-
Wed Jul 21 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.52.5.el7uek]
- seq_file: disallow extremely large seq buffer allocations (Eric Sandeen) [Orabug: 33135634] {CVE-2021-33909}
-
Tue Jun 22 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.52.4.el7uek]
- IB/core: Only update PKEY and GID caches on respective events (HÃ¥kon Bugge) [Orabug: 32816368]
- Revert "Allow mce to reset instead of panic on UE" (William Roche) [Orabug: 32820278]
- Bluetooth: verify AMP hci_chan before amp_destroy (Archie Pusaka) [Orabug: 32912103] {CVE-2021-33034}
- Bluetooth: Fix slab-out-of-bounds read in hci_extended_inquiry_result_evt() (Peilin Ye) [Orabug: 33013890] {CVE-2020-36386}
- qla2xxx: update version to 9.00.00.00.42.0-k1-v5 (Quinn Tran) [Orabug: 33015884]
- scsi: qla2xxx: v2: Fix login retry count (Quinn Tran) [Orabug: 29411891] [Orabug: 33015884]
- scsi: qla2xxx: Properly extract ADISC error codes (Quinn Tran) [Orabug: 33015884]
- scsi: qla2xxx: Replace GPDB with async ADISC command (Quinn Tran) [Orabug: 33015884]
- qla2xxx: update version to 9.00.00.00.42.0-k1-v4 (Quinn Tran) [Orabug: 33015884]
- qla2xxx: fix relogin stalled. (Quinn Tran) [Orabug: 27700529] [Orabug: 33015884]
- net/mlx4: Treat VFs fair when handling comm_channel_events (Hans Westgaard Ry) [Orabug: 33017263]
-
Tue Jun 15 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.52.3.el7uek]
- iommu/vt-d: Don't dereference iommu_device if IOMMU_API is not built (Bartosz Golaszewski) [Orabug: 32974492]
- iommu/vt-d: Gracefully handle DMAR units with no supported address widths (David Woodhouse) [Orabug: 32974492]
- secureboot: make sure kernel-signing.cer is copied to kernel-keys dir (Brian Maly) [Orabug: 32978042]
-
Tue Jun 08 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.52.2.el7uek]
- Bluetooth: A2MP: Fix not initializing all members (Luiz Augusto von Dentz) [Orabug: 32021289] {CVE-2020-12352}
- RDS tcp loopback connection can hang (Rao Shoaib) [Orabug: 32926868]
-
Tue Jun 01 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.52.1.el7uek]
- dm ioctl: fix out of bounds array access when no devices (Mikulas Patocka) [Orabug: 32860494] {CVE-2021-31916}
-
Tue May 11 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.51.2.el7uek]
- IB/ipoib: Improve latency in ipoib/cm connection formation (Manjunath Patil) [Orabug: 32219842]
- mm: madv_doexec_flag sysctl (Anthony Yznaga) [Orabug: 32387889]
- mm: introduce MADV_DOEXEC (Anthony Yznaga) [Orabug: 32387889]
- exec, elf: require opt-in for accepting preserved mem (Anthony Yznaga) [Orabug: 32387889]
- mm: introduce VM_EXEC_KEEP (Anthony Yznaga) [Orabug: 32387889]
- mm: fail exec if stack expansion will overlap another vma (Anthony Yznaga) [Orabug: 32387889]
- mm: do not assume only the stack vma exists in setup_arg_pages() (Anthony Yznaga) [Orabug: 32387889]
- ELF: when loading PIE binaries check for overlap with existing mappings (Anthony Yznaga) [Orabug: 32387889]
-
Tue May 04 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.51.1.el7uek]
- tcp: grow window for OOO packets only for SACK flows (Eric Dumazet) [Orabug: 30804714]
-
Tue Apr 20 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.50.2.el7uek]
- btrfs: fix race when cloning extent buffer during rewind of an old root (Filipe Manana) [Orabug: 32669454] {CVE-2021-28964}
- xen-blkback: don't leak persistent grants from xen_blkbk_map() (Jan Beulich) [Orabug: 32697855] {CVE-2021-28688}
- netfilter: x_tables: Use correct memory barriers. (Mark Tomlinson) [Orabug: 32709125] {CVE-2021-29650}
- netfilter: x_tables: make xt_replace_table wait until old rules are not used anymore (Florian Westphal) [Orabug: 32709125] {CVE-2021-29650}
- do_epoll_ctl(): clean the failure exits up a bit (Al Viro) [Orabug: 32759496] {CVE-2020-0466}
- epoll: Keep a reference on files added to the check list (Marc Zyngier) [Orabug: 32759496] {CVE-2020-0466}
- HID: core: Sanitize event code and type when mapping input (Marc Zyngier) [Orabug: 32759553] {CVE-2020-0465}
-
Tue Apr 06 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.50.1.el7uek]
- floppy: fix lock_fdc() signal handling (Jiri Kosina) [Orabug: 32624116] {CVE-2021-20261}
- Xen/gnttab: handle p2m update errors on a per-slot basis (Jan Beulich) [Orabug: 32651478] {CVE-2021-28038}
- n_tty: Fix stall at n_tty_receive_char_special(). (Tetsuo Handa) [Orabug: 32656942] {CVE-2021-20219}
- fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent (Eddy Wu) [Orabug: 32695783] {CVE-2020-35508}
- Return EBUSY from BLKRRPART for mounted whole-dev fs (Eric Sandeen) [Orabug: 32696741]
- SecureBoot Digicert 2021 certificates update (Brian Maly) [Orabug: 32734505]
-
Tue Mar 23 2021 Brian Maly <brian.maly@oracle.com> [4.1.12-124.49.3.el7uek]
- xen/netback: avoid race in xenvif_rx_ring_slots_available() (Juergen Gross) [Orabug: 32485156]
- audit: fix error handling in audit_data_to_entry() (Paul Moore) [Orabug: 32608451] {CVE-2020-0444}