diff --git a/.gitignore b/.gitignore index ec3887b..b56869f 100644 --- a/.gitignore +++ b/.gitignore @@ -1,6 +1,6 @@ SOURCES/centossecureboot201.cer SOURCES/centossecurebootca2.cer -SOURCES/linux-4.18.0-553.104.1.rt7.445.el8_10.tar.xz +SOURCES/linux-4.18.0-553.105.1.rt7.446.el8_10.tar.xz SOURCES/redhatsecureboot302.cer SOURCES/redhatsecureboot303.cer SOURCES/redhatsecureboot501.cer diff --git a/.kernel-rt.metadata b/.kernel-rt.metadata index f11fee2..dfb1717 100644 --- a/.kernel-rt.metadata +++ b/.kernel-rt.metadata @@ -1,6 +1,6 @@ 2ba40bf9138b48311e5aa1b737b7f0a8ad66066f SOURCES/centossecureboot201.cer bfdb3d7cffc43f579655af5155d50c08671d95e5 SOURCES/centossecurebootca2.cer -f95d0f2ed5327c6e52740a75157be6778e50efc2 SOURCES/linux-4.18.0-553.104.1.rt7.445.el8_10.tar.xz +fdb49384e11f5bba46b8eb1c0468a981924b35fa SOURCES/linux-4.18.0-553.105.1.rt7.446.el8_10.tar.xz 13e5cd3f856b472fde80a4deb75f4c18dfb5b255 SOURCES/redhatsecureboot302.cer e89890ca0ded2f9058651cc5fa838b78db2e6cc2 SOURCES/redhatsecureboot303.cer ba0b760e594ff668ee72ae348adf3e49b97f75fb SOURCES/redhatsecureboot501.cer diff --git a/SPECS/kernel.spec b/SPECS/kernel.spec index a91f3d1..64c954c 100644 --- a/SPECS/kernel.spec +++ b/SPECS/kernel.spec @@ -38,10 +38,10 @@ # define buildid .local %define specversion 4.18.0 -%define pkgrelease 553.104.1.rt7.445.el8_10 +%define pkgrelease 553.105.1.rt7.446.el8_10 # allow pkg_release to have configurable %%{?dist} tag -%define specrelease 553.104.1.rt7.445%{?dist} +%define specrelease 553.105.1.rt7.446%{?dist} %define pkg_release %{specrelease}%{?buildid} @@ -148,7 +148,7 @@ # The preempt RT patch level %global rttag .rt7 # realtimeN -%global rtbuild .445 +%global rtbuild .446 %define with_doc 0 %define with_headers 0 %define with_cross_headers 0 @@ -2720,7 +2720,7 @@ fi # # %changelog -* Mon Feb 09 2026 Andrei Lukoshko - 4.18.0-553.104.1.rt7.445 +* Tue Feb 17 2026 Andrei Lukoshko - 4.18.0-553.105.1.rt7.446 - hpsa: bring back deprecated PCI ids #CFHack #CFHack2024 - mptsas: bring back deprecated PCI ids #CFHack #CFHack2024 - megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024 @@ -2731,11 +2731,33 @@ fi - kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained -* Mon Feb 09 2026 Eduard Abdullin - 4.18.0-553.104.1.rt7.445 +* Tue Feb 17 2026 Eduard Abdullin - 4.18.0-553.105.1.rt7.446 - Use AlmaLinux OS secure boot cert - Debrand for AlmaLinux OS -* Tue Feb 03 2026 CKI KWF Bot [4.18.0-553.104.1.rt7.445.el8_10] +* Sat Feb 07 2026 CKI KWF Bot [4.18.0-553.105.1.rt7.446.el8_10] +- s390/ipl: Clear SBP flag when bootprog is set (Mete Durlu) [RHEL-145334] +- Bluetooth: hci_event: Fix checking conn for le_conn_complete_evt (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_sync: Fix UAF on hci_abort_conn_sync (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_conn: Consolidate code for aborting connections (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: Fix printing errors if LE Connection times out (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_conn: Fix not cleaning up on LE Connection failure (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_sync: hold hdev->lock when cleanup hci_conn (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: Move hci_abort_conn to hci_conn.c (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: mgmt: Fix using hci_conn_abort (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_conn: Fix hci_connect_le_sync (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_sync: Cleanup hci_conn if it cannot be aborted (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_event: Fix checking for invalid handle on error status (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: call hci_le_conn_failed with hdev lock in hci_le_conn_failed (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_sync: fix undefined return of hci_disconnect_all_sync() (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: hci_event: Ignore multiple conn complete events (David Marlin) [RHEL-137111] {CVE-2023-53762} +- Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (David Marlin) [RHEL-137111] {CVE-2023-53762} +- fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds (CKI Backport Bot) [RHEL-137678] {CVE-2025-40304} +- gfs2: Fix duplicate should_fault_in_pages() call (Andreas Gruenbacher) [RHEL-130505] +- smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). (Mete Durlu) [RHEL-130012] {CVE-2025-40168} + +E* Wed Feb 04 2026 Alexandra Hájková [4.18.0-553.104.1.rt7.445.el8_10] - Revert "audit: Avoid excessive dput/dget in audit_context setup and reset paths" (Alexandra Hájková) [RHEL-145856] * Tue Feb 03 2026 CKI KWF Bot [4.18.0-553.103.1.rt7.444.el8_10]