- 
    Mon Feb 25 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.3.2.el7uek]
    - uek-rpm: Remove hardcoded 'kernel_git_commit' macro from specfile (Victor Erminpour)  [Orabug: 29357695]  
- mm: cleancache: fix corruption on missed inode invalidation (Pavel Tikhomirov)  [Orabug: 29364665]  {CVE-2018-16862} 
- l2tp: fix reading optional fields of L2TPv3 (Jacob Wen)  [Orabug: 29368046]
- 
    Tue Feb 19 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.3.1.el7uek]
    - x86/speculation: Add support for STIBP always-on preferred mode (Thomas Lendacky)  [Orabug: 29344486]  
- x86/speculation: Provide IBPB always command line options (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Add seccomp Spectre v2 user space protection mode (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Enable prctl mode for spectre_v2_user (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Add prctl() control for indirect branch speculation (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Prepare arch_smt_update() for PRCTL mode (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Prevent stale SPEC_CTRL msr content (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Split out TIF update (Thomas Gleixner)  [Orabug: 29344486]  
- ptrace: Remove unused ptrace_may_access_sched() and MODE_IBRS (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Remove static key ibpb_enabled_key (Anjali Kulkarni)  [Orabug: 29344486]  
- x86/speculation: Prepare for conditional IBPB in switch_mm() (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Avoid __switch_to_xtra() calls (Thomas Gleixner)  [Orabug: 29344486]  
- x86/process: Consolidate and simplify switch_to_xtra() code (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Prepare for per task indirect branch speculation control (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Add command line control for indirect branch speculation (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Unify conditional spectre v2 print functions (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculataion: Mark command line parser data __initdata (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Mark string arrays const correctly (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Reorder the spec_v2 code (Thomas Gleixner)  [Orabug: 29344486]  
- x86/l1tf: Show actual SMT state (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Rework SMT state change (Thomas Gleixner)  [Orabug: 29344486]  
- sched/smt: Expose sched_smt_present static key (Thomas Gleixner)  [Orabug: 29344486]  
- x86/Kconfig: Select SCHED_SMT if SMP enabled (Thomas Gleixner)  [Orabug: 29344486]  
- sched/smt: Make sched_smt_present track topology (Peter Zijlstra (Intel))  [Orabug: 29344486]  
- x86/speculation: Reorganize speculation control MSRs update (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Rename SSBD update functions (Thomas Gleixner)  [Orabug: 29344486]  
- x86/speculation: Disable STIBP when enhanced IBRS is in use (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Move STIPB/IBPB string conditionals out of cpu_show_common() (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Remove unnecessary ret variable in cpu_show_common() (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Clean up spectre_v2_parse_cmdline() (Tim Chen)  [Orabug: 29344486]  
- x86/speculation: Update the TIF_SSBD comment (Tim Chen)  [Orabug: 29344486]  
- sched/core: Fix cpu.max vs. cpuhotplug deadlock (Peter Zijlstra)  [Orabug: 29344486]  
- x86/speculation: Enable cross-hyperthread spectre v2 STIBP mitigation (Jiri Kosina)  [Orabug: 29344486]  
- x86/speculation: Apply IBPB more strictly to avoid cross-process data leak (Jiri Kosina)  [Orabug: 29344486]  
- netfilter: nf_tables: deactivate expressions in rule replecement routine (Taehee Yoo)  [Orabug: 29355502]  
- btrfs: Verify that every chunk has corresponding block group at mount time (Qu Wenruo)  [Orabug: 29355254]  {CVE-2018-14612} 
- mlx4_ib: Distribute completion vectors when zero is supplied (Håkon Bugge)  [Orabug: 29324328]  
- x86/speculation: Clean up retpoline code in bugs.c (Alejandro Jimenez)  [Orabug: 29211613]  
- x86, modpost: Replace last remnants of RETPOLINE with CONFIG_RETPOLINE (WANG Chao)  [Orabug: 29211613]  
- x86/build: Fix compiler support check for CONFIG_RETPOLINE (Masahiro Yamada)  [Orabug: 29211613]  
- x86/retpoline: Remove minimal retpoline support (Zhenzhong Duan)  [Orabug: 29211613]  
- uek-rpm: Enable device-mapper era driver (Dave Aldridge)  [Orabug: 29283140]  
- uek-rpm: use multi-threaded xz compression for rpms (Alexander Burmashev)  [Orabug: 29322860]  
- uek-rpm: optimize find-requires usage (Alexander Burmashev)  [Orabug: 29322860]  
- find-debuginfo.sh: backport parallel files procession (Alexander Burmashev)  [Orabug: 29322860]
- 
    Mon Feb 04 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.3.0.el7uek]
    - xfs: refactor short form directory structure verifier function (Darrick J. Wong)  [Orabug: 29301204]  
- xfs: provide a centralized method for verifying inline fork data (Darrick J. Wong)  [Orabug: 29301204]  
- xfs: create structure verifier function for short form symlinks (Darrick J. Wong)  [Orabug: 29301204]  
- xfs: create structure verifier function for shortform xattrs (Darrick J. Wong)  [Orabug: 29301204]  
- btrfs: relocation: Only remove reloc rb_trees if reloc control has been initialized (Qu Wenruo)  [Orabug: 29301101]  {CVE-2018-14609} 
- iommu/amd: Fix IOMMU page flush when detach device from a domain (Suravee Suthikulpanit)  [Orabug: 29297191]  
- x86/apic: Switch all APICs to Fixed delivery mode (Thomas Gleixner)  [Orabug: 29262403]  
- kvm: x86: Report STIBP on GET_SUPPORTED_CPUID (Eduardo Habkost)  [Orabug: 29229728]  
- bnx2x: disable GSO where gso_size is too big for hardware (Daniel Axtens)  [Orabug: 29125104]  {CVE-2018-1000026} 
- net: create skb_gso_validate_mac_len() (Daniel Axtens)  [Orabug: 29125104]  {CVE-2018-1000026} 
- slub: make ->cpu_partial unsigned (Alexey Dobriyan)  [Orabug: 28973025]
- 
    Tue Jan 29 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.2.4.el7uek]
    - x86/platform/UV: Add check of TSC state set by UV BIOS (mike.travis@hpe.com)  [Orabug: 29205471]  
- x86/tsc: Provide a means to disable TSC ART (mike.travis@hpe.com)  [Orabug: 29205471]  
- x86/tsc: Drastically reduce the number of firmware bug warnings (mike.travis@hpe.com)  [Orabug: 29205471]  
- x86/tsc: Skip TSC test and error messages if already unstable (mike.travis@hpe.com)  [Orabug: 29205471]  
- x86/tsc: Add option that TSC on Socket 0 being non-zero is valid (mike.travis@hpe.com)  [Orabug: 29205471]  
- scsi: lpfc: Enable Management features for IF_TYPE=6 (James Smart)  [Orabug: 29248376] 
- 
    Mon Jan 28 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.2.3.el7uek]
    - RDS: Heap OOB write in rds_message_alloc_sgs() (Mohamed Ghannam)  [Orabug: 28983233]  
- proc: restrict kernel stack dumps to root (Jann Horn)  [Orabug: 29114876]  {CVE-2018-17972} 
- rds: congestion updates can be missed when kernel low on memory (Mukesh Kacker)  [Orabug: 29200902]  
- x86/retpoline: Make CONFIG_RETPOLINE depend on compiler support (Zhenzhong Duan)  [Orabug: 29211613]  
- xen-netback: wake up xenvif_dealloc_kthread when it should stop (Dongli Zhang)  [Orabug: 29237355]  
- xen/blkback: rework validate_io_op() (Dongli Zhang)  [Orabug: 29237430]  
- xen/blkback: optimize validate_io_op() to filter BLKIF_OP_RESERVED_1 operation (Dongli Zhang)  [Orabug: 29237430]  
- xen/blkback: do not BUG() for invalid blkif_request from frontend (Dongli Zhang)  [Orabug: 29237430]  
- net/rds: WARNING: at net/rds/recv.c:222 rds_recv_hs_exthdrs+0xf8/0x1e0 (Venkat Venkatsubra)  [Orabug: 29248238]  
- kvm: x86: Add AMD's EX_CFG to the list of ignored MSRs (Eduardo Habkost)  [Orabug: 29254549]  
- alarmtimer: Prevent overflow for relative nanosleep (Thomas Gleixner)  [Orabug: 29269148]  {CVE-2018-13053}
- 
    Tue Jan 22 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.2.2.el7uek]
    - genirq/affinity: Don't return with empty affinity masks on error (Thomas Gleixner)  [Orabug: 29209330]  
- x86/apic/x2apic: set affinity of a single interrupt to one cpu (Jianchao Wang)  [Orabug: 29201434]  
- uek-rpm: Update x86_64 config options (Victor Erminpour)  [Orabug: 29129556]  
- net: rds: fix excess initialization of the recv SGEs (Zhu Yanjun)  [Orabug: 29004501]  
- nvme-pci: fix memory leak on probe failure (Keith Busch)  [Orabug: 29214245]  
- nvme-pci: limit max IO size and segments to avoid high order allocations (Jens Axboe)  [Orabug: 29214245]  
- arm64, dtrace: add non-virtual clocksources to fbt blacklist (Nick Alcock)  [Orabug: 29220926]  
- net/rds: ib: Fix endless RNR Retries caused by memory allocation failures (Venkat Venkatsubra)  [Orabug: 29222874]  
- x86/speculation: simplify IBRS firmware control (Alexandre Chartre)  [Orabug: 29225114]  
- x86/speculation: use jump label instead of alternative to control IBRS firmware (Alexandre Chartre)  [Orabug: 29225114]  
- x86/speculation: fix and simplify IBPB control (Alexandre Chartre)  [Orabug: 29225114]  
- x86/speculation: use jump label instead of alternative to control IBPB (Alexandre Chartre)  [Orabug: 29225114]  
- x86/speculation: move ANNOTATE_* macros to a new header file (Alexandre Chartre)  [Orabug: 29225114]  
- be2net: Update the driver version to 12.0.0.0 (Suresh Reddy)  [Orabug: 29228473]  
- be2net: Handle transmit completion errors in Lancer (Suresh Reddy)  [Orabug: 29228473]  
- be2net: Fix HW stall issue in Lancer (Suresh Reddy)  [Orabug: 29228473]  
- x86/platform/UV: Fix GAM MMR references in the UV x2apic code (Mike Travis)  [Orabug: 29205471]  
- x86/platform/UV: Fix GAM MMR changes in UV4A (Mike Travis)  [Orabug: 29205471]  
- x86/platform/UV: Add references to access fixed UV4A HUB MMRs (Mike Travis)  [Orabug: 29205471]  
- x86/platform/UV: Fix UV4A support on new Intel Processors (Mike Travis)  [Orabug: 29205471]  
- x86/platform/UV: Update uv_mmrs.h to prepare for UV4A fixes (Mike Travis)  [Orabug: 29205471] 
- 
    Mon Jan 14 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.2.1.el7uek]
    - rds: Incorrect rds-info send and retransmission message output (Ka-Cheong Poon)  [Orabug: 29024033]  
- mlx4_core: Disable P_Key Violation Traps (Håkon Bugge)  [Orabug: 28861014]  
- rds: ib: Use a delay when reconnecting to the very same IP address (Håkon Bugge)  [Orabug: 29161391]  
- KVM: Fix UAF in nested posted interrupt processing (Cfir Cohen)  [Orabug: 29172125]  {CVE-2018-16882} 
- x86/alternative: check int3 breakpoint physical addresses (Alexandre Chartre)  [Orabug: 29178334]  
- Change mincore() to count "mapped" pages rather than "cached" pages (Linus Torvalds)  [Orabug: 29187408]  {CVE-2019-5489} 
- net/rds: RDS connection does not reconnect after CQ access violation error (Venkat Venkatsubra)  [Orabug: 29180514]
- 
    Mon Jan 07 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.2.0.el7uek]
    - userfaultfd: check VM_MAYWRITE was set after verifying the uffd is registered (Andrea Arcangeli)  [Orabug: 29163742]  {CVE-2018-18397} 
- userfaultfd: shmem/hugetlbfs: only allow to register VM_MAYWRITE vmas (Andrea Arcangeli)  [Orabug: 29163742]  {CVE-2018-18397} 
- ocfs2: don't clear bh uptodate for block read (Junxiao Bi)  [Orabug: 29159655]  
- ocfs2: clear journal dirty flag after shutdown journal (Junxiao Bi)  [Orabug: 29154599]  
- ocfs2: fix panic due to unrecovered local alloc (Junxiao Bi)  [Orabug: 29154599]
- 
    Wed Jan 02 2019 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.1.3.el7uek]
    - net: rds: fix rds_ib_sysctl_max_recv_allocation error (Zhu Yanjun)  [Orabug: 29003422]  
- nfs: don't dirty kernel pages read by direct-io (Dave Kleikamp)  [Orabug: 29122062]  
- KVM: X86: Fix scan ioapic use-before-initialization (Wanpeng Li)  [Orabug: 29026132]  {CVE-2018-19407} 
- hugetlb: take PMD sharing into account when flushing tlb/caches (Mike Kravetz)  [Orabug: 28951436]  
- mm: migration: fix migration of huge PMD shared pages (Mike Kravetz)  [Orabug: 28951436]  
- mm/mmu_notifier: avoid double notification when it is useless (Jérôme Glisse)  [Orabug: 28951436]
- 
    Tue Dec 18 2018 Jack Vogel <jack.vogel@oracle.com> [4.14.35-1844.1.2.el7uek]
    - ALSA: usb-audio: Fix UAF decrement if card has no live interfaces in card.c (Hui Peng)  [Orabug: 29042979]  {CVE-2018-19824} 
- arm64/kernel: kaslr: reduce module randomization range to 4 GB (Ard Biesheuvel)  [Orabug: 28954789]  
- xfs: enhance dinode verifier (Eric Sandeen)  [Orabug: 28997653]  {CVE-2018-10322} 
- xfs: move inode fork verifiers to xfs_dinode_verify (Darrick J. Wong)  [Orabug: 28997653]  {CVE-2018-10322} 
- Revert "xfs: move inode fork verifiers to xfs_dinode_verify" (Shan Hai)  [Orabug: 28997653]  
- Revert "xfs: enhance dinode verifier" (Shan Hai)  [Orabug: 28997653]