Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
K
kernel
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Metrics
    • Incidents
    • Environments
  • Packages & Registries
    • Packages & Registries
    • Package Registry
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • TeligenOS
  • kernel
  • Merge Requests
  • !20

Merged
Opened Sep 26, 2023 by heqing@heqingReporter
  • Report abuse
Report abuse

update kernel to 5.10.0-136.50.0.129.r1 to fix cves

  • Overview 3
  • Changes 3

issue:#14 (closed)
!2221 [sync] PR-2210: jbd2: Fix potential data lost in recovering journal raced with synchronizing fs bdev
!2232 [sync] PR-2086: fix CVE-2023-20588
!2240 [sync] PR-2169: net: sched: sch_qfq: Fix UAF in qfq_dequeue()
!2243 [sync] PR-2230: media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb()
!2234 [sync] PR-1962: x86/speculation: Add force option to GDS mitigation
media: ttusb-dec: fix memory leak in ttusb_dec_exit_dvb()
net: sched: sch_qfq: Fix UAF in qfq_dequeue()
x86: Move gds_ucode_mitigated() declaration to header
Documentation/x86: Fix backwards on/off logic about YMM support
KVM: Add GDS_NO support to KVM
x86/speculation: Add Kconfig option for GDS
x86/speculation: Add force option to GDS mitigation
x86/CPU/AMD: Fix the DIV(0) initial fix attempt
x86/CPU/AMD: Do not leak quotient data after a division by 0
!1878 [sync] PR-1826: x86/speculation: Add Gather Data Sampling mitigation
jbd2: Fix potential data lost in recovering journal raced with synchronizing fs bdev
!2204 [sync] PR-2153: netfilter: nftables: exthdr: fix 4-byte stack OOB write
netfilter: nftables: exthdr: fix 4-byte stack OOB write
!2152 io_uring: ensure IOPOLL locks around deferred work
io_uring: ensure IOPOLL locks around deferred work
x86/speculation: Add cpu_show_gds() prototype
x86/speculation: Add Gather Data Sampling mitigation

Rename the PGP certificates

!2146 netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR
netfilter: nf_tables: skip immediate deactivate in _PREPARE_ERROR
!2139 net/sched: sch_hfsc: Ensure inner classes have fsc curve
!2138 netfilter: nf_tables: skip bound chain on rule flush
!2136 af_unix: Fix null-ptr-deref in unix_stream_sendpage().
net/sched: sch_hfsc: Ensure inner classes have fsc curve
netfilter: nf_tables: skip bound chain on rule flush
af_unix: Fix null-ptr-deref in unix_stream_sendpage().
!2114 Fixed 4 CVEs of the ksmbd
!2077 [sync] PR-2065: dm: switch to precise io accounting
ksmbd: not allow guest user on multichannel
ksmbd: fix deadlock in ksmbd_find_crypto_ctx()
ksmbd: block asynchronous requests when making a delay on session setup
ksmbd: destroy expired sessions
!1926 [sync] PR-1883: SUNRPC: don't pause on incomplete allocation
dm: switch to precise io accounting
!2058 [sync] PR-2055: Only enable unicast promisc when mac table full to fix the hns3 bug
SUNRPC: don't pause on incomplete allocation
net: hns3: only enable unicast promisc when mac table full
!2048 [sync] PR-1752: ksmbd: validate session id and tree id in the compound request
ksmbd: validate session id and tree id in the compound request

!2003 [sync] PR-1911: ksmbd: fix out-of-bound read in smb2_write
!2010 block: don't get gendisk if queue has not been registered
block: don't get gendisk if queue has not been registered
!1627 [sync] PR-1621: fix three CVEs by backport mainline patchs
!1818 [sync] PR-1788: exfat: check if filename entries exceeds max filename length
ksmbd: fix out-of-bound read in smb2_write
!1980 [sync] PR-1446: Fix the default return value of dm_pool_dec_data_range()
Fix the default return value of dm_pool_dec_data_range()
!1385 [sync] PR-1346: dm thin metadata: check fail_io before using data_sm
exfat: check if filename entries exceeds max filename length
ksmbd: fix racy issue from session setup and logoff
ksmbd: Fix spelling mistake "excceed" -> "exceeded"
ksmbd: limit pdu length size according to connection status
ksmbd: Implements sess->ksmbd_chann_list as xarray
dm thin metadata: check fail_io before using data_sm

!1892 [sync] PR-1784: tun/tap: fix CVE-2023-4194
!1886 [sync] PR-1815: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
!1867 [sync] PR-1821: nbd: pass nbd_sock to nbd_read_reply() instead of index
!1781 [sync] PR-1766: xen/netback: Fix buffer overrun triggered by unusual packet
!1889 [sync] PR-1835: tcp: Reduce chance of collisions in inet6_hashfn().
net: tap_open(): set sk_uid from current_fsuid()
net: tun_chr_open(): set sk_uid from current_fsuid()
tcp: Reduce chance of collisions in inet6_hashfn().
Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_ready_cb
!1828 [sync] PR-1813: ksmbd: fix cve-2023-38432
nbd: pass nbd_sock to nbd_read_reply() instead of index
ksmbd: validate command request size
ksmbd: validate command payload size
xen/netback: Fix buffer overrun triggered by unusual packet

!1839 fix CVE-2023-20593 for openEuler
tools arch x86: Sync the msr-index.h copy with the kernel sources
x86/cpu/amd: Enable Zenbleed fix for AMD Custom APU 0405
x86/cpu/amd: Add a Zenbleed fix
x86/cpu/amd: Move the errata checking functionality up
x86/cpu: Restore AMD's DE_CFG MSR after resume
!1776 [sync] PR-1729: fix CVE-2023-4128 in OLK510
net/sched: cls_route: No longer copy tcf_result on update to avoid use-after-free
net/sched: cls_fw: No longer copy tcf_result on update to avoid use-after-free
net/sched: cls_u32: No longer copy tcf_result on update to avoid use-after-free

!1757 [sync] PR-1742: cxgb4: fix use after free bugs caused by circular dependency problem
!1764 [sync] PR-1749: Input: cyttsp4_core change del_timer_sync() to timer_shutdown_sync()
!1669 [sync] PR-1657: media: usb: siano: Fix CVE-2023-4132
Input: cyttsp4_core change del_timer_sync() to timer_shutdown_sync() !1754 [sync] PR-1737: ksmbd: fix out of bounds read in smb2_sess_setup
cxgb4: fix use after free bugs caused by circular dependency problem
!1745 [sync] PR-1727: add support for timer_shutdown() api
!1732 [sync] PR-1713: netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID
ksmbd: fix out of bounds read in smb2_sess_setup
timers: Keep del_timer_sync exported
timers: Provide timer_shutdown_sync
timers: Add shutdown mechanism to the internal functions
timers: Split [try_to_]del_timer_sync to prepare for shutdown mode
timers: Silently ignore timers with a NULL function
timers: Rename del_timer() to timer_delete()
timers: Rename del_timer_sync() to timer_delete_sync()
timers: Use del_timer_sync() even on UP
timers: Update kernel-doc for various functions
timers: Replace BUG_ON()s
timers: Get rid of del_singleshot_timer_sync()
sw64: Do not use timer namespace for timer_shutdown() function
clocksource/drivers/sp804: Do not use timer namespace for timer_shutdown() function
clocksource/drivers/arm_arch_timer: Do not use timer namespace for timer_shutdown() function
ARM: spear: Do not use timer namespace for timer_shutdown() function !1715 [sync] PR-1711: xfrm: add NULL check in xfrm_update_ae_params
!1633 [sync] PR-1604: net: nfc: Fix CVE-2023-3863
netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID
xfrm: add NULL check in xfrm_update_ae_params
media: usb: siano: Fix warning due to null work_func_t function pointer
media: usb: siano: Fix use after free bugs caused by do_submit_urb net: nfc: Fix use-after-free caused by nfc_llcp_find_local
nfc: llcp: simplify llcp_sock_connect() error paths

!1703 [sync] PR-1682: netfilter: nft_set_pipapo: fix improper element removal
!1675 [sync] PR-1596: ksmbd: fix out-of-bound read in deassemble_neg_contexts()
netfilter: nft_set_pipapo: fix improper element removal !1642 [sync] PR-1551: ksmbd: allocate one more byte for implied bcc[0
!1644 [sync] PR-1605: CVE-2023-38430
ksmbd: fix out-of-bound read in deassemble_neg_contexts()
ksmbd: validate smb request protocol id
ksmbd: define SMB2_COMPRESSION_TRANSFORM_ID in fs/ksmbd/smb2pdu.h
ksmbd: allocate one more byte for implied bcc[0]
ksmbd: validate smb request protocol id
ksmbd: define SMB2_COMPRESSION_TRANSFORM_ID in fs/ksmbd/smb2pdu.h

!1588 [sync] PR-1557: net/sched: cls_fw: Fix improper refcount update leads to use-after-free !1583 [sync] PR-1480: ksmbd: fix wrong UserName check in session_user
!1599 [sync] PR-1547: binder: fix UAF caused by faulty buffer cleanup
!1602 [sync] PR-1581: psi: fix compile error for psi cgroupv1 when CONFIG_CGROUP=n
!1615 [sync] PR-1591: net/sched: cls_u32: Fix reference counter leak leading to overflow net/sched: cls_u32: Fix reference counter leak leading to overflow
!1593 [sync] PR-1585: ksmbd: fix global-out-of-bounds in smb2_find_context_vals
psi: fix compile error for psi cgroupv1 when CONFIG_CGROUP=n
binder: fix UAF caused by faulty buffer cleanup
ksmbd: fix global-out-of-bounds in smb2_find_context_vals
net/sched: cls_fw: Fix improper refcount update leads to use-after-free
ksmbd: fix wrong UserName check in session_user
!1465 [sync] PR-1428: scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()
!1574 [sync] PR-1535: net/sched: sch_qfq: account for stab overhead in qfq_enqueue
net/sched: sch_qfq: account for stab overhead in qfq_enqueue !1559 [sync] PR-1548: mm: memcontrol: fix cannot alloc the maximum memcg ID
!1362 [sync] PR-1294: dm stats: check for and propagate alloc_percpu failure
!1503 block: don't set GD_NEED_PART_SCAN if scan partition failed
!1478 [sync] PR-1345: dm: requeue IO if mapping table not yet
mm: memcontrol: fix cannot alloc the maximum memcg ID block: don't set GD_NEED_PART_SCAN if scan partition failed
dm: don't lock fs when the map is NULL during suspend or resume
dm: don't lock fs when the map is NULL in process of resume
dm: requeue IO if mapping table not yet available
Revert "dm: make sure dm_table is binded before queue request" scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()
dm stats: check for and propagate alloc_percpu failure

!1525 [sync] PR-1482: CVE-2023-3567 fix patches
!1336 [sync] PR-1335: bpf: Fix incorrect verifier pruning due to missing register precision taints
vc_screen: modify vcs_size() handling in vcs_read()
vc_screen: don't clobber return value in vcs_read
vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
!1490 [sync] PR-1476: ipv6/addrconf: fix a potential refcount underflow for idev
!1486 [sync] PR-1452: media: dvb-core: Fix use-after-free due on race condition at dvb_net
!1495 [sync] PR-1445: netfilter: nf_tables: prevent OOB access in nft_byteorder_eval netfilter: nf_tables: prevent OOB access in nft_byteorder_eval
ipv6/addrconf: fix a potential refcount underflow for idev
media: dvb-core: Fix use-after-free due on race condition at dvb_net
!1422 [sync] PR-1254: Two CVE fixes of ksmbd
ksmbd: fix NULL pointer dereference in smb2_get_info_filesystem()
ksmbd: fix memleak in session setup
bpf: Fix incorrect verifier pruning due to missing register precision taints

Fix error provides

!1290 [sync] PR-1262: drm/msm/dpu: Add check for pstates
!1456 [sync] PR-1358: Remove DECnet support from kernel
!1439 [sync] PR-1426: netfilter: nf_tables: do not ignore genmask when looking up chain by id
!1460 [sync] PR-1425: loop: loop_set_status_from_info() check before assignment
!1463 [sync] PR-1436: Fix CVE-2023-3117
!1318 [sync] PR-1285: nbd: fix null-ptr-dereference while accessing 'nbd->config'
netfilter: nf_tables: unbind non-anonymous set if rule construction fails
netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain
netfilter: nf_tables: fix chain binding transaction logic
netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE
loop: loop_set_status_from_info() check before assignment
Remove DECnet support from kernel
netfilter: nf_tables: do not ignore genmask when looking up chain by id
!1420 [sync] PR-1415: Fix generic/299 fail
!1378 [sync] PR-1295: blk-wbt: don't show valid wbt_lat_usec in
ext4: Add debug message to notify user space is out of free
Revert "ext4: Stop trying writing pages if no free blocks generated"
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
!759 【kernel-openEuler-22.03-LTS-SP1】kernel:fix a type error with 5.10 kernel on openEuler 22.03 LTS SP1 system
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
ubifs: Fix memory leak in do_rename
ubifs: Free memory for tmpfile name !1389 [sync] PR-1312: quota: fix race condition between dqput() and dquot_mark_dquot_dirty()
!1392 [sync] PR-1376: jbd2: Check 'jh->b_transaction' before remove it from checkpoint
!1308 [sync] PR-1280: cgroup: always put cset in cgroup_css_set_put_fork
jbd2: Check 'jh->b_transaction' before remove it from checkpoint
quota: simplify drop_dquot_ref()
quota: fix dqput() to follow the guarantees dquot_srcu should provide
quota: add new helper dquot_active() quota: rename dquot_active() to inode_quota_active()
quota: factor out dquot_write_dquot()
Merge branch 'openEuler-22.03-LTS-SP1' of https://gitee.com/openeuler/kernel into openEuler-22.03-LTS-SP1
!1329 [sync] PR-1325: jbd2: fix several checkpoint
!1332 [sync] PR-1314: ext4: Stop trying writing pages if no free blocks generated
dm thin: fix deadlock when swapping to thin device
blk-wbt: don't show valid wbt_lat_usec in sysfs while wbt is disabled
blk-wbt: make enable_state more accurate
!1340 [sync] PR-1286: ext4: turning quotas off if mount failed after enable quotas
ext4: turning quotas off if mount failed after enable quotas
ext4: Stop trying writing pages if no free blocks generated
jbd2: fix checkpoint cleanup performance regression jbd2: remove __journal_try_to_free_buffer()
jbd2: fix a race when checking checkpoint buffer busy
jbd2: Fix wrongly judgement for buffer head removing while doing checkpoint
jbd2: remove journal_clean_one_cp_list()
nbd: fix null-ptr-dereference while accessing 'nbd->config'
nbd: factor out a helper to get nbd_config without holding 'config_lock'
nbd: fold nbd config initialization into nbd_alloc_config()
cgroup: always put cset in cgroup_css_set_put_fork
drm/msm/dpu: Add check for pstates
spdxcheck.py: Fix a type error

!1367 [sync] PR-1324: io_uring: hold uring mutex around poll removal !1363 [sync] PR-1287: ipvlan:Fix out-of-bounds caused by unclear skb->cb
io_uring: hold uring mutex around poll removal
ipvlan:Fix out-of-bounds caused by unclear skb->cb
!1343 [sync] PR-1272: xfs: fix some problems recently
xfs: fix uninitialized variable access
xfs: set XFS_FEAT_NLINK correctly
xfs: don't leak perag when growfs fails
xfs: factor out xfs_destroy_perag()
xfs: fix warning in xfs_vm_writepages()
xfs: don't leak intent item when recovery intents fail
xfs: factor out xfs_defer_pending_abort
xfs: fix mounting failed caused by sequencing problem in the log records
Fix x86 provides error symbol

Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
Reference: teligenos/kernel!20
Source branch: hopestage-v2.0

Revert this merge request

This will create a new commit in order to revert the existing changes.

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.

Cherry-pick this merge request

Switch branch
Cancel
A new branch will be created in your fork and a new merge request will be started.