html https://www.suse.com/security/cve/CVE-2021-3348.html https://bugzilla.suse.com/1065600 https://bugzilla.suse.com/1149032 https://bugzilla.suse.com/1152472 https://bugzilla.suse.com/1152489 https://bugzilla.suse.com/1153274 https://bugzilla.suse.com/1154353 https://bugzilla.suse.com/1155518 https://bugzilla.suse.com/1163930 https://bugzilla.suse.com/1165545 https://bugzilla.suse.com/1167773 https://bugzilla.suse.com/1172355 https://bugzilla.suse.com/1175389 https://bugzilla.suse.com/1176395 https://bugzilla.suse.com/1176831 https://bugzilla.suse.com/1176846 https://bugzilla.suse.com/1178142 https://bugzilla.suse.com/1178372 https://bugzilla.suse.com/1178631 https://bugzilla.suse.com/1178684 https://bugzilla.suse.com/1178995 https://bugzilla.suse.com/1179142 https://bugzilla.suse.com/1179396 https://bugzilla.suse.com/1179508 https://bugzilla.suse.com/1179509 https://bugzilla.suse.com/1179567 https://bugzilla.suse.com/1179572 https://bugzilla.suse.com/1179575 https://bugzilla.suse.com/1179878 https://bugzilla.suse.com/1180008 https://bugzilla.suse.com/1180130 https://bugzilla.suse.com/1180264 https://bugzilla.suse.com/1180412 https://bugzilla.suse.com/1180676 https://bugzilla.suse.com/1180759 https://bugzilla.suse.com/1180765 https://bugzilla.suse.com/1180773 https://bugzilla.suse.com/1180809 https://bugzilla.suse.com/1180812 https://bugzilla.suse.com/1180848 https://bugzilla.suse.com/1180859 https://bugzilla.suse.com/1180889 https://bugzilla.suse.com/1180891 https://bugzilla.suse.com/1180964 https://bugzilla.suse.com/1180971 https://bugzilla.suse.com/1181014 https://bugzilla.suse.com/1181018 https://bugzilla.suse.com/1181077 https://bugzilla.suse.com/1181104 https://bugzilla.suse.com/1181148 https://bugzilla.suse.com/1181158 https://bugzilla.suse.com/1181161 https://bugzilla.suse.com/1181169 https://bugzilla.suse.com/1181203 https://bugzilla.suse.com/1181217 https://bugzilla.suse.com/1181218 https://bugzilla.suse.com/1181219 https://bugzilla.suse.com/1181220 https://bugzilla.suse.com/1181237 https://bugzilla.suse.com/1181318 https://bugzilla.suse.com/1181335 https://bugzilla.suse.com/1181346 https://bugzilla.suse.com/1181349 https://bugzilla.suse.com/1181425 https://bugzilla.suse.com/1181494 https://bugzilla.suse.com/1181504 https://bugzilla.suse.com/1181511 https://bugzilla.suse.com/1181538 https://bugzilla.suse.com/1181544 https://bugzilla.suse.com/1181553 https://bugzilla.suse.com/1181584 https://bugzilla.suse.com/1181645 . Red Hat's recent patches tackle 12 flaws withinthe OpenStack framework, enhancing both application reliability and security measures.. SUSE Linux Kernel Update, Security Patch, Local Exploits, System Security, Kernel Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves 11 vulnerabilities and has 62 fixes is now available. . SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2904-1 Rating: important References: #1055186 #1065600 #1065729 #1094244 #1112178 #1113956 #1154366 #1163524 #1167527 #1168468 #1169972 #1171675 #1171688 #1171742 #1173115 #1174354 #1174899 #1175228 #1175528 #1175716 #1175749 #1175882 #1176011 #1176022 #1176038 #1176235 #1176242 #1176278 #1176316 #1176317 #1176318 #1176319 #1176320 #1176321 #1176381 #1176423 #1176482 #1176507 #1176536 #1176544 #1176545 #1176546 #1176548 #1176659 #1176698 #1176699 #1176700 #1176721 #1176722 #1176725 #1176732 #1176788 #1176789 #1176869 #1176877 #1176935 #1176950 #1176962 #1176966 #1176990 #1177030 #1177041 #1177042 #1177043 #1177044 #1177121 #1177206 #1177258 #1177291 #1177293 #1177294 #1177295 #1177296 Cross-References: CVE-2020-0404 CVE-2020-0427 CVE-2020-0431 CVE-2020-0432 CVE-2020-14381 CVE-2020-14390 CVE-2020-25212 CVE-2020-25284 CVE-2020-25641 CVE-2020-25643 CVE-2020-26088 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Live Patching 12-SP5 SUSE Linux Enterprise High Availability 12-SP5 ______________________________________________________________________________ An update that solves 11 vulnerabilities and has 62 fixes is now available. Description: The SUSELinux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990). - CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235). - CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721). - CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725). - CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722). - CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423). - CVE-2020-25212: Fixed getxattr kernel panic and memory overflow (bsc#1176381). - CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482). - CVE-2020-14381: Fixed requeue paths such that filp was valid when dropping the references (bsc#1176011). - CVE-2019-25643: Fixed an improper input validation in ppp_cp_parse_cr function which could have led to memory corruption and read overflow (bsc#1177206). - CVE-2020-25641: Fixed ann issue where length bvec was causing softlockups (bsc#1177121). The following non-security bugs were fixed: - 9p: Fix memory leak in v9fs_mount (git-fixes). - ACPI: EC: Reference count query handlers under lock (git-fixes). - airo: Add missing CAP_NET_ADMIN check in AIROOLDIOCTL/SIOCDEVPRIVATE (git-fixes). - airo: Fix possible info leak in AIROOLDIOCTL/SIOCDEVPRIVATE (git-fixes). - airo: Fix read overflows sending packets (git-fixes). - ALSA: asihpi: fix iounmap in error handler (git-fixes). - ALSA: firewire-digi00x: excludeAvid Adrenaline from detection (git-fixes). - ALSA: firewire-tascam: exclude Tascam FE-8 from detection (git-fixes). - ALSA: hda: Fix 2 channel swapping for Tegra (git-fixes). - ALSA: hda: fix a runtime pm issue in SOF when integrated GPU is disabled (git-fixes). - ALSA: hda/realtek: Add quirk for Samsung Galaxy Book Ion NT950XCJ-X716A (git-fixes). - ALSA: hda/realtek - Improved routing for Thinkpad X1 7th/8th Gen (git-fixes). - altera-stapl: altera_get_note: prevent write beyond end of 'key' (git-fixes). - ar5523: Add USB ID of SMCWUSBT-G2 wireless adapter (git-fixes). - arm64: KVM: Do not generate UNDEF when LORegion feature is present (jsc#SLE-4084). - arm64: KVM: regmap: Fix unexpected switch fall-through (jsc#SLE-4084). - asm-generic: fix -Wtype-limits compiler warnings (bsc#1112178). - ASoC: kirkwood: fix IRQ error handling (git-fixes). - ASoC: tegra: Fix reference count leaks (git-fixes). - ath10k: fix array out-of-bounds access (git-fixes). - ath10k: fix memory leak for tpc_stats_final (git-fixes). - ath10k: use kzalloc to read for ath10k_sdio_hif_diag_read (git-fixes). - batman-adv: Add missing include for in_interrupt() (git-fixes). - batman-adv: Avoid uninitialized chaddr when handling DHCP (git-fixes). - batman-adv: bla: fix type misuse for backbone_gw hash indexing (git-fixes). - batman-adv: bla: use netif_rx_ni when not in interrupt context (git-fixes). - batman-adv: mcast: fix duplicate mcast packets in BLA backbone from mesh (git-fixes). - batman-adv: mcast/TT: fix wrongly dropped or rerouted packets (git-fixes). - bcache: Convert pr_ uses to a more typical style (git fixes (block drivers)). - bcache: fix overflow in offset_to_stripe() (git fixes (block drivers)). - bcm63xx_enet: correct clock usage (git-fixes). - bcm63xx_enet: do not write to random DMA channel on BCM6345 (git-fixes). - bitfield.h: do not compile-time validate _val in FIELD_FIT (git fixes (bitfield)). - blktrace: fix debugfs use after free (git fixes (block drivers)). - block: add docs for gendisk / request_queue refcount helpers (git fixes (block drivers)). - block: revert back to synchronous request_queue removal (git fixes (block drivers)). - block: Use non _rcu version of list functions for tag_set_list (git-fixes). - Bluetooth: Fix refcount use-after-free issue (git-fixes). - Bluetooth: guard against controllers sending zero'd events (git-fixes). - Bluetooth: Handle Inquiry Cancel error after Inquiry Complete (git-fixes). - Bluetooth: L2CAP: handle l2cap config request during open state (git-fixes). - Bluetooth: prefetch channel before killing sock (git-fixes). - bnxt_en: Fix completion ring sizing with TPA enabled (networking-stable-20_07_29). - bonding: use nla_get_u64 to extract the value for IFLA_BOND_AD_ACTOR_SYSTEM (git-fixes). - btrfs: avoid possible signal interruption of btrfs_drop_snapshot() on relocation tree (bsc#1174354). - btrfs: balance: print to system log when balance ends or is paused (bsc#1174354). - btrfs: relocation: allow signal to cancel balance (bsc#1174354). - btrfs: relocation: review the call sites which can be interrupted by signal (bsc#1174354). - btrfs: require only sector size alignment for parent eb bytenr (bsc#1176789). - btrfs: take overcommit into account in inc_block_group_ro (bsc#1174354). - btrfs: tree-checker: fix the error message for transid error (bsc#1176788). - ceph: do not allow setlease on cephfs (bsc#1177041). - ceph: fix potential mdsc use-after-free crash (bsc#1177042). - ceph: fix use-after-free for fsc-> mdsc (bsc#1177043). - ceph: handle zero-length feature mask in session messages (bsc#1177044). - cfg80211: regulatory: reject invalid hints (bsc#1176699). - cifs: Fix leak when handling lease break for cached root fid (bsc#1176242). - cifs/smb3: Fix data inconsistent when punch hole (bsc#1176544). -cifs/smb3: Fix data inconsistent when zero file range (bsc#1176536). - clk: Add (devm_)clk_get_optional() functions (git-fixes). - clk: rockchip: Fix initialization of mux_pll_src_4plls_p (git-fixes). - clk: samsung: exynos4: mark 'chipid' clock as CLK_IGNORE_UNUSED (git-fixes). - clk/ti/adpll: allocate room for terminating null (git-fixes). - clocksource/drivers/h8300_timer8: Fix wrong return value in h8300_8timer_init() (git-fixes). - cpufreq: intel_pstate: Fix EPP setting via sysfs in active mode (bsc#1176966). - crypto: dh - check validity of Z before export (bsc#1175716). - crypto: dh - SP800-56A rev 3 local public key validation (bsc#1175716). - crypto: ecc - SP800-56A rev 3 local public key validation (bsc#1175716). - crypto: ecdh - check validity of Z before export (bsc#1175716). - dmaengine: at_hdmac: check return value of of_find_device_by_node() in at_dma_xlate() (git-fixes). - dmaengine: of-dma: Fix of_dma_router_xlate's of_dma_xlate handling (git-fixes). - dmaengine: pl330: Fix burst length if burst size is smaller than bus width (git-fixes). - dmaengine: tegra-apb: Prevent race conditions on channel's freeing (git-fixes). - dmaengine: zynqmp_dma: fix burst length configuration (git-fixes). - dm crypt: avoid truncating the logical block size (git fixes (block drivers)). - dm: fix redundant IO accounting for bios that need splitting (git fixes (block drivers)). - dm integrity: fix a deadlock due to offloading to an incorrect workqueue (git fixes (block drivers)). - dm integrity: fix integrity recalculation that is improperly skipped (git fixes (block drivers)). - dm: report suspended device during destroy (git fixes (block drivers)). - dm rq: do not call blk_mq_queue_stopped() in dm_stop_queue() (git fixes (block drivers)). - dm: use noio when sending kobject event (git fixes (block drivers)). - dm writecache: add cond_resched to loop in persistent_memory_claim() (gitfixes (block drivers)). - dm writecache: correct uncommitted_block when discarding uncommitted entry (git fixes (block drivers)). - dm zoned: assign max_io_len correctly (git fixes (block drivers)). - Drivers: char: tlclk.c: Avoid data race between init and interrupt handler (git-fixes). - Drivers: hv: Specify receive buffer size using Hyper-V page size (bsc#1176877). - Drivers: hv: vmbus: Add timeout to vmbus_wait_for_unload (git-fixes). - drivers/net/wan/x25_asy: Fix to make it work (networking-stable-20_07_29). - drm/amd/display: dal_ddc_i2c_payloads_create can fail causing panic (git-fixes). - drm/amd/display: fix ref count leak in amdgpu_drm_ioctl (git-fixes). - drm/amdgpu/display: fix ref count leak when pm_runtime_get_sync fails (git-fixes). - drm/amdgpu: Fix buffer overflow in INFO ioctl (git-fixes). - drm/amdgpu: Fix bug in reporting voltage for CIK (git-fixes). - drm/amdgpu: fix ref count leak in amdgpu_driver_open_kms (git-fixes). - drm/amdgpu: increase atombios cmd timeout (git-fixes). - drm/amdgpu/powerplay: fix AVFS handling with custom powerplay table (git-fixes). - drm/amdgpu/powerplay/smu7: fix AVFS handling with custom powerplay table (git-fixes). - drm/amdkfd: fix a memory leak issue (git-fixes). - drm/amdkfd: Fix reference count leaks (git-fixes). - drm/amd/pm: correct Vega10 swctf limit setting (git-fixes). - drm/amd/pm: correct Vega12 swctf limit setting (git-fixes). - drm/ast: Initialize DRAM type before posting GPU (bsc#1113956) * context changes - drm/mediatek: Add exception handing in mtk_drm_probe() if component init fail (git-fixes). - drm/mediatek: Add missing put_device() call in mtk_hdmi_dt_parse_pdata() (git-fixes). - drm/msm/a5xx: Always set an OPP supported hardware value (git-fixes). - drm/msm: add shutdown support for display platform_driver (git-fixes). - drm/msm: Disable preemption on all 5xx targets (git-fixes). - drm/msm: fix leaks ifinitialization fails (git-fixes). - drm/msm/gpu: make ringbuffer readonly (bsc#1112178) * context changes - drm/nouveau/debugfs: fix runtime pm imbalance on error (git-fixes). - drm/nouveau/dispnv50: fix runtime pm imbalance on error (git-fixes). - drm/nouveau/drm/noveau: fix reference count leak in nouveau_fbcon_open (git-fixes). - drm/nouveau: Fix reference count leak in nouveau_connector_detect (git-fixes). - drm/nouveau: fix reference count leak in nv50_disp_atomic_commit (git-fixes). - drm/nouveau: fix runtime pm imbalance on error (git-fixes). - drm/omap: fix possible object reference leak (git-fixes). - drm/radeon: fix multiple reference count leak (git-fixes). - drm/radeon: Prefer lower feedback dividers (git-fixes). - drm/radeon: revert "Prefer lower feedback dividers" (git-fixes). - drm/sun4i: Fix dsi dcs long write function (git-fixes). - drm/sun4i: sun8i-csc: Secondary CSC register correction (git-fixes). - drm/tve200: Stabilize enable/disable (git-fixes). - drm/vc4/vc4_hdmi: fill ASoC card owner (git-fixes). - e1000: Do not perform reset in reset_task if we are already down (git-fixes). - fbcon: prevent user font height or width change from causing (bsc#1112178) * move from drivers/video/fbdev/fbcon to drivers/video/console * context changes - Fix error in kabi fix for: NFSv4: Fix OPEN / CLOSE race (bsc#1176950). - ftrace: Move RCU is watching check after recursion check (git-fixes). - ftrace: Setup correct FTRACE_FL_REGS flags for module (git-fixes). - gma/gma500: fix a memory disclosure bug due to uninitialized bytes (git-fixes). - gpio: tc35894: fix up tc35894 interrupt configuration (git-fixes). - gtp: add missing gtp_encap_disable_sock() in gtp_encap_enable() (git-fixes). - gtp: fix Illegal context switch in RCU read-side critical section (git-fixes). - gtp: fix use-after-free in gtp_newlink() (git-fixes). - HID: hiddev: Fix slab-out-of-bounds write inhiddev_ioctl_usage() (git-fixes). - hsr: use netdev_err() instead of WARN_ONCE() (bsc#1176659). - hv_utils: drain the timesync packets on onchannelcallback (bsc#1176877). - hv_utils: return error if host timesysnc update is stale (bsc#1176877). - hwmon: (applesmc) check status earlier (git-fixes). - i2c: core: Do not fail PRP0001 enumeration when no ID table exist (git-fixes). - i2c: cpm: Fix i2c_ram structure (git-fixes). - ibmvnic: add missing parenthesis in do_reset() (bsc#1176700 ltc#188140). - ieee802154/adf7242: check status of adf7242_read_reg (git-fixes). - ieee802154: fix one possible memleak in ca8210_dev_com_init (git-fixes). - iio:accel:bmc150-accel: Fix timestamp alignment and prevent data leak (git-fixes). - iio: accel: kxsd9: Fix alignment of local buffer (git-fixes). - iio:accel:mma7455: Fix timestamp alignment and prevent data leak (git-fixes). - iio:adc:ina2xx Fix timestamp alignment issue (git-fixes). - iio: adc: mcp3422: fix locking on error path (git-fixes). - iio: adc: mcp3422: fix locking scope (git-fixes). - iio:adc:ti-adc081c Fix alignment and data leak issues (git-fixes). - iio: adc: ti-ads1015: fix conversion when CONFIG_PM is not set (git-fixes). - iio: improve IIO_CONCENTRATION channel type description (git-fixes). - iio:light:ltr501 Fix timestamp alignment issue (git-fixes). - iio:light:max44000 Fix timestamp alignment and prevent data leak (git-fixes). - iio:magnetometer:ak8975 Fix alignment and data leak issues (git-fixes). - include: add additional sizes (bsc#1094244 ltc#168122). - iommu/amd: Fix IOMMU AVIC not properly update the is_run bit in IRTE (bsc#1177293). - iommu/amd: Fix potential @entry null deref (bsc#1177294). - iommu/amd: Print extended features in one line to fix divergent log levels (bsc#1176316). - iommu/amd: Re-factor guest virtual APIC (de-)activation code (bsc#1177291). - iommu/amd: Restore IRTE.RemapEn bit after programming IRTE(bsc#1176317). - iommu/amd: Restore IRTE.RemapEn bit for amd_iommu_activate_guest_mode (bsc#1177295). - iommu/amd: Use cmpxchg_double() when updating 128-bit IRTE (bsc#1176318). - iommu/exynos: add missing put_device() call in exynos_iommu_of_xlate() (bsc#1177296). - iommu/omap: Check for failure of a call to omap_iommu_dump_ctx (bsc#1176319). - iommu/vt-d: Serialize IOMMU GCMD register modifications (bsc#1176320). - kernel-binary.spec.in: SLE12 tar does not understand --verbatim-files-from - kernel-syms.spec.in: Also use bz compression (boo#1175882). - KVM: arm64: Change 32-bit handling of VM system registers (jsc#SLE-4084). - KVM: arm64: Cleanup __activate_traps and __deactive_traps for VHE and non-VHE (jsc#SLE-4084). - KVM: arm64: Configure c15, PMU, and debug register traps on cpu load/put for VHE (jsc#SLE-4084). - KVM: arm64: Defer saving/restoring 32-bit sysregs to vcpu load/put (jsc#SLE-4084). - KVM: arm64: Defer saving/restoring 64-bit sysregs to vcpu load/put on VHE (jsc#SLE-4084). - KVM: arm64: Directly call VHE and non-VHE FPSIMD enabled functions (jsc#SLE-4084). - KVM: arm64: Do not deactivate VM on VHE systems (jsc#SLE-4084). - KVM: arm64: Do not save the host ELR_EL2 and SPSR_EL2 on VHE systems (jsc#SLE-4084). - KVM: arm64: Factor out fault info population and gic workarounds (jsc#SLE-4084). - KVM: arm64: Fix order of vcpu_write_sys_reg() arguments (jsc#SLE-4084). - KVM: arm64: Forbid kprobing of the VHE world-switch code (jsc#SLE-4084). - KVM: arm64: Improve debug register save/restore flow (jsc#SLE-4084). - KVM: arm64: Introduce framework for accessing deferred sysregs (jsc#SLE-4084). - KVM: arm64: Introduce separate VHE/non-VHE sysreg save/restore functions (jsc#SLE-4084). - KVM: arm64: Introduce VHE-specific kvm_vcpu_run (jsc#SLE-4084). - KVM: arm64: Move common VHE/non-VHE trap config in separate functions (jsc#SLE-4084). - KVM: arm64: Move debug dirtyflag calculation out of world switch (jsc#SLE-4084). - KVM: arm64: Move HCR_INT_OVERRIDE to default HCR_EL2 guest flag (jsc#SLE-4084). - KVM: arm64: Move userspace system registers into separate function (jsc#SLE-4084). - KVM: arm64: Prepare to handle deferred save/restore of 32-bit registers (jsc#SLE-4084). - KVM: arm64: Prepare to handle deferred save/restore of ELR_EL1 (jsc#SLE-4084). - KVM: arm64: Remove kern_hyp_va() use in VHE switch function (jsc#SLE-4084). - KVM: arm64: Remove noop calls to timer save/restore from VHE switch (jsc#SLE-4084). - KVM: arm64: Rework hyp_panic for VHE and non-VHE (jsc#SLE-4084). - KVM: arm64: Rewrite sysreg alternatives to static keys (jsc#SLE-4084). - KVM: arm64: Rewrite system register accessors to read/write functions (jsc#SLE-4084). - KVM: arm64: Slightly improve debug save/restore functions (jsc#SLE-4084). - KVM: arm64: Unify non-VHE host/guest sysreg save and restore functions (jsc#SLE-4084). - KVM: arm64: Write arch.mdcr_el2 changes since last vcpu_load on VHE (jsc#SLE-4084). - KVM: arm/arm64: Avoid vcpu_load for other vcpu ioctls than KVM_RUN (jsc#SLE-4084). - KVM: arm/arm64: Avoid VGICv3 save/restore on VHE with no IRQs (jsc#SLE-4084). - KVM: arm/arm64: Get rid of vcpu-> arch.irq_lines (jsc#SLE-4084). - KVM: arm/arm64: Handle VGICv3 save/restore from the main VGIC code on VHE (jsc#SLE-4084). - KVM: arm/arm64: Move vcpu_load call after kvm_vcpu_first_run_init (jsc#SLE-4084). - KVM: arm/arm64: Move VGIC APR save/restore to vgic put/load (jsc#SLE-4084). - KVM: arm/arm64: Prepare to handle deferred save/restore of SPSR_EL1 (jsc#SLE-4084). - KVM: arm/arm64: Remove leftover comment from kvm_vcpu_run_vhe (jsc#SLE-4084). - KVM: introduce kvm_arch_vcpu_async_ioctl (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_get_fpu (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specifickvm_arch_vcpu_ioctl_get_mpstate (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_get_regs (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_run (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_set_fpu (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_set_guest_debug (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_set_mpstate (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_set_regs (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_set_sregs (jsc#SLE-4084). - KVM: Move vcpu_load to arch-specific kvm_arch_vcpu_ioctl_translate (jsc#SLE-4084). - KVM: PPC: Fix compile error that occurs when CONFIG_ALTIVEC=n (jsc#SLE-4084). - KVM: Prepare for moving vcpu_load/vcpu_put into arch specific code (jsc#SLE-4084). - KVM: SVM: Add a dedicated INVD intercept routine (bsc#1112178). - KVM: SVM: Fix disable pause loop exit/pause filtering capability on SVM (bsc#1176321). - KVM: Take vcpu-> mutex outside vcpu_load (jsc#SLE-4084). - libceph: allow setting abort_on_full for rbd (bsc#1169972). - lib/mpi: Add mpi_sub_ui() (bsc#1175716). - libnvdimm: cover up nvdimm_security_ops changes (bsc#1171742). - libnvdimm: cover up struct nvdimm changes (bsc#1171742). - libnvdimm/security, acpi/nfit: unify zero-key for all security commands (bsc#1171742). - libnvdimm/security: fix a typo (bsc#1171742 bsc#1167527). - libnvdimm/security: Introduce a 'frozen' attribute (bsc#1171742). - lib/raid6: use vdupq_n_u8 to avoid endianness warnings (git fixes (block drivers)). - mac802154: tx: fix use-after-free (git-fixes). - md: raid0/linear: fix dereference before null check on pointer mddev (git fixes (block drivers)). - media: davinci: vpif_capture: fixpotential double free (git-fixes). - media: pci: ttpci: av7110: fix possible buffer overflow caused by bad DMA value in debiirq() (git-fixes). - media: smiapp: Fix error handling at NVM reading (git-fixes). - media: ti-vpe: cal: Restrict DMA to avoid memory corruption (git-fixes). - mfd: intel-lpss: Add Intel Emmitsburg PCH PCI IDs (git-fixes). - mfd: mfd-core: Protect against NULL call-back function pointer (git-fixes). - mm: Avoid calling build_all_zonelists_init under hotplug context (bsc#1154366). - mmc: cqhci: Add cqhci_deactivate() (git-fixes). - mmc: sdhci-msm: Add retries when all tuning phases are found valid (git-fixes). - mmc: sdhci-pci: Fix SDHCI_RESET_ALL for CQHCI for Intel GLK-based controllers (git-fixes). - mmc: sdhci: Workaround broken command queuing on Intel GLK based IRBIS models (git-fixes). - mm/page_alloc.c: fix a crash in free_pages_prepare() (git fixes (mm/pgalloc)). - mm/vmalloc.c: move 'area-> pages' after if statement (git fixes (mm/vmalloc)). - mtd: cfi_cmdset_0002: do not free cfi-> cfiq in error path of cfi_amdstd_setup() (git-fixes). - mtd: lpddr: Fix a double free in probe() (git-fixes). - mtd: phram: fix a double free issue in error path (git-fixes). - mtd: properly check all write ioctls for permissions (git-fixes). - net: dsa: b53: Fix sparse warnings in b53_mmap.c (git-fixes). - net: dsa: b53: Use strlcpy() for ethtool::get_strings (git-fixes). - net: dsa: mv88e6xxx: fix 6085 frame mode masking (git-fixes). - net: dsa: mv88e6xxx: Fix interrupt masking on removal (git-fixes). - net: dsa: mv88e6xxx: Fix name of switch 88E6141 (git-fixes). - net: dsa: mv88e6xxx: fix shift of FID bits in mv88e6185_g1_vtu_loadpurge() (git-fixes). - net: dsa: mv88e6xxx: Unregister MDIO bus on error path (git-fixes). - net: dsa: qca8k: Allow overwriting CPU port setting (git-fixes). - net: dsa: qca8k: Enable RXMAC when bringing up a port (git-fixes). - net: dsa: qca8k:Force CPU port to its highest bandwidth (git-fixes). - net: ethernet: mlx4: Fix memory allocation in mlx4_buddy_init() (git-fixes). - net: fs_enet: do not call phy_stop() in interrupts (git-fixes). - net: initialize fastreuse on inet_inherit_port (networking-stable-20_08_15). - net: lan78xx: Bail out if lan78xx_get_endpoints fails (git-fixes). - net: lan78xx: replace bogus endpoint lookup (networking-stable-20_08_08). - net: lio_core: fix potential sign-extension overflow on large shift (git-fixes). - net/mlx5: Add meaningful return codes to status_to_err function (git-fixes). - net/mlx5: E-Switch, Use correct flags when configuring vlan (git-fixes). - net/mlx5e: XDP, Avoid checksum complete when XDP prog is loaded (git-fixes). - net: mvneta: fix mtu change on port without link (git-fixes). - net-next: ax88796: Do not free IRQ in ax_remove() (already freed in ax_close()) (git-fixes). - net/nfc/rawsock.c: add CAP_NET_RAW check (networking-stable-20_08_15). - net: qca_spi: Avoid packet drop during initial sync (git-fixes). - net: qca_spi: Make sure the QCA7000 reset is triggered (git-fixes). - net: refactor bind_bucket fastreuse into helper (networking-stable-20_08_15). - net/smc: fix dmb buffer shortage (git-fixes). - net/smc: fix restoring of fallback changes (git-fixes). - net/smc: fix sock refcounting in case of termination (git-fixes). - net/smc: improve close of terminated socket (git-fixes). - net/smc: Prevent kernel-infoleak in __smc_diag_dump() (git-fixes). - net/smc: remove freed buffer from list (git-fixes). - net/smc: reset sndbuf_desc if freed (git-fixes). - net/smc: set rx_off for SMCR explicitly (git-fixes). - net/smc: switch smcd_dev_list spinlock to mutex (git-fixes). - net/smc: tolerate future SMCD versions (git-fixes). - net: stmmac: call correct function in stmmac_mac_config_rx_queues_routing() (git-fixes). - net: stmmac: Disable ACS Feature for GMAC > = 4 (git-fixes). -net: stmmac: do not stop NAPI processing when dropping a packet (git-fixes). - net: stmmac: dwmac4: fix flow control issue (git-fixes). - net: stmmac: dwmac_lib: fix interchanged sleep/timeout values in DMA reset function (git-fixes). - net: stmmac: dwmac-meson8b: Add missing boundary to RGMII TX clock array (git-fixes). - net: stmmac: dwmac-meson8b: fix internal RGMII clock configuration (git-fixes). - net: stmmac: dwmac-meson8b: fix setting the RGMII TX clock on Meson8b (git-fixes). - net: stmmac: dwmac-meson8b: Fix the RGMII TX delay on Meson8b/8m2 SoCs (git-fixes). - net: stmmac: dwmac-meson8b: only configure the clocks in RGMII mode (git-fixes). - net: stmmac: dwmac-meson8b: propagate rate changes to the parent clock (git-fixes). - net: stmmac: Fix error handling path in 'alloc_dma_rx_desc_resources()' (git-fixes). - net: stmmac: Fix error handling path in 'alloc_dma_tx_desc_resources()' (git-fixes). - net: stmmac: rename dwmac4_tx_queue_routing() to match reality (git-fixes). - net: stmmac: set MSS for each tx DMA channel (git-fixes). - net: stmmac: Use correct values in TQS/RQS fields (git-fixes). - net-sysfs: add a newline when printing 'tx_timeout' by sysfs (networking-stable-20_07_29). - net: systemport: Fix software statistics for SYSTEMPORT Lite (git-fixes). - net: systemport: Fix sparse warnings in bcm_sysport_insert_tsb() (git-fixes). - net: tulip: de4x5: Drop redundant MODULE_DEVICE_TABLE() (git-fixes). - net: ucc_geth - fix Oops when changing number of buffers in the ring (git-fixes). - NFSv4: do not mark all open state for recovery when handling recallable state revoked flag (bsc#1176935). - nvme-fc: set max_segments to lldd max value (bsc#1176038). - nvme-pci: override the value of the controller's numa node (bsc#1176507). - ocfs2: give applications more IO opportunities during fstrim (bsc#1175228). - omapfb: fix multiple reference count leaks dueto pm_runtime_get_sync (git-fixes). - PCI/ASPM: Allow re-enabling Clock PM (git-fixes). - PCI: Fix pci_create_slot() reference count leak (git-fixes). - PCI: qcom: Add missing ipq806x clocks in PCIe driver (git-fixes). - PCI: qcom: Add missing reset for ipq806x (git-fixes). - PCI: qcom: Add support for tx term offset for rev 2.1.0 (git-fixes). - PCI: qcom: Define some PARF params needed for ipq8064 SoC (git-fixes). - PCI: rcar: Fix incorrect programming of OB windows (git-fixes). - phy: samsung: s5pv210-usb2: Add delay after reset (git-fixes). - pinctrl: mvebu: Fix i2c sda definition for 98DX3236 (git-fixes). - powerpc/64s: Blacklist functions invoked on a trap (bsc#1094244 ltc#168122). - powerpc/64s: Fix HV NMI vs HV interrupt recoverability test (bsc#1094244 ltc#168122). - powerpc/64s: Fix unrelocated interrupt trampoline address test (bsc#1094244 ltc#168122). - powerpc/64s: Include header file to fix a warning (bsc#1094244 ltc#168122). - powerpc/64s: machine check do not trace real-mode handler (bsc#1094244 ltc#168122). - powerpc/64s: sreset panic if there is no debugger or crash dump handlers (bsc#1094244 ltc#168122). - powerpc/64s: system reset interrupt preserve HSRRs (bsc#1094244 ltc#168122). - powerpc: Add cputime_to_nsecs() (bsc#1065729). - powerpc/book3s64/radix: Add kernel command line option to disable radix GTSE (bsc#1055186 ltc#153436). - powerpc/book3s64/radix: Fix boot failure with large amount of guest memory (bsc#1176022 ltc#187208). - powerpc: Implement ftrace_enabled() helpers (bsc#1094244 ltc#168122). - powerpc/init: Do not advertise radix during client-architecture-support (bsc#1055186 ltc#153436 ). - powerpc/kernel: Cleanup machine check function declarations (bsc#1065729). - powerpc/kernel: Enables memory hot-remove after reboot on pseries guests (bsc#1177030 ltc#187588). - powerpc/mm: Enable radix GTSE only if supported (bsc#1055186 ltc#153436). -powerpc/mm: Limit resize_hpt_for_hotplug() call to hash guests only (bsc#1177030 ltc#187588). - powerpc/mm: Move book3s64 specifics in subdirectory mm/book3s64 (bsc#1176022 ltc#187208). - powerpc/powernv: Remove real mode access limit for early allocations (bsc#1176022 ltc#187208). - powerpc/prom: Enable Radix GTSE in cpu pa-features (bsc#1055186 ltc#153436). - powerpc/pseries/le: Work around a firmware quirk (bsc#1094244 ltc#168122). - powerpc/pseries: lift RTAS limit for radix (bsc#1176022 ltc#187208). - powerpc/pseries: Limit machine check stack to 4GB (bsc#1094244 ltc#168122). - powerpc/pseries: Machine check use rtas_call_unlocked() with args on stack (bsc#1094244 ltc#168122). - powerpc/pseries: radix is not subject to RMA limit, remove it (bsc#1176022 ltc#187208). - powerpc/pseries/ras: Avoid calling rtas_token() in NMI paths (bsc#1094244 ltc#168122). - powerpc/pseries/ras: Fix FWNMI_VALID off by one (bsc#1094244 ltc#168122). - powerpc/pseries/ras: fwnmi avoid modifying r3 in error case (bsc#1094244 ltc#168122). - powerpc/pseries/ras: fwnmi sreset should not interlock (bsc#1094244 ltc#168122). - powerpc/traps: Do not trace system reset (bsc#1094244 ltc#168122). - powerpc/traps: fix recoverability of machine check handling on book3s/32 (bsc#1094244 ltc#168122). - powerpc/traps: Make unrecoverable NMIs die instead of panic (bsc#1094244 ltc#168122). - powerpc/xmon: Use `dcbf` inplace of `dcbi` instruction for 64bit Book3S (bsc#1065729). - power: supply: max17040: Correct voltage reading (git-fixes). - rcu: Do RCU GP kthread self-wakeup from softirq and interrupt (git fixes (rcu)). - regulator: push allocation in set_consumer_device_supply() out of lock (git-fixes). - rpadlpar_io: Add MODULE_DESCRIPTION entries to kernel modules (bsc#1176869 ltc#188243). - rpm/constraints.in: recognize also kernel-source-azure (bsc#1176732) - rpm/kernel-binary.spec.in: Also signppc64 kernels (jsc#SLE-15857 jsc#SLE-13618). - rpm/kernel-cert-subpackage: add CA check on key enrollment (bsc#1173115) To avoid the unnecessary key enrollment, when enrolling the signing key of the kernel package, "--ca-check" is added to mokutil so that mokutil will ignore the request if the CA of the signing key already exists in MokList or UEFI db. Since the macro, %_suse_kernel_module_subpackage, is only defined in a kernel module package (KMP), it's used to determine whether the %post script is running in a kernel package, or a kernel module package. - rpm/kernel-source.spec.in: Also use bz compression (boo#1175882). - rpm/macros.kernel-source: pass -c proerly in kernel module package (bsc#1176698) The "-c" option wasn't passed down to %_kernel_module_package so the ueficert subpackage wasn't generated even if the certificate is specified in the spec file. - rtc: ds1374: fix possible race condition (git-fixes). - rtlwifi: rtl8192cu: Prevent leaking urb (git-fixes). - rxrpc: Fix race between recvmsg and sendmsg on immediate call failure (networking-stable-20_08_08). - rxrpc: Fix sendmsg() returning EPIPE due to recvmsg() returning ENODATA (networking-stable-20_07_29). - s390/mm: fix huge pte soft dirty copying (git-fixes). - s390/qeth: do not process empty bridge port events (git-fixes). - s390/qeth: integrate RX refill worker with NAPI (git-fixes). - s390/qeth: tolerate pre-filled RX buffer (git-fixes). - scsi: fcoe: Memory leak fix in fcoe_sysfs_fcf_del() (bsc#1174899). - scsi: fnic: Do not call 'scsi_done()' for unhandled commands (bsc#1168468, bsc#1171675). - scsi: ibmvfc: Avoid link down on FS9100 canister reboot (bsc#1176962 ltc#188304). - scsi: ibmvfc: Use compiler attribute defines instead of __attribute__() (bsc#1176962 ltc#188304). - scsi: iscsi: iscsi_tcp: Avoid holding spinlock while calling getpeername() (bsc#1177258). - scsi: libfc: Fix for double free()(bsc#1174899). - scsi: libfc: free response frame from GPN_ID (bsc#1174899). - scsi: libfc: Free skb in fc_disc_gpn_id_resp() for valid cases (bsc#1174899). - scsi: libfc: free skb when receiving invalid flogi resp (bsc#1175528). - scsi: libfc: Handling of extra kref (bsc#1175528). - scsi: libfc: If PRLI rejected, move rport to PLOGI state (bsc#1175528). - scsi: libfc: rport state move to PLOGI if all PRLI retry exhausted (bsc#1175528). - scsi: libfc: Skip additional kref updating work event (bsc#1175528). - scsi: lpfc: Add dependency on CPU_FREQ (git-fixes). - scsi: lpfc: Fix setting IRQ affinity with an empty CPU mask (git-fixes). - scsi: qla2xxx: Fix regression on sparc64 (git-fixes). - scsi: qla2xxx: Fix the return value (bsc#1171688). - scsi: qla2xxx: Fix the size used in a 'dma_free_coherent()' call (bsc#1171688). - scsi: qla2xxx: Fix wrong return value in qla_nvme_register_hba() (bsc#1171688). - scsi: qla2xxx: Fix wrong return value in qlt_chk_unresolv_exchg() (bsc#1171688). - scsi: qla2xxx: Handle incorrect entry_type entries (bsc#1171688). - scsi: qla2xxx: Log calling function name in qla2x00_get_sp_from_handle() (bsc#1171688). - scsi: qla2xxx: Remove pci-dma-compat wrapper API (bsc#1171688). - scsi: qla2xxx: Remove redundant variable initialization (bsc#1171688). - scsi: qla2xxx: Remove superfluous memset() (bsc#1171688). - scsi: qla2xxx: Simplify return value logic in qla2x00_get_sp_from_handle() (bsc#1171688). - scsi: qla2xxx: Suppress two recently introduced compiler warnings (git-fixes). - scsi: qla2xxx: Warn if done() or free() are called on an already freed srb (bsc#1171688). - sdhci: tegra: Remove SDHCI_QUIRK_DATA_TIMEOUT_USES_SDCLK for Tegra186 (git-fixes). - sdhci: tegra: Remove SDHCI_QUIRK_DATA_TIMEOUT_USES_SDCLK for Tegra210 (git-fixes). - serial: 8250: 8250_omap: Terminate DMA before pushing data on RX timeout (git-fixes). - serial: 8250_omap: Fixsleeping function called from invalid context during probe (git-fixes). - serial: 8250_port: Do not service RX FIFO if throttled (git-fixes). - Set CONFIG_HAVE_KVM_VCPU_ASYNC_IOCTL=y (jsc#SLE-4084). - SMB3: Honor persistent/resilient handle flags for multiuser mounts (bsc#1176546). - SMB3: Honor 'seal' flag for multiuser mounts (bsc#1176545). - SMB3: warn on confusing error scenario with sec=krb5 (bsc#1176548). - stmmac: Do not access tx_q-> dirty_tx before netif_tx_lock (git-fixes). - tcp: apply a floor of 1 for RTT samples from TCP timestamps (networking-stable-20_08_08). - thermal: ti-soc-thermal: Fix bogus thermal shutdowns for omap4430 (git-fixes). - tools/power/cpupower: Fix initializer override in hsw_ext_cstates (bsc#1112178). - USB: core: fix slab-out-of-bounds Read in read_descriptors (git-fixes). - USB: dwc3: Increase timeout for CmdAct cleared by device controller (git-fixes). - USB: EHCI: ehci-mv: fix error handling in mv_ehci_probe() (git-fixes). - USB: EHCI: ehci-mv: fix less than zero comparison of an unsigned int (git-fixes). - USB: Fix out of sync data toggle if a configured device is reconfigured (git-fixes). - USB: gadget: f_ncm: add bounds checks to ncm_unwrap_ntb() (git-fixes). - USB: gadget: f_ncm: Fix NDP16 datagram validation (git-fixes). - USB: gadget: u_f: add overflow checks to VLA macros (git-fixes). - USB: gadget: u_f: Unbreak offset calculation in VLAs (git-fixes). - USB: hso: check for return value in hso_serial_common_create() (networking-stable-20_08_08). - usblp: fix race between disconnect() and read() (git-fixes). - USB: lvtest: return proper error code in probe (git-fixes). - usbnet: ipheth: fix potential null pointer dereference in ipheth_carrier_set (git-fixes). - USB: qmi_wwan: add D-Link DWM-222 A2 device ID (git-fixes). - USB: quirks: Add no-lpm quirk for another Raydium touchscreen (git-fixes). - USB: quirks: AddUSB_QUIRK_IGNORE_REMOTE_WAKEUP quirk for BYD zhaoxin notebook (git-fixes). - USB: quirks: Ignore duplicate endpoint on Sound Devices MixPre-D (git-fixes). - USB: serial: ftdi_sio: add IDs for Xsens Mti USB converter (git-fixes). - USB: serial: option: add support for SIM7070/SIM7080/SIM7090 modules (git-fixes). - USB: serial: option: support dynamic Quectel USB compositions (git-fixes). - USB: sisusbvga: Fix a potential UB casued by left shifting a negative value (git-fixes). - USB: storage: Add unusual_uas entry for Sony PSZ drives (git-fixes). - USB: typec: ucsi: acpi: Check the _DEP dependencies (git-fixes). - USB: uas: Add quirk for PNY Pro Elite (git-fixes). - USB: UAS: fix disconnect by unplugging a hub (git-fixes). - USB: yurex: Fix bad gfp argument (git-fixes). - vgacon: remove software scrollback support (bsc#1176278). - video: fbdev: fix OOB read in vga_8planes_imageblit() (git-fixes). - virtio-blk: free vblk-vqs in error path of virtblk_probe() (git fixes (block drivers)). - vrf: prevent adding upper devices (git-fixes). - vxge: fix return of a free'd memblock on a failed dma mapping (git-fixes). - xen: do not reschedule in preemption off sections (bsc#1175749). - xen/events: do not use chip_data for legacy IRQs (bsc#1065600). - xen uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (bsc#1065600). - xhci: Do warm-reset when both CAS and XDEV_RESUME are set (git-fixes). - yam: fix possible memory leak in yam_init_driver (git-fixes). Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patchSUSE-SLE-WE-12-SP5-2020-2904=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2904=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-2904=1 - SUSE Linux Enterprise Live Patching 12-SP5: zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2020-2904=1 - SUSE Linux Enterprise High Availability 12-SP5: zypper in -t patch SUSE-SLE-HA-12-SP5-2020-2904=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): kernel-default-debuginfo-4.12.14-122.41.1 kernel-default-debugsource-4.12.14-122.41.1 kernel-default-extra-4.12.14-122.41.1 kernel-default-extra-debuginfo-4.12.14-122.41.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): kernel-obs-build-4.12.14-122.41.1 kernel-obs-build-debugsource-4.12.14-122.41.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (noarch): kernel-docs-4.12.14-122.41.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): kernel-default-4.12.14-122.41.1 kernel-default-base-4.12.14-122.41.1 kernel-default-base-debuginfo-4.12.14-122.41.1 kernel-default-debuginfo-4.12.14-122.41.1 kernel-default-debugsource-4.12.14-122.41.1 kernel-default-devel-4.12.14-122.41.1 kernel-syms-4.12.14-122.41.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): kernel-devel-4.12.14-122.41.1 kernel-macros-4.12.14-122.41.1 kernel-source-4.12.14-122.41.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): kernel-default-devel-debuginfo-4.12.14-122.41.1 - SUSE Linux Enterprise Server 12-SP5 (s390x): kernel-default-man-4.12.14-122.41.1 - SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64): kernel-default-debuginfo-4.12.14-122.41.1 kernel-default-debugsource-4.12.14-122.41.1 kernel-default-kgraft-4.12.14-122.41.1 kernel-default-kgraft-devel-4.12.14-122.41.1 kgraft-patch-4_12_14-122_41-default-1-8.3.1 - SUSE Linux Enterprise High Availability 12-SP5 (ppc64le s390x x86_64): cluster-md-kmp-default-4.12.14-122.41.1 cluster-md-kmp-default-debuginfo-4.12.14-122.41.1 dlm-kmp-default-4.12.14-122.41.1 dlm-kmp-default-debuginfo-4.12.14-122.41.1 gfs2-kmp-default-4.12.14-122.41.1 gfs2-kmp-default-debuginfo-4.12.14-122.41.1 kernel-default-debuginfo-4.12.14-122.41.1 kernel-default-debugsource-4.12.14-122.41.1 ocfs2-kmp-default-4.12.14-122.41.1 ocfs2-kmp-default-debuginfo-4.12.14-122.41.1 References: https://www.suse.com/security/cve/CVE-2020-0404.html https://www.suse.com/security/cve/CVE-2020-0427.html https://www.suse.com/security/cve/CVE-2020-0431.html https://www.suse.com/security/cve/CVE-2020-0432.html https://www.suse.com/security/cve/CVE-2020-14381.html https://www.suse.com/security/cve/CVE-2020-14390.html https://www.suse.com/security/cve/CVE-2020-25212.html https://www.suse.com/security/cve/CVE-2020-25284.html https://www.suse.com/security/cve/CVE-2020-25641.html https://www.suse.com/security/cve/CVE-2020-25643.html https://www.suse.com/security/cve/CVE-2020-26088.html https://bugzilla.suse.com/1055186 https://bugzilla.suse.com/1065600 https://bugzilla.suse.com/1065729 https://bugzilla.suse.com/1094244 https://bugzilla.suse.com/1112178 https://bugzilla.suse.com/1113956 https://bugzilla.suse.com/1154366 https://bugzilla.suse.com/1163524 https://bugzilla.suse.com/1167527 https://bugzilla.suse.com/1168468 https://bugzilla.suse.com/1169972 https://bugzilla.suse.com/1171675 https://bugzilla.suse.com/1171688 https://bugzilla.suse.com/1171742 https://bugzilla.suse.com/1173115 https://bugzilla.suse.com/1174354 https://bugzilla.suse.com/1174899 https://bugzilla.suse.com/1175228 https://bugzilla.suse.com/1175528 https://bugzilla.suse.com/1175716 https://bugzilla.suse.com/1175749 https://bugzilla.suse.com/1175882 https://bugzilla.suse.com/1176011 https://bugzilla.suse.com/1176022 https://bugzilla.suse.com/1176038 https://bugzilla.suse.com/1176235 https://bugzilla.suse.com/1176242 https://bugzilla.suse.com/1176278 https://bugzilla.suse.com/1176316 https://bugzilla.suse.com/1176317 https://bugzilla.suse.com/1176318 https://bugzilla.suse.com/1176319 https://bugzilla.suse.com/1176320 https://bugzilla.suse.com/1176321 https://bugzilla.suse.com/1176381 https://bugzilla.suse.com/1176423 https://bugzilla.suse.com/1176482 https://bugzilla.suse.com/1176507 https://bugzilla.suse.com/1176536 https://bugzilla.suse.com/1176544 https://bugzilla.suse.com/1176545 https://bugzilla.suse.com/1176546 https://bugzilla.suse.com/1176548 https://bugzilla.suse.com/1176659 https://bugzilla.suse.com/1176698 https://bugzilla.suse.com/1176699 https://bugzilla.suse.com/1176700 https://bugzilla.suse.com/1176721 https://bugzilla.suse.com/1176722 https://bugzilla.suse.com/1176725 https://bugzilla.suse.com/1176732 https://bugzilla.suse.com/1176788 https://bugzilla.suse.com/1176789 https://bugzilla.suse.com/1176869 https://bugzilla.suse.com/1176877 https://bugzilla.suse.com/1176935 https://bugzilla.suse.com/1176950 https://bugzilla.suse.com/1176962 https://bugzilla.suse.com/1176966 https://bugzilla.suse.com/1176990 https://bugzilla.suse.com/1177030 https://bugzilla.suse.com/1177041 https://bugzilla.suse.com/1177042 https://bugzilla.suse.com/1177043 https://bugzilla.suse.com/1177044 https://bugzilla.suse.com/1177121 https://bugzilla.suse.com/1177206 https://bugzilla.suse.com/1177258 https://bugzilla.suse.com/1177291 https://bugzilla.suse.com/1177293 https://bugzilla.suse.com/1177294 https://bugzilla.suse.com/1177295 https://bugzilla.suse.com/1177296 _______________________________________________ sle-security-updates mailinglist
An update that solves four vulnerabilities and has 64 fixes An update that solves four vulnerabilities and has 64 fixes An update that solves four vulnerabilities and has 64 fixes is now available. It includes one version update. is now available. It includes one version update.. SUSE Security Update: kernel update for SLE11 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:0689-1 Rating: important References: #704280 #708836 #718521 #721857 #725592 #732296 #738528 #738644 #743232 #744758 #745088 #746938 #748112 #748463 #748806 #748859 #750426 #751550 #752022 #752634 #753172 #753698 #754085 #754428 #754690 #754969 #755178 #755537 #755758 #755812 #756236 #756821 #756840 #756940 #757077 #757202 #757205 #757289 #757373 #757517 #757565 #757719 #757783 #757789 #757950 #758104 #758279 #758532 #758540 #758731 #758813 #758833 #759340 #759539 #759541 #759657 #759908 #759971 #760015 #760279 #760346 #760974 #761158 #761387 #761772 #762285 #762329 #762424 Cross-References: CVE-2012-2127 CVE-2012-2133 CVE-2012-2313 CVE-2012-2319 Affected Products: SUSE Linux Enterprise Server 11 SP2 for VMware SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise High Availability Extension 11 SP2 SUSE Linux Enterprise Desktop 11 SP2 SLE 11 SERVER Unsupported Extras ______________________________________________________________________________ An update that solves four vulnerabilities and has 64 fixes is now available. It includes one version update. Description: The SUSE Linux Enterprise 11 SP2 kernel was updated to 3.0.31, fixing lots of bugs and security issues. Varioussecurity and bug fixes contained in the Linux 3.0 stable releases 3.0.27 up to 3.0.31 are included, but not explicitly listed below. Following security issues were fixed: CVE-2012-2313: The dl2k network card driver lacked permission handling for some ethtool ioctls, which could allow local attackers to start/stop the network card. CVE-2012-2133: A use after free bug in hugetlb support could be used by local attackers to crash the system. CVE-2012-2127: Various leaks in namespace handling over fork where fixed, which could be exploited by e.g. vsftpd access by remote users. CVE-2012-2319: A memory corruption when mounting a hfsplus filesystem was fixed that could be used by local attackers able to mount filesystem to crash the system. Following non security bugs were fixed by this update: BTRFS: - btrfs: partial revert of truncation improvements (bnc#748463 bnc#760279). - btrfs: fix eof while discarding extents - btrfs: check return value of bio_alloc() properly - btrfs: return void from clear_state_bit - btrfs: avoid possible use-after-free in clear_extent_bit() - btrfs: Make free_ipath() deal gracefully with NULL pointers - btrfs: do not call free_extent_buffer twice in iterate_irefs - btrfs: add missing read locks in backref.c - btrfs: fix max chunk size check in chunk allocator - btrfs: double unlock bug in error handling - btrfs: do not return EINTR - btrfs: fix btrfs_ioctl_dev_info() crash on missing device - btrfs: fix that check_int_data mount option was ignored - btrfs: do not mount when we have a sectorsize unequal to PAGE_SIZE - btrfs: avoid possible use-after-free in clear_extent_bit() - btrfs: retrurn void from clear_state_bit - btrfs: Fix typo in free-space-cache.c - btrfs: remove the ideal caching code - btrfs: remove search_start and search_end from find_free_extent and callers - btrfs: adjust the write_lock_level as we unlock - btrfs: actually call btrfs_init_lockdep - btrfs: fix regression in scrub path resolving - btrfs: show useful info in space reservation tracepoint - btrfs: flush out and clean up any block device pages during mount - btrfs: fix deadlock during allocating chunks - btrfs: fix race between direct io and autodefrag - btrfs: fix the mismatch of page-> mapping - btrfs: fix recursive defragment with autodefrag option - btrfs: add a check to decide if we should defrag the range - btrfs: do not bother to defrag an extent if it is a big real extent - btrfs: update to the right index of defragment - btrfs: Fix use-after-free in __btrfs_end_transaction - btrfs: stop silently switching single chunks to raid0 on balance - btrfs: add wrappers for working with alloc profiles - btrfs: make profile_is_valid() check more strict - btrfs: move alloc_profile_is_valid() to volumes.c - btrfs: add get_restripe_target() helper - btrfs: add __get_block_group_index() helper - btrfs: improve the logic in btrfs_can_relocate() - btrfs: validate target profiles only if we are going to use them - btrfs: allow dup for data chunks in mixed mode - btrfs: fix memory leak in resolver code - btrfs: fix infinite loop in btrfs_shrink_device() - btrfs: error handling locking fixu - btrfs: fix uninit variable in repair_eb_io_failure - btrfs: always store the mirror we read the eb from - btrfs: do not count CRC or header errors twice while scrubbing - btrfs: do not start delalloc inodes during sync - btrfs: fix repair code for RAID10 - btrfs: Prevent root_list corruption - btrfs: fix block_rsv and space_info lock ordering - btrfs: Fix space checking during fs resize - btrfs: avoid deadlocks from GFP_KERNEL allocations during btrfs_real_readdir - btrfs: reduce lock contention during extent insertion - btrfs: Add properly locking around add_root_to_dirty_list - btrfs: Fix mismatching struct members in ioctl.h netfilter: - netfilter: nf_conntrack: make event callbackregistration per-netns (bnc#758540). DRM: - drm/edid: Add a workaround for 1366x768 HD panel (bnc#753172). - drm/edid: Add extra_modes (bnc#753172). - drm/edid: Add packed attribute to new gtf2 and cvt structs (bnc#753172). - drm/edid: Add the reduced blanking DMT modes to the DMT list (bnc#753172). - drm/edid: Allow drm_mode_find_dmt to hunt for reduced-blanking modes (bnc#753172). - drm/edid: Do drm_dmt_modes_for_range() for all range descriptor types (bnc#753172). - drm/edid: Document drm_mode_find_dmt (bnc#753172). - drm/edid: Fix some comment typos in the DMT mode list (bnc#753172). - drm/edid: Generate modes from extra_modes for range descriptors (bnc#753172). - drm/edid: Give the est3 mode struct a real name (bnc#753172). - drm/edid: Remove a misleading comment (bnc#753172). - drm/edid: Rewrite drm_mode_find_dmt search loop (bnc#753172). - drm/edid: Update range descriptor struct for EDID 1.4 (bnc#753172). - drm/edid: add missing NULL checks (bnc#753172). - drm/edid: s/drm_gtf_modes_for_range/drm_dmt_modes_for_range/ (bnc#753172). - Fix kABI for drm EDID improvement patches (bnc#753172). - drm: Fix the case where multiple modes are returned from EDID (bnc#753172) - drm/i915: Add more standard modes to LVDS output (bnc#753172). - drm/i915: Disable LVDS at mode change (bnc#752022). - drm/i915: add Ivy Bridge GT2 Server entries (bnc#759971). - drm/i915: delay drm_irq_install() at resume (bnc#753698). - EDD: Check for correct EDD 3.0 length (bnc#762285). XEN: - blkfront: make blkif_io_lock spinlock per-device. - blkback: streamline main processing loop (fate#309305). - blkback: Implement discard requests handling (fate#309305). - blkback: Enhance discard support with secure erasing support (fate#309305). - blkfront: Handle discard requests (fate#309305). - blkfront: Enhance discard support with secure erasing support (fate#309305). - blkif: support discard(fate#309305). - blkif: Enhance discard support with secure erasing support (fate#309305). - xen/smpboot: adjust ordering of operations. - x86-64: provide a memset() that can deal with 4Gb or above at a time (bnc#738528). - Update Xen patches to 3.0.27. - Update Xen patches to 3.0.31. - xen: fix VM_FOREIGN users after c/s 878:eba6fe6d8d53 (bnc#760974). - xen/gntdev: fix multi-page slot allocation (bnc#760974). TG3: - tg3: Avoid panic from reserved statblk field access (bnc#760346). - tg3: Fix 5717 serdes powerdown problem (bnc#756940). - tg3: Fix RSS ring refill race condition (bnc#756940). - tg3: Fix single-vector MSI-X code (bnc#756940). - tg3: fix ipv6 header length computation (bnc#756940). S/390: - dasd: Fix I/O stall when reserving dasds (bnc#757719). - s390/af_iucv: detect down state of HS transport interface (bnc#758279,LTC#80859). - s390/af_iucv: allow shutdown for HS transport sockets (bnc#758279,LTC#80860). - mm: s390: Fix BUG by using __set_page_dirty_no_writeback on swap. (bnc#751550) - s390/qeth: Improve OSA Express 4 blkt defaults (bnc#754969,LTC#80325). - s390/zcrypt: Fix parameter checking for ZSECSENDCPRB ioctl (bnc#754969,LTC#80378). - zfcpdump: Implement async sdias event processing (bnc#761387,LTC#81330). ALSA: - ALSA: hda - Always resume the codec immediately (bnc#750426). - ALSA: hda - Add Creative CA0132 HDA codec support (bnc#762424). - ALSA: hda - Fix error handling in patch_ca0132.c (bnc#762424). - ALSA: hda - Add the support for Creative SoundCore3D (bnc#762424). OTHER: - ixgbe: fix ring assignment issues for SR-IOV and drop cases (bnc#761158). - ixgbe: add missing rtnl_lock in PM resume path (bnc#748859). - MCE, AMD: Drop too granulary family model checks (bnc#758833). - EDAC, MCE, AMD: Print CPU number when reporting the error (bnc#758833). - EDAC, MCE, AMD: Print valid addr when reporting an error (bnc#758833). - libata:skip old error history when counting probe trials. - x86: kdb: restore kdb stack trace (bnc#760015). - ehea: fix allmulticast support, - ehea: fix promiscuous mode (both bnc#757289) - ehea: only register irq after setting up ports (bnc#758731). - ehea: fix losing of NEQ events when one event occurred early (bnc#758731). - scsi: Silence unnecessary warnings about ioctl to partition (bnc#758104). - scsi_dh_rdac: Update match function to check page C8 (bnc#757077). - scsi_dh_rdac: Add new NetApp IDs (bnc#757077). - bluetooth: Add support for Foxconn/Hon Hai AR5BBU22 0489:E03C (bnc#759908). - x86/amd: Add missing feature flag for fam15h models 10h-1fh processors (bnc#759340). - x86: Report cpb and eff_freq_ro flags correctly (bnc#759340). - x86, amd: Fix up numa_node information for AMD CPU family 15h model 0-0fh northbridge functions (bnc#759340). - x86/PCI: amd: Kill misleading message about enablement of IO access to PCI ECS] (bnc#759340). - cdc-wdm: fix race leading leading to memory corruption (bnc#759539). - tlan: add cast needed for proper 64 bit operation (bnc#756840). - bonding:update speed/duplex for NETDEV_CHANGE (bnc#752634). - bonding: comparing a u8 with -1 is always false (bnc#752634). - bonding: start slaves with link down for ARP monitor (bnc#752634). - bonding: do not increase rx_dropped after processing LACPDUs (bnc#759657). - x86: fix the initialization of physnode_map (bnc#748112). - sched,rt: fix isolated CPUs leaving root_task_group indefinitely throttled (bnc#754085). - Fix SLE11-SP1-> SLE11-SP2 interrupt latency regression. Revert 0209f649, and turn tick skew on globally, since 0209f649 came about to mitigate lock contention that skew removal induces, both on xtime_lock and on RCU leaf node locks. NOTE: This change trades ~400% latency regression fix for power consumption progression that skew removal bought (at high cost). - Revert mainline0209f649 - rcu: limit rcu_node leaf-level fanout (bnc#718521). - md: fix possible corruption of array metadata on shutdown. - md/bitmap: prevent bitmap_daemon_work running while initialising bitmap. - md: ensure changes to write-mostly are reflected in metadata (bnc#755178). - cciss: Add IRQF_SHARED back in for the non-MSI(X) interrupt handler (bnc#757789). - procfs, namespace, pid_ns: fix leakage upon fork() failure (bnc#757783). - mqueue: fix a vfsmount longterm reference leak (bnc#757783). - procfs: fix a vfsmount longterm reference leak (bnc#757783). - scsi_dh_alua: Optimize stpg command (bnc#744758). - scsi_dh_alua: Store pref bit from RTPG (bnc#755758). - scsi_dh_alua: set_params interface (bnc#755758). - uwb: fix error handling (bnc#757950). - uwb: fix use of del_timer_sync() in interrupt (bnc#757950). - usbhid: fix error handling of not enough bandwidth (bnc#704280). - mm: Improve preservation of page-age information (bnc#754690) - pagecache limit: Fix the shmem deadlock (bnc#755537). - USB: sierra: add support for Sierra Wireless MC7710 (bnc#757517). - USB: fix resource leak in xhci power loss path (bnc#746938). - x86/iommu/intel: Fix identity mapping for sandy bridge (bnc#743232). - ipv6: Check dest prefix length on original route not copied one in rt6_alloc_cow() (bnc#757202). - ipv6: do not use inetpeer to store metrics for routes (bnc#757202). - ipv6: fix problem with expired dst cache (bnc#757205). - ipv6: unshare inetpeers. - bridge: correct IPv6 checksum after pull (bnc#738644). - scsi: storvsc: Account for in-transit packets in the RESET path. - patches.fixes/mm-mempolicy.c-fix-pgoff-in-mbind-vma-merge.pa tch: - patches.fixes/mm-mempolicy.c-refix-mbind_range-vma-issue.pat ch: Fix vma merging issue during mbind affecting JVMs. - ACPI, APEI: Fix incorrect APEI register bit width check and usage (bnc#725592). - vmxnet3: cap copy length atsize of skb to prevent dropped frames on tx (bnc#755812). - rt2x00: rt2x00dev: move rfkill_polling register to proper place (bnc#748806). - pagecache: fix the BUG_ON safety belt - pagecache: Fixed the GFP_NOWAIT is zero and not suitable for tests bug (bnc#755537) - igb: reset PHY after recovering from PHY power down. (bnc#745088) - igb: fix rtnl race in PM resume path (bnc#748859). - watchdog: iTCO_wdt.c - problems with newer hardware due to SMI clearing (bnc#757373). - watchdog: iTCO_wdt.c - problems with newer hardware due to SMI clearing (bnc#757373, redhat#727875). - cfq-iosched: Reduce linked group count upon group destruction (bnc#759541). - cdc_ether: Ignore bogus union descriptor for RNDIS devices (bnc#761772). - sys_poll: fix incorrect type for timeout parameter (bnc#754428). - staging:rts_pstor:Avoid "Bad target number" message when probing driver (bnc#762329). - staging:rts_pstor:Complete scanning_done variable (bnc#762329). - staging:rts_pstor:Fix SDIO issue (bnc#762329). - staging:rts_pstor: Fix a bug that a MMCPlus card ca not be accessed (bnc#762329). - staging:rts_pstor: Fix a miswriting (bnc#762329). - staging:rts_pstor:Fix possible panic by NULL pointer dereference (bnc#762329). - staging:rts_pstor: fix thread synchronization flow (bnc#762329). - freezer:do not unnecessarily set PF_NOFREEZE explicitly (bnc#762329). - staging:rts_pstor: off by one in for loop (bnc#762329). - patches.suse/cgroup-disable-memcg-when-low-lowmem.patch: fix typo: use if defined(CONFIG_*) rather than if CONFIG_* Indications: Everyone using the Linux Kernel on x86_64 architecture should update. Contraindications: Indications: Everyone using the Linux Kernel on x86_64 architecture should update. Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you canrun the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 for VMware: zypper in -t patch slessp2-kernel-6338 slessp2-kernel-6349 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-kernel-6338 slessp2-kernel-6339 slessp2-kernel-6345 slessp2-kernel-6348 slessp2-kernel-6349 - SUSE Linux Enterprise High Availability Extension 11 SP2: zypper in -t patch sleshasp2-kernel-6338 sleshasp2-kernel-6339 sleshasp2-kernel-6345 sleshasp2-kernel-6348 sleshasp2-kernel-6349 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-kernel-6338 sledsp2-kernel-6349 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 for VMware (i586 x86_64) [New Version: 3.0.31]: kernel-default-3.0.31-0.9.1 kernel-default-base-3.0.31-0.9.1 kernel-default-devel-3.0.31-0.9.1 kernel-source-3.0.31-0.9.1 kernel-syms-3.0.31-0.9.1 kernel-trace-3.0.31-0.9.1 kernel-trace-base-3.0.31-0.9.1 kernel-trace-devel-3.0.31-0.9.1 kernel-xen-devel-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 for VMware (i586) [New Version: 3.0.31]: kernel-pae-3.0.31-0.9.1 kernel-pae-base-3.0.31-0.9.1 kernel-pae-devel-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 3.0.31]: kernel-default-3.0.31-0.9.1 kernel-default-base-3.0.31-0.9.1 kernel-default-devel-3.0.31-0.9.1 kernel-source-3.0.31-0.9.1 kernel-syms-3.0.31-0.9.1 kernel-trace-3.0.31-0.9.1 kernel-trace-base-3.0.31-0.9.1 kernel-trace-devel-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 (i586 x86_64) [New Version: 3.0.31]: kernel-ec2-3.0.31-0.9.1 kernel-ec2-base-3.0.31-0.9.1 kernel-ec2-devel-3.0.31-0.9.1 kernel-xen-3.0.31-0.9.1 kernel-xen-base-3.0.31-0.9.1 kernel-xen-devel-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 (s390x) [New Version: 3.0.31]: kernel-default-man-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 (ppc64) [New Version: 3.0.31]: kernel-ppc64-3.0.31-0.9.1 kernel-ppc64-base-3.0.31-0.9.1 kernel-ppc64-devel-3.0.31-0.9.1 - SUSE Linux Enterprise Server 11 SP2 (i586) [New Version: 3.0.31]: kernel-pae-3.0.31-0.9.1 kernel-pae-base-3.0.31-0.9.1 kernel-pae-devel-3.0.31-0.9.1 - SUSE Linux Enterprise High Availability Extension 11 SP2 (i586 ia64 ppc64 s390x x86_64): cluster-network-kmp-default-1.4_3.0.31_0.9-2.10.23 cluster-network-kmp-trace-1.4_3.0.31_0.9-2.10.23 gfs2-kmp-default-2_3.0.31_0.9-0.7.23 gfs2-kmp-trace-2_3.0.31_0.9-0.7.23 ocfs2-kmp-default-1.6_3.0.31_0.9-0.7.23 ocfs2-kmp-trace-1.6_3.0.31_0.9-0.7.23 - SUSE Linux Enterprise High Availability Extension 11 SP2 (i586 x86_64): cluster-network-kmp-xen-1.4_3.0.31_0.9-2.10.23 gfs2-kmp-xen-2_3.0.31_0.9-0.7.23 ocfs2-kmp-xen-1.6_3.0.31_0.9-0.7.23 - SUSE Linux Enterprise High Availability Extension 11 SP2 (ppc64): cluster-network-kmp-ppc64-1.4_3.0.31_0.9-2.10.23 gfs2-kmp-ppc64-2_3.0.31_0.9-0.7.23 ocfs2-kmp-ppc64-1.6_3.0.31_0.9-0.7.23 - SUSE Linux Enterprise High Availability Extension 11 SP2 (i586): cluster-network-kmp-pae-1.4_3.0.31_0.9-2.10.23 gfs2-kmp-pae-2_3.0.31_0.9-0.7.23 ocfs2-kmp-pae-1.6_3.0.31_0.9-0.7.23 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 3.0.31]: kernel-default-3.0.31-0.9.1 kernel-default-base-3.0.31-0.9.1 kernel-default-devel-3.0.31-0.9.1 kernel-default-extra-3.0.31-0.9.1 kernel-source-3.0.31-0.9.1 kernel-syms-3.0.31-0.9.1 kernel-trace-3.0.31-0.9.1 kernel-trace-base-3.0.31-0.9.1 kernel-trace-devel-3.0.31-0.9.1 kernel-trace-extra-3.0.31-0.9.1 kernel-xen-3.0.31-0.9.1 kernel-xen-base-3.0.31-0.9.1 kernel-xen-devel-3.0.31-0.9.1 kernel-xen-extra-3.0.31-0.9.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586) [NewVersion: 3.0.31]: kernel-pae-3.0.31-0.9.1 kernel-pae-base-3.0.31-0.9.1 kernel-pae-devel-3.0.31-0.9.1 kernel-pae-extra-3.0.31-0.9.1 - SLE 11 SERVER Unsupported Extras (i586 ia64 ppc64 s390x x86_64): ext4-writeable-kmp-default-0_3.0.31_0.9-0.14.4 kernel-default-extra-3.0.31-0.9.1 - SLE 11 SERVER Unsupported Extras (i586 x86_64): ext4-writeable-kmp-xen-0_3.0.31_0.9-0.14.4 kernel-xen-extra-3.0.31-0.9.1 - SLE 11 SERVER Unsupported Extras (ppc64): ext4-writeable-kmp-ppc64-0_3.0.31_0.9-0.14.4 kernel-ppc64-extra-3.0.31-0.9.1 - SLE 11 SERVER Unsupported Extras (i586): ext4-writeable-kmp-pae-0_3.0.31_0.9-0.14.4 kernel-pae-extra-3.0.31-0.9.1 References: https://www.suse.com/security/cve/CVE-2012-2127.html https://www.suse.com/security/cve/CVE-2012-2133.html https://www.suse.com/security/cve/CVE-2012-2313.html https://www.suse.com/security/cve/CVE-2012-2319.html . The SUSE kernel upgrade for SLE11 SP2 addresses various local vulnerabilities and enhances overall system security and stability for its users.. SUSE Linux Kernel Update, Security Patches, System Updates. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.