Zeros312
oval:com.oracle.elsa:def:202630844 | ELSA-2026-30844: mod_md security update (MODERATE) | [1:2.4.26-2.1]
- Resolves: RHEL-175644 - mod_md: OCSP response limits
(CVE-2026-29168)
[1:2.4.26-2]
- Resolves: RHEL-134497 - httpd: Apache HTTP Server: mod_md (ACME), unintended
retry intervals (CVE-2025-55753) | MODERATE | 2026-06-29 00:00:00+03:00 | ['CVE-2026-29168'] | ['Oracle Linux 9'] | ['CVE-2026-29168', 'ELSA-2026-30844', 'https://linux.oracle.com/cve/CVE-2026-29168.html', 'https://linux.oracle.com/errata/ELSA-2026-30844.html'] | f3d50f4034097537f71a6a4e709147b04473819ff875588081739c58dd4b7f27 | 2026-06-29 20:18:23.536535+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202618916 | ELSA-2026-18916: tomcat security update (IMPORTANT) | [1:9.0.117-1]
- Resolves: RHEL-150714 Certificate revocation bypass due to improper OCSP response validation
- Resolves:
Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (CVE-2026-34500)
- Resolves:
Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token (CVE-2026-34487)
- Resolves:
Tomcat: The fix for CVE-2026-29146 allowed the bypass of the EncryptInterceptor (CVE-2026-34486)
- Resolves:
Tomcat: Incomplete escaping of JSON access logs (CVE-2026-34483)
- Resolves:
Tomcat: The fix for CVE-2025-66614 was incomplete (CVE-2026-32990)
- Resolves:
Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default (CVE-2026-29146)
- Resolves:
Tomcat: OCSP checks sometimes soft-fail even when soft-fail is disabled (CVE-2026-29145)
- Resolves:
Tomcat: Configured TLS cipher preference order not preserved (CVE-2026-29129)
- Resolves:
Tomcat: Occasionally open redirect (CVE-2026-25854)
- Resolves:
Tomcat: Request smuggling via invalid chunk extension (CVE-2026-24880)
- Resolves:
Tomcat: Incomplete OCSP verification checks (CVE-2026-24734)
- Resolves:
Tomcat: Security constraint bypass (CVE-2026-24733)
- Resolves:
Tomcat: Client certificate verification bypass due to virtual host mapping (CVE-2025-66614) | IMPORTANT | 2026-06-29 00:00:00+03:00 | ['CVE-2025-46701', 'CVE-2025-55668', 'CVE-2025-55754'] | ['Oracle Linux 9'] | ['CVE-2025-46701', 'CVE-2025-55668', 'CVE-2025-55754', 'ELSA-2026-18916', 'https://linux.oracle.com/cve/CVE-2025-46701.html', 'https://linux.oracle.com/cve/CVE-2025-55668.html', 'https://linux.oracle.com/cve/CVE-2025-55754.html', 'https://linux.oracle.com/errata/ELSA-2026-18916.html'] | 6e1249676519ab9fc90a88321c779dce7efa53a9f4e86a32435a724791fe670f | 2026-06-29 20:18:23.536535+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202650346 | ELSA-2026-50346: gnutls security fix update (IMPORTANT) | [3.8.10-4_fips]
- Add FIPS package change: add fips suffix to Release and
set Epoch to 10 [Orabug: 35925409]
- Update FIPS module name for Oracle Linux [Orabug: 35925409]
[3.8.10-4]
- Fix CVE-2026-33846 (DTLS fragment reassembly, High, heap overwrite)
- Fix CVE-2026-42009 (DTLS fragment reassembly, High, undefined behaviour)
- Fix CVE-2026-33845 (DTLS fragment reassembly, High, heap overread)
- Fix CVE-2026-42010 (PSK authentication, High, authentication bypass)
- Fix CVE-2026-3833 (Name constraints, Medium, name constraint bypass)
- Fix CVE-2026-42011 (Name constraints, Medium, name constraint bypass)
- Fix CVE-2026-42012 (CN fallback, Medium, certificate misuse)
- Fix CVE-2026-42013 (CN fallback, Medium, certificate misuse)
- Fix CVE-2026-42014 (PKCS#11 PIN change, Medium, use-after-free)
- Fix CVE-2026-5260 (PKCS#11 RSA, Medium, heap overread)
- Fix CVE-2026-42015 (PKCS#12 appending, Low, heap overwrite)
- Fix CVE-2026-3832 (OCSP, Low, revocation bypass)
- Fix CVE-2026-5419 (PKCS#7, Low, timing side-channel)
- Fix upstream security issue #1808 (PSK rehandshake)
- Fix upstream security issue #1810 (EKU OID prefix match)
- Fix upstream security issue #1813 (pkcs11-provider persistent keys)
- Fix upstream security issue #1818 (RSA correctness, OpenSSL format import)
- Fix upstream security issue #1819 (PKCS#11 trust removal error path)
- Fix upstream security issue #1822 (SCT extension parser OOB read)
- Fix upstream security issue #1841 (key zeroization in hybrid kex)
- Fix upstream security issue #1823 (malformed certtool template)
- Fix upstream security issue #1817 (session parameter loading robustness)
- Fix upstream security issue #1820 (PKCS#11 KDF succeeding w/o deriving)
- gnutls-3.8.10-CVE-2025-9820.patch: update Makefile.in
[3.8.10-3]
- Fix PKCS#11 token initialization label overflow (CVE-2025-9820)
- Fix name constraint processing performance issue (CVE-2025-14831)
[3.8.10-2]
- Reinstate and update the prematurely dropped rekeying patch
[3.8.10-1]
- Rebase to 3.8.10
- Revert defaulting to PBMAC1 in FIPS mode
- Revert unapproving 1024-, 1280-, 1536- and 1792-bit RSA verification | IMPORTANT | 2026-06-24 00:00:00+03:00 | ['CVE-2026-33845', 'CVE-2026-33846', 'CVE-2026-3832', 'CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42011', 'CVE-2026-42012', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260', 'CVE-2026-5419'] | ['Oracle Linux 9'] | ['CVE-2026-33845', 'CVE-2026-33846', 'CVE-2026-3832', 'CVE-2026-3833', 'CVE-2026-42009', 'CVE-2026-42010', 'CVE-2026-42011', 'CVE-2026-42012', 'CVE-2026-42013', 'CVE-2026-42014', 'CVE-2026-42015', 'CVE-2026-5260', 'CVE-2026-5419', 'ELSA-2026-50346', 'https://linux.oracle.com/cve/CVE-2026-33845.html', 'https://linux.oracle.com/cve/CVE-2026-33846.html', 'https://linux.oracle.com/cve/CVE-2026-3832.html', 'https://linux.oracle.com/cve/CVE-2026-3833.html', 'https://linux.oracle.com/cve/CVE-2026-42009.html', 'https://linux.oracle.com/cve/CVE-2026-42010.html', 'https://linux.oracle.com/cve/CVE-2026-42011.html', 'https://linux.oracle.com/cve/CVE-2026-42012.html', 'https://linux.oracle.com/cve/CVE-2026-42013.html', 'https://linux.oracle.com/cve/CVE-2026-42014.html', 'https://linux.oracle.com/cve/CVE-2026-42015.html', 'https://linux.oracle.com/cve/CVE-2026-5260.html', 'https://linux.oracle.com/cve/CVE-2026-5419.html', 'https://linux.oracle.com/errata/ELSA-2026-50346.html'] | 868e3d178529e558636fa39a877fffa1dd75d05ea7a43b814e77f903cb6e760e | 2026-06-29 20:18:23.536535+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202650345 | ELSA-2026-50345: openssl security fix update (MODERATE) | [3.5.5-3.0.1]
- Replace upstream references in fips man pages [Orabug: 35824276]
- Update additional upstream references
- Add FIPS package change: add fips suffix to Release and
set Epoch to 10 [Orabug: 35824276]
- Update FIPS module name [Orabug: 35824276]
- Enable openssl-fips-provider dependency [Orabug: 36504822]
- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]
- Replace upstream references [Orabug: 34340177]
[1:3.5.5-3]
- Fix CVE-2026-28390
Resolves: RHEL-165870
[1:3.5.5-2]
- Fix CVE-2026-31790
Resolves: RHEL-161586
[1:3.5.5-1]
- Rebase to OpenSSL 3.5.5
Resolves: RHEL-136895
Resolves: RHEL-142004
Resolves: RHEL-142012
Resolves: RHEL-142020
Resolves: RHEL-142024
Resolves: RHEL-142028
Resolves: RHEL-142032
Resolves: RHEL-142036
Resolves: RHEL-142040
Resolves: RHEL-142044
Resolves: RHEL-142048
Resolves: RHEL-142052
Resolves: RHEL-142056 | MODERATE | 2026-06-24 00:00:00+03:00 | ['CVE-2026-28390'] | ['Oracle Linux 9'] | ['CVE-2026-28390', 'ELSA-2026-50345', 'https://linux.oracle.com/cve/CVE-2026-28390.html', 'https://linux.oracle.com/errata/ELSA-2026-50345.html'] | f1d42d2133c43a83676181db78a79c25418a8bff1b8b414a20fb2ff384e005d9 | 2026-06-29 20:18:23.536535+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202629898 | ELSA-2026-29898: libpng security update (MODERATE) | [2:1.6.37-11]
- fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161344) | MODERATE | 2026-06-25 00:00:00+03:00 | ['CVE-2026-33416'] | ['Oracle Linux 8'] | ['CVE-2026-33416', 'ELSA-2026-29898', 'https://linux.oracle.com/cve/CVE-2026-33416.html', 'https://linux.oracle.com/errata/ELSA-2026-29898.html'] | a6fe006e69f44c37601cf83f931b6de98f3dd692241963beef38c23e25ed2a6c | 2026-06-26 01:31:49.792705+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202515904 | ELSA-2025-15904: container-tools:ol8 security update (IMPORTANT) | aardvark-dns
buildah
cockpit-podman
conmon
containernetworking-plugins
containers-common
[1-82.0.1]
- Updated removed references [Orabug: 33473101] (Alex Burmashev)
- Adjust registries.conf (Nikita Gerasimov)
- remove references to RedHat registry (Nikita Gerasimov)
[2:1-82]
- update vendored components
- Resolves: RHEL-40801
[2:1-81]
- Update shortnames from Pyxis
- Related: Jira:RHEL-2110
[2:1-80]
- bump release to preserve upgrade path
- Resolves: Jira:RHEL-12277
[2:1-59]
- update vendored components
- Related: Jira:RHEL-2110
[2:1-58]
- update vendored components
- Related: Jira:RHEL-2110
[2:1-57]
- fix shortnames for rhel-minimal
- Related: Jira:RHEL-2110
[2:1-56]
- implement GPG auto updating mechanism from redhat-release
- Resolves: #RHEL-2110
[2:1-55]
- update GPG keys to the current content of redhat-release
- Resolves: #RHEL-3164
[2:1-54]
- update vendored components and shortnames
- Related: #2176055
[2:1-53]
- update vendored components
- Related: #2176055
[2:1-52]
- update vendored components
- Related: #2176055
[2:1-51]
- be sure default_capabilities contain SYS_CHROOT
- Resolves: #2166195
[2:1-50]
- improve shortnames generation
- Related: #2176055
[2:1-49]
- update vendored components and configuration files
- Related: #2123641
[2:1-48]
- update vendored components and configuration files
- Related: #2123641
[2:1-47]
- enable NET_RAW capability for RHEL8 only
- Related: #2123641
[2:1-46]
- update vendored components and configuration files
- Related: #2123641
[2:1-45]
- update vendored components and configuration files
- Related: #2123641
[2:1-44]
- update vendored components and configuration files
- Related: #2123641
[2:1-43]
- update vendored components and configuration files
- Related: #2123641
[2:1-42]
- update vendored components and configuration files
- Related: #2123641
[2:1-41]
- add beta GPG key
- Related: #2123641
[2:1-40]
- add beta keys to default-policy.json
- Related: #2061390
[2:1-39]
- update shortnames
- Related: #2061390
[2:1-38]
- arch limitation because of go-md2man (missing on i686)
- Related: #2061390
[2:1-37]
- add install section
- update vendored components
- Related: #2061390
[2:1-36]
- remove aardvark-dns and netavark - packaged separately
- update vendored components and configuration files
- Related: #2061390
[2:1-35]
- update vendored components and configuration files
- Related: #2061390
[2:1-34]
- remove rhel-els and update shortnames
- Related: #2061390
[2:1-33]
- update shortnames
- Related: #2061390
[2:1-32]
- additional fix for unqualified registries
- Related: #2061390
[2:1-31]
- fix unqualified registries
- Related: #2061390
[2:1-30]
- update vendored components and configuration files
- Related: #2061390
[2:1-29]
- update unqualified registries list
- Related: #2061390
[2:1-28]
- update aardvark-dns and netavark to 1.0.3
- update vendored components
- Related: #2061390
[2:1-27]
- add man page sources too
- Related: #2061390
[2:1-26]
- add missing man pages from Fedora
- Related: #2061390
[2:1-25]
- allow consuming aardvark-dns and netavark from upstream branch
- Related: #2061390
[2:1-24]
- update to netavark and aardvark-dns 1.0.2
- update vendored components
- Related: #2061390
[2:1-23]
- update to netavark and aardvark-dns 1.0.1
- Related: #2001445
[2:1-22]
- build rust packages with RUSTFLAGS set to make ExecShield happy
- Related: #2001445
[2:1-21]
- do not specify infra_image in containers.conf
- needed to resolve gating test failures
- Related: #2001445
[2:1-20]
- update to netavark-1.0.0 and aardvark-dns-1.0.0
- Related: #2001445
[2:1-19]
- package aarvark-dns and netavark as part of the containers-common
- Related: #2001445
[2:1-18]
- update shortnames and vendored components
- Related: #2001445
[2:1-17]
- containers.conf should contain network_backend = 'cni' in RHEL8.6
- Related: #2001445
[2:1-16]
- update vendored components and configuration files
- Related: #2001445
[2:1-15]
- sync vendored components
- Related: #2001445
[2:1-14]
- sync vendored components
- Related: #2001445
[2:1-13]
- update shortnames from Pyxis
- Related: #2001445
[2:1-12]
- do not allow broken content from Pyxis to land in shortnames.conf
- Related: #2001445
[2:1-11]
- sync vendored components
- update shortnames from Pyxis
- Related: #2001445
[2:1-10]
- use log_driver = 'journald' and events_logger = 'journald' for RHEL9
- Related: #2001445
[2:1-9]
- consume seccomp.json from the oldest vendored version of c/common,
not main branch
- Related: #2001445
[2:1-8]
- update vendored components
- Related: #2001445
[2:1-7]
- make log_driver = 'k8s-file' default in containers.conf
- Related: #2001445
[2:1-6]
- sync vendored components
- Related: #2001445
[2:1-5]
- update to the new vendored components
- Related: #2001445
[2:1-4]
- update to the new vendored components
- Related: #2001445
[2:1-3]
- update to the new vendored components
- Related: #2001445
[2:1-2]
- synchronize config files for RHEL-8.5
- Related: #1934415
[2:1-1]
- initial import
- Related: #1934415
container-selinux
criu
crun
fuse-overlayfs
libslirp
netavark
oci-seccomp-bpf-hook
podman
[4.9.4-23.0.1]
- Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813]
- Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802]
- Fixes issue of podman execvp error while using podmansh [Orabug: 36756665]
[4:4.9.4-23]
- update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel
(https://github.com/containers/podman/commit/ff15af1)
- fixes 'CVE-2025-9566 container-tools:rhel8/podman: Podman kube play command may overwrite host files [rhel-8.10.z]'
- Resolves: RHEL-113145
python-podman
runc
skopeo
slirp4netns
udica | IMPORTANT | 2025-09-17 00:00:00+03:00 | ['CVE-2025-9566'] | ['Oracle Linux 8'] | ['CVE-2025-9566', 'ELSA-2025-15904', 'https://linux.oracle.com/cve/CVE-2025-9566.html', 'https://linux.oracle.com/errata/ELSA-2025-15904.html'] | dc31866a90280f6e646d700cf83e198de76e52f544928cdeffc559039720b6c7 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20261631 | ELSA-2026-1631: python3 security update (MODERATE) | [3.6.8-72.0.1]
- Add Oracle Linux distribution in platform.py [Orabug: 20812544]
[3.6.8.openela.0]
- Add openela to supported dists
[3.6.8-72]
- Security fix for CVE-2025-12084
Resolves: RHEL-135911 | MODERATE | 2026-02-01 00:00:00+03:00 | ['CVE-2025-12084'] | ['Oracle Linux 8'] | ['CVE-2025-12084', 'ELSA-2026-1631', 'https://linux.oracle.com/cve/CVE-2025-12084.html', 'https://linux.oracle.com/errata/ELSA-2026-1631.html'] | 34e391268635668f8a0d307cb608db990da5f2c1be8336ad67151915e9ccd482 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202623332 | ELSA-2026-23332: mysql security update (MODERATE) | [8.0.46-1]
- Rebase to 8.0.46
[8.0.45-2]
- Revert to soft static allocation of MariaDB and MySQL sysusers.d files | MODERATE | 2026-06-26 00:00:00+03:00 | ['CVE-2026-21998', 'CVE-2026-22001', 'CVE-2026-22002', 'CVE-2026-22004', 'CVE-2026-22005', 'CVE-2026-22009', 'CVE-2026-22015', 'CVE-2026-22017', 'CVE-2026-34267', 'CVE-2026-34270', 'CVE-2026-34271', 'CVE-2026-34276', 'CVE-2026-34278', 'CVE-2026-34293', 'CVE-2026-34303', 'CVE-2026-34304', 'CVE-2026-34308', 'CVE-2026-35236', 'CVE-2026-35237', 'CVE-2026-35238', 'CVE-2026-35239', 'CVE-2026-35240'] | ['Oracle Linux 9'] | ['CVE-2026-21998', 'CVE-2026-22001', 'CVE-2026-22002', 'CVE-2026-22004', 'CVE-2026-22005', 'CVE-2026-22009', 'CVE-2026-22015', 'CVE-2026-22017', 'CVE-2026-34267', 'CVE-2026-34270', 'CVE-2026-34271', 'CVE-2026-34276', 'CVE-2026-34278', 'CVE-2026-34293', 'CVE-2026-34303', 'CVE-2026-34304', 'CVE-2026-34308', 'CVE-2026-35236', 'CVE-2026-35237', 'CVE-2026-35238', 'CVE-2026-35239', 'CVE-2026-35240', 'ELSA-2026-23332', 'https://linux.oracle.com/cve/CVE-2026-21998.html', 'https://linux.oracle.com/cve/CVE-2026-22001.html', 'https://linux.oracle.com/cve/CVE-2026-22002.html', 'https://linux.oracle.com/cve/CVE-2026-22004.html', 'https://linux.oracle.com/cve/CVE-2026-22005.html', 'https://linux.oracle.com/cve/CVE-2026-22009.html', 'https://linux.oracle.com/cve/CVE-2026-22015.html', 'https://linux.oracle.com/cve/CVE-2026-22017.html', 'https://linux.oracle.com/cve/CVE-2026-34267.html', 'https://linux.oracle.com/cve/CVE-2026-34270.html', 'https://linux.oracle.com/cve/CVE-2026-34271.html', 'https://linux.oracle.com/cve/CVE-2026-34276.html', 'https://linux.oracle.com/cve/CVE-2026-34278.html', 'https://linux.oracle.com/cve/CVE-2026-34293.html', 'https://linux.oracle.com/cve/CVE-2026-34303.html', 'https://linux.oracle.com/cve/CVE-2026-34304.html', 'https://linux.oracle.com/cve/CVE-2026-34308.html', 'https://linux.oracle.com/cve/CVE-2026-35236.html', 'https://linux.oracle.com/cve/CVE-2026-35237.html', 'https://linux.oracle.com/cve/CVE-2026-35238.html', 'https://linux.oracle.com/cve/CVE-2026-35239.html', 'https://linux.oracle.com/cve/CVE-2026-35240.html', 'https://linux.oracle.com/errata/ELSA-2026-23332.html'] | 35bbb181b706f42f6086c14895b4d8cf144ed34e8133147e5bab4ad32b879690 | 2026-06-27 11:22:03.294410+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202628158 | ELSA-2026-28158: python-urllib3 security update (IMPORTANT) | [1.26.5-8]
- Security fix for CVE-2026-44431 and CVE-2026-44432
Resolves: RHEL-184816, RHEL-185123
[1.26.5-7]
- Security fix for CVE-2025-66471
- Security fix for CVE-2025-66418
- Security fix for CVE-2026-21441
Resolves: RHEL-142750, RHEL-139398, RHEL-142767 | IMPORTANT | 2026-06-24 00:00:00+03:00 | ['CVE-2026-44431', 'CVE-2026-44432'] | ['Oracle Linux 9'] | ['CVE-2026-44431', 'CVE-2026-44432', 'ELSA-2026-28158', 'https://linux.oracle.com/cve/CVE-2026-44431.html', 'https://linux.oracle.com/cve/CVE-2026-44432.html', 'https://linux.oracle.com/errata/ELSA-2026-28158.html'] | a89d22f08bc4c629929f311c542282b7317f8ceda18ddfe4913781144b8ad2f1 | 2026-06-26 01:31:49.792705+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202410980 | ELSA-2024-10980: python3.12 security update (IMPORTANT) | [3.12.8-1]
- Update to 3.12.8
- Security fix for CVE-2024-9287 and CVE-2024-12254
Resolves: RHEL-64880, RHEL-70315 | IMPORTANT | 2024-12-12 00:00:00+03:00 | ['CVE-2024-12254', 'CVE-2024-9287'] | ['Oracle Linux 8'] | ['CVE-2024-12254', 'CVE-2024-9287', 'ELSA-2024-10980', 'https://linux.oracle.com/cve/CVE-2024-12254.html', 'https://linux.oracle.com/cve/CVE-2024-9287.html', 'https://linux.oracle.com/errata/ELSA-2024-10980.html'] | d9929e722e42124dd7230cca2ede08b2ee60c5dcf9273c3bc5443924a24a321d | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523241 | ELSA-2025-23241: kernel security update (IMPORTANT) | [5.14.0-611.16.1]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-611.16.1]
- CVE-2025-38499 kernel: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Abhi Das) [RHEL-129261] {CVE-2025-38499}
- tls: wait for pending async decryptions if tls_strp_msg_hold fails (CKI Backport Bot) [RHEL-128860] {CVE-2025-40176}
[5.14.0-611.15.1]
- nbd: override creds to kernel when calling sock_{send,recv}msg() (Ming Lei) [RHEL-123845]
- scsi: lpfc: avoid crashing in lpfc_nlp_get() if lpfc_nodelist was freed (Ewan D. Milne) [RHEL-127982]
- scsi: lpfc: Fix reusing an ndlp that is marked NLP_DROPPED during FLOGI (Ewan D. Milne) [RHEL-127982]
- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Fix SNP panic notifier unregistration (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Fix dereferencing uninitialized error pointer (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Fix __sev_snp_shutdown_locked (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Move SEV/SNP Platform initialization to KVM (Lenny Szubowicz) [RHEL-70006]
- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Add new SEV/SNP platform shutdown API (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Register SNP panic notifier only if SNP is enabled (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Reset TMR size at SNP Shutdown (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Ensure implicit SEV/SNP init and shutdown in ioctls (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (Lenny Szubowicz) [RHEL-70006]
- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Lenny Szubowicz) [RHEL-70006]
[5.14.0-611.14.1]
- iommufd: Fix race during abort for file descriptors (Eder Zulian) [RHEL-123786] {CVE-2025-39966} | IMPORTANT | 2025-12-18 00:00:00+03:00 | ['CVE-2025-38499', 'CVE-2025-39966', 'CVE-2025-40176'] | ['Oracle Linux 9'] | ['CVE-2025-38499', 'CVE-2025-39966', 'CVE-2025-40176', 'ELSA-2025-23241', 'https://linux.oracle.com/cve/CVE-2025-38499.html', 'https://linux.oracle.com/cve/CVE-2025-39966.html', 'https://linux.oracle.com/cve/CVE-2025-40176.html', 'https://linux.oracle.com/errata/ELSA-2025-23241.html'] | 1c3c1b2734dc566cd1d6d1b601ab9be97a3e99273aea9e60df276ef344d2befd | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523295 | ELSA-2025-23295: podman security update (MODERATE) | [5.6.0-8.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.6.0-8]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
(https://github.com/containers/podman/commit/3bf5313)
- fixes 'run 1.2.x upgrade throws error while using nocopy volume mount filesystem option - [RHEL 10.1]'
- Resolves: RHEL-132532
[7:5.6.0-7]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125640 | MODERATE | 2025-12-18 00:00:00+03:00 | ['CVE-2025-58183'] | ['Oracle Linux 10'] | ['CVE-2025-58183', 'ELSA-2025-23295', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-23295.html'] | 75fd8d0139f7ea2a6e248c801bf328d9d13c701ff02fa185d7c353fc088856a1 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523294 | ELSA-2025-23294: skopeo security update (MODERATE) | [1:1.20.0-2]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125643 | MODERATE | 2025-12-18 00:00:00+03:00 | ['CVE-2025-58183'] | ['Oracle Linux 10'] | ['CVE-2025-58183', 'ELSA-2025-23294', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-23294.html'] | 21da9a18da66114a517063145116dd14f515638e4222ddac30c3030da03ac5bf | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523481 | ELSA-2025-23481: openssh security update (MODERATE) | [8.0p1-27.0.1]
- Update upstream references [Orabug: 36587718]
[8.0p1-27]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128400
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128390 | MODERATE | 2025-12-18 00:00:00+03:00 | ['CVE-2025-61984', 'CVE-2025-61985'] | ['Oracle Linux 8'] | ['CVE-2025-61984', 'CVE-2025-61985', 'ELSA-2025-23481', 'https://linux.oracle.com/cve/CVE-2025-61984.html', 'https://linux.oracle.com/cve/CVE-2025-61985.html', 'https://linux.oracle.com/errata/ELSA-2025-23481.html'] | d17cd68fb8f8804dbc4d62ebbdc6fa8a693fd92d46175856bf3a6835994cf818 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523480 | ELSA-2025-23480: openssh security update (MODERATE) | [8.7p1-47.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37814929]
- upstream: fix AuthorizedPrincipalsCommand when AuthorizedKeysCommand [Orabug: 37647064]
- Update upstream references [Orabug: 36564626]
[8.7p1-47]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128401
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128392 | MODERATE | 2025-12-18 00:00:00+03:00 | ['CVE-2025-61984', 'CVE-2025-61985'] | ['Oracle Linux 9'] | ['CVE-2025-61984', 'CVE-2025-61985', 'ELSA-2025-23480', 'https://linux.oracle.com/cve/CVE-2025-61984.html', 'https://linux.oracle.com/cve/CVE-2025-61985.html', 'https://linux.oracle.com/errata/ELSA-2025-23480.html'] | db7e46df002174d1ff632a110c24b859b9a155610c88c4f5265657a4819e3701 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523484 | ELSA-2025-23484: libssh security update (MODERATE) | [0.11.1-5]
- Fix CVE-2025-5987
Resolves: RHEL-130040 | MODERATE | 2025-12-17 00:00:00+03:00 | ['CVE-2025-5987'] | ['Oracle Linux 10'] | ['CVE-2025-5987', 'ELSA-2025-23484', 'https://linux.oracle.com/cve/CVE-2025-5987.html', 'https://linux.oracle.com/errata/ELSA-2025-23484.html'] | eebc590b8882284f61a0037ba20d06c87681c20b4db84f02609565fd6ef3492b | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523479 | ELSA-2025-23479: openssh security update (MODERATE) | [9.9p1-12.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]
[9.9p1-12]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128397
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128387 | MODERATE | 2025-12-17 00:00:00+03:00 | ['CVE-2025-61984', 'CVE-2025-61985'] | ['Oracle Linux 10'] | ['CVE-2025-61984', 'CVE-2025-61985', 'ELSA-2025-23479', 'https://linux.oracle.com/cve/CVE-2025-61984.html', 'https://linux.oracle.com/cve/CVE-2025-61985.html', 'https://linux.oracle.com/errata/ELSA-2025-23479.html'] | 038d386c43cda1a78498e942cfeefab186b86a4240fb0e31cfa86305b0e8092e | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523279 | ELSA-2025-23279: kernel security update (IMPORTANT) | [6.12.0-124.21.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-124.21.1]
- CVE-2025-38499 kernel: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Abhi Das) [RHEL-129282] {CVE-2025-38499}
- net: tun: Update napi->skb after XDP process (CKI Backport Bot) [RHEL-122247] {CVE-2025-39984} | IMPORTANT | 2025-12-17 00:00:00+03:00 | ['CVE-2025-38499', 'CVE-2025-39984'] | ['Oracle Linux 10'] | ['CVE-2025-38499', 'CVE-2025-39984', 'ELSA-2025-23279', 'https://linux.oracle.com/cve/CVE-2025-38499.html', 'https://linux.oracle.com/cve/CVE-2025-39984.html', 'https://linux.oracle.com/errata/ELSA-2025-23279.html'] | 7c36086187eb4625efa2faacf550cdaadf041816d006a2248a3a62c6b4c41cc3 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523201 | ELSA-2025-23201: keylime security update (IMPORTANT) | [7.12.1-15]
- Registrar allows identity takeover via duplicate UUID registration
[7.12.1-14]
- Properly fix malformed TPM certificates workaround
[7.12.1-13]
- Avoid opening /dev/stdout when printing
[7.12.1-12]
- Fix malformed TPM certificates workaround | IMPORTANT | 2025-12-16 00:00:00+03:00 | ['CVE-2025-13609'] | ['Oracle Linux 10'] | ['CVE-2025-13609', 'ELSA-2025-23201', 'https://linux.oracle.com/cve/CVE-2025-13609.html', 'https://linux.oracle.com/errata/ELSA-2025-23201.html'] | 417dafad1c005a1461b3a684eb4a11235bb2fa40565d496fb7a5f398d761fe02 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523210 | ELSA-2025-23210: keylime security update (IMPORTANT) | [7.12.1-11.3]
- Registrar allows identity takeover via duplicate UUID registration
Resolves: RHEL-130760
[7.12.1-11.2]
- Properly fix the malformed certificate workaround
Resolves: RHEL-111244 | IMPORTANT | 2025-12-16 00:00:00+03:00 | ['CVE-2025-13609'] | ['Oracle Linux 9'] | ['CVE-2025-13609', 'ELSA-2025-23210', 'https://linux.oracle.com/cve/CVE-2025-13609.html', 'https://linux.oracle.com/errata/ELSA-2025-23210.html'] | 3541f355c3c4f6a43fd5d0e88a9868cb35f2b16d77243d59a93482819f76c539 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521063 | ELSA-2025-21063: kernel security update (MODERATE) | [3.10.0-1160.119.1.0.14]
- HID: core: fix shift-out-of-bounds in hid_report_raw_event {CVE-2022-48978} [Orabug: 38644370]
- crypto: seqiv - Handle EBUSY correctly {CVE-2023-53373} [Orabug: 38644370]
- nfsd: don't ignore the return code of svc_proc_register() {CVE-2025-22026} [Orabug: 38644370]
- net_sched: hfsc: Fix a UAF vulnerability in class handling {CVE-2025-37797} [Orabug: 38644370]
- HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} [Orabug: 38644370]
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control {CVE-2025-39751} [Orabug: 38644370]
[3.10.0-1160.119.1.0.13]
- ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() {CVE-2022-48701} [Orabug: 38493400]
- md-raid10: fix KASAN warning {CVE-2022-50211} [Orabug: 38493400]
- ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50229} [Orabug: 38493400]
- net: usb: smsc75xx: Limit packet length to skb->len {CVE-2023-53125} [Orabug: 38493400]
- i40e: fix MMIO write access to an invalid page in i40e_clear_hw {CVE-2025-38200} [Orabug: 38493400]
- net/sched: sch_qfq: Fix race condition on qfq_aggregate {CVE-2025-38477} [Orabug: 38493400]
[3.10.0-1160.119.1.0.12]
- scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) [Orabug: 38414589]
- posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CVE-2025-38352) [Orabug: 38414589]
[3.10.0-1160.119.1.0.11]
- kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
- kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CVE-2025-21928)
- kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
- kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)
- kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000)
- kernel: ext4: avoid resizing to a partial cluster size (CVE-2022-50020)
- kernel: drivers:md:fix a potential use-after-free bug (CVE-2022-50022)
- kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-38177)
- kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350)
- crypto: algif_hash - fix double free in hash_accept (CVE-2025-38079)
[3.10.0-1160.119.1.0.10]
- net: atlantic: fix aq_vec index out of range error (Chia-Lin Kao) {CVE-2022-50066} [Orabug: 38201271]
- net: atm: fix use after free in lec_send() (Dan Carpenter) {CVE-2025-22004} [Orabug: 38201271]
[3.10.0-1160.119.1.0.9]
- netfilter: ipset: add missing range check in bitmap_ip_uadt (Jeongjun Park) {CVE-2024-53141} [Orabug: 37964173]
- Update OL SB certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985797]
[3.10.0-1160.119.1.0.8]
- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (Takashi Iwai) {CVE-2024-53150} [Orabug: 37830084]
[3.10.0-1160.119.1.0.7]
- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Benoit Sevens) {CVE-2024-53197} [Orabug: 37686305]
- can: bcm: Fix UAF in bcm_proc_show() (YueHaibing) {CVE-2023-52922} [Orabug: 37686305]
- HID: core: zero-initialize the report buffer (Benoit Sevens) {CVE-2024-50302} [Orabug: 37686305]
[3.10.0-1160.119.1.0.6]
- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (Benoit Sevens) {CVE-2024-53104} [Orabug: 37584712] | MODERATE | 2025-12-16 00:00:00+03:00 | ['CVE-2022-48978', 'CVE-2023-53373', 'CVE-2025-22026', 'CVE-2025-37797', 'CVE-2025-38556', 'CVE-2025-39751'] | ['Oracle Linux 7'] | ['CVE-2022-48978', 'CVE-2023-53373', 'CVE-2025-22026', 'CVE-2025-37797', 'CVE-2025-38556', 'CVE-2025-39751', 'ELSA-2025-21063', 'https://linux.oracle.com/cve/CVE-2022-48978.html', 'https://linux.oracle.com/cve/CVE-2023-53373.html', 'https://linux.oracle.com/cve/CVE-2025-22026.html', 'https://linux.oracle.com/cve/CVE-2025-37797.html', 'https://linux.oracle.com/cve/CVE-2025-38556.html', 'https://linux.oracle.com/cve/CVE-2025-39751.html', 'https://linux.oracle.com/errata/ELSA-2025-21063.html'] | b9607121545b115fea7fa91c225d4d820231635ab0995e792151fc5f8841de02 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522371 | ELSA-2025-22371: firefox security update (IMPORTANT) | [140.5.0-1.0.1]
- Update to 140.5.0 ESR [Orabug: 38708474][CVE-2025-13012][CVE-2025-13013]
[CVE-2025-13014][CVE-2025-13015][CVE-2025-13016][CVE-2025-13017]
[CVE-2025-13018][CVE-2025-13019][CVE-2025-13020] | IMPORTANT | 2025-12-15 00:00:00+03:00 | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020'] | ['Oracle Linux 7'] | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020', 'ELSA-2025-22371', 'https://linux.oracle.com/cve/CVE-2025-13012.html', 'https://linux.oracle.com/cve/CVE-2025-13013.html', 'https://linux.oracle.com/cve/CVE-2025-13014.html', 'https://linux.oracle.com/cve/CVE-2025-13015.html', 'https://linux.oracle.com/cve/CVE-2025-13016.html', 'https://linux.oracle.com/cve/CVE-2025-13017.html', 'https://linux.oracle.com/cve/CVE-2025-13018.html', 'https://linux.oracle.com/cve/CVE-2025-13019.html', 'https://linux.oracle.com/cve/CVE-2025-13020.html', 'https://linux.oracle.com/errata/ELSA-2025-22371.html'] | 7fc794574270b9fb4ea2560484e228f2db5667c39fbe59a545d226e70c402559 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202626410 | ELSA-2026-26410: rsync security update (IMPORTANT) | [3.2.5-7.2]
- Fix integer overflow in compressed-token decoding (CVE-2026-43618)
- Resolves: RHEL-174932
[3.2.5-7.1]
- Fix TOCTOU symlink race in daemon no-chroot mode (CVE-2026-29518)
- Resolves: RHEL-174952
[3.2.5-4]
- Resolves: RHEL-104404 - Do not clear DISPLAY unconditionally | IMPORTANT | 2026-06-23 00:00:00+03:00 | ['CVE-2026-29518', 'CVE-2026-43618'] | ['Oracle Linux 9'] | ['CVE-2026-29518', 'CVE-2026-43618', 'ELSA-2026-26410', 'https://linux.oracle.com/cve/CVE-2026-29518.html', 'https://linux.oracle.com/cve/CVE-2026-43618.html', 'https://linux.oracle.com/errata/ELSA-2026-26410.html'] | e7858bd1eef40b8b0acdbd55cc6b130a392977beffe04f67a4508755db4d9822 | 2026-06-26 01:31:49.792705+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202626534 | ELSA-2026-26534: dracut security update (IMPORTANT) | [049-244.git20260529.0.1]
- Refactor get_ucode_file [Orabug: 36989953]
- Revert the fixes for bugs 33676753 and 33888951 due to regressions [Orabug: 35656614]
- Fix typo in orabug33888951-dracut-Enable-the-code-to-create-ifcfg-file.patch [Orabug: 35268918]
- Enable the code to create ifcfg file [Orabug: 33888951]
- Skip parse iscsiroot.sh on PV VMs [Orabug: 33676753]
- Add blk_mq_alloc_disk and blk_cleanup_disk to blockfuncs [Orabug: 33603682]
- Change installation dir in network legacy module-setup so that file is never missing [Orabug: 33516170]
- Fix paths in squash module, so that correct modprobe is installed [Orabug: 33514517]
- Restore 51-dracut-rescue-postinst.sh for anaconda compatibility
- Install missing 68-del-part-node.rules [Orabug: 32827579]
- Add manpage for single-dhcp [Orabug 32201686]
- Fix permission denied error while upgrading from OL8u2 to OL8u3 [Orabug 32160196]
- Use pgrep in dhcp-multi.sh to make efficient and error free [Orabug 32254008]
- Send DHCP request in parallel on all interfaces for 80% boot time improvement [Orabug: 32034110]
- Revert fix for [Orabug: 31404167]
- drop 51-dracut-rescue.install patch
- Send DHCP query only on min BDF device to improve boot times by 50-60 secs [Orabug: 31404167]
- add ofb and cts to 01fips kernel module list [Orabug: 30622737]
- dracut-shutdown.service should run before shutdown.target is invoked [Orabug: 29629738]
- Fix kernel-core POSTTRANS script issues with kernel command line [Orabug: 29542203]
- Update list of necessary files after squashfs execution [Orabug: 29864620]
- Supress iscsidm error output during non-debug PV boot [Orabug: 29846195]
- Stop block device service in case system is dropped to emergency shell [Orabug: 29851988]
- Enable booting from block device if netroot=iscsi has failed [Orabug: 29478156]
- Fix BOOTPROTO calculation for iscsi [Orabug: 29518713]
- Calculate relative path for kernel and initrd in 51-dracut-rescue.instal [Orabug: 29503293]
- 40network scripts ifup and netlib updates for iSCSI [Orabug: 28502725]
- Increase timeout when waiting for carrier detection on a network interface [Orabug: 24657828] (kevin.x.lyons@oracle.com)
- add hyperv-keyboard for Hyper-V Gen2 VM [Orabug: 19191303] (Vaughan Cao)
[049-244.git20260529]
- fix(network-manager): escape DHCP lease values in dhcpopts
- fix(network-legacy): replace echo writes with printf to
- fix(iscsi): replace echo writes with printf to prevent
- fix(network): warn on suspicious shell metacharacters in
- fix(base): escape arguments in initqueue hook script | IMPORTANT | 2026-06-17 00:00:00+03:00 | ['CVE-2026-6893'] | ['Oracle Linux 8'] | ['CVE-2026-6893', 'ELSA-2026-26534', 'https://linux.oracle.com/cve/CVE-2026-6893.html', 'https://linux.oracle.com/errata/ELSA-2026-26534.html'] | ddc72af031fec8eb749de880cb06ac432959669932c42ef56dc9a38c1adbad52 | 2026-06-20 14:30:27.254805+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202517453 | ELSA-2025-17453: firefox security update (IMPORTANT) | [140.3.0-1.0.1]
- Update to 140.3.0 [Orabug: 38509157][CVE-2025-10527][CVE-2025-10528]
[CVE-2025-10529][CVE-2025-10532][CVE-2025-10533][CVE-2025-10536]
[CVE-2025-10537]
- Disable SVE parts of libyuv if not supported [Orabug: 38509157] | IMPORTANT | 2025-12-15 00:00:00+03:00 | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537'] | ['Oracle Linux 7'] | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537', 'ELSA-2025-17453', 'https://linux.oracle.com/cve/CVE-2025-10527.html', 'https://linux.oracle.com/cve/CVE-2025-10528.html', 'https://linux.oracle.com/cve/CVE-2025-10529.html', 'https://linux.oracle.com/cve/CVE-2025-10532.html', 'https://linux.oracle.com/cve/CVE-2025-10533.html', 'https://linux.oracle.com/cve/CVE-2025-10536.html', 'https://linux.oracle.com/cve/CVE-2025-10537.html', 'https://linux.oracle.com/errata/ELSA-2025-17453.html'] | 9e679db0c3d18758faaeb133e221296a339438b972cb5e1f9c383d7d98fae10a | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202516260 | ELSA-2025-16260: firefox security update (IMPORTANT) | [140.3.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789]
[140.3.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.3.0-1]
- Update to 140.3.0 | IMPORTANT | 2025-09-23 00:00:00+03:00 | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537'] | ['Oracle Linux 8'] | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537', 'ELSA-2025-16260', 'https://linux.oracle.com/cve/CVE-2025-10527.html', 'https://linux.oracle.com/cve/CVE-2025-10528.html', 'https://linux.oracle.com/cve/CVE-2025-10529.html', 'https://linux.oracle.com/cve/CVE-2025-10532.html', 'https://linux.oracle.com/cve/CVE-2025-10533.html', 'https://linux.oracle.com/cve/CVE-2025-10536.html', 'https://linux.oracle.com/cve/CVE-2025-10537.html', 'https://linux.oracle.com/errata/ELSA-2025-16260.html'] | 4c6f8e595b391cdec1d8ca03d663beeacc6545c1b12161ceb033cd2013f08c4c | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202516157 | ELSA-2025-16157: thunderbird security update (IMPORTANT) | [140.3.0-1.0.1]
- Add Oracle prefs
[140.3.0]
- Add OpenELA debranding
[140.3.0-1]
- Update to 140.3.0 ESR | IMPORTANT | 2025-09-18 00:00:00+03:00 | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537'] | ['Oracle Linux 10'] | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537', 'ELSA-2025-16157', 'https://linux.oracle.com/cve/CVE-2025-10527.html', 'https://linux.oracle.com/cve/CVE-2025-10528.html', 'https://linux.oracle.com/cve/CVE-2025-10529.html', 'https://linux.oracle.com/cve/CVE-2025-10532.html', 'https://linux.oracle.com/cve/CVE-2025-10533.html', 'https://linux.oracle.com/cve/CVE-2025-10536.html', 'https://linux.oracle.com/cve/CVE-2025-10537.html', 'https://linux.oracle.com/errata/ELSA-2025-16157.html'] | eeb337cbd1701cf6aa69cb9410620b4d66458617a9aee6004c5b2d57365cf54f | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202516109 | ELSA-2025-16109: firefox security update (IMPORTANT) | [140.3.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.3.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.3.0-1]
- Update to 140.3.0 | IMPORTANT | 2025-09-18 00:00:00+03:00 | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537'] | ['Oracle Linux 10'] | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537', 'ELSA-2025-16109', 'https://linux.oracle.com/cve/CVE-2025-10527.html', 'https://linux.oracle.com/cve/CVE-2025-10528.html', 'https://linux.oracle.com/cve/CVE-2025-10529.html', 'https://linux.oracle.com/cve/CVE-2025-10532.html', 'https://linux.oracle.com/cve/CVE-2025-10533.html', 'https://linux.oracle.com/cve/CVE-2025-10536.html', 'https://linux.oracle.com/cve/CVE-2025-10537.html', 'https://linux.oracle.com/errata/ELSA-2025-16109.html'] | a4d1b2f757e73821313bb8f02600b5a4bee13405ba4f69f0f6b5e31923c8fb1f | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20205003 | ELSA-2020-5003: fence-agents security and bug fix update (LOW) | [4.2.1-41.2]
- Upgrade bundled python-httplib2 to fix CVE-2020-11078
Resolves: rhbz#1850114
[4.2.1-41.1]
- fence_lpar: fix issue with long username, hostname, etc not
working when the command run by the agent exceeds 80 characters
- fence_evacuate: enable evacuation of instances using private flavors
Resolves: rhbz#1860545
Resolves: rhbz#1862024 | LOW | 2020-11-13 00:00:00+03:00 | ['CVE-2020-11078'] | ['Oracle Linux 7'] | ['CVE-2020-11078', 'ELSA-2020-5003', 'https://linux.oracle.com/cve/CVE-2020-11078.html', 'https://linux.oracle.com/errata/ELSA-2020-5003.html'] | 1ae4fc5ca2d4c13ffb88e85c9f3f59561e228618724cbe339a0bfc5e9128b9bd | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202628998 | ELSA-2026-28998: evince security update (IMPORTANT) | [3.28.4-17]
- Fix CVE-2026-46529: quote string arguments passed to ev_spawn
- Resolves: RHEL-184039 | IMPORTANT | 2026-06-24 00:00:00+03:00 | ['CVE-2026-46529'] | ['Oracle Linux 8'] | ['CVE-2026-46529', 'ELSA-2026-28998', 'https://linux.oracle.com/cve/CVE-2026-46529.html', 'https://linux.oracle.com/errata/ELSA-2026-28998.html'] | 8df6664c4363fc2c11b126067e80f1d6687eba81c225f50a86330cd2f66c0ddb | 2026-06-26 01:31:49.792705+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202516108 | ELSA-2025-16108: firefox security update (IMPORTANT) | [140.3.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.3.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.3.0-1]
- Update to 140.3.0 | IMPORTANT | 2025-09-18 00:00:00+03:00 | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537'] | ['Oracle Linux 9'] | ['CVE-2025-10527', 'CVE-2025-10528', 'CVE-2025-10529', 'CVE-2025-10532', 'CVE-2025-10533', 'CVE-2025-10536', 'CVE-2025-10537', 'ELSA-2025-16108', 'https://linux.oracle.com/cve/CVE-2025-10527.html', 'https://linux.oracle.com/cve/CVE-2025-10528.html', 'https://linux.oracle.com/cve/CVE-2025-10529.html', 'https://linux.oracle.com/cve/CVE-2025-10532.html', 'https://linux.oracle.com/cve/CVE-2025-10533.html', 'https://linux.oracle.com/cve/CVE-2025-10536.html', 'https://linux.oracle.com/cve/CVE-2025-10537.html', 'https://linux.oracle.com/errata/ELSA-2025-16108.html'] | 4866b936e449de8bdb82c684421e0a7453ba7fabdefd0d346661ec12af197cb1 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528049 | ELSA-2025-28049: Unbreakable Enterprise kernel security update (IMPORTANT) | [5.4.17-2136.350.3.1]
- Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha) [Orabug: 38744458]
- fbcon: fix integer overflow in font allocation (Samasth Norway Ananda) [Orabug: 38744453]
[5.4.17-2136.350.3]
- net/rds: Fix rs_recv_pending counting issue (Gerd Rausch) [Orabug: 38506370]
[5.4.17-2136.350.2]
- LTS tag: v5.4.301 (Alok Tiwari)
- net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg (Zhengchao Shao)
- media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann)
- NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov)
- NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov)
- padata: Reset next CPU when reorder sequence wraps around (Xiao Liang)
- KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers)
- NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601819] {CVE-2025-40087}
- vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601924] {CVE-2025-40105}
- jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi)
- ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey) [Orabug: 38649223] {CVE-2025-40167}
- drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han)
- ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() (Theodore Ts'O) [Orabug: 38649412] {CVE-2025-40198}
- spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav)
- spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav)
- memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni)
- memory: samsung: exynos-srom: Correct alignment (Krzysztof Kozlowski)
- arm64: errata: Apply workarounds for Neoverse-V3AE (Mark Rutland)
- arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland)
- comedi: fix divide-by-zero in comedi_buf_munge() (Deepanshu Kartikey)
- binder: remove 'invalid inc weak' check (Alice Ryhl)
- xhci: dbc: enable back DbC in resume if it was enabled before suspend (Mathias Nyman)
- usb/core/quirks: Add Huawei ME906S to wakeup quirk (Tim Guttzeit)
- USB: serial: option: add Telit FN920C04 ECM compositions (Li Qingwu)
- USB: serial: option: add Quectel RG255C (Reinhard Speyerer)
- USB: serial: option: add UNISOC UIS7720 (Renjun Wang)
- net: ravb: Ensure memory write completes before ringing TX doorbell (Lad Prabhakar)
- net: usb: rtl8150: Fix frame padding (Michal Pecio)
- ocfs2: clear extent cache after moving/defragmenting extents (Deepanshu Kartikey) [Orabug: 38730547] {CVE-2025-40233}
- MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering (Maciej W. Rozycki)
- Revert 'cpuidle: menu: Avoid discarding useful information' (Rafael J. Wysocki)
- net: bonding: fix possible peer notify event loss or dup issue (Tonghao Zhang)
- sctp: avoid NULL dereference when chunk data buffer is missing (Alexey Simakov) [Orabug: 38730567] {CVE-2025-40240}
- arm64, mm: avoid always making PTE dirty in pte_mkwrite() (Huang, Ying)
- net: enetc: correct the value of ENETC_RXB_TRUESIZE (Wei Fang)
- rtnetlink: Allow deleting FDB entries in user namespace (Johannes Wiesboeck)
- net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del (Nikolay Aleksandrov)
- net: add ndo_fdb_del_bulk (Nikolay Aleksandrov)
- net: rtnetlink: add bulk delete support flag (Nikolay Aleksandrov)
- net: netlink: add NLM_F_BULK delete request modifier (Nikolay Aleksandrov)
- net: rtnetlink: use BIT for flag values (Nikolay Aleksandrov)
- net: rtnetlink: add helper to extract msg type's kind (Nikolay Aleksandrov)
- net: rtnetlink: add msg kind names (Nikolay Aleksandrov)
- net: rtnetlink: remove redundant assignment to variable err (Colin Ian King)
- m68k: bitops: Fix find_*_bit() signatures (Geert Uytterhoeven)
- hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() (Yangtao Li)
- hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() (Viacheslav Dubeyko)
- dlm: check for defined force value in dlm_lockspace_release (Alexander Aring)
- hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (Viacheslav Dubeyko)
- hfs: validate record offset in hfsplus_bmap_alloc (Yang Chenzhi)
- hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() (Viacheslav Dubeyko)
- hfs: make proper initalization of struct hfs_find_data (Viacheslav Dubeyko)
- hfs: clear offset and space out of valid records in b-tree node (Viacheslav Dubeyko)
- exec: Fix incorrect type for ret (Xichao Zhao)
- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko)
- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap)
- sched/fair: Fix pelt lost idle time detection (Vincent Guittot)
- sched/balancing: Rename newidle_balance() => sched_balance_newidle() (Ingo Molnar)
- sched/fair: Trivial correction of the newidle_balance() comment (Barry Song)
- sched: Make newidle_balance() static again (Chen Yu)
- tls: don't rely on tx_work during send() (Sabrina Dubroca)
- tls: always set record_type in tls_process_cmsg (Sabrina Dubroca)
- tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov)
- tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet)
- amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju)
- net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov) [Orabug: 38649261] {CVE-2025-40173}
- net: dlink: handle dma_map_single() failure properly (Moon Yeounsu)
- net: dl2k: switch from 'pci_' to 'dma_' API (Christophe Jaillet)
- media: pci: ivtv: Add missing check after DMA map (Thomas Fourier)
- media: pci/ivtv: switch from 'pci_' to 'dma_' API (Christophe Jaillet)
- xen/events: Update virq_to_irq on migration (Jason Andryuk)
- media: lirc: Fix error handling in lirc_register() (Ma Ke)
- media: rc: Directly use ida_free() (Keliu)
- drm/exynos: exynos7_drm_decon: remove ctx->suspended (Kaustabh Chakraborty)
- btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento) [Orabug: 38649463] {CVE-2025-40205}
- pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang)
- media: cx18: Add missing check after DMA map (Thomas Fourier)
- xen/events: Cleanup find_virq() return codes (Jason Andryuk)
- cramfs: Verify inode mode when loading from disk (Tetsuo Handa)
- fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu)
- pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17) [Orabug: 38649276] {CVE-2025-40178}
- minixfs: Verify inode mode when loading from disk (Tetsuo Handa)
- tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592033] {CVE-2025-40042}
- dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing) [Orabug: 38649057] {CVE-2025-40134}
- mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede)
- mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko)
- mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede)
- Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher) [Orabug: 38649425] {CVE-2025-40200}
- Squashfs: add additional inode sanity checking (Phillip Lougher)
- media: mc: Clear minor number before put device (Edward Adam Davis) [Orabug: 38649399] {CVE-2025-40197}
- mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski)
- fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592048] {CVE-2025-40044}
- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591959] {CVE-2025-40026}
- net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591965] {CVE-2025-40027}
- ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag) [Orabug: 38649330] {CVE-2025-40190}
- ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo)
- ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun)
- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia)
- x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson)
- x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson)
- PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli)
- PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle)
- PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle) [Orabug: 38730513] {CVE-2025-40219}
- rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson)
- rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal)
- rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal)
- mmc: core: SPI mode remove cmd7 (Rex Chen)
- mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij)
- sparc: fix error handling in scan_one_device() (Ma Ke)
- sparc64: fix hugetlb for sun4u (Anthony Yznaga)
- sctp: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 38649451] {CVE-2025-40204}
- scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum)
- parisc: don't reference obsolete termio struct for TC* constants (Sam James)
- lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold)
- iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich)
- iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng)
- iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng)
- crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier)
- cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki) [Orabug: 38649367] {CVE-2025-40194}
- drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu)
- media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng)
- firmware: meson_sm: fix device leak at probe (Johan Hovold)
- xen/manage: Fix suspend error path (Lukas Wunner)
- arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold)
- ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad)
- ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang)
- tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets)
- tpm, tpm_tis: Claim locality before writing interrupt registers (Lino Sanfilippo)
- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581456,38705546] {CVE-2025-40019}
- mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T)
- mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T)
- tools build: Align warning options with perf (Leo Yan)
- net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja)
- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima) [Orabug: 38649579] {CVE-2025-40186}
- net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov) [Orabug: 38649313] {CVE-2025-40187}
- drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes) [Orabug: 38643546] {CVE-2025-40111}
- net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter)
- scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557654] {CVE-2025-40001}
- scsi: mvsas: Use sas_task_find_rq() for tagging (John Garry)
- scsi: mvsas: Delete mvs_tag_init() (John Garry)
- scsi: libsas: Add sas_task_find_rq() (John Garry)
- clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari)
- clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney)
- perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan)
- rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring)
- perf util: Fix compression checks returning -1 as bool (Yunseong Kim)
- iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich)
- clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni)
- pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591981] {CVE-2025-40030}
- Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38592002] {CVE-2025-40035}
- mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi) [Orabug: 38649150] {CVE-2025-40153}
- uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592067] {CVE-2025-40048}
- Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592077] {CVE-2025-40049}
- net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju)
- nfp: fix RSS hash key size when RSS is not supported (Kohei Enju)
- drivers/base/node: fix double free in register_one_node() (Donet Tom)
- ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592110] {CVE-2025-40055}
- net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath) [Orabug: 38649096] {CVE-2025-40140}
- RDMA/siw: Always report immediate post SQ errors (Bernard Metzler)
- usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea)
- scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar) [Orabug: 38648982] {CVE-2025-40115}
- ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581446] {CVE-2025-40018}
- NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos)
- remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold)
- sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher)
- IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu)
- RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit)
- wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal)
- drivers/base/node: handle error properly in register_one_node() (Donet Tom)
- watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy)
- netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni)
- iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede)
- ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai)
- ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai)
- ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai)
- pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592170] {CVE-2025-40070}
- misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King)
- usb: gadget: configfs: Correctly set use_os_string at bind (William Wu)
- usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao)
- tcp: fix __tcp_close() to only send RST when required (Eric Dumazet)
- PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation (Alok Tiwari)
- wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann)
- ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng)
- media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong)
- scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier)
- scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel) [Orabug: 38649567] {CVE-2025-40118}
- serial: max310x: Add error checking in probe() (Dan Carpenter)
- usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter)
- drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das)
- i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi)
- i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu)
- bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592205] {CVE-2025-40078}
- selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil)
- pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig)
- block: use int to store blk_stack_limits() return value (Rong Qianfeng)
- blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan) [Orabug: 38649026] {CVE-2025-40125}
- pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue)
- soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad)
- ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li)
- regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven)
- x86/vdso: Fix output operand size of RDPID (Uros Bizjak)
- perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592223] {CVE-2025-40081}
- driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki)
- staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait)
- staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait)
- perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu)
- dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka)
- wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)
- USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li)
- media: rc: fix races with imon_disconnect() (Larshin Sergey) [Orabug: 38548027] {CVE-2025-39993}
- media: imon: grab lock earlier in imon_ir_change_protocol() (Tetsuo Handa)
- media: imon: reorganize serialization (Tetsuo Handa)
- media: rc: Add support for another iMON 0xffdc device (Flavius Georgescu)
- media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou) [Orabug: 38548044] {CVE-2025-39995}
- media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou) [Orabug: 38548037] {CVE-2025-39994}
- media: tunner: xc5000: Refactor firmware load (Ricardo Ribalda)
- udp: Fix memory accounting leak. (Kuniyuki Iwashima) [Orabug: 37844325] {CVE-2025-22058}
- media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou) [Orabug: 38548051] {CVE-2025-39996}
- scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran) [Orabug: 38548059] {CVE-2025-39998}
- LTS tag: v5.4.300 (Alok Tiwari)
- KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (Maciej S. Szmigiero)
- mm/hugetlb: fix folio is still mapped when deleted (Tu Jinjiang) [Orabug: 38560482] {CVE-2025-40006}
- i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik)
- i40e: fix validation of VF state in get resources (Lukasz Czapnik) [Orabug: 38547929] {CVE-2025-39969}
- i40e: fix idx validation in config queues msg (Lukasz Czapnik) [Orabug: 38547938] {CVE-2025-39971}
- i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38547952,38604168,38604171] {CVE-2025-39973}
- i40e: increase max descriptors for XL710 (Justin Bronder)
- mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() (David Hildenbrand)
- fbcon: Fix OOB access in font allocation (Thomas Zimmermann)
- fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda) [Orabug: 38547913] {CVE-2025-39967}
- i40e: add max boundary check for VF filters (Lukasz Czapnik) [Orabug: 38547923] {CVE-2025-39968}
- i40e: fix input validation logic for action_meta (Lukasz Czapnik) [Orabug: 38547933] {CVE-2025-39970}
- i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik) [Orabug: 38547946] {CVE-2025-39972}
- drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita) [Orabug: 38560496] {CVE-2025-40011}
- can: peak_usb: fix shift-out-of-bounds issue (Stephane Grosjean) [Orabug: 38581463] {CVE-2025-40020}
- can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven)
- IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov)
- usb: core: Add 0x prefix to quirks debug output (Jiayi Li)
- ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai)
- ALSA: usb-audio: Convert comma to semicolon (Chen Ni)
- ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea)
- ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea)
- net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede)
- net: rfkill: gpio: add DT support (Philipp Zabel)
- serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve)
- USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern)
- usb: gadget: dummy_hcd: remove usage of list iterator past the loop body (Jakob Koschel)
- ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King)
- ASoC: wm8974: Correct PLL rate rounding (Charles Keepax)
- ASoC: wm8940: Correct typo in control name (Charles Keepax)
- mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier)
- nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor)
- cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503849] {CVE-2025-39945}
- net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih)
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima) [Orabug: 38526388] {CVE-2025-39955}
- i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski)
- net: natsemi: fix rx_dropped double accounting on netif_rx() failure (Moon Yeounsu)
- cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503892] {CVE-2025-39953}
- pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven)
- wifi: mac80211: fix incorrect type for ret (Liao Yuanhong)
- ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto)
- mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461848] {CVE-2025-39883}
- phy: ti-pipe3: fix device leak at unbind (Johan Hovold)
- dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494822] {CVE-2025-39923}
- dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell)
- can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa)
- can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa)
- i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494787] {CVE-2025-39911}
- i40e: Use irq_update_affinity_hint() (Nitesh Narayan Lal)
- genirq: Provide new interfaces for affinity hints (Thomas Gleixner)
- genirq: Export affinity setter for modules (Thomas Gleixner)
- genirq/affinity: Add irq_update_affinity_desc() (John Garry)
- igb: fix link test skipping when interface is admin down (Kohei Enju)
- net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren)
- USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)
- USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda)
- tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt)
- mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin)
- mtd: nand: raw: atmel: Fix comment in timings preparation (Alexander Dahl)
- mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello)
- mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang)
- fuse: prevent overflow in copy_file_range return value (Miklos Szeredi)
- fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi)
- mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello)
- ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461859] {CVE-2025-39885}
- EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki)
- tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. (Kuniyuki Iwashima) [Orabug: 38494797] {CVE-2025-39913}
- net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. (Kuniyuki Iwashima) [Orabug: 37901604] {CVE-2025-23143}
[5.4.17-2136.350.1]
- device-dax: correct pgoff align in dax_set_mapping() (Kun(Llfl)) [Orabug: 37206404] {CVE-2024-50022}
[5.4.17-2136.349.3]
- Revert 'net/mlx5e: Update and set Xon/Xoff upon MTU set' (Jakub Kicinski) [Orabug: 38545204]
- KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass producer (Sean Christopherson) [Orabug: 38494247]
- rds: Free all frags when rds_ib_recv_cache_put() fails (Hans Westgaard Ry) [Orabug: 38492234]
[5.4.17-2136.349.2]
- bpf/bpf_get,set_sockopt: add option to set TCP-BPF sock ops flags (Alan Maguire) [Orabug: 36699199]
[5.4.17-2136.349.1]
- NFSv4: Don't clear capabilities that won't be reset (Trond Myklebust)
- power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller)
- power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller)
- usb: hub: Fix flushing of delayed work used for post resume purposes (Mathias Nyman)
- soc: qcom: mdt_loader: Deal with zero e_shentsize (Bjorn Andersson)
- Revert 'net/mlx5e: Update and set Xon/Xoff upon port speed set' (Tariq Toukan)
- LTS tag: v5.4.299 (Alok Tiwari)
- scsi: lpfc: Fix buffer free/clear order in deferred receive path (John Evans) [Orabug: 38456754] {CVE-2025-39841}
- dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (Qiu-Ji Chen)
- cifs: fix integer overflow in match_server() (Roman Smirnov)
- spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (Larisa Grigore)
- spi: spi-fsl-lpspi: Set correct chip-select polarity bit (Larisa Grigore)
- spi: spi-fsl-lpspi: Fix transmissions when using CONT (Larisa Grigore)
- pcmcia: Add error handling for add_interval() in do_validate_mem() (Xu Wang)
- ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (Takashi Iwai)
- randstruct: gcc-plugin: Fix attribute addition (Kees Cook)
- randstruct: gcc-plugin: Remove bogus void member (Kees Cook)
- vmxnet3: update MTU after device quiesce (Ronak Doshi)
- net: dsa: microchip: linearize skb for tail-tagging switches (Jakob Unterwurzacher)
- net: dsa: microchip: update tag_ksz masks for KSZ9477 family (Pieter Van Trappen)
- dmaengine: mediatek: Fix a possible deadlock error in mtk_cqdma_tx_status() (Qiu-Ji Chen)
- ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup (Chris Chiu)
- gpio: pca953x: fix IRQ storm on system wake up (Emanuele Ghidoli)
- iio: light: opt3001: fix deadlock due to concurrent flag access (Luca Ceresoli) [Orabug: 37977028] {CVE-2025-37968}
- iio: chemical: pms7003: use aligned_s64 for timestamp (David Lechner)
- cpufreq/sched: Explicitly synchronize limits_changed flag handling (Rafael J. Wysocki)
- mm/slub: avoid accessing metadata when pointer is invalid in object_err() (Li Qiong) [Orabug: 38494761] {CVE-2025-39902}
- mm/khugepaged: fix ->anon_vma race (Jann Horn)
- e1000e: fix heap overflow in e1000_set_eeprom (Vitaly Lifshits)
- batman-adv: fix OOB read/write in network-coding decode (Stanislav Fort)
- drm/amdgpu: drop hw access in non-DC audio fini (Alex Deucher)
- wifi: mwifiex: Initialize the chan_stats array to zero (Rong Qianfeng) [Orabug: 38494723] {CVE-2025-39891}
- pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (Ma Ke)
- ALSA: usb-audio: Add mute TLV for playback volumes on some devices (Cryolitia Pukngae)
- ppp: fix memory leak in pad_compress_skb (Qingfang Deng) [Orabug: 38456781] {CVE-2025-39847}
- net: atm: fix memory leak in atm_register_sysfs when device_register fail (Wang Liang)
- ax25: properly unshare skbs in ax25_kiss_rcv() (Eric Dumazet)
- ipv4: Fix NULL vs error pointer check in inet_blackhole_dev_init() (Dan Carpenter)
- net: thunder_bgx: add a missing of_node_put (Rosen Penev)
- wifi: libertas: cap SSID len in lbs_associate() (Dan Carpenter)
- wifi: cw1200: cap SSID length in cw1200_do_join() (Dan Carpenter)
- net: ethernet: mtk_eth_soc: fix tx vlan tag for llc packets (Felix Fietkau)
- i40e: Fix potential invalid access when MAC list is empty (Zhen Ni) [Orabug: 38456814] {CVE-2025-39853}
- icmp: fix icmp_ndo_send address translation for reply direction (Fabian Blase)
- mISDN: Fix memory leak in dsp_hwec_enable() (Miaoqian Lin)
- xirc2ps_cs: fix register access when enabling FullDuplex (Alok Tiwari)
- Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (Kuniyuki Iwashima) [Orabug: 38456834] {CVE-2025-39860}
- netfilter: conntrack: helper: Replace -EEXIST by -EBUSY (Phil Sutter)
- wifi: cfg80211: fix use-after-free in cmp_bss() (Dmitry Antipov) [Orabug: 38456860] {CVE-2025-39864}
- powerpc: boot: Remove leading zero in label in udelay() (Nathan Chancellor)
[5.4.17-2136.348.3]
- hugetlbfs: take read_lock on i_mmap for PMD sharing (Waiman Long) [Orabug: 38459576]
- kallsyms: add module_kallsyms_on_each_symbol_locked (Julian Pidancet) [Orabug: 38418686]
- kallsyms: export module_kallsyms_on_each_symbol (Julian Pidancet) [Orabug: 38418686]
[5.4.17-2136.348.2]
- uek-rpm: Move ifb module to nano modules (Harshit Mogalapalli) [Orabug: 38443798]
- clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (Al Viro) [Orabug: 38310007,38453918] {CVE-2025-38499}
- x86/vmscape: Warn when STIBP is disabled with SMT (Pawan Gupta) [Orabug: 38424094]
- x86/bugs: Move cpu_bugs_smt_update() down (Pawan Gupta) [Orabug: 38424094]
- x86/vmscape: Enable the mitigation (Pawan Gupta) [Orabug: 38424094]
- x86/vmscape: Add conditional IBPB mitigation (Pawan Gupta) [Orabug: 38424094]
- x86/vmscape: Add old Intel CPUs to affected list (Pawan Gupta) [Orabug: 38424094]
- x86/vmscape: Enumerate VMSCAPE bug (Pawan Gupta) [Orabug: 38424094]
- Documentation/hw-vuln: Add VMSCAPE documentation (Pawan Gupta) [Orabug: 38424094]
[5.4.17-2136.348.1]
- LTS tag: v5.4.298 (Sherry Yang)
- Revert 'drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS' (Imre Deak)
- net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)
- Revert 'drm/amdgpu: fix incorrect vm flags to map bo' (Alex Deucher) [Orabug: 38343661]
- HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (Minjong Kim) [Orabug: 38440228] {CVE-2025-39808}
- HID: wacom: Add a new Art Pen 2 (Ping Cheng)
- HID: asus: fix UAF via HID_CLAIMED_INPUT validation (Qasim Ijaz) [Orabug: 38440310] {CVE-2025-39824}
- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (Li Nan) [Orabug: 38440277] {CVE-2025-39817}
- sctp: initialize more fields in sctp_v6_from_sk() (Eric Dumazet) [Orabug: 38440251] {CVE-2025-39812}
- net: stmmac: xgmac: Do not enable RX FIFO Overflow interrupts (Rohan G Thomas)
- net/mlx5e: Set local Xoff after FW update (Alexei Lazar)
- net/mlx5e: Update and set Xon/Xoff upon port speed set (Alexei Lazar)
- net/mlx5e: Update and set Xon/Xoff upon MTU set (Alexei Lazar)
- net: dlink: fix multicast stats being counted incorrectly (Moon Yeounsu)
- atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). (Kuniyuki Iwashima) [Orabug: 38440347] {CVE-2025-39828}
- net/atm: remove the atmdev_ops {get, set}sockopt methods (Christoph Hellwig)
- Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (Luiz Augusto von Dentz)
- powerpc/kvm: Fix ifdef to remove build warning (Madhavan Srinivasan)
- net: ipv4: fix regression in local-broadcast routes (Oscar Maes) [Orabug: 38343661]
- vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (Nikolay Kuratov)
- scsi: core: sysfs: Correct sysfs attributes access rights (Damien Le Moal)
- ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (Tengda Wu) [Orabug: 38440259] {CVE-2025-39813}
- pinctrl: STMFX: add missing HAS_IOMEM dependency (Randy Dunlap)
- LTS tag: v5.4.297 (Sherry Yang)
- alloc_fdtable(): change calling conventions. (Al Viro)
- s390/hypfs: Enable limited access during lockdown (Peter Oberparleiter)
- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (Peter Oberparleiter)
- ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (Takashi Iwai)
- net/sched: Remove unnecessary WARNING condition for empty child qdisc in htb_activate (William Liu)
- net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (William Liu)
- ixgbe: xsk: resolve the negative overflow of budget in ixgbe_xmit_zc (Jason Xing)
- ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add (Heminhong)
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Dan Carpenter) [Orabug: 38343661]
- scsi: qla4xxx: Prevent a potential error pointer dereference (Dan Carpenter) [Orabug: 38401514] {CVE-2025-39676}
- usb: xhci: Fix slot_id resource race conflict (Weitao Wang)
- nfs: fix UAF in direct writes (Josef Bacik) [Orabug: 36596831] {CVE-2024-26958}
- NFS: Fix up commit deadlocks (Trond Myklebust)
- cifs: Fix UAF in cifs_demultiplex_thread() (Zhang Xiaoxu)
- Bluetooth: fix use-after-free in device_for_each_child() (Dmitry Antipov) [Orabug: 37433654] {CVE-2024-53237}
- act_mirred: use the backlog for nested calls to mirred ingress (Davide Caratti) [Orabug: 34882838] {CVE: CVE-2022-4269}
- net/sched: act_mirred: better wording on protection against excessive stack growth (Davide Caratti)
- net/sched: act_mirred: refactor the handle of xmit (Wenxu)
- selftests: forwarding: tc_actions.sh: add matchall mirror test (Jiri Pirko)
- net: sched: don't expose action qstats to skb_tc_reinsert() (Vlad Buslov)
- net: sched: extract qstats update code into functions (Vlad Buslov)
- net: sched: extract bstats update code into function (Vlad Buslov)
- net: sched: extract common action counters update code into function (Vlad Buslov)
- mm: perform the mapping_map_writable() check after call_mmap() (Lorenzo Stoakes)
- mm: update memfd seal write check to include F_SEAL_WRITE (Lorenzo Stoakes)
- mm: drop the assumption that VM_SHARED always implies writable (Lorenzo Stoakes)
- codel: remove sch->q.qlen check before qdisc_tree_reduce_backlog() (Cong Wang) [Orabug: 37908492] {CVE-2025-37798}
- sch_qfq: make qfq_qlen_notify() idempotent (Cong Wang)
- sch_hfsc: make hfsc_qlen_notify() idempotent (Cong Wang) [Orabug: 38158396] {CVE-2025-38177}
- sch_drr: make drr_qlen_notify() idempotent (Cong Wang)
- btrfs: populate otime when logging an inode item (Qu Wenruo)
- media: venus: hfi: explicitly release IRQ during teardown (Jorge Ramirez-Ortiz)
- f2fs: fix to avoid out-of-boundary access in dnode page (Chao Yu)
- media: venus: protect against spurious interrupts during probe (Jorge Ramirez-Ortiz)
- media: qcom: camss: cleanup media device allocated resource on error path (Vladimir Zapolskiy)
- media: venus: vdec: Clamp param smaller than 1fps and bigger than 240. (Ricardo Ribalda)
- drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (Imre Deak)
- pwm: mediatek: Fix duty and period setting (Uwe Kleine-Konig)
- pwm: mediatek: Handle hardware enable and clock enable separately (Uwe Kleine-Konig)
- pwm: mediatek: Implement .apply() callback (Uwe Kleine-Konig)
- media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (Gui-Dong Han) [Orabug: 38401677] {CVE-2025-39713}
- media: v4l2-ctrls: Don't reset handler's error in v4l2_ctrl_handler_free() (Sakari Ailus)
- media: v4l2-ctrls: always copy the controls on completion (Hans Verkuil)
- ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig (Damien Le Moal)
- soc: qcom: mdt_loader: Ensure we don't read past the ELF header (Bjorn Andersson) [Orabug: 38423524] {CVE-2025-39787}
- rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (Meagan Lloyd)
- usb: musb: omap2430: fix device leak at unbind (Johan Hovold)
- NFS: Fix the setting of capabilities when automounting a new filesystem (Trond Myklebust) [Orabug: 38429211] {CVE-2025-39798}
- NFS: Fix up handling of outstanding layoutcommit in nfs_update_inode() (Trond Myklebust)
- NFSv4: Fix nfs4_bitmap_copy_adjust() (Trond Myklebust)
- usb: typec: fusb302: cache PD RX state (Sebastian Reichel)
- cdc-acm: fix race between initial clearing halt and open (Oliver Neukum)
- USB: cdc-acm: do not log successful probe on later errors (Johan Hovold)
- mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock (Breno Leitao)
- mm/kmemleak: turn kmemleak_lock and object->lock to raw_spinlock_t (He Zhe)
- ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (Geoffrey D. Bennett)
- x86/fpu: Delay instruction pointer fixup until after warning (Dave Hansen)
- mm/hmm: move pmd_to_hmm_pfn_flags() to the respective #ifdeffery (Andy Shevchenko)
- nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (Jeff Layton) [Orabug: 38395081,38501612] {CVE-2025-38724}
- pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov (Maulik Shah)
- tracing: Add down_write(trace_event_sem) when adding trace event (Steven Rostedt) [Orabug: 38324271] {CVE-2025-38539}
- usb: hub: Don't try to recover devices lost during warm reset. (Mathias Nyman)
- usb: hub: avoid warm port reset during USB3 disconnect (Mathias Nyman)
- x86/mce/amd: Add default names for MCA banks and blocks (Yazen Ghannam)
- iio: hid-sensor-prox: Fix incorrect OFFSET calculation (Zhang Lixu)
- f2fs: fix to do sanity check on ino and xnid (Chao Yu)
- mm/zsmalloc: do not pass __GFP_MOVABLE if CONFIG_COMPACTION=n (Harry Yoo)
- mm/zsmalloc.c: convert to use kmem_cache_zalloc in cache_alloc_zspage() (Miaohe Lin)
- drm/sched: Remove optimization that causes hang when killing dependent jobs (Lin Cao)
- ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (Haoxiang Li) [Orabug: 38351930] {CVE-2025-38664}
- net: usbnet: Fix the wrong netif_carrier_on() call (Ammar Faizi)
- net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (John Ernberg)
- PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (Lukas Wunner)
- ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value (Li Zhong)
- comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (Ian Abbott)
- comedi: Fix initialization of data for instructions that write to subdevice (Ian Abbott)
- kbuild: Add KBUILD_CPPFLAGS to as-option invocation (Nathan Chancellor)
- kbuild: add to KBUILD_CPPFLAGS (Masahiro Yamada)
- kbuild: Add CLANG_FLAGS to as-instr (Nathan Chancellor)
- mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation (Nathan Chancellor)
- kbuild: Update assembler calls to use proper flags and language target (Nick Desaulniers)
- ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS (Nathan Chancellor)
- usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (Kuen-Han Tsai)
- USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (Zenm Chen)
- usb: storage: realtek_cr: Use correct byte order for bcs->Residue (Thorsten Blum)
- USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (Mael Guerin)
- usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (Miao Li)
- iio: proximity: isl29501: fix buffered read on big-endian systems (David Lechner)
- ftrace: Also allocate and copy hash for reading of filter files (Steven Rostedt) [Orabug: 38401581] {CVE-2025-39689}
- fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() (Xu Yilun)
- use uniform permission checks for all mount propagation changes (Al Viro)
- move_mount: allow to add a mount into an existing group (Pavel Tikhomirov)
- fs/buffer: fix use-after-free when call bh_read() helper (Ye Bin) [Orabug: 38401587] {CVE-2025-39691}
- drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (Timur Kristof)
- drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (Timur Kristof)
- memstick: Fix deadlock by moving removing flag earlier (Jiayi Li)
- media: venus: Add a check for packet size after reading from shared memory (Vedang Nagar)
- media: ov2659: Fix memory leaks in ov2659_probe() (Zhang Shurong)
- media: usbtv: Lock resolution while streaming (Ludwig Disterhof) [Orabug: 38401684] {CVE-2025-39714}
- media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (Haoxiang Li)
- media: gspca: Add bounds checking to firmware parser (Dan Carpenter)
- soc/tegra: pmc: Ensure power-domains are in a known state (Jonathan Hunter)
- jbd2: prevent softlockup in jbd2_log_do_checkpoint() (Baokun Li) [Orabug: 38423509] {CVE-2025-39782}
- PCI: endpoint: Fix configfs group removal on driver teardown (Damien Le Moal)
- PCI: endpoint: Fix configfs group list head handling (Damien Le Moal)
- mtd: rawnand: fsmc: Add missing check after DMA map (Thomas Fourier)
- pwm: imx-tpm: Reset counter if CMOD is 0 (Laurentiu Mihalcea)
- wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (Nathan Chancellor)
- zynq_fpga: use sgtable-based scatterlist wrappers (Marek Szyprowski)
- ata: libata-scsi: Fix ata_to_sense_error() status handling (Damien Le Moal)
- ext4: fix reserved gdt blocks handling in fsmap (Ojaswin Mujoo)
- ext4: fix fsmap end of range reporting with bigalloc (Ojaswin Mujoo)
- ext4: check fast symlink for ea_inode correctly (Andreas Dilger)
- vt: defkeymap: Map keycodes above 127 to K_HOLE (Myrrh Periwinkle)
- vt: keyboard: Don't process Unicode characters in K_OFF mode (Myrrh Periwinkle)
- usb: dwc3: meson-g12a: fix device leaks at unbind (Johan Hovold)
- usb: gadget: udc: renesas_usb3: fix device leak at unbind (Johan Hovold)
- usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (Nathan Chancellor)
- m68k: Fix lost column on framebuffer debug console (Finn Thain)
- cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() (Dan Carpenter)
- serial: 8250: fix panic due to PSLVERR (Yunhui Cui) [Orabug: 38401729] {CVE-2025-39724}
- media: uvcvideo: Do not mark valid metadata as invalid (Ricardo Ribalda)
- media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (Youngjun Lee) [Orabug: 38394816] {CVE-2025-38680}
- mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() (Waiman Long)
- parisc: Makefile: fix a typo in palo.conf (Randy Dunlap)
- btrfs: fix log tree replay failure due to file with 0 links and extents (Filipe Manana)
- thunderbolt: Fix copy+paste error in match_service_id() (Eric Biggers)
- comedi: fix race between polling and detaching (Ian Abbott)
- misc: rtsx: usb: Ensure mmc child device is active when card is present (Ricky Wu)
- drm/amdgpu: fix incorrect vm flags to map bo (Jack Xiao)
- scsi: lpfc: Remove redundant assignment to avoid memory leak (Jiasheng Jiang)
- rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (Meagan Lloyd)
- pNFS: Fix uninited ptr deref in block/scsi layout (Sergey Bashirov) [Orabug: 38394867] {CVE-2025-38691}
- pNFS: Handle RPC size limit for layoutcommits (Sergey Bashirov)
- pNFS: Fix disk addr range check in block/scsi layout (Sergey Bashirov)
- pNFS: Fix stripe mapping in block/scsi layout (Sergey Bashirov)
- net: phy: smsc: add proper reset flags for LAN8710A (Csaba Buday)
- ipmi: Fix strcpy source and destination the same (Corey Minyard)
- kconfig: lxdialog: fix 'space' to (de)select options (Yann E. MORIN)
- kconfig: gconf: fix potential memory leak in renderer_edited() (Masahiro Yamada)
- kconfig: gconf: avoid hardcoding model2 in on_treeview2_cursor_changed() (Masahiro Yamada)
- ipmi: Use dev_warn_ratelimited() for incorrect message warnings (Breno Leitao)
- scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Garry)
- scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (Ranjan Kumar)
- kconfig: nconf: Ensure null termination where strncpy is used (Shankari Anand)
- kconfig: lxdialog: replace strcpy() with strncpy() in inputbox.c (Suchit Karunakaran)
- i3c: don't fail if GETHDRCAP is unsupported (Wolfram Sang)
- PCI: pnv_php: Work around switches with broken presence detection (Timothy Pearson)
- i3c: add missing include to internal header (Wolfram Sang)
- media: uvcvideo: Fix bandwidth issue for Alcor camera (Chenchangcheng)
- media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (Alex Guo) [Orabug: 38394880] {CVE-2025-38693}
- media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (Alex Guo) [Orabug: 38394887] {CVE-2025-38694}
- media: usb: hdpvr: disable zero-length read messages (Wolfram Sang)
- media: tc358743: Increase FIFO trigger level to 374 (Dave Stevenson)
- media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (Dave Stevenson)
- media: tc358743: Check I2C succeeded during probe (Dave Stevenson)
- pinctrl: stm32: Manage irq affinity settings (Cheick Traore)
- scsi: mpt3sas: Correctly handle ATA device errors (Damien Le Moal)
- scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (Justin Tee) [Orabug: 38394894] {CVE-2025-38695}
- RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (Yury Norov) [Orabug: 38423286] {CVE-2025-39742}
- MIPS: Don't crash in stack_top() for tasks without ABI or vDSO (Thomas Weissschuh)
- jfs: upper bound check of tree index in dbAllocAG (Arnaud Lecomte)
- jfs: Regular file corruption check (Edward Adam Davis)
- jfs: truncate good inode pages when hard link is 0 (Lizhi Xu)
- scsi: bfa: Double-free fix (Jackysliu) [Orabug: 38394925] {CVE-2025-38699}
- MIPS: vpe-mt: add missing prototypes for vpe_{alloc,start,stop,free} (Shiji Yang)
- watchdog: dw_wdt: Fix default timeout (Sebastian Reichel)
- fs/orangefs: use snprintf() instead of sprintf() (Amir Mohammad Jahangirzad)
- scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated (Showrya M N) [Orabug: 38394931] {CVE-2025-38700}
- ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (Theodore Ts'O) [Orabug: 38394937] {CVE-2025-38701}
- cifs: Fix calling CIFSFindFirst() for root path without msearch (Pali Rohar)
- vhost: fail early when __vhost_add_used() fails (Jason Wang)
- net: dsa: b53: fix IP_MULTICAST_CTRL on BCM5325 (Alvaro Fernandez Rojas)
- uapi: in6: restore visibility of most IPv6 socket options (Jakub Kicinski)
- net: ncsi: Fix buffer overflow in fetching version id (Hari Kalavakunta)
- net: dsa: b53: prevent SWITCH_CTRL access on BCM5325 (Alvaro Fernandez Rojas)
- net: dsa: b53: fix b53_imp_vlan_setup for BCM5325 (Alvaro Fernandez Rojas)
- net: vlan: Replace BUG() with WARN_ON_ONCE() in vlan_dev_* stubs (Gal Pressman)
- wifi: iwlegacy: Check rate_idx range after addition (Stanislaw Gruszka)
- netmem: fix skb_frag_address_safe with unreadable skbs (Mina Almasry)
- wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_rx_interrupt(). (Thomas Fourier)
- wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (Anjaneyulu)
- wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (Rand Deeb)
- net: fec: allow disable coalescing (Jonas Rebmann)
- (powerpc/512) Fix possible dma_unmap_single() on uninitialized pointer (Thomas Fourier)
- s390/stp: Remove udelay from stp_sync_clock() (Sven Schnelle)
- wifi: iwlwifi: mvm: fix scan request validation (Avraham Stern)
- net: thunderx: Fix format-truncation warning in bgx_acpi_match_id() (Alok Tiwari)
- net: ipv4: fix incorrect MTU in broadcast routes (Oscar Maes)
- wifi: cfg80211: Fix interface type validation (Ilan Peer)
- rcu: Protect ->defer_qs_iw_pending from data race (Paul E. McKenney) [Orabug: 38423341] {CVE-2025-39749}
- net: ag71xx: Add missing check after DMA map (Thomas Fourier)
- et131x: Add missing check after DMA map (Thomas Fourier)
- be2net: Use correct byte order and format string for TCP seq and ack_seq (Alok Tiwari)
- s390/time: Use monotonic clock in get_cycles() (Sven Schnelle)
- wifi: cfg80211: reject HTC bit for management frames (Johannes Berg)
- ktest.pl: Prevent recursion of default variable options (Steven Rostedt)
- ASoC: codecs: rt5640: Retry DEVICE_ID verification (Xinxin Wan)
- ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (Cristian Ciocaltea)
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (Lucy Thrun)
- platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (Kees Cook)
- pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (Gautham R. Shenoy)
- usb: core: usb_submit_urb: downgrade type check (Oliver Neukum)
- ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (Alok Tiwari)
- ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (Mark Brown)
- mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (Ulf Hansson)
- ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path (Breno Leitao)
- ACPI: processor: fix acpi_object initialization (Sebastian Ott)
- PM: sleep: console: Fix the black screen issue (Tuhaowen)
- thermal: sysfs: Return ENODATA instead of EAGAIN for reads (Hsin-Te Yuan)
- PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (Rafael J. Wysocki)
- selftests: tracing: Use mutex_unlock for testing glob filter (Masami Hiramatsu)
- ARM: tegra: Use I/O memcpy to write to IRAM (Aaron Kling)
- gpio: tps65912: check the return value of regmap_update_bits() (Bartosz Golaszewski)
- ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (Kuninori Morimoto)
- ARM: rockchip: fix kernel hang during smp initialization (Alexander Kochetkov)
- cpufreq: Exit governor when failed to start old governor (Lifeng Zheng)
- usb: xhci: Avoid showing errors during surprise removal (Mario Limonciello)
- usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (Jay Chen)
- usb: xhci: Avoid showing warnings for dying controller (Mario Limonciello)
- selftests/futex: Define SYS_futex on 32-bit architectures with 64-bit time_t (Cynthia Huang)
- usb: xhci: print xhci->xhc_state when queue_command failed (Su Hui)
- securityfs: don't pin dentries twice, once is enough... (Al Viro)
- hfs: fix not erasing deleted b-tree node issue (Viacheslav Dubeyko)
- drbd: add missing kref_get in handle_write_conflicts (Sarah Newman) [Orabug: 38394995] {CVE-2025-38708}
- udf: Verify partition map count (Jan Kara)
- arm64: Handle KCOV __init vs inline mismatches (Kees Cook)
- hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() (Tetsuo Handa)
- hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (Viacheslav Dubeyko)
- hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (Viacheslav Dubeyko)
- hfs: fix slab-out-of-bounds in hfs_bnode_read() (Viacheslav Dubeyko)
- sctp: linearize cloned gso packets in sctp_rcv (Xin Long) [Orabug: 38395059] {CVE-2025-38718}
- netfilter: ctnetlink: fix refcount leak on table dump (Florian Westphal) [Orabug: 38395068] {CVE-2025-38721}
- udp: also consider secpath when evaluating ipsec use for checksumming (Sabrina Dubroca)
- ACPI: processor: perflib: Move problematic pr->performance check (Rafael J. Wysocki)
- ACPI: processor: perflib: Fix initial _PPC limit application (Jiayi Li)
- Documentation: ACPI: Fix parent device references (Andy Shevchenko)
- fs: Prevent file descriptor table allocations exceeding INT_MAX (Sasha Levin) [Orabug: 38423397] {CVE-2025-39756}
- sunvdc: Balance device refcount in vdc_port_mpgroup_check (Ma Ke)
- NFSD: detect mismatch of file handle and delegation stateid in OPEN op (Dai Ngo)
- net: dpaa: fix device leak when querying time stamp info (Johan Hovold)
- net: gianfar: fix device leak when querying time stamp info (Johan Hovold)
- netlink: avoid infinite retry looping in netlink_unicast() (Fedor Pchelkin) [Orabug: 38401319] {CVE-2025-38727}
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Takashi Iwai) [Orabug: 38423407] {CVE-2025-39757}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Takashi Iwai) [Orabug: 38395101] {CVE-2025-38729}
- io_uring: don't use int for ABI (Pavel Begunkov)
- usb: gadget : fix use-after-free in composite_dev_cleanup() (Taoxue) [Orabug: 38334898] {CVE-2025-38555}
- MIPS: mm: tlb-r4k: Uniquify TLB entries on init (Jiaxun Yang)
- USB: serial: option: add Foxconn T99W709 (Slark Xiao)
- vsock: Do not allow binding to VMADDR_PORT_ANY (Budimir Markovic) [Orabug: 38351771,38453914] {CVE-2025-38618}
- net/packet: fix a race in packet_set_ring() and packet_notifier() (Quang Le) [Orabug: 38351764] {CVE-2025-38617}
- perf/core: Prevent VMA split of buffer mappings (Thomas Gleixner) [Orabug: 38334948] {CVE-2025-38563}
- perf/core: Exit early on perf_mmap() fail (Thomas Gleixner) [Orabug: 38334959] {CVE-2025-38565}
- perf/core: Don't leak AUX buffer refcount on allocation failure (Thomas Gleixner)
- pptp: fix pptp_xmit() error path (Eric Dumazet)
- smb: client: let recv_done() cleanup before notifying the callers. (Stefan Metzmacher)
- benet: fix BUG when creating VFs (Michal Schmidt) [Orabug: 38334976] {CVE-2025-38569}
- net: drop UFO packets in udp_rcv_segment() (Wang Liang) [Orabug: 38351786] {CVE-2025-38622}
- ipv6: reject malicious packets in ipv6_gso_segment() (Eric Dumazet) [Orabug: 38334988] {CVE-2025-38572}
- pptp: ensure minimal skb length in pptp_xmit() (Eric Dumazet) [Orabug: 38335004] {CVE-2025-38574}
- netpoll: prevent hanging NAPI when netcons gets enabled (Jakub Kicinski)
- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (Trond Myklebust) [Orabug: 38401745] {CVE-2025-39730}
- pci/hotplug/pnv-php: Wrap warnings in macro (Frederic Barrat)
- pci/hotplug/pnv-php: Improve error msg on power state change failure (Frederic Barrat)
- usb: chipidea: udc: fix sleeping function called from invalid context (Peter Chen)
- f2fs: fix to avoid out-of-boundary access in devs.path (Chao Yu)
- f2fs: fix to avoid panic in f2fs_evict_inode (Chao Yu)
- f2fs: fix to avoid UAF in f2fs_sync_inode_meta() (Chao Yu)
- rtc: pcf8563: fix incorrect maximum clock rate handling (Brian Masney)
- rtc: hym8563: fix incorrect maximum clock rate handling (Brian Masney)
- rtc: ds1307: fix incorrect maximum clock rate handling (Brian Masney)
- module: Restore the moduleparam prefix length check (Petr Pavlu)
- bpf: Check flow_dissector ctx accesses are aligned (Paul Chaignon)
- mtd: rawnand: atmel: set pmecc data setup time (Balamanikandan Gunasundar)
- mtd: rawnand: atmel: Fix dma_mapping_error() address (Thomas Fourier)
- jfs: fix metapage reference count leak in dbAllocCtl (Zheng Yu)
- fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (Chenyuan Yang)
- crypto: qat - fix seq_file position update in adf_ring_next() (Giovanni Cabiddu)
- dmaengine: nbpfaxi: Add missing check after DMA map (Thomas Fourier)
- dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (Thomas Fourier)
- fs/orangefs: Allow 2 more characters in do_c_string() (Dan Carpenter)
- soundwire: stream: restore params when prepare ports fail (Bard Liao)
- crypto: img-hash - Fix dma_unmap_sg() nents value (Thomas Fourier)
- hwrng: mtk - handle devm_pm_runtime_enable errors (Ovidiu Panait)
- watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (Dan Carpenter)
- scsi: isci: Fix dma_unmap_sg() nents value (Thomas Fourier)
- scsi: mvsas: Fix dma_unmap_sg() nents value (Thomas Fourier)
- scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (Thomas Fourier)
- clk: sunxi-ng: v3s: Fix de clock definition (Paul Kocialkowski)
- perf tests bp_account: Fix leaked file descriptor (Leo Yan)
- crypto: ccp - Fix crash when rebind ccp device for ccp.ko (Mengbiao Xiong)
- pinctrl: sunxi: Fix memory leak on krealloc failure (Yuan Chen)
- power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (Charles Han)
- clk: davinci: Add NULL check in davinci_lpsc_clk_register() (Henry Martin)
- mtd: fix possible integer overflow in erase_xfer() (Ivan Stepchenko)
- crypto: marvell/cesa - Fix engine load inaccuracy (Herbert Xu)
- PCI: rockchip-host: Fix 'Unexpected Completion' log message (Hans Zhang)
- vrf: Drop existing dst reference in vrf_ip6_input_dst (Stanislav Fomichev)
- selftests: rtnetlink.sh: remove esp4_offload after test (Xiumei Mu)
- netfilter: xt_nfacct: don't assume acct name is null-terminated (Florian Westphal) [Orabug: 38351854] {CVE-2025-38639}
- can: kvaser_usb: Assign netdev.dev_port based on device channel index (Jimmy Assarsson)
- can: kvaser_pciefd: Store device channel index (Jimmy Assarsson)
- wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (Gokul Sivakumar)
- Reapply 'wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()' (Remi Pommarel)
- mwl8k: Add missing check after DMA map (Thomas Fourier)
- wifi: rtl8xxxu: Fix RX skb size for aggregation disabled (Martin Kaistra)
- net/sched: Restrict conditions for adding duplicating netems to qdisc tree (William Liu) [Orabug: 38331466] {CVE-2025-38553}
- arch: powerpc: defconfig: Drop obsolete CONFIG_NET_CLS_TCINDEX (Johan Korsnes)
- drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (Fedor Pchelkin)
- m68k: Don't unregister boot console needlessly (Finn Thain)
- tcp: fix tcp_ofo_queue() to avoid including too much DUP SACK range (Xin Guo)
- iwlwifi: Add missing check for alloc_ordered_workqueue (Jiasheng Jiang) [Orabug: 38335110] {CVE-2025-38602}
- wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (Xiu Jianfeng)
- wifi: rtl818x: Kill URBs before clearing tx status queue (Daniil Dulov) [Orabug: 38335120] {CVE-2025-38604}
- caif: reduce stack size, again (Arnd Bergmann)
- bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (Yuan Chen)
- bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (Jiayuan Chen) [Orabug: 38335131] {CVE-2025-38608}
- staging: nvec: Fix incorrect null termination of battery manufacturer (Alok Tiwari)
- samples: mei: Fix building on musl libc (Brahmajit Das)
- cpufreq: Init policy->rwsem before it may be possibly used (Lifeng Zheng)
- ARM: dts: imx6ul-kontron-bl-common: Fix RTS polarity for RS485 interface (Annette Kobou)
- usb: early: xhci-dbc: Fix early_ioremap leak (Lucas De Marchi)
- Revert 'vmci: Prevent the dispatching of uninitialized payloads' (Greg Kroah-Hartman)
- pps: fix poll support (Denis Osterland-Heim)
- vmci: Prevent the dispatching of uninitialized payloads (Lizhi Xu)
- staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (Abdun Nihaal) [Orabug: 38335153] {CVE-2025-38612}
- ARM: dts: vfxxx: Correctly use two tuples for timer address (Krzysztof Kozlowski)
- hfsplus: remove mutex_lock check in hfsplus_free_extents (Yangtao Li)
- ASoC: Intel: fix SND_SOC_SOF dependencies (Arnd Bergmann)
- ethernet: intel: fix building with large NR_CPUS (Arnd Bergmann)
- usb: phy: mxs: disconnect line when USB charger is attached (Xu Yang)
- usb: chipidea: add USB PHY event (Xu Yang)
- usb: chipidea: introduce CI_HDRC_CONTROLLER_VBUS_EVENT glue layer use (Peter Chen)
- usb: chipidea: udc: protect usb interrupt enable (Li Jun)
- usb: chipidea: udc: add new API ci_hdrc_gadget_connect (Peter Chen)
- ALSA: hda: Add missing NVIDIA HDA codec IDs (Daniel Dadap)
- comedi: comedi_test: Fix possible deletion of uninitialized timers (Ian Abbott)
- nilfs2: reject invalid file types when reading inodes (Ryusuke Konishi)
- i2c: qup: jump out of the loop in case of timeout (Yang Xiwen) [Orabug: 38351994] {CVE-2025-38671}
- net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (Xiang Mei)
- net: appletalk: Fix use-after-free in AARP proxy probe (Kito Xu)
- net: appletalk: fix kerneldoc warnings (Andrew Lunn)
- RDMA/core: Rate limit GID cache warning messages (Maor Gottlieb)
- regulator: core: fix NULL dereference on unbind due to stale coupling data (Alessandro Carminati) [Orabug: 38351978] {CVE-2025-38668}
- usb: hub: Fix flushing and scheduling of delayed work that tunes runtime pm (Mathias Nyman)
- usb: hub: fix detection of high tier USB3 devices behind suspended hubs (Mathias Nyman)
- net_sched: sch_sfq: reject invalid perturb period (Eric Dumazet) [Orabug: 38158477] {CVE-2025-38193}
- power: supply: bq24190: Fix use after free bug in bq24190_remove due to race condition (Zheng Wang)
- power: supply: bq24190_charger: using pm_runtime_resume_and_get instead of pm_runtime_get_sync (Minghao Chi)
- power: supply: bq24190_charger: Fix runtime PM imbalance on error (Dinghao Liu)
- xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (Hongyu Xie)
- virtio-net: ensure the received length does not exceed allocated size (Bui Quang Minh) [Orabug: 38253834] {CVE-2025-38375}
- ASoC: fsl_sai: Force a software reset when starting in consumer mode (Arun Raghavan)
- usb: dwc3: qcom: Don't leave BCR asserted (Krishna Kurapati)
- usb: musb: fix gadget state on disconnect (Drew Hamilton)
- net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (William Liu) [Orabug: 38254214] {CVE-2025-38468}
- net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (Dong Chenchen) [Orabug: 38254225] {CVE-2025-38470}
- Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (Luiz Augusto von Dentz)
- Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (Luiz Augusto von Dentz)
- Bluetooth: SMP: If an unallowed command is received consider it a failure (Luiz Augusto von Dentz)
- Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (Kuniyuki Iwashima) [Orabug: 38254241] {CVE-2025-38473}
- usb: net: sierra: check for no status endpoint (Oliver Neukum) [Orabug: 38254249] {CVE-2025-38474}
- net/sched: sch_qfq: Fix race condition on qfq_aggregate (Xiang Mei) [Orabug: 38254266] {CVE-2025-38477}
- net: emaclite: Fix missing pointer increment in aligned_read() (Alok Tiwari)
- comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (Ian Abbott)
- comedi: Fix some signed shift left operations (Ian Abbott)
- comedi: das6402: Fix bit shift out of bounds (Ian Abbott)
- comedi: das16m1: Fix bit shift out of bounds (Ian Abbott)
- comedi: aio_iiro_16: Fix bit shift out of bounds (Ian Abbott)
- comedi: pcl812: Fix bit shift out of bounds (Ian Abbott)
- iio: adc: stm32-adc: Fix race in installing chained IRQ handler (Chen Ni)
- iio: adc: max1363: Reorder mode_list[] entries (Fabio Estevam)
- iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (Fabio Estevam)
- soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled (Andrew Jeffery)
- soc: aspeed: lpc-snoop: Cleanup resources in stack-order (Andrew Jeffery)
- mmc: sdhci_am654: Workaround for Errata i2312 (Judith Mendez)
- mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (Edson Juliano Drosdeck)
- mmc: bcm2835: Fix dma_unmap_sg() nents value (Thomas Fourier)
- memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (Nathan Chancellor)
- isofs: Verify inode mode when loading from disk (Jan Kara)
- dmaengine: nbpfaxi: Fix memory corruption in probe() (Dan Carpenter)
- af_packet: fix soft lockup issue caused by tpacket_snd() (Yun Lu)
- af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (Yun Lu)
- phonet/pep: Move call to pn_skb_get_dst_sockaddr() earlier in pep_sock_accept() (Nathan Chancellor)
- HID: core: do not bypass hid_hw_raw_request (Benjamin Tissoires) [Orabug: 38254340,38453904] {CVE-2025-38494}
- HID: core: ensure __hid_request reserves the report ID as the first byte (Benjamin Tissoires)
- HID: core: ensure the allocated report buffer can contain the reserved report ID (Benjamin Tissoires) [Orabug: 38254348,38453908] {CVE-2025-38495}
- pch_uart: Fix dma_sync_sg_for_device() nents value (Thomas Fourier)
- Input: xpad - set correct controller type for Acer NGR200 (Nilton Perim Neto)
- i2c: stm32: fix the device used for the DMA map (Clement Le Goffic)
- usb: gadget: configfs: Fix OOB read on empty string write (Xinyu Liu) [Orabug: 38254358] {CVE-2025-38497}
- USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (Ryan Mann)
- USB: serial: option: add Foxconn T99W640 (Slark Xiao)
- USB: serial: option: add Telit Cinterion FE910C04 (ECM) composition (Fabio Porcedda)
- LTS tag: v5.4.296 (Sherry Yang)
- x86/mm: Disable hugetlb page table sharing on 32-bit (Jann Horn)
- Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID (Hans de Goede)
- HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (Chia-Lin Kao) [Orabug: 38324280] {CVE-2025-38540}
- HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (Zhang Heng)
- vt: add missing notification when switching back to text mode (Nicolas Pitre)
- net: usb: qmi_wwan: add SIMCom 8230C composition (Xiaowei Li)
- atm: idt77252: Add missing dma_map_error() (Thomas Fourier)
- bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (Somnath Kotur) [Orabug: 38254090] {CVE-2025-38439}
- bnxt_en: Fix DCB ETS validation (Shravya Kn)
- can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (Sean Nyekjaer)
- net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (Oleksij Rempel)
- net: appletalk: Fix device refcount leak in atrtr_create() (Kito Xu)
- md/raid1: Fix stack memory use after return in raid1_reshape (Wang Jinchao) [Orabug: 38254109] {CVE-2025-38445}
- wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (Daniil Dulov) [Orabug: 38324161] {CVE-2025-38513}
- dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (Christian Konig)
- Input: xpad - support Acer NGR 200 Controller (Nilton Perim Neto)
- Input: xpad - add VID for Turtle Beach controllers (Vicki Pfau)
- Input: xpad - add support for Amazon Game Controller (Matt Reynolds)
- NFSv4/flexfiles: Fix handling of NFS level errors in I/O (Trond Myklebust)
- flexfiles/pNFS: update stats on NFS4ERR_DELAY for v4.1 DSes (Tigran Mkrtchyan)
- RDMA/mlx5: Fix vport loopback for MPV device (Patrisious Haddad)
- netlink: Fix rmem check in netlink_broadcast_deliver(). (Kuniyuki Iwashima)
- netlink: make sure we allow at least one dump skb (Jakub Kicinski)
- Revert 'ACPI: battery: negate current when discharging' (Rafael J. Wysocki)
- usb: gadget: u_serial: Fix race condition in TTY wakeup (Kuen-Han Tsai) [Orabug: 38254118] {CVE-2025-38448}
- drm/sched: Increment job count before swapping tail spsc queue (Matthew Brost) [Orabug: 38324180] {CVE-2025-38515}
- pinctrl: qcom: msm: mark certain pins as invalid for interrupts (Bartosz Golaszewski) [Orabug: 38324186] {CVE-2025-38516}
- x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (Jp Kobryn)
- x86/mce: Don't remove sysfs if thresholding sysfs init fails (Yazen Ghannam)
- x86/mce/amd: Fix threshold limit reset (Yazen Ghannam)
- rxrpc: Fix oops due to non-existence of prealloc backlog struct (David Howells)
- net/sched: Abort __tc_modify_qdisc if parent class does not exist (Victor Nogueira) [Orabug: 38254147] {CVE-2025-38457}
- atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (Yue Haibing) [Orabug: 38254153] {CVE-2025-38458}
- atm: clip: Fix infinite recursive call of clip_push(). (Kuniyuki Iwashima) [Orabug: 38254161] {CVE-2025-38459}
- atm: clip: Fix memory leak of struct clip_vcc. (Kuniyuki Iwashima) [Orabug: 38324309] {CVE-2025-38546}
- atm: clip: Fix potential null-ptr-deref in to_atmarpd(). (Kuniyuki Iwashima) [Orabug: 38254167] {CVE-2025-38460}
- tipc: Fix use-after-free in tipc_conn_close(). (Kuniyuki Iwashima) [Orabug: 38254181] {CVE-2025-38464}
- netlink: Fix wraparounds of sk->sk_rmem_alloc. (Kuniyuki Iwashima) [Orabug: 38254188] {CVE-2025-38465}
- fix proc_sys_compare() handling of in-lookup dentries (Al Viro)
- proc: Clear the pieces of proc_inode that proc_evict_inode cares about (Eric W. Biederman)
- drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (Kaustabh Chakraborty) [Orabug: 38254203] {CVE-2025-38467}
- staging: rtl8723bs: Avoid memset() in aes_cipher() and aes_decipher() (Nathan Chancellor)
- media: uvcvideo: Rollback non processed entities on error (Ricardo Ribalda)
- media: uvcvideo: Send control events for partial succeeds (Ricardo Ribalda)
- media: uvcvideo: Return the number of processed controls (Ricardo Ribalda)
- ACPI: PAD: fix crash in exit_round_robin() (Seiji Nishikawa) [Orabug: 37206006] {CVE-2024-49935}
- usb: typec: displayport: Fix potential deadlock (Andrei Kuchynski) [Orabug: 38401436] {CVE-2025-38404}
- Logitech C-270 even more broken (Oliver Neukum)
- rose: fix dangling neighbour pointers in rose_rt_device_down() (Kohei Enju)
- net: rose: Fix fall-through warnings for Clang (Gustavo A R Silva)
- drm/i915/gt: Fix timeline left held on VMA alloc error (Janusz Krzysztofik) [Orabug: 38253887] {CVE-2025-38389}
- drm/i915/selftests: Change mock_request() to return error pointers (Dan Carpenter)
- spi: spi-fsl-dspi: Clear completion counter before initiating transfer (James Clark)
- spi: spi-fsl-dspi: Fix interrupt-less DMA mode taking an XSPI code path (Vladimir Oltean)
- spi: spi-fsl-dspi: Rename fifo_{read,write} and {tx,cmd}_fifo_write (Vladimir Oltean)
- dpaa2-eth: fix xdp_rxq_info leak (Wangfushuai)
- ethernet: atl1: Add missing DMA mapping error checks and count errors (Thomas Fourier)
- btrfs: use btrfs_record_snapshot_destroy() during rmdir (Filipe Manana)
- btrfs: propagate last_unlink_trans earlier when doing a rmdir (Filipe Manana)
- RDMA/mlx5: Fix CC counters query for MPV (Patrisious Haddad)
- RDMA/core: Create and destroy counters in the ib_core (Leon Romanovsky)
- scsi: ufs: core: Fix spelling of a sysfs attribute name (Bart Van Assche)
- drm/v3d: Disable interrupts before resetting the GPU (Maira Canal)
- mtk-sd: reset host->mrq on prepare_data() error (Sergey Senozhatsky)
- mtk-sd: Prevent memory corruption from DMA map failure (Masami Hiramatsu)
- mmc: mediatek: use data instead of mrq parameter from msdc_{un}prepare_data() (Yue Hu)
- regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (Manivannan Sadhasivam) [Orabug: 38253907] {CVE-2025-38395}
- regulator: gpio: Add input_supply support in gpio_regulator_config (Jerome Neanne)
- ACPICA: Refuse to evaluate a method if arguments are missing (Rafael J. Wysocki) [Orabug: 38253875] {CVE-2025-38386}
- wifi: ath6kl: remove WARN on bad firmware input (Johannes Berg) [Orabug: 38253946] {CVE-2025-38406}
- wifi: mac80211: drop invalid source address OCB frames (Johannes Berg)
- powerpc: Fix struct termio related ioctl macros (Madhavan Srinivasan)
- ata: pata_cs5536: fix build on 32-bit UML (Johannes Berg)
- ALSA: sb: Force to disable DMAs once when DMA mode is changed (Takashi Iwai)
- nui: Fix dma_mapping_error() check (Thomas Fourier)
- enic: fix incorrect MTU comparison in enic_change_mtu() (Alok Tiwari)
- amd-xgbe: align CL37 AN sequence as per databook (Raju Rangoju)
- lib: test_objagg: Set error message in check_expect_hints_stats() (Dan Carpenter)
- drm/exynos: fimd: Guard display clock control with runtime PM calls (Marek Szyprowski)
- btrfs: fix missing error handling when searching for inode refs during log replay (Filipe Manana)
- scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (Thomas Fourier)
- nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. (Kuniyuki Iwashima) [Orabug: 38253923] {CVE-2025-38400}
- RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert (Mark Zhang) [Orabug: 38253881] {CVE-2025-38387}
- platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (David Thompson)
- mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (Masami Hiramatsu)
- usb: typec: altmodes/displayport: do not index invalid pin_assignments (Rd Babiera) [Orabug: 38253894] {CVE-2025-38391}
- mmc: sdhci: Add a helper function for dump register in dynamic debug mode (Victor Shih)
- vsock/vmci: Clear the vmci transport packet properly when initializing it (Harshavardhana S A) [Orabug: 38253937] {CVE-2025-38403}
- btrfs: don't abort filesystem when attempting to snapshot deleted subvolume (Omar Sandoval) [Orabug: 36530119] {CVE-2024-26644}
- arm64: Restrict pagetable teardown to avoid false warning (Dev Jain)
- s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS (Nathan Chancellor)
- drm/bridge: cdns-dsi: Check return value when getting default PHY config (Aradhya Bhatia)
- drm/bridge: cdns-dsi: Fix connecting to next bridge (Aradhya Bhatia)
- drm/bridge: cdns-dsi: Fix the clock variable for mode_valid() (Aradhya Bhatia)
- drm/tegra: Assign plane type before registration (Thierry Reding)
- HID: wacom: fix kobject reference count leak (Qasim Ijaz)
- HID: wacom: fix memory leak on sysfs attribute creation failure (Qasim Ijaz)
- HID: wacom: fix memory leak on kobject creation failure (Qasim Ijaz)
- dm-raid: fix variable in journal device check (Heinz Mauelshagen)
- Bluetooth: L2CAP: Fix L2CAP MTU negotiation (Frederic Danis)
- atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). (Kuniyuki Iwashima) [Orabug: 38175045] {CVE-2025-38245}
- net: enetc: Correct endianness handling in _enetc_rd_reg64 (Simon Horman)
- um: ubd: Add missing error check in start_io_thread() (Tiwei Bie)
- vsock/uapi: fix linux/vm_sockets.h userspace compilation errors (Stefano Garzarella)
- wifi: mac80211: fix beacon interval calculation overflow (Lachlan Hodges)
- attach_recursive_mnt(): do not lock the covering tree when sliding something under it (Al Viro)
- ALSA: usb-audio: Fix out-of-bounds read in snd_usb_get_audioformat_uac3() (Youngjun Lee) [Orabug: 38175065] {CVE-2025-38249}
- i2c: robotfuzz-osif: disable zero-length read messages (Wolfram Sang)
- i2c: tiny-usb: disable zero-length read messages (Wolfram Sang)
- RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (Shin'Ichiro Kawasaki) [Orabug: 38158592] {CVE-2025-38211}
- RDMA/core: Use refcount_t instead of atomic_t on refcount of iwcm_id_private (Weihang Li)
- media: vivid: Change the siize of the composing (Denis Arefev)
- media: omap3isp: use sgtable-based scatterlist wrappers (Marek Szyprowski)
- media: cxusb: no longer judge rbuf when the write fails (Edward Adam Davis) [Orabug: 38158692] {CVE-2025-38229}
- media: cxusb: use dev_dbg() rather than hand-rolled debug (Sean Young)
- jfs: validate AG parameters in dbMount() to prevent crashes (Vasiliy Kovalev)
- fs/jfs: consolidate sanity checking in dbMount (Dave Kleikamp)
- ASoC: meson: meson-card-utils: use of_property_present() for DT parsing (Martin Blumenstingl)
- of: Add of_property_present() helper (Rob Herring)
- of: property: define of_property_read_u{8,16,32,64}_array() unconditionally (Michael Walle)
- kbuild: hdrcheck: fix cross build with clang (Arnd Bergmann)
- kbuild: add --target to correctly cross-compile UAPI headers with Clang (Masahiro Yamada)
- bpfilter: match bit size of bpfilter_umh to that of the kernel (Masahiro Yamada)
- kbuild: use -MMD instead of -MD to exclude system headers from dependency (Masahiro Yamada)
- VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify (Ma Wupeng) [Orabug: 38152869] {CVE-2025-38102}
- VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF (George Kennedy)
- ovl: Check for NULL d_inode() in ovl_dentry_upper() (Kees Cook)
- ceph: fix possible integer overflow in ceph_zero_objects() (Dmitry Kandybka)
- ALSA: hda: Ignore unsol events for cards being shut down (Cezary Rojewski)
- usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode (Jos Wang)
- usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (Robert Hodaszi)
- usb: Add checks for snprintf() calls in usb_alloc_dev() (Andy Shevchenko)
- tty: serial: uartlite: register uart driver in init (Jakub Lewalski)
- usb: potential integer overflow in usbg_make_tpg() (Chen Yufeng)
- iio: pressure: zpa2326: Use aligned_s64 for the timestamp (Jonathan Cameron)
- md/md-bitmap: fix dm-raid max_write_behind setting (Yu Kuai)
- dmaengine: xilinx_dma: Set dma_device directions (Thomas Gessler)
- mfd: max14577: Fix wakeup source leaks on device unbind (Krzysztof Kozlowski)
- mailbox: Not protect module_put with spin_lock_irqsave (Peng Fan)
- cifs: Fix cifs_query_path_info() for Windows NT servers (Pali Rohar) | IMPORTANT | 2025-12-12 00:00:00+03:00 | ['CVE-2024-50022', 'CVE-2025-22058', 'CVE-2025-23143', 'CVE-2025-39883', 'CVE-2025-39885', 'CVE-2025-39911', 'CVE-2025-39913', 'CVE-2025-39923', 'CVE-2025-39945', 'CVE-2025-39953', 'CVE-2025-39955', 'CVE-2025-39967', 'CVE-2025-39968', 'CVE-2025-39969', 'CVE-2025-39970', 'CVE-2025-39971', 'CVE-2025-39972', 'CVE-2025-39973', 'CVE-2025-39993', 'CVE-2025-39994', 'CVE-2025-39995', 'CVE-2025-39996', 'CVE-2025-39998', 'CVE-2025-40001', 'CVE-2025-40006', 'CVE-2025-40011', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40020', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40035', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40055', 'CVE-2025-40070', 'CVE-2025-40078', 'CVE-2025-40081', 'CVE-2025-40087', 'CVE-2025-40105', 'CVE-2025-40111', 'CVE-2025-40115', 'CVE-2025-40118', 'CVE-2025-40125', 'CVE-2025-40134', 'CVE-2025-40140', 'CVE-2025-40153', 'CVE-2025-40167', 'CVE-2025-40173', 'CVE-2025-40178', 'CVE-2025-40186', 'CVE-2025-40187', 'CVE-2025-40190', 'CVE-2025-40194', 'CVE-2025-40197', 'CVE-2025-40198', 'CVE-2025-40200', 'CVE-2025-40204', 'CVE-2025-40205', 'CVE-2025-40219', 'CVE-2025-40233', 'CVE-2025-40240'] | ['Oracle Linux 7', 'Oracle Linux 8'] | ['CVE-2024-50022', 'CVE-2025-22058', 'CVE-2025-23143', 'CVE-2025-39883', 'CVE-2025-39885', 'CVE-2025-39911', 'CVE-2025-39913', 'CVE-2025-39923', 'CVE-2025-39945', 'CVE-2025-39953', 'CVE-2025-39955', 'CVE-2025-39967', 'CVE-2025-39968', 'CVE-2025-39969', 'CVE-2025-39970', 'CVE-2025-39971', 'CVE-2025-39972', 'CVE-2025-39973', 'CVE-2025-39993', 'CVE-2025-39994', 'CVE-2025-39995', 'CVE-2025-39996', 'CVE-2025-39998', 'CVE-2025-40001', 'CVE-2025-40006', 'CVE-2025-40011', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40020', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40035', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40055', 'CVE-2025-40070', 'CVE-2025-40078', 'CVE-2025-40081', 'CVE-2025-40087', 'CVE-2025-40105', 'CVE-2025-40111', 'CVE-2025-40115', 'CVE-2025-40118', 'CVE-2025-40125', 'CVE-2025-40134', 'CVE-2025-40140', 'CVE-2025-40153', 'CVE-2025-40167', 'CVE-2025-40173', 'CVE-2025-40178', 'CVE-2025-40186', 'CVE-2025-40187', 'CVE-2025-40190', 'CVE-2025-40194', 'CVE-2025-40197', 'CVE-2025-40198', 'CVE-2025-40200', 'CVE-2025-40204', 'CVE-2025-40205', 'CVE-2025-40219', 'CVE-2025-40233', 'CVE-2025-40240', 'ELSA-2025-28049', 'https://linux.oracle.com/cve/CVE-2024-50022.html', 'https://linux.oracle.com/cve/CVE-2025-22058.html', 'https://linux.oracle.com/cve/CVE-2025-23143.html', 'https://linux.oracle.com/cve/CVE-2025-39883.html', 'https://linux.oracle.com/cve/CVE-2025-39885.html', 'https://linux.oracle.com/cve/CVE-2025-39911.html', 'https://linux.oracle.com/cve/CVE-2025-39913.html', 'https://linux.oracle.com/cve/CVE-2025-39923.html', 'https://linux.oracle.com/cve/CVE-2025-39945.html', 'https://linux.oracle.com/cve/CVE-2025-39953.html', 'https://linux.oracle.com/cve/CVE-2025-39955.html', 'https://linux.oracle.com/cve/CVE-2025-39967.html', 'https://linux.oracle.com/cve/CVE-2025-39968.html', 'https://linux.oracle.com/cve/CVE-2025-39969.html', 'https://linux.oracle.com/cve/CVE-2025-39970.html', 'https://linux.oracle.com/cve/CVE-2025-39971.html', 'https://linux.oracle.com/cve/CVE-2025-39972.html', 'https://linux.oracle.com/cve/CVE-2025-39973.html', 'https://linux.oracle.com/cve/CVE-2025-39993.html', 'https://linux.oracle.com/cve/CVE-2025-39994.html', 'https://linux.oracle.com/cve/CVE-2025-39995.html', 'https://linux.oracle.com/cve/CVE-2025-39996.html', 'https://linux.oracle.com/cve/CVE-2025-39998.html', 'https://linux.oracle.com/cve/CVE-2025-40001.html', 'https://linux.oracle.com/cve/CVE-2025-40006.html', 'https://linux.oracle.com/cve/CVE-2025-40011.html', 'https://linux.oracle.com/cve/CVE-2025-40018.html', 'https://linux.oracle.com/cve/CVE-2025-40019.html', 'https://linux.oracle.com/cve/CVE-2025-40020.html', 'https://linux.oracle.com/cve/CVE-2025-40026.html', 'https://linux.oracle.com/cve/CVE-2025-40027.html', 'https://linux.oracle.com/cve/CVE-2025-40030.html', 'https://linux.oracle.com/cve/CVE-2025-40035.html', 'https://linux.oracle.com/cve/CVE-2025-40042.html', 'https://linux.oracle.com/cve/CVE-2025-40044.html', 'https://linux.oracle.com/cve/CVE-2025-40048.html', 'https://linux.oracle.com/cve/CVE-2025-40049.html', 'https://linux.oracle.com/cve/CVE-2025-40055.html', 'https://linux.oracle.com/cve/CVE-2025-40070.html', 'https://linux.oracle.com/cve/CVE-2025-40078.html', 'https://linux.oracle.com/cve/CVE-2025-40081.html', 'https://linux.oracle.com/cve/CVE-2025-40087.html', 'https://linux.oracle.com/cve/CVE-2025-40105.html', 'https://linux.oracle.com/cve/CVE-2025-40111.html', 'https://linux.oracle.com/cve/CVE-2025-40115.html', 'https://linux.oracle.com/cve/CVE-2025-40118.html', 'https://linux.oracle.com/cve/CVE-2025-40125.html', 'https://linux.oracle.com/cve/CVE-2025-40134.html', 'https://linux.oracle.com/cve/CVE-2025-40140.html', 'https://linux.oracle.com/cve/CVE-2025-40153.html', 'https://linux.oracle.com/cve/CVE-2025-40167.html', 'https://linux.oracle.com/cve/CVE-2025-40173.html', 'https://linux.oracle.com/cve/CVE-2025-40178.html', 'https://linux.oracle.com/cve/CVE-2025-40186.html', 'https://linux.oracle.com/cve/CVE-2025-40187.html', 'https://linux.oracle.com/cve/CVE-2025-40190.html', 'https://linux.oracle.com/cve/CVE-2025-40194.html', 'https://linux.oracle.com/cve/CVE-2025-40197.html', 'https://linux.oracle.com/cve/CVE-2025-40198.html', 'https://linux.oracle.com/cve/CVE-2025-40200.html', 'https://linux.oracle.com/cve/CVE-2025-40204.html', 'https://linux.oracle.com/cve/CVE-2025-40205.html', 'https://linux.oracle.com/cve/CVE-2025-40219.html', 'https://linux.oracle.com/cve/CVE-2025-40233.html', 'https://linux.oracle.com/cve/CVE-2025-40240.html', 'https://linux.oracle.com/errata/ELSA-2025-28049.html'] | 84670ea3abcfa19774261d4a9af793da4b339d8c35e9747452a7db0d5d25618f | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523134 | ELSA-2025-23134: mysql:8.0 security update (MODERATE) | mecab
mecab-ipadic
mysql
[8.0.44-1]
- Rebase to MySQL 8.0.44 | MODERATE | 2025-12-12 00:00:00+03:00 | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069'] | ['Oracle Linux 8'] | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069', 'ELSA-2025-23134', 'https://linux.oracle.com/cve/CVE-2025-53040.html', 'https://linux.oracle.com/cve/CVE-2025-53042.html', 'https://linux.oracle.com/cve/CVE-2025-53044.html', 'https://linux.oracle.com/cve/CVE-2025-53045.html', 'https://linux.oracle.com/cve/CVE-2025-53053.html', 'https://linux.oracle.com/cve/CVE-2025-53054.html', 'https://linux.oracle.com/cve/CVE-2025-53062.html', 'https://linux.oracle.com/cve/CVE-2025-53069.html', 'https://linux.oracle.com/errata/ELSA-2025-23134.html'] | 0ecdd4c96c5fc9b55660a0459c59f8f61af4867a0369528d0220147d315346fe | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523109 | ELSA-2025-23109: mysql security update (MODERATE) | [8.0.44-1]
- Rebase to MySQL 8.0.44 | MODERATE | 2025-12-12 00:00:00+03:00 | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069'] | ['Oracle Linux 9'] | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069', 'ELSA-2025-23109', 'https://linux.oracle.com/cve/CVE-2025-53040.html', 'https://linux.oracle.com/cve/CVE-2025-53042.html', 'https://linux.oracle.com/cve/CVE-2025-53044.html', 'https://linux.oracle.com/cve/CVE-2025-53045.html', 'https://linux.oracle.com/cve/CVE-2025-53053.html', 'https://linux.oracle.com/cve/CVE-2025-53054.html', 'https://linux.oracle.com/cve/CVE-2025-53062.html', 'https://linux.oracle.com/cve/CVE-2025-53069.html', 'https://linux.oracle.com/errata/ELSA-2025-23109.html'] | 5e2262bcbaebbe476d366050c3430e05e4307e3f51554bc02c3d617874500e9a | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528048 | ELSA-2025-28048: Unbreakable Enterprise kernel security update (IMPORTANT) | [5.15.0-315.196.5.1]
- netfilter: nf_tables: reject duplicate device on updates (Pablo Neira Ayuso) [Orabug: 38744086] {CVE-2025-38678}
- Reapply 'cpuidle: menu: Avoid discarding useful information' (Harshvardhan Jha) [Orabug: 38744084]
- rtc: expose RTC_FEATURE_UPDATE_INTERRUPT (Alexandre Belloni) [Orabug: 38744082]
[5.15.0-315.196.5]
- uek-rpm: add 'bpf' to CONFIG_LSM (Alan Maguire) [Orabug: 35653191]
- Revert 'cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry' (Samasth Norway Ananda) [Orabug: 38613264]
[5.15.0-315.196.4]
- net/rds: Fix rs_recv_pending counting issue (Gerd Rausch) [Orabug: 38506368]
[5.15.0-315.196.3]
- KVM: VMX: Intercept reads to invalid and write-only x2APIC registers (Sean Christopherson) [Orabug: 38535186]
- KVM: VMX: Always intercept accesses to unsupported 'extended' x2APIC regs (Sean Christopherson) [Orabug: 38535186]
- KVM: x86: Split out logic to generate 'readable' APIC regs mask to helper (Sean Christopherson) [Orabug: 38535186]
- KVM: x86: Mark x2APIC DFR reg as non-existent for x2APIC (Sean Christopherson) [Orabug: 38535186]
- uek-rpm/ol9/config-mips64-emb: Enable NF_TABLES for MIPS64 (Vijay Kumar) [Orabug: 38578981]
- LTS version: v5.15.196 (Vijayendra Suman)
- PCI: rcar: Demote WARN() to dev_warn_ratelimited() in rcar_pcie_wakeup() (Marek Vasut) [Orabug: 38641258] {CVE-2024-43876}
- net: rtnetlink: fix module reference count leak issue in rtnetlink_rcv_msg (Zhengchao Shao)
- usb: gadget: f_acm: Refactor bind path to use __free() (Kuen-Han Tsai) [Orabug: 38601854] {CVE-2025-40094}
- usb: gadget: f_ncm: Refactor bind path to use __free() (Kuen-Han Tsai) [Orabug: 38601837] {CVE-2025-40092}
- usb: gadget: Introduce free_usb_request helper (Kuen-Han Tsai)
- usb: gadget: Store endpoint pointer in usb_request (Kuen-Han Tsai)
- arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (Kaushlendra Kumar)
- xfs: always warn about deprecated mount options (Darrick J. Wong)
- devcoredump: Fix circular locking dependency with devcd->mutex. (Maarten Lankhorst)
- PCI: tegra194: Reset BARs when running in PCIe endpoint mode (Niklas Cassel)
- PCI: rcar-host: Drop PMSR spinlock (Marek Vasut)
- PCI: rcar: Finish transition to L1 state in rcar_pcie_config_access() (Marek Vasut)
- PCI: tegra194: Handle errors in BPMP response (Vidya Sagar)
- f2fs: fix wrong block mapping for multi-devices (Jaegeuk Kim)
- NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601818] {CVE-2025-40087}
- vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601923] {CVE-2025-40105}
- drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han)
- PCI: rcar-host: Convert struct rcar_msi mask_lock into raw spinlock (Marek Vasut)
- wifi: ath11k: HAL SRNG: don't deinitialize and re-initialize again (Muhammad Usama Anjum)
- PCI: j721e: Fix programming sequence of 'strap' settings (Siddharth Vadapalli)
- PCI: j721e: Enable ACSPCIE Refclk if 'ti,syscon-acspcie-proxy-ctrl' exists (Siddharth Vadapalli)
- fuse: fix livelock in synchronous file put from fuseblk workers (Darrick J. Wong)
- fuse: allocate ff->release_args only if release is needed (Amir Goldstein)
- padata: Reset next CPU when reorder sequence wraps around (Xiao Liang)
- iio: imu: inv_icm42600: Simplify pm_runtime setup (Sean Nyekjaer)
- PM: runtime: Add new devm functions (Csokas Bence)
- iio: imu: inv_icm42600: Avoid configuring if already pm_runtime suspended (Sean Nyekjaer)
- iio: imu: inv_icm42600: use = { } instead of memset() (David Lechner)
- NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov)
- NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov)
- NFSD: Rework encoding and decoding of nfsd4_deviceid (Sergey Bashirov)
- xfs: fix log CRC mismatches between i386 and other architectures (Christoph Hellwig)
- xfs: rename the old_crc variable in xlog_recover_process (Christoph Hellwig)
- s390/cio: Update purge function to unregister the unused subchannels (Vineeth Vijayan)
- arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland)
- serial: 8250_exar: add support for Advantech 2 port card with Device ID 0x0018 (Florian Eckert)
- most: usb: hdm_probe: Fix calling put_device() before device initialization (Victoria Votokina)
- most: usb: Fix use-after-free in hdm_disconnect (Victoria Votokina)
- mei: me: add wildcat lake P DID (Alexander Usyskin)
- comedi: fix divide-by-zero in comedi_buf_munge() (Deepanshu Kartikey)
- binder: remove 'invalid inc weak' check (Alice Ryhl)
- xhci: dbc: enable back DbC in resume if it was enabled before suspend (Mathias Nyman)
- usb: raw-gadget: do not limit transfer length (Andrey Konovalov)
- usb/core/quirks: Add Huawei ME906S to wakeup quirk (Tim Guttzeit)
- USB: serial: option: add Telit FN920C04 ECM compositions (Li Qingwu)
- USB: serial: option: add Quectel RG255C (Reinhard Speyerer)
- USB: serial: option: add UNISOC UIS7720 (Renjun Wang)
- net: ravb: Ensure memory write completes before ringing TX doorbell (Lad Prabhakar)
- net: usb: rtl8150: Fix frame padding (Michal Pecio)
- vsock: fix lock inversion in vsock_assign_transport() (Stefano Garzarella)
- ocfs2: clear extent cache after moving/defragmenting extents (Deepanshu Kartikey)
- MIPS: Malta: Fix keyboard resource preventing i8042 driver from registering (Maciej W. Rozycki)
- Revert 'cpuidle: menu: Avoid discarding useful information' (Rafael J. Wysocki)
- net: bonding: fix possible peer notify event loss or dup issue (Tonghao Zhang)
- sctp: avoid NULL dereference when chunk data buffer is missing (Alexey Simakov)
- arm64, mm: avoid always making PTE dirty in pte_mkwrite() (Huang, Ying)
- dpaa2-eth: fix the pointer passed to PTR_ALIGN on Tx path (Ioana Ciornei)
- net: enetc: correct the value of ENETC_RXB_TRUESIZE (Wei Fang)
- rtnetlink: Allow deleting FDB entries in user namespace (Johannes Wiesboeck)
- net: rtnetlink: add NLM_F_BULK support to rtnl_fdb_del (Nikolay Aleksandrov)
- net: rtnetlink: add bulk delete support flag (Nikolay Aleksandrov)
- net: netlink: add NLM_F_BULK delete request modifier (Nikolay Aleksandrov)
- net: rtnetlink: use BIT for flag values (Nikolay Aleksandrov)
- net: rtnetlink: add helper to extract msg type's kind (Nikolay Aleksandrov)
- m68k: bitops: Fix find_*_bit() signatures (Geert Uytterhoeven)
- hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() (Yangtao Li)
- hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits() (Viacheslav Dubeyko)
- dlm: check for defined force value in dlm_lockspace_release (Alexander Aring)
- hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (Viacheslav Dubeyko)
- hfs: validate record offset in hfsplus_bmap_alloc (Yang Chenzhi)
- hfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent() (Viacheslav Dubeyko)
- hfs: make proper initalization of struct hfs_find_data (Viacheslav Dubeyko)
- hfs: clear offset and space out of valid records in b-tree node (Viacheslav Dubeyko)
- nios2: ensure that memblock.current_limit is set when setting pfn limits (Simon Schuster)
- exec: Fix incorrect type for ret (Xichao Zhao)
- PCI/sysfs: Ensure devices are powered for config reads (part 2) (Brian Norris)
- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko)
- ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card (Jiaming Zhang) [Orabug: 38597093] {CVE-2025-40085}
- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap)
- sched/fair: Fix pelt lost idle time detection (Vincent Guittot)
- sched/balancing: Rename newidle_balance() => sched_balance_newidle() (Ingo Molnar)
- drm/amd/powerplay: Fix CIK shutdown temperature (Timur Kristof)
- net: usb: lan78xx: fix use of improperly initialized dev->chipid in lan78xx_reset (I Viswanath)
- net: usb: lan78xx: Add error handling to lan78xx_init_mac_address (Oleksij Rempel)
- net: usb: use eth_hw_addr_set() instead of ether_addr_copy() (Jakub Kicinski)
- tls: don't rely on tx_work during send() (Sabrina Dubroca)
- tls: always set record_type in tls_process_cmsg (Sabrina Dubroca)
- tls: wait for async encrypt in case of error during latter iterations of sendmsg (Sabrina Dubroca)
- net: tls: wait for async completion on last message (Sascha Hauer)
- tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov)
- tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet)
- amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju)
- net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov) [Orabug: 38649259] {CVE-2025-40173}
- r8169: fix packet truncation after S4 resume on RTL8168H/RTL8111H (Linmao Li)
- doc: fix seg6_flowlabel path (Nicolas Dichtel)
- net: dlink: handle dma_map_single() failure properly (Moon Yeounsu)
- can: m_can: m_can_plat_remove(): add missing pm_runtime_disable() (Marc Kleine-Budde)
- dax: skip read lock assertion for read-only filesystems (Yuezhang Mo)
- HID: multitouch: fix sticky fingers (Benjamin Tissoires)
- cpufreq: CPPC: Avoid using CPUFREQ_ETERNAL as transition delay (Rafael J. Wysocki)
- crypto: rockchip - Fix dma_unmap_sg() nents value (Thomas Fourier)
- drm/exynos: exynos7_drm_decon: remove ctx->suspended (Kaustabh Chakraborty)
- drm/exynos: exynos7_drm_decon: properly clear channels during bind (Kaustabh Chakraborty)
- drm/exynos: exynos7_drm_decon: fix uninitialized crtc reference in functions (Kaustabh Chakraborty)
- blk-crypto: fix missing blktrace bio split events (Yu Kuai)
- media: lirc: Fix error handling in lirc_register() (Ma Ke)
- media: rc: Directly use ida_free() (Keliu)
- media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann)
- btrfs: fix clearing of BTRFS_FS_RELOC_RUNNING if relocation already running (Filipe Manana)
- ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey) [Orabug: 38649222] {CVE-2025-40167}
- jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi)
- r8152: add error handling in rtl8152_driver_init (Yi Cong)
- LTS version: v5.15.195 (Vijayendra Suman)
- selftests: mptcp: join: validate C-flag + def limit (Matthieu Baerts)
- mptcp: pm: in-kernel: usable client side with C-flag (Matthieu Baerts)
- media: pci: ivtv: Add check for DMA map result (Mikhail Kobuk) [Orabug: 38641260] {CVE-2024-43877}
- xen/events: Update virq_to_irq on migration (Jason Andryuk)
- media: pci: ivtv: Add missing check after DMA map (Thomas Fourier)
- media: pci/ivtv: switch from 'pci_' to 'dma_' API (Christophe Jaillet)
- arm64: mte: Do not flag the zero page as PG_mte_tagged (Catalin Marinas)
- media: cx18: Add missing check after DMA map (Thomas Fourier)
- media: switch from 'pci_' to 'dma_' API (Christophe Jaillet)
- writeback: Avoid excessively long inode switching times (Jan Kara)
- writeback: Avoid softlockup when switching many inodes (Jan Kara)
- cramfs: Verify inode mode when loading from disk (Tetsuo Handa)
- fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu)
- pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17) [Orabug: 38649275] {CVE-2025-40178}
- minixfs: Verify inode mode when loading from disk (Tetsuo Handa)
- minmax.h: remove some #defines that are only expanded once (David Laight)
- minmax.h: simplify the variants of clamp() (David Laight)
- minmax.h: move all the clamp() definitions after the min/max() ones (David Laight)
- minmax.h: use BUILD_BUG_ON_MSG() for the lo < hi test in clamp() (David Laight)
- minmax.h: reduce the #define expansion of min(), max() and clamp() (David Laight)
- minmax.h: update some comments (David Laight)
- minmax.h: add whitespace around operators and after commas (David Laight)
- minmax: fix up min3() and max3() too (Linus Torvalds)
- minmax: improve macro expansion and type checking (Linus Torvalds)
- minmax: simplify min()/max()/clamp() implementation (Linus Torvalds)
- minmax: don't use max() in situations that want a C constant expression (Linus Torvalds)
- minmax: make generic MIN() and MAX() macros available everywhere (Linus Torvalds)
- minmax: simplify and clarify min_t()/max_t() implementation (Linus Torvalds)
- minmax: add a few more MIN_T/MAX_T users (Linus Torvalds)
- minmax: avoid overly complicated constant expressions in VM code (Linus Torvalds)
- minmax: fix indentation of __cmp_once() and __clamp_once() (David Laight)
- minmax: deduplicate __unconst_integer_typeof() (Andy Shevchenko)
- minmax: Introduce {min,max}_array() (Herve Codina)
- arm64: dts: qcom: sdm845: Fix slimbam num-channels/ees (Stephan Gerhold)
- btrfs: fix the incorrect max_bytes value for find_lock_delalloc_range() (Qu Wenruo)
- fscontext: do not consume log entries when returning -EMSGSIZE (Aleksa Sarai)
- dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing) [Orabug: 38649056] {CVE-2025-40134}
- tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592032] {CVE-2025-40042}
- ksmbd: fix error code overwriting in smb2_get_info_filesystem() (Matvey Kovalev)
- net: usb: asix: hold PM usage ref to avoid PM/MDIO + RTNL deadlock (Oleksij Rempel) [Orabug: 38649002] {CVE-2025-40120}
- mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede)
- mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko)
- mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede)
- media: mc: Clear minor number before put device (Edward Adam Davis) [Orabug: 38649397] {CVE-2025-40197}
- Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher) [Orabug: 38649424] {CVE-2025-40200}
- Squashfs: add additional inode sanity checking (Phillip Lougher)
- ASoC: wcd934x: fix error handling in wcd934x_codec_parse_data() (Ma Ke)
- ASoC: codecs: wcd934x: Simplify with dev_err_probe (Krzysztof Kozlowski)
- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591958] {CVE-2025-40026}
- lib/crypto/curve25519-hacl64: Disable KASAN with clang-17 and older (Nathan Chancellor)
- ext4: free orphan info with kvfree (Jan Kara)
- ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag) [Orabug: 38649329] {CVE-2025-40190}
- ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo)
- ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun)
- ext4: verify orphan file size is not too big (Jan Kara) [Orabug: 38649284] {CVE-2025-40179}
- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia)
- NFSD: Fix destination buffer size in nfsd4_ssc_setup_dul() (Thorsten Blum)
- mm/page_alloc: only set ALLOC_HIGHATOMIC for __GPF_HIGH allocations (Thadeu Lima de Souza Cascardo)
- x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson)
- x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson)
- spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav)
- spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav)
- PCI: tegra194: Fix broken tegra_pcie_ep_raise_msi_irq() (Niklas Cassel)
- PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli)
- PCI/AER: Support errors introduced by PCIe r6.0 (Lukas Wunner)
- PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle)
- PCI/ERR: Fix uevent on failure to recover (Lukas Wunner)
- PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle)
- PCI/sysfs: Ensure devices are powered for config reads (Brian Norris)
- rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson)
- rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal)
- rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal)
- memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni)
- mmc: core: SPI mode remove cmd7 (Rex Chen)
- mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij)
- sparc: fix error handling in scan_one_device() (Ma Ke)
- sparc64: fix hugetlb for sun4u (Anthony Yznaga)
- sctp: Fix MAC comparison to be constant-time (Eric Biggers) [Orabug: 38649450] {CVE-2025-40204}
- scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum)
- pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang)
- powerpc/pseries/msi: Fix potential underflow and leak issue (Nam Cao)
- powerpc/powernv/pci: Fix underflow and leak issue (Nam Cao)
- nvme-pci: Add TUXEDO IBS Gen8 to Samsung sleep quirk (Georg Gottleuber)
- parisc: don't reference obsolete termio struct for TC* constants (Sam James)
- openat2: don't trigger automounts with RESOLVE_NO_XDEV (Askar Safin)
- lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold)
- KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers)
- iommu/vt-d: PRS isn't usable if PDS isn't supported (Lu Baolu)
- iio: imu: inv_icm42600: Drop redundant pm_runtime reinitialization in resume (Sean Nyekjaer)
- init: handle bootloader identifier in kernel parameters (Huacai Chen)
- iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich)
- iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng)
- iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng)
- fs/ntfs3: Fix a resource leak bug in wnd_extend() (Haoxiang Li)
- crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier)
- cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki) [Orabug: 38649365] {CVE-2025-40194}
- copy_sighand: Handle architectures where sizeof(unsigned long) < sizeof(u64) (Simon Schuster)
- bus: mhi: host: Do not use uninitialized 'dev' pointer in mhi_init_irq_setup() (Adam Xue)
- btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento) [Orabug: 38649461] {CVE-2025-40205}
- drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu)
- media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng)
- firmware: meson_sm: fix device leak at probe (Johan Hovold)
- xen/manage: Fix suspend error path (Lukas Wunner)
- xen/events: Cleanup find_virq() return codes (Jason Andryuk)
- ARM: OMAP2+: pm33xx-core: ix device node reference leaks in amx3_idle_init (Miaoqian Lin)
- arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold)
- ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad)
- ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang)
- bpf: Avoid RCU context warning when unpinning htab with internal structs (Kafai Wan)
- gpio: wcd934x: mark the GPIO controller as sleeping (Bartosz Golaszewski)
- gpio: wcd934x: Remove duplicate assignment of of_gpio_n_cells (Andy Shevchenko)
- tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets)
- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581454] {CVE-2025-40019}
- bridge: br_vlan_fill_forward_path_pvid: use br_vlan_group_rcu() (Eric Woudstra)
- drm/amd/display: Properly disable scaling on DCE6 (Timur Kristof)
- drm/amd/display: Properly clear SCL_*_FILTER_CONTROL on DCE6 (Timur Kristof)
- drm/amd/display: Add missing DCE6 SCL_HORZ_FILTER_INIT* SRIs (Timur Kristof)
- drm/amdgpu: Add additional DCE6 SCL registers (Alex Deucher)
- bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6} (Daniel Borkmann) [Orabug: 38649299] {CVE-2025-40183}
- mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T)
- mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T)
- tools build: Align warning options with perf (Leo Yan)
- net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja)
- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima) [Orabug: 38649578] {CVE-2025-40186}
- net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov) [Orabug: 38649311] {CVE-2025-40187}
- drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes) [Orabug: 38643545] {CVE-2025-40111}
- drm/vmwgfx: Copy DRM hash-table code into driver (Thomas Zimmermann)
- s390/cio: unregister the subchannel while purging (Vineeth Vijayan)
- net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter)
- scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557653] {CVE-2025-40001}
- scsi: mvsas: Use sas_task_find_rq() for tagging (John Garry)
- scsi: mvsas: Delete mvs_tag_init() (John Garry)
- scsi: libsas: Add sas_task_find_rq() (John Garry)
- cpufreq: tegra186: Set target frequency for all cpus in policy (Aaron Kling)
- clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari)
- clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney)
- perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan)
- rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring)
- perf util: Fix compression checks returning -1 as bool (Yunseong Kim)
- clk: at91: peripheral: fix return value (Brian Masney)
- libperf event: Ensure tracing data is multiple of 8 sized (Ian Rogers)
- perf evsel: Avoid container_of on a NULL leader (Ian Rogers)
- iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich)
- clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni)
- fs: always return zero on success from replace_fd() (Thomas Weissschuh)
- usb: cdns3: cdnsp-pci: remove redundant pci_disable_device() call (Miaoqian Lin)
- bus: fsl-mc: Check return value of platform_get_resource() (Salah Triki)
- pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591980] {CVE-2025-40030}
- Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38592000] {CVE-2025-40035}
- Input: atmel_mxt_ts - allow reset GPIO to sleep (Marek Vasut)
- nvdimm: ndtest: Return -ENOMEM if devm_kcalloc() fails in ndtest_probe() (Guangshuo Li)
- mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi) [Orabug: 38649149] {CVE-2025-40153}
- ext4: fix checks for orphan inodes (Jan Kara)
- mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski)
- net: nfc: nci: Add parameter validation for packet data (Deepak Sharma)
- fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592047] {CVE-2025-40044}
- uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592066] {CVE-2025-40048}
- Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592076] {CVE-2025-40049}
- net: dlink: handle copy_thresh allocation failure (Moon Yeounsu) [Orabug: 38592097] {CVE-2025-40053}
- net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju)
- nfp: fix RSS hash key size when RSS is not supported (Kohei Enju)
- drivers/base/node: fix double free in register_one_node() (Donet Tom)
- ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592109] {CVE-2025-40055}
- hwrng: ks-sa - fix division by zero in ks_sa_rng_init (Nishanth Menon)
- Bluetooth: MGMT: Fix not exposing debug UUID on MGMT_OP_READ_EXP_FEATURES_INFO (Luiz Augusto von Dentz)
- net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath) [Orabug: 38649095] {CVE-2025-40140}
- RDMA/siw: Always report immediate post SQ errors (Bernard Metzler)
- usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea)
- scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar) [Orabug: 38648980] {CVE-2025-40115}
- ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581444] {CVE-2025-40018}
- NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos)
- coresight: trbe: Return NULL pointer for allocation failures (Leo Yan)
- remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold)
- sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher)
- wifi: ath10k: avoid unnecessary wait for service ready message (Baochen Qiang)
- Documentation: trace: historgram-design: Separate sched_waking histogram section heading and the following diagram (Bagas Sanjaya)
- IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu)
- RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit)
- Revert 'usb: xhci: Avoid Stop Endpoint retry loop if the endpoint seems Running' (Michal Pecio)
- scsi: qla2xxx: Fix incorrect sign of error code in START_SP_W_RETRIES() (Rong Qianfeng)
- scsi: qla2xxx: edif: Fix incorrect sign of error code (Rong Qianfeng)
- ACPI: NFIT: Fix incorrect ndr_desc being reportedin dev_err message (Colin Ian King)
- wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal)
- RDMA/cm: Rate limit destroy CM ID timeout error message (Hakon Bugge)
- drivers/base/node: handle error properly in register_one_node() (Donet Tom)
- watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy)
- netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni)
- iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede)
- fs: ntfs3: Fix integer overflow in run_unpack() (Vitaly Grigoryev)
- ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai) [Orabug: 38649006] {CVE-2025-40121}
- ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai) [Orabug: 38649156] {CVE-2025-40154}
- ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai)
- pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592169] {CVE-2025-40070}
- misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King)
- usb: gadget: configfs: Correctly set use_os_string at bind (William Wu)
- usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao)
- drm/amdkfd: Fix error code sign for EINVAL in svm_ioctl() (Rong Qianfeng)
- tcp: fix __tcp_close() to only send RST when required (Eric Dumazet)
- PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation (Alok Tiwari)
- wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann)
- drm/amdgpu: Power up UVD 3 for FW validation (v2) (Timur Kristof)
- ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng)
- media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong)
- scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier)
- scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel) [Orabug: 38649566] {CVE-2025-40118}
- usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter)
- drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das)
- i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi)
- i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu)
- thermal/drivers/qcom/lmh: Add missing IRQ includes (Dmitry Baryshkov)
- thermal/drivers/qcom: Make LMH select QCOM_SCM (Dmitry Baryshkov)
- tools/nolibc: make time_t robust if __kernel_old_time_t is missing in host headers (Zhouyi Zhou)
- smp: Fix up and expand the smp_call_function_many() kerneldoc (Rafael J. Wysocki)
- bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592204] {CVE-2025-40078}
- selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil)
- i3c: master: svc: Recycle unused IBI slot (Stanley Chu)
- nvmet-fc: move lsop put work to nvmet_fc_ls_req_op (Daniel Wagner) [Orabug: 38649248] {CVE-2025-40171}
- pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig)
- arm64: dts: mediatek: mt8516-pumpkin: Fix machine compatible (AngeloGioacchino Del Regno)
- firmware: firmware: meson-sm: fix compile-test default (Johan Hovold)
- pinctrl: renesas: Use int type to store negative error codes (Rong Qianfeng)
- PM: sleep: core: Clear power.must_resume in noirq suspend error path (Rafael J. Wysocki)
- block: use int to store blk_stack_limits() return value (Rong Qianfeng)
- regulator: scmi: Use int type to store negative error codes (Rong Qianfeng)
- ARM: at91: pm: fix MCKx restore routine (Nicolas Ferre)
- blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan) [Orabug: 38649025] {CVE-2025-40125}
- pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue)
- soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad)
- ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li)
- cpufreq: scmi: Account for malformed DT in scmi_dev_used_by_cpus() (Florian Fainelli)
- libbpf: Fix reuse of DEVMAP (Yureka Lilian)
- regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven)
- x86/vdso: Fix output operand size of RDPID (Uros Bizjak)
- perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592220] {CVE-2025-40081}
- coresight: trbe: Prevent overflow in PERF_IDX2OFF() (Leo Yan)
- selftests: arm64: Check fread return value in exec_target (Bala-Vignesh-Reddy)
- filelock: add FL_RECLAIM to show_fl_flags() macro (Jeff Layton)
- net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591964] {CVE-2025-40027}
- minmax: add in_range() macro (Matthew Wilcox)
- crypto: rng - Ensure set_ent is always present (Herbert Xu) [Orabug: 38643530] {CVE-2025-40109}
- platform/x86: int3472: Check for adev == NULL (Hans de Goede)
- driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki)
- staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait)
- staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait)
- serial: stm32: allow selecting console when the driver is module (Raphael Gallais-Pou)
- hid: fix I2C read buffer overflow in raw_event() for mcp2221 (Arnaud Lecomte)
- perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu)
- dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka)
- wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)
- USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li)
- media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou)
- media: tuner: xc5000: Fix use-after-free in xc5000_release (Duoming Zhou) [Orabug: 38548036] {CVE-2025-39994}
- media: tunner: xc5000: Refactor firmware load (Ricardo Ribalda)
- udp: Fix memory accounting leak. (Kuniyuki Iwashima) [Orabug: 37844324] {CVE-2025-22058}
- KVM: arm64: Fix softirq masking in FPSIMD register saving sequence (Will Deacon) [Orabug: 38513233]
- media: rc: fix races with imon_disconnect() (Larshin Sergey) [Orabug: 38548026] {CVE-2025-39993}
- media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (Duoming Zhou) [Orabug: 38548050] {CVE-2025-39996}
- scsi: target: target_core_configfs: Add length check to avoid buffer overflow (Wang Haoran) [Orabug: 38548058] {CVE-2025-39998}
- LTS version: v5.15.194 (Vijayendra Suman)
- drm/i915/backlight: Return immediately when scale() finds invalid parameters (Guenter Roeck)
- i40e: add validation for ring_len param (Lukasz Czapnik) [Orabug: 38547951,38603025,38607608] {CVE-2025-39973}
- i40e: increase max descriptors for XL710 (Justin Bronder)
- i40e: fix idx validation in config queues msg (Lukasz Czapnik) [Orabug: 38547937] {CVE-2025-39971}
- i40e: fix validation of VF state in get resources (Lukasz Czapnik) [Orabug: 38547928] {CVE-2025-39969}
- mm/hugetlb: fix folio is still mapped when deleted (Tu Jinjiang) [Orabug: 38560480] {CVE-2025-40006}
- mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() (David Hildenbrand)
- fbcon: Fix OOB access in font allocation (Thomas Zimmermann)
- fbcon: fix integer overflow in fbcon_do_set_font (Samasth Norway Ananda) [Orabug: 38547912] {CVE-2025-39967}
- tracing: dynevent: Add a missing lockdown check on dynevent (Masami Hiramatsu) [Orabug: 38581470] {CVE-2025-40021}
- i40e: add mask to apply valid bits for itr_idx (Lukasz Czapnik)
- i40e: add max boundary check for VF filters (Lukasz Czapnik) [Orabug: 38547922] {CVE-2025-39968}
- i40e: fix input validation logic for action_meta (Lukasz Czapnik) [Orabug: 38547932] {CVE-2025-39970}
- i40e: fix idx validation in i40e_validate_queue_map (Lukasz Czapnik) [Orabug: 38547945] {CVE-2025-39972}
- crypto: af_alg - Fix incorrect boolean values in af_alg_ctx (Eric Biggers) [Orabug: 38641289] {CVE-2025-40022}
- crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (Herbert Xu) [Orabug: 38537468,38575792,38575804] {CVE-2025-39964}
- drm/gma500: Fix null dereference in hdmi teardown (Zabelin Nikita) [Orabug: 38560495] {CVE-2025-40011}
- net: dsa: lantiq_gswip: suppress -EINVAL errors for bridge FDB entries added to the CPU port (Vladimir Oltean)
- net: dsa: lantiq_gswip: move gswip_add_single_port_br() call to port_setup() (Vladimir Oltean)
- net: dsa: lantiq_gswip: do also enable or disable cpu port (Martin Schiller)
- selftests: fib_nexthops: Fix creation of non-FDB nexthops (Ido Schimmel)
- nexthop: Forbid FDB status change while nexthop is in a group (Ido Schimmel) [Orabug: 38547971] {CVE-2025-39980}
- bnxt_en: correct offset handling for IPv6 destination address (Alok Tiwari)
- ethernet: rvu-af: Remove slash from the driver name (Petr Malat)
- can: peak_usb: fix shift-out-of-bounds issue (Stephane Grosjean) [Orabug: 38581461] {CVE-2025-40020}
- can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow (Vincent Mailhol)
- can: etas_es58x: sort the includes by alphabetic order (Vincent Mailhol)
- can: etas_es58x: advertise timestamping capabilities and add ioctl support (Vincent Mailhol)
- can: dev: add generic function can_eth_ioctl_hwts() (Vincent Mailhol)
- can: dev: add generic function can_ethtool_op_get_ts_info_hwts() (Vincent Mailhol)
- can: bittiming: replace CAN units with the generic ones from linux/units.h (Vincent Mailhol)
- can: bittiming: allow TDC{V,O} to be zero and add can_tdc_const::tdc{v,o,f}_min (Vincent Mailhol)
- bpf: Reject bpf_timer for PREEMPT_RT (Leon Hwang)
- can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (Geert Uytterhoeven)
- arm64: dts: imx8mp: Correct thermal sensor index (Peng Fan)
- IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (Or Har-Toov)
- usb: core: Add 0x prefix to quirks debug output (Jiayi Li)
- ALSA: usb-audio: Fix build with CONFIG_INPUT=n (Takashi Iwai)
- ALSA: usb-audio: Convert comma to semicolon (Chen Ni)
- ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (Cristian Ciocaltea)
- ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Drop unnecessary parentheses in mixer_quirks (Cristian Ciocaltea)
- ALSA: usb-audio: Fix block comments in mixer_quirks (Cristian Ciocaltea)
- net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (Hans de Goede)
- net: rfkill: gpio: add DT support (Philipp Zabel)
- mptcp: propagate shutdown to subflows when possible (Matthieu Baerts)
- ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer (Namjae Jeon)
- mptcp: set remote_deny_join_id0 on SYN recv (Matthieu Baerts)
- phy: ti: omap-usb2: fix device leak at unbind (Johan Hovold)
- phy: Use device_get_match_data() (Rob Herring)
- phy: broadcom: ns-usb3: fix Wvoid-pointer-to-enum-cast warning (Krzysztof Kozlowski)
- USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (Alan Stern)
- usb: gadget: dummy_hcd: remove usage of list iterator past the loop body (Jakob Koschel)
- xhci: dbc: Fix full DbC transfer ring after several reconnects (Mathias Nyman)
- xhci: dbc: decouple endpoint allocation from initialization (Mathias Nyman)
- serial: sc16is7xx: fix bug in flow control levels init (Hugo Villeneuve)
- drm: bridge: cdns-mhdp8546: Fix missing mutex unlock on error path (Qi Xi)
- drm: bridge: anx7625: Fix NULL pointer dereference with early IRQ (Loic Poulain)
- ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (Colin Ian King)
- ASoC: wm8974: Correct PLL rate rounding (Charles Keepax)
- ASoC: wm8940: Correct typo in control name (Charles Keepax)
- mmc: mvsdio: Fix dma_unmap_sg() nents value (Thomas Fourier)
- btrfs: tree-checker: fix the incorrect inode ref size check (Qu Wenruo)
- power: supply: bq27xxx: restrict no-battery detection to bq27000 (H. Nikolaus Schaller)
- power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (H. Nikolaus Schaller)
- nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (Nathan Chancellor)
- cnic: Fix use-after-free bugs in cnic_delete_task (Duoming Zhou) [Orabug: 38503848] {CVE-2025-39945}
- net: liquidio: fix overflow in octeon_init_instr_queue() (Alexey Nepomnyashih)
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Kuniyuki Iwashima) [Orabug: 38526387] {CVE-2025-39955}
- i40e: remove redundant memory barrier when cleaning Tx descs (Maciej Fijalkowski)
- net: natsemi: fix rx_dropped double accounting on netif_rx() failure (Moon Yeounsu)
- qed: Don't collect too many protection override GRC elements (Jamie Bainbridge) [Orabug: 38503869] {CVE-2025-39949}
- dpaa2-switch: fix buffer pool seeding for control traffic (Ioana Ciornei)
- um: virtio_uml: Fix use-after-free after put_device in probe (Miaoqian Lin)
- cgroup: split cgroup_destroy_wq into 3 workqueues (Chen Ridong) [Orabug: 38503891] {CVE-2025-39953}
- pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch (Geert Uytterhoeven)
- wifi: mac80211: fix incorrect type for ret (Liao Yuanhong)
- ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (Takashi Sakamoto)
- net: hsr: hsr_slave: Fix the promiscuous mode in offload mode (Ravi Gunasekaran)
- mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (Miaohe Lin) [Orabug: 38461847] {CVE-2025-39883}
- drm/i915/power: fix size for for_each_set_bit() in abox iteration (Jani Nikula)
- phy: ti-pipe3: fix device leak at unbind (Johan Hovold)
- phy: tegra: xusb: fix device and OF node leak at probe (Johan Hovold)
- dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (Stephan Gerhold) [Orabug: 38494821] {CVE-2025-39923}
- regulator: sy7636a: fix lifecycle of power good gpio (Andreas Kemnade)
- dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (Anders Roxell)
- hsr: use hsr_for_each_port_rtnl in hsr_port_get_hsr (Hangbin Liu)
- hsr: use rtnl lock when iterating over ports (Hangbin Liu)
- net: hsr: Add VLAN CTAG filter support (Murali Karicheri)
- net: hsr: Add support for MC filtering at the slave device (Murali Karicheri)
- net: hsr: Disable promiscuous mode in offload mode (Ravi Gunasekaran)
- can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB (Anssi Hannula)
- can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (Tetsuo Handa)
- can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (Tetsuo Handa)
- i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (Michal Schmidt) [Orabug: 38494786] {CVE-2025-39911}
- i40e: Use irq_update_affinity_hint() (Nitesh Narayan Lal)
- igb: fix link test skipping when interface is admin down (Kohei Enju)
- tunnels: reset the GSO metadata before reusing the skb (Antoine Tenart)
- net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (Stefan Wahren)
- USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (Fabio Porcedda)
- USB: serial: option: add Telit Cinterion FN990A w/audio compositions (Fabio Porcedda)
- dt-bindings: serial: brcm,bcm7271-uart: Constrain clocks (Krzysztof Kozlowski)
- tty: hvc_console: Call hvc_kick in hvc_write unconditionally (Fabian Vogt)
- Input: i8042 - add TUXEDO InfinityBook Pro Gen10 AMD to i8042 quirk table (Christoffer Sandberg)
- mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (Christophe Kerello)
- mtd: rawnand: stm32_fmc2: Fix dma_map_sg error check (Jack Wang)
- mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (Alexander Sverdlin)
- mtd: nand: raw: atmel: Fix comment in timings preparation (Alexander Dahl)
- mm/khugepaged: fix the address passed to notifier on testing young (Wei Yang)
- libceph: fix invalid accesses to ceph_connection_v1_info (Ilya Dryomov) [Orabug: 38461836] {CVE-2025-39880}
- fuse: prevent overflow in copy_file_range return value (Miklos Szeredi)
- fuse: check if copy_file_range() returns larger than requested size (Miklos Szeredi)
- mtd: rawnand: stm32_fmc2: fix ECC overwrite (Christophe Kerello)
- ocfs2: fix recursive semaphore deadlock in fiemap call (Mark Tinguely) [Orabug: 38461858] {CVE-2025-39885}
- mptcp: sockopt: make sync_socket_options propagate SOCK_KEEPOPEN (Krister Johansen)
- compiler-clang.h: define __SANITIZE_*__ macros only when undefined (Nathan Chancellor)
- EDAC/altera: Delete an inappropriate dma_free_coherent() call (Salah Triki)
- tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. (Kuniyuki Iwashima) [Orabug: 38494796] {CVE-2025-39913}
- NFSv4/flexfiles: Fix layout merge mirror check. (Jonathan Curley)
- tracing: Fix tracing_marker may trigger page fault during preempt_disable (Luo Gengkun)
- NFSv4: Clear the NFS_CAP_XATTR flag if not supported by the server (Trond Myklebust)
- NFSv4: Clear the NFS_CAP_FS_LOCATIONS flag if it is not set (Trond Myklebust)
- mm/rmap: reject hugetlb folios in folio_make_device_exclusive() (David Hildenbrand)
- net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. (Kuniyuki Iwashima) [Orabug: 37901603] {CVE-2025-23143}
- media: i2c: imx214: Fix link frequency validation (Andre Apitzsch)
- media: mtk-vcodec: venc: avoid -Wenum-compare-conditional warning (Arnd Bergmann)
- mm: introduce and use {pgd,p4d}_populate_kernel() (Harry Yoo)
- kunit: kasan_test: disable fortify string checker on kasan_strings() test (Levi Yun)
- xfs: short circuit xfs_growfs_data_private() if delta is zero (Eric Sandeen)
- Revert 'fbdev: Disable sysfb device registration when removing conflicting FBs' (Brett A C Sheffield)
[5.15.0-315.193.2]
- KVM: x86: Don't unnecessarily force masterclock update on vCPU hotplug (Sean Christopherson) [Orabug: 38530514]
- KVM: x86: Expose TSC offset controls to userspace (Oliver Upton) [Orabug: 38530514]
- KVM: x86: Refactor tsc synchronization code (Oliver Upton) [Orabug: 38530514]
- kvm: x86: protect masterclock with a seqcount (Paolo Bonzini) [Orabug: 38530514]
- KVM: x86: Report host tsc and realtime values in KVM_GET_CLOCK (Oliver Upton) [Orabug: 38530514]
- KVM: x86: Fix potential race in KVM_GET_CLOCK (Oliver Upton) [Orabug: 38530514]
- KVM: x86: extract KVM_GET_CLOCK/KVM_SET_CLOCK to separate functions (Paolo Bonzini) [Orabug: 38530514]
- kvm: x86: abstract locking around pvclock_update_vm_gtod_copy (Paolo Bonzini) [Orabug: 38530514]
- Revert 'KVM: x86: Don't unnecessarily force masterclock update on vCPU hotplug' (Dongli Zhang) [Orabug: 38530514]
[5.15.0-315.193.1]
- uek-rpm: Set KFENCE_SAMPLE_INTERVAL to 100. (Imran Khan) [Orabug: 38549476]
- uek-rpm: Enable CONFIG_COMPAT_32BIT_TIME for x86 container kernel (Boris Ostrovsky) [Orabug: 38540641] | IMPORTANT | 2025-12-12 00:00:00+03:00 | ['CVE-2024-43876', 'CVE-2024-43877', 'CVE-2025-22058', 'CVE-2025-23143', 'CVE-2025-38678', 'CVE-2025-39880', 'CVE-2025-39883', 'CVE-2025-39885', 'CVE-2025-39911', 'CVE-2025-39913', 'CVE-2025-39923', 'CVE-2025-39945', 'CVE-2025-39949', 'CVE-2025-39953', 'CVE-2025-39955', 'CVE-2025-39964', 'CVE-2025-39967', 'CVE-2025-39968', 'CVE-2025-39969', 'CVE-2025-39970', 'CVE-2025-39971', 'CVE-2025-39972', 'CVE-2025-39973', 'CVE-2025-39980', 'CVE-2025-39993', 'CVE-2025-39994', 'CVE-2025-39996', 'CVE-2025-39998', 'CVE-2025-40001', 'CVE-2025-40006', 'CVE-2025-40011', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40020', 'CVE-2025-40021', 'CVE-2025-40022', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40035', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40053', 'CVE-2025-40055', 'CVE-2025-40070', 'CVE-2025-40078', 'CVE-2025-40081', 'CVE-2025-40085', 'CVE-2025-40087', 'CVE-2025-40092', 'CVE-2025-40094', 'CVE-2025-40105', 'CVE-2025-40109', 'CVE-2025-40111', 'CVE-2025-40115', 'CVE-2025-40118', 'CVE-2025-40120', 'CVE-2025-40121', 'CVE-2025-40125', 'CVE-2025-40134', 'CVE-2025-40140', 'CVE-2025-40153', 'CVE-2025-40154', 'CVE-2025-40167', 'CVE-2025-40171', 'CVE-2025-40173', 'CVE-2025-40178', 'CVE-2025-40179', 'CVE-2025-40183', 'CVE-2025-40186', 'CVE-2025-40187', 'CVE-2025-40190', 'CVE-2025-40194', 'CVE-2025-40197', 'CVE-2025-40200', 'CVE-2025-40204', 'CVE-2025-40205'] | ['Oracle Linux 8', 'Oracle Linux 9'] | ['CVE-2024-43876', 'CVE-2024-43877', 'CVE-2025-22058', 'CVE-2025-23143', 'CVE-2025-38678', 'CVE-2025-39880', 'CVE-2025-39883', 'CVE-2025-39885', 'CVE-2025-39911', 'CVE-2025-39913', 'CVE-2025-39923', 'CVE-2025-39945', 'CVE-2025-39949', 'CVE-2025-39953', 'CVE-2025-39955', 'CVE-2025-39964', 'CVE-2025-39967', 'CVE-2025-39968', 'CVE-2025-39969', 'CVE-2025-39970', 'CVE-2025-39971', 'CVE-2025-39972', 'CVE-2025-39973', 'CVE-2025-39980', 'CVE-2025-39993', 'CVE-2025-39994', 'CVE-2025-39996', 'CVE-2025-39998', 'CVE-2025-40001', 'CVE-2025-40006', 'CVE-2025-40011', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40020', 'CVE-2025-40021', 'CVE-2025-40022', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40035', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40053', 'CVE-2025-40055', 'CVE-2025-40070', 'CVE-2025-40078', 'CVE-2025-40081', 'CVE-2025-40085', 'CVE-2025-40087', 'CVE-2025-40092', 'CVE-2025-40094', 'CVE-2025-40105', 'CVE-2025-40109', 'CVE-2025-40111', 'CVE-2025-40115', 'CVE-2025-40118', 'CVE-2025-40120', 'CVE-2025-40121', 'CVE-2025-40125', 'CVE-2025-40134', 'CVE-2025-40140', 'CVE-2025-40153', 'CVE-2025-40154', 'CVE-2025-40167', 'CVE-2025-40171', 'CVE-2025-40173', 'CVE-2025-40178', 'CVE-2025-40179', 'CVE-2025-40183', 'CVE-2025-40186', 'CVE-2025-40187', 'CVE-2025-40190', 'CVE-2025-40194', 'CVE-2025-40197', 'CVE-2025-40200', 'CVE-2025-40204', 'CVE-2025-40205', 'ELSA-2025-28048', 'https://linux.oracle.com/cve/CVE-2024-43876.html', 'https://linux.oracle.com/cve/CVE-2024-43877.html', 'https://linux.oracle.com/cve/CVE-2025-22058.html', 'https://linux.oracle.com/cve/CVE-2025-23143.html', 'https://linux.oracle.com/cve/CVE-2025-38678.html', 'https://linux.oracle.com/cve/CVE-2025-39880.html', 'https://linux.oracle.com/cve/CVE-2025-39883.html', 'https://linux.oracle.com/cve/CVE-2025-39885.html', 'https://linux.oracle.com/cve/CVE-2025-39911.html', 'https://linux.oracle.com/cve/CVE-2025-39913.html', 'https://linux.oracle.com/cve/CVE-2025-39923.html', 'https://linux.oracle.com/cve/CVE-2025-39945.html', 'https://linux.oracle.com/cve/CVE-2025-39949.html', 'https://linux.oracle.com/cve/CVE-2025-39953.html', 'https://linux.oracle.com/cve/CVE-2025-39955.html', 'https://linux.oracle.com/cve/CVE-2025-39964.html', 'https://linux.oracle.com/cve/CVE-2025-39967.html', 'https://linux.oracle.com/cve/CVE-2025-39968.html', 'https://linux.oracle.com/cve/CVE-2025-39969.html', 'https://linux.oracle.com/cve/CVE-2025-39970.html', 'https://linux.oracle.com/cve/CVE-2025-39971.html', 'https://linux.oracle.com/cve/CVE-2025-39972.html', 'https://linux.oracle.com/cve/CVE-2025-39973.html', 'https://linux.oracle.com/cve/CVE-2025-39980.html', 'https://linux.oracle.com/cve/CVE-2025-39993.html', 'https://linux.oracle.com/cve/CVE-2025-39994.html', 'https://linux.oracle.com/cve/CVE-2025-39996.html', 'https://linux.oracle.com/cve/CVE-2025-39998.html', 'https://linux.oracle.com/cve/CVE-2025-40001.html', 'https://linux.oracle.com/cve/CVE-2025-40006.html', 'https://linux.oracle.com/cve/CVE-2025-40011.html', 'https://linux.oracle.com/cve/CVE-2025-40018.html', 'https://linux.oracle.com/cve/CVE-2025-40019.html', 'https://linux.oracle.com/cve/CVE-2025-40020.html', 'https://linux.oracle.com/cve/CVE-2025-40021.html', 'https://linux.oracle.com/cve/CVE-2025-40022.html', 'https://linux.oracle.com/cve/CVE-2025-40026.html', 'https://linux.oracle.com/cve/CVE-2025-40027.html', 'https://linux.oracle.com/cve/CVE-2025-40030.html', 'https://linux.oracle.com/cve/CVE-2025-40035.html', 'https://linux.oracle.com/cve/CVE-2025-40042.html', 'https://linux.oracle.com/cve/CVE-2025-40044.html', 'https://linux.oracle.com/cve/CVE-2025-40048.html', 'https://linux.oracle.com/cve/CVE-2025-40049.html', 'https://linux.oracle.com/cve/CVE-2025-40053.html', 'https://linux.oracle.com/cve/CVE-2025-40055.html', 'https://linux.oracle.com/cve/CVE-2025-40070.html', 'https://linux.oracle.com/cve/CVE-2025-40078.html', 'https://linux.oracle.com/cve/CVE-2025-40081.html', 'https://linux.oracle.com/cve/CVE-2025-40085.html', 'https://linux.oracle.com/cve/CVE-2025-40087.html', 'https://linux.oracle.com/cve/CVE-2025-40092.html', 'https://linux.oracle.com/cve/CVE-2025-40094.html', 'https://linux.oracle.com/cve/CVE-2025-40105.html', 'https://linux.oracle.com/cve/CVE-2025-40109.html', 'https://linux.oracle.com/cve/CVE-2025-40111.html', 'https://linux.oracle.com/cve/CVE-2025-40115.html', 'https://linux.oracle.com/cve/CVE-2025-40118.html', 'https://linux.oracle.com/cve/CVE-2025-40120.html', 'https://linux.oracle.com/cve/CVE-2025-40121.html', 'https://linux.oracle.com/cve/CVE-2025-40125.html', 'https://linux.oracle.com/cve/CVE-2025-40134.html', 'https://linux.oracle.com/cve/CVE-2025-40140.html', 'https://linux.oracle.com/cve/CVE-2025-40153.html', 'https://linux.oracle.com/cve/CVE-2025-40154.html', 'https://linux.oracle.com/cve/CVE-2025-40167.html', 'https://linux.oracle.com/cve/CVE-2025-40171.html', 'https://linux.oracle.com/cve/CVE-2025-40173.html', 'https://linux.oracle.com/cve/CVE-2025-40178.html', 'https://linux.oracle.com/cve/CVE-2025-40179.html', 'https://linux.oracle.com/cve/CVE-2025-40183.html', 'https://linux.oracle.com/cve/CVE-2025-40186.html', 'https://linux.oracle.com/cve/CVE-2025-40187.html', 'https://linux.oracle.com/cve/CVE-2025-40190.html', 'https://linux.oracle.com/cve/CVE-2025-40194.html', 'https://linux.oracle.com/cve/CVE-2025-40197.html', 'https://linux.oracle.com/cve/CVE-2025-40200.html', 'https://linux.oracle.com/cve/CVE-2025-40204.html', 'https://linux.oracle.com/cve/CVE-2025-40205.html', 'https://linux.oracle.com/errata/ELSA-2025-28048.html'] | 5f0ed4ab3e23ab6af0fc1f439b63f5df5f6c94e66c9e23b5e8a0c4e992871efe | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528040 | ELSA-2025-28040: Unbreakable Enterprise kernel security update (IMPORTANT) | [6.12.0-106.55.4.1]
- netfilter: nf_tables: reject duplicate device on updates (Pablo Neira Ayuso) [Orabug: 38712798] {CVE-2025-38678}
[6.12.0-106.55.4]
- ice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw() (Mateusz Polchlopek) [Orabug: 37844696] {CVE-2025-22117}
[6.12.0-106.55.3]
- uek-rpm: kabi: Remove the kabi protection for debug kernels (Yifei Liu) [Orabug: 38594966]
- Revert 'mptcp: disable by default' (Harshvardhan Jha) [Orabug: 38277777]
[6.12.0-106.55.2]
- LTS version: v6.12.55 (Jack Vogel)
- dmaengine: Add missing cleanup on module unload (Guenter Roeck)
- arm64: errata: Apply workarounds for Neoverse-V3AE (Mark Rutland)
- arm64: cputype: Add Neoverse-V3AE definitions (Mark Rutland)
- mm/ksm: fix flag-dropping behavior in ksm_madvise (Jakub Acs) [Orabug: 38592024] {CVE-2025-40040}
- NFSD: Define a proc_layoutcommit for the FlexFiles layout type (Chuck Lever) [Orabug: 38601817] {CVE-2025-40087}
- phy: cadence: cdns-dphy: Update calibration wait time for startup state machine (Devarsh Thakkar)
- mptcp: reset blackhole on success with non-loopback ifaces (Matthieu Baerts)
- mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable(). (Kuniyuki Iwashima)
- mptcp: Call dst_release() in mptcp_active_enable(). (Kuniyuki Iwashima)
- net: Add locking to protect skb->dev access in ip_output (Sharath Chandra Vurukala)
- ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu] (Eric Dumazet)
- net: dst: add four helpers to annotate data-races around dst->dev (Eric Dumazet)
- tcp: cache RTAX_QUICKACK metric in a hot cache line (Eric Dumazet)
- tcp: convert to dev_net_rcu() (Eric Dumazet)
- ixgbevf: fix mailbox API compatibility by negotiating supported features (Jedrzej Jagielski) [Orabug: 38601914] {CVE-2025-40104}
- ixgbevf: fix getting link speed data for E610 devices (Jedrzej Jagielski)
- vfs: Don't leak disconnected dentries on umount (Jan Kara) [Orabug: 38601921] {CVE-2025-40105}
- d_alloc_parallel(): set DCACHE_PAR_LOOKUP earlier (Al Viro)
- x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID (Babu Moger)
- x86/resctrl: Refactor resctrl_arch_rmid_read() (Babu Moger)
- md: fix mssing blktrace bio split events (Yu Kuai)
- padata: Reset next CPU when reorder sequence wraps around (Xiao Liang)
- xfs: use deferred intent items for reaping crosslinked blocks (Darrick J. Wong)
- wifi: rtw89: avoid possible TX wait initialization race (Fedor Pchelkin)
- NFSD: Fix last write offset handling in layoutcommit (Sergey Bashirov)
- NFSD: Implement large extent array support in pNFS (Sergey Bashirov)
- NFSD: Minor cleanup in layoutcommit processing (Sergey Bashirov)
- NFSD: Rework encoding and decoding of nfsd4_deviceid (Sergey Bashirov)
- nfsd: Drop dprintk in blocklayout xdr functions (Sergey Bashirov)
- nfsd: Use correct error code when decoding extents (Sergey Bashirov)
- iio: imu: inv_icm42600: Avoid configuring if already pm_runtime suspended (Sean Nyekjaer)
- iio: imu: inv_icm42600: Simplify pm_runtime setup (Sean Nyekjaer)
- PM: runtime: Add new devm functions (Csokas Bence)
- phy: cadence: cdns-dphy: Fix PLL lock and O_CMN_READY polling (Devarsh Thakkar)
- phy: cdns-dphy: Store hs_clk_rate and return it (Tomi Valkeinen)
- xfs: fix log CRC mismatches between i386 and other architectures (Christoph Hellwig)
- xfs: rename the old_crc variable in xlog_recover_process (Christoph Hellwig)
- hfsplus: fix slab-out-of-bounds read in hfsplus_strcasecmp() (Viacheslav Dubeyko)
- nvme/tcp: handle tls partially sent records in write_space() (Wilfred Mallawa)
- selftests: arg_parsing: Ensure data is flushed to disk before reading. (Xing Guo)
- ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf() fails (Li Qiang)
- HID: multitouch: fix name of Stylus input devices (Thadeu Lima de Souza Cascardo)
- HID: hid-input: only ignore 0 battery events for digitizers (Dmitry Torokhov)
- ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card (Jiaming Zhang) [Orabug: 38597092] {CVE-2025-40085}
- selftests/bpf: make arg_parsing.c more robust to crashes (Andrii Nakryiko)
- accel/qaic: Synchronize access to DBC request queue head & tail pointer (Pranjal Ramajor Asha Kanojiya)
- accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() (Youssef Samir)
- accel/qaic: Fix bootlog initialization ordering (Jeffrey Hugo)
- ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings (Randy Dunlap)
- sched/fair: Fix pelt lost idle time detection (Vincent Guittot)
- drm/rockchip: vop2: use correct destination rectangle height check (Alok Tiwari)
- drm/draw: fix color truncation in drm_draw_fill24 (Francesco Valla)
- drm/amd/powerplay: Fix CIK shutdown temperature (Timur Kristof)
- drm/amdgpu: fix handling of harvesting for ip_discovery firmware (Alex Deucher)
- drm/amdgpu: add support for cyan skillfish without IP discovery (Alex Deucher)
- drm/amdgpu: add ip offset support for cyan skillfish (Alex Deucher)
- drm/i915/guc: Skip communication warning on reset in progress (Zhanjun Dong)
- ASoC: nau8821: Add DMI quirk to bypass jack debounce circuit (Cristian Ciocaltea)
- ASoC: nau8821: Generalize helper to clear IRQ status (Cristian Ciocaltea)
- ASoC: nau8821: Cancel jdet_work before handling jack ejection (Cristian Ciocaltea)
- ASoC: codecs: Fix gain setting ranges for Renesas IDT821034 codec (Christophe Leroy)
- drm/bridge: lt9211: Drop check for last nibble of version register (Marek Vasut)
- riscv: kprobes: Fix probe address validation (Fabian Vogt)
- nvme-multipath: Skip nr_active increments in RETRY disposition (Amit Chaudhary)
- drm/panthor: Ensure MCU is disabled on suspend (Ketil Johnsen)
- net: usb: lan78xx: fix use of improperly initialized dev->chipid in lan78xx_reset (I Viswanath)
- net: usb: lan78xx: Add error handling to lan78xx_init_mac_address (Oleksij Rempel)
- netdevsim: set the carrier when the device goes up (Breno Leitao)
- tls: don't rely on tx_work during send() (Sabrina Dubroca)
- tls: wait for pending async decryptions if tls_strp_msg_hold fails (Sabrina Dubroca)
- tls: always set record_type in tls_process_cmsg (Sabrina Dubroca)
- tls: wait for async encrypt in case of error during latter iterations of sendmsg (Sabrina Dubroca)
- tls: trim encrypted message to match the plaintext on short splice (Sabrina Dubroca)
- tg3: prevent use of uninitialized remote_adv and local_adv variables (Alexey Simakov)
- ksmbd: fix recursive locking in RPC handle list access (Marios Makassikis)
- tcp: fix tcp_tso_should_defer() vs large RTT (Eric Dumazet)
- amd-xgbe: Avoid spurious link down messages during interface toggle (Raju Rangoju)
- net/ip6_tunnel: Prevent perpetual tunnel growth (Dmitry Safonov)
- r8169: fix packet truncation after S4 resume on RTL8168H/RTL8111H (Linmao Li)
- doc: fix seg6_flowlabel path (Nicolas Dichtel)
- net: dlink: handle dma_map_single() failure properly (Moon Yeounsu)
- can: m_can: fix CAN state in system PM (Marc Kleine-Budde)
- can: m_can: call deinit/init callback when going into suspend/resume (Sean Nyekjaer)
- can: m_can: add deinit callback (Sean Nyekjaer)
- can: m_can: m_can_chip_config(): bring up interface in correct state (Marc Kleine-Budde)
- can: m_can: m_can_handle_state_errors(): fix CAN state transition to Error Active (Marc Kleine-Budde)
- can: m_can: m_can_plat_remove(): add missing pm_runtime_disable() (Marc Kleine-Budde)
- dax: skip read lock assertion for read-only filesystems (Yuezhang Mo)
- HID: multitouch: fix sticky fingers (Benjamin Tissoires)
- Revert 'io_uring/rw: drop -EOPNOTSUPP check in __io_complete_rw_common()' (Jens Axboe)
- cpufreq: CPPC: Avoid using CPUFREQ_ETERNAL as transition delay (Rafael J. Wysocki)
- usb: gadget: f_rndis: Refactor bind path to use __free() (Kuen-Han Tsai)
- usb: gadget: f_ecm: Refactor bind path to use __free() (Kuen-Han Tsai)
- usb: gadget: f_acm: Refactor bind path to use __free() (Kuen-Han Tsai)
- usb: gadget: f_ncm: Refactor bind path to use __free() (Kuen-Han Tsai)
- usb: gadget: Introduce free_usb_request helper (Kuen-Han Tsai)
- usb: gadget: Store endpoint pointer in usb_request (Kuen-Han Tsai)
- drm/exynos: exynos7_drm_decon: remove ctx->suspended (Kaustabh Chakraborty)
- drm/exynos: exynos7_drm_decon: properly clear channels during bind (Kaustabh Chakraborty)
- drm/exynos: exynos7_drm_decon: fix uninitialized crtc reference in functions (Kaustabh Chakraborty)
- media: nxp: imx8-isi: m2m: Fix streaming cleanup on release (Guoniu Zhou)
- media: nxp: imx8-isi: Drop unused argument to mxc_isi_channel_chain() (Laurent Pinchart)
- drm/msm/a6xx: Fix PDC sleep sequence (Akhil P Oommen)
- cdx: Fix device node reference leak in cdx_msi_domain_init (Miaoqian Lin)
- irqdomain: cdx: Switch to of_fwnode_handle() (Jiri Slaby)
- drm/amd: Check whether secure display TA loaded successfully (Mario Limonciello)
- perf/core: Fix MMAP2 event device with backing files (Adrian Hunter)
- perf/core: Fix MMAP event path names with backing files (Adrian Hunter)
- perf/core: Fix address filter match with backing files (Adrian Hunter)
- drm/amdgpu: fix gfx12 mes packet status return check (Jonathan Kim)
- drm/amdgpu: use atomic functions with memory barriers for vm fault info (Gui-Dong Han)
- drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies (Tvrtko Ursulin) [Orabug: 38601869] {CVE-2025-40096}
- cifs: parse_dfs_referrals: prevent oob on malformed input (Eugene Korenevsky) [Orabug: 38601876] {CVE-2025-40099}
- can: gs_usb: increase max interface to U8_MAX (Celeste Liu)
- can: gs_usb: gs_make_candev(): populate net_device->dev_port (Celeste Liu)
- btrfs: do not assert we found block group item when creating free space tree (Filipe Manana) [Orabug: 38601884] {CVE-2025-40100}
- btrfs: fix memory leaks when rejecting a non SINGLE data profile without an RST (Miquel Sabate Sola) [Orabug: 38601892] {CVE-2025-40101}
- btrfs: fix incorrect readahead expansion length (Boris Burkov)
- btrfs: fix memory leak on duplicated memory in the qgroup assign ioctl (Miquel Sabate Sola)
- btrfs: fix clearing of BTRFS_FS_RELOC_RUNNING if relocation already running (Filipe Manana)
- ext4: detect invalid INLINE_DATA + EXTENTS flag combination (Deepanshu Kartikey)
- ext4: wait for ongoing I/O to complete before freeing blocks (Zhang Yi)
- jbd2: ensure that all ongoing I/O complete before freeing blocks (Zhang Yi)
- f2fs: fix wrong block mapping for multi-devices (Jaegeuk Kim)
- r8152: add error handling in rtl8152_driver_init (Yi Cong)
- slab: reset slab->obj_ext when freeing and it is OBJEXTS_ALLOC_FAIL (Hao Ge)
- smb: client: Fix refcount leak for cifs_sb_tlink (Shuhao Fu) [Orabug: 38601903] {CVE-2025-40103}
- rust: cfi: only 64-bit arm and x86 support CFI_CLANG (Conor Dooley)
- drm/xe/guc: Check GuC running state before deregistering exec queue (Shuicheng Lin)
- LTS version: v6.12.54 (Jack Vogel)
- nfsd: decouple the xprtsec policy check from check_nfsd_access() (Scott Mayhew)
- mount: handle NULL values in mnt_ns_release() (Christian Brauner)
- ASoC: SOF: ipc4-pcm: fix start offset calculation for chain DMA (Kai Vehmanen)
- nfsd: fix access checking for NLM under XPRTSEC policies (Olga Kornievskaia)
- nfsd: fix __fh_verify for localio (Olga Kornievskaia)
- perf test stat: Avoid hybrid assumption when virtualized (Ian Rogers)
- sched/fair: Block delayed tasks on throttled hierarchy during dequeue (K Prateek Nayak)
- writeback: Avoid excessively long inode switching times (Jan Kara)
- writeback: Avoid softlockup when switching many inodes (Jan Kara)
- cramfs: Verify inode mode when loading from disk (Tetsuo Handa)
- fs: Add 'initramfs_options' to set initramfs mount options (Lichen Liu)
- pid: Add a judgment for ns null in pid_nr_ns (Gaoxiang17)
- minixfs: Verify inode mode when loading from disk (Tetsuo Handa)
- copy_file_range: limit size if in compat mode (Miklos Szeredi)
- irqchip/sifive-plic: Avoid interrupt ID 0 handling during suspend/resume (Lucas Zampieri)
- irqchip/sifive-plic: Make use of __assign_bit() (Hongbo Li)
- s390/bpf: Write back tail call counter for BPF_TRAMP_F_CALL_ORIG (Ilya Leoshkevich)
- s390/bpf: Write back tail call counter for BPF_PSEUDO_CALL (Ilya Leoshkevich)
- s390/bpf: Describe the frame using a struct instead of constants (Ilya Leoshkevich)
- s390/bpf: Centralize frame offset calculations (Ilya Leoshkevich)
- mm/rmap: fix soft-dirty and uffd-wp bit loss when remapping zero-filled mTHP subpage to shared zeropage (Lance Yang)
- ipmi: Fix handling of messages with provided receive message pointer (Guenter Roeck)
- ipmi: Rework user message limit handling (Corey Minyard)
- mptcp: pm: in-kernel: usable client side with C-flag (Matthieu Baerts)
- ACPI: property: Do not pass NULL handles to acpi_attach_data() (Rafael J. Wysocki)
- ACPI: property: Add code comments explaining what is going on (Rafael J. Wysocki)
- ACPI: property: Disregard references in data-only subnode lists (Rafael J. Wysocki)
- ACPI: battery: Add synchronization between interface updates (Rafael J. Wysocki)
- ACPI: battery: Check for error code from devm_mutex_init() call (Andy Shevchenko)
- ACPI: battery: initialize mutexes through devm_ APIs (Thomas Weissschuh)
- ACPI: battery: allocate driver data through devm_ APIs (Thomas Weissschuh)
- nfsd: unregister with rpcbind when deleting a transport (Olga Kornievskaia)
- nfsd: don't use sv_nrthreads in connection limiting calculations. (Neil Brown)
- nfsd: refine and rename NFSD_MAY_LOCK (Neil Brown)
- NFSD: Replace use of NFSD_MAY_LOCK in nfsd4_lock() (Chuck Lever)
- nfsd: Fix NFSD_MAY_BYPASS_GSS and NFSD_MAY_BYPASS_GSS_ON_ROOT (Pali Rohar)
- x86/kvm: Force legacy PCI hole to UC when overriding MTRRs for TDX/SNP (Sean Christopherson)
- x86/mtrr: Rename mtrr_overwrite_state() to guest_force_mtrr_state() (Kirill A. Shutemov)
- arm64: mte: Do not flag the zero page as PG_mte_tagged (Catalin Marinas)
- statmount: don't call path_put() under namespace semaphore (Christian Brauner)
- cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition latency (Rafael J. Wysocki)
- btrfs: fix the incorrect max_bytes value for find_lock_delalloc_range() (Qu Wenruo)
- mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config flag (Hans de Goede)
- mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for cache_type (Andy Shevchenko)
- mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config max_register value (Hans de Goede)
- ASoC: SOF: ipc4-pcm: fix delay calculation when DSP resamples (Kai Vehmanen)
- ASoC: SOF: ipc4-pcm: Enable delay reporting for ChainDMA streams (Peter Ujfalusi)
- PCI: endpoint: pci-epf-test: Add NULL check for DMA channels before release (Shin'Ichiro Kawasaki)
- PCI: endpoint: Remove surplus return statement from pci_epf_test_clean_dma_chan() (Wang Jiang)
- mm/ksm: fix incorrect KSM counter handling in mm_struct during fork (Donet Tom)
- tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (Yuan Chen) [Orabug: 38592031] {CVE-2025-40042}
- Squashfs: reject negative file sizes in squashfs_read_inode() (Phillip Lougher)
- Squashfs: add additional inode sanity checking (Phillip Lougher)
- media: mc: Clear minor number before put device (Edward Adam Davis)
- selftests/mm: skip soft-dirty tests when CONFIG_MEM_SOFT_DIRTY is disabled (Lance Yang)
- lib/crypto/curve25519-hacl64: Disable KASAN with clang-17 and older (Nathan Chancellor)
- ext4: free orphan info with kvfree (Jan Kara)
- ACPICA: Allow to skip Global Lock initialization (Huacai Chen)
- ext4: validate ea_ino and size in check_xattrs (Deepanshu Kartikey)
- ext4: guard against EA inode refcount underflow in xattr update (Ahmet Eray Karadag)
- ext4: fix an off-by-one issue during moving extents (Zhang Yi)
- ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() (Theodore Ts'O)
- ext4: correctly handle queries for metadata mappings (Ojaswin Mujoo)
- ext4: increase i_disksize to offset + len in ext4_update_disksize_before_punch() (Yongjian Sun)
- ext4: verify orphan file size is not too big (Jan Kara)
- ext4: add ext4_sb_bread_nofail() helper function for ext4_free_branches() (Baokun Li)
- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia)
- NFSD: Fix destination buffer size in nfsd4_ssc_setup_dul() (Thorsten Blum)
- mm/damon/lru_sort: use param_ctx for damon_attrs staging (Seongjae Park)
- mm/damon/vaddr: do not repeat pte_offset_map_lock() until success (Seongjae Park)
- mm/hugetlb: early exit from hugetlb_pages_alloc_boot() when max_huge_pages=0 (Li Rongqing)
- mm/page_alloc: only set ALLOC_HIGHATOMIC for __GPF_HIGH allocations (Thadeu Lima de Souza Cascardo)
- mm/thp: fix MTE tag mismatch when replacing zero-filled subpages (Lance Yang)
- wifi: mt76: mt7921u: Add VID/PID for Netgear A7500 (Nick Morrow)
- wifi: mt76: mt7925u: Add VID/PID for Netgear A9000 (Nick Morrow)
- wifi: ath11k: HAL SRNG: don't deinitialize and re-initialize again (Muhammad Usama Anjum)
- slab: mark slab->obj_exts allocation failures unconditionally (Suren Baghdasaryan)
- slab: prevent warnings when slab obj_exts vector allocation fails (Suren Baghdasaryan)
- s390: Add -Wno-pointer-sign to KBUILD_CFLAGS_DECOMPRESSOR (Heiko Carstens)
- s390/dasd: Return BLK_STS_INVAL for EINVAL from do_dasd_request (Jaehoon Kim)
- s390/dasd: enforce dma_alignment to ensure proper buffer validation (Jaehoon Kim)
- selftests: mptcp: join: validate C-flag + def limit (Matthieu Baerts)
- x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) (Sean Christopherson)
- x86/umip: Check that the instruction opcode is at least two bytes (Sean Christopherson)
- x86/fred: Remove ENDBR64 from FRED entry points (Xin Li)
- spi: cadence-quadspi: Fix cqspi_setup_flash() (Santhosh Kumar K)
- spi: cadence-quadspi: Flush posted register writes before DAC access (Pratyush Yadav)
- spi: cadence-quadspi: Flush posted register writes before INDAC access (Pratyush Yadav)
- PCI: tegra194: Reset BARs when running in PCIe endpoint mode (Niklas Cassel)
- PCI: tegra194: Handle errors in BPMP response (Vidya Sagar)
- PCI: tegra194: Fix broken tegra_pcie_ep_raise_msi_irq() (Niklas Cassel)
- PCI: rcar-host: Convert struct rcar_msi mask_lock into raw spinlock (Marek Vasut)
- PCI: rcar-host: Drop PMSR spinlock (Marek Vasut)
- PCI: rcar-gen4: Fix PHY initialization (Marek Vasut)
- PCI: keystone: Use devm_request_irq() to free 'ks-pcie-error-irq' on exit (Siddharth Vadapalli)
- PCI: j721e: Fix programming sequence of 'strap' settings (Siddharth Vadapalli)
- PCI/AER: Support errors introduced by PCIe r6.0 (Lukas Wunner)
- PCI/AER: Fix missing uevent on recovery when a reset is requested (Niklas Schnelle)
- PCI/ERR: Fix uevent on failure to recover (Lukas Wunner)
- PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV (Niklas Schnelle)
- PCI/sysfs: Ensure devices are powered for config reads (Brian Norris)
- PCI: tegra: Convert struct tegra_msi mask_lock into raw spinlock (Marek Vasut)
- PCI: xilinx-nwl: Fix ECAM programming (Jani Nurminen)
- rseq/selftests: Use weak symbol reference, not definition, to link with glibc (Sean Christopherson)
- rtc: interface: Fix long-standing race when setting alarm (Esben Haabendal)
- rtc: interface: Ensure alarm irq is enabled when UIE is enabled (Esben Haabendal)
- memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (Zhen Ni)
- mmc: mmc_spi: multiple block read remove read crc ack (Rex Chen)
- mmc: core: SPI mode remove cmd7 (Rex Chen)
- mtd: rawnand: fsmc: Default to autodetect buswidth (Linus Walleij)
- xsk: Harden userspace-supplied xdp_desc validation (Alexander Lobakin)
- xtensa: simdisk: add input size check in proc_write_simdisk (Miaoqian Lin)
- sparc: fix error handling in scan_one_device() (Ma Ke)
- sparc64: fix hugetlb for sun4u (Anthony Yznaga)
- sctp: Fix MAC comparison to be constant-time (Eric Biggers)
- scsi: sd: Fix build warning in sd_revalidate_disk() (Abinash Lalotra)
- scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (Thorsten Blum)
- sched/deadline: Fix race in push_dl_task() (Harshit Agarwal)
- Revert 'ipmi: fix msg stack when IPMI is disconnected' (Corey Minyard)
- pwm: berlin: Fix wrong register in suspend/resume (Jisheng Zhang)
- powerpc/pseries/msi: Fix potential underflow and leak issue (Nam Cao)
- powerpc/powernv/pci: Fix underflow and leak issue (Nam Cao)
- power: supply: max77976_charger: fix constant current reporting (Dzmitry Sankouski)
- pinctrl: samsung: Drop unused S3C24xx driver data (Krzysztof Kozlowski)
- nvme-pci: Add TUXEDO IBS Gen8 to Samsung sleep quirk (Georg Gottleuber)
- parisc: Remove spurious if statement from raw_copy_from_user() (John David Anglin)
- parisc: don't reference obsolete termio struct for TC* constants (Sam James)
- openat2: don't trigger automounts with RESOLVE_NO_XDEV (Askar Safin)
- of: unittest: Fix device reference count leak in of_unittest_pci_node_verify (Ma Ke)
- loop: fix backing file reference leak on validation error (Li Chen)
- lib/genalloc: fix device leak in of_gen_pool_get() (Johan Hovold)
- KEYS: trusted_tpm1: Compare HMAC values in constant time (Eric Biggers)
- kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths (Oleg Nesterov)
- iommu/vt-d: PRS isn't usable if PDS isn't supported (Lu Baolu)
- iio: imu: inv_icm42600: Drop redundant pm_runtime reinitialization in resume (Sean Nyekjaer)
- init: handle bootloader identifier in kernel parameters (Huacai Chen)
- iio: xilinx-ams: Unmask interrupts after updating alarms (Sean Anderson)
- iio: xilinx-ams: Fix AMS_ALARM_THR_DIRECT_MASK (Sean Anderson)
- iio: frequency: adf4350: Fix prescaler usage. (Michael Hennerich)
- iio: dac: ad5421: use int type to store negative error codes (Rong Qianfeng)
- iio: dac: ad5360: use int type to store negative error codes (Rong Qianfeng)
- iio/adc/pac1934: fix channel disable configuration (Aleksandar Gerasimovski)
- fuse: fix livelock in synchronous file put from fuseblk workers (Darrick J. Wong)
- fuse: fix possibly missing fuse_copy_finish() call in fuse_notify() (Miklos Szeredi)
- fs: quota: create dedicated workqueue for quota_release_work (Shashank A P)
- fs/ntfs3: Fix a resource leak bug in wnd_extend() (Haoxiang Li)
- fbdev: Fix logic error in 'offb' name match (Finn Thain)
- eventpoll: Replace rwlock with spinlock (Nam Cao)
- crypto: rockchip - Fix dma_unmap_sg() nents value (Thomas Fourier)
- crypto: atmel - Fix dma_unmap_sg() direction (Thomas Fourier)
- crypto: aspeed - Fix dma_unmap_sg() direction (Thomas Fourier)
- cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (Rafael J. Wysocki)
- copy_sighand: Handle architectures where sizeof(unsigned long) < sizeof(u64) (Simon Schuster)
- clk: qcom: tcsrcc-x1e80100: Set the bi_tcxo as parent to eDP refclk (Abel Vesa)
- bus: mhi: host: Do not use uninitialized 'dev' pointer in mhi_init_irq_setup() (Adam Xue)
- bus: mhi: ep: Fix chained transfer handling in read path (Sumit Kumar)
- btrfs: avoid potential out-of-bounds in btrfs_encode_fh() (Anderson Nascimento)
- blk-crypto: fix missing blktrace bio split events (Yu Kuai)
- drm/amd/display: Enable Dynamic DTBCLK Switch (Fangzhi Zuo)
- drm/xe/uapi: loosen used tracking restriction (Matthew Auld)
- drm/nouveau: fix bad ret code in nouveau_bo_move_prep (Shuhao Fu)
- drm/rcar-du: dsi: Fix 1/2/3 lane support (Marek Vasut)
- drm/panthor: Fix memory leak in panthor_ioctl_group_create() (Jann Horn)
- media: lirc: Fix error handling in lirc_register() (Ma Ke)
- media: ti: j721e-csi2rx: Fix source subdev link creation (Jai Luthra)
- media: ti: j721e-csi2rx: Use devm_of_platform_populate (Jai Luthra)
messages (Hans Verkuil)
- media: venus: firmware: Use correct reset sequence for IRIS2 (Stephan Gerhold)
- media: s5p-mfc: remove an unused/uninitialized variable (Arnd Bergmann)
- media: pci: mg4b: fix uninitialized iio scan data (David Lechner)
- media: pci: ivtv: Add missing check after DMA map (Thomas Fourier)
- media: mc: Fix MUST_CONNECT handling for pads with no links (Laurent Pinchart)
- media: i2c: mt9v111: fix incorrect type for ret (Rong Qianfeng)
- media: cx18: Add missing check after DMA map (Thomas Fourier)
- media: cec: extron-da-hd-4k-plus: drop external-module make commands (Randy Dunlap)
- firmware: meson_sm: fix device leak at probe (Johan Hovold)
- xen/events: Update virq_to_irq on migration (Jason Andryuk)
- xen/events: Return -EEXIST for bound VIRQs (Jason Andryuk)
- xen/manage: Fix suspend error path (Lukas Wunner)
- xen/events: Cleanup find_virq() return codes (Jason Andryuk)
- dt-bindings: phy: rockchip-inno-csi-dphy: make power-domains non-required (Michael Riesch)
- perf/arm-cmn: Fix CMN S3 DTM offset (Robin Murphy)
- ARM: OMAP2+: pm33xx-core: ix device node reference leaks in amx3_idle_init (Miaoqian Lin)
- ARM: AM33xx: Implement TI advisory 1.0.36 (EMU0/EMU1 pins state on reset) (Alexander Sverdlin)
- arm64: kprobes: call set_memory_rox() for kprobe page (Yang Shi)
- arm64: dts: ti: k3-am62a-main: Fix main padcfg length (Vibhore Vardhan)
- arm64: dts: qcom: x1e80100-pmics: Disable pm8010 by default (Aleksandrs Vinarskis)
- arm64: dts: qcom: sdm845: Fix slimbam num-channels/ees (Stephan Gerhold)
- arm64: dts: qcom: msm8939: Add missing MDSS reset (Stephan Gerhold)
- arm64: dts: qcom: msm8916: Add missing MDSS reset (Stephan Gerhold)
- ACPI: debug: fix signedness issues in read/write helpers (Amir Mohammad Jahangirzad)
- ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (Daniel Tang)
- ACPI: property: Fix buffer properties extraction for subnodes (Rafael J. Wysocki)
- s390/vmlinux.lds.S: Move .vmlinux.info to end of allocatable sections (Nathan Chancellor)
- s390: vmlinux.lds.S: Reorder sections (Alexey Gladkov)
- bpf: Avoid RCU context warning when unpinning htab with internal structs (Kafai Wan)
- gpio: wcd934x: mark the GPIO controller as sleeping (Bartosz Golaszewski)
- tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single (Gunnar Kudrjavets)
- cifs: Query EA in cifs_query_path_info() for WSL reparse points (Pali Rohar)
- smb: client: fix missing timestamp updates after utime(2) (Paulo Alcantara)
- cifs: Fix copy_to_iter return value check (Wangfushuai)
- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38581453] {CVE-2025-40019}
- selftests: netfilter: query conntrack state to check for port clash resolution (Florian Westphal)
- bridge: br_vlan_fill_forward_path_pvid: use br_vlan_group_rcu() (Eric Woudstra)
- netfilter: nft_objref: validate objref and objrefmap expressions (Fernando Fernandez Mancera)
- drm/amd/display: Properly disable scaling on DCE6 (Timur Kristof)
- drm/amd/display: Properly clear SCL_*_FILTER_CONTROL on DCE6 (Timur Kristof)
- drm/amd/display: Add missing DCE6 SCL_HORZ_FILTER_INIT* SRIs (Timur Kristof)
- drm/amdgpu: Add additional DCE6 SCL registers (Alex Deucher)
- mailbox: mtk-cmdq: Remove pm_runtime APIs from cmdq_mbox_send_data() (Jason-JH Lin)
- mailbox: mtk-cmdq: Switch to pm_runtime_put_autosuspend() (Sakari Ailus)
- mailbox: mtk-cmdq-mailbox: Switch to __pm_runtime_put_autosuspend() (Sakari Ailus)
- bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6} (Daniel Borkmann)
- mailbox: zynqmp-ipi: Fix SGI cleanup on unbind (Harini T)
- mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop (Harini T)
- mailbox: zynqmp-ipi: Remove dev.parent check in zynqmp_ipi_free_mboxes (Harini T)
- mailbox: zynqmp-ipi: Remove redundant mbox_controller_unregister() call (Harini T)
- tcp: take care of zero tp->window_clamp in tcp_set_rcvlowat() (Eric Dumazet)
- perf python: split Clang options when invoking Popen (Leo Yan)
- tools build: Align warning options with perf (Leo Yan)
- net: fsl_pq_mdio: Fix device node reference leak in fsl_pq_mdio_probe (Erick Karanja)
- ice: ice_adapter: release xa entry on adapter allocation failure (Xu Wang)
- net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (Duoming Zhou)
- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Kuniyuki Iwashima)
- net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (Alexandr Sapozhnikov)
- drm/vmwgfx: Fix copy-paste typo in validation (Ian Forbes)
- drm/vmwgfx: Fix Use-after-free in validation (Ian Forbes)
- drm/vmwgfx: Fix a null-ptr access in the cursor snooper (Zack Rusin)
- s390/cio: Update purge function to unregister the unused subchannels (Vineeth Vijayan)
- drm/xe/hw_engine_group: Fix double write lock release in error path (Shuicheng Lin)
- net/mlx4: prevent potential use after free in mlx4_en_do_uc_filter() (Dan Carpenter)
- ASoC: SOF: Intel: Read the LLP via the associated Link DMA channel (Peter Ujfalusi)
- LoongArch: Init acpi_gbl_use_global_lock to false (Huacai Chen)
- LoongArch: Add cflag -fno-isolate-erroneous-paths-dereference (Tiezhu Yang)
- ASoC: SOF: Intel: hda-pcm: Place the constraint on period time instead of buffer time (Peter Ujfalusi)
- ASoC: SOF: ipc4-topology: Account for different ChainDMA host buffer size (Peter Ujfalusi)
- ASoC: SOF: ipc4-topology: Correct the minimum host DMA buffer size (Peter Ujfalusi)
- scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (Duoming Zhou) [Orabug: 38557652] {CVE-2025-40001}
- cpufreq: tegra186: Set target frequency for all cpus in policy (Aaron Kling)
- clk: tegra: do not overallocate memory for bpmp clocks (Fedor Pchelkin)
- clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver (Alok Tiwari)
- clk: nxp: lpc18xx-cgu: convert from round_rate() to determine_rate() (Brian Masney)
- clk: mediatek: clk-mux: Do not pass flags to clk_mux_determine_rate_flags() (Chen-Yu Tsai)
- clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m (AngeloGioacchino Del Regno)
- perf evsel: Ensure the fallback message is always written to (Ian Rogers)
- perf tools: Add fallback for exclude_guest (Namhyung Kim)
- perf test: Add a test for default perf stat command (James Clark)
- perf test: Don't leak workload gopipe in PERF_RECORD_* (Ian Rogers)
- perf session: Fix handling when buffer exceeds 2 GiB (Leo Yan)
- perf test shell lbr: Avoid failures with perf event paranoia (Ian Rogers)
- perf test: Update sysfs path for core PMU caps (Namhyung Kim)
- perf vendor events arm64 AmpereOneX: Fix typo - should be l1d_cache_access_prefetches (Ilkka Koskinen)
- perf arm_spe: Correct memory level for remote access (Leo Yan)
- perf arm_spe: Correct setting remote access (Leo Yan)
- rtc: optee: fix memory leak on driver removal (Clement Le Goffic)
- rtc: x1205: Fix Xicor X1205 vendor prefix (Rob Herring)
- perf util: Fix compression checks returning -1 as bool (Yunseong Kim)
- clk: renesas: cpg-mssr: Fix memory leak in cpg_mssr_reserved_init() (Yuan Chen)
- clk: at91: peripheral: fix return value (Brian Masney)
- clk: qcom: common: Fix NULL vs IS_ERR() check in qcom_cc_icc_register() (Dan Carpenter)
- libperf event: Ensure tracing data is multiple of 8 sized (Ian Rogers)
- perf evsel: Avoid container_of on a NULL leader (Ian Rogers)
- perf test trace_btf_enum: Skip if permissions are insufficient (Ian Rogers)
- perf disasm: Avoid undefined behavior in incrementing NULL (Ian Rogers)
- asm-generic/io.h: Skip trace helpers if rwmmio events are disabled (Varad Gautam)
- media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() (Tomi Valkeinen)
- iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (Michael Hennerich)
- KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2 (Sean Christopherson)
- dma-mapping: fix direction in dma_alloc direction traces (Petr Tesarik)
- page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (Toke Hoiland-Jorgensen)
- clocksource/drivers/clps711x: Fix resource leaks in error paths (Zhen Ni)
- listmount: don't call path_put() under namespace semaphore (Christian Brauner)
- rseq: Protect event mask against membarrier IPI (Thomas Gleixner)
- arm64: map [_text, _stext) virtual address range non-executable+read-only (Omar Sandoval)
- fscontext: do not consume log entries when returning -EMSGSIZE (Aleksa Sarai)
- fs: always return zero on success from replace_fd() (Thomas Weissschuh)
- LTS version: v6.12.53 (Jack Vogel)
- usb: cdns3: cdnsp-pci: remove redundant pci_disable_device() call (Miaoqian Lin)
- arm64: dts: qcom: qcm2290: Disable USB SS bus instances in park mode (Konrad Dybcio)
- usb: typec: tipd: Clear interrupts first (Sven Peter)
- net: usb: asix: hold PM usage ref to avoid PM/MDIO + RTNL deadlock (Oleksij Rempel)
- net/9p: Fix buffer overflow in USB transport layer (Dominique Martinet)
- bus: fsl-mc: Check return value of platform_get_resource() (Salah Triki)
- pinctrl: check the return value of pinmux_ops::get_function_name() (Bartosz Golaszewski) [Orabug: 38591979] {CVE-2025-40030}
- tee: fix register_shm_helper() (Jens Wiklander) [Orabug: 38591986] {CVE-2025-40031}
- remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (Zhen Ni)
- sunrpc: fix null pointer dereference on zero-length checksum (Lei Lu)
- Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak (Zhen Ni) [Orabug: 38591999] {CVE-2025-40035}
- Input: atmel_mxt_ts - allow reset GPIO to sleep (Marek Vasut)
- misc: fastrpc: Skip reference for DMA handles (Ling Xu)
- misc: fastrpc: fix possible map leak in fastrpc_put_args (Ling Xu)
- misc: fastrpc: Fix fastrpc_map_lookup operation (Ling Xu)
- misc: fastrpc: Save actual DMA size in fastrpc_map structure (Ling Xu)
- nvdimm: ndtest: Return -ENOMEM if devm_kcalloc() fails in ndtest_probe() (Guangshuo Li)
- mm: hugetlb: avoid soft lockup when mprotect to large memory area (Yang Shi)
- fbdev: simplefb: Fix use after free in simplefb_detach_genpds() (Janne Grunau) [Orabug: 38592013] {CVE-2025-40037}
- KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid (Sean Christopherson) [Orabug: 38592015] {CVE-2025-40038}
- ext4: fix checks for orphan inodes (Jan Kara)
- ksmbd: add max ip connections parameter (Namjae Jeon)
- ksmbd: fix error code overwriting in smb2_get_info_filesystem() (Matvey Kovalev)
- ksmbd: Fix race condition in RPC handle list access (Yunseong Kim)
- LoongArch: Automatically disable kaslr if boot from kexec_file (Youling Tang)
- dm: fix NULL pointer dereference in __dm_suspend() (Zheng Qixing)
- dm: fix queue start/stop imbalance under suspend/load/resume races (Zheng Qixing)
- mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (Bartosz Golaszewski)
- mfd: rz-mtu3: Fix MTU5 NFCR register offset (Cosmin Tanislav)
- net: nfc: nci: Add parameter validation for packet data (Deepak Sharma)
- fs: udf: fix OOB read in lengthAllocDescs handling (Larshin Sergey) [Orabug: 38592045] {CVE-2025-40044}
- ASoC: codecs: wcd937x: make stub functions inline (Srinivas Kandagatla)
- ASoC: codecs: wcd937x: set the comp soundwire port correctly (Srinivas Kandagatla)
- ASoC: SOF: ipc3-topology: Fix multi-core and static pipelines tear down (Ranjani Sridharan)
- ASoC: wcd934x: fix error handling in wcd934x_codec_parse_data() (Ma Ke)
- io_uring/waitid: always prune wait queue entry in io_waitid_wait() (Jens Axboe) [Orabug: 38592063] {CVE-2025-40047}
- uio_hv_generic: Let userspace take care of interrupt mask (Naman Jain) [Orabug: 38592065] {CVE-2025-40048}
- Squashfs: fix uninit-value in squashfs_get_parent (Phillip Lougher) [Orabug: 38592075] {CVE-2025-40049}
- bpf: Reject negative offsets for ALU ops (Yazhou Tang)
- vhost: vringh: Modify the return value check (Zhang Jiao) [Orabug: 38592084] {CVE-2025-40051}
- Revert 'net/mlx5e: Update and set Xon/Xoff upon MTU set' (Jakub Kicinski) [Orabug: 38545203]
- smb: client: fix crypto buffers in non-linear memory (Enzo Matsumiya) [Orabug: 38592090] {CVE-2025-40052}
- net/mlx5: fw reset, add reset timeout work (Moshe Shemesh)
- net/mlx5: pagealloc: Fix reclaim race during command interface teardown (Shay Drory)
- net/mlx5: Stop polling for command response if interface goes down (Moshe Shemesh)
- net: dlink: handle copy_thresh allocation failure (Moon Yeounsu) [Orabug: 38592094] {CVE-2025-40053}
- net: ena: return 0 in ena_get_rxfh_key_size() when RSS hash key is not configurable (Kohei Enju)
- nfp: fix RSS hash key size when RSS is not supported (Kohei Enju)
- idpf: fix mismatched free function for dma_alloc_coherent (Alok Tiwari)
- PCI: j721e: Fix incorrect error message in probe() (Alok Tiwari)
- mtd: rawnand: atmel: Fix error handling path in atmel_nand_controller_add_nands (Erick Karanja)
- drivers/base/node: fix double free in register_one_node() (Donet Tom)
- ocfs2: fix double free in user_cluster_connect() (Dan Carpenter) [Orabug: 38592108] {CVE-2025-40055}
- hwrng: ks-sa - fix division by zero in ks_sa_rng_init (Nishanth Menon)
- KEYS: X.509: Fix Basic Constraints CA flag parsing (Fan Wu)
- Bluetooth: hci_sync: Fix using random address for BIG/PA advertisements (Luiz Augusto von Dentz)
- Bluetooth: ISO: don't leak skb in ISO_CONT RX (Pauli Virtanen)
- Bluetooth: ISO: free rx_skb if not consumed (Pauli Virtanen)
- Bluetooth: ISO: Fix possible UAF on iso_conn_free (Luiz Augusto von Dentz)
- Bluetooth: MGMT: Fix not exposing debug UUID on MGMT_OP_READ_EXP_FEATURES_INFO (Luiz Augusto von Dentz)
- vhost: vringh: Fix copy_to_iter return value check (Michael S. Tsirkin) [Orabug: 38592116] {CVE-2025-40056}
- ptp: Add a upper bound on max_vclocks (I Viswanath) [Orabug: 38592122] {CVE-2025-40057}
- net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (I Viswanath)
- RDMA/siw: Always report immediate post SQ errors (Bernard Metzler)
- iommu/vt-d: Disallow dirty tracking if incoherent page walk (Lu Baolu) [Orabug: 38592128] {CVE-2025-40058}
- PCI: rcar-gen4: Fix inverted break condition in PHY initialization (Marek Vasut)
- PCI: rcar-gen4: Assure reset occurs before DBI access (Marek Vasut)
- PCI: rcar-gen4: Add missing 1ms delay after PWR reset assertion (Marek Vasut)
- usb: vhci-hcd: Prevent suspending virtually attached devices (Cristian Ciocaltea)
- scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (Ranjan Kumar)
- netfilter: nfnetlink: reset nlh pointer during batch replay (Fernando Fernandez Mancera)
- ipvs: Defer ip_vs_ftp unregister during netns cleanup (Slavin Liu) [Orabug: 38581443] {CVE-2025-40018}
- NFSv4.1: fix backchannel max_resp_sz verification check (Anthony Iliopoulos)
- coresight: Fix incorrect handling for return value of devm_kzalloc (Lin Yujun)
- coresight: tpda: fix the logic to setup the element size (Jie Gan)
- coresight: trbe: Return NULL pointer for allocation failures (Leo Yan)
- coresight: etm4x: Support atclk (Leo Yan)
- coresight: catu: Support atclk (Leo Yan)
- coresight: tmc: Support atclk (Leo Yan)
- coresight-etm4x: Conditionally access register TRCEXTINSELR (Yuanfang Zhang)
- dm vdo: return error on corrupted metadata in start_restoring_volume functions (Ivan Abramov)
- remoteproc: qcom: q6v5: Avoid disabling handover IRQ twice (Stephan Gerhold)
- PCI: tegra194: Fix duplicate PLL disable in pex_ep_event_pex_rst_assert() (Nagarjuna Kristam)
- wifi: rtw89: avoid circular locking dependency in ser_state_run() (Fedor Pchelkin)
- RDMA/rxe: Fix race in do_task() when draining (Gui-Dong Han) [Orabug: 38592139] {CVE-2025-40061}
- crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs (Chenghai Huang)
- vfio/pds: replace bitmap_free with vfree (Zilin Guan)
- sparc: fix accurate exception reporting in copy_{from,to}_user for M7 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_to_user for Niagara 4 (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for Niagara (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC III (Michael Karcher)
- sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC (Michael Karcher)
- ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback (Richard Fitzgerald)
- wifi: mac80211: fix Rx packet handling when pubsta information is not available (Aditya Kumar Singh)
- iommu/vt-d: debugfs: Fix legacy mode page table dump logic (Vineeth Pillai)
- wifi: ath10k: avoid unnecessary wait for service ready message (Baochen Qiang)
- wifi: ath12k: fix wrong logging ID used for CE (Baochen Qiang)
- Documentation: trace: historgram-design: Separate sched_waking histogram section heading and the following diagram (Bagas Sanjaya)
- IB/sa: Fix sa_local_svc_timeout_ms read race (Vlad Dumitrescu)
- RDMA/core: Resolve MAC of next-hop device without ARP support (Parav Pandit)
- Revert 'usb: xhci: Avoid Stop Endpoint retry loop if the endpoint seems Running' (Michal Pecio)
- f2fs: fix zero-sized extent for precache extents (Zijie Wang)
- HID: hidraw: tighten ioctl command parsing (Benjamin Tissoires)
- scsi: qla2xxx: Fix incorrect sign of error code in qla_nvme_xmt_ls_rsp() (Rong Qianfeng)
- scsi: qla2xxx: Fix incorrect sign of error code in START_SP_W_RETRIES() (Rong Qianfeng)
- scsi: qla2xxx: edif: Fix incorrect sign of error code (Rong Qianfeng)
- ACPI: NFIT: Fix incorrect ndr_desc being reportedin dev_err message (Colin Ian King)
- ALSA: pcm: Disable bottom softirqs as part of spin_lock_irq() on PREEMPT_RT (Sebastian Andrzej Siewior)
- f2fs: fix to mitigate overhead of f2fs_zero_post_eof_page() (Chao Yu)
- f2fs: fix to truncate first page in error path of f2fs_truncate() (Chao Yu)
- f2fs: fix to update map->m_next_extent correctly in f2fs_map_blocks() (Chao Yu)
- wifi: mt76: mt7915: fix mt7981 pre-calibration (Zhi-Jun You)
- wifi: mt76: mt7996: Convert mt7996_wed_rro_addr to LE (Lorenzo Bianconi)
- wifi: mt76: mt7996: Fix RX packets configuration for primary WED device (Lorenzo Bianconi)
- wifi: mt76: fix potential memory leak in mt76_wmac_probe() (Abdun Nihaal)
- RDMA/cm: Rate limit destroy CM ID timeout error message (Hakon Bugge)
- drivers/base/node: handle error properly in register_one_node() (Donet Tom)
- watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling the watchdog (Christophe Leroy)
- ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable (Zhang Tengfei)
- netfilter: ipset: Remove unused htable_bits in macro ahash_region (Zhen Ni)
- iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (Hans de Goede)
- iio: consumers: Fix handling of negative channel scale in iio_convert_raw_to_processed() (Hans de Goede)
- fs/ntfs3: reject index allocation if is empty but blocks exist (Moon Hee Lee)
- fs: ntfs3: Fix integer overflow in run_unpack() (Vitaly Grigoryev)
- drm/msm/dpu: fix incorrect type for ret (Rong Qianfeng)
- ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (Takashi Iwai)
- ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (Takashi Iwai)
- ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (Takashi Iwai)
- idpf: fix Rx descriptor ready check barrier in splitq (Alexander Lobakin)
- wifi: iwlwifi: Remove redundant header files (Liao Yuanhong)
- pps: fix warning in pps_register_cdev when register device fail (Wang Liang) [Orabug: 38592168] {CVE-2025-40070}
- misc: genwqe: Fix incorrect cmd field being reported in error (Colin Ian King)
- tty: n_gsm: Don't block input queue by waiting MSC (Seppo Takalo) [Orabug: 38592173] {CVE-2025-40071}
- usb: gadget: configfs: Correctly set use_os_string at bind (William Wu)
- usb: phy: twl6030: Fix incorrect type for ret (Xichao Zhao)
- drm/amdkfd: Fix error code sign for EINVAL in svm_ioctl() (Rong Qianfeng)
- tcp: fix __tcp_close() to only send RST when required (Eric Dumazet)
- PCI: tegra: Fix devm_kcalloc() argument order for port->phys allocation (Alok Tiwari)
- wifi: mwifiex: send world regulatory domain to driver (Stefan Kerkmann)
- drm/amd/pm: Disable SCLK switching on Oland with high pixel clocks (v3) (Timur Kristof)
- drm/amd/pm: Disable MCLK switching with non-DC at 120 Hz+ (v2) (Timur Kristof)
- drm/amd/pm: Treat zero vblank time as too short in si_dpm (v3) (Timur Kristof)
- drm/amd/pm: Adjust si_upload_smc_data register programming (v3) (Timur Kristof)
- drm/amd/pm: Fix si_upload_smc_data (v3) (Timur Kristof)
- drm/amd/pm: Disable ULV even if unsupported (v3) (Timur Kristof)
- drm/amdgpu: Power up UVD 3 for FW validation (v2) (Timur Kristof)
- coresight: Only register perf symlink for sinks with alloc_buffer (Yuanfang Zhang)
- inet: ping: check sock_net() in ping_get_port() and ping_lookup() (Eric Dumazet)
- crypto: hisilicon/qm - check whether the input function and PF are on the same device (Zhushuai Yin)
- crypto: hisilicon - re-enable address prefetch after device resuming (Chenghai Huang)
- crypto: hisilicon/zip - remove unnecessary validation for high-performance mode configurations (Chenghai Huang)
- media: st-delta: avoid excessive stack usage (Arnd Bergmann)
- ALSA: lx_core: use int type to store negative error codes (Rong Qianfeng)
- PCI/ACPI: Fix pci_acpi_preserve_config() memory leak (Nirmoy Das)
- RDMA/mlx5: Better estimate max_qp_wr to reflect WQE count (Or Har-Toov)
- media: rj54n1cb0c: Fix memleak in rj54n1_probe() (Zhang Shurong)
- crypto: octeontx2 - Call strscpy() with correct size argument (Thorsten Blum)
- scsi: myrs: Fix dma_alloc_coherent() error check (Thomas Fourier)
- scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (Niklas Cassel)
- hwrng: nomadik - add ARM_AMBA dependency (Arnd Bergmann)
- crypto: keembay - Add missing check after sg_nents_for_len() (Thomas Fourier)
- drm/amd/display: Remove redundant semicolons (Liao Yuanhong)
- serial: max310x: Add error checking in probe() (Dan Carpenter)
- usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure calls (Komal Bajaj)
- usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (Dan Carpenter)
- phy: rockchip: naneng-combphy: Enable U3 OTG port for RK3568 (Jonas Karlman)
- media: zoran: Remove zoran_fh structure (Jacopo Mondi)
- drm/bridge: it6505: select REGMAP_I2C (Chia-I Wu)
- f2fs: fix condition in __allow_reserved_blocks() (Chao Yu)
- drm/radeon/r600_cs: clean up of dead code in r600_cs (Brahmajit Das)
- drm/panel: novatek-nt35560: Fix invalid return value (Brigham Campbell)
- bpf: Enforce expected_attach_type for tailcall compatibility (Daniel Borkmann)
- libbpf: Fix error when st-prefix_ops and ops from differ btf (D. Wythe)
- i2c: designware: Add disabling clocks when probe fails (Kunihiko Hayashi)
- i2c: designware: Fix clock issue when PM is disabled (Kunihiko Hayashi)
- i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (Leilk Liu)
- thermal/drivers/qcom/lmh: Add missing IRQ includes (Dmitry Baryshkov)
- thermal/drivers/qcom: Make LMH select QCOM_SCM (Dmitry Baryshkov)
- hwmon: (mlxreg-fan) Separate methods of fan setting coming from different subsystems (Vadim Pasternak)
- once: fix race by moving DO_ONCE to separate section (Qi Xi)
- bpf: Mark kfuncs as __noclone (Andrea Righi)
- spi: fix return code when spi device has too many chipselects (Jonas Gorski)
- tools/nolibc: make time_t robust if __kernel_old_time_t is missing in host headers (Zhouyi Zhou)
- smp: Fix up and expand the smp_call_function_many() kerneldoc (Rafael J. Wysocki)
- bpf, arm64: Call bpf_jit_binary_pack_finalize() in bpf_jit_free() (Hengqi Chen)
- bpf: Explicitly check accesses to bpf_sock_addr (Paul Chaignon) [Orabug: 38592203] {CVE-2025-40078}
- selftests: watchdog: skip ping loop if WDIOF_KEEPALIVEPING not supported (Akhilesh Patil)
- i3c: master: svc: Recycle unused IBI slot (Stanley Chu)
- i3c: master: svc: Use manual response for IBI events (Stanley Chu)
- nvmet-fc: move lsop put work to nvmet_fc_ls_req_op (Daniel Wagner)
- riscv, bpf: Sign extend struct ops return values properly (Hengqi Chen)
- ACPICA: Fix largest possible resource descriptor index (Dmitry Antipov)
- pwm: tiehrpwm: Fix corner case in clock divisor calculation (Uwe Kleine-Konig)
- pwm: tiehrpwm: Fix various off-by-one errors in duty-cycle calculation (Uwe Kleine-Konig)
- pwm: tiehrpwm: Make code comment in .free() more useful (Uwe Kleine-Konig)
- pwm: tiehrpwm: Don't drop runtime PM reference in .free() (Uwe Kleine-Konig)
- arm64: dts: mediatek: mt8516-pumpkin: Fix machine compatible (AngeloGioacchino Del Regno)
- arm64: dts: mediatek: mt8395-kontron-i1200: Fix MT6360 regulator nodes (AngeloGioacchino Del Regno)
- arm64: dts: mediatek: mt6795-xperia-m5: Fix mmc0 latch-ck value (AngeloGioacchino Del Regno)
- mmc: core: Fix variable shadowing in mmc_route_rpmb_frames() (Bean Huo)
- arm64: dts: mediatek: mt6331: Fix pmic, regulators, rtc, keys node names (AngeloGioacchino Del Regno)
- arm64: dts: mediatek: mt8186-tentacruel: Fix touchscreen model (Chen-Yu Tsai)
- cpuidle: qcom-spm: fix device and OF node leaks at probe (Johan Hovold)
- soc: mediatek: mtk-svs: fix device leaks on mt8192 probe failure (Johan Hovold)
- soc: mediatek: mtk-svs: fix device leaks on mt8183 probe failure (Johan Hovold)
- firmware: firmware: meson-sm: fix compile-test default (Johan Hovold)
- PM / devfreq: rockchip-dfi: double count on RK3588 (Nicolas Frattaroli)
- nbd: restrict sockets to TCP and UDP (Eric Dumazet) [Orabug: 38592211] {CVE-2025-40080}
- arm64: dts: mediatek: mt8195: Remove suspend-breaking reset from pcie0 (Guoqing Jiang)
- selftests: vDSO: vdso_test_abi: Correctly skip whole test with missing vDSO (Thomas Weissschuh)
- selftests: vDSO: Fix -Wunitialized in powerpc VDSO_CALL() wrapper (Thomas Weissschuh)
- null_blk: Fix the description of the cache_size module argument (Genjian Zhang)
- pinctrl: renesas: Use int type to store negative error codes (Rong Qianfeng)
- power: supply: cw2015: Fix a alignment coding style issue (Andy Yan)
- PM / devfreq: mtk-cci: Fix potential error pointer dereference in probe() (Dan Carpenter)
- ARM: dts: omap: am335x-cm-t335: Remove unused mcasp num-serializer property (Jihed Chaibi)
- ARM: dts: ti: omap: omap3-devkit8000-lcd: Fix ti,keep-vref-on property to use correct boolean syntax in DTS (Jihed Chaibi)
- ARM: dts: ti: omap: am335x-baltos: Fix ti,en-ck32k-xtal property in DTS to use correct boolean syntax (Jihed Chaibi)
- vdso: Add struct __kernel_old_timeval forward declaration to gettime.h (Thomas Weissschuh)
- PM: sleep: core: Clear power.must_resume in noirq suspend error path (Rafael J. Wysocki)
- block: use int to store blk_stack_limits() return value (Rong Qianfeng)
- leds: leds-lp55xx: Use correct address for memory programming (Andrei Lalaev)
- selftests/nolibc: fix EXPECT_NZ macro (Benjamin Berg)
- regulator: scmi: Use int type to store negative error codes (Rong Qianfeng)
- arm64: dts: apple: t8103-j457: Fix PCIe ethernet iommu-map (Janne Grunau)
- ARM: at91: pm: fix MCKx restore routine (Nicolas Ferre)
- blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx (Li Nan)
- pinctrl: meson-gxl: add missing i2c_d pinmux (Da Xue)
- soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (Sneh Mankad)
- ACPI: processor: idle: Fix memory leak when register cpuidle device failed (Huisong Li)
- arm64: dts: imx95: Correct the lpuart7 and lpuart8 srcid (Joy Zou)
- arm64: dts: imx93-kontron: Fix USB port assignment (Frieder Schrempf)
- arm64: dts: imx93-kontron: Fix GPIO for panel regulator (Annette Kobou)
- firmware: arm_scmi: Mark VirtIO ready before registering scmi_virtio_driver (Junnan Wu)
- cpufreq: scmi: Account for malformed DT in scmi_dev_used_by_cpus() (Florian Fainelli)
- leds: flash: leds-qcom-flash: Update torch current clamp setting (Fenglin Wu)
- ARM: dts: renesas: porter: Fix CAN pin group (Geert Uytterhoeven)
- libbpf: Fix reuse of DEVMAP (Yureka Lilian)
- bpf: Remove migrate_disable in kprobe_multi_link_prog_run (Tao Chen)
- bpf/selftests: Fix test_tcpnotify_user (Matt Bobrowski)
- regmap: Remove superfluous check for !config in __regmap_init() (Geert Uytterhoeven)
- arm64: dts: renesas: rzg2lc-smarc: Disable CAN-FD channel0 (Biju Das)
- pinctrl: renesas: rzg2l: Fix invalid unsigned return in rzg3s_oen_read() (Lad Prabhakar)
- btrfs: return any hit error from extent_writepage_io() (Qu Wenruo)
- lsm: CONFIG_LSM can depend on CONFIG_SECURITY (Randy Dunlap)
- x86/vdso: Fix output operand size of RDPID (Uros Bizjak)
- EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller (Qiuxu Zhuo)
- smb: server: fix IRD/ORD negotiation with the client (Stefan Metzmacher)
- perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (Leo Yan) [Orabug: 38592219] {CVE-2025-40081}
- coresight: trbe: Prevent overflow in PERF_IDX2OFF() (Leo Yan)
- uprobes: uprobe_warn should use passed task (Jeremy Linton)
- powerpc/603: Really copy kernel PGD entries into all PGDIRs (Christophe Leroy)
- powerpc/8xx: Remove left-over instruction and comments in DataStoreTLBMiss handler (Christophe Leroy)
- gfs2: Fix GLF_INVALIDATE_IN_PROGRESS flag clearing in do_xmote (Andreas Gruenbacher)
- selftests: arm64: Check fread return value in exec_target (Bala-Vignesh-Reddy)
- seccomp: Fix a race with WAIT_KILLABLE_RECV if the tracer replies too fast (Johannes Nixdorf)
- init: INITRAMFS_PRESERVE_MTIME should depend on BLK_DEV_INITRD (Geert Uytterhoeven)
- filelock: add FL_RECLAIM to show_fl_flags() macro (Jeff Layton)
- LTS version: v6.12.52 (Jack Vogel)
- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Sean Christopherson) [Orabug: 38591957] {CVE-2025-40026}
- net/9p: fix double req put in p9_fd_cancelled (Nalivayko Sergey) [Orabug: 38591963] {CVE-2025-40027}
- crypto: rng - Ensure set_ent is always present (Herbert Xu)
- driver core/PM: Set power.no_callbacks along with power.no_pm (Rafael J. Wysocki)
- staging: axis-fifo: flush RX FIFO on read errors (Ovidiu Panait)
- staging: axis-fifo: fix TX handling on copy_from_user() failure (Ovidiu Panait)
- staging: axis-fifo: fix maximum TX packet length check (Ovidiu Panait)
- serial: stm32: allow selecting console when the driver is module (Raphael Gallais-Pou)
- binder: fix double-free in dbitmap (Carlos Llamas)
- nvmem: layouts: fix automatic module loading (Michael Walle)
- hid: fix I2C read buffer overflow in raw_event() for mcp2221 (Arnaud Lecomte)
- ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (Jeongjun Park)
- ALSA: usb-audio: Kill timer properly at removal (Takashi Iwai) [Orabug: 38152882] {CVE-2025-38105}
- drm/amdgpu: Enable MES lr_compute_wa by default (Mario Limonciello)
- drm/amd/include : Update MES v12 API for fence update (Shaoyun Liu)
- drm/amd/include : MES v11 and v12 API header update (Shaoyun Liu)
- drm/amd : Update MES API header file for v11 & v12 (Shaoyun Liu)
- platform/x86/amd/pmc: Add Stellaris Slim Gen6 AMD to spurious 8042 quirks list (Christoffer Sandberg)
- can: rcar_canfd: Fix controller mode setting (Duy Nguyen)
- can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled (Chen Yufeng)
- netfs: Prevent duplicate unlocking (Lizhi Xu)
- btrfs: ref-verify: handle damaged extent root tree (David Sterba)
- ASoC: rt5682s: Adjust SAR ADC button mode to fix noise issue (Jack Yu)
- platform/x86/amd/pmf: Support new ACPI ID AMDI0108 (Shyam Sundar S K)
- perf subcmd: avoid crash in exclude_cmds when excludes is empty (Hupu)
- platform/x86/amd/pmc: Add MECHREVO Yilong15Pro to spurious_8042 list (April Grimoire)
- dm-integrity: limit MAX_TAG_SIZE to 255 (Mikulas Patocka)
- ASoC: amd: acp: Adjust pdm gain value (Venkata Prasad Potturu)
- rust: block: fix srctree/ links (Miguel Ojeda)
- wifi: rtl8xxxu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)
- wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188 (Bitterblue Smith)
- Bluetooth: btusb: Add USB ID 2001:332a for D-Link AX9U rev. A1 (Zenm Chen)
- USB: serial: option: add SIMCom 8230C compositions (Xiaowei Li)
- media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe (Duoming Zhou)
- wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() (Fedor Pchelkin)
[6.12.0-106.51.1]
- KVM: x86: Advertise SRSO_USER_KERNEL_NO to userspace (Harshit Mogalapalli) [Orabug: 38478491]
1 VM count transitions (Harshit Mogalapalli) [Orabug: 38478491]
- x86/bugs: KVM: Add support for SRSO_MSR_FIX (Harshit Mogalapalli) [Orabug: 38478491]
- x86/bugs: Add SRSO_USER_KERNEL_NO support (Harshit Mogalapalli) [Orabug: 38478491]
- x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit (Harshit Mogalapalli) [Orabug: 38478491]
- Revert 'x86/bugs: Adjust SRSO mitigation to new features' (Harshit Mogalapalli) [Orabug: 38478491]
- uek-rpm: add 'bpf' to CONFIG_LSM as overheads are reduced (Alan Maguire) [Orabug: 38519747]
- uek-rpm: Enable CONFIG_COMPAT_32BIT_TIME for x86 container kernel (Boris Ostrovsky) [Orabug: 38540664] | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-22117', 'CVE-2025-38105', 'CVE-2025-38678', 'CVE-2025-40001', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40031', 'CVE-2025-40035', 'CVE-2025-40037', 'CVE-2025-40038', 'CVE-2025-40040', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40047', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40051', 'CVE-2025-40052', 'CVE-2025-40053', 'CVE-2025-40055', 'CVE-2025-40056', 'CVE-2025-40057', 'CVE-2025-40058', 'CVE-2025-40061', 'CVE-2025-40070', 'CVE-2025-40071', 'CVE-2025-40078', 'CVE-2025-40080', 'CVE-2025-40081', 'CVE-2025-40085', 'CVE-2025-40087', 'CVE-2025-40096', 'CVE-2025-40099', 'CVE-2025-40100', 'CVE-2025-40101', 'CVE-2025-40103', 'CVE-2025-40104', 'CVE-2025-40105'] | ['Oracle Linux 10', 'Oracle Linux 9'] | ['CVE-2025-22117', 'CVE-2025-38105', 'CVE-2025-38678', 'CVE-2025-40001', 'CVE-2025-40018', 'CVE-2025-40019', 'CVE-2025-40026', 'CVE-2025-40027', 'CVE-2025-40030', 'CVE-2025-40031', 'CVE-2025-40035', 'CVE-2025-40037', 'CVE-2025-40038', 'CVE-2025-40040', 'CVE-2025-40042', 'CVE-2025-40044', 'CVE-2025-40047', 'CVE-2025-40048', 'CVE-2025-40049', 'CVE-2025-40051', 'CVE-2025-40052', 'CVE-2025-40053', 'CVE-2025-40055', 'CVE-2025-40056', 'CVE-2025-40057', 'CVE-2025-40058', 'CVE-2025-40061', 'CVE-2025-40070', 'CVE-2025-40071', 'CVE-2025-40078', 'CVE-2025-40080', 'CVE-2025-40081', 'CVE-2025-40085', 'CVE-2025-40087', 'CVE-2025-40096', 'CVE-2025-40099', 'CVE-2025-40100', 'CVE-2025-40101', 'CVE-2025-40103', 'CVE-2025-40104', 'CVE-2025-40105', 'ELSA-2025-28040', 'https://linux.oracle.com/cve/CVE-2025-22117.html', 'https://linux.oracle.com/cve/CVE-2025-38105.html', 'https://linux.oracle.com/cve/CVE-2025-38678.html', 'https://linux.oracle.com/cve/CVE-2025-40001.html', 'https://linux.oracle.com/cve/CVE-2025-40018.html', 'https://linux.oracle.com/cve/CVE-2025-40019.html', 'https://linux.oracle.com/cve/CVE-2025-40026.html', 'https://linux.oracle.com/cve/CVE-2025-40027.html', 'https://linux.oracle.com/cve/CVE-2025-40030.html', 'https://linux.oracle.com/cve/CVE-2025-40031.html', 'https://linux.oracle.com/cve/CVE-2025-40035.html', 'https://linux.oracle.com/cve/CVE-2025-40037.html', 'https://linux.oracle.com/cve/CVE-2025-40038.html', 'https://linux.oracle.com/cve/CVE-2025-40040.html', 'https://linux.oracle.com/cve/CVE-2025-40042.html', 'https://linux.oracle.com/cve/CVE-2025-40044.html', 'https://linux.oracle.com/cve/CVE-2025-40047.html', 'https://linux.oracle.com/cve/CVE-2025-40048.html', 'https://linux.oracle.com/cve/CVE-2025-40049.html', 'https://linux.oracle.com/cve/CVE-2025-40051.html', 'https://linux.oracle.com/cve/CVE-2025-40052.html', 'https://linux.oracle.com/cve/CVE-2025-40053.html', 'https://linux.oracle.com/cve/CVE-2025-40055.html', 'https://linux.oracle.com/cve/CVE-2025-40056.html', 'https://linux.oracle.com/cve/CVE-2025-40057.html', 'https://linux.oracle.com/cve/CVE-2025-40058.html', 'https://linux.oracle.com/cve/CVE-2025-40061.html', 'https://linux.oracle.com/cve/CVE-2025-40070.html', 'https://linux.oracle.com/cve/CVE-2025-40071.html', 'https://linux.oracle.com/cve/CVE-2025-40078.html', 'https://linux.oracle.com/cve/CVE-2025-40080.html', 'https://linux.oracle.com/cve/CVE-2025-40081.html', 'https://linux.oracle.com/cve/CVE-2025-40085.html', 'https://linux.oracle.com/cve/CVE-2025-40087.html', 'https://linux.oracle.com/cve/CVE-2025-40096.html', 'https://linux.oracle.com/cve/CVE-2025-40099.html', 'https://linux.oracle.com/cve/CVE-2025-40100.html', 'https://linux.oracle.com/cve/CVE-2025-40101.html', 'https://linux.oracle.com/cve/CVE-2025-40103.html', 'https://linux.oracle.com/cve/CVE-2025-40104.html', 'https://linux.oracle.com/cve/CVE-2025-40105.html', 'https://linux.oracle.com/errata/ELSA-2025-28040.html'] | b98e0c812753f1c8684d65c79de846f4430b8c9b61015d9a11b34c8be7c4ad03 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523137 | ELSA-2025-23137: mysql:8.4 security update (MODERATE) | mecab
mecab-ipadic
mysql
[8.4.7-1]
- Rebase to 8.4.7 | MODERATE | 2025-12-12 00:00:00+03:00 | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069'] | ['Oracle Linux 8'] | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069', 'ELSA-2025-23137', 'https://linux.oracle.com/cve/CVE-2025-53040.html', 'https://linux.oracle.com/cve/CVE-2025-53042.html', 'https://linux.oracle.com/cve/CVE-2025-53044.html', 'https://linux.oracle.com/cve/CVE-2025-53045.html', 'https://linux.oracle.com/cve/CVE-2025-53053.html', 'https://linux.oracle.com/cve/CVE-2025-53054.html', 'https://linux.oracle.com/cve/CVE-2025-53062.html', 'https://linux.oracle.com/cve/CVE-2025-53069.html', 'https://linux.oracle.com/errata/ELSA-2025-23137.html'] | 235bdc9fb4effb6d8822ede627ee912ebfc05c5b4406b37584c484fbc724a4c3 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523111 | ELSA-2025-23111: mysql:8.4 security update (MODERATE) | mecab
mecab-ipadic
mysql
[8.4.7-1]
- Rebase to 8.4.7
rapidjson | MODERATE | 2025-12-12 00:00:00+03:00 | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069'] | ['Oracle Linux 9'] | ['CVE-2025-53040', 'CVE-2025-53042', 'CVE-2025-53044', 'CVE-2025-53045', 'CVE-2025-53053', 'CVE-2025-53054', 'CVE-2025-53062', 'CVE-2025-53069', 'ELSA-2025-23111', 'https://linux.oracle.com/cve/CVE-2025-53040.html', 'https://linux.oracle.com/cve/CVE-2025-53042.html', 'https://linux.oracle.com/cve/CVE-2025-53044.html', 'https://linux.oracle.com/cve/CVE-2025-53045.html', 'https://linux.oracle.com/cve/CVE-2025-53053.html', 'https://linux.oracle.com/cve/CVE-2025-53054.html', 'https://linux.oracle.com/cve/CVE-2025-53062.html', 'https://linux.oracle.com/cve/CVE-2025-53069.html', 'https://linux.oracle.com/errata/ELSA-2025-23111.html'] | 77ec449c2e42b5c11536591279b7e9d8a5557bcc069f5923479ee0fb26c5de88 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523063 | ELSA-2025-23063: ruby:3.3 security update (MODERATE) | ruby
[3.3.10-5]
- Upgrade to Ruby 3.3.10.
Resolves: RHEL-127912
- Fix possible denial of service in resolv gem (CVE-2025-24294)
- Fix URI Credential Leakage Bypass previous fixes. (CVE-2025-61594)
- Fix REXML denial of service. (CVE-2025-58767)
Resolves: RHEL-122015
rubygem-mysql2
rubygem-pg | MODERATE | 2025-12-11 00:00:00+03:00 | ['CVE-2025-24294', 'CVE-2025-58767', 'CVE-2025-61594'] | ['Oracle Linux 9'] | ['CVE-2025-24294', 'CVE-2025-58767', 'CVE-2025-61594', 'ELSA-2025-23063', 'https://linux.oracle.com/cve/CVE-2025-24294.html', 'https://linux.oracle.com/cve/CVE-2025-58767.html', 'https://linux.oracle.com/cve/CVE-2025-61594.html', 'https://linux.oracle.com/errata/ELSA-2025-23063.html'] | aafdaa56caeaefc05ada2229a267c886e3599d1ef267e231601ea38d204c8479 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528047 | ELSA-2025-28047: edk2 security update (IMPORTANT) | [20250905-4]
- Create new 20250905 release for OL9 which includes the following fixed CVEs:
- EDK2: EDK2 contains a vulnerability in BIOS where an attacker may cause 'Protection Mechanism Failure' by local access [Orabug: 38381983] {CVE-2025-3770}
- EDK2: EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means [Orabug: 38382190] {CVE-2024-38805}
- EDK2: EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network [Orabug: 38382286] {CVE-2024-38797}
- EDK2: Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity. [Orabug: 38413860] {CVE-2024-36331}
- Update to OpenSSL 3.5.1 which includes the following fixed CVEs:
{CVE-2025-4575} {CVE-2024-12797} {CVE-2024-13176} {CVE-2024-12797} {CVE-2024-13176} {CVE-2024-9143} | IMPORTANT | 2025-12-11 00:00:00+03:00 | ['CVE-2024-36331', 'CVE-2024-38797', 'CVE-2024-38805', 'CVE-2025-3770'] | ['Oracle Linux 9'] | ['CVE-2024-36331', 'CVE-2024-38797', 'CVE-2024-38805', 'CVE-2025-3770', 'ELSA-2025-28047', 'https://linux.oracle.com/cve/CVE-2024-36331.html', 'https://linux.oracle.com/cve/CVE-2024-38797.html', 'https://linux.oracle.com/cve/CVE-2024-38805.html', 'https://linux.oracle.com/cve/CVE-2025-3770.html', 'https://linux.oracle.com/errata/ELSA-2025-28047.html'] | 4612ba9b748304fc070a4bf62591b25c90cf96b22bcf5ce5f6e713e2e801e208 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523139 | ELSA-2025-23139: libsoup3 security update (MODERATE) | [3.6.5-7]
- Add patch for CVE-2025-12105 | MODERATE | 2025-12-11 00:00:00+03:00 | ['CVE-2025-12105'] | ['Oracle Linux 10'] | ['CVE-2025-12105', 'ELSA-2025-23139', 'https://linux.oracle.com/cve/CVE-2025-12105.html', 'https://linux.oracle.com/errata/ELSA-2025-23139.html'] | 98b56f65863bdee28859181e19d5e2d9bf12ebd0b461dce0cb7ff6eed78a4df1 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20204465 | ELSA-2020-4465: binutils security update (LOW) | [2.30-79.0.1]
- Forward-port Oracle patches from 2.30-75.0.1
- Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
[2.30-79]
- Fix x86 assemblers handling of non-8-bit displacements. (#1869401)
[2.30-77]
- Add tests missing from PT_GNU_SEGMENT patch. (#1870039)
[2.30-75.0.1]
- Forward-port Oracle patches to OL8.3 beta.
[2.30-76]
- Have the s.390 assembler include alignment hints with vector instructions. (#1850490)
[2.30-75]
- Prevent the s/390 linker from rewriting the GOT access for certain symbol types. (#1846972) | LOW | 2020-11-10 00:00:00+03:00 | ['CVE-2019-17450'] | ['Oracle Linux 8'] | ['CVE-2019-17450', 'ELSA-2020-4465', 'https://linux.oracle.com/cve/CVE-2019-17450.html', 'https://linux.oracle.com/errata/ELSA-2020-4465.html'] | 50866ab087ba6ab057c8a826a40a27ef3a2473af22d4c680f12e1890940bf768 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523128 | ELSA-2025-23128: firefox security update (IMPORTANT) | [140.6.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789]
[140.6.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.6.0-1]
- Update to 140.6.0 ESR | IMPORTANT | 2025-12-11 00:00:00+03:00 | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333'] | ['Oracle Linux 8'] | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333', 'ELSA-2025-23128', 'https://linux.oracle.com/cve/CVE-2025-14321.html', 'https://linux.oracle.com/cve/CVE-2025-14322.html', 'https://linux.oracle.com/cve/CVE-2025-14323.html', 'https://linux.oracle.com/cve/CVE-2025-14324.html', 'https://linux.oracle.com/cve/CVE-2025-14325.html', 'https://linux.oracle.com/cve/CVE-2025-14328.html', 'https://linux.oracle.com/cve/CVE-2025-14329.html', 'https://linux.oracle.com/cve/CVE-2025-14330.html', 'https://linux.oracle.com/cve/CVE-2025-14331.html', 'https://linux.oracle.com/cve/CVE-2025-14333.html', 'https://linux.oracle.com/errata/ELSA-2025-23128.html'] | f3736e459fccbcf6588381b85fe47dcbb4026379f9e4e3bebe3595c8e106f2b9 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523062 | ELSA-2025-23062: ruby:3.3 security update (MODERATE) | ruby
[3.3.10-5]
- Upgrade to Ruby 3.3.10.
Resolves: RHEL-106820
- Fix possible denial of service in resolv gem (CVE-2025-24294)
- Fix URI Credential Leakage Bypass previous fixes. (CVE-2025-61594)
- Fix REXML denial of service. (CVE-2025-58767)
Resolves: RHEL-122012
rubygem-abrt
rubygem-mysql2
rubygem-pg | MODERATE | 2025-12-11 00:00:00+03:00 | ['CVE-2025-24294', 'CVE-2025-58767', 'CVE-2025-61594'] | ['Oracle Linux 8'] | ['CVE-2025-24294', 'CVE-2025-58767', 'CVE-2025-61594', 'ELSA-2025-23062', 'https://linux.oracle.com/cve/CVE-2025-24294.html', 'https://linux.oracle.com/cve/CVE-2025-58767.html', 'https://linux.oracle.com/cve/CVE-2025-61594.html', 'https://linux.oracle.com/errata/ELSA-2025-23062.html'] | c96c57e3d3fdb2e72f45b68607858719fbfffe76c1e18c5d589710de87063d41 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523035 | ELSA-2025-23035: firefox security update (IMPORTANT) | [140.6.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.6.0-1]
- Update to 140.6.0 ESR | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333'] | ['Oracle Linux 10'] | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333', 'ELSA-2025-23035', 'https://linux.oracle.com/cve/CVE-2025-14321.html', 'https://linux.oracle.com/cve/CVE-2025-14322.html', 'https://linux.oracle.com/cve/CVE-2025-14323.html', 'https://linux.oracle.com/cve/CVE-2025-14324.html', 'https://linux.oracle.com/cve/CVE-2025-14325.html', 'https://linux.oracle.com/cve/CVE-2025-14328.html', 'https://linux.oracle.com/cve/CVE-2025-14329.html', 'https://linux.oracle.com/cve/CVE-2025-14330.html', 'https://linux.oracle.com/cve/CVE-2025-14331.html', 'https://linux.oracle.com/cve/CVE-2025-14333.html', 'https://linux.oracle.com/errata/ELSA-2025-23035.html'] | d33006832637b2586d7f802b3b5bd1e09afd82f9244f9114cd9f48e4cad8a609 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523034 | ELSA-2025-23034: firefox security update (IMPORTANT) | [140.6.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.6.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.6.0-1]
- Update to 140.6.0 ESR | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333'] | ['Oracle Linux 9'] | ['CVE-2025-14321', 'CVE-2025-14322', 'CVE-2025-14323', 'CVE-2025-14324', 'CVE-2025-14325', 'CVE-2025-14328', 'CVE-2025-14329', 'CVE-2025-14330', 'CVE-2025-14331', 'CVE-2025-14333', 'ELSA-2025-23034', 'https://linux.oracle.com/cve/CVE-2025-14321.html', 'https://linux.oracle.com/cve/CVE-2025-14322.html', 'https://linux.oracle.com/cve/CVE-2025-14323.html', 'https://linux.oracle.com/cve/CVE-2025-14324.html', 'https://linux.oracle.com/cve/CVE-2025-14325.html', 'https://linux.oracle.com/cve/CVE-2025-14328.html', 'https://linux.oracle.com/cve/CVE-2025-14329.html', 'https://linux.oracle.com/cve/CVE-2025-14330.html', 'https://linux.oracle.com/cve/CVE-2025-14331.html', 'https://linux.oracle.com/cve/CVE-2025-14333.html', 'https://linux.oracle.com/errata/ELSA-2025-23034.html'] | fdf3f0836f29ad20581f7e32f3404b1956db8ce6c73e01cf4648d40893cc0066 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523087 | ELSA-2025-23087: grafana security update (MODERATE) | [10.2.6-17]
- Resolves RHEL-125692: CVE-2025-58183
- Resolves RHEL-120426: Grafana-selinux prevents plugins from searching cgroups | MODERATE | 2025-12-10 00:00:00+03:00 | ['CVE-2025-58183'] | ['Oracle Linux 9'] | ['CVE-2025-58183', 'ELSA-2025-23087', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-23087.html'] | 6dee85f0eb137d60085e2fa32bda899679d7f6800f67370ff920b73f4e80d5f0 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523086 | ELSA-2025-23086: luksmeta security update (MODERATE) | [9-4.1]
- Fix handling of large metadata
Resolves: RHEL-122138 | MODERATE | 2025-12-10 00:00:00+03:00 | ['CVE-2025-11568'] | ['Oracle Linux 8'] | ['CVE-2025-11568', 'ELSA-2025-23086', 'https://linux.oracle.com/cve/CVE-2025-11568.html', 'https://linux.oracle.com/errata/ELSA-2025-23086.html'] | d0d503b2e98cc143a49f6e94ea9c000ada5784a5b908d0db9481bc3e4ac26d61 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523088 | ELSA-2025-23088: grafana security update (MODERATE) | [10.2.6-21]
- Resolves RHEL-125631: CVE-2025-58183
- Resolves RHEL-132760: Grafana-selinux prevents plugins from searching cgroups | MODERATE | 2025-12-10 00:00:00+03:00 | ['CVE-2025-58183'] | ['Oracle Linux 10'] | ['CVE-2025-58183', 'ELSA-2025-23088', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-23088.html'] | 600f9c5ea228ac40edc3456ee4199a237f8ee5c7f7952d407db54891553d2b32 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523083 | ELSA-2025-23083: wireshark security update (IMPORTANT) | [4.4.2-4.0.1.1]
- Fix post script to not fail during initial installation [Orabug: 37565359]
[1:4.4.2-4.1]
- Resolves: RHEL-130425 - Access of Uninitialized Pointer in Wireshark | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-13499'] | ['Oracle Linux 10'] | ['CVE-2025-13499', 'ELSA-2025-23083', 'https://linux.oracle.com/cve/CVE-2025-13499.html', 'https://linux.oracle.com/errata/ELSA-2025-23083.html'] | 4a75548061fc4720a3395021e5c5ed0556d20d2ff066ebe902501d479dd0639f | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521404 | ELSA-2025-21404: lasso security update (CRITICAL) | [2.5.1-8.0.1]
- Fixes CVE-2025-47151 lasso: Type confusion in Entr'ouvert Lasso [Orabug: 38658691] | CRITICAL | 2025-12-10 00:00:00+03:00 | ['CVE-2025-47151'] | ['Oracle Linux 7'] | ['CVE-2025-47151', 'ELSA-2025-21404', 'https://linux.oracle.com/cve/CVE-2025-47151.html', 'https://linux.oracle.com/errata/ELSA-2025-21404.html'] | 1b286cb761f2259afe93012c3b1e3ddcbb1b9c5c03ad0d946ddba9f173edc6d8 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202619365 | ELSA-2026-19365: jq security update (IMPORTANT) | [1.6-19.2]
- Fix CVE-2026-40164 - Denial of Service via crafted JSON object causing hash collisions
- Resolves: RHEL-168185
[1.6-19.1]
- Fix CVE-2026-39979 out-of-bounds read in jv_parse_sized()
- Resolves: RHEL-168202 | IMPORTANT | 2026-06-23 00:00:00+03:00 | ['CVE-2026-39979', 'CVE-2026-40164'] | ['Oracle Linux 9'] | ['CVE-2026-39979', 'CVE-2026-40164', 'ELSA-2026-19365', 'https://linux.oracle.com/cve/CVE-2026-39979.html', 'https://linux.oracle.com/cve/CVE-2026-40164.html', 'https://linux.oracle.com/errata/ELSA-2026-19365.html'] | 33bad66bc4413b7d55aa8ff2c32f9290f784b2ce01fc0f8bb3abee1fee5661c9 | 2026-06-26 01:31:49.792705+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523048 | ELSA-2025-23048: tomcat security update (IMPORTANT) | [1:9.0.87-1.7]
- Resolves: RHEL-124507
tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-91743
tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-31651', 'CVE-2025-55752'] | ['Oracle Linux 8'] | ['CVE-2025-31651', 'CVE-2025-55752', 'ELSA-2025-23048', 'https://linux.oracle.com/cve/CVE-2025-31651.html', 'https://linux.oracle.com/cve/CVE-2025-55752.html', 'https://linux.oracle.com/errata/ELSA-2025-23048.html'] | 68a1a8877127bbea654daeee588f7a2544bac1a946601d34a2e80dbd078cae6d | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202523049 | ELSA-2025-23049: tomcat security update (IMPORTANT) | [1:9.0.87-6.1]
- Resolves: RHEL-124518
tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)
- Resolves: RHEL-91753
tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-31651', 'CVE-2025-55752'] | ['Oracle Linux 9'] | ['CVE-2025-31651', 'CVE-2025-55752', 'ELSA-2025-23049', 'https://linux.oracle.com/cve/CVE-2025-31651.html', 'https://linux.oracle.com/cve/CVE-2025-55752.html', 'https://linux.oracle.com/errata/ELSA-2025-23049.html'] | b0785121b83e7216bf4c0529588bb9c39f6bc35975a7ea2bad1f71114bf0e9b8 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522096 | ELSA-2025-22096: tigervnc security update (IMPORTANT) | [1.8.0-33.0.9]
- Fix CVE-2025-62229: xorg-x11-server: Use-after-free in XPresentNotify structures creation [Orabug: 38694278]
- Fix CVE-2025-62230: xorg-x11-server: Use-after-free in Xkb client resource removal
- Fix CVE-2025-62231: xorg-x11-server: Value overflow in Xkb extension XkbSetCompatMap()
[1.8.0-33.0.7]
- Fix CVE-2025-49175, CVE-2025-49176, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 [Orabug: 38157695]
[1.8.0-33.0.5]
- Fix CVE-2025-26594 xorg-x11-server Use-after-free of the root cursor [Orabug: 37712725]
- Fix CVE-2025-26595 xorg-x11-server Buffer overflow in XkbVModMaskText()
- Fix CVE-2025-26596 xorg-x11-server Heap overflow in XkbWriteKeySyms()
- Fix CVE-2025-26597 xorg-x11-server Buffer overflow in XkbChangeTypesOfKey()
- Fix CVE-2025-26598 xorg-x11-server Out-of-bounds write in CreatePointerBarrierClient()
- Fix CVE-2025-26599 xorg-x11-server Use of uninitialized pointer in compRedirectWindow()
- Fix CVE-2025-26600 xorg-x11-server Use-after-free in PlayReleasedEvents()
- Fix CVE-2025-26601 xorg-x11-server Use-after-free in SyncInitTrigger() | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-62229', 'CVE-2025-62230', 'CVE-2025-62231'] | ['Oracle Linux 7'] | ['CVE-2025-62229', 'CVE-2025-62230', 'CVE-2025-62231', 'ELSA-2025-22096', 'https://linux.oracle.com/cve/CVE-2025-62229.html', 'https://linux.oracle.com/cve/CVE-2025-62230.html', 'https://linux.oracle.com/cve/CVE-2025-62231.html', 'https://linux.oracle.com/errata/ELSA-2025-22096.html'] | 7831bc01e755655caa8604bdc2eef1709f6135f024c730521a659652c1e51d05 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521657 | ELSA-2025-21657: libsoup security update (IMPORTANT) | [2.62.2-2.0.7]
- Backport patch for CVE-2025-4945 and CVE-2025-11021 [Orabug: 38664275]
[2.62.2-2.0.5]
- Fixes CVE-2025-2784 CVE-2025-4948 CVE-2025-32049 [Orabug: 38085184]
- CVE-2025-32906 CVE-2025-32911 CVE-2025-32913 CVE-2025-32914
[2.62.2-2.0.3]
- Fixed CVE-2024-52531 buffer overflow via UTF-8 conversion in
- soup_header_parse_param_list_strict [Orabug: 37557504] | IMPORTANT | 2025-12-10 00:00:00+03:00 | ['CVE-2025-11021', 'CVE-2025-2784', 'CVE-2025-32049', 'CVE-2025-32906', 'CVE-2025-32911', 'CVE-2025-32913', 'CVE-2025-32914', 'CVE-2025-4945', 'CVE-2025-4948'] | ['Oracle Linux 7'] | ['CVE-2025-11021', 'CVE-2025-2784', 'CVE-2025-32049', 'CVE-2025-32906', 'CVE-2025-32911', 'CVE-2025-32913', 'CVE-2025-32914', 'CVE-2025-4945', 'CVE-2025-4948', 'ELSA-2025-21657', 'https://linux.oracle.com/cve/CVE-2025-11021.html', 'https://linux.oracle.com/cve/CVE-2025-2784.html', 'https://linux.oracle.com/cve/CVE-2025-32049.html', 'https://linux.oracle.com/cve/CVE-2025-32906.html', 'https://linux.oracle.com/cve/CVE-2025-32911.html', 'https://linux.oracle.com/cve/CVE-2025-32913.html', 'https://linux.oracle.com/cve/CVE-2025-32914.html', 'https://linux.oracle.com/cve/CVE-2025-4945.html', 'https://linux.oracle.com/cve/CVE-2025-4948.html', 'https://linux.oracle.com/errata/ELSA-2025-21657.html'] | 68ce7d60ac33242c90c81b254f2e284a0b4ba9184c4cda6bed7b990b0883e055 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528041 | ELSA-2025-28041: openssl security update (MODERATE) | [3.5.1-4.0.1]
- Replace upstream references [Orabug: 34340177]
- Update FIPS provider name [Orabug: 35824276]
[1:3.5.1-4]
- Fix CVE-2025-9230
Resolves: RHEL-115885
[1:3.5.1-3]
- Add custom define to disable symbol versioning in downstream patched code
Also add stricter Suggests for openssl-fips-provider
Resolves: RHEL-101548
- Fix Requires/Provider to fix default install of fips providers
Resolves: RHEL-105010
[1:3.5.1-2]
- Move fips.so to a seprate subpackage
Reverts FIPS self test for SLH-DSA
Add Suggests to try to prefer the openssl-fips-provider package
over the fips-provider-next package by default
Revolves: RHEL-102408
Related: RHEL-80811
[1:3.5.1-1]
- Rebasing to OpenSSL 3.5.1
Resolves: RHEL-90350
Resolves: RHEL-95613
Resolves: RHEL-97796
Resolves: RHEL-99353
Resolves: RHEL-100168
[1:3.5.0-8]
- rebuilt
Related: RHEL-80811
[1:3.5.0-7]
- rebuilt
Related: RHEL-80811
[1:3.5.0-6]
- rebuilt
Related: RHEL-80811
[1:3.5.0-5]
- Compact patches for better maintainability
Related: RHEL-80811
- Make hybrid MLKEM work with our FIPS provider (3.0.7)
Resolves: RHEL-94614
[1:3.5.0-4]
- Fix regressions caused by rebase to OpenSSL 3.5
Related: RHEL-80811
- Fix UEFI builds on double function definitions
Resolves: RHEL-93168 | MODERATE | 2025-12-09 00:00:00+03:00 | ['CVE-2025-9230'] | ['Oracle Linux 10'] | ['CVE-2025-9230', 'ELSA-2025-28041', 'https://linux.oracle.com/cve/CVE-2025-9230.html', 'https://linux.oracle.com/errata/ELSA-2025-28041.html'] | 6a1fe2156204375e253bff39c3f47aadb59c288503c43831185e9f28b6af8a1f | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522854 | ELSA-2025-22854: kernel security update (MODERATE) | [6.12.0-124.20.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-124.20.1]
- iommu/vt-d: Disallow dirty tracking if incoherent page walk (CKI Backport Bot) [RHEL-125482] {CVE-2025-40058}
- net/mlx5: fs, fix UAF in flow counter release (Michal Schmidt) [RHEL-124432] {CVE-2025-39979}
- dpll: zl3073x: Fix output pin registration (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Handle missing or corrupted flash configuration (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Refactor DPLL initialization (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: ZL3073X_I2C and ZL3073X_SPI should depend on NET (Ivan Vecera) [RHEL-114795]
- dpll: Make ZL3073X invisible (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Fix build failure (Ivan Vecera) [RHEL-114795]
- redhat/configs: enable CONFIG_ZL3073X* (Ivan Vecera) [RHEL-114795]
- redhat/configs: enable CONFIG_I2C_MUX_PCA954x on x86 (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to get fractional frequency offset (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to adjust phase (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Implement phase offset monitor feature (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to get phase offset on connected input pin (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to get/set esync on pins (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to get/set frequency on pins (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Implement input pin state setting in automatic mode (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Add support to get/set priority on input pins (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Implement input pin selection in manual mode (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Register DPLL devices and pins (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Read DPLL types and pin properties from system firmware (Ivan Vecera) [RHEL-114795]
- dpll: zl3073x: Fetch invariants during probe (Ivan Vecera) [RHEL-114795]
- dpll: Add basic Microchip ZL3073x support (Ivan Vecera) [RHEL-114795]
- dt-bindings: dpll: Add support for Microchip Azurite chip family (Ivan Vecera) [RHEL-114795]
- dt-bindings: dpll: Add DPLL device and pin (Ivan Vecera) [RHEL-114795]
- idpf: set mac type when adding and removing MAC filters (CKI Backport Bot) [RHEL-123372]
- crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Fix SNP panic notifier unregistration (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Fix dereferencing uninitialized error pointer (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Fix __sev_snp_shutdown_locked (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Move SEV/SNP Platform initialization to KVM (Lenny Szubowicz) [RHEL-76557]
- KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Add new SEV/SNP platform shutdown API (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Register SNP panic notifier only if SNP is enabled (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Reset TMR size at SNP Shutdown (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Ensure implicit SEV/SNP init and shutdown in ioctls (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (Lenny Szubowicz) [RHEL-76557]
- crypto: ccp - Abort doing SEV INIT if SNP INIT fails (Lenny Szubowicz) [RHEL-76557]
- s390/pci: Do not try re-enabling load/store if device is disabled (CKI Backport Bot) [RHEL-114448]
- s390/pci: Fix stale function handles in error handling (CKI Backport Bot) [RHEL-114448]
[6.12.0-124.19.1]
- Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: MGMT: Fix sparse errors (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: MGMT: Fix possible UAFs (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: hci_sync: fix set_local_name race condition (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: MGMT: set_mesh: update LE scan interval and window (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: MGMT: Protect mgmt_pending list with its own lock (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete (CKI Backport Bot) [RHEL-122901] {CVE-2025-39981}
- Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CKI Backport Bot) [RHEL-124134] {CVE-2025-39983}
- can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (CKI Backport Bot) [RHEL-124110] {CVE-2025-39925}
- can: j1939: implement NETDEV_UNREGISTER notification handler (CKI Backport Bot) [RHEL-124110] {CVE-2025-39925}
- Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CKI Backport Bot) [RHEL-123824] {CVE-2025-39982}
[6.12.0-124.18.1]
- ice: ice_adapter: release xa entry on adapter allocation failure (CKI Backport Bot) [RHEL-128472] {CVE-2025-40185}
- cifs: Fix oops due to uninitialised variable (CKI Backport Bot) [RHEL-120562] {CVE-2025-38737}
[6.12.0-124.17.1]
- x86/hyperv: Fix kdump on Azure CVMs (Li Tian) [RHEL-129777]
- tunnels: reset the GSO metadata before reusing the skb (Antoine Tenart) [RHEL-113919]
- io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CKI Backport Bot) [RHEL-124974] {CVE-2025-40047} | MODERATE | 2025-12-08 00:00:00+03:00 | ['CVE-2025-38737', 'CVE-2025-39925', 'CVE-2025-39979', 'CVE-2025-39981', 'CVE-2025-39982', 'CVE-2025-39983', 'CVE-2025-40047', 'CVE-2025-40058', 'CVE-2025-40185'] | ['Oracle Linux 10'] | ['CVE-2025-38737', 'CVE-2025-39925', 'CVE-2025-39979', 'CVE-2025-39981', 'CVE-2025-39982', 'CVE-2025-39983', 'CVE-2025-40047', 'CVE-2025-40058', 'CVE-2025-40185', 'ELSA-2025-22854', 'https://linux.oracle.com/cve/CVE-2025-38737.html', 'https://linux.oracle.com/cve/CVE-2025-39925.html', 'https://linux.oracle.com/cve/CVE-2025-39979.html', 'https://linux.oracle.com/cve/CVE-2025-39981.html', 'https://linux.oracle.com/cve/CVE-2025-39982.html', 'https://linux.oracle.com/cve/CVE-2025-39983.html', 'https://linux.oracle.com/cve/CVE-2025-40047.html', 'https://linux.oracle.com/cve/CVE-2025-40058.html', 'https://linux.oracle.com/cve/CVE-2025-40185.html', 'https://linux.oracle.com/errata/ELSA-2025-22854.html'] | aee8fce562c9c43e931e11172c9764feed59db75425e7f89e1471d53b25dedbb | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522801 | ELSA-2025-22801: kernel security update (MODERATE) | [4.18.0-553.89.1]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]
[4.18.0-553.89.1]
- mm: memcg: use READ_ONCE()/WRITE_ONCE() to access stock->cached (Radostin Stoyanov) [RHEL-122774]
- mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() (Radostin Stoyanov) [RHEL-122774] {CVE-2023-53401}
- mm/memcg: revert ('mm/memcg: optimize user context object stock access') (Radostin Stoyanov) [RHEL-122774] {CVE-2023-53401}
- gfs2: Add proper lockspace locking (Andreas Gruenbacher) [RHEL-88660]
- gfs2: do_xmote cleanup (Andreas Gruenbacher) [RHEL-88660]
[4.18.0-553.88.1]
- scsi: s390: zfcp: Ensure synchronous unit_add (Mete Durlu) [RHEL-129199]
- RDMA/rxe: Fix incomplete state save in rxe_requester (Kamal Heib) [RHEL-124700] {CVE-2023-53539}
- RDMA/rxe: Fix mr->map double free (CKI Backport Bot) [RHEL-123715] {CVE-2022-50543} | MODERATE | 2025-12-08 00:00:00+03:00 | ['CVE-2022-50543', 'CVE-2023-53401', 'CVE-2023-53539'] | ['Oracle Linux 8'] | ['CVE-2022-50543', 'CVE-2023-53401', 'CVE-2023-53539', 'ELSA-2025-22801', 'https://linux.oracle.com/cve/CVE-2022-50543.html', 'https://linux.oracle.com/cve/CVE-2023-53401.html', 'https://linux.oracle.com/cve/CVE-2023-53539.html', 'https://linux.oracle.com/errata/ELSA-2025-22801.html'] | ff796411911b8d30b26c6ced9ecc130e50be07848e58ffe185c5229840d114fa | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522789 | ELSA-2025-22789: webkit2gtk3 security update (IMPORTANT) | [2.50.3-1]
- Update to 2.50.3 | IMPORTANT | 2025-12-08 00:00:00+03:00 | ['CVE-2023-43000', 'CVE-2025-13502', 'CVE-2025-13947', 'CVE-2025-43392', 'CVE-2025-43419', 'CVE-2025-43421', 'CVE-2025-43425', 'CVE-2025-43427', 'CVE-2025-43429', 'CVE-2025-43430', 'CVE-2025-43431', 'CVE-2025-43432', 'CVE-2025-43434', 'CVE-2025-43440', 'CVE-2025-43443', 'CVE-2025-43458', 'CVE-2025-43480', 'CVE-2025-66287'] | ['Oracle Linux 8'] | ['CVE-2023-43000', 'CVE-2025-13502', 'CVE-2025-13947', 'CVE-2025-43392', 'CVE-2025-43419', 'CVE-2025-43421', 'CVE-2025-43425', 'CVE-2025-43427', 'CVE-2025-43429', 'CVE-2025-43430', 'CVE-2025-43431', 'CVE-2025-43432', 'CVE-2025-43434', 'CVE-2025-43440', 'CVE-2025-43443', 'CVE-2025-43458', 'CVE-2025-43480', 'CVE-2025-66287', 'ELSA-2025-22789', 'https://linux.oracle.com/cve/CVE-2023-43000.html', 'https://linux.oracle.com/cve/CVE-2025-13502.html', 'https://linux.oracle.com/cve/CVE-2025-13947.html', 'https://linux.oracle.com/cve/CVE-2025-43392.html', 'https://linux.oracle.com/cve/CVE-2025-43419.html', 'https://linux.oracle.com/cve/CVE-2025-43421.html', 'https://linux.oracle.com/cve/CVE-2025-43425.html', 'https://linux.oracle.com/cve/CVE-2025-43427.html', 'https://linux.oracle.com/cve/CVE-2025-43429.html', 'https://linux.oracle.com/cve/CVE-2025-43430.html', 'https://linux.oracle.com/cve/CVE-2025-43431.html', 'https://linux.oracle.com/cve/CVE-2025-43432.html', 'https://linux.oracle.com/cve/CVE-2025-43434.html', 'https://linux.oracle.com/cve/CVE-2025-43440.html', 'https://linux.oracle.com/cve/CVE-2025-43443.html', 'https://linux.oracle.com/cve/CVE-2025-43458.html', 'https://linux.oracle.com/cve/CVE-2025-43480.html', 'https://linux.oracle.com/cve/CVE-2025-66287.html', 'https://linux.oracle.com/errata/ELSA-2025-22789.html'] | 13ce87713715ec5ca1187c6697eaeec3e270754c8be359f169405e376b2e1d0d | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522790 | ELSA-2025-22790: webkit2gtk3 security update (IMPORTANT) | [2.50.3-1]
- Update to 2.50.3 | IMPORTANT | 2025-12-08 00:00:00+03:00 | ['CVE-2023-43000', 'CVE-2025-13502', 'CVE-2025-13947', 'CVE-2025-43392', 'CVE-2025-43419', 'CVE-2025-43421', 'CVE-2025-43425', 'CVE-2025-43427', 'CVE-2025-43429', 'CVE-2025-43430', 'CVE-2025-43431', 'CVE-2025-43432', 'CVE-2025-43434', 'CVE-2025-43440', 'CVE-2025-43443', 'CVE-2025-43458', 'CVE-2025-43480', 'CVE-2025-66287'] | ['Oracle Linux 9'] | ['CVE-2023-43000', 'CVE-2025-13502', 'CVE-2025-13947', 'CVE-2025-43392', 'CVE-2025-43419', 'CVE-2025-43421', 'CVE-2025-43425', 'CVE-2025-43427', 'CVE-2025-43429', 'CVE-2025-43430', 'CVE-2025-43431', 'CVE-2025-43432', 'CVE-2025-43434', 'CVE-2025-43440', 'CVE-2025-43443', 'CVE-2025-43458', 'CVE-2025-43480', 'CVE-2025-66287', 'ELSA-2025-22790', 'https://linux.oracle.com/cve/CVE-2023-43000.html', 'https://linux.oracle.com/cve/CVE-2025-13502.html', 'https://linux.oracle.com/cve/CVE-2025-13947.html', 'https://linux.oracle.com/cve/CVE-2025-43392.html', 'https://linux.oracle.com/cve/CVE-2025-43419.html', 'https://linux.oracle.com/cve/CVE-2025-43421.html', 'https://linux.oracle.com/cve/CVE-2025-43425.html', 'https://linux.oracle.com/cve/CVE-2025-43427.html', 'https://linux.oracle.com/cve/CVE-2025-43429.html', 'https://linux.oracle.com/cve/CVE-2025-43430.html', 'https://linux.oracle.com/cve/CVE-2025-43431.html', 'https://linux.oracle.com/cve/CVE-2025-43432.html', 'https://linux.oracle.com/cve/CVE-2025-43434.html', 'https://linux.oracle.com/cve/CVE-2025-43440.html', 'https://linux.oracle.com/cve/CVE-2025-43443.html', 'https://linux.oracle.com/cve/CVE-2025-43458.html', 'https://linux.oracle.com/cve/CVE-2025-43480.html', 'https://linux.oracle.com/cve/CVE-2025-66287.html', 'https://linux.oracle.com/errata/ELSA-2025-22790.html'] | b3a2afca7427adea0f0b776f9a61b489848cae501edd2c04f48aea2edc4363b0 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202519847 | ELSA-2025-19847: sssd security update (IMPORTANT) | [1.16.5-10.0.5.16]
- krb5: disable Kerberos localauth an2ln plugin for AD/IPA [Orabug: 38621159] | IMPORTANT | 2025-12-05 00:00:00+03:00 | ['CVE-2025-11561'] | ['Oracle Linux 7'] | ['CVE-2025-11561', 'ELSA-2025-19847', 'https://linux.oracle.com/cve/CVE-2025-11561.html', 'https://linux.oracle.com/errata/ELSA-2025-19847.html'] | d1ebbca47a790b27efaf748aebd7323e81813e79be52c0b03a404a4ae664ccb4 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521931 | ELSA-2025-21931: kernel security update (MODERATE) | [6.12.0-124.13.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-124.13.1]
- NFSv4: handle ERR_GRACE on delegation recalls (Olga Kornievskaia) [RHEL-127623]
- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia) [RHEL-127623]
- Revert 'SUNRPC: Don't allow waiting for exiting tasks' (Scott Mayhew) [RHEL-110051]
- smb: client: get rid of d_drop() in cifs_do_rename() (Paulo Alcantara) [RHEL-124955]
- smb: client: fix wrong index reference in smb2_compound_op() (Paulo Alcantara) [RHEL-124955]
- smb: client: handle unlink(2) of files open by different clients (Paulo Alcantara) [RHEL-124955]
- smb: client: fix filename matching of deferred files (Paulo Alcantara) [RHEL-124955]
- fs/smb: Fix inconsistent refcnt update (Paulo Alcantara) [RHEL-124955] {CVE-2025-39819}
- ice: don't leave device non-functional if Tx scheduler config fails (Petr Oros) [RHEL-116535]
[6.12.0-124.12.1]
- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Antoine Tenart) [RHEL-120672]
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Antoine Tenart) [RHEL-120672] {CVE-2025-39955}
- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (CKI Backport Bot) [RHEL-113613] {CVE-2025-39730}
[6.12.0-124.11.1]
- of_numa: fix uninitialized memory nodes causing kernel panic (Charles Mirabile) [RHEL-123154] {CVE-2025-39903}
- redhat: use the same cert as UKI's to sign addons (Li Tian) [RHEL-124734]
- ibmveth: Add multi buffers rx replenishment hcall support (Mamatha Inamdar) [RHEL-116193]
- net: ibmveth: Reset the adapter when unexpected states are detected (Mamatha Inamdar) [RHEL-116193]
- ibmvnic: Increase max subcrq indirect entries with fallback (Mamatha Inamdar) [RHEL-116189]
- redhat: enable TDX host config (Paolo Bonzini) [RHEL-27145]
- KVM/TDX: Explicitly do WBINVD when no more TDX SEAMCALLs (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Update the kexec section in the TDX documentation (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Remove the !KEXEC_CORE dependency (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Disable kexec/kdump on platforms with TDX partial write erratum (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Mark memory cache state incoherent when making SEAMCALL (Paolo Bonzini) [RHEL-27145]
- x86/sme: Use percpu boolean to control WBINVD during kexec (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Consolidate relocate_kernel() function parameters (Paolo Bonzini) [RHEL-27145]
- x86/paravirt: Remove the WBINVD callback (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use typedef for relocate_kernel_fn function prototype (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Cope with relocate_kernel() not being at the start of the page (Paolo Bonzini) [RHEL-27145]
- kexec_core: Add and update comments regarding the KEXEC_JUMP flow (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Mark machine_kexec() with __nocfi (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Fix location of relocate_kernel with -ffunction-sections (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Fix stack and handling of re-entry point for ::preserve_context (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use correct swap page in swap_pages function (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Ensure preserve_context flag is set on return to kernel (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Disable global pages before writing to control page (Paolo Bonzini) [RHEL-27145]
- x86: Fix build regression with CONFIG_KEXEC_JUMP enabled (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Mark relocate_kernel page as ROX instead of RWX (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Clean up register usage in relocate_kernel() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Eliminate writes through kernel mapping of relocate_kernel page (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Drop page_list argument from relocate_kernel() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Add data section to relocate_kernel (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Move relocate_kernel to kernel .data section (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Invoke copy of relocate_kernel() instead of the original (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Copy control page into place in machine_kexec_prepare() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Allocate PGD for x86_64 transition page tables separately (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Only swap pages for ::preserve_context mode (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use named labels in swap_pages in relocate_kernel_64.S (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Clean up and document register use in relocate_kernel_64.S (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Restore GDT on return from ::preserve_context kexec (Paolo Bonzini) [RHEL-27145]
[6.12.0-124.10.1]
- wifi: cfg80211: fix use-after-free in cmp_bss() (CKI Backport Bot) [RHEL-122880] {CVE-2025-39864}
- selftests: tls: test skb copy under mem pressure and OOB (CKI Backport Bot) [RHEL-120380] {CVE-2025-39946}
- tls: make sure to abort the stream if headers are bogus (CKI Backport Bot) [RHEL-120380] {CVE-2025-39946}
- ixgbe: fix ixgbe_orom_civd_info struct layout (Michal Schmidt) [RHEL-119079]
- ice: fix Rx page leak on multi-buffer frames (Petr Oros) [RHEL-116543]
- eventpoll: Fix semi-unbounded recursion (CKI Backport Bot) [RHEL-111055] {CVE-2025-38614}
[6.12.0-124.9.1]
- platform/x86/intel: power-domains: Use topology_logical_package_id() for package ID (CKI Backport Bot) [RHEL-123290]
- smb: client: fix file open check in __cifs_unlink() (Paulo Alcantara) [RHEL-122417]
- smb: client: fix data loss due to broken rename(2) (Paulo Alcantara) [RHEL-122417]
- smb: client: fix compound alignment with encryption (Paulo Alcantara) [RHEL-122417]
- smb: client: fix race with concurrent opens in rename(2) (Paulo Alcantara) [RHEL-122417]
- smb: client: fix race with concurrent opens in unlink(2) (Paulo Alcantara) [RHEL-122417]
- use uniform permission checks for all mount propagation changes (Ian Kent) [RHEL-121702] {CVE-2025-38498}
- do_change_type(): refuse to operate on unmounted/not ours mounts (Ian Kent) [RHEL-121702] {CVE-2025-38498}
- cgroup/psi: Set of->priv to NULL upon file release (CKI Backport Bot) [RHEL-119143] {CVE-2025-39881}
- kernfs: Fix UAF in polling when open file is released (CKI Backport Bot) [RHEL-119143] {CVE-2025-39881}
- redhat: rpminspect: update emptyrpm list for kernel variants (Alexandra Hajkova)
- scsi: lpfc: Fix buffer free/clear order in deferred receive path (CKI Backport Bot) [RHEL-119132] {CVE-2025-39841}
- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (CKI Backport Bot) [RHEL-118462] {CVE-2025-39817}
- wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() (CKI Backport Bot) [RHEL-117585] {CVE-2025-39849}
- xfs: do not propagate ENODATA disk errors into xattr code (Carlos Maiolino) [RHEL-115733]
- ipv6: sr: Fix MAC comparison to be constant-time (CKI Backport Bot) [RHEL-116387] {CVE-2025-39702}
- s390/ism: fix concurrency management in ism_cmd() (CKI Backport Bot) [RHEL-114500]
- s390/hypfs: Enable limited access during lockdown (CKI Backport Bot) [RHEL-114431]
- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (CKI Backport Bot) [RHEL-114431]
- redhat/configs: Enable CONFIG_MITIGATION_VMSCAPE for x86 (Waiman Long) [RHEL-114276]
- x86/vmscape: Add old Intel CPUs to affected list (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Warn when STIBP is disabled with SMT (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/bugs: Move cpu_bugs_smt_update() down (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Enable the mitigation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Add conditional IBPB mitigation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Enumerate VMSCAPE bug (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- Documentation/hw-vuln: Add VMSCAPE documentation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- RDMA/mana_ib: Fix DSCP value in modify QP (Maxim Levitsky) [RHEL-114931]
- net: mana: Handle Reset Request from MANA NIC (Maxim Levitsky) [RHEL-114931]
- net: mana: Set tx_packets to post gso processing packet count (Maxim Levitsky) [RHEL-114931]
- net: mana: Handle unsupported HWC commands (Maxim Levitsky) [RHEL-114931]
- net: mana: Add handler for hardware servicing events (Maxim Levitsky) [RHEL-114931]
- net: mana: Expose additional hardware counters for drop and TC via ethtool. (Maxim Levitsky) [RHEL-114931]
- mm: swap: fix potential buffer overflow in setup_clusters() (CKI Backport Bot) [RHEL-114862] {CVE-2025-39727}
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (CKI Backport Bot) [RHEL-114852] {CVE-2025-39751}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Jaroslav Kysela) [RHEL-114693] {CVE-2025-38729}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Jaroslav Kysela) [RHEL-114693]
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (CKI Backport Bot) [RHEL-114693] {CVE-2025-39757}
- ibmvnic: Use ndo_get_stats64 to fix inaccurate SAR reporting (Mamatha Inamdar) [RHEL-114439]
- ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic sizeof (Mamatha Inamdar) [RHEL-114439]
- ibmvnic: Add stat for tx direct vs tx batched (Mamatha Inamdar) [RHEL-114439]
- vsock/virtio: Validate length in packet header before skb_put() (CKI Backport Bot) [RHEL-114301] {CVE-2025-39718}
- NFS: Fix a race when updating an existing write (CKI Backport Bot) [RHEL-113861] {CVE-2025-39697} | MODERATE | 2025-12-05 00:00:00+03:00 | ['CVE-2025-39730', 'CVE-2025-39955'] | ['Oracle Linux 10'] | ['CVE-2025-39730', 'CVE-2025-39955', 'ELSA-2025-21931', 'https://linux.oracle.com/cve/CVE-2025-39730.html', 'https://linux.oracle.com/cve/CVE-2025-39955.html', 'https://linux.oracle.com/errata/ELSA-2025-21931.html'] | c179b6357c4e6003545c6919997248bc68254d5b2c8ce1cd78a650a8df0bea78 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202619363 | ELSA-2026-19363: libtiff security update (IMPORTANT) | [4.4.0-18]
- rebuild
[4.4.0-15.3]
- fix CVE-2026-4775: signed integer overflow in putcontig8bitYCbCr44tile (RHEL-159331) | IMPORTANT | 2026-06-23 00:00:00+03:00 | ['CVE-2026-4775'] | ['Oracle Linux 9'] | ['CVE-2026-4775', 'ELSA-2026-19363', 'https://linux.oracle.com/cve/CVE-2026-4775.html', 'https://linux.oracle.com/errata/ELSA-2026-19363.html'] | e290e04dbc83c257fca0b4d8c269cb8da74462a9de2114eac7ac86340f401adc | 2026-06-24 18:41:44.947363+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522760 | ELSA-2025-22760: abrt security update (IMPORTANT) | [2.10.9-25.0.1]
- Replaces sosreport to sos report in sosreport-event.conf [Orabug: 38590929]
- abrt-dump-oops-Fix-vmcore-call-trace-parsing-arm [Orabug: 34184473]
- Disable autoreporting on Oracle Linux [Orabug: 32890748]
- Add orabug32082455-Upstream_reference_in_python3-abrt-addon.patch [Orabug: 32082455]
- Add bug29870394-fix-redhat-reference.patch [Orabug: 29870394]
- Drop libreport-rhel and libreport-plugin-rhtsupport requires
[2.10.9-25.openela.0.1]
- Remove RHT patches
[2.10.9-25]
- a-a-save-container-data: validate input
- Resolves: CVE-2025-12744 | IMPORTANT | 2025-12-05 00:00:00+03:00 | ['CVE-2025-12744'] | ['Oracle Linux 8'] | ['CVE-2025-12744', 'ELSA-2025-22760', 'https://linux.oracle.com/cve/CVE-2025-12744.html', 'https://linux.oracle.com/errata/ELSA-2025-22760.html'] | 2fc3acdd7d31bed7ec9211c42e9abb79d83d97163207c88f19c04ec2912fda70 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elba:def:202520993 | ELBA-2025-20993: .NET 10.0 bug fix and enhancement update (IMPORTANT) | [10.0.100~rc.2.25502.107-0.12.0.1]
- Add support for Oracle Linux
[10.0.100~rc.2.25502.107-0.12]
- Update to .NET SDK 10.0.100-rc.2.25502.107 and Runtime 10.0.0-rc.2.25502.107
- Resolves: RHEL-121558
[10.0.100~rc.1.25451.107-0.11]
- Disable bootstrap
- Related: RHEL-114571
[10.0.100~rc.1.25451.107-0.10]
- Update to .NET 10 RC 1
- Resolves: RHEL-114571 | IMPORTANT | 2025-12-03 00:00:00+03:00 | ['CVE-2025-55247', 'CVE-2025-55315'] | ['Oracle Linux 10'] | ['CVE-2025-55247', 'CVE-2025-55315', 'ELBA-2025-20993', 'https://linux.oracle.com/cve/CVE-2025-55247.html', 'https://linux.oracle.com/cve/CVE-2025-55315.html', 'https://linux.oracle.com/errata/ELBA-2025-20993.html'] | e6a82c37bfc4315c08e3a1388c436ebe446bde395a70ccc96fd8b2a73966811c | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521463 | ELSA-2025-21463: kernel security update (MODERATE) | [6.12.0-124.13.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-124.13.1]
- NFSv4: handle ERR_GRACE on delegation recalls (Olga Kornievskaia) [RHEL-127623]
- nfsd: nfserr_jukebox in nlm_fopen should lead to a retry (Olga Kornievskaia) [RHEL-127623]
- Revert 'SUNRPC: Don't allow waiting for exiting tasks' (Scott Mayhew) [RHEL-110051]
- smb: client: get rid of d_drop() in cifs_do_rename() (Paulo Alcantara) [RHEL-124955]
- smb: client: fix wrong index reference in smb2_compound_op() (Paulo Alcantara) [RHEL-124955]
- smb: client: handle unlink(2) of files open by different clients (Paulo Alcantara) [RHEL-124955]
- smb: client: fix filename matching of deferred files (Paulo Alcantara) [RHEL-124955]
- fs/smb: Fix inconsistent refcnt update (Paulo Alcantara) [RHEL-124955] {CVE-2025-39819}
- ice: don't leave device non-functional if Tx scheduler config fails (Petr Oros) [RHEL-116535]
[6.12.0-124.12.1]
- tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). (Antoine Tenart) [RHEL-120672]
- tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect(). (Antoine Tenart) [RHEL-120672] {CVE-2025-39955}
- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (CKI Backport Bot) [RHEL-113613] {CVE-2025-39730}
[6.12.0-124.11.1]
- of_numa: fix uninitialized memory nodes causing kernel panic (Charles Mirabile) [RHEL-123154] {CVE-2025-39903}
- redhat: use the same cert as UKI's to sign addons (Li Tian) [RHEL-124734]
- ibmveth: Add multi buffers rx replenishment hcall support (Mamatha Inamdar) [RHEL-116193]
- net: ibmveth: Reset the adapter when unexpected states are detected (Mamatha Inamdar) [RHEL-116193]
- ibmvnic: Increase max subcrq indirect entries with fallback (Mamatha Inamdar) [RHEL-116189]
- redhat: enable TDX host config (Paolo Bonzini) [RHEL-27145]
- KVM/TDX: Explicitly do WBINVD when no more TDX SEAMCALLs (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Update the kexec section in the TDX documentation (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Remove the !KEXEC_CORE dependency (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Disable kexec/kdump on platforms with TDX partial write erratum (Paolo Bonzini) [RHEL-27145]
- x86/virt/tdx: Mark memory cache state incoherent when making SEAMCALL (Paolo Bonzini) [RHEL-27145]
- x86/sme: Use percpu boolean to control WBINVD during kexec (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Consolidate relocate_kernel() function parameters (Paolo Bonzini) [RHEL-27145]
- x86/paravirt: Remove the WBINVD callback (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use typedef for relocate_kernel_fn function prototype (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Cope with relocate_kernel() not being at the start of the page (Paolo Bonzini) [RHEL-27145]
- kexec_core: Add and update comments regarding the KEXEC_JUMP flow (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Mark machine_kexec() with __nocfi (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Fix location of relocate_kernel with -ffunction-sections (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Fix stack and handling of re-entry point for ::preserve_context (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use correct swap page in swap_pages function (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Ensure preserve_context flag is set on return to kernel (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Disable global pages before writing to control page (Paolo Bonzini) [RHEL-27145]
- x86: Fix build regression with CONFIG_KEXEC_JUMP enabled (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Mark relocate_kernel page as ROX instead of RWX (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Clean up register usage in relocate_kernel() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Eliminate writes through kernel mapping of relocate_kernel page (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Drop page_list argument from relocate_kernel() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Add data section to relocate_kernel (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Move relocate_kernel to kernel .data section (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Invoke copy of relocate_kernel() instead of the original (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Copy control page into place in machine_kexec_prepare() (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Allocate PGD for x86_64 transition page tables separately (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Only swap pages for ::preserve_context mode (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Use named labels in swap_pages in relocate_kernel_64.S (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Clean up and document register use in relocate_kernel_64.S (Paolo Bonzini) [RHEL-27145]
- x86/kexec: Restore GDT on return from ::preserve_context kexec (Paolo Bonzini) [RHEL-27145]
[6.12.0-124.10.1]
- wifi: cfg80211: fix use-after-free in cmp_bss() (CKI Backport Bot) [RHEL-122880] {CVE-2025-39864}
- selftests: tls: test skb copy under mem pressure and OOB (CKI Backport Bot) [RHEL-120380] {CVE-2025-39946}
- tls: make sure to abort the stream if headers are bogus (CKI Backport Bot) [RHEL-120380] {CVE-2025-39946}
- ixgbe: fix ixgbe_orom_civd_info struct layout (Michal Schmidt) [RHEL-119079]
- ice: fix Rx page leak on multi-buffer frames (Petr Oros) [RHEL-116543]
- eventpoll: Fix semi-unbounded recursion (CKI Backport Bot) [RHEL-111055] {CVE-2025-38614}
[6.12.0-124.9.1]
- platform/x86/intel: power-domains: Use topology_logical_package_id() for package ID (CKI Backport Bot) [RHEL-123290]
- smb: client: fix file open check in __cifs_unlink() (Paulo Alcantara) [RHEL-122417]
- smb: client: fix data loss due to broken rename(2) (Paulo Alcantara) [RHEL-122417]
- smb: client: fix compound alignment with encryption (Paulo Alcantara) [RHEL-122417]
- smb: client: fix race with concurrent opens in rename(2) (Paulo Alcantara) [RHEL-122417]
- smb: client: fix race with concurrent opens in unlink(2) (Paulo Alcantara) [RHEL-122417]
- use uniform permission checks for all mount propagation changes (Ian Kent) [RHEL-121702] {CVE-2025-38498}
- do_change_type(): refuse to operate on unmounted/not ours mounts (Ian Kent) [RHEL-121702] {CVE-2025-38498}
- cgroup/psi: Set of->priv to NULL upon file release (CKI Backport Bot) [RHEL-119143] {CVE-2025-39881}
- kernfs: Fix UAF in polling when open file is released (CKI Backport Bot) [RHEL-119143] {CVE-2025-39881}
- redhat: rpminspect: update emptyrpm list for kernel variants (Alexandra Hajkova)
- scsi: lpfc: Fix buffer free/clear order in deferred receive path (CKI Backport Bot) [RHEL-119132] {CVE-2025-39841}
- efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (CKI Backport Bot) [RHEL-118462] {CVE-2025-39817}
- wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() (CKI Backport Bot) [RHEL-117585] {CVE-2025-39849}
- xfs: do not propagate ENODATA disk errors into xattr code (Carlos Maiolino) [RHEL-115733]
- ipv6: sr: Fix MAC comparison to be constant-time (CKI Backport Bot) [RHEL-116387] {CVE-2025-39702}
- s390/ism: fix concurrency management in ism_cmd() (CKI Backport Bot) [RHEL-114500]
- s390/hypfs: Enable limited access during lockdown (CKI Backport Bot) [RHEL-114431]
- s390/hypfs: Avoid unnecessary ioctl registration in debugfs (CKI Backport Bot) [RHEL-114431]
- redhat/configs: Enable CONFIG_MITIGATION_VMSCAPE for x86 (Waiman Long) [RHEL-114276]
- x86/vmscape: Add old Intel CPUs to affected list (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Warn when STIBP is disabled with SMT (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/bugs: Move cpu_bugs_smt_update() down (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Enable the mitigation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Add conditional IBPB mitigation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- x86/vmscape: Enumerate VMSCAPE bug (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- Documentation/hw-vuln: Add VMSCAPE documentation (Waiman Long) [RHEL-114276] {CVE-2025-40300}
- RDMA/mana_ib: Fix DSCP value in modify QP (Maxim Levitsky) [RHEL-114931]
- net: mana: Handle Reset Request from MANA NIC (Maxim Levitsky) [RHEL-114931]
- net: mana: Set tx_packets to post gso processing packet count (Maxim Levitsky) [RHEL-114931]
- net: mana: Handle unsupported HWC commands (Maxim Levitsky) [RHEL-114931]
- net: mana: Add handler for hardware servicing events (Maxim Levitsky) [RHEL-114931]
- net: mana: Expose additional hardware counters for drop and TC via ethtool. (Maxim Levitsky) [RHEL-114931]
- mm: swap: fix potential buffer overflow in setup_clusters() (CKI Backport Bot) [RHEL-114862] {CVE-2025-39727}
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (CKI Backport Bot) [RHEL-114852] {CVE-2025-39751}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Jaroslav Kysela) [RHEL-114693] {CVE-2025-38729}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Jaroslav Kysela) [RHEL-114693]
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (CKI Backport Bot) [RHEL-114693] {CVE-2025-39757}
- ibmvnic: Use ndo_get_stats64 to fix inaccurate SAR reporting (Mamatha Inamdar) [RHEL-114439]
- ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic sizeof (Mamatha Inamdar) [RHEL-114439]
- ibmvnic: Add stat for tx direct vs tx batched (Mamatha Inamdar) [RHEL-114439]
- vsock/virtio: Validate length in packet header before skb_put() (CKI Backport Bot) [RHEL-114301] {CVE-2025-39718}
- NFS: Fix a race when updating an existing write (CKI Backport Bot) [RHEL-113861] {CVE-2025-39697} | MODERATE | 2025-12-04 00:00:00+03:00 | ['CVE-2025-38614', 'CVE-2025-39864', 'CVE-2025-39903', 'CVE-2025-39946'] | ['Oracle Linux 10'] | ['CVE-2025-38614', 'CVE-2025-39864', 'CVE-2025-39903', 'CVE-2025-39946', 'ELSA-2025-21463', 'https://linux.oracle.com/cve/CVE-2025-38614.html', 'https://linux.oracle.com/cve/CVE-2025-39864.html', 'https://linux.oracle.com/cve/CVE-2025-39903.html', 'https://linux.oracle.com/cve/CVE-2025-39946.html', 'https://linux.oracle.com/errata/ELSA-2025-21463.html'] | dbe3af77c6837cf21bfc02668a7a833a78becf6764311c660aa7c54921a556f8 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202520343 | ELSA-2025-20343: systemd security update (IMPORTANT) | [239-82.0.4.5]
- coredump: use %d in kernel core pattern - CVE-2025-4598 | IMPORTANT | 2025-05-29 00:00:00+03:00 | ['CVE-2025-4598'] | ['Oracle Linux 8'] | ['CVE-2025-4598', 'ELSA-2025-20343', 'https://linux.oracle.com/cve/CVE-2025-4598.html', 'https://linux.oracle.com/errata/ELSA-2025-20343.html'] | b97a44edc3994805bf0b4f23e1324a041355268c9269007d1cf289bf0df75cd7 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202520344 | ELSA-2025-20344: systemd security update (IMPORTANT) | [252-51.0.2]
- coredump: use %d in kernel core pattern - CVE-2025-4598 | IMPORTANT | 2025-05-29 00:00:00+03:00 | ['CVE-2025-4598'] | ['Oracle Linux 9'] | ['CVE-2025-4598', 'ELSA-2025-20344', 'https://linux.oracle.com/cve/CVE-2025-4598.html', 'https://linux.oracle.com/errata/ELSA-2025-20344.html'] | 0e04461b8ae8ea20a90d2fbd358079f8ae1d5641816f2e004434d3ee687ffacc | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521037 | ELSA-2025-21037: qt6-qtsvg security update (IMPORTANT) | [6.9.1-2.1]
- Fix CVE-2025-10729: Prevent dangling pointers in SVG group node creation
Resolves: RHEL-119699 | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-10729'] | ['Oracle Linux 10'] | ['CVE-2025-10729', 'ELSA-2025-21037', 'https://linux.oracle.com/cve/CVE-2025-10729.html', 'https://linux.oracle.com/errata/ELSA-2025-21037.html'] | ba954bf9a4d3c0fc86f69e8dcb92244706af30fcec86dbb8ceb2d21a1eb7c37e | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521281 | ELSA-2025-21281: firefox security update (IMPORTANT) | [140.5.0-2.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079773]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red Hat file
[140.5.0-2]
- Update to 140.5.0 ESR | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020'] | ['Oracle Linux 10'] | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020', 'ELSA-2025-21281', 'https://linux.oracle.com/cve/CVE-2025-13012.html', 'https://linux.oracle.com/cve/CVE-2025-13013.html', 'https://linux.oracle.com/cve/CVE-2025-13014.html', 'https://linux.oracle.com/cve/CVE-2025-13015.html', 'https://linux.oracle.com/cve/CVE-2025-13016.html', 'https://linux.oracle.com/cve/CVE-2025-13017.html', 'https://linux.oracle.com/cve/CVE-2025-13018.html', 'https://linux.oracle.com/cve/CVE-2025-13019.html', 'https://linux.oracle.com/cve/CVE-2025-13020.html', 'https://linux.oracle.com/errata/ELSA-2025-21281.html'] | c2828b57bbf307f43c4671ef0252482ec05b78a730e9037b5014736bcc941733 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521036 | ELSA-2025-21036: pcs security update (IMPORTANT) | [0.12.1-1.el10_1.1]
- Fixed CVE-2025-59830, CVE-2025-61770, CVE-2025-61771, CVE-2025-61772, CVE-2025-61919 by updating bundled rubygem rack
Resolves: RHEL-120945, RHEL-121035, RHEL-123630, RHEL-123642, RHEL-124938 | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-59830', 'CVE-2025-61770', 'CVE-2025-61771', 'CVE-2025-61772', 'CVE-2025-61919'] | ['Oracle Linux 10'] | ['CVE-2025-59830', 'CVE-2025-61770', 'CVE-2025-61771', 'CVE-2025-61772', 'CVE-2025-61919', 'ELSA-2025-21036', 'https://linux.oracle.com/cve/CVE-2025-59830.html', 'https://linux.oracle.com/cve/CVE-2025-61770.html', 'https://linux.oracle.com/cve/CVE-2025-61771.html', 'https://linux.oracle.com/cve/CVE-2025-61772.html', 'https://linux.oracle.com/cve/CVE-2025-61919.html', 'https://linux.oracle.com/errata/ELSA-2025-21036.html'] | cd62c37ceed9a0353b768a89c3401bf4a7be41d0321edf9a6b1834aeb92a1942 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202611412 | ELSA-2026-11412: yggdrasil-worker-package-manager security update (IMPORTANT) | [0.2.3-5]
- Bump release for rebuild | IMPORTANT | 2026-04-28 00:00:00+03:00 | ['CVE-2026-25679'] | ['Oracle Linux 10'] | ['CVE-2026-25679', 'ELSA-2026-11412', 'https://linux.oracle.com/cve/CVE-2026-25679.html', 'https://linux.oracle.com/errata/ELSA-2026-11412.html'] | 8728c675686e1472fc9d55af65a65e8b49e0fe6cd679a4292664bd07f7e9c676 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521035 | ELSA-2025-21035: xorg-x11-server-Xwayland security update (MODERATE) | [24.1.5-5]
- CVE fix for: CVE-2025-62229 (RHEL-119965), CVE-2025-62230 (RHEL-120014),
CVE-2025-62231 (RHEL-125004) | MODERATE | 2025-12-02 00:00:00+03:00 | ['CVE-2025-62229', 'CVE-2025-62230', 'CVE-2025-62231'] | ['Oracle Linux 10'] | ['CVE-2025-62229', 'CVE-2025-62230', 'CVE-2025-62231', 'ELSA-2025-21035', 'https://linux.oracle.com/cve/CVE-2025-62229.html', 'https://linux.oracle.com/cve/CVE-2025-62230.html', 'https://linux.oracle.com/cve/CVE-2025-62231.html', 'https://linux.oracle.com/errata/ELSA-2025-21035.html'] | 7ad4a539c3d338ad24863cf4710680a1cfe1a9fc6f1a956b833ea3e8cce471f3 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202520983 | ELSA-2025-20983: podman security update (IMPORTANT) | [5.6.0-6.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.6.0-6]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
(https://github.com/containers/podman/commit/2791007)
- fixes '[Minor Incident] CVE-2025-52881 podman: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [rhel-10.1.z]'
- Resolves: RHEL-126635
[7:5.6.0-5]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
(https://github.com/containers/podman/commit/61231e1)
- fixes 'Timeouts while pushing Sigstore logs to Rekor - [RHEL 10.1] 0day'
- Resolves: RHEL-111077 | IMPORTANT | 2025-12-03 00:00:00+03:00 | ['CVE-2025-47907', 'CVE-2025-9566'] | ['Oracle Linux 10'] | ['CVE-2025-47907', 'CVE-2025-9566', 'ELSA-2025-20983', 'https://linux.oracle.com/cve/CVE-2025-47907.html', 'https://linux.oracle.com/cve/CVE-2025-9566.html', 'https://linux.oracle.com/errata/ELSA-2025-20983.html'] | 18d1549e12312736bd0572465114164092c8fb1dcce200ebd56c0617ba6ba689 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521485 | ELSA-2025-21485: java-25-openjdk security update (MODERATE) | [1:25.0.1.0.8-2.0.1]
- Add Oracle vendor bug URL [Orabug: 34340155]
[1:25.0.1.0.8-2]
- Remove superfluous backslashes that cause two alternative commands to be combined
- Related: RHEL-120553
[1:25.0.1.0.8-1]
- Update to jdk-25.0.1+8 (GA)
- Update release notes with features of JDK 25
- Mention finalisation JEP for features finalised in JDK 22, 23 & 24
- Drop fakefeaturever now we have reached OpenJDK 25
- Update release notes to 25.0.1+8
- Sync the copy of the portable specfile with the latest update
- Resolves: RHEL-120553
[1:24.0.2.0.12-1]
- Update to jdk-24.0.2+12 (GA)
- Update release notes with features of JDK 24
- alt-java man page installation is now handled by the OpenJDK build
- Adjust TestTranslations.java with updated German translations from CLDR 46 (JDK-8333582) (Mountain->Mountains)
- Run javap with the disassembled code (-c) option now required for -l by JDK-8345145
- Sync the copy of the portable specfile with the latest update
- Remove default.policy and java.policy following JDK-8338411: 'Permanently Disable the Security Manager'
- Make man page handling dependent on pandoc being available during the portable build
- Handle new CDS archive variants (*_coh*) added by Compact Object Headers (JDK-8305895)
- Add missing man page alternatives for jdeprscan, jfr, jhsdb, jimage, jlink & jmod and fix alphabetical ordering
- Support jnativescan added by JDK-8317611: 'Add a tool like jdeprscan to find usage of restricted methods'
- Add recent native libraries to _privatelibs (libjsvml.so, libsimdsort.so, libsyslookup.so)
- Support libsleef on AArch64 & RISC-V added by JDK-8329816, JDK-8320500 (RISC-V) & JDK-8312425 (AArch64)
- Related: RHEL-120553
[1:23.0.2.0.7-1]
- Update to jdk-23.0.2+7 (GA)
- Update release notes with features of JDK 23
- Sync the copy of the portable specfile with the latest update
- Remove lible.so handling following its removal in JDK-8327476: 'Upgrade JLine to 3.26.1'
- Install jaxp-strict.properties.template added by JDK-8330542: 'Template for Creating Strict JAXP Configuration File'
- Related: RHEL-120553 | MODERATE | 2025-12-03 00:00:00+03:00 | ['CVE-2025-53057', 'CVE-2025-53066', 'CVE-2025-61748'] | ['Oracle Linux 10'] | ['CVE-2025-53057', 'CVE-2025-53066', 'CVE-2025-61748', 'ELSA-2025-21485', 'https://linux.oracle.com/cve/CVE-2025-53057.html', 'https://linux.oracle.com/cve/CVE-2025-53066.html', 'https://linux.oracle.com/cve/CVE-2025-61748.html', 'https://linux.oracle.com/errata/ELSA-2025-21485.html'] | dbfea9ef0d83e37ef6b51e1d002818516cca98fd1b38ca4885026095e9d72721 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202519105 | ELSA-2025-19105: kernel security update (MODERATE) | [5.14.0-570.58.1.0.1]
- nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985764]
[5.14.0-570.58.1]
- pstore/ram: Check start of empty przs during init (CKI Backport Bot) [RHEL-122067] {CVE-2023-53331}
- vsock/virtio: Validate length in packet header before skb_put() (Jon Maloy) [RHEL-114299] {CVE-2025-39718}
[5.14.0-570.57.1]
- NFSv4/flexfiles: Fix layout merge mirror check. (Benjamin Coddington) [RHEL-118731]
- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() (CKI Backport Bot) [RHEL-113610] {CVE-2025-39730}
[5.14.0-570.56.1]
- NFS: Return the file btime in the statx results when appropriate (Benjamin Coddington) [RHEL-111706]
- nfs: Add timecreate to nfs inode (Benjamin Coddington) [RHEL-111706]
- Expand the type of nfs_fattr->valid (Benjamin Coddington) [RHEL-111706]
- smb: client: fix wrong index reference in smb2_compound_op() (Paulo Alcantara) [RHEL-117879]
- smb: client: handle unlink(2) of files open by different clients (Paulo Alcantara) [RHEL-117879]
- smb: client: fix file open check in __cifs_unlink() (Paulo Alcantara) [RHEL-117879]
- smb: client: fix filename matching of deferred files (Paulo Alcantara) [RHEL-117879]
- smb: client: fix data loss due to broken rename(2) (Paulo Alcantara) [RHEL-117879]
- smb: client: fix compound alignment with encryption (Paulo Alcantara) [RHEL-117879]
- fs/smb: Fix inconsistent refcnt update (Paulo Alcantara) [RHEL-117879] {CVE-2025-39819}
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (CKI Backport Bot) [RHEL-114848] {CVE-2025-39751}
- NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY (Benjamin Coddington) [RHEL-116232]
- xfs: make sure sb_fdblocks is non-negative (CKI Backport Bot) [RHEL-114540]
- block: fix adding folio to bio (Ming Lei) [RHEL-96789] | MODERATE | 2025-10-28 00:00:00+03:00 | ['CVE-2023-53331', 'CVE-2025-39718', 'CVE-2025-39730', 'CVE-2025-39751', 'CVE-2025-39819'] | ['Oracle Linux 9'] | ['CVE-2023-53331', 'CVE-2025-39718', 'CVE-2025-39730', 'CVE-2025-39751', 'CVE-2025-39819', 'ELSA-2025-19105', 'https://linux.oracle.com/cve/CVE-2023-53331.html', 'https://linux.oracle.com/cve/CVE-2025-39718.html', 'https://linux.oracle.com/cve/CVE-2025-39730.html', 'https://linux.oracle.com/cve/CVE-2025-39751.html', 'https://linux.oracle.com/cve/CVE-2025-39819.html', 'https://linux.oracle.com/errata/ELSA-2025-19105.html'] | 05fbd9e99027fdebfa30fd0c153cad8dece7d5234a157a9ff361bd8fac60f0f9 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20210558 | ELSA-2021-0558: kernel security, bug fix, and enhancement update (IMPORTANT) | [4.18.0-240.15.1_3.OL8]
- Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15-2.0.3.el7
[4.18.0-240.15.1_3]
- [x86] kvm: svm: Initialize prev_ga_tag before use (Vitaly Kuznetsov) [1919885 1909254]
- [net] tls: move mark_tech_preview to tls_init (Sabrina Dubroca) [1918743 1907477]
- [video] hyperv_fb: Fix the cache type when mapping the VRAM (Mohammed Gamal) [1917711 1908893]
- [video] hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (Mohammed Gamal) [1917711 1908893]
- [net] esp: select CRYPTO_SEQIV (Vladis Dronov) [1912872 1905088]
- [crypto] treewide: Use fallthrough pseudo-keyword (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: drbg - always try to free Jitter RNG instance (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: drbg - should select CTR (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: ctr - no longer needs CRYPTO_SEQIV (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: drbg - always seeded with SP800-90B compliant noise source (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: jitter - SP800-90B compliance (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: jitter - add header to fix buildwarnings (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: jitter - fix comments (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: jitter - update implementation to 2.1.2 (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: drbg - in-place cipher operation for CTR (Vladis Dronov) [1912872 1905088]
- [crypto] crypto: drbg - eliminate constant reinitialization of SGL (Vladis Dronov) [1912872 1905088]
- [netdrv] ionic: start queues before announcing link up (Jonathan Toppins) [1918372 1906250]
- [drm] drm/i915: Enable Tigerlake support by default (Lyude Paul) [1882620 1877005]
- [drm] drm/i915: Simplify intel_set_cdclk_{pre, post}_plane_update() calling convention (Lyude Paul) [1882620 1877005]
- [drm] drm/i915/psr: Program default IO buffer Wake and Fast Wake (Lyude Paul) [1882620 1877005]
- [kernel] rcu: Force on tick when invoking lots of callbacks (Waiman Long) [1915638 1862812]
- [kernel] nohz: Add TICK_DEP_BIT_RCU (Waiman Long) [1915638 1862812]
- [pci] PCI: Mark AMD Navi10 GPU rev 0x00 ATS as broken (Myron Stowe) [1906516 1888310]
[4.18.0-240.14.1_3]
- [netdrv] net: usb: lan78xx: Disable interrupts before calling generic_handle_irq() (Waiman Long) [1915814 1904213]
- [mm] x86/mm/cpa: Prevent large page split when ftrace flips RW on kernel text (Waiman Long) [1915814 1904213]
- [mm] x86/mm/cpa: Fix cpa_flush_array() TLB invalidation (Waiman Long) [1915814 1904213]
- [hv] hv: vmbus: Add timeout to vmbus_wait_for_unload (Mohammed Gamal) [1913528 1888980]
- [kernel] perf/core: Fix race in the perf_mmap_close() function (Michael Petlan) [1897016 1869925] {CVE-2020-14351}
- [kernel] perf: Make struct ring_buffer less ambiguous (Michael Petlan) [1897016 1869925] {CVE-2020-14351}
- [tty] tty: Fix ->pgrp locking in tiocspgrp() (Waiman Long) [1908196 1908197] {CVE-2020-29661}
- [x86] x86/tboot: Don't disable swiotlb when iommu is forced on (Tony Camuso) [1911555 1883395]
- [iommu] iommu/vt-d: Avoid panic if iommu init fails in tboot system (Tony Camuso) [1911555 1883395]
- [kernel] sched/deadline: Fix priority inheritance with multiple scheduling classes (Phil Auld) [1908731 1780490]
- [kernel] locking/rwsem: Remove reader optimistic spinning (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Enable reader optimistic lock stealing (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Prevent potential lock starvation (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Pass the current atomic count to rwsem_down_read_slowpath() (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Fold __down_{read,write}*() (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Introduce rwsem_write_trylock() (Waiman Long) [1908519 1895046]
- [kernel] locking/rwsem: Better collate rwsem_read_trylock() (Waiman Long) [1908519 1895046]
- [kernel] rwsem: Implement down_read_interruptible (Waiman Long) [1908519 1895046]
- [kernel] rwsem: Implement down_read_killable_nested (Waiman Long) [1908519 1895046]
- [firmware] efi/esrt: Only call efi_mem_reserve() for boot services memory (Kairui Song) [1907775 1878024]
- [firmware] efi: Drop type and attribute checks in efi_mem_desc_lookup() (Kairui Song) [1907775 1878024]
- [scsi] scsi: core: Don't start concurrent async scan on same host (Ming Lei) [1905214 1874501]
[4.18.0-240.13.1_3]
- [arm64] arm64: pgtable: Ensure dirty bit is preserved across pte_wrprotect() (Andrew Jones) [1909577 1908439]
- [arm64] arm64: pgtable: Fix pte_accessible() (Andrew Jones) [1909577 1908439]
- [net] icmp: randomize the global rate limiter (Guillaume Nault) [1906371 1896516] {CVE-2020-25705}
- [tools] kvm: x86: do not attempt TSC synchronization on guest writes (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: x86: fix MSR_IA32_TSC read for nested migration (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: nsvm: delay MSR permission processing to first nested VM run (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: x86: rename KVM_REQ_GET_VMCS12_PAGES (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: use __GFP_ZERO instead of clear_page (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: refactor msr permission bitmap allocation (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: rename a variable in the svm_create_vcpu (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: nsvm: Avoid freeing uninitialized pointers in svm_set_nested_state() (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: nested: Don't allocate VMCB structures on stack (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: nsvm: more strict SMM checks when returning to nested guest (Paolo Bonzini) [1905084 1898018]
- [x86] svm: nsvm: setup nested msr permission bitmap on nested state load (Paolo Bonzini) [1905084 1898018]
- [x86] svm: nsvm: correctly restore GIF on vmexit from nesting after migration (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: avoid emulation with stale next_rip (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: nsvm: remove nonsensical EXITINFO1 adjustment on nested NPF (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: Rename svm_nested_virtualize_tpr() to nested_svm_virtualize_tpr() (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: Add svm_ prefix to set/clr/is_intercept() (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: Add vmcb_ prefix to mark_*() functions (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: svm: Rename struct nested_state to svm_nested_state (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: nsvm: Check that DR6[63:32] and DR7[64:32] are not set on vmrun of nested guests (Paolo Bonzini) [1905084 1898018]
- [x86] kvm: x86: Move the check for upper 32 reserved bits of DR6 to separate function (Paolo Bonzini) [1905084 1898018]
- [netdrv] net/mlx5e: Add IPv6 traffic class (DSCP) header rewrite support (Alaa Hleihel) [1897688 1889981]
- [netdrv] net/mlx5e: Fix endianness when calculating pedit mask first bit (Alaa Hleihel) [1897688 1889981]
- [net] openvswitch: fix to make sure flow_lookup() is not preempted (Eelco Chaudron) [1893281 1888237]
[4.18.0-240.12.1_3]
- [net] SUNRPC: Properly set the @subbuf parameter of xdr_buf_subsegment() (Steve Dickson) [1912478 1884361]
- [net] SUNRPC: Fix ('SUNRPC: Add '@len' parameter to gss_unwrap()') (Steve Dickson) [1912478 1884361]
- [mm] x86/ioremap: Map EFI runtime services data as encrypted for SEV (Lenny Szubowicz) [1909243 1883134]
- [kernel] sched/deadline: Unthrottle PI boosted threads while enqueuing (Daniel Bristot de Oliveira) [1913964 1869760]
- [kernel] sched/deadline: Fix stale throttling on de-/boosted tasks (Daniel Bristot de Oliveira) [1913964 1869760]
- [fs] NFSv4.1 handle ERR_DELAY error reclaiming locking state on delegation recall (Scott Mayhew) [1908313 1881550]
- [fs] NFS: Fix interrupted slots by sending a solo SEQUENCE operation (Scott Mayhew) [1908312 1887577]
- [net] netfilter: bridge: reset skb->pkt_type after NF_INET_POST_ROUTING traversal (Antoine Tenart) [1907576 1901026]
- [powerpc] powerpc/powernv/opal-dump : Use IRQ_HANDLED instead of numbers in interrupt handler (Diego Domingos) [1907301 1891822]
- [powerpc] powerpc/powernv/dump: Handle multiple writes to ack attribute (Diego Domingos) [1907301 1891822]
- [powerpc] powerpc/powernv/dump: Fix race while processing OPAL dump (Diego Domingos) [1907301 1891822]
- [powerpc] powerpc/opal_elog: Handle multiple writes to ack attribute (Diego Domingos) [1907301 1891822]
- [powerpc] powerpc/powernv/elog: Fix race while processing OPAL error log event (Diego Domingos) [1907301 1891822]
- [block] block: fix incorrect branching in blk_max_size_offset() (Mike Snitzer) [1905136 1903722]
- [md] dm: fix IO splitting (Mike Snitzer) [1905136 1903722]
- [block] block: fix get_max_io_size() (Mike Snitzer) [1905136 1903722]
- [block] block: Improve physical block alignment of split bios (Mike Snitzer) [1905136 1903722]
- [block] block: use gcd() to fix chunk_sectors limit stacking (Mike Snitzer) [1905136 1903722]
- [netdrv] net/mlx5e: Add LAG warning if bond slave is not lag master (Alaa Hleihel) [1892344 1851709]
- [netdrv] net/mlx5e: Add LAG warning for unsupported tx type (Alaa Hleihel) [1892344 1851709]
- [netdrv] net/mlx5e: Return a valid errno if can't get lag device index (Alaa Hleihel) [1892344 1851709]
- [net] openvswitch: handle DNAT tuple collision (Dumitru Ceara) [1892744 1877128]
- [mm] mm/page_idle.c: skip offline pages (Chris von Recklinghausen) [1903019 1867490]
- [include] mm/hotplug: invalid PFNs from pfn_to_online_page() (Waiman Long) [1903019 1878006]
[4.18.0-240.11.1_3]
- [scsi] scsi: core: Return BLK_STS_AGAIN for ALUA transitioning (Ewan Milne) [1900112 1867264]
- [scsi] scsi: scsi_dh_alua: Set 'transitioning' state on Unit Attention (Ewan Milne) [1900112 1867264]
- [scsi] scsi: scsi_dh_alua: Return BLK_STS_AGAIN for ALUA transitioning state (Ewan Milne) [1900112 1867264]
- [block] scsi: block: Return status code in blk_mq_end_request() (Ewan Milne) [1900112 1867264]
- [include] compiler_attributes.h: Add 'fallthrough' pseudo keyword for switch/case use (Ivan Vecera) [1900112 1867168]
- [net] net: sctp: Rename fallthrough label to unhandled (Ivan Vecera) [1900112 1867168]
- [idle] intel_idle: Customize IceLake server support (David Arcari) [1897183 1881620] | IMPORTANT | 2021-02-17 00:00:00+03:00 | ['CVE-2020-14351', 'CVE-2020-25705', 'CVE-2020-29661'] | ['Oracle Linux 8'] | ['CVE-2020-14351', 'CVE-2020-25705', 'CVE-2020-29661', 'ELSA-2021-0558', 'https://linux.oracle.com/cve/CVE-2020-14351.html', 'https://linux.oracle.com/cve/CVE-2020-25705.html', 'https://linux.oracle.com/cve/CVE-2020-29661.html', 'https://linux.oracle.com/errata/ELSA-2021-0558.html'] | 9d32a157fc089e9d2efb0a88bd22dc2204a60bad1edf1e897bbb8c3e78e42cbc | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20205350 | ELSA-2020-5350: net-snmp security update (IMPORTANT) | [1:5.7.2-49.1]
- fix CVE-2020-15862 (#1875496) | IMPORTANT | 2020-12-07 00:00:00+03:00 | ['CVE-2020-15862'] | ['Oracle Linux 7'] | ['CVE-2020-15862', 'ELSA-2020-5350', 'https://linux.oracle.com/cve/CVE-2020-15862.html', 'https://linux.oracle.com/errata/ELSA-2020-5350.html'] | 7a93f3c90d7cd6c9663cd25950988c576f459a9c863f36a83e40d296e63bac77 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202518297 | ELSA-2025-18297: kernel security update (MODERATE) | [4.18.0-553.80.1_10.OL8]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.3
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34750652]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985772]
[4.18.0-553.80.1_10]
- block: remove some blk_mq_hw_ctx debugfs entries (Ricardo Robaina) [RHEL-8816]
- blk-mq: Remove the hctx 'run' debugfs attribute (Ricardo Robaina) [RHEL-8816]
- block: remove debugfs blk_mq_ctx dispatched/merged/completed attributes (Ricardo Robaina) [RHEL-8816]
- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (CKI Backport Bot) [RHEL-114840] {CVE-2025-39751}
- crypto: seqiv - Handle EBUSY correctly (CKI Backport Bot) [RHEL-117228] {CVE-2023-53373}
- ALSA: usb-audio: Validate UAC3 power domain descriptors, too (Jaroslav Kysela) [RHEL-114681] {CVE-2025-38729}
- ALSA: usb-audio: Fix size validation in convert_chmap_v3() (Jaroslav Kysela) [RHEL-114681]
- ALSA: usb-audio: Validate UAC3 cluster segment descriptors (Jaroslav Kysela) [RHEL-114681] {CVE-2025-39757} | MODERATE | 2025-10-20 00:00:00+03:00 | ['CVE-2023-53373', 'CVE-2025-39751', 'CVE-2025-39757'] | ['Oracle Linux 8'] | ['CVE-2023-53373', 'CVE-2025-39751', 'CVE-2025-39757', 'ELSA-2025-18297', 'https://linux.oracle.com/cve/CVE-2023-53373.html', 'https://linux.oracle.com/cve/CVE-2025-39751.html', 'https://linux.oracle.com/cve/CVE-2025-39757.html', 'https://linux.oracle.com/errata/ELSA-2025-18297.html'] | d0c42c95a73e4f9a5e8f5052c7be8ffafcfddfadafd18f1994414658c5cdc719 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202520669 | ELSA-2025-20669: edk2 security update (IMPORTANT) | [20250905-4.el8]
- Create new 20250905 release for OL8 which includes the following fixed CVEs:
- EDK2: EDK2 contains a vulnerability in BIOS where an attacker may cause "Protection Mechanism Failure" by local access [Orabug: 38381983] {CVE-2025-3770}
- EDK2: EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means [Orabug: 38382190] {CVE-2024-38805}
- EDK2: EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network [Orabug: 38382286] {CVE-2024-38797}
- EDK2: Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity. [Orabug: 38413860] {CVE-2024-36331}
- Update to OpenSSL 3.5.1 which includes the following fixed CVEs:
{CVE-2025-4575} {CVE-2024-12797} {CVE-2024-13176} {CVE-2024-12797} {CVE-2024-13176} {CVE-2024-9143} | IMPORTANT | 2025-12-03 00:00:00+03:00 | ['CVE-2024-36331', 'CVE-2024-38797', 'CVE-2024-38805', 'CVE-2025-3770'] | ['Oracle Linux 8'] | ['CVE-2024-36331', 'CVE-2024-38797', 'CVE-2024-38805', 'CVE-2025-3770', 'ELSA-2025-20669', 'https://linux.oracle.com/cve/CVE-2024-36331.html', 'https://linux.oracle.com/cve/CVE-2024-38797.html', 'https://linux.oracle.com/cve/CVE-2024-38805.html', 'https://linux.oracle.com/cve/CVE-2025-3770.html', 'https://linux.oracle.com/errata/ELSA-2025-20669.html'] | ab1641d57cc7ed4dd2cbb2472215067afa82b2b8de31ffb7390fa4b84426b32e | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522012 | ELSA-2025-22012: buildah security update (IMPORTANT) | [1.41.6-1.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]
[2:1.41.6-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.41
(https://github.com/containers/buildah/commit/2ece502)
- fixes '[Minor Incident] CVE-2025-52881 buildah: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [rhel-10.1.z]'
- Resolves: RHEL-126634
[2:1.41.4-3]
- rebuild for CVE-2025-58183
- Resolves: RHEL-125628
[2:1.41.4-2]
- rebuild as the last build was built in the wrong tag
- Related: RHEL-115167
[2:1.41.4-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.41
(https://github.com/containers/buildah/commit/ee5b574)
- fixes 'buildah: create parent directories of mount targets with mode 0755 - [RHEL-10.1] 0day'
- Resolves: RHEL-115167 | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-52881', 'CVE-2025-58183'] | ['Oracle Linux 10'] | ['CVE-2025-52881', 'CVE-2025-58183', 'ELSA-2025-22012', 'https://linux.oracle.com/cve/CVE-2025-52881.html', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-22012.html'] | 0daf5a73fa3d68703cced06036006e4fac25667114f1f98234e75c77d5b88c15 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521936 | ELSA-2025-21936: valkey security update (IMPORTANT) | [8.0.6-2]
- rebase to 8.0.6 for CVE-2025-49844 CVE-2025-46817 CVE-2025-46818 CVE-2025-46819
[8.0.4-3]
- fix ImageMode: ensure ownership of /etc/valkey
[8.0.4-2]
- fix ImageMode: add tmpfiles.d entries for directories below /var
[8.0.4-1]
- rebase to 8.0.4 for CVE-2025-27151 CVE-2025-48367 and CVE-2025-32023
[8.0.3.1]
- rebase to 8.0.3
[8.0.2.1]
- rebase to 8.0.2
Resolves: RHEL-73273
[7.2.6-2]
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
[7.2.6.1]
- rebase to 7.2.6
- merge limit.conf in main service files
- drop /etc/sysconfig/valkey
- rename compat package
- fix working dir
- partially enable upstream test suite
[7.2.5-4]
- Bump release for June 2024 mass rebuild
[7.2.5-3]
- remove version_no_tilde code | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-46817', 'CVE-2025-46818', 'CVE-2025-46819', 'CVE-2025-49844'] | ['Oracle Linux 10'] | ['CVE-2025-46817', 'CVE-2025-46818', 'CVE-2025-46819', 'CVE-2025-49844', 'ELSA-2025-21936', 'https://linux.oracle.com/cve/CVE-2025-46817.html', 'https://linux.oracle.com/cve/CVE-2025-46818.html', 'https://linux.oracle.com/cve/CVE-2025-46819.html', 'https://linux.oracle.com/cve/CVE-2025-49844.html', 'https://linux.oracle.com/errata/ELSA-2025-21936.html'] | 8a4deb7039201149486cd312a707c0b2d308ef1ab74f03b4405ae6d1ce96e4ed | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521843 | ELSA-2025-21843: thunderbird security update (IMPORTANT) | [140.5.0-2.0.1]
- Add Oracle prefs
[140.5.0-2]
- Update to 140.5.0 ESR | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020'] | ['Oracle Linux 10'] | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020', 'ELSA-2025-21843', 'https://linux.oracle.com/cve/CVE-2025-13012.html', 'https://linux.oracle.com/cve/CVE-2025-13013.html', 'https://linux.oracle.com/cve/CVE-2025-13014.html', 'https://linux.oracle.com/cve/CVE-2025-13015.html', 'https://linux.oracle.com/cve/CVE-2025-13016.html', 'https://linux.oracle.com/cve/CVE-2025-13017.html', 'https://linux.oracle.com/cve/CVE-2025-13018.html', 'https://linux.oracle.com/cve/CVE-2025-13019.html', 'https://linux.oracle.com/cve/CVE-2025-13020.html', 'https://linux.oracle.com/errata/ELSA-2025-21843.html'] | 84ddbe3ec2b75c15fe030de01de3c543b0fc09dc5e78abe989ff52b6ed1cc2fb | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202629940 | ELSA-2026-29940: thunderbird security update (IMPORTANT) | [140.12.0-1.0.1]
- Fix prefs for new nss [Orabug: 37079813]
- Add Oracle prefs
[140.12.0]
- Add OpenELA debranding
[140.12.0-1]
- Update to 140.12.0 ESR | IMPORTANT | 2026-06-26 00:00:00+03:00 | ['CVE-2026-12289', 'CVE-2026-12290', 'CVE-2026-12291', 'CVE-2026-12292', 'CVE-2026-12294', 'CVE-2026-12295', 'CVE-2026-12296', 'CVE-2026-12297', 'CVE-2026-12298', 'CVE-2026-12299', 'CVE-2026-12302', 'CVE-2026-12304', 'CVE-2026-12305', 'CVE-2026-12306', 'CVE-2026-12307', 'CVE-2026-12308', 'CVE-2026-12309', 'CVE-2026-12310', 'CVE-2026-12311', 'CVE-2026-12312', 'CVE-2026-12313', 'CVE-2026-12314', 'CVE-2026-12315', 'CVE-2026-12324', 'CVE-2026-12325', 'CVE-2026-12327', 'CVE-2026-12328', 'CVE-2026-12329', 'CVE-2026-12330'] | ['Oracle Linux 9'] | ['CVE-2026-12289', 'CVE-2026-12290', 'CVE-2026-12291', 'CVE-2026-12292', 'CVE-2026-12294', 'CVE-2026-12295', 'CVE-2026-12296', 'CVE-2026-12297', 'CVE-2026-12298', 'CVE-2026-12299', 'CVE-2026-12302', 'CVE-2026-12304', 'CVE-2026-12305', 'CVE-2026-12306', 'CVE-2026-12307', 'CVE-2026-12308', 'CVE-2026-12309', 'CVE-2026-12310', 'CVE-2026-12311', 'CVE-2026-12312', 'CVE-2026-12313', 'CVE-2026-12314', 'CVE-2026-12315', 'CVE-2026-12324', 'CVE-2026-12325', 'CVE-2026-12327', 'CVE-2026-12328', 'CVE-2026-12329', 'CVE-2026-12330', 'ELSA-2026-29940', 'https://linux.oracle.com/cve/CVE-2026-12289.html', 'https://linux.oracle.com/cve/CVE-2026-12290.html', 'https://linux.oracle.com/cve/CVE-2026-12291.html', 'https://linux.oracle.com/cve/CVE-2026-12292.html', 'https://linux.oracle.com/cve/CVE-2026-12294.html', 'https://linux.oracle.com/cve/CVE-2026-12295.html', 'https://linux.oracle.com/cve/CVE-2026-12296.html', 'https://linux.oracle.com/cve/CVE-2026-12297.html', 'https://linux.oracle.com/cve/CVE-2026-12298.html', 'https://linux.oracle.com/cve/CVE-2026-12299.html', 'https://linux.oracle.com/cve/CVE-2026-12302.html', 'https://linux.oracle.com/cve/CVE-2026-12304.html', 'https://linux.oracle.com/cve/CVE-2026-12305.html', 'https://linux.oracle.com/cve/CVE-2026-12306.html', 'https://linux.oracle.com/cve/CVE-2026-12307.html', 'https://linux.oracle.com/cve/CVE-2026-12308.html', 'https://linux.oracle.com/cve/CVE-2026-12309.html', 'https://linux.oracle.com/cve/CVE-2026-12310.html', 'https://linux.oracle.com/cve/CVE-2026-12311.html', 'https://linux.oracle.com/cve/CVE-2026-12312.html', 'https://linux.oracle.com/cve/CVE-2026-12313.html', 'https://linux.oracle.com/cve/CVE-2026-12314.html', 'https://linux.oracle.com/cve/CVE-2026-12315.html', 'https://linux.oracle.com/cve/CVE-2026-12324.html', 'https://linux.oracle.com/cve/CVE-2026-12325.html', 'https://linux.oracle.com/cve/CVE-2026-12327.html', 'https://linux.oracle.com/cve/CVE-2026-12328.html', 'https://linux.oracle.com/cve/CVE-2026-12329.html', 'https://linux.oracle.com/cve/CVE-2026-12330.html', 'https://linux.oracle.com/errata/ELSA-2026-29940.html'] | 091c92fd37fc318b0b0bd4b57aec939710ceec8a6d8b92607085e4517de2374b | 2026-06-27 11:22:03.294410+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521220 | ELSA-2025-21220: podman security update (IMPORTANT) | [5.6.0-6.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]
[7:5.6.0-6]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
(https://github.com/containers/podman/commit/2791007)
- fixes '[Minor Incident] CVE-2025-52881 podman: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [rhel-10.1.z]'
- Resolves: RHEL-126635
[7:5.6.0-5]
- update to the latest content of https://github.com/containers/podman/tree/v5.6-rhel
(https://github.com/containers/podman/commit/61231e1)
- fixes 'Timeouts while pushing Sigstore logs to Rekor - [RHEL 10.1] 0day'
- Resolves: RHEL-111077 | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-52881'] | ['Oracle Linux 10'] | ['CVE-2025-52881', 'ELSA-2025-21220', 'https://linux.oracle.com/cve/CVE-2025-52881.html', 'https://linux.oracle.com/errata/ELSA-2025-21220.html'] | d9b021a194a33eb2ab8ddc94bc73dafc38ff1345e7107455f041d1b6919c9866 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521816 | ELSA-2025-21816: delve and golang security update (MODERATE) | delve
[1.25.2-1.0.1]
- Disable DWARF compression which has issues (Alex Burmashev)
[1.25.2-1]
- Update Delve to 1.25.2
[1.24.1-3]
- Update CI support
golang
[1.25.3-1]
- Update to Go 1.25.3
[1.25.1-1]
- Update to Go1.25.1 -Resolves: RHEL-116849
[1.25.0-5]
- Disable race for risv64
[1.25.0-4]
- Revert DWARF5 defaults
[1.25.0-3]
- Update CI support
[1.25.0-2]
- rpminspect.yaml: Add preprofile binary as it contains debugging symbols
[1.25.0-1]
- Update to Go 1.25.0 | MODERATE | 2025-12-03 00:00:00+03:00 | ['CVE-2025-58183'] | ['Oracle Linux 10'] | ['CVE-2025-58183', 'ELSA-2025-21816', 'https://linux.oracle.com/cve/CVE-2025-58183.html', 'https://linux.oracle.com/errata/ELSA-2025-21816.html'] | 394751c77f5f9d76da03dbc54d6fbf910b6cf826fa758a9f41fc659d7dea7efc | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521142 | ELSA-2025-21142: python-kdcproxy security update (IMPORTANT) | [1.0.0-19]
- Use DNS discovery for declared realms only (CVE-2025-59088)
Resolves: RHEL-122777
- Fix DoS vulnerability based on unbounded TCP buffering (CVE-2025-59089)
Resolves: RHEL-122776 | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-59088', 'CVE-2025-59089'] | ['Oracle Linux 10'] | ['CVE-2025-59088', 'CVE-2025-59089', 'ELSA-2025-21142', 'https://linux.oracle.com/cve/CVE-2025-59088.html', 'https://linux.oracle.com/cve/CVE-2025-59089.html', 'https://linux.oracle.com/errata/ELSA-2025-21142.html'] | dc33f0783972b081e992ea1b0b3cfa00b986dac19c0128bdc741bf290909b2b8 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521034 | ELSA-2025-21034: bind security update (IMPORTANT) | [9.18.33-10.0.1]
- Fix warning when changing device file permissions [Orabug: 36518580]
[32:9.18.33-10.2]
- Fix upstream reported regression in recent CVE fix (CVE-2025-8677)
[32:9.18.33-10.1]
- Refuse malformed DNSKEY records (CVE-2025-8677)
- Address various spoofing attacks (CVE-2025-40778)
- Prevent cache poisoning due to weak PRNG (CVE-2025-40780)
[32:9.18.33-10]
- Fix failures in idna system test (RHEL-66172)
[32:9.18.33-9]
- Decode IDN names on input in all situations in utilities (RHEL-66172)
[32:9.18.33-8]
- logrotate: skip if empty and remove old variants (RHEL-113942)
[32:9.18.33-7]
- Add runtime tunable limit by environment NAMED_MAXADDITIONAL (RHEL-84006)
[32:9.18.33-6]
- Change additional NS to be served partially (RHEL-84006) | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-40778', 'CVE-2025-40780', 'CVE-2025-8677'] | ['Oracle Linux 10'] | ['CVE-2025-40778', 'CVE-2025-40780', 'CVE-2025-8677', 'ELSA-2025-21034', 'https://linux.oracle.com/cve/CVE-2025-40778.html', 'https://linux.oracle.com/cve/CVE-2025-40780.html', 'https://linux.oracle.com/cve/CVE-2025-8677.html', 'https://linux.oracle.com/errata/ELSA-2025-21034.html'] | 841d37d39f3c8835fec7f1d9ce1540e5b1baf45d075f07fba4cdc7868a7fb067 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202521032 | ELSA-2025-21032: libsoup3 security update (IMPORTANT) | [3.6.5-6]
- Fix integer overflow in date/time parsing
[3.6.5-5]
- Bump revision number
[3.6.5-4]
- Fix several CVEs | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-11021', 'CVE-2025-4945'] | ['Oracle Linux 10'] | ['CVE-2025-11021', 'CVE-2025-4945', 'ELSA-2025-21032', 'https://linux.oracle.com/cve/CVE-2025-11021.html', 'https://linux.oracle.com/cve/CVE-2025-4945.html', 'https://linux.oracle.com/errata/ELSA-2025-21032.html'] | 5b76217fa09bbd4fd75a1ec81c5ae2d0d43e173eaeb6c6a60ea36b2fa38dc393 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202622468 | ELSA-2026-22468: openssh security update (IMPORTANT) | [7.4p1-23.0.5]
- Fix privilege escalation via scp legacy protocol when not in preserving
file mode [CVE-2026-35385][Orabug: 39480251] | IMPORTANT | 2026-06-18 00:00:00+03:00 | ['CVE-2026-35385'] | ['Oracle Linux 7'] | ['CVE-2026-35385', 'ELSA-2026-22468', 'https://linux.oracle.com/cve/CVE-2026-35385.html', 'https://linux.oracle.com/errata/ELSA-2026-22468.html'] | 0c85ae8dd7a742209935e338cd9303392b7024f0d99158e005de8c8181901b80 | 2026-06-19 05:16:40.850747+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522417 | ELSA-2025-22417: gimp:2.8 security update (IMPORTANT) | gimp
[2:2.8.22-26.3]
- fix CVE-2025-10920
- fix CVE-2025-10921
- fix CVE-2025-10922
- fix CVE-2025-10923
- fix CVE-2025-10924
- fix CVE-2025-10925
- fix CVE-2025-10934
[2:2.8.22-26.2]
- fix CVE-2025-5473 (RHEL-95696)
[2:2.8.22-26.1]
- fix CVE-2025-48797 (RHEL-93503)
- fix CVE-2025-48798 (RHEL-93506)
[2:2.28.22-26]
- bump spec
[2:2.8.22-25]
- fix CVE-2023-44442
- fix CVE-2023-44444
- disable gimp-2.8.22-python-path.patch required for flatpak
- partially cherry-pick from upstream commit 2987f012 to fix fclose leak
Resolves: RHEL-17048 RHEL-17060
[2:2.8.22-24]
- fallback to RPM gegl
[2:2.8.22-23]
- enforce gegl04
[2:2.8.22-22]
- change gegl requirement to gegl04
[2:2.8.22-21]
- set manual shebang in python files
[2:2.8.22-20]
- fix python path in source code
pygobject2
[2.28.7-5]
- bump spec to fix NVR
[2.28.7-4]
- update python macro to python2
[2.28.7-3]
- Add MIT license
[2.28.7-2.1]
- Fix python shebangs (#1580854)
[2.28.7-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
[2.28.7-1]
- Update to 2.28.7
[2.28.6-19]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
[2.28.6-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
[2.28.6-17]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
[2.28.6-16]
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages
pygtk2
[2.24.0-25]
- Fix shebang mangling for _prefix=app (#1907579)
- disable numpy for flatpak (#1907579)
[2.24.0-24]
- remove libglade dependency and sub-package (#1622134)
[2.24.0-23.1]
- fix python2 regex in sed command
[2.24.0-23]
- resotre doc sub package
[2.24.0-22]
- fix python2 macros
[2.24.0-21.1]
- Fix python shebangs (#1580855)
[2.24.0-21]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
[2.24.0-20]
- Try again to fix shebangs
[2.24.0-19]
- Fix shebangs
[2.24.0-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
python2-pycairo
[1.16.3-7]
- bump spec for NVR fix
[1.16.3-6]
- Rename pycairo to python2-pycairo (RCM-39388)
[1.16.3-5]
- Add python3 packages (RCM-39388)
- remove python3-test due its missing in build root
[1.16.3-4]
- Setup python2 stream branch for python2 binding of cairo library
[1.16.3-3]
- Remove the python2 subpackages
https://bugzilla.redhat.com/show_bug.cgi?id=1590820
[1.16.3-2]
- Allow Python 2 for build
See: https://hurl.corp.redhat.com/rhel8-py2
- Skip tests on Python 2 (python2-pytest is being removed)
[1.16.3-1]
- Update to 1.16.3
[1.16.1-1]
- Update to 1.16.1
[1.16.0-1]
- Update to 1.16.0
[1.15.6-1]
- Update to 1.15.6 | IMPORTANT | 2025-12-01 00:00:00+03:00 | ['CVE-2025-10920', 'CVE-2025-10921', 'CVE-2025-10922', 'CVE-2025-10923', 'CVE-2025-10924', 'CVE-2025-10925', 'CVE-2025-10934'] | ['Oracle Linux 8'] | ['CVE-2025-10920', 'CVE-2025-10921', 'CVE-2025-10922', 'CVE-2025-10923', 'CVE-2025-10924', 'CVE-2025-10925', 'CVE-2025-10934', 'ELSA-2025-22417', 'https://linux.oracle.com/cve/CVE-2025-10920.html', 'https://linux.oracle.com/cve/CVE-2025-10921.html', 'https://linux.oracle.com/cve/CVE-2025-10922.html', 'https://linux.oracle.com/cve/CVE-2025-10923.html', 'https://linux.oracle.com/cve/CVE-2025-10924.html', 'https://linux.oracle.com/cve/CVE-2025-10925.html', 'https://linux.oracle.com/cve/CVE-2025-10934.html', 'https://linux.oracle.com/errata/ELSA-2025-22417.html'] | c0768b2df6149fa09edaa0b5265cc68bb2a11e3e556625fd18cf3144438ebecc | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:2025201810 | ELSA-2025-20181-0: pam security update (IMPORTANT) | [1.6.1-8]
- pam_namespace: fix potential privilege escalation.
Resolves: CVE-2025-6020 and RHEL-101174 | IMPORTANT | 2025-11-25 00:00:00+03:00 | ['CVE-2025-6020'] | ['Oracle Linux 10'] | ['CVE-2025-6020', 'ELSA-2025-20181-0', 'https://linux.oracle.com/cve/CVE-2025-6020.html', 'https://linux.oracle.com/errata/ELSA-2025-20181-0.html'] | fe694b1b0afdf0c084063e23c30fd60827a9ceab026727519ca10cc62209a836 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:2025201260 | ELSA-2025-20126-0: openssh security update (MODERATE) | [9.9p1-11.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]
[9.9p1-11]
- Move the redhat help message to debug1 log level
Resolves: RHEL-93957
[9.9p1-10]
- Support for authentication indicators in OpenSSH
Resolves: RHEL-40790
[9.9p1-9]
- CVE-2025-32728: Fix logic error in DisableForwarding option
Resolves: RHEL-86819
- Provide better error for non-supported private keys
Resolves: RHEL-68124
- Ignore bad hostkeys in known_hosts file
Resolves: RHEL-83644
[9.9p1-8]
- OpenSSH should not use its own implementation of MLKEM
Resolves: RHEL-58252
- Correct processing of Compression directive
Resolves: RHEL-68346
- Supress systemd warning
Resolves: RHEL-84816 | MODERATE | 2025-11-25 00:00:00+03:00 | ['CVE-2025-32728'] | ['Oracle Linux 10'] | ['CVE-2025-32728', 'ELSA-2025-20126-0', 'https://linux.oracle.com/cve/CVE-2025-32728.html', 'https://linux.oracle.com/errata/ELSA-2025-20126-0.html'] | 33d5f326f2c707e58bdc8334ff85855a49ecf5a89c7b43d0932588962cb83b10 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:2025200950 | ELSA-2025-20095-0: kernel security update (MODERATE) | [6.12.0-124.8.1]
- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782]
- Disable UKI signing [Orabug: 36571828]
- Update Oracle Linux certificates (Kevin Lyons)
- Disable signing for aarch64 (Ilya Okomin)
- Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237]
- Update x509.genkey [Orabug: 24817676]
- Conflict with shim-ia32 and shim-x64 <= 15.3-1.0.5]
- Remove upstream reference during boot (Kevin Lyons) [Orabug: 34729535]
- Add Oracle Linux IMA certificates
- Update module name for cryptographic module [Orabug: 37400433]
- Clean git history at setup stage
[6.12.0-124.8.1]
- redhat: revert to using redhatsecureboot504 for RHEL UKI (Vitaly Kuznetsov) [RHEL-122226]
[6.12.0-124.7.1]
- drm/amdgpu: Include sdma_4_4_4.bin (Peter Colberg) [RHEL-117567]
[6.12.0-124.6.1]
- redhat: use new x86/aarch64 signing key (801/804) (Jan Stancek) [RHEL-116728]
[6.12.0-124.5.1]
- scsi: mpi3mr: Update driver version to 8.15.0.5.50 (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Fix premature TM timeouts on virtual drives (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Update MPI headers to revision 37 (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Fix I/O failures during controller reset (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Fix controller init failure on fault during queue creation (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Fix device loss during enclosure reboot due to zero link speed (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Fix race between config read submit and interrupt completion (Chandrakanth Patil) [RHEL-111654]
- scsi: mpi3mr: Correctly handle ATA device errors (Chandrakanth Patil) [RHEL-111654]
- selftests: tls: add tests for zero-length records (CKI Backport Bot) [RHEL-114328] {CVE-2025-39682}
- tls: fix handling of zero-length records on the rx_list (CKI Backport Bot) [RHEL-114328] {CVE-2025-39682}
- cxgb4: Avoid removal of uninserted tid (Jakub Ramaseuski) [RHEL-75570]
- SUNRPC: call xs_sock_process_cmsg for all cmsg (Scott Mayhew) [RHEL-112414]
- sctp: linearize cloned gso packets in sctp_rcv (CKI Backport Bot) [RHEL-113338] {CVE-2025-38718}
- kabi: enable check-kabi (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol zgid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol zap_vma_ptes to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_uses_need_wakeup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_tx_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_tx_peek_release_desc_batch to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_tx_peek_desc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_tx_completed to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_set_tx_need_wakeup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_set_rx_need_wakeup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_get_pool_from_qid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xsk_clear_rx_need_wakeup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_set_rxq_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_raw_get_dma to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_fill_cb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_dma_unmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_dma_map to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_can_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_alloc_batch to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xp_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xfrm_aead_get_byname to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_warn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_set_features_flag to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_rxq_info_unreg_mem_model to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_rxq_info_unreg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_rxq_info_reg_mem_model to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __xdp_rxq_info_reg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_rxq_info_is_reg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_return_frame_rx_napi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_return_frame_bulk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_return_frame to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_return_buff to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_master_redirect to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_flush_frame_bulk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_features_set_redirect_target to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_features_clear_redirect_target to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_do_redirect to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_do_flush to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xdp_convert_zc_to_xdp_frame to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_store to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_load to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __xa_insert to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_find_after to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_find to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_erase to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol xa_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __xa_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_return_thunk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rsi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rdx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rdi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rcx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rbx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rbp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_rax to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r9 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r8 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r15 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r14 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r13 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r12 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r11 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __x86_indirect_thunk_r10 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol x86_cpu_to_apicid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __warn_printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol wake_up_process to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __wake_up_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __wake_up to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol wait_for_completion_timeout to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol wait_for_completion_io_timeout to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol wait_for_completion_interruptible to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol wait_for_completion to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vzalloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vsprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vsnprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vscnprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vm_munmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vm_mmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmemmap_base to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmalloc_to_page to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmalloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __vmalloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmalloc_node_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmalloc_base to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vmalloc_array_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vlan_dev_vlan_id to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vlan_dev_real_dev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __virt_addr_valid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vfs_unlink to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vfs_mknod to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vfs_mkdir to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vfs_fsync_range to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol vfree to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_undefined to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_teardown_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_setup_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_possible_blades to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __uv_hub_info_list to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_get_hubless_system to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __uv_cpu_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_obj_count to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_install_heap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_get_pci_topology to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_get_master_nasid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_get_heapsize to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_get_geoinfo to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_enum_ports to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol uv_bios_enum_objs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol usleep_range_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol up_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol up_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol up to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_sysctl_table to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_switchdev_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_switchdev_blocking_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_reboot_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_netevent_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_netdevice_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_netdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_kprobe to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_inetaddr_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_inet6addr_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_chrdev_region to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __unregister_chrdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol unregister_blkdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol udp_tunnel_nic_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __udelay to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_unregister_driver to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_termios_encode_baud_rate to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_std_termios to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_register_driver to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_port_link_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_port_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_port_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_flip_buffer_push to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_driver_kref_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tty_buffer_request_room to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tty_alloc_driver to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tsc_khz to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol try_module_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __trace_trigger_soft_disabled to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __trace_set_current_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_seq_putc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_seq_printf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_raw_output_prep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_print_bitmask_seq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_xdp_exception to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_write_msr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_sched_set_state_tp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_read_msr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_mmap_lock_start_locking to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_mmap_lock_released to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tracepoint_mmap_lock_acquire_returned to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_handle_return to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_reg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_raw_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_printf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_ignore_this_pid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_buffer_reserve to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_event_buffer_commit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_array_set_clr_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_array_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol trace_array_get_by_name to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol touch_softlockup_watchdog to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tls_validate_xmit_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tls_get_record to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tls_encrypt_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tls_device_sk_destruct to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timer_shutdown_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timer_shutdown to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timer_delete_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timer_delete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timecounter_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timecounter_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol timecounter_cyc2time to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol time64_to_tm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol this_cpu_off to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tcp_gro_complete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __tasklet_schedule to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tasklet_kill to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol tasklet_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sys_tz to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol system_wq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol system_unbound_wq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol system_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_streq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_remove_group to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_remove_file_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_remove_bin_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __sysfs_match_string to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_emit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_create_group to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_create_file_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sysfs_create_bin_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol synchronize_rcu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol synchronize_net to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol synchronize_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sync_blockdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __symbol_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __symbol_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol switchdev_handle_port_obj_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol switchdev_handle_port_obj_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol switchdev_handle_port_attr_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __sw_hweight64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __sw_hweight32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol submit_bio_noacct to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol submit_bio to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strstr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strsep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strrchr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strnlen to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strncpy_from_user to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strncpy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strncmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strncasecmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strlen to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strlcat to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strim to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strcspn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strcpy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strcmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strchr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strcat to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol strcasecmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol static_key_slow_inc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol static_key_slow_dec to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol static_key_enable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol static_key_disable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol static_key_count to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol starget_for_each_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __stack_chk_fail to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sscanf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sort to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol softnet_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sock_gen_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sn_region_size to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol snprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sn_partition_id to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol smp_call_function_single_async to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol smp_call_function_single to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol smp_call_function_many to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol smp_call_function to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol slab_build_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sk_skb_reason_drop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sk_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_tstamp_tx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_realloc_headroom to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_queue_tail to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_push to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_pull to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __skb_pad to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __skb_gso_segment to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __skb_flow_dissect to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_dequeue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_copy_header to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_copy_expand to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_copy_bits to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_copy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_clone_tx_timestamp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_clone to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_checksum_help to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol skb_add_rx_frag_netmem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sk_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sized_strscpy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol single_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol single_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_write_to_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_strtoul to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_strtol to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_read_from_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_attr_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol simple_attr_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol si_meminfo to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_pcopy_to_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_pcopy_from_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_nents to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_miter_stop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_miter_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_miter_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_copy_to_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_copy_from_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sg_copy_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_user_nice to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_normalized_timespec64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_memory_wc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_cpus_allowed_ptr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_capacity to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol set_blocksize to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __seq_puts to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_putc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_printf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol seq_lseek to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol send_sig_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol send_sig to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol secure_tcpv6_seq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol secure_tcp_seq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol secpath_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sdev_prefix_printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCT__tp_func_xdp_exception to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCT__preempt_schedule_notrace to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCT__preempt_schedule to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCT__might_resched to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCT__cond_resched to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_unblock_requests to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_scan_target to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_scan_host to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_sanitize_inquiry_string to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_rescan_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_remove_target to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_remove_host to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_remove_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_print_command to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_normalize_sense to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsilun_to_int to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __scsi_iterate_devices to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_is_sdev_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_is_host_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_is_fc_rport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_host_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_host_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_host_busy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_host_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_get_vpd_page to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_done to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_dma_unmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_dma_map to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_device_type to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_device_set_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_device_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_device_lookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_device_from_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_change_queue_depth to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_build_sense_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_build_sense to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_block_requests to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_add_host_with_dma to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scsi_add_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scnprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol scmd_printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __SCK__tp_func_xdp_exception to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol schedule_timeout_uninterruptible to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol schedule_timeout to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol schedule to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sched_clock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_rphy_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_rphy_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_remove_host to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_release_transport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_delete_phy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_delete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_alloc_num to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_add_phy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_port_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_phy_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_phy_delete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_phy_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_phy_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_expander_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_end_device_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_attach_transport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol sas_ata_ncq_prio_supported to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rtnl_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rtnl_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rtnl_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rtnl_is_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rps_may_expire_flow to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol round_jiffies to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol root_device_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __root_device_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rht_bucket_nested_insert to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rht_bucket_nested to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __rht_bucket_nested to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_walk_stop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_walk_start_check to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_walk_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_walk_exit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_walk_enter to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_insert_slow to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_init_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rhashtable_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol reset_devices to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol request_threaded_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __request_region to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __request_module to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol request_firmware_nowait to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol request_firmware to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rep_movs_alternative to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol remove_wait_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol remove_proc_entry to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol remap_pfn_range to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __release_region to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol release_firmware to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_switchdev_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_switchdev_blocking_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_reboot_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_netevent_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_netdevice_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_netdevice to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_netdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_kprobe to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_inetaddr_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_inet6addr_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol register_chrdev_region to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __register_chrdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __register_blkdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __refrigerator to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol refcount_warn_saturate to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_user_mmap_io to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_user_mmap_entry_remove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_user_mmap_entry_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_user_mmap_entry_insert to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_user_mmap_entry_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_read_gid_l2_fields to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_query_gid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __rdma_block_iter_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __rdma_block_iter_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rdma_alloc_hw_stats_struct to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rcuref_get_slowpath to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __rcu_read_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __rcu_read_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rb_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol rb_first to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_write_unlock_irqrestore to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_write_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_write_lock_irqsave to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_write_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_unlock_irqrestore to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_unlock_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_unlock_bh to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_lock_irqsave to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_lock_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_lock_bh to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_spin_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_read_unlock_irqrestore to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_read_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_read_lock_irqsave to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _raw_read_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ___ratelimit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol radix_tree_lookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol queue_work_on to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol queue_limits_commit_update to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol queue_delayed_work_on to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol qdisc_reset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pv_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __put_user_nocheck_4 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __put_user_8 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __put_user_4 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __put_user_2 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol put_disk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __put_devmap_managed_folio_refs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol put_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptrs_per_p4d to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_schedule_worker to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_parse_header to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_find_pin to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_clock_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_clock_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_clock_index to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_clock_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_classify_raw to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ptp_cancel_worker_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ___pskb_trim to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __pskb_pull_tail to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pskb_expand_head to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol proc_remove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol proc_mkdir to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol proc_dostring to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol proc_create_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol proc_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol priv_to_devlink to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __printk_ratelimit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol print_hex_dump to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol prepare_to_wait_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol prepare_to_wait to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol prepare_creds to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pm_schedule_suspend to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __pm_runtime_resume to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __pm_runtime_idle to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pldmfw_op_pci_match_record to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pldmfw_flash_image to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pid_task to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_validate_pause to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_support_asym_pause to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_stop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_start_aneg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol physical_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_set_max_speed to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_set_asym_pause to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phys_base to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_mii_ioctl to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_ethtool_ksettings_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_ethtool_ksettings_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_disconnect to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_connect to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol phy_attached_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pgprot_writecombine to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pgdir_shift to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol perf_trace_run_bpf_submit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol perf_trace_buf_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __per_cpu_offset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcpu_hot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcpu_alloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcix_set_mmrbc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_write_config_word to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_write_config_dword to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_write_config_byte to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_wake_from_d3 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_wait_for_pending_transaction to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_vpd_find_ro_info_keyword to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_vpd_check_csum to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_vpd_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_vfs_assigned to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_unregister_driver to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_try_set_mwi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_sriov_set_totalvfs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_set_power_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_set_mwi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_set_master to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_select_bars to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_save_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_restore_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_restore_msi_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_reset_bus to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_request_selected_regions to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_request_regions to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_release_selected_regions to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_release_regions to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __pci_register_driver to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_read_vpd to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_read_config_word to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_read_config_dword to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_read_config_byte to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_prepare_to_sleep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_num_vf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_msix_free_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_msix_can_alloc_dyn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_msix_alloc_irq_at to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcim_iomap_table to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcim_iomap_regions to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcim_enable_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_irq_vector to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_irq_get_affinity to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_iov_virtfn_devfn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_iounmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_ioremap_bar to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_iomap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_get_slot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_get_dsn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_get_domain_bus_and_slot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_get_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_free_irq_vectors to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_find_ext_capability to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_find_capability to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_set_readrq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_ptm_enabled to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_print_link_status to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_wake to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_sriov to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_ptm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_msix_range to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_msi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_device_mem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_enable_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_get_readrq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_flr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_capability_write_word to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_capability_read_word to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_capability_read_dword to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_capability_clear_and_set_word_unlocked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pcie_capability_clear_and_set_word_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_disable_sriov to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_disable_rom to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_disable_msix to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_disable_msi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_disable_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_dev_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_dev_present to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_device_is_present to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_dev_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_clear_mwi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_clear_master to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_choose_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_cfg_access_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_cfg_access_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_bus_type to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_alloc_irq_vectors_affinity to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_alloc_irq_vectors to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pci_aer_clear_nonfatal_status to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol path_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_ushort to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_ulong to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_ullong to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_uint to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_short to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_long to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_int to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_charp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_byte to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_ops_bool to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol param_array_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol panic_notifier_list to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol panic to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_put_unrefed_netmem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_disable_direct_recycling to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_alloc_pages to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_pool_alloc_frag to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_offset_base to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol page_frag_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __page_frag_cache_drain to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol pack_fields_u8 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_unregister_targetport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_register_targetport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_rcv_ls_req to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_rcv_fcp_req to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_rcv_fcp_abort to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvmet_fc_invalidate_host to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_unregister_remoteport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_unregister_localport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_set_remoteport_devloss to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_rescan_remoteport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_register_remoteport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_register_localport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_rcv_ls_req to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nvme_fc_io_getuuid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __num_online_cpus to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol numa_node to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ns_to_timespec64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nr_cpu_ids to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol noop_llseek to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol node_to_cpumask_map to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol node_states to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __node_distance to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol nla_find to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol net_ratelimit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_tx_wake_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_tx_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_tx_stop_all_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_tx_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_set_xps_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_set_tso_max_size to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_set_tso_max_segs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_set_real_num_tx_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_set_real_num_rx_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_schedule_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_rx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_receive_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_queue_set_napi to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __netif_napi_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_napi_add_weight to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_get_num_default_rss_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_device_detach to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_device_attach to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_carrier_on to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netif_carrier_off to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol net_dim_get_rx_moderation to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol net_dim to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_warn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_walk_all_upper_dev_rcu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_update_features to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_unbind_sb_channel to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_state_change to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_set_tc_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_set_sb_channel to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_set_num_tc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_rx_handler_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_rx_handler_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_rss_key_fill to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_reset_tc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_refcnt_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_port_same_parent_id to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_pick_tx to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_notice to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_master_upper_dev_get_rcu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_master_upper_dev_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_lower_get_next to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_features_change to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_err to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_crit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_core_stats_inc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol netdev_bind_sb_channel_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __netdev_alloc_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __netdev_alloc_frag_align to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __neigh_event_send to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol neigh_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ndo_dflt_fdb_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ndo_dflt_bridge_getlink to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __ndelay to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_schedule_prep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __napi_schedule_irqoff to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __napi_schedule to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_gro_receive to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_enable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_disable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_consume_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_complete_done to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_build_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol napi_alloc_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __napi_alloc_frag_align to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol names_cachep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mutex_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mutex_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mutex_lock_interruptible to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mutex_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mutex_is_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __mutex_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol msleep_interruptible to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol msleep to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __msecs_to_jiffies to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mpi_read_raw_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mpi_powm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mpi_get_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mpi_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mpi_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol module_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol module_layout to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __module_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mod_timer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mod_delayed_work_on to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mmu_notifier_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mmu_notifier_get_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mmput to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __mmap_lock_do_trace_start_locking to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __mmap_lock_do_trace_released to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __mmap_lock_do_trace_acquire_returned to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mlx5_core_uplink_netdev_event_replay to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mlx5_core_access_reg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mlx5_blocking_notifier_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mlx5_blocking_notifier_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol misc_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol misc_deregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol metadata_dst_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol metadata_dst_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mem_section to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_kmalloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_kfree to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_free_slab to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_create_node_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_alloc_slab to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mempool_alloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memory_read_from_buffer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memmove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memdup_user_nul to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memdup_user to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memcpy_toio to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memcpy_fromio to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memcpy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memcmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memchr_inv to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol memchr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdio_mii_ioctl to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __mdiobus_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_get_phy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_c45_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_c45_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdiobus_alloc_size to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol mdio45_probe to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol loops_per_jiffy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol lookup_one_len to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol local_clock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __local_bh_enable_ip to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __list_del_entry_valid_or_report to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __list_add_valid_or_report to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol libie_rx_pt_lut to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol libeth_rx_recycle_slow to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol libeth_rx_fq_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol libeth_rx_fq_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kvfree_call_rcu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_with_offset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_ts64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_snapshot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_seconds to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_real_ts64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_real_seconds to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get_raw_ts64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ktime_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_use_mm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_unuse_mm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_stop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_should_stop to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_queue_work to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_queue_delayed_work to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_destroy_worker to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_delayed_work_timer_fn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_create_worker_on_node to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_create_on_node to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_complete_and_exit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_cancel_work_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_cancel_delayed_work_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kthread_bind to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtoull to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtouint to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtou8 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtou16 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtos16 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtoll to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtoint to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kstrtobool to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ksize to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol krealloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_uevent_env to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_uevent to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_set_name to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_init_and_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_get_unless_zero to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kobject_create_and_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmemdup_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmem_cache_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmem_cache_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmem_cache_create_args to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmem_cache_alloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmalloc_size_roundup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_node_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_large_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_large_node_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kmalloc_caches to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_cache_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __kmalloc_cache_node_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kill_pid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kill_pgrp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kill_fasync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kfree_sensitive to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kfree to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kexec_crash_loaded to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kern_path_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kern_path to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kernel_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kernel_sigaction to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kernel_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol kasprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol jiffies_to_usecs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol jiffies_to_msecs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol jiffies to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol iter_div_u64_rem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol is_vmalloc_addr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol is_uv_system to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_set_affinity_notifier to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_set_affinity to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_poll_sched to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_poll_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_poll_enable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_poll_disable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_poll_complete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_modify_status to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol irq_cpu_rmap_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __irq_apply_affinity_hint to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ipv6_skip_exthdr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ipv6_find_hdr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ipv6_ext_hdr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ipv6_chk_addr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __ipv6_addr_type to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol iput to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip_tos2prio to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip_route_output_flow to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip_queue_xmit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __ip_dev_find to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip_compute_csum to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip6_route_output_flags to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ip6_dst_hoplimit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __iowrite64_copy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol iowrite32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol iounmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ioremap_wc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ioremap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __ioread32_copy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ioread32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol iomem_resource to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol invalidate_bdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol int_to_scsilun to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __init_waitqueue_head to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol init_wait_entry to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol init_uts_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol init_user_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol init_timer_key to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __init_swait_queue_head to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __init_rwsem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol init_net to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __inet_lookup_established to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol inet_del_protocol to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol inet_add_protocol to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __inet6_lookup_established to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol in_dev_finish_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ilookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol idr_remove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol idr_find to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol idr_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol idr_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ida_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ida_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ida_alloc_range to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_unregister_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_umem_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_umem_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_umem_find_best_pgsz to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_umem_dmabuf_get_pinned to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_sg_to_pages to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_set_device_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_register_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_query_port to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_modify_qp_is_ok to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_get_eth_speed to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_dispatch_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ibdev_warn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ibdev_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_device_set_netdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_device_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_device_get_by_netdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ibdev_err to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol I_BDEV to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ib_dealloc_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _ib_alloc_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol i2c_smbus_write_byte_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol i2c_smbus_read_byte_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol i2c_new_client_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol i2c_del_adapter to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol i2c_bit_add_bus to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hwmon_notify_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hwmon_device_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hwmon_device_register_with_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hwmon_device_register_with_groups to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hwmon_device_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __hw_addr_unsync_dev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __hw_addr_sync_dev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __hw_addr_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hugetlb_optimize_vmemmap_key to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hrtimer_start_range_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hrtimer_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hrtimer_forward to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol hrtimer_cancel to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol high_memory to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol gnss_register_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol gnss_put_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol gnss_insert_raw to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol gnss_deregister_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol gnss_allocate_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_zeroed_page_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_user_pages_remote to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __get_user_nocheck_4 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __get_user_4 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __get_user_2 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_random_u32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_random_u16 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_random_bytes to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_free_pages_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_device_system_crosststamp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol get_cpu_idle_time to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol generic_file_write_iter to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol generic_file_read_iter to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fs_bio_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol freezing_slow_path to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_percpu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_pages to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __free_pages to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_netdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_irq_cpu_rmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol free_cpumask_var to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fput to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __fortify_panic to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __folio_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __flush_workqueue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flush_work to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flush_signals to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_vlan to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_tcp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_pppoe to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_ports to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_l2tpv3 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_ipv6_addrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_ipv4_addrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_ip to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_icmp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_eth_addrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_ports to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_opts to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_keyid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_ipv6_addrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_ipv4_addrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_ip to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_enc_control to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_cvlan to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_control to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_rule_match_basic to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_keys_dissector to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_indr_dev_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_indr_dev_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_indr_block_cb_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_block_cb_setup_simple to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol flow_block_cb_lookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fixed_size_llseek to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol firmware_request_nowarn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol finish_wait to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol find_vma to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol find_pid_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_next_zero_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_next_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_next_and_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_last_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol find_get_pid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_first_zero_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _find_first_bit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol filp_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol filp_close to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol file_ns_capable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol file_bdev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fget to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __fentry__ to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_vport_terminate to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_vport_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_remove_host to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_remote_port_rolechg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_remote_port_delete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_remote_port_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_release_transport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_host_post_vendor_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_host_post_event to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_host_fpin_rcv to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_get_event_number to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_eh_timed_out to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_eh_should_retry_cmd to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_block_scsi_eh to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_block_rport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fc_attach_transport to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol fasync_helper to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol event_triggers_call to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol eth_validate_addr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol eth_type_trans to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_sprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_rxfh_context_lost to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_puts to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_params_from_link_mode to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_op_get_ts_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_op_get_link to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_intersect_link_masks to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_forced_speed_maps_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_convert_link_mode_to_legacy_u32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ethtool_convert_legacy_u32_to_link_mode to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol eth_platform_get_mac_address to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol eth_get_headlen to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol ether_setup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol enable_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol empty_zero_page to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol emergency_restart to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol elfcorehdr_addr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dynamic_pr_debug to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dynamic_netdev_dbg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dynamic_ibdev_dbg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dynamic_dev_dbg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dump_stack to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dst_release to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol driver_remove_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol driver_for_each_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol driver_create_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dql_reset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dql_completed to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dput to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_on_pin_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_on_pin_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_pin_change_ntf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_netdev_pin_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_netdev_pin_clear to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_device_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_device_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_device_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_device_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dpll_device_change_ntf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_write_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_read_trylock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down_interruptible to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol downgrade_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol down to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol do_wait_intr_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol do_trace_write_msr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol do_trace_read_msr to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol do_trace_netlink_extack to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol done_path_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dmi_get_system_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dmi_first_match to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dmi_find_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_unmap_sg_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_unmap_page_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dma_sync_single_for_device to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dma_sync_single_for_cpu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_set_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_set_coherent_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_pool_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_pool_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_pool_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_pool_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dmam_free_coherent to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_map_sg_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_map_page_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dmam_alloc_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_get_required_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_free_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dma_alloc_attrs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol disable_irq_nosync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol disable_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dget_parent to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_warn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_uc_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_uc_add_excl to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_uc_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_trans_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_set_promiscuity to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_set_name to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_set_mtu to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_set_mac_address to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_remove_pack to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __dev_queue_xmit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_printk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_open to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_notice to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_request_threaded_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_mdiobus_alloc_size to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_kmemdup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_kmalloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_kfree to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_kasprintf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_hwmon_device_register_with_groups to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devm_free_irq to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_mc_del_global to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_mc_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_mc_add_global to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_mc_add_excl to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_mc_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devmap_managed_key to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __devm_add_action to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_unlock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_region_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_region_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_rate_nodes_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_rate_node_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_rate_leaf_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_rate_leaf_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_port_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_port_register_with_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_port_fn_devlink_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_params_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_params_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_param_driverinit_value_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_param_driverinit_value_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_nested_devlink_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_remote_reload_actions_performed to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_priv to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_port_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_port_register_with_ops to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_port_attrs_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_params_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_params_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_version_stored_put_ext to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_version_stored_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_version_running_put_ext to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_version_running_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_version_fixed_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_serial_number_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_info_board_serial_number_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_reporter_state_update to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_reporter_recovery_done to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_reporter_priv to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_reporter_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_reporter_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_health_report to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_u8_pair_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_u32_pair_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_string_pair_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_pair_nest_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_pair_nest_end to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_obj_nest_start to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_obj_nest_end to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_dump_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_fmsg_binary_pair_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_flash_update_timeout_notify to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_flash_update_status_notify to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devlink_alloc_ns to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_health_reporter_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_health_reporter_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol devl_assert_locked to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_kfree_skb_irq_reason to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_kfree_skb_any_reason to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_wakeup_disable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_show_string to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_set_wakeup_enable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_set_wakeup_capable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_remove_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_initialize to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_create_file to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_add_disk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol device_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_get_stats to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_get_by_name to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_err to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_driver_string to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _dev_crit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_close to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_addr_mod to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_addr_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_addr_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dev_add_pack to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol destroy_workqueue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol del_gendisk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol delayed_work_timer_fn to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __delay to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol default_wake_function to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol default_llseek to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_remove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_lookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_create_u32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_create_file_full to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_create_dir to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_create_devm_seqfile to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_attr_write to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol debugfs_attr_read to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcbnl_ieee_notify to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcb_ieee_setapp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcb_ieee_getapp_prio_dscp_mask_map to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcb_ieee_getapp_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcb_ieee_delapp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dcb_getapp to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dca_unregister_notify to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dca_remove_requester to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dca_register_notify to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dca_add_requester to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol dca3_get_tag to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol current_work to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _ctype to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol csum_partial to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol csum_ipv6_magic to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crypto_shash_update to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crypto_shash_final to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crypto_destroy_tfm to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crypto_alloc_shash to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crc_t10dif to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol crc32_le to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpu_sibling_map to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpu_present_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpu_possible_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpu_online_mask to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpumask_next_wrap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpumask_local_spread to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpu_khz to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpu_info to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpuhp_state_remove_instance to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpuhp_state_add_instance to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpuhp_setup_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __cpuhp_remove_state to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpufreq_quick_get to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cpu_bit_bitmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _copy_to_user to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __copy_overflow to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _copy_from_user to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol consume_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __const_udelay to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol const_pcpu_hot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol config_group_init_type_name to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol config_group_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol configfs_unregister_subsystem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol configfs_register_subsystem to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol complete_all to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol complete to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol commit_creds to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol clock_t_to_jiffies to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol class_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol class_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol class_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol class_create to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __check_object_size to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cdev_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cdev_del to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cdev_alloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cdev_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cc_mkdec to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol capable to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cancel_work_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cancel_delayed_work_sync to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cancel_delayed_work to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol call_usermodehelper to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol call_switchdev_notifiers to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol call_netdevice_notifiers to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol cachemode2protval to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol byte_rev_table to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol build_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol BUG_func to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_update to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_remove to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_lookup to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_last to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_insert to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_get_prev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_geo64 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_geo32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol btree_destroy to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bsg_setup_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bsg_remove_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bsg_job_done to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bsearch to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __break_lease to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_warn_invalid_xdp_action to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run8 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run5 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run4 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run3 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run2 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_trace_run1 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_stats_enabled_key to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_prog_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_prog_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_master_redirect_enabled_key to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bpf_dispatcher_xdp_func to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol boot_cpu_data to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blockdev_superblock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_status_to_errno to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_start_plug to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_stack_limits to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_queue_rq_timeout to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_mq_unique_tag to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_mq_tagset_busy_iter to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_mq_map_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_mq_map_hw_queues to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blk_finish_plug to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol blkcg_get_fc_appid to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __blk_alloc_disk to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_zalloc to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_xor to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_weight to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_subset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_set to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_print_to_pagebuf to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_parselist to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_or to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_intersects to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_from_arr32 to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bitmap_find_next_zero_area_off to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_equal to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_clear to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_andnot to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __bitmap_and to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bioset_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bioset_exit to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_put to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_endio to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_clone_blkg_association to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_associate_blkg to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_alloc_clone to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bio_alloc_bioset to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _bin2bcd to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bdev_thaw to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bdev_freeze to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bdev_file_open_by_path to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol bdev_file_open_by_dev to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol auxiliary_driver_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __auxiliary_driver_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol auxiliary_device_init to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __auxiliary_device_add to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol autoremove_wake_function to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol atomic_notifier_chain_unregister to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol atomic_notifier_chain_register to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol _atomic_dec_and_lock to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol argv_split to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol argv_free to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol arch_touch_nmi_watchdog to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_workqueue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __alloc_skb to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_pages_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol __alloc_pages_noprof to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_netdev_mqs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_etherdev_mqs to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_cpu_rmap to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_cpumask_var_node to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol alloc_chrdev_region to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol add_wait_queue_exclusive to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol add_wait_queue to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol add_timer to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol acpi_get_table to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol acpi_disabled to stablelist (Cestmir Kalina) [RHEL-113009]
- kabi: add symbol abort_creds to stablelist (Cestmir Kalina) [RHEL-113009]
[6.12.0-124.4.1]
- ipv6: reject malicious packets in ipv6_gso_segment() (CKI Backport Bot) [RHEL-113251] {CVE-2025-38572}
- wifi: ath12k: Decrement TID on RX peer frag setup error handling (CKI Backport Bot) [RHEL-114710] {CVE-2025-39761}
- xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CKI Backport Bot) [RHEL-109531] {CVE-2025-38500}
- net: add reserved fields to devlink_port_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_health_reporter_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_port_region_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_region_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_param (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_dpipe_table_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_linecard_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_ops (Ivan Vecera) [RHEL-111907]
- net: add reserved fields to devlink_port (Ivan Vecera) [RHEL-111907]
- ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (Hangbin Liu) [RHEL-111156] {CVE-2025-38550}
- tcp: Correct signedness in skb remaining space calculation (Florian Westphal) [RHEL-107843] {CVE-2025-38463}
- ice: use fixed adapter index for E825C embedded devices (Michal Schmidt) [RHEL-111791]
[6.12.0-124.3.1]
- net: stmmac: fix TSO DMA API usage causing oops (Izabela Bakollari) [RHEL-84762]
- octeon_ep: Fix host hang issue during device reboot (Kamal Heib) [RHEL-90058]
- octeon_ep_vf: Resolve netdevice usage count issue (Kamal Heib) [RHEL-90058]
- octeon_ep_vf: update tx/rx stats locally for persistence (Kamal Heib) [RHEL-90058]
- octeon_ep_vf: remove firmware stats fetch in ndo_get_stats64 (Kamal Heib) [RHEL-90058]
- octeon_ep: update tx/rx stats locally for persistence (Kamal Heib) [RHEL-90058]
- octeon_ep: remove firmware stats fetch in ndo_get_stats64 (Kamal Heib) [RHEL-90058]
- octeon_ep: add ndo ops for VFs in PF driver (Kamal Heib) [RHEL-90058]
- net: marvell: use ethtool string helpers (Kamal Heib) [RHEL-90058]
- io_uring/futex: ensure io_futex_wait() cleans up properly on failure (CKI Backport Bot) [RHEL-114338] {CVE-2025-39698}
- net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (CKI Backport Bot) [RHEL-106587] {CVE-2025-38468}
- dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using (Audra Mitchell) [RHEL-106609] {CVE-2025-38369}
- ethtool: Block setting of symmetric RSS when non-symmetric rx-flow-hash is requested (CKI Backport Bot) [RHEL-107023]
[6.12.0-124.2.1]
- flexfiles/pNFS: fix NULL checks on result of ff_layout_choose_ds_for_read (Benjamin Coddington) [RHEL-110294]
- pNFS/flexfiles: don't attempt pnfs on fatal DS errors (Benjamin Coddington) [RHEL-110294]
- HID: core: Harden s32ton() against conversion to 0 bits (Benjamin Tissoires) [RHEL-111038] {CVE-2025-38556}
- Revert 'KVM: arm64: Hide ID_AA64MMFR2_EL1.NV from guest and userspace' (Eric Auger) [RHEL-112491]
- fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass (Audra Mitchell) [RHEL-106613] {CVE-2025-38396}
- Revert 'e1000e: change k1 configuration on MTP and later platforms' (Michal Schmidt) [RHEL-109782]
- s390/sclp: Fix SCCB present check (CKI Backport Bot) [RHEL-113560] {CVE-2025-39694}
- idpf: convert control queue mutex to a spinlock (CKI Backport Bot) [RHEL-106059] {CVE-2025-38392}
- redhat/configs: Enable CONFIG_MITIGATION_TSA for x86 (Waiman Long) [RHEL-83893]
- x86/process: Move the buffer clearing before MONITOR (Waiman Long) [RHEL-83893 RHEL-83903] {CVE-2024-36357 CVE-2024-36350}
- x86/microcode/AMD: Add TSA microcode SHAs (Waiman Long) [RHEL-83893 RHEL-83903] {CVE-2024-36357 CVE-2024-36350}
- KVM: SVM: Advertise TSA CPUID bits to guests (Waiman Long) [RHEL-83893 RHEL-83903] {CVE-2024-36357 CVE-2024-36350}
- x86/bugs: Add a Transient Scheduler Attacks mitigation (Waiman Long) [RHEL-83893 RHEL-83903] {CVE-2024-36357 CVE-2024-36350}
- x86/bugs: Rename MDS machinery to something more generic (Waiman Long) [RHEL-83893 RHEL-83903] {CVE-2024-36357 CVE-2024-36350}
- x86/bugs: Fix spectre_v2 mitigation default on Intel (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure ITS mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Fix SRSO reporting on Zen1/2 with SMT disabled (Waiman Long) [RHEL-83893]
(Waiman Long) [RHEL-83893]
- x86/idle: Remove .s output beautifying delimiters from simpler asm() templates (Waiman Long) [RHEL-83893]
- x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt() (Waiman Long) [RHEL-83893]
- x86/cpufeatures: Add X86_FEATURE_APX (Waiman Long) [RHEL-83893]
- x86/cpufeatures: Shorten X86_FEATURE_AMD_HETEROGENEOUS_CORES (Waiman Long) [RHEL-83893]
- x86/cpufeatures: Shorten X86_FEATURE_CLEAR_BHB_LOOP_ON_VMEXIT (Waiman Long) [RHEL-83893]
- x86/cpufeatures: Clean up formatting (Waiman Long) [RHEL-83893]
- x86/bugs: Remove X86_BUG_MMIO_UNKNOWN (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure SRSO mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure L1TF mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure SSB mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure spectre_v2 mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure BHI mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure spectre_v2_user mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure retbleed mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Allow retbleed=stuff only on Intel (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure spectre_v1 mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure GDS mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure SRBDS mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Remove md_clear_*_mitigation() (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure RFDS mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure MMIO mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure TAA mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Restructure MDS mitigation (Waiman Long) [RHEL-83893]
- x86/bugs: Rename mmio_stale_data_clear to cpu_buf_vm_clear (Waiman Long) [RHEL-83893]
- x86/microcode: Consolidate the loader enablement checking (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (Waiman Long) [RHEL-83893] {CVE-2025-22047}
- x86: move ZMM exclusion list into CPU feature flag (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Add some forgotten models to the SHA check (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Load only SHA256-checksummed patches (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Add get_patch_level() (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Get rid of the _load_microcode_amd() forward declaration (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Merge early_apply_microcode() into its single callsite (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Remove unused save_microcode_in_initrd_amd() declarations (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Remove ugly linebreak in __verify_patch_section() signature (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Remove ret local var in early_apply_microcode() (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Have __apply_microcode_amd() return bool (Waiman Long) [RHEL-83893]
- x86/microcode/AMD: Return bool from find_blobs_in_containers() (Waiman Long) [RHEL-83893]
- x86/cpu: Fix formatting of cpuid_bits[] in scattered.c (Waiman Long) [RHEL-83893]
- x86/cpufeatures: Add X86_FEATURE_AMD_WORKLOAD_CLASS feature bit (Waiman Long) [RHEL-83893]
[6.12.0-124.1.1]
- cxl: core/region - ignore interleave granularity when ways=1 (John W. Linville) [RHEL-107880]
- posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CKI Backport Bot) [RHEL-112787] {CVE-2025-38352}
- netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (Florian Westphal) [RHEL-106441] {CVE-2025-38472}
- netfilter: nf_tables: hide clash bit from userspace (Florian Westphal) [RHEL-106441]
- selftests: netfilter: conntrack_resize.sh: extend resize test (Florian Westphal) [RHEL-106441]
- redhat: Explicitly disable 'hostonly' mode on the dracut cmdline (Vitaly Kuznetsov) [RHEL-109610]
- redhat: Directly use 'ukify' for building the UKI (Vitaly Kuznetsov) [RHEL-109610]
- redhat: Add SBAT to the UKI unconditionally (Vitaly Kuznetsov) [RHEL-109610]
- sunrpc: fix handling of server side tls alerts (Olga Kornievskaia) [RHEL-111072] {CVE-2025-38566}
- dpll: add reserved fields to dpll_device_ops and dpll_pin_ops structs (Ivan Vecera) [RHEL-111905]
- sunrpc: fix client side handling of tls alerts (Olga Kornievskaia) [RHEL-110814] {CVE-2025-38571}
- i40e: report VF tx_dropped with tx_errors instead of tx_discards (Dennis Chen) [RHEL-105134]
- kselftests/mm: fix khugepaged build broken (Chunyu Hu) [RHEL-112084]
- iommu/virtio: Make instance lookup robust (Eric Auger) [RHEL-108207]
- enic: fix incorrect MTU comparison in enic_change_mtu() (CKI Backport Bot) [RHEL-108262]
- net/enic: Allow at least 8 RQs to always be used (CKI Backport Bot) [RHEL-108262]
- ixgbe: prevent from unwanted interface name changes (CKI Backport Bot) [RHEL-109604]
- devlink: let driver opt out of automatic phys_port_name generation (CKI Backport Bot) [RHEL-109604]
- redhat: set defaults for RHEL 10.1 (Julio Faracco)
[6.12.0-124]
- ACPI: PRM: Reduce unnecessary printing to avoid user confusion (Frank Liang) [RHEL-107449]
- scsi: aacraid: Stop using PCI_IRQ_AFFINITY (John Meneghini) [RHEL-41234]
- loop: use kiocb helpers to fix lockdep warning (Ming Lei) [RHEL-103981]
- tipc: Fix use-after-free in tipc_conn_close(). (CKI Backport Bot) [RHEL-106663] {CVE-2025-38464}
- sched/deadline: Fix accounting after global limits change (Phil Auld) [RHEL-105980]
- tools/sched: Add root_domains_dump.py which dumps root domains info (Phil Auld) [RHEL-105980]
- tools/sched: Add dl_bw_dump.py for printing bandwidth accounting info (Phil Auld) [RHEL-105980]
- sched/deadline: Initialize dl_servers after SMP (Phil Auld) [RHEL-105980]
- sched/deadline: Less agressive dl_server handling (Phil Auld) [RHEL-105980]
- sched/deadline: Reset extra_bw to max_bw when clearing root domains (Phil Auld) [RHEL-105980]
- sched: Change nr_uninterruptible type to unsigned long (Phil Auld) [RHEL-105980]
- sched/fair: Always trigger resched at the end of a protected period (Phil Auld) [RHEL-105980]
- sched/fair: Fix entity's lag with run to parity (Phil Auld) [RHEL-105980]
- sched/fair: Limit run to parity to the min slice of enqueued entities (Phil Auld) [RHEL-105980]
- sched/fair: Remove spurious shorter slice preemption (Phil Auld) [RHEL-105980]
- sched/fair: Fix NO_RUN_TO_PARITY case (Phil Auld) [RHEL-105980]
- sched: Cancel the slice protection of the idle entity (Phil Auld) [RHEL-105980]
- sched/fair: Use protect_slice() instead of direct comparison (Phil Auld) [RHEL-105980]
- sched/deadline: Fix dl_server runtime calculation formula (Phil Auld) [RHEL-105980]
- sched/core: Fix migrate_swap() vs. hotplug (Phil Auld) [RHEL-105980]
- sched: Fix preemption string of preempt_dynamic_none (Phil Auld) [RHEL-105980]
- sched/debug: Print the local group's asym_prefer_cpu (Phil Auld) [RHEL-105980]
- cpufreq/amd-pstate: Update asym_prefer_cpu when core rankings change (Phil Auld) [RHEL-105980]
- sched/topology: Introduce sched_update_asym_prefer_cpu() (Phil Auld) [RHEL-105980]
- sched/fair: Use READ_ONCE() to read sg->asym_prefer_cpu (Phil Auld) [RHEL-105980]
... | MODERATE | 2025-11-25 00:00:00+03:00 | ['CVE-2024-28956', 'CVE-2024-36350', 'CVE-2024-36357', 'CVE-2024-49570', 'CVE-2024-52332', 'CVE-2024-53147', 'CVE-2024-53216', 'CVE-2024-53222', 'CVE-2024-53241', 'CVE-2024-54456', 'CVE-2024-56662', 'CVE-2024-56675', 'CVE-2024-56690', 'CVE-2024-57901', 'CVE-2024-57902', 'CVE-2024-57941', 'CVE-2024-57942', 'CVE-2024-57977', 'CVE-2024-57981', 'CVE-2024-57984', 'CVE-2024-57986', 'CVE-2024-57987', 'CVE-2024-57988', 'CVE-2024-57989', 'CVE-2024-57995', 'CVE-2024-58004', 'CVE-2024-58005', 'CVE-2024-58006', 'CVE-2024-58012', 'CVE-2024-58013', 'CVE-2024-58014', 'CVE-2024-58015', 'CVE-2024-58020', 'CVE-2024-58057', 'CVE-2024-58061', 'CVE-2024-58069', 'CVE-2024-58072', 'CVE-2024-58075', 'CVE-2024-58077', 'CVE-2024-58088', 'CVE-2025-21633', 'CVE-2025-21647', 'CVE-2025-21652', 'CVE-2025-21655', 'CVE-2025-21671', 'CVE-2025-21680', 'CVE-2025-21691', 'CVE-2025-21693', 'CVE-2025-21696', 'CVE-2025-21702', 'CVE-2025-21726', 'CVE-2025-21732', 'CVE-2025-21738', 'CVE-2025-21741', 'CVE-2025-21742', 'CVE-2025-21743', 'CVE-2025-21750', 'CVE-2025-21761', 'CVE-2025-21765', 'CVE-2025-21771', 'CVE-2025-21777', 'CVE-2025-21785', 'CVE-2025-21786', 'CVE-2025-21790', 'CVE-2025-21791', 'CVE-2025-21795', 'CVE-2025-21796', 'CVE-2025-21826', 'CVE-2025-21828', 'CVE-2025-21837', 'CVE-2025-21844', 'CVE-2025-21846', 'CVE-2025-21847', 'CVE-2025-21851', 'CVE-2025-21853', 'CVE-2025-21855', 'CVE-2025-21857', 'CVE-2025-21861', 'CVE-2025-21863', 'CVE-2025-21864', 'CVE-2025-21976', 'CVE-2025-22056', 'CVE-2025-37749', 'CVE-2025-37994', 'CVE-2025-38116', 'CVE-2025-38369', 'CVE-2025-38412', 'CVE-2025-38468'] | ['Oracle Linux 10'] | ['CVE-2024-28956', 'CVE-2024-36350', 'CVE-2024-36357', 'CVE-2024-49570', 'CVE-2024-52332', 'CVE-2024-53147', 'CVE-2024-53216', 'CVE-2024-53222', 'CVE-2024-53241', 'CVE-2024-54456', 'CVE-2024-56662', 'CVE-2024-56675', 'CVE-2024-56690', 'CVE-2024-57901', 'CVE-2024-57902', 'CVE-2024-57941', 'CVE-2024-57942', 'CVE-2024-57977', 'CVE-2024-57981', 'CVE-2024-57984', 'CVE-2024-57986', 'CVE-2024-57987', 'CVE-2024-57988', 'CVE-2024-57989', 'CVE-2024-57995', 'CVE-2024-58004', 'CVE-2024-58005', 'CVE-2024-58006', 'CVE-2024-58012', 'CVE-2024-58013', 'CVE-2024-58014', 'CVE-2024-58015', 'CVE-2024-58020', 'CVE-2024-58057', 'CVE-2024-58061', 'CVE-2024-58069', 'CVE-2024-58072', 'CVE-2024-58075', 'CVE-2024-58077', 'CVE-2024-58088', 'CVE-2025-21633', 'CVE-2025-21647', 'CVE-2025-21652', 'CVE-2025-21655', 'CVE-2025-21671', 'CVE-2025-21680', 'CVE-2025-21691', 'CVE-2025-21693', 'CVE-2025-21696', 'CVE-2025-21702', 'CVE-2025-21726', 'CVE-2025-21732', 'CVE-2025-21738', 'CVE-2025-21741', 'CVE-2025-21742', 'CVE-2025-21743', 'CVE-2025-21750', 'CVE-2025-21761', 'CVE-2025-21765', 'CVE-2025-21771', 'CVE-2025-21777', 'CVE-2025-21785', 'CVE-2025-21786', 'CVE-2025-21790', 'CVE-2025-21791', 'CVE-2025-21795', 'CVE-2025-21796', 'CVE-2025-21826', 'CVE-2025-21828', 'CVE-2025-21837', 'CVE-2025-21844', 'CVE-2025-21846', 'CVE-2025-21847', 'CVE-2025-21851', 'CVE-2025-21853', 'CVE-2025-21855', 'CVE-2025-21857', 'CVE-2025-21861', 'CVE-2025-21863', 'CVE-2025-21864', 'CVE-2025-21976', 'CVE-2025-22056', 'CVE-2025-37749', 'CVE-2025-37994', 'CVE-2025-38116', 'CVE-2025-38369', 'CVE-2025-38412', 'CVE-2025-38468', 'ELSA-2025-20095-0', 'https://linux.oracle.com/cve/CVE-2024-28956.html', 'https://linux.oracle.com/cve/CVE-2024-36350.html', 'https://linux.oracle.com/cve/CVE-2024-36357.html', 'https://linux.oracle.com/cve/CVE-2024-49570.html', 'https://linux.oracle.com/cve/CVE-2024-52332.html', 'https://linux.oracle.com/cve/CVE-2024-53147.html', 'https://linux.oracle.com/cve/CVE-2024-53216.html', 'https://linux.oracle.com/cve/CVE-2024-53222.html', 'https://linux.oracle.com/cve/CVE-2024-53241.html', 'https://linux.oracle.com/cve/CVE-2024-54456.html', 'https://linux.oracle.com/cve/CVE-2024-56662.html', 'https://linux.oracle.com/cve/CVE-2024-56675.html', 'https://linux.oracle.com/cve/CVE-2024-56690.html', 'https://linux.oracle.com/cve/CVE-2024-57901.html', 'https://linux.oracle.com/cve/CVE-2024-57902.html', 'https://linux.oracle.com/cve/CVE-2024-57941.html', 'https://linux.oracle.com/cve/CVE-2024-57942.html', 'https://linux.oracle.com/cve/CVE-2024-57977.html', 'https://linux.oracle.com/cve/CVE-2024-57981.html', 'https://linux.oracle.com/cve/CVE-2024-57984.html', 'https://linux.oracle.com/cve/CVE-2024-57986.html', 'https://linux.oracle.com/cve/CVE-2024-57987.html', 'https://linux.oracle.com/cve/CVE-2024-57988.html', 'https://linux.oracle.com/cve/CVE-2024-57989.html', 'https://linux.oracle.com/cve/CVE-2024-57995.html', 'https://linux.oracle.com/cve/CVE-2024-58004.html', 'https://linux.oracle.com/cve/CVE-2024-58005.html', 'https://linux.oracle.com/cve/CVE-2024-58006.html', 'https://linux.oracle.com/cve/CVE-2024-58012.html', 'https://linux.oracle.com/cve/CVE-2024-58013.html', 'https://linux.oracle.com/cve/CVE-2024-58014.html', 'https://linux.oracle.com/cve/CVE-2024-58015.html', 'https://linux.oracle.com/cve/CVE-2024-58020.html', 'https://linux.oracle.com/cve/CVE-2024-58057.html', 'https://linux.oracle.com/cve/CVE-2024-58061.html', 'https://linux.oracle.com/cve/CVE-2024-58069.html', 'https://linux.oracle.com/cve/CVE-2024-58072.html', 'https://linux.oracle.com/cve/CVE-2024-58075.html', 'https://linux.oracle.com/cve/CVE-2024-58077.html', 'https://linux.oracle.com/cve/CVE-2024-58088.html', 'https://linux.oracle.com/cve/CVE-2025-21633.html', 'https://linux.oracle.com/cve/CVE-2025-21647.html', 'https://linux.oracle.com/cve/CVE-2025-21652.html', 'https://linux.oracle.com/cve/CVE-2025-21655.html', 'https://linux.oracle.com/cve/CVE-2025-21671.html', 'https://linux.oracle.com/cve/CVE-2025-21680.html', 'https://linux.oracle.com/cve/CVE-2025-21691.html', 'https://linux.oracle.com/cve/CVE-2025-21693.html', 'https://linux.oracle.com/cve/CVE-2025-21696.html', 'https://linux.oracle.com/cve/CVE-2025-21702.html', 'https://linux.oracle.com/cve/CVE-2025-21726.html', 'https://linux.oracle.com/cve/CVE-2025-21732.html', 'https://linux.oracle.com/cve/CVE-2025-21738.html', 'https://linux.oracle.com/cve/CVE-2025-21741.html', 'https://linux.oracle.com/cve/CVE-2025-21742.html', 'https://linux.oracle.com/cve/CVE-2025-21743.html', 'https://linux.oracle.com/cve/CVE-2025-21750.html', 'https://linux.oracle.com/cve/CVE-2025-21761.html', 'https://linux.oracle.com/cve/CVE-2025-21765.html', 'https://linux.oracle.com/cve/CVE-2025-21771.html', 'https://linux.oracle.com/cve/CVE-2025-21777.html', 'https://linux.oracle.com/cve/CVE-2025-21785.html', 'https://linux.oracle.com/cve/CVE-2025-21786.html', 'https://linux.oracle.com/cve/CVE-2025-21790.html', 'https://linux.oracle.com/cve/CVE-2025-21791.html', 'https://linux.oracle.com/cve/CVE-2025-21795.html', 'https://linux.oracle.com/cve/CVE-2025-21796.html', 'https://linux.oracle.com/cve/CVE-2025-21826.html', 'https://linux.oracle.com/cve/CVE-2025-21828.html', 'https://linux.oracle.com/cve/CVE-2025-21837.html', 'https://linux.oracle.com/cve/CVE-2025-21844.html', 'https://linux.oracle.com/cve/CVE-2025-21846.html', 'https://linux.oracle.com/cve/CVE-2025-21847.html', 'https://linux.oracle.com/cve/CVE-2025-21851.html', 'https://linux.oracle.com/cve/CVE-2025-21853.html', 'https://linux.oracle.com/cve/CVE-2025-21855.html', 'https://linux.oracle.com/cve/CVE-2025-21857.html', 'https://linux.oracle.com/cve/CVE-2025-21861.html', 'https://linux.oracle.com/cve/CVE-2025-21863.html', 'https://linux.oracle.com/cve/CVE-2025-21864.html', 'https://linux.oracle.com/cve/CVE-2025-21976.html', 'https://linux.oracle.com/cve/CVE-2025-22056.html', 'https://linux.oracle.com/cve/CVE-2025-37749.html', 'https://linux.oracle.com/cve/CVE-2025-37994.html', 'https://linux.oracle.com/cve/CVE-2025-38116.html', 'https://linux.oracle.com/cve/CVE-2025-38369.html', 'https://linux.oracle.com/cve/CVE-2025-38412.html', 'https://linux.oracle.com/cve/CVE-2025-38468.html', 'https://linux.oracle.com/errata/ELSA-2025-20095-0.html'] | fe99d2c31c7918ad920b3b787419491b66789185d64b0e4aa0f5ecc5ac02856e | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528026 | ELSA-2025-28026: Unbreakable Enterprise kernel security update (IMPORTANT) | [5.4.17-2136.349.3.2]
- crypto: essiv - Check ssize for decryption and in-place encryption (Herbert Xu) [Orabug: 38705546] {CVE-2025-40019} | IMPORTANT | 2025-12-02 00:00:00+03:00 | ['CVE-2025-40019'] | ['Oracle Linux 7', 'Oracle Linux 8'] | ['CVE-2025-40019', 'ELSA-2025-28026', 'https://linux.oracle.com/cve/CVE-2025-40019.html', 'https://linux.oracle.com/errata/ELSA-2025-28026.html'] | 911c95ee2272ca6a9cabfb4d664eb680fba10ddffd436561172f762e14b589e5 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:20210671 | ELSA-2021-0671: bind security update (IMPORTANT) | [32:9.11.4-26.P2.4]
- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
[32:9.11.4-26.P2.3]
- Fix inline re-signing (#rh1889902)
[32:9.11.4-26.P2.2]
- Fix unsupported algorithms validation (#rh1769876)
[32:9.11.4-26.P2.1]
- Fix tsig-request verify (CVE-2020-8622)
- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)
- Correct update-policy type subdomain to match documentation (CVE-2020-8624) | IMPORTANT | 2021-03-02 00:00:00+03:00 | ['CVE-2020-8625'] | ['Oracle Linux 7'] | ['CVE-2020-8625', 'ELSA-2021-0671', 'https://linux.oracle.com/cve/CVE-2020-8625.html', 'https://linux.oracle.com/errata/ELSA-2021-0671.html'] | 2d073169df2e0df6ce8759d39c66c546461564071b311408d10e6a0c63f2d6d5 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202619356 | ELSA-2026-19356: libsoup security update (MODERATE) | [2.72.0-16.1]
- Backport patch for CVE-2026-5119
[2.72.0-16]
- Backport patch for CVE-2026-1761
[2.72.0-15]
- Backport patch for CVE-2026-0719
- Fix NTLM authentication test failures in FIPS mode
[2.72.0-14]
- Backport patch for CVE-2025-14523
[2.72.0-13]
- Backport patch for CVE-2025-4945 and CVE-2025-11021 | MODERATE | 2026-06-23 00:00:00+03:00 | ['CVE-2026-5119'] | ['Oracle Linux 9'] | ['CVE-2026-5119', 'ELSA-2026-19356', 'https://linux.oracle.com/cve/CVE-2026-5119.html', 'https://linux.oracle.com/errata/ELSA-2026-19356.html'] | 7ba4ca56d8437be1426f5270284f6a12c3ea396c940bce79f13998eb6eb56582 | 2026-06-24 18:41:44.947363+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202522363 | ELSA-2025-22363: firefox security update (IMPORTANT) | [140.5.0-1.0.1]
- Fix firefox-oracle-default-prefs.js for new nss [Orabug: 37079789]
[140.5.0]
- Add debranding patches (Mustafa Gezen)
- Add OpenELA default preferences (Louis Abel)
[140.5.0-1]
- Update to 140.5.0 ESR | IMPORTANT | 2025-12-01 00:00:00+03:00 | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020'] | ['Oracle Linux 8'] | ['CVE-2025-13012', 'CVE-2025-13013', 'CVE-2025-13014', 'CVE-2025-13015', 'CVE-2025-13016', 'CVE-2025-13017', 'CVE-2025-13018', 'CVE-2025-13019', 'CVE-2025-13020', 'ELSA-2025-22363', 'https://linux.oracle.com/cve/CVE-2025-13012.html', 'https://linux.oracle.com/cve/CVE-2025-13013.html', 'https://linux.oracle.com/cve/CVE-2025-13014.html', 'https://linux.oracle.com/cve/CVE-2025-13015.html', 'https://linux.oracle.com/cve/CVE-2025-13016.html', 'https://linux.oracle.com/cve/CVE-2025-13017.html', 'https://linux.oracle.com/cve/CVE-2025-13018.html', 'https://linux.oracle.com/cve/CVE-2025-13019.html', 'https://linux.oracle.com/cve/CVE-2025-13020.html', 'https://linux.oracle.com/errata/ELSA-2025-22363.html'] | 14e1a5e31b47f16e4e33622720e53e68d3f7f7658b51eeeedf8a9e772bcd02e3 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 | |
oval:com.oracle.elsa:def:202528003 | ELSA-2025-28003: glibc security update (MODERATE) | [2.39-58.0.1]
- Forward port Oracle changes to 2.39-58.
- Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
Oracle history:
August-29-2025 Cupertino Miranda <cupertino.miranda@oracle.com> - 2.39-54.0.1
- Forward port Oracle changes.
Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
August-7-2025 Cupertino Miranda <cupertino.miranda@oracle.com> - 2.39-46.0.1
- Forward port Oracle changes.
Reviewed-by: David Faust <david.faust@oracle.com>
July-15-2025 Cupertino Miranda <cupertino.miranda@oracle.com> - 2.39-43.0.1
- Forward port Oracle changes.
Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
March-5-2025 Cupertino Miranda <cupertino.miranda@oracle.com> - 2.39-37.0.1
- Forward port Oracle changes to 2.39-37.
Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
Jan-22-2025 Cupertino Miranda <cupertino.miranda@oracle.com> - 2.39-32.0.1
- Integration of relevant Oracle patches.
Reviewed-by: Jose E. Marchesi <jose.marchesi@oracle.com>
[2.39-58]
- Use Requires(pre): libgcc(x86-64) to break libgcc cycle (RHEL-110559)
[2.39-57]
- Sync with upstream branch release/2.39/master (RHEL-109536)
- Upstream commit: fffc2df8a3e2c8cda2991063d23086360268b777
- Extend struct r_debug to support multiple namespaces (RHEL-101985)
- Fix a potential crash in the dynamic loader when processing specific
symbol versions (RHEL-109683)
- Signal la_objopen for ld.so with dlmopen (RHEL-109693)
- Switch to main malloc after final ld.so self-relocation (RHEL-109703)
- Prevent ld.so from asserting and crashing during audited library loads
(RHEL-109702)
- x86-64: Provide GLIBC_ABI_DT_X86_64_PLT symbol version (RHEL-109621)
- x86-64: Provide GLIBC_ABI_GNU2_TLS symbol version (RHEL-109625)
- Ensure fallback initialization of ctype TLS data pointers to fix segfaults in
programs using dlmopen or auditors (RHEL-72018)
- Handle load segment gaps in _dl_find_object (RHEL-104854)
- AArch64: Improve codegen in SVE log1p
- AArch64: Optimize inverse trig functions
- AArch64: Avoid memset ifunc in cpu-features.c [BZ #33112]
[2.39-56]
- Add FUSE based tests for fchmod, lstat, and mkstemp (RHEL-108823)
[2.39-55]
- Various updates to the manual from upstream (RHEL-108974)
[2.39-54]
- Fix memory leak after fdopen seek failure (RHEL-108475)
[2.39-53]
- Updated glibc to support Linux 6.15 kernel system calls and constants.
(RHEL-107695)
[2.39-52]
- Add sched_setattr and sched_getattr functions (RHEL-58357)
[2.39-51]
- Enhanced glibc documentation for core descriptor APIs. (RHEL-107861)
[2.39-50]
- Improve test coverage (RHEL-106562) | MODERATE | 2025-11-20 00:00:00+03:00 | ['CVE-2025-8058'] | ['Oracle Linux 10'] | ['CVE-2025-8058', 'ELSA-2025-28003', 'https://linux.oracle.com/cve/CVE-2025-8058.html', 'https://linux.oracle.com/errata/ELSA-2025-28003.html'] | 08cf0500350d5517e83505e0560c28351187c6c58176bf0554ee31741dbf6d02 | 2026-05-30 01:54:59.821900+03:00 | 2026-06-29 20:18:23.536535+03:00 |