-
Tue Aug 26 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.29.1.0.1.el10_0.OL10]
- nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
-
Tue Aug 26 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.29.1.el10_0]
- Bump internal version to 55.29.1
- ice: fix eswitch code memory leak in reset scenario - CVE-2025-38417
- net/sched: Abort __tc_modify_qdisc if parent class does not exist
- net_sched: ets: Fix double list add in class with netem as child qdisc - CVE-2025-37914
- sch_ets: make est_qlen_notify() idempotent
- i40e: fix MMIO write access to an invalid page in i40e_clear_hw - CVE-2025-38200
- cxgb4: use port number to set mac addr
-
Wed Aug 20 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.28.1.el10_0]
- Conflict with xdp-tools < 1.5.4
- Bump internal version to 55.28.1
- tls: always refresh the queue when reading sock - CVE-2025-38471
- selftests: net: bpf_offload: add 'libbpf_global' to ignored maps
- selftests: net: fix error message in bpf_offload
- selftests: net: add more info to error in bpf_offload
- net: fix udp gso skb_segment after pull from frag_list - CVE-2025-38124
- powerpc/pseries/vas: Add close() callback in vas_vm_ops struct
- s390/pci: Serialize device addition and removal
- s390/pci: Allow re-add of a reserved but not yet removed device
- s390/pci: Prevent self deletion in disable_slot()
- s390/pci: Remove redundant bus removal and disable from zpci_release_device()
- s390/pci: Fix duplicate pci_dev_put() in disable_slot() when PF has child VFs
- s390/pci: Fix missing check for zpci_create_device() error return
- s390/pci: Fix potential double remove of hotplug slot
- s390/topology: Improve topology detection
- Bluetooth: hci_core: Fix use-after-free in vhci_flush() - CVE-2025-38250
- selftests/bpf: Adjust data size to have ETH_HLEN - CVE-2025-21867
- bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() - CVE-2025-21867
- i2c/designware: Fix an initialization issue - CVE-2025-38380
-
Thu Aug 14 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.27.1.el10_0]
- Bump internal version to 55.27.1
- Fix includes for mm: fix copy_vma() error handling for hugetlb mappings
- Revert sch_htb: make htb_qlen_notify() idempotent
- Revert sch_drr: make drr_qlen_notify() idempotent
- Revert sch_qfq: make qfq_qlen_notify() idempotent
- Revert codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()
- Revert sch_htb: make htb_deactivate() idempotent
- Revert net/sched: Always pass notifications when child class becomes empty
- wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds - CVE-2025-38159
- Documentation: Fix pci=config_acs= example
- PCI/ACS: Fix 'pci=config_acs=' parameter
- Revert "smb: client: fix TCP timers deadlock after rmmod" - CVE-2025-22077
- Revert smb: client: Fix netns refcount imbalance causing leaks and use-after-free
- smb: client: Fix netns refcount imbalance causing leaks and use-after-free
- wifi: ath12k: fix invalid access to memory - CVE-2025-38292
- x86/CPU/AMD: Terminate the erratum_1386_microcode array - CVE-2024-56721
- crypto: algif_hash - fix double free in hash_accept - CVE-2025-38079
- net/sched: Always pass notifications when child class becomes empty - CVE-2025-38350
- sch_htb: make htb_deactivate() idempotent - CVE-2025-38350
- codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() - CVE-2025-38350
- sch_qfq: make qfq_qlen_notify() idempotent - CVE-2025-38350
- sch_drr: make drr_qlen_notify() idempotent - CVE-2025-38350
- sch_htb: make htb_qlen_notify() idempotent - CVE-2025-38350
- mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race - CVE-2025-38085
- mm/hugetlb: unshare page tables during VMA split, not before - CVE-2025-38084
- tools/testing/vma: add missing function stub
- mm: fix copy_vma() error handling for hugetlb mappings
- PCI: Use downstream bridges for distributing resources
- PCI/pwrctrl: Cancel outstanding rescan work when unregistering - CVE-2025-38137
- bnxt_en: Skip MAC loopback selftest if it is unsupported by FW
- bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW
-
Thu Aug 07 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.25.1.el10_0]
- Bump internal version to 55.25.1
- net_sched: hfsc: Address reentrant enqueue adding class to eltree twice - CVE-2025-38001
- sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() - CVE-2025-38000
- net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc - CVE-2025-37890
- sch_hfsc: make hfsc_qlen_notify() idempotent
- RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem - CVE-2025-38022
- RDMA/core: Fix use-after-free when rename device name - CVE-2025-22085
- nvme-tcp: sanitize request list handling - CVE-2025-38264
- net: tipc: fix refcount warning in tipc_aead_encrypt
- net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done - CVE-2025-38052
- tcp: adjust rcvq_space after updating scaling ratio
- ext4: avoid journaling sb update on error if journal is destroying - CVE-2025-22113
- ext4: define ext4_journal_destroy wrapper - CVE-2025-22113
- HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() - CVE-2025-21928
- HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() - CVE-2025-21929
- usb: hub: Fix flushing of delayed work used for post resume purposes
- usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm
- usb: hub: fix detection of high tier USB3 devices behind suspended hubs
- net/sched: fix use-after-free in taprio_dev_notifier - CVE-2025-38087
- net: ch9200: fix uninitialised access during mii_nway_restart - CVE-2025-38086
- padata: avoid UAF for reorder_work - CVE-2025-21726
- padata: fix UAF in padata_reorder - CVE-2025-21727
- padata: add pd get/put refcnt helper
- padata: fix sysfs store callback check
- padata: Clean up in padata_do_multithreaded()
- memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove -CVE-2025-22020
-
Tue Jul 29 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.24.1.el10_0]
- Bump internal version to 55.24.1
- net_sched: hfsc: Fix a UAF vulnerability in class handling - CVE-2025-37797
- ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() - CVE-2025-22121
- ext4: introduce ITAIL helper - CVE-2025-22121
- net/mdiobus: Fix potential out-of-bounds clause 45 read/write access - CVE-2025-38110
- powerpc/vas: Return -EINVAL if the offset is non-zero in mmap() - CVE-2025-38088
- powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap - CVE-2025-38088
- net/mlx5: Fill out devlink dev info only for PFs
- RDMA/mlx5: Fix page_size variable overflow - CVE-2025-22091
- ACPI: CPPC: Fix _CPC register setting issue
-
Tue Jul 22 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.22.1.el10_0]
- Bump internal version to 55.22.1
- mm/huge_memory: fix dereferencing invalid pmd migration entry - CVE-2025-37958
- i2c: tegra: check msg length in SMBUS block read
- s390/virtio_ccw: Don't allocate/assign airqs for non-existing queues
- sunrpc: handle SVC_GARBAGE during svc auth processing as auth error - CVE-2025-38089
- media: uvcvideo: Announce the user our deprecation intentions
- media: uvcvideo: Allow changing noparam on the fly
- media: uvcvideo: Invert default value for nodrop module param
- media: uvcvideo: Propagate buf->error to userspace
- media: uvcvideo: Flush the control cache when we get an event
- media: uvcvideo: Annotate lock requirements for uvc_ctrl_set
- media: uvcvideo: Remove dangling pointers - CVE-2024-58002
- media: uvcvideo: Remove redundant NULL assignment
- media: uvcvideo: Only save async fh if success
- media: uvcvideo: Fix double free in error path - CVE-2024-57980
- wifi: iwlwifi: limit printed string from FW file - CVE-2025-21905
-
Tue Jul 15 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.21.1.el10_0]
- Bump internal version to 55.21.1
- ice, irdma: fix an off by one in error handling code
- irdma: free iwdev->rf after removing MSI-X
- ice: Fix signedness bug in ice_init_interrupt_scheme()
- ice: init flow director before RDMA
- ice: simplify VF MSI-X managing
- ice: enable_rdma devlink param
- ice: treat dyn_allowed only as suggestion
- ice, irdma: move interrupts code to irdma
- ice: get rid of num_lan_msix field
- ice: remove splitting MSI-X between features
- ice: devlink PF MSI-X max and min parameter
- ice: ice_probe: init ice_adapter after HW init
- ice: minor: rename goto labels from err to unroll
- ice: split ice_init_hw() out from ice_init_dev()
- ice: c827: move wait for FW to ice_init_hw()
- exfat: fix random stack corruption after get_block - CVE-2025-22036
-
Mon Jul 07 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.20.1.el10_0]
- Bump internal version to 55.20.1
- Adjust page_pool: Track DMA-mapped pages and unmap them when destroying the pool
- Adjust dm mpath: Interface for explicit probing of active paths
- x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes - CVE-2025-21991
- page_pool: Track DMA-mapped pages and unmap them when destroying the pool
- page_pool: Move pp_magic check into helper functions
- scsi: storvsc: Explicitly set max_segment_size to UINT_MAX
- vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp - CVE-2025-37799
- dm mpath: replace spin_lock_irqsave with spin_lock_irq
- dm-mpath: Don't grab work_mutex while probing paths
- dm mpath: Interface for explicit probing of active paths
- dm: Allow .prepare_ioctl to handle ioctls directly
- ipv6: mcast: extend RCU protection in igmp6_send() - CVE-2025-21759
-
Tue Jul 01 2025 Alex Burmashev <alexander.burmashev@oracle.com> [6.12.0-55.19.1.el10_0]
- Clean git history at setup stage
- Prevent kABI check error for BLK_CGROUP_PUNT_BIO
- Bump internal version to 55.19.1
- ibmvnic: Use kernel helpers for hex dumps
- eth: bnxt: fix truesize for mb-xdp-pass case
- ice: Avoid setting default Rx VSI twice in switchdev setup
- ice: Fix deinitializing VF in error path
- ice: add E830 HW VF mailbox message limit support
- block/Kconfig: Allow selecting BLK_CGROUP_PUNT_BIO