LWN.net Logo

Fedora alert FEDORA-2007-277 (kernel)

From:  "Chuck Ebbert" <cebbert@redhat.com>
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora Core 5 Update: kernel-2.6.19-1.2288.2.1.fc5
Date:  Fri, 2 Mar 2007 11:58:32 -0500

--------------------------------------------------------------------- Fedora Update Notification FEDORA-2007-277 2007-03-02 --------------------------------------------------------------------- Product : Fedora Core 5 Name : kernel Version : 2.6.19 Release : 1.2288.2.1.fc5 Summary : The Linux kernel (the core of the Linux operating system) Description : The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc. --------------------------------------------------------------------- Update Information: Updated to kernel 2.6.19.5-rc1 plus additional fixes: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6... 2.6.19.5-rc1: 4 V4L fixes 3 usbaudio fixes 3 wireless driver fixes 2 IDE driver cable detection fixes NFS bugfix various other fixes CVE-2007-0772: Summary: The Linux kernel before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer. CVE-2006-5753: Summary: Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors. --------------------------------------------------------------------- * Thu Feb 22 2007 Chuck Ebbert <cebbert@redhat.com> - 2.6.19.4 (CVE-2007-0772) - 2.6.19.5-rc1 - bad_inode_ops patch (CVE-2006-5753) - disable MSI on forcedeth cards (FC6 bz #222556) - Intel HDA si3054 codec (FC6 bz #228879) - "no irq for vector" fix (FC6 bz #225399) - usbnet oops fix (FC6 bz #228231) - swiotlb synchronization fix - scsi cdrom ioctls were broken - NAPI netpoll fixes from FC6 2911 kernel * Sat Feb 10 2007 Chuck Ebbert <cebbert@redhat.com> - add missing "provides" for debug-devel packages - clean up some other "provides" things - add fixes for RHBZ#211672 (CIFS) and RHBZ#227802 (8139too) * Wed Feb 7 2007 Chuck Ebbert <cebbert@redhat.com> - add missing debug-devel and smp-debug-devel sections * Wed Feb 7 2007 Chuck Ebbert <cebbert@redhat.com> - fix up x86_64 Xen build * Tue Feb 6 2007 Chuck Ebbert <cebbert@redhat.com> - disable Tux - add another GFS2 update - add crypto key collision patch (CVE-2007-0006) * Mon Feb 5 2007 Dave Jones <davej@redhat.com> - Reenable Tux. * Mon Feb 5 2007 Chuck Ebbert <cebbert@redhat.com> - 2.6.19.3 - updated mirrors: refer to ftp2.kernel.org until kernel.org problems are fixed * Sun Feb 4 2007 Dave Jones <davej@redhat.com> - 2.6.19.3rc1 * Sat Feb 3 2007 Dave Jones <davej@redhat.com> - Disable kdump options in non-kdump kernels. * Thu Feb 1 2007 Chuck Ebbert <cebbert@redhat.com> - Added i586 optimized AES and Blowfish modules to the i686 config - Fixed .cvsignore * Wed Jan 31 2007 Markus Armbruster <armbru@redhat.com> - The previous cset folded the Xen paravirt framebuffer patch into linux-2.6-xen.patch, and commented out the obsoleted patch files. Remove them. * Wed Jan 31 2007 Chuck Ebbert <cebbert@redhat.com> - Update to 2.6.19.2 * Tue Jan 30 2007 Markus Armbruster <armbru@redhat.com> - Update Xen paravirt framebuffer patch to upstream xen-unstable changeset 13066, less changeset 12680, because that breaks with console=tty console=xvc. Also change default domU console back to /dev/xcv0. This changes the protocol to the one accepted upstream. - Add compatibility with guests running our initial protocol. - Update Xen console major/minor to lanana.org-assigned numbers. * Wed Dec 20 2006 Dave Jones <davej@redhat.com> - Update to 2.6.18.6 final (no changes since rc2) - Reenable squashfs (#220293) * Fri Dec 15 2006 Dave Jones <davej@redhat.com> - 2.6.18.6rc2 * Wed Dec 13 2006 Dave Jones <davej@redhat.com> - squashfs robustness fixes from Phillip Lougher. - lower max CPU count for x86-64 to 64 CPUs. * Thu Dec 7 2006 Juan Quintela <quintela@redhat.com> - update xen to 2.6.18.5. - Fix bug 211986 on xen eventchn (Glaubert). * Tue Dec 5 2006 Dave Jones <davej@redhat.com> - 2.6.18.5 - Disable auto-apic patch, it needs more thought. - Enable sonypi driver for 586 kernels. (#218434) * Tue Nov 21 2006 Juan Quintela <quintela@redhat.com> - Update xen to 2.6.18.3. * linux-2.6.18-xen changeset: 36186:053cdad40903 * xen-3.0.3-testing changeset: 11774:52ae8dd4bc75 * linux-2.6-xen-3.0.3 changeset: 22949:4281f5246814 * Mon Nov 20 2006 Dave Jones <davej@redhat.com> - 2.6.18.3 - Fix CIFS mount failure when domain not specified (#211753) - Avoid null pointer dereference in SATA Promise. (#199142) * Fri Nov 17 2006 Dave Jones <davej@redhat.com> - Fix up fallout from disabling utrace. * Fri Nov 17 2006 Juan Quintela <quintela@redhat.com> - merge xen missing bits from FC6 kernel. * Thu Nov 16 2006 Dave Jones <davej@redhat.com> - Fix up error handling in HFS. (MOKB-14-11-2006) * Thu Nov 16 2006 Juan Quintela <quintela@redhat.com> - Update xen HV to 3.0.3_0 (cset 11774). - Update xen kernel patch to 3.0.3_0: * linux-2.6.18-xen changeset: 36182:c6ef4b521aef * xen-3.0.3-testing changeset: 11774:52ae8dd4bc75 * linux-2.6-xen-3.0.3 changeset: 22949:4281f5246814 * Thu Nov 16 2006 Dave Jones <davej@redhat.com> - Fix squashfs corruption bug. (#211237) - Drop experimental utrace from FC5. * Fri Nov 10 2006 Juan Quintela <quintela@redhat.com> - disable XEN_FRAMEBUFFER & XEN_KEYBOARD. * Fri Nov 10 2006 Dave Jones <davej@redhat.com> - Xen grant table operations security fix. - Disable W1 (#195825) * Thu Nov 9 2006 Dave Jones <davej@redhat.com> - Change HZ to 1000 for increased accuracy. (Except in Xen, where it stays at 250 for now). - TTY locking fixes. - splice : Must fully check for FIFO - Fix potential NULL dereference in sys_move_pages - ISO9660 __find_get_block_slow() denial of service CVE-2006-5757 - Fix up oops in cramfs when encountering corrupt images. - E1000 suspend/resume fixes. - Set CIFS preferred IO size. (#214607) * Mon Nov 6 2006 Roland McGrath <roland@redhat.com> - New utrace patch: fix locking snafu crash on second engine attach. * Sun Nov 5 2006 Dave Jones <davej@redhat.com> - Suspend/Resume fixes for forcedeth. (#187653) * Sat Nov 4 2006 Dave Jones <davej@redhat.com> - 2.6.18.2 * Thu Nov 2 2006 Dave Jones <davej@redhat.com> - Nuke broken lazy execshield xen patch. - Use heuristics to determine whether to enable lapic on i386. * Wed Nov 1 2006 Dave Jones <davej@redhat.com> - 2.6.18.2-rc1 * Tue Oct 31 2006 Dave Jones <davej@redhat.com> - Fix UFS mounts on x86-64 (#209921) - Fix problem where USB storage isn't seen on reboot. (#212191) * Sun Oct 29 2006 Dave Jones <davej@redhat.com> - More ext3 robustness fixes. - Include more verbose BUG() data - x86_64: Fix up C3 timer latency. * Sat Oct 21 2006 Dave Jones <davej@redhat.com> - Reenable NCPFS (#211325, #203663) - Netpoll fixes. (#199295) * Fri Oct 20 2006 Dave Jones <davej@redhat.com> - Fix autofs creating bad dentries in NFS mount. (#211206, #211207) - Fix softlockup with ips driver. (#196437) - Further exec-shield improvements. - Fix lockup with sky2 driver. (#202203) * Thu Oct 19 2006 Dave Jones <davej@redhat.com> - Export copy_4K_page for ppc64 (#211410) - Attempt to fix CIFS bug (#211070) * Wed Oct 18 2006 Dave Jones <davej@redhat.com> - Fix up aic7xxx SBLKCTL register handling (#211251) - Disable SECMARK by default. (#211115) - Disable some extra debugging stuff that crept in. - Remove broken VIA quirk that prevented booting on some EPIAs (#211298) * Tue Oct 17 2006 Dave Jones <davej@redhat.com> - Silence noisy boot-time messages. (#180606) - Workaround gcc bug with weak symbols (#191458) - Don't let speedstep-smi register on mobile Pentium4 (#204477) * Sat Oct 14 2006 Dave Jones <davej@redhat.com> - Fix jbd crash with 1KB block size filesystems. * Sat Oct 14 2006 Dave Jones <davej@redhat.com> [2.6.18-1.2200.fc5] - 2.6.18.1 * Tue Oct 10 2006 Dave Jones <davej@redhat.com> - DWARF2 unwinder fixes. - Various lockdep fixes. - Sync various other patches from the FC6 kernel. * Sun Oct 1 2006 Dave Jones <davej@redhat.com> - Drop the STICKY tag from acpi-cpufreq, it breaks suspend/resume. * Fri Sep 29 2006 Dave Jones <davej@redhat.com> - Execshield improvements. (Bart Oldeman) - Disable PM_DEBUG * Thu Sep 28 2006 Roland McGrath <roland@redhat.com> - utrace typo fix for x86-64 watchpoints (#207467) * Thu Sep 28 2006 Dave Jones <davej@redhat.com> - Fix ISAPNP messages on ppc32. (#207641) * Thu Sep 28 2006 Dave Jones <davej@redhat.com> - Another day, another round of lockdep fixes. - Align kernel data segment to page boundary. (#206863) * Thu Sep 28 2006 Steven Whitehouse <swhiteho@redhat.com> - New GFS2 patch * Thu Sep 28 2006 Dave Jones <davej@redhat.com> - Fix "kernel BUG at fs/buffer.c:2789!" bug * Wed Sep 27 2006 Dave Jones <davej@redhat.com> - yet more lockdep fixes. - Fix a problem with XFS & the inode diet patches. - Fix rpc_pipefs umount oops - Enable alternative TCP congestion algorithms. * Tue Sep 26 2006 Dave Jones <davej@redhat.com> - Enable serverworks IDE driver for x86-64. - More lockdep fixes. * Mon Sep 25 2006 Jarod Wilson <jwilson@redhat.com> - Make kernel packages own initrd files * Mon Sep 25 2006 John W. Linville <linville@redhat.com> - Add periodic work fix for bcm43xx driver * Sat Sep 23 2006 Dave Jones <davej@redhat.com> - Disable dgrs driver. * Thu Sep 21 2006 Dave Jones <davej@redhat.com> - reiserfs: make sure all dentry refs are released before calling kill_block_super - Fix up some compile warnings * Thu Sep 21 2006 Juan Quintela <quintela@redhat.com> - re-enable xen. - update xen: * linux-2.6 changeset: 34294:dc1d277d06e0 * linux-2.6-xen-fedora changeset: 36184:47c098fdce14 * xen-unstable changeset: 11540:9837ff37e354 - update xen HV to changeset: 11540:9837ff37e354 - xen HV printf rate limit (rostedt). * Wed Sep 20 2006 Dave Jones <davej@redhat.com> - 2.6.18 - i965 AGP suspend support. - AGP x8 fixes. * Tue Sep 19 2006 Juan Quintela <quintela@redhat.com> - updated xen configs to sync with rawhide ones (don't be afraid, xen0/xenU still around). - xen update. * linux-2.6 changeset: 34228:ea3369ba1e2c * linux-2.6-xen-fedora changeset: 36109:eefcfd07d102 * linux-2.6-xen changeset: 22905:d8ae02f7df05 * xen-unstable changeset: 11460:1ece34466781ec55f41fd29d53f6dafd208ba2fa * Mon Sep 18 2006 Dave Jones <davej@redhat.com> - Bring back 586smp - Fix RTC lockdep bug. (Peter Zijlstra) * Mon Sep 18 2006 Juan Quintela <quintela@redhat.com> - xen HV update (cset 11470:2b8dc69744e3). * Sun Sep 17 2006 Juan Quintela <quintela@redhat.com> - xen update: * linux-2.6 changeset: 34228:ea3369ba1e2c * linux-2.6-xen-fedora changeset: 36107:47256dbb1583 * linux-2.6-xen changeset: 22905:d8ae02f7df05 * xen-unstable changeset: 11460:1ece34466781ec55f41fd29d53f6dafd208ba2fa * Sun Sep 17 2006 Dave Jones <davej@redhat.com> - Rebase to 2.6.18rc7-git2 * Mon Sep 11 2006 Dave Jones <davej@redhat.com> [2.6.17-1.2187_FC5] - Add quirk for Samsung mp3 player. (#198128) * Sun Sep 10 2006 Dave Jones <davej@redhat.com> - Fix up mismerge in USB storage driver. * Sat Sep 9 2006 Dave Jones <davej@redhat.com> - 2.6.17.13 * Fri Sep 8 2006 Dave Jones <davej@redhat.com> - 2.6.17.12 * Thu Aug 24 2006 Jarod Wilson <jwilson@redhat.com> - update to 2.6.17.11 * Tue Aug 22 2006 Bill Nottingham <notting@redhat.com> - update to 2.6.17.10« * Tue Aug 15 2006 Juan Quintela <quintela@redhat.com> - linux-2.6-xen update * linux-2.6.17-xen cset changeset: 29033:e6adb54afb96 * linux-2.6-xen cset 22813:80c2ccf5c330 - s/xen_version/xen_hv_cset/ as Fedora. - update xen hv to cset 11061. * Mon Aug 7 2006 Mike Christie <mchristi@redhat.com> - Drop iscsi update patch. * Mon Aug 7 2006 Dave Jones <davej@redhat.com> - 2.6.17.8 * Fri Aug 4 2006 Dave Jones <davej@redhat.com> - Fix split lock patch for 64bit. * Fri Aug 4 2006 Dave Jones <davej@redhat.com> [2.6.17-1.2171_FC5] - 2.6.17.8rc1 * Wed Aug 2 2006 Dave Jones <davej@redhat.com> - Readd patch to allow 460800 baud on 16C950 UARTs * Sat Jul 29 2006 Dave Jones <davej@redhat.com> - Silence noisy SCSI ioctl. (#200638) * Fri Jul 28 2006 Dave Jones <davej@redhat.com> - 2.6.17.7 * Thu Jul 27 2006 Rik van Riel <riel@redhat.com> - reduce hypervisor stack use with -O2, this really fixes bug (#198932) * Tue Jul 25 2006 Rik van Riel <riel@redhat.com> - disable debug=y hypervisor build option because of stack overflow (#198932) * Tue Jul 25 2006 Dave Jones <davej@redhat.com> - Enable serio_raw (#199387) * Sun Jul 16 2006 Dave Jones <davej@redhat.com> - Support up to 4GB in the 586 kernel again. * Sun Jul 16 2006 Dave Jones <davej@redhat.com> - 2.6.17.6 * Fri Jul 14 2006 Dave Jones <davej@redhat.com> - Reenable SMC NIC driver. * Tue Jul 11 2006 Dave Jones <davej@redhat.com> - 2.6.17.4 - Disable split pagetable lock * Sat Jul 8 2006 Juan Quintela <quintela@redhat.com> - enable CONFIG_CRASH on xen kernels. - enable CONFIG_PCIDEV_BACKEND on xen kernels. - make BLKDEV_FRONTEND a module on xen kernels. - rebase with linux-2.6-xen-fedora 28918. - Update to xen-unstable HV cset 10508. - xen: credit scheduler is the default now. * Wed Jul 5 2006 Dave Jones <davej@redhat.com> - Get rid of stack backtrace on panic, which in most cases actually caused a loss of info instead of a gain. * Tue Jul 4 2006 Juan Quintela <quintela@redhat.com> - new merge with xen upstream. - xen kernel don't require xen userland. - new xen kernel (same as rawhide one) with PAE support. - removed xen0-PAE & xenU-PAE (see xen kernel). * Fri Jun 30 2006 Dave Jones <davej@redhat.com> - 2.6.17.3 - 2.6.17.2 - Fix the ALSA list_add bug. * Mon Jun 26 2006 Dave Jones <davej@redhat.com> - Enable fake PCI hotplug driver. (#190437) - Enable gameport/joystick on i586 builds. (#196581) * Sat Jun 24 2006 Dave Jones <davej@redhat.com> - Enable profiling for 586 kernels. * Fri Jun 23 2006 Dave Jones <davej@redhat.com> - Make 'quiet' work again. * Tue Jun 20 2006 Dave Jones <davej@redhat.com> [2.6.17-1.2139_FC5] - Rebuild with slab debug off. * Tue Jun 20 2006 Dave Jones <davej@redhat.com> [2.6.17-1.2138_FC5] - 2.6.17.1 * Sun Jun 18 2006 Dave Jones <davej@redhat.com> - 2.6.17 - Only print info about SMP alternatives on SMP kernels. * Tue Jun 6 2006 Dave Jones <davej@redhat.com> [2.6.16-1.2133_FC5] - Add a PPC64 kdump kernel. * Mon Jun 5 2006 Dave Jones <davej@redhat.com> [2.6.16-1.2132_FC5] - 2.6.16.20 * Thu Jun 1 2006 Dave Jones <davej@redhat.com> - Reenable Xen builds. * Tue May 30 2006 Dave Jones <davej@redhat.com> - 2.6.16.19 * Sun May 28 2006 Dave Jones <davej@redhat.com> - Fix unresolved symbol. (#193333) * Sat May 27 2006 Dave Jones <davej@redhat.com> - Improve list corruption debugging patch. * Fri May 26 2006 Dave Jones <davej@redhat.com> - Remove xenU initrd's when kernel is removed. * Fri May 26 2006 Juan Quintela <quintela@redhat.com> - Remove ARCH=xen reminiscences on spec file --------------------------------------------------------------------- This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/u... 82623291d8b24f73db7c1e74c8199cbcb45267c7 SRPMS/kernel-2.6.19-1.2288.2.1.fc5.src.rpm 82623291d8b24f73db7c1e74c8199cbcb45267c7 noarch/kernel-2.6.19-1.2288.2.1.fc5.src.rpm bdc515a55fc99a40b3770535f76a90be89fb5692 ppc/kernel-2.6.19-1.2288.2.1.fc5.ppc.rpm a7932bd6a0346b28b9c723c5eb46b60a48f1cdf9 ppc/debug/kernel-debuginfo-2.6.19-1.2288.2.1.fc5.ppc.rpm a82e1ad7bdff7199624da1d414d4cce8d2762a7f ppc/kernel-smp-devel-2.6.19-1.2288.2.1.fc5.ppc.rpm ef08c9019190ced47523abdc9b453a4173189379 ppc/kernel-smp-2.6.19-1.2288.2.1.fc5.ppc.rpm d39072fe42024465182826e366499ff095577a46 ppc/kernel-devel-2.6.19-1.2288.2.1.fc5.ppc.rpm 13288f3db86f210017415d5b90e72f7649db53bd ppc/kernel-doc-2.6.19-1.2288.2.1.fc5.noarch.rpm 374d4826a762a8cf808d7513a5b667a72fab8598 x86_64/kernel-devel-2.6.19-1.2288.2.1.fc5.x86_64.rpm f6cb1e9dbb708e3561b3f8e0583f5ec816356665 x86_64/kernel-2.6.19-1.2288.2.1.fc5.x86_64.rpm 1aab8ee0a54899e5f240d1fd6e226cbc3a0060d6 x86_64/kernel-kdump-devel-2.6.19-1.2288.2.1.fc5.x86_64.rpm 27607f435d59babc4caf6dbef081119c99f5b8b8 x86_64/kernel-debug-devel-2.6.19-1.2288.2.1.fc5.x86_64.rpm 833ea971cbcc4df3c44a9cc45b19f6e40da40272 x86_64/kernel-kdump-2.6.19-1.2288.2.1.fc5.x86_64.rpm 04ae05187f352dc2107287a621256f6e68bb2256 x86_64/debug/kernel-debuginfo-2.6.19-1.2288.2.1.fc5.x86_64.rpm 14a432b179b3c46aa2976513297be23004befe8e x86_64/kernel-debug-2.6.19-1.2288.2.1.fc5.x86_64.rpm 13288f3db86f210017415d5b90e72f7649db53bd x86_64/kernel-doc-2.6.19-1.2288.2.1.fc5.noarch.rpm e969b055be17653023522006701995e6d6737be3 i386/debug/kernel-debuginfo-2.6.19-1.2288.2.1.fc5.i386.rpm a33501849bba5269f15be82d261c429a01d24b1c i386/kernel-smp-2.6.19-1.2288.2.1.fc5.i586.rpm 1c045a9a21c2bcccf43576f9487a651880359717 i386/debug/kernel-debuginfo-2.6.19-1.2288.2.1.fc5.i586.rpm f29e07edebe59ad2e17b158a5b397c9e9bd4bd28 i386/kernel-devel-2.6.19-1.2288.2.1.fc5.i586.rpm 713a48ad101f28508fc57a8f19d667a0f74acbd0 i386/kernel-2.6.19-1.2288.2.1.fc5.i586.rpm 8d49860b7338b0061f2c6286d66078f1c982b7e3 i386/kernel-smp-devel-2.6.19-1.2288.2.1.fc5.i586.rpm 39598844dc8ec41ca2024b4c2834413e774db718 i386/kernel-smp-debug-devel-2.6.19-1.2288.2.1.fc5.i686.rpm 096a8c967a10f8c0da2484a1a13e6e0ebaf5dbf0 i386/kernel-smp-2.6.19-1.2288.2.1.fc5.i686.rpm 39dacd647234179631a381c62050c8da1fd3048a i386/kernel-smp-debug-2.6.19-1.2288.2.1.fc5.i686.rpm 95c559d9be94102ef5fe626cac745ac2822ace2f i386/kernel-2.6.19-1.2288.2.1.fc5.i686.rpm cfc79fdbb56179ca9adb276cfb77fbcb8e6d72be i386/kernel-devel-2.6.19-1.2288.2.1.fc5.i686.rpm 8ec8d6309d60d124931274dcf1210ffaa065b08c i386/kernel-smp-devel-2.6.19-1.2288.2.1.fc5.i686.rpm b647349b8e582d4d3098f34bf0967af382808f56 i386/kernel-kdump-devel-2.6.19-1.2288.2.1.fc5.i686.rpm 499a6b1cc16f092ba140f34354b683e1ee832b6f i386/kernel-debug-2.6.19-1.2288.2.1.fc5.i686.rpm a4a094bc5a42507e01e5b0ab3d4e2dd2ceec46f7 i386/kernel-debug-devel-2.6.19-1.2288.2.1.fc5.i686.rpm 0a44dc2d7b90ca66a4f2ad77b212e1d86288d795 i386/debug/kernel-debuginfo-2.6.19-1.2288.2.1.fc5.i686.rpm e3442de6f6ee41b00ee2105608e7ea80a85ab0f9 i386/kernel-kdump-2.6.19-1.2288.2.1.fc5.i686.rpm 13288f3db86f210017415d5b90e72f7649db53bd i386/kernel-doc-2.6.19-1.2288.2.1.fc5.noarch.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://fedora.redhat.com/docs/yum/. --------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds