Container summary for


SUSE-IU-2024:1472-1

Container Advisory IDSUSE-IU-2024:1472-1
Container Tags
Container Release
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3166-1
ReleasedMon Sep 9 12:25:30 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1228042
Description:

This update for glibc fixes the following issue:


Advisory IDSUSE-RU-2024:3178-1
ReleasedMon Sep 9 14:39:12 2024
SummaryRecommended update for libzypp, zypper, libsolv, zypp-plugin, PackageKit-branding-SLE, PackageKit, libyui, yast2-pkg-bindings
Typerecommended
Severityimportant
References1081596,1223094,1224771,1225267,1226014,1226030,1226493,1227205,1227625,1227793,1228138,1228206,1228208,1228420,1228787,222971
Description:

This update for libzypp, zypper, libsolv, zypp-plugin, PackageKit-branding-SLE, PackageKit, libyui, yast2-pkg-bindings fixes the following issues:


Advisory IDSUSE-SU-2024:3204-1
ReleasedWed Sep 11 10:55:22 2024
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1230093,CVE-2024-8096
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-SU-2024:3216-1
ReleasedThu Sep 12 13:05:20 2024
SummarySecurity update for expat
Typesecurity
Severitymoderate
References1229930,1229931,1229932,CVE-2024-45490,CVE-2024-45491,CVE-2024-45492
Description:

This update for expat fixes the following issues:


Advisory IDSUSE-SU-2024:3217-1
ReleasedThu Sep 12 13:06:07 2024
SummarySecurity update for libpcap
Typesecurity
Severitymoderate
References1230020,1230034,CVE-2023-7256,CVE-2024-8006
Description:

This update for libpcap fixes the following issues:


Advisory IDSUSE-SU-2024:3221-1
ReleasedThu Sep 12 13:18:18 2024
SummarySecurity update for containerd
Typesecurity
Severityimportant
References1200528,1217070,1228553,CVE-2022-1996,CVE-2023-45142,CVE-2023-47108
Description:

This update for containerd fixes the following issues:


Advisory IDSUSE-SU-2024:3222-1
ReleasedThu Sep 12 13:20:47 2024
SummarySecurity update for runc
Typesecurity
Severitylow
References1230092,CVE-2024-45310
Description:

This update for runc fixes the following issues:


Advisory IDSUSE-RU-2024:3235-1
ReleasedFri Sep 13 08:50:24 2024
SummaryRecommended update for grub2
Typerecommended
Severitymoderate
References1226497
Description:

This update for grub2 fixes the following issues:


Advisory IDSUSE-RU-2024:3239-1
ReleasedFri Sep 13 12:00:58 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1229476
Description:

This update for util-linux fixes the following issue:


Advisory IDSUSE-RU-2024:3300-1
ReleasedWed Sep 18 14:27:53 2024
SummaryRecommended update for ncurses
Typerecommended
Severitymoderate
References1229028
Description:

This update for ncurses fixes the following issues:


Advisory IDSUSE-RU-2024:3317-1
ReleasedWed Sep 18 16:38:50 2024
SummaryRecommended update for fipscheck
Typerecommended
Severitymoderate
References1221714
Description:

This update for fipscheck fixes the following issue:


Advisory IDSUSE-RU-2024:3326-1
ReleasedThu Sep 19 09:36:47 2024
SummaryRecommended update for suseconnect-ng
Typerecommended
Severityimportant
References1229014,1230229
Description:

This update for suseconnect-ng fixes the following issue:


Advisory IDSUSE-RU-2024:3346-1
ReleasedThu Sep 19 17:20:06 2024
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitymoderate
References1228647,1230267
Description:

This update for libzypp, zypper fixes the following issues:


Advisory IDSUSE-SU-2024:3383-1
ReleasedMon Sep 23 10:29:54 2024
SummarySecurity update for the Linux Kernel
Typesecurity
Severityimportant
References1012628,1193454,1194869,1205462,1208783,1213123,1214285,1215199,1220066,1220252,1220877,1221326,1221630,1221645,1221652,1221857,1222254,1222335,1222350,1222364,1222372,1222387,1222433,1222434,1222463,1222625,1222633,1222634,1222808,1222967,1222973,1223053,1223074,1223191,1223395,1223635,1223720,1223731,1223742,1223763,1223767,1223777,1223803,1224105,1224415,1224485,1224496,1224510,1224535,1224631,1224636,1224690,1224694,1224700,1224711,1225475,1225582,1225607,1225717,1225718,1225744,1225745,1225751,1225814,1225832,1225838,1225903,1226031,1226127,1226502,1226530,1226588,1226604,1226743,1226751,1226765,1226798,1226801,1226834,1226874,1226885,1226920,1227149,1227182,1227383,1227437,1227492,1227493,1227494,1227618,1227620,1227623,1227627,1227634,1227706,1227722,1227724,1227725,1227728,1227729,1227732,1227733,1227734,1227747,1227750,1227754,1227758,1227760,1227761,1227764,1227766,1227770,1227771,1227772,1227774,1227781,1227784,1227785,1227787,1227790,1227791,1227792,1227796,1227798,1227799,1227802,1227808,1227810,1227811,1227812,1227815,1227816,1227818,1227820,1227823,1227824,1227826,1227828,1227829,1227830,1227832,1227833,1227834,1227839,1227840,1227846,1227849,1227851,1227853,1227863,1227864,1227865,1227867,1227869,1227870,1227883,1227884,1227891,1227893,1227929,1227950,1227957,1227981,1228020,1228021,1228114,1228192,1228195,1228202,1228235,1228236,1228237,1228247,1228321,1228409,1228410,1228426,1228427,1228429,1228446,1228447,1228449,1228450,1228452,1228456,1228457,1228458,1228459,1228460,1228462,1228463,1228466,1228467,1228468,1228469,1228470,1228472,1228479,1228480,1228481,1228482,1228483,1228484,1228485,1228486,1228487,1228489,1228491,1228492,1228493,1228494,1228495,1228496,1228499,1228500,1228501,1228502,1228503,1228505,1228508,1228509,1228510,1228511,1228513,1228515,1228516,1228518,1228520,1228525,1228527,1228530,1228531,1228539,1228561,1228563,1228564,1228565,1228567,1228568,1228572,1228576,1228579,1228580,1228581,1228582,1228584,1228586,1228588,1228590,1228591,1228599,1228615,1228616,1228617,1228625,1228626,1228633,1228635,1228636,1228640,1228643,1228644,1228646,1228649,1228650,1228654,1228655,1228656,1228658,1228660,1228662,1228665,1228666,1228667,1228672,1228673,1228674,1228677,1228680,1228687,1228705,1228706,1228707,1228708,1228709,1228710,1228718,1228720,1228721,1228722,1228723,1228724,1228726,1228727,1228733,1228737,1228743,1228748,1228754,1228756,1228757,1228758,1228764,1228766,1228779,1228801,1228849,1228850,1228857,1228959,1228964,1228966,1228967,1228973,1228977,1228978,1228979,1228986,1228988,1228989,1228991,1228992,1229005,1229024,1229042,1229045,1229046,1229054,1229056,1229086,1229134,1229136,1229154,1229156,1229160,1229167,1229168,1229169,1229170,1229171,1229172,1229173,1229174,1229239,1229240,1229241,1229243,1229244,1229245,1229246,1229247,1229248,1229249,1229250,1229251,1229252,1229253,1229254,1229255,1229256,1229287,1229290,1229291,1229292,1229294,1229296,1229297,1229298,1229299,1229301,1229303,1229304,1229305,1229307,1229309,1229312,1229313,1229314,1229315,1229316,1229317,1229318,1229319,1229320,1229327,1229341,1229342,1229344,1229345,1229346,1229347,1229349,1229350,1229351,1229353,1229354,1229355,1229356,1229357,1229358,1229359,1229360,1229365,1229366,1229369,1229370,1229373,1229374,1229379,1229381,1229382,1229383,1229386,1229388,1229390,1229391,1229392,1229395,1229398,1229399,1229400,1229402,1229403,1229404,1229407,1229409,1229410,1229411,1229413,1229414,1229417,1229444,1229451,1229452,1229455,1229456,1229480,1229481,1229482,1229484,1229485,1229486,1229487,1229488,1229489,1229490,1229493,1229495,1229496,1229497,1229500,1229503,1229707,1229739,1229743,1229746,1229747,1229752,1229754,1229755,1229756,1229759,1229761,1229767,1229781,1229784,1229785,1229787,1229788,1229789,1229792,1229820,1229827,1229830,1229837,1229940,1230056,1230350,1230413,CVE-2023-52489,CVE-2023-52581,CVE-2023-52668,CVE-2023-52688,CVE-2023-52735,CVE-2023-52859,CVE-2023-52885,CVE-2023-52886,CVE-2023-52887,CVE-2023-52889,CVE-2024-26590,CVE-2024-26631,CVE-2024-26637,CVE-2024-26668,CVE-2024-26669,CVE-2024-26677,CVE-2024-26682,CVE-2024-26683,CVE-2024-26691,CVE-2024-26735,CVE-2024-26808,CVE-2024-26809,CVE-2024-26812,CVE-2024-26835,CVE-2024-26837,CVE-2024-26849,CVE-2024-26851,CVE-2024-26889,CVE-2024-26920,CVE-2024-26944,CVE-2024-26976,CVE-2024-27010,CVE-2024-27011,CVE-2024-27024,CVE-2024-27049,CVE-2024-27050,CVE-2024-27079,CVE-2024-27403,CVE-2024-27433,CVE-2024-27437,CVE-2024-31076,CVE-2024-35854,CVE-2024-35855,CVE-2024-35897,CVE-2024-35902,CVE-2024-35913,CVE-2024-35939,CVE-2024-35949,CVE-2024-36270,CVE-2024-36286,CVE-2024-36288,CVE-2024-36489,CVE-2024-36881,CVE-2024-36907,CVE-2024-36909,CVE-2024-36910,CVE-2024-36911,CVE-2024-36929,CVE-2024-36933,CVE-2024-36939,CVE-2024-36970,CVE-2024-36979,CVE-2024-38548,CVE-2024-38563,CVE-2024-38609,CVE-2024-38662,CVE-2024-39476,CVE-2024-39483,CVE-2024-39484,CVE-2024-39486,CVE-2024-39488,CVE-2024-39489,CVE-2024-39491,CVE-2024-39493,CVE-2024-39497,CVE-2024-39499,CVE-2024-39500,CVE-2024-39501,CVE-2024-39505,CVE-2024-39506,CVE-2024-39508,CVE-2024-39509,CVE-2024-39510,CVE-2024-40899,CVE-2024-40900,CVE-2024-40902,CVE-2024-40903,CVE-2024-40904,CVE-2024-40905,CVE-2024-40909,CVE-2024-40910,CVE-2024-40911,CVE-2024-40912,CVE-2024-40913,CVE-2024-40916,CVE-2024-40920,CVE-2024-40921,CVE-2024-40922,CVE-2024-40924,CVE-2024-40926,CVE-2024-40927,CVE-2024-40929,CVE-2024-40930,CVE-2024-40932,CVE-2024-40934,CVE-2024-40936,CVE-2024-40938,CVE-2024-40939,CVE-2024-40941,CVE-2024-40942,CVE-2024-40943,CVE-2024-40944,CVE-2024-40945,CVE-2024-40954,CVE-2024-40956,CVE-2024-40957,CVE-2024-40958,CVE-2024-40959,CVE-2024-40962,CVE-2024-40964,CVE-2024-40967,CVE-2024-40976,CVE-2024-40977,CVE-2024-40978,CVE-2024-40981,CVE-2024-40982,CVE-2024-40984,CVE-2024-40987,CVE-2024-40988,CVE-2024-40989,CVE-2024-40990,CVE-2024-40992,CVE-2024-40994,CVE-2024-40995,CVE-2024-40997,CVE-2024-41000,CVE-2024-41001,CVE-2024-41002,CVE-2024-41004,CVE-2024-41007,CVE-2024-41009,CVE-2024-41010,CVE-2024-41011,CVE-2024-41012,CVE-2024-41015,CVE-2024-41016,CVE-2024-41020,CVE-2024-41022,CVE-2024-41024,CVE-2024-41025,CVE-2024-41028,CVE-2024-41032,CVE-2024-41035,CVE-2024-41036,CVE-2024-41037,CVE-2024-41038,CVE-2024-41039,CVE-2024-41040,CVE-2024-41041,CVE-2024-41044,CVE-2024-41045,CVE-2024-41048,CVE-2024-41049,CVE-2024-41050,CVE-2024-41051,CVE-2024-41056,CVE-2024-41057,CVE-2024-41058,CVE-2024-41059,CVE-2024-41060,CVE-2024-41061,CVE-2024-41062,CVE-2024-41063,CVE-2024-41064,CVE-2024-41065,CVE-2024-41066,CVE-2024-41068,CVE-2024-41069,CVE-2024-41070,CVE-2024-41071,CVE-2024-41072,CVE-2024-41073,CVE-2024-41074,CVE-2024-41075,CVE-2024-41076,CVE-2024-41078,CVE-2024-41079,CVE-2024-41080,CVE-2024-41081,CVE-2024-41084,CVE-2024-41087,CVE-2024-41088,CVE-2024-41089,CVE-2024-41092,CVE-2024-41093,CVE-2024-41094,CVE-2024-41095,CVE-2024-41096,CVE-2024-41097,CVE-2024-41098,CVE-2024-42064,CVE-2024-42069,CVE-2024-42070,CVE-2024-42073,CVE-2024-42074,CVE-2024-42076,CVE-2024-42077,CVE-2024-42079,CVE-2024-42080,CVE-2024-42082,CVE-2024-42085,CVE-2024-42086,CVE-2024-42087,CVE-2024-42089,CVE-2024-42090,CVE-2024-42092,CVE-2024-42093,CVE-2024-42095,CVE-2024-42096,CVE-2024-42097,CVE-2024-42098,CVE-2024-42101,CVE-2024-42104,CVE-2024-42105,CVE-2024-42106,CVE-2024-42107,CVE-2024-42109,CVE-2024-42110,CVE-2024-42113,CVE-2024-42114,CVE-2024-42115,CVE-2024-42117,CVE-2024-42119,CVE-2024-42120,CVE-2024-42121,CVE-2024-42122,CVE-2024-42124,CVE-2024-42125,CVE-2024-42126,CVE-2024-42127,CVE-2024-42130,CVE-2024-42131,CVE-2024-42132,CVE-2024-42133,CVE-2024-42136,CVE-2024-42137,CVE-2024-42138,CVE-2024-42139,CVE-2024-42141,CVE-2024-42142,CVE-2024-42143,CVE-2024-42144,CVE-2024-42145,CVE-2024-42147,CVE-2024-42148,CVE-2024-42152,CVE-2024-42153,CVE-2024-42155,CVE-2024-42156,CVE-2024-42157,CVE-2024-42158,CVE-2024-42159,CVE-2024-42161,CVE-2024-42162,CVE-2024-42223,CVE-2024-42224,CVE-2024-42225,CVE-2024-42226,CVE-2024-42227,CVE-2024-42228,CVE-2024-42229,CVE-2024-42230,CVE-2024-42232,CVE-2024-42236,CVE-2024-42237,CVE-2024-42238,CVE-2024-42239,CVE-2024-42240,CVE-2024-42241,CVE-2024-42244,CVE-2024-42245,CVE-2024-42246,CVE-2024-42247,CVE-2024-42250,CVE-2024-42253,CVE-2024-42259,CVE-2024-42268,CVE-2024-42269,CVE-2024-42270,CVE-2024-42271,CVE-2024-42274,CVE-2024-42276,CVE-2024-42277,CVE-2024-42278,CVE-2024-42279,CVE-2024-42280,CVE-2024-42281,CVE-2024-42283,CVE-2024-42284,CVE-2024-42285,CVE-2024-42286,CVE-2024-42287,CVE-2024-42288,CVE-2024-42289,CVE-2024-42290,CVE-2024-42291,CVE-2024-42292,CVE-2024-42295,CVE-2024-42298,CVE-2024-42301,CVE-2024-42302,CVE-2024-42303,CVE-2024-42308,CVE-2024-42309,CVE-2024-42310,CVE-2024-42311,CVE-2024-42312,CVE-2024-42313,CVE-2024-42314,CVE-2024-42315,CVE-2024-42316,CVE-2024-42318,CVE-2024-42319,CVE-2024-42320,CVE-2024-42322,CVE-2024-43816,CVE-2024-43817,CVE-2024-43818,CVE-2024-43819,CVE-2024-43821,CVE-2024-43823,CVE-2024-43824,CVE-2024-43825,CVE-2024-43826,CVE-2024-43829,CVE-2024-43830,CVE-2024-43831,CVE-2024-43833,CVE-2024-43834,CVE-2024-43837,CVE-2024-43839,CVE-2024-43840,CVE-2024-43841,CVE-2024-43842,CVE-2024-43846,CVE-2024-43847,CVE-2024-43849,CVE-2024-43850,CVE-2024-43851,CVE-2024-43853,CVE-2024-43854,CVE-2024-43855,CVE-2024-43856,CVE-2024-43858,CVE-2024-43860,CVE-2024-43861,CVE-2024-43863,CVE-2024-43864,CVE-2024-43866,CVE-2024-43867,CVE-2024-43871,CVE-2024-43872,CVE-2024-43873,CVE-2024-43874,CVE-2024-43875,CVE-2024-43876,CVE-2024-43877,CVE-2024-43879,CVE-2024-43880,CVE-2024-43881,CVE-2024-43882,CVE-2024-43883,CVE-2024-43884,CVE-2024-43885,CVE-2024-43889,CVE-2024-43892,CVE-2024-43893,CVE-2024-43894,CVE-2024-43895,CVE-2024-43897,CVE-2024-43899,CVE-2024-43900,CVE-2024-43902,CVE-2024-43903,CVE-2024-43905,CVE-2024-43906,CVE-2024-43907,CVE-2024-43908,CVE-2024-43909,CVE-2024-43911,CVE-2024-43912,CVE-2024-44931,CVE-2024-44938,CVE-2024-44939
Description:


The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:



The following non-security bugs were fixed:


Advisory IDSUSE-RU-2024:3402-1
ReleasedMon Sep 23 15:37:36 2024
SummaryRecommended update for makedumpfile
Typerecommended
Severitymoderate
References1226183
Description:

This update for makedumpfile fixes the following issue:


Advisory IDSUSE-SU-2024:3424-1
ReleasedTue Sep 24 17:25:50 2024
SummarySecurity update for xen
Typesecurity
Severitymoderate
References1230366,CVE-2024-45817
Description:

This update for xen fixes the following issues:


Advisory IDSUSE-RU-2024:3450-1
ReleasedThu Sep 26 09:09:16 2024
SummaryRecommended update for pam-config
Typerecommended
Severitymoderate
References1227216
Description:

This update for pam-config fixes the following issues:


Advisory IDSUSE-RU-2024:3466-1
ReleasedFri Sep 27 08:18:07 2024
SummaryRecommended update for perl-Bootloader
Typerecommended
Severitymoderate
References1230070
Description:

This update for perl-Bootloader fixes the following issues:


Advisory IDSUSE-SU-2024:3470-1
ReleasedFri Sep 27 14:34:46 2024
SummarySecurity update for python3
Typesecurity
Severityimportant
References1227233,1227378,1227999,1228780,1229596,1230227,CVE-2024-5642,CVE-2024-6232,CVE-2024-6923,CVE-2024-7592
Description:

This update for python3 fixes the following issues:


Bug fixes:


Advisory IDSUSE-RU-2024:3476-1
ReleasedFri Sep 27 15:16:38 2024
SummaryRecommended update for curl
Typerecommended
Severitymoderate
References1230516
Description:

This update for curl fixes the following issue:


Advisory IDSUSE-RU-2024:3487-1
ReleasedFri Sep 27 19:56:02 2024
SummaryRecommended update for logrotate
Typerecommended
Severitymoderate
References
Description:

This update for logrotate fixes the following issues:


Advisory IDSUSE-RU-2024:3496-1
ReleasedMon Sep 30 09:19:26 2024
SummaryRecommended update for rsyslog
Typerecommended
Severitymoderate
References1230984
Description:

This update for rsyslog fixes the following issue:


Advisory IDSUSE-SU-2024:3501-1
ReleasedTue Oct 1 16:03:34 2024
SummarySecurity update for openssl-3
Typesecurity
Severityimportant
References1230698,CVE-2024-41996
Description:

This update for openssl-3 fixes the following issues:


Advisory IDSUSE-RU-2024:3504-1
ReleasedTue Oct 1 16:22:27 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1230638
Description:

This update for glibc fixes the following issue:


Advisory IDSUSE-RU-2024:3512-1
ReleasedWed Oct 2 18:14:56 2024
SummaryRecommended update for systemd
Typerecommended
Severityimportant
References1226414,1228091,1228223,1228809,1229518
Description:

This update for systemd fixes the following issues:


Advisory IDSUSE-RU-2024:3522-1
ReleasedFri Oct 4 10:02:34 2024
SummaryRecommended update for dracut
Typerecommended
Severitymoderate
References1230110,1230330,1230468,1230639
Description:

This update for dracut fixes the following issues:


Advisory IDSUSE-RU-2024:3528-1
ReleasedFri Oct 4 15:31:43 2024
SummaryRecommended update for e2fsprogs
Typerecommended
Severitymoderate
References1230145
Description:

This update for e2fsprogs fixes the following issue:


Advisory IDSUSE-RU-2024:3529-1
ReleasedFri Oct 4 15:37:44 2024
SummaryRecommended update for libpcap
Typerecommended
Severitymoderate
References1230894
Description:

This update for libpcap fixes the following issue:


SUSE-IU-2024:1184-1

Container Advisory IDSUSE-IU-2024:1184-1
Container Tags
Container Release
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2869-1
ReleasedFri Aug 9 15:59:29 2024
SummarySecurity update for ca-certificates-mozilla
Typesecurity
Severityimportant
References1220356,1227525
Description:

This update for ca-certificates-mozilla fixes the following issues:



Advisory IDSUSE-RU-2024:2886-1
ReleasedTue Aug 13 09:46:48 2024
SummaryRecommended update for dmidecode
Typerecommended
Severitymoderate
References
Description:

This update for dmidecode fixes the following issues:

Update for HPE servers from upstream:
  • dmioem-update-hpe-oem-type-238 patch: Decode PCI bus segment in HPE type 238 records

  • Advisory IDSUSE-RU-2024:2888-1
    ReleasedTue Aug 13 11:07:41 2024
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1159034,1194818,1218609,1222285
    Description:

    This update for util-linux fixes the following issues:


    Advisory IDSUSE-RU-2024:2912-1
    ReleasedWed Aug 14 20:20:13 2024
    SummaryRecommended update for cloud-regionsrv-client
    Typerecommended
    Severityimportant
    References1222985,1223571,1224014,1224016,1227308
    Description:

    This update for cloud-regionsrv-client contains the following fixes:



    Advisory IDSUSE-RU-2024:2918-1
    ReleasedThu Aug 15 06:59:39 2024
    SummaryRecommended update for grub2
    Typerecommended
    Severityimportant
    References1223535,1226100,1228124
    Description:

    This update for grub2 fixes the following issues:


    Advisory IDSUSE-RU-2024:2932-1
    ReleasedThu Aug 15 12:05:04 2024
    SummaryRecommended update for supportutils
    Typerecommended
    Severitymoderate
    References1222021,1227127,1228265
    Description:

    This update for supportutils fixes the following issues:
    Changes to version 3.2.8


    Advisory IDSUSE-SU-2024:2933-1
    ReleasedThu Aug 15 12:12:50 2024
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitymoderate
    References1225907,1226463,1227138,CVE-2024-5535
    Description:

    This update for openssl-1_1 fixes the following issues:


    Other fixes:


    Advisory IDSUSE-RU-2024:2952-1
    ReleasedFri Aug 16 17:05:34 2024
    SummaryRecommended update for nfs-utils
    Typerecommended
    Severitymoderate
    References1228159
    Description:

    This update for nfs-utils fixes the following issues:


    Advisory IDSUSE-RU-2024:2957-1
    ReleasedMon Aug 19 10:48:01 2024
    SummaryRecommended update for ldb, samba
    Typerecommended
    Severitymoderate
    References1228732
    Description:

    This update for ldb, samba fixes the following issues:


    Advisory IDSUSE-RU-2024:2967-1
    ReleasedMon Aug 19 15:41:29 2024
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1194818
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-SU-2024:3054-1
    ReleasedWed Aug 28 14:48:31 2024
    SummarySecurity update for python3-setuptools
    Typesecurity
    Severityimportant
    References1228105,CVE-2024-6345
    Description:

    This update for python3-setuptools fixes the following issues:


    Advisory IDSUSE-RU-2024:3071-1
    ReleasedMon Sep 2 15:17:11 2024
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1229339
    Description:

    This update for suse-build-key fixes the following issue:


    Advisory IDSUSE-RU-2024:3103-1
    ReleasedTue Sep 3 16:59:06 2024
    SummaryRecommended update for xfsprogs
    Typerecommended
    Severitymoderate
    References1229160
    Description:

    This update for xfsprogs fixes the following issue:


    Advisory IDSUSE-SU-2024:3106-1
    ReleasedTue Sep 3 17:00:40 2024
    SummarySecurity update for openssl-3
    Typesecurity
    Severitymoderate
    References1220523,1220690,1220693,1220696,1221365,1221751,1221752,1221753,1221760,1221786,1221787,1221821,1221822,1221824,1221827,1229465,CVE-2024-6119
    Description:

    This update for openssl-3 fixes the following issues:


    Other fixes:


    Advisory IDSUSE-SU-2024:3113-1
    ReleasedTue Sep 3 17:04:05 2024
    SummarySecurity update for xen
    Typesecurity
    Severityimportant
    References1027519,1228574,1228575,CVE-2024-31145,CVE-2024-31146
    Description:

    This update for xen fixes the following issues:


    Other fixes:


    Advisory IDSUSE-SU-2024:3120-1
    ReleasedTue Sep 3 17:12:57 2024
    SummarySecurity update for buildah, docker
    Typesecurity
    Severitycritical
    References1214855,1219267,1219268,1219438,1221243,1221677,1221916,1223409,1224117,1228324,CVE-2024-1753,CVE-2024-23651,CVE-2024-23652,CVE-2024-23653,CVE-2024-24786,CVE-2024-28180,CVE-2024-3727,CVE-2024-41110
    Description:

    This update for buildah, docker fixes the following issues:
    Changes in docker:


    Other fixes:


    Changes in buildah:






    Advisory IDSUSE-RU-2024:3124-1
    ReleasedTue Sep 3 17:38:34 2024
    SummaryRecommended update for cryptsetup
    Typerecommended
    Severitymoderate
    References1229975
    Description:

    This update for cryptsetup fixes the following issues:


    Advisory IDSUSE-RU-2024:3132-1
    ReleasedTue Sep 3 17:43:10 2024
    SummaryRecommended update for permissions
    Typerecommended
    Severitymoderate
    References1228968,1229329
    Description:

    This update for permissions fixes the following issues:



    Advisory IDSUSE-RU-2024:3135-1
    ReleasedWed Sep 4 08:36:23 2024
    SummaryRecommended update for rsyslog
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for rsyslog fixes the following issues:


    Advisory IDSUSE-RU-2024:3147-1
    ReleasedThu Sep 5 09:30:37 2024
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1228398,1228847
    Description:

    This update for dracut fixes the following issues:


    SUSE-IU-2024:722-1

    Container Advisory IDSUSE-IU-2024:722-1
    Container Tags
    Container Release
    The following patches have been included in this update:
    Advisory IDSUSE-SU-2024:2393-1
    ReleasedWed Jul 10 17:33:47 2024
    SummarySecurity update for openssh
    Typesecurity
    Severitymoderate
    References1218215,1224392,1225904,1227318,1227350,CVE-2023-51385,CVE-2024-39894
    Description:

    This update for openssh fixes the following issues:
    Security fixes:


    Other fixes:


    Advisory IDSUSE-SU-2024:2401-1
    ReleasedThu Jul 11 06:36:43 2024
    SummarySecurity update for oniguruma
    Typesecurity
    Severitymoderate
    References1141157,CVE-2019-13225
    Description:

    This update for oniguruma fixes the following issues:


    Advisory IDSUSE-RU-2024:2406-1
    ReleasedThu Jul 11 11:27:05 2024
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1227429
    Description:

    This update for suse-build-key fixes the following issue:


    Advisory IDSUSE-SU-2024:2479-1
    ReleasedMon Jul 15 10:33:22 2024
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1219559,1220664,1221563,1221854,1222075,1226447,1226448,CVE-2023-52425,CVE-2024-0397,CVE-2024-0450,CVE-2024-4032
    Description:

    This update for python3 fixes the following issues:


    Advisory IDSUSE-SU-2024:2531-1
    ReleasedTue Jul 16 14:12:12 2024
    SummarySecurity update for xen
    Typesecurity
    Severityimportant
    References1027519,1214718,1221984,1225953,1227355,CVE-2023-46842,CVE-2024-31143
    Description:

    This update for xen fixes the following issues:


    Advisory IDSUSE-SU-2024:2571-1
    ReleasedMon Jul 22 12:34:16 2024
    SummarySecurity update for the Linux Kernel
    Typesecurity
    Severityimportant
    References1186716,1195775,1204562,1209834,1217481,1217912,1218442,1219224,1219478,1219596,1219633,1219847,1219953,1221086,1221777,1221958,1222011,1222015,1222080,1222241,1222380,1222588,1222617,1222619,1222809,1222810,1223018,1223265,1224049,1224187,1224439,1224497,1224498,1224515,1224520,1224523,1224539,1224540,1224549,1224572,1224575,1224583,1224584,1224606,1224612,1224614,1224619,1224655,1224659,1224661,1224662,1224670,1224673,1224698,1224735,1224751,1224759,1224928,1224930,1224932,1224933,1224935,1224937,1224939,1224941,1224944,1224946,1224947,1224949,1224951,1224988,1224992,1224998,1225000,1225001,1225004,1225006,1225008,1225009,1225014,1225015,1225022,1225025,1225028,1225029,1225031,1225036,1225041,1225044,1225049,1225050,1225076,1225077,1225078,1225081,1225085,1225086,1225090,1225092,1225096,1225097,1225098,1225101,1225103,1225104,1225105,1225106,1225108,1225120,1225132,1225180,1225300,1225391,1225472,1225475,1225476,1225477,1225478,1225485,1225490,1225527,1225529,1225530,1225532,1225534,1225548,1225550,1225553,1225554,1225555,1225556,1225557,1225559,1225560,1225564,1225565,1225566,1225568,1225569,1225570,1225571,1225572,1225573,1225577,1225581,1225583,1225584,1225585,1225586,1225587,1225588,1225589,1225590,1225591,1225592,1225594,1225595,1225599,1225602,1225605,1225609,1225611,1225681,1225702,1225723,1225726,1225731,1225732,1225737,1225741,1225758,1225759,1225760,1225761,1225762,1225763,1225767,1225770,1225815,1225820,1225823,1225827,1225834,1225866,1225872,1225898,1225903,1226022,1226131,1226145,1226149,1226155,1226158,1226163,1226211,1226212,1226226,1226457,1226503,1226513,1226514,1226520,1226582,1226587,1226588,1226592,1226593,1226594,1226595,1226597,1226607,1226608,1226610,1226612,1226613,1226630,1226632,1226633,1226634,1226637,1226657,1226658,1226734,1226735,1226737,1226738,1226739,1226740,1226741,1226742,1226744,1226746,1226747,1226749,1226754,1226758,1226760,1226761,1226764,1226767,1226768,1226769,1226771,1226772,1226774,1226775,1226776,1226777,1226780,1226781,1226786,1226788,1226789,1226790,1226791,1226796,1226799,1226837,1226839,1226840,1226841,1226842,1226844,1226848,1226852,1226856,1226857,1226859,1226861,1226863,1226864,1226867,1226868,1226875,1226876,1226878,1226879,1226886,1226890,1226891,1226894,1226895,1226905,1226908,1226909,1226911,1226928,1226934,1226938,1226939,1226941,1226948,1226949,1226950,1226962,1226976,1226989,1226990,1226992,1226994,1226995,1226996,1227066,1227072,1227085,1227089,1227090,1227096,1227101,1227190,CVE-2021-47432,CVE-2022-48772,CVE-2023-52622,CVE-2023-52656,CVE-2023-52672,CVE-2023-52699,CVE-2023-52735,CVE-2023-52749,CVE-2023-52750,CVE-2023-52753,CVE-2023-52754,CVE-2023-52757,CVE-2023-52759,CVE-2023-52762,CVE-2023-52763,CVE-2023-52764,CVE-2023-52765,CVE-2023-52766,CVE-2023-52767,CVE-2023-52768,CVE-2023-52769,CVE-2023-52773,CVE-2023-52774,CVE-2023-52776,CVE-2023-52777,CVE-2023-52780,CVE-2023-52781,CVE-2023-52782,CVE-2023-52783,CVE-2023-52784,CVE-2023-52786,CVE-2023-52787,CVE-2023-52788,CVE-2023-52789,CVE-2023-52791,CVE-2023-52792,CVE-2023-52794,CVE-2023-52795,CVE-2023-52796,CVE-2023-52798,CVE-2023-52799,CVE-2023-52800,CVE-2023-52801,CVE-2023-52803,CVE-2023-52804,CVE-2023-52805,CVE-2023-52806,CVE-2023-52807,CVE-2023-52808,CVE-2023-52809,CVE-2023-52810,CVE-2023-52811,CVE-2023-52812,CVE-2023-52813,CVE-2023-52814,CVE-2023-52815,CVE-2023-52816,CVE-2023-52817,CVE-2023-52818,CVE-2023-52819,CVE-2023-52821,CVE-2023-52825,CVE-2023-52826,CVE-2023-52827,CVE-2023-52829,CVE-2023-52832,CVE-2023-52833,CVE-2023-52834,CVE-2023-52835,CVE-2023-52836,CVE-2023-52837,CVE-2023-52838,CVE-2023-52840,CVE-2023-52841,CVE-2023-52842,CVE-2023-52843,CVE-2023-52844,CVE-2023-52845,CVE-2023-52846,CVE-2023-52847,CVE-2023-52849,CVE-2023-52850,CVE-2023-52851,CVE-2023-52853,CVE-2023-52854,CVE-2023-52855,CVE-2023-52856,CVE-2023-52857,CVE-2023-52858,CVE-2023-52861,CVE-2023-52862,CVE-2023-52863,CVE-2023-52864,CVE-2023-52865,CVE-2023-52866,CVE-2023-52867,CVE-2023-52868,CVE-2023-52869,CVE-2023-52870,CVE-2023-52871,CVE-2023-52872,CVE-2023-52873,CVE-2023-52874,CVE-2023-52875,CVE-2023-52876,CVE-2023-52877,CVE-2023-52878,CVE-2023-52879,CVE-2023-52880,CVE-2023-52881,CVE-2023-52883,CVE-2023-52884,CVE-2024-26482,CVE-2024-26625,CVE-2024-26676,CVE-2024-26750,CVE-2024-26758,CVE-2024-26767,CVE-2024-26780,CVE-2024-26813,CVE-2024-26814,CVE-2024-26845,CVE-2024-26889,CVE-2024-26920,CVE-2024-27414,CVE-2024-27419,CVE-2024-33619,CVE-2024-34777,CVE-2024-35247,CVE-2024-35807,CVE-2024-35827,CVE-2024-35831,CVE-2024-35843,CVE-2024-35848,CVE-2024-35857,CVE-2024-35880,CVE-2024-35884,CVE-2024-35886,CVE-2024-35892,CVE-2024-35896,CVE-2024-35898,CVE-2024-35900,CVE-2024-35925,CVE-2024-35926,CVE-2024-35957,CVE-2024-35962,CVE-2024-35970,CVE-2024-35976,CVE-2024-35979,CVE-2024-35998,CVE-2024-36005,CVE-2024-36008,CVE-2024-36010,CVE-2024-36017,CVE-2024-36024,CVE-2024-36281,CVE-2024-36477,CVE-2024-36478,CVE-2024-36479,CVE-2024-36882,CVE-2024-36887,CVE-2024-36899,CVE-2024-36900,CVE-2024-36903,CVE-2024-36904,CVE-2024-36915,CVE-2024-36916,CVE-2024-36917,CVE-2024-36919,CVE-2024-36923,CVE-2024-36924,CVE-2024-36926,CVE-2024-36934,CVE-2024-36935,CVE-2024-36937,CVE-2024-36938,CVE-2024-36945,CVE-2024-36952,CVE-2024-36957,CVE-2024-36960,CVE-2024-36962,CVE-2024-36964,CVE-2024-36965,CVE-2024-36967,CVE-2024-36969,CVE-2024-36971,CVE-2024-36972,CVE-2024-36973,CVE-2024-36975,CVE-2024-36977,CVE-2024-36978,CVE-2024-37021,CVE-2024-37078,CVE-2024-37353,CVE-2024-37354,CVE-2024-38381,CVE-2024-38384,CVE-2024-38385,CVE-2024-38388,CVE-2024-38390,CVE-2024-38391,CVE-2024-38539,CVE-2024-38540,CVE-2024-38541,CVE-2024-38543,CVE-2024-38544,CVE-2024-38545,CVE-2024-38546,CVE-2024-38547,CVE-2024-38548,CVE-2024-38549,CVE-2024-38550,CVE-2024-38551,CVE-2024-38552,CVE-2024-38553,CVE-2024-38554,CVE-2024-38555,CVE-2024-38556,CVE-2024-38557,CVE-2024-38559,CVE-2024-38560,CVE-2024-38562,CVE-2024-38564,CVE-2024-38565,CVE-2024-38566,CVE-2024-38567,CVE-2024-38568,CVE-2024-38569,CVE-2024-38570,CVE-2024-38571,CVE-2024-38572,CVE-2024-38573,CVE-2024-38575,CVE-2024-38578,CVE-2024-38579,CVE-2024-38580,CVE-2024-38581,CVE-2024-38582,CVE-2024-38583,CVE-2024-38587,CVE-2024-38588,CVE-2024-38590,CVE-2024-38591,CVE-2024-38592,CVE-2024-38594,CVE-2024-38595,CVE-2024-38597,CVE-2024-38599,CVE-2024-38600,CVE-2024-38601,CVE-2024-38602,CVE-2024-38603,CVE-2024-38605,CVE-2024-38608,CVE-2024-38610,CVE-2024-38611,CVE-2024-38615,CVE-2024-38616,CVE-2024-38617,CVE-2024-38618,CVE-2024-38619,CVE-2024-38621,CVE-2024-38622,CVE-2024-38627,CVE-2024-38628,CVE-2024-38629,CVE-2024-38630,CVE-2024-38633,CVE-2024-38634,CVE-2024-38635,CVE-2024-38636,CVE-2024-38661,CVE-2024-38663,CVE-2024-38664,CVE-2024-38780,CVE-2024-39277,CVE-2024-39291,CVE-2024-39296,CVE-2024-39301,CVE-2024-39362,CVE-2024-39371,CVE-2024-39463,CVE-2024-39466,CVE-2024-39469,CVE-2024-39471
    Description:

    The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security bugfixes.

    The following security bugs were fixed:


    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2024:2587-1
    ReleasedMon Jul 22 13:44:54 2024
    SummaryRecommended update for openssh
    Typerecommended
    Severitymoderate
    References1227456
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-RU-2024:2609-1
    ReleasedFri Jul 26 18:07:05 2024
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1227681
    Description:

    This update for suse-build-key fixes the following issue:


    Advisory IDSUSE-SU-2024:2630-1
    ReleasedTue Jul 30 09:12:44 2024
    SummarySecurity update for shadow
    Typesecurity
    Severityimportant
    References916845,CVE-2013-4235
    Description:

    This update for shadow fixes the following issues:


    Advisory IDSUSE-SU-2024:2635-1
    ReleasedTue Jul 30 09:14:09 2024
    SummarySecurity update for openssl-3
    Typesecurity
    Severityimportant
    References1222899,1223336,1226463,1227138,CVE-2024-5535
    Description:

    This update for openssl-3 fixes the following issues:
    Security fixes:


    Other fixes:


    Advisory IDSUSE-SU-2024:2636-1
    ReleasedTue Jul 30 09:14:22 2024
    SummarySecurity update for bind
    Typesecurity
    Severityimportant
    References1228255,1228256,1228257,1228258,CVE-2024-0760,CVE-2024-1737,CVE-2024-1975,CVE-2024-4076
    Description:

    This update for bind fixes the following issues:
    Update to release 9.18.28
    Security fixes:


    Changelog:
    * Command-line options for IPv4-only (named -4) and IPv6-only (named -6) modes are now respected for zone primaries, also-notify, and parental-agents. * An RPZ response’s SOA record TTL was set to 1 instead of the SOA TTL, if add-soa was used. This has been fixed. * When a query related to zone maintenance (NOTIFY, SOA) timed out close to a view shutdown (triggered e.g. by rndc reload), named could crash with an assertion failure. This has been fixed. * The statistics channel counters that indicated the number of currently connected TCP IPv4/IPv6 clients were not properly adjusted in certain failure scenarios. This has been fixed. * Some servers that could not be reached due to EHOSTDOWN or ENETDOWN conditions were incorrectly prioritized during server selection. These are now properly handled as unreachable. * On some systems the libuv call may return an error code when sending a TCP reset for a connection, which triggers an assertion failure in named. This error condition is now dealt with in a more graceful manner, by logging the incident and shutting down the connection. * Changes to listen-on statements were ignored on reconfiguration unless the port or interface address was changed, making it impossible to change a related listener transport type. That issue has been fixed. * A bug in the keymgr code unintentionally slowed down some DNSSEC key rollovers. This has been fixed. * Some ISO 8601 durations were accepted erroneously, leading to shorter durations than expected. This has been fixed * A regression in cache-cleaning code enabled memory use to grow significantly more quickly than before, until the configured max-cache-size limit was reached. This has been fixed. * Using rndc flush inadvertently caused cache cleaning to become less effective. This could ultimately lead to the configured max-cache-size limit being exceeded and has now been fixed. * The logic for cleaning up expired cached DNS records was tweaked to be more aggressive. This change helps with enforcing max-cache-ttl and max-ncache-ttl in a timely manner. * It was possible to trigger a use-after-free assertion when the overmem cache cleaning was initiated. This has been fixed. New Features: * A new option signatures-jitter has been added to dnssec-policy to allow signature expirations to be spread out over a period of time. * The statistics channel now includes counters that indicate the number of currently connected TCP IPv4/IPv6 clients. * Added RESOLVER.ARPA to the built in empty zones. Feature Changes: * DNSSEC signatures that are not valid because the current time falls outside the signature inception and expiration dates are skipped instead of causing an immediate validation failure. Security Fixes: * A malicious DNS client that sent many queries over TCP but never read the responses could cause a server to respond slowly or not at all for other clients. This has been fixed. (CVE-2024-0760) * It is possible to craft excessively large resource records sets, which have the effect of slowing down database processing. This has been addressed by adding a configurable limit to the number of records that can be stored per name and type in a cache or zone database. The default is 100, which can be tuned with the new max-records-per-type option. * It is possible to craft excessively large numbers of resource record types for a given owner name, which has the effect of slowing down database processing. This has been addressed by adding a configurable limit to the number of records that can be stored per name and type in a cache or zone database. The default is 100, which can be tuned with the new max-types-per-name option. (CVE-2024-1737) * Validating DNS messages signed using the SIG(0) protocol (RFC 2931) could cause excessive CPU load, leading to a denial-of-service condition. Support for SIG(0) message validation was removed from this version of named. (CVE-2024-1975) * Due to a logic error, lookups that triggered serving stale data and required lookups in local authoritative zone data could have resulted in an assertion failure. This has been fixed. * Potential data races were found in our DoH implementation, related to HTTP/2 session object management and endpoints set object management after reconfiguration. These issues have been fixed. * When looking up the NS records of parent zones as part of looking up DS records, it was possible for named to trigger an assertion failure if serve-stale was enabled. This has been fixed. (CVE-2024-4076)


    Advisory IDSUSE-RU-2024:2641-1
    ReleasedTue Jul 30 09:29:36 2024
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd fixes the following issues:
    systemd was updated from version 254.13 to version 254.15:


    * boot: cover for hardware keys on phones/tablets * Conditional PSI check to reflect changes done in 5.13 * core/dbus-manager: refuse SoftReboot() for user managers * core/exec-invoke: reopen OpenFile= fds with O_NOCTTY * core/exec-invoke: use sched_setattr instead of sched_setscheduler * core/unit: follow merged units before updating SourcePath= timestamp too * coredump: correctly take tmpfs size into account for compression * cryptsetup: improve TPM2 blob display * docs: Add section to HACKING.md on distribution packages * docs: fixed dead link to GNOME documentation * docs/CODING_STYLE: document that we nowadays prefer (const char*) for func ret type * Fixed typo in CAP_BPF description * LICENSES/README: expand text to summarize state for binaries and libs * man: fully adopt ~/.local/state/ * man/systemd.exec: list inaccessible files for ProtectKernelTunables * man/tmpfiles: remove outdated behavior regarding symlink ownership * meson: bpf: propagate 'sysroot' for cross compilation * meson: Define __TARGET_ARCH macros required by bpf * mkfs-util: Set sector size for btrfs as well * mkosi: drop CentOS 8 from CI * mkosi: Enable hyperscale-packages-experimental for CentOS * mountpoint-util: do not assume symlinks are not mountpoints * os-util: avoid matching on the wrong extension-release file * README: add missing CONFIG_MEMCG kernel config option for oomd * README: update requirements for signed dm-verity * resolved: allow the full TTL to be used by OPT records * resolved: correct parsing of OPT extended RCODEs * sysusers: handle NSS errors gracefully * TEST-58-REPART: reverse order of diff args * TEST-64-UDEV-STORAGE: Make nvme_subsystem expected pci symlinks more generic * test: fixed TEST-24-CRYPTSETUP on SUSE * test: install /etc/hosts * Use consistent spelling of systemd.condition_first_boot argument * util: make file_read() 64bit offset safe * vmm: make sure we can handle smbios objects without variable part
    * analyze: show pcrs also in sha384 bank * chase: Tighten '.' and './' check * core/service: fixed accept-socket deserialization * efi-api: check /sys/class/tpm/tpm0/tpm_version_major, too * executor: check for all permission related errnos when setting up IPC namespace * install: allow removing symlinks even for units that are gone * json: use secure un{base64,hex}mem for sensitive variants * man,units: drop 'temporary' from description of systemd-tmpfiles * missing_loop.h: fixed LOOP_SET_STATUS_SETTABLE_FLAGS * repart: fixed memory leak * repart: Use CRYPT_ACTIVATE_PRIVATE * resolved: permit dnssec rrtype questions when we aren't validating * rules: Limit the number of device units generated for serial ttys * run: do not pass the pty slave fd to transient service in a machine * sd-dhcp-server: clear buffer before receive * strbuf: use GREEDY_REALLOC to grow the buffer


    Advisory IDSUSE-SU-2024:2662-1
    ReleasedTue Jul 30 15:41:34 2024
    SummarySecurity update for python-urllib3
    Typesecurity
    Severitymoderate
    References1226469,CVE-2024-37891
    Description:

    This update for python-urllib3 fixes the following issues:


    Advisory IDSUSE-RU-2024:2677-1
    ReleasedWed Jul 31 06:58:52 2024
    SummaryRecommended update for wicked
    Typerecommended
    Severityimportant
    References1225976,1226125,1226664
    Description:

    This update for wicked fixes the following issues:


    Advisory IDSUSE-feature-2024:2688-1
    ReleasedThu Aug 1 07:00:59 2024
    SummaryFeature update for Public Cloud
    Typefeature
    Severityimportant
    References1222075,1227067,1227106,1227711
    Description:

    This update for Public Cloud fixes the following issues:




    Advisory IDSUSE-RU-2024:2695-1
    ReleasedThu Aug 1 15:06:12 2024
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1208690,1226412,1226529
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-RU-2024:2747-1
    ReleasedMon Aug 5 18:14:40 2024
    SummaryRecommended update for suseconnect-ng
    Typerecommended
    Severityimportant
    References1219004,1223107,1226128
    Description:

    This update for suseconnect-ng fixes the following issues:


    Advisory IDSUSE-RU-2024:2779-1
    ReleasedTue Aug 6 14:35:49 2024
    SummaryRecommended update for permissions
    Typerecommended
    Severitymoderate
    References1228548
    Description:


    This update for permissions fixes the following issue:


    Advisory IDSUSE-SU-2024:2784-1
    ReleasedTue Aug 6 14:58:38 2024
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1227888,1228535,CVE-2024-6197,CVE-2024-7264
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2024:2788-1
    ReleasedTue Aug 6 15:50:29 2024
    SummaryRecommended update for sudo
    Typerecommended
    Severitymoderate
    References1227574
    Description:

    This update for sudo fixes the following issue:


    Advisory IDSUSE-RU-2024:2791-1
    ReleasedTue Aug 6 16:35:06 2024
    SummaryRecommended update for various 32bit packages
    Typerecommended
    Severitymoderate
    References1228322
    Description:


    This update of various packages delivers 32bit variants to allow running Wine on SLE PackageHub 15 SP6.


    Advisory IDSUSE-RU-2024:2799-1
    ReleasedWed Aug 7 08:19:10 2024
    SummaryRecommended update for runc
    Typerecommended
    Severityimportant
    References1214960
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-SU-2024:2802-1
    ReleasedWed Aug 7 09:46:02 2024
    SummarySecurity update for the Linux Kernel
    Typesecurity
    Severityimportant
    References1194869,1215199,1215587,1218442,1218730,1218820,1219832,1220138,1220427,1220430,1220942,1221057,1221647,1221654,1221656,1221659,1222326,1222328,1222438,1222463,1222768,1222775,1222779,1222893,1223010,1223021,1223570,1223731,1223740,1223778,1223804,1223806,1223807,1223813,1223815,1223836,1223863,1224414,1224422,1224490,1224499,1224512,1224516,1224544,1224545,1224589,1224604,1224636,1224641,1224743,1224767,1225088,1225172,1225272,1225489,1225600,1225601,1225711,1225717,1225719,1225744,1225745,1225746,1225752,1225753,1225757,1225805,1225810,1225830,1225835,1225839,1225840,1225843,1225847,1225851,1225856,1225894,1225895,1225896,1226202,1226213,1226502,1226519,1226750,1226757,1226783,1226866,1226883,1226915,1226993,1227103,1227149,1227282,1227362,1227363,1227383,1227432,1227433,1227434,1227435,1227443,1227446,1227447,1227487,1227573,1227626,1227716,1227719,1227723,1227730,1227736,1227755,1227757,1227762,1227763,1227779,1227780,1227783,1227786,1227788,1227789,1227797,1227800,1227801,1227803,1227806,1227813,1227814,1227836,1227855,1227862,1227866,1227886,1227899,1227910,1227913,1227926,1228090,1228192,1228193,1228211,1228269,1228289,1228327,1228328,1228403,1228405,1228408,1228417,CVE-2023-38417,CVE-2023-47210,CVE-2023-51780,CVE-2023-52435,CVE-2023-52472,CVE-2023-52751,CVE-2023-52775,CVE-2024-25741,CVE-2024-26615,CVE-2024-26623,CVE-2024-26633,CVE-2024-26635,CVE-2024-26636,CVE-2024-26641,CVE-2024-26663,CVE-2024-26665,CVE-2024-26691,CVE-2024-26734,CVE-2024-26785,CVE-2024-26826,CVE-2024-26863,CVE-2024-26944,CVE-2024-27012,CVE-2024-27015,CVE-2024-27016,CVE-2024-27019,CVE-2024-27020,CVE-2024-27025,CVE-2024-27064,CVE-2024-27065,CVE-2024-27402,CVE-2024-27404,CVE-2024-35805,CVE-2024-35853,CVE-2024-35854,CVE-2024-35890,CVE-2024-35893,CVE-2024-35899,CVE-2024-35908,CVE-2024-35934,CVE-2024-35942,CVE-2024-36003,CVE-2024-36004,CVE-2024-36889,CVE-2024-36901,CVE-2024-36902,CVE-2024-36909,CVE-2024-36910,CVE-2024-36911,CVE-2024-36912,CVE-2024-36913,CVE-2024-36914,CVE-2024-36922,CVE-2024-36930,CVE-2024-36940,CVE-2024-36941,CVE-2024-36942,CVE-2024-36944,CVE-2024-36946,CVE-2024-36947,CVE-2024-36949,CVE-2024-36950,CVE-2024-36951,CVE-2024-36955,CVE-2024-36959,CVE-2024-36974,CVE-2024-38558,CVE-2024-38586,CVE-2024-38598,CVE-2024-38604,CVE-2024-38659,CVE-2024-39276,CVE-2024-39468,CVE-2024-39472,CVE-2024-39473,CVE-2024-39474,CVE-2024-39475,CVE-2024-39479,CVE-2024-39481,CVE-2024-39482,CVE-2024-39487,CVE-2024-39490,CVE-2024-39494,CVE-2024-39496,CVE-2024-39498,CVE-2024-39502,CVE-2024-39504,CVE-2024-39507,CVE-2024-40901,CVE-2024-40906,CVE-2024-40908,CVE-2024-40919,CVE-2024-40923,CVE-2024-40925,CVE-2024-40928,CVE-2024-40931,CVE-2024-40935,CVE-2024-40937,CVE-2024-40940,CVE-2024-40947,CVE-2024-40948,CVE-2024-40953,CVE-2024-40960,CVE-2024-40961,CVE-2024-40966,CVE-2024-40970,CVE-2024-40972,CVE-2024-40975,CVE-2024-40979,CVE-2024-40998,CVE-2024-40999,CVE-2024-41006,CVE-2024-41011,CVE-2024-41013,CVE-2024-41014,CVE-2024-41017,CVE-2024-41090,CVE-2024-41091
    Description:


    The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security bugfixes.

    The following security bugs were fixed:


    The following non-security bugs were fixed:


    Advisory IDSUSE-SU-2024:2808-1
    ReleasedWed Aug 7 09:49:32 2024
    SummarySecurity update for shadow
    Typesecurity
    Severitymoderate
    References1228770,CVE-2013-4235
    Description:

    This update for shadow fixes the following issues:


    Advisory IDSUSE-RU-2024:3101-1
    ReleasedTue Sep 3 16:48:21 2024
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1227600
    Description:

    This update for python-azure-agent fixes the following issue:


    SUSE-IU-2024:626-1

    Container Advisory IDSUSE-IU-2024:626-1
    Container Tags
    Container Release
    The following patches have been included in this update:
    Advisory IDSUSE-RU-2024:2253-1
    ReleasedMon Jul 1 18:33:02 2024
    SummaryRecommended update for containerd
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for containerd fixes the following issues:


    Switching to noarch causes issues on SLES maintenance updates, reverting it fixes our image builds


    Advisory IDSUSE-SU-2024:2275-1
    ReleasedTue Jul 2 16:33:30 2024
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1226642,CVE-2024-6387
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-OU-2024:2282-1
    ReleasedTue Jul 2 22:41:28 2024
    SummaryOptional update for openscap, scap-security-guide
    Typeoptional
    Severitymoderate
    References
    Description:


    This update for scap-security-guide and openscap provides the SCAP tooling for SLE Micro 5.3, 5.4, 5.5.
    This includes shipping openscap dependencies libxmlsec1-1 and libxmlsec1-openssl for SLE Micro.


    Advisory IDSUSE-SU-2024:2290-1
    ReleasedWed Jul 3 11:35:00 2024
    SummarySecurity update for libxml2
    Typesecurity
    Severitylow
    References1224282,CVE-2024-34459
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2024:2307-1
    ReleasedFri Jul 5 12:04:34 2024
    SummarySecurity update for krb5
    Typesecurity
    Severityimportant
    References1227186,1227187,CVE-2024-37370,CVE-2024-37371
    Description:

    This update for krb5 fixes the following issues:


    SUSE-IU-2024:569-1

    Container Advisory IDSUSE-IU-2024:569-1
    Container Tags
    Container Release
    The following patches have been included in this update:
    Advisory IDSUSE-RU-2018:1756-1
    ReleasedFri Aug 24 17:12:55 2018
    SummaryRecommended update for growpart
    Typerecommended
    Severitymoderate
    References1097455,1098681
    Description:

    This update for growpart provides the following fix:


    Advisory IDSUSE-RU-2018:1804-1
    ReleasedFri Aug 31 13:02:24 2018
    SummaryRecommended update for docker
    Typerecommended
    Severitymoderate
    References1065609,1073877,1099277,1100727
    Description:

    This update for docker fixes the following issues:


    Advisory IDSUSE-RU-2018:2022-1
    ReleasedWed Sep 26 09:48:09 2018
    SummaryRecommended update for SUSE Manager Client Tools
    Typerecommended
    Severitymoderate
    References1103388,1104120,1106523
    Description:

    This update fixes the following issues:
    hwdata:


    spacewalk-backend:


    Advisory IDSUSE-SU-2018:2340-1
    ReleasedFri Oct 19 16:05:53 2018
    SummarySecurity update for fuse
    Typesecurity
    Severitymoderate
    References1101797,CVE-2018-10906
    Description:

    This update for fuse fixes the following issues:


    Advisory IDSUSE-RU-2018:2569-1
    ReleasedFri Nov 2 19:00:18 2018
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1110700
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2018:2607-1
    ReleasedWed Nov 7 15:42:48 2018
    SummaryOptional update for gcc8
    Typerecommended
    Severitylow
    References1084812,1084842,1087550,1094222,1102564
    Description:


    The GNU Compiler GCC 8 is being added to the Development Tools Module by this update.
    The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
    Various optimizers have been improved in GCC 8, several of bugs fixed, quite some new warnings added and the error pin-pointing and fix-suggestions have been greatly improved.
    The GNU Compiler page for GCC 8 contains a summary of all the changes that have happened:
    https://gcc.gnu.org/gcc-8/changes.html
    Also changes needed or common pitfalls when porting software are described on:
    https://gcc.gnu.org/gcc-8/porting_to.html


    Advisory IDSUSE-RU-2018:2742-1
    ReleasedThu Nov 22 13:28:36 2018
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References969953
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-SU-2018:2825-1
    ReleasedMon Dec 3 15:35:02 2018
    SummarySecurity update for pam
    Typesecurity
    Severityimportant
    References1115640,CVE-2018-17953
    Description:

    This update for pam fixes the following issue:
    Security issue fixed:


    Advisory IDSUSE-SU-2018:2861-1
    ReleasedThu Dec 6 14:32:01 2018
    SummarySecurity update for ncurses
    Typesecurity
    Severityimportant
    References1103320,1115929,CVE-2018-19211
    Description:

    This update for ncurses fixes the following issues:
    Security issue fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2018:3064-1
    ReleasedFri Dec 28 18:39:08 2018
    SummarySecurity update for containerd, docker and go
    Typesecurity
    Severityimportant
    References1047218,1074971,1080978,1081495,1084533,1086185,1094680,1095817,1098017,1102522,1104821,1105000,1108038,1113313,1113978,1114209,1118897,1118898,1118899,1119634,1119706,CVE-2018-16873,CVE-2018-16874,CVE-2018-16875,CVE-2018-7187
    Description:


    This update for containerd, docker and go fixes the following issues:
    containerd and docker:


    go:
    Additionally, the package go1.10 has been added.


    Advisory IDSUSE-RU-2019:44-1
    ReleasedTue Jan 8 13:07:32 2019
    SummaryRecommended update for acl
    Typerecommended
    Severitylow
    References953659
    Description:

    This update for acl fixes the following issues:


    Advisory IDSUSE-RU-2019:82-1
    ReleasedFri Jan 11 17:16:48 2019
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1044232
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-SU-2019:247-1
    ReleasedWed Feb 6 07:18:45 2019
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1123043,CVE-2019-6706
    Description:

    This update for lua53 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:286-1
    ReleasedThu Feb 7 13:45:27 2019
    SummarySecurity update for docker
    Typesecurity
    Severitymoderate
    References1001161,1112980,1115464,1118897,1118898,1118899,1118990,1121412,CVE-2018-16873,CVE-2018-16874,CVE-2018-16875
    Description:

    This update for containerd, docker, docker-runc and golang-github-docker-libnetwork fixes the following issues:
    Security issues fixed for containerd, docker, docker-runc and golang-github-docker-libnetwork:


    Non-security issues fixed for docker:


    Advisory IDSUSE-SU-2019:495-1
    ReleasedTue Feb 26 16:42:35 2019
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc
    Typesecurity
    Severityimportant
    References1048046,1051429,1114832,1118897,1118898,1118899,1121967,1124308,CVE-2018-16873,CVE-2018-16874,CVE-2018-16875,CVE-2019-5736
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc fixes the following issues:
    Security issues fixed:


    Other changes and fixes:


    Advisory IDSUSE-SU-2019:571-1
    ReleasedThu Mar 7 18:13:46 2019
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
    Description:

    This update for file fixes the following issues:
    The following security vulnerabilities were addressed:


    Advisory IDSUSE-SU-2019:788-1
    ReleasedThu Mar 28 11:55:06 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1119687,CVE-2018-20346
    Description:

    This update for sqlite3 to version 3.27.2 fixes the following issue:
    Security issue fixed:


    Release notes: https://www.sqlite.org/releaselog/3_27_2.html


    Advisory IDSUSE-SU-2019:926-1
    ReleasedWed Apr 10 16:33:12 2019
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1120610,1130496,CVE-2018-20482,CVE-2019-9923
    Description:

    This update for tar fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-RU-2019:1022-1
    ReleasedWed Apr 24 13:46:51 2019
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1121410
    Description:

    This update for hwdata fixes the following issues:
    Update to version 0.320 (bsc#1121410):


    Advisory IDSUSE-SU-2019:1040-1
    ReleasedThu Apr 25 17:09:21 2019
    SummarySecurity update for samba
    Typesecurity
    Severityimportant
    References1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880
    Description:

    This update for samba fixes the following issues:
    Security issue fixed:



    ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:1127-1
    ReleasedThu May 2 09:39:24 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1130325,1130326,CVE-2019-9936,CVE-2019-9937
    Description:

    This update for sqlite3 to version 3.28.0 fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:1156-1
    ReleasedMon May 6 13:46:07 2019
    SummarySecurity update for python-Jinja2
    Typesecurity
    Severityimportant
    References1125815,1132174,1132323,CVE-2016-10745,CVE-2019-10906,CVE-2019-8341
    Description:

    This update for python-Jinja2 to version 2.10.1 fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:1234-1
    ReleasedTue May 14 18:31:52 2019
    SummarySecurity update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork
    Typesecurity
    Severityimportant
    References1114209,1114832,1118897,1118898,1118899,1121397,1121967,1123013,1128376,1128746,1134068,CVE-2018-16873,CVE-2018-16874,CVE-2018-16875,CVE-2019-5736,CVE-2019-6486
    Description:

    This update for containerd, docker, docker-runc, go, go1.11, go1.12, golang-github-docker-libnetwork fixes the following issues:
    Security issues fixed:


    Other changes and bug fixes:


    Advisory IDSUSE-SU-2019:1368-1
    ReleasedTue May 28 13:15:38 2019
    SummaryRecommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root
    Typesecurity
    Severityimportant
    References1134524,CVE-2019-5021
    Description:

    This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:


    Advisory IDSUSE-SU-2019:1372-1
    ReleasedTue May 28 16:53:28 2019
    SummarySecurity update for libtasn1
    Typesecurity
    Severitymoderate
    References1105435,CVE-2018-1000654
    Description:

    This update for libtasn1 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:1562-1
    ReleasedWed Jun 19 09:16:07 2019
    SummarySecurity update for docker
    Typesecurity
    Severitymoderate
    References1096726,CVE-2018-15664
    Description:

    This update for docker fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:1616-1
    ReleasedFri Jun 21 11:04:39 2019
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References1134659
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-RU-2019:2001-1
    ReleasedFri Jul 26 18:09:41 2019
    SummaryRecommended update for docker
    Typerecommended
    Severityimportant
    References1138920
    Description:

    This update for docker fixes the following issues:


    Advisory IDSUSE-RU-2019:2005-1
    ReleasedMon Jul 29 13:02:15 2019
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1116767,1119397,1121878,1123694,1125950,1125992,1126101,1132692,1136440
    Description:

    This update for cloud-init fixes the following issues:


    Some more fixes were included within the 19.1 update of cloud-init. Please refer to the package changelog for more details.


    Advisory IDSUSE-SU-2019:2117-1
    ReleasedTue Aug 13 14:56:55 2019
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork
    Typesecurity
    Severityimportant
    References1100331,1121967,1138920,1139649,1142160,1142413,1143409,CVE-2018-10892,CVE-2019-13509,CVE-2019-14271,CVE-2019-5736
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
    Docker:


    runc:

    containerd:

    golang-github-docker-libnetwork:


    Advisory IDSUSE-RU-2019:2218-1
    ReleasedMon Aug 26 11:29:57 2019
    SummaryRecommended update for pinentry
    Typerecommended
    Severitymoderate
    References1141883
    Description:

    This update for pinentry fixes the following issues:


    Advisory IDSUSE-RU-2019:2494-1
    ReleasedMon Sep 30 16:22:20 2019
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1141969,1144363,1144881
    Description:

    This update for cloud-init provides the following fixes:


    Advisory IDSUSE-SU-2019:2533-1
    ReleasedThu Oct 3 15:02:50 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1150137,CVE-2019-16168
    Description:

    This update for sqlite3 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:2657-1
    ReleasedMon Oct 14 17:04:07 2019
    SummarySecurity update for dhcp
    Typesecurity
    Severitymoderate
    References1089524,1134078,1136572,CVE-2019-6470
    Description:

    This update for dhcp fixes the following issues:
    Secuirty issue fixed:


    Bug fixes:


    Advisory IDSUSE-RU-2019:2693-1
    ReleasedWed Oct 16 16:43:30 2019
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References1142343
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-SU-2019:2730-1
    ReleasedMon Oct 21 16:04:57 2019
    SummarySecurity update for procps
    Typesecurity
    Severityimportant
    References1092100,1121753,CVE-2018-1122,CVE-2018-1123,CVE-2018-1124,CVE-2018-1125,CVE-2018-1126
    Description:

    This update for procps fixes the following issues:
    procps was updated to 3.3.15. (bsc#1092100)
    Following security issues were fixed:



    Also this non-security issue was fixed:

    The update to 3.3.15 contains the following fixes:


    Advisory IDSUSE-SU-2019:2810-1
    ReleasedTue Oct 29 14:56:44 2019
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1131314,1131553,1152308,CVE-2019-16884
    Description:

    This update for runc fixes the following issues:
    Security issue fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:2997-1
    ReleasedMon Nov 18 15:16:38 2019
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
    Description:

    This update for ncurses fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2019:3061-1
    ReleasedMon Nov 25 17:34:22 2019
    SummarySecurity update for gcc9
    Typesecurity
    Severitymoderate
    References1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
    Description:



    This update includes the GNU Compiler Collection 9.
    A full changelog is provided by the GCC team on:
    https://www.gnu.org/software/gcc/gcc-9/changes.html

    The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages.
    To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it.

    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:3086-1
    ReleasedThu Nov 28 10:02:24 2019
    SummarySecurity update for libidn2
    Typesecurity
    Severitymoderate
    References1154884,1154887,CVE-2019-12290,CVE-2019-18224
    Description:

    This update for libidn2 to version 2.2.0 fixes the following issues:


    Advisory IDSUSE-SU-2019:3096-1
    ReleasedThu Nov 28 16:48:21 2019
    SummarySecurity update for cloud-init
    Typesecurity
    Severitymoderate
    References1099358,1129124,1136440,1142988,1144363,1151488,1154092,CVE-2019-0816
    Description:

    This update for cloud-init to version 19.2 fixes the following issues:
    Security issue fixed:


    Non-security issues fixed:


    Advisory IDSUSE-RU-2019:3173-1
    ReleasedWed Dec 4 20:22:45 2019
    SummaryRecommended update for growpart, growpart-rootgrow
    Typerecommended
    Severitymoderate
    References1154357,ECO-550
    Description:

    This update for growpart, growpart-rootgrow contains the following fixes:
    growpart:


    growpart-rootgrow:


    Advisory IDSUSE-SU-2020:35-1
    ReleasedWed Jan 8 09:06:32 2020
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork
    Typesecurity
    Severitymoderate
    References1122469,1143349,1150397,1152308,1153367,1158590,CVE-2019-16884
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
    Security issue fixed:


    Bug fixes:


    Advisory IDSUSE-RU-2020:119-1
    ReleasedThu Jan 16 15:42:39 2020
    SummaryRecommended update for python-jsonpatch
    Typerecommended
    Severitymoderate
    References1160978
    Description:

    This update for python-jsonpatch fixes the following issues:


    Advisory IDSUSE-RU-2020:225-1
    ReleasedFri Jan 24 06:49:07 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:245-1
    ReleasedTue Jan 28 09:42:30 2020
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1155376,1156139,1157894,1161132,1161133
    Description:

    This update for cloud-init fixes the following issues:


    Advisory IDSUSE-SU-2020:440-1
    ReleasedMon Feb 24 15:31:42 2020
    SummarySecurity update for python-azure-agent
    Typesecurity
    Severitymoderate
    References1127838,CVE-2019-0804
    Description:

    This update for python-azure-agent fixes the following issues:
    python-azure-agent was updated to version 2.2.45 (jsc#ECO-80)


    From 2.2.44 update:

    From 2.2.42 update:

    From 2.2.41 update:

    From 2.2.40 update:

    From 2.2.38 update:
    Security issue fixed:
    From 2.2.37 update:


    Advisory IDSUSE-RU-2020:521-1
    ReleasedThu Feb 27 18:08:56 2020
    SummaryRecommended update for c-ares
    Typerecommended
    Severitymoderate
    References1125306,1159006
    Description:

    This update for c-ares fixes the following issues:
    c-ares version update to 1.15.0:



    Advisory IDSUSE-RU-2020:525-1
    ReleasedFri Feb 28 11:49:36 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1164562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:655-1
    ReleasedThu Mar 12 13:17:03 2020
    SummaryRecommended update for growpart
    Typerecommended
    Severitymoderate
    References1164736
    Description:

    This update for growpart fixes the following issues:


    Advisory IDSUSE-RU-2020:689-1
    ReleasedFri Mar 13 17:09:01 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:


    This update for PAM fixes the following issue:


    Advisory IDSUSE-RU-2020:690-1
    ReleasedFri Mar 13 17:09:28 2020
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1166334
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-SU-2020:751-1
    ReleasedMon Mar 23 16:32:44 2020
    SummarySecurity update for cloud-init
    Typesecurity
    Severitymoderate
    References1162936,1162937,1163178,CVE-2020-8631,CVE-2020-8632
    Description:

    This update for cloud-init fixes the following security issues:


    Advisory IDSUSE-RU-2020:917-1
    ReleasedFri Apr 3 15:02:25 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2020:944-1
    ReleasedTue Apr 7 15:49:33 2020
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1149954,1160452,CVE-2019-19921
    Description:

    This update for runc fixes the following issues:
    runc was updated to v1.0.0~rc10


    Advisory IDSUSE-SU-2020:948-1
    ReleasedWed Apr 8 07:44:21 2020
    SummarySecurity update for gmp, gnutls, libnettle
    Typesecurity
    Severitymoderate
    References1152692,1155327,1166881,1168345,CVE-2020-11501
    Description:

    This update for gmp, gnutls, libnettle fixes the following issues:
    Security issue fixed:


    FIPS related bugfixes:


    Advisory IDSUSE-SU-2020:693-1
    ReleasedWed Apr 8 14:11:14 2020
    SummarySecurity update for wireshark
    Typesecurity
    Severitymoderate
    References1093733,1094301,1101776,1101777,1101786,1101788,1101791,1101794,1101800,1101802,1101804,1101810,1106514,1111647,1117740,1121231,1121232,1121233,1121234,1121235,1127367,1127369,1127370,1131941,1131945,1136021,1141980,1150690,1156288,1158505,1161052,1165241,1165710,957624,CVE-2018-11354,CVE-2018-11355,CVE-2018-11356,CVE-2018-11357,CVE-2018-11358,CVE-2018-11359,CVE-2018-11360,CVE-2018-11361,CVE-2018-11362,CVE-2018-12086,CVE-2018-14339,CVE-2018-14340,CVE-2018-14341,CVE-2018-14342,CVE-2018-14343,CVE-2018-14344,CVE-2018-14367,CVE-2018-14368,CVE-2018-14369,CVE-2018-14370,CVE-2018-16056,CVE-2018-16057,CVE-2018-16058,CVE-2018-18225,CVE-2018-18226,CVE-2018-18227,CVE-2018-19622,CVE-2018-19623,CVE-2018-19624,CVE-2018-19625,CVE-2018-19626,CVE-2018-19627,CVE-2018-19628,CVE-2019-10894,CVE-2019-10895,CVE-2019-10896,CVE-2019-10897,CVE-2019-10898,CVE-2019-10899,CVE-2019-10900,CVE-2019-10901,CVE-2019-10902,CVE-2019-10903,CVE-2019-13619,CVE-2019-16319,CVE-2019-19553,CVE-2019-5716,CVE-2019-5717,CVE-2019-5718,CVE-2019-5719,CVE-2019-5721,CVE-2019-9208,CVE-2019-9209,CVE-2019-9214,CVE-2020-7044,CVE-2020-9428,CVE-2020-9429,CVE-2020-9430,CVE-2020-9431
    Description:

    This update for wireshark and libmaxminddb fixes the following issues:
    Update wireshark to new major version 3.2.2 and introduce libmaxminddb for GeoIP support (bsc#1156288).
    New features include:


    Advisory IDSUSE-RU-2020:1037-1
    ReleasedMon Apr 20 10:49:39 2020
    SummaryRecommended update for python-pytest
    Typerecommended
    Severitylow
    References1002895,1107105,1138666,1167732
    Description:


    This update fixes the following issues:
    New python-pytest versions are provided.
    In Basesystem:


    In Python2:


    Advisory IDSUSE-RU-2020:1056-1
    ReleasedTue Apr 21 16:26:22 2020
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1099358,1144881,1145622,1148645,1163178,1165296
    Description:

    This update for cloud-init contains the following fixes:




    Advisory IDSUSE-RU-2020:1112-1
    ReleasedFri Apr 24 16:44:20 2020
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1170347
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-RU-2020:1222-1
    ReleasedFri May 8 08:23:57 2020
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1167601,1167602
    Description:

    This update for python-azure-agent fixes the following issues:


    Advisory IDSUSE-RU-2020:1226-1
    ReleasedFri May 8 10:51:05 2020
    SummaryRecommended update for gcc9
    Typerecommended
    Severitymoderate
    References1149995,1152590,1167898
    Description:

    This update for gcc9 fixes the following issues:
    This update ships the GCC 9.3 release.


    Advisory IDSUSE-RU-2020:1261-1
    ReleasedTue May 12 18:40:18 2020
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1168806
    Description:

    This update for hwdata fixes the following issues:
    Update from version 0.320 to version 0.324 (bsc#1168806)


    Advisory IDSUSE-RU-2020:1266-1
    ReleasedWed May 13 10:20:54 2020
    SummaryRecommended update for jq
    Typerecommended
    Severitymoderate
    References1170838
    Description:

    This update for jq fixes the following issues:
    jq was updated to version 1.6:

    '.' for the program, regardless of stdin/stdout
  • fix: Make sorting stable regardless of qsort.


  • Advisory IDSUSE-SU-2020:1294-1
    ReleasedMon May 18 07:38:36 2020
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1154661,1169512,CVE-2019-18218
    Description:

    This update for file fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-RU-2020:1328-1
    ReleasedMon May 18 17:16:04 2020
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1155271
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-SU-2020:1353-1
    ReleasedWed May 20 13:02:32 2020
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1079603,1091109,CVE-2018-6942
    Description:

    This update for freetype2 to version 2.10.1 fixes the following issues:
    Security issue fixed:


    Non-security issues fixed:









    Advisory IDSUSE-SU-2020:1657-1
    ReleasedThu Jun 18 10:49:53 2020
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork
    Typesecurity
    Severitymoderate
    References1172377,CVE-2020-13401
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
    Docker was updated to 19.03.11-ce runc was updated to version 1.0.0-rc10 containerd was updated to version 1.2.13


    Advisory IDSUSE-RU-2020:1852-1
    ReleasedMon Jul 6 16:50:23 2020
    SummaryRecommended update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts
    Typerecommended
    Severitymoderate
    References1169444
    Description:

    This update for fontforge, ghostscript-fonts, ttf-converter, xorg-x11-fonts fixes the following issues:
    Changes in fontforge:


    Changes in ttf-converter:

    --shift-unicode-values: When passed 3 comma separated numbers a,b,c this shifts the unicode values of glyphs between a and b (both included) by adding c. Can be used more than once. * Add --bitmapTransform parameter to transform bitmap glyphs. (bsc#1169444) When used, all glyphs are modified with the transformation function and values passed as parameters. The parameter has three values separated by commas: fliph|flipv|rotate90cw|rotate90ccw|rotate180|skew|transmove,xoff,yoff * Add support to convert bitmap fonts (bsc#1169444) * Rename MediumItalic subfamily to Medium Italic * Show some more information when removing duplicated glyphs * Add a --force-monospaced argument instead of hardcoding font names * Convert `BoldCond` subfamily to `Bold Condensed` * Fixes for Monospaced fonts and force the Nimbus Mono L font to be Monospaced. (bsc#1169444 #c41) * Add a --version argument * Fix subfamily names so the converted font's subfamily match the original ones. (bsc#1169444 #c41)
    Changes in xorg-x11-fonts:

    Changes in ghostscript-fonts:


    Advisory IDSUSE-RU-2020:1885-1
    ReleasedFri Jul 10 14:54:22 2020
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1170154,1171546,1171995
    Description:

    This update for cloud-init contains the following fixes:


    + Explicitly test for netconfig version 1 as well as 2.
    + Handle netconfig v2 device configurations (bsc#1171546, bsc#1171995)


    Advisory IDSUSE-RU-2020:1986-1
    ReleasedTue Jul 21 16:06:29 2020
    SummaryRecommended update for openvswitch
    Typerecommended
    Severitymoderate
    References1172861,1172929
    Description:

    This update for openvswitch fixes the following issues:


    Advisory IDSUSE-RU-2020:2000-1
    ReleasedWed Jul 22 09:04:41 2020
    SummaryRecommended update for efivar
    Typerecommended
    Severityimportant
    References1100077,1101023,1120862,1127544
    Description:

    This update for efivar fixes the following issues:


    Advisory IDSUSE-RU-2020:2083-1
    ReleasedThu Jul 30 10:27:59 2020
    SummaryRecommended update for diffutils
    Typerecommended
    Severitymoderate
    References1156913
    Description:

    This update for diffutils fixes the following issue:


    Advisory IDSUSE-RU-2020:2127-1
    ReleasedWed Aug 5 10:28:23 2020
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severityimportant
    References1173866
    Description:

    This update for python-azure-agent fixes the following issues:


    Advisory IDSUSE-RU-2020:2148-1
    ReleasedThu Aug 6 13:36:17 2020
    SummaryRecommended update for ca-certificates-mozilla
    Typerecommended
    Severityimportant
    References1174673
    Description:

    This update for ca-certificates-mozilla fixes the following issues:
    Update to 2.42 state of the Mozilla NSS Certificate store (bsc#1174673)
    Removed CAs:
    * AddTrust External CA Root * AddTrust Class 1 CA Root * LuxTrust Global Root 2 * Staat der Nederlanden Root CA - G2 * Symantec Class 1 Public Primary Certification Authority - G4 * Symantec Class 2 Public Primary Certification Authority - G4 * VeriSign Class 3 Public Primary Certification Authority - G3
    Added CAs:
    * certSIGN Root CA G2 * e-Szigno Root CA 2017 * Microsoft ECC Root Certificate Authority 2017 * Microsoft RSA Root Certificate Authority 2017


    Advisory IDSUSE-RU-2020:2219-1
    ReleasedWed Aug 12 15:47:42 2020
    SummaryRecommended update for supportutils-plugin-suse-public-cloud and python3-azuremetadata
    Typerecommended
    Severitymoderate
    References1170475,1170476,1173238,1173240,1173357,1174618,1174847
    Description:

    This update for supportutils-plugin-suse-public-cloud and python3-azuremetadata fixes the following issues:
    supportutils-plugin-suse-public-cloud:


    python3-azuremetadata:


    Advisory IDSUSE-RU-2020:2349-1
    ReleasedWed Aug 26 17:15:21 2020
    SummaryRecommended update for hyper-v
    Typerecommended
    Severitymoderate
    References1093910,1174443,1174444
    Description:

    This update for hyper-v fixes the following issues:


    Advisory IDSUSE-RU-2020:2378-1
    ReleasedFri Aug 28 14:52:31 2020
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1175198
    Description:

    This update for python-azure-agent contains the following fix:


    Advisory IDSUSE-RU-2020:2380-1
    ReleasedFri Aug 28 14:54:08 2020
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severitymoderate
    References1175250,1175251
    Description:

    This update for supportutils-plugin-suse-public-cloud contains the following fix:


    Advisory IDSUSE-RU-2020:2440-1
    ReleasedTue Sep 1 22:14:33 2020
    SummaryRecommended update for libmaxminddb
    Typerecommended
    Severitymoderate
    References1175006
    Description:

    This update for libmaxminddb fixes the following issues:


    Advisory IDSUSE-RU-2020:2735-1
    ReleasedThu Sep 24 13:32:25 2020
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1173034
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2020:2782-1
    ReleasedTue Sep 29 11:40:22 2020
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severityimportant
    References1176932
    Description:

    This update for systemd-rpm-macros fixes the following issues:



    Advisory IDSUSE-RU-2020:2796-1
    ReleasedTue Sep 29 14:30:55 2020
    SummaryRecommended update for hyper-v
    Typerecommended
    Severitymoderate
    References1116957
    Description:

    This update for hyper-v fixes the following issues:


    Advisory IDSUSE-RU-2020:2825-1
    ReleasedFri Oct 2 08:44:28 2020
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1170347,1176759
    Description:

    This update for suse-build-key fixes the following issues:



    Advisory IDSUSE-RU-2020:2863-1
    ReleasedTue Oct 6 09:28:41 2020
    SummaryRecommended update for efivar
    Typerecommended
    Severitymoderate
    References1175989
    Description:

    This update for efivar fixes the following issues:


    Advisory IDSUSE-RU-2020:2945-1
    ReleasedFri Oct 16 10:06:06 2020
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitycritical
    References1176368,1176369,1177161,1177257
    Description:

    This update for python-azure-agent fixes the following issues:


    Update to version 2.2.49.2 (bsc#1176368, bsc#1176369)
    + Do not use --unit with systemd-cgls (#1910) + Report processes that do not belong to the agent's cgroup (#1908) + Use controller mount point for extension cgroup path (#1899) + Improvements in setup of cgroups (#1896) + Remove ExtensionsMetricsData and per-process Memory data (#1884) + Fix return value of start_extension_command (#1927) + Remove import * (#1900) + Fix flaky ExtensionCleanupTest class (#1898) + Fix codecov badge (#1883) + Changed codecov to run on py3.8 (#1875) + Update documentation on /dev/random (#1909) + Mount options are in mount(8) (#1893) + Remove ssh host key thumbprint in report ready (#1913) + Emit AutoUpdate value at service start only (#1907) + Add logging for version mismatch (#1895) + Send telemetry event if libdir changes (#1897) + Add log collector utility (#1847) + Move AutoUpdate reporting to HeartBeat event (#1919) + Removing infinite download of extension manifest without a new GS (#1874) + Fix wrongful dir deletion (#1873) + Fix the cleanup-outdated-handlers to only delete handlers that are not present in the GS (#1889) + Expose periods of environment thread in waagent.conf (#1891) + Added user @kevinclark19a as Contributor. (#1906)

    + [#1741] Do not update goal state when refreshing the host plugin + [#1731] Fix upgrade sequence when update command fails + [#1725] Initialize CPU usage + [#1716, #1737] Added UTC logging and correcting the format + [#1651, #1729] Start sending PerformanceCounter metrics and additional memory information for Cgroups


    Advisory IDSUSE-SU-2020:2947-1
    ReleasedFri Oct 16 15:23:07 2020
    SummarySecurity update for gcc10, nvptx-tools
    Typesecurity
    Severitymoderate
    References1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844
    Description:

    This update for gcc10, nvptx-tools fixes the following issues:
    This update provides the GCC10 compiler suite and runtime libraries.
    The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by the gcc10 variants.
    The new compiler variants are available with '-10' suffix, you can specify them via:
    CC=gcc-10 CXX=g++-10
    or similar commands.
    For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
    Changes in nvptx-tools:


    Advisory IDSUSE-RU-2020:2958-1
    ReleasedTue Oct 20 12:24:55 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:2983-1
    ReleasedWed Oct 21 15:03:03 2020
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1176123
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-SU-2020:2995-1
    ReleasedThu Oct 22 10:03:09 2020
    SummarySecurity update for freetype2
    Typesecurity
    Severityimportant
    References1177914,CVE-2020-15999
    Description:

    This update for freetype2 fixes the following issues:


    Advisory IDSUSE-RU-2020:3059-1
    ReleasedWed Oct 28 06:11:23 2020
    SummaryRecommended update for sysconfig
    Typerecommended
    Severitymoderate
    References1173391,1176285,1176325
    Description:

    This update for sysconfig fixes the following issues:


    Advisory IDSUSE-RU-2020:3157-1
    ReleasedWed Nov 4 15:37:05 2020
    SummaryRecommended update for ca-certificates-mozilla
    Typerecommended
    Severitymoderate
    References1177864
    Description:

    This update for ca-certificates-mozilla fixes the following issues:
    The SSL Root CA store was updated to the 2.44 state of the Mozilla NSS Certificate store (bsc#1177864)


    - EE Certification Centre Root CA - Taiwan GRCA

    - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority


    Advisory IDSUSE-RU-2020:3323-1
    ReleasedFri Nov 13 15:25:55 2020
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1174443,1174444,1177526
    Description:

    This update for cloud-init contains the following fixes:


    Update to version 20.2 (bsc#1174443, bsc#1174444)
    + doc/format: reference make-mime.py instead of an inline script (#334) + Add docs about creating parent folders (#330) [Adrian Wilkins] + DataSourceNoCloud/OVF: drop claim to support FTP (#333) (LP: #1875470) + schema: ignore spurious pylint error (#332) + schema: add json schema for write_files module (#152) + BSD: find_devs_with_ refactoring (#298) [Gonéri Le Bouder] + nocloud: drop work around for Linux 2.6 (#324) [Gonéri Le Bouder] + cloudinit: drop dependencies on unittest2 and contextlib2 (#322) + distros: handle a potential mirror filtering error case (#328) + log: remove unnecessary import fallback logic (#327) + .travis.yml: don't run integration test on ubuntu/* branches (#321) + More unit test documentation (#314) + conftest: introduce disable_subp_usage autouse fixture (#304) + YAML align indent sizes for docs readability (#323) [Tak Nishigori] + network_state: add missing space to log message (#325) + tests: add missing mocks for get_interfaces_by_mac (#326) (LP: #1873910) + test_mounts: expand happy path test for both happy paths (#319) + cc_mounts: fix incorrect format specifiers (#316) (LP: #1872836) + swap file 'size' being used before checked if str (#315) [Eduardo Otubo] + HACKING.rst: add pytest version gotchas section (#311) + docs: Add steps to re-run cloud-id and cloud-init (#313) [Joshua Powers] + readme: OpenBSD is now supported (#309) [Gonéri Le Bouder] + net: ignore 'renderer' key in netplan config (#306) (LP: #1870421) + Add support for NFS/EFS mounts (#300) [Andrew Beresford] (LP: #1870370) + openbsd: set_passwd should not unlock user (#289) [Gonéri Le Bouder] + tools/.github-cla-signers: add beezly as CLA signer (#301) + util: remove unnecessary lru_cache import fallback (#299) + HACKING.rst: reorganise/update CLA signature info (#297) + distros: drop leading/trailing hyphens from mirror URL labels (#296) + HACKING.rst: add note about variable annotations (#295) + CiTestCase: stop using and remove sys_exit helper (#283) + distros: replace invalid characters in mirror URLs with hyphens (#291) (LP: #1868232) + rbxcloud: gracefully handle arping errors (#262) [Adam Dobrawy] + Fix cloud-init ignoring some misdeclared mimetypes in user-data. [Kurt Garloff] + net: ubuntu focal prioritize netplan over eni even if both present (#267) (LP: #1867029) + cloudinit: refactor util.is_ipv4 to net.is_ipv4_address (#292) + net/cmdline: replace type comments with annotations (#294) + HACKING.rst: add Type Annotations design section (#293) + net: introduce is_ip_address function (#288) + CiTestCase: remove now-unneeded parse_and_read helper method (#286) + .travis.yml: allow 30 minutes of inactivity in cloud tests (#287) + sources/tests/test_init: drop use of deprecated inspect.getargspec (#285) + setup.py: drop NIH check_output implementation (#282) + Identify SAP Converged Cloud as OpenStack [Silvio Knizek] + add Openbsd support (#147) [Gonéri Le Bouder] + HACKING.rst: add examples of the two test class types (#278) + VMWware: support to update guest info gc status if enabled (#261) [xiaofengw-vmware] + Add lp-to-git mapping for kgarloff (#279) + set_passwords: avoid chpasswd on BSD (#268) [Gonéri Le Bouder] + HACKING.rst: add Unit Testing design section (#277) + util: read_cc_from_cmdline handle urlencoded yaml content (#275) + distros/tests/test_init: add tests for _get_package_mirror_info (#272) + HACKING.rst: add links to new Code Review Process doc (#276) + freebsd: ensure package update works (#273) [Gonéri Le Bouder] + doc: introduce Code Review Process documentation (#160) + tools: use python3 (#274) + cc_disk_setup: fix RuntimeError (#270) (LP: #1868327) + cc_apt_configure/util: combine search_for_mirror implementations (#271) + bsd: boottime does not depend on the libc soname (#269) [Gonéri Le Bouder] + test_oracle,DataSourceOracle: sort imports (#266) + DataSourceOracle: update .network_config docstring (#257) + cloudinit/tests: remove unneeded with_logs configuration (#263) + .travis.yml: drop stale comment (#255) + .gitignore: add more common directories (#258) + ec2: render network on all NICs and add secondary IPs as static (#114) (LP: #1866930) + ec2 json validation: fix the reference to the 'merged_cfg' key (#256) [Paride Legovini] + releases.yaml: quote the Ubuntu version numbers (#254) [Paride Legovini] + cloudinit: remove six from packaging/tooling (#253) + util/netbsd: drop six usage (#252) + workflows: introduce stale pull request workflow (#125) + cc_resolv_conf: introduce tests and stabilise output across Python versions (#251) + fix minor issue with resolv_conf template (#144) [andreaf74] + doc: CloudInit also support NetBSD (#250) [Gonéri Le Bouder] + Add Netbsd support (#62) [Gonéri Le Bouder] + tox.ini: avoid substition syntax that causes a traceback on xenial (#245) + Add pub_key_ed25519 to cc_phone_home (#237) [Daniel Hensby] + Introduce and use of a list of GitHub usernames that have signed CLA (#244) + workflows/cla.yml: use correct username for CLA check (#243) + tox.ini: use xenial version of jsonpatch in CI (#242) + workflows: CLA validation altered to fail status on pull_request (#164) + tox.ini: bump pyflakes version to 2.1.1 (#239) + cloudinit: move to pytest for running tests (#211) + instance-data: add cloud-init merged_cfg and sys_info keys to json (#214) (LP: #1865969) + ec2: Do not fallback to IMDSv1 on EC2 (#216) + instance-data: write redacted cfg to instance-data.json (#233) (LP: #1865947) + net: support network-config:disabled on the kernel commandline (#232) (LP: #1862702) + ec2: only redact token request headers in logs, avoid altering request (#230) (LP: #1865882) + docs: typo fixed: dta → data [Alexey Vazhnov] + Fixes typo on Amazon Web Services (#217) [Nick Wales] + Fix docs for OpenStack DMI Asset Tag (#228) [Mark T. Voelker] (LP: #1669875) + Add physical network type: cascading to openstack helpers (#200) [sab-systems] + tests: add focal integration tests for ubuntu (#225)


    Advisory IDSUSE-RU-2020:3462-1
    ReleasedFri Nov 20 13:14:35 2020
    SummaryRecommended update for pam and sudo
    Typerecommended
    Severitymoderate
    References1174593,1177858,1178727
    Description:

    This update for pam and sudo fixes the following issue:
    pam:


    sudo:


    Advisory IDSUSE-SU-2020:3478-1
    ReleasedMon Nov 23 09:33:17 2020
    SummarySecurity update for c-ares
    Typesecurity
    Severitymoderate
    References1178882,CVE-2020-8277
    Description:

    This update for c-ares fixes the following issues:


    Advisory IDSUSE-RU-2020:3608-1
    ReleasedWed Dec 2 18:16:12 2020
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1177526,1179150,1179151
    Description:

    This update for cloud-init contains the following fixes:




    Advisory IDSUSE-RU-2020:3616-1
    ReleasedThu Dec 3 10:56:12 2020
    SummaryRecommended update for c-ares
    Typerecommended
    Severitymoderate
    References1178882
    Description:




    Advisory IDSUSE-RU-2020:3620-1
    ReleasedThu Dec 3 17:03:55 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:3791-1
    ReleasedMon Dec 14 17:39:19 2020
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gzip fixes the following issue:


    Advisory IDSUSE-OU-2020:3795-1
    ReleasedMon Dec 14 17:43:26 2020
    SummaryOptional update for systemd-rpm-macros
    Typeoptional
    Severitylow
    References1059627,1178481,1179020
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2020:3942-1
    ReleasedTue Dec 29 12:22:01 2020
    SummaryRecommended update for libidn2
    Typerecommended
    Severitymoderate
    References1180138
    Description:

    This update for libidn2 fixes the following issues:


    Advisory IDSUSE-RU-2021:220-1
    ReleasedTue Jan 26 14:00:51 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for keyutils fixes the following issues:


    Advisory IDSUSE-RU-2021:292-1
    ReleasedWed Feb 3 11:46:32 2021
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1180719,1181600,1181601
    Description:

    This update for python-azure-agent contains the following fix:


    Advisory IDSUSE-RU-2021:293-1
    ReleasedWed Feb 3 12:52:34 2021
    SummaryRecommended update for gmp
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-OU-2021:339-1
    ReleasedMon Feb 8 13:16:07 2021
    SummaryOptional update for pam
    Typeoptional
    Severitylow
    References
    Description:

    This update for pam fixes the following issues:


    This patch is optional to be installed - it doesn't fix any bugs.


    Advisory IDSUSE-RU-2021:421-1
    ReleasedWed Feb 10 12:05:23 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitylow
    References1180422,1180482
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-SU-2021:435-1
    ReleasedThu Feb 11 14:47:25 2021
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork
    Typesecurity
    Severityimportant
    References1174075,1176708,1178801,1178969,1180243,1180401,1181730,1181732,CVE-2020-15257,CVE-2021-21284,CVE-2021-21285
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
    Security issues fixed:


    Non-security issues fixed:













    Advisory IDSUSE-RU-2021:516-1
    ReleasedThu Feb 18 14:42:51 2021
    SummaryRecommended update for docker, golang-github-docker-libnetwork
    Typerecommended
    Severitymoderate
    References1178801,1180401,1182168
    Description:

    This update for docker, golang-github-docker-libnetwork fixes the following issues:


    Advisory IDSUSE-RU-2021:526-1
    ReleasedFri Feb 19 12:46:27 2021
    SummaryRecommended update for python-distro
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for python-distro fixes the following issues:
    Upgrade from version 1.2.0 to 1.5.0 (jsc#ECO-3212)




    Advisory IDSUSE-RU-2021:571-1
    ReleasedTue Feb 23 16:11:33 2021
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1180176
    Description:

    This update for cloud-init contains the following fixes:



    Advisory IDSUSE-SU-2021:654-1
    ReleasedFri Feb 26 20:01:10 2021
    SummarySecurity update for python-Jinja2
    Typesecurity
    Severityimportant
    References1181944,1182244,CVE-2020-28493
    Description:

    This update for python-Jinja2 fixes the following issues:


    Advisory IDSUSE-RU-2021:656-1
    ReleasedMon Mar 1 09:34:21 2021
    SummaryRecommended update for protobuf
    Typerecommended
    Severitymoderate
    References1177127
    Description:

    This update for protobuf fixes the following issues:


    Advisory IDSUSE-RU-2021:707-1
    ReleasedThu Mar 4 09:19:36 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1177039
    Description:

    This update for systemd-rpm-macros fixes the following issues:




    Advisory IDSUSE-RU-2021:784-1
    ReleasedMon Mar 15 11:19:08 2021
    SummaryRecommended update for efivar
    Typerecommended
    Severitymoderate
    References1181967
    Description:

    This update for efivar fixes the following issues:


    Advisory IDSUSE-RU-2021:795-1
    ReleasedTue Mar 16 10:28:02 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References1182661,1183012,1183051
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2021:880-1
    ReleasedFri Mar 19 04:14:38 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitylow
    References1170160,1182482
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2021:924-1
    ReleasedTue Mar 23 10:00:49 2021
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094
    Description:

    This update for filesystem the following issues:


    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2021:960-1
    ReleasedMon Mar 29 11:16:28 2021
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1181283
    Description:

    This update for cloud-init fixes the following issues:


    Advisory IDSUSE-SU-2021:974-1
    ReleasedMon Mar 29 19:31:27 2021
    SummarySecurity update for tar
    Typesecurity
    Severitylow
    References1181131,CVE-2021-20193
    Description:

    This update for tar fixes the following issues:
    CVE-2021-20193: Memory leak in read_header() in list.c (bsc#1181131)


    Advisory IDSUSE-RU-2021:985-1
    ReleasedTue Mar 30 14:43:43 2021
    SummaryRecommended update for the Azure SDK and CLI
    Typerecommended
    Severitymoderate
    References1125671,1140565,1154393,1174514,1175289,1176784,1176785,1178168,CVE-2020-14343,CVE-2020-25659
    Description:


    This update for the Azure SDK and CLI adds support for the AHB (Azure Hybrid Benefit). (bsc#1176784, jsc#ECO=3105)


    Advisory IDSUSE-RU-2021:1018-1
    ReleasedTue Apr 6 14:29:13 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1180713
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1169-1
    ReleasedTue Apr 13 15:01:42 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitylow
    References1181976
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1289-1
    ReleasedWed Apr 21 14:02:46 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1177047
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1451-1
    ReleasedFri Apr 30 08:08:45 2021
    SummaryRecommended update for dhcp
    Typerecommended
    Severitymoderate
    References1185157
    Description:

    This update for dhcp fixes the following issues:


    Advisory IDSUSE-RU-2021:1462-1
    ReleasedFri Apr 30 14:54:23 2021
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1181283,1184085
    Description:

    This update for cloud-init fixes the following issues:


    Advisory IDSUSE-RU-2021:1549-1
    ReleasedMon May 10 13:48:00 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1185417
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1643-1
    ReleasedWed May 19 13:51:48 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1181443,1184358,1185562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:1675-1
    ReleasedThu May 20 15:00:23 2021
    SummaryRecommended update for snappy
    Typerecommended
    Severitymoderate
    References1080040,1184507
    Description:

    This update for snappy fixes the following issues:
    Update from version 1.1.3 to 1.1.8


    Advisory IDSUSE-SU-2021:1841-1
    ReleasedWed Jun 2 16:30:17 2021
    SummarySecurity update for dhcp
    Typesecurity
    Severityimportant
    References1186382,CVE-2021-25217
    Description:

    This update for dhcp fixes the following issues:


    Advisory IDSUSE-SU-2021:1859-1
    ReleasedFri Jun 4 09:02:38 2021
    SummarySecurity update for python-py
    Typesecurity
    Severitymoderate
    References1179805,1184505,CVE-2020-29651
    Description:

    This update for python-py fixes the following issues:


    Advisory IDSUSE-RU-2021:1861-1
    ReleasedFri Jun 4 09:59:40 2021
    SummaryRecommended update for gcc10
    Typerecommended
    Severitymoderate
    References1029961,1106014,1178577,1178624,1178675,1182016
    Description:

    This update for gcc10 fixes the following issues:


    Advisory IDSUSE-RU-2021:1935-1
    ReleasedThu Jun 10 10:45:09 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for gzip fixes the following issue:


    Advisory IDSUSE-RU-2021:1941-1
    ReleasedThu Jun 10 10:49:52 2021
    SummaryRecommended update for sysconfig
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for sysconfig fixes the following issue:


    Advisory IDSUSE-RU-2021:1950-1
    ReleasedThu Jun 10 14:42:00 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1170160,1182482,1185697
    Description:

    This update for hwdata fixes the following issues:



    Advisory IDSUSE-SU-2021:1954-1
    ReleasedFri Jun 11 10:45:09 2021
    SummarySecurity update for containerd, docker, runc
    Typesecurity
    Severityimportant
    References1168481,1175081,1175821,1181594,1181641,1181677,1181730,1181732,1181749,1182451,1182476,1182947,1183024,1183855,1184768,1184962,1185405,CVE-2021-21284,CVE-2021-21285,CVE-2021-21334,CVE-2021-30465
    Description:

    This update for containerd, docker, runc fixes the following issues:
    Docker was updated to 20.10.6-ce (bsc#1184768, bsc#1182947, bsc#1181594)


    runc was updated to v1.0.0~rc93 (bsc#1182451, bsc#1175821 bsc#1184962).

    containerd was updated to v1.4.4


    Advisory IDSUSE-SU-2021:2012-1
    ReleasedFri Jun 18 09:15:13 2021
    SummarySecurity update for python-urllib3
    Typesecurity
    Severityimportant
    References1187045,CVE-2021-33503
    Description:

    This update for python-urllib3 fixes the following issues:


    Advisory IDSUSE-RU-2021:2096-1
    ReleasedMon Jun 21 13:35:38 2021
    SummaryRecommended update for python-six
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for python-six fixes the following issue:


    Advisory IDSUSE-SU-2021:2106-1
    ReleasedMon Jun 21 19:26:19 2021
    SummarySecurity update for salt
    Typesecurity
    Severitycritical
    References1171257,1176293,1179831,1181368,1182281,1182293,1182382,1185092,1185281,1186674,CVE-2018-15750,CVE-2018-15751,CVE-2020-11651,CVE-2020-11652,CVE-2020-25592,CVE-2021-25315,CVE-2021-31607
    Description:

    This update for salt fixes the following issues:
    Update to Salt release version 3002.2 (jsc#ECO-3212, jsc#SLE-18033, jsc#SLE-18028)


    Advisory IDSUSE-RU-2021:2173-1
    ReleasedMon Jun 28 14:59:45 2021
    SummaryRecommended update for automake
    Typerecommended
    Severitymoderate
    References1040589,1047218,1182604,1185540,1186049
    Description:

    This update for automake fixes the following issues:


    This update for pcre fixes the following issues:

    This update for brp-check-suse fixes the following issues:


    Advisory IDSUSE-RU-2021:2191-1
    ReleasedMon Jun 28 18:38:12 2021
    SummaryRecommended update for patterns-microos
    Typerecommended
    Severitymoderate
    References1186791
    Description:

    This update for patterns-microos provides the following fix:


    Advisory IDSUSE-RU-2021:2193-1
    ReleasedMon Jun 28 18:38:43 2021
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1184124
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-SU-2021:2196-1
    ReleasedTue Jun 29 09:41:39 2021
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1175448,1175449,CVE-2020-24370,CVE-2020-24371
    Description:

    This update for lua53 fixes the following issues:
    Update to version 5.3.6:


    Advisory IDSUSE-RU-2021:2286-1
    ReleasedFri Jul 9 17:38:53 2021
    SummaryRecommended update for dosfstools
    Typerecommended
    Severitymoderate
    References1172863
    Description:

    This update for dosfstools fixes the following issue:


    Advisory IDSUSE-SU-2021:2320-1
    ReleasedWed Jul 14 17:01:06 2021
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2021:2395-1
    ReleasedMon Jul 19 12:08:34 2021
    SummaryRecommended update for efivar
    Typerecommended
    Severitymoderate
    References1187386
    Description:

    This update for efivar provides the following fix:


    Advisory IDSUSE-SU-2021:2412-1
    ReleasedTue Jul 20 15:25:21 2021
    SummarySecurity update for containerd
    Typesecurity
    Severitymoderate
    References1188282,CVE-2021-32760
    Description:

    This update for containerd fixes the following issues:


    Advisory IDSUSE-RU-2021:2447-1
    ReleasedThu Jul 22 08:26:29 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1186749,1187948
    Description:

    This update for hwdata fixes the following issue:


    Advisory IDSUSE-RU-2021:2464-1
    ReleasedFri Jul 23 14:20:23 2021
    SummaryRecommended update for shim
    Typerecommended
    Severitymoderate
    References1185232,1185261,1185441,1185464,1185961,1187071,1187260,1187696
    Description:

    This update for shim fixes the following issues:


    Advisory IDSUSE-RU-2021:2481-1
    ReleasedTue Jul 27 14:20:27 2021
    SummaryRecommended update for sysconfig
    Typerecommended
    Severitymoderate
    References1184124
    Description:

    This update for sysconfig fixes the following issues:


    Advisory IDSUSE-RU-2021:2558-1
    ReleasedThu Jul 29 12:05:03 2021
    SummaryRecommended update for python-pytz
    Typerecommended
    Severitymoderate
    References1185748
    Description:

    This update for python-pytz fixes the following issues:


    Advisory IDSUSE-RU-2021:2627-1
    ReleasedThu Aug 5 12:10:46 2021
    SummaryRecommended maintenance update for systemd-default-settings
    Typerecommended
    Severitymoderate
    References1188348
    Description:

    This update for systemd-default-settings fixes the following issue:


    Advisory IDSUSE-SU-2021:2760-1
    ReleasedTue Aug 17 17:11:14 2021
    SummarySecurity update for c-ares
    Typesecurity
    Severityimportant
    References1188881,CVE-2021-3672
    Description:

    This update for c-ares fixes the following issues:
    Version update to git snapshot 1.17.1+20200724:


    Advisory IDSUSE-SU-2021:2817-1
    ReleasedMon Aug 23 15:05:18 2021
    SummarySecurity update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3
    Typesecurity
    Severitymoderate
    References1102408,1138715,1138746,1176389,1177120,1182421,1182422,CVE-2020-26137
    Description:

    This patch updates the Python AWS SDK stack in SLE 15:
    General:
    # aws-cli


    # python-boto3

    # python-botocore

    # python-urllib3

    # python-service_identity

    # python-trustme

    Security fixes:
    # python-urllib3:


    Advisory IDSUSE-RU-2021:2887-1
    ReleasedTue Aug 31 13:31:19 2021
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1183939,1184758
    Description:

    This update for cloud-init contains the following:


    Advisory IDSUSE-RU-2021:2899-1
    ReleasedWed Sep 1 08:30:58 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1186282,1187332
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2021:2962-1
    ReleasedMon Sep 6 18:23:01 2021
    SummaryRecommended update for runc
    Typerecommended
    Severitycritical
    References1189743
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-RU-2021:2973-1
    ReleasedTue Sep 7 16:56:08 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1190091
    Description:

    This update for hwdata fixes the following issue:


    Advisory IDSUSE-RU-2021:2997-1
    ReleasedThu Sep 9 14:37:34 2021
    SummaryRecommended update for python3
    Typerecommended
    Severitymoderate
    References1187338,1189659
    Description:

    This update for python3 fixes the following issues:


    Advisory IDSUSE-RU-2021:3001-1
    ReleasedThu Sep 9 15:08:13 2021
    SummaryRecommended update for netcfg
    Typerecommended
    Severitymoderate
    References1189683
    Description:

    This update for netcfg fixes the following issues:


    Advisory IDSUSE-RU-2021:3022-1
    ReleasedMon Sep 13 10:48:16 2021
    SummaryRecommended update for c-ares
    Typerecommended
    Severityimportant
    References1190225
    Description:

    This update for c-ares fixes the following issue:


    Advisory IDSUSE-RU-2021:3182-1
    ReleasedTue Sep 21 17:04:26 2021
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1189996
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-RU-2021:3245-1
    ReleasedTue Sep 28 13:54:31 2021
    SummaryRecommended update for docker
    Typerecommended
    Severityimportant
    References1190670
    Description:

    This update for docker fixes the following issues:


    Advisory IDSUSE-RU-2021:3274-1
    ReleasedFri Oct 1 10:34:17 2021
    SummaryRecommended update for ca-certificates-mozilla
    Typerecommended
    Severityimportant
    References1190858
    Description:

    This update for ca-certificates-mozilla fixes the following issues:


    Advisory IDSUSE-RU-2021:3382-1
    ReleasedTue Oct 12 14:30:17 2021
    SummaryRecommended update for ca-certificates-mozilla
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for ca-certificates-mozilla fixes the following issues:


    Advisory IDSUSE-SU-2021:3490-1
    ReleasedWed Oct 20 16:31:55 2021
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1190793,CVE-2021-39537
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2021:3494-1
    ReleasedWed Oct 20 16:48:46 2021
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1190052
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3506-1
    ReleasedMon Oct 25 10:20:22 2021
    SummarySecurity update for containerd, docker, runc
    Typesecurity
    Severityimportant
    References1102408,1185405,1187704,1188282,1190826,1191015,1191121,1191334,1191355,1191434,CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
    Description:

    This update for containerd, docker, runc fixes the following issues:
    Docker was updated to 20.10.9-ce. (bsc#1191355)
    See upstream changelog in the packaged /usr/share/doc/packages/docker/CHANGELOG.md.
    CVE-2021-41092 CVE-2021-41089 CVE-2021-41091 CVE-2021-41103
    container was updated to v1.4.11, to fix CVE-2021-41103. bsc#1191355



    Update to runc v1.0.2. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.2

    Update to runc v1.0.1. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.1

    Update to runc v1.0.0. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.0
    ! The usage of relative paths for mountpoints will now produce a warning (such configurations are outside of the spec, and in future runc will produce an error when given such configurations).
    Update to runc v1.0.0~rc95. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc95
    This release of runc contains a fix for CVE-2021-30465, and users are strongly recommended to update (especially if you are providing semi-limited access to spawn containers to untrusted users). (bsc#1185405)
    Update to runc v1.0.0~rc94. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc94
    Breaking Changes:
    Regression Fixes:


    Advisory IDSUSE-RU-2021:3510-1
    ReleasedTue Oct 26 11:22:15 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1191987
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3529-1
    ReleasedWed Oct 27 09:23:32 2021
    SummarySecurity update for pcre
    Typesecurity
    Severitymoderate
    References1172973,1172974,CVE-2019-20838,CVE-2020-14155
    Description:

    This update for pcre fixes the following issues:
    Update pcre to version 8.45:


    Advisory IDSUSE-RU-2021:3799-1
    ReleasedWed Nov 24 18:07:54 2021
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1187153,1187273,1188623
    Description:

    This update for gcc11 fixes the following issues:
    The additional GNU compiler collection GCC 11 is provided:
    To select these compilers install the packages:


    to select them for building:

    The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


    Advisory IDSUSE-RU-2021:3832-1
    ReleasedWed Dec 1 14:51:19 2021
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1191375
    Description:

    This update for hwdata fixes the following issue:


    Advisory IDSUSE-RU-2021:3891-1
    ReleasedFri Dec 3 10:21:49 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1029961,1113013,1187654
    Description:

    This update for keyutils fixes the following issues:


    keyutils was updated to 1.6.3 (jsc#SLE-20016):

    Updated to 1.6:

    Updated to 1.5.11 (bsc#1113013)


    Advisory IDSUSE-SU-2021:3942-1
    ReleasedMon Dec 6 14:46:05 2021
    SummarySecurity update for brotli
    Typesecurity
    Severitymoderate
    References1175825,CVE-2020-8927
    Description:

    This update for brotli fixes the following issues:


    Advisory IDSUSE-SU-2021:3945-1
    ReleasedMon Dec 6 14:56:55 2021
    SummarySecurity update for python-Babel
    Typesecurity
    Severityimportant
    References1185768,CVE-2021-42771
    Description:

    This update for python-Babel fixes the following issues:


    Advisory IDSUSE-SU-2021:3946-1
    ReleasedMon Dec 6 14:57:42 2021
    SummarySecurity update for gmp
    Typesecurity
    Severitymoderate
    References1192717,CVE-2021-43618
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-RU-2021:4009-1
    ReleasedMon Dec 13 11:24:43 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-SU-2021:4104-1
    ReleasedThu Dec 16 11:14:12 2021
    SummarySecurity update for python3
    Typesecurity
    Severitymoderate
    References1180125,1183374,1183858,1185588,1187668,1189241,1189287,CVE-2021-3426,CVE-2021-3733,CVE-2021-3737
    Description:

    This update for python3 fixes the following issues:



    Advisory IDSUSE-SU-2021:4171-1
    ReleasedThu Dec 23 09:55:13 2021
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1193436,CVE-2021-43784
    Description:

    This update for runc fixes the following issues:
    Update to runc v1.0.3.


    Advisory IDSUSE-RU-2022:48-1
    ReleasedTue Jan 11 09:17:57 2022
    SummaryRecommended update for python3
    Typerecommended
    Severitymoderate
    References1190566,1192249,1193179
    Description:

    This update for python3 fixes the following issues:



    Advisory IDSUSE-RU-2022:84-1
    ReleasedMon Jan 17 04:40:30 2022
    SummaryRecommended update for dosfstools
    Typerecommended
    Severitymoderate
    References1172863,1188401
    Description:

    This update for dosfstools fixes the following issues:


    Advisory IDSUSE-RU-2022:100-1
    ReleasedTue Jan 18 05:20:03 2022
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1194338
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2022:203-1
    ReleasedWed Jan 26 14:13:45 2022
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1186004
    Description:

    This update for cloud-init fixes the following issues:

    From 21.1 + Azure: Support for VMs without ephemeral resource disks. (#800) [Johnson Shi] (LP: #1901011) + cc_keys_to_console: add option to disable key emission (#811) [Michael Hudson-Doyle] (LP: #1915460) + integration_tests: introduce lxd_use_exec mark (#802) + azure: case-insensitive UUID to avoid new IID during kernel upgrade (#798) (LP: #1835584) + stale.yml: don't ask submitters to reopen PRs (#816) + integration_tests: fix use of SSH agent within tox (#815) + integration_tests: add UPGRADE CloudInitSource (#812) + integration_tests: use unique MAC addresses for tests (#813) + Update .gitignore (#814) + Port apt cloud_tests to integration tests (#808) + integration_tests: fix test_gh626 on LXD VMs (#809) + Fix attempting to decode binary data in test_seed_random_data test (#806) + Remove wait argument from tests with session_cloud calls (#805) + Datasource for UpCloud (#743) [Antti Myyrä] + test_gh668: fix failure on LXD VMs (#801) + openstack: read the dynamic metadata group vendor_data2.json (#777) [Andrew Bogott] (LP: #1841104) + includedir in suoders can be prefixed by 'arroba' (#783) [Jordi Massaguer Pla] + [VMware] change default max wait time to 15s (#774) [xiaofengw-vmware] + Revert integration test associated with reverted #586 (#784) + Add jordimassaguerpla as contributor (#787) [Jordi Massaguer Pla] + Add Rick Harding to CLA signers (#792) [Rick Harding] + HACKING.rst: add clarifying note to LP CLA process section (#789) + Stop linting cloud_tests (#791) + cloud-tests: update cryptography requirement (#790) [Joshua Powers] + Remove 'remove-raise-on-failure' calls from integration_tests (#788) + Use more cloud defaults in integration tests (#757) + Adding self to cla signers (#776) [Andrew Bogott] + doc: avoid two warnings (#781) [Dan Kenigsberg] + Use proper spelling for Red Hat (#778) [Dan Kenigsberg] + Add antonyc to .github-cla-signers (#747) [Anton Chaporgin] + integration_tests: log image serial if available (#772) + [VMware] Support cloudinit raw data feature (#691) [xiaofengw-vmware] + net: Fix static routes to host in eni renderer (#668) [Pavel Abalikhin] + .travis.yml: don't run cloud_tests in CI (#756) + test_upgrade: add some missing commas (#769) + cc_seed_random: update documentation and fix integration test (#771) (LP: #1911227) + Fix test gh-632 test to only run on NoCloud (#770) (LP: #1911230) + archlinux: fix package upgrade command handling (#768) [Bao Trinh] + integration_tests: add integration test for LP: #1910835 (#761) + Fix regression with handling of IMDS ssh keys (#760) [Thomas Stringer] + integration_tests: log cloud-init version in SUT (#758) + Add ajmyyra as contributor (#742) [Antti Myyrä] + net_convert: add some missing help text (#755) + Missing IPV6_AUTOCONF=no to render sysconfig dhcp6 stateful on RHEL (#753) [Eduardo Otubo] + doc: document missing IPv6 subnet types (#744) [Antti Myyrä] + Add example configuration for datasource `AliYun` (#751) [Xiaoyu Zhong] + integration_tests: add SSH key selection settings (#754) + fix a typo in man page cloud-init.1 (#752) [Amy Chen] + network-config-format-v2.rst: add Netplan Passthrough section (#750) + stale: re-enable post holidays (#749) + integration_tests: port ca_certs tests from cloud_tests (#732) + Azure: Add telemetry for poll IMDS (#741) [Johnson Shi] + doc: move testing section from HACKING to its own doc (#739) + No longer allow integration test failures on travis (#738) + stale: fix error in definition (#740) + integration_tests: set log-cli-level to INFO by default (#737) + PULL_REQUEST_TEMPLATE.md: use backticks around commit message (#736) + stale: disable check for holiday break (#735) + integration_tests: log the path we collect logs into (#733) + .travis.yml: add (most) supported Python versions to CI (#734) + integration_tests: fix IN_PLACE CLOUD_INIT_SOURCE (#731) + cc_ca_certs: add RHEL support (#633) [cawamata] + Azure: only generate config for NICs with addresses (#709) [Thomas Stringer] + doc: fix CloudStack configuration example (#707) [Olivier Lemasle] + integration_tests: restrict test_lxd_bridge appropriately (#730) + Add integration tests for CLI functionality (#729) + Integration test for gh-626 (#728) + Some test_upgrade fixes (#726) + Ensure overriding test vars with env vars works for booleans (#727) + integration_tests: port lxd_bridge test from cloud_tests (#718) + Integration test for gh-632. (#725) + Integration test for gh-671 (#724) + integration-requirements.txt: bump pycloudlib commit (#723) + Drop unnecessary shebang from cmd/main.py (#722) [Eduardo Otubo] + Integration test for LP: #1813396 and #669 (#719) + integration_tests: include timestamp in log output (#720) + integration_tests: add test for LP: #1898997 (#713) + Add integration test for power_state_change module (#717) + Update documentation for network-config-format-v2 (#701) [ggiesen] + sandbox CA Cert tests to not require ca-certificates (#715) [Eduardo Otubo] + Add upgrade integration test (#693) + Integration test for 570 (#712) + Add ability to keep snapshotted images in integration tests (#711) + Integration test for pull #586 (#706) + integration_tests: introduce skipping of tests by OS (#702) + integration_tests: introduce IntegrationInstance.restart (#708) + Add lxd-vm to list of valid integration test platforms (#705) + Adding BOOTPROTO = dhcp to render sysconfig dhcp6 stateful on RHEL (#685) [Eduardo Otubo] + Delete image snapshots created for integration tests (#682) + Parametrize ssh_keys_provided integration test (#700) [lucasmoura] + Drop use_sudo attribute on IntegrationInstance (#694) [lucasmoura] + cc_apt_configure: add riscv64 as a ports arch (#687) [Dimitri John Ledkov] + cla: add xnox (#692) [Dimitri John Ledkov] + Collect logs from integration test runs (#675) From 20.4.1 + Revert 'ssh_util: handle non-default AuthorizedKeysFile config (#586)' From 20.4 + tox: avoid tox testenv subsvars for xenial support (#684) + Ensure proper root permissions in integration tests (#664) [James Falcon] + LXD VM support in integration tests (#678) [James Falcon] + Integration test for fallocate falling back to dd (#681) [James Falcon] + .travis.yml: correctly integration test the built .deb (#683) + Ability to hot-attach NICs to preprovisioned VMs before reprovisioning (#613) [aswinrajamannar] + Support configuring SSH host certificates. (#660) [Jonathan Lung] + add integration test for LP: #1900837 (#679) + cc_resizefs on FreeBSD: Fix _can_skip_ufs_resize (#655) [Mina Galić] (LP: #1901958, #1901958) + DataSourceAzure: push dmesg log to KVP (#670) [Anh Vo] + Make mount in place for tests work (#667) [James Falcon] + integration_tests: restore emission of settings to log (#657) + DataSourceAzure: update password for defuser if exists (#671) [Anh Vo] + tox.ini: only select 'ci' marked tests for CI runs (#677) + Azure helper: Increase Azure Endpoint HTTP retries (#619) [Johnson Shi] + DataSourceAzure: send failure signal on Azure datasource failure (#594) [Johnson Shi] + test_persistence: simplify VersionIsPoppedFromState (#674) + only run a subset of integration tests in CI (#672) + cli: add + -system param to allow validating system user-data on a machine (#575) + test_persistence: add VersionIsPoppedFromState test (#673) + introduce an upgrade framework and related testing (#659) + add + -no-tty option to gpg (#669) [Till Riedel] (LP: #1813396) + Pin pycloudlib to a working commit (#666) [James Falcon] + DataSourceOpenNebula: exclude SRANDOM from context output (#665) + cloud_tests: add hirsute release definition (#662) + split integration and cloud_tests requirements (#652) + faq.rst: add warning to answer that suggests running `clean` (#661) + Fix stacktrace in DataSourceRbxCloud if no metadata disk is found (#632) [Scott Moser] + Make wakeonlan Network Config v2 setting actually work (#626) [dermotbradley] + HACKING.md: unify network-refactoring namespace (#658) [Mina Galić] + replace usage of dmidecode with kenv on FreeBSD (#621) [Mina Galić] + Prevent timeout on travis integration tests. (#651) [James Falcon] + azure: enable pushing the log to KVP from the last pushed byte (#614) [Moustafa Moustafa] + Fix launch_kwargs bug in integration tests (#654) [James Falcon] + split read_fs_info into linux & freebsd parts (#625) [Mina Galić] + PULL_REQUEST_TEMPLATE.md: expand commit message section (#642) + Make some language improvements in growpart documentation (#649) [Shane Frasier] + Revert '.travis.yml: use a known-working version of lxd (#643)' (#650) + Fix not sourcing default 50-cloud-init ENI file on Debian (#598) [WebSpider] + remove unnecessary reboot from gpart resize (#646) [Mina Galić] + cloudinit: move dmi functions out of util (#622) [Scott Moser] + integration_tests: various launch improvements (#638) + test_lp1886531: don't assume /etc/fstab exists (#639) + Remove Ubuntu restriction from PR template (#648) [James Falcon] + util: fix mounting of vfat on *BSD (#637) [Mina Galić] + conftest: improve docstring for disable_subp_usage (#644) + doc: add example query commands to debug Jinja templates (#645) + Correct documentation and testcase data for some user-data YAML (#618) [dermotbradley] + Hetzner: Fix instance_id / SMBIOS serial comparison (#640) [Markus Schade] + .travis.yml: use a known-working version of lxd (#643) + tools/build-on-freebsd: fix comment explaining purpose of the script (#635) [Mina Galić] + Hetzner: initialize instance_id from system-serial-number (#630) [Markus Schade] (LP: #1885527) + Explicit set IPV6_AUTOCONF and IPV6_FORCE_ACCEPT_RA on static6 (#634) [Eduardo Otubo] + get_interfaces: don't exclude Open vSwitch bridge/bond members (#608) [Lukas Märdian] (LP: #1898997) + Add config modules for controlling IBM PowerVM RMC. (#584) [Aman306] (LP: #1895979) + Update network config docs to clarify MAC address quoting (#623) [dermotbradley] + gentoo: fix hostname rendering when value has a comment (#611) [Manuel Aguilera] + refactor integration testing infrastructure (#610) [James Falcon] + stages: don't reset permissions of cloud-init.log every boot (#624) (LP: #1900837) + docs: Add how to use cloud-localds to boot qemu (#617) [Joshua Powers] + Drop vestigial update_resolve_conf_file function (#620) [Scott Moser] + cc_mounts: correctly fallback to dd if fallocate fails (#585) (LP: #1897099) + .travis.yml: add integration-tests to Travis matrix (#600) + ssh_util: handle non-default AuthorizedKeysFile config (#586) [Eduardo Otubo] + Multiple file fix for AuthorizedKeysFile config (#60) [Eduardo Otubo] + bddeb: new + -packaging-branch argument to pull packaging from branch (#576) [Paride Legovini] + Add more integration tests (#615) [lucasmoura] + DataSourceAzure: write marker file after report ready in preprovisioning (#590) [Johnson Shi] + integration_tests: emit settings to log during setup (#601) + integration_tests: implement citest tests run in Travis (#605) + Add Azure support to integration test framework (#604) [James Falcon] + openstack: consider product_name as valid chassis tag (#580) [Adrian Vladu] (LP: #1895976) + azure: clean up and refactor report_diagnostic_event (#563) [Johnson Shi] + net: add the ability to blacklist network interfaces based on driver during enumeration of physical network devices (#591) [Anh Vo] + integration_tests: don't error on cloud-init failure (#596) + integration_tests: improve cloud-init.log assertions (#593) + conftest.py: remove top-level import of httpretty (#599) + tox.ini: add integration-tests testenv definition (#595) + PULL_REQUEST_TEMPLATE.md: empty checkboxes need a space (#597) + add integration test for LP: #1886531 (#592) + Initial implementation of integration testing infrastructure (#581) [James Falcon] + Fix name of ntp and chrony service on CentOS and RHEL. (#589) [Scott Moser] (LP: #1897915) + Adding a PR template (#587) [James Falcon] + Azure parse_network_config uses fallback cfg when generate IMDS network cfg fails (#549) [Johnson Shi] + features: refresh docs for easier out-of-context reading (#582) + Fix typo in resolv_conf module's description (#578) [Wacław Schiller] + cc_users_groups: minor doc formatting fix (#577) + Fix typo in disk_setup module's description (#579) [Wacław Schiller] + Add vendor-data support to seedfrom parameter for NoCloud and OVF (#570) [Johann Queuniet] + boot.rst: add First Boot Determination section (#568) (LP: #1888858) + opennebula.rst: minor readability improvements (#573) [Mina Galić] + cloudinit: remove unused LOG variables (#574) + create a shutdown_command method in distro classes (#567) [Emmanuel Thomé] + user_data: remove unused constant (#566) + network: Fix type and respect name when rendering vlan in sysconfig. (#541) [Eduardo Otubo] (LP: #1788915, #1826608) + Retrieve SSH keys from IMDS first with OVF as a fallback (#509) [Thomas Stringer] + Add jqueuniet as contributor (#569) [Johann Queuniet] + distros: minor typo fix (#562) + Bump the integration-requirements versioned dependencies (#565) [Paride Legovini] + network-config-format-v1: fix typo in nameserver example (#564) [Stanislas] + Run cloud-init-local.service after the hv_kvp_daemon (#505) [Robert Schweikert] + Add method type hints for Azure helper (#540) [Johnson Shi] + systemd: add Before=shutdown.target when Conflicts=shutdown.target is used (#546) [Paride Legovini] + LXD: detach network from profile before deleting it (#542) [Paride Legovini] (LP: #1776958) + redhat spec: add missing BuildRequires (#552) [Paride Legovini] + util: remove debug statement (#556) [Joshua Powers] + Fix cloud config on chef example (#551) [lucasmoura] From 20.3 + Azure: Add netplan driver filter when using hv_netvsc driver (#539) [James Falcon] (LP: #1830740) + query: do not handle non-decodable non-gzipped content (#543) + DHCP sandboxing failing on noexec mounted /var/tmp (#521) [Eduardo Otubo] + Update the list of valid ssh keys. (#487) [Ole-Martin Bratteng] (LP: #1877869) + cmd: cloud-init query to handle compressed userdata (#516) (LP: #1889938) + Pushing cloud-init log to the KVP (#529) [Moustafa Moustafa] + Add Alpine Linux support. (#535) [dermotbradley] + Detect kernel version before swap file creation (#428) [Eduardo Otubo] + cli: add devel make-mime subcommand (#518) + user-data: only verify mime-types for TYPE_NEEDED and x-shellscript (#511) (LP: #1888822) + DataSourceOracle: retry twice (and document why we retry at all) (#536) + Refactor Azure report ready code (#468) [Johnson Shi] + tox.ini: pin correct version of httpretty in xenial{,-dev} envs (#531) + Support Oracle IMDSv2 API (#528) [James Falcon] + .travis.yml: run a doc build during CI (#534) + doc/rtd/topics/datasources/ovf.rst: fix doc8 errors (#533) + Fix 'Users and Groups' configuration documentation (#530) [sshedi] + cloudinit.distros: update docstrings of add_user and create_user (#527) + Fix headers for device types in network v2 docs (#532) [Caleb Xavier Berger] + Add AlexBaranowski as contributor (#508) [Aleksander Baranowski] + DataSourceOracle: refactor to use only OPC v1 endpoint (#493) + .github/workflows/stale.yml: s/Josh/Rick/ (#526) + Fix a typo in apt pipelining module (#525) [Xiao Liang] + test_util: parametrize devlist tests (#523) [James Falcon] + Recognize LABEL_FATBOOT labels (#513) [James Falcon] (LP: #1841466) + Handle additional identifier for SLES For HPC (#520) [Robert Schweikert] + Revert 'test-requirements.txt: pin pytest to <6 (#512)' (#515) + test-requirements.txt: pin pytest to <6 (#512) + Add 'tsanghan' as contributor (#504) [tsanghan] + fix brpm building (LP: #1886107) + Adding eandersson as a contributor (#502) [Erik Olof Gunnar Andersson] + azure: disable bouncing hostname when setting hostname fails (#494) [Anh Vo] + VMware: Support parsing DEFAULT-RUN-POST-CUST-SCRIPT (#441) [xiaofengw-vmware] + DataSourceAzure: Use ValueError when JSONDecodeError is not available (#490) [Anh Vo] + cc_ca_certs.py: fix blank line problem when removing CAs and adding new one (#483) [dermotbradley] + freebsd: py37-serial is now py37-pyserial (#492) [Gonéri Le Bouder] + ssh exit with non-zero status on disabled user (#472) [Eduardo Otubo] (LP: #1170059) + cloudinit: remove global disable of pylint W0107 and fix errors (#489) + networking: refactor wait_for_physdevs from cloudinit.net (#466) (LP: #1884626) + HACKING.rst: add pytest.param pytest gotcha (#481) + cloudinit: remove global disable of pylint W0105 and fix errors (#480) + Fix two minor warnings (#475) + test_data: fix faulty patch (#476) + cc_mounts: handle missing fstab (#484) (LP: #1886531) + LXD cloud_tests: support more lxd image formats (#482) [Paride Legovini] + Add update_etc_hosts as default module on *BSD (#479) [Adam Dobrawy] + cloudinit: fix tip-pylint failures and bump pinned pylint version (#478) + Added BirknerAlex as contributor and sorted the file (#477) [Alexander Birkner] + Update list of types of modules in cli.rst [saurabhvartak1982] + tests: use markers to configure disable_subp_usage (#473) + Add mention of vendor-data to no-cloud format documentation (#470) [Landon Kirk] + Fix broken link to OpenStack metadata service docs (#467) [Matt Riedemann] + Disable ec2 mirror for non aws instances (#390) [lucasmoura] (LP: #1456277) + cloud_tests: don't pass + -python-version to read-dependencies (#465) + networking: refactor is_physical from cloudinit.net (#457) (LP: #1884619) + Enable use of the caplog fixture in pytest tests, and add a cc_final_message test using it (#461) + RbxCloud: Add support for FreeBSD (#464) [Adam Dobrawy] + Add schema for cc_chef module (#375) [lucasmoura] (LP: #1858888) + test_util: add (partial) testing for util.mount_cb (#463) + .travis.yml: revert to installing ubuntu-dev-tools (#460) + HACKING.rst: add details of net refactor tracking (#456) + .travis.yml: rationalise installation of dependencies in host (#449) + Add dermotbradley as contributor. (#458) [dermotbradley] + net/networking: remove unused functions/methods (#453) + distros.networking: initial implementation of layout (#391) + cloud-init.service.tmpl: use 'rhel' instead of 'redhat' (#452) + Change from redhat to rhel in systemd generator tmpl (#450) [Eduardo Otubo] + Hetzner: support reading user-data that is base64 encoded. (#448) [Scott Moser] (LP: #1884071) + HACKING.rst: add strpath gotcha to testing gotchas section (#446) + cc_final_message: don't create directories when writing boot-finished (#445) (LP: #1883903) + .travis.yml: only store new schroot if something has changed (#440) + util: add ensure_dir_exists parameter to write_file (#443) + printing the error stream of the dhclient process before killing it (#369) [Moustafa Moustafa] + Fix link to the MAAS documentation (#442) [Paride Legovini] (LP: #1883666) + RPM build: disable the dynamic mirror URLs when using a proxy (#437) [Paride Legovini] + util: rename write_file's copy_mode parameter to preserve_mode (#439) + .travis.yml: use $TRAVIS_BUILD_DIR for lxd_image caching (#438) + cli.rst: alphabetise devel subcommands and add net-convert to list (#430) + Default to UTF-8 in /var/log/cloud-init.log (#427) [James Falcon] + travis: cache the chroot we use for package builds (#429) + test: fix all flake8 E126 errors (#425) [Joshua Powers] + Fixes KeyError for bridge with no 'parameters:' setting (#423) [Brian Candler] (LP: #1879673) + When tools.conf does not exist, running cmd 'vmware-toolbox-cmd config get deployPkg enable-custom-scripts', the return code will be EX_UNAVAILABLE(69), on this condition, it should not take it as error. (#413) [chengcheng-chcheng] + Document CloudStack data-server well-known hostname (#399) [Gregor Riepl] + test: move conftest.py to top-level, to cover tests/ also (#414) + Replace cc_chef is_installed with use of subp.is_exe. (#421) [Scott Moser] + Move runparts to subp. (#420) [Scott Moser] + Move subp into its own module. (#416) [Scott Moser] + readme: point at travis-ci.com (#417) [Joshua Powers] + New feature flag functionality and fix includes failing silently (#367) [James Falcon] (LP: #1734939) + Enhance poll imds logging (#365) [Moustafa Moustafa] + test: fix all flake8 E121 and E123 errors (#404) [Joshua Powers] + test: fix all flake8 E241 (#403) [Joshua Powers] + test: ignore flake8 E402 errors in main.py (#402) [Joshua Powers] + cc_grub_dpkg: determine idevs in more robust manner with grub-probe (#358) [Matthew Ruffell] (LP: #1877491) + test: fix all flake8 E741 errors (#401) [Joshua Powers] + tests: add groovy integration tests for ubuntu (#400) + Enable chef_license support for chef infra client (#389) [Bipin Bachhao] + testing: use flake8 again (#392) [Joshua Powers] + enable Puppet, Chef mcollective in default config (#385) [Mina Galić (deprecated: Igor Galić)] (LP: #1880279) + HACKING.rst: introduce .net + > Networking refactor section (#384) + Travis: do not install python3-contextlib2 (dropped dependency) (#388) [Paride Legovini] + HACKING: mention that .github-cla-signers is alpha-sorted (#380) + Add bipinbachhao as contributor (#379) [Bipin Bachhao] + cc_snap: validate that assertions property values are strings (#370) + conftest: implement partial disable_subp_usage (#371) + test_resolv_conf: refresh stale comment (#374) + cc_snap: apply validation to snap.commands properties (#364) + make finding libc platform independent (#366) [Mina Galić (deprecated: Igor Galić)] + doc/rtd/topics/faq: Updates LXD docs links to current site (#368) [TomP] + templater: drop Jinja Python 2 compatibility shim (#353) + cloudinit: minor pylint fixes (#360) + cloudinit: remove unneeded __future__ imports (#362) + migrating momousta lp user to Moustafa-Moustafa GitHub user (#361) [Moustafa Moustafa] + cloud_tests: emit dots on Travis while fetching images (#347) + Add schema to apt configure config (#357) [lucasmoura] (LP: #1858884) + conftest: add docs and tests regarding CiTestCase's subp functionality (#343) + analyze/dump: refactor shared string into variable (#350) + doc: update boot.rst with correct timing of runcmd (#351) + HACKING.rst: change contact info to Rick Harding (#359) [lucasmoura] + HACKING.rst: guide people to add themselves to the CLA file (#349) + HACKING.rst: more unit testing documentation (#354) + .travis.yml: don't run lintian during integration test package builds (#352) + Add test to ensure docs examples are valid cloud-init configs (#355) [James Falcon] (LP: #1876414) + make suse and sles support 127.0.1.1 (#336) [chengcheng-chcheng] + Create tests to validate schema examples (#348) [lucasmoura] (LP: #1876412) + analyze/dump: add support for Amazon Linux 2 log lines (#346) (LP: #1876323) + bsd: upgrade support (#305) [Gonéri Le Bouder] + Add lucasmoura as contributor (#345) [lucasmoura] + Add 'therealfalcon' as contributor (#344) [James Falcon] + Adapt the package building scripts to use Python 3 (#231) [Paride Legovini] + DataSourceEc2: use metadata's NIC ordering to determine route-metrics (#342) (LP: #1876312) + .travis.yml: introduce caching (#329) + cc_locale: introduce schema (#335) + doc/rtd/conf.py: bump copyright year to 2020 (#341) + yum_add_repo: Add Centos to the supported distro list (#340)


    Advisory IDSUSE-RU-2022:228-1
    ReleasedMon Jan 31 06:07:52 2022
    SummaryRecommended update for boost
    Typerecommended
    Severitymoderate
    References1194522
    Description:

    This update for boost fixes the following issues:


    Advisory IDSUSE-SU-2022:334-1
    ReleasedFri Feb 4 09:30:58 2022
    SummarySecurity update for containerd, docker
    Typesecurity
    Severitymoderate
    References1191015,1191121,1191334,1191434,1193273,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103,CVE-2021-41190
    Description:

    This update for containerd, docker fixes the following issues:


    Advisory IDSUSE-RU-2022:353-1
    ReleasedTue Feb 8 17:41:48 2022
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:



    Advisory IDSUSE-RU-2022:548-1
    ReleasedTue Feb 22 13:48:55 2022
    SummaryRecommended update for blog
    Typerecommended
    Severitymoderate
    References1186506,1191057
    Description:

    This update for blog fixes the following issues:






    Advisory IDSUSE-RU-2022:682-1
    ReleasedThu Mar 3 11:37:03 2022
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severityimportant
    References1195095,1195096
    Description:

    This update for supportutils-plugin-suse-public-cloud fixes the following issues:


    Advisory IDSUSE-RU-2022:692-1
    ReleasedThu Mar 3 15:46:47 2022
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1190447
    Description:

    This update for filesystem fixes the following issues:


    Advisory IDSUSE-SU-2022:720-1
    ReleasedFri Mar 4 10:20:28 2022
    SummarySecurity update for containerd
    Typesecurity
    Severitymoderate
    References1196441,CVE-2022-23648
    Description:

    This update for containerd fixes the following issues:


    Advisory IDSUSE-RU-2022:775-1
    ReleasedWed Mar 9 12:55:03 2022
    SummaryRecommended update for pciutils
    Typerecommended
    Severitymoderate
    References1192862
    Description:

    This update for pciutils fixes the following issues:


    Advisory IDSUSE-RU-2022:789-1
    ReleasedThu Mar 10 11:22:05 2022
    SummaryRecommended update for update-alternatives
    Typerecommended
    Severitymoderate
    References1195654
    Description:

    This update for update-alternatives fixes the following issues:


    Advisory IDSUSE-RU-2022:792-1
    ReleasedThu Mar 10 11:58:18 2022
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1194845,1196494,1196495
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-RU-2022:808-1
    ReleasedFri Mar 11 06:07:58 2022
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1195468
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2022:861-1
    ReleasedTue Mar 15 23:31:21 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1182959,1195149,1195792,1195856
    Description:

    This update for openssl-1_1 fixes the following issues:
    openssl-1_1:

    glibc:
    linux-glibc-devel:

    libxcrypt:

    zlib:


    Advisory IDSUSE-RU-2022:884-1
    ReleasedThu Mar 17 09:47:43 2022
    SummaryRecommended update for python-jsonschema, python-rfc3987, python-strict-rfc3339
    Typerecommended
    Severitymoderate
    References1082318
    Description:

    This update for python-jsonschema, python-rfc3987, python-strict-rfc3339 fixes the following issues:











    Advisory IDSUSE-RU-2022:936-1
    ReleasedTue Mar 22 18:10:17 2022
    SummaryRecommended update for filesystem and systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1196275,1196406
    Description:

    This update for filesystem and systemd-rpm-macros fixes the following issues:
    filesystem:


    systemd-rpm-macros:


    Advisory IDSUSE-SU-2022:942-1
    ReleasedThu Mar 24 10:30:15 2022
    SummarySecurity update for python3
    Typesecurity
    Severitymoderate
    References1186819,CVE-2021-3572
    Description:

    This update for python3 fixes the following issues:


    Advisory IDSUSE-RU-2022:1047-1
    ReleasedWed Mar 30 16:20:56 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1196093,1197024
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2022:1074-1
    ReleasedFri Apr 1 13:27:00 2022
    SummaryRecommended update for cloud-init
    Typerecommended
    Severitymoderate
    References1193531
    Description:

    This update for cloud-init contains the following fixes:




    Advisory IDSUSE-RU-2022:1147-1
    ReleasedMon Apr 11 15:49:43 2022
    SummaryRecommended update for containerd
    Typerecommended
    Severitymoderate
    References1195784
    Description:


    This update of containerd fixes the following issue:


    Advisory IDSUSE-RU-2022:1150-1
    ReleasedMon Apr 11 17:34:19 2022
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1197293
    Description:

    This update for suse-build-key fixes the following issues:
    No longer install 1024bit keys by default. (bsc#1197293)


    Advisory IDSUSE-RU-2022:1190-1
    ReleasedWed Apr 13 20:52:23 2022
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1192343
    Description:

    This update for cloud-init contains the following fixes:



    + Still need to consider the 'network' configuration option


    Advisory IDSUSE-RU-2022:1204-1
    ReleasedThu Apr 14 12:15:55 2022
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References1196332
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2022:1281-1
    ReleasedWed Apr 20 12:26:38 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1409-1
    ReleasedTue Apr 26 12:54:57 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1195628,1196107
    Description:

    This update for gcc11 fixes the following issues:


    Advisory IDSUSE-RU-2022:1451-1
    ReleasedThu Apr 28 10:47:22 2022
    SummaryRecommended update for perl
    Typerecommended
    Severitymoderate
    References1193489
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-SU-2022:1548-1
    ReleasedThu May 5 16:45:28 2022
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1029961,1120610,1130496,1181131,CVE-2018-20482,CVE-2019-9923,CVE-2021-20193
    Description:

    This update for tar fixes the following issues:







    Advisory IDSUSE-SU-2022:1617-1
    ReleasedTue May 10 14:40:12 2022
    SummarySecurity update for gzip
    Typesecurity
    Severityimportant
    References1198062,1198922,CVE-2022-1271
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2022:1655-1
    ReleasedFri May 13 15:36:10 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1197794
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:1658-1
    ReleasedFri May 13 15:40:20 2022
    SummaryRecommended update for libpsl
    Typerecommended
    Severityimportant
    References1197771
    Description:

    This update for libpsl fixes the following issues:


    Advisory IDSUSE-SU-2022:1689-1
    ReleasedMon May 16 14:09:01 2022
    SummarySecurity update for containerd, docker
    Typesecurity
    Severityimportant
    References1193930,1196441,1197284,1197517,CVE-2021-43565,CVE-2022-23648,CVE-2022-24769,CVE-2022-27191
    Description:

    This update for containerd, docker fixes the following issues:


    Advisory IDSUSE-RU-2022:1703-1
    ReleasedTue May 17 12:13:36 2022
    SummaryRecommended update for hwdata
    Typerecommended
    Severityimportant
    References1196332
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2022:1824-1
    ReleasedTue May 24 10:31:13 2022
    SummaryRecommended update for dhcp
    Typerecommended
    Severitymoderate
    References1198657
    Description:

    This update for dhcp fixes the following issues:


    Advisory IDSUSE-RU-2022:1843-1
    ReleasedWed May 25 15:25:44 2022
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1198504
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-RU-2022:1887-1
    ReleasedTue May 31 09:24:18 2022
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1040589
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-RU-2022:1899-1
    ReleasedWed Jun 1 10:43:22 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severityimportant
    References1198176
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:2019-1
    ReleasedWed Jun 8 16:50:07 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1192951,1193659,1195283,1196861,1197065
    Description:

    This update for gcc11 fixes the following issues:
    Update to the GCC 11.3.0 release.


    Advisory IDSUSE-RU-2022:2024-1
    ReleasedThu Jun 9 10:13:12 2022
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1198258
    Description:

    This update for python-azure-agent fixes the following issues:


    Advisory IDSUSE-SU-2022:2294-1
    ReleasedWed Jul 6 13:34:15 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:2341-1
    ReleasedFri Jul 8 16:09:12 2022
    SummarySecurity update for containerd, docker and runc
    Typesecurity
    Severityimportant
    References1192051,1199460,1199565,1200088,1200145,CVE-2022-29162,CVE-2022-31030
    Description:

    This update for containerd, docker and runc fixes the following issues:
    containerd:


    docker:

    runc:
    Update to runc v1.1.3.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.3.

    Update to runc v1.1.2.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.2.
    Security issue fixed:


    Update to runc v1.1.1.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.1.

    Update to runc v1.1.0.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.0.

    Update to runc v1.1.0~rc1.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.0-rc.1.


    Advisory IDSUSE-RU-2022:2355-1
    ReleasedMon Jul 11 12:44:33 2022
    SummaryRecommended update for python-cryptography
    Typerecommended
    Severitymoderate
    References1198331,CVE-2020-25659
    Description:


    This update for python-cryptography fixes the following issues:
    python-cryptography was updated to 3.3.2.
    update to 3.3.0:


    Update to 3.2.1:
    Disable blinding on RSA public keys to address an error with some versions of OpenSSL.
    update to 3.2 (bsc#1178168, CVE-2020-25659):

    update to 3.1:

    update to 3.0:

    Update to 2.9:


    Advisory IDSUSE-SU-2022:2357-1
    ReleasedMon Jul 11 20:34:20 2022
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1198511,CVE-2015-20107
    Description:

    This update for python3 fixes the following issues:


    Advisory IDSUSE-SU-2022:2361-1
    ReleasedTue Jul 12 12:05:01 2022
    SummarySecurity update for pcre
    Typesecurity
    Severityimportant
    References1199232,CVE-2022-1586
    Description:

    This update for pcre fixes the following issues:


    Advisory IDSUSE-SU-2022:2378-1
    ReleasedWed Jul 13 10:27:03 2022
    SummarySecurity update for cifs-utils
    Typesecurity
    Severityimportant
    References1197216,CVE-2022-27239
    Description:

    This update for cifs-utils fixes the following issues:


    Advisory IDSUSE-SU-2022:2396-1
    ReleasedThu Jul 14 11:57:58 2022
    SummarySecurity update for logrotate
    Typesecurity
    Severityimportant
    References1192449,1199652,1200278,1200802,CVE-2022-1348
    Description:

    This update for logrotate fixes the following issues:
    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2022:2402-1
    ReleasedThu Jul 14 16:58:22 2022
    SummarySecurity update for python-PyJWT
    Typesecurity
    Severityimportant
    References1199756,CVE-2022-29217
    Description:

    This update for python-PyJWT fixes the following issues:


    Advisory IDSUSE-RU-2022:2406-1
    ReleasedFri Jul 15 11:49:01 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1197718,1199140,1200334,1200855
    Description:

    This update for glibc fixes the following issues:


    This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).


    Advisory IDSUSE-RU-2022:2493-1
    ReleasedThu Jul 21 14:35:08 2022
    SummaryRecommended update for rpm-config-SUSE
    Typerecommended
    Severitymoderate
    References1193282
    Description:

    This update for rpm-config-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2022:2548-1
    ReleasedTue Jul 26 13:48:28 2022
    SummaryCritical update for python-cssselect
    Typerecommended
    Severitycritical
    References
    Description:

    This update for python-cssselect implements packages to the unrestrictied repository.


    Advisory IDSUSE-SU-2022:2632-1
    ReleasedWed Aug 3 09:51:00 2022
    SummarySecurity update for permissions
    Typesecurity
    Severityimportant
    References1198720,1200747,1201385
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:2640-1
    ReleasedWed Aug 3 10:43:44 2022
    SummaryRecommended update for yaml-cpp
    Typerecommended
    Severitymoderate
    References1160171,1178331,1178332,1200624
    Description:

    This update for yaml-cpp fixes the following issue:


    Advisory IDSUSE-SU-2022:2717-1
    ReleasedTue Aug 9 12:54:16 2022
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1198627,CVE-2022-29458
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2022:2735-1
    ReleasedWed Aug 10 04:31:41 2022
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1200657
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-RU-2022:2796-1
    ReleasedFri Aug 12 14:34:31 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for jitterentropy fixes the following issues:
    jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
    This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library, used by other FIPS libraries.


    Advisory IDSUSE-SU-2022:2831-1
    ReleasedWed Aug 17 14:41:07 2022
    SummaryRecommended update for aws-efs-utils, python-ansi2html, python-py, python-pytest-html, python-pytest-metadata, python-pytest-rerunfailures, python-coverage, python-oniconfig, python-unittest-mixins
    Typesecurity
    Severitymoderate
    References1195916,1196696,CVE-2020-29651
    Description:

    This update for aws-efs-utils, python-ansi2html, python-py, python-pytest-html, python-pytest-metadata, python-pytest-rerunfailures fixes the following issues:



    Advisory IDSUSE-RU-2022:2844-1
    ReleasedThu Aug 18 14:41:25 2022
    SummaryRecommended update for tar
    Typerecommended
    Severityimportant
    References1202436
    Description:

    This update for tar fixes the following issues:



    Advisory IDSUSE-RU-2022:2853-1
    ReleasedFri Aug 19 15:59:42 2022
    SummaryRecommended update for sle-module-legacy-release
    Typerecommended
    Severitylow
    References1202498
    Description:

    This update for python-iniconfig provides the following fix:


    Advisory IDSUSE-RU-2022:2901-1
    ReleasedFri Aug 26 03:34:23 2022
    SummaryRecommended update for elfutils
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for elfutils fixes the following issues:


    Advisory IDSUSE-RU-2022:2925-1
    ReleasedMon Aug 29 03:16:48 2022
    SummaryRecommended update for audit-secondary
    Typerecommended
    Severityimportant
    References1201519
    Description:

    This update for audit-secondary fixes the following issues:


    Advisory IDSUSE-RU-2022:2943-1
    ReleasedTue Aug 30 15:42:16 2022
    SummaryRecommended update for python-iniconfig
    Typerecommended
    Severitylow
    References1202498
    Description:

    This update for python-iniconfig provides the following fix:


    Advisory IDSUSE-RU-2022:2944-1
    ReleasedWed Aug 31 05:39:14 2022
    SummaryRecommended update for procps
    Typerecommended
    Severityimportant
    References1181475
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2022:3022-1
    ReleasedMon Sep 5 15:16:02 2022
    SummaryRecommended update for python-pyOpenSSL
    Typerecommended
    Severitymoderate
    References1200771
    Description:

    This update for python-pyOpenSSL fixes the following issues:


    python-pyOpenSSL was updated to 21.0.0 (bsc#1200771, jsc#SLE-24519):


    Advisory IDSUSE-RU-2022:3028-1
    ReleasedMon Sep 5 16:31:24 2022
    SummaryRecommended update for python-pytz
    Typerecommended
    Severitylow
    References
    Description:

    This update for python-pytz fixes the following issues:



    Advisory IDSUSE-RU-2022:3127-1
    ReleasedWed Sep 7 04:36:10 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1198752,1200800
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:3135-1
    ReleasedWed Sep 7 08:39:31 2022
    SummaryRecommended update for hwdata
    Typerecommended
    Severitylow
    References1200110
    Description:

    This update for hwdata fixes the following issue:


    Advisory IDSUSE-SU-2022:3162-1
    ReleasedWed Sep 7 15:07:31 2022
    SummarySecurity update for libyajl
    Typesecurity
    Severitymoderate
    References1198405,CVE-2022-24795
    Description:

    This update for libyajl fixes the following issues:


    Advisory IDSUSE-RU-2022:3219-1
    ReleasedThu Sep 8 21:15:24 2022
    SummaryRecommended update for sysconfig
    Typerecommended
    Severitymoderate
    References1185882,1194557,1199093
    Description:

    This update for sysconfig fixes the following issues:


    Advisory IDSUSE-SU-2022:3252-1
    ReleasedMon Sep 12 09:07:53 2022
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1198823,1198830,1198832,CVE-2022-27404,CVE-2022-27405,CVE-2022-27406
    Description:

    This update for freetype2 fixes the following issues:


    Non-security fixes:


    Advisory IDSUSE-RU-2022:3262-1
    ReleasedTue Sep 13 15:34:29 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1199140
    Description:


    This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)


    Advisory IDSUSE-SU-2022:3271-1
    ReleasedWed Sep 14 06:45:39 2022
    SummarySecurity update for perl
    Typesecurity
    Severitymoderate
    References1047178,CVE-2017-6512
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-RU-2022:3304-1
    ReleasedMon Sep 19 11:43:25 2022
    SummaryRecommended update for libassuan
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libassuan fixes the following issues:


    Advisory IDSUSE-SU-2022:3305-1
    ReleasedMon Sep 19 11:45:57 2022
    SummarySecurity update for libtirpc
    Typesecurity
    Severityimportant
    References1201680,CVE-2021-46828
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3307-1
    ReleasedMon Sep 19 13:26:51 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-SU-2022:3327-1
    ReleasedWed Sep 21 12:47:17 2022
    SummarySecurity update for oniguruma
    Typesecurity
    Severityimportant
    References1142847,1150130,1157805,1164550,1164569,1177179,CVE-2019-13224,CVE-2019-16163,CVE-2019-19203,CVE-2019-19204,CVE-2019-19246,CVE-2020-26159
    Description:

    This update for oniguruma fixes the following issues:


    Advisory IDSUSE-RU-2022:3328-1
    ReleasedWed Sep 21 12:48:56 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1202870
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-SU-2022:3353-1
    ReleasedFri Sep 23 15:23:40 2022
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1203018,CVE-2022-31252
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:3395-1
    ReleasedMon Sep 26 16:35:18 2022
    SummaryRecommended update for ca-certificates-mozilla
    Typerecommended
    Severitymoderate
    References1181994,1188006,1199079,1202868
    Description:

    This update for ca-certificates-mozilla fixes the following issues:
    Updated to 2.56 state of Mozilla SSL root CAs (bsc#1202868)


    - Certainly Root E1 - Certainly Root R1 - DigiCert SMIME ECC P384 Root G5 - DigiCert SMIME RSA4096 Root G5 - DigiCert TLS ECC P384 Root G5 - DigiCert TLS RSA4096 Root G5 - E-Tugra Global Root CA ECC v3 - E-Tugra Global Root CA RSA v3

    - Hellenic Academic and Research Institutions RootCA 2011
    Updated to 2.54 state of Mozilla SSL root CAs (bsc#1199079)

    - Autoridad de Certificacion Firmaprofesional CIF A62634068 - D-TRUST BR Root CA 1 2020 - D-TRUST EV Root CA 1 2020 - GlobalSign ECC Root CA R4 - GTS Root R1 - GTS Root R2 - GTS Root R3 - GTS Root R4 - HiPKI Root CA - G1 - ISRG Root X2 - Telia Root CA v2 - vTrus ECC Root CA - vTrus Root CA

    - Cybertrust Global Root - DST Root CA X3 - DigiNotar PKIoverheid CA Organisatie - G2 - GlobalSign ECC Root CA R4 - GlobalSign Root CA R2 - GTS Root R1 - GTS Root R2 - GTS Root R3 - GTS Root R4
    Updated to 2.50 state of the Mozilla NSS Certificate store (bsc#1188006)

    - HARICA Client ECC Root CA 2021 - HARICA Client RSA Root CA 2021 - HARICA TLS ECC Root CA 2021 - HARICA TLS RSA Root CA 2021 - TunTrust Root CA

    Updated to 2.46 state of the Mozilla NSS Certificate store (bsc#1181994)

    - NAVER Global Root Certification Authority

    - GeoTrust Global CA - GeoTrust Primary Certification Authority - GeoTrust Primary Certification Authority - G3 - GeoTrust Universal CA - GeoTrust Universal CA 2 - thawte Primary Root CA - thawte Primary Root CA - G2 - thawte Primary Root CA - G3 - VeriSign Class 3 Public Primary Certification Authority - G4 - VeriSign Class 3 Public Primary Certification Authority - G5


    Advisory IDSUSE-RU-2022:3435-1
    ReleasedTue Sep 27 14:55:38 2022
    SummaryRecommended update for runc
    Typerecommended
    Severityimportant
    References1202821
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-SU-2022:3489-1
    ReleasedSat Oct 1 13:35:24 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1203438,CVE-2022-40674
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-feature-2022:3520-1
    ReleasedTue Oct 4 14:18:34 2022
    SummaryFeature update for dmidecode
    Typefeature
    Severitymoderate
    References
    Description:

    This feature update for dmidecode fixes the following issues:
    Update dmidecode from version 3.2 to version 3.4 (jsc#SLE-24502, jsc#SLE-24591, jsc#PED-411):


    Advisory IDSUSE-SU-2022:3525-1
    ReleasedWed Oct 5 12:17:14 2022
    SummarySecurity update for cifs-utils
    Typesecurity
    Severitymoderate
    References1198976,CVE-2022-29869
    Description:

    This update for cifs-utils fixes the following issues:


    Advisory IDSUSE-SU-2022:3544-1
    ReleasedThu Oct 6 13:48:42 2022
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1202624,CVE-2021-28861
    Description:

    This update for python3 fixes the following issues:


    Advisory IDSUSE-RU-2022:3555-1
    ReleasedMon Oct 10 14:05:12 2022
    SummaryRecommended update for aaa_base
    Typerecommended
    Severityimportant
    References1199492
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2022:3784-1
    ReleasedWed Oct 26 18:03:28 2022
    SummarySecurity update for libtasn1
    Typesecurity
    Severitycritical
    References1204690,CVE-2021-46848
    Description:

    This update for libtasn1 fixes the following issues:


    Advisory IDSUSE-RU-2022:3787-1
    ReleasedThu Oct 27 04:41:09 2022
    SummaryRecommended update for permissions
    Typerecommended
    Severityimportant
    References1194047,1203911
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:3806-1
    ReleasedThu Oct 27 17:21:11 2022
    SummarySecurity update for dbus-1
    Typesecurity
    Severityimportant
    References1087072,1204111,1204112,1204113,CVE-2022-42010,CVE-2022-42011,CVE-2022-42012
    Description:

    This update for dbus-1 fixes the following issues:
    - CVE-2022-42010: Fixed potential crash that could be triggered by an invalid signature (bsc#1204111). - CVE-2022-42011: Fixed an out of bounds read caused by a fixed length array (bsc#1204112). - CVE-2022-42012: Fixed a use-after-free that could be trigged by a message in non-native endianness with out-of-band Unix file descriptor (bsc#1204113).
    Bugfixes:
    - Disable asserts (bsc#1087072).


    Advisory IDSUSE-SU-2022:3884-1
    ReleasedMon Nov 7 10:59:26 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1204708,CVE-2022-43680
    Description:

    This update for expat fixes the following issues:
    - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).


    Advisory IDSUSE-RU-2022:3900-1
    ReleasedTue Nov 8 10:47:55 2022
    SummaryRecommended update for docker
    Typerecommended
    Severitymoderate
    References1200022
    Description:

    This update for docker fixes the following issues:


    Advisory IDSUSE-RU-2022:3910-1
    ReleasedTue Nov 8 13:05:04 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:3917-1
    ReleasedTue Nov 8 16:41:28 2022
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1203164,1203181
    Description:

    This update for python-azure-agent fixes the following issues:


    Advisory IDSUSE-RU-2022:3927-1
    ReleasedWed Nov 9 14:55:47 2022
    SummaryRecommended update for runc
    Typerecommended
    Severitymoderate
    References1202021,1202821
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-RU-2022:3985-1
    ReleasedTue Nov 15 12:54:11 2022
    Summary Recommended update for python-apipkg
    Typerecommended
    Severitymoderate
    References1204145
    Description:


    This update fixes for python3-apipkg the following issues:


    Advisory IDSUSE-SU-2022:3991-1
    ReleasedTue Nov 15 13:54:13 2022
    SummarySecurity update for dhcp
    Typesecurity
    Severitymoderate
    References1203988,1203989,CVE-2022-2928,CVE-2022-2929
    Description:

    This update for dhcp fixes the following issues:
    - CVE-2022-2928: Fixed an option refcount overflow (bsc#1203988). - CVE-2022-2929: Fixed a DHCP memory leak (bsc#1203989).


    Advisory IDSUSE-RU-2022:4062-1
    ReleasedFri Nov 18 09:05:07 2022
    SummaryRecommended update for libusb-1_0
    Typerecommended
    Severitymoderate
    References1201590
    Description:

    This update for libusb-1_0 fixes the following issues:


    Advisory IDSUSE-RU-2022:4063-1
    ReleasedFri Nov 18 09:07:50 2022
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-SU-2022:4081-1
    ReleasedFri Nov 18 15:40:46 2022
    SummarySecurity update for dpkg
    Typesecurity
    Severitylow
    References1199944,CVE-2022-1664
    Description:

    This update for dpkg fixes the following issues:


    Advisory IDSUSE-RU-2022:4135-1
    ReleasedMon Nov 21 00:13:40 2022
    SummaryRecommended update for libeconf
    Typerecommended
    Severitymoderate
    References1198165
    Description:

    This update for libeconf fixes the following issues:



    Advisory IDSUSE-RU-2022:4256-1
    ReleasedMon Nov 28 12:36:32 2022
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
    The Go, D and Ada language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-SU-2022:4281-1
    ReleasedTue Nov 29 15:46:10 2022
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1188607,1203125,1204577,CVE-2019-18348,CVE-2020-10735,CVE-2020-8492,CVE-2022-37454
    Description:

    This update for python3 fixes the following issues:


    The following non-security bug was fixed:


    Advisory IDSUSE-RU-2022:4312-1
    ReleasedFri Dec 2 11:16:47 2022
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1200657,1203600
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-RU-2022:4328-1
    ReleasedTue Dec 6 12:25:12 2022
    SummaryRecommended update for audit-secondary
    Typerecommended
    Severitymoderate
    References1204844
    Description:

    This update for audit-secondary fixes the following issues:


    Advisory IDSUSE-RU-2022:4412-1
    ReleasedTue Dec 13 04:47:03 2022
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1204706
    Description:

    This update for suse-build-key fixes the following issues:


    Advisory IDSUSE-SU-2022:4463-1
    ReleasedTue Dec 13 17:04:31 2022
    SummarySecurity update for containerd
    Typesecurity
    Severityimportant
    References1197284,1206065,1206235,CVE-2022-23471,CVE-2022-27191
    Description:

    This update for containerd fixes the following issues:
    Update to containerd v1.6.12 including Docker v20.10.21-ce (bsc#1206065).
    Also includes the following fix:


    Advisory IDSUSE-SU-2022:4628-1
    ReleasedWed Dec 28 09:23:13 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1206337,CVE-2022-46908
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-SU-2023:37-1
    ReleasedFri Jan 6 15:35:49 2023
    SummarySecurity update for ca-certificates-mozilla
    Typesecurity
    Severityimportant
    References1206212,1206622
    Description:

    This update for ca-certificates-mozilla fixes the following issues:


    Advisory IDSUSE-RU-2023:46-1
    ReleasedMon Jan 9 10:35:21 2023
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2023:48-1
    ReleasedMon Jan 9 10:37:54 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1199467
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2023:139-1
    ReleasedWed Jan 25 14:41:55 2023
    SummarySecurity update for python-certifi
    Typesecurity
    Severityimportant
    References1206212,CVE-2022-23491
    Description:

    This update for python-certifi fixes the following issues:


    Advisory IDSUSE-SU-2023:159-1
    ReleasedThu Jan 26 18:21:56 2023
    SummarySecurity update for python-setuptools
    Typesecurity
    Severitymoderate
    References1206667,CVE-2022-40897
    Description:

    This update for python-setuptools fixes the following issues:


    Advisory IDSUSE-SU-2023:161-1
    ReleasedThu Jan 26 18:23:16 2023
    SummarySecurity update for python-py
    Typesecurity
    Severitymoderate
    References1204364,CVE-2022-42969
    Description:

    This update for python-py fixes the following issues:


    Advisory IDSUSE-RU-2023:179-1
    ReleasedThu Jan 26 21:54:30 2023
    SummaryRecommended update for tar
    Typerecommended
    Severitylow
    References1202436
    Description:

    This update for tar fixes the following issue:


    Advisory IDSUSE-RU-2023:181-1
    ReleasedThu Jan 26 21:55:43 2023
    SummaryRecommended update for procps
    Typerecommended
    Severitylow
    References1206412
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-SU-2023:463-1
    ReleasedMon Feb 20 16:33:39 2023
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1202436,1207753,CVE-2022-48303
    Description:

    This update for tar fixes the following issues:


    Bug fixes:


    Advisory IDSUSE-SU-2023:486-1
    ReleasedThu Feb 23 10:38:13 2023
    SummarySecurity update for c-ares
    Typesecurity
    Severityimportant
    References1208067,CVE-2022-4904
    Description:

    This update for c-ares fixes the following issues:
    Updated to version 1.19.0:
    - CVE-2022-4904: Fixed missing string length check in config_sortlist() (bsc#1208067).


    Advisory IDSUSE-SU-2023:549-1
    ReleasedMon Feb 27 17:35:07 2023
    SummarySecurity update for python3
    Typesecurity
    Severitymoderate
    References1205244,1208443,CVE-2022-45061
    Description:

    This update for python3 fixes the following issues:
    - CVE-2022-45061: Fixed DoS when IDNA decodes extremely long domain names (bsc#1205244).
    Bugfixes:
    - Fixed issue where email.generator.py replaces a non-existent header (bsc#1208443).


    Advisory IDSUSE-SU-2023:557-1
    ReleasedTue Feb 28 09:29:15 2023
    SummarySecurity update for libxslt
    Typesecurity
    Severityimportant
    References1208574,CVE-2021-30560
    Description:

    This update for libxslt fixes the following issues:


    Advisory IDSUSE-RU-2023:617-1
    ReleasedFri Mar 3 16:49:06 2023
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1207789
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-RU-2023:709-1
    ReleasedFri Mar 10 16:04:41 2023
    SummaryRecommended update for console-setup
    Typerecommended
    Severitymoderate
    References1202853
    Description:

    This update for console-setup and kbd fixes the following issue:


    Advisory IDSUSE-RU-2023:713-1
    ReleasedMon Mar 13 10:25:04 2023
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for suse-build-key fixes the following issues:
    This update provides multiple new 4096 RSA keys for SUSE Linux Enterprise 15, SUSE Manager 4.2/4.3, Storage 7.1, SUSE Registry) that we will switch to mid of 2023. (jsc#PED-2777)


    Advisory IDSUSE-SU-2023:722-1
    ReleasedTue Mar 14 14:57:15 2023
    SummarySecurity update for python-cryptography
    Typesecurity
    Severitymoderate
    References1208036,CVE-2023-23931
    Description:

    This update for python-cryptography fixes the following issues:
    - CVE-2023-23931: Fixed memory corruption due to invalidly changed immutable object (bsc#1208036).


    Advisory IDSUSE-RU-2023:776-1
    ReleasedThu Mar 16 17:29:23 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
    SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes

    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided in the SUSE Linux Enterprise Module for Development Tools.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-SU-2023:794-1
    ReleasedFri Mar 17 08:42:12 2023
    SummarySecurity update for python-PyJWT
    Typesecurity
    Severitycritical
    References1176785,1199282,1199756,CVE-2022-29217
    Description:

    This update for python-PyJWT fixes the following issues:




    Advisory IDSUSE-SU-2023:795-1
    ReleasedFri Mar 17 09:13:12 2023
    SummarySecurity update for docker
    Typesecurity
    Severitymoderate
    References1205375,1206065,CVE-2022-36109
    Description:


    This update for docker fixes the following issues:
    Docker was updated to 20.10.23-ce.
    See upstream changelog at https://docs.docker.com/engine/release-notes/#201023
    Docker was updated to 20.10.21-ce (bsc#1206065)
    See upstream changelog at https://docs.docker.com/engine/release-notes/#201021
    Security issues fixed:



    Advisory IDSUSE-SU-2023:868-1
    ReleasedWed Mar 22 09:41:01 2023
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1203355,1208471,CVE-2023-24329
    Description:

    This update for python3 fixes the following issues:


    The following non-security bug was fixed:


    Advisory IDSUSE-SU-2023:1628-1
    ReleasedTue Mar 28 12:28:51 2023
    SummarySecurity update for containerd
    Typesecurity
    Severityimportant
    References1206235,CVE-2022-23471
    Description:

    This update for containerd fixes the following issues:



    Advisory IDSUSE-SU-2023:1702-1
    ReleasedThu Mar 30 15:23:23 2023
    SummarySecurity update for shim
    Typesecurity
    Severityimportant
    References1185232,1185261,1185441,1185621,1187071,1187260,1193282,1198458,1201066,1202120,1205588,CVE-2022-28737
    Description:

    This update for shim fixes the following issues:




    Update to 15.7 (bsc#1198458) (jsc#PED-127):

    Other fixes:


    Update to 15.6 (bsc#1198458):

    Update to 15.5 (bsc#1198458):





    - Updated dbx-cert.tar.xz and vendor-dbx-sles.bin for adding SLES-UEFI-SIGN-Certificate-2021-05.crt to vendor dbx list. - Updated dbx-cert.tar.xz and vendor-dbx-opensuse.bin for adding openSUSE-UEFI-SIGN-Certificate-2021-05.crt to vendor dbx list. - Updated vendor-dbx.bin for adding SLES-UEFI-SIGN-Certificate-2021-05.crt and openSUSE-UEFI-SIGN-Certificate-2021-05.crt for testing environment. - Updated generate-vendor-dbx.sh script for generating a vendor-dbx.bin file which includes all .der for testing environment.


    Advisory IDSUSE-SU-2023:1827-1
    ReleasedThu Apr 13 10:18:16 2023
    SummarySecurity update for containerd
    Typesecurity
    Severitymoderate
    References1208423,1208426,CVE-2023-25153,CVE-2023-25173
    Description:

    This update for containerd fixes the following issues:
    Update to containerd v1.6.19:
    Security fixes:


    Advisory IDSUSE-RU-2023:1880-1
    ReleasedTue Apr 18 11:11:27 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References1208079
    Description:

    This update for systemd-rpm-macros fixes the following issue:


    Advisory IDSUSE-RU-2023:1920-1
    ReleasedWed Apr 19 16:22:58 2023
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-SU-2023:1947-1
    ReleasedFri Apr 21 14:14:41 2023
    SummarySecurity update for dmidecode
    Typesecurity
    Severitymoderate
    References1210418,CVE-2023-30630
    Description:

    This update for dmidecode fixes the following issues:


    Advisory IDSUSE-SU-2023:2003-1
    ReleasedTue Apr 25 18:05:42 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1168481,1208962,1209884,1209888,CVE-2023-25809,CVE-2023-27561,CVE-2023-28642
    Description:

    This update for runc fixes the following issues:
    Update to runc v1.1.5:
    Security fixes:


    Other fixes:
    - Fix the inability to use `/dev/null` when inside a container. - Fix changing the ownership of host's `/dev/null` caused by fd redirection (bsc#1168481). - Fix rare runc exec/enter unshare error on older kernels. - nsexec: Check for errors in `write_log()`. - Drop version-specific Go requirement.


    Advisory IDSUSE-SU-2023:2084-1
    ReleasedTue May 2 13:31:52 2023
    SummarySecurity update for shim
    Typesecurity
    Severityimportant
    References1210382,CVE-2022-28737
    Description:

    This update for shim fixes the following issues:



    After closing Leap-gap project since Leap 15.3, openSUSE Leap direct uses shim from SLE. So the ca_string is 'SUSE Linux Enterprise Secure Boot CA1', not 'openSUSE Secure Boot CA1'. It causes that the update_boot=no, so all files in /boot/efi/EFI/boot are not updated.
    Logic was added that is using ID field in os-release for checking Leap distro and set ca_string to 'SUSE Linux Enterprise Secure Boot CA1'. Then /boot/efi/EFI/boot/* can also be updated.


    Advisory IDSUSE-RU-2023:2104-1
    ReleasedThu May 4 21:05:30 2023
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1209122
    Description:

    This update for procps fixes the following issue:


    Advisory IDSUSE-SU-2023:2111-1
    ReleasedFri May 5 14:34:00 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1210434,CVE-2023-29491
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-SU-2023:2135-1
    ReleasedTue May 9 13:38:11 2023
    SummarySecurity update for libfastjson
    Typesecurity
    Severityimportant
    References1171479,CVE-2020-12762
    Description:

    This update for libfastjson fixes the following issues:


    Advisory IDSUSE-RU-2023:2166-1
    ReleasedWed May 10 20:18:51 2023
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severitymoderate
    References1209026
    Description:

    This update for supportutils-plugin-suse-public-cloud fixes the following issues:


    Advisory IDSUSE-feature-2023:2192-1
    ReleasedFri May 12 12:49:02 2023
    SummaryFeature update for python311, python311-pip, python311-setuptools
    Typefeature
    Severitymoderate
    References
    Description:

    This release of python311, python311-pip, python311-setuptools adds the following feature:


    Advisory IDSUSE-RU-2023:2216-1
    ReleasedTue May 16 11:27:50 2023
    SummaryRecommended update for python-packaging
    Typerecommended
    Severityimportant
    References1186870,1199282
    Description:

    This update for python-packaging fixes the following issues:









    Advisory IDSUSE-SU-2023:2254-1
    ReleasedFri May 19 15:20:23 2023
    SummarySecurity update for containerd
    Typesecurity
    Severityimportant
    References1210298
    Description:

    This update for containerd fixes the following issues:


    Advisory IDSUSE-SU-2023:2256-1
    ReleasedFri May 19 15:26:43 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1200441
    Description:


    This update of runc fixes the following issues:


    Advisory IDSUSE-RU-2023:2307-1
    ReleasedMon May 29 10:29:49 2023
    SummaryRecommended update for kbd
    Typerecommended
    Severitylow
    References1210702
    Description:

    This update for kbd fixes the following issue:


    Advisory IDSUSE-SU-2023:2313-1
    ReleasedTue May 30 09:29:25 2023
    SummarySecurity update for c-ares
    Typesecurity
    Severityimportant
    References1211604,1211605,1211606,1211607,CVE-2023-31124,CVE-2023-31130,CVE-2023-31147,CVE-2023-32067
    Description:

    This update for c-ares fixes the following issues:
    Update to version 1.19.1:


    Advisory IDSUSE-RU-2023:2430-1
    ReleasedTue Jun 6 22:55:28 2023
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severitycritical
    References
    Description:

    This update for supportutils-plugin-suse-public-cloud fixes the following issues:
    - This update will be delivered to SLE Micro. (SMO-219)


    Advisory IDSUSE-RU-2023:2482-1
    ReleasedMon Jun 12 07:19:53 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1211272
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-SU-2023:2517-1
    ReleasedThu Jun 15 07:09:52 2023
    SummarySecurity update for python3
    Typesecurity
    Severitymoderate
    References1203750,1211158,CVE-2007-4559
    Description:

    This update for python3 fixes the following issues:



    Advisory IDSUSE-RU-2023:2625-1
    ReleasedFri Jun 23 17:16:11 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:


    * includes regression and other bug fixes


    Advisory IDSUSE-SU-2023:2628-1
    ReleasedFri Jun 23 21:43:22 2023
    SummarySecurity update for cloud-init
    Typesecurity
    Severityimportant
    References1171511,1203393,1210277,1210652,CVE-2022-2084,CVE-2023-1786
    Description:

    This update for cloud-init fixes the following issues:


    + Support transactional-updates for SUSE based distros + Set ownership for new folders in Write Files Module + add OpenCloudOS and TencentOS support + lxd: Retry if the server isn't ready + test: switch pycloudlib source to pypi + test: Fix integration test deprecation message + Recognize opensuse-microos, dev tooling fixes + sources/azure: refactor imds handler into own module + docs: deprecation generation support + add function is_virtual to distro/FreeBSD + cc_ssh: support multiple hostcertificates + Fix minor schema validation regression and fixup typing + doc: Reword user data debug section + cli: schema also validate vendordata*. + ci: sort and add checks for cla signers file + Add 'ederst' as contributor + readme: add reference to packages dir + docs: update downstream package list + docs: add google search verification + docs: fix 404 render use default notfound_urls_prefix in RTD conf + Fix OpenStack datasource detection on bare metal + docs: add themed RTD 404 page and pointer to readthedocs-hosted + schema: fix gpt labels, use type string for GUID + cc_disk_setup: code cleanup + netplan: keep custom strict perms when 50-cloud-init.yaml exists + cloud-id: better handling of change in datasource files + Warn on empty network key + Fix Vultr cloud_interfaces usage + cc_puppet: Update puppet service name + docs: Clarify networking docs + lint: remove httpretty + cc_set_passwords: Prevent traceback when restarting ssh + tests: fix lp1912844 + tests: Skip ansible test on bionic + Wait for NetworkManager + docs: minor polishing + CI: migrate integration-test to GH actions + Fix permission of SSH host keys + Fix default route rendering on v2 ipv6 + doc: fix path in net_convert command + docs: update net_convert docs + doc: fix dead link + cc_set_hostname: ignore /var/lib/cloud/data/set-hostname if it's empty + distros/rhel.py: _read_hostname() missing strip on 'hostname' + integration tests: add IBM VPC support + machine-id: set to uninitialized to trigger regeneration on clones + sources/azure: retry on connection error when fetching metdata + Ensure ssh state accurately obtained + bddeb: drop dh-systemd dependency on newer deb-based releases + doc: fix `config formats` link in cloudsigma.rst + Fix wrong subp syntax in cc_set_passwords.py + docs: update the PR template link to readthedocs + ci: switch unittests to gh actions + Add mount_default_fields for PhotonOS. + sources/azure: minor refactor for metadata source detection logic + add 'CalvoM' as contributor + ci: doc to gh actions + lxd: handle 404 from missing devices route for LXD 4.0 + docs: Diataxis overhaul + vultr: Fix issue regarding cache and region codes + cc_set_passwords: Move ssh status checking later + Improve Wireguard module idempotency + network/netplan: add gateways as on-link when necessary + tests: test_lxd assert features.networks.zones when present + Use btrfs enquque when available (#1926) [Robert Schweikert] + sources/azure: fix device driver matching for net config (#1914) + BSD: fix duplicate macs in Ifconfig parser + pycloudlib: add lunar support for integration tests + nocloud: add support for dmi variable expansion for seedfrom URL + tools: read-version drop extra call to git describe --long + doc: improve cc_write_files doc + read-version: When insufficient tags, use cloudinit.version.get_version + mounts: document weird prefix in schema + Ensure network ready before cloud-init service runs on RHEL + docs: add copy button to code blocks + netplan: define features.NETPLAN_CONFIG_ROOT_READ_ONLY flag + azure: fix support for systems without az command installed + Fix the distro.osfamily output problem in the openEuler system. + pycloudlib: bump commit dropping azure api smoke test + net: netplan config root read-only as wifi config can contain creds + autoinstall: clarify docs for users + sources/azure: encode health report as utf-8 + Add back gateway4/6 deprecation to docs + networkd: Add support for multiple [Route] sections + doc: add qemu tutorial + lint: fix tip-flake8 and tip-mypy + Add support for setting uid when creating users on FreeBSD + Fix exception in BSD networking code-path + Append derivatives to is_rhel list in cloud.cfg.tmpl + FreeBSD init: use cloudinit_enable as only rcvar + feat: add support aliyun metadata security harden mode + docs: uprate analyze to performance page + test: fix lxd preseed managed network config + Add support for static IPv6 addresses for FreeBSD + Make 3.12 failures not fail the build + Docs: adding relative links + Fix setup.py to align with PEP 440 versioning replacing trailing + Add 'nkukard' as contributor + doc: add how to render new module doc + doc: improve module creation explanation + Add Support for IPv6 metadata to OpenStack + add xiaoge1001 to .github-cla-signers + network: Deprecate gateway{4,6} keys in network config v2 + VMware: Move Guest Customization transport from OVF to VMware + doc: home page links added + net: skip duplicate mac check for netvsc nic and its VF
    This update for python-responses fixes the following issues:


    Advisory IDSUSE-RU-2023:2649-1
    ReleasedTue Jun 27 10:01:13 2023
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:


    Advisory IDSUSE-RU-2023:2658-1
    ReleasedTue Jun 27 14:46:15 2023
    SummaryRecommended update for containerd, docker, runc
    Typerecommended
    Severitymoderate
    References1207004,1208074,1210298,1211578
    Description:

    This update for containerd, docker, runc fixes the following issues:


    Advisory IDSUSE-SU-2023:2765-1
    ReleasedMon Jul 3 20:28:14 2023
    SummarySecurity update for libcap
    Typesecurity
    Severitymoderate
    References1211418,1211419,CVE-2023-2602,CVE-2023-2603
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-RU-2023:2827-1
    ReleasedFri Jul 14 11:27:47 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:2847-1
    ReleasedMon Jul 17 08:40:42 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1210004
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-SU-2023:2866-1
    ReleasedTue Jul 18 11:09:03 2023
    SummarySecurity update for python-requests
    Typesecurity
    Severitymoderate
    References1211674,CVE-2023-32681
    Description:

    This update for python-requests fixes the following issues:


    Advisory IDSUSE-SU-2023:2877-1
    ReleasedWed Jul 19 09:43:42 2023
    SummarySecurity update for dbus-1
    Typesecurity
    Severitymoderate
    References1212126,CVE-2023-34969
    Description:

    This update for dbus-1 fixes the following issues:


    Advisory IDSUSE-SU-2023:2882-1
    ReleasedWed Jul 19 11:49:39 2023
    SummarySecurity update for perl
    Typesecurity
    Severityimportant
    References1210999,CVE-2023-31484
    Description:

    This update for perl fixes the following issues:

    - CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).


    Advisory IDSUSE-feature-2023:2898-1
    ReleasedThu Jul 20 09:15:33 2023
    SummaryRecommended update for python-instance-billing-flavor-check
    Typefeature
    Severitycritical
    References
    Description:

    This update for python-instance-billing-flavor-check fixes the following issues:


    Advisory IDSUSE-RU-2023:2905-1
    ReleasedThu Jul 20 10:17:54 2023
    SummaryRecommended update for fstrm
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for fstrm fixes the following issues:


    - fstrm_capture: ignore SIGPIPE, which will cause the interrupted connections to generate an EPIPE instead. - Fix truncation in snprintf calls in argument processing. - fstrm_capture: Fix output printf format.

    It adds a new feature for fstrm_capture. It can perform output file rotation when a SIGUSR1 signal is received by fstrm_capture. (See the --gmtime or --localtime options.) This allows fstrm_capture's output file to be rotated by logrotate or a similar external utility. (Output rotation is suppressed if fstrm_capture is writing to stdout.)
    Update to 0.5.0

    Update to 0.4.0
    The C implementation of the Frame Streams data transport protocol, fstrm version 0.4.0, was released. It adds TCP support, a new tool, new documentation, and several improvements.


    Advisory IDSUSE-RU-2023:2918-1
    ReleasedThu Jul 20 12:00:17 2023
    SummaryRecommended update for gpgme
    Typerecommended
    Severitymoderate
    References1089497
    Description:

    This update for gpgme fixes the following issues:
    gpgme:

    libassuan:


    Advisory IDSUSE-RU-2023:2966-1
    ReleasedTue Jul 25 14:26:14 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3117-1
    ReleasedWed Aug 2 05:57:30 2023
    SummaryRecommended update for hwinfo
    Typerecommended
    Severitymoderate
    References1212756
    Description:

    This update for hwinfo fixes the following issues:


    Advisory IDSUSE-RU-2023:335-1
    ReleasedThu Aug 10 16:26:04 2023
    SummaryRecommended update for hyper-v
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hyper-v fixes the following issues: - Provide the latest version for SLE-15-SP4.


    Advisory IDSUSE-RU-2023:3282-1
    ReleasedFri Aug 11 10:26:23 2023
    SummaryRecommended update for blog
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for blog fixes the following issues:


    Advisory IDSUSE-feature-2023:3283-1
    ReleasedFri Aug 11 10:28:34 2023
    SummaryFeature update for cloud-init
    Typefeature
    Severitymoderate
    References1184758,1210273,1212879,CVE-2021-3429,CVE-2023-1786
    Description:

    This update for cloud-init fixes the following issues:


    Advisory IDSUSE-SU-2023:3301-1
    ReleasedMon Aug 14 07:24:59 2023
    SummarySecurity update for libyajl
    Typesecurity
    Severitymoderate
    References1212928,CVE-2023-33460
    Description:

    This update for libyajl fixes the following issues:
    - CVE-2023-33460: Fixed memory leak which could cause out-of-memory in server (bsc#1212928).


    Advisory IDSUSE-RU-2023:3330-1
    ReleasedWed Aug 16 08:59:33 2023
    SummaryRecommended update for python-pyasn1
    Typerecommended
    Severityimportant
    References1207805
    Description:

    This update for python-pyasn1 fixes the following issues:


    Advisory IDSUSE-SU-2023:3369-1
    ReleasedTue Aug 22 11:12:02 2023
    SummarySecurity update for python-configobj
    Typesecurity
    Severitylow
    References1210070,CVE-2023-26112
    Description:

    This update for python-configobj fixes the following issues:


    Advisory IDSUSE-RU-2023:3371-1
    ReleasedTue Aug 22 13:30:18 2023
    SummaryRecommended update for liblognorm
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for liblognorm fixes the following issues:


    Advisory IDSUSE-RU-2023:3410-1
    ReleasedThu Aug 24 06:56:32 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1201519,1204844
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-SU-2023:3440-1
    ReleasedMon Aug 28 08:57:10 2023
    SummarySecurity update for gawk
    Typesecurity
    Severitylow
    References1214025,CVE-2023-4156
    Description:

    This update for gawk fixes the following issues:


    Advisory IDSUSE-RU-2023:3452-1
    ReleasedMon Aug 28 12:41:11 2023
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severitymoderate
    References1213951
    Description:

    This update for supportutils-plugin-suse-public-cloud fixes the following issues:


    Advisory IDSUSE-SU-2023:3454-1
    ReleasedMon Aug 28 13:43:18 2023
    SummarySecurity update for ca-certificates-mozilla
    Typesecurity
    Severityimportant
    References1214248
    Description:

    This update for ca-certificates-mozilla fixes the following issues:


    Advisory IDSUSE-SU-2023:3461-1
    ReleasedMon Aug 28 17:25:09 2023
    SummarySecurity update for freetype2
    Typesecurity
    Severitymoderate
    References1210419,CVE-2023-2004
    Description:

    This update for freetype2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3468-1
    ReleasedTue Aug 29 09:22:18 2023
    SummaryRecommended update for python3
    Typerecommended
    Severitylow
    References
    Description:

    This update for python3 fixes the following issue:


    Advisory IDSUSE-RU-2023:3470-1
    ReleasedTue Aug 29 10:49:33 2023
    SummaryRecommended update for parted
    Typerecommended
    Severitylow
    References1182142,1193412
    Description:

    This update for parted fixes the following issues:


    Advisory IDSUSE-SU-2023:3472-1
    ReleasedTue Aug 29 10:55:16 2023
    SummarySecurity update for procps
    Typesecurity
    Severitylow
    References1214290,CVE-2023-4016
    Description:

    This update for procps fixes the following issues:
    - CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290).


    Advisory IDSUSE-SU-2023:3497-1
    ReleasedWed Aug 30 21:25:05 2023
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1210996,1211256,1211257,1211461,CVE-2023-2426,CVE-2023-2609,CVE-2023-2610
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.0 with patch level 1572.


    Advisory IDSUSE-RU-2023:3521-1
    ReleasedTue Sep 5 08:56:45 2023
    SummaryRecommended update for python-iniconfig
    Typerecommended
    Severitymoderate
    References1213582
    Description:


    This update for python-iniconfig provides python3-iniconfig to SUSE Linux Enterprise Micro 5.2.


    Advisory IDSUSE-SU-2023:3536-1
    ReleasedTue Sep 5 15:00:27 2023
    SummarySecurity update for docker
    Typesecurity
    Severitymoderate
    References1210797,1212368,1213120,1213229,1213500,1214107,1214108,1214109,CVE-2023-28840,CVE-2023-28841,CVE-2023-28842
    Description:

    This update for docker fixes the following issues:


    See upstream changelong online at bsc#1213229

    See upstream changelog online at . bsc#1213500

    See upstream changelog online at . bsc#1213120
    • Recommend docker-rootless-extras instead of Require(ing) it, given it's an additional functionality and not inherently required for docker to function.

    • Add docker-rootless-extras subpackage (https://docs.docker.com/engine/security/rootless)

    • Update to Docker 24.0.2-ce. See upstream changelog online at . bsc#1212368

    * Includes the upstreamed fix for the mount table pollution issue. bsc#1210797
    • Add Recommends for docker-buildx, and add /usr/lib/docker/cli-plugins as being provided by this package.

    • was rebuilt against current GO compiler.


    Advisory IDSUSE-RU-2023:3611-1
    ReleasedFri Sep 15 09:28:36 2023
    SummaryRecommended update for sysuser-tools
    Typerecommended
    Severitymoderate
    References1195391,1205161,1207778,1213240,1214140
    Description:

    This update for sysuser-tools fixes the following issues:

    • Update to version 3.2
    • Always create a system group of the same name as the system user (bsc#1205161, bsc#1207778, bsc#1213240)
    • Add 'quilt setup' friendly hint to %sysusers_requires usage
    • Use append so if a pre file already exists it isn't overridden
    • Invoke bash for bash scripts (bsc#1195391)
    • Remove all systemd requires not supported on SLE15 (bsc#1214140)


    Advisory IDSUSE-SU-2023:3661-1
    ReleasedMon Sep 18 21:44:09 2023
    SummarySecurity update for gcc12
    Typesecurity
    Severityimportant
    References1214052,CVE-2023-4039
    Description:

    This update for gcc12 fixes the following issues:

    • CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).


    Advisory IDSUSE-SU-2023:3666-1
    ReleasedMon Sep 18 21:52:18 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severityimportant
    References1214768,CVE-2023-39615
    Description:

    This update for libxml2 fixes the following issues:

    • CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).


    Advisory IDSUSE-RU-2023:3780-1
    ReleasedTue Sep 26 10:58:21 2023
    SummaryRecommended update hidapi
    Typerecommended
    Severitymoderate
    References1214535
    Description:


    This update for hidapi ships the missing libhidapi-raw0 library to SLE and Leap Micro 5.3 and 5.4.


    Advisory IDSUSE-SU-2023:3817-1
    ReleasedWed Sep 27 18:31:14 2023
    SummarySecurity update for containerd
    Typesecurity
    Severityimportant
    References1212475
    Description:


    This update of containerd fixes the following issues:

    • rebuild the package with the go 1.21 security release (bsc#1212475).


    Advisory IDSUSE-SU-2023:3828-1
    ReleasedWed Sep 27 19:07:38 2023
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1214692,CVE-2023-40217
    Description:

    This update for python3 fixes the following issues:

    • CVE-2023-40217: Fixed TLS handshake bypass on closed sockets (bsc#1214692).


    Advisory IDSUSE-RU-2023:3843-1
    ReleasedWed Sep 27 20:18:06 2023
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severityimportant
    References
    Description:

    This update for suse-build-key fixes the following issues:
    This update adds and runs a import-suse-build-key script.
    It is run after installation with libzypp based installers. (jsc#PED-2777)
    It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys.
    To manually import them you can also run:
    # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc


    Advisory IDSUSE-SU-2023:3952-1
    ReleasedTue Oct 3 20:06:23 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1212475
    Description:


    This update of runc fixes the following issues:

    • Update to runc v1.1.8.

    Upstream changelog is available from .
    • rebuild the package with the go 1.21 security release (bsc#1212475).


    Advisory IDSUSE-SU-2023:3954-1
    ReleasedTue Oct 3 20:09:47 2023
    SummarySecurity update for libeconf
    Typesecurity
    Severityimportant
    References1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181
    Description:

    This update for libeconf fixes the following issues:
    Update to version 0.5.2.

    • CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078).
    • CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078)


    Advisory IDSUSE-RU-2023:4073-1
    ReleasedFri Oct 13 11:40:26 2023
    SummaryRecommended update for rpm
    Typerecommended
    Severitylow
    References
    Description:

    This update for rpm fixes the following issue:

    • Enables build for all python modules (jsc#PED-68, jsc#PED-1988)


    Advisory IDSUSE-SU-2023:4108-1
    ReleasedWed Oct 18 11:51:12 2023
    SummarySecurity update for python-urllib3
    Typesecurity
    Severitymoderate
    References1215968,CVE-2023-43804
    Description:

    This update for python-urllib3 fixes the following issues:

    • CVE-2023-43804: Fixed a potential cookie leak via HTTP redirect if the user manually set the corresponding header (bsc#1215968).


    Advisory IDSUSE-RU-2023:4138-1
    ReleasedThu Oct 19 17:15:38 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:

    • Switch to `systemd-hwdb` tool when updating the HW database. It's been introduced in systemd v219 and replaces the deprecated command `udevadm hwdb`.


    Advisory IDSUSE-RU-2023:4139-1
    ReleasedFri Oct 20 10:06:58 2023
    SummaryRecommended update for containerd, runc
    Typerecommended
    Severitymoderate
    References1215323
    Description:

    This update for containerd, runc fixes the following issues:
    runc was updated to v1.1.9. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.1.9
    containerd was updated to containerd v1.7.7 for Docker v24.0.6-ce. Upstream release notes:

    • https://github.com/containerd/containerd/releases/tag/v1.7.7
    • https://github.com/containerd/containerd/releases/tag/v1.7.6 bsc#1215323
    • Add `Provides: cri-runtime` to use containerd as container runtime in Factory Kubernetes packages


    Advisory IDSUSE-RU-2023:4154-1
    ReleasedFri Oct 20 19:33:25 2023
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1107342,1215434
    Description:

    This update for aaa_base fixes the following issues:

    • Respect /etc/update-alternatives/java when setting JAVA_HOME (bsc#1215434,bsc#1107342)


    Advisory IDSUSE-SU-2023:4162-1
    ReleasedMon Oct 23 15:33:03 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:

    • install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
    • override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages.

    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:

    • CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052)

    • Turn cross compiler to s390x to a glibc cross. [bsc#1214460]

    • Also handle -static-pie in the default-PIE specs
    • Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101]
    • Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427]
    • Add new x86-related intrinsics (amxcomplexintrin.h).
    • RISC-V: Add support for inlining subword atomic operations
    • Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver.
    • Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC.
    • Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing.
    • Bump included newlib to version 4.3.0.
    • Also package libhwasan_preinit.o on aarch64.
    • Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite.
    • Package libhwasan_preinit.o on x86_64.
    • Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
    • Enable PRU flavour for gcc13
    • update floatn fixinclude pickup to check each header separately (bsc#1206480)
    • Redo floatn fixinclude pick-up to simply keep what is there.
    • Bump libgo SONAME to libgo22.
    • Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers.
    • Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15.
    • Depend on at least LLVM 13 for GCN cross compiler.
    • Update embedded newlib to version 4.2.0
    • Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build.


    Advisory IDSUSE-feature-2023:4194-1
    ReleasedWed Oct 25 11:01:41 2023
    SummaryFeature update for python3
    Typefeature
    Severitylow
    References
    Description:

    This feature update for python3 packages adds the following:

    • First batch of python3.11 modules (jsc#PED-68)
    • Rename sources of python3-kubernetes, python3-cryptography and python3-cryptography-vectors to accommodate
    the new 3.11 versions, this 3 packages have no code changes.


    Advisory IDSUSE-SU-2023:4215-1
    ReleasedThu Oct 26 12:19:25 2023
    SummarySecurity update for zlib
    Typesecurity
    Severitymoderate
    References1216378,CVE-2023-45853
    Description:

    This update for zlib fixes the following issues:

    • CVE-2023-45853: Fixed an integer overflow that would lead to a buffer overflow in the minizip subcomponent (bsc#1216378).


    Advisory IDSUSE-RU-2023:4268-1
    ReleasedMon Oct 30 16:51:57 2023
    SummaryRecommended update for pciutils
    Typerecommended
    Severityimportant
    References1215265
    Description:

    This update for pciutils fixes the following issues:

    • Buffer overflow error that would cause lspci to crash on systems with complex topologies (bsc#1215265)


    Advisory IDSUSE-RU-2023:4310-1
    ReleasedTue Oct 31 14:10:47 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467)
    * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage
    Update to 1.3.3:

    • Fix DoS vulnerability in libtirpc - replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch
    • _rpc_dtablesize: use portable system call
    • libtirpc: Fix use-after-free accessing the error number
    • Fix potential memory leak of parms.r_addr - replaces 0001-fix-parms.r_addr-memory-leak.patch
    • rpcb_clnt.c add mechanism to try v2 protocol first - preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch
    • Eliminate deadlocks in connects with an MT environment
    • clnt_dg_freeres() uncleared set active state may deadlock
    • thread safe clnt destruction
    • SUNRPC: mutexed access blacklist_read state variable
    • SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c

    Update to 1.3.2:
    • Replace the final SunRPC licenses with BSD licenses
    • blacklist: Add a few more well known ports
    • libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS

    Update to 1.3.1:
    • Remove AUTH_DES interfaces from auth_des.h The unsupported AUTH_DES authentication has be compiled out since commit d918e41d889 (Wed Oct 9 2019) replaced by API routines that return errors.
    • svc_dg: Free xp_netid during destroy
    • Fix memory management issues of fd locks
    • libtirpc: replace array with list for per-fd locks
    • __svc_vc_dodestroy: fix double free of xp_ltaddr.buf
    • __rpc_dtbsize: rlim_cur instead of rlim_max
    • pkg-config: use the correct replacements for libdir/includedir


    Advisory IDSUSE-SU-2023:4458-1
    ReleasedThu Nov 16 14:38:48 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:

    • install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
    • override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages.

    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:

    • CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052)

    • Work around third party app crash during C++ standard library initialization. [bsc#1216664]
    • Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427)
    • Bump included newlib to version 4.3.0.
    • Update to GCC trunk head (r13-5254-g05b9868b182bb9)
    • Redo floatn fixinclude pick-up to simply keep what is there.
    • Turn cross compiler to s390x to a glibc cross. [bsc#1214460]

    • Also handle -static-pie in the default-PIE specs
    • Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101]
    • Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427]
    • Add new x86-related intrinsics (amxcomplexintrin.h).
    • RISC-V: Add support for inlining subword atomic operations
    • Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver.
    • Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC.
    • Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing.
    • Bump included newlib to version 4.3.0.
    • Also package libhwasan_preinit.o on aarch64.
    • Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite.
    • Package libhwasan_preinit.o on x86_64.
    • Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
    • Enable PRU flavour for gcc13
    • update floatn fixinclude pickup to check each header separately (bsc#1206480)
    • Redo floatn fixinclude pick-up to simply keep what is there.
    • Bump libgo SONAME to libgo22.
    • Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers.
    • Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15.
    • Depend on at least LLVM 13 for GCN cross compiler.
    • Update embedded newlib to version 4.2.0
    • Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build.


    Advisory IDSUSE-SU-2023:4467-1
    ReleasedThu Nov 16 17:57:51 2023
    SummarySecurity update for python-urllib3
    Typesecurity
    Severitymoderate
    References1216377,CVE-2023-45803
    Description:

    This update for python-urllib3 fixes the following issues:

    • CVE-2023-45803: Fix a request body leak that could occur when receiving a 303 HTTP response (bsc#1216377).


    Advisory IDSUSE-SU-2023:4504-1
    ReleasedTue Nov 21 13:27:50 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1216129,CVE-2023-45322
    Description:

    This update for libxml2 fixes the following issues:

    • CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129).


    Advisory IDSUSE-SU-2023:4517-1
    ReleasedTue Nov 21 17:30:27 2023
    SummarySecurity update for python3-setuptools
    Typesecurity
    Severitymoderate
    References1206667,CVE-2022-40897
    Description:

    This update for python3-setuptools fixes the following issues:

    • CVE-2022-40897: Fixed Regular Expression Denial of Service (ReDoS) in package_index.py (bsc#1206667).


    Advisory IDSUSE-SU-2023:4557-1
    ReleasedFri Nov 24 17:04:36 2023
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1214922,1214924,1214925,1215004,1215006,1215033,1215940,1216001,1216167,1216696,CVE-2023-46246,CVE-2023-4733,CVE-2023-4734,CVE-2023-4735,CVE-2023-4738,CVE-2023-4752,CVE-2023-4781,CVE-2023-5344,CVE-2023-5441,CVE-2023-5535
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.0 with patch level 2103, fixes the following security problems

    • CVE-2023-5344: vim: Heap-based Buffer Overflow in vim prior to 9.0.1969 (bsc#1215940)
    • CVE-2023-5441: vim: segfault in exmode when redrawing (bsc#1216001)
    • CVE-2023-5535: vim: use-after-free from buf_contents_changed() (bsc#1216167)
    • CVE-2023-46246: vim: Integer Overflow in :history command (bsc#1216696)
    • CVE-2023-4738: vim: heap-buffer-overflow in vim_regsub_both (bsc#1214922)
    • CVE-2023-4735: vim: OOB Write ops.c (bsc#1214924)
    • CVE-2023-4734: vim: segmentation fault in function f_fullcommand (bsc#1214925)
    • CVE-2023-4733: vim: use-after-free in function buflist_altfpos (bsc#1215004)
    • CVE-2023-4752: vim: Heap Use After Free in function ins_compl_get_exp (bsc#1215006)
    • CVE-2023-4781: vim: heap-buffer-overflow in function vim_regsub_both (bsc#1215033)


    Advisory IDSUSE-feature-2023:4583-1
    ReleasedMon Nov 27 10:16:11 2023
    SummaryFeature update for python-psutil
    Typefeature
    Severitymoderate
    References1111622,1170175,1176785,1184753,1199282
    Description:

    This update for python-psutil, python-requests fixes the following issues:

    • update python-psutil to 5.9.1 (bsc#1199282, bsc#1184753, jsc#SLE-24629, jsc#PM-3243, gh#giampaolo/psutil#2043)
    • Fix tests: setuptools changed the builddir library path and does not find the module from it. Use the installed platlib instead and exclude psutil.tests only later.
    • remove the dependency on net-tools, since it conflicts with busybox-hostnmame which is default on MicroOS

    • Update python-requests to 2.25.1 (bsc#1176785, bsc#1170175, jsc#ECO-3105, jsc#PM-2352, jsc#PED-7192)
    • Fixed bug with unintended Authorization header stripping for redirects using default ports (bsc#1111622).


    Advisory IDSUSE-SU-2023:4619-1
    ReleasedThu Nov 30 10:13:52 2023
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1210660,CVE-2023-2137
    Description:

    This update for sqlite3 fixes the following issues:

    • CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660).


    Advisory IDSUSE-RU-2023:4671-1
    ReleasedWed Dec 6 14:33:41 2023
    SummaryRecommended update for man
    Typerecommended
    Severitymoderate
    References
    Description:


    This update of man fixes the following problem:

    • The 'man' commands is delivered to SUSE Linux Enterprise Micro to allow browsing man pages.


    Advisory IDSUSE-SU-2023:4672-1
    ReleasedWed Dec 6 14:37:37 2023
    SummarySecurity update for suse-build-key
    Typesecurity
    Severityimportant
    References1216410,1217215
    Description:

    This update for suse-build-key fixes the following issues:
    This update runs a import-suse-build-key script.
    The previous libzypp-post-script based installation is replaced with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777). - suse-build-key-import.service - suse-build-key-import.timer
    It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys. After successful import the timer is disabled.
    To manually import them you can also run:
    # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc


    Advisory IDSUSE-RU-2023:4700-1
    ReleasedMon Dec 11 07:03:27 2023
    SummaryRecommended update for p11-kit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for p11-kit fixes the following issues:

    • Ensure that programs using can be compiled with CRYPTOKI_GNU. Fixes GnuTLS builds (jsc#PED-6705).


    Advisory IDSUSE-RU-2023:4723-1
    ReleasedTue Dec 12 09:57:51 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1216862
    Description:

    This update for libtirpc fixes the following issue:

    • fix sed parsing in specfile (bsc#1216862)


    Advisory IDSUSE-SU-2023:4727-1
    ReleasedTue Dec 12 12:27:39 2023
    SummarySecurity update for catatonit, containerd, runc
    Typesecurity
    Severityimportant
    References1200528,CVE-2022-1996
    Description:


    This update of runc and containerd fixes the following issues:
    containerd:

    • Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8

    * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528)
    catatonit:
    • Update to catatonit v0.2.0. * Change license to GPL-2.0-or-later.

    • Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done).

    • Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors).

    runc:
    • Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10


    Advisory IDSUSE-SU-2023:4843-1
    ReleasedThu Dec 14 12:22:44 2023
    SummarySecurity update for python3-cryptography
    Typesecurity
    Severitymoderate
    References1217592,CVE-2023-49083
    Description:

    This update for python3-cryptography fixes the following issues:

    • CVE-2023-49083: Fixed a NULL pointer dereference when loading certificates from a PKCS#7 bundle (bsc#1217592).


    Advisory IDSUSE-SU-2023:4891-1
    ReleasedMon Dec 18 16:31:49 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1201384,1218014,CVE-2023-50495
    Description:

    This update for ncurses fixes the following issues:

    • CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014)
    • Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384)


    Advisory IDSUSE-SU-2023:4936-1
    ReleasedWed Dec 20 17:18:21 2023
    SummarySecurity update for docker, rootlesskit
    Typesecurity
    Severityimportant
    References1170415,1170446,1178760,1210141,1213229,1213500,1215323,1217513,CVE-2020-12912,CVE-2020-8694,CVE-2020-8695
    Description:

    This update for docker, rootlesskit fixes the following issues:
    docker:

    • Update to Docker 24.0.7-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2407>. bsc#1217513 * Deny containers access to /sys/devices/virtual/powercap by default. - CVE-2020-8694 bsc#1170415 - CVE-2020-8695 bsc#1170446 - CVE-2020-12912 bsc#1178760

    • Update to Docker 24.0.6-ce. See upstream changelong online at

    https://docs.docker.com/engine/release-notes/24.0/#2406 . bsc#1215323
    • Add a docker.socket unit file, but with socket activation effectively disabled to ensure that Docker will always run even if you start the socket individually. Users should probably just ignore this unit file. bsc#1210141

    • Update to Docker 24.0.5-ce. See upstream changelong online at

    https://docs.docker.com/engine/release-notes/24.0/#2405 . bsc#1213229
    This update ships docker-rootless support in the docker-rootless-extra package. (jsc#PED-6180)
    rootlesskit:
    • new package, for docker rootless support. (jsc#PED-6180)


    Advisory IDSUSE-RU-2023:4973-1
    ReleasedTue Dec 26 04:44:10 2023
    SummaryRecommended update for duktape
    Typerecommended
    Severitymoderate
    References1216296
    Description:


    This update of duktape fixes the following issue:

    • duktape-devel is shipped to Basesystem module (bsc#1216296).


    Advisory IDSUSE-RU-2024:11-1
    ReleasedTue Jan 2 13:24:52 2024
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1029961,1158830,1206798,1209122
    Description:

    This update for procps fixes the following issues:

    • Update procps to 3.3.17 (jsc#PED-3244 jsc#PED-6369)

    • For support up to 2048 CPU as well (bsc#1185417)
    • Allow `-´ as leading character to ignore possible errors on systctl entries (bsc#1209122)
    • Get the first CPU summary correct (bsc#1121753)
    • Enable pidof for SLE-15 as this is provided by sysvinit-tools
    • Use a check on syscall __NR_pidfd_open to decide if the pwait tool and its manual page will be build
    • Do not truncate output of w with option -n
    • Prefer logind over utmp (jsc#PED-3144)
    • Don't install translated man pages for non-installed binaries (uptime, kill).
    • Fix directory for Ukrainian man pages translations.
    • Move localized man pages to lang package.

    • Update to procps-ng-3.3.17

    * library: Incremented to 8:3:0 (no removals or additions, internal changes only) * all: properly handle utf8 cmdline translations * kill: Pass int to signalled process * pgrep: Pass int to signalled process * pgrep: Check sanity of SG_ARG_MAX * pgrep: Add older than selection * pidof: Quiet mode * pidof: show worker threads * ps.1: Mention stime alias * ps: check also match on truncated 16 char comm names * ps: Add exe output option * ps: A lot more sorting available * pwait: New command waits for a process * sysctl: Match systemd directory order * sysctl: Document directory order * top: ensure config file backward compatibility * top: add command line 'e' for symmetry with 'E' * top: add '4' toggle for two abreast cpu display * top: add '!' toggle for combining multiple cpus * top: fix potential SEGV involving -p switch * vmstat: Wide mode gives wider proc columns * watch: Add environment variable for interval * watch: Add no linewrap option * watch: Support more colors * free,uptime,slabtop: complain about extra ops
    • Package translations in procps-lang.

    • Fix pgrep: cannot allocate 4611686018427387903 bytes when ulimit -s is unlimited.

    • Enable pidof by default

    • Update to procps-ng-3.3.16

    * library: Increment to 8:2:0
    No removals or functions Internal changes only, so revision is incremented. Previous version should have been 8:1:0 not 8:0:1
    * docs: Use correct symbols for -h option in free.1 * docs: ps.1 now warns about command name length * docs: install translated man pages * pgrep: Match on runstate * snice: Fix matching on pid * top: can now exploit 256-color terminals * top: preserves 'other filters' in configuration file * top: can now collapse/expand forest view children * top: parent %CPU time includes collapsed children * top: improve xterm support for vim navigation keys * top: avoid segmentation fault at program termination * 'ps -C' does not allow anymore an argument longer than 15 characters (bsc#1158830)


    Advisory IDSUSE-RU-2024:50-1
    ReleasedMon Jan 8 03:18:56 2024
    SummaryRecommended update for python-instance-billing-flavor-check
    Typerecommended
    Severitymoderate
    References1217695,1217696
    Description:

    This update for python-instance-billing-flavor-check fixes the following issues:

    • Run the command as sudo only (bsc#1217696, bsc#1217695)
    • Handle exception for Python 3.4


    Advisory IDSUSE-RU-2024:62-1
    ReleasedMon Jan 8 11:44:47 2024
    SummaryRecommended update for libxcrypt
    Typerecommended
    Severitymoderate
    References1215496
    Description:

    This update for libxcrypt fixes the following issues:

    • fix variable name for datamember [bsc#1215496]
    • added patches fix https://github.com/besser82/libxcrypt/commit/b212d601549a0fc84cbbcaf21b931f903787d7e2


    Advisory IDSUSE-SU-2024:70-1
    ReleasedTue Jan 9 18:29:39 2024
    SummarySecurity update for tar
    Typesecurity
    Severitylow
    References1217969,CVE-2023-39804
    Description:

    This update for tar fixes the following issues:

    • CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969).


    Advisory IDSUSE-RU-2024:105-1
    ReleasedMon Jan 15 15:41:05 2024
    SummaryRecommended update for grub2 and efibootmgr
    Typerecommended
    Severityimportant
    References1217237
    Description:

    This update for grub2 and efibootmgr fixes the following issues:
    grub2:

    • Deliver missing grub2-arm64-efi and grub2-powerpc-ieee1275 to SUSE Manager 4.3 (no source changes) (bsc#1217237)

    efibootmgr:
    • Deliver missing efibootmgr to SUSE Manager 4.3 (no source changes) (bsc#1217237)


    Advisory IDSUSE-SU-2024:128-1
    ReleasedTue Jan 16 13:50:37 2024
    SummarySecurity update for cloud-init
    Typesecurity
    Severitymoderate
    References1198269,1201010,1214169,1215740,1215794,1216007,1216011,CVE-2023-1786
    Description:

    This update for cloud-init contains the following fixes:

    • Move fdupes call back to %install.(bsc#1214169)

    • Update to version 23.3. (bsc#1216011) * (bsc#1215794) * (bsc#1215740) * (bsc#1216007) + Bump pycloudlib to 1!5.1.0 for ec2 mantic daily image support (#4390) + Fix cc_keyboard in mantic (LP: #2030788) + ec2: initialize get_instance_userdata return value to bytes (#4387) [Noah Meyerhans] + cc_users_groups: Add doas/opendoas support (#4363) [dermotbradley] + Fix pip-managed ansible + status: treat SubState=running and MainPID=0 as service exited + azure/imds: increase read-timeout to 30s (#4372) [Chris Patterson] + collect-logs fix memory usage (SC-1590) (#4289) [Alec Warren] (LP: #1980150) + cc_mounts: Use fallocate to create swapfile on btrfs (#4369) + Undocument nocloud-net (#4318) + feat(akamai): add akamai to settings.py and apport.py (#4370) + read-version: fallback to get_version when git describe fails (#4366) + apt: fix cloud-init status --wait blocking on systemd v 253 (#4364) + integration tests: Pass username to pycloudlib (#4324) + Bump pycloudlib to 1!5.1.0 (#4353) + cloud.cfg.tmpl: reorganise, minimise/reduce duplication (#4272) [dermotbradley] + analyze: fix (unexpected) timestamp parsing (#4347) [Mina Galić] + cc_growpart: fix tests to run on FreeBSD (#4351) [Mina Galić] + subp: Fix spurious test failure on FreeBSD (#4355) [Mina Galić] + cmd/clean: fix tests on non-Linux platforms (#4352) [Mina Galić] + util: Fix get_proc_ppid() on non-Linux systems (#4348) [Mina Galić] + cc_wireguard: make tests pass on FreeBSD (#4346) [Mina Galić] + unittests: fix breakage in test_read_cfg_paths_fetches_cached_datasource (#4328) [Ani Sinha] + Fix test_tools.py collection (#4315) + cc_keyboard: add Alpine support (#4278) [dermotbradley] + Flake8 fixes (#4340) [Robert Schweikert] + cc_mounts: Fix swapfile not working on btrfs (#4319) [王煎饼] (LP: #1884127) + ds-identify/CloudStack: $DS_MAYBE if vm running on vmware/xen (#4281) [Wei Zhou] + ec2: Support double encoded userdata (#4275) [Noah Meyerhans] + cc_mounts: xfs is a Linux only FS (#4334) [Mina Galić] + tests/net: fix TestGetInterfaces' mock coverage for get_master (#4336) [Chris Patterson] + change openEuler to openeuler and fix some bugs in openEuler (#4317) [sxt1001] + Replace flake8 with ruff (#4314) + NM renderer: set default IPv6 addr-gen-mode for all interfaces to eui64 (#4291) [Ani Sinha] + cc_ssh_import_id: add Alpine support and add doas support (#4277) [dermotbradley] + sudoers not idempotent (SC-1589) (#4296) [Alec Warren] (LP: #1998539) + Added support for Akamai Connected Cloud (formerly Linode) (#4167) [Will Smith] + Fix reference before assignment (#4292) + Overhaul module reference page (#4237) [Sally] + replaced spaces with commas for setting passenv (#4269) [Alec Warren] + DS VMware: modify a few log level (#4284) [PengpengSun] + tools/read-version refactors and unit tests (#4268) + Ensure get_features() grabs all features (#4285) + Don't always require passlib dependency (#4274) + tests: avoid leaks into host system checking of ovs-vsctl cmd (#4275) + Fix NoCloud kernel commandline key parsing (#4273) + testing: Clear all LRU caches after each test (#4249) + Remove the crypt dependency (#2139) [Gonéri Le Bouder] + logging: keep current file mode of log file if its stricter than the new mode (#4250) [Ani Sinha] + Remove default membership in redundant groups (#4258) [Dave Jones] (LP: #1923363) + doc: improve datasource_creation.rst (#4262) + Remove duplicate Integration testing button (#4261) [Rishita Shaw] + tools/read-version: fix the tool so that it can handle version parsing errors (#4234) [Ani Sinha] + net/dhcp: add udhcpc support (#4190) [Jean-François Roche] + DS VMware: add i386 arch dir to deployPkg plugin search path [PengpengSun] + LXD moved from linuxcontainers.org to Canonical [Simon Deziel] + cc_mounts.py: Add note about issue with creating mounts inside mounts (#4232) [dermotbradley] + lxd: install lxd from snap, not deb if absent in image + landscape: use landscape-config to write configuration + Add deprecation log during init of DataSourceDigitalOcean (#4194) [tyb-truth] + doc: fix typo on apt.primary.arches (#4238) [Dan Bungert] + Inspect systemd state for cloud-init status (#4230) + instance-data: add system-info and features to combined-cloud-config (#4224) + systemd: Block login until config stage completes (#2111) (LP: #2013403) + tests: proposed should invoke apt-get install -t=-proposed (#4235) + cloud.cfg.tmpl: reinstate ca_certs entry (#4236) [dermotbradley] + Remove feature flag override ability (#4228) + tests: drop stray unrelated file presence test (#4227) + Update LXD URL (#4223) [Sally] + schema: add network v1 schema definition and validation functions + tests: daily PPA for devel series is version 99.daily update tests to match (#4225) + instance-data: write /run/cloud-init/combined-cloud-config.json + mount parse: Fix matching non-existent directories (#4222) [Mina Galić] + Specify build-system for pep517 (#4218) + Fix network v2 metric rendering (#4220) + Migrate content out of FAQ page (SD-1187) (#4205) [Sally] + setup: fix generation of init templates (#4209) [Mina Galić] + docs: Correct some bootcmd example wording + fix changelog + tests: reboot client to assert x-shellscript-per-boot is triggered + nocloud: parse_cmdline no longer detects nocloud-net datasource (#4204) (LP: 4203, #2025180) + Add docstring and typing to mergemanydict (#4200) + BSD: add dsidentify to early startup scripts (#4182) [Mina Galić] + handler: report errors on skipped merged cloud-config.txt parts (LP: #1999952) + Add cloud-init summit writeups (#4179) [Sally] + tests: Update test_clean_log for oci (#4187) + gce: improve ephemeral fallback NIC selection (CPC-2578) (#4163) + tests: pin pytest 7.3.1 to avoid adverse testpaths behavior (#4184) + Ephemeral Networking for FreeBSD (#2165) [Mina Galić] + Clarify directory syntax for nocloud local filesystem. (#4178) + Set default renderer as sysconfig for centos/rhel (#4165) [Ani Sinha] + Test static routes and netplan 0.106 + FreeBSD fix parsing of mount and mount options (#2146) [Mina Galić] + test: add tracking bug id (#4164) + tests: can't match MAC for LXD container veth due to netplan 0.106 (#4162) + Add kaiwalyakoparkar as a contributor (#4156) [Kaiwalya Koparkar] + BSD: remove datasource_list from cloud.cfg template (#4159) [Mina Galić] + launching salt-minion in masterless mode (#4110) [Denis Halturin] + tools: fix run-container builds for rockylinux/8 git hash mismatch (#4161) + fix doc lint: spellchecker tripped up (#4160) [Mina Galić] + Support Ephemeral Networking for BSD (#2127) + Added / fixed support for static routes on OpenBSD and FreeBSD (#2157) [Kadir Mueller] + cc_rsyslog: Refactor for better multi-platform support (#4119) [Mina Galić] (LP: #1798055) + tests: fix test_lp1835584 (#4154) + cloud.cfg mod names: docs and rename salt_minion and set_password (#4153) + vultr: remove check_route check (#2151) [Jonas Chevalier] + Update SECURITY.md (#4150) [Indrranil Pawar] + Update CONTRIBUTING.rst (#4149) [Indrranil Pawar] + Update .github-cla-signers (#4151) [Indrranil Pawar] + Standardise module names in cloud.cfg.tmpl to only use underscore (#4128) [dermotbradley] + Modify PR template so autoclose works
    From 23.2.2 + Fix NoCloud kernel commandline key parsing (#4273) (Fixes: #4271) (LP: #2028562) + Fix reference before assignment (#4292) (Fixes: #4288) (LP: #2028784) From 23.2.1 + nocloud: Fix parse_cmdline detection of nocloud-net datasource (#4204) (Fixes: 4203) (LP: #2025180) From 23.2 + BSD: simplify finding MBR partitions by removing duplicate code [Mina Galić] + tests: bump pycloudlib version for mantic builds + network-manager: Set higher autoconnect priority for nm keyfiles (#3671) [Ani Sinha] + alpine.py: change the locale file used (#4139) [dermotbradley] + cc_ntp: Sync up with current FreeBSD ntp.conf (#4122) [Mina Galić] + config: drop refresh_rmc_and_interface as RHEL 7 no longer supported [Robert Schweikert] + docs: Add feedback button to docs + net/sysconfig: enable sysconfig renderer if network manager has ifcfg-rh plugin (#4132) [Ani Sinha] + For Alpine use os-release PRETTY_NAME (#4138) [dermotbradley] + network_manager: add a method for ipv6 static IP configuration (#4127) [Ani Sinha] + correct misnamed template file host.mariner.tmpl (#4124) [dermotbradley] + nm: generate ipv6 stateful dhcp config at par with sysconfig (#4115) [Ani Sinha] + Add templates for GitHub Issues + Add 'peers' and 'allow' directives in cc_ntp (#3124) [Jacob Salmela] + FreeBSD: Fix user account locking (#4114) [Mina Galić] (GH: #1854594) + FreeBSD: add ResizeGrowFS class to cc_growpart (#2334) [Mina Galić] + Update tests in Azure TestCanDevBeReformatted class (#2771) [Ksenija Stanojevic] + Replace Launchpad references with GitHub Issues + Fix KeyError in iproute pformat (#3287) [Dmitry Zykov] + schema: read_cfg_paths call init.fetch to lookup /v/l/c/instance + azure/errors: introduce reportable errors for imds (#3647) [Chris Patterson] + FreeBSD (and friends): better identify MBR slices (#2168) [Mina Galić] (LP: #2016350) + azure/errors: add host reporting for dhcp errors (#2167) [Chris Patterson] + net: purge blacklist_drivers across net and azure (#2160) [Chris Patterson] + net: refactor hyper-v VF filtering and apply to get_interfaces() (#2153) [Chris Patterson] + tests: avoid leaks to underlying filesystem for /etc/cloud/clean.d (#2251) + net: refactor find_candidate_nics_on_linux() to use get_interfaces() (#2159) [Chris Patterson] + resolv_conf: Allow > 3 nameservers (#2152) [Major Hayden] + Remove mount NTFS error message (#2134) [Ksenija Stanojevic] + integration tests: fix image specification parsing (#2166) + ci: add hypothesis scheduled GH check (#2149) + Move supported distros list to docs (#2162) + Fix logger, use instance rather than module function (#2163) + README: Point to Github Actions build status (#2158) + Revert 'fix linux-specific code on bsd (#2143)' (#2161) + Do not generate dsa and ed25519 key types when crypto FIPS mode is enabled (#2142) [Ani Sinha] (LP: 2017761) + Add documentation label automatically (#2156) + sources/azure: report success to host and introduce kvp module (#2141) [Chris Patterson] + setup.py: use pkg-config for udev/rules path (#2137) [dankm] + openstack/static: honor the DNS servers associated with a network (#2138) [Gonéri Le Bouder] + fix linux-specific code on bsd (#2143) + cli: schema validation of jinja template user-data (SC-1385) (#2132) (LP: #1881925) + gce: activate network discovery on every boot (#2128) + tests: update integration test to assert 640 across reboots (#2145) + Make user/vendor data sensitive and remove log permissions (#2144) (LP: #2013967) + Update kernel command line docs (SC-1457) (#2133) + docs: update network configuration path links (#2140) [d1r3ct0r] + sources/azure: report failures to host via kvp (#2136) [Chris Patterson] + net: Document use of `ip route append` to add routes (#2130) + dhcp: Add missing mocks (#2135) + azure/imds: retry fetching metadata up to 300 seconds (#2121) [Chris Patterson] + [1/2] DHCP: Refactor dhcp client code (#2122) + azure/errors: treat traceback_base64 as string (#2131) [Chris Patterson] + azure/errors: introduce reportable errors (#2129) [Chris Patterson] + users: schema permit empty list to indicate create no users + azure: introduce identity module (#2116) [Chris Patterson] + Standardize disabling cloud-init on non-systemd (#2112) + Update .github-cla-signers (#2126) [Rob Tongue] + NoCloud: Use seedfrom protocol to determine mode (#2107) + rhel: Remove sysvinit files. (#2114) + tox.ini: set -vvvv --showlocals for pytest (#2104) [Chris Patterson] + Fix NoCloud kernel commandline semi-colon args + run-container: make the container/VM timeout configurable (#2118) [Paride Legovini] + suse: Remove sysvinit files. (#2115) + test: Backport assert_call_count for old requests (#2119) + Add 'licebmi' as contributor (#2113) [Mark Martinez] + Adapt DataSourceScaleway to upcoming IPv6 support (#2033) [Louis Bouchard] + rhel: make sure previous-hostname file ends with a new line (#2108) [Ani Sinha] + Adding contributors for DataSourceAkamai (#2110) [acourdavAkamai] + Cleanup ephemeral IP routes on exception (#2100) [sxt1001] + commit 09a64badfb3f51b1b391fa29be19962381a4bbeb [sxt1001] (LP: #2011291) + Standardize kernel commandline user interface (#2093) + config/cc_resizefs: fix do_resize arguments (#2106) [Chris Patterson] + Fix test_dhclient_exits_with_error (#2105) + net/dhcp: catch dhclient failures and raise NoDHCPLeaseError (#2083) [Chris Patterson] + sources/azure: move pps handling out of _poll_imds() (#2075) [Chris Patterson] + tests: bump pycloudlib version (#2102) + schema: do not manipulate draft4 metaschema for jsonschema 2.6.0 (#2098) + sources/azure/imds: don't count timeout errors as connection errors (#2074) [Chris Patterson] + Fix Python 3.12 unit test failures (#2099) + integration tests: Refactor instance checking (#1989) + ci: migrate remaining jobs from travis to gh (#2085) + missing ending quote in instancedata docs(#2094) [Hong L] + refactor: stop passing log instances to cc_* handlers (#2016) [d1r3ct0r] + tests/vmware: fix test_no_data_access_method failure (#2092) [Chris Patterson] + Don't change permissions of netrules target (#2076) (LP: #2011783) + tests/sources: patch util.get_cmdline() for datasource tests (#2091) [Chris Patterson] + macs: ignore duplicate MAC for devs with driver driver qmi_wwan (#2090) (LP: #2008888) + Fedora: Enable CA handling (#2086) [František Zatloukal] + Send dhcp-client-identifier for InfiniBand ports (#2043) [Waleed Mousa] + cc_ansible: complete the examples and doc (#2082) [Yves] + bddeb: for dev package, derive debhelper-compat from host system + apport: only prompt for cloud_name when instance-data.json is absent + datasource: Optimize datasource detection, fix bugs (#2060) + Handle non existent ca-cert-config situation (#2073) [Shreenidhi Shedi] + sources/azure: add networking check for all source PPS (#2061) [Chris Patterson] + do not attempt dns resolution on ip addresses (#2040) + chore: fix style tip (#2071) + Fix metadata IP in instancedata.rst (#2063) [Brian Haley] + util: Pass deprecation schedule in deprecate_call() (#2064) + config: Update grub-dpkg docs (#2058) + docs: Cosmetic improvements and styling (#2057) [s-makin] + cc_grub_dpkg: Added UEFI support (#2029) [Alexander Birkner] + tests: Write to /var/spool/rsyslog to adhere to apparmor profile (#2059) + oracle-ds: prefer system_cfg over ds network config source (#1998) (LP: #1956788) + Remove dead code (#2038) + source: Force OpenStack when it is only option (#2045) (LP: #2008727) + cc_ubuntu_advantage: improve UA logs discovery + sources/azure: fix regressions in IMDS behavior (#2041) [Chris Patterson] + tests: fix test_schema (#2042) + dhcp: Cleanup unused kwarg (#2037) + sources/vmware/imc: fix-missing-catch-few-negtive-scenarios (#2027) [PengpengSun] + dhclient_hook: remove vestigal dhclient_hook command (#2015) + log: Add standardized deprecation tooling (SC-1312) (#2026) + Enable SUSE based distros for ca handling (#2036) [Robert Schweikert] From 23.1.2 + Make user/vendor data sensitive and remove log permissions (LP: #2013967) (CVE-2023-1786)
    • Remove six dependency (bsc#1198269)
    • Update to version 22.4 (bsc#1201010)


    Advisory IDSUSE-SU-2024:136-1
    ReleasedThu Jan 18 09:53:47 2024
    SummarySecurity update for pam
    Typesecurity
    Severitymoderate
    References1217000,1218475,CVE-2024-22365
    Description:

    This update for pam fixes the following issues:

    • CVE-2024-22365: Fixed a local denial of service during PAM login due to a missing check during path manipulation (bsc#1218475).
    • Check localtime_r() return value to fix crashing (bsc#1217000)


    Advisory IDSUSE-RU-2024:161-1
    ReleasedThu Jan 18 18:40:44 2024
    SummaryRecommended update for dpdk22
    Typerecommended
    Severitymoderate
    References
    Description:


    This update of dpdk22 fixes the following issue:

    • DPDK 22.11.1 is shipped to SLE Micro 5.5. (jsc#PED-7147)


    Advisory IDSUSE-RU-2024:187-1
    ReleasedTue Jan 23 13:38:00 2024
    SummaryRecommended update for python-chardet
    Typerecommended
    Severitymoderate
    References1218765
    Description:

    This update for python-chardet fixes the following issues:

    • Fix update-alternative in %postun (bsc#1218765)


    Advisory IDSUSE-SU-2024:238-1
    ReleasedFri Jan 26 10:56:41 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:

    • CVE-2023-7207: Fixed a path traversal issue that could lead to an arbitrary file write during archive extraction (bsc#1218571).


    Advisory IDSUSE-RU-2024:254-1
    ReleasedFri Jan 26 17:19:30 2024
    SummaryRecommended update for containerd
    Typerecommended
    Severitymoderate
    References1217952
    Description:

    This update for containerd fixes the following issues:

    • Fix permissions of address file (bsc#1217952)
    • Update to version 1.7.10


    Advisory IDSUSE-SU-2024:295-1
    ReleasedThu Feb 1 08:23:17 2024
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1218894,CVE-2024-21626
    Description:

    This update for runc fixes the following issues:
    Update to runc v1.1.11:

    • CVE-2024-21626: Fixed container breakout. (bsc#1218894)


    Advisory IDSUSE-RU-2024:306-1
    ReleasedThu Feb 1 17:58:09 2024
    SummaryRecommended update for python-instance-billing-flavor-check
    Typerecommended
    Severitymoderate
    References1218561,1218739
    Description:

    This update for python-instance-billing-flavor-check fixes the following issues:

    • Support proxy setup on the client to access the update infrastructure API (bsc#1218561)
    • Add IPv6 support (bsc#1218739)


    Advisory IDSUSE-RU-2024:322-1
    ReleasedFri Feb 2 15:13:26 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1107342,1215434
    Description:

    This update for aaa_base fixes the following issues:

    • Set JAVA_HOME correctly (bsc#1107342, bsc#1215434)


    Advisory IDSUSE-SU-2024:444-1
    ReleasedFri Feb 9 16:39:32 2024
    SummarySecurity update for suse-build-key
    Typesecurity
    Severityimportant
    References1219123,1219189
    Description:

    This update for suse-build-key fixes the following issues:
    This update runs a import-suse-build-key script.
    The previous libzypp-post-script based installation is replaced with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777). - suse-build-key-import.service - suse-build-key-import.timer
    It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys. After successful import the timer is disabled.
    To manually import them you can also run:
    # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc
    Bugfix added since last update:

    • run rpm commands in import script only when libzypp is not active. bsc#1219189 bsc#1219123


    Advisory IDSUSE-RU-2024:458-1
    ReleasedTue Feb 13 14:34:14 2024
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:

    • Update to version 0.378
    • Update pci, usb and vendor ids


    Advisory IDSUSE-SU-2024:459-1
    ReleasedTue Feb 13 15:28:56 2024
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1218894,CVE-2024-21626
    Description:

    This update for runc fixes the following issues:

    • Update to runc v1.1.12 (bsc#1218894)
    The following CVE was already fixed with the previous release.
  • CVE-2024-21626: Fixed container breakout.

  • Advisory IDSUSE-RU-2024:534-1
    ReleasedTue Feb 20 08:48:52 2024
    SummaryRecommended update for supportutils-plugin-suse-public-cloud
    Typerecommended
    Severitymoderate
    References1218762,1218763
    Description:

    This update for supportutils-plugin-suse-public-cloud fixes the following issues:

    • Update to version 1.0.9 (bsc#1218762, bsc#1218763)
    • Remove duplicate data collection for the plugin itself
    • Collect archive metering data when available
    • Query billing flavor status


    Advisory IDSUSE-SU-2024:555-1
    ReleasedTue Feb 20 17:22:17 2024
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1219576,CVE-2024-25062
    Description:

    This update for libxml2 fixes the following issues:

    • CVE-2024-25062: Fixed use-after-free in XMLReader (bsc#1219576).


    Advisory IDSUSE-SU-2024:581-1
    ReleasedWed Feb 21 14:08:16 2024
    SummarySecurity update for python3
    Typesecurity
    Severitymoderate
    References1210638,CVE-2023-27043
    Description:

    This update for python3 fixes the following issues:

    • CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638).


    Advisory IDSUSE-SU-2024:586-1
    ReleasedThu Feb 22 09:54:21 2024
    SummarySecurity update for docker
    Typesecurity
    Severityimportant
    References1219267,1219268,1219438,CVE-2024-23651,CVE-2024-23652,CVE-2024-23653
    Description:

    This update for docker fixes the following issues:
    Vendor latest buildkit v0.11 including bugfixes for the following:

    • CVE-2024-23653: BuildKit API doesn't validate entitlement on container creation (bsc#1219438).
    • CVE-2024-23652: Fixed arbitrary deletion of files (bsc#1219268).
    • CVE-2024-23651: Fixed race condition in mount (bsc#1219267).


    Advisory IDSUSE-RU-2024:614-1
    ReleasedMon Feb 26 11:31:18 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severityimportant
    References1216752
    Description:

    This update for rpm fixes the following issues:

    • backport lua support for rpm.execute to ease migrating from SLE Micro 5.5 to 6.0 (bsc#1216752)


    Advisory IDSUSE-RU-2024:615-1
    ReleasedMon Feb 26 11:32:32 2024
    SummaryRecommended update for netcfg
    Typerecommended
    Severitymoderate
    References1211886
    Description:

    This update for netcfg fixes the following issues:

    • Add krb-prop entry (bsc#1211886)


    Advisory IDSUSE-RU-2024:637-1
    ReleasedTue Feb 27 10:06:55 2024
    SummaryRecommended update for duktape
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for duktape fixes the following issues:

    • Ship libduktape206-32bit: needed by libproxy since version 0.5.


    Advisory IDSUSE-RU-2024:725-1
    ReleasedThu Feb 29 11:03:34 2024
    SummaryRecommended update for suse-build-key
    Typerecommended
    Severitymoderate
    References1219123,1219189
    Description:

    This update for suse-build-key fixes the following issues:

    • Switch container key to be default RSA 4096bit. (jsc#PED-2777)
    • run import script also in %posttrans section, but only when libzypp is not active. bsc#1219189 bsc#1219123


    Advisory IDSUSE-SU-2024:305-1
    ReleasedMon Mar 11 14:15:37 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,1219238,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:

    • Fixed cpio not extracting correctly when using --no-absolute-filenames option the security fix for CVE-2023-7207 (bsc#1218571, bsc#1219238)


    Advisory IDSUSE-RU-2024:849-1
    ReleasedTue Mar 12 15:38:03 2024
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1198533,1214169,1218952
    Description:

    This update for cloud-init contains the following fixes:

    • Skip tests with empty config.

    • Support reboot on package update/upgrade via the cloud-init config. (bsc#1198533, bsc#1218952, jsc#SMO-326)

    • Switch build dependency to the generic distribution-release package.

    • Move fdupes call back to %install. (bsc#1214169)


    Advisory IDSUSE-RU-2024:861-1
    ReleasedWed Mar 13 09:12:30 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1218232
    Description:

    This update for aaa_base fixes the following issues:

    • Silence the output in the case of broken symlinks (bsc#1218232)


    Advisory IDSUSE-SU-2024:901-1
    ReleasedThu Mar 14 17:49:10 2024
    SummarySecurity update for python3
    Typesecurity
    Severityimportant
    References1214691,1219666,CVE-2022-48566,CVE-2023-6597
    Description:

    This update for python3 fixes the following issues:

    • CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666).
    • CVE-2022-48566: Make compare_digest more constant-time (bsc#1214691).


    Advisory IDSUSE-RU-2024:907-1
    ReleasedFri Mar 15 08:57:38 2024
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1215377
    Description:

    This update for audit fixes the following issue:

    • Fix plugin termination when using systemd service units (bsc#1215377)


    Advisory IDSUSE-RU-2024:929-1
    ReleasedTue Mar 19 06:36:24 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1219321
    Description:

    This update for coreutils fixes the following issues:

    • tail: fix tailing sysfs files where PAGE_SIZE > BUFSIZ (bsc#1219321)


    Advisory IDSUSE-RU-2024:982-1
    ReleasedMon Mar 25 12:56:33 2024
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1217964
    Description:

    This update for systemd-rpm-macros fixes the following issue:

    • Order packages that requires systemd after systemd-sysvcompat if needed. (bsc#1217964)


    Advisory IDSUSE-RU-2024:984-1
    ReleasedMon Mar 25 16:04:44 2024
    SummaryRecommended update for runc
    Typerecommended
    Severityimportant
    References1192051,1221050
    Description:

    This update for runc fixes the following issues:

    • Add upstream patch to properly fix -ENOSYS stub on ppc64le. bsc#1192051 bsc#1221050

    This allows running 15 SP6 containers on older distributions.


    Advisory IDSUSE-RU-2024:1091-1
    ReleasedTue Apr 2 12:18:46 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for rpm fixes the following issues:

    • Turn on IMA/EVM file signature support, move the imaevm code that needs the libiamevm library into a plugin, and install this plugin as part of a new 'rpm-imaevmsign' subpackage (jsc#PED-7246).

    • Backport signature reserved space handling from upstream.


    Advisory IDSUSE-RU-2024:1104-1
    ReleasedWed Apr 3 14:29:58 2024
    SummaryRecommended update for docker, containerd, rootlesskit, catatonit, slirp4netns, fuse-overlayfs
    Typerecommended
    Severityimportant
    References
    Description:

    This update for docker fixes the following issues:

    • Overlay files are world-writable (bsc#1220339)
    • Allow disabling apparmor support (some products only support SELinux)

    The other packages in the update (containerd, rootlesskit, catatonit, slirp4netns, fuse-overlayfs) are no-change rebuilds required because the corresponding binary packages were missing in a number of repositories, thus making docker not installable on some products.


    Advisory IDSUSE-SU-2024:1129-1
    ReleasedMon Apr 8 09:12:08 2024
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1219559,1221289,CVE-2023-52425,CVE-2024-28757
    Description:

    This update for expat fixes the following issues:

    • CVE-2023-52425: Fixed a DoS caused by processing large tokens. (bsc#1219559)
    • CVE-2024-28757: Fixed an XML Entity Expansion. (bsc#1221289)


    Advisory IDSUSE-SU-2024:1133-1
    ReleasedMon Apr 8 11:29:02 2024
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1220061,CVE-2023-45918
    Description:

    This update for ncurses fixes the following issues:

    • CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061).


    Advisory IDSUSE-SU-2024:1136-1
    ReleasedMon Apr 8 11:30:15 2024
    SummarySecurity update for c-ares
    Typesecurity
    Severitymoderate
    References1220279,CVE-2024-25629
    Description:

    This update for c-ares fixes the following issues:

    • CVE-2024-25629: Fixed out of bounds read in ares__read_line() (bsc#1220279).


    Advisory IDSUSE-RU-2024:1176-1
    ReleasedTue Apr 9 10:43:33 2024
    SummaryRecommended update for hwdata
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for hwdata fixes the following issues:

    • Update to 0.380
    • Update pci, usb and vendor ids


    Advisory IDSUSE-RU-2024:1180-1
    ReleasedTue Apr 9 21:13:49 2024
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severityimportant
    References1217301,1217302
    Description:

    This update for python-azure-agent contains the following fixes:

    • Recognise SLE-Micro as a SLE based distro.

    • Create sub-packages for the config (jsc#PED-7869) + Remove config manipulation from image building + Set up a config for SLE-Micro + Makes deafult upstream config available

    • Update to 2.9.1.1 (bsc#1217301, bsc#1217302) + Update unittest.mock + Download certificates when goal state source is fast track #2761 + Increase the max number of extension events by 20% #2785 + Remove version suffix from extension slice #2782 + Support int type for eventPid and eventTid fields #2786 + Improve log for swap counter not found #2789 + Remove cgroup files during deprovisioning #2790 + Log VM architecture in heartbeat telemetry for arm64 adoption monitoring #2818 + Enforce memory usage for agent #2671 + Use common download logic for agent downloads #2682 + Implement Fedora distro #2642 + Report message in handler heartbeat #2688 + Remove dependency on pathlib from makepkg #2717 + Do not fetch extensions goal state in log collector #2713 + Update log collector unit file to remove memory limit #2757 + Fix bug in get_dhcp_pid (CoreOS) #2784 + Fetch full distro version for mariner #2773

    From 2.9.04 + Resource Governance on extensions (CPU monitoring and enforcing & Memory monitoring) #2632 #2581 #2555 + Agent resource governance #2597 #2591 #2546 + monitor system-wide memory metrics (#2610) + Additional telemetry for goal state (#2675) + HostGAPlugin usage improvements #2662 #2673 #2655 #2651 + Add logging statements for mrseq migration during update (#2667) + Logcollector memory usage #2658 #2637 + Update Log Collector default in Comments and Readme (#2608) + Improve telemetry success and failure markers (#2605) #2604 #2599 + Fix formatting of exceptions on Python 3.10 (traceback.format's etype argument) (#2663) + Fix UNKNOWN(Zombie) Process in unexpected processes check (#2644) + SUSE: Fix valid values for DHCLIENT_HOSTNAME_OPTION (#2643) + Debian - string conversion for systemd service (#2574) + Do not set a CPU quota on the agent for RHEL and Centos (#2685) #2689 #2693 + support rhel distro (#2620) #2598 + Added support for devuan linux distribution (#2553)
    No incremental updates between 2.8.011 and 2.9.0.4
    • Clean up conditions in spec file: + There is no maintained distro > 1315 (SLE12) AND < 1500 (SLE15). Only openSUSE 13.2 and 13.3 lived in that space, but they are clearly not the target of this spec file. + if 0%{?Suse_version} && 0{?suse_version} > 1315: no need to first validate suse_version being defined: whenever it is > 1315, must be defined.

    • Add patch to use unittest.mock first, falling back to mock if required.
    • Tighten Requires against python3-mock.


    Advisory IDSUSE-RU-2024:1206-1
    ReleasedThu Apr 11 12:56:24 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severitymoderate
    References1222259
    Description:

    This update for rpm fixes the following issues:

    • remove imaevmsign plugin from rpm-ndb [bsc#1222259]


    Advisory IDSUSE-RU-2024:1253-1
    ReleasedFri Apr 12 08:15:18 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1210959,1214934,1217450,1217667,1218492,1219031,1219520,1220724,1221239
    Description:

    This update for gcc13 fixes the following issues:

    • Fix unwinding for JIT code. [bsc#1221239]
    • Revert libgccjit dependency change. [bsc#1220724]
    • Remove crypt and crypt_r interceptors. The crypt API change in SLE15 SP3 breaks them. [bsc#1219520]
    • Add support for -fmin-function-alignment. [bsc#1214934]
    • Use %{_target_cpu} to determine host and build.
    • Fix for building TVM. [bsc#1218492]
    • Add cross-X-newlib-devel requires to newlib cross compilers. [bsc#1219031]
    • Package m2rte.so plugin in the gcc13-m2 sub-package rather than in gcc13-devel. [bsc#1210959]
    • Require libstdc++6-devel-gcc13 from gcc13-m2 as m2 programs are linked against libstdc++6.
    • Fixed building mariadb on i686. [bsc#1217667]
    • Avoid update-alternatives dependency for accelerator crosses.
    • Package tool links to llvm in cross-amdgcn-gcc13 rather than in cross-amdgcn-newlib13-devel since that also has the dependence.
    • Depend on llvmVER instead of llvm with VER equal to %product_libs_llvm_ver where available and adjust tool discovery accordingly. This should also properly trigger re-builds when the patchlevel version of llvmVER changes, possibly changing the binary names we link to. [bsc#1217450]


    Advisory IDSUSE-RU-2024:1279-1
    ReleasedFri Apr 12 21:35:09 2024
    SummaryRecommended update for python3
    Typerecommended
    Severitymoderate
    References1222109
    Description:

    This update for python3 fixes the following issue:

    • Fix syslog making default 'ident' from sys.argv (bsc#1222109)


    Advisory IDSUSE-SU-2024:1287-1
    ReleasedMon Apr 15 15:03:40 2024
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1215005,1217316,1217320,1217321,1217324,1217326,1217329,1217330,1217432,1219581,CVE-2023-4750,CVE-2023-48231,CVE-2023-48232,CVE-2023-48233,CVE-2023-48234,CVE-2023-48235,CVE-2023-48236,CVE-2023-48237,CVE-2023-48706,CVE-2024-22667
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.1.0111, fixes the following security problems

    • CVE-2023-48231: Use-After-Free in win_close() (bsc#1217316).
    • CVE-2023-48232: Floating point Exception in adjust_plines_for_skipcol() (bsc#1217320).
    • CVE-2023-48233: overflow with count for :s command (bsc#1217321).
    • CVE-2023-48234: overflow in nv_z_get_count (bsc#1217324).
    • CVE-2023-48235: overflow in ex address parsing (CVE-2023-48235).
    • CVE-2023-48236: overflow in get_number (bsc#1217329).
    • CVE-2023-48237: overflow in shift_line (bsc#1217330).
    • CVE-2023-48706: heap-use-after-free in ex_substitute (bsc#1217432).
    • CVE-2024-22667: stack-based buffer overflow in did_set_langmap function in map.c (bsc#1219581).
    • CVE-2023-4750: Heap use-after-free in function bt_quickfix (bsc#1215005).


    Advisory IDSUSE-RU-2024:1302-1
    ReleasedTue Apr 16 07:23:44 2024
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitycritical
    References1222620
    Description:

    This update for python-azure-agent fixes the following issues:

    • Keep the existing config file (bsc#1222620)
    • Do not force wicked dependency for networking, allow NM in SLE Micro 5.5 and for ALP based products


    Advisory IDSUSE-RU-2024:1352-1
    ReleasedFri Apr 19 15:28:38 2024
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1220132,1221132,1221726,1222113
    Description:

    This update for cloud-init contains the following fixes:

    • Add cloud-init-no-nmcfg-needed.patch (bsc#1221726)
    • Do not require a NetworkManager config file in order to detect
    NetworkManager as the renderer
    • Add cloud-init-no-openstack-guess.patch (bsc#1222113)
    • Do not guess if we are running on OpenStack or not. Only recognize
    the known markers and enable cloud-init if we know for sure.
    • Do not guess a data source when checking for a CloudStack environment. (bsc#1221132)

    • Hardcode distribution to suse for proper cloud.cfg generation (bsc#1220132).

    • Prepare for RPM 4.20 switch patch syntax


    Advisory IDSUSE-SU-2024:1368-1
    ReleasedMon Apr 22 11:06:29 2024
    SummarySecurity update for shim
    Typesecurity
    Severityimportant
    References1198101,1205588,1205855,1210382,1213945,1215098,1215099,1215100,1215101,1215102,1215103,1219460,CVE-2022-28737,CVE-2023-40546,CVE-2023-40547,CVE-2023-40548,CVE-2023-40549,CVE-2023-40550,CVE-2023-40551
    Description:

    This update for shim fixes the following issues:

    • Update shim-install to set the TPM2 SRK algorithm (bsc#1213945)
    • Limit the requirement of fde-tpm-helper-macros to the distro with suse_version 1600 and above (bsc#1219460)

    Update to version 15.8:
    Security issues fixed:
    • mok: fix LogError() invocation (bsc#1215099,CVE-2023-40546)
    • avoid incorrectly trusting HTTP headers (bsc#1215098,CVE-2023-40547)
    • Fix integer overflow on SBAT section size on 32-bit system (bsc#1215100,CVE-2023-40548)
    • Authenticode: verify that the signature header is in bounds (bsc#1215101,CVE-2023-40549)
    • pe: Fix an out-of-bound read in verify_buffer_sbat() (bsc#1215102,CVE-2023-40550)
    • pe-relocate: Fix bounds check for MZ binaries (bsc#1215103,CVE-2023-40551)

    The NX flag is disable which is same as the default value of shim-15.8, hence, not need to enable it by this patch now.
    • Generate dbx during build so we don't include binary files in sources
    • Don't require grub so shim can still be used with systemd-boot
    • Update shim-install to fix boot failure of ext4 root file system on RAID10 (bsc#1205855)
    • Adopt the macros from fde-tpm-helper-macros to update the signature in the sealed key after a bootloader upgrade

    • Update shim-install to amend full disk encryption support - Adopt TPM 2.0 Key File for grub2 TPM 2.0 protector - Use the long name to specify the grub2 key protector - cryptodisk: support TPM authorized policies - Do not use tpm_record_pcrs unless the command is in command.lst

    • Removed POST_PROCESS_PE_FLAGS=-N from the build command in shim.spec to enable the NX compatibility flag when using post-process-pe after discussed with grub2 experts in mail. It's useful for further development and testing. (bsc#1205588)


    Advisory IDSUSE-RU-2024:1398-1
    ReleasedTue Apr 23 13:58:22 2024
    SummaryRecommended update for systemd-default-settings
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd-default-settings fixes the following issues:

    • Disable pids controller limit under user instances (jsc#SLE-10123)
    • Disable controllers by default (jsc#PED-2276)
    • The usage of drop-ins is now the official way for configuring systemd and its various daemons on Factory/ALP, hence the early drop-ins SUSE specific 'feature' has been abandoned.
    • User priority '26' for SLE-Micro
    • Convert more drop-ins into early ones


    Advisory IDSUSE-RU-2024:1429-1
    ReleasedWed Apr 24 15:13:10 2024
    SummaryRecommended update for ca-certificates
    Typerecommended
    Severitymoderate
    References1188500,1221184
    Description:

    This update for ca-certificates fixes the following issue:

    • Update version (bsc#1221184) * Use flock to serialize calls (bsc#1188500) * Make certbundle.run container friendly * Create /var/lib/ca-certificates if needed


    Advisory IDSUSE-SU-2024:1439-1
    ReleasedThu Apr 25 23:41:12 2024
    SummarySecurity update for python-idna
    Typesecurity
    Severitymoderate
    References1222842,CVE-2024-3651
    Description:

    This update for python-idna fixes the following issues:

    • CVE-2024-3651: Fixed potential DoS via resource consumption via specially crafted inputs to idna.encode() (bsc#1222842).


    Advisory IDSUSE-RU-2024:1458-1
    ReleasedMon Apr 29 07:47:34 2024
    SummaryRecommended update for vim
    Typerecommended
    Severitymoderate
    References1220763
    Description:

    This update for vim fixes the following issues:

    • Fix segmentation fault after updating to version 9.1.0111-150500.20.9.1 (bsc#1220763)


    Advisory IDSUSE-RU-2024:1487-1
    ReleasedThu May 2 10:43:53 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1211721,1221361,1221407,1222547
    Description:

    This update for aaa_base fixes the following issues:

    • home and end button not working from ssh client (bsc#1221407)
    • use autosetup in prep stage of specfile
    • drop the stderr redirection for csh (bsc#1221361)
    • drop sysctl.d/50-default-s390.conf (bsc#1211721)
    • make sure the script does not exit with 1 if a file with content is found (bsc#1222547)


    Advisory IDSUSE-SU-2024:1557-1
    ReleasedWed May 8 11:42:34 2024
    SummarySecurity update for rpm
    Typesecurity
    Severitymoderate
    References1189495,1191175,1218686,CVE-2021-3521
    Description:

    This update for rpm fixes the following issues:
    Security fixes:

    • CVE-2021-3521: Fixed missing subkey binding signature checking (bsc#1191175)

    Other fixes:
    • accept more signature subpackets marked as critical (bsc#1218686)
    • backport limit support for the autopatch macro (bsc#1189495)


    Advisory IDSUSE-RU-2024:1566-1
    ReleasedThu May 9 12:33:21 2024
    SummaryRecommended update for catatonit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for catatonit fixes the following issues:

    • Update to catatonit v0.2.0
    • Change license to GPL-2.0-or-later


    Advisory IDSUSE-RU-2024:1665-1
    ReleasedThu May 16 08:00:09 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1221632
    Description:

    This update for coreutils fixes the following issues:

    • ls: avoid triggering automounts (bsc#1221632)


    Advisory IDSUSE-SU-2024:1762-1
    ReleasedWed May 22 16:14:17 2024
    SummarySecurity update for perl
    Typesecurity
    Severityimportant
    References1082216,1082233,1213638,CVE-2018-6798,CVE-2018-6913
    Description:

    This update for perl fixes the following issues:
    Security issues fixed:

    • CVE-2018-6913: Fixed space calculation issues in pp_pack.c (bsc#1082216)
    • CVE-2018-6798: Fixed heap buffer overflow in regexec.c (bsc#1082233)

    Non-security issue fixed:
    • make Net::FTP work with TLS 1.3 (bsc#1213638)


    Advisory IDSUSE-RU-2024:1852-1
    ReleasedThu May 30 14:02:02 2024
    SummaryRecommended update for wicked
    Typerecommended
    Severitymoderate
    References1205604,1218926,1219108,1224100
    Description:

    This update for wicked fixes the following issues:

    • client: fix ifreload to pull UP ports/links again when the config of their master/lower changed (bsc#1224100, gh#openSUSE/wicked#1014) - cleanup: fix ni_fsm_state_t enum-int-mismatch warnings - cleanup: fix overflow warnings in a socket testcase on i586 - ifcheck: report new and deleted configs as changed (bsc#1218926) - man: improve ARP configuration options in the wicked-config.5 - bond: add ports when master is UP to avoid port MTU revert (bsc#1219108) - cleanup: fix interface dependencies and shutdown order (bsc#1205604)
    • removed patches included in the source archive


    Advisory IDSUSE-SU-2024:1863-1
    ReleasedThu May 30 14:18:27 2024
    SummarySecurity update for python-Jinja2
    Typesecurity
    Severitymoderate
    References1218722,1223980,CVE-2024-22195,CVE-2024-34064
    Description:

    This update for python-Jinja2 fixes the following issues:

    • Fixed HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-34064, bsc#1223980, CVE-2024-22195, bsc#1218722)


    Advisory IDSUSE-RU-2024:1876-1
    ReleasedFri May 31 06:47:32 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1221361
    Description:

    This update for aaa_base fixes the following issues:

    • Fix the typo to set JAVA_BINDIR in the csh variant of the alljava profile script (bsc#1221361)


    Advisory IDSUSE-SU-2024:1880-1
    ReleasedFri May 31 08:45:12 2024
    SummarySecurity update for python-requests
    Typesecurity
    Severitymoderate
    References1224788,CVE-2024-35195
    Description:

    This update for python-requests fixes the following issues:

    • CVE-2024-35195: Fixed cert verification regardless of changes to the value of `verify` (bsc#1224788).


    Advisory IDSUSE-RU-2024:1883-1
    ReleasedFri May 31 09:31:11 2024
    SummaryRecommended update for iputils
    Typerecommended
    Severitymoderate
    References1224877
    Description:

    This update for iputils fixes the following issue:

    • 'arping: Fix 1s delay on exit for unsolicited arpings', backport upstream fix (bsc#1224877)
    • Backport proposed fix for regression in upstream commit 4db1de6 (bsc#1224877)


    Advisory IDSUSE-RU-2024:1887-1
    ReleasedFri May 31 19:08:38 2024
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1192014,1216717,1217979,1223278,1224320
    Description:

    This update for suse-module-tools fixes the following issues:

    • Include unblacklist in initramfs (bsc#1224320)
    • regenerate-initrd-posttrans: run update-bootloader --refresh for XEN (bsc#1223278)
    • 60-io-scheduler.rules: test for 'scheduler' sysfs attribute (bsc#1216717)
    • README: Update blacklist description (gh#openSUSE/suse-module-tools#71)
    • macros.initrd: %regenerate_initrd_post: don't fail if mkdir is unavailable (bsc#1217979)
    • Don't rebuild existing initramfs images if the environment variable SKIP_REGENERATE_ALL=1 is set (bsc#1192014)


    Advisory IDSUSE-RU-2024:1915-1
    ReleasedMon Jun 3 17:36:50 2024
    SummaryRecommended update for xfsprogs
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for xfsprogs fixes the following issue:

    • update to 6.7.0


    Advisory IDSUSE-SU-2024:1943-1
    ReleasedFri Jun 7 17:04:06 2024
    SummarySecurity update for util-linux
    Typesecurity
    Severityimportant
    References1218609,1220117,1221831,1223605,CVE-2024-28085
    Description:

    This update for util-linux fixes the following issues:

    • CVE-2024-28085: Properly neutralize escape sequences in wall to avoid potential account takeover. (bsc#1221831)


    Advisory IDSUSE-SU-2024:1950-1
    ReleasedFri Jun 7 17:20:14 2024
    SummarySecurity update for glib2
    Typesecurity
    Severitymoderate
    References1224044,CVE-2024-34397
    Description:

    This update for glib2 fixes the following issues:
    Update to version 2.78.6:

    • Fix a regression with IBus caused by the fix for CVE-2024-34397

    Changes in version 2.78.5:
    • Fix CVE-2024-34397: GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing. (bsc#1224044)
    • Bugs fixed: - gvfs-udisks2-volume-monitor SIGSEGV in g_content_type_guess_for_tree() due to filename with bad encoding - gcontenttype: Make filename valid utf-8 string before processing. - gdbusconnection: Don't deliver signals if the sender doesn't match.

    Changes in version 2.78.4:
    • Bugs fixed: - Fix generated RST anchors for methods, signals and properties. - docs/reference: depend on a native gtk-doc. - gobject_gdb.py: Do not break bt on optimized build. - gregex: clean up usage of _GRegex.jit_status.


    Advisory IDSUSE-RU-2024:1951-1
    ReleasedFri Jun 7 17:27:16 2024
    SummaryRecommended update for libbpf
    Typerecommended
    Severitymoderate
    References1221101
    Description:

    This update for libbpf fixes the following issues:

    • Fixed potential null pointer dereference in bpf_object__collect_prog_relos() (bsc#1221101)


    Advisory IDSUSE-RU-2024:1952-1
    ReleasedFri Jun 7 17:27:34 2024
    SummaryRecommended update for socat
    Typerecommended
    Severitymoderate
    References1160293
    Description:

    This update for socat fixes the following issues:
    Update to 1.8.0.0:

    • Support for network namespaces (option netns)
    • TCP client now automatically tries all addresses (IPv4 and IPv6) provided by nameserver until success
    • Implementation of POSIX message queue (mq) control and access on Linux (addresses POSIXMQ-READ and following)
    • New wrapper script socat-chain.sh allows to stack two addresses, e.g.HTTP proxy connect over SSL
    • New script socat-mux.sh allows n-to-1 / 1-to-n communications
    • New script socat-broker.sh allows group communications
    • Experimental socks5 client feature
    • Address ACCEPT-FD for systemd 'inetd' mode
    • UDP-Lite and DCCP address types
    • Addresses SOCKETPAIR and SHELL
    • New option bind-tmpname allows forked off children to bind UNIX domain client sockets to random unique pathes
    • New option retrieve-vlan (with INTERFACE addresses) now makes kernel keep VLAN tags in incoming packets
    • Simple statistics output with Socat option --statistics and with SIGUSR1
    • A couple of new options, many fixes and corrections, see file CHANGES

    • Note: This version introduces 'socat1', linking to 'socat'

    Update to 1.7.4.4:
    • FIX: In error.c msg2() there was a stack overflow on long messages: The terminating \0 Byte was written behind the last position.
    • FIX: UDP-RECVFROM with fork sometimes terminated when multiple packets arrived.
    • FIX: a couple of weaknesses and errors when accessing invalid or incompatible file system entries with UNIX domain, file, and generic addresses.
    • FIX: bad parser error message on 'socat /tmp/x\'x/x -'

    Update to 1.7.4.3:
    • fixes the TCP_INFO issue that broke building on non-Linux platforms.

    Update to version 1.7.4.2:
    • Fixes a lot of bugs, e.g., for options -r and -R.
    • Further bugfixes, see the CHANGES file

    Update to 1.7.4.1:
    Security:
    • Buffer size option (-b) is internally doubled for CR-CRLF conversion, but not checked for integer overflow. This could lead to heap based buffer overflow, assuming the attacker could provide this parameter.
    • Many further bugfixes and new features, see the CHANGES file

    Update to version 1.7.3.4:
    • bugfix release, see the CHANGES file for all changes

    Update to version 1.7.3.3:
    • bugfix release, see the CHANGES file for all changes

    • We HAVE_SSLv23_*_method, just not as functions, but macros add the relevant defines in the command line so support for autonegotiation of the highest TLS version is restored.


    Advisory IDSUSE-RU-2024:1954-1
    ReleasedFri Jun 7 18:01:06 2024
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1221482
    Description:

    This update for glibc fixes the following issues:

    • Also include stat64 in the 32-bit libc_nonshared.a workaround (bsc#1221482)


    Advisory IDSUSE-RU-2024:1994-1
    ReleasedTue Jun 11 15:03:55 2024
    SummaryRecommended update for iputils
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for iputils fixes the following issue:

    • After upstream merged the fix, update git commit hashes.


    Advisory IDSUSE-RU-2024:1997-1
    ReleasedTue Jun 11 17:24:32 2024
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1223596
    Description:

    This update for e2fsprogs fixes the following issues:

    • EA Inode handling fixes: - e2fsck: add more checks for ea inode consistency (bsc#1223596) - e2fsck: fix golden output of several tests (bsc#1223596)


    Advisory IDSUSE-RU-2024:2022-1
    ReleasedThu Jun 13 16:13:20 2024
    SummaryRecommended update for chrony
    Typerecommended
    Severitymoderate
    References1213551
    Description:

    This update for chrony fixes the following issues:

    • Use shorter NTS-KE retry interval when network is down (bsc#1213551)
    • Use make quickcheck instead of make check to avoid more than 1h build times and failures due to timeouts. This was the default before 3.2 but it changed to make tests more reliable


    Advisory IDSUSE-RU-2024:2024-1
    ReleasedThu Jun 13 16:15:18 2024
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1209627
    Description:

    This update for jitterentropy fixes the following issues:

    • Fixed a stack corruption on s390x: [bsc#1209627] * Output size of the STCKE command on s390x is 16 bytes, compared to 8 bytes of the STCK command. Fix a stack corruption in the s390x version of jent_get_nstime(). Add some more detailed information on the STCKE command.

    Updated to 3.4.1
    • add FIPS 140 hints to man page
    • simplify the test tool to search for optimal configurations
    • fix: jent_loop_shuffle: re-add setting the time that was lost with 3.4.0
    • enhancement: add ARM64 assembler code to read high-res timer


    Advisory ID33664
    ReleasedThu Jun 13 21:03:11 2024
    SummaryRecommended update for libsolv, libzypp, zypper, PackageKit-branding-SLE, PackageKit, libyui, yast2-pkg-bindings
    Typerecommended
    Severityimportant
    References1222086,1223430,1223766,1224242
    Description:

    This update for libsolv, libzypp, zypper, PackageKit-branding-SLE, PackageKit, libyui, yast2-pkg-bindings fixes the following issues:

    • Fix the dependency for Packagekit-backend-zypp in SUMa 4.3 (bsc#1224242)
    • Improve updating of installed multiversion packages
    • Fix decision introspection going into an endless loop in some cases
    • Split libsolv-tools into libsolv-tools-base [jsc#PED-8153]
    • Improve checks against corrupt rpm
    • Fixed check for outdated repo metadata as non-root user (bsc#1222086)
    • Add ZYPP_API for exported functions and switch to visibility=hidden (jsc#PED-8153)
    • Dynamically resolve libproxy (jsc#PED-8153)
    • Fix download from gpgkey URL (bsc#1223430)
    • Delay zypp lock until command options are parsed (bsc#1223766)
    • Unify message format


    Advisory IDSUSE-SU-2024:2059-1
    ReleasedTue Jun 18 13:11:29 2024
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1225551,CVE-2024-4741
    Description:

    This update for openssl-1_1 fixes the following issues:

    • CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551)


    Advisory IDSUSE-SU-2024:2060-1
    ReleasedTue Jun 18 13:11:47 2024
    SummarySecurity update for less
    Typesecurity
    Severityimportant
    References1222849,CVE-2024-32487
    Description:

    This update for less fixes the following issues:

    • CVE-2024-32487: Fixed OS command injection via a newline character in the file name. (bsc#1222849)


    Advisory IDSUSE-SU-2024:2066-1
    ReleasedTue Jun 18 13:16:09 2024
    SummarySecurity update for openssl-3
    Typesecurity
    Severityimportant
    References1223428,1224388,1225291,1225551,CVE-2024-4603,CVE-2024-4741
    Description:

    This update for openssl-3 fixes the following issues:
    Security issues fixed:

    • CVE-2024-4603: Check DSA parameters for excessive sizes before validating (bsc#1224388)
    • CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551)

    Other issues fixed:
    • Enable livepatching support (bsc#1223428)
    • Fix HDKF key derivation (bsc#1225291, gh#openssl/openssl#23448, + gh#openssl/openssl#23456)


    Advisory IDSUSE-RU-2024:2075-1
    ReleasedTue Jun 18 17:52:50 2024
    SummaryRecommended update for sudo
    Typerecommended
    Severitymoderate
    References1222104,1226008
    Description:

    This update for sudo fixes the following issues:

    • Revert the 'Match using canonicalized directories where possible.' feature just for SLE-15 This causes a breaking change in behavior for some customers (bsc#1222104, bsc#1226008)


    Advisory IDSUSE-RU-2024:2085-1
    ReleasedWed Jun 19 11:36:00 2024
    Summaryrecommended update for python-requests
    Typerecommended
    Severitymoderate
    References1225912
    Description:

    This update for python-requests fixes the following issue:

    • Allow the usage of 'verify' parameter as a directory. (bsc#1225912)


    Advisory IDSUSE-RU-2024:2086-1
    ReleasedWed Jun 19 11:48:24 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1188441
    Description:

    This update for gcc13 fixes the following issues:
    Update to GCC 13.3 release

    • Removed Fiji support from the GCN offload compiler as that is requiring Code Object version 3 which is no longer supported by llvm18.
    • Avoid combine spending too much compile-time and memory doing nothing on s390x. [bsc#1188441]
    • Make requirement to lld version specific to avoid requiring the meta-package.


    Advisory IDSUSE-RU-2024:2104-1
    ReleasedThu Jun 20 10:44:39 2024
    SummaryRecommended update for google-cloud SDK
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for protobuf and python-grpcio fixes the following issue:

    • Add python311 binaries to Python Module.


    Advisory IDSUSE-SU-2024:2108-1
    ReleasedThu Jun 20 19:35:51 2024
    SummarySecurity update for containerd
    Typesecurity
    Severityimportant
    References1221400,1224323,CVE-2023-45288
    Description:

    This update for containerd fixes the following issues:
    Update to containerd v1.7.17.

    • CVE-2023-45288: Fixed the limit of CONTINUATION frames read for an HTTP/2 request (bsc#1221400).
    • Fixed /sys/devices/virtual/powercap accessibility by default containers to mitigate power-based side channel attacks (bsc#1224323).


    Advisory IDSUSE-RU-2024:2172-1
    ReleasedMon Jun 24 05:51:55 2024
    SummaryRecommended update for iproute2
    Typerecommended
    Severitymoderate
    References1204562
    Description:

    This update for iproute2 fixes the following issues:
    iproute2 was updated to version 6.4 (jsc#PED-6820 jsc#PED-6844, jsc#PED-8358):

    • Fixed display of bound but unconnected sockets (bsc#1204562)
    • Changes in version 6.4: * bridge: mdb: added underlay destination IP support, UDP destination port support, destination VNI support, source VNI support, outgoing interface support * macvlan: added the 'bclim' parameter

    • Changes in version 6.3: * New release of iproute2 corresponding to the 6.3 kernel. No large feature improvements only incremental improvements to the bridge mdb support, mostly just bug fixes.

    • Changes in version 6.2:

    * f_flower: Introduce L2TPv3 support * bridge: fdb: Add support for locked FDB entries * bridge: link: Add MAC Authentication Bypass (MAB) support * ip: Support --json on `ip neigh get` * tc: Add JSON output to tc-class
    • Changes in version 6.1:

    * man: ss.8: fix a typo * testsuite: fix build failure * genl: remove unused vars in Makefile * json: do not escape single quotes * ip-monitor: Do not error out when RTNLGRP_STATS is not available * ip-link: man: Document existence of netns argument in add command * macsec: add Extended Packet Number support * macsec: add user manual description for extended packet number feature * ip: xfrm: support 'external' (`collect_md`) mode in xfrm interfaces * ip: xfrm: support adding xfrm metadata as lwtunnel info in routes * ip: add NLM_F_ECHO support * libnetlink: add offset for nl_dump_ext_ack_done * tc/tc_monitor: print netlink extack message * rtnetlink: add new function rtnl_echo_talk() * ip: fix return value for rtnl_talk failures * iplink_bridge: Add no_linklocal_learn option support * devlink: use dl_no_arg instead of checking dl_argc == 0 * devlink: remove dl_argv_parse_put * mnlg: remove unnused mnlg_socket structure * utils: extract CTRL_ATTR_MAXATTR and save it * devlink: expose nested devlink for a line card object * devlink: load port-ifname map on demand * devlink: fix parallel flash notifications processing * devlink: move use_iec into struct dl * devlink: fix typo in variable name in ifname_map_cb() * devlink: load ifname map on demand from ifname_map_rev_lookup() as well * dcb: unblock mnl_socket_recvfrom if not message received * libnetlink: Fix memory leak in __rtnl_talk_iov() * tc_util: Fix no error return when large parent id used * tc_util: Change datatype for maj to avoid overflow issue * ss: man: add missing entries for MPTCP * ss: man: add missing entries for TIPC * ss: usage: add missing parameters * ss: re-add TIPC query support * devlink: Fix setting parent for 'rate add' * link: display 'allmulti' counter * seg6: add support for flavors in SRv6 End* behaviors * tc: ct: Fix invalid pointer dereference * uapi: update from 6.1 pre rc1 * u32: fix json formatting of flowid * tc_stab: remove dead code * uapi: update for in.h and ip.h * remove #if 0 code * tc: add json support to size table * tc: put size table options in json object * tc/basic: fix json output filter * iplink: support JSON in MPLS output * tc: print errors on stderr * ip: print mpls errors on stderr * tc: make prefix const * man: add missing tc class show * iplink_can: add missing `]' of the bitrate, dbitrate and termination arrays * ip link: add sub-command to view and change DSA conduit interface
    • Changes in version 6.0:

    * ipstats: Add param.h for musl * Update kernel headers * libbpf: add xdp program name support * iplink: bond_slave: add per port prio support * seg6: add support for SRv6 Headend Reduced Encapsulation * lib: Introduce ppp protocols * f_flower: Introduce PPPoE support
    • Changes in version 5.19:

    * ip/iplink_virt_wifi: add support for virt_wifi * Update kernel headers * libnetlink: Add filtering to rtnl_statsdump_req_filter() * ipstats: Add a 'set' command * ipstats: Add a group 'link' * libbpf: Use bpf_object__load instead of bpf_object__load_xattr * uapi: change name for zerocopy sendfile in tls * bridge: vxlan device vnifilter support * f_flower: Add num of vlans parameter
    • Changes in version 5.18:

    * The build issues with libbpf should be fixed now. * Building with clang is now supported. * There are still some warnings with gcc-12 that will need to be fixed in the upstream kernel headers.
    • Changes in version 5.17:

    * lib/fs: fix memory leak in get_task_name() * bridge: Remove vlan listing from `bridge link` * bond: add arp_missed_max option * libnetlink: fix socket leak in rtnl_open_byproto() * dcb: Fix error reporting when accessing 'dcb app' * tc_util: Fix parsing action control with space and slash * lib: fix ax25.h include for musl * uapi: add missing rose and ax25 files * rdma: Fix res_print_uint() and add res_print_u64() * tc: Add support for ce_threshold_value/mask in fq_codel
    • Add tmpfiles.d conf for /run/netns

    • Changes in version 5.16:

    * devlink: Fix cmd_dev_param_set() to check configuration mode * ip: add AMT support * iplink_can: fix configuration ranges in print_usage() and add unit * tc: flower: Fix buffer overflow on large labels * ip/ipnexthop: fix unsigned overflow in parse_nh_group_type_res() * tc/m_vlan: fix print_vlan() conditional on TCA_VLAN_ACT_PUSH_ETH * iplink_can: add new CAN FD bittiming parameters: Transmitter Delay Compensation (TDC)
    • Changes in version 5.15:

    * lib: bpf_legacy: fix bpffs mount when /sys/fs/bpf exists * man: devlink-port: fix the devlink port add synopsis * man: devlink-port: fix pfnum for devlink port add * iptuntap: fix multi-queue flag display * mptcp: unbreak JSON endpoint list * ipneigh: add support to print brief output of neigh cache in tabular format * ip/bond: add LACP active support * ip/tunnel: always print all known attributes * Add, show, link, remove IOAM namespaces and schemas * New IOAM6 encap type for routes * tc/skbmod: Introduce SKBMOD_F_ECN option * tc/f_flower: fix port range parsing


    Advisory IDSUSE-SU-2024:2200-1
    ReleasedTue Jun 25 13:53:17 2024
    SummarySecurity update for avahi
    Typesecurity
    Severitymoderate
    References1216594,1216598,1226586,CVE-2023-38469,CVE-2023-38471
    Description:

    This update for avahi fixes the following issues:

    • CVE-2023-38471: Fixed a reachable assertion in dbus_set_host_name. (bsc#1216594)
    • CVE-2023-38469: Fixed a reachable assertion in avahi_dns_packet_append_record. (bsc#1216598)


    Advisory IDSUSE-SU-2024:2201-1
    ReleasedTue Jun 25 13:53:39 2024
    SummarySecurity update for wget
    Typesecurity
    Severitymoderate
    References1226419,CVE-2024-38428
    Description:

    This update for wget fixes the following issues:

    • CVE-2024-38428: Fix mishandled semicolons in the userinfo subcomponent of a URI. (bsc#1226419)


    Advisory IDSUSE-SU-2024:2203-1
    ReleasedTue Jun 25 15:04:37 2024
    SummarySecurity update for the Linux Kernel
    Typesecurity
    Severityimportant
    References1012628,1065729,1181674,1187716,1193599,1194869,1207948,1208593,1209657,1213573,1214852,1215199,1216196,1216358,1216702,1217169,1217384,1217408,1217489,1217750,1217959,1218205,1218336,1218447,1218779,1218917,1219104,1219170,1219596,1219623,1219834,1220021,1220045,1220120,1220148,1220328,1220342,1220428,1220430,1220569,1220587,1220783,1220915,1221044,1221293,1221303,1221504,1221612,1221615,1221635,1221645,1221649,1221765,1221777,1221783,1221816,1221829,1221830,1221858,1222048,1222173,1222264,1222273,1222294,1222301,1222303,1222304,1222307,1222357,1222366,1222368,1222371,1222378,1222385,1222422,1222426,1222428,1222437,1222445,1222459,1222464,1222489,1222522,1222525,1222532,1222557,1222559,1222563,1222585,1222596,1222606,1222608,1222613,1222615,1222618,1222622,1222624,1222627,1222630,1222635,1222721,1222727,1222769,1222771,1222775,1222777,1222780,1222782,1222793,1222799,1222801,1222968,1223007,1223011,1223015,1223020,1223023,1223024,1223033,1223034,1223035,1223038,1223039,1223041,1223045,1223046,1223051,1223052,1223058,1223060,1223061,1223076,1223077,1223111,1223113,1223138,1223143,1223187,1223189,1223190,1223191,1223198,1223202,1223285,1223315,1223338,1223369,1223380,1223384,1223390,1223439,1223462,1223532,1223539,1223575,1223590,1223591,1223592,1223593,1223625,1223629,1223633,1223634,1223637,1223641,1223643,1223649,1223650,1223651,1223652,1223653,1223654,1223655,1223660,1223661,1223664,1223665,1223666,1223668,1223669,1223670,1223671,1223675,1223677,1223678,1223686,1223692,1223693,1223695,1223696,1223698,1223705,1223712,1223718,1223728,1223732,1223735,1223739,1223741,1223744,1223745,1223747,1223748,1223749,1223750,1223752,1223754,1223757,1223759,1223761,1223762,1223774,1223782,1223787,1223788,1223789,1223790,1223802,1223805,1223810,1223822,1223827,1223831,1223834,1223838,1223869,1223870,1223871,1223872,1223874,1223944,1223945,1223946,1223991,1224076,1224096,1224098,1224099,1224137,1224166,1224174,1224177,1224180,1224181,1224331,1224423,1224429,1224430,1224432,1224433,1224437,1224438,1224442,1224443,1224445,1224449,1224477,1224479,1224480,1224481,1224482,1224486,1224487,1224488,1224491,1224492,1224493,1224494,1224495,1224500,1224501,1224502,1224504,1224505,1224506,1224507,1224508,1224509,1224511,1224513,1224517,1224519,1224521,1224524,1224525,1224526,1224530,1224531,1224534,1224537,1224541,1224542,1224543,1224546,1224550,1224552,1224553,1224555,1224557,1224558,1224559,1224562,1224565,1224566,1224567,1224568,1224569,1224571,1224573,1224576,1224577,1224578,1224579,1224580,1224581,1224582,1224585,1224586,1224587,1224588,1224592,1224596,1224598,1224600,1224601,1224602,1224603,1224605,1224607,1224608,1224609,1224611,1224613,1224615,1224617,1224618,1224620,1224621,1224622,1224623,1224624,1224626,1224627,1224628,1224629,1224630,1224632,1224633,1224634,1224636,1224637,1224638,1224639,1224640,1224643,1224644,1224645,1224646,1224647,1224648,1224649,1224650,1224651,1224652,1224653,1224654,1224657,1224660,1224663,1224664,1224665,1224666,1224667,1224668,1224671,1224672,1224674,1224675,1224676,1224677,1224678,1224679,1224680,1224681,1224682,1224683,1224685,1224686,1224687,1224688,1224692,1224696,1224697,1224699,1224701,1224703,1224704,1224705,1224706,1224707,1224709,1224710,1224712,1224714,1224716,1224717,1224718,1224719,1224720,1224721,1224722,1224723,1224725,1224727,1224728,1224729,1224730,1224731,1224732,1224733,1224736,1224738,1224739,1224740,1224741,1224742,1224747,1224749,1224763,1224764,1224765,1224766,1224790,1224792,1224793,1224803,1224804,1224866,1224936,1224989,1225007,1225053,1225133,1225134,1225136,1225172,1225502,1225578,1225579,1225580,1225593,1225605,1225607,1225610,1225616,1225618,1225640,1225642,1225692,1225694,1225695,1225696,1225698,1225699,1225704,1225705,1225708,1225710,1225712,1225714,1225715,1225720,1225722,1225728,1225734,1225735,1225736,1225747,1225748,1225749,1225750,1225756,1225765,1225766,1225769,1225773,1225775,1225842,1225945,1226158,CVE-2023-0160,CVE-2023-52434,CVE-2023-52458,CVE-2023-52472,CVE-2023-52503,CVE-2023-52616,CVE-2023-52618,CVE-2023-52631,CVE-2023-52635,CVE-2023-52640,CVE-2023-52641,CVE-2023-52645,CVE-2023-52652,CVE-2023-52653,CVE-2023-52654,CVE-2023-52655,CVE-2023-52657,CVE-2023-52658,CVE-2023-52659,CVE-2023-52660,CVE-2023-52661,CVE-2023-52662,CVE-2023-52663,CVE-2023-52664,CVE-2023-52667,CVE-2023-52669,CVE-2023-52670,CVE-2023-52671,CVE-2023-52673,CVE-2023-52674,CVE-2023-52675,CVE-2023-52676,CVE-2023-52678,CVE-2023-52679,CVE-2023-52680,CVE-2023-52681,CVE-2023-52683,CVE-2023-52685,CVE-2023-52686,CVE-2023-52687,CVE-2023-52690,CVE-2023-52691,CVE-2023-52692,CVE-2023-52693,CVE-2023-52694,CVE-2023-52695,CVE-2023-52696,CVE-2023-52697,CVE-2023-52698,CVE-2023-52771,CVE-2023-52772,CVE-2023-52860,CVE-2023-52882,CVE-2023-6238,CVE-2023-7042,CVE-2024-0639,CVE-2024-21823,CVE-2024-22099,CVE-2024-23848,CVE-2024-24861,CVE-2024-25739,CVE-2024-26601,CVE-2024-26611,CVE-2024-26614,CVE-2024-26632,CVE-2024-26638,CVE-2024-26642,CVE-2024-26643,CVE-2024-26650,CVE-2024-26654,CVE-2024-26656,CVE-2024-26657,CVE-2024-26671,CVE-2024-26673,CVE-2024-26674,CVE-2024-26679,CVE-2024-26684,CVE-2024-26685,CVE-2024-26692,CVE-2024-26704,CVE-2024-26714,CVE-2024-26726,CVE-2024-26731,CVE-2024-26733,CVE-2024-26737,CVE-2024-26739,CVE-2024-26740,CVE-2024-26742,CVE-2024-26760,CVE-2024-267600,CVE-2024-26761,CVE-2024-26764,CVE-2024-26769,CVE-2024-26772,CVE-2024-26773,CVE-2024-26774,CVE-2024-26775,CVE-2024-26783,CVE-2024-26786,CVE-2024-26791,CVE-2024-26793,CVE-2024-26794,CVE-2024-26802,CVE-2024-26805,CVE-2024-26807,CVE-2024-26815,CVE-2024-26816,CVE-2024-26822,CVE-2024-26832,CVE-2024-26836,CVE-2024-26844,CVE-2024-26846,CVE-2024-26853,CVE-2024-26854,CVE-2024-26855,CVE-2024-26856,CVE-2024-26857,CVE-2024-26858,CVE-2024-26860,CVE-2024-26861,CVE-2024-26862,CVE-2024-26866,CVE-2024-26868,CVE-2024-26870,CVE-2024-26878,CVE-2024-26881,CVE-2024-26882,CVE-2024-26883,CVE-2024-26884,CVE-2024-26885,CVE-2024-26899,CVE-2024-26900,CVE-2024-26901,CVE-2024-26903,CVE-2024-26906,CVE-2024-26909,CVE-2024-26921,CVE-2024-26922,CVE-2024-26923,CVE-2024-26925,CVE-2024-26928,CVE-2024-26932,CVE-2024-26933,CVE-2024-26934,CVE-2024-26935,CVE-2024-26937,CVE-2024-26938,CVE-2024-26940,CVE-2024-26943,CVE-2024-26945,CVE-2024-26946,CVE-2024-26948,CVE-2024-26949,CVE-2024-26950,CVE-2024-26951,CVE-2024-26957,CVE-2024-26958,CVE-2024-26960,CVE-2024-26961,CVE-2024-26962,CVE-2024-26963,CVE-2024-26964,CVE-2024-26972,CVE-2024-26973,CVE-2024-26978,CVE-2024-26981,CVE-2024-26982,CVE-2024-26983,CVE-2024-26984,CVE-2024-26986,CVE-2024-26988,CVE-2024-26989,CVE-2024-26990,CVE-2024-26991,CVE-2024-26992,CVE-2024-26993,CVE-2024-26994,CVE-2024-26995,CVE-2024-26996,CVE-2024-26997,CVE-2024-26999,CVE-2024-27000,CVE-2024-27001,CVE-2024-27002,CVE-2024-27003,CVE-2024-27004,CVE-2024-27008,CVE-2024-27013,CVE-2024-27014,CVE-2024-27022,CVE-2024-27027,CVE-2024-27028,CVE-2024-27029,CVE-2024-27030,CVE-2024-27031,CVE-2024-27036,CVE-2024-27046,CVE-2024-27056,CVE-2024-27057,CVE-2024-27062,CVE-2024-27067,CVE-2024-27080,CVE-2024-27388,CVE-2024-27389,CVE-2024-27393,CVE-2024-27395,CVE-2024-27396,CVE-2024-27398,CVE-2024-27399,CVE-2024-27400,CVE-2024-27401,CVE-2024-27405,CVE-2024-27408,CVE-2024-27410,CVE-2024-27411,CVE-2024-27412,CVE-2024-27413,CVE-2024-27416,CVE-2024-27417,CVE-2024-27418,CVE-2024-27431,CVE-2024-27432,CVE-2024-27434,CVE-2024-27435,CVE-2024-27436,CVE-2024-35784,CVE-2024-35786,CVE-2024-35788,CVE-2024-35789,CVE-2024-35790,CVE-2024-35791,CVE-2024-35794,CVE-2024-35795,CVE-2024-35796,CVE-2024-35799,CVE-2024-35800,CVE-2024-35801,CVE-2024-35803,CVE-2024-35804,CVE-2024-35806,CVE-2024-35808,CVE-2024-35809,CVE-2024-35810,CVE-2024-35811,CVE-2024-35812,CVE-2024-35813,CVE-2024-35814,CVE-2024-35815,CVE-2024-35817,CVE-2024-35819,CVE-2024-35821,CVE-2024-35822,CVE-2024-35823,CVE-2024-35824,CVE-2024-35825,CVE-2024-35828,CVE-2024-35829,CVE-2024-35830,CVE-2024-35833,CVE-2024-35834,CVE-2024-35835,CVE-2024-35836,CVE-2024-35837,CVE-2024-35838,CVE-2024-35841,CVE-2024-35842,CVE-2024-35845,CVE-2024-35847,CVE-2024-35849,CVE-2024-35850,CVE-2024-35851,CVE-2024-35852,CVE-2024-35854,CVE-2024-35860,CVE-2024-35861,CVE-2024-35862,CVE-2024-35863,CVE-2024-35864,CVE-2024-35865,CVE-2024-35866,CVE-2024-35867,CVE-2024-35868,CVE-2024-35869,CVE-2024-35870,CVE-2024-35872,CVE-2024-35875,CVE-2024-35877,CVE-2024-35878,CVE-2024-35879,CVE-2024-35883,CVE-2024-35885,CVE-2024-35887,CVE-2024-35889,CVE-2024-35891,CVE-2024-35895,CVE-2024-35901,CVE-2024-35903,CVE-2024-35904,CVE-2024-35905,CVE-2024-35907,CVE-2024-35909,CVE-2024-35911,CVE-2024-35912,CVE-2024-35914,CVE-2024-35915,CVE-2024-35916,CVE-2024-35917,CVE-2024-35921,CVE-2024-35922,CVE-2024-35924,CVE-2024-35927,CVE-2024-35928,CVE-2024-35930,CVE-2024-35931,CVE-2024-35932,CVE-2024-35933,CVE-2024-35935,CVE-2024-35936,CVE-2024-35937,CVE-2024-35938,CVE-2024-35940,CVE-2024-35943,CVE-2024-35944,CVE-2024-35945,CVE-2024-35946,CVE-2024-35947,CVE-2024-35950,CVE-2024-35951,CVE-2024-35952,CVE-2024-35953,CVE-2024-35954,CVE-2024-35955,CVE-2024-35956,CVE-2024-35958,CVE-2024-35959,CVE-2024-35960,CVE-2024-35961,CVE-2024-35963,CVE-2024-35964,CVE-2024-35965,CVE-2024-35966,CVE-2024-35967,CVE-2024-35969,CVE-2024-35971,CVE-2024-35972,CVE-2024-35973,CVE-2024-35974,CVE-2024-35975,CVE-2024-35977,CVE-2024-35978,CVE-2024-35981,CVE-2024-35982,CVE-2024-35984,CVE-2024-35986,CVE-2024-35989,CVE-2024-35990,CVE-2024-35991,CVE-2024-35992,CVE-2024-35995,CVE-2024-35997,CVE-2024-35999,CVE-2024-36002,CVE-2024-36006,CVE-2024-36007,CVE-2024-36009,CVE-2024-36011,CVE-2024-36012,CVE-2024-36013,CVE-2024-36014,CVE-2024-36015,CVE-2024-36016,CVE-2024-36018,CVE-2024-36019,CVE-2024-36020,CVE-2024-36021,CVE-2024-36025,CVE-2024-36026,CVE-2024-36029,CVE-2024-36030,CVE-2024-36032,CVE-2024-36880,CVE-2024-36885,CVE-2024-36890,CVE-2024-36891,CVE-2024-36893,CVE-2024-36894,CVE-2024-36895,CVE-2024-36896,CVE-2024-36897,CVE-2024-36898,CVE-2024-36906,CVE-2024-36918,CVE-2024-36921,CVE-2024-36922,CVE-2024-36928,CVE-2024-36930,CVE-2024-36931,CVE-2024-36936,CVE-2024-36940,CVE-2024-36941,CVE-2024-36942,CVE-2024-36944,CVE-2024-36947,CVE-2024-36949,CVE-2024-36950,CVE-2024-36951,CVE-2024-36955,CVE-2024-36959
    Description:



    The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security bugfixes.

    The following security bugs were fixed:

    • CVE-2023-0160: Fixed deadlock flaw in BPF that could allow a local user to potentially crash the system (bsc#1209657).
    • CVE-2023-52434: Fixed potential OOBs in smb2_parse_contexts() (bsc#1220148).
    • CVE-2023-52458: Fixed check that partition length needs to be aligned with block size (bsc#1220428).
    • CVE-2023-52503: Fixed tee/amdtee use-after-free vulnerability in amdtee_close_session (bsc#1220915).
    • CVE-2023-52618: Fixed string overflow in block/rnbd-srv (bsc#1221615).
    • CVE-2023-52631: Fixed an NULL dereference bug (bsc#1222264 CVE-2023-52631).
    • CVE-2023-52635: Fixed PM/devfreq to synchronize devfreq_monitor_[start/stop] (bsc#1222294).
    • CVE-2023-52640: Fixed out-of-bounds in ntfs_listxattr (bsc#1222301).
    • CVE-2023-52641: Fixed NULL ptr dereference checking at the end of attr_allocate_frame() (bsc#1222303)
    • CVE-2023-52645: Fixed pmdomain/mediatek race conditions with genpd (bsc#1223033).
    • CVE-2023-52652: Fixed NTB for possible name leak in ntb_register_device() (bsc#1223686).
    • CVE-2023-52659: Fixed to pfn_to_kaddr() not treated as a 64-bit type (bsc#1224442).
    • CVE-2023-52674: Add clamp() in scarlett2_mixer_ctl_put() (bsc#1224727).
    • CVE-2023-52680: Fixed missing error checks to *_ctl_get() (bsc#1224608).
    • CVE-2023-52692: Fixed missing error check to scarlett2_usb_set_config() (bsc#1224628).
    • CVE-2023-52698: Fixed memory leak in netlbl_calipso_add_pass() (CVE-2023-52698 bsc#1224621)
    • CVE-2023-52771: Fixed delete_endpoint() vs parent unregistration race (bsc#1225007).
    • CVE-2023-52772: Fixed use-after-free in unix_stream_read_actor() (bsc#1224989).
    • CVE-2023-52860: Fixed null pointer dereference in hisi_hns3 (bsc#1224936).
    • CVE-2023-6238: Fixed kcalloc() arguments order (bsc#1217384).
    • CVE-2023-7042: Fixed a null-pointer-dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() (bsc#1218336).
    • CVE-2024-0639: Fixed a denial-of-service vulnerability due to a deadlock found in sctp_auto_asconf_init in net/sctp/socket.c (bsc#1218917).
    • CVE-2024-21823: Fixed safety flag to struct ends (bsc#1223625).
    • CVE-2024-22099: Fixed a null-pointer-dereference in rfcomm_check_security (bsc#1219170).
    • CVE-2024-23848: Fixed media/cec for possible use-after-free in cec_queue_msg_fh (bsc#1219104).
    • CVE-2024-24861: Fixed an overflow due to race condition in media/xc4000 device driver in xc4000 xc4000_get_frequency() function (bsc#1219623).
    • CVE-2024-25739: Fixed possible crash in create_empty_lvol() in drivers/mtd/ubi/vtbl.c (bsc#1219834).
    • CVE-2024-26601: Fixed ext4 buddy bitmap corruption via fast commit replay (bsc#1220342).
    • CVE-2024-26614: Fixed the initialization of accept_queue's spinlocks (bsc#1221293).
    • CVE-2024-26632: Fixed iterating over an empty bio with bio_for_each_folio_all (bsc#1221635).
    • CVE-2024-26638: Fixed uninitialize struct msghdr completely (bsc#1221649 CVE-2024-26638).
    • CVE-2024-26642: Fixed the set of anonymous timeout flag in netfilter nf_tables (bsc#1221830).
    • CVE-2024-26643: Fixed mark set as dead when unbinding anonymous set with timeout (bsc#1221829).
    • CVE-2024-26654: Fixed use after free in ALSA/sh/aica (bsc#1222304).
    • CVE-2024-26656: Fixed drm/amdgpu use-after-free bug (bsc#1222307).
    • CVE-2024-26671: Fixed blk-mq IO hang from sbitmap wakeup race (bsc#1222357).
    • CVE-2024-26673: Fixed netfilter/nft_ct layer 3 and 4 protocol sanitization (bsc#1222368).
    • CVE-2024-26674: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups (bsc#1222378).
    • CVE-2024-26679: Fixed read sk->sk_family once in inet_recv_error() (bsc#1222385).
    • CVE-2024-26684: Fixed net/stmmac/xgmac handling of DPP safety error for DMA channels (bsc#1222445).
    • CVE-2024-26685: Fixed nilfs2 potential bug in end_buffer_async_write (bsc#1222437).
    • CVE-2024-26692: Fixed regression in writes when non-standard maximum write size negotiated (bsc#1222464).
    • CVE-2024-26704: Fixed a double-free of blocks due to wrong extents moved_len in ext4 (bsc#1222422).
    • CVE-2024-26726: Fixed invalid drop extent_map for free space inode on write error (bsc#1222532)
    • CVE-2024-26731: Fixed NULL pointer dereference in sk_psock_verdict_data_ready() (bsc#1222371).
    • CVE-2024-26733: Fixed an overflow in arp_req_get() in arp (bsc#1222585).
    • CVE-2024-26737: Fixed selftests/bpf racing between bpf_timer_cancel_and_free and bpf_timer_cancel (bsc#1222557).
    • CVE-2024-26740: Fixed use the backlog for mirred ingress (bsc#1222563).
    • CVE-2024-26760: Fixed bio_put() for error case (bsc#1222596 cve-2024-267600).
    • CVE-2024-26760: Fixed scsi/target/pscsi bio_put() for error case (bsc#1222596).
    • CVE-2024-26764: Fixed IOCB_AIO_RW check in fs/aio before the struct aio_kiocb conversion (bsc#1222721).
    • CVE-2024-26772: Fixed ext4 to avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() (bsc#1222613).
    • CVE-2024-26773: Fixed ext4 block allocation from corrupted group in ext4_mb_try_best_found() (bsc#1222618).
    • CVE-2024-26774: Fixed dividing by 0 in mb_update_avg_fragment_size() when block bitmap corrupt (bsc#1222622).
    • CVE-2024-26775: Fixed potential deadlock at set_capacity (bsc#1222627).
    • CVE-2024-26783: Fixed mm/vmscan bug when calling wakeup_kswapd() with a wrong zone index (bsc#1222615).
    • CVE-2024-26791: Fixed properly validate device names in btrfs (bsc#1222793)
    • CVE-2024-26793: Fixed an use-after-free and null-ptr-deref in gtp_newlink() in gtp (bsc#1222428).
    • CVE-2024-26805: Fixed a kernel-infoleak-after-free in __skb_datagram_iter in netlink (bsc#1222630).
    • CVE-2024-26807: Fixed spi/cadence-qspi NULL pointer reference in runtime PM hooks (bsc#1222801).
    • CVE-2024-26815: Fixed improper TCA_TAPRIO_TC_ENTRY_INDEX check (bsc#1222635).
    • CVE-2024-26816: Fixed relocations in .notes section when building with CONFIG_XEN_PV=y (bsc#1222624).
    • CVE-2024-26822: Set correct id, uid and cruid for multiuser automounts (bsc#1223011).
    • CVE-2024-26832: Fixed missing folio cleanup in writeback race path (bsc#1223007).
    • CVE-2024-26836: Fixed platform/x86/think-lmi password opcode ordering for workstations (bsc#1222968).
    • CVE-2024-26844: Fixed WARNING in _copy_from_iter (bsc#1223015).
    • CVE-2024-26853: Fixed igc returning frame twice in XDP_REDIRECT (bsc#1223061).
    • CVE-2024-26855: Fixed net/ice potential NULL pointer dereference in ice_bridge_setlink() (bsc#1223051).
    • CVE-2024-26856: Fixed use-after-free inside sparx5_del_mact_entry (bsc#1223052).
    • CVE-2024-26857: Fixed geneve to make sure to pull inner header in geneve_rx() (bsc#1223058).
    • CVE-2024-26860: Fixed a memory leak when rechecking the data (bsc#1223077).
    • CVE-2024-26861: Fixed wireguard/receive annotate data-race around receiving_counter.counter (bsc#1223076).
    • CVE-2024-26862: Fixed packet annotate data-races around ignore_outgoing (bsc#1223111).
    • CVE-2024-26866: Fixed spi/spi-fsl-lpspi by removing redundant spi_controller_put call (bsc#1223024).
    • CVE-2024-26878: Fixed quota for potential NULL pointer dereference (bsc#1223060).
    • CVE-2024-26881: Fixed net/hns3 kernel crash when 1588 is received on HIP08 devices (bsc#1223041).
    • CVE-2024-26882: Fixed net/ip_tunnel to make sure to pull inner header in ip_tunnel_rcv() (bsc#1223034).
    • CVE-2024-26883: Fixed bpf stackmap overflow check on 32-bit arches (bsc#1223035).
    • CVE-2024-26884: Fixed bpf hashtab overflow check on 32-bit arches (bsc#1223189).
    • CVE-2024-26885: Fixed bpf DEVMAP_HASH overflow check on 32-bit arches (bsc#1223190).
    • CVE-2024-26899: Fixed deadlock between bd_link_disk_holder and partition scan (bsc#1223045).
    • CVE-2024-26901: Fixed do_sys_name_to_handle() to use kzalloc() to prevent kernel-infoleak (bsc#1223198).
    • CVE-2024-26906: Fixed invalid vsyscall page read for copy_from_kernel_nofault() (bsc#1223202).
    • CVE-2024-26909: Fixed drm bridge use-after-free (bsc#1223143).
    • CVE-2024-26921: Preserve kabi for sk_buff (bsc#1223138).
    • CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223384).
    • CVE-2024-26925: Release mutex after nft_gc_seq_end from abort path (bsc#1223390).
    • CVE-2024-26928: Fix potential UAF in cifs_debug_files_proc_show() (bsc#1223532).
    • CVE-2024-26945: Fixed nr_cpus < nr_iaa case (bsc#1223732).
    • CVE-2024-26946: Fixed copy_from_kernel_nofault() to read from unsafe address (bsc#1223669).
    • CVE-2024-26948: Fixed drm/amd/display by adding dc_state NULL check in dc_state_release (bsc#1223664).
    • CVE-2024-26950: Fixed wireguard/netlink to access device through ctx instead of peer (bsc#1223661).
    • CVE-2024-26951: Fixed wireguard/netlink check for dangling peer via is_dead instead of empty list (bsc#1223660).
    • CVE-2024-26958: Fixed UAF in direct writes (bsc#1223653).
    • CVE-2024-26960: Fixed mm/swap race between free_swap_and_cache() and swapoff() (bsc#1223655).
    • CVE-2024-26982: Fixed Squashfs inode number check not to be an invalid value of zero (bsc#1223634).
    • CVE-2024-26991: Fixed overflow lpage_info when checking attributes (bsc#1223695).
    • CVE-2024-26993: Fixed fs/sysfs reference leak in sysfs_break_active_protection() (bsc#1223693).
    • CVE-2024-27013: Fixed tun limit printing rate when illegal packet received by tun device (bsc#1223745).
    • CVE-2024-27014: Fixed net/mlx5e to prevent deadlock while disabling aRFS (bsc#1223735).
    • CVE-2024-27022: Fixed linking file vma until vma is fully initialized (bsc#1223774).
    • CVE-2024-27030: Fixed octeontx2-af to use separate handlers for interrupts (bsc#1223790).
    • CVE-2024-27036: Fixed writeback data corruption (bsc#1223810).
    • CVE-2024-27046: Fixed nfp/flower handling acti_netdevs allocation failure (bsc#1223827).
    • CVE-2024-27056: Fixed wifi/iwlwifi/mvm to ensure offloading TID queue exists (bsc#1223822).
    • CVE-2024-27062: Fixed nouveau lock inside client object tree (bsc#1223834).
    • CVE-2024-27389: Fixed pstore inode handling with d_invalidate() (bsc#1223705).
    • CVE-2024-27395: Fixed Use-After-Free in ovs_ct_exit (bsc#1224098).
    • CVE-2024-27396: Fixed Use-After-Free in gtp_dellink (bsc#1224096).
    • CVE-2024-27401: Fixed user_length taken into account when fetching packet contents (bsc#1224181).
    • CVE-2024-27408: Fixed race condition in dmaengine w-edma/eDMA (bsc#1224430).
    • CVE-2024-27417: Fixed potential 'struct net' leak in inet6_rtm_getaddr() (bsc#1224721)
    • CVE-2024-27418: Fixed memory leak in mctp_local_output (bsc#1224720)
    • CVE-2024-27431: Fixed Zero-initialise xdp_rxq_info struct before running XDP program (bsc#1224718).
    • CVE-2024-35852: Fixed memory leak when canceling rehash work (bsc#1224502).
    • CVE-2024-35854: Fixed possible use-after-free during rehash (bsc#1224636).
    • CVE-2024-35860: struct bpf_link and bpf_link_ops kABI workaround (bsc#1224531).
    • CVE-2024-35861: Fixed potential UAF in cifs_signal_cifsd_for_reconnect() (bsc#1224766).
    • CVE-2024-35862: Fixed potential UAF in smb2_is_network_name_deleted() (bsc#1224764).
    • CVE-2024-35863: Fixed potential UAF in is_valid_oplock_break() (bsc#1224763).
    • CVE-2024-35864: Fixed potential UAF in smb2_is_valid_lease_break() (bsc#1224765).
    • CVE-2024-35865: Fixed potential UAF in smb2_is_valid_oplock_break() (bsc#1224668).
    • CVE-2024-35866: Fixed potential UAF in cifs_dump_full_key() (bsc#1224667).
    • CVE-2024-35867: Fixed potential UAF in cifs_stats_proc_show() (bsc#1224664).
    • CVE-2024-35868: Fixed potential UAF in cifs_stats_proc_write() (bsc#1224678).
    • CVE-2024-35869: Guarantee refcounted children from parent session (bsc#1224679).
    • CVE-2024-35870: Fixed UAF in smb2_reconnect_server() (bsc#1224672).
    • CVE-2024-35872: Fixed GUP-fast succeeding on secretmem folios (bsc#1224530).
    • CVE-2024-35877: Fixed VM_PAT handling in COW mappings (bsc#1224525).
    • CVE-2024-35895: Fixed lock inversion deadlock in map delete elem (bsc#1224511).
    • CVE-2024-35903: Fixed IP after emitting call depth accounting (bsc#1224493).
    • CVE-2024-35905: Fixed int overflow for stack access size (bsc#1224488).
    • CVE-2024-35917: Fixed Fix bpf_plt pointer arithmetic (bsc#1224481).
    • CVE-2024-35921: Fixed oops when HEVC init fails (bsc#1224477).
    • CVE-2024-35931: Fixed PCI error slot reset during RAS recovery (bsc#1224652).
    • CVE-2024-35943: Fixed a null pointer dereference in omap_prm_domain_init (bsc#1224649).
    • CVE-2024-35944: Fixed memcpy() run-time warning in dg_dispatch_as_host() (bsc#1224648).
    • CVE-2024-35956: Fixed qgroup prealloc rsv leak in subvolume operations (bsc#1224674)
    • CVE-2024-35964: Fixed not validating setsockopt user input (bsc#1224581).
    • CVE-2024-35969: Fixed race condition between ipv6_get_ifaddr and ipv6_del_addr (bsc#1224580).
    • CVE-2024-35991: Fixed kABI workaround for struct idxd_evl (bsc#1224553).
    • CVE-2024-35999: Fixed missing lock when picking channel (bsc#1224550).
    • CVE-2024-36006: Fixed incorrect list API usage (bsc#1224541).
    • CVE-2024-36007: Fixed warning during rehash (bsc#1224543).
    • CVE-2024-36030: Fixed the double free in rvu_npc_freemem() (bsc#1225712)

    The following non-security bugs were fixed:
    • 9p: add missing locking around taking dentry fid list (git-fixes)
    • accel/ivpu: Fix deadlock in context_xa (git-fixes).
    • ACPI: bus: Indicate support for IRQ ResourceSource thru _OSC (git-fixes).
    • ACPI: bus: Indicate support for _TFP thru _OSC (git-fixes).
    • ACPI: bus: Indicate support for the Generic Event Device thru _OSC (git-fixes).
    • ACPICA: debugger: check status of acpi_evaluate_object() in acpi_db_walk_for_fields() (git-fixes).
    • ACPI: CPPC: Fix access width used for PCC registers (git-fixes).
    • ACPI: CPPC: Fix bit_offset shift in MASK_VAL() macro (git-fixes).
    • ACPI: CPPC: Use access_width over bit_width for system memory accesses (stable-fixes).
    • ACPI: disable -Wstringop-truncation (git-fixes).
    • ACPI: Fix Generic Initiator Affinity _OSC bit (git-fixes).
    • ACPI: LPSS: Advertise number of chip selects via property (git-fixes).
    • ACPI: resource: Add Infinity laptops to irq1_edge_low_force_override (stable-fixes).
    • ACPI: resource: Do IRQ override on Lunnen Ground laptops (stable-fixes).
    • ACPI: scan: Do not increase dep_unmet for already met dependencies (git-fixes).
    • ACPI: video: Add backlight=native quirk for Lenovo Slim 7 16ARH7 (bsc#1217750).
    • ACPI: x86: Move acpi_quirk_skip_serdev_enumeration() out of CONFIG_X86_ANDROID_TABLETS (stable-fixes).
    • Add alt-commit to a nouveau patch
    • Add reference to L3 bsc#1225765 in BPF control flow graph and precision backtrack fixes (bsc#1225756) The L3 bsc#1225765 was created seperately since our customer requires PTF.
    • admin-guide/hw-vuln/core-scheduling: fix return type of PR_SCHED_CORE_GET (git-fixes).
    • ahci: asm1064: asm1166: do not limit reported ports (git-fixes).
    • ahci: asm1064: correct count of reported ports (stable-fixes).
    • ALSA: aoa: avoid false-positive format truncation warning (git-fixes).
    • ALSA: core: Fix NULL module pointer assignment at card init (git-fixes).
    • ALSA: core: Remove debugfs at disconnection (git-fixes).
    • ALSA: firewire-lib: handle quirk to calculate payload quadlets as data block counter (stable-fixes).
    • ALSA: Fix deadlocks with kctl removals at disconnection (stable-fixes).
    • ALSA: hda: Add Intel BMG PCI ID and HDMI codec vid (stable-fixes).
    • ALSA: hda: clarify Copyright information (stable-fixes).
    • ALSA: hda: cs35l41: Add support for ASUS ROG 2024 Laptops (stable-fixes).
    • ALSA: hda: cs35l41: Ignore errors when configuring IRQs (stable-fixes).
    • ALSA: hda: cs35l41: Remove redundant argument to cs35l41_request_firmware_file() (stable-fixes).
    • ALSA: hda: cs35l41: Remove Speaker ID for Lenovo Legion slim 7 16ARHA7 (git-fixes).
    • ALSA: hda: cs35l41: Set the max PCM Gain using tuning setting (stable-fixes).
    • ALSA: hda: cs35l41: Support HP Omen models without _DSD (stable-fixes).
    • ALSA: hda: cs35l41: Support Lenovo 13X laptop without _DSD (stable-fixes).
    • ALSA: hda: cs35l41: Update DSP1RX5/6 Sources for DSP config (stable-fixes).
    • ALSA: hda: cs35l56: Add ACPI device match tables (git-fixes).
    • ALSA: hda: cs35l56: Exit cache-only after cs35l56_wait_for_firmware_boot() (stable-fixes).
    • ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance (git-fixes).
    • ALSA: hda: cs35l56: Set the init_done flag before component_add() (git-fixes).
    • ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup (git-fixes).
    • ALSA: hda: hda_cs_dsp_ctl: Remove notification of driver write (stable-fixes).
    • ALSA: hda: intel-dsp-config: harden I2C/I2S codec detection (stable-fixes).
    • ALSA/hda: intel-dsp-config: reduce log verbosity (git-fixes).
    • ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() (git-fixes).
    • ALSA: hda/realtek: Add quirk for HP SnowWhite laptops (stable-fixes).
    • ALSA: hda/realtek: Add quirk for HP Spectre x360 14 eu0000 (stable-fixes).
    • ALSA: hda/realtek: Add quirks for ASUS Laptops using CS35L56 (stable-fixes).
    • ALSA: hda/realtek: Add quirks for HP Omen models using CS35L41 (stable-fixes).
    • ALSA: hda/realtek: Add quirks for Huawei Matebook D14 NBLB-WAX9N (stable-fixes).
    • ALSA: hda/realtek: Add quirks for Lenovo 13X (stable-fixes).
    • ALSA: hda/realtek: Add quirks for some Clevo laptops (stable-fixes).
    • ALSA: hda/realtek: Add sound quirks for Lenovo Legion slim 7 16ARHA7 models (stable-fixes).
    • ALSA: hda/realtek: Add support for ASUS Zenbook 2024 HN7306W (stable-fixes).
    • ALSA: hda/realtek: Adjust G814JZR to use SPI init for amp (git-fixes).
    • ALSA: hda/realtek: cs35l41: Support ASUS ROG G634JYR (stable-fixes).
    • ALSA: hda/realtek: Drop doubly quirk entry for 103c:8a2e (git-fixes).
    • ALSA: hda/realtek - Enable audio jacks of Haier Boyue G42 with ALC269VC (stable-fixes).
    • ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with ALC897 (stable-fixes).
    • ALSA: hda/realtek: Fix build error without CONFIG_PM (stable-fixes).
    • ALSA: hda/realtek: Fix conflicting PCI SSID 17aa:386f for Lenovo Legion models (bsc#1223462).
    • ALSA: hda/realtek - fixed headset Mic not show (stable-fixes).
    • ALSA: hda/realtek: Fixes for Asus GU605M and GA403U sound (stable-fixes).
    • ALSA: hda/realtek - Fix inactive headset mic jack (stable-fixes).
    • ALSA: hda/realtek: Fix internal speakers for Legion Y9000X 2022 IAH7 (stable-fixes).
    • ALSA: hda/realtek: Fix mute led of HP Laptop 15-da3001TU (stable-fixes).
    • ALSA: hda/realtek: fix mute/micmute LEDs do not work for ProBook 440/460 G11 (stable-fixes).
    • ALSA: hda/realtek: fix the hp playback volume issue for LG machines (stable-fixes).
    • ALSA: hda/realtek: Fix volumn control of ThinkBook 16P Gen4 (git-fixes).
    • ALSA: hda/realtek - Set GPIO3 to default at S4 state for Thinkpad with ALC1318 (stable-fixes).
    • ALSA: hda/realtek: Update Panasonic CF-SZ6 quirk to support headset with microphone (git-fixes).
    • ALSA: hda/tas2781: add locks to kcontrols (git-fixes).
    • ALSA: hda/tas2781: Add new vendor_id and subsystem_id to support ThinkPad ICE-1 (stable-fixes).
    • ALSA: hda/tas2781: correct the register for pow calibrated data (git-fixes).
    • ALSA: hda/tas2781: remove digital gain kcontrol (git-fixes).
    • ALSA: line6: Zero-initialize message buffers (stable-fixes).
    • ALSA: scarlett2: Add Focusrite Clarett+ 2Pre and 4Pre support (stable-fixes).
    • ALSA: scarlett2: Add Focusrite Clarett 2Pre and 4Pre USB support (stable-fixes).
    • ALSA: scarlett2: Add missing error check to scarlett2_config_save() (git-fixes).
    • ALSA: scarlett2: Add support for Clarett 8Pre USB (stable-fixes).
    • ALSA: scarlett2: Default mixer driver to enabled (stable-fixes).
    • ALSA: scarlett2: Move USB IDs out from device_info struct (stable-fixes).
    • ALSA: seq: Do not clear bank selection at event -> UMP MIDI2 conversion (git-fixes).
    • ALSA: seq: Fix incorrect UMP type for system messages (git-fixes).
    • ALSA: seq: Fix missing bank setup between MIDI1/MIDI2 UMP conversion (git-fixes).
    • ALSA: seq: Fix yet another spot for system message conversion (git-fixes).
    • ALSA: seq: ump: Fix conversion from MIDI2 to MIDI1 UMP messages (git-fixes).
    • ALSA: seq: ump: Fix swapped song position pointer data (git-fixes).
    • ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs (git-fixes).
    • ALSA: timer: Set lower bound of start tick time (stable-fixes).
    • ALSA: ump: Do not accept an invalid UMP protocol number (git-fixes).
    • ALSA: ump: Do not clear bank selection after sending a program change (git-fixes).
    • ALSA: ump: Set default protocol when not given explicitly (git-fixes).
    • ALSA: usb-audio: Add sampling rates support for Mbox3 (stable-fixes).
    • ALSA: usb-audio: Fix for sampling rates support for Mbox3 (stable-fixes).
    • amd/amdkfd: sync all devices to wait all processes being evicted (stable-fixes).
    • amdkfd: use calloc instead of kzalloc to avoid integer overflow (stable-fixes).
    • arm64: bpf: fix 32bit unconditional bswap (git-fixes).
    • arm64: dts: allwinner: h616: Fix I2C0 pins (git-fixes)
    • arm64: dts: allwinner: Pine H64: correctly remove reg_gmac_3v3 (git-fixes)
    • arm64: dts: broadcom: bcmbca: bcm4908: drop invalid switch cells (git-fixes)
    • arm64: dts: Fix dtc interrupt_provider warnings (git-fixes)
    • arm64: dts: hi3798cv200: fix the size of GICR (git-fixes)
    • arm64: dts: imx8qm-ss-dma: fix can lpcg indices (git-fixes)
    • arm64: dts: imx8-ss-conn: fix usb lpcg indices (git-fixes)
    • arm64: dts: imx8-ss-conn: fix usdhc wrong lpcg clock order (git-fixes)
    • arm64: dts: imx8-ss-dma: fix adc lpcg indices (git-fixes)
    • arm64: dts: imx8-ss-dma: fix can lpcg indices (git-fixes)
    • arm64: dts: imx8-ss-dma: fix spi lpcg indices (git-fixes)
    • arm64: dts: imx8-ss-lsio: fix pwm lpcg indices (git-fixes)
    • arm64: dts: marvell: reorder crypto interrupts on Armada SoCs (git-fixes)
    • arm64: dts: microchip: sparx5: fix mdio reg (git-fixes)
    • arm64: dts: rockchip: Add enable-strobe-pulldown to emmc phy on ROCK (git-fixes)
    • arm64: dts: rockchip: enable internal pull-up for Q7_THRM# on RK3399 (git-fixes)
    • arm64: dts: rockchip: enable internal pull-up on PCIE_WAKE# for (git-fixes)
    • arm64: dts: rockchip: enable internal pull-up on Q7_USB_ID for RK3399 (git-fixes)
    • arm64: dts: rockchip: fix rk3328 hdmi ports node (git-fixes)
    • arm64: dts: rockchip: fix rk3399 hdmi ports node (git-fixes)
    • arm64: dts: rockchip: regulator for sd needs to be always on for (git-fixes)
    • arm64: dts: rockchip: Remove unsupported node from the Pinebook Pro (git-fixes)
    • arm64: dts: rockchip: set PHY address of MT7531 switch to 0x1f (git-fixes)
    • arm64/head: Disable MMU at EL2 before clearing HCR_EL2.E2H (git-fixes).
    • arm64: hibernate: Fix level3 translation fault in swsusp_save() (git-fixes).
    • arm64/ptrace: Use saved floating point state type to determine SVE (git-fixes)
    • arm64/sve: Lower the maximum allocation for the SVE ptrace regset (git-fixes)
    • arm64: tegra: Correct Tegra132 I2C alias (git-fixes)
    • arm64: tegra: Set the correct PHY mode for MGBE (git-fixes)
    • ARM: 9381/1: kasan: clear stale stack poison (git-fixes).
    • ARM: imx: Check return value of devm_kasprintf in imx_mmdc_perf_init (git-fixes).
    • ARM: imx_v6_v7_defconfig: Restore CONFIG_BACKLIGHT_CLASS_DEVICE (git-fixes).
    • ARM: OMAP2+: fix N810 MMC gpiod table (git-fixes).
    • ARM: OMAP2+: fix USB regression on Nokia N8x0 (git-fixes).
    • arm_pmu: acpi: Add a representative platform device for TRBE (bsc#1220587)
    • arm_pmu: acpi: Refactor arm_spe_acpi_register_device() (bsc#1220587)
    • ARM: prctl: reject PR_SET_MDWE on pre-ARMv6 (stable-fixes).
    • ARM: s5pv210: fix pm.c kernel-doc warning (git-fixes).
    • asm-generic: make sparse happy with odd-sized put_unaligned_*() (stable-fixes).
    • ASoC: acp: Support microphone from device Acer 315-24p (git-fixes).
    • ASoC: amd: acp: fix for acp_init function error handling (git-fixes).
    • ASoC: amd: yc: Add Lenovo ThinkBook 21J0 into DMI quirk table (stable-fixes).
    • ASoC: amd: yc: Fix non-functional mic on ASUS M7600RE (stable-fixes).
    • ASoC: amd: yc: Fix non-functional mic on Lenovo 21J2 (stable-fixes).
    • ASoC: amd: yc: Revert 'Fix non-functional mic on Lenovo 21J2' (stable-fixes).
    • ASoC: codecs: wsa881x: set clk_stop_mode1 flag (git-fixes).
    • ASoC: cs35l56: Fix unintended bus access while resetting amp (git-fixes).
    • ASoC: cs35l56: Prevent overwriting firmware ASP config (git-fixes).
    • ASoC: da7219-aad: fix usage of device_get_named_child_node() (git-fixes).
    • ASoC: Intel: avs: Fix ASRC module initialization (git-fixes).
    • ASoC: Intel: avs: Fix potential integer overflow (git-fixes).
    • ASoC: Intel: avs: Populate board selection with new I2S entries (stable-fixes).
    • ASoC: Intel: avs: Set name of control as in topology (git-fixes).
    • ASoC: Intel: avs: ssm4567: Do not ignore route checks (git-fixes).
    • ASoC: Intel: avs: Test result of avs_get_module_entry() (git-fixes).
    • ASoC: Intel: bytcr_rt5640: Apply Asus T100TA quirk to Asus T100TAM too (git-fixes).
    • ASoC: Intel: common: DMI remap for rebranded Intel NUC M15 (LAPRC710) laptops (stable-fixes).
    • ASoC: Intel: Disable route checks for Skylake boards (git-fixes).
    • ASoC: kirkwood: Fix potential NULL dereference (git-fixes).
    • ASoC: mediatek: Assign dummy when codec not specified for a DAI link (git-fixes).
    • ASoC: mediatek: mt8192: fix register configuration for tdm (git-fixes).
    • ASoC: meson: axg-card: make links nonatomic (git-fixes).
    • ASoC: meson: axg-fifo: use FIELD helpers (stable-fixes).
    • ASoC: meson: axg-fifo: use threaded irq to check periods (git-fixes).
    • ASoC: meson: axg-tdm-interface: manage formatters in trigger (git-fixes).
    • ASoC: meson: cards: select SND_DYNAMIC_MINORS (git-fixes).
    • ASoC: ops: Fix wraparound for mask in snd_soc_get_volsw (git-fixes).
    • ASoC: rockchip: i2s-tdm: Fix inaccurate sampling rates (git-fixes).
    • ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating (git-fixes).
    • ASoC: rt5645: Make LattePanda board DMI match more precise (stable-fixes).
    • ASoC: rt5682-sdw: fix locking sequence (git-fixes).
    • ASoC: rt711-sdca: fix locking sequence (git-fixes).
    • ASoC: rt711-sdw: fix locking sequence (git-fixes).
    • ASoC: rt712-sdca-sdw: fix locking sequence (git-fixes).
    • ASoC: rt715: add vendor clear control register (git-fixes).
    • ASoC: rt715-sdca: volume step modification (git-fixes).
    • ASoC: rt722-sdca: add headset microphone vrefo setting (git-fixes).
    • ASoC: rt722-sdca: modify channel number to support 4 channels (git-fixes).
    • ASoC: rt722-sdca-sdw: fix locking sequence (git-fixes).
    • ASoC: soc-core.c: Skip dummy codec when adding platforms (stable-fixes).
    • ASoC: SOF: amd: Optimize quirk for Valve Galileo (stable-fixes).
    • ASoC: SOF: Intel: add default firmware library path for LNL (git-fixes).
    • ASoC: SOF: Intel: hda-dsp: Skip IMR boot on ACE platforms in case of S3 suspend (stable-fixes).
    • ASoC: SOF: Intel: lnl: Correct rom_status_reg (git-fixes).
    • ASoC: SOF: Intel: mtl: call dsp dump when boot retry fails (stable-fixes).
    • ASoC: SOF: Intel: mtl: Correct rom_status_reg (git-fixes).
    • ASoC: SOF: Intel: mtl: Disable interrupts when firmware boot failed (git-fixes).
    • ASoC: SOF: Intel: mtl: Implement firmware boot state check (git-fixes).
    • ASoC: SOF: ipc4-pcm: Workaround for crashed firmware on system suspend (stable-fixes).
    • ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension (git-fixes).
    • ASoC: tas2552: Add TX path for capturing AUDIO-OUT data (git-fixes).
    • ASoC: tas2781: Fix a warning reported by robot kernel test (git-fixes).
    • ASoC: tas2781: Fix wrong loading calibrated data sequence (git-fixes).
    • ASoC: tas2781: mark dvc_tlv with __maybe_unused (git-fixes).
    • ASoC: tegra: Fix DSPK 16-bit playback (git-fixes).
    • ASoC: ti: Convert Pandora ASoC to GPIO descriptors (stable-fixes).
    • ASoC: ti: davinci-mcasp: Fix race condition during probe (git-fixes).
    • ASoC: tlv320adc3xxx: Do not strip remove function when driver is builtin (git-fixes).
    • ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value (git-fixes).
    • ASoC: wm_adsp: Add missing MODULE_DESCRIPTION() (git-fixes).
    • ASoC: wm_adsp: Fix missing mutex_lock in wm_adsp_write_ctl() (git-fixes).
    • ata: libata-core: Allow command duration limits detection for ACS-4 drives (git-fixes).
    • ata: pata_legacy: make legacy_exit() work again (git-fixes).
    • ata: sata_gemini: Check clk_enable() result (stable-fixes).
    • ata: sata_mv: Fix PCI device ID table declaration compilation warning (git-fixes).
    • ata: sata_sx4: fix pdc20621_get_from_dimm() on 64-bit (git-fixes).
    • autofs: use wake_up() instead of wake_up_interruptible(() (bsc#1224166).
    • ax25: Fix netdev refcount issue (git-fixes).
    • ax25: Fix reference count leak issue of net_device (git-fixes).
    • ax25: Fix reference count leak issues of ax25_dev (git-fixes).
    • ax25: fix use-after-free bugs caused by ax25_ds_del_timer (git-fixes).
    • batman-adv: Avoid infinite loop trying to resize local TT (git-fixes).
    • bitops: add missing prototype check (git-fixes).
    • blk-cgroup: fix list corruption from reorder of WRITE ->lqueued (bsc#1225605).
    • blk-cgroup: fix list corruption from resetting io stat (bsc#1225605).
    • block: fix q->blkg_list corruption during disk rebind (bsc#1223591).
    • Bluetooth: Add new quirk for broken read key length on ATS2851 (stable-fixes).
    • Bluetooth: add quirk for broken address properties (git-fixes).
    • Bluetooth: btintel: Fixe build regression (git-fixes).
    • Bluetooth: btintel: Fix null ptr deref in btintel_read_version (stable-fixes).
    • Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x0bda:0x4853 (stable-fixes).
    • Bluetooth: btusb: Fix triggering coredump implementation for QCA (git-fixes).
    • Bluetooth: Fix memory leak in hci_req_sync_complete() (git-fixes).
    • Bluetooth: Fix TOCTOU in HCI debugfs implementation (git-fixes).
    • Bluetooth: Fix type of len in {l2cap,sco}_sock_getsockopt_old() (stable-fixes).
    • Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout (git-fixes).
    • Bluetooth: hci_core: Cancel request on command timeout (stable-fixes).
    • Bluetooth: hci_event: Fix sending HCI_OP_READ_ENC_KEY_SIZE (git-fixes).
    • Bluetooth: hci_event: set the conn encrypted before conn establishes (stable-fixes).
    • Bluetooth: HCI: Fix potential null-ptr-deref (git-fixes).
    • Bluetooth: hci_sock: Fix not validating setsockopt user input (git-fixes).
    • Bluetooth: hci_sync: Fix not checking error on hci_cmd_sync_cancel_sync (git-fixes).
    • Bluetooth: hci_sync: Fix using the same interval and window for Coded PHY (git-fixes).
    • Bluetooth: hci_sync: Use QoS to determine which PHY to scan (stable-fixes).
    • Bluetooth: ISO: Align broadcast sync_timeout with connection timeout (stable-fixes).
    • Bluetooth: ISO: Do not reject BT_ISO_QOS if parameters are unset (git-fixes).
    • Bluetooth: l2cap: Do not double set the HCI_CONN_MGMT_CONNECTED bit (git-fixes).
    • Bluetooth: L2CAP: Fix not validating setsockopt user input (git-fixes).
    • Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout (git-fixes).
    • Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() (git-fixes).
    • Bluetooth: MGMT: Fix failing to MGMT_OP_ADD_UUID/MGMT_OP_REMOVE_UUID (bsc#1221504).
    • Bluetooth: mgmt: Fix limited discoverable off timeout (stable-fixes).
    • Bluetooth: msft: fix slab-use-after-free in msft_do_close() (git-fixes).
    • Bluetooth: qca: add missing firmware sanity checks (git-fixes).
    • Bluetooth: qca: fix device-address endianness (git-fixes).
    • Bluetooth: qca: Fix error code in qca_read_fw_build_info() (git-fixes).
    • Bluetooth: qca: fix firmware check error path (git-fixes).
    • Bluetooth: qca: fix info leak when fetching fw build id (git-fixes).
    • Bluetooth: qca: fix NULL-deref on non-serdev setup (git-fixes).
    • Bluetooth: qca: fix NULL-deref on non-serdev suspend (git-fixes).
    • Bluetooth: qca: fix NVM configuration parsing (git-fixes).
    • Bluetooth: RFCOMM: Fix not validating setsockopt user input (git-fixes).
    • Bluetooth: SCO: Fix not validating setsockopt user input (git-fixes).
    • bnx2x: Fix firmware version string character counts (git-fixes).
    • bnxt_en: Fix error recovery for RoCE ulp client (git-fixes).
    • bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() (git-fixes).
    • bnxt_en: Reset PTP tx_avail after possible firmware reset (git-fixes).
    • bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq (git-fixes)
    • bootconfig: Fix the kerneldoc of _xbc_exit() (git-fixes).
    • bootconfig: use memblock_free_late to free xbc memory to buddy (git-fixes).
    • bootmem: use kmemleak_free_part_phys in free_bootmem_page (git-fixes).
    • bootmem: use kmemleak_free_part_phys in put_page_bootmem (git-fixes).
    • bpf, arm64: fix bug in BPF_LDX_MEMSX (git-fixes)
    • bpf, arm64: Fix incorrect runtime stats (git-fixes)
    • bpf: fix precision backtracking instruction iteration (bsc#1225756).
    • bpf: Fix precision tracking for BPF_ALU | BPF_TO_BE | BPF_END (git-fixes).
    • bpf: handle ldimm64 properly in check_cfg() (bsc#1225756).
    • bpf, scripts: Correct GPL license name (git-fixes).
    • btrfs: add a helper to read the superblock metadata_uuid (git-fixes)
    • btrfs: add and use helper to check if block group is used (bsc#1220120).
    • btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks() (git-fixes)
    • btrfs: add new unused block groups to the list of unused block groups (bsc#1220120).
    • btrfs: allow to run delayed refs by bytes to be released instead of count (bsc#1220120).
    • btrfs: always print transaction aborted messages with an error level (git-fixes)
    • btrfs: always reserve space for delayed refs when starting transaction (bsc#1220120).
    • btrfs: assert correct lock is held at btrfs_select_ref_head() (bsc#1220120).
    • btrfs: assert delayed node locked when removing delayed item (git-fixes)
    • btrfs: avoid starting and committing empty transaction when flushing space (bsc#1220120).
    • btrfs: avoid starting new transaction when flushing delayed items and refs (bsc#1220120).
    • btrfs: check for BTRFS_FS_ERROR in pending ordered assert (git-fixes)
    • btrfs: compare the correct fsid/metadata_uuid in btrfs_validate_super (git-fixes)
    • btrfs: defrag: avoid unnecessary defrag caused by incorrect extent size (git-fixes)
    • btrfs: defrag: reject unknown flags of btrfs_ioctl_defrag_range_args (git-fixes)
    • btrfs: do not allow non subvolume root targets for snapshot (git-fixes)
    • btrfs: do not arbitrarily slow down delalloc if we're committing (git-fixes)
    • btrfs: do not delete unused block group if it may be used soon (bsc#1220120).
    • btrfs: do not refill whole delayed refs block reserve when starting transaction (bsc#1220120).
    • btrfs: do not start transaction when joining with TRANS_JOIN_NOSTART (git-fixes)
    • btrfs: do not steal space from global rsv after a transaction abort (bsc#1220120).
    • btrfs: do not warn if discard range is not aligned to sector (git-fixes)
    • btrfs: ensure fiemap does not race with writes when FIEMAP_FLAG_SYNC is given (bsc#1223285).
    • btrfs: error out when COWing block using a stale transaction (git-fixes)
    • btrfs: error out when reallocating block for defrag using a stale transaction (git-fixes)
    • btrfs: error when COWing block from a root that is being deleted (git-fixes)
    • btrfs: export: handle invalid inode or root reference in btrfs_get_parent() (git-fixes)
    • btrfs: fail priority metadata ticket with real fs error (bsc#1220120).
    • btrfs: file_remove_privs needs an exclusive lock in direct io write (git-fixes)
    • btrfs: fix 64bit compat send ioctl arguments not initializing version member (git-fixes)
    • btrfs: fix deadlock with fiemap and extent locking (bsc#1223285).
    • btrfs: fix information leak in btrfs_ioctl_logical_to_ino() (git-fixes)
    • btrfs: fix kvcalloc() arguments order in btrfs_ioctl_send() (git-fixes)
    • btrfs: fix lockdep splat and potential deadlock after failure running delayed items (git-fixes)
    • btrfs: fix off-by-one chunk length calculation at contains_pending_extent() (git-fixes)
    • btrfs: fix off-by-one when checking chunk map includes logical address (git-fixes)
    • btrfs: fix race between ordered extent completion and fiemap (bsc#1223285).
    • btrfs: fix race when detecting delalloc ranges during fiemap (bsc#1223285).
    • btrfs: fix race when refilling delayed refs block reserve (git-fixes)
    • btrfs: fix start transaction qgroup rsv double free (git-fixes)
    • btrfs: fix stripe length calculation for non-zoned data chunk allocation (bsc#1217489).
    • btrfs: fix wrong block_start calculation for btrfs_drop_extent_map_range() (git-fixes) Dropped hunk in selftests (test_case_7), 92e1229b204d6.
    • btrfs: free qgroup rsv on io failure (git-fixes)
    • btrfs: free the allocated memory if btrfs_alloc_page_array() fails (git-fixes)
    • btrfs: get rid of label and goto at insert_delayed_ref() (bsc#1220120).
    • btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks() (git-fixes)
    • btrfs: handle errors properly in update_inline_extent_backref() (git-fixes)
    • btrfs: initialize key where it's used when running delayed data ref (bsc#1220120).
    • btrfs: log message if extent item not found when running delayed extent op (bsc#1220120).
    • btrfs: make btrfs_cleanup_fs_roots() static (bsc#1220120).
    • btrfs: make btrfs_destroy_delayed_refs() return void (bsc#1220120).
    • btrfs: make btrfs_destroy_marked_extents() return void (bsc#1220120).
    • btrfs: make btrfs_destroy_pinned_extent() return void (bsc#1220120).
    • btrfs: make error messages more clear when getting a chunk map (git-fixes)
    • btrfs: make find_first_extent_bit() return a boolean (bsc#1220120).
    • btrfs: make find_free_dev_extent() static (bsc#1220120).
    • btrfs: make insert_delayed_ref() return a bool instead of an int (bsc#1220120).
    • btrfs: merge find_free_dev_extent() and find_free_dev_extent_start() (bsc#1220120).
    • btrfs: move btrfs_free_excluded_extents() into block-group.c (bsc#1220120).
    • btrfs: open code trivial btrfs_add_excluded_extent() (bsc#1220120).
    • btrfs: output extra debug info if we failed to find an inline backref (git-fixes)
    • btrfs: pass a space_info argument to btrfs_reserve_metadata_bytes() (bsc#1220120).
    • btrfs: prevent transaction block reserve underflow when starting transaction (git-fixes)
    • btrfs: print available space across all block groups when dumping space info (bsc#1220120).
    • btrfs: print available space for a block group when dumping a space info (bsc#1220120).
    • btrfs: print block group super and delalloc bytes when dumping space info (bsc#1220120).
    • btrfs: print target number of bytes when dumping free space (bsc#1220120).
    • btrfs: qgroup: always free reserved space for extent records (bsc#1216196).
    • btrfs: qgroup: convert PREALLOC to PERTRANS after record_root_in_trans (git-fixes)
    • btrfs: record delayed inode root in transaction (git-fixes)
    • btrfs: reject encoded write if inode has nodatasum flag set (git-fixes)
    • btrfs: release path before inode lookup during the ino lookup ioctl (git-fixes)
    • btrfs: remove pointless initialization at btrfs_delayed_refs_rsv_release() (bsc#1220120).
    • btrfs: remove pointless in_tree field from struct btrfs_delayed_ref_node (bsc#1220120).
    • btrfs: remove pointless 'ref_root' variable from run_delayed_data_ref() (bsc#1220120).
    • btrfs: remove redundant BUG_ON() from __btrfs_inc_extent_ref() (bsc#1220120).
    • btrfs: remove refs_to_add argument from __btrfs_inc_extent_ref() (bsc#1220120).
    • btrfs: remove refs_to_drop argument from __btrfs_free_extent() (bsc#1220120).
    • btrfs: remove the refcount warning/check at btrfs_put_delayed_ref() (bsc#1220120).
    • btrfs: remove unnecessary logic when running new delayed references (bsc#1220120).
    • btrfs: remove unnecessary prototype declarations at disk-io.c (bsc#1220120).
    • btrfs: remove unused is_head field from struct btrfs_delayed_ref_node (bsc#1220120).
    • btrfs: rename add_new_free_space() to btrfs_add_new_free_space() (bsc#1220120).
    • btrfs: reorder some members of struct btrfs_delayed_ref_head (bsc#1220120).
    • btrfs: reserve space for delayed refs on a per ref basis (bsc#1220120).
    • btrfs: reset destination buffer when read_extent_buffer() gets invalid range (git-fixes)
    • btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to 1 (git-fixes)
    • btrfs: return -EUCLEAN if extent item is missing when searching inline backref (bsc#1220120).
    • btrfs: return real error when orphan cleanup fails due to a transaction abort (bsc#1220120).
    • btrfs: send: do not issue unnecessary zero writes for trailing hole (bsc#1222459).
    • btrfs: send: ensure send_fd is writable (git-fixes)
    • btrfs: send: handle path ref underflow in header iterate_inode_ref() (git-fixes)
    • btrfs: send: return EOPNOTSUPP on unknown flags (git-fixes)
    • btrfs: set page extent mapped after read_folio in relocate_one_page (git-fixes)
    • btrfs: simplify check for extent item overrun at lookup_inline_extent_backref() (bsc#1220120).
    • btrfs: stop doing excessive space reservation for csum deletion (bsc#1220120).
    • btrfs: store the error that turned the fs into error state (bsc#1220120).
    • btrfs: sysfs: validate scrub_speed_max value (git-fixes)
    • btrfs: tree-checker: fix inline ref size in error messages (git-fixes)
    • btrfs: update comment for btrfs_join_transaction_nostart() (bsc#1220120).
    • btrfs: update documentation for add_new_free_space() (bsc#1220120).
    • btrfs: use a bool to track qgroup record insertion when adding ref head (bsc#1220120).
    • btrfs: use a single switch statement when initializing delayed ref head (bsc#1220120).
    • btrfs: use a single variable for return value at lookup_inline_extent_backref() (bsc#1220120).
    • btrfs: use a single variable for return value at run_delayed_extent_op() (bsc#1220120).
    • btrfs: use bool type for delayed ref head fields that are used as booleans (bsc#1220120).
    • btrfs: use the correct superblock to compare fsid in btrfs_validate_super (git-fixes)
    • btrfs: use u64 for buffer sizes in the tree search ioctls (git-fixes)
    • btrfs: zoned: do not skip block groups with 100% zone unusable (bsc#1220120).
    • bus: mhi: ep: check the correct variable in mhi_ep_register_controller() (git-fixes).
    • ceph: redirty page before returning AOP_WRITEPAGE_ACTIVATE (bsc#1224866).
    • ceph: stop copying to iter at EOF on sync reads (bsc#1222606).
    • certs: Add ECDSA signature verification self-test (bsc#1222777).
    • certs: Move RSA self-test data to separate file (bsc#1222777).
    • cifs: account for primary channel in the interface list (bsc#1225172).
    • cifs: cifs_chan_is_iface_active should be called with chan_lock held (bsc#1225172).
    • cifs: distribute channels across interfaces based on speed (bsc#1225172).++ kernel-source.spec (revision 4)%define git_commit 596cd3fdbd0fb5902e80279485ad8596f4e82397Release: <RELEASE>.g596cd3f
    • cifs: do not pass cifs_sb when trying to add channels (bsc#1225172).
    • cifs: Do not use certain unnecessary folio_*() functions (bsc#1225172).
    • cifs: failure to add channel on iface should bump up weight (git-fixes, bsc#1225172).
    • cifs: fix charset issue in reconnection (bsc#1225172).
    • cifs: fix leak of iface for primary channel (git-fixes, bsc#1225172).
    • cifs: handle cases where a channel is closed (bsc#1225172).
    • cifs: handle cases where multiple sessions share connection (bsc#1225172).
    • cifs: reconnect work should have reference on server struct (bsc#1225172).
    • clk: Do not hold prepare_lock when calling kref_put() (stable-fixes).
    • clk: Get runtime PM before walking tree during disable_unused (git-fixes).
    • clk: Get runtime PM before walking tree for clk_summary (git-fixes).
    • clk: Initialize struct clk_core kref earlier (stable-fixes).
    • clk: mediatek: Do a runtime PM get on controllers during probe (git-fixes).
    • clk: mediatek: mt8365-mm: fix DPI0 parent (git-fixes).
    • clk: mediatek: pllfh: Do not log error for missing fhctl node (git-fixes).
    • clk: qcom: clk-alpha-pll: fix rate setting for Stromer PLLs (git-fixes).
    • clk: qcom: clk-alpha-pll: remove invalid Stromer register offset (git-fixes).
    • clk: qcom: dispcc-sm6350: fix DisplayPort clocks (git-fixes).
    • clk: qcom: dispcc-sm8450: fix DisplayPort clocks (git-fixes).
    • clk: qcom: dispcc-sm8550: fix DisplayPort clocks (git-fixes).
    • clk: qcom: mmcc-msm8998: fix venus clock issue (git-fixes).
    • clk: qcom: reset: Commonize the de/assert functions (stable-fixes).
    • clk: qcom: reset: Ensure write completion on reset de/assertion (git-fixes).
    • clk: Remove prepare_lock hold assertion in __clk_release() (git-fixes).
    • clk: renesas: r8a779a0: Fix CANFD parent clock (git-fixes).
    • clk: renesas: r9a07g043: Add clock and reset entry for PLIC (git-fixes).
    • clk: rs9: fix wrong default value for clock amplitude (git-fixes).
    • clk: samsung: exynosautov9: fix wrong pll clock id value (git-fixes).
    • clk: Show active consumers of clocks in debugfs (stable-fixes).
    • clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change (git-fixes).
    • clocksource/drivers/arm_global_timer: Fix maximum prescaler value (git-fixes).
    • clocksource/drivers/imx: Fix -Wunused-but-set-variable warning (git-fixes).
    • comedi: vmk80xx: fix incomplete endpoint checking (git-fixes).
    • coresight: trbe: Add a representative coresight_platform_data for (bsc#1220587)
    • coresight: trbe: Allocate platform data per device (bsc#1220587)
    • coresight: trbe: Enable ACPI based TRBE devices (bsc#1220587)
    • counter: linux/counter.h: fix Excess kernel-doc description warning (git-fixes).
    • cppc_cpufreq: Fix possible null pointer dereference (git-fixes).
    • cpufreq: brcmstb-avs-cpufreq: ISO C90 forbids mixed declarations (git-fixes).
    • cpufreq: exit() callback is optional (git-fixes).
    • cpumask: Add for_each_cpu_from() (bsc#1225053).
    • crypto: bcm - Fix pointer arithmetic (git-fixes).
    • crypto: ccp - Add support for PCI device 0x156E (bsc#1223338).
    • crypto: ccp - Add support for PCI device 0x17E0 (bsc#1223338).
    • crypto: ccp - drop platform ifdef checks (git-fixes).
    • crypto: ecc - update ecc_gen_privkey for FIPS 186-5 (bsc#1222782).
    • crypto: ecdsa - Fix module auto-load on add-key (git-fixes).
    • crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init (git-fixes).
    • crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak (git-fixes).
    • crypto: qat - fix ring to service map for dcc in 4xxx (git-fixes).
    • crypto: qat - improve error logging to be consistent across features (git-fixes).
    • crypto: qat - relocate and rename get_service_enabled() (stable-fixes).
    • crypto: qat - specify firmware files for 402xx (git-fixes).
    • crypto: rsa - add a check for allocation failure (bsc#1222775).
    • crypto: rsa - allow only odd e and restrict value in FIPS mode (bsc#1222775).
    • crypto: testmgr - remove unused xts4096 and xts512 algorithms from testmgr.c (bsc#1222769).
    • crypto: x86/nh-avx2 - add missing vzeroupper (git-fixes).
    • crypto: x86/sha256-avx2 - add missing vzeroupper (git-fixes).
    • crypto: x86/sha512-avx2 - add missing vzeroupper (git-fixes).
    • cxl/acpi: Fix load failures due to single window creation failure (git-fixes).
    • cxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window (git-fixes).
    • cxl/trace: Properly initialize cxl_poison region name (git-fixes).
    • dax: alloc_dax() return ERR_PTR(-EOPNOTSUPP) for CONFIG_DAX=n (jsc#PED-5853).
    • dax/bus.c: replace driver-core lock usage by a local rwsem (jsc#PED-5853).
    • dax/bus.c: replace several sprintf() with sysfs_emit() (jsc#PED-5853).
    • device-dax: make dax_bus_type const (jsc#PED-5853).
    • dlm: fix user space lkb refcounting (git-fixes).
    • dma-buf: Fix NULL pointer dereference in sanitycheck() (git-fixes).
    • dma-buf/sw-sync: do not enable IRQ from sync_print_obj() (git-fixes).
    • dmaengine: axi-dmac: fix possible race in remove() (git-fixes).
    • dmaengine: idma64: Add check for dma_set_max_seg_size (git-fixes).
    • dmaengine: idxd: Avoid unnecessary destruction of file_ida (git-fixes).
    • dmaengine: idxd: Fix oops during rmmod on single-CPU platforms (git-fixes).
    • dmaengine: owl: fix register access functions (git-fixes).
    • dmaengine: tegra186: Fix residual calculation (git-fixes).
    • dma-mapping: benchmark: fix node id validation (git-fixes).
    • dma-mapping: benchmark: handle NUMA_NO_NODE correctly (git-fixes).
    • dm/amd/pm: Fix problems with reboot/shutdown for some SMU 13.0.4/13.0.11 users (git-fixes).
    • dma: xilinx_dpdma: Fix locking (git-fixes).
    • dm crypt: remove redundant state settings after waking up (jsc#PED-7542).
    • dm-integrity: set max_integrity_segments in dm_integrity_io_hints (jsc#PED-7542).
    • dm-multipath: dont't attempt SG_IO on non-SCSI-disks (bsc#1223575).
    • dm-raid: add a new helper prepare_suspend() in md_personality (jsc#PED-7542).
    • dm-raid: really frozen sync_thread during suspend (jsc#PED-7542).
    • dm thin: add braces around conditional code that spans lines (jsc#PED-7542).
    • dm: update relevant MODULE_AUTHOR entries to latest dm-devel mailing list (jsc#PED-7542).
    • dm verity: set DM_TARGET_SINGLETON feature flag (jsc#PED-7542).
    • Docs/admin-guide/mm/damon/usage: fix wrong example of DAMOS filter matching sysfs file (git-fixes).
    • docs: kernel_include.py: Cope with docutils 0.21 (stable-fixes).
    • docs: netdev: Fix typo in Signed-off-by tag (git-fixes).
    • docs: Restore 'smart quotes' for quotes (stable-fixes).
    • driver core: Introduce device_link_wait_removal() (stable-fixes).
    • drivers/nvme: Add quirks for device 126f:2262 (git-fixes).
    • drm: add drm_gem_object_is_shared_for_memory_stats() helper (stable-fixes).
    • drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init() (stable-fixes).
    • drm/amd/display: Add dml2 copy functions (stable-fixes).
    • drm/amd/display: Allow dirty rects to be sent to dmub when abm is active (stable-fixes).
    • drm/amd/display: Atom Integrated System Info v2_2 for DCN35 (stable-fixes).
    • drm/amd/display: Change default size for dummy plane in DML2 (stable-fixes).
    • drm/amd/display: Do not recursively call manual trigger programming (stable-fixes).
    • drm/amd/display: Enable colorspace property for MST connectors (git-fixes).
    • drm/amd/display: Fix bounds check for dcn35 DcfClocks (git-fixes).
    • drm/amd/display: fix disable otg wa logic in DCN316 (stable-fixes).
    • drm/amd/display: Fix division by zero in setup_dsc_config (stable-fixes).
    • drm/amd/display: Fix idle check for shared firmware state (stable-fixes).
    • drm/amd/display: Fix incorrect DSC instance for MST (stable-fixes).
    • drm/amd/display: fix input states translation error for dcn35 & dcn351 (stable-fixes).
    • drm/amd/display: Fix nanosec stat overflow (stable-fixes).
    • drm/amd/display: Fix noise issue on HDMI AV mute (stable-fixes).
    • drm/amd/display: Fix potential index out of bounds in color transformation function (git-fixes).
    • drm/amd/display: handle range offsets in VRR ranges (stable-fixes).
    • drm/amd/display: Handle Y carry-over in VCP X.Y calculation (stable-fixes).
    • drm/amd/display: Init DPPCLK from SMU on dcn32 (stable-fixes).
    • drm/amd/display: Override min required DCFCLK in dml1_validate (stable-fixes).
    • drm/amd/display: Prevent crash when disable stream (stable-fixes).
    • drm/amd/display: Program VSC SDP colorimetry for all DP sinks >= 1.4 (stable-fixes).
    • drm/amd/display: Remove MPC rate control logic from DCN30 and above (stable-fixes).
    • drm/amd/display: Remove redundant condition in dcn35_calc_blocks_to_gate() (git-fixes).
    • drm/amd/display: Return the correct HDCP error code (stable-fixes).
    • drm/amd/display: Set DCN351 BB and IP the same as DCN35 (stable-fixes).
    • drm/amd/display: Set VSC SDP Colorimetry same way for MST and SST (stable-fixes).
    • drm/amd/display: Use freesync when `DRM_EDID_FEATURE_CONTINUOUS_FREQ` found (stable-fixes).
    • drm/amd: Flush GFXOFF requests in prepare stage (git-fixes).
    • drm/amdgpu: always force full reset for SOC21 (stable-fixes).
    • drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag (stable-fixes).
    • drm/amdgpu: Assign correct bits for SDMA HDP flush (stable-fixes).
    • drm/amdgpu/display: Address kdoc for 'is_psr_su' in 'fill_dc_dirty_rects' (git-fixes).
    • drm/amdgpu: drop setting buffer funcs in sdma442 (git-fixes).
    • drm/amdgpu: Fix comparison in amdgpu_res_cpu_visible (git-fixes).
    • drm/amdgpu: fix deadlock while reading mqd from debugfs (git-fixes).
    • drm/amdgpu: fix doorbell regression (git-fixes).
    • drm/amdgpu: fix incorrect number of active RBs for gfx11 (stable-fixes).
    • drm/amdgpu: Fix leak when GPU memory allocation fails (stable-fixes).
    • drm/amdgpu: fix mmhub client id out-of-bounds access (git-fixes).
    • drm/amdgpu: fix use-after-free bug (stable-fixes).
    • drm/amdgpu: Fix VCN allocation in CPX partition (stable-fixes).
    • drm/amdgpu: fix visible VRAM handling during faults (git-fixes).
    • drm/amdgpu: implement IRQ_STATE_ENABLE for SDMA v4.4.2 (stable-fixes).
    • drm/amdgpu: make damage clips support configurable (stable-fixes).
    • drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 (git-fixes).
    • drm/amdgpu/pm: Check the validity of overdiver power limit (git-fixes).
    • drm/amdgpu/pm: Fix NULL pointer dereference when get power limit (git-fixes).
    • drm/amdgpu/pm: Fix the error of pwm1_enable setting (stable-fixes).
    • drm/amdgpu: Refine IB schedule error logging (stable-fixes).
    • drm/amdgpu: remove invalid resource->start check v2 (git-fixes).
    • drm/amdgpu: Reset dGPU if suspend got aborted (stable-fixes).
    • drm/amdgpu/sdma5.2: use legacy HDP flush for SDMA2/3 (stable-fixes).
    • drm/amdgpu: validate the parameters of bo mapping operations more clearly (git-fixes).
    • drm/amdkfd: Check cgroup when returning DMABuf info (stable-fixes).
    • drm/amdkfd: do not allow mapping the MMIO HDP page with large pages (git-fixes).
    • drm/amdkfd: Fix memory leak in create_process failure (git-fixes).
    • drm/amdkfd: fix TLB flush after unmap for GFX9.4.2 (stable-fixes).
    • drm/amdkfd: range check cp bad op exception interrupts (stable-fixes).
    • drm/amdkfd: Reset GPU on queue preemption failure (stable-fixes).
    • drm/amd/pm: fixes a random hang in S4 for SMU v13.0.4/11 (stable-fixes).
    • drm/amd/swsmu: modify the gfx activity scaling (stable-fixes).
    • drm/arm/malidp: fix a possible null pointer dereference (git-fixes).
    • drm/ast: Fix soft lockup (git-fixes).
    • drm/bridge: anx7625: Do not log an error when DSI host can't be found (git-fixes).
    • drm: bridge: cdns-mhdp8546: Fix possible null pointer dereference (git-fixes).
    • drm/bridge: dpc3433: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: Fix improper bridge init order with pre_enable_prev_first (git-fixes).
    • drm/bridge: icn6211: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: lt8912b: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: lt9611: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: lt9611uxc: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: tc358775: Do not log an error when DSI host can't be found (git-fixes).
    • drm/bridge: tc358775: fix support for jeida-18 and jeida-24 (git-fixes).
    • drm/buddy: check range allocation matches alignment (stable-fixes).
    • drm: Check output polling initialized before disabling (stable-fixes).
    • drm: Check polling initialized before enabling in drm_helper_probe_single_connector_modes (stable-fixes).
    • drm/client: Fully protect modes[] with dev->mode_config.mutex (stable-fixes).
    • drm/connector: Add \n to message about demoting connector force-probes (git-fixes).
    • drm/display: fix typo (git-fixes).
    • drm/exynos: do not return negative values from .get_modes() (stable-fixes).
    • drm/fbdev-generic: Do not set physical framebuffer address (git-fixes).
    • drm: Fix drm_fixp2int_round() making it add 0.5 (git-fixes).
    • drm/gma500: Remove lid code (git-fixes).
    • drm/i915/audio: Fix audio time stamp programming for DP (stable-fixes).
    • drm/i915/bios: Fix parsing backlight BDB data (git-fixes).
    • drm/i915/bios: Tolerate devdata==NULL in intel_bios_encoder_supports_dp_dual_mode() (stable-fixes).
    • drm/i915/cdclk: Fix CDCLK programming order when pipes are active (git-fixes).
    • drm/i915: Disable live M/N updates when using bigjoiner (stable-fixes).
    • drm/i915: Disable port sync when bigjoiner is used (stable-fixes).
    • drm/i915/display: Use i915_gem_object_get_dma_address to get dma address (stable-fixes).
    • drm/i915: Do not match JSL in ehl_combo_pll_div_frac_wa_needed() (git-fixes).
    • drm/i915/dp: Fix the computation for compressed_bpp for DISPLAY < 13 (git-fixes).
    • drm/i915/dp: Remove support for UHBR13.5 (git-fixes).
    • drm/i915/dpt: Make DPT object unshrinkable (git-fixes).
    • drm/i915/dsb: Fix DSB vblank waits when using VRR (git-fixes).
    • drm/i915/dsi: Go back to the previous INIT_OTP/DISPLAY_ON order, mostly (git-fixes).
    • drm/i915: Fix audio component initialization (git-fixes).
    • drm/i915/gt: Automate CCS Mode setting during engine resets (git-fixes).
    • drm/i915/gt: Disable HW load balancing for CCS (git-fixes).
    • drm/i915/gt: Disarm breadcrumbs if engines are already idle (git-fixes).
    • drm/i915/gt: Do not generate the command streamer for all the CCS (git-fixes).
    • drm/i915/gt: Enable only one CCS for compute workload (git-fixes).
    • drm/i915/gt: Fix CCS id's calculation for CCS mode setting (git-fixes).
    • drm/i915/gt: Reset queue_priority_hint on parking (git-fixes).
    • drm/i915/guc: avoid FIELD_PREP warning (git-fixes).
    • drm/i915/hwmon: Fix locking inversion in sysfs getter (git-fixes).
    • drm/i915: Include the PLL name in the debug messages (stable-fixes).
    • drm/i915/lspcon: Separate function to set expected mode (bsc#1193599).
    • drm/i915/lspcon: Separate lspcon probe and lspcon init (bsc#1193599).
    • drm/i915/mst: Limit MST+DSC to TGL+ (git-fixes).
    • drm/i915/mst: Reject FEC+MST on ICL (git-fixes).
    • drm/i915: Pre-populate the cursor physical dma address (git-fixes).
    • drm/i915: Replace a memset() with zero initialization (stable-fixes).
    • drm/i915: Stop printing pipe name as hex (stable-fixes).
    • drm/i915: Suppress old PLL pipe_mask checks for MG/TC/TBT PLLs (stable-fixes).
    • drm/i915: Try to preserve the current shared_dpll for fastset on type-c ports (stable-fixes).
    • drm/i915: Use named initializers for DPLL info (stable-fixes).
    • drm/i915/vrr: Disable VRR when using bigjoiner (stable-fixes).
    • drm/i915/vrr: Generate VRR 'safe window' for DSB (git-fixes).
    • drm/imx/ipuv3: do not return negative values from .get_modes() (stable-fixes).
    • drm/lcdif: Do not disable clocks on already suspended hardware (git-fixes).
    • drm/mediatek: Add 0 size check to mtk_drm_gem_obj (git-fixes).
    • drm/mediatek: dp: Fix mtk_dp_aux_transfer return value (git-fixes).
    • drm/mediatek: Init `ddp_comp` with devm_kcalloc() (git-fixes).
    • drm/meson: dw-hdmi: add bandgap setting for g12 (git-fixes).
    • drm/meson: dw-hdmi: power up phy on device init (git-fixes).
    • drm/meson: gate px_clk when setting rate (git-fixes).
    • drm/meson: vclk: fix calculation of 59.94 fractional rates (git-fixes).
    • drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails (git-fixes).
    • drm/msm: Add newlines to some debug prints (git-fixes).
    • drm/msm/adreno: fix CP cycles stat retrieval on a7xx (git-fixes).
    • drm/msm/dp: allow voltage swing / pre emphasis of 3 (git-fixes).
    • drm/msm/dp: Avoid a long timeout for AUX transfer if nothing connected (git-fixes).
    • drm/msm/dp: fix typo in dp_display_handle_port_status_changed() (git-fixes).
    • drm/msm/dpu: Add callback function pointer check before its call (git-fixes).
    • drm/msm/dpu: Allow configuring multiple active DSC blocks (git-fixes).
    • drm/msm/dpu: Always flush the slave INTF on the CTL (git-fixes).
    • drm/msm/dpu: do not allow overriding data from catalog (git-fixes).
    • drm/msm/dpu: make error messages at dpu_core_irq_register_callback() more sensible (git-fixes).
    • drm/msm/dpu: use devres-managed allocation for MDP TOP (stable-fixes).
    • drm/msm/dsi: Print dual-DSI-adjusted pclk instead of original mode pclk (git-fixes).
    • drm/nouveau/disp: Fix missing backlight control on Macbook 5, 1 (bsc#1223838).
    • drm/nouveau/dp: Do not probe eDP ports twice harder (stable-fixes).
    • drm/nouveau/dp: Fix incorrect return code in r535_dp_aux_xfer() (git-fixes).
    • drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor() (stable-fixes).
    • drm/nouveau: use tile_mode and pte_kind for VM_BIND bo allocations (git-fixes).
    • drm: nv04: Fix out of bounds access (git-fixes).
    • drm/omapdrm: Fix console by implementing fb_dirty (git-fixes).
    • drm/panel: do not return negative error codes from drm_panel_get_modes() (stable-fixes).
    • drm/panel: ili9341: Respect deferred probe (git-fixes).
    • drm/panel: ili9341: Use predefined error codes (git-fixes).
    • drm/panel: ltk050h3146w: add MIPI_DSI_MODE_VIDEO to LTK050H3148W flags (git-fixes).
    • drm/panel: ltk050h3146w: drop duplicate commands from LTK050H3148W init (git-fixes).
    • drm/panel: novatek-nt35950: Do not log an error when DSI host can't be found (git-fixes).
    • drm: panel-orientation-quirks: Add quirk for GPD Win Mini (stable-fixes).
    • drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector (git-fixes).
    • drm/panel: sitronix-st7789v: fix display size for jt240mhqs_hwt_ek_e3 panel (git-fixes).
    • drm/panel: sitronix-st7789v: fix timing for jt240mhqs_hwt_ek_e3 panel (git-fixes).
    • drm/panel: sitronix-st7789v: tweak timing for jt240mhqs_hwt_ek_e3 panel (git-fixes).
    • drm/panel: visionox-rm69299: do not unregister DSI device (git-fixes).
    • drm/panfrost: fix power transition timeout warnings (git-fixes).
    • drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr() (git-fixes).
    • drm/prime: Unbreak virtgpu dma-buf export (git-fixes).
    • drm/probe-helper: warn about negative .get_modes() (stable-fixes).
    • drm/qxl: remove unused `count` variable from `qxl_surface_id_alloc()` (git-fixes).
    • drm/qxl: remove unused variable from `qxl_process_single_command()` (git-fixes).
    • drm/radeon: make -fstrict-flex-arrays=3 happy (git-fixes).
    • drm/radeon: silence UBSAN warning (v3) (stable-fixes).
    • drm/rockchip: vop2: Do not divide height twice for YUV (git-fixes).
    • drm/rockchip: vop2: Remove AR30 and AB30 format support (git-fixes).
    • drm/sched: fix null-ptr-deref in init entity (git-fixes).
    • drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE) (git-fixes).
    • drm/ttm: return ENOSPC from ttm_bo_mem_space v3 (stable-fixes).
    • drm/ttm: stop pooling cached NUMA pages v2 (git-fixes).
    • drm/vc4: do not check if plane->state->fb == state->fb (stable-fixes).
    • drm: vc4: Fix possible null pointer dereference (git-fixes).
    • drm/vc4: hdmi: do not return negative values from .get_modes() (stable-fixes).
    • drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed (git-fixes).
    • drm/vmwgfx: Enable DMA mappings with SEV (git-fixes).
    • drm/vmwgfx: Fix crtc's atomic check conditional (git-fixes).
    • drm/vmwgfx: Fix invalid reads in fence signaled events (git-fixes).
    • drm/vmwgfx: Fix Legacy Display Unit (git-fixes).
    • drm/vmwgfx: Fix prime import/export (git-fixes).
    • drm/vmwgfx: Sort primary plane formats by order of preference (git-fixes).
    • drm: zynqmp_dpsub: Always register bridge (git-fixes).
    • dt-bindings: clock: qcom: Add missing UFS QREF clocks (git-fixes)
    • dump_stack: Do not get cpu_sync for panic CPU (bsc#1225607).
    • dyndbg: fix old BUG_ON in >control parser (stable-fixes).
    • e1000e: Minor flow correction in e1000_shutdown function (git-fixes).
    • e1000e: move force SMBUS from enable ulp function to avoid PHY loss issue (git-fixes).
    • e1000e: Workaround for sporadic MDI error on Meteor Lake systems (git-fixes).
    • ecryptfs: Fix buffer size for tag 66 packet (git-fixes)
    • ecryptfs: Reject casefold directory inodes (git-fixes)
    • EDAC/synopsys: Fix ECC status and IRQ control race condition (git-fixes).
    • Edit 'amdkfd: use calloc instead of kzalloc to avoid integer overflow' Reference CVE and bug numbers.
    • efi: disable mirror feature during crashkernel (stable-fixes).
    • efi: fix panic in kdump kernel (git-fixes).
    • efi: libstub: only free priv.runtime_map when allocated (git-fixes).
    • efi/unaccepted: do not let /proc/vmcore try to access unaccepted memory (git-fixes).
    • efi/unaccepted: touch soft lockup during memory accept (git-fixes).
    • Enable CONFIG_FIPS_SIGNATURE_SELFTEST (bsc#1222771)
    • Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA.
    • Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_RSA.
    • extcon: max8997: select IRQ_DOMAIN instead of depending on it (git-fixes).
    • fast_dput(): handle underflows gracefully (git-fixes)
    • fat: fix uninitialized field in nostale filehandles (git-fixes)
    • fbdev: fix incorrect address computation in deferred IO (git-fixes).
    • fbdev: savage: Handle err return when savagefb_check_var failed (git-fixes).
    • fbdev: sh7760fb: allow modular build (git-fixes).
    • fbdev: shmobile: fix snprintf truncation (git-fixes).
    • fbdev: sisfb: hide unused variables (git-fixes).
    • fbdev: viafb: fix typo in hw_bitblt_1 and hw_bitblt_2 (stable-fixes).
    • fbmon: prevent division by zero in fb_videomode_from_videomode() (stable-fixes).
    • firewire: core: use long bus reset on gap count error (stable-fixes).
    • firewire: ohci: mask bus reset interrupts between ISR and bottom half (stable-fixes).
    • firmware: arm_scmi: Make raw debugfs entries non-seekable (git-fixes).
    • firmware: dmi-id: add a release callback function (git-fixes).
    • firmware: raspberrypi: Use correct device for DMA mappings (git-fixes).
    • firmware: tegra: bpmp: Return directly after a failed kzalloc() in get_filename() (stable-fixes).
    • Fix a potential infinite loop in extract_user_to_sg() (git-fixes).
    • Fix build errors due to new UIO_MEM_DMA_COHERENT mess (git-fixes).
    • fs/9p: only translate RWX permissions for plain 9P2000 (git-fixes)
    • fs/9p: translate O_TRUNC into OTRUNC (git-fixes)
    • fs: Fix error checking for d_hash_and_lookup() (git-fixes)
    • fs: indicate request originates from old mount API (git-fixes)
    • fs: relax mount_setattr() permission checks (git-fixes)
    • fsverity: skip PKCS#7 parser when keyring is empty (git-fixes)
    • ftrace: Fix possible use-after-free issue in ftrace_location() (git-fixes).
    • fuse: do not unhash root (bsc#1223946).
    • fuse: fix root lookup with nonzero generation (bsc#1223945).
    • geneve: fix header validation in geneve[6]_xmit_skb (git-fixes).
    • geneve: make sure to pull inner header in geneve_rx() (git-fixes).
    • gpio: cdev: check for NULL labels when sanitizing them for irqs (git-fixes).
    • gpio: cdev: fix missed label sanitizing in debounce_setup() (git-fixes).
    • gpio: cdev: sanitize the label before requesting the interrupt (stable-fixes).
    • gpio: crystalcove: Use -ENOTSUPP consistently (stable-fixes).
    • gpiolib: cdev: fix uninitialised kfifo (git-fixes).
    • gpiolib: cdev: relocate debounce_period_us from struct gpio_desc (stable-fixes).
    • gpiolib: swnode: Remove wrong header inclusion (git-fixes).
    • gpio: tangier: Use correct type for the IRQ chip data (git-fixes).
    • gpio: tegra186: Fix tegra186_gpio_is_accessible() check (git-fixes).
    • gpio: wcove: Use -ENOTSUPP consistently (stable-fixes).
    • gpu: host1x: Do not setup DMA for virtual devices (stable-fixes).
    • gtp: fix use-after-free and null-ptr-deref in gtp_newlink() (git-fixes).
    • HID: amd_sfh: Handle 'no sensors' in PM operations (git-fixes).
    • HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up (git-fixes).
    • HID: input: avoid polling stylus battery on Chromebook Pompom (stable-fixes).
    • HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors (git-fixes).
    • HID: intel-ish-hid: ipc: Fix dev_err usage with uninitialized dev->devc (git-fixes).
    • HID: logitech-dj: allow mice to use all types of reports (git-fixes).
    • HID: multitouch: Add required quirk for Synaptics 0xcddc device (stable-fixes).
    • hwmon: (amc6821) add of_match table (stable-fixes).
    • hwmon: (corsair-cpro) Protect ccp->wait_input_report with a spinlock (git-fixes).
    • hwmon: (corsair-cpro) Use a separate buffer for sending commands (git-fixes).
    • hwmon: (corsair-cpro) Use complete_all() instead of complete() in ccp_raw_event() (git-fixes).
    • hwmon: (intel-m10-bmc-hwmon) Fix multiplier for N6000 board power sensor (git-fixes).
    • hwmon: (lm70) fix links in doc and comments (git-fixes).
    • hwmon: (pmbus/ucd9000) Increase delay from 250 to 500us (git-fixes).
    • hwmon: (shtc1) Fix property misspelling (git-fixes).
    • hwtracing: hisi_ptt: Move type check to the beginning of hisi_ptt_pmu_event_init() (git-fixes).
    • i2c: acpi: Unbind mux adapters before delete (git-fixes).
    • i2c: cadence: Avoid fifo clear after start (git-fixes).
    • i2c: pxa: hide unused icr_bits[] variable (git-fixes).
    • i2c: smbus: fix NULL function pointer dereference (git-fixes).
    • i2c: synquacer: Fix an error handling path in synquacer_i2c_probe() (git-fixes).
    • i3c: master: svc: change ENXIO to EAGAIN when IBI occurs during start frame (git-fixes).
    • i3c: master: svc: fix invalidate IBI type and miss call client IBI handler (git-fixes).
    • i40e: disable NAPI right after disabling irqs when handling xsk_pool (git-fixes).
    • i40e: Enforce software interrupt during busy-poll exit (git-fixes).
    • i40e: Fix firmware version comparison function (git-fixes).
    • i40e: fix i40e_count_filters() to count only active/new filters (git-fixes).
    • i40e: Fix VF MAC filter removal (git-fixes).
    • i40e: fix vf may be used uninitialized in this function warning (git-fixes).
    • i915: make inject_virtual_interrupt() void (stable-fixes).
    • IB/mlx5: Use __iowrite64_copy() for write combining stores (git-fixes)
    • ice: fix enabling RX VLAN filtering (git-fixes).
    • ice: fix memory corruption bug with suspend and rebuild (git-fixes).
    • ice: fix stats being updated by way too large values (git-fixes).
    • ice: fix typo in assignment (git-fixes).
    • ice: fix uninitialized dplls mutex usage (git-fixes).
    • ice: reconfig host after changing MSI-X on VF (git-fixes).
    • ice: Refactor FW data type and fix bitmap casting issue (git-fixes).
    • ice: reorder disabling IRQ and NAPI in ice_qp_dis (git-fixes).
    • ice: use relative VSI index for VFs instead of PF VSI number (git-fixes).
    • ice: virtchnl: stop pretending to support RSS over AQ or registers (git-fixes).
    • ida: make 'ida_dump' static (git-fixes).
    • idma64: Do not try to serve interrupts when device is powered off (git-fixes).
    • idpf: disable local BH when scheduling napi for marker packets (git-fixes).
    • idpf: extend tx watchdog timeout (bsc#1224137).
    • idpf: fix kernel panic on unknown packet types (git-fixes).
    • igb: extend PTP timestamp adjustments to i211 (git-fixes).
    • igb: Fix missing time sync events (git-fixes).
    • igc: avoid returning frame twice in XDP_REDIRECT (git-fixes).
    • igc: Fix missing time sync events (git-fixes).
    • igc: Remove stale comment about Tx timestamping (git-fixes).
    • iio: accel: mxc4005: Interrupt handling fixes (git-fixes).
    • iio: adc: stm32: Fixing err code to not indicate success (git-fixes).
    • iio: core: Leave private pointer NULL when no private data supplied (git-fixes).
    • iio: dummy_evgen: remove Excess kernel-doc comments (git-fixes).
    • iio: gts-helper: Fix division loop (git-fixes).
    • iio:imu: adis16475: Fix sync mode setting (git-fixes).
    • iio: pressure: dps310: support negative temperature values (git-fixes).
    • iio: pressure: Fixes BME280 SPI driver data (git-fixes).
    • inet_diag: annotate data-races around inet_diag_table[] (git-fixes).
    • inet: frags: eliminate kernel-doc warning (git-fixes).
    • init/main.c: Fix potential static_command_line memory overflow (git-fixes).
    • init: open /initrd.image with O_LARGEFILE (stable-fixes).
    • Input: allocate keycode for Display refresh rate toggle (stable-fixes).
    • Input: cyapa - add missing input core locking to suspend/resume functions (git-fixes).
    • Input: gpio_keys_polled - suppress deferred probe error for gpio (stable-fixes).
    • Input: imagis - use FIELD_GET where applicable (stable-fixes).
    • Input: ims-pcu - fix printf string overflow (git-fixes).
    • Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation (git-fixes).
    • Input: synaptics-rmi4 - fail probing if memory allocation for 'phys' fails (stable-fixes).
    • input/touchscreen: imagis: Correct the maximum touch area value (stable-fixes).
    • Input: xpad - add additional HyperX Controller Identifiers (stable-fixes).
    • Input: xpad - add support for Snakebyte GAMEPADs (stable-fixes).
    • intel: legacy: Partial revert of field get conversion (git-fixes).
    • interconnect: qcom: osm-l3: Replace custom implementation of COUNT_ARGS() (git-fixes).
    • interconnect: qcom: qcm2290: Fix mas_snoc_bimc QoS port assignment (git-fixes).
    • interconnect: qcom: sc8180x: Mark CO0 BCM keepalive (git-fixes).
    • interconnect: qcom: sm8550: Enable sync_state (git-fixes).
    • iomap: clear the per-folio dirty bits on all writeback failures (git-fixes)
    • iommu/arm-smmu-v3: Check that the RID domain is S1 in SVA (git-fixes).
    • iommu/dma: Force swiotlb_max_mapping_size on an untrusted device (bsc#1224331)
    • iommu/dma: Trace bounce buffer usage when mapping buffers (git-fixes).
    • iommufd: Add missing IOMMUFD_DRIVER kconfig for the selftest (git-fixes).
    • iommufd: Fix iopt_access_list_id overwrite bug (git-fixes).
    • iommufd/iova_bitmap: Bounds check mapped::pages access (git-fixes).
    • iommufd/iova_bitmap: Consider page offset for the pages to be pinned (git-fixes).
    • iommufd/iova_bitmap: Switch iova_bitmap::bitmap to an u8 array (git-fixes).
    • iommufd: Reject non-zero data_type if no data_len is provided (git-fixes).
    • iommu: Map reserved memory as cacheable if device is coherent (git-fixes).
    • iommu/vt-d: Allocate local memory for page request queue (git-fixes).
    • iommu/vt-d: Fix wrong use of pasid config (git-fixes).
    • iommu/vt-d: Set SSADE when attaching to a parent with dirty tracking (git-fixes).
    • iommu/vt-d: Update iotlb in nested domain attach (git-fixes).
    • ionic: set adminq irq affinity (git-fixes).
    • io_uring: kabi cookie remove (bsc#1217384).
    • ipv4: annotate data-races around fi->fib_dead (git-fixes).
    • irqchip/alpine-msi: Fix off-by-one in allocation error path (git-fixes).
    • irqchip/armada-370-xp: Suppress unused-function warning (git-fixes).
    • irqchip/gic-v3-its: Do not assume vPE tables are preallocated (git-fixes).
    • irqchip/gic-v3-its: Fix VSYNC referencing an unmapped VPE on GIC v4.1 (git-fixes).
    • irqchip/gic-v3-its: Prevent double free on error (git-fixes).
    • irqchip/loongson-pch-msi: Fix off-by-one on allocation error path (git-fixes).
    • irqchip/mbigen: Do not use bus_get_dev_root() to find the parent (git-fixes).
    • irqchip/renesas-rzg2l: Add macro to retrieve TITSR register offset based on register's index (stable-fixes).
    • irqchip/renesas-rzg2l: Flush posted write in irq_eoi() (git-fixes).
    • irqchip/renesas-rzg2l: Implement restriction when writing ISCR register (stable-fixes).
    • irqchip/renesas-rzg2l: Prevent spurious interrupts when setting trigger type (git-fixes).
    • irqchip/renesas-rzg2l: Rename rzg2l_irq_eoi() (stable-fixes).
    • irqchip/renesas-rzg2l: Rename rzg2l_tint_eoi() (stable-fixes).
    • ixgbe: avoid sleeping allocation in ixgbe_ipsec_vf_add_sa() (git-fixes).
    • ixgbe: {dis, en}able irqs in ixgbe_txrx_ring_{dis, en}able (git-fixes).
    • jffs2: prevent xattr node from overflowing the eraseblock (git-fixes).
    • kABI: Adjust trace_iterator.wait_index (git-fixes).
    • kABI fix of KVM: x86/pmu: Allow programming events that match unsupported arch events (bsc#1225696).
    • kABI fix of KVM: x86: Snapshot if a vCPU's vendor model is AMD vs. Intel compatible (git-fixes).
    • kabi fix of perf/x86/intel: Expose existence of callback support to KVM (git fixes).
    • kabi/severities: ignore brcmfmac-specific local symbols
    • kabi/severities: ignore IMS functions They were dropped in previous patches. Noone is supposed to use them.
    • kabi/severities: ignore TAS2781 symbol drop, it's only locally used
    • kabi/severities: ignore Wangxun ethernet driver local symbols
    • kabi/severities: Remove mitigation-related symbols Those are used by the core kernel to implement CPU vulnerabilities mitigation and are not expected to be consumed by 3rd party users.
    • kABI workaround for cs35l56 (git-fixes).
    • kABI workaround for of driver changes (git-fixes).
    • kasan: disable kasan_non_canonical_hook() for HW tags (git-fixes).
    • kasan, fortify: properly rename memintrinsics (git-fixes).
    • kasan: print the original fault addr when access invalid shadow (git-fixes).
    • kasan/test: avoid gcc warning for intentional overflow (git-fixes).
    • kbuild: Move -Wenum-{compare-conditional,enum-conversion} into W=1 (stable-fixes).
    • kconfig: fix infinite loop when expanding a macro at the end of file (git-fixes).
    • kexec: do syscore_shutdown() in kernel_kexec (git-fixes).
    • KEYS: trusted: Do not use WARN when encode fails (git-fixes).
    • KEYS: trusted: Fix memory leak in tpm2_key_encode() (git-fixes).
    • kprobes: Fix possible use-after-free issue on kprobe registration (git-fixes).
    • kselftest: Add a ksft_perror() helper (stable-fixes).
    • kunit/fortify: Fix mismatched kvalloc()/vfree() usage (git-fixes).
    • KVM: nVMX: Clear EXIT_QUALIFICATION when injecting an EPT Misconfig (git-fixes).
    • KVM: s390: Check kvm pointer when testing KVM_CAP_S390_HPAGE_1M (git-fixes bsc#1224790).
    • KVM: SVM: Add support for allowing zero SEV ASIDs (git-fixes).
    • KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() (git-fixes).
    • KVM: SVM: Use unsigned integers when dealing with ASIDs (git-fixes).
    • KVM: VMX: Disable LBR virtualization if the CPU does not support LBR callstacks (git-fixes).
    • KVM: VMX: Report up-to-date exit qualification to userspace (git-fixes).
    • KVM: x86: Allow, do not ignore, same-value writes to immutable MSRs (git-fixes).
    • KVM: x86: Fix broken debugregs ABI for 32 bit kernels (git-fixes).
    • KVM: x86: Fully re-initialize supported_mce_cap on vendor module load (git-fixes).
    • KVM: x86: Introduce __kvm_get_hypervisor_cpuid() helper (git-fixes).
    • KVM: x86: Mark target gfn of emulated atomic instruction as dirty (git-fixes).
    • KVM: x86/mmu: Do not force emulation of L2 accesses to non-APIC internal slots (git-fixes).
    • KVM: x86/mmu: Move private vs. shared check above slot validity checks (git-fixes).
    • KVM: x86/mmu: Restrict KVM_SW_PROTECTED_VM to the TDP MMU (git-fixes).
    • KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing dirty status (git-fixes).
    • KVM: x86: Only set APICV_INHIBIT_REASON_ABSENT if APICv is enabled (git-fixes).
    • KVM: x86/pmu: Allow programming events that match unsupported arch events (git-fixes).
    • KVM: x86/pmu: Always treat Fixed counters as available when supported (git-fixes).
    • KVM: x86/pmu: Apply 'fast' RDPMC only to Intel PMUs (git-fixes).
    • KVM: x86/pmu: Disable support for adaptive PEBS (git-fixes).
    • KVM: x86/pmu: Disallow 'fast' RDPMC for architectural Intel PMUs (git-fixes).
    • KVM: x86/pmu: Do not ignore bits 31:30 for RDPMC index on AMD (git-fixes).
    • KVM: x86/pmu: Do not mask LVTPC when handling a PMI on AMD platforms (git-fixes).
    • KVM: x86/pmu: Explicitly check NMI from guest to reducee false positives (git-fixes).
    • KVM: x86/pmu: Prioritize VMX interception over #GP on RDPMC due to bad index (git-fixes).
    • KVM: x86/pmu: Set enable bits for GP counters in PERF_GLOBAL_CTRL at 'RESET' (git-fixes).
    • KVM: x86/pmu: Zero out PMU metadata on AMD if PMU is disabled (git-fixes).
    • KVM: x86: Snapshot if a vCPU's vendor model is AMD vs. Intel compatible (git-fixes).
    • KVM: x86: Update KVM_SW_PROTECTED_VM docs to make it clear they're a WIP (git-fixes).
    • KVM: x86: Use actual kvm_cpuid.base for clearing KVM_FEATURE_PV_UNHALT (git-fixes).
    • KVM: x86/xen: fix recursive deadlock in timer injection (git-fixes).
    • KVM: x86/xen: improve accuracy of Xen timers (git-fixes).
    • KVM: x86/xen: inject vCPU upcall vector when local APIC is enabled (git-fixes).
    • KVM: x86/xen: remove WARN_ON_ONCE() with false positives in evtchn delivery (git-fixes).
    • leds: pwm: Disable PWM when going to suspend (git-fixes).
    • libnvdimm: Fix ACPI_NFIT in BLK_DEV_PMEM help (jsc#PED-5853).
    • libperf evlist: Avoid out-of-bounds access (git-fixes).
    • libsubcmd: Fix parse-options memory leak (git-fixes).
    • lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure (git-fixes).
    • livepatch: Fix missing newline character in klp_resolve_symbols() (bsc#1223539).
    • locks: fix KASAN: use-after-free in trace_event_raw_event_filelock_lock (git-fixes)
    • lsm: fix the logic in security_inode_getsecctx() (git-fixes).
    • mac802154: fix llsec key resources release in mac802154_llsec_key_del (git-fixes).
    • maple_tree: fix mas_empty_area_rev() null pointer dereference (git-fixes).
    • md: add a new helper rdev_has_badblock() (jsc#PED-7542).
    • md: add a new helper reshape_interrupted() (jsc#PED-7542).
    • md: changed the switch of RAID_VERSION to if (jsc#PED-7542).
    • md: check mddev->pers before calling md_set_readonly() (jsc#PED-7542).
    • md: clean up invalid BUG_ON in md_ioctl (jsc#PED-7542).
    • md: clean up openers check in do_md_stop() and md_set_readonly() (jsc#PED-7542).
    • md/dm-raid: do not call md_reap_sync_thread() directly (jsc#PED-7542).
    • md: Do not clear MD_CLOSING when the raid is about to stop (jsc#PED-7542).
    • md: do not clear MD_RECOVERY_FROZEN for new dm-raid until resume (jsc#PED-7542).
    • md: export helper md_is_rdwr() (jsc#PED-7542).
    • md: export helpers to stop sync_thread (jsc#PED-7542).
    • md: factor out a helper to sync mddev (jsc#PED-7542).
    • md: fix kmemleak of rdev->serial (jsc#PED-7542).
    • md: get rdev->mddev with READ_ONCE() (jsc#PED-7542).
    • md: merge the check of capabilities into md_ioctl_valid() (jsc#PED-7542).
    • md: preserve KABI in struct md_personality (jsc#PED-7542).
    • md/raid1-10: add a helper raid1_check_read_range() (jsc#PED-7542).
    • md/raid1-10: factor out a new helper raid1_should_read_first() (jsc#PED-7542).
    • md/raid1: factor out choose_bb_rdev() from read_balance() (jsc#PED-7542).
    • md/raid1: factor out choose_slow_rdev() from read_balance() (jsc#PED-7542).
    • md/raid1: factor out helpers to add rdev to conf (jsc#PED-7542).
    • md/raid1: factor out helpers to choose the best rdev from read_balance() (jsc#PED-7542).
    • md/raid1: factor out read_first_rdev() from read_balance() (jsc#PED-7542).
    • md/raid1: factor out the code to manage sequential IO (jsc#PED-7542).
    • md/raid1: fix choose next idle in read_balance() (jsc#PED-7542).
    • md/raid1: record nonrot rdevs while adding/removing rdevs to conf (jsc#PED-7542).
    • md: remove redundant check of 'mddev->sync_thread' (jsc#PED-7542).
    • md: remove redundant md_wakeup_thread() (jsc#PED-7542).
    • md: return directly before setting did_set_md_closing (jsc#PED-7542).
    • md: sync blockdev before stopping raid or setting readonly (jsc#PED-7542).
    • md: use RCU lock to protect traversal in md_spares_need_change() (jsc#PED-7542).
    • media: atomisp: ssh_css: Fix a null-pointer dereference in load_video_binaries (git-fixes).
    • media: cadence: csi2rx: use match fwnode for media link (git-fixes).
    • media: cec: core: remove length check of Timer Status (stable-fixes).
    • media: dt-bindings: ovti,ov2680: Fix the power supply names (git-fixes).
    • media: flexcop-usb: fix sanity check of bNumEndpoints (git-fixes).
    • media: i2c: et8ek8: Do not strip remove function when driver is builtin (git-fixes).
    • media: ipu3-cio2: Request IRQ earlier (git-fixes).
    • media: mc: Fix flags handling when creating pad links (stable-fixes).
    • media: mc: Fix graph walk in media_pipeline_start (git-fixes).
    • media: mc: mark the media devnode as registered from the, start (git-fixes).
    • media: mc: Rename pad variable to clarify intent (stable-fixes).
    • media: ngene: Add dvb_ca_en50221_init return value check (git-fixes).
    • media: rcar-vin: work around -Wenum-compare-conditional warning (git-fixes).
    • media: rkisp1: Fix IRQ handling due to shared interrupts (stable-fixes).
    • media: sta2x11: fix irq handler cast (stable-fixes).
    • media: stk1160: fix bounds checking in stk1160_copy_video() (git-fixes).
    • media: sunxi: a83-mips-csi2: also select GENERIC_PHY (git-fixes).
    • media: uvcvideo: Add quirk for Logitech Rally Bar (git-fixes).
    • media: v4l2-subdev: Fix stream handling for crop API (git-fixes).
    • media: v4l: Do not turn on privacy LED if streamon fails (git-fixes).
    • mei: me: add arrow lake point H DID (stable-fixes).
    • mei: me: add arrow lake point S DID (stable-fixes).
    • mei: me: add lunar lake point M DID (stable-fixes).
    • mei: me: disable RPL-S on SPS and IGN firmwares (git-fixes).
    • mlxbf_gige: call request_irq() after NAPI initialized (git-fixes).
    • mlxbf_gige: stop interface during shutdown (git-fixes).
    • mlxbf_gige: stop PHY during open() error paths (git-fixes).
    • mlxsw: Use refcount_t for reference counting (git-fixes).
    • mmc: core: Add HS400 tuning in HS400es initialization (stable-fixes).
    • mmc: core: Avoid negative index with array access (git-fixes).
    • mmc: core: Initialize mmc_blk_ioc_data (git-fixes).
    • mmc: davinci: Do not strip remove function when driver is builtin (git-fixes).
    • mmc: omap: fix broken slot switch lookup (git-fixes).
    • mmc: omap: fix deferred probe (git-fixes).
    • mmc: omap: restore original power up/down steps (git-fixes).
    • mmc: sdhci_am654: Add ITAPDLYSEL in sdhci_j721e_4bit_set_clock (git-fixes).
    • mmc: sdhci_am654: Add OTAP/ITAP delay enable (git-fixes).
    • mmc: sdhci_am654: Add tuning algorithm for delay chain (git-fixes).
    • mmc: sdhci_am654: Fix ITAPDLY for HS400 timing (git-fixes).
    • mmc: sdhci_am654: Write ITAPDLY for DDR52 timing (git-fixes).
    • mmc: sdhci-msm: pervent access to suspended controller (git-fixes).
    • mmc: sdhci-omap: re-tuning is needed after a pm transition to support emmc HS200 mode (git-fixes).
    • mm_init kABI workaround (git-fixes).
    • mm: memcg: do not periodically flush stats when memcg is disabled (bsc#1222525).
    • mm: memcg: use larger batches for proactive reclaim (bsc#1222522).
    • mm,page_owner: check for null stack_record before bumping its refcount (bsc#1222366).
    • mm,page_owner: Defer enablement of static branch (bsc#1222366).
    • mm,page_owner: drop unnecessary check (bsc#1222366).
    • mm,page_owner: Fix accounting of pages when migrating (bsc#1222366).
    • mm,page_owner: Fix printing of stack records (bsc#1222366).
    • mm,page_owner: fix recursion (bsc#1222366).
    • mm,page_owner: Fix refcount imbalance (bsc#1222366).
    • mm: page_owner: fix wrong information in dump_page_owner (git-fixes).
    • mm,page_owner: Update metadata for tail pages (bsc#1222366).
    • mm/slab: make __free(kfree) accept error pointers (git-fixes).
    • modpost: Add '.ltext' and '.ltext.*' to TEXT_SECTIONS (stable-fixes).
    • mptcp: annotate data-races around msk->rmem_fwd_alloc (git-fixes).
    • mptcp: fix bogus receive window shrinkage with multiple subflows (git-fixes).
    • mptcp: move __mptcp_error_report in protocol.c (git-fixes).
    • mptcp: process pending subflow error on close (git-fixes).
    • mptcp: Remove unnecessary test for __mptcp_init_sock() (git-fixes).
    • mtd: core: Report error if first mtd_otp_size() call fails in mtd_otp_nvmem_add() (git-fixes).
    • mtd: diskonchip: work around ubsan link failure (stable-fixes).
    • mtd: rawnand: hynix: fixed typo (git-fixes).
    • mtd: spinand: Add support for 5-byte IDs (stable-fixes).
    • net: add netdev_lockdep_set_classes() to virtual drivers (git-fixes).
    • net: annotate data-races around sk->sk_bind_phc (git-fixes).
    • net: annotate data-races around sk->sk_forward_alloc (git-fixes).
    • net: annotate data-races around sk->sk_lingertime (git-fixes).
    • net: annotate data-races around sk->sk_tsflags (git-fixes).
    • net: bonding: remove kernel-doc comment marker (git-fixes).
    • net: cfg802154: fix kernel-doc notation warnings (git-fixes).
    • net: dsa: microchip: fix register write order in ksz8_ind_write8() (git-fixes).
    • net: dsa: mt7530: fix handling of all link-local frames (git-fixes).
    • net: dsa: mt7530: fix link-local frames that ingress vlan filtering ports (git-fixes).
    • net: dsa: mt7530: prevent possible incorrect XTAL frequency selection (git-fixes).
    • net: dsa: mt7530: trap link-local frames regardless of ST Port State (git-fixes).
    • net: dsa: sja1105: Fix parameters order in sja1110_pcs_mdio_write_c45() (git-fixes).
    • net: ena: Fix incorrect descriptor free behavior (git-fixes).
    • net: ena: Fix potential sign extension issue (git-fixes).
    • net: ena: Move XDP code to its new files (git-fixes).
    • net: ena: Pass ena_adapter instead of net_device to ena_xmit_common() (git-fixes).
    • net: ena: Remove ena_select_queue (git-fixes).
    • net: ena: Set tx_info->xdpf value to NULL (git-fixes).
    • net: ena: Use tx_ring instead of xdp_ring for XDP channel TX (git-fixes).
    • net: ena: Wrong missing IO completions check order (git-fixes).
    • net: ethernet: mtk_eth_soc: fix PPE hanging issue (git-fixes).
    • net: ethernet: ti: cpsw: enable mac_managed_pm to fix mdio (git-fixes).
    • net: fec: Set mac_managed_pm during probe (git-fixes).
    • netfilter: nf_tables: disable toggling dormant table state more than once (git-fixes).
    • netfilter: nf_tables: uapi: Describe NFTA_RULE_CHAIN_ID (git-fixes).
    • netfilter: nft_ct: fix l3num expectations with inet pseudo family (git-fixes).
    • netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention (git-fixes).
    • net: hns3: fix index limit to support all queue stats (git-fixes).
    • net: hns3: fix kernel crash when 1588 is received on HIP08 devices (git-fixes).
    • net: hns3: fix kernel crash when devlink reload during pf initialization (git-fixes).
    • net: hns3: fix port duplex configure error in IMP reset (git-fixes).
    • net: hns3: fix wrong judgment condition issue (git-fixes).
    • net: hns3: mark unexcuted loopback test result as UNEXECUTED (git-fixes).
    • net: hns3: tracing: fix hclgevf trace event strings (git-fixes).
    • net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (git-fixes).
    • net: ks8851: Handle softirqs at the end of IRQ thread to fix hang (git-fixes).
    • net: ks8851: Inline ks8851_rx_skb() (git-fixes).
    • net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs (git-fixes).
    • net: lan743x: Add set RFE read fifo threshold for PCI1x1x chips (git-fixes).
    • net: libwx: fix memory leak on free page (git-fixes).
    • net: llc: fix kernel-doc notation warnings (git-fixes).
    • net: ll_temac: platform_get_resource replaced by wrong function (git-fixes).
    • net: mana: Fix Rx DMA datasize and skb_over_panic (git-fixes).
    • net: mediatek: mtk_eth_soc: clear MAC_MCR_FORCE_LINK only when MAC is up (git-fixes).
    • net/mlx5: Correctly compare pkt reformat ids (git-fixes).
    • net/mlx5e: Change the warning when ignore_flow_level is not supported (git-fixes).
    • net/mlx5e: Do not produce metadata freelist entries in Tx port ts WQE xmit (git-fixes).
    • net/mlx5e: Fix MACsec state loss upon state update in offload path (git-fixes).
    • net/mlx5e: Fix mlx5e_priv_init() cleanup flow (git-fixes).
    • net/mlx5e: HTB, Fix inconsistencies with QoS SQs number (git-fixes).
    • net/mlx5e: RSS, Block changing channels number when RXFH is configured (git-fixes).
    • net/mlx5e: RSS, Block XOR hash with over 128 channels (git-fixes).
    • net/mlx5: E-switch, Change flow rule destination checking (git-fixes).
    • net/mlx5: E-switch, store eswitch pointer before registering devlink_param (git-fixes).
    • net/mlx5e: Switch to using _bh variant of of spinlock API in port timestamping NAPI poll context (git-fixes).
    • net/mlx5e: Use a memory barrier to enforce PTP WQ xmit submission tracking occurs after populating the metadata_map (git-fixes).
    • net/mlx5: Fix fw reporter diagnose output (git-fixes).
    • net/mlx5: Fix peer devlink set for SF representor devlink port (git-fixes).
    • net/mlx5: Lag, restore buckets number to default after hash LAG deactivation (git-fixes).
    • net/mlx5: offset comp irq index in name by one (git-fixes).
    • net/mlx5: Properly link new fs rules into the tree (git-fixes).
    • net/mlx5: Register devlink first under devlink lock (git-fixes).
    • net/mlx5: Restore mistakenly dropped parts in register devlink flow (git-fixes).
    • net/mlx5: SF, Stop waiting for FW as teardown was called (git-fixes).
    • net: nfc: remove inappropriate attrs check (stable-fixes).
    • net: NSH: fix kernel-doc notation warning (git-fixes).
    • net: pcs: xpcs: Return EINVAL in the internal methods (git-fixes).
    • net: phy: fix phy_read_poll_timeout argument type in genphy_loopback (git-fixes).
    • net: phy: micrel: Fix potential null pointer dereference (git-fixes).
    • net: phy: micrel: lan8814: Fix when enabling/disabling 1-step timestamping (git-fixes).
    • net: phy: micrel: set soft_reset callback to genphy_soft_reset for KSZ8061 (git-fixes).
    • net: phy: phy_device: Prevent nullptr exceptions on ISR (git-fixes).
    • net: phy: phy_device: Prevent nullptr exceptions on ISR (stable-fixes).
    • net: ravb: Always process TX descriptor ring (git-fixes).
    • net: ravb: Let IP-specific receive function to interrogate descriptors (git-fixes).
    • net/smc: bugfix for smcr v2 server connect success statistic (git-fixes).
    • net/smc: fix documentation of buffer sizes (git-fixes).
    • net/smc: use smc_lgr_list.lock to protect smc_lgr_list.list iterate in smcr_port_add (git-fixes).
    • net: smsc95xx: add support for SYS TEC USB-SPEmodule1 (git-fixes).
    • net: sparx5: Fix use after free inside sparx5_del_mact_entry (git-fixes).
    • net: sparx5: fix wrong config being used when reconfiguring PCS (git-fixes).
    • net: sparx5: flower: fix fragment flags handling (git-fixes).
    • net: stmmac: dwmac-starfive: Add support for JH7100 SoC (git-fixes).
    • net: stmmac: Fix incorrect dereference in interrupt handlers (git-fixes).
    • net: stmmac: fix rx queue priority assignment (git-fixes).
    • net: sunrpc: Fix an off by one in rpc_sockaddr2uaddr() (git-fixes).
    • net: tcp: fix unexcepted socket die when snd_wnd is 0 (git-fixes).
    • net: tls: fix returned read length with async decrypt (bsc#1221858).
    • net: tls: fix use-after-free with partial reads and async (bsc#1221858).
    • net: tls, fix WARNIING in __sk_msg_free (bsc#1221858).
    • net: usb: ax88179_178a: avoid the interface always configured as random address (git-fixes).
    • net: usb: ax88179_178a: avoid writing the mac address before first reading (git-fixes).
    • net: usb: ax88179_178a: fix link status when link is set to down/up (git-fixes).
    • net: usb: ax88179_178a: stop lying about skb->truesize (git-fixes).
    • net:usb:qmi_wwan: support Rolling modules (stable-fixes).
    • net: usb: smsc95xx: stop lying about skb->truesize (git-fixes).
    • net: usb: sr9700: stop lying about skb->truesize (git-fixes).
    • net: Use sockaddr_storage for getsockopt(SO_PEERNAME) (git-fixes).
    • net: veth: do not manipulate GRO when using XDP (git-fixes).
    • net: wwan: t7xx: Split 64bit accesses to fix alignment issues (git-fixes).
    • net/x25: fix incorrect parameter validation in the x25_getsockopt() function (git-fixes).
    • nfc: nci: Fix handling of zero-length payload packets in nci_rx_work() (git-fixes).
    • nfc: nci: Fix kcov check in nci_rx_work() (git-fixes).
    • nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet (git-fixes).
    • nfc: nci: Fix uninit-value in nci_rx_work (git-fixes).
    • nf_conntrack: fix -Wunused-const-variable= (git-fixes).
    • NFC: trf7970a: disable all regulators on removal (git-fixes).
    • nfp: flower: handle acti_netdevs allocation failure (git-fixes).
    • NFSD: change LISTXATTRS cookie encoding to big-endian (git-fixes).
    • NFSD: Convert the callback workqueue to use delayed_work (git-fixes).
    • nfsd: do not call locks_release_private() twice concurrently (git-fixes).
    • nfsd: Fix a regression in nfsd_setattr() (git-fixes).
    • NFSD: fix LISTXATTRS returning a short list with eof=TRUE (git-fixes).
    • NFSD: fix LISTXATTRS returning more bytes than maxcount (git-fixes).
    • NFSD: fix nfsd4_listxattr_validate_cookie (git-fixes).
    • NFSD: Fix nfsd_clid_class use of __string_len() macro (git-fixes).
    • NFSD: Reschedule CB operations when backchannel rpc_clnt is shut down (git-fixes).
    • NFSD: Reset cb_seq_status after NFS4ERR_DELAY (git-fixes).
    • NFSD: Retransmit callbacks after client reconnects (git-fixes).
    • nfsd: use __fput_sync() to avoid delayed closing of files (bsc#1223380 bsc#1217408).
    • NFS: Fix an off by one in root_nfs_cat() (git-fixes).
    • NFS: Fix nfs_netfs_issue_read() xarray locking for writeback interrupt (git-fixes).
    • nfs: fix panic when nfs4_ff_layout_prepare_ds() fails (git-fixes).
    • NFS: Read unlock folio on nfs_page_create_from_folio() error (git-fixes).
    • NFSv4.1/pnfs: fix NFS with TLS in pnfs (git-fixes).
    • NFSv4.2: fix listxattr maximum XDR buffer size (git-fixes).
    • NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102 (git-fixes).
    • nilfs2: fix OOB in nilfs_set_de_type (git-fixes).
    • nilfs2: fix out-of-range warning (git-fixes).
    • nilfs2: fix potential bug in end_buffer_async_write (git-fixes).
    • nilfs2: fix unexpected freezing of nilfs_segctor_sync() (git-fixes).
    • nilfs2: fix use-after-free of timer for log writer thread (git-fixes).
    • nilfs2: make superblock data array index computation sparse friendly (git-fixes).
    • nouveau/dmem: handle kcalloc() allocation failure (git-fixes).
    • nouveau: fix devinit paths to only handle display on GSP (git-fixes).
    • nouveau: fix function cast warning (git-fixes).
    • nouveau: fix instmem race condition around ptr stores (git-fixes).
    • nouveau/gsp: do not check devinit disable on GSP (git-fixes).
    • nouveau: lock the client object tree (stable-fixes).
    • nouveau: reset the bo resource bus info after an eviction (git-fixes).
    • nouveau/uvmm: fix addr/range calcs for remap operations (git-fixes).
    • nvdimm: make nvdimm_bus_type const (jsc#PED-5853).
    • nvdimm/pmem: fix leak on dax_add_host() failure (jsc#PED-5853).
    • nvdimm/pmem: Treat alloc_dax() -EOPNOTSUPP failure as non-fatal (jsc#PED-5853).
    • nvme-fc: do not wait in vain when unloading module (git-fixes).
    • nvme: fix multipath batched completion accounting (git-fixes).
    • nvme: fix reconnection fail due to reserved tag allocation (git-fixes).
    • nvme: fix warn output about shared namespaces without CONFIG_NVME_MULTIPATH (git-fixes).
    • nvme-multipath: fix io accounting on failover (git-fixes).
    • nvme-pci: Add quirk for broken MSIs (git-fixes).
    • nvme-tcp: strict pdu pacing to avoid send stalls on TLS (bsc#1221858).
    • nvmet-fc: abort command when there is no binding (git-fixes).
    • nvmet-fc: avoid deadlock on delete association path (git-fixes).
    • nvmet-fc: defer cleanup using RCU properly (git-fixes).
    • nvmet-fc: hold reference on hostport match (git-fixes).
    • nvmet-fcloop: swap the list_add_tail arguments (git-fixes).
    • nvmet-fc: release reference on target port (git-fixes).
    • nvmet-fc: take ref count on tgtport before delete assoc (git-fixes).
    • nvmet: fix ns enable/disable possible hang (git-fixes).
    • nvmet-tcp: fix nvme tcp ida memory leak (git-fixes).
    • octeontx2-af: Add array index check (git-fixes).
    • octeontx2-af: Fix devlink params (git-fixes).
    • octeontx2-af: Fix issue with loading coalesced KPU profiles (git-fixes).
    • octeontx2-af: Fix NIX SQ mode and BP config (git-fixes).
    • Octeontx2-af: fix pause frame configuration in GMP mode (git-fixes).
    • octeontx2-af: Use matching wake_up API variant in CGX command interface (git-fixes).
    • octeontx2-af: Use separate handlers for interrupts (git-fixes).
    • octeontx2: Detect the mbox up or down message via register (git-fixes).
    • octeontx2-pf: check negative error code in otx2_open() (git-fixes).
    • octeontx2-pf: fix FLOW_DIS_IS_FRAGMENT implementation (git-fixes).
    • octeontx2-pf: Fix transmit scheduler resource leak (git-fixes).
    • octeontx2-pf: Send UP messages to VF only when VF is up (git-fixes).
    • octeontx2-pf: Use default max_active works instead of one (git-fixes).
    • octeontx2-pf: Wait till detach_resources msg is complete (git-fixes).
    • of: dynamic: Synchronize of_changeset_destroy() with the devlink removals (git-fixes).
    • of: module: add buffer overflow check in of_modalias() (git-fixes).
    • of: module: prevent NULL pointer dereference in vsnprintf() (stable-fixes).
    • of: property: Add in-ports/out-ports support to of_graph_get_port_parent() (stable-fixes).
    • of: property: fix typo in io-channels (git-fixes).
    • of: property: fw_devlink: Fix stupid bug in remote-endpoint parsing (git-fixes).
    • of: property: Improve finding the consumer of a remote-endpoint property (git-fixes).
    • of: property: Improve finding the supplier of a remote-endpoint property (git-fixes).
    • of: unittest: Fix compile in the non-dynamic case (git-fixes).
    • overflow: Allow non-type arg to type_max() and type_min() (stable-fixes).
    • PCI/AER: Block runtime suspend when handling errors (stable-fixes).
    • PCI/ASPM: Use RMW accessors for changing LNKCTL (git-fixes).
    • PCI: Delay after FLR of Solidigm P44 Pro NVMe (stable-fixes).
    • PCI: Disable D3cold on Asus B1400 PCI-NVMe bridge (stable-fixes).
    • PCI/DPC: Quirk PIO log size for Intel Raptor Lake Root Ports (stable-fixes).
    • PCI/DPC: Use FIELD_GET() (stable-fixes).
    • PCI: dwc: ep: Fix DBI access failure for drivers requiring refclk from host (git-fixes).
    • PCI/EDR: Align EDR_PORT_DPC_ENABLE_DSM with PCI Firmware r3.3 (git-fixes).
    • PCI/EDR: Align EDR_PORT_LOCATE_DSM with PCI Firmware r3.3 (git-fixes).
    • PCI: Execute quirk_enable_clear_retrain_link() earlier (stable-fixes).
    • PCI: Fix typos in docs and comments (stable-fixes).
    • PCI: hv: Fix ring buffer size calculation (git-fixes).
    • PCI: Make link retraining use RMW accessors for changing LNKCTL (git-fixes).
    • PCI/PM: Drain runtime-idle callbacks before driver removal (stable-fixes).
    • PCI: qcom: Add support for sa8775p SoC (git-fixes).
    • PCI: qcom: Disable ASPM L0s for sc8280xp, sa8540p and sa8295p (git-fixes).
    • PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id (git-fixes).
    • PCI: rpaphp: Error out on busy status from get-sensor-state (bsc#1223369 ltc#205888).
    • PCI: Simplify pcie_capability_clear_and_set_word() to ..._clear_word() (stable-fixes).
    • PCI: switchtec: Add support for PCIe Gen5 devices (stable-fixes).
    • PCI: switchtec: Use normal comment style (stable-fixes).
    • PCI: tegra194: Fix probe path for Endpoint mode (git-fixes).
    • peci: linux/peci.h: fix Excess kernel-doc description warning (git-fixes).
    • perf annotate: Fix annotation_calc_lines() to pass correct address to get_srcline() (git-fixes).
    • perf annotate: Get rid of duplicate --group option item (git-fixes).
    • perf auxtrace: Fix multiple use of --itrace option (git-fixes).
    • perf bench internals inject-build-id: Fix trap divide when collecting just one DSO (git-fixes).
    • perf bench uprobe: Remove lib64 from libc.so.6 binary path (git-fixes).
    • perf bpf: Clean up the generated/copied vmlinux.h (git-fixes).
    • perf daemon: Fix file leak in daemon_session__control (git-fixes).
    • perf docs: Document bpf event modifier (git-fixes).
    • perf evsel: Fix duplicate initialization of data->id in evsel__parse_sample() (git-fixes).
    • perf expr: Fix 'has_event' function for metric style events (git-fixes).
    • perf intel-pt: Fix unassigned instruction op (discovered by MemorySanitizer) (git-fixes).
    • perf jevents: Drop or simplify small integer values (git-fixes).
    • perf list: fix short description for some cache events (git-fixes).
    • perf lock contention: Add a missing NULL check (git-fixes).
    • perf metric: Do not remove scale from counts (git-fixes).
    • perf pmu: Count sys and cpuid JSON events separately (git fixes).
    • perf pmu: Fix a potential memory leak in perf_pmu__lookup() (git-fixes).
    • perf pmu: Treat the msr pmu as software (git-fixes).
    • perf print-events: make is_event_supported() more robust (git-fixes).
    • perf probe: Add missing libgen.h header needed for using basename() (git-fixes).
    • perf record: Check conflict between '--timestamp-filename' option and pipe mode before recording (git-fixes).
    • perf record: Fix debug message placement for test consumption (git-fixes).
    • perf record: Fix possible incorrect free in record__switch_output() (git-fixes).
    • perf report: Avoid SEGV in report__setup_sample_type() (git-fixes).
    • perf sched timehist: Fix -g/--call-graph option failure (git-fixes).
    • perf script: Show also errors for --insn-trace option (git-fixes).
    • perf srcline: Add missed addr2line closes (git-fixes).
    • perf stat: Avoid metric-only segv (git-fixes).
    • perf stat: Do not display metric header for non-leader uncore events (git-fixes).
    • perf stat: Do not fail on metrics on s390 z/VM systems (git-fixes).
    • perf symbols: Fix ownership of string in dso__load_vmlinux() (git-fixes).
    • perf tests: Apply attributes to all events in object code reading test (git-fixes).
    • perf test shell arm_coresight: Increase buffer size for Coresight basic tests (git-fixes).
    • perf tests: Make data symbol test wait for perf to start (bsc#1220045).
    • perf tests: Make 'test data symbol' more robust on Neoverse N1 (git-fixes).
    • perf tests: Skip data symbol test if buf1 symbol is missing (bsc#1220045).
    • perf thread: Fixes to thread__new() related to initializing comm (git-fixes).
    • perf thread_map: Free strlist on normal path in thread_map__new_by_tid_str() (git-fixes).
    • perf top: Uniform the event name for the hybrid machine (git-fixes).
    • perf top: Use evsel's cpus to replace user_requested_cpus (git-fixes).
    • perf ui browser: Avoid SEGV on title (git fixes).
    • perf ui browser: Do not save pointer to stack memory (git-fixes).
    • perf vendor events amd: Add Zen 4 memory controller events (git-fixes).
    • perf vendor events amd: Fix Zen 4 cache latency events (git-fixes).
    • perf/x86/amd/core: Avoid register reset when CPU is dead (git-fixes).
    • perf/x86/amd/lbr: Discard erroneous branch entries (git-fixes).
    • perf/x86/amd/lbr: Use freeze based on availability (git-fixes).
    • perf/x86: Fix out of range data (git-fixes).
    • perf/x86/intel/ds: Do not clear ->pebs_data_cfg for the last PEBS event (git-fixes).
    • perf/x86/intel: Expose existence of callback support to KVM (git-fixes).
    • phy: freescale: imx8m-pcie: fix pcie link-up instability (git-fixes).
    • phy: marvell: a3700-comphy: Fix hardcoded array size (git-fixes).
    • phy: marvell: a3700-comphy: Fix out of bounds read (git-fixes).
    • phy: rockchip: naneng-combphy: Fix mux on rk3588 (git-fixes).
    • phy: rockchip-snps-pcie3: fix bifurcation on rk3588 (git-fixes).
    • phy: rockchip-snps-pcie3: fix clearing PHP_GRF_PCIESEL_CON bits (git-fixes).
    • phy: ti: tusb1210: Resolve charger-det crash if charger psy is unregistered (git-fixes).
    • pinctrl: armada-37xx: remove an unused variable (git-fixes).
    • pinctrl: baytrail: Fix selecting gpio pinctrl state (git-fixes).
    • pinctrl: core: delete incorrect free in pinctrl_enable() (git-fixes).
    • pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() (git-fixes).
    • pinctrl: mediatek: paris: Fix PIN_CONFIG_INPUT_SCHMITT_ENABLE readback (git-fixes).
    • pinctrl: mediatek: paris: Rework support for PIN_CONFIG_{INPUT,OUTPUT}_ENABLE (git-fixes).
    • pinctrl/meson: fix typo in PDM's pin name (git-fixes).
    • pinctrl: pinctrl-aspeed-g6: Fix register offset for pinconf of GPIOR-T (git-fixes).
    • pinctrl: qcom: pinctrl-sm7150: Fix sdc1 and ufs special pins regs (git-fixes).
    • pinctrl: renesas: checker: Limit cfg reg enum checks to provided IDs (stable-fixes).
    • platform/chrome: cros_ec_uart: properly fix race condition (git-fixes).
    • platform/x86/amd/pmc: Extend Framework 13 quirk to more BIOSes (stable-fixes).
    • platform/x86/intel-uncore-freq: Do not present root domain on error (git-fixes).
    • platform/x86: intel-vbtn: Update tablet mode switch at end of probe (git-fixes).
    • platform/x86: ISST: Add Granite Rapids-D to HPM CPU list (stable-fixes).
    • platform/x86: touchscreen_dmi: Add an extra entry for a variant of the Chuwi Vi8 tablet (stable-fixes).
    • platform/x86: x86-android-tablets: Fix acer_b1_750_goodix_gpios name (stable-fixes).
    • platform/x86: xiaomi-wmi: Fix race condition when reporting key events (git-fixes).
    • PM / devfreq: Synchronize devfreq_monitor_[start/stop] (stable-fixes).
    • PM: s2idle: Make sure CPUs will wakeup directly on resume (git-fixes).
    • Port 'certs: Add ECDSA signature verification self-test'.
    • Port 'certs: Move RSA self-test data to separate file'.
    • powerpc: Avoid nmi_enter/nmi_exit in real mode interrupt (bsc#1221645 ltc#205739 bsc#1223191).
    • powerpc/crypto/chacha-p10: Fix failure on non Power10 (bsc#1218205).
    • powerpc/eeh: Permanently disable the removed device (bsc#1223991 ltc#205740).
    • powerpc/hv-gpci: Fix the H_GET_PERF_COUNTER_INFO hcall return value checks (git-fixes).
    • powerpc/pseries/lparcfg: drop error message from guest name lookup (bsc#1187716 ltc#193451 git-fixes).
    • powerpc/pseries: make max polling consistent for longer H_CALLs (bsc#1215199).
    • powerpc/pseries/vio: Do not return ENODEV if node or compatible missing (bsc#1220783).
    • powerpc/uaccess: Fix build errors seen with GCC 13/14 (bsc#1194869).
    • powerpc/uaccess: Use YZ asm constraint for ld (bsc#1194869).
    • power: rt9455: hide unused rt9455_boost_voltage_values (git-fixes).
    • power: supply: mt6360_charger: Fix of_match for usb-otg-vbus regulator (git-fixes).
    • ppdev: Add an error check in register_device (git-fixes).
    • prctl: generalize PR_SET_MDWE support check to be per-arch (bsc#1225610).
    • printk: Add this_cpu_in_panic() (bsc#1225607).
    • printk: Adjust mapping for 32bit seq macros (bsc#1225607).
    • printk: Avoid non-panic CPUs writing to ringbuffer (bsc#1225607).
    • printk: Consolidate console deferred printing (bsc#1225607).
    • printk: Disable passing console lock owner completely during panic() (bsc#1225607).
    • printk: Do not take console lock for console_flush_on_panic() (bsc#1225607).
    • printk: For @suppress_panic_printk check for other CPU in panic (bsc#1225607).
    • printk: Keep non-panic-CPUs out of console lock (bsc#1225607).
    • printk: Let no_printk() use _printk() (bsc#1225618).
    • printk: nbcon: Relocate 32bit seq macros (bsc#1225607).
    • printk: Reduce console_unblank() usage in unsafe scenarios (bsc#1225607).
    • printk: Rename abandon_console_lock_in_panic() to other_cpu_in_panic() (bsc#1225607).
    • printk: ringbuffer: Clarify special lpos values (bsc#1225607).
    • printk: ringbuffer: Cleanup reader terminology (bsc#1225607).
    • printk: ringbuffer: Do not skip non-finalized records with prb_next_seq() (bsc#1225607).
    • printk: ringbuffer: Skip non-finalized records in panic (bsc#1225607).
    • printk: Update @console_may_schedule in console_trylock_spinning() (bsc#1225616).
    • printk: Use prb_first_seq() as base for 32bit seq macros (bsc#1225607).
    • printk: Wait for all reserved records with pr_flush() (bsc#1225607).
    • proc/kcore: do not try to access unaccepted memory (git-fixes).
    • pstore: inode: Convert mutex usage to guard(mutex) (stable-fixes).
    • pstore: inode: Only d_invalidate() is needed (git-fixes).
    • pstore/zone: Add a null pointer check to the psz_kmsg_read (stable-fixes).
    • pwm: img: fix pwm clock lookup (git-fixes).
    • qibfs: fix dentry leak (git-fixes)
    • r8169: fix issue caused by buggy BIOS on certain boards with RTL8168d (git-fixes).
    • r8169: skip DASH fw status checks when DASH is disabled (git-fixes).
    • random: handle creditable entropy from atomic process context (git-fixes).
    • RAS/AMD/FMPM: Avoid NULL ptr deref in get_saved_records() (jsc#PED-7619).
    • RAS/AMD/FMPM: Fix build when debugfs is not enabled (jsc#PED-7619).
    • RAS/AMD/FMPM: Safely handle saved records of various sizes (jsc#PED-7619).
    • RDMA/cm: add timeout to cm_destroy_id wait (git-fixes)
    • RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw (git-fixes)
    • RDMA/cm: Print the old state when cm_destroy_id gets timeout (git-fixes)
    • RDMA/hns: Add max_ah and cq moderation capacities in query_device() (git-fixes)
    • RDMA/hns: Fix deadlock on SRQ async events. (git-fixes)
    • RDMA/hns: Fix GMV table pagesize (git-fixes)
    • RDMA/hns: Fix return value in hns_roce_map_mr_sg (git-fixes)
    • RDMA/hns: Fix UAF for cq async event (git-fixes)
    • RDMA/hns: Modify the print level of CQE error (git-fixes)
    • RDMA/hns: Use complete parentheses in macros (git-fixes)
    • RDMA/IPoIB: Fix format truncation compilation errors (git-fixes)
    • RDMA/mana_ib: Fix bug in creation of dma regions (git-fixes).
    • RDMA/mlx5: Adding remote atomic access flag to updatable flags (git-fixes)
    • RDMA/mlx5: Change check for cacheable mkeys (git-fixes)
    • RDMA/mlx5: Fix port number for counter query in multi-port configuration (git-fixes)
    • RDMA/mlx5: Uncacheable mkey has neither rb_key or cache_ent (git-fixes)
    • RDMA/rxe: Allow good work requests to be executed (git-fixes)
    • RDMA/rxe: Fix incorrect rxe_put in error path (git-fixes)
    • RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt (git-fixes)
    • RDMA/rxe: Fix the problem 'mutex_destroy missing' (git-fixes)
    • README.BRANCH: Remove copy of branch name
    • Reapply 'drm/qxl: simplify qxl_fence_wait' (stable-fixes).
    • regmap: Add regmap_read_bypassed() (git-fixes).
    • regmap: kunit: Ensure that changed bytes are actually different (stable-fixes).
    • regmap: maple: Fix cache corruption in regcache_maple_drop() (git-fixes).
    • regmap: maple: Fix uninitialized symbol 'ret' warnings (git-fixes).
    • regulator: bd71828: Do not overwrite runtime voltages (git-fixes).
    • regulator: change devm_regulator_get_enable_optional() stub to return Ok (git-fixes).
    • regulator: change stubbed devm_regulator_get_enable to return Ok (git-fixes).
    • regulator: core: fix debugfs creation regression (git-fixes).
    • regulator: mt6360: De-capitalize devicetree regulator subnodes (git-fixes).
    • regulator: tps65132: Add of_match table (stable-fixes).
    • remoteproc: k3-r5: Do not allow core1 to power up before core0 via sysfs (git-fixes).
    • remoteproc: k3-r5: Jump to error handling labels in start/stop errors (git-fixes).
    • remoteproc: k3-r5: Wait for core0 power-up before powering up core1 (git-fixes).
    • remoteproc: mediatek: Make sure IPI buffer fits in L2TCM (git-fixes).
    • remoteproc: stm32: Fix incorrect type assignment returned by stm32_rproc_get_loaded_rsc_tablef (git-fixes).
    • remoteproc: virtio: Fix wdg cannot recovery remote processor (git-fixes).
    • Remove NTFSv3 from configs (bsc#1224429) References: bsc#1224429 comment#3 We only support fuse version of the NTFS-3g driver. Disable NTFSv3 from all configs. This was enabled in d016c04d731 ('Bump to 6.4 kernel (jsc#PED-4593)')
    • Revert 'ACPI: PM: Block ASUS B1400CEAE from suspend to idle by default' (stable-fixes).
    • Revert 'ASoC: SOF: Intel: hda-dai-ops: only allocate/release streams for first CPU DAI' (stable-fixes).
    • Revert 'ASoC: SOF: Intel: hda-dai-ops: reset device count for SoundWire DAIs' (stable-fixes).
    • Revert 'cifs: reconnect work should have reference on server struct' (git-fixes, bsc#1225172).
    • Revert 'drm/amd/amdgpu: Fix potential ioremap() memory leaks in amdgpu_device_init()' (stable-fixes).
    • Revert 'drm/amd/display: Fix sending VSC (+ colorimetry) packets for DP/eDP displays without PSR' (stable-fixes).
    • Revert 'drm/amdkfd: fix gfx_target_version for certain 11.0.3 devices' (stable-fixes).
    • Revert 'drm/bridge: ti-sn65dsi83: Fix enable error path' (git-fixes).
    • Revert 'drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()' (stable-fixes).
    • Revert 'drm/qxl: simplify qxl_fence_wait' (git-fixes).
    • Revert 'iommu/amd: Enable PCI/IMS' (git-fixes).
    • Revert 'iommu/vt-d: Enable PCI/IMS' (git-fixes).
    • Revert 'net/mlx5: Block entering switchdev mode with ns inconsistency' (git-fixes).
    • Revert 'net/mlx5e: Check the number of elements before walk TC rhashtable' (git-fixes).
    • Revert 'PCI/MSI: Provide IMS (Interrupt Message Store) support' (git-fixes).
    • Revert 'PCI/MSI: Provide pci_ims_alloc/free_irq()' (git-fixes).
    • Revert 'PCI/MSI: Provide stubs for IMS functions' (git-fixes).
    • Revert 'selinux: introduce an initial SID for early boot processes' (bsc#1208593) It caused a regression on ALP-current branch, kernel-obs-qa build failed.
    • Revert 'usb: cdc-wdm: close race between read and workqueue' (git-fixes).
    • Revert 'usb: phy: generic: Get the vbus supply' (git-fixes).
    • ring-buffer: Do not set shortest_full when full target is hit (git-fixes).
    • ring-buffer: Fix a race between readers and resize checks (git-fixes).
    • ring-buffer: Fix full_waiters_pending in poll (git-fixes).
    • ring-buffer: Fix resetting of shortest_full (git-fixes).
    • ring-buffer: Fix waking up ring buffer readers (git-fixes).
    • ring-buffer: Make wake once of ring_buffer_wait() more robust (git-fixes).
    • ring-buffer: use READ_ONCE() to read cpu_buffer->commit_page in concurrent environment (git-fixes).
    • ring-buffer: Use wait_event_interruptible() in ring_buffer_wait() (git-fixes).
    • rtc: mt6397: select IRQ_DOMAIN instead of depending on it (git-fixes).
    • s390/bpf: Emit a barrier for BPF_FETCH instructions (git-fixes bsc#1224792).
    • s390/cio: Ensure the copied buf is NUL terminated (git-fixes bsc#1223869).
    • s390/cio: fix tracepoint subchannel type field (git-fixes bsc#1224793).
    • s390/cpacf: Split and rework cpacf query functions (git-fixes bsc#1225133).
    • s390/ipl: Fix incorrect initialization of len fields in nvme reipl block (git-fixes bsc#1225136).
    • s390/ipl: Fix incorrect initialization of nvme dump block (git-fixes bsc#1225134).
    • s390/ism: Properly fix receive message buffer allocation (git-fixes bsc#1223590).
    • s390/mm: Fix clearing storage keys for huge pages (git-fixes bsc#1223871).
    • s390/mm: Fix storage key clearing for guest huge pages (git-fixes bsc#1223872).
    • s390/qeth: Fix kernel panic after setting hsuid (git-fixes bsc#1223874).
    • s390/vdso: Add CFI for RA register to asm macro vdso_func (git-fixes bsc#1223870).
    • s390/vdso: drop '-fPIC' from LDFLAGS (git-fixes bsc#1223593).
    • s390/vtime: fix average steal time calculation (git-fixes bsc#1221783).
    • s390/zcrypt: fix reference counting on zcrypt card objects (git-fixes bsc#1223592).
    • sched/balancing: Rename newidle_balance() => sched_balance_newidle() (bsc#1222173).
    • sched/fair: Check root_domain::overload value before update (bsc#1222173).
    • sched/fair: Use helper functions to access root_domain::overload (bsc#1222173).
    • sched/psi: Select KERNFS as needed (git-fixes).
    • sched/topology: Optimize topology_span_sane() (bsc#1225053).
    • scsi: bfa: Fix function pointer type mismatch for hcb_qe->cbfn (git-fixes).
    • scsi: core: Consult supported VPD page list prior to fetching page (git-fixes).
    • scsi: core: Fix unremoved procfs host directory regression (git-fixes).
    • scsi: csiostor: Avoid function pointer casts (git-fixes).
    • scsi: hisi_sas: Modify the deadline for ata_wait_after_reset() (git-fixes).
    • scsi: libsas: Add a helper sas_get_sas_addr_and_dev_type() (git-fixes).
    • scsi: libsas: Fix disk not being scanned in after being removed (git-fixes).
    • scsi: lpfc: Add support for 32 byte CDBs (bsc#1225842).
    • scsi: lpfc: Change default logging level for unsolicited CT MIB commands (bsc#1225842).
    • scsi: lpfc: Change lpfc_hba hba_flag member into a bitmask (bsc#1225842). Refresh: - patches.suse/lpfc-reintroduce-old-irq-probe-logic.patch
    • scsi: lpfc: Clear deferred RSCN processing flag when driver is unloading (bsc#1225842).
    • scsi: lpfc: Copyright updates for 14.4.0.1 patches (bsc#1221777).
    • scsi: lpfc: Copyright updates for 14.4.0.2 patches (bsc#1225842).
    • scsi: lpfc: Correct size for cmdwqe/rspwqe for memset() (bsc#1221777).
    • scsi: lpfc: Correct size for wqe for memset() (bsc#1221777).
    • scsi: lpfc: Define lpfc_dmabuf type for ctx_buf ptr (bsc#1221777).
    • scsi: lpfc: Define lpfc_nodelist type for ctx_ndlp ptr (bsc#1221777).
    • scsi: lpfc: Define types in a union for generic void *context3 ptr (bsc#1221777).
    • scsi: lpfc: Introduce rrq_list_lock to protect active_rrq_list (bsc#1225842).
    • scsi: lpfc: Move NPIV's transport unregistration to after resource clean up (bsc#1221777).
    • scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (bsc#1221777).
    • scsi: lpfc: Remove IRQF_ONESHOT flag from threaded IRQ handling (bsc#1221777 bsc#1217959).
    • scsi: lpfc: Remove unnecessary log message in queuecommand path (bsc#1221777).
    • scsi: lpfc: Replace hbalock with ndlp lock in lpfc_nvme_unregister_port() (bsc#1221777).
    • scsi: lpfc: Update logging of protection type for T10 DIF I/O (bsc#1225842).
    • scsi: lpfc: Update lpfc_ramp_down_queue_handler() logic (bsc#1221777).
    • scsi: lpfc: Update lpfc version to 14.4.0.1 (bsc#1221777).
    • scsi: lpfc: Update lpfc version to 14.4.0.2 (bsc#1225842).
    • scsi: lpfc: Use a dedicated lock for ras_fwlog state (bsc#1221777).
    • scsi: mpt3sas: Prevent sending diag_reset when the controller is ready (git-fixes).
    • scsi: mylex: Fix sysfs buffer lengths (git-fixes).
    • scsi: qla2xxx: Change debug message during driver unload (bsc1221816).
    • scsi: qla2xxx: Delay I/O Abort on PCI error (bsc1221816).
    • scsi: qla2xxx: Fix command flush on cable pull (bsc1221816).
    • scsi: qla2xxx: Fix double free of fcport (bsc1221816).
    • scsi: qla2xxx: Fix double free of the ha->vp_map pointer (bsc1221816).
    • scsi: qla2xxx: Fix N2N stuck connection (bsc1221816).
    • scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() (git-fixes).
    • scsi: qla2xxx: NVME|FCP prefer flag not being honored (bsc1221816).
    • scsi: qla2xxx: Prevent command send on chip reset (bsc1221816).
    • scsi: qla2xxx: Split FCE|EFT trace control (bsc1221816).
    • scsi: qla2xxx: Update manufacturer detail (bsc1221816).
    • scsi: qla2xxx: Update version to 10.02.09.200-k (bsc1221816).
    • scsi: sd: Unregister device if device_add_disk() failed in sd_probe() (git-fixes).
    • scsi: sg: Avoid race in error handling & drop bogus warn (git-fixes).
    • scsi: sg: Avoid sg device teardown race (git-fixes).
    • scsi: smartpqi: Fix disable_managed_interrupts (git-fixes).
    • sctp: annotate data-races around sk->sk_wmem_queued (git-fixes).
    • sdhci-of-dwcmshc: disable PM runtime in dwcmshc_remove() (git-fixes).
    • selftests/binderfs: use the Makefile's rules, not Make's implicit rules (git-fixes).
    • selftests/bpf: add edge case backtracking logic test (bsc#1225756).
    • selftests/bpf: precision tracking test for BPF_NEG and BPF_END (bsc#1225756).
    • selftests: default to host arch for LLVM builds (git-fixes).
    • selftests: forwarding: Fix ping failure due to short timeout (git-fixes).
    • selftests/ftrace: Fix event filter target_func selection (stable-fixes).
    • selftests/ftrace: Limit length in subsystem-enable tests (git-fixes).
    • selftests/kcmp: remove unused open mode (git-fixes).
    • selftests: kselftest: Fix build failure with NOLIBC (git-fixes).
    • selftests: kselftest: Mark functions that unconditionally call exit() as __noreturn (git-fixes).
    • selftests: net: bridge: increase IGMP/MLD exclude timeout membership interval (git-fixes).
    • selftests/net: convert test_bridge_neigh_suppress.sh to run it in unique namespace (stable-fixes).
    • selftests: net: kill smcrouted in the cleanup logic in amt.sh (git-fixes).
    • selftests: net: move amt to socat for better compatibility (git-fixes).
    • selftests/pidfd: Fix config for pidfd_setns_test (git-fixes).
    • selftests/powerpc/dexcr: Add -no-pie to hashchk tests (git-fixes).
    • selftests/powerpc/papr-vpd: Fix missing variable initialization (jsc#PED-4486 git-fixes).
    • selftests/resctrl: fix clang build failure: use LOCAL_HDRS (git-fixes).
    • selftests: test_bridge_neigh_suppress.sh: Fix failures due to duplicate MAC (git-fixes).
    • selftests: timers: Convert posix_timers test to generate KTAP output (stable-fixes).
    • selftests: timers: Fix abs() warning in posix_timers test (git-fixes).
    • selftests: timers: Fix posix_timers ksft_print_msg() warning (git-fixes).
    • selftests: timers: Fix valid-adjtimex signed left-shift undefined behavior (stable-fixes).
    • selftests/timers/posix_timers: Reimplement check_timer_distribution() (git-fixes).
    • selftests: vxlan_mdb: Fix failures with old libnet (git-fixes).
    • selinux: avoid dereference of garbage after mount failure (git-fixes).
    • selinux: introduce an initial SID for early boot processes (bsc#1208593).
    • serial: 8250_bcm7271: use default_mux_rate if possible (git-fixes).
    • serial: 8250_dw: Revert: Do not reclock if already at correct rate (git-fixes).
    • serial: 8250_exar: Do not remove GPIO device on suspend (git-fixes).
    • serial: 8520_mtk: Set RTS on shutdown for Rx in-band wakeup (git-fixes).
    • serial: core: Fix atomicity violation in uart_tiocmget (git-fixes).
    • serial: core: only stop transmit when HW fifo is empty (git-fixes).
    • serial: kgdboc: Fix NMI-safety problems from keyboard reset code (stable-fixes).
    • serial: Lock console when calling into driver before registration (git-fixes).
    • serial: max3100: Fix bitwise types (git-fixes).
    • serial: max3100: Lock port->lock when calling uart_handle_cts_change() (git-fixes).
    • serial: max310x: fix NULL pointer dereference in I2C instantiation (git-fixes).
    • serial: max310x: fix syntax error in IRQ error message (git-fixes).
    • serial: mxs-auart: add spinlock around changing cts state (git-fixes).
    • serial/pmac_zilog: Remove flawed mitigation for rx irq flood (git-fixes).
    • serial: sc16is7xx: add proper sched.h include for sched_set_fifo() (git-fixes).
    • serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using prescaler (git-fixes).
    • serial: sh-sci: protect invalidating RXDMA on shutdown (git-fixes).
    • serial: stm32: Reset .throttled state in .startup() (git-fixes).
    • series.conf: cleanup Fix subsection header to silence series_insert error.
    • SEV: disable SEV-ES DebugSwap by default (git-fixes).
    • slimbus: core: Remove usage of the deprecated ida_simple_xx() API (git-fixes).
    • slimbus: qcom-ngd-ctrl: Add timeout for wait operation (git-fixes).
    • smb3: show beginning time for per share stats (bsc#1225172).
    • smb: client: ensure to try all targets when finding nested links (bsc#1225172).
    • smb: client: fix mount when dns_resolver key is not available (git-fixes, bsc#1225172).
    • smb: client: fix parsing of SMB3.1.1 POSIX create context (git-fixes, bsc#1225172).
    • smb: client: get rid of dfs code dep in namespace.c (bsc#1225172).
    • smb: client: get rid of dfs naming in automount code (bsc#1225172).
    • smb: client: introduce DFS_CACHE_TGT_LIST() (bsc#1225172).
    • smb: client: reduce stack usage in cifs_try_adding_channels() (bsc#1225172).
    • smb: client: remove extra @chan_count check in __cifs_put_smb_ses() (bsc#1225172).
    • smb: client: rename cifs_dfs_ref.c to namespace.c (bsc#1225172).
    • soc: fsl: qbman: Always disable interrupts when taking cgr_lock (git-fixes).
    • soc: fsl: qbman: Use raw spinlock for cgr_lock (git-fixes).
    • sock_diag: annotate data-races around sock_diag_handlers[family] (git-fixes).
    • soc: mediatek: cmdq: Fix typo of CMDQ_JUMP_RELATIVE (git-fixes).
    • soc: microchip: Fix POLARFIRE_SOC_SYS_CTRL input prompt (stable-fixes).
    • soc: qcom: pmic_glink: do not traverse clients list without a lock (git-fixes).
    • soc: qcom: pmic_glink: Make client-lock non-sleeping (git-fixes).
    • soc: qcom: pmic_glink: notify clients about the current state (git-fixes).
    • soc: qcom: rpmh-rsc: Enhance check for VRM in-flight request (git-fixes).
    • soundwire: amd: fix for wake interrupt handling for clockstop mode (git-fixes).
    • speakup: Avoid crash on very long word (git-fixes).
    • speakup: Fix 8bit characters from direct synth (git-fixes).
    • speakup: Fix sizeof() vs ARRAY_SIZE() bug (git-fixes).
    • spi: Do not mark message DMA mapped when no transfer in it is (git-fixes).
    • spi: fix null pointer dereference within spi_sync (git-fixes).
    • spi: intel-pci: Add support for Lunar Lake-M SPI serial flash (stable-fixes).
    • spi: lm70llp: fix links in doc and comments (git-fixes).
    • spi: lpspi: Avoid potential use-after-free in probe() (git-fixes).
    • spi: mchp-pci1xxx: Fix a possible null pointer dereference in pci1xxx_spi_probe (git-fixes).
    • spi: microchip-core-qspi: fix setting spi bus clock rate (git-fixes).
    • spi: spi-fsl-lpspi: remove redundant spi_controller_put call (git-fixes).
    • spi: spi-mt65xx: Fix NULL pointer access in interrupt handler (git-fixes).
    • spi: stm32: Do not warn about spurious interrupts (git-fixes).
    • spi: xilinx: Fix kernel documentation in the xilinx_spi.h (git-fixes).
    • spmi: hisi-spmi-controller: Do not override device identifier (git-fixes).
    • staging: vc04_services: changen strncpy() to strscpy_pad() (stable-fixes).
    • staging: vc04_services: fix information leak in create_component() (git-fixes).
    • staging: vt6655: Remove unused declaration of RFbAL7230SelectChannelPostProcess() (git-fixes).
    • stmmac: Clear variable when destroying workqueue (git-fixes).
    • SUNRPC: fix a memleak in gss_import_v2_context (git-fixes).
    • SUNRPC: fix some memleaks in gssx_dec_option_array (git-fixes).
    • supported.conf: support tcp_dctcp module (jsc#PED-8111)
    • swiotlb: extend buffer pre-padding to alloc_align_mask if necessary (bsc#1224331)
    • swiotlb: Fix alignment checks when both allocation and DMA masks are (bsc#1224331)
    • swiotlb: Fix double-allocation of slots due to broken alignment (bsc#1224331)
    • swiotlb: Honour dma_alloc_coherent() alignment in swiotlb_alloc() (bsc#1224331)
    • swiotlb: use the calculated number of areas (git-fixes).
    • Temporarily drop KVM patch that caused a regression (bsc#1226158).
    • thermal: devfreq_cooling: Fix perf state when calculate dfc res_util (git-fixes).
    • thermal/drivers/qcom/lmh: Check for SCM availability at probe (git-fixes).
    • thermal/drivers/tsens: Fix null pointer dereference (git-fixes).
    • thermal/of: Assume polling-delay(-passive) 0 when absent (stable-fixes).
    • thunderbolt: Avoid notify PM core about runtime PM resume (stable-fixes).
    • thunderbolt: Do not create DisplayPort tunnels on adapters of the same router (git-fixes).
    • thunderbolt: Fix wake configurations after device unplug (stable-fixes).
    • thunderbolt: Introduce tb_path_deactivate_hop() (stable-fixes).
    • thunderbolt: Introduce tb_port_reset() (stable-fixes).
    • thunderbolt: Make tb_switch_reset() support Thunderbolt 2, 3 and USB4 routers (stable-fixes).
    • thunderbolt: Reset only non-USB4 host routers in resume (git-fixes).
    • tls: break out of main loop when PEEK gets a non-data record (bsc#1221858).
    • tls: do not skip over different type records from the rx_list (bsc#1221858).
    • tls: fix peeking with sync+async decryption (bsc#1221858).
    • tls: stop recv() if initial process_rx_list gave us non-DATA (bsc#1221858).
    • tools/arch/x86/intel_sdsi: Fix maximum meter bundle length (git-fixes).
    • tools/arch/x86/intel_sdsi: Fix meter_certificate decoding (git-fixes).
    • tools/arch/x86/intel_sdsi: Fix meter_show display (git-fixes).
    • tools/latency-collector: Fix -Wformat-security compile warns (git-fixes).
    • tools/power turbostat: Expand probe_intel_uncore_frequency() (bsc#1221765).
    • tools/power/turbostat: Fix uncore frequency file string (bsc#1221765).
    • tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer (git-fixes).
    • tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test (git-fixes).
    • tracing: Have saved_cmdlines arrays all in one allocation (git-fixes).
    • tracing: hide unused ftrace_event_id_fops (git-fixes).
    • tracing/net_sched: Fix tracepoints that save qdisc_dev() as a string (git-fixes).
    • tracing: Remove precision vsnprintf() check from print event (git-fixes).
    • tracing/ring-buffer: Fix wait_on_pipe() race (git-fixes).
    • tracing: Use .flush() call to wake up readers (git-fixes).
    • tty: n_gsm: fix missing receive state reset after mode switch (git-fixes).
    • tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (git-fixes).
    • tty: serial: samsung: fix tx_empty() to return TIOCSER_TEMT (git-fixes).
    • tty: vt: fix 20 vs 0x20 typo in EScsiignore (git-fixes).
    • ubifs: dbg_check_idx_size: Fix kmemleak if loading znode failed (git-fixes).
    • ubifs: fix sort function prototype (git-fixes).
    • ubifs: Queue up space reservation tasks if retrying many times (git-fixes).
    • ubifs: Remove unreachable code in dbg_check_ltab_lnum (git-fixes).
    • ubifs: Set page uptodate in the correct place (git-fixes).
    • Update config files. Disable N_GSM (jsc#PED-8240).
    • Update patches.suse/nvme-ensure-disabling-pairs-with-unquiesce.patch (jsc#PED-6252 jsc#PED-5728 jsc#PED-5062 jsc#PED-3535 bsc#1224534).
    • usb: aqc111: stop lying about skb->truesize (git-fixes).
    • usb: audio-v2: Correct comments for struct uac_clock_selector_descriptor (git-fixes).
    • usb: cdc-wdm: close race between read and workqueue (git-fixes).
    • USB: core: Add hub_get() and hub_put() routines (stable-fixes).
    • USB: core: Fix access violation during port device removal (git-fixes).
    • USB: core: Fix deadlock in port 'disable' sysfs attribute (stable-fixes).
    • USB: core: Fix deadlock in usb_deauthorize_interface() (git-fixes).
    • usb: Disable USB3 LPM at shutdown (stable-fixes).
    • usb: dwc2: gadget: Fix exiting from clock gating (git-fixes).
    • usb: dwc2: gadget: LPM flow fix (git-fixes).
    • usb: dwc2: host: Fix dereference issue in DDMA completion flow (git-fixes).
    • usb: dwc2: host: Fix hibernation flow (git-fixes).
    • usb: dwc2: host: Fix ISOC flow in DDMA mode (git-fixes).
    • usb: dwc2: host: Fix remote wakeup from hibernation (git-fixes).
    • usb: dwc3-am62: Disable wakeup at remove (git-fixes).
    • usb: dwc3-am62: fix module unload/reload behavior (git-fixes).
    • usb: dwc3-am62: Rename private data (git-fixes).
    • usb: dwc3: core: Prevent phy suspend during init (Git-fixes).
    • usb: dwc3: pci: Drop duplicate ID (git-fixes).
    • usb: dwc3: Properly set system wakeup (git-fixes).
    • usb: dwc3: Wait unconditionally after issuing EndXfer command (git-fixes).
    • usb: Fix regression caused by invalid ep0 maxpacket in virtual SuperSpeed device (bsc#1220569).
    • usb: fotg210: Add missing kernel doc description (git-fixes).
    • usb: gadget: composite: fix OS descriptors w_value logic (git-fixes).
    • usb: gadget: f_fs: Fix a race condition when processing setup packets (git-fixes).
    • usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete (git-fixes).
    • usb: gadget: f_ncm: Fix UAF ncm object at re-bind after usb ep transport error (stable-fixes).
    • usb: gadget: net2272: Use irqflags in the call to net2272_probe_fin (git-fixes).
    • usb: gadget: u_audio: Clear uac pointer when freed (git-fixes).
    • usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind (git-fixes).
    • usb: gadget: uvc: mark incomplete frames with UVC_STREAM_ERR (stable-fixes).
    • usb: gadget: uvc: use correct buffer size when parsing configfs lists (git-fixes).
    • usb: ohci: Prevent missed ohci interrupts (git-fixes).
    • usb: phy: generic: Get the vbus supply (git-fixes).
    • USB: serial: add device ID for VeriFone adapter (stable-fixes).
    • USB: serial: cp210x: add ID for MGP Instruments PDS100 (stable-fixes).
    • USB: serial: cp210x: add pid/vid for TDK NC0110013M and MM0110113M (stable-fixes).
    • USB: serial: ftdi_sio: add support for GMC Z216C Adapter IR-USB (stable-fixes).
    • USB: serial: option: add Fibocom FM135-GL variants (stable-fixes).
    • USB: serial: option: add Lonsung U8300/U9300 product (stable-fixes).
    • USB: serial: option: add MeiG Smart SLM320 product (stable-fixes).
    • USB: serial: option: add Rolling RW101-GL and RW135-GL support (stable-fixes).
    • USB: serial: option: add support for Fibocom FM650/FG650 (stable-fixes).
    • USB: serial: option: add Telit FN920C04 rmnet compositions (stable-fixes).
    • USB: serial: option: support Quectel EM060K sub-models (stable-fixes).
    • usb: sl811-hcd: only defined function checkdone if QUIRK2 is defined (stable-fixes).
    • usb: typec: Return size of buffer if pd_set operation succeeds (git-fixes).
    • usb: typec: tcpci: add generic tcpci fallback compatible (stable-fixes).
    • usb: typec: tcpm: Check for port partner validity before consuming it (git-fixes).
    • usb: typec: tcpm: clear pd_event queue in PORT_RESET (git-fixes).
    • usb: typec: tcpm: Correct port source pdo array in pd_set callback (git-fixes).
    • usb: typec: tcpm: Correct the PDO counting in pd_set (git-fixes).
    • usb: typec: tcpm: fix double-free issue in tcpm_port_unregister_pd() (git-fixes).
    • usb: typec: tcpm: unregister existing source caps before re-registration (git-fixes).
    • usb: typec: tipd: fix event checking for tps6598x (git-fixes).
    • usb: typec: ucsi: Ack unsupported commands (stable-fixes).
    • usb: typec: ucsi_acpi: Refactor and fix DELL quirk (git-fixes).
    • usb: typec: ucsi: always register a link to USB PD device (git-fixes).
    • usb: typec: ucsi: Check for notifications after init (git-fixes).
    • usb: typec: ucsi: Clean up UCSI_CABLE_PROP macros (git-fixes).
    • usb: typec: ucsi: Clear EVENT_PENDING under PPM lock (git-fixes).
    • usb: typec: ucsi: Clear UCSI_CCI_RESET_COMPLETE before reset (stable-fixes).
    • usb: typec: ucsi: displayport: Fix potential deadlock (git-fixes).
    • usb: typec: ucsi: Fix connector check on init (git-fixes).
    • usb: typec: ucsi: Fix race between typec_switch and role_switch (git-fixes).
    • usb: typec: ucsi: Limit read size on v1.2 (stable-fixes).
    • usb: typec: ucsi: simplify partner's PD caps registration (git-fixes).
    • USB: UAS: return ENODEV when submit urbs fail with device not attached (stable-fixes).
    • usb: udc: remove warning when queue disabled ep (stable-fixes).
    • usb: xhci: Add error handling in xhci_map_urb_for_dma (git-fixes).
    • usb: xhci: correct return value in case of STS_HCE (git-fixes).
    • usb: xhci: Implement xhci_handshake_check_state() helper.
    • usb: xhci-plat: Do not include xhci.h (stable-fixes).
    • vboxsf: Avoid an spurious warning if load_nls_xxx() fails (git-fixes).
    • vboxsf: explicitly deny setlease attempts (stable-fixes).
    • vdpa/mlx5: Allow CVQ size changes (git-fixes).
    • vdpa_sim: reset must not run (git-fixes).
    • veth: try harder when allocating queue memory (git-fixes).
    • vhost: Add smp_rmb() in vhost_enable_notify() (git-fixes).
    • vhost: Add smp_rmb() in vhost_vq_avail_empty() (git-fixes).
    • virtio-blk: Ensure no requests in virtqueues before deleting vqs (git-fixes).
    • virtio_net: Do not send RSS key if it is not supported (git-fixes).
    • virtio: treat alloc_dax() -EOPNOTSUPP failure as non-fatal (bsc#1223944).
    • VMCI: Fix an error handling path in vmci_guest_probe_device() (git-fixes).
    • VMCI: Fix possible memcpy() run-time warning in vmci_datagram_invoke_guest_handler() (stable-fixes).
    • vmci: prevent speculation leaks by sanitizing event in event_deliver() (git-fixes).
    • vsock/virtio: fix packet delivery to tap device (git-fixes).
    • watchdog: bd9576: Drop 'always-running' property (git-fixes).
    • watchdog: cpu5wdt.c: Fix use-after-free bug caused by cpu5wdt_trigger (git-fixes).
    • watchdog: rti_wdt: Set min_hw_heartbeat_ms to accommodate a safety margin (git-fixes).
    • watchdog: sa1100: Fix PTR_ERR_OR_ZERO() vs NULL check in sa1100dog_probe() (git-fixes).
    • wifi: ar5523: enable proper endpoint verification (git-fixes).
    • wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger() (git-fixes).
    • wifi: ath10k: poll service ready message before failing (git-fixes).
    • wifi: ath10k: populate board data for WCN3990 (git-fixes).
    • wifi: ath11k: decrease MHI channel buffer length to 8KB (bsc#1207948).
    • wifi: ath11k: do not force enable power save on non-running vdevs (git-fixes).
    • wifi: ath12k: fix out-of-bound access of qmi_invoke_handler() (git-fixes).
    • wifi: ath9k: fix LNA selection in ath_ant_try_scan() (stable-fixes).
    • wifi: brcmfmac: Add DMI nvram filename quirk for ACEPC W5 Pro (stable-fixes).
    • wifi: brcmfmac: add per-vendor feature detection callback (stable-fixes).
    • wifi: brcmfmac: cfg80211: Use WSEC to set SAE password (stable-fixes).
    • wifi: brcmfmac: Demote vendor-specific attach/detach messages to info (git-fixes).
    • wifi: brcmfmac: pcie: handle randbuf allocation failure (git-fixes).
    • wifi: carl9170: add a proper sanity check for endpoints (git-fixes).
    • wifi: carl9170: re-fix fortified-memset warning (git-fixes).
    • wifi: cfg80211: check A-MSDU format more carefully (stable-fixes).
    • wifi: cfg80211: fix rdev_dump_mpp() arguments order (stable-fixes).
    • wifi: ieee80211: fix ieee80211_mle_basic_sta_prof_size_ok() (git-fixes).
    • wifi: iwlwifi: fw: do not always use FW dump trig (git-fixes).
    • wifi: iwlwifi: fw: fix compile w/o CONFIG_ACPI (git-fixes).
    • wifi: iwlwifi: mvm: allocate STA links only for active links (git-fixes).
    • wifi: iwlwifi: mvm: fix active link counting during recovery (git-fixes).
    • wifi: iwlwifi: mvm: fix check in iwl_mvm_sta_fw_id_mask (git-fixes).
    • wifi: iwlwifi: mvm: guard against invalid STA ID on removal (stable-fixes).
    • wifi: iwlwifi: mvm: include link ID when releasing frames (git-fixes).
    • wifi: iwlwifi: mvm: init vif works only once (git-fixes).
    • wifi: iwlwifi: mvm: remove old PASN station when adding a new one (git-fixes).
    • wifi: iwlwifi: mvm: return uid from iwl_mvm_build_scan_cmd (git-fixes).
    • wifi: iwlwifi: mvm: rfi: fix potential response leaks (git-fixes).
    • wifi: iwlwifi: mvm: select STA mask only for active links (git-fixes).
    • wifi: iwlwifi: mvm: use correct address 3 in A-MSDU (stable-fixes).
    • wifi: iwlwifi: pcie: Add the PCI device id for new hardware (stable-fixes).
    • wifi: iwlwifi: pcie: fix RB status reading (stable-fixes).
    • wifi: iwlwifi: read txq->read_ptr under lock (stable-fixes).
    • wifi: iwlwifi: reconfigure TLC during HW restart (git-fixes).
    • wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes (stable-fixes).
    • wifi: mac80211: clean up assignments to pointer cache (stable-fixes).
    • wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc (stable-fixes).
    • wifi: mac80211: fix prep_connection error path (stable-fixes).
    • wifi: mac80211: fix unaligned le16 access (git-fixes).
    • wifi: mac80211_hwsim: init peer measurement result (git-fixes).
    • wifi: mac80211: only call drv_sta_rc_update for uploaded stations (stable-fixes).
    • wifi: mac80211: remove link before AP (git-fixes).
    • wifi: mt76: mt7603: add wpdma tx eof flag for PSE client reset (git-fixes).
    • wifi: mt76: mt7603: fix tx queue of loopback packets (git-fixes).
    • wifi: mt76: mt7915: workaround too long expansion sparse warnings (git-fixes).
    • wifi: mt76: mt7996: add locking for accessing mapped registers (stable-fixes).
    • wifi: mt76: mt7996: disable AMSDU for non-data frames (stable-fixes).
    • wifi: mwl8k: initialize cmd->addr[] properly (git-fixes).
    • wifi: nl80211: do not free NULL coalescing rule (git-fixes).
    • wifi: rtw88: 8821cu: Fix connection failure (stable-fixes).
    • wifi: rtw88: Add missing VID/PIDs for 8811CU and 8821CU (stable-fixes).
    • wifi: rtw89: fix null pointer access when abort scan (stable-fixes).
    • wifi: rtw89: pci: correct TX resource checking for PCI DMA channel of firmware command (git-fixes).
    • wifi: rtw89: pci: enlarge RX DMA buffer to consider size of RX descriptor (stable-fixes).
    • wireguard: netlink: access device through ctx instead of peer (git-fixes).
    • wireguard: netlink: check for dangling peer via is_dead instead of empty list (git-fixes).
    • wireguard: receive: annotate data-race around receiving_counter.counter (git-fixes).
    • Workaround broken chacha crypto fallback (bsc#1218205).
    • x86/bugs: Fix BHI retpoline check (git-fixes).
    • x86/bugs: Fix the SRSO mitigation on Zen3/4 (git-fixes).
    • x86/bugs: Remove default case for fully switched enums (git-fixes).
    • x86/calldepth: Rename __x86_return_skl() to call_depth_return_thunk() (git-fixes).
    • x86/coco: Require seeding RNG with RDRAND on CoCo systems (git-fixes).
    • x86/cpu: Add model number for Intel Arrow Lake mobile processor (git-fixes).
    • x86/CPU/AMD: Add models 0x10-0x1f to the Zen5 range (git-fixes).
    • x86/CPU/AMD: Update the Zenbleed microcode revisions (git-fixes).
    • x86/cpufeatures: Fix dependencies for GFNI, VAES, and VPCLMULQDQ (git-fixes).
    • x86/efistub: Add missing boot_params for mixed mode compat entry (git-fixes).
    • x86/efistub: Call mixed mode boot services on the firmware's stack (git-fixes).
    • x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD (git-fixes).
    • x86/hyperv: Allow 15-bit APIC IDs for VTL platforms (git-fixes).
    • x86/hyperv: Use per cpu initial stack for vtl context (git-fixes).
    • x86/Kconfig: Remove CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT (git-fixes).
    • x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y (git-fixes).
    • x86/kvm/Kconfig: Have KVM_AMD_SEV select ARCH_HAS_CC_PLATFORM (git-fixes).
    • x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() (git-fixes).
    • x86/nmi: Fix the inverse 'in NMI handler' check (git-fixes).
    • x86/nospec: Refactor UNTRAIN_RET[_*] (git-fixes).
    • x86/pm: Work around false positive kmemleak report in msr_build_context() (git-fixes).
    • x86/purgatory: Switch to the position-independent small code model (git-fixes).
    • x86/rethunk: Use SYM_CODE_START[_LOCAL]_NOALIGN macros (git-fixes).
    • x86/retpoline: Add NOENDBR annotation to the SRSO dummy return thunk (git-fixes).
    • x86/retpoline: Do the necessary fixup to the Zen3/4 srso return thunk for !SRSO (git-fixes).
    • x86/srso: Disentangle rethunk-dependent options (git-fixes).
    • x86/srso: Fix unret validation dependencies (git-fixes).
    • x86/srso: Improve i-cache locality for alias mitigation (git-fixes).
    • x86/srso: Print actual mitigation if requested mitigation isn't possible (git-fixes).
    • x86/srso: Remove 'pred_cmd' label (git-fixes).
    • x86/srso: Unexport untraining functions (git-fixes).
    • x86/xen: Add some null pointer checking to smp.c (git-fixes).
    • x86/xen: attempt to inflate the memory balloon on PVH (git-fixes).
    • xdp, bonding: Fix feature flags when there are no slave devs anymore (git-fixes).
    • xen/events: drop xen_allocate_irqs_dynamic() (git-fixes).
    • xen/events: fix error code in xen_bind_pirq_msi_to_irq() (git-fixes).
    • xen/events: increment refcnt only if event channel is refcounted (git-fixes).
    • xen/events: modify internal [un]bind interfaces (git-fixes).
    • xen/events: reduce externally visible helper functions (git-fixes).
    • xen/events: remove some simple helpers from events_base.c (git-fixes).
    • xen: evtchn: Allow shared registration of IRQ handers (git-fixes).
    • xen/evtchn: avoid WARN() when unbinding an event channel (git-fixes).
    • xen-netfront: Add missing skb_mark_for_recycle (git-fixes).
    • xfs: add lock protection when remove perag from radix tree (git-fixes).
    • xfs: allow extent free intents to be retried (git-fixes).
    • xfs: fix perag leak when growfs fails (git-fixes).
    • xfs: force all buffers to be written during btree bulk load (git-fixes).
    • xfs: make xchk_iget safer in the presence of corrupt inode btrees (git-fixes).
    • xfs: pass the xfs_defer_pending object to iop_recover (git-fixes).
    • xfs: recompute growfsrtfree transaction reservation while growing rt volume (git-fixes).
    • xfs: transfer recovered intent item ownership in ->iop_recover (git-fixes).
    • xfs: use xfs_defer_pending objects to recover intent items (git-fixes).
    • xhci: add helper that checks for unhandled events on a event ring (git-fixes).
    • xhci: remove unnecessary event_ring_deq parameter from xhci_handle_event() (git-fixes).
    • xhci: Simplify event ring dequeue pointer update for port change events (git-fixes).
    • xhci: simplify event ring dequeue tracking for transfer events (git-fixes).


    Advisory IDSUSE-RU-2024:2214-1
    ReleasedTue Jun 25 17:11:26 2024
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1225598
    Description:

    This update for util-linux fixes the following issue:

    • Fix hang of lscpu -e (bsc#1225598)


    Advisory IDSUSE-RU-2024:2215-1
    ReleasedTue Jun 25 17:15:25 2024
    SummaryRecommended update for python-azure-agent
    Typerecommended
    Severitymoderate
    References1225946
    Description:

    This update for python-azure-agent fixes the following issue:

    • Use the -Z option for mv and cp in the posttrans to properly handle SELinux context (bsc#1225946)


    Advisory IDSUSE-RU-2024:2222-1
    ReleasedTue Jun 25 18:10:29 2024
    SummaryRecommended update for cloud-init
    Typerecommended
    Severityimportant
    References1219680,1223469
    Description:

    This update for cloud-init fixes the following issues:

    • Brute force approach to skip renames if the device is already present (bsc#1219680)
    • Handle the existence of /usr/etc/sudoers to search for the expected include location (bsc#1223469)
    • Do not enable cloud-init on systems where there is no DMI just because no data source has been found. No data source means cloud-init will not run.


    Advisory IDSUSE-RU-2024:2225-1
    ReleasedWed Jun 26 08:18:23 2024
    SummaryRecommended update for kdump
    Typerecommended
    Severityimportant
    References1191410,1222228,1224214
    Description:

    This update for kdump fixes the following issues:

    • Use fadump=nocma when user data not filtered out (bsc#1224214)
    • Differentiate between uninstall and upgrade in postun/preun (bsc#1191410)
    • Return success from pre, post, preun and postun scriplets (bsc#1222228)
    • Update calibrate values for SLE-15-SP6


    Advisory IDSUSE-RU-2024:2234-1
    ReleasedWed Jun 26 12:54:27 2024
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1224400
    Description:

    This update for suse-module-tools fixes the following issue:

    • Version update, udevrules: activate CPUs on hotplug for s390, too (bsc#1224400)


    Advisory IDSUSE-RU-2024:2239-1
    ReleasedWed Jun 26 13:09:10 2024
    SummaryRecommended update for systemd
    Typerecommended
    Severitycritical
    References1226415
    Description:

    This update for systemd contains the following fixes:

    • testsuite: move a misplaced %endif

    • Do not remove existing configuration files in /etc. If these files were modified on the systemd, that may cause unwanted side effects (bsc#1226415).

    • Import upstream commit (merge of v254.13) Use the pty slave fd opened from the namespace when transient service is running in a container. This revert the backport of the broken commit until a fix is released in the v254-stable tree.

    • Import upstream commit (merge of v254.11) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/e8d77af4240894da620de74fbc7823aaaa448fef...85db84ee440eac202c4b5507e96e1704269179bc


    Advisory IDSUSE-RU-2024:2241-1
    ReleasedWed Jun 26 15:37:28 2024
    SummaryRecommended update for wicked
    Typerecommended
    Severityimportant
    References1218668
    Description:

    This update for wicked fixes the following issues:

    • Fix VLANs/bonds randomly not coming up after reboot or wicked restart. [bsc#1218668]