Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
K
kernel
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 6
    • Issues 6
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Metrics
    • Incidents
    • Environments
  • Packages & Registries
    • Packages & Registries
    • Package Registry
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • teligen_admin
  • kernel
  • Issues
  • #14

Closed
Open
Opened Sep 26, 2023 by teligen_admin@Teligen_adminMaintainer
  • Report abuse
  • New issue
Report abuse New issue

update kernel to 5.10.0-136.50.0.129.r1 to fix cves

!2221 [sync] PR-2210: jbd2: Fix potential data lost in recovering journal raced with synchronizing fs bdev
!2232 [sync] PR-2086: fix CVE-2023-20588
!2240 [sync] PR-2169: net: sched: sch_qfq: Fix UAF in qfq_dequeue()
!2243 [sync] PR-2230: media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb()
!2234 [sync] PR-1962: x86/speculation: Add force option to GDS mitigation
media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb()
net: sched: sch_qfq: Fix UAF in qfq_dequeue()
x86: Move gds_ucode_mitigated() declaration to header
Documentation/x86: Fix backwards on/off logic about YMM support
KVM: Add GDS_NO support to KVM
x86/speculation: Add Kconfig option for GDS
x86/speculation: Add force option to GDS mitigation
x86/CPU/AMD: Fix the DIV(0) initial fix attempt
x86/CPU/AMD: Do not leak quotient data after a division by 0
!1878 [sync] PR-1826: x86/speculation: Add Gather Data Sampling mitigation
jbd2: Fix potential data lost in recovering journal raced with synchronizing fs bdev
!2204 [sync] PR-2153: netfilter: nftables: exthdr: fix 4-byte stack OOB write
netfilter: nftables: exthdr: fix 4-byte stack OOB write
!2152 io_uring: ensure IOPOLL locks around deferred work
io_uring: ensure IOPOLL locks around deferred work
x86/speculation: Add cpu_show_gds() prototype
x86/speculation: Add Gather Data Sampling mitigation

Rename the PGP certificates

!2146 netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR
netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR
!2139 net/sched: sch_hfsc: Ensure inner classes have fsc curve
!2138 netfilter: nf_tables: skip bound chain on rule flush
!2136 af_unix: Fix null-ptr-deref in unix_stream_sendpage().
net/sched: sch_hfsc: Ensure inner classes have fsc curve
netfilter: nf_tables: skip bound chain on rule flush
af_unix: Fix null-ptr-deref in unix_stream_sendpage().
!2114 Fixed 4 CVEs of the ksmbd
!2077 [sync] PR-2065: dm: switch to precise io accounting
ksmbd: not allow guest user on multichannel
ksmbd: fix deadlock in ksmbd_find_crypto_ctx()
ksmbd: block asynchronous requests when making a delay on session setup
ksmbd: destroy expired sessions
!1926 [sync] PR-1883: SUNRPC: don't pause on incomplete allocation
dm: switch to precise io accounting
!2058 [sync] PR-2055: Only enable unicast promisc when mac table full to fix the hns3 bug
SUNRPC: don't pause on incomplete allocation
net: hns3: only enable unicast promisc when mac table full
!2048 [sync] PR-1752: ksmbd: validate session id and tree id in the compound request
ksmbd: validate session id and tree id in the compound request

!2003 [sync] PR-1911: ksmbd: fix out-of-bound read in smb2_write
!2010 block: don't get gendisk if queue has not been registered
block: don't get gendisk if queue has not been registered
!1627 [sync] PR-1621: fix three CVEs by backport mainline patchs
!1818 [sync] PR-1788: exfat: check if filename entries exceeds max filename length
ksmbd: fix out-of-bound read in smb2_write
!1980 [sync] PR-1446: Fix the default return value of dm_pool_dec_data_range()
Fix the default return value of dm_pool_dec_data_range()
!1385 [sync] PR-1346: dm thin metadata: check fail_io before using data_sm
exfat: check if filename entries exceeds max filename length
ksmbd: fix racy issue from session setup and logoff
ksmbd: Fix spelling mistake "excceed" -> "exceeded"
ksmbd: limit pdu length size according to connection status
ksmbd: Implements sess->ksmbd_chann_list as xarray
dm thin metadata: check fail_io before using data_sm

!1892 [sync] PR-1784: tun/tap: fix CVE-2023-4194
!1886 [sync] PR-1815: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
!1867 [sync] PR-1821: nbd: pass nbd_sock to nbd_read_reply() instead of index
!1781 [sync] PR-1766: xen/netback: Fix buffer overrun triggered by unusual packet
!1889 [sync] PR-1835: tcp: Reduce chance of collisions in inet6_hashfn().
net: tap_open(): set sk_uid from current_fsuid()
net: tun_chr_open(): set sk_uid from current_fsuid()
tcp: Reduce chance of collisions in inet6_hashfn().
Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
!1828 [sync] PR-1813: ksmbd: fix cve-2023-38432
nbd: pass nbd_sock to nbd_read_reply() instead of index
ksmbd: validate command request size
ksmbd: validate command payload size
xen/netback: Fix buffer overrun triggered by unusual packet

!1839 fix CVE-2023-20593 for openEuler
tools arch x86: Sync the msr-index.h copy with the kernel sources
x86/cpu/amd: Enable Zenbleed fix for AMD Custom APU 0405
x86/cpu/amd: Add a Zenbleed fix
x86/cpu/amd: Move the errata checking functionality up
x86/cpu: Restore AMD's DE_CFG MSR after resume
!1776 [sync] PR-1729: fix CVE-2023-4128 in OLK510
net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free
net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free
net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free

!1757 [sync] PR-1742: cxgb4: fix use after free bugs caused by circular dependency problem
!1764 [sync] PR-1749: Input: cyttsp4_core change del_timer_sync() to timer_shutdown_sync()
!1669 [sync] PR-1657: media: usb: siano: Fix CVE-2023-4132
Input: cyttsp4_core change del_timer_sync() to timer_shutdown_sync() !1754 [sync] PR-1737: ksmbd: fix out of bounds read in smb2_sess_setup
cxgb4: fix use after free bugs caused by circular dependency problem
!1745 [sync] PR-1727: add support for timer_shutdown() api
!1732 [sync] PR-1713: netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID
ksmbd: fix out of bounds read in smb2_sess_setup
timers: Keep del_timer_sync exported
timers: Provide timer_shutdown_sync
timers: Add shutdown mechanism to the internal functions
timers: Split [try_to_]del_timer_sync to prepare for shutdown mode
timers: Silently ignore timers with a NULL function
timers: Rename del_timer() to timer_delete()
timers: Rename del_timer_sync() to timer_delete_sync()
timers: Use del_timer_sync() even on UP
timers: Update kernel-doc for various functions
timers: Replace BUG_ON()s
timers: Get rid of del_singleshot_timer_sync()
sw64: Do not use timer namespace for timer_shutdown() function
clocksource/drivers/sp804: Do not use timer namespace for timer_shutdown() function
clocksource/drivers/arm_arch_timer: Do not use timer namespace for timer_shutdown() function
ARM: spear: Do not use timer namespace for timer_shutdown() function !1715 [sync] PR-1711: xfrm: add NULL check in xfrm_update_ae_params
!1633 [sync] PR-1604: net: nfc: Fix CVE-2023-3863
netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID
xfrm: add NULL check in xfrm_update_ae_params
media: usb: siano: Fix warning due to null work_func_t function pointer
media: usb: siano: Fix use after free bugs caused by do_submit_urb net: nfc: Fix use-after-free caused by nfc_llcp_find_local
nfc: llcp: simplify llcp_sock_connect() error paths

!1703 [sync] PR-1682: netfilter: nft_set_pipapo: fix improper element removal
!1675 [sync] PR-1596: ksmbd: fix out-of-bound read in deassemble_neg_contexts()
netfilter: nft_set_pipapo: fix improper element removal !1642 [sync] PR-1551: ksmbd: allocate one more byte for implied bcc[0
!1644 [sync] PR-1605: CVE-2023-38430
ksmbd: fix out-of-bound read in deassemble_neg_contexts()
ksmbd: validate smb request protocol id
ksmbd: define SMB2_COMPRESSION_TRANSFORM_ID in fs/ksmbd/smb2pdu.h
ksmbd: allocate one more byte for implied bcc[0]
ksmbd: validate smb request protocol id
ksmbd: define SMB2_COMPRESSION_TRANSFORM_ID in fs/ksmbd/smb2pdu.h

!1588 [sync] PR-1557: net/sched: cls_fw: Fix improper refcount update leads to use-after-free !1583 [sync] PR-1480: ksmbd: fix wrong UserName check in session_user
!1599 [sync] PR-1547: binder: fix UAF caused by faulty buffer cleanup
!1602 [sync] PR-1581: psi: fix compile error for psi cgroupv1 when CONFIG_CGROUP=n
!1615 [sync] PR-1591: net/sched: cls_u32: Fix reference counter leak leading to overflow net/sched: cls_u32: Fix reference counter leak leading to overflow
!1593 [sync] PR-1585: ksmbd: fix global-out-of-bounds in smb2_find_context_vals
psi: fix compile error for psi cgroupv1 when CONFIG_CGROUP=n
binder: fix UAF caused by faulty buffer cleanup
ksmbd: fix global-out-of-bounds in smb2_find_context_vals
net/sched: cls_fw: Fix improper refcount update leads to use-after-free
ksmbd: fix wrong UserName check in session_user
!1465 [sync] PR-1428: scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()
!1574 [sync] PR-1535: net/sched: sch_qfq: account for stab overhead in qfq_enqueue
net/sched: sch_qfq: account for stab overhead in qfq_enqueue !1559 [sync] PR-1548: mm: memcontrol: fix cannot alloc the maximum memcg ID
!1362 [sync] PR-1294: dm stats: check for and propagate alloc_percpu failure
!1503 block: don't set GD_NEED_PART_SCAN if scan partition failed
!1478 [sync] PR-1345: dm: requeue IO if mapping table not yet
mm: memcontrol: fix cannot alloc the maximum memcg ID block: don't set GD_NEED_PART_SCAN if scan partition failed
dm: don't lock fs when the map is NULL during suspend or resume
dm: don't lock fs when the map is NULL in process of resume
dm: requeue IO if mapping table not yet available
Revert "dm: make sure dm_table is binded before queue request" scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()
dm stats: check for and propagate alloc_percpu failure

!1525 [sync] PR-1482: CVE-2023-3567 fix patches
!1336 [sync] PR-1335: bpf: Fix incorrect verifier pruning due to missing register precision taints
vc_screen: modify vcs_size() handling in vcs_read()
vc_screen: don't clobber return value in vcs_read
vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
!1490 [sync] PR-1476: ipv6/addrconf: fix a potential refcount underflow for idev
!1486 [sync] PR-1452: media: dvb-core: Fix use-after-free due on race condition at dvb_net
!1495 [sync] PR-1445: netfilter: nf_tables: prevent OOB access in nft_byteorder_eval netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
ipv6/addrconf: fix a potential refcount underflow for idev
media: dvb-core: Fix use-after-free due on race condition at dvb_net
!1422 [sync] PR-1254: Two CVE fixes of ksmbd
ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem()
ksmbd: fix memleak in session setup
bpf: Fix incorrect verifier pruning due to missing register precision taints

Fix error provides

!1290 [sync] PR-1262: drm/msm/dpu: Add check for pstates
!1456 [sync] PR-1358: Remove DECnet support from kernel
!1439 [sync] PR-1426: netfilter: nf_tables: do not ignore genmask when looking up chain by id
!1460 [sync] PR-1425: loop: loop_set_status_from_info() check before assignment
!1463 [sync] PR-1436: Fix CVE-2023-3117
!1318 [sync] PR-1285: nbd: fix null-ptr-dereference while accessing 'nbd->config'
netfilter: nf_tables: unbind non-anonymous set if rule construction fails
netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain
netfilter: nf_tables: fix chain binding transaction logic
netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
loop: loop_set_status_from_info() check before assignment
Remove DECnet support from kernel
netfilter: nf_tables: do not ignore genmask when looking up chain by id
!1420 [sync] PR-1415: Fix generic/299 fail
!1378 [sync] PR-1295: blk-wbt: don't show valid wbt_lat_usec in
ext4: Add debug message to notify user space is out of free
Revert "ext4: Stop trying writing pages if no free blocks generated"
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
!759 【kernel-openEuler-22.03-LTS-SP1】kernel:fix a type error with 5.10 kernel on openEuler 22.03 LTS SP1 system
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
ubifs: Fix memory leak in do_rename
ubifs: Free memory for tmpfile name !1389 [sync] PR-1312: quota: fix race condition between dqput() and dquot_mark_dquot_dirty()
!1392 [sync] PR-1376: jbd2: Check 'jh->b_transaction' before remove it from checkpoint
!1308 [sync] PR-1280: cgroup: always put cset in cgroup_css_set_put_fork
jbd2: Check 'jh->b_transaction' before remove it from checkpoint
quota: simplify drop_dquot_ref()
quota: fix dqput() to follow the guarantees dquot_srcu should provide
quota: add new helper dquot_active() quota: rename dquot_active() to inode_quota_active()
quota: factor out dquot_write_dquot()
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
!1329 [sync] PR-1325: jbd2: fix several checkpoint
!1332 [sync] PR-1314: ext4: Stop trying writing pages if no free blocks generated
dm thin: fix deadlock when swapping to thin device
blk-wbt: don't show valid wbt_lat_usec in sysfs while wbt is disabled
blk-wbt: make enable_state more accurate
!1340 [sync] PR-1286: ext4: turning quotas off if mount failed after enable quotas
ext4: turning quotas off if mount failed after enable quotas
ext4: Stop trying writing pages if no free blocks generated
jbd2: fix checkpoint cleanup performance regression jbd2: remove __journal_try_to_free_buffer()
jbd2: fix a race when checking checkpoint buffer busy
jbd2: Fix wrongly judgement for buffer head removing while doing checkpoint
jbd2: remove journal_clean_one_cp_list()
nbd: fix null-ptr-dereference while accessing 'nbd->config'
nbd: factor out a helper to get nbd_config without holding 'config_lock'
nbd: fold nbd config initialization into nbd_alloc_config()
cgroup: always put cset in cgroup_css_set_put_fork
drm/msm/dpu: Add check for pstates
spdxcheck.py: Fix a type error

!1367 [sync] PR-1324: io_uring: hold uring mutex around poll removal !1363 [sync] PR-1287: ipvlan:Fix out-of-bounds caused by unclear skb->cb
io_uring: hold uring mutex around poll removal
ipvlan:Fix out-of-bounds caused by unclear skb->cb
!1343 [sync] PR-1272: xfs: fix some problems recently
xfs: fix uninitialized variable access
xfs: set XFS_FEAT_NLINK correctly
xfs: don't leak perag when growfs fails
xfs: factor out xfs_destroy_perag()
xfs: fix warning in xfs_vm_writepages()
xfs: don't leak intent item when recovery intents fail
xfs: factor out xfs_defer_pending_abort
xfs: fix mounting failed caused by sequencing problem in the log records
Fix x86 provides error symbol

Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: Teligen_admin/kernel#14