hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le
KVM: PPC: Book3S HV: Make PMU save/restore symbols global for module builds
- Drop AlmaLinux ahead-of-RHEL rtmutex remove_waiter() fixes (1756, 1757),
superseded by RHEL's CVE-2026-43499 copies in 687.25.1
- Add RHEL 687.25.1 backports recreated from CS9/upstream (1761-1769),
including the futex/requeue guard and its same-release revert (net zero,
kept for changelog fidelity)
Re-add the rtmutex self-deadlock NULL deref fixes (upstream 3bfdc63936dd +
40a25d59e85b) as patches 1756/1757, previously shipped as 1736/1738 in
687.22.2 and temporarily dropped in 687.23.1.
- Drop AlmaLinux ahead-of-RHEL eventpoll CVE-2026-46242 fix (1712), superseded
by the RHEL eventpoll series in 687.23.1
- Temporarily drop the rtmutex remove_waiter() fixes (1736, 1738)
- Add RHEL 687.23.1 backports recreated from CS10/upstream (1739-1755)
Add the RHEL 687.14.1..687.15.1 backports (1270-1284) from centos-stream-9 and
upstream stable, on top of 687.13.1. The dpll/zl3073x and ice RSS-queue series are
consolidated (they carry RHEL kABI wrapping and RHEL-only files). The mlx5 kabi
removal (RHEL-181822) is applied via updated Module.kabi_{aarch64,s390x,x86_64}.
Bump pkgrelease and specrelease to 687.15.1.
Add the RHEL 687.13.1 backports (1253-1269) from centos-stream-9 and upstream
stable, on top of 687.12.1. RHEL now ships the smb cifs.spnego fix (CVE-2026-46243)
too. Bump pkgrelease and specrelease to 687.13.1.
Drop the 687.5.3/687.5.4 security-ahead patches superseded by the RHEL
687.6.1..687.10.1 backports (1100-1104), and add those backports (1100-1196)
sourced from centos-stream-9 and upstream stable. Keep the AlmaLinux-ahead
smb cifs.spnego fix (retained as 1197). Bump to 5.14.0-687.10.1.
Refresh the dirtyfrag backport to upstream v5 and add the cifs.spnego
hardening patch.
1102-net-skbuff-propagate-shared-frag-marker.patch
Refreshed from upstream v3 to v5
(https://lore.kernel.org/all/ageeJfJHwgzmKXbh@v4bel/). The v5
series adds two skb_segment() hunks on top of v3: it folds
frag_skb-> flags into nskb on the per-iteration flag merge, and
fills the marker again when the inner switch rebinds frag_skb to
a list_skb on head_skb-frags exhaustion. The other v5 site
(tcp_clone_payload()) does not exist in 5.14 and is omitted.
skb_try_coalesce() hunk is retained as in v3/v4 because the
upstream commit that dropped it (f84eca581739) is only partially
backported in 5.14 -- its skb_split() half is present, but the
skb_try_coalesce() half is missing.
1105-smb-client-reject-userspace-cifs.spnego-descriptions.patch
Upstream commit 3da1fdf4efbc verbatim. Refuses userspace-created
cifs.spnego keys via request_key(2)/add_key(2); only kernel CIFS
using the private spnego_cred may create them. cifs.upcall
treats the key description as kernel-originating
pid/uid/creduid/upcall_target -- without this fence, userspace
can spoof those fields.
All four patches verified to apply with patch -p1 -F0 against the
5.14.0-687.5.1.el9_8 source tree (no fuzz, no rejects).
Bring back three local patches that were dropped from a9 after
upstream landed the related fixes. The xfrm-esp fix (CVE-2026-43284)
came in via the CKI Backport Bot at 5.14.0-611.55.1, but rxrpc,
net/skbuff and ptrace did not -- restore them here. Blobs are
imported verbatim from the latest a9 commits that carried them
(2530dd40b / d62b1833b / cbd86e459 / cc48c27cd):
1101-rxrpc-linearize-paged-frags.patch (CVE-2026-43500)
1102-net-skbuff-propagate-shared-frag-marker.patch
v3 frag-transfer helpers variant (CVE-2026-46300 "Fragnesia")
1103-ptrace-require-cap-on-mm-less-task.patch
CVE-2026-46333, kABI-safe replacement for upstream 31e62c2ebbfd
Release is not bumped; a second changelog entry is added under the
existing 5.14.0-611.55.1 version. All three verified to apply with
`patch -p1 -F0` against the 5.14.0-611.55.1.el9_7 source tree
(one minor offset, no fuzz, no rejects).
mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
qla4xxx: bring back deprecated PCI ids
lpfc: bring back deprecated PCI ids
be2iscsi: bring back deprecated PCI ids
kernel/rh_messages.h: enable all disabled pci devices by moving to unmaintained
Use AlmaLinux OS secure boot cert
Debrand for AlmaLinux OS
Add KVM support for ppc64le