-
Tue May 11 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.51.2.el7uek]
- IB/ipoib: Improve latency in ipoib/cm connection formation (Manjunath Patil) [Orabug: 32219842]
- mm: madv_doexec_flag sysctl (Anthony Yznaga) [Orabug: 32387889]
- mm: introduce MADV_DOEXEC (Anthony Yznaga) [Orabug: 32387889]
- exec, elf: require opt-in for accepting preserved mem (Anthony Yznaga) [Orabug: 32387889]
- mm: introduce VM_EXEC_KEEP (Anthony Yznaga) [Orabug: 32387889]
- mm: fail exec if stack expansion will overlap another vma (Anthony Yznaga) [Orabug: 32387889]
- mm: do not assume only the stack vma exists in setup_arg_pages() (Anthony Yznaga) [Orabug: 32387889]
- ELF: when loading PIE binaries check for overlap with existing mappings (Anthony Yznaga) [Orabug: 32387889]
-
Tue May 04 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.51.1.el7uek]
- tcp: grow window for OOO packets only for SACK flows (Eric Dumazet) [Orabug: 30804714]
-
Tue Apr 20 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.50.2.el7uek]
- btrfs: fix race when cloning extent buffer during rewind of an old root (Filipe Manana) [Orabug: 32669454] {CVE-2021-28964}
- xen-blkback: don't leak persistent grants from xen_blkbk_map() (Jan Beulich) [Orabug: 32697855] {CVE-2021-28688}
- netfilter: x_tables: Use correct memory barriers. (Mark Tomlinson) [Orabug: 32709125] {CVE-2021-29650}
- netfilter: x_tables: make xt_replace_table wait until old rules are not used anymore (Florian Westphal) [Orabug: 32709125] {CVE-2021-29650}
- do_epoll_ctl(): clean the failure exits up a bit (Al Viro) [Orabug: 32759496] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Marc Zyngier) [Orabug: 32759496] {CVE-2020-0466}
- HID: core: Sanitize event code and type when mapping input (Marc Zyngier) [Orabug: 32759553] {CVE-2020-0465}
-
Tue Apr 06 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.50.1.el7uek]
- floppy: fix lock_fdc() signal handling (Jiri Kosina) [Orabug: 32624116] {CVE-2021-20261}
- Xen/gnttab: handle p2m update errors on a per-slot basis (Jan Beulich) [Orabug: 32651478] {CVE-2021-28038}
- n_tty: Fix stall at n_tty_receive_char_special(). (Tetsuo Handa) [Orabug: 32656942] {CVE-2021-20219}
- fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent (Eddy Wu) [Orabug: 32695783] {CVE-2020-35508}
- Return EBUSY from BLKRRPART for mounted whole-dev fs (Eric Sandeen) [Orabug: 32696741]
- SecureBoot Digicert 2021 certificates update (Brian Maly) [Orabug: 32734505]
-
Tue Mar 23 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.49.3.el7uek]
- xen/netback: avoid race in xenvif_rx_ring_slots_available() (Juergen Gross) [Orabug: 32485156]
- audit: fix error handling in audit_data_to_entry() (Paul Moore) [Orabug: 32608451] {CVE-2020-0444}
-
Tue Mar 16 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.49.2.el7uek]
- scsi: iscsi: Verify lengths on passthrough PDUs (Chris Leech) [Orabug: 32640641]
- scsi: iscsi: Ensure sysfs attributes are limited to PAGE_SIZE (Chris Leech) [Orabug: 32640641] {CVE-2021-27363} {CVE-2021-27364} {CVE-2021-27365}
- scsi: iscsi: Report connection state in sysfs (Gabriel Krisman Bertazi) [Orabug: 32640641] {CVE-2021-27363} {CVE-2021-27364} {CVE-2021-27365}
- sysfs: Add sysfs_emit and sysfs_emit_at to format sysfs output (Joe Perches) [Orabug: 32640641]
- scsi: iscsi: Restrict sessions and handles to admin capabilities (Lee Duncan) [Orabug: 32640641] {CVE-2021-27363} {CVE-2021-27364} {CVE-2021-27365}
-
Wed Mar 10 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.49.1.el7uek]
- hsr: use netdev_err() instead of WARN_ONCE() (Taehee Yoo) [Orabug: 32576074]
-
Thu Feb 18 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.48.5.el7uek]
- kernel/acct.c: fix the acct->needcheck check in check_free_space() (Oleg Nesterov) [Orabug: 31587485]
- HID: hid-input: clear unmapped usages (Dmitry Torokhov) [Orabug: 32464790] {CVE-2020-0431}
- tcp: fix to update snd_wl1 in bulk receiver fast path (Neal Cardwell) [Orabug: 32498826]
-
Thu Feb 18 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.48.4.el7uek]
- xen-blkback: fix error handling in xen_blkbk_map() (Jan Beulich) [Orabug: 32520758] {CVE-2021-26930}
- xen-scsiback: don't "handle" error by BUG() (Jan Beulich) [Orabug: 32520750] {CVE-2021-26931}
- xen-netback: don't "handle" error by BUG() (Jan Beulich) [Orabug: 32520750] {CVE-2021-26931}
- xen-blkback: don't "handle" error by BUG() (Jan Beulich) [Orabug: 32520750] {CVE-2021-26931}
- Xen/gntdev: correct error checking in gntdev_map_grant_pages() (Jan Beulich) [Orabug: 32520717] {CVE-2021-26932}
- Xen/gntdev: correct dev_bus_addr handling in gntdev_map_grant_pages() (Jan Beulich) [Orabug: 32520717] {CVE-2021-26932}
- Xen/x86: also check kernel mapping in set_foreign_p2m_mapping() (Jan Beulich) [Orabug: 32520717] {CVE-2021-26932}
- Xen/x86: don't bail early from clear_foreign_p2m_mapping() (Jan Beulich) [Orabug: 32520717] {CVE-2021-26932}
-
Tue Feb 09 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.48.3.el7uek]
- bnxt_en: Fix ethtool -x crash when device is down. (Michael Chan) [Orabug: 32466092]