diff --git a/.gitignore b/.gitignore index eb688dc70..c9c62dabc 100644 --- a/.gitignore +++ b/.gitignore @@ -1,6 +1,6 @@ -SOURCES/kernel-abi-stablelists-5.14.0-570.21.1.el9_6.tar.bz2 -SOURCES/kernel-kabi-dw-5.14.0-570.21.1.el9_6.tar.bz2 -SOURCES/linux-5.14.0-570.21.1.el9_6.tar.xz +SOURCES/kernel-abi-stablelists-5.14.0-570.22.1.el9_6.tar.bz2 +SOURCES/kernel-kabi-dw-5.14.0-570.22.1.el9_6.tar.bz2 +SOURCES/linux-5.14.0-570.22.1.el9_6.tar.xz SOURCES/nvidiagpuoot001.x509 SOURCES/olima1.x509 SOURCES/olimaca1.x509 diff --git a/.kernel.metadata b/.kernel.metadata index 016f23aae..f50cde4c3 100644 --- a/.kernel.metadata +++ b/.kernel.metadata @@ -1,6 +1,6 @@ -51dad9e6359227ee71542273caf0e4a49d5bd1dc SOURCES/kernel-abi-stablelists-5.14.0-570.21.1.el9_6.tar.bz2 -6909c898143ff5188494043be7f22f98542b8d79 SOURCES/kernel-kabi-dw-5.14.0-570.21.1.el9_6.tar.bz2 -85597a937c7d26aa36d3aa1150c0afe01037114a SOURCES/linux-5.14.0-570.21.1.el9_6.tar.xz +b395f44c5cbfad792c59ef640b2c768477250054 SOURCES/kernel-abi-stablelists-5.14.0-570.22.1.el9_6.tar.bz2 +34ff1cb825173d244edc511528f2051acce1b40a SOURCES/kernel-kabi-dw-5.14.0-570.22.1.el9_6.tar.bz2 +a6562532e0efca9b30d733b128a75e01ecc7c559 SOURCES/linux-5.14.0-570.22.1.el9_6.tar.xz 4fff8080e88afffc06d8ef5004db8d53bb21237f SOURCES/nvidiagpuoot001.x509 706ae01dd14efa38f0f565a3706acac19c78df02 SOURCES/olima1.x509 6e3f0d61414c0b50f48dc2d4c3b3cd024e1c3a43 SOURCES/olimaca1.x509 diff --git a/SOURCES/Makefile.rhelver b/SOURCES/Makefile.rhelver index 9880c7730..52ba9cd67 100644 --- a/SOURCES/Makefile.rhelver +++ b/SOURCES/Makefile.rhelver @@ -12,7 +12,7 @@ RHEL_MINOR = 6 # # Use this spot to avoid future merge conflicts. # Do not trim this comment. -RHEL_RELEASE = 570.21.1 +RHEL_RELEASE = 570.22.1 # # ZSTREAM diff --git a/SOURCES/kernel.changelog b/SOURCES/kernel.changelog index fe660944b..0298d1b14 100644 --- a/SOURCES/kernel.changelog +++ b/SOURCES/kernel.changelog @@ -1,3 +1,27 @@ +* Sat Jun 07 2025 CKI KWF Bot [5.14.0-570.22.1.el9_6] +- Bluetooth: L2CAP: Fix corrupted list in hci_chan_del (David Marlin) [RHEL-87890] {CVE-2025-21969} +- Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd (David Marlin) [RHEL-87890] {CVE-2025-21969} +- Revert "SUNRPC: Revert e0a912e8ddba" (Benjamin Coddington) [RHEL-94811] +- mm/hugetlb: fix kernel NULL pointer dereference when migrating hugetlb folio (Jay Shin) [RHEL-92291] +- mm: fix crashes from deferred split racing folio migration (Jay Shin) [RHEL-92291] {CVE-2024-42234} +- mm: memcg: fix split queue list crash when large folio migration (Jay Shin) [RHEL-92291] +- proc: fix UAF in proc_get_inode() (Ian Kent) [RHEL-86808] {CVE-2025-21999} +- cifs: Fix integer overflow while processing acdirmax mount option (Paulo Alcantara) [RHEL-87941] {CVE-2025-21963} +- wifi: cfg80211: init wiphy_work before allocating rfkill fails (CKI Backport Bot) [RHEL-87931] {CVE-2025-21979} +- wifi: cfg80211: cancel wiphy_work before freeing wiphy (CKI Backport Bot) [RHEL-87931] {CVE-2025-21979} +- eth: bnxt: fix truesize for mb-xdp-pass case (CKI Backport Bot) [RHEL-88328] {CVE-2025-21961} +- vmxnet3: unregister xdp rxq info in the reset path (CKI Backport Bot) [RHEL-92471] +- md: fix mddev uaf while iterating all_mddevs list (CKI Backport Bot) [RHEL-89062] {CVE-2025-22126} +- nvme: print firmware bug note for non-unique identifiers (Bryan Gurney) [RHEL-91163] +- nvme-pci: add BOGUS_NID quirk for Samsung PM1733 (Bryan Gurney) [RHEL-91163] +- media: v4l2-mediabus: Drop V4L2_MBUS_CSI2_CONTINUOUS_CLOCK flag (Kate Hsuan) [RHEL-90323] +- media: v4l2-mediabus: Drop legacy V4L2_MBUS_CSI2_CHANNEL_* flags (Kate Hsuan) [RHEL-90323] +- media: v4l2-mediabus: Use structures to describe bus configuration (Kate Hsuan) [RHEL-90323] +- media: v4l2-fwnode: Move bus config structure to v4l2_mediabus.h (Kate Hsuan) [RHEL-90323] +- sched/fair: Fix CPU bandwidth limit bypass during CPU hotplug (Phil Auld) [RHEL-86302] +- smb: client: fix UAF in decryption with multichannel (CKI Backport Bot) [RHEL-94460] {CVE-2025-37750} +Resolves: RHEL-86302, RHEL-86808, RHEL-87890, RHEL-87931, RHEL-87941, RHEL-88328, RHEL-89062, RHEL-90323, RHEL-91163, RHEL-92291, RHEL-92471, RHEL-94460, RHEL-94811 + * Tue Jun 03 2025 CKI KWF Bot [5.14.0-570.21.1.el9_6] - xsk: fix an integer overflow in xp_create_and_assign_umem() (CKI Backport Bot) [RHEL-87911] {CVE-2025-21997} - vlan: enforce underlying device type (Guillaume Nault) [RHEL-87884] {CVE-2025-21920} diff --git a/SPECS/kernel.spec b/SPECS/kernel.spec index ddb3b5d4d..9e58da40b 100644 --- a/SPECS/kernel.spec +++ b/SPECS/kernel.spec @@ -165,15 +165,15 @@ Summary: The Linux kernel # define buildid .local %define specversion 5.14.0 %define patchversion 5.14 -%define pkgrelease 570.21.1 +%define pkgrelease 570.22.1 %define kversion 5 -%define tarfile_release 5.14.0-570.21.1.el9_6 +%define tarfile_release 5.14.0-570.22.1.el9_6 # This is needed to do merge window version magic %define patchlevel 14 # This allows pkg_release to have configurable %%{?dist} tag -%define specrelease 570.21.1%{?buildid}%{?dist} +%define specrelease 570.22.1%{?buildid}%{?dist} # This defines the kabi tarball version -%define kabiversion 5.14.0-570.21.1.el9_6 +%define kabiversion 5.14.0-570.22.1.el9_6 # # End of genspec.sh variables @@ -3863,7 +3863,7 @@ fi # # %changelog -* Wed Jun 11 2025 Andrei Lukoshko - 5.14.0-570.21.1 +* Thu Jun 19 2025 Andrei Lukoshko - 5.14.0-570.22.1 - hpsa: bring back deprecated PCI ids #CFHack #CFHack2024 - mptsas: bring back deprecated PCI ids #CFHack #CFHack2024 - megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024 @@ -3874,11 +3874,34 @@ fi - kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained -* Wed Jun 11 2025 Eduard Abdullin - 5.14.0-570.21.1 +* Thu Jun 19 2025 Eduard Abdullin - 5.14.0-570.22.1 - Use AlmaLinux OS secure boot cert - Debrand for AlmaLinux OS - Add KVM support for ppc64le +* Sat Jun 07 2025 CKI KWF Bot [5.14.0-570.22.1.el9_6] +- Bluetooth: L2CAP: Fix corrupted list in hci_chan_del (David Marlin) [RHEL-87890] {CVE-2025-21969} +- Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd (David Marlin) [RHEL-87890] {CVE-2025-21969} +- Revert "SUNRPC: Revert e0a912e8ddba" (Benjamin Coddington) [RHEL-94811] +- mm/hugetlb: fix kernel NULL pointer dereference when migrating hugetlb folio (Jay Shin) [RHEL-92291] +- mm: fix crashes from deferred split racing folio migration (Jay Shin) [RHEL-92291] {CVE-2024-42234} +- mm: memcg: fix split queue list crash when large folio migration (Jay Shin) [RHEL-92291] +- proc: fix UAF in proc_get_inode() (Ian Kent) [RHEL-86808] {CVE-2025-21999} +- cifs: Fix integer overflow while processing acdirmax mount option (Paulo Alcantara) [RHEL-87941] {CVE-2025-21963} +- wifi: cfg80211: init wiphy_work before allocating rfkill fails (CKI Backport Bot) [RHEL-87931] {CVE-2025-21979} +- wifi: cfg80211: cancel wiphy_work before freeing wiphy (CKI Backport Bot) [RHEL-87931] {CVE-2025-21979} +- eth: bnxt: fix truesize for mb-xdp-pass case (CKI Backport Bot) [RHEL-88328] {CVE-2025-21961} +- vmxnet3: unregister xdp rxq info in the reset path (CKI Backport Bot) [RHEL-92471] +- md: fix mddev uaf while iterating all_mddevs list (CKI Backport Bot) [RHEL-89062] {CVE-2025-22126} +- nvme: print firmware bug note for non-unique identifiers (Bryan Gurney) [RHEL-91163] +- nvme-pci: add BOGUS_NID quirk for Samsung PM1733 (Bryan Gurney) [RHEL-91163] +- media: v4l2-mediabus: Drop V4L2_MBUS_CSI2_CONTINUOUS_CLOCK flag (Kate Hsuan) [RHEL-90323] +- media: v4l2-mediabus: Drop legacy V4L2_MBUS_CSI2_CHANNEL_* flags (Kate Hsuan) [RHEL-90323] +- media: v4l2-mediabus: Use structures to describe bus configuration (Kate Hsuan) [RHEL-90323] +- media: v4l2-fwnode: Move bus config structure to v4l2_mediabus.h (Kate Hsuan) [RHEL-90323] +- sched/fair: Fix CPU bandwidth limit bypass during CPU hotplug (Phil Auld) [RHEL-86302] +- smb: client: fix UAF in decryption with multichannel (CKI Backport Bot) [RHEL-94460] {CVE-2025-37750} + * Tue Jun 03 2025 CKI KWF Bot [5.14.0-570.21.1.el9_6] - xsk: fix an integer overflow in xp_create_and_assign_umem() (CKI Backport Bot) [RHEL-87911] {CVE-2025-21997} - vlan: enforce underlying device type (Guillaume Nault) [RHEL-87884] {CVE-2025-21920}