diff --git a/kernel.spec b/kernel.spec index ed42a39..0d20f38 100644 --- a/kernel.spec +++ b/kernel.spec @@ -49,10 +49,10 @@ # define buildid .local %define specversion 4.18.0 -%define pkgrelease 553.146.1.rt7.487.el8_10 +%define pkgrelease 553.147.1.rt7.488.el8_10 # allow pkg_release to have configurable %%{?dist} tag -%define specrelease 553.146.1.rt7.487%{?dist} +%define specrelease 553.147.1.rt7.488%{?dist} %define pkg_release %{specrelease}%{?buildid} @@ -159,7 +159,7 @@ # The preempt RT patch level %global rttag .rt7 # realtimeN -%global rtbuild .487 +%global rtbuild .488 %define with_doc 0 %define with_headers 0 %define with_cross_headers 0 @@ -2726,6 +2726,30 @@ fi # # %changelog +* Thu Jul 23 2026 CKI KWF Bot [4.18.0-553.147.1.rt7.488.el8_10] +- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (Aidan Wallace) [RHEL-213341] {CVE-2026-63807} +- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Aidan Wallace) [RHEL-213341] +- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Aidan Wallace) [RHEL-213341] +- KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state (Aidan Wallace) [RHEL-213341] +- KVM: nVMX: Add helper to put (unmap) vmcs12 pages (Aidan Wallace) [RHEL-213341] +- KVM: nVMX: Use kvm_vcpu_map() to get/pin vmcs12's APIC-access page (Aidan Wallace) [RHEL-213341] +- KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (Aidan Wallace) [RHEL-211228] {CVE-2025-40026} +- KVM: x86: wean in-kernel PIO from vcpu->arch.pio* (Aidan Wallace) [RHEL-211228] +- KVM: x86: move all vcpu->arch.pio* setup in emulator_pio_in_out() (Aidan Wallace) [RHEL-211228] +- KVM: x86: drop PIO from unregistered devices (Aidan Wallace) [RHEL-211228] +- KVM: x86: inline kernel_pio into its sole caller (Aidan Wallace) [RHEL-211228] +- serial: 8250_mid: Disable DMA for selected platforms (Mark Salter) [RHEL-190191] +- tipc: fix double-free in tipc_buf_append() (CKI Backport Bot) [RHEL-192178] {CVE-2026-52993} +- xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178324] +- dm log: fix out-of-bounds write due to region_count overflow (CKI Backport Bot) [RHEL-188543] {CVE-2026-53059} +- xfs: Use xarray to track SB UUIDs instead of plain array. (Lukas Herbolt) [RHEL-127174] +- selftests: kvm: try getting XFD and XSAVE state out of sync (Paolo Bonzini) [RHEL-166738] +- selftests: kvm: replace numbering of sync points with actions (Paolo Bonzini) [RHEL-166738] +- x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 (Paolo Bonzini) [RHEL-166738] +- mount: Retest MNT_LOCKED in do_umount (Ian Kent) [RHEL-152655] +- mount: Don't allow copying MNT_UNBINDABLE|MNT_LOCKED mounts (Ian Kent) [RHEL-152655] +- mount: Prevent MNT_DETACH from disconnecting locked mounts (Ian Kent) [RHEL-152655] + * Mon Jul 20 2026 CKI KWF Bot [4.18.0-553.146.1.rt7.487.el8_10] - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (Gaurav Goklani) [RHEL-180153] {CVE-2026-46117} - PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type (Herton R. Krzesinski) [RHEL-174916] diff --git a/sources b/sources index 8a35332..f34a533 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (linux-4.18.0-553.146.1.rt7.487.el8_10.tar.xz) = c3277280c0ddaae474f4995cbd4d1e2aa02d08c67d6c323ffcd25b86404ffb73356e8038648778588d4a9b625d596f707d021fce76c2094ed785e8724ff1fe4f +SHA512 (linux-4.18.0-553.147.1.rt7.488.el8_10.tar.xz) = 8d01480303c79fe5d1d24fd7f21495b92542948e71942ee6e946f0f6386f572e632b29e5169a446e894ecb2aa0d7908d0ed9ba9c4c62d90fc7a01de140e925f2