Oracle Linux 6264 Published by

Oracle Linux has issued a number of security updates, including fixes for mdadm, unbreakable Enterprise kernel, httpd security, audit, libvirt, crash, oracle-ocne-release-el9, oracle-ocne-release-el8, audit, selinux-policy, linux-firmware, httpd security, linux-firmware, and selinux-policy:

ELBA-2024-6577 Oracle Linux 9 mdadm bug fix update
ELSA-2024-12618 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update
ELSA-2024-4943 Important: Oracle Linux 7 httpd security update (aarch64)
ELBA-2024-12664 Oracle Linux 9 audit bug fix update
ELBA-2024-6669 Oracle Linux 9 libvirt bug fix and enhancement update
ELBA-2024-12666 Oracle Linux 9 crash bug fix update
ELBA-2024-12626 Oracle Linux 9 oracle-ocne-release-el9 bug fix update
ELBA-2024-12625 Oracle Linux 8 oracle-ocne-release-el8 bug fix update
ELBA-2024-12638 Oracle Linux 8 audit bug fix update
ELBA-2024-12651 Oracle Linux 7 selinux-policy bug fix update (aarch64)
ELBA-2024-12654 Oracle Linux 7 linux-firmware bug fix update
ELBA-2024-12653 Oracle Linux 7 linux-firmware bug fix update (aarch64)
ELSA-2024-4943 Important: Oracle Linux 7 httpd security update
ELBA-2024-12652 Oracle Linux 7 linux-firmware bug fix update
ELBA-2024-12627 Oracle Linux 7 selinux-policy bug fix update




ELBA-2024-6577 Oracle Linux 9 mdadm bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-6577

http://linux.oracle.com/errata/ELBA-2024-6577.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
mdadm-4.2-14.0.1.el9_4.x86_64.rpm

aarch64:
mdadm-4.2-14.0.1.el9_4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//mdadm-4.2-14.0.1.el9_4.src.rpm

Description of changes:

[4.2-14.0.1]
- super1: remove support for name= in config. [Orabug 36958575]
- mdadm: Increase number limit in md device name to 1024. [Orabug: 36958528]
- Fix socket connection failure when mdmon runs in foreground mode. [Orabug: 36077756]

[4.2-14]
- IMSM raid0 can't grow
- Resolves RHEL-39990

[4.2-13]
- consistency-policy cannot be changed on active volume
- Resolves RHEL-34763



ELSA-2024-12618 Important: Oracle Linux 9 Unbreakable Enterprise kernel security update


Oracle Linux Security Advisory ELSA-2024-12618

http://linux.oracle.com/errata/ELSA-2024-12618.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
bpftool-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-core-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-debug-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-debug-core-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-debug-devel-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-debug-modules-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-debug-modules-extra-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-devel-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-doc-5.15.0-210.163.7.el9uek.noarch.rpm
kernel-uek-modules-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-modules-extra-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-container-5.15.0-210.163.7.el9uek.x86_64.rpm
kernel-uek-container-debug-5.15.0-210.163.7.el9uek.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//kernel-uek-5.15.0-210.163.7.el9uek.src.rpm

Related CVEs:

CVE-2022-3566
CVE-2022-3567
CVE-2024-36032
CVE-2024-36033
CVE-2024-36484
CVE-2024-36894
CVE-2024-36901
CVE-2024-36974
CVE-2024-36978
CVE-2024-37078
CVE-2024-38588
CVE-2024-38619
CVE-2024-39362
CVE-2024-39468
CVE-2024-39469
CVE-2024-39482
CVE-2024-39484
CVE-2024-39487
CVE-2024-39495
CVE-2024-39499
CVE-2024-39500
CVE-2024-39501
CVE-2024-39502
CVE-2024-39505
CVE-2024-39506
CVE-2024-39507
CVE-2024-39509
CVE-2024-40901
CVE-2024-40902
CVE-2024-40904
CVE-2024-40905
CVE-2024-40908
CVE-2024-40911
CVE-2024-40912
CVE-2024-40914
CVE-2024-40927
CVE-2024-40929
CVE-2024-40931
CVE-2024-40932
CVE-2024-40934
CVE-2024-40937
CVE-2024-40941
CVE-2024-40942
CVE-2024-40943
CVE-2024-40945
CVE-2024-40947
CVE-2024-40956
CVE-2024-40957
CVE-2024-40958
CVE-2024-40959
CVE-2024-40960
CVE-2024-40961
CVE-2024-40963
CVE-2024-40967
CVE-2024-40968
CVE-2024-40970
CVE-2024-40971
CVE-2024-40974
CVE-2024-40976
CVE-2024-40978
CVE-2024-40980
CVE-2024-40981
CVE-2024-40983
CVE-2024-40987
CVE-2024-40988
CVE-2024-40990
CVE-2024-40993
CVE-2024-40994
CVE-2024-40995
CVE-2024-41000
CVE-2024-41002
CVE-2024-41005
CVE-2024-41006
CVE-2024-41007
CVE-2024-41027
CVE-2024-41034
CVE-2024-41035
CVE-2024-41040
CVE-2024-41041
CVE-2024-41044
CVE-2024-41046
CVE-2024-41047
CVE-2024-41048
CVE-2024-41049
CVE-2024-41087
CVE-2024-41089
CVE-2024-41092
CVE-2024-41093
CVE-2024-41095
CVE-2024-41097
CVE-2024-42068
CVE-2024-42069
CVE-2024-42070
CVE-2024-42076
CVE-2024-42077
CVE-2024-42080
CVE-2024-42082
CVE-2024-42084
CVE-2024-42085
CVE-2024-42086
CVE-2024-42087
CVE-2024-42089
CVE-2024-42090
CVE-2024-42092
CVE-2024-42093
CVE-2024-42094
CVE-2024-42095
CVE-2024-42096
CVE-2024-42097
CVE-2024-42098
CVE-2024-42101
CVE-2024-42103
CVE-2024-42104
CVE-2024-42105
CVE-2024-42106
CVE-2024-42109
CVE-2024-42115
CVE-2024-42116
CVE-2024-42119
CVE-2024-42120
CVE-2024-42121
CVE-2024-42124
CVE-2024-42127
CVE-2024-42130
CVE-2024-42131
CVE-2024-42137
CVE-2024-42140
CVE-2024-42143
CVE-2024-42145
CVE-2024-42148
CVE-2024-42152
CVE-2024-42153
CVE-2024-42154
CVE-2024-42157
CVE-2024-42161
CVE-2024-42223
CVE-2024-42224
CVE-2024-42225
CVE-2024-42229
CVE-2024-42232
CVE-2024-42236
CVE-2024-42244
CVE-2024-42247

Description of changes:

[5.15.0-210.163.7.el9uek]
- crypto: qat - specify firmware files for 402xx (Giovanni Cabiddu) [Orabug: 37030280]

[5.15.0-210.163.6.el9uek]
- Revert "Fix userfaultfd_api to return EINVAL as expected" (Vijayendra Suman) [Orabug: 37004422]

[5.15.0-210.163.5.el9uek]
- Revert "bpf: Allow reads from uninit stack" (Vijayendra Suman) [Orabug: 36992948]
- selftests/vm: Fix build issue with pkey_sighandler_tests.c (Aruna Ramakrishna) [Orabug: 36992941]

[5.15.0-210.163.4.el9uek]
- driver core: Fix uevent_show() vs driver detach race (Dan Williams)
- ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT (Jerome Brunet)
- kdb: Use the passed prompt in kdb_position_cursor() (Douglas Anderson)
- MIPS: Octeron: remove source file executable bit (Dominique Martinet)
- sched: act_ct: take care of padding in struct zones_ht_key (Eric Dumazet)
- ipvs: Avoid unnecessary calls to skb_is_gso_sctp (Ismael Luceno)
- drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq() (Dan Carpenter)
- KVM: x86: check the kvm_cpu_get_interrupt result before using it (Maxim Levitsky) [Orabug: 36893301]
- KVM: x86: VMX: set irr_pending in kvm_apic_update_irr (Maxim Levitsky) [Orabug: 36893301]
- KVM: x86: VMX: __kvm_apic_update_irr must update the IRR atomically (Maxim Levitsky) [Orabug: 36893301]
- KVM: x86: Allow APICv APIC ID inhibit to be cleared (Greg Edwards) [Orabug: 36839768]
- printk: add kthread for long-running print (Stephen Brennan) [Orabug: 36456581]

[5.15.0-210.163.3.el9uek]
- selftests/net: remove extra argument domain for do_recv_completions() (Samasth Norway Ananda) [Orabug: 36949448]
- selftests/mm: Add new testcases for pkeys (Keith Lucas) [Orabug: 36943199]
- x86/pkeys: Restore altstack access in sigreturn() (Aruna Ramakrishna) [Orabug: 36943199]
- x86/pkeys: Update PKRU to enable all pkeys before XSAVE (Aruna Ramakrishna) [Orabug: 36943199]
- x86/pkeys: Add helper functions to update PKRU on the sigframe (Aruna Ramakrishna) [Orabug: 36943199]
- x86/pkeys: Add PKRU as a parameter in signal handling functions (Aruna Ramakrishna) [Orabug: 36943199]
- x86/signal/64: Move 64-bit signal code to its own file (Brian Gerst) [Orabug: 36943199]
- x86/signal/32: Merge native and compat 32-bit signal code (Brian Gerst) [Orabug: 36943199]
- x86/signal: Add ABI prefixes to frame setup functions (Brian Gerst) [Orabug: 36943199]
- x86/signal: Merge get_sigframe() (Brian Gerst) [Orabug: 36943199]
- x86: Remove __USER32_DS (Brian Gerst) [Orabug: 36943199]
- signal/compat: Remove compat_sigset_t override (Brian Gerst) [Orabug: 36943199]
- x86/signal: Remove sigset_t parameter from frame setup functions (Brian Gerst) [Orabug: 36943199]
- x86/signal: Remove sig parameter from frame setup functions (Brian Gerst) [Orabug: 36943199]

[5.15.0-210.163.2.el9uek]
- fsnotify: clear PARENT_WATCHED flags lazily (Amir Goldstein) [Orabug: 36922239]
- net: mana: Fix possible double free in error handling path (Ma Ke) [Orabug: 36897038] {CVE-2024-42069}
- x86/aperfmperf: Dont wake idle CPUs in arch_freq_get_on_cpu() (Thomas Gleixner) [Orabug: 35773810]
- xfs: fix agf/agfl verification on v4 filesystems (Mark Tinguely) [Orabug: 35623655]

[5.15.0-210.163.1.el9uek]
- net: relax socket state check at accept time. (Paolo Abeni) [Orabug: 36768888] {CVE-2024-36484}
- LTS version: v5.15.163 (Vijayendra Suman)
- i2c: rcar: fix error code in probe() (Dan Carpenter)
- kbuild: Make ld-version.sh more robust against version string changes (Nathan Chancellor)
- x86/entry/64: Remove obsolete comment on tracing vs. SYSRET (Brian Gerst)
- i2c: rcar: clear NO_RXDMA flag after resetting (Wolfram Sang)
- i2c: testunit: avoid re-issued work after read message (Wolfram Sang)
- i2c: rcar: ensure Gen3+ reset does not disturb local targets (Wolfram Sang)
- i2c: rcar: introduce Gen4 devices (Wolfram Sang)
- i2c: rcar: reset controller is mandatory for Gen3+ (Wolfram Sang)
- i2c: rcar: Add R-Car Gen4 support (Geert Uytterhoeven)
- i2c: mark HostNotify target address as used (Wolfram Sang)
- i2c: rcar: bring hardware to known state when probing (Wolfram Sang)
- nilfs2: fix kernel bug on rename operation of broken directory (Ryusuke Konishi) [Orabug: 36896820] {CVE-2024-41034}
- bpf: Allow reads from uninit stack (Eduard Zingerman)
- ipv6: prevent NULL dereference in ip6_output() (Eric Dumazet) [Orabug: 36683273] {CVE-2024-36901}
- ipv6: annotate data-races around cnf.disable_ipv6 (Eric Dumazet)
- wireguard: send: annotate intentional data race in checking empty queue (Jason A. Donenfeld)
- wireguard: queueing: annotate intentional data race in cpu round robin (Jason A. Donenfeld)
- wireguard: allowedips: avoid unaligned 64-bit memory accesses (Helge Deller) [Orabug: 36930166] {CVE-2024-42247}
- libceph: fix race between delayed_work() and ceph_monc_stop() (Ilya Dryomov) [Orabug: 36930127] {CVE-2024-42232}
- Fix userfaultfd_api to return EINVAL as expected (Audra Mitchell) [Orabug: 36896804] {CVE-2024-41027}
- ALSA: hda/realtek: Limit mic boost on VAIO PRO PX (Edson Juliano Drosdeck)
- ALSA: hda/realtek: Enable Mute LED on HP 250 G7 (Nazar Bilinskyi)
- ALSA: hda/realtek: add quirk for Clevo V5[46]0TU (Michał Kopeć)
- nvmem: core: only change name to fram for current attribute (Thomas Weißschuh)
- nvmem: meson-efuse: Fix return value of nvmem callbacks (Joy Chakraborty)
- nvmem: rmem: Fix return value of rmem_read() (Joy Chakraborty)
- hpet: Support 32-bit userspace (He Zhe)
- USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor (Alan Stern) [Orabug: 36896825] {CVE-2024-41035}
- usb: gadget: configfs: Prevent OOB read/write in usb_string_copy() (Lee Jones) [Orabug: 36930137] {CVE-2024-42236}
- USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k (WangYuli)
- USB: serial: mos7840: fix crash on resume (Dmitry Smirnov) [Orabug: 36930153] {CVE-2024-42244}
- USB: serial: option: add Rolling RW350-GL variants (Vanillan Wang)
- USB: serial: option: add Netprisma LCUK54 series modules (Mank Wang)
- USB: serial: option: add support for Foxconn T99W651 (Slark Xiao)
- USB: serial: option: add Fibocom FM350-GL (Bjørn Mork)
- USB: serial: option: add Telit FN912 rmnet compositions (Daniele Palmas)
- USB: serial: option: add Telit generic core-dump composition (Daniele Palmas)
- net: ks8851: Fix potential TX stall after interface reopen (Ronald Wahl)
- tcp: avoid too many retransmit packets (Eric Dumazet) [Orabug: 36841815] {CVE-2024-41007}
- tcp: use signed arithmetic in tcp_rtx_probe0_timed_out() (Eric Dumazet)
- octeontx2-af: fix issue with IPv4 match for RSS (Satheesh Paul)
- octeontx2-af: fix issue with IPv6 ext match for RSS (Kiran Kumar K)
- octeontx2-af: extend RSS supported offload types (Kiran Kumar K)
- octeontx2-af: fix detection of IP layer (Michal Mazur)
- octeontx2-af: fix a issue with cpt_lf_alloc mailbox (Srujana Challa)
- octeontx2-af: update cpt lf alloc mailbox (Srujana Challa)
- octeontx2-af: replace cpt slot with lf id on reg write (Nithin Dabilpuram)
- ARM: davinci: Convert comma to semicolon (Chen Ni)
- s390: Mark psw in __load_psw_mask() as __unitialized (Sven Schnelle)
- net/sched: Fix UAF when resolving a clash (Chengen Du) [Orabug: 36896837] {CVE-2024-41040}
- udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). (Kuniyuki Iwashima) [Orabug: 36896841] {CVE-2024-41041}
- ethtool: netlink: do not return SQI value if link is down (Oleksij Rempel)
- ppp: reject claimed-as-LCP but actually malformed packets (Dmitry Antipov) [Orabug: 36896855] {CVE-2024-41044}
- net: ethernet: mtk-star-emac: set mac_managed_pm when probing (Jian Hui Lee)
- net: ethernet: lantiq_etop: fix double free in detach (Aleksander Jan Bajkowski) [Orabug: 36896862] {CVE-2024-41046}
- net: lantiq_etop: add blank line after declaration (Aleksander Jan Bajkowski)
- i40e: Fix XDP program unloading while removing the driver (Michal Kubiak) [Orabug: 36896869] {CVE-2024-41047}
- net: fix rc7's __skb_datagram_iter() (Hugh Dickins)
- octeontx2-af: Fix incorrect value output on error path in rvu_check_rsrc_availability() (Aleksandr Mishin)
- skmsg: Skip zero length skb in sk_msg_recvmsg (Geliang Tang) [Orabug: 36896872] {CVE-2024-41048}
- tcp: fix incorrect undo caused by DSACK of TLP retransmit (Neal Cardwell)
- vfs: don't mod negative dentry count when on shrinker list (Brian Foster)
- fs/dcache: Re-use value stored to dentry->d_flags instead of re-reading (linke li)
- filelock: fix potential use-after-free in posix_lock_inode (Jeff Layton) [Orabug: 36896875] {CVE-2024-41049}
- nilfs2: fix incorrect inode allocation from reserved inodes (Ryusuke Konishi)
- null_blk: Do not allow runt zone with zone capacity smaller then zone size (Damien Le Moal)
- nfc/nci: Add the inconsistency check between the input data length and count (Edward Adam Davis) [Orabug: 36897796] {CVE-2024-42130}
- kbuild: fix short log for AS in link-vmlinux.sh (Masahiro Yamada)
- nvmet: fix a possible leak when destroy a ctrl during qp establishment (Sagi Grimberg) [Orabug: 36897901] {CVE-2024-42152}
- platform/x86: touchscreen_dmi: Add info for the EZpad 6s Pro (hmtheboy154)
- platform/x86: touchscreen_dmi: Add info for GlobalSpace SolT IVW 11.6" tablet (hmtheboy154)
- regmap-i2c: Subtract reg size from max_write (Jim Wylder)
- nvme: adjust multiples of NVME_CTRL_PAGE_SIZE in offset (Kundan Kumar)
- dma-mapping: benchmark: avoid needless copy_to_user if benchmark fails (Fedor Pchelkin)
- nvme-multipath: find NUMA path only for online numa-node (Nilay Shroff)
- ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897 (Jian-Hong Pan)
- fs/ntfs3: Mark volume as dirty if xattr is broken (Konstantin Komarov)
- i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr (Piotr Wojtaszczyk) [Orabug: 36897908] {CVE-2024-42153}
- clk: qcom: gcc-sm6350: Fix gpll6* & gpll7 parents (Luca Weiss)
- media: dw2102: fix a potential buffer overflow (Mauro Carvalho Chehab)
- ima: Avoid blocking in RCU read-side critical section (GUO Zihua) [Orabug: 36835827] {CVE-2024-40947}
- bnx2x: Fix multiple UBSAN array-index-out-of-bounds (Ghadi Elie Rahme) [Orabug: 36897884] {CVE-2024-42148}
- mtd: rawnand: rockchip: ensure NVDDR timings are rejected (Val Packett)
- mtd: rawnand: Bypass a couple of sanity checks during NAND identification (Miquel Raynal)
- mtd: rawnand: Ensure ECC configuration is propagated to upper layers (Miquel Raynal)
- drm/amdgpu/atomfirmware: silence UBSAN warning (Alex Deucher)
- drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes (Ma Ke) [Orabug: 36897639] {CVE-2024-42101}
- fsnotify: Do not generate events for O_PATH file descriptors (Jan Kara)
- can: kvaser_usb: Explicitly initialize family in leafimx driver_info struct (Jimmy Assarsson)
- Bluetooth: qca: Fix BT enable failure again for QCA6390 after warm reboot (Zijun Hu) [Orabug: 36897825] {CVE-2024-42137}
- btrfs: fix adding block group to a reclaim list and the unused list during reclaim (Naohiro Aota) [Orabug: 36934739] {CVE-2024-42103}
- mm: avoid overflows in dirty throttling logic (Jan Kara) [Orabug: 36897802] {CVE-2024-42131}
- mm: optimize the redundant loop of mm_update_owner_next() (Jinliang Zheng)
- nilfs2: add missing check for inode numbers on directory entries (Ryusuke Konishi) [Orabug: 36897651] {CVE-2024-42104}
- nilfs2: fix inode number range checks (Ryusuke Konishi) [Orabug: 36897657] {CVE-2024-42105}
- Revert "igc: fix a log entry using uninitialized netdev" (Sasha Neftin)
- gpiolib: of: add polarity quirk for TSC2005 (Dmitry Torokhov)
- gpiolib: of: add a quirk for reset line polarity for Himax LCDs (Dmitry Torokhov)
- gpiolib: of: factor out code overriding gpio line polarity (Dmitry Torokhov)
- inet_diag: Initialize pad field in struct inet_diag_req_v2 (Shigeru Yoshida) [Orabug: 36897665] {CVE-2024-42106}
- selftests: make order checking verbose in msg_zerocopy selftest (Zijian Zhang)
- selftests: fix OOM in msg_zerocopy selftest (Zijian Zhang)
- bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() (Sam Sun) [Orabug: 36825247] {CVE-2024-39487}
- netfilter: nf_tables: unconditionally flush pending work before notifier (Florian Westphal) [Orabug: 36897676] {CVE-2024-42109}
- riscv: kexec: Avoid deadlock in kexec crash path (Song Shuai) [Orabug: 36897831] {CVE-2024-42140}
- wifi: wilc1000: fix ies_len type in connect path (Jozef Hopko)
- net: allow skb_datagram_iter to be called from any context (Sagi Grimberg)
- e1000e: Fix S0ix residency on corporate systems (Dima Ruinskiy)
- KVM: s390: fix LPSWEY handling (Christian Borntraeger)
- tcp_metrics: validate source addr length (Jakub Kicinski) [Orabug: 36897914] {CVE-2024-42154}
- UPSTREAM: tcp: fix DSACK undo in fast recovery to call tcp_try_to_open() (Neal Cardwell)
- tools/power turbostat: Remember global max_die_id (Len Brown)
- s390/pkey: Wipe sensitive data on failure (Holger Dengler) [Orabug: 36897933] {CVE-2024-42157}
- jffs2: Fix potential illegal address access in jffs2_free_inode (Wang Yong) [Orabug: 36897693] {CVE-2024-42115}
- bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD (Jose E. Marchesi) [Orabug: 36897964] {CVE-2024-42161}
- igc: fix a log entry using uninitialized netdev (Corinna Vinschen) [Orabug: 36897705] {CVE-2024-42116}
- powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#" (Greg Kurz)
- kunit: Fix timeout message (Mickaël Salaün)
- orangefs: fix out-of-bounds fsid access (Mike Marshall) [Orabug: 36897836] {CVE-2024-42143}
- powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for CONFIG_PCI=n (Michael Ellerman)
- i2c: i801: Annotate apanel_addr as __ro_after_init (Heiner Kallweit)
- media: dvb-frontends: tda10048: Fix integer overflow (Ricardo Ribalda) [Orabug: 36897975] {CVE-2024-42223}
- media: s2255: Use refcount_t instead of atomic_t for num_channels (Ricardo Ribalda)
- media: dvb-frontends: tda18271c2dd: Remove casting during div (Ricardo Ribalda)
- net: dsa: mv88e6xxx: Correct check for empty list (Simon Horman) [Orabug: 36897981] {CVE-2024-42224}
- wifi: mt76: replace skb_put with skb_put_zero (Felix Fietkau) [Orabug: 36897988] {CVE-2024-42225}
- Input: ff-core - prefer struct_size over open coded arithmetic (Erick Archer)
- firmware: dmi: Stop decoding on broken entry (Jean Delvare)
- sctp: prefer struct_size over open coded arithmetic (Erick Archer)
- media: dw2102: Don't translate i2c read into write (Michael Bunk)
- drm/amd/display: Skip finding free audio for unknown engine_id (Alex Hung) [Orabug: 36897725] {CVE-2024-42119}
- drm/amd/display: Check pipe offset before setting vblank (Alex Hung) [Orabug: 36897731] {CVE-2024-42120}
- drm/amd/display: Check index msg_id before read or write (Alex Hung) [Orabug: 36897738] {CVE-2024-42121}
- drm/amdgpu: Initialize timestamp for some legacy SOCs (Ma Jun)
- crypto: aead,cipher - zeroize key buffer after use (Hailey Mothershead) [Orabug: 36898013] {CVE-2024-42229}
- scsi: qedf: Make qedf_execute_tmf() non-preemptible (John Meneghini) [Orabug: 36897759] {CVE-2024-42124}
- IB/core: Implement a limit on UMAD receive List (Michael Guralnik) [Orabug: 36897846] {CVE-2024-42145}
- media: dvb-usb: dib0700_devices: Add missing release_firmware() (Ricardo Ribalda)
- media: dvb: as102-fe: Fix as10x_register_addr packing (Ricardo Ribalda)
- drm/lima: fix shared irq handling on driver remove (Erico Nunes) [Orabug: 36897778] {CVE-2024-42127}
- locking/mutex: Introduce devm_mutex_init() (George Stark)
- Compiler Attributes: Add __uninitialized macro (Heiko Carstens)
- LTS version: v5.15.162 (Vijayendra Suman)
- serial: 8250_omap: Fix Errata i2310 with RX FIFO level check (Udit Kumar)
- arm64: dts: rockchip: Add sound-dai-cells for RK3368 (Alex Bee)
- arm64: dts: rockchip: fix PMIC interrupt pin on ROCK Pi E (FUKAUMI Naoki)
- ARM: dts: rockchip: rk3066a: add #sound-dai-cells to hdmi node (Johan Jonker)
- KVM: arm64: vgic-v4: Make the doorbell request robust w.r.t preemption (Marc Zyngier)
- efi/x86: Free EFI memory map only when installing a new one. (Ard Biesheuvel)
- efi: xen: Set EFI_PARAVIRT for Xen dom0 boot on all architectures (Ard Biesheuvel)
- efi: memmap: Move manipulation routines into x86 arch tree (Ard Biesheuvel)
- efi: Correct comment on efi_memmap_alloc (Liu Zixian)
- drivers: fix typo in firmware/efi/memmap.c (Zheng Zhi Yuan)
- tcp: Fix data races around icsk->icsk_af_ops. (Kuniyuki Iwashima) [Orabug: 34719865] {CVE-2022-3566}
- ipv6: Fix data races around sk->sk_prot. (Kuniyuki Iwashima) [Orabug: 34719905] {CVE-2022-3567}
- ipv6: annotate some data-races around sk->sk_prot (Eric Dumazet)
- nfs: Leave pages in the pagecache if readpage failed (Matthew Wilcox (Oracle))
- pwm: stm32: Refuse too small period requests (Uwe Kleine-König)
- syscalls: fix sys_fanotify_mark prototype (Arnd Bergmann)
- syscalls: fix compat_sys_io_pgetevents_time64 usage (Arnd Bergmann)
- ftruncate: pass a signed offset (Arnd Bergmann) [Orabug: 36897557] {CVE-2024-42084}
- ata: libata-core: Fix double free on error (Niklas Cassel) [Orabug: 36897373] {CVE-2024-41087}
- ata: ahci: Clean up sysfs file on error (Niklas Cassel)
- batman-adv: Don't accept TT entries for out-of-spec VIDs (Sven Eckelmann)
- drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_hd_modes (Ma Ke) [Orabug: 36897379] {CVE-2024-41089}
- drm/i915/gt: Fix potential UAF by revoke of fence registers (Janusz Krzysztofik) [Orabug: 36897385] {CVE-2024-41092}
- drm/amdgpu: avoid using null object of framebuffer (Julia Zhang) [Orabug: 36897435] {CVE-2024-41093}
- drm/nouveau/dispnv04: fix null pointer dereference in nv17_tv_get_ld_modes (Ma Ke) [Orabug: 36897442] {CVE-2024-41095}
- hexagon: fix fadvise64_64 calling conventions (Arnd Bergmann)
- csky, hexagon: fix broken sys_sync_file_range (Arnd Bergmann)
- sh: rework sync_file_range ABI (Arnd Bergmann)
- kbuild: Install dtb files as 0644 in Makefile.dtbinst (Dragan Simic)
- cpu/hotplug: Fix dynstate assignment in __cpuhp_setup_state_cpuslocked() (Yuntao Wang)
- net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new (Oleksij Rempel)
- net: can: j1939: recover socket queue on CAN bus error during BAM transmission (Oleksij Rempel)
- net: can: j1939: Initialize unused data in j1939_send_one() (Shigeru Yoshida) [Orabug: 36897515] {CVE-2024-42076}
- tty: mcf: MCF54418 has 10 UARTS (Jean-Michel Hautbois)
- serial: 8250_omap: Implementation of Errata i2310 (Udit Kumar) [Orabug: 36897613] {CVE-2024-42095}
- usb: dwc3: core: remove lock of otg mode during gadget suspend/resume to avoid deadlock (Meng Li) [Orabug: 36897563] {CVE-2024-42085}
- usb: atm: cxacru: fix endpoint checking in cxacru_bind() (Nikita Zhandarovich) [Orabug: 36897450] {CVE-2024-41097}
- usb: musb: da8xx: fix a resource leak in probe() (Dan Carpenter)
- usb: gadget: printer: fix races against disable (Oliver Neukum)
- usb: gadget: printer: SS+ support (Oliver Neukum)
- net: usb: ax88179_178a: improve link status logs (Jose Ignacio Tornos Martinez)
- iio: chemical: bme680: Fix sensor data read operation (Vasileios Amoiridis)
- iio: chemical: bme680: Fix overflows in compensate() functions (Vasileios Amoiridis) [Orabug: 36897565] {CVE-2024-42086}
- iio: chemical: bme680: Fix calibration data variable (Vasileios Amoiridis)
- iio: chemical: bme680: Fix pressure value output (Vasileios Amoiridis)
- iio: accel: fxls8962af: select IIO_BUFFER & IIO_KFIFO_BUF (Alexander Sverdlin)
- iio: adc: ad7266: Fix variable checking bug (Fernando Yang)
- i2c: testunit: discard write requests while old command is running (Wolfram Sang)
- i2c: testunit: don't erase registers after STOP (Wolfram Sang)
- mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro() (Adrian Hunter)
- mmc: sdhci: Do not invert write-protect twice (Adrian Hunter)
- mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos (Ilpo Järvinen)
- ocfs2: fix DIO failure due to insufficient transaction credits (Jan Kara) [Orabug: 36897528] {CVE-2024-42077}
- parisc: use generic sys_fanotify_mark implementation (Arnd Bergmann)
- x86: stop playing stack games in profile_pc() (Linus Torvalds) [Orabug: 36897615] {CVE-2024-42096}
- gpiolib: cdev: Disallow reconfiguration without direction (uAPI v1) (Kent Gibson)
- gpio: davinci: Validate the obtained number of IRQs (Aleksandr Mishin) [Orabug: 36897598] {CVE-2024-42092}
- drm/panel: simple: Add missing display timing flags for KOE TX26D202VM0BWA (Liu Ying)
- nvme: fixup comment for nvme RDMA Provider Type (Hannes Reinecke)
- drm/radeon/radeon_display: Decrease the size of allocated memory (Erick Archer)
- soc: ti: wkup_m3_ipc: Send NULL dummy message instead of pointer message (Andrew Davis)
- media: dvbdev: Initialize sbuf (Ricardo Ribalda)
- ALSA: emux: improve patch ioctl data validation (Oswald Buddenhagen) [Orabug: 36897623] {CVE-2024-42097}
- crypto: ecdh - explicitly zeroize private_key (Joachim Vandersmissen) [Orabug: 36897630] {CVE-2024-42098}
- net/dpaa2: Avoid explicit cpumask var allocation on stack (Dawei Li) [Orabug: 36897601] {CVE-2024-42093}
- net/iucv: Avoid explicit cpumask var allocation on stack (Dawei Li) [Orabug: 36897607] {CVE-2024-42094}
- RDMA/restrack: Fix potential invalid address access (Wenchao Hao) [Orabug: 36897540] {CVE-2024-42080}
- bpf: Add a check for struct bpf_fib_lookup size (Anton Protopopov)
- mtd: partitions: redboot: Added conversion of operands to a larger type (Denis Arefev)
- x86/fpu: Fix AMD X86_BUG_FXSAVE_LEAK fixup (Uros Bizjak)
- vduse: Temporarily fail if control queue feature requested (Maxime Coquelin)
- vduse: validate block features only with block devices (Maxime Coquelin)
- drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers that sleep (Laurent Pinchart) [Orabug: 36897569] {CVE-2024-42087}
- bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro() (Christophe Leroy) [Orabug: 36897491] {CVE-2024-42068}
- netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers (Pablo Neira Ayuso) [Orabug: 36897499] {CVE-2024-42070}
- tcp: fix tcp_rcv_fastopen_synack() to enter TCP_CA_Loss for failed TFO (Neal Cardwell)
- parisc: use correct compat recv/recvfrom syscalls (Arnd Bergmann)
- sparc: fix compat recv/recvfrom syscalls (Arnd Bergmann)
- sparc: fix old compat_sys_select() (Arnd Bergmann)
- Fix race for duplicate reqsk on identical SYN (luoxuanqiang)
- xdp: Remove WARN() from __xdp_reg_mem_model() (Daniil Dulov) [Orabug: 36897553] {CVE-2024-42082}
- net: phy: micrel: add Microchip KSZ 9477 to the device table (Enguerrand de Ribaucourt)
- ibmvnic: Free any outstanding tx skbs during scrq reset (Nick Child)
- net: dsa: microchip: fix initial port flush problem (Tristram Ha)
- ASoC: fsl-asoc-card: set priv->pdev before using it (Elinor Montmasson) [Orabug: 36897577] {CVE-2024-42089}
- net: stmmac: Assign configured channel value to EXTTS event (Oleksij Rempel)
- net: mdio: add helpers to extract clause 45 regad and devad fields (Russell King (Oracle))
- drm/amdgpu: fix UBSAN warning in kv_dpm.c (Alex Deucher) [Orabug: 36835991] {CVE-2024-40987}
- cifs: fix typo in module parameter enable_gcm_256 (Steve French)
- pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set (Huang-Huang Bao)
- pinctrl: rockchip: use dedicated pinctrl type for RK3328 (Huang-Huang Bao)
- pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins (Huang-Huang Bao)
- pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins (Huang-Huang Bao)
- pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER (Hagar Hemdan) [Orabug: 36897585] {CVE-2024-42090}
- Input: ili210x - fix ili251x_read_touch_data() return value (John Keeping)
- gve: Clear napi->skb before dev_kfree_skb_any() (Ziwei Xiao) [Orabug: 36835798] {CVE-2024-40937}
- gve: Add RX context. (David Awogbemila)
- ACPI: x86: Force StorageD3Enable on more products (Mario Limonciello)
- ACPI: x86: utils: Add Picasso to the list for forcing StorageD3Enable (Mario Limonciello)
- smb: client: fix deadlock in smb2_find_smb_tcon() (Enzo Matsumiya) [Orabug: 36774640] {CVE-2024-39468}
- x86/amd_nb: Check for invalid SMN reads (Yazen Ghannam)
- PCI: Add PCI_ERROR_RESPONSE and related definitions (Naveen Naidu)
- perf/core: Fix missing wakeup when waiting for context reference (Haifeng Xu)
- riscv: fix overlap of allocated page and PTR_ERR (Nam Cao)
- riscv: mm: init: try best to use IS_ENABLED(CONFIG_64BIT) instead of #ifdef (Jisheng Zhang)
- kheaders: explicitly define file modes for archived headers (Matthias Maennich)
- Revert "kheaders: substituting --sort in archive creation" (Masahiro Yamada)
- drm/i915/gt: Disarm breadcrumbs if engines are already idle (Chris Wilson)
- drm/i915/gt: Only kick the signal worker if there's been an update (Chris Wilson)
- ksmbd: ignore trailing slashes in share paths (Nandor Kracser)
- x86/cpu: Fix x86_match_cpu() to match just X86_VENDOR_INTEL (Tony Luck)
- x86/cpu/vfm: Add new macros to work with (vendor/family/model) values (Tony Luck)
- tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test (Jeff Johnson)
- bcache: fix variable length array abuse in btree_iter (Matthew Mirvish) [Orabug: 36809293] {CVE-2024-39482}
- pmdomain: ti-sci: Fix duplicate PD referrals (Tomi Valkeinen)
- wifi: rtlwifi: rtl8192de: Fix 5 GHz TX power (Bitterblue Smith)
- rtlwifi: rtl8192de: Style clean-ups (Kees Cook)
- ARM: dts: samsung: smdk4412: fix keypad no-autorepeat (Krzysztof Kozlowski)
- ARM: dts: samsung: exynos4412-origen: fix keypad no-autorepeat (Krzysztof Kozlowski)
- ARM: dts: samsung: smdkv310: fix keypad no-autorepeat (Krzysztof Kozlowski)
- perf script: Show also errors for --insn-trace option (Adrian Hunter)
- perf: script: add raw|disasm arguments to --insn-trace option (Changbin Du)
- drm/amd/display: revert Exit idle optimizations before HDCP execution (Martin Leung)
- arm64: dts: imx8qm-mek: fix gpio number for reg_usdhc2_vmmc (Frank Li)
- dt-bindings: i2c: google,cros-ec-i2c-tunnel: correct path to i2c-controller schema (Krzysztof Kozlowski)
- i2c: ocores: set IACK bit after core is enabled (Grygorii Tertychnyi)
- tcp: clear tp->retrans_stamp in tcp_rcv_fastopen_synack() (Eric Dumazet)
- kcov: don't lose track of remote references during softirqs (Aleksandr Nogikh)
- gcov: add support for GCC 14 (Peter Oberparleiter)
- drm/radeon: fix UBSAN warning in kv_dpm.c (Alex Deucher) [Orabug: 36835996] {CVE-2024-40988}
- drm/i915/mso: using joiner is not possible with eDP MSO (Jani Nikula)
- ALSA: hda/realtek: Limit mic boost on N14AP7 (Edson Juliano Drosdeck)
- KVM: x86: Always sync PIR to IRR prior to scanning I/O APIC routes (Sean Christopherson)
- btrfs: retry block group reclaim without infinite loop (Boris Burkov)
- net: do not leave a dangling sk pointer, when socket creation fails (Ignat Korchagin)
- serial: stm32: rework RX over DMA (Erwan Le Ray)
- RDMA/mlx5: Add check for srq max_sge attribute (Patrisious Haddad) [Orabug: 36836003] {CVE-2024-40990}
- ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." (Raju Rangoju)
- regulator: bd71815: fix ramp values (Kalle Niemi)
- dmaengine: ioatdma: Fix missing kmem_cache_destroy() (Nikita Shubin)
- dmaengine: ioatdma: Fix kmemleak in ioat_pci_probe() (Nikita Shubin)
- dmaengine: ioatdma: Fix error path in ioat3_dma_probe() (Nikita Shubin)
- dmaengine: ioat: use PCI core macros for PCIe Capability (Bjorn Helgaas)
- dmaengine: ioatdma: Fix leaking on version mismatch (Nikita Shubin)
- dmaengine: ioat: Drop redundant pci_enable_pcie_error_reporting() (Bjorn Helgaas)
- dmaengine: ioat: switch from 'pci_' to 'dma_' API (Qing Wang)
- dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list (Li RongQing) [Orabug: 36835844] {CVE-2024-40956}
- regulator: core: Fix modpost error "regulator_get_regmap" undefined (Biju Das)
- net: usb: rtl8150 fix unintiatilzed variables in rtl8150_get_link_ksettings (Oliver Neukum)
- bnxt_en: Restore PTP tx_avail count in case of skb_pad() error (Pavan Chebbi)
- seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors (Jianguo Wu) [Orabug: 36835846] {CVE-2024-40957}
- netfilter: ipset: Fix suspicious rcu_dereference_protected() (Jozsef Kadlecsik) [Orabug: 36836326] {CVE-2024-40993}
- octeontx2-pf: Add error handling to VLAN unoffload handling (Simon Horman)
- virtio_net: checksum offloading handling fix (Heng Qi)
- net: stmmac: No need to calculate speed divider when offload is disabled (Xiaolei Wang)
- ptp: fix integer overflow in max_vclocks_store (Dan Carpenter) [Orabug: 36836016] {CVE-2024-40994}
- sched: act_ct: add netns into the key of tcf_ct_flow_table (Xin Long)
- net/sched: act_ct: set 'net' pointer when creating new nf_flow_table (Vlad Buslov)
- tipc: force a dst refcount before doing decryption (Xin Long) [Orabug: 36835980] {CVE-2024-40983}
- net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() (David Ruth) [Orabug: 36836018] {CVE-2024-40995}
- net/sched: act_api: rely on rcu in tcf_idr_check_alloc (Pedro Tammela)
- qca_spi: Make interrupt remembering atomic (Stefan Wahren)
- netns: Make get_net_ns() handle zero refcount net (Yue Haibing) [Orabug: 36835848] {CVE-2024-40958}
- xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() (Eric Dumazet) [Orabug: 36835851] {CVE-2024-40959}
- ipv6: prevent possible NULL dereference in rt6_probe() (Eric Dumazet) [Orabug: 36835856] {CVE-2024-40960}
- ipv6: prevent possible NULL deref in fib6_nh_init() (Eric Dumazet) [Orabug: 36835861] {CVE-2024-40961}
- netrom: Fix a memory leak in nr_heartbeat_expiry() (Gavrilov Ilia) [Orabug: 36836085] {CVE-2024-41006}
- cipso: fix total option length computation (Ondrej Mosnacek)
- tracing: Build event generation tests only as modules (Masami Hiramatsu (Google))
- mips: bmips: BCM6358: make sure CBR is correctly set (Christian Marangi) [Orabug: 36835869] {CVE-2024-40963}
- MIPS: Routerboard 532: Fix vendor retry check code (Ilpo Järvinen)
- serial: exar: adding missing CTI and Exar PCI ids (Parker Newman)
- serial: imx: Introduce timeout when waiting on transmitter empty (Esben Haabendal) [Orabug: 36835886] {CVE-2024-40967}
- MIPS: Octeon: Add PCIe link status check (Songyang Li) [Orabug: 36835892] {CVE-2024-40968}
- PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports (Mario Limonciello)
- udf: udftime: prevent overflow in udf_disk_stamp_to_time() (Roman Smirnov)
- Avoid hw_desc array overrun in dw-axi-dmac (Joao Pinto) [Orabug: 36835903] {CVE-2024-40970}
- usb: misc: uss720: check for incompatible versions of the Belkin F5U002 (Alex Henrie)
- f2fs: remove clear SB_INLINECRYPT flag in default_options (Yunlei He) [Orabug: 36835908] {CVE-2024-40971}
- iommu/arm-smmu-v3: Free MSIs in case of ENOMEM (Aleksandr Aprelkov)
- power: supply: cros_usbpd: provide ID table for avoiding fallback match (Tzung-Bi Shih)
- powerpc/io: Avoid clang null pointer arithmetic warnings (Michael Ellerman)
- powerpc/pseries: Enforce hcall result buffer validity and size (Nathan Lynch) [Orabug: 36835925] {CVE-2024-40974}
- drm/lima: mask irqs in timeout path before hard reset (Erico Nunes) [Orabug: 36835935] {CVE-2024-40976}
- drm/lima: add mask irq callback to gp and pp (Erico Nunes)
- drm/amd/display: Exit idle optimizations before HDCP execution (Nicholas Kazlauskas)
- Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl (Uri Arev)
- ACPI: video: Add backlight=native quirk for Lenovo Slim 7 16ARH7 (Takashi Iwai)
- HID: Add quirk for Logitech Casa touchpad (Sean O'Brien)
- netpoll: Fix race condition in netpoll_owner_active (Breno Leitao) [Orabug: 36836079] {CVE-2024-41005}
- kselftest: arm64: Add a null pointer check (Kunwu Chan)
- scsi: qedi: Fix crash while reading debugfs attribute (Manish Rangankar) [Orabug: 36835946] {CVE-2024-40978}
- drop_monitor: replace spin_lock by raw_spin_lock (Wander Lairson Costa) [Orabug: 36835959] {CVE-2024-40980}
- af_packet: avoid a false positive warning in packet_setsockopt() (Eric Dumazet)
- wifi: ath9k: work around memset overflow warning (Arnd Bergmann)
- batman-adv: bypass empty buckets in batadv_purge_orig_ref() (Eric Dumazet) [Orabug: 36835965] {CVE-2024-40981}
- selftests/bpf: Fix flaky test btf_map_in_map/lookup_update (Yonghong Song)
- selftests/bpf: Prevent client connect before server bind in test_tc_tunnel.sh (Alessandro Carminati (Red Hat))
- block/ioctl: prefer different overflow check (Justin Stitt) [Orabug: 36836043] {CVE-2024-41000}
- rcutorture: Fix invalid context warning when enable srcu barrier testing (Zqiang)
- rcutorture: Make stall-tasks directly exit when rcutorture tests end (Zqiang)
- rcutorture: Fix rcu_torture_one_read() pipe_count overflow comment (Paul E. McKenney)
- crypto: hisilicon/sec - Fix memory leak for sec resource release (Chenghai Huang) [Orabug: 36836053] {CVE-2024-41002}
- padata: Disable BH when taking works lock on MT path (Herbert Xu)
- Bluetooth: qca: fix info leak when fetching board id (Johan Hovold) [Orabug: 36934735] {CVE-2024-36033}
- Bluetooth: qca: Fix error code in qca_read_fw_build_info() (Dan Carpenter)
- zap_pid_ns_processes: clear TIF_NOTIFY_SIGNAL along with TIF_SIGPENDING (Oleg Nesterov)
- i2c: designware: Fix the functionality flags of the slave-only interface (Jean Delvare)
- i2c: at91: Fix the functionality flags of the slave-only interface (Jean Delvare)
- usb-storage: alauda: Check whether the media is initialized (Shichao Lai) [Orabug: 36753733] {CVE-2024-38619}
- greybus: Fix use-after-free bug in gb_interface_release due to race condition. (Sicong Huang) [Orabug: 36835563] {CVE-2024-39495}
- kbuild: Remove support for Clang's ThinLTO caching (Nathan Chancellor)
- mptcp: pm: update add_addr counters after connect (YonglongLi)
- mptcp: pm: inc RmAddr MIB counter once per RM_ADDR ID (YonglongLi)
- hugetlb_encode.h: fix undefined behaviour (34 speed with the portTransmitRate from the tc-cbs parameters (Xiaolei Wang)
- net/mlx5e: Fix features validation check for tunneled UDP (non-VXLAN) packets (Gal Pressman)
- tcp: fix race in tcp_v6_syn_recv_sock() (Eric Dumazet)
- drm/bridge/panel: Fix runtime warning on panel bridge release (Adam Miotk)
- drm/komeda: check for error-valued pointer (Amjad Ouled-Ameur) [Orabug: 36835673] {CVE-2024-39505}
- liquidio: Adjust a NULL pointer handling path in lio_vf_rep_copy_packet (Aleksandr Mishin) [Orabug: 36835676] {CVE-2024-39506}
- net: hns3: add cond_resched() to hns3 ring buffer init process (Jie Wang)
- net: hns3: fix kernel crash problem in concurrent scenario (Yonglong Liu) [Orabug: 36835679] {CVE-2024-39507}
- net: sfp: Always call sfp_sm_mod_remove() on remove (Csókás, Bence)
- drm/vmwgfx: 3D disabled should not effect STDU memory limits (Ian Forbes)
- HID: logitech-dj: Fix memory leak in logi_dj_recv_switch_to_dj_mode() (José Expósito) [Orabug: 36835792] {CVE-2024-40934}
- iommu: Return right value in iommu_sva_bind_device() (Lu Baolu) [Orabug: 36835823] {CVE-2024-40945}
- iommu/amd: Fix sysfs leak in iommu init (Kun(llfl))
- iommu/amd: Introduce pci segment structure (Vasant Hegde)
- HID: core: remove unnecessary WARN_ON() in implement() (Nikita Zhandarovich) [Orabug: 36835688] {CVE-2024-39509}
- gpio: tqmx86: store IRQ trigger type and unmask status separately (Matthias Schiffer)
- gpio: tqmx86: fix typo in Kconfig label (Gregor Herburger)
- platform/x86: dell-smbios: Fix wrong token data in sysfs (Armin Wolf)
- platform/x86: dell-smbios-base: Use sysfs_emit() (ye xingchen)
- SUNRPC: return proper error from gss_wrap_req_priv (Chen Hanxiao)
- clk: sifive: Do not register clkdevs for PRCI clocks (Samuel Holland)
- Input: try trimming too long modalias strings (Dmitry Torokhov)
- powerpc/uaccess: Fix build errors seen with GCC 13/14 (Michael Ellerman)
- scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory (Breno Leitao) [Orabug: 36835695] {CVE-2024-40901}
- xhci: Apply broken streams quirk to Etron EJ188 xHCI host (Kuangyi Chiang)
- xhci: Handle TD clearing for multiple streams case (Hector Martin) [Orabug: 36835772] {CVE-2024-40927}
- xhci: Apply reset resume quirk to Etron EJ188 xHCI host (Kuangyi Chiang)
- xhci: Set correct transferred length for cancelled bulk transfers (Mathias Nyman)
- jfs: xattr: fix buffer overflow for invalid xattr (Greg Kroah-Hartman) [Orabug: 36835700] {CVE-2024-40902}
- mei: me: release irq in mei_me_pci_resume error path (Tomas Winkler)
- usb: typec: tcpm: Ignore received Hard Reset in TOGGLING state (Kyle Tso)
- USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages (Alan Stern) [Orabug: 36835708] {CVE-2024-40904}
- nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors (Ryusuke Konishi) [Orabug: 36774645] {CVE-2024-39469}
- nilfs2: return the mapped address from nilfs_get_page() (Matthew Wilcox (Oracle))
- nilfs2: Remove check for PageError (Matthew Wilcox (Oracle))
- btrfs: fix leak of qgroup extent records after transaction abort (Filipe Manana)
- wifi: ath10k: fix QCOM_RPROC_COMMON dependency (Dmitry Baryshkov)
- selftests/mm: compaction_test: fix bogus test success on Aarch64 (Dev Jain)
- selftests/mm: conform test to TAP format output (Muhammad Usama Anjum)
- selftests/mm: compaction_test: fix incorrect write of zero to nr_hugepages (Dev Jain)
- mm/cma: drop incorrect alignment check in cma_init_reserved_mem (Frank van der Linden)
- cma: factor out minimum alignment requirement (David Hildenbrand)
- i2c: acpi: Unbind mux adapters before delete (Hamish Martin) [Orabug: 36774617] {CVE-2024-39362}
- i2c: add fwnode APIs (Russell King (Oracle))
- mmc: davinci: Don't strip remove function when driver is builtin (Uwe Kleine-König) [Orabug: 36809300] {CVE-2024-39484}
- mmc: davinci_mmc: Convert to platform remove callback returning void (Yangtao Li)
- ftrace: Fix possible use-after-free issue in ftrace_location() (Zheng Yejian) [Orabug: 36753573] {CVE-2024-38588}
- x86/ibt,ftrace: Search for __fentry__ location (Peter Zijlstra)
- serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler (Hugo Villeneuve)
- serial: sc16is7xx: replace hardcoded divisor value with BIT() macro (Hugo Villeneuve)
- Bluetooth: qca: fix info leak when fetching fw build id (Johan Hovold) [Orabug: 36683103] {CVE-2024-36032}
- Bluetooth: qca: add support for QCA2066 (Tim Jiang)
- Bluetooth: qca: use switch case for soc type behavior (Neil Armstrong)
- Bluetooth: btqca: Add WCN3988 support (Luca Weiss)
- Bluetooth: btqca: use le32_to_cpu for ver.soc_id (Min-Hua Chen)
- Bluetooth: hci_qca: mark OF related data as maybe unused (Krzysztof Kozlowski)
- skbuff: introduce skb_pull_data (Luiz Augusto von Dentz)
- misc/pvpanic-pci: register attributes via pci_driver (Thomas Weißschuh)
- misc/pvpanic: deduplicate common code (Thomas Weißschuh)
- pvpanic: Indentation fixes here and there (Andy Shevchenko)
- pvpanic: Keep single style across modules (Andy Shevchenko)
- drm/amd/display: Fix incorrect DSC instance for MST (Hersen Wu)
- drm/amd/display: drop unnecessary NULL checks in debugfs (Alexey Kodanev)
- drm/amd/display: Clean up some inconsistent indenting (Jiapeng Chong)
- drm/amd/display: Handle Y carry-over in VCP X.Y calculation (George Shen)
- iio: accel: mxc4005: Reset chip on probe() and resume() (Hans de Goede)
- usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete (Wesley Cheng) [Orabug: 36683254] {CVE-2024-36894}
- usb: gadget: f_fs: use io_data->status consistently (John Keeping)
- ipv6: fix possible race in __fib6_drop_pcpu_from() (Eric Dumazet) [Orabug: 36835713] {CVE-2024-40905}
- af_unix: Annotate data-race of sk->sk_shutdown in sk_diag_fill(). (Kuniyuki Iwashima)
- af_unix: Use skb_queue_len_lockless() in sk_diag_show_rqlen(). (Kuniyuki Iwashima)
- af_unix: Use skb_queue_empty_lockless() in unix_release_sock(). (Kuniyuki Iwashima)
- af_unix: annotate lockless accesses to sk->sk_err (Eric Dumazet)
- af_unix: Use unix_recvq_full_lockless() in unix_stream_connect(). (Kuniyuki Iwashima)
- af_unix: Annotate data-race of net->unx.sysctl_max_dgram_qlen. (Kuniyuki Iwashima)
- af_unix: Annotate data-races around sk->sk_state in UNIX_DIAG. (Kuniyuki Iwashima)
- af_unix: Annotate data-race of sk->sk_state in unix_stream_read_skb(). (Kuniyuki Iwashima)
- af_unix: Annotate data-races around sk->sk_state in sendmsg() and recvmsg(). (Kuniyuki Iwashima)
- af_unix: Annotate data-race of sk->sk_state in unix_stream_connect(). (Kuniyuki Iwashima)
- af_unix: Annotate data-races around sk->sk_state in unix_write_space() and poll(). (Kuniyuki Iwashima)
- af_unix: Annotate data-race of sk->sk_state in unix_inq_len(). (Kuniyuki Iwashima)
- af_unix: Annodate data-races around sk->sk_state for writers. (Kuniyuki Iwashima)
- af_unix: Set sk->sk_state under unix_state_lock() for truly disconencted peer. (Kuniyuki Iwashima)
- ptp: Fix error message on failed pin verification (Karol Kolacinski)
- net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP (Eric Dumazet) [Orabug: 36748168] {CVE-2024-36974}
- tcp: count CLOSE-WAIT sockets for TCP_MIB_CURRESTAB (Jason Xing)
- net: sched: sch_multiq: fix possible OOB write in multiq_tune() (Hangyu Hua) [Orabug: 36748175] {CVE-2024-36978}
- octeontx2-af: Always allocate PF entries from low prioriy zone (Subbaraya Sundeep)
- bpf: Set run context for rawtp test_run callback (Jiri Olsa) [Orabug: 36835722] {CVE-2024-40908}
- ipv6: sr: block BH in seg6_output_core() and seg6_input_core() (Eric Dumazet)
- net/ncsi: Fix the multi thread manner of NCSI driver (DelphineCCChiu)
- net/ncsi: Simplify Kconfig/dts control flow (Peter Delevoryas)
- wifi: mac80211: correctly parse Spatial Reuse Parameter Set element (Lingbo Kong)
- wifi: iwlwifi: mvm: don't read past the mfuart notifcation (Emmanuel Grumbach) [Orabug: 36835807] {CVE-2024-40941}
- wifi: iwlwifi: mvm: check n_ssids before accessing the ssids (Miri Korenblit) [Orabug: 36835779] {CVE-2024-40929}
- wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of debugfs ifdef (Shahar S Matityahu)
- wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64 (Johannes Berg)
- wifi: cfg80211: pmsr: use correct nla_get_uX functions (Lin Ma)
- wifi: cfg80211: Lock wiphy in cfg80211_get_station (Remi Pommarel) [Orabug: 36835729] {CVE-2024-40911}
- wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup() (Remi Pommarel) [Orabug: 36835734] {CVE-2024-40912}
- wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects (Nicolas Escande) [Orabug: 36835811] {CVE-2024-40942}



ELSA-2024-4943 Important: Oracle Linux 7 httpd security update (aarch64)


Oracle Linux Security Advisory ELSA-2024-4943

http://linux.oracle.com/errata/ELSA-2024-4943.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
httpd-2.4.6-99.0.3.el7_9.1.aarch64.rpm
httpd-devel-2.4.6-99.0.3.el7_9.1.aarch64.rpm
httpd-manual-2.4.6-99.0.3.el7_9.1.noarch.rpm
httpd-tools-2.4.6-99.0.3.el7_9.1.aarch64.rpm
mod_session-2.4.6-99.0.3.el7_9.1.aarch64.rpm
mod_ssl-2.4.6-99.0.3.el7_9.1.aarch64.rpm
mod_ldap-2.4.6-99.0.3.el7_9.1.aarch64.rpm
mod_proxy_html-2.4.6-99.0.3.el7_9.1.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//httpd-2.4.6-99.0.3.el7_9.1.src.rpm

Related CVEs:

CVE-2024-38474
CVE-2024-38475
CVE-2024-38477

Description of changes:

[2.4.6-99.0.3.1]
- Opt-ins for unsafe prefix_stat and %3f [Orabug: 36904263][CVE-2024-38474][CVE-2024-38475]
- mod_proxy: validate hostname [Orabug: 36904263][CVE-2024-38477]



ELBA-2024-12664 Oracle Linux 9 audit bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12664

http://linux.oracle.com/errata/ELBA-2024-12664.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
audispd-plugins-3.1.2-2.0.1.el9.x86_64.rpm
audispd-plugins-zos-3.1.2-2.0.1.el9.x86_64.rpm
audit-3.1.2-2.0.1.el9.x86_64.rpm
audit-libs-3.1.2-2.0.1.el9.i686.rpm
audit-libs-3.1.2-2.0.1.el9.x86_64.rpm
audit-libs-devel-3.1.2-2.0.1.el9.i686.rpm
audit-libs-devel-3.1.2-2.0.1.el9.x86_64.rpm
python3-audit-3.1.2-2.0.1.el9.x86_64.rpm

aarch64:
audispd-plugins-3.1.2-2.0.1.el9.aarch64.rpm
audispd-plugins-zos-3.1.2-2.0.1.el9.aarch64.rpm
audit-3.1.2-2.0.1.el9.aarch64.rpm
audit-libs-3.1.2-2.0.1.el9.aarch64.rpm
audit-libs-devel-3.1.2-2.0.1.el9.aarch64.rpm
python3-audit-3.1.2-2.0.1.el9.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//audit-3.1.2-2.0.1.el9.src.rpm

Description of changes:

[3.1.2-2.0.1]
- Modify the error message when audit is disabled to mention that it may be disabled [Orabug: 37040467]



ELBA-2024-6669 Oracle Linux 9 libvirt bug fix and enhancement update


Oracle Linux Bug Fix Advisory ELBA-2024-6669

http://linux.oracle.com/errata/ELBA-2024-6669.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
libvirt-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-client-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-client-qemu-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-common-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-config-network-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-config-nwfilter-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-interface-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-network-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-nodedev-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-nwfilter-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-qemu-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-secret-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-core-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-disk-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-logical-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-mpath-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-rbd-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-driver-storage-scsi-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-kvm-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-lock-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-log-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-plugin-lockd-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-proxy-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-libs-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-nss-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-daemon-plugin-sanlock-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-devel-10.0.0-6.7.0.1.el9_4.x86_64.rpm
libvirt-docs-10.0.0-6.7.0.1.el9_4.x86_64.rpm

aarch64:
libvirt-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-client-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-client-qemu-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-common-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-config-network-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-config-nwfilter-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-interface-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-network-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-nodedev-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-nwfilter-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-qemu-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-secret-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-core-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-disk-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-iscsi-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-logical-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-mpath-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-rbd-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-driver-storage-scsi-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-kvm-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-lock-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-log-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-plugin-lockd-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-proxy-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-libs-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-nss-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-daemon-plugin-sanlock-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-devel-10.0.0-6.7.0.1.el9_4.aarch64.rpm
libvirt-docs-10.0.0-6.7.0.1.el9_4.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//libvirt-10.0.0-6.7.0.1.el9_4.src.rpm

Description of changes:

[10.0.0-6.7.0.1.el9_4]
- Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]

[10.0.0-6.7.el9_4]
- vmx: Allow '*' to appear in VMX file keys (RHEL-58676)



ELBA-2024-12666 Oracle Linux 9 crash bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12666

http://linux.oracle.com/errata/ELBA-2024-12666.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
crash-8.0.5-1.0.2.el9.x86_64.rpm
crash-devel-8.0.5-1.0.2.el9.i686.rpm
crash-devel-8.0.5-1.0.2.el9.x86_64.rpm

aarch64:
crash-8.0.5-1.0.2.el9.aarch64.rpm
crash-devel-8.0.5-1.0.2.el9.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//crash-8.0.5-1.0.2.el9.src.rpm

Description of changes:

[8.0.5-1.0.2]
- Fix crash tool fails with kcore of mainline/LUCI kernels [Orabug: 36928869]



ELBA-2024-12626 Oracle Linux 9 oracle-ocne-release-el9 bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12626

http://linux.oracle.com/errata/ELBA-2024-12626.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
oracle-ocne-release-el9-1.0-5.el9.x86_64.rpm

aarch64:
oracle-ocne-release-el9-1.0-5.el9.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates//oracle-ocne-release-el9-1.0-5.el9.src.rpm

Description of changes:

[1.0-5.el9]
- Deprecate the package with old name of olcne and rename it to ocne
- Added ocne 2.0 repositories for x86_64 and aarch64 on ol8 and ol9

[1.0-5.el9]
- Added olcne version 1.9 repository for x86_64 and aarch64 on ol8 and ol9

[1.0-5.el9]
- Disable all OCNE channels by default

[1.0-5.el9]
- Added olcne version 1.8 repository for x86_64 and aarch64 on ol8 and ol9

[1.0-8]
- Added olcne version 1.7 repository for x86_64 and ol8_developer_olcne repo for aarch64

[1.0-7]
- Added olcne version 1.6 repository for x86_64 [OraBug: 35182554]



ELBA-2024-12625 Oracle Linux 8 oracle-ocne-release-el8 bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12625

http://linux.oracle.com/errata/ELBA-2024-12625.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
oracle-ocne-release-el8-1.0-12.el8.x86_64.rpm

aarch64:
oracle-ocne-release-el8-1.0-12.el8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//oracle-ocne-release-el8-1.0-12.el8.src.rpm

Description of changes:

[1.0-12.el8]
- Deprecate the package with old name of olcne and rename it to ocne
- Added ocne 2.0 repositories for x86_64 and aarch64 on ol8 and ol9

[1.0-12.el8]
- Added olcne version 1.9 repository for x86_64 and aarch64 on ol8 and ol9

[1.0-12.el8]
- Disable all OCNE channels by default

[1.0-12.el8]
- Added olcne version 1.8 repository for x86_64 and aarch64 on ol8 and ol9

[1.0-8]
- Added olcne version 1.7 repository for x86_64 and ol8_developer_olcne repo for aarch64

[1.0-7]
- Added olcne version 1.6 repository for x86_64 [OraBug: 35182554]

[1.0-6]
- Added olcne version 1.5 repository for x86_64 [OraBug: 34111597]

[1.0-5]
- Added olcne developer repository [OraBug: 33820720]

[1.0-4]
- Added olcne version 1.4 repository for aarch64 [OraBug: 33641138]

[1.0-3]
- Added olcne version 1.3 repository for aarch64 [OraBug: 33010226]

[1.0-2]
- Added olcne version 1.3 repository [OraBug: 32914245]

[1.0-1]
- Initial package



ELBA-2024-12638 Oracle Linux 8 audit bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12638

http://linux.oracle.com/errata/ELBA-2024-12638.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
audispd-plugins-3.1.2-1.0.1.el8.x86_64.rpm
audispd-plugins-zos-3.1.2-1.0.1.el8.x86_64.rpm
audit-3.1.2-1.0.1.el8.x86_64.rpm
audit-libs-3.1.2-1.0.1.el8.i686.rpm
audit-libs-3.1.2-1.0.1.el8.x86_64.rpm
audit-libs-devel-3.1.2-1.0.1.el8.i686.rpm
audit-libs-devel-3.1.2-1.0.1.el8.x86_64.rpm
python3-audit-3.1.2-1.0.1.el8.x86_64.rpm

aarch64:
audispd-plugins-3.1.2-1.0.1.el8.aarch64.rpm
audispd-plugins-zos-3.1.2-1.0.1.el8.aarch64.rpm
audit-3.1.2-1.0.1.el8.aarch64.rpm
audit-libs-3.1.2-1.0.1.el8.aarch64.rpm
audit-libs-devel-3.1.2-1.0.1.el8.aarch64.rpm
python3-audit-3.1.2-1.0.1.el8.aarch64.rpm

SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//audit-3.1.2-1.0.1.el8.src.rpm

Description of changes:

[3.1.2-1.0.1]
- Modify the error message when audit is disabled to mention that it may be disabled [Orabug: 37000898]



ELBA-2024-12651 Oracle Linux 7 selinux-policy bug fix update (aarch64)


Oracle Linux Bug Fix Advisory ELBA-2024-12651

http://linux.oracle.com/errata/ELBA-2024-12651.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
selinux-policy-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-devel-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-minimum-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-mls-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-targeted-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-doc-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-sandbox-3.13.1-268.0.25.el7_9.2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//selinux-policy-3.13.1-268.0.25.el7_9.2.src.rpm

Description of changes:

[3.13.1-268.0.25.2]
- Allow kdump_t to serach in xenfs context [Orabug: 36841527]



ELBA-2024-12654 Oracle Linux 7 linux-firmware bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12654

http://linux.oracle.com/errata/ELBA-2024-12654.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
iwl1000-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl100-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl105-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl135-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2000-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2030-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl3160-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwl3945-firmware-15.32.2.9-999.34.el7.noarch.rpm
iwl4965-firmware-228.61.2.24-999.34.el7.noarch.rpm
iwl5000-firmware-8.83.5.1_1-999.34.el7.noarch.rpm
iwl5150-firmware-8.24.2.2-999.34.el7.noarch.rpm
iwl6000-firmware-9.221.4.1-999.34.el7.noarch.rpm
iwl6000g2a-firmware-17.168.5.3-999.34.el7.noarch.rpm
iwl6000g2b-firmware-17.168.5.2-999.34.el7.noarch.rpm
iwl6050-firmware-41.28.5.1-999.34.el7.noarch.rpm
iwl7260-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwlax2xx-firmware-20240715-999.34.el7.noarch.rpm
linux-firmware-20240715-999.34.git4c8fb21e.el7.noarch.rpm

aarch64:
iwl1000-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl100-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl105-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl135-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2000-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2030-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl3160-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwl3945-firmware-15.32.2.9-999.34.el7.noarch.rpm
iwl4965-firmware-228.61.2.24-999.34.el7.noarch.rpm
iwl5000-firmware-8.83.5.1_1-999.34.el7.noarch.rpm
iwl5150-firmware-8.24.2.2-999.34.el7.noarch.rpm
iwl6000-firmware-9.221.4.1-999.34.el7.noarch.rpm
iwl6000g2a-firmware-17.168.5.3-999.34.el7.noarch.rpm
iwl6000g2b-firmware-17.168.5.2-999.34.el7.noarch.rpm
iwl6050-firmware-41.28.5.1-999.34.el7.noarch.rpm
iwl7260-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwlax2xx-firmware-20240715-999.34.el7.noarch.rpm
linux-firmware-20240715-999.34.git4c8fb21e.el7.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//linux-firmware-20240715-999.34.git4c8fb21e.el7.src.rpm

Description of changes:

[20240715-999.34.git4c8fb21e.el7]
- Rebase to latest upstream [Orabug: 36826157]

[20240606-999.33.git90df68d2.el7]
- Rebase to latest upstream [Orabug: 36706197]

[20240415-999.32.git5da74b16.el7]
- Rebase to latest upstream [Orabug: 36482906]

[20240122-999.31.gitbf0987d3.el7]
- Rebase to latest upstream [Orabug: 36174455]
- Remove python3 dependency for linux-firmware [Orabug: 36067969]
- Ignore duplicates as we don't have rdfind installed [Orabug: 36242384]
- Avoid conflicts when upgrading from OL7 to OL8 [Orabug: 36077380]

[20231102-999.29.git2b304bfe.el7]
- Rebase to latest upstream [Orabug: 35978299]
- Update AMD Genoa microcode from upstream commit [Orabug: 35965948]

[20231025-999.28.git4ee01756.el7]
- Rebase to upstream and contains AMD fix [Orabug: 35933859]
- Add some iwlwifi-gl* files to be included to rpm package [Orabug: 35933859]
- Make python3 as the default version for specfile [Orabug: 35933859]

[20230516-999.27.git6c9e0ed5.el7]
- Update firmware for qat_4xxx devices [Orabug: 35811008]

[20230516-999.26.git6c9e0ed5.el7]
- Run dracut -f in %posttrans instead of %post [Orabug: 35661938]
- Drop latest AMD microcode commits to family 19 file to include Milan microcode but not Genoa [Orabug: 35708511]

[20230516-999.25.git6c9e0ed5.el7]
- Add missing amd-ucode/ files to nano rpm [Orabug: 35642190]
- Add posttrans scriptlet to reload microcode on AMD [Orabug: 35636951]
- Recreate initramfs for AMD systems [Orabug: 35636951]

[20230516-999.24.git6c9e0ed5.el7]
- 8a07fa49 linux-firmware: Update AMD fam19h cpu microcode [Orabug: 35659485]

[20230516-999.22.git6c9e0ed5.el7]
- remove amd-ucode/README [Orabug: 35645306]
- Resolves "Zenbleed" [Orabug: 35650345] {CVE-2023-20593}

[20230516-999.20.git6c9e0ed5.el7]
- cd72938cb480 linux-firmware: Update AMD fam17h cpu microcode
- 92624e57af69 linux-firmware: Update AMD cpu microcode

[20230516-999.19.git6c9e0ed5.el7]
- Rebase to upstream
- Revert removal of old iwlwifi firmwares [Orabug: 35260375]

[20230315-999.18.gitc761dbe8.el7]
- Rebase to upstream [Orabug: 35160866]

[20230227-999.17.git60971a64.el7]
- Revert "qcom: rename Lenovo ThinkPad X13s firmware paths"

[20230227-999.16.git60971a64.el7]
- Fix rpm install issue due to directory replaced by symlink [Orabug: 35112753]
- Rebase to upstream

[20230125-999.15.git5c11a374.el7]
- Rebase to upstream

[20220907-999.14.git2f2f0181.el7]
- Rebase to upstream

[20211203-999.9.gitb0e898fb.el7]
- Move the build env to latest OL chroot.
- Split Intel wireless AX2xx series to a separate package
- Rebase to latest upstream linux-firmware

[20210617-999.8.git0f66b74b.el7]
- Rebase to latest upstream linux-firmware

[20201217-999.7.git7455a360.el7]
- Sync to latest to get fix for CVE-2020-12321 linux-firmware: hardware: buffer overflow in bluetooth firmware (bz# 62321)

[20201016-999.6.git58d41d0f.el7]
- Rebase to latest upstream linux-firmware

[20200902-999.5.gitd5f9eea5.el7]
- Rebase to latest upstream linux-firmware [Orabug: 31782949].

[20200124-999.4.git1eb2408c.el7]
- Rebase to latest upstream firmware [Orabug: 30762405].
- Create symlinks from WHENCE file [Orabug: 30762405]
- Merge iwl7265-firmware rpm files to iwl7260-firmware [Orabug: 30707813].
- Fix linux-firmware package description [Orabug: 30707718].

[20200109-999.3.git67d4ff59.el7]
- Rebase to latest upstream linux-firmware.

[20190627-999.2.git7ae3a09d.el7]
- Rebase to latest upstream linux-firmware.
- Fix rpm build break.

[20181031-999.1.git1baa3486.el7]
- Add Epoch: to guarantee uniqueness.
- Bump RPM version for above change.

[20181031-999.git1baa3486.el7]
- Rebase to latest upstream linux-firmware.
- Sync with RHEL linux-firmware-20180911-69.git85c5d90.el7

[20180906-999.git85c5d90f.el7]
- Rebase to latest upstream linux-firmware.
- Sync with RHEL linux-firmware-20180529-66.git7518922.el7

[20180507-63.git0df406af.0.1.el7]
- Rebase to latest upstream linux-firmware.
- Don't add linux-nano-firmware.list to rpm.
- Remove the temporary files at the cleanup
- Bump release number.

[20180408-60.git8c1e439c.0.1.el7]
- Rebased to latest upstream update.
- Bump release number.

[20171128-58.git17e62881.0.1.el7]
- Update ql2600_fw.bin ql2700_fw.bin ql8300_fw.bin to 8.07.00 [Orabug: 27160935]
- Merge latest upstream change [Orabug: 27210871]
- Fix cxgb4 symlinks [Orabug: 27223984]
- Pack iwl* FW files as separate packages [Orabug: 27174930]
- Bump release number to avoid conflict with existing product build [Orabug: 27256604]

[20171027-56.gitbf042913.0.3.el7]
- Update linux-firmware-base.list with ls_fw.sh and UEK5 dev build [Orabug 27026301]
- For UEK5 kernel-uek-base-4.14.0-1.el7uek.x86_64.rpm and later build.

[20171027-56.gitbf042913.0.2.el7]
- Create UEK5 layout pakcages with linux-firmware-base.list [Orabug 27026301].

[20171027-56.gitbf042913.0.1.el7]
- Merge upstream change and bump up version [Orabug 27026301]

[20170803-56.git7d2c913d.0.1.el7]
- Merge upstream change and bump up version [Orabug 26566815]
- opa: Revert switch firmware back to 0.47 (rhbz 1464629)

[20170411-52.gitb1413458.0.1.el7]
- Merge upstream change and bump up version [Orabug 25861810]

[20170224-51.git432444c5.0.1.el7]
- Merge upstream change for UEK4QU4 [Orabug 25581267]

[20160909-50.gitc883a6b6.0.1.el7]
- Revise release version higher for 7.3 release

[20160909-47.gitc883a6b6]
- Merge update from upstream linux-firmware repo.
- Merge spec update from RHEL7.3 [Orabug 24602475]

[20160604-44.git57b649d9]
- Pull last update from upstream linux-firmware repo. [Orabug 23337630]
- Merged firmware from vendors for bug22066196,bug22066196,bug22003659



ELBA-2024-12653 Oracle Linux 7 linux-firmware bug fix update (aarch64)


Oracle Linux Bug Fix Advisory ELBA-2024-12653

http://linux.oracle.com/errata/ELBA-2024-12653.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
iwl1000-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl100-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl105-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl135-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2000-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2030-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl3160-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwl3945-firmware-15.32.2.9-999.34.el7.noarch.rpm
iwl4965-firmware-228.61.2.24-999.34.el7.noarch.rpm
iwl5000-firmware-8.83.5.1_1-999.34.el7.noarch.rpm
iwl5150-firmware-8.24.2.2-999.34.el7.noarch.rpm
iwl6000-firmware-9.221.4.1-999.34.el7.noarch.rpm
iwl6000g2a-firmware-17.168.5.3-999.34.el7.noarch.rpm
iwl6000g2b-firmware-17.168.5.2-999.34.el7.noarch.rpm
iwl6050-firmware-41.28.5.1-999.34.el7.noarch.rpm
iwl7260-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwlax2xx-firmware-20240715-999.34.el7.noarch.rpm
linux-firmware-20240715-999.34.git4c8fb21e.el7.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//linux-firmware-20240715-999.34.git4c8fb21e.el7.src.rpm

Description of changes:

[20240715-999.34.git4c8fb21e.el7]
- Rebase to latest upstream [Orabug: 36826157]



ELSA-2024-4943 Important: Oracle Linux 7 httpd security update


Oracle Linux Security Advisory ELSA-2024-4943

http://linux.oracle.com/errata/ELSA-2024-4943.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
httpd-2.4.6-99.0.3.el7_9.1.x86_64.rpm
httpd-devel-2.4.6-99.0.3.el7_9.1.x86_64.rpm
httpd-manual-2.4.6-99.0.3.el7_9.1.noarch.rpm
httpd-tools-2.4.6-99.0.3.el7_9.1.x86_64.rpm
mod_ldap-2.4.6-99.0.3.el7_9.1.x86_64.rpm
mod_proxy_html-2.4.6-99.0.3.el7_9.1.x86_64.rpm
mod_session-2.4.6-99.0.3.el7_9.1.x86_64.rpm
mod_ssl-2.4.6-99.0.3.el7_9.1.x86_64.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//httpd-2.4.6-99.0.3.el7_9.1.src.rpm

Related CVEs:

CVE-2024-38474
CVE-2024-38475
CVE-2024-38477

Description of changes:

[2.4.6-99.0.3.1]
- Opt-ins for unsafe prefix_stat and %3f [Orabug: 36904263][CVE-2024-38474][CVE-2024-38475]
- mod_proxy: validate hostname [Orabug: 36904263][CVE-2024-38477]



ELBA-2024-12652 Oracle Linux 7 linux-firmware bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12652

http://linux.oracle.com/errata/ELBA-2024-12652.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
iwl1000-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl100-firmware-39.31.5.1-999.34.el7.noarch.rpm
iwl105-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl135-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2000-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl2030-firmware-18.168.6.1-999.34.el7.noarch.rpm
iwl3160-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwl3945-firmware-15.32.2.9-999.34.el7.noarch.rpm
iwl4965-firmware-228.61.2.24-999.34.el7.noarch.rpm
iwl5000-firmware-8.83.5.1_1-999.34.el7.noarch.rpm
iwl5150-firmware-8.24.2.2-999.34.el7.noarch.rpm
iwl6000-firmware-9.221.4.1-999.34.el7.noarch.rpm
iwl6000g2a-firmware-17.168.5.3-999.34.el7.noarch.rpm
iwl6000g2b-firmware-17.168.5.2-999.34.el7.noarch.rpm
iwl6050-firmware-41.28.5.1-999.34.el7.noarch.rpm
iwl7260-firmware-22.0.7.0-999.34.el7.noarch.rpm
iwlax2xx-firmware-20240715-999.34.el7.noarch.rpm
linux-firmware-20240715-999.34.git4c8fb21e.el7.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//linux-firmware-20240715-999.34.git4c8fb21e.el7.src.rpm

Description of changes:

[20240715-999.34.git4c8fb21e.el7]
- Rebase to latest upstream [Orabug: 36826157]



ELBA-2024-12627 Oracle Linux 7 selinux-policy bug fix update


Oracle Linux Bug Fix Advisory ELBA-2024-12627

http://linux.oracle.com/errata/ELBA-2024-12627.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
selinux-policy-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-devel-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-minimum-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-mls-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-targeted-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-doc-3.13.1-268.0.25.el7_9.2.noarch.rpm
selinux-policy-sandbox-3.13.1-268.0.25.el7_9.2.noarch.rpm

SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates//selinux-policy-3.13.1-268.0.25.el7_9.2.src.rpm

Description of changes:

[3.13.1-268.0.25.2]
- Allow kdump_t to serach in xenfs context [Orabug: 36841527]