-
Wed Apr 16 2025 Craig Guiller <craig.guiller@oracle.com> - [5.14.0-503.38.1.el9_5.OL9]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5.el9
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
-
Mon Apr 14 2025 Chao YE <cye@redhat.com> [5.14.0-503.38.1.el9_5]
- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (CKI Backport Bot) [RHEL-86726] {CVE-2024-53150}
-
Sun Apr 06 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-503.37.1.el9_5]
- scsi: core: Fix command pass through retry regression (Ewan D. Milne) [RHEL-77123]
-
Sun Mar 30 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-503.36.1.el9_5]
- cpufreq: intel_pstate: Support Emerald Rapids OOB mode (Steve Best) [RHEL-67636]
- cxgb4: use port number to set mac addr (Michal Schmidt) [RHEL-79672]
- ice: stop storing XDP verdict within ice_rx_buf (Petr Oros) [RHEL-76141]
- ice: gather page_count()'s of each frag right before XDP prog call (Petr Oros) [RHEL-76141]
- ice: put Rx buffers after being done with current frame (Petr Oros) [RHEL-76141]
- gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup (Joshua Washington) [RHEL-74413]
- gve: process XSK TX descriptors as part of RX NAPI (Joshua Washington) [RHEL-74413]
- gve: guard XSK operations on the existence of queues (Joshua Washington) [RHEL-74413] {CVE-2024-57933}
- gve: guard XDP xmit NDO on existence of xdp queues (Joshua Washington) [RHEL-74413] {CVE-2024-57932}
- gve: Fix an edge case for TSO skb validity check (Joshua Washington) [RHEL-74413]
- gve: Fix XDP TX completion handling when counters overflow (Joshua Washington) [RHEL-74413]
- gve: Clear napi->skb before dev_kfree_skb_any() (Joshua Washington) [RHEL-74413] {CVE-2024-40937}
- gve: ignore nonrelevant GSO type bits when processing TSO headers (Joshua Washington) [RHEL-74413]
-
Sun Mar 23 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-503.35.1.el9_5]
- cppc_cpufreq: Use desired perf if feedback ctrs are 0 or unchanged (Mark Langsdorf) [RHEL-78643]
- coresight: etm4x: Add ACPI support in platform driver (Mark Salter) [RHEL-80223]
- block: Fix lockdep warning in blk_mq_mark_tag_wait (Ming Lei) [RHEL-73024]
- md: fix deadlock between mddev_suspend and flush bio (Nigel Croxon) [RHEL-76058] {CVE-2024-43855}
- redhat/configs: replace IOMMU_DEFAULT_DMA_STRICT with IOMMU_DEFAULT_DMA_LAZY (Jerry Snitselaar) [RHEL-76412]
- ibmvnic: Only record tx completed bytes once per handler (Mamatha Inamdar) [RHEL-71289]
- ibmvnic: Only replenish rx pool when resources are getting low (Mamatha Inamdar) [RHEL-71289]
- ibmvnic: Return error code on TX scrq flush fail (Mamatha Inamdar) [RHEL-71289]
- intel_idle: fix ACPI _CST matching for newer Xeon platforms (David Arcari) [RHEL-62987]
-
Mon Mar 17 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-503.34.1.el9_5]
- arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (CKI Backport Bot) [RHEL-82734] {CVE-2025-21785}
- crypto: rng - Fix extrng EFAULT handling (Herbert Xu) [RHEL-70643]
-
Wed Mar 12 2025 Chao YE <cye@redhat.com> [5.14.0-503.33.1.el9_5]
- scsi: st: New session only when Unit Attention for new tape (John Meneghini) [RHEL-62266]
- scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after device reset (John Meneghini) [RHEL-62266]
- scsi: st: Don't modify unknown block number in MTIOCGET (John Meneghini) [RHEL-62266]
- x86/mm/ident_map: Use gbpages only where full GB page should be mapped. (Chris von Recklinghausen) [RHEL-62210]
- SUNRPC: Handle -ETIMEDOUT return from tlshd (Benjamin Coddington) [RHEL-79870]
- SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT (Benjamin Coddington) [RHEL-79870]
- tls: Fix tls_sw_sendmsg error handling (Benjamin Coddington) [RHEL-79870]
- SUNRPC: Fix a hang in TLS sock_close if sk_write_pending (Benjamin Coddington) [RHEL-79870]
-
Sun Mar 09 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-503.32.1.el9_5]
- SUNRPC: Handle -ETIMEDOUT return from tlshd (Benjamin Coddington) [RHEL-79870]
- SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT (Benjamin Coddington) [RHEL-79870]
- tls: Fix tls_sw_sendmsg error handling (Benjamin Coddington) [RHEL-79870]
- SUNRPC: Fix a hang in TLS sock_close if sk_write_pending (Benjamin Coddington) [RHEL-79870]
-
Thu Mar 06 2025 Chao YE <cye@redhat.com> [5.14.0-503.31.1.el9_5]
- HID: core: zero-initialize the report buffer (Benjamin Tissoires) [RHEL-81838] {CVE-2024-50302}
- x86/kaslr: Expose and use the end of the physical memory address space (Waiman Long) [RHEL-70002]
- ALSA: usb-audio: Fix a DMA to stack memory bug (Jaroslav Kysela) [RHEL-81799]
- ALSA: usb-audio: Fix for sampling rates support for Mbox3 (Jaroslav Kysela) [RHEL-81799]
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Jaroslav Kysela) [RHEL-81799] {CVE-2024-53197}
- ALSA: usb-audio: Add sampling rates support for Mbox3 (Jaroslav Kysela) [RHEL-81799]
- x86/kexec: Add EFI config table identity mapping for kexec kernel (Jay Shin) [RHEL-74170]
- mm: fix NULL pointer dereference in alloc_pages_bulk_noprof (Jay Shin) [RHEL-73210] {CVE-2024-53113}
- can: bcm: Fix UAF in bcm_proc_show() (CKI KWF BOT) [RHEL-80746] {CVE-2023-52922}
- smb: client: fix chmod(2) regression with ATTR_READONLY (Jay Shin) [RHEL-80526]
- hugetlb: prioritize surplus allocation from current node (Aristeu Rozanski) [RHEL-77488]
- dev: Acquire netdev_rename_lock before restoring dev->name in dev_change_name(). (Antoine Tenart) [RHEL-77338]
- net: add softirq safety to netdev_rename_lock (Antoine Tenart) [RHEL-77343]
- arp: Convert ioctl(SIOCGARP) to RCU. (Antoine Tenart) [RHEL-77343]
- net: Protect dev->name by seqlock. (Antoine Tenart) [RHEL-77343]
- net: Remove unused declaration dev_restart() (Antoine Tenart) [RHEL-77343]
- arp: Get dev after calling arp_req_(delete|set|get)(). (Antoine Tenart) [RHEL-77343]
- arp: Remove a nest in arp_req_get(). (Antoine Tenart) [RHEL-77343]
- arp: Factorise ip_route_output() call in arp_req_set() and arp_req_delete(). (Antoine Tenart) [RHEL-77343]
- arp: Validate netmask earlier for SIOCDARP and SIOCSARP in arp_ioctl(). (Antoine Tenart) [RHEL-77343]
- arp: Move ATF_COM setting in arp_req_set(). (Antoine Tenart) [RHEL-77343]
- ACPI: extlog: fix NULL pointer dereference check (Mark Langsdorf) [RHEL-75250] {CVE-2023-52605}
- vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (Jon Maloy) [RHEL-75461] {CVE-2024-50264}
- x86/pci: Skip early E820 check for ECAM region (CKI Backport Bot) [RHEL-67065]
- cpufreq: intel_pstate: Update Balance performance EPP for Emerald Rapids (Steve Best) [RHEL-64291]
-
Sun Mar 02 2025 Patrick Talbert <ptalbert@redhat.com> [5.14.0-503.30.1.el9_5]
- can: bcm: Fix UAF in bcm_proc_show() (CKI KWF BOT) [RHEL-80746] {CVE-2023-52922}
- smb: client: fix chmod(2) regression with ATTR_READONLY (Jay Shin) [RHEL-80526]
- hugetlb: prioritize surplus allocation from current node (Aristeu Rozanski) [RHEL-77488]
- dev: Acquire netdev_rename_lock before restoring dev->name in dev_change_name(). (Antoine Tenart) [RHEL-77338]
- net: add softirq safety to netdev_rename_lock (Antoine Tenart) [RHEL-77343]
- arp: Convert ioctl(SIOCGARP) to RCU. (Antoine Tenart) [RHEL-77343]
- net: Protect dev->name by seqlock. (Antoine Tenart) [RHEL-77343]
- net: Remove unused declaration dev_restart() (Antoine Tenart) [RHEL-77343]
- arp: Get dev after calling arp_req_(delete|set|get)(). (Antoine Tenart) [RHEL-77343]
- arp: Remove a nest in arp_req_get(). (Antoine Tenart) [RHEL-77343]
- arp: Factorise ip_route_output() call in arp_req_set() and arp_req_delete(). (Antoine Tenart) [RHEL-77343]
- arp: Validate netmask earlier for SIOCDARP and SIOCSARP in arp_ioctl(). (Antoine Tenart) [RHEL-77343]
- arp: Move ATF_COM setting in arp_req_set(). (Antoine Tenart) [RHEL-77343]
- ACPI: extlog: fix NULL pointer dereference check (Mark Langsdorf) [RHEL-75250] {CVE-2023-52605}
- vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (Jon Maloy) [RHEL-75461] {CVE-2024-50264}
- x86/pci: Skip early E820 check for ECAM region (CKI Backport Bot) [RHEL-67065]
- cpufreq: intel_pstate: Update Balance performance EPP for Emerald Rapids (Steve Best) [RHEL-64291]