From sle-security-updates at lists.suse.com Mon Jul 3 13:09:55 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 3 Jul 2017 21:09:55 +0200 (CEST) Subject: SUSE-SU-2017:1760-1: important: Security update for unrar Message-ID: <20170703190955.9AA6FFFD9@maintenance.suse.de> SUSE Security Update: Security update for unrar ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1760-1 Rating: important References: #1045315 Cross-References: CVE-2012-6706 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for unrar fixes the following issues: - CVE-2012-6706: decoding malicious RAR files could have lead to memory corruption or code execution. (bsc#1045315). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-unrar-13191=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-unrar-13191=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-unrar-13191=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-unrar-13191=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-unrar-13191=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): unrar-3.80.2-4.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): unrar-3.80.2-4.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): unrar-3.80.2-4.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): unrar-debuginfo-3.80.2-4.1 unrar-debugsource-3.80.2-4.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): unrar-debuginfo-3.80.2-4.1 unrar-debugsource-3.80.2-4.1 References: https://www.suse.com/security/cve/CVE-2012-6706.html https://bugzilla.suse.com/1045315 From sle-security-updates at lists.suse.com Mon Jul 3 13:11:23 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 3 Jul 2017 21:11:23 +0200 (CEST) Subject: SUSE-SU-2017:1763-1: important: Security update for clamav Message-ID: <20170703191123.8118AFFD6@maintenance.suse.de> SUSE Security Update: Security update for clamav ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1763-1 Rating: important References: #1045490 #815106 Cross-References: CVE-2012-6706 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for clamav fixes the following issues: Security issue fixed: - CVE-2012-6706: Fixed an arbitrary memory write in VMSF_DELTA filter in libclamunrar (bsc#1045490) Non security issue fixed: - Fix permissions of /var/spool/amavis. (bsc#815106) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-clamav-13190=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-clamav-13190=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-clamav-13190=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-clamav-13190=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-clamav-13190=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): clamav-0.99.2-0.19.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): clamav-0.99.2-0.19.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): clamav-0.99.2-0.19.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): clamav-debuginfo-0.99.2-0.19.1 clamav-debugsource-0.99.2-0.19.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): clamav-debuginfo-0.99.2-0.19.1 clamav-debugsource-0.99.2-0.19.1 References: https://www.suse.com/security/cve/CVE-2012-6706.html https://bugzilla.suse.com/1045490 https://bugzilla.suse.com/815106 From sle-security-updates at lists.suse.com Tue Jul 4 13:10:10 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:10:10 +0200 (CEST) Subject: SUSE-SU-2017:1769-1: moderate: Security update for libquicktime Message-ID: <20170704191010.40BC2FFD9@maintenance.suse.de> SUSE Security Update: Security update for libquicktime ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1769-1 Rating: moderate References: #1044000 #1044002 #1044006 #1044008 #1044009 #1044077 #1044122 Cross-References: CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125 CVE-2017-9126 CVE-2017-9127 CVE-2017-9128 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: This update for libquicktime fixes the following issues: * CVE-2017-9122: A DoS in quicktime_read_moov function in moov.c via acrafted mp4 file was fixed. (bsc#1044077) * CVE-2017-9123: An invalid memory read in lqt_frame_duration via a crafted mp4 file was fixed. (bsc#1044009) * CVE-2017-9124: A NULL pointer dereference in quicktime_match_32 via a crafted mp4 file was fixed. (bsc#1044008) * CVE-2017-9125: A DoS in lqt_frame_duration function in lqt_quicktime.c via crafted mp4 file was fixed. (bsc#1044122) * CVE-2017-9126: A heap-based buffer overflow in quicktime_read_dref_table via a crafted mp4 file was fixed. (bsc#1044006) * CVE-2017-9127: A heap-based buffer overflow in quicktime_user_atoms_read_atom via a crafted mp4 file was fixed. (bsc#1044002) * CVE-2017-9128: A heap-based buffer over-read in quicktime_video_width via a crafted mp4 file was fixed. (bsc#1044000) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1107=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1107=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1107=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1107=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libquicktime-debugsource-1.2.4-13.1 libquicktime-devel-1.2.4-13.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libquicktime-debugsource-1.2.4-13.1 libquicktime0-1.2.4-13.1 libquicktime0-debuginfo-1.2.4-13.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libquicktime-debugsource-1.2.4-13.1 libquicktime0-1.2.4-13.1 libquicktime0-debuginfo-1.2.4-13.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libquicktime-debugsource-1.2.4-13.1 libquicktime0-1.2.4-13.1 libquicktime0-debuginfo-1.2.4-13.1 References: https://www.suse.com/security/cve/CVE-2017-9122.html https://www.suse.com/security/cve/CVE-2017-9123.html https://www.suse.com/security/cve/CVE-2017-9124.html https://www.suse.com/security/cve/CVE-2017-9125.html https://www.suse.com/security/cve/CVE-2017-9126.html https://www.suse.com/security/cve/CVE-2017-9127.html https://www.suse.com/security/cve/CVE-2017-9128.html https://bugzilla.suse.com/1044000 https://bugzilla.suse.com/1044002 https://bugzilla.suse.com/1044006 https://bugzilla.suse.com/1044008 https://bugzilla.suse.com/1044009 https://bugzilla.suse.com/1044077 https://bugzilla.suse.com/1044122 From sle-security-updates at lists.suse.com Tue Jul 4 13:11:17 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:11:17 +0200 (CEST) Subject: SUSE-SU-2017:1770-1: important: Security update for xen Message-ID: <20170704191117.1A98BFFD6@maintenance.suse.de> SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1770-1 Rating: important References: #1014136 #1026236 #1027519 #1031460 #1032148 #1034845 #1036470 #1037243 #1042160 #1042863 #1042882 #1042893 #1042915 #1042924 #1042931 #1042938 #1043074 #1043297 Cross-References: CVE-2017-8112 CVE-2017-8309 CVE-2017-8905 CVE-2017-9330 CVE-2017-9374 CVE-2017-9503 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves 6 vulnerabilities and has 12 fixes is now available. Description: This update for xen fixes several issues. These security issues were fixed: - blkif responses leaked backend stack data, which allowed unprivileged guest to obtain sensitive information from the host or other guests (XSA-216, bsc#1042863) - Page transfer might have allowed PV guest to elevate privilege (XSA-217, bsc#1042882) - Races in the grant table unmap code allowed for informations leaks and potentially privilege escalation (XSA-218, bsc#1042893) - Insufficient reference counts during shadow emulation allowed a malicious pair of guest to elevate their privileges to the privileges that XEN runs under (XSA-219, bsc#1042915) - Stale P2M mappings due to insufficient error checking allowed malicious guest to leak information or elevate privileges (XSA-222, bsc#1042931) - Grant table operations mishandled reference counts allowing malicious guests to escape (XSA-224, bsc#1042938) - CVE-2017-9330: USB OHCI Emulation in qemu allowed local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value (bsc#1042160) - CVE-2017-8309: Memory leak in the audio/audio.c allowed remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture (bsc#1037243) - CVE-2017-8905: Xen a failsafe callback, which might have allowed PV guest OS users to execute arbitrary code on the host OS (XSA-215, bsc#1034845). - CVE-2017-9503: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to a null pointer dereference issue which allowed a privileged user inside guest to crash the Qemu process on the host resulting in DoS (bsc#1043297) - CVE-2017-9374: Missing free of 's->ipacket', causes a host memory leak, allowing for DoS (bsc#1043074) - CVE-2017-8112: hw/scsi/vmw_pvscsi.c allowed local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count (bsc#1036470) - Missing NULL pointer check in event channel poll allows guests to DoS the host (XSA-221, bsc#1042924) These non-security issues were fixed: - bsc#1032148: Ensure that time doesn't goes backwards during live migration of HVM domU - bsc#1031460: Fixed DomU Live Migration - bsc#1014136: Fixed kdump SLES12-SP2 - bsc#1026236: Equalized paravirtualized vs. fully virtualized migration speed Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-xen-13193=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-xen-13193=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-xen-13193=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): xen-devel-4.4.4_20-60.3 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): xen-kmp-default-4.4.4_20_3.0.101_104-60.3 xen-libs-4.4.4_20-60.3 xen-tools-domU-4.4.4_20-60.3 - SUSE Linux Enterprise Server 11-SP4 (x86_64): xen-4.4.4_20-60.3 xen-doc-html-4.4.4_20-60.3 xen-libs-32bit-4.4.4_20-60.3 xen-tools-4.4.4_20-60.3 - SUSE Linux Enterprise Server 11-SP4 (i586): xen-kmp-pae-4.4.4_20_3.0.101_104-60.3 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64): xen-debuginfo-4.4.4_20-60.3 xen-debugsource-4.4.4_20-60.3 References: https://www.suse.com/security/cve/CVE-2017-8112.html https://www.suse.com/security/cve/CVE-2017-8309.html https://www.suse.com/security/cve/CVE-2017-8905.html https://www.suse.com/security/cve/CVE-2017-9330.html https://www.suse.com/security/cve/CVE-2017-9374.html https://www.suse.com/security/cve/CVE-2017-9503.html https://bugzilla.suse.com/1014136 https://bugzilla.suse.com/1026236 https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1031460 https://bugzilla.suse.com/1032148 https://bugzilla.suse.com/1034845 https://bugzilla.suse.com/1036470 https://bugzilla.suse.com/1037243 https://bugzilla.suse.com/1042160 https://bugzilla.suse.com/1042863 https://bugzilla.suse.com/1042882 https://bugzilla.suse.com/1042893 https://bugzilla.suse.com/1042915 https://bugzilla.suse.com/1042924 https://bugzilla.suse.com/1042931 https://bugzilla.suse.com/1042938 https://bugzilla.suse.com/1043074 https://bugzilla.suse.com/1043297 From sle-security-updates at lists.suse.com Tue Jul 4 13:14:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:14:08 +0200 (CEST) Subject: SUSE-SU-2017:1771-1: moderate: Security update for sudo Message-ID: <20170704191408.E1924FFD9@maintenance.suse.de> SUSE Security Update: Security update for sudo ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1771-1 Rating: moderate References: #1045986 Cross-References: CVE-2017-1000368 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sudo fixes the following issues: - A regression in the fix for the CVE-2017-1000368 that broke sudo with the "requiretty" flag (bsc#1045986) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1105=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1105=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1105=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1105=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1105=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): sudo-debuginfo-1.8.10p3-10.13.1 sudo-debugsource-1.8.10p3-10.13.1 sudo-devel-1.8.10p3-10.13.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): sudo-1.8.10p3-10.13.1 sudo-debuginfo-1.8.10p3-10.13.1 sudo-debugsource-1.8.10p3-10.13.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): sudo-1.8.10p3-10.13.1 sudo-debuginfo-1.8.10p3-10.13.1 sudo-debugsource-1.8.10p3-10.13.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): sudo-1.8.10p3-10.13.1 sudo-debuginfo-1.8.10p3-10.13.1 sudo-debugsource-1.8.10p3-10.13.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): sudo-1.8.10p3-10.13.1 sudo-debuginfo-1.8.10p3-10.13.1 sudo-debugsource-1.8.10p3-10.13.1 References: https://www.suse.com/security/cve/CVE-2017-1000368.html https://bugzilla.suse.com/1045986 From sle-security-updates at lists.suse.com Tue Jul 4 13:15:00 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:15:00 +0200 (CEST) Subject: SUSE-SU-2017:1773-1: moderate: Security update for systemd Message-ID: <20170704191500.EEA56FFD6@maintenance.suse.de> SUSE Security Update: Security update for systemd ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1773-1 Rating: moderate References: #1004995 #1029102 #1029516 #1036873 #1038865 #1040258 #1040614 #1040942 #1043758 #982303 Cross-References: CVE-2017-9217 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that solves one vulnerability and has 9 fixes is now available. Description: This update for systemd fixes the following issues: Security issue fixed: - CVE-2017-9217: resolved: Fix null pointer p->question dereferencing that could lead to resolved aborting (bsc#1040614) The update also fixed several non-security bugs: - core/mount: Use the "-c" flag to not canonicalize paths when calling /bin/umount - automount: Handle expire_tokens when the mount unit changes its state (bsc#1040942) - automount: Rework propagation between automount and mount units - build: Make sure tmpfiles.d/systemd-remote.conf get installed when necessary - build: Fix systemd-journal-upload installation - basic: Detect XEN Dom0 as no virtualization (bsc#1036873) - virt: Make sure some errors are not ignored - fstab-generator: Do not skip Before= ordering for noauto mountpoints - fstab-gen: Do not convert device timeout into seconds when initializing JobTimeoutSec - core/device: Use JobRunningTimeoutSec= for device units (bsc#1004995) - fstab-generator: Apply the _netdev option also to device units (bsc#1004995) - job: Add JobRunningTimeoutSec for JOB_RUNNING state (bsc#1004995) - job: Ensure JobRunningTimeoutSec= survives serialization (bsc#1004995) - rules: Export NVMe WWID udev attribute (bsc#1038865) - rules: Introduce disk/by-id (model_serial) symbolic links for NVMe drives - rules: Add rules for NVMe devices - sysusers: Make group shadow support configurable (bsc#1029516) - core: When deserializing a unit, fully restore its cgroup state (bsc#1029102) - core: Introduce cg_mask_from_string()/cg_mask_to_string() - core:execute: Fix handling failures of calling fork() in exec_spawn() (bsc#1040258) - Fix systemd-sysv-convert when a package starts shipping service units (bsc#982303) The database might be missing when upgrading a package which was shipping no sysv init scripts nor unit files (at the time --save was called) but the new version start shipping unit files. - Disable group shadow support (bsc#1029516) - Only check signature job error if signature job exists (bsc#1043758) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1104=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1104=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1104=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1104=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1104=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libudev-devel-228-149.3 systemd-debuginfo-228-149.3 systemd-debugsource-228-149.3 systemd-devel-228-149.3 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libsystemd0-228-149.3 libsystemd0-debuginfo-228-149.3 libudev1-228-149.3 libudev1-debuginfo-228-149.3 systemd-228-149.3 systemd-debuginfo-228-149.3 systemd-debugsource-228-149.3 systemd-sysvinit-228-149.3 udev-228-149.3 udev-debuginfo-228-149.3 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): systemd-bash-completion-228-149.3 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libsystemd0-228-149.3 libsystemd0-debuginfo-228-149.3 libudev1-228-149.3 libudev1-debuginfo-228-149.3 systemd-228-149.3 systemd-debuginfo-228-149.3 systemd-debugsource-228-149.3 systemd-sysvinit-228-149.3 udev-228-149.3 udev-debuginfo-228-149.3 - SUSE Linux Enterprise Server 12-SP2 (noarch): systemd-bash-completion-228-149.3 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libsystemd0-32bit-228-149.3 libsystemd0-debuginfo-32bit-228-149.3 libudev1-32bit-228-149.3 libudev1-debuginfo-32bit-228-149.3 systemd-32bit-228-149.3 systemd-debuginfo-32bit-228-149.3 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libsystemd0-228-149.3 libsystemd0-32bit-228-149.3 libsystemd0-debuginfo-228-149.3 libsystemd0-debuginfo-32bit-228-149.3 libudev1-228-149.3 libudev1-32bit-228-149.3 libudev1-debuginfo-228-149.3 libudev1-debuginfo-32bit-228-149.3 systemd-228-149.3 systemd-32bit-228-149.3 systemd-debuginfo-228-149.3 systemd-debuginfo-32bit-228-149.3 systemd-debugsource-228-149.3 systemd-sysvinit-228-149.3 udev-228-149.3 udev-debuginfo-228-149.3 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): systemd-bash-completion-228-149.3 - OpenStack Cloud Magnum Orchestration 7 (x86_64): libsystemd0-228-149.3 libsystemd0-debuginfo-228-149.3 libudev1-228-149.3 libudev1-debuginfo-228-149.3 systemd-228-149.3 systemd-debuginfo-228-149.3 systemd-debugsource-228-149.3 systemd-sysvinit-228-149.3 udev-228-149.3 udev-debuginfo-228-149.3 References: https://www.suse.com/security/cve/CVE-2017-9217.html https://bugzilla.suse.com/1004995 https://bugzilla.suse.com/1029102 https://bugzilla.suse.com/1029516 https://bugzilla.suse.com/1036873 https://bugzilla.suse.com/1038865 https://bugzilla.suse.com/1040258 https://bugzilla.suse.com/1040614 https://bugzilla.suse.com/1040942 https://bugzilla.suse.com/1043758 https://bugzilla.suse.com/982303 From sle-security-updates at lists.suse.com Tue Jul 4 13:16:49 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:16:49 +0200 (CEST) Subject: SUSE-SU-2017:1774-1: important: Security update for qemu Message-ID: <20170704191649.B9368FFD9@maintenance.suse.de> SUSE Security Update: Security update for qemu ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1774-1 Rating: important References: #1016503 #1016504 #1017081 #1017084 #1020427 #1021741 #1025109 #1025311 #1028184 #1028656 #1030624 #1031142 #1032075 #1034866 #1034908 #1035406 #1035950 #1036211 #1037242 #1037334 #1037336 #1039495 #1042159 #1042800 #1042801 #1043073 #1043296 Cross-References: CVE-2016-10028 CVE-2016-10029 CVE-2016-9602 CVE-2016-9603 CVE-2017-5579 CVE-2017-5973 CVE-2017-5987 CVE-2017-6505 CVE-2017-7377 CVE-2017-7471 CVE-2017-7493 CVE-2017-7718 CVE-2017-7980 CVE-2017-8086 CVE-2017-8112 CVE-2017-8309 CVE-2017-8379 CVE-2017-8380 CVE-2017-9330 CVE-2017-9373 CVE-2017-9374 CVE-2017-9375 CVE-2017-9503 Affected Products: SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that solves 23 vulnerabilities and has four fixes is now available. Description: This update for qemu fixes several issues. These security issues were fixed: - CVE-2017-9330: USB OHCI Emulation in qemu allowed local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value (bsc#1042159). - CVE-2017-8379: Memory leak in the keyboard input event handlers support allowed local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events (bsc#1037334). - CVE-2017-8309: Memory leak in the audio/audio.c allowed remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture (bsc#1037242). - CVE-2017-7493: The VirtFS, host directory sharing via Plan 9 File System(9pfs) support, was vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could have used this flaw to escalate their privileges inside guest (bsc#1039495). - CVE-2017-7377: The v9fs_create and v9fs_lcreate functions in hw/9pfs/9p.c allowed local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid (bsc#1032075). - CVE-2017-8086: A memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c allowed local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable (bsc#1035950). - CVE-2017-5973: A infinite loop while doing control transfer in xhci_kick_epctx allowed privileged user inside the guest to crash the host process resulting in DoS (bsc#1025109) - CVE-2017-5987: The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c allowed local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer (bsc#1025311). - CVE-2017-6505: The ohci_service_ed_list function in hw/usb/hcd-ohci.c allowed local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors (bsc#1028184) - CVE-2016-9603: A privileged user within the guest VM could have caused a heap overflow in the device model process, potentially escalating their privileges to that of the device model process (bsc#1028656) - CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions (bsc#1034908) - CVE-2017-7980: An out-of-bounds r/w access issues in the Cirrus CLGD 54xx VGA Emulator support allowed privileged user inside guest to use this flaw to crash the Qemu process resulting in DoS or potentially execute arbitrary code on a host with privileges of Qemu process on the host (bsc#1035406) - CVE-2017-8112: hw/scsi/vmw_pvscsi.c allowed local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count (bsc#1036211). - CVE-2017-9375: The USB xHCI controller emulator support was vulnerable to an infinite recursive call loop issue, which allowed a privileged user inside guest to crash the Qemu process resulting in DoS (bsc#1042800). - CVE-2017-9374: Missing free of 's->ipacket', causes a host memory leak, allowing for DoS (bsc#1043073). - CVE-2017-9373: The IDE AHCI Emulation support was vulnerable to a host memory leakage issue, which allowed a privileged user inside guest to leak host memory resulting in DoS (bsc#1042801). - CVE-2017-8380: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to an out-of-bounds read access issue which allowed a privileged user inside guest to read host memory resulting in DoS (bsc#1037336). - CVE-2016-9602: The VirtFS host directory sharing via Plan 9 File System(9pfs) support was vulnerable to an improper link following issue which allowed a privileged user inside guest to access host file system beyond the shared folder and potentially escalating their privileges on a host (bsc#1020427). - CVE-2017-7471: The VirtFS host directory sharing via Plan 9 File System(9pfs) support was vulnerable to an improper access control issue which allowed a privileged user inside guest to access host file system beyond the shared folder and potentially escalating their privileges on a host (bsc#1034866). - Fix privilege escalation in TCG mode of QEMU. This is not considered a security issue by the upstream project, but is included as additional hardening (bsc#1030624) - Fix potential DoS in virtfs - CVE-2016-10028: The Virtio GPU Device emulator support was vulnerable to an out of bounds memory access issue allowing a guest user to crash the Qemu process instance on a host, resulting in DoS (bsc#1017084, bsc#1016503) - CVE-2016-10029: The Virtio GPU Device emulator support was vulnerable to an OOB read issue allowing a guest user to crash the Qemu process instance resulting in Dos (bsc#1017081, bsc#1016504) - CVE-2017-5579: The 16550A UART serial device emulation support was vulnerable to a memory leakage issue allowing a privileged user to cause a DoS and/or potentially crash the Qemu process on the host (bsc#1021741) - CVE-2017-9503: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to a null pointer dereference issue which allowed a privileged user inside guest to crash the Qemu process on the host resulting in DoS (bsc#1043296). This non-security issue was fixed: - Enable MONITOR/MWAIT support for guests (bsc#1031142) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1102=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1102=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1102=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): qemu-2.6.2-41.16.1 qemu-arm-2.6.2-41.16.1 qemu-arm-debuginfo-2.6.2-41.16.1 qemu-block-curl-2.6.2-41.16.1 qemu-block-curl-debuginfo-2.6.2-41.16.1 qemu-block-rbd-2.6.2-41.16.1 qemu-block-rbd-debuginfo-2.6.2-41.16.1 qemu-block-ssh-2.6.2-41.16.1 qemu-block-ssh-debuginfo-2.6.2-41.16.1 qemu-debugsource-2.6.2-41.16.1 qemu-guest-agent-2.6.2-41.16.1 qemu-guest-agent-debuginfo-2.6.2-41.16.1 qemu-lang-2.6.2-41.16.1 qemu-tools-2.6.2-41.16.1 qemu-tools-debuginfo-2.6.2-41.16.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): qemu-ipxe-1.0.0-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): qemu-2.6.2-41.16.1 qemu-block-curl-2.6.2-41.16.1 qemu-block-curl-debuginfo-2.6.2-41.16.1 qemu-block-ssh-2.6.2-41.16.1 qemu-block-ssh-debuginfo-2.6.2-41.16.1 qemu-debugsource-2.6.2-41.16.1 qemu-guest-agent-2.6.2-41.16.1 qemu-guest-agent-debuginfo-2.6.2-41.16.1 qemu-lang-2.6.2-41.16.1 qemu-tools-2.6.2-41.16.1 qemu-tools-debuginfo-2.6.2-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 x86_64): qemu-block-rbd-2.6.2-41.16.1 qemu-block-rbd-debuginfo-2.6.2-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (ppc64le): qemu-ppc-2.6.2-41.16.1 qemu-ppc-debuginfo-2.6.2-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64): qemu-arm-2.6.2-41.16.1 qemu-arm-debuginfo-2.6.2-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): qemu-kvm-2.6.2-41.16.1 qemu-x86-2.6.2-41.16.1 - SUSE Linux Enterprise Server 12-SP2 (noarch): qemu-ipxe-1.0.0-41.16.1 qemu-seabios-1.9.1-41.16.1 qemu-sgabios-8-41.16.1 qemu-vgabios-1.9.1-41.16.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): qemu-2.6.2-41.16.1 qemu-block-curl-2.6.2-41.16.1 qemu-block-curl-debuginfo-2.6.2-41.16.1 qemu-debugsource-2.6.2-41.16.1 qemu-kvm-2.6.2-41.16.1 qemu-tools-2.6.2-41.16.1 qemu-tools-debuginfo-2.6.2-41.16.1 qemu-x86-2.6.2-41.16.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): qemu-ipxe-1.0.0-41.16.1 qemu-seabios-1.9.1-41.16.1 qemu-sgabios-8-41.16.1 qemu-vgabios-1.9.1-41.16.1 References: https://www.suse.com/security/cve/CVE-2016-10028.html https://www.suse.com/security/cve/CVE-2016-10029.html https://www.suse.com/security/cve/CVE-2016-9602.html https://www.suse.com/security/cve/CVE-2016-9603.html https://www.suse.com/security/cve/CVE-2017-5579.html https://www.suse.com/security/cve/CVE-2017-5973.html https://www.suse.com/security/cve/CVE-2017-5987.html https://www.suse.com/security/cve/CVE-2017-6505.html https://www.suse.com/security/cve/CVE-2017-7377.html https://www.suse.com/security/cve/CVE-2017-7471.html https://www.suse.com/security/cve/CVE-2017-7493.html https://www.suse.com/security/cve/CVE-2017-7718.html https://www.suse.com/security/cve/CVE-2017-7980.html https://www.suse.com/security/cve/CVE-2017-8086.html https://www.suse.com/security/cve/CVE-2017-8112.html https://www.suse.com/security/cve/CVE-2017-8309.html https://www.suse.com/security/cve/CVE-2017-8379.html https://www.suse.com/security/cve/CVE-2017-8380.html https://www.suse.com/security/cve/CVE-2017-9330.html https://www.suse.com/security/cve/CVE-2017-9373.html https://www.suse.com/security/cve/CVE-2017-9374.html https://www.suse.com/security/cve/CVE-2017-9375.html https://www.suse.com/security/cve/CVE-2017-9503.html https://bugzilla.suse.com/1016503 https://bugzilla.suse.com/1016504 https://bugzilla.suse.com/1017081 https://bugzilla.suse.com/1017084 https://bugzilla.suse.com/1020427 https://bugzilla.suse.com/1021741 https://bugzilla.suse.com/1025109 https://bugzilla.suse.com/1025311 https://bugzilla.suse.com/1028184 https://bugzilla.suse.com/1028656 https://bugzilla.suse.com/1030624 https://bugzilla.suse.com/1031142 https://bugzilla.suse.com/1032075 https://bugzilla.suse.com/1034866 https://bugzilla.suse.com/1034908 https://bugzilla.suse.com/1035406 https://bugzilla.suse.com/1035950 https://bugzilla.suse.com/1036211 https://bugzilla.suse.com/1037242 https://bugzilla.suse.com/1037334 https://bugzilla.suse.com/1037336 https://bugzilla.suse.com/1039495 https://bugzilla.suse.com/1042159 https://bugzilla.suse.com/1042800 https://bugzilla.suse.com/1042801 https://bugzilla.suse.com/1043073 https://bugzilla.suse.com/1043296 From sle-security-updates at lists.suse.com Tue Jul 4 13:21:09 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:21:09 +0200 (CEST) Subject: SUSE-SU-2017:1775-1: moderate: Security update for vim Message-ID: <20170704192109.4A763FFD9@maintenance.suse.de> SUSE Security Update: Security update for vim ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1775-1 Rating: moderate References: #1024724 Cross-References: CVE-2017-5953 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for vim fixes the following issues: - CVE-2017-5953: Fixed a possible overflow with corrupted spell file (bsc#1024724) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-vim-13194=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-vim-13194=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): gvim-7.2-8.20.8 vim-7.2-8.20.8 vim-base-7.2-8.20.8 vim-data-7.2-8.20.8 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): vim-debuginfo-7.2-8.20.8 vim-debugsource-7.2-8.20.8 References: https://www.suse.com/security/cve/CVE-2017-5953.html https://bugzilla.suse.com/1024724 From sle-security-updates at lists.suse.com Tue Jul 4 13:21:46 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:21:46 +0200 (CEST) Subject: SUSE-SU-2017:1777-1: moderate: Security update for freeradius-server Message-ID: <20170704192146.609F1FFD9@maintenance.suse.de> SUSE Security Update: Security update for freeradius-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1777-1 Rating: moderate References: #1041445 #912873 #935573 Cross-References: CVE-2015-4680 CVE-2017-9148 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for freeradius-server fixes the following issues: - CVE-2017-9148: Disable OpenSSL's internal session cache to mitigate authentication bypass. (bnc#1041445) - CVE-2015-4680: Add a configuration option to allow checking of all intermediate certificates for revocations. (bnc#935573) The following non security issue was fixed: - Cannot create table radpostauth because of deprecated TIMESTAMP(14) syntax. (bsc#912873) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-freeradius-server-13192=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-freeradius-server-13192=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-freeradius-server-13192=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): freeradius-server-devel-2.1.1-7.24.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): freeradius-server-libs-2.1.1-7.24.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): freeradius-server-2.1.1-7.24.1 freeradius-server-dialupadmin-2.1.1-7.24.1 freeradius-server-doc-2.1.1-7.24.1 freeradius-server-libs-2.1.1-7.24.1 freeradius-server-utils-2.1.1-7.24.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): freeradius-server-debuginfo-2.1.1-7.24.1 freeradius-server-debugsource-2.1.1-7.24.1 References: https://www.suse.com/security/cve/CVE-2015-4680.html https://www.suse.com/security/cve/CVE-2017-9148.html https://bugzilla.suse.com/1041445 https://bugzilla.suse.com/912873 https://bugzilla.suse.com/935573 From sle-security-updates at lists.suse.com Tue Jul 4 13:22:27 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 4 Jul 2017 21:22:27 +0200 (CEST) Subject: SUSE-SU-2017:1778-1: important: Security update for sudo Message-ID: <20170704192227.9EC78FFD6@maintenance.suse.de> SUSE Security Update: Security update for sudo ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1778-1 Rating: important References: #1045986 Cross-References: CVE-2017-1000368 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sudo fixes the following issues: - A regression in the fix for the CVE-2017-1000368 that broke sudo with the "requiretty" flag (bsc#1045986) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1106=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1106=1 - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1106=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1106=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1106=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): sudo-1.8.10p3-2.19.1 sudo-debuginfo-1.8.10p3-2.19.1 sudo-debugsource-1.8.10p3-2.19.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): sudo-1.8.10p3-2.19.1 sudo-debuginfo-1.8.10p3-2.19.1 sudo-debugsource-1.8.10p3-2.19.1 - SUSE Linux Enterprise Server for SAP 12 (x86_64): sudo-1.8.10p3-2.19.1 sudo-debuginfo-1.8.10p3-2.19.1 sudo-debugsource-1.8.10p3-2.19.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): sudo-1.8.10p3-2.19.1 sudo-debuginfo-1.8.10p3-2.19.1 sudo-debugsource-1.8.10p3-2.19.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): sudo-1.8.10p3-2.19.1 sudo-debuginfo-1.8.10p3-2.19.1 sudo-debugsource-1.8.10p3-2.19.1 References: https://www.suse.com/security/cve/CVE-2017-1000368.html https://bugzilla.suse.com/1045986 From sle-security-updates at lists.suse.com Wed Jul 5 13:09:38 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 5 Jul 2017 21:09:38 +0200 (CEST) Subject: SUSE-SU-2017:1783-1: moderate: Security update for postgresql94 Message-ID: <20170705190938.23071FFD9@maintenance.suse.de> SUSE Security Update: Security update for postgresql94 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1783-1 Rating: moderate References: #1029547 #1037603 #1037624 #1038293 Cross-References: CVE-2017-7484 CVE-2017-7485 CVE-2017-7486 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for postgresql93 fixes the following issues: - bsc#1029547: Fix tests with timezone 2017a - CVE-2017-7486: Restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options. (bsc#1037624) - CVE-2017-7485: Recognize PGREQUIRESSL variable again. (bsc#1038293) - CVE-2017-7484: Prevent exposure of statistical information via leaky operators. (bsc#1037603) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-postgresql94-13196=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-postgresql94-13196=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-postgresql94-13196=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): postgresql94-devel-9.4.12-0.22.3 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libecpg6-9.4.12-0.22.3 libpq5-9.4.12-0.22.3 postgresql94-9.4.12-0.22.3 postgresql94-contrib-9.4.12-0.22.3 postgresql94-docs-9.4.12-0.22.3 postgresql94-server-9.4.12-0.22.3 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libpq5-32bit-9.4.12-0.22.3 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): postgresql94-debuginfo-9.4.12-0.22.3 postgresql94-debugsource-9.4.12-0.22.3 postgresql94-libs-debuginfo-9.4.12-0.22.3 postgresql94-libs-debugsource-9.4.12-0.22.3 References: https://www.suse.com/security/cve/CVE-2017-7484.html https://www.suse.com/security/cve/CVE-2017-7485.html https://www.suse.com/security/cve/CVE-2017-7486.html https://bugzilla.suse.com/1029547 https://bugzilla.suse.com/1037603 https://bugzilla.suse.com/1037624 https://bugzilla.suse.com/1038293 From sle-security-updates at lists.suse.com Thu Jul 6 07:12:50 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 6 Jul 2017 15:12:50 +0200 (CEST) Subject: SUSE-SU-2017:1790-1: important: Recommended update for ncurses Message-ID: <20170706131250.619FCF433@maintenance.suse.de> SUSE Security Update: Recommended update for ncurses ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1790-1 Rating: important References: #1046853 #1046858 Cross-References: CVE-2017-10684 CVE-2017-10685 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for ncurses fixes the following issues: Security issues fixed: - CVE-2017-10684: Possible RCE via stack-based buffer overflow in the fmt_entry function. (bsc#1046858) - CVE-2017-10685: Possible RCE with format string vulnerability in the fmt_entry function. (bsc#1046853) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-ncurses-13197=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-ncurses-13197=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-ncurses-13197=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): ncurses-devel-5.6-92.1 tack-5.6-92.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (x86_64): ncurses-devel-32bit-5.6-92.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libncurses5-5.6-92.1 libncurses6-5.6-92.1 ncurses-devel-5.6-92.1 ncurses-utils-5.6-92.1 tack-5.6-92.1 terminfo-5.6-92.1 terminfo-base-5.6-92.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libncurses5-32bit-5.6-92.1 libncurses6-32bit-5.6-92.1 ncurses-devel-32bit-5.6-92.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libncurses5-x86-5.6-92.1 libncurses6-x86-5.6-92.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): ncurses-debuginfo-5.6-92.1 ncurses-debugsource-5.6-92.1 References: https://www.suse.com/security/cve/CVE-2017-10684.html https://www.suse.com/security/cve/CVE-2017-10685.html https://bugzilla.suse.com/1046853 https://bugzilla.suse.com/1046858 From sle-security-updates at lists.suse.com Thu Jul 6 07:13:41 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 6 Jul 2017 15:13:41 +0200 (CEST) Subject: SUSE-SU-2017:1792-1: moderate: Security update for libcares2 Message-ID: <20170706131341.844B2F39D@maintenance.suse.de> SUSE Security Update: Security update for libcares2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1792-1 Rating: moderate References: #1044946 Cross-References: CVE-2017-1000381 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP2 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libcares2 fixes the following issues: - CVE-2017-1000381: A NAPTR parser out of bounds access was fixed that could lead to crashes. (bsc#1044946) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1117=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1117=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1117=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1117=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1117=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64): libcares2-32bit-1.9.1-8.1 libcares2-debuginfo-32bit-1.9.1-8.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libcares-devel-1.9.1-8.1 libcares2-debuginfo-1.9.1-8.1 libcares2-debugsource-1.9.1-8.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libcares2-1.9.1-8.1 libcares2-debuginfo-1.9.1-8.1 libcares2-debugsource-1.9.1-8.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libcares2-1.9.1-8.1 libcares2-debuginfo-1.9.1-8.1 libcares2-debugsource-1.9.1-8.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libcares2-1.9.1-8.1 libcares2-32bit-1.9.1-8.1 libcares2-debuginfo-1.9.1-8.1 libcares2-debuginfo-32bit-1.9.1-8.1 libcares2-debugsource-1.9.1-8.1 References: https://www.suse.com/security/cve/CVE-2017-1000381.html https://bugzilla.suse.com/1044946 From sle-security-updates at lists.suse.com Thu Jul 6 07:14:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 6 Jul 2017 15:14:08 +0200 (CEST) Subject: SUSE-SU-2017:1793-1: moderate: Security update for libgcrypt Message-ID: <20170706131408.633BDF39D@maintenance.suse.de> SUSE Security Update: Security update for libgcrypt ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1793-1 Rating: moderate References: #1046607 Cross-References: CVE-2017-7526 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libgcrypt fixes the following issues: - CVE-2017-7526: Hardening a against local side-channel attack in RSA key handling has been added (bsc#1046607) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-libgcrypt-13198=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-libgcrypt-13198=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-libgcrypt-13198=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libgcrypt-devel-1.5.0-0.25.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): libgcrypt-devel-32bit-1.5.0-0.25.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libgcrypt11-1.5.0-0.25.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libgcrypt11-32bit-1.5.0-0.25.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libgcrypt11-x86-1.5.0-0.25.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): libgcrypt-debuginfo-1.5.0-0.25.1 libgcrypt-debugsource-1.5.0-0.25.1 References: https://www.suse.com/security/cve/CVE-2017-7526.html https://bugzilla.suse.com/1046607 From sle-security-updates at lists.suse.com Thu Jul 6 07:14:35 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 6 Jul 2017 15:14:35 +0200 (CEST) Subject: SUSE-SU-2017:1794-1: moderate: Security update for libgcrypt Message-ID: <20170706131435.22E85F39D@maintenance.suse.de> SUSE Security Update: Security update for libgcrypt ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1794-1 Rating: moderate References: #1046607 Cross-References: CVE-2017-7526 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libgcrypt fixes the following issues: - CVE-2017-7526: Hardening against a local side-channel attack in RSA key handling has been added (bsc#1046607) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1116=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1116=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1116=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1116=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1116=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libgcrypt-debugsource-1.6.1-16.42.1 libgcrypt-devel-1.6.1-16.42.1 libgcrypt-devel-debuginfo-1.6.1-16.42.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libgcrypt-debugsource-1.6.1-16.42.1 libgcrypt20-1.6.1-16.42.1 libgcrypt20-debuginfo-1.6.1-16.42.1 libgcrypt20-hmac-1.6.1-16.42.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libgcrypt-debugsource-1.6.1-16.42.1 libgcrypt20-1.6.1-16.42.1 libgcrypt20-debuginfo-1.6.1-16.42.1 libgcrypt20-hmac-1.6.1-16.42.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libgcrypt20-32bit-1.6.1-16.42.1 libgcrypt20-debuginfo-32bit-1.6.1-16.42.1 libgcrypt20-hmac-32bit-1.6.1-16.42.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libgcrypt-debugsource-1.6.1-16.42.1 libgcrypt20-1.6.1-16.42.1 libgcrypt20-32bit-1.6.1-16.42.1 libgcrypt20-debuginfo-1.6.1-16.42.1 libgcrypt20-debuginfo-32bit-1.6.1-16.42.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): libgcrypt-debugsource-1.6.1-16.42.1 libgcrypt20-1.6.1-16.42.1 libgcrypt20-debuginfo-1.6.1-16.42.1 References: https://www.suse.com/security/cve/CVE-2017-7526.html https://bugzilla.suse.com/1046607 From sle-security-updates at lists.suse.com Thu Jul 6 07:15:01 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 6 Jul 2017 15:15:01 +0200 (CEST) Subject: SUSE-SU-2017:1795-1: important: Security update for xen Message-ID: <20170706131501.D4F40F39D@maintenance.suse.de> SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1795-1 Rating: important References: #1014136 #1026236 #1027519 #1031460 #1032148 #1034845 #1036470 #1037243 #1042160 #1042863 #1042882 #1042893 #1042915 #1042924 #1042931 #1042938 #1043074 #1043297 Cross-References: CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10917 CVE-2017-10918 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-8112 CVE-2017-8309 CVE-2017-8905 CVE-2017-9330 CVE-2017-9374 CVE-2017-9503 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves 16 vulnerabilities and has two fixes is now available. Description: This update for xen fixes several issues. These security issues were fixed: - CVE-2017-9503: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to a null pointer dereference issue which allowed a privileged user inside guest to crash the Qemu process on the host resulting in DoS (bsc#1043297) - CVE-2017-9374: Missing free of 's->ipacket', causes a host memory leak, allowing for DoS (bsc#1043074) - CVE-2017-10911: blkif responses leaked backend stack data, which allowed unprivileged guest to obtain sensitive information from the host or other guests (XSA-216, bsc#1042863) - CVE-2017-10912: Page transfer might have allowed PV guest to elevate privilege (XSA-217, bsc#1042882) - CVE-2017-10913, CVE-2017-10914: Races in the grant table unmap code allowed for informations leaks and potentially privilege escalation (XSA-218, bsc#1042893) - CVE-2017-10915: Insufficient reference counts during shadow emulation allowed a malicious pair of guest to elevate their privileges to the privileges that XEN runs under (XSA-219, bsc#1042915) - CVE-2017-10917: Missing NULL pointer check in event channel poll allows guests to DoS the host (XSA-221, bsc#1042924) - CVE-2017-10918: Stale P2M mappings due to insufficient error checking allowed malicious guest to leak information or elevate privileges (XSA-222, bsc#1042931) - CVE-2017-10920, CVE-2017-10921, CVE-2017-10922: Grant table operations mishandled reference counts allowing malicious guests to escape (XSA-224, bsc#1042938) - CVE-2017-9330: USB OHCI Emulation in qemu allowed local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value (bsc#1042160) - CVE-2017-8309: Memory leak in the audio/audio.c allowed remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture (bsc#1037243) - CVE-2017-8112: hw/scsi/vmw_pvscsi.c allowed local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count (bsc#1036470) - CVE-2017-8905: Xen a failsafe callback, which might have allowed PV guest OS users to execute arbitrary code on the host OS (XSA-215, bsc#1034845). These non-security issues were fixed: - bsc#1031460: Fixed DomU Live Migration - bsc#1014136: Fixed kdump SLES12-SP2 - bsc#1026236: Equalized paravirtualized vs. fully virtualized migration speed - bsc#1032148: Ensure that time doesn't goes backwards during live migration of HVM domU - bsc#1027519: Included various upstream patches Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1118=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1118=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): xen-4.4.4_21-22.42.1 xen-debugsource-4.4.4_21-22.42.1 xen-doc-html-4.4.4_21-22.42.1 xen-kmp-default-4.4.4_21_k3.12.61_52.77-22.42.1 xen-kmp-default-debuginfo-4.4.4_21_k3.12.61_52.77-22.42.1 xen-libs-32bit-4.4.4_21-22.42.1 xen-libs-4.4.4_21-22.42.1 xen-libs-debuginfo-32bit-4.4.4_21-22.42.1 xen-libs-debuginfo-4.4.4_21-22.42.1 xen-tools-4.4.4_21-22.42.1 xen-tools-debuginfo-4.4.4_21-22.42.1 xen-tools-domU-4.4.4_21-22.42.1 xen-tools-domU-debuginfo-4.4.4_21-22.42.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): xen-4.4.4_21-22.42.1 xen-debugsource-4.4.4_21-22.42.1 xen-doc-html-4.4.4_21-22.42.1 xen-kmp-default-4.4.4_21_k3.12.61_52.77-22.42.1 xen-kmp-default-debuginfo-4.4.4_21_k3.12.61_52.77-22.42.1 xen-libs-32bit-4.4.4_21-22.42.1 xen-libs-4.4.4_21-22.42.1 xen-libs-debuginfo-32bit-4.4.4_21-22.42.1 xen-libs-debuginfo-4.4.4_21-22.42.1 xen-tools-4.4.4_21-22.42.1 xen-tools-debuginfo-4.4.4_21-22.42.1 xen-tools-domU-4.4.4_21-22.42.1 xen-tools-domU-debuginfo-4.4.4_21-22.42.1 References: https://www.suse.com/security/cve/CVE-2017-10911.html https://www.suse.com/security/cve/CVE-2017-10912.html https://www.suse.com/security/cve/CVE-2017-10913.html https://www.suse.com/security/cve/CVE-2017-10914.html https://www.suse.com/security/cve/CVE-2017-10915.html https://www.suse.com/security/cve/CVE-2017-10917.html https://www.suse.com/security/cve/CVE-2017-10918.html https://www.suse.com/security/cve/CVE-2017-10920.html https://www.suse.com/security/cve/CVE-2017-10921.html https://www.suse.com/security/cve/CVE-2017-10922.html https://www.suse.com/security/cve/CVE-2017-8112.html https://www.suse.com/security/cve/CVE-2017-8309.html https://www.suse.com/security/cve/CVE-2017-8905.html https://www.suse.com/security/cve/CVE-2017-9330.html https://www.suse.com/security/cve/CVE-2017-9374.html https://www.suse.com/security/cve/CVE-2017-9503.html https://bugzilla.suse.com/1014136 https://bugzilla.suse.com/1026236 https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1031460 https://bugzilla.suse.com/1032148 https://bugzilla.suse.com/1034845 https://bugzilla.suse.com/1036470 https://bugzilla.suse.com/1037243 https://bugzilla.suse.com/1042160 https://bugzilla.suse.com/1042863 https://bugzilla.suse.com/1042882 https://bugzilla.suse.com/1042893 https://bugzilla.suse.com/1042915 https://bugzilla.suse.com/1042924 https://bugzilla.suse.com/1042931 https://bugzilla.suse.com/1042938 https://bugzilla.suse.com/1043074 https://bugzilla.suse.com/1043297 From sle-security-updates at lists.suse.com Fri Jul 7 07:09:37 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 7 Jul 2017 15:09:37 +0200 (CEST) Subject: SUSE-SU-2017:1812-1: important: Security update for xen Message-ID: <20170707130937.C0918FF3A@maintenance.suse.de> SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1812-1 Rating: important References: #1014136 #1026236 #1027519 #1031460 #1034845 #1036470 #1037243 #1042160 #1042863 #1042882 #1042893 #1042915 #1042923 #1042924 #1042931 #1042938 #1043074 #1043297 Cross-References: CVE-2017-10911 CVE-2017-10912 CVE-2017-10913 CVE-2017-10914 CVE-2017-10915 CVE-2017-10916 CVE-2017-10917 CVE-2017-10918 CVE-2017-10920 CVE-2017-10921 CVE-2017-10922 CVE-2017-8112 CVE-2017-8309 CVE-2017-8905 CVE-2017-9330 CVE-2017-9374 CVE-2017-9503 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves 17 vulnerabilities and has one errata is now available. Description: This update for xen fixes several issues. These security issues were fixed: - CVE-2017-10911: blkif responses leaked backend stack data, which allowed unprivileged guest to obtain sensitive information from the host or other guests (XSA-216, bsc#1042863) - CVE-2017-10912: Page transfer might have allowed PV guest to elevate privilege (XSA-217, bsc#1042882) - CVE-2017-10913, CVE-2017-10914: Races in the grant table unmap code allowed for informations leaks and potentially privilege escalation (XSA-218, bsc#1042893) - CVE-2017-10915: Insufficient reference counts during shadow emulation allowed a malicious pair of guest to elevate their privileges to the privileges that XEN runs under (XSA-219, bsc#1042915) - CVE-2017-10917: Missing NULL pointer check in event channel poll allows guests to DoS the host (XSA-221, bsc#1042924) - CVE-2017-10918: Stale P2M mappings due to insufficient error checking allowed malicious guest to leak information or elevate privileges (XSA-222, bsc#1042931) - CVE-2017-10922, CVE-2017-10921, CVE-2017-10920: Grant table operations mishandled reference counts allowing malicious guests to escape (XSA-224, bsc#1042938) - CVE-2017-10916: PKRU and BND* leakage between vCPU-s might have leaked information to other guests (XSA-220, bsc#1042923) - CVE-2017-9330: USB OHCI Emulation in qemu allowed local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value (bsc#1042160) - CVE-2017-8309: Memory leak in the audio/audio.c allowed remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture (bsc#1037243) - CVE-2017-8112: hw/scsi/vmw_pvscsi.c allowed local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count (bsc#1036470) - CVE-2017-8905: Xen a failsafe callback, which might have allowed PV guest OS users to execute arbitrary code on the host OS (XSA-215, bsc#1034845). - CVE-2017-9503: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation support was vulnerable to a null pointer dereference issue which allowed a privileged user inside guest to crash the Qemu process on the host resulting in DoS (bsc#1043297) - CVE-2017-9374: Missing free of 's->ipacket', causes a host memory leak, allowing for DoS (bsc#1043074) These non-security issues were fixed: - bsc#1031460: Fixed DomU Live Migration - bsc#1014136: Fixed kdump SLES12-SP2 - bsc#1026236: Equalized paravirtualized vs. fully virtualized migration speed Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1121=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1121=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1121=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): xen-4.5.5_12-22.18.1 xen-debugsource-4.5.5_12-22.18.1 xen-doc-html-4.5.5_12-22.18.1 xen-kmp-default-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-kmp-default-debuginfo-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-libs-32bit-4.5.5_12-22.18.1 xen-libs-4.5.5_12-22.18.1 xen-libs-debuginfo-32bit-4.5.5_12-22.18.1 xen-libs-debuginfo-4.5.5_12-22.18.1 xen-tools-4.5.5_12-22.18.1 xen-tools-debuginfo-4.5.5_12-22.18.1 xen-tools-domU-4.5.5_12-22.18.1 xen-tools-domU-debuginfo-4.5.5_12-22.18.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): xen-4.5.5_12-22.18.1 xen-debugsource-4.5.5_12-22.18.1 xen-doc-html-4.5.5_12-22.18.1 xen-kmp-default-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-kmp-default-debuginfo-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-libs-32bit-4.5.5_12-22.18.1 xen-libs-4.5.5_12-22.18.1 xen-libs-debuginfo-32bit-4.5.5_12-22.18.1 xen-libs-debuginfo-4.5.5_12-22.18.1 xen-tools-4.5.5_12-22.18.1 xen-tools-debuginfo-4.5.5_12-22.18.1 xen-tools-domU-4.5.5_12-22.18.1 xen-tools-domU-debuginfo-4.5.5_12-22.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): xen-4.5.5_12-22.18.1 xen-debugsource-4.5.5_12-22.18.1 xen-doc-html-4.5.5_12-22.18.1 xen-kmp-default-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-kmp-default-debuginfo-4.5.5_12_k3.12.74_60.64.45-22.18.1 xen-libs-32bit-4.5.5_12-22.18.1 xen-libs-4.5.5_12-22.18.1 xen-libs-debuginfo-32bit-4.5.5_12-22.18.1 xen-libs-debuginfo-4.5.5_12-22.18.1 xen-tools-4.5.5_12-22.18.1 xen-tools-debuginfo-4.5.5_12-22.18.1 xen-tools-domU-4.5.5_12-22.18.1 xen-tools-domU-debuginfo-4.5.5_12-22.18.1 References: https://www.suse.com/security/cve/CVE-2017-10911.html https://www.suse.com/security/cve/CVE-2017-10912.html https://www.suse.com/security/cve/CVE-2017-10913.html https://www.suse.com/security/cve/CVE-2017-10914.html https://www.suse.com/security/cve/CVE-2017-10915.html https://www.suse.com/security/cve/CVE-2017-10916.html https://www.suse.com/security/cve/CVE-2017-10917.html https://www.suse.com/security/cve/CVE-2017-10918.html https://www.suse.com/security/cve/CVE-2017-10920.html https://www.suse.com/security/cve/CVE-2017-10921.html https://www.suse.com/security/cve/CVE-2017-10922.html https://www.suse.com/security/cve/CVE-2017-8112.html https://www.suse.com/security/cve/CVE-2017-8309.html https://www.suse.com/security/cve/CVE-2017-8905.html https://www.suse.com/security/cve/CVE-2017-9330.html https://www.suse.com/security/cve/CVE-2017-9374.html https://www.suse.com/security/cve/CVE-2017-9503.html https://bugzilla.suse.com/1014136 https://bugzilla.suse.com/1026236 https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1031460 https://bugzilla.suse.com/1034845 https://bugzilla.suse.com/1036470 https://bugzilla.suse.com/1037243 https://bugzilla.suse.com/1042160 https://bugzilla.suse.com/1042863 https://bugzilla.suse.com/1042882 https://bugzilla.suse.com/1042893 https://bugzilla.suse.com/1042915 https://bugzilla.suse.com/1042923 https://bugzilla.suse.com/1042924 https://bugzilla.suse.com/1042931 https://bugzilla.suse.com/1042938 https://bugzilla.suse.com/1043074 https://bugzilla.suse.com/1043297 From sle-security-updates at lists.suse.com Fri Jul 7 07:13:06 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 7 Jul 2017 15:13:06 +0200 (CEST) Subject: SUSE-SU-2017:1813-1: moderate: Security update for libxml2 Message-ID: <20170707131306.94626FF3A@maintenance.suse.de> SUSE Security Update: Security update for libxml2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1813-1 Rating: moderate References: #1024989 #1044337 #1044887 #1044894 Cross-References: CVE-2017-0663 CVE-2017-5969 CVE-2017-7375 CVE-2017-7376 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libxml2 fixes the following issues: Security issues fixed: * CVE-2017-0663: Fixed a heap buffer overflow in xmlAddID (bsc#1044337) * CVE-2017-5969: Fixed a NULL pointer deref in xmlDumpElementContent (bsc#1024989) * CVE-2017-7375: Prevented an unwanted external entity reference (bsc#1044894) * CVE-2017-7376: Increase buffer space for port in HTTP redirect support (bsc#1044887) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-libxml2-13199=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-libxml2-13199=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-libxml2-13199=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libxml2-devel-2.7.6-0.76.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): libxml2-devel-32bit-2.7.6-0.76.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libxml2-2.7.6-0.76.1 libxml2-doc-2.7.6-0.76.1 libxml2-python-2.7.6-0.76.4 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libxml2-32bit-2.7.6-0.76.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libxml2-x86-2.7.6-0.76.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): libxml2-debuginfo-2.7.6-0.76.1 libxml2-debugsource-2.7.6-0.76.1 libxml2-python-debuginfo-2.7.6-0.76.4 libxml2-python-debugsource-2.7.6-0.76.4 References: https://www.suse.com/security/cve/CVE-2017-0663.html https://www.suse.com/security/cve/CVE-2017-5969.html https://www.suse.com/security/cve/CVE-2017-7375.html https://www.suse.com/security/cve/CVE-2017-7376.html https://bugzilla.suse.com/1024989 https://bugzilla.suse.com/1044337 https://bugzilla.suse.com/1044887 https://bugzilla.suse.com/1044894 From sle-security-updates at lists.suse.com Fri Jul 7 07:14:14 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 7 Jul 2017 15:14:14 +0200 (CEST) Subject: SUSE-SU-2017:1815-1: important: Recommended update for ncurses Message-ID: <20170707131414.6636FFF3A@maintenance.suse.de> SUSE Security Update: Recommended update for ncurses ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1815-1 Rating: important References: #1000662 #1046853 #1046858 Cross-References: CVE-2017-10684 CVE-2017-10685 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for ncurses fixes the following issues: Security issues fixed: - CVE-2017-10684: Possible RCE via stack-based buffer overflow in the fmt_entry function. (bsc#1046858) - CVE-2017-10685: Possible RCE with format string vulnerability in the fmt_entry function. (bsc#1046853) Bugfixes: - Drop patch ncurses-5.9-environment.dif as YaST2 ncurses GUI does not need it anymore and as well as it causes bug bsc#1000662 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1119=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1119=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1119=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1119=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1119=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): ncurses-debugsource-5.9-44.1 ncurses-devel-5.9-44.1 ncurses-devel-debuginfo-5.9-44.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libncurses5-5.9-44.1 libncurses5-debuginfo-5.9-44.1 libncurses6-5.9-44.1 libncurses6-debuginfo-5.9-44.1 ncurses-debugsource-5.9-44.1 ncurses-devel-5.9-44.1 ncurses-devel-debuginfo-5.9-44.1 ncurses-utils-5.9-44.1 ncurses-utils-debuginfo-5.9-44.1 tack-5.9-44.1 tack-debuginfo-5.9-44.1 terminfo-5.9-44.1 terminfo-base-5.9-44.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libncurses5-5.9-44.1 libncurses5-debuginfo-5.9-44.1 libncurses6-5.9-44.1 libncurses6-debuginfo-5.9-44.1 ncurses-debugsource-5.9-44.1 ncurses-devel-5.9-44.1 ncurses-devel-debuginfo-5.9-44.1 ncurses-utils-5.9-44.1 ncurses-utils-debuginfo-5.9-44.1 tack-5.9-44.1 tack-debuginfo-5.9-44.1 terminfo-5.9-44.1 terminfo-base-5.9-44.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libncurses5-32bit-5.9-44.1 libncurses5-debuginfo-32bit-5.9-44.1 libncurses6-32bit-5.9-44.1 libncurses6-debuginfo-32bit-5.9-44.1 ncurses-devel-32bit-5.9-44.1 ncurses-devel-debuginfo-32bit-5.9-44.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libncurses5-32bit-5.9-44.1 libncurses5-5.9-44.1 libncurses5-debuginfo-32bit-5.9-44.1 libncurses5-debuginfo-5.9-44.1 libncurses6-32bit-5.9-44.1 libncurses6-5.9-44.1 libncurses6-debuginfo-32bit-5.9-44.1 libncurses6-debuginfo-5.9-44.1 ncurses-debugsource-5.9-44.1 ncurses-devel-5.9-44.1 ncurses-devel-debuginfo-5.9-44.1 ncurses-utils-5.9-44.1 ncurses-utils-debuginfo-5.9-44.1 tack-5.9-44.1 tack-debuginfo-5.9-44.1 terminfo-5.9-44.1 terminfo-base-5.9-44.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): libncurses5-5.9-44.1 libncurses5-debuginfo-5.9-44.1 libncurses6-5.9-44.1 libncurses6-debuginfo-5.9-44.1 ncurses-debugsource-5.9-44.1 ncurses-utils-5.9-44.1 ncurses-utils-debuginfo-5.9-44.1 terminfo-base-5.9-44.1 References: https://www.suse.com/security/cve/CVE-2017-10684.html https://www.suse.com/security/cve/CVE-2017-10685.html https://bugzilla.suse.com/1000662 https://bugzilla.suse.com/1046853 https://bugzilla.suse.com/1046858 From sle-security-updates at lists.suse.com Fri Jul 7 19:10:59 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Sat, 8 Jul 2017 03:10:59 +0200 (CEST) Subject: SUSE-SU-2017:1821-1: moderate: Security update for libreoffice Message-ID: <20170708011059.8C1B2F7BE@maintenance.suse.de> SUSE Security Update: Security update for libreoffice ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1821-1 Rating: moderate References: #1015115 #1015118 #1015360 #1017925 #1021369 #1021373 #1028817 #1034192 #1034329 #1034568 #1035087 #1036975 #1042828 #948058 #959926 #962777 #963436 #972777 #975283 #976831 #989564 Cross-References: CVE-2015-8947 CVE-2016-10327 CVE-2016-2052 CVE-2017-7870 CVE-2017-7882 CVE-2017-8358 CVE-2017-9433 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP2 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that solves 7 vulnerabilities and has 14 fixes is now available. Description: LibreOffice was updated to version 5.3.3.2, bringing new features and enhancements: Writer: - New "Go to Page" dialog for quickly jumping to another page. - Support for "Table Styles". - New drawing tools were added. - Improvements in the toolbar. - Borderless padding is displayed. Calc: - New drawing tools were added. - In new installations the default setting for new documents is now "Enable wildcards in formulas" instead of regular expressions. - Improved compatibility with ODF 1.2 Impress: - Images inserted via "Photo Album" can now be linked instead of embedded in the document. - When launching Impress, a Template Selector allows you to choose a Template to start with. - Two new default templates: Vivid and Pencil. - All existing templates have been improved. Draw: - New arrow endings, including Crow's foot notation's ones. Base: - Firebird has been upgraded to version 3.0.0. It is unable to read back Firebird 2.5 data, so embedded Firebird odb files created in LibreOffice version up to 5.2 cannot be opened with LibreOffice 5.3. Some security issues have also been fixed: - CVE-2017-7870: An out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function. - CVE-2017-7882: An out-of-bounds write related to the HWPFile::TagsRead function. - CVE-2017-8358: an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function. - CVE-2016-10327: An out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function. - CVE-2017-9433: An out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in libmwaw. A comprehensive list of new features and changes in this release is available at: https://wiki.documentfoundation.org/ReleaseNotes/5.3 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1125=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1125=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1125=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP2 (noarch): libreoffice-icon-theme-galaxy-5.3.3.2-40.5.9 libreoffice-icon-theme-tango-5.3.3.2-40.5.9 libreoffice-l10n-af-5.3.3.2-40.5.9 libreoffice-l10n-ar-5.3.3.2-40.5.9 libreoffice-l10n-bg-5.3.3.2-40.5.9 libreoffice-l10n-ca-5.3.3.2-40.5.9 libreoffice-l10n-cs-5.3.3.2-40.5.9 libreoffice-l10n-da-5.3.3.2-40.5.9 libreoffice-l10n-de-5.3.3.2-40.5.9 libreoffice-l10n-en-5.3.3.2-40.5.9 libreoffice-l10n-es-5.3.3.2-40.5.9 libreoffice-l10n-fi-5.3.3.2-40.5.9 libreoffice-l10n-fr-5.3.3.2-40.5.9 libreoffice-l10n-gu-5.3.3.2-40.5.9 libreoffice-l10n-hi-5.3.3.2-40.5.9 libreoffice-l10n-hr-5.3.3.2-40.5.9 libreoffice-l10n-hu-5.3.3.2-40.5.9 libreoffice-l10n-it-5.3.3.2-40.5.9 libreoffice-l10n-ja-5.3.3.2-40.5.9 libreoffice-l10n-ko-5.3.3.2-40.5.9 libreoffice-l10n-lt-5.3.3.2-40.5.9 libreoffice-l10n-nb-5.3.3.2-40.5.9 libreoffice-l10n-nl-5.3.3.2-40.5.9 libreoffice-l10n-nn-5.3.3.2-40.5.9 libreoffice-l10n-pl-5.3.3.2-40.5.9 libreoffice-l10n-pt_BR-5.3.3.2-40.5.9 libreoffice-l10n-pt_PT-5.3.3.2-40.5.9 libreoffice-l10n-ro-5.3.3.2-40.5.9 libreoffice-l10n-ru-5.3.3.2-40.5.9 libreoffice-l10n-sk-5.3.3.2-40.5.9 libreoffice-l10n-sv-5.3.3.2-40.5.9 libreoffice-l10n-uk-5.3.3.2-40.5.9 libreoffice-l10n-xh-5.3.3.2-40.5.9 libreoffice-l10n-zh_CN-5.3.3.2-40.5.9 libreoffice-l10n-zh_TW-5.3.3.2-40.5.9 libreoffice-l10n-zu-5.3.3.2-40.5.9 myspell-af_NA-20170511-15.1 myspell-af_ZA-20170511-15.1 myspell-ar-20170511-15.1 myspell-ar_AE-20170511-15.1 myspell-ar_BH-20170511-15.1 myspell-ar_DZ-20170511-15.1 myspell-ar_EG-20170511-15.1 myspell-ar_IQ-20170511-15.1 myspell-ar_JO-20170511-15.1 myspell-ar_KW-20170511-15.1 myspell-ar_LB-20170511-15.1 myspell-ar_LY-20170511-15.1 myspell-ar_MA-20170511-15.1 myspell-ar_OM-20170511-15.1 myspell-ar_QA-20170511-15.1 myspell-ar_SA-20170511-15.1 myspell-ar_SD-20170511-15.1 myspell-ar_SY-20170511-15.1 myspell-ar_TN-20170511-15.1 myspell-ar_YE-20170511-15.1 myspell-be_BY-20170511-15.1 myspell-bg_BG-20170511-15.1 myspell-bn_BD-20170511-15.1 myspell-bn_IN-20170511-15.1 myspell-bs-20170511-15.1 myspell-bs_BA-20170511-15.1 myspell-ca-20170511-15.1 myspell-ca_AD-20170511-15.1 myspell-ca_ES-20170511-15.1 myspell-ca_ES_valencia-20170511-15.1 myspell-ca_FR-20170511-15.1 myspell-ca_IT-20170511-15.1 myspell-cs_CZ-20170511-15.1 myspell-da_DK-20170511-15.1 myspell-de-20170511-15.1 myspell-de_AT-20170511-15.1 myspell-de_CH-20170511-15.1 myspell-de_DE-20170511-15.1 myspell-el_GR-20170511-15.1 myspell-en-20170511-15.1 myspell-en_AU-20170511-15.1 myspell-en_BS-20170511-15.1 myspell-en_BZ-20170511-15.1 myspell-en_CA-20170511-15.1 myspell-en_GB-20170511-15.1 myspell-en_GH-20170511-15.1 myspell-en_IE-20170511-15.1 myspell-en_IN-20170511-15.1 myspell-en_JM-20170511-15.1 myspell-en_MW-20170511-15.1 myspell-en_NA-20170511-15.1 myspell-en_NZ-20170511-15.1 myspell-en_PH-20170511-15.1 myspell-en_TT-20170511-15.1 myspell-en_US-20170511-15.1 myspell-en_ZA-20170511-15.1 myspell-en_ZW-20170511-15.1 myspell-es-20170511-15.1 myspell-es_AR-20170511-15.1 myspell-es_BO-20170511-15.1 myspell-es_CL-20170511-15.1 myspell-es_CO-20170511-15.1 myspell-es_CR-20170511-15.1 myspell-es_CU-20170511-15.1 myspell-es_DO-20170511-15.1 myspell-es_EC-20170511-15.1 myspell-es_ES-20170511-15.1 myspell-es_GT-20170511-15.1 myspell-es_HN-20170511-15.1 myspell-es_MX-20170511-15.1 myspell-es_NI-20170511-15.1 myspell-es_PA-20170511-15.1 myspell-es_PE-20170511-15.1 myspell-es_PR-20170511-15.1 myspell-es_PY-20170511-15.1 myspell-es_SV-20170511-15.1 myspell-es_UY-20170511-15.1 myspell-es_VE-20170511-15.1 myspell-et_EE-20170511-15.1 myspell-fr_BE-20170511-15.1 myspell-fr_CA-20170511-15.1 myspell-fr_CH-20170511-15.1 myspell-fr_FR-20170511-15.1 myspell-fr_LU-20170511-15.1 myspell-fr_MC-20170511-15.1 myspell-gu_IN-20170511-15.1 myspell-he_IL-20170511-15.1 myspell-hi_IN-20170511-15.1 myspell-hr_HR-20170511-15.1 myspell-hu_HU-20170511-15.1 myspell-it_IT-20170511-15.1 myspell-lo_LA-20170511-15.1 myspell-lt_LT-20170511-15.1 myspell-lv_LV-20170511-15.1 myspell-nb_NO-20170511-15.1 myspell-nl_BE-20170511-15.1 myspell-nl_NL-20170511-15.1 myspell-nn_NO-20170511-15.1 myspell-no-20170511-15.1 myspell-pl_PL-20170511-15.1 myspell-pt_AO-20170511-15.1 myspell-pt_BR-20170511-15.1 myspell-pt_PT-20170511-15.1 myspell-ro-20170511-15.1 myspell-ro_RO-20170511-15.1 myspell-ru_RU-20170511-15.1 myspell-sk_SK-20170511-15.1 myspell-sl_SI-20170511-15.1 myspell-sr-20170511-15.1 myspell-sr_CS-20170511-15.1 myspell-sr_Latn_CS-20170511-15.1 myspell-sr_Latn_RS-20170511-15.1 myspell-sr_RS-20170511-15.1 myspell-sv_FI-20170511-15.1 myspell-sv_SE-20170511-15.1 myspell-te-20170511-15.1 myspell-te_IN-20170511-15.1 myspell-th_TH-20170511-15.1 myspell-uk_UA-20170511-15.1 myspell-vi-20170511-15.1 myspell-vi_VN-20170511-15.1 myspell-zu_ZA-20170511-15.1 - SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64): libixion-0_12-0-0.12.1-12.1 libixion-0_12-0-debuginfo-0.12.1-12.1 libixion-debugsource-0.12.1-12.1 libmwaw-0_3-3-0.3.11-9.1 libmwaw-0_3-3-debuginfo-0.3.11-9.1 libmwaw-debugsource-0.3.11-9.1 liborcus-0_12-0-0.12.1-12.1 liborcus-0_12-0-debuginfo-0.12.1-12.1 liborcus-debugsource-0.12.1-12.1 libreoffice-5.3.3.2-40.5.9 libreoffice-base-5.3.3.2-40.5.9 libreoffice-base-debuginfo-5.3.3.2-40.5.9 libreoffice-base-drivers-mysql-5.3.3.2-40.5.9 libreoffice-base-drivers-mysql-debuginfo-5.3.3.2-40.5.9 libreoffice-base-drivers-postgresql-5.3.3.2-40.5.9 libreoffice-base-drivers-postgresql-debuginfo-5.3.3.2-40.5.9 libreoffice-calc-5.3.3.2-40.5.9 libreoffice-calc-debuginfo-5.3.3.2-40.5.9 libreoffice-calc-extensions-5.3.3.2-40.5.9 libreoffice-debuginfo-5.3.3.2-40.5.9 libreoffice-debugsource-5.3.3.2-40.5.9 libreoffice-draw-5.3.3.2-40.5.9 libreoffice-draw-debuginfo-5.3.3.2-40.5.9 libreoffice-filters-optional-5.3.3.2-40.5.9 libreoffice-gnome-5.3.3.2-40.5.9 libreoffice-gnome-debuginfo-5.3.3.2-40.5.9 libreoffice-impress-5.3.3.2-40.5.9 libreoffice-impress-debuginfo-5.3.3.2-40.5.9 libreoffice-mailmerge-5.3.3.2-40.5.9 libreoffice-math-5.3.3.2-40.5.9 libreoffice-math-debuginfo-5.3.3.2-40.5.9 libreoffice-officebean-5.3.3.2-40.5.9 libreoffice-officebean-debuginfo-5.3.3.2-40.5.9 libreoffice-pyuno-5.3.3.2-40.5.9 libreoffice-pyuno-debuginfo-5.3.3.2-40.5.9 libreoffice-writer-5.3.3.2-40.5.9 libreoffice-writer-debuginfo-5.3.3.2-40.5.9 libreoffice-writer-extensions-5.3.3.2-40.5.9 libreofficekit-5.3.3.2-40.5.9 libstaroffice-0_0-0-0.0.3-2.1 libstaroffice-0_0-0-debuginfo-0.0.3-2.1 libstaroffice-debugsource-0.0.3-2.1 libzmf-0_0-0-0.0.1-2.1 libzmf-0_0-0-debuginfo-0.0.1-2.1 libzmf-debugsource-0.0.1-2.1 myspell-dictionaries-20170511-15.1 myspell-lightproof-en-20170511-15.1 myspell-lightproof-hu_HU-20170511-15.1 myspell-lightproof-pt_BR-20170511-15.1 myspell-lightproof-ru_RU-20170511-15.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libixion-0_12-0-0.12.1-12.1 libixion-0_12-0-debuginfo-0.12.1-12.1 libixion-debugsource-0.12.1-12.1 libixion-devel-0.12.1-12.1 libmwaw-debugsource-0.3.11-9.1 libmwaw-devel-0.3.11-9.1 liborcus-debugsource-0.12.1-12.1 liborcus-devel-0.12.1-12.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 x86_64): libreoffice-debuginfo-5.3.3.2-40.5.9 libreoffice-debugsource-5.3.3.2-40.5.9 libreoffice-sdk-5.3.3.2-40.5.9 libreoffice-sdk-debuginfo-5.3.3.2-40.5.9 - SUSE Linux Enterprise Software Development Kit 12-SP2 (noarch): libmwaw-devel-doc-0.3.11-9.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libixion-0_12-0-0.12.1-12.1 libixion-0_12-0-debuginfo-0.12.1-12.1 libixion-debugsource-0.12.1-12.1 libmwaw-0_3-3-0.3.11-9.1 libmwaw-0_3-3-debuginfo-0.3.11-9.1 libmwaw-debugsource-0.3.11-9.1 liborcus-0_12-0-0.12.1-12.1 liborcus-0_12-0-debuginfo-0.12.1-12.1 liborcus-debugsource-0.12.1-12.1 libreoffice-5.3.3.2-40.5.9 libreoffice-base-5.3.3.2-40.5.9 libreoffice-base-debuginfo-5.3.3.2-40.5.9 libreoffice-base-drivers-mysql-5.3.3.2-40.5.9 libreoffice-base-drivers-mysql-debuginfo-5.3.3.2-40.5.9 libreoffice-base-drivers-postgresql-5.3.3.2-40.5.9 libreoffice-base-drivers-postgresql-debuginfo-5.3.3.2-40.5.9 libreoffice-calc-5.3.3.2-40.5.9 libreoffice-calc-debuginfo-5.3.3.2-40.5.9 libreoffice-calc-extensions-5.3.3.2-40.5.9 libreoffice-debuginfo-5.3.3.2-40.5.9 libreoffice-debugsource-5.3.3.2-40.5.9 libreoffice-draw-5.3.3.2-40.5.9 libreoffice-draw-debuginfo-5.3.3.2-40.5.9 libreoffice-filters-optional-5.3.3.2-40.5.9 libreoffice-gnome-5.3.3.2-40.5.9 libreoffice-gnome-debuginfo-5.3.3.2-40.5.9 libreoffice-impress-5.3.3.2-40.5.9 libreoffice-impress-debuginfo-5.3.3.2-40.5.9 libreoffice-mailmerge-5.3.3.2-40.5.9 libreoffice-math-5.3.3.2-40.5.9 libreoffice-math-debuginfo-5.3.3.2-40.5.9 libreoffice-officebean-5.3.3.2-40.5.9 libreoffice-officebean-debuginfo-5.3.3.2-40.5.9 libreoffice-pyuno-5.3.3.2-40.5.9 libreoffice-pyuno-debuginfo-5.3.3.2-40.5.9 libreoffice-writer-5.3.3.2-40.5.9 libreoffice-writer-debuginfo-5.3.3.2-40.5.9 libreoffice-writer-extensions-5.3.3.2-40.5.9 libreofficekit-5.3.3.2-40.5.9 libstaroffice-0_0-0-0.0.3-2.1 libstaroffice-0_0-0-debuginfo-0.0.3-2.1 libstaroffice-debugsource-0.0.3-2.1 libzmf-0_0-0-0.0.1-2.1 libzmf-0_0-0-debuginfo-0.0.1-2.1 libzmf-debugsource-0.0.1-2.1 myspell-dictionaries-20170511-15.1 myspell-lightproof-en-20170511-15.1 myspell-lightproof-hu_HU-20170511-15.1 myspell-lightproof-pt_BR-20170511-15.1 myspell-lightproof-ru_RU-20170511-15.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): libreoffice-icon-theme-galaxy-5.3.3.2-40.5.9 libreoffice-icon-theme-tango-5.3.3.2-40.5.9 libreoffice-l10n-af-5.3.3.2-40.5.9 libreoffice-l10n-ar-5.3.3.2-40.5.9 libreoffice-l10n-ca-5.3.3.2-40.5.9 libreoffice-l10n-cs-5.3.3.2-40.5.9 libreoffice-l10n-da-5.3.3.2-40.5.9 libreoffice-l10n-de-5.3.3.2-40.5.9 libreoffice-l10n-en-5.3.3.2-40.5.9 libreoffice-l10n-es-5.3.3.2-40.5.9 libreoffice-l10n-fi-5.3.3.2-40.5.9 libreoffice-l10n-fr-5.3.3.2-40.5.9 libreoffice-l10n-gu-5.3.3.2-40.5.9 libreoffice-l10n-hi-5.3.3.2-40.5.9 libreoffice-l10n-hu-5.3.3.2-40.5.9 libreoffice-l10n-it-5.3.3.2-40.5.9 libreoffice-l10n-ja-5.3.3.2-40.5.9 libreoffice-l10n-ko-5.3.3.2-40.5.9 libreoffice-l10n-nb-5.3.3.2-40.5.9 libreoffice-l10n-nl-5.3.3.2-40.5.9 libreoffice-l10n-nn-5.3.3.2-40.5.9 libreoffice-l10n-pl-5.3.3.2-40.5.9 libreoffice-l10n-pt_BR-5.3.3.2-40.5.9 libreoffice-l10n-pt_PT-5.3.3.2-40.5.9 libreoffice-l10n-ro-5.3.3.2-40.5.9 libreoffice-l10n-ru-5.3.3.2-40.5.9 libreoffice-l10n-sk-5.3.3.2-40.5.9 libreoffice-l10n-sv-5.3.3.2-40.5.9 libreoffice-l10n-xh-5.3.3.2-40.5.9 libreoffice-l10n-zh_CN-5.3.3.2-40.5.9 libreoffice-l10n-zh_TW-5.3.3.2-40.5.9 libreoffice-l10n-zu-5.3.3.2-40.5.9 myspell-af_NA-20170511-15.1 myspell-af_ZA-20170511-15.1 myspell-ar-20170511-15.1 myspell-ar_AE-20170511-15.1 myspell-ar_BH-20170511-15.1 myspell-ar_DZ-20170511-15.1 myspell-ar_EG-20170511-15.1 myspell-ar_IQ-20170511-15.1 myspell-ar_JO-20170511-15.1 myspell-ar_KW-20170511-15.1 myspell-ar_LB-20170511-15.1 myspell-ar_LY-20170511-15.1 myspell-ar_MA-20170511-15.1 myspell-ar_OM-20170511-15.1 myspell-ar_QA-20170511-15.1 myspell-ar_SA-20170511-15.1 myspell-ar_SD-20170511-15.1 myspell-ar_SY-20170511-15.1 myspell-ar_TN-20170511-15.1 myspell-ar_YE-20170511-15.1 myspell-be_BY-20170511-15.1 myspell-bg_BG-20170511-15.1 myspell-bn_BD-20170511-15.1 myspell-bn_IN-20170511-15.1 myspell-bs-20170511-15.1 myspell-bs_BA-20170511-15.1 myspell-ca-20170511-15.1 myspell-ca_AD-20170511-15.1 myspell-ca_ES-20170511-15.1 myspell-ca_ES_valencia-20170511-15.1 myspell-ca_FR-20170511-15.1 myspell-ca_IT-20170511-15.1 myspell-cs_CZ-20170511-15.1 myspell-da_DK-20170511-15.1 myspell-de-20170511-15.1 myspell-de_AT-20170511-15.1 myspell-de_CH-20170511-15.1 myspell-de_DE-20170511-15.1 myspell-el_GR-20170511-15.1 myspell-en-20170511-15.1 myspell-en_AU-20170511-15.1 myspell-en_BS-20170511-15.1 myspell-en_BZ-20170511-15.1 myspell-en_CA-20170511-15.1 myspell-en_GB-20170511-15.1 myspell-en_GH-20170511-15.1 myspell-en_IE-20170511-15.1 myspell-en_IN-20170511-15.1 myspell-en_JM-20170511-15.1 myspell-en_MW-20170511-15.1 myspell-en_NA-20170511-15.1 myspell-en_NZ-20170511-15.1 myspell-en_PH-20170511-15.1 myspell-en_TT-20170511-15.1 myspell-en_US-20170511-15.1 myspell-en_ZA-20170511-15.1 myspell-en_ZW-20170511-15.1 myspell-es-20170511-15.1 myspell-es_AR-20170511-15.1 myspell-es_BO-20170511-15.1 myspell-es_CL-20170511-15.1 myspell-es_CO-20170511-15.1 myspell-es_CR-20170511-15.1 myspell-es_CU-20170511-15.1 myspell-es_DO-20170511-15.1 myspell-es_EC-20170511-15.1 myspell-es_ES-20170511-15.1 myspell-es_GT-20170511-15.1 myspell-es_HN-20170511-15.1 myspell-es_MX-20170511-15.1 myspell-es_NI-20170511-15.1 myspell-es_PA-20170511-15.1 myspell-es_PE-20170511-15.1 myspell-es_PR-20170511-15.1 myspell-es_PY-20170511-15.1 myspell-es_SV-20170511-15.1 myspell-es_UY-20170511-15.1 myspell-es_VE-20170511-15.1 myspell-et_EE-20170511-15.1 myspell-fr_BE-20170511-15.1 myspell-fr_CA-20170511-15.1 myspell-fr_CH-20170511-15.1 myspell-fr_FR-20170511-15.1 myspell-fr_LU-20170511-15.1 myspell-fr_MC-20170511-15.1 myspell-gu_IN-20170511-15.1 myspell-he_IL-20170511-15.1 myspell-hi_IN-20170511-15.1 myspell-hr_HR-20170511-15.1 myspell-hu_HU-20170511-15.1 myspell-it_IT-20170511-15.1 myspell-lo_LA-20170511-15.1 myspell-lt_LT-20170511-15.1 myspell-lv_LV-20170511-15.1 myspell-nb_NO-20170511-15.1 myspell-nl_BE-20170511-15.1 myspell-nl_NL-20170511-15.1 myspell-nn_NO-20170511-15.1 myspell-no-20170511-15.1 myspell-pl_PL-20170511-15.1 myspell-pt_AO-20170511-15.1 myspell-pt_BR-20170511-15.1 myspell-pt_PT-20170511-15.1 myspell-ro-20170511-15.1 myspell-ro_RO-20170511-15.1 myspell-ru_RU-20170511-15.1 myspell-sk_SK-20170511-15.1 myspell-sl_SI-20170511-15.1 myspell-sr-20170511-15.1 myspell-sr_CS-20170511-15.1 myspell-sr_Latn_CS-20170511-15.1 myspell-sr_Latn_RS-20170511-15.1 myspell-sr_RS-20170511-15.1 myspell-sv_FI-20170511-15.1 myspell-sv_SE-20170511-15.1 myspell-te-20170511-15.1 myspell-te_IN-20170511-15.1 myspell-th_TH-20170511-15.1 myspell-uk_UA-20170511-15.1 myspell-vi-20170511-15.1 myspell-vi_VN-20170511-15.1 myspell-zu_ZA-20170511-15.1 References: https://www.suse.com/security/cve/CVE-2015-8947.html https://www.suse.com/security/cve/CVE-2016-10327.html https://www.suse.com/security/cve/CVE-2016-2052.html https://www.suse.com/security/cve/CVE-2017-7870.html https://www.suse.com/security/cve/CVE-2017-7882.html https://www.suse.com/security/cve/CVE-2017-8358.html https://www.suse.com/security/cve/CVE-2017-9433.html https://bugzilla.suse.com/1015115 https://bugzilla.suse.com/1015118 https://bugzilla.suse.com/1015360 https://bugzilla.suse.com/1017925 https://bugzilla.suse.com/1021369 https://bugzilla.suse.com/1021373 https://bugzilla.suse.com/1028817 https://bugzilla.suse.com/1034192 https://bugzilla.suse.com/1034329 https://bugzilla.suse.com/1034568 https://bugzilla.suse.com/1035087 https://bugzilla.suse.com/1036975 https://bugzilla.suse.com/1042828 https://bugzilla.suse.com/948058 https://bugzilla.suse.com/959926 https://bugzilla.suse.com/962777 https://bugzilla.suse.com/963436 https://bugzilla.suse.com/972777 https://bugzilla.suse.com/975283 https://bugzilla.suse.com/976831 https://bugzilla.suse.com/989564 From sle-security-updates at lists.suse.com Tue Jul 11 13:10:12 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:10:12 +0200 (CEST) Subject: SUSE-SU-2017:1832-1: important: Security update for spice Message-ID: <20170711191012.35537FC6C@maintenance.suse.de> SUSE Security Update: Security update for spice ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1832-1 Rating: important References: #1046779 Cross-References: CVE-2017-7506 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for spice fixes the following issues: - CVE-2017-7506: A possible buffer overflow via invalid monitor configurations (bsc#1046779) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1137=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1137=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1137=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): libspice-server1-0.12.5-10.1 libspice-server1-debuginfo-0.12.5-10.1 spice-debugsource-0.12.5-10.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): libspice-server1-0.12.5-10.1 libspice-server1-debuginfo-0.12.5-10.1 spice-debugsource-0.12.5-10.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): libspice-server1-0.12.5-10.1 libspice-server1-debuginfo-0.12.5-10.1 spice-debugsource-0.12.5-10.1 References: https://www.suse.com/security/cve/CVE-2017-7506.html https://bugzilla.suse.com/1046779 From sle-security-updates at lists.suse.com Tue Jul 11 13:13:24 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:13:24 +0200 (CEST) Subject: SUSE-SU-2017:1835-1: moderate: Security update for libICE Message-ID: <20170711191324.8FF87FF3A@maintenance.suse.de> SUSE Security Update: Security update for libICE ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1835-1 Rating: moderate References: #1025068 Cross-References: CVE-2017-2626 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libICE fixes the following issues: - CVE-2017-2626: Creation of the ICE auth session cookies used insufficient randomness, making these cookies predictable. A more random generation method has been implemented. (boo#1025068) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1134=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1134=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1134=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1134=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libICE-debugsource-1.0.8-10.1 libICE-devel-1.0.8-10.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libICE-debugsource-1.0.8-10.1 libICE6-1.0.8-10.1 libICE6-debuginfo-1.0.8-10.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libICE-debugsource-1.0.8-10.1 libICE6-1.0.8-10.1 libICE6-debuginfo-1.0.8-10.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libICE6-32bit-1.0.8-10.1 libICE6-debuginfo-32bit-1.0.8-10.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libICE-debugsource-1.0.8-10.1 libICE6-1.0.8-10.1 libICE6-32bit-1.0.8-10.1 libICE6-debuginfo-1.0.8-10.1 libICE6-debuginfo-32bit-1.0.8-10.1 References: https://www.suse.com/security/cve/CVE-2017-2626.html https://bugzilla.suse.com/1025068 From sle-security-updates at lists.suse.com Tue Jul 11 13:13:51 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:13:51 +0200 (CEST) Subject: SUSE-SU-2017:1836-1: important: Security update for spice Message-ID: <20170711191351.F26B5F7BE@maintenance.suse.de> SUSE Security Update: Security update for spice ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1836-1 Rating: important References: #1046779 Cross-References: CVE-2017-7506 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for spice fixes the following issues: - CVE-2017-7506: A possible buffer overflow via invalid monitor configurations (bsc#1046779) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1138=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1138=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1138=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (x86_64): libspice-server-devel-0.12.7-10.3.1 spice-debugsource-0.12.7-10.3.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libspice-server1-0.12.7-10.3.1 libspice-server1-debuginfo-0.12.7-10.3.1 spice-debugsource-0.12.7-10.3.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libspice-server1-0.12.7-10.3.1 libspice-server1-debuginfo-0.12.7-10.3.1 spice-debugsource-0.12.7-10.3.1 References: https://www.suse.com/security/cve/CVE-2017-7506.html https://bugzilla.suse.com/1046779 From sle-security-updates at lists.suse.com Tue Jul 11 13:14:14 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:14:14 +0200 (CEST) Subject: SUSE-SU-2017:1837-1: important: Security update for spice Message-ID: <20170711191414.678BEF7BE@maintenance.suse.de> SUSE Security Update: Security update for spice ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1837-1 Rating: important References: #1046779 Cross-References: CVE-2017-7506 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for spice fixes the following issues: - CVE-2017-7506: A possible buffer overflow via invalid monitor configurations (bsc#1046779) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-spice-13203=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-spice-13203=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-spice-13203=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): libspice-server-devel-0.12.4-11.1 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): libspice-server1-0.12.4-11.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64): spice-debuginfo-0.12.4-11.1 spice-debugsource-0.12.4-11.1 References: https://www.suse.com/security/cve/CVE-2017-7506.html https://bugzilla.suse.com/1046779 From sle-security-updates at lists.suse.com Tue Jul 11 13:14:40 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:14:40 +0200 (CEST) Subject: SUSE-SU-2017:1838-1: moderate: Security update for gnutls Message-ID: <20170711191440.0CE29F7BE@maintenance.suse.de> SUSE Security Update: Security update for gnutls ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1838-1 Rating: moderate References: #1034173 #1038337 #1043398 Cross-References: CVE-2017-7507 CVE-2017-7869 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for gnutls fixes the following issues: - GNUTLS-SA-2017-4 / CVE-2017-7507: Fix crash in status response TLS extension decoding (bsc#1043398) - GNUTLS-SA-2017-3 / CVE-2017-7869: Fix out-of-bounds write in OpenPGP certificate decoding (bsc#1034173) - Address read of 4 bytes past the end of buffer in OpenPGP certificate parsing (bsc#1038337) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1133=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1133=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1133=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1133=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): gnutls-debuginfo-3.2.15-18.3.1 gnutls-debugsource-3.2.15-18.3.1 libgnutls-devel-3.2.15-18.3.1 libgnutls-openssl-devel-3.2.15-18.3.1 libgnutlsxx-devel-3.2.15-18.3.1 libgnutlsxx28-3.2.15-18.3.1 libgnutlsxx28-debuginfo-3.2.15-18.3.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): gnutls-3.2.15-18.3.1 gnutls-debuginfo-3.2.15-18.3.1 gnutls-debugsource-3.2.15-18.3.1 libgnutls-openssl27-3.2.15-18.3.1 libgnutls-openssl27-debuginfo-3.2.15-18.3.1 libgnutls28-3.2.15-18.3.1 libgnutls28-debuginfo-3.2.15-18.3.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): gnutls-3.2.15-18.3.1 gnutls-debuginfo-3.2.15-18.3.1 gnutls-debugsource-3.2.15-18.3.1 libgnutls-openssl27-3.2.15-18.3.1 libgnutls-openssl27-debuginfo-3.2.15-18.3.1 libgnutls28-3.2.15-18.3.1 libgnutls28-debuginfo-3.2.15-18.3.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libgnutls28-32bit-3.2.15-18.3.1 libgnutls28-debuginfo-32bit-3.2.15-18.3.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): gnutls-3.2.15-18.3.1 gnutls-debuginfo-3.2.15-18.3.1 gnutls-debugsource-3.2.15-18.3.1 libgnutls28-3.2.15-18.3.1 libgnutls28-32bit-3.2.15-18.3.1 libgnutls28-debuginfo-3.2.15-18.3.1 libgnutls28-debuginfo-32bit-3.2.15-18.3.1 References: https://www.suse.com/security/cve/CVE-2017-7507.html https://www.suse.com/security/cve/CVE-2017-7869.html https://bugzilla.suse.com/1034173 https://bugzilla.suse.com/1038337 https://bugzilla.suse.com/1043398 From sle-security-updates at lists.suse.com Tue Jul 11 13:15:24 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 11 Jul 2017 21:15:24 +0200 (CEST) Subject: SUSE-SU-2017:1839-1: important: Security update for spice Message-ID: <20170711191524.4AD67F7BE@maintenance.suse.de> SUSE Security Update: Security update for spice ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1839-1 Rating: important References: #1046779 Cross-References: CVE-2017-7506 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for spice fixes the following issues: - CVE-2017-7506: A possible buffer overflow via invalid monitor configurations (bsc#1046779) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1136=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1136=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): libspice-server1-0.12.4-8.15.1 libspice-server1-debuginfo-0.12.4-8.15.1 spice-debugsource-0.12.4-8.15.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): libspice-server1-0.12.4-8.15.1 libspice-server1-debuginfo-0.12.4-8.15.1 spice-debugsource-0.12.4-8.15.1 References: https://www.suse.com/security/cve/CVE-2017-7506.html https://bugzilla.suse.com/1046779 From sle-security-updates at lists.suse.com Wed Jul 12 13:10:30 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 12 Jul 2017 21:10:30 +0200 (CEST) Subject: SUSE-SU-2017:1848-1: moderate: Security update for xorg-x11-libICE Message-ID: <20170712191030.56DEAFF3A@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-libICE ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1848-1 Rating: moderate References: #1025068 Cross-References: CVE-2017-2626 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xorg-x11-libICE fixes the following issues: - CVE-2017-2626: Creation of the ICE auth session cookies used insufficient randomness, making these cookies predictable. A more random generation method has been implemented. (boo#1025068) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-xorg-x11-libICE-13207=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-xorg-x11-libICE-13207=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-xorg-x11-libICE-13207=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libICE-devel-7.4-3.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): xorg-x11-libICE-devel-32bit-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libICE-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): xorg-x11-libICE-32bit-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): xorg-x11-libICE-x86-7.4-3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libICE-debuginfo-7.4-3.1 xorg-x11-libICE-debugsource-7.4-3.1 References: https://www.suse.com/security/cve/CVE-2017-2626.html https://bugzilla.suse.com/1025068 From sle-security-updates at lists.suse.com Wed Jul 12 13:11:54 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 12 Jul 2017 21:11:54 +0200 (CEST) Subject: SUSE-SU-2017:1850-1: important: Security update for xorg-x11-server Message-ID: <20170712191154.E196EF7BE@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1850-1 Rating: important References: #1035283 Cross-References: CVE-2017-10971 CVE-2017-10972 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for xorg-x11-server fixes the following issues: - CVE-2017-10971: Fix endianess handling of GenericEvent to prevent a stack overflow by clients. (bnc#1035283) - Make sure the type of all events to be sent by ProcXSendExtensionEvent are in the allowed range. - CVE-2017-10972: Initialize the xEvent eventT with zeros to avoid information leakage. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-xorg-x11-server-13206=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-xorg-x11-server-13206=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-xorg-x11-server-13206=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-xorg-x11-server-13206=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-xorg-x11-server-13206=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-xorg-x11-server-13206=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-server-sdk-7.4-27.121.2 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-Xvnc-7.4-27.121.2 xorg-x11-server-7.4-27.121.2 xorg-x11-server-extra-7.4-27.121.2 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): xorg-x11-Xvnc-7.4-27.121.2 xorg-x11-server-7.4-27.121.2 xorg-x11-server-extra-7.4-27.121.2 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): xorg-x11-Xvnc-7.4-27.121.2 xorg-x11-server-7.4-27.121.2 xorg-x11-server-extra-7.4-27.121.2 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-server-debuginfo-7.4-27.121.2 xorg-x11-server-debugsource-7.4-27.121.2 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): xorg-x11-server-debuginfo-7.4-27.121.2 xorg-x11-server-debugsource-7.4-27.121.2 References: https://www.suse.com/security/cve/CVE-2017-10971.html https://www.suse.com/security/cve/CVE-2017-10972.html https://bugzilla.suse.com/1035283 From sle-security-updates at lists.suse.com Thu Jul 13 07:09:40 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 13 Jul 2017 15:09:40 +0200 (CEST) Subject: SUSE-SU-2017:1853-1: important: Security update for the Linux Kernel Message-ID: <20170713130940.D7996FF3A@maintenance.suse.de> SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1853-1 Rating: important References: #1003581 #1004003 #1011044 #1012060 #1012382 #1012422 #1012452 #1012829 #1012910 #1012985 #1013561 #1013887 #1015342 #1015452 #1017461 #1018885 #1020412 #1021424 #1022266 #1022595 #1023287 #1025461 #1026570 #1027101 #1027512 #1027974 #1028217 #1028310 #1028340 #1028883 #1029607 #1030057 #1030070 #1031040 #1031142 #1031147 #1031470 #1031500 #1031512 #1031555 #1031717 #1031796 #1032141 #1032339 #1032345 #1032400 #1032581 #1032803 #1033117 #1033281 #1033336 #1033340 #1033885 #1034048 #1034419 #1034635 #1034670 #1034671 #1034762 #1034902 #1034995 #1035024 #1035866 #1035887 #1035920 #1035922 #1036214 #1036638 #1036752 #1036763 #1037177 #1037186 #1037384 #1037483 #1037669 #1037840 #1037871 #1037969 #1038033 #1038043 #1038085 #1038142 #1038143 #1038297 #1038458 #1038544 #1038842 #1038843 #1038846 #1038847 #1038848 #1038879 #1038981 #1038982 #1039214 #1039348 #1039354 #1039700 #1039864 #1039882 #1039883 #1039885 #1039900 #1040069 #1040125 #1040182 #1040279 #1040351 #1040364 #1040395 #1040425 #1040463 #1040567 #1040609 #1040855 #1040929 #1040941 #1041087 #1041160 #1041168 #1041242 #1041431 #1041810 #1042286 #1042356 #1042421 #1042517 #1042535 #1042536 #1042863 #1042886 #1043014 #1043231 #1043236 #1043347 #1043371 #1043467 #1043488 #1043598 #1043912 #1043935 #1043990 #1044015 #1044082 #1044120 #1044125 #1044532 #1044767 #1044772 #1044854 #1044880 #1044912 #1045154 #1045235 #1045286 #1045307 #1045467 #1045568 #1046105 #1046434 #1046589 #799133 #863764 #922871 #939801 #966170 #966172 #966191 #966321 #966339 #971975 #988065 #989311 #990058 #990682 #993832 #995542 Cross-References: CVE-2017-1000365 CVE-2017-1000380 CVE-2017-7346 CVE-2017-7487 CVE-2017-7616 CVE-2017-7618 CVE-2017-8890 CVE-2017-8924 CVE-2017-8925 CVE-2017-9074 CVE-2017-9075 CVE-2017-9076 CVE-2017-9077 CVE-2017-9150 CVE-2017-9242 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP2 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Live Patching 12 SUSE Linux Enterprise High Availability 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that solves 15 vulnerabilities and has 162 fixes is now available. Description: The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.74 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but did not take the argument and environment pointers into account, which allowed attackers to bypass this limitation. (bnc#1039354). - CVE-2017-1000380: sound/core/timer.c in the Linux kernel is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time (bnc#1044125). - CVE-2017-7346: The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel did not validate certain levels data, which allowed local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device (bnc#1031796). - CVE-2017-9242: The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel is too late in checking whether an overwrite of an skb data structure may occur, which allowed local users to cause a denial of service (system crash) via crafted system calls (bnc#1041431). - CVE-2017-9076: The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1039885). - CVE-2017-9077: The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1040069). - CVE-2017-9075: The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1039883). - CVE-2017-9074: The IPv6 fragmentation implementation in the Linux kernel did not consider that the nexthdr field may be associated with an invalid option, which allowed local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls (bnc#1039882). - CVE-2017-8924: The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel allowed local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow. (bsc#1038982) - CVE-2017-8925: The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel allowed local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling. (bsc#1038981) - CVE-2017-7487: The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel mishandled reference counts, which allowed local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface (bnc#1038879). - CVE-2017-8890: The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel allowed attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call (bnc#1038544). - CVE-2017-9150: The do_check function in kernel/bpf/verifier.c in the Linux kernel did not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allowed local users to obtain sensitive address information via crafted bpf system calls (bnc#1040279). - CVE-2017-7618: crypto/ahash.c in the Linux kernel allowed attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue (bnc#1033340). - CVE-2017-7616: Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel allowed local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation (bnc#1033336). The following non-security bugs were fixed: - 9p: fix a potential acl leak (4.4.68 stable queue). - acpi / APEI: Add missing synchronize_rcu() on NOTIFY_SCI removal (bsc#1031717). - acpi / scan: Drop support for force_remove (bnc#1029607). - ahci: disable correct irq for dummy ports (bsc#1040125). - alsa: hda - Fix deadlock of controller device lock at unbinding (4.4.68 stable queue). - arm: 8452/3: PJ4: make coprocessor access sequences buildable in Thumb2 mode (4.4.68 stable queue). - arm: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build (4.4.68 stable queue). - ASoC: Intel: Skylake: Uninitialized variable in probe_codec() (bsc#1043231). - ASoC: rt5640: use msleep() for long delays (bsc#1031717). - ASoC: sti: Fix error handling if of_clk_get() fails (bsc#1031717). - bcache: fix calling ida_simple_remove() with incorrect minor (bsc#1038085). - block: copy NOMERGE flag from bio to request (bsc#1030070). - block: get rid of blk_integrity_revalidate() (4.4.68 stable queue). - bna: add missing per queue ethtool stat (bsc#966321). - bna: avoid writing uninitialized data into hw registers (bsc#966321). - bna: integer overflow bug in debugfs (bsc#966321). - bnxt_en: allocate enough space for ->ntp_fltr_bmap (bsc#1020412 FATE#321671). - bonding: avoid defaulting hard_header_len to ETH_HLEN on slave removal (bsc#1042286). - bonding: do not use stale speed and duplex information (bsc#1042286). - bonding: prevent out of bound accesses (bsc#1042286). - bpf, arm64: fix jit branch offset related to ldimm64 (4.4.68 stable queue). - brcmfmac: add fallback for devices that do not report per-chain values (bsc#1043231). - brcmfmac: avoid writing channel out of allocated array (bsc#1043231). - brcmfmac: Ensure pointer correctly set if skb data location changes (4.4.68 stable queue). - brcmfmac: Make skb header writable before use (4.4.68 stable queue). - brcmfmac: restore stopping netdev queue when bus clogs up (bsc#1031717). - btrfs: add a flags field to btrfs_fs_info (bsc#1012452). - btrfs: add ASSERT for block group's memory leak (bsc#1012452). - btrfs: add btrfs_trans_handle->fs_info pointer (bsc#1012452). - btrfs: add bytes_readonly to the spaceinfo at once (bsc#1012452). - btrfs: add check to sysfs handler of label (bsc#1012452). - btrfs: add dynamic debug support (bsc#1012452). - btrfs: add error handling for extent buffer in print tree (bsc#1012452). - btrfs: add missing bytes_readonly attribute file in sysfs (bsc#1012452). - btrfs: add missing check for writeback errors on fsync (bsc#1012452). - btrfs: add more validation checks for superblock (bsc#1012452). - btrfs: Add ratelimit to btrfs printing (bsc#1012452). - btrfs: add read-only check to sysfs handler of features (bsc#1012452). - btrfs: add semaphore to synchronize direct IO writes with fsync (bsc#1012452). - btrfs: add tracepoint for adding block groups (bsc#1012452). - btrfs: add tracepoints for flush events (bsc#1012452). - btrfs: add transaction space reservation tracepoints (bsc#1012452). - btrfs: add validadtion checks for chunk loading (bsc#1012452). - btrfs: add write protection to SET_FEATURES ioctl (bsc#1012452). - btrfs: allow balancing to dup with multi-device (bsc#1012452). - btrfs: always reserve metadata for delalloc extents (bsc#1012452). - btrfs: always use trans->block_rsv for orphans (bsc#1012452). - btrfs: avoid blocking open_ctree from cleaner_kthread (bsc#1012452). - btrfs: avoid deadlocks during reservations in btrfs_truncate_block (bsc#1012452). - btrfs: avoid overflowing f_bfree (bsc#1012452). - btrfs: avoid uninitialized variable warning (bsc#1012452). - btrfs: btrfs_abort_transaction, drop root parameter (bsc#1012452). - btrfs: __btrfs_buffered_write: Pass valid file offset when releasing delalloc space (bsc#1012452). - btrfs: __btrfs_buffered_write: Reserve/release extents aligned to block size (bsc#1012452). - btrfs: btrfs_check_super_valid: Allow 4096 as stripesize (bsc#1012452). - btrfs: btrfs_debug should consume fs_info when DEBUG is not defined (bsc#1012452). - btrfs: btrfs_ioctl_clone: Truncate complete page after performing clone operation (bsc#1012452). - btrfs: btrfs_page_mkwrite: Reserve space in sectorsized units (bsc#1012452). - btrfs: btrfs_relocate_chunk pass extent_root to btrfs_end_transaction (bsc#1012452). - btrfs: btrfs_submit_direct_hook: Handle map_length < bio vector length (bsc#1012452). - btrfs: build fixup for qgroup_account_snapshot (bsc#1012452). - btrfs: change BUG_ON()'s to ASSERT()'s in backref_cache_cleanup() (bsc#1012452). - btrfs: change delayed reservation fallback behavior (bsc#1012452). - btrfs: change how we calculate the global block rsv (bsc#1012452). - btrfs: change how we update the global block rsv (bsc#1012452). - btrfs: check btree node's nritems (bsc#1012452). - btrfs: check if extent buffer is aligned to sectorsize (bsc#1012452). - btrfs: check inconsistence between chunk and block group (bsc#1012452). - btrfs: check reserved when deciding to background flush (bsc#1012452). - btrfs: clarify do_chunk_alloc()'s return value (bsc#1012452). - btrfs: Clean pte corresponding to page straddling i_size (bsc#1012452). - btrfs: clean the old superblocks before freeing the device (bsc#1012452). - btrfs: clean up and optimize __check_raid_min_device() (bsc#1012452). - btrfs: cleanup assigning next active device with a check (bsc#1012452). - btrfs: cleanup BUG_ON in merge_bio (bsc#1012452). - btrfs: Cleanup compress_file_range() (bsc#1012452). - btrfs: cleanup error handling in extent_write_cached_pages (bsc#1012452). - btrfs: clear uptodate flags of pages in sys_array eb (bsc#1012452). - btrfs: clone: use vmalloc only as fallback for nodesize bufer (bsc#1012452). - btrfs: Compute and look up csums based on sectorsized blocks (bsc#1012452). - btrfs: convert nodesize macros to static inlines (bsc#1012452). - btrfs: convert printk(KERN_* to use pr_* calls (bsc#1012452). - btrfs: convert pr_* to btrfs_* where possible (bsc#1012452). - btrfs: convert send's verbose_printk to btrfs_debug (bsc#1012452). - btrfs: copy_to_sk drop unused root parameter (bsc#1012452). - btrfs: create a helper function to read the disk super (bsc#1012452). - btrfs: create example debugfs file only in debugging build (bsc#1012452). - btrfs: create helper btrfs_find_device_by_user_input() (bsc#1012452). - btrfs: create helper function __check_raid_min_devices() (bsc#1012452). - btrfs: csum_tree_block: return proper errno value (bsc#1012452). - btrfs: detect corruption when non-root leaf has zero item (bsc#1012452). - btrfs: device add and remove: use GFP_KERNEL (bsc#1012452). - btrfs: Direct I/O read: Work on sectorsized blocks (bsc#1012452). - btrfs: disable possible cause of premature ENOSPC (bsc#1040182) - btrfs: divide btrfs_update_reserved_bytes() into two functions (bsc#1012452). - btrfs: do not background blkdev_put() (bsc#1012452). - btrfs: do not bother kicking async if there's nothing to reclaim (bsc#1012452). - btrfs: do not BUG_ON() in btrfs_orphan_add (bsc#1012452). - btrfs: do not create empty block group if we have allocated data (bsc#1012452). - btrfs: do not decrease bytes_may_use when replaying extents (bsc#1012452). - btrfs: do not do nocow check unless we have to (bsc#1012452). - btrfs: do not do unnecessary delalloc flushes when relocating (bsc#1012452). - btrfs: do not force mounts to wait for cleaner_kthread to delete one or more subvolumes (bsc#1012452). - btrfs: do not wait for unrelated IO to finish before relocation (bsc#1012452). - btrfs: do not WARN() in btrfs_transaction_abort() for IO errors (bsc#1035866). - btrfs: do not write corrupted metadata blocks to disk (bsc#1012452). - btrfs: end transaction if we abort when creating uuid root (bsc#1012452). - btrfs: enhance btrfs_find_device_by_user_input() to check device path (bsc#1012452). - btrfs: error out if generic_bin_search get invalid arguments (bsc#1012452). - btrfs: expand cow_file_range() to support in-band dedup and subpage-blocksize (bsc#1012452). - btrfs: extend btrfs_set_extent_delalloc and its friends to support in-band dedupe and subpage size patchset (bsc#1012452). - btrfs: extent same: use GFP_KERNEL for page array allocations (bsc#1012452). - btrfs: fallback to vmalloc in btrfs_compare_tree (bsc#1012452). - btrfs: fallocate: use GFP_KERNEL (bsc#1012452). - btrfs: fallocate: Work with sectorsized blocks (bsc#1012452). - btrfs: fill relocation block rsv after allocation (bsc#1012452). - btrfs: fix an integer overflow check (bsc#1012452). - btrfs: fix a possible umount deadlock (bsc#1012452). - btrfs: Fix block size returned to user space (bsc#1012452). - btrfs: fix btrfs_no_printk stub helper (bsc#1012452). - btrfs: Fix BUG_ON condition in scrub_setup_recheck_block() (bsc#1012452). - btrfs: fix BUG_ON in btrfs_mark_buffer_dirty (bsc#1012452). - btrfs: fix BUG_ON in btrfs_submit_compressed_write (bsc#1012452). - btrfs: fix build warning (bsc#1012452). - btrfs: fix callers of btrfs_block_rsv_migrate (bsc#1012452). - btrfs: fix check_direct_IO() for non-iovec iterators (bsc#1012452). - btrfs: fix check_shared for fiemap ioctl (bsc#1037177). - btrfs: fix crash when tracepoint arguments are freed by wq callbacks (bsc#1012452). - btrfs: fix data loss after truncate when using the no-holes feature (bsc#1036214). - btrfs: fix deadlock in delayed_ref_async_start (bsc#1012452). - btrfs: fix delalloc accounting after copy_from_user faults (bsc#1012452). - btrfs: fix delalloc reservation amount tracepoint (bsc#1012452). - btrfs: fix disk_i_size update bug when fallocate() fails (bsc#1012452). - btrfs: fix divide error upon chunk's stripe_len (bsc#1012452). - btrfs: fix double free of fs root (bsc#1012452). - btrfs: fix eb memory leak due to readpage failure (bsc#1012452). - btrfs: fix em leak in find_first_block_group (bsc#1012452). - btrfs: fix emptiness check for dirtied extent buffers at check_leaf() (bsc#1012452). - btrfs: fix error handling in map_private_extent_buffer (bsc#1012452). - btrfs: fix error return code in btrfs_init_test_fs() (bsc#1012452). - btrfs: fix extent_same allowing destination offset beyond i_size (bsc#1012452). - btrfs: fix free space calculation in dump_space_info() (bsc#1012452). - btrfs: fix fsfreeze hang caused by delayed iputs deal (bsc#1012452). - btrfs: fix fspath error deallocation (bsc#1012452). - btrfs: fix handling of faults from btrfs_copy_from_user (bsc#1012452). - btrfs: fix int32 overflow in shrink_delalloc() (bsc#1012452). - btrfs: Fix integer overflow when calculating bytes_per_bitmap (bsc#1012452). - btrfs: fix invalid dereference in btrfs_retry_endio (bsc#1040395). - btrfs: fix invalid reference in replace_path (bsc#1012452). - btrfs: fix listxattrs not listing all xattrs packed in the same item (bsc#1012452). - btrfs: fix lockdep deadlock warning due to dev_replace (bsc#1012452). - btrfs: fix lock dep warning, move scratch dev out of device_list_mutex and uuid_mutex (bsc#1012452). - btrfs: fix lock dep warning move scratch super outside of chunk_mutex (bsc#1012452). - btrfs: fix __MAX_CSUM_ITEMS (bsc#1012452). - btrfs: fix memory leak during RAID 5/6 device replacement (bsc#1012452). - btrfs: fix memory leak of block group cache (bsc#1012452). - btrfs: fix memory leak of reloc_root (bsc#1012452). - btrfs: fix mixed block count of available space (bsc#1012452). - btrfs: fix one bug that process may endlessly wait for ticket in wait_reserve_ticket() (bsc#1012452). - btrfs: fix panic in balance due to EIO (bsc#1012452). - btrfs: fix race between block group relocation and nocow writes (bsc#1012452). - btrfs: fix race between device replace and block group removal (bsc#1012452). - btrfs: fix race between device replace and chunk allocation (bsc#1012452). - btrfs: fix race between device replace and discard (bsc#1012452). - btrfs: fix race between device replace and read repair (bsc#1012452). - btrfs: fix race between fsync and direct IO writes for prealloc extents (bsc#1012452). - btrfs: fix race between readahead and device replace/removal (bsc#1012452). - btrfs: fix race setting block group back to RW mode during device replace (bsc#1012452). - btrfs: fix race setting block group readonly during device replace (bsc#1012452). - btrfs: fix read_node_slot to return errors (bsc#1012452). - btrfs: fix release reserved extents trace points (bsc#1012452). - btrfs: fix segmentation fault when doing dio read (bsc#1040425). - btrfs: Fix slab accounting flags (bsc#1012452). - btrfs: fix truncate_space_check (bsc#1012452). - btrfs: fix unexpected return value of fiemap (bsc#1012452). - btrfs: fix unprotected assignment of the left cursor for device replace (bsc#1012452). - btrfs: fix WARNING in btrfs_select_ref_head() (bsc#1012452). - btrfs: flush_space: treat return value of do_chunk_alloc properly (bsc#1012452). - btrfs: Force stripesize to the value of sectorsize (bsc#1012452). - btrfs: free sys_array eb as soon as possible (bsc#1012452). - btrfs: GFP_NOFS does not GFP_HIGHMEM (bsc#1012452). - btrfs: Handle uninitialised inode eviction (bsc#1012452). - btrfs: hide test-only member under ifdef (bsc#1012452). - btrfs: improve check_node to avoid reading corrupted nodes (bsc#1012452). - btrfs: Improve FL_KEEP_SIZE handling in fallocate (bsc#1012452). - btrfs: introduce BTRFS_MAX_ITEM_SIZE (bsc#1012452). - btrfs: introduce device delete by devid (bsc#1012452). - btrfs: introduce raid-type to error-code table, for minimum device constraint (bsc#1012452). - btrfs: introduce ticketed enospc infrastructure (bsc#1012452). - btrfs: introduce tickets_id to determine whether asynchronous metadata reclaim work makes progress (bsc#1012452). - btrfs: ioctl: reorder exclusive op check in RM_DEV (bsc#1012452). - btrfs: kill BUG_ON in do_relocation (bsc#1012452). - btrfs: kill BUG_ON in run_delayed_tree_ref (bsc#1012452). - btrfs: kill BUG_ON()'s in btrfs_mark_extent_written (bsc#1012452). - btrfs: kill invalid ASSERT() in process_all_refs() (bsc#1012452). - btrfs: kill the start argument to read_extent_buffer_pages (bsc#1012452). - btrfs: kill unused writepage_io_hook callback (bsc#1012452). - btrfs: let callers of btrfs_alloc_root pass gfp flags (bsc#1012452). - btrfs: Limit inline extents to root->sectorsize (bsc#1012452). - btrfs: make find_workspace always succeed (bsc#1012452). - btrfs: make find_workspace warn if there are no workspaces (bsc#1012452). - btrfs: make mapping->writeback_index point to the last written page (bsc#1012452). - btrfs: make state preallocation more speculative in __set_extent_bit (bsc#1012452). - btrfs: make sure device is synced before return (bsc#1012452). - btrfs: make sure we stay inside the bvec during __btrfs_lookup_bio_sums (bsc#1012452). - btrfs: make use of btrfs_find_device_by_user_input() (bsc#1012452). - btrfs: make use of btrfs_scratch_superblocks() in btrfs_rm_device() (bsc#1012452). - btrfs: Manually implement device_total_bytes getter/setter (bsc#1043912). - btrfs: memset to avoid stale content in btree leaf (bsc#1012452). - btrfs: memset to avoid stale content in btree node block (bsc#1012452). - btrfs: move error handling code together in ctree.h (bsc#1012452). - btrfs: optimize check for stale device (bsc#1012452). - btrfs: Output more info for enospc_debug mount option (bsc#1012452). - btrfs: parent_start initialization cleanup (bsc#1012452). - btrfs: pass correct args to btrfs_async_run_delayed_refs() (bsc#1012452). - btrfs: pass number of devices to btrfs_check_raid_min_devices (bsc#1012452). - btrfs: pass the right error code to the btrfs_std_error (bsc#1012452). - btrfs: preallocate compression workspaces (bsc#1012452). - btrfs: Print Warning only if ENOSPC_DEBUG is enabled (bsc#1012452). - btrfs: Ratelimit "no csum found" info message (bsc#1012452). - btrfs: reada: add all reachable mirrors into reada device list (bsc#1012452). - btrfs: reada: Add missed segment checking in reada_find_zone (bsc#1012452). - btrfs: reada: Avoid many times of empty loop (bsc#1012452). - btrfs: reada: avoid undone reada extents in btrfs_reada_wait (bsc#1012452). - btrfs: reada: bypass adding extent when all zone failed (bsc#1012452). - btrfs: reada: Fix a debug code typo (bsc#1012452). - btrfs: reada: Fix in-segment calculation for reada (bsc#1012452). - btrfs: reada: ignore creating reada_extent for a non-existent device (bsc#1012452). - btrfs: reada: Jump into cleanup in direct way for __readahead_hook() (bsc#1012452). - btrfs: reada: limit max works count (bsc#1012452). - btrfs: reada: Move is_need_to_readahead contition earlier (bsc#1012452). - btrfs: reada: move reada_extent_put to place after __readahead_hook() (bsc#1012452). - btrfs: reada: Pass reada_extent into __readahead_hook directly (bsc#1012452). - btrfs: reada: reduce additional fs_info->reada_lock in reada_find_zone (bsc#1012452). - btrfs: reada: Remove level argument in severial functions (bsc#1012452). - btrfs: reada: simplify dev->reada_in_flight processing (bsc#1012452). - btrfs: reada: Use fs_info instead of root in __readahead_hook's argument (bsc#1012452). - btrfs: reada: use GFP_KERNEL everywhere (bsc#1012452). - btrfs: readdir: use GFP_KERNEL (bsc#1012452). - btrfs: refactor btrfs_dev_replace_start for reuse (bsc#1012452). - btrfs: Refactor btrfs_lock_cluster() to kill compiler warning (bsc#1012452). - btrfs: remove BUG() in raid56 (bsc#1012452). - btrfs: remove BUG_ON in start_transaction (bsc#1012452). - btrfs: remove BUG_ON()'s in btrfs_map_block (bsc#1012452). - btrfs: remove build fixup for qgroup_account_snapshot (bsc#1012452). - btrfs: remove redundant error check (bsc#1012452). - btrfs: remove save_error_info() (bsc#1012452). - btrfs: remove unnecessary btrfs_mark_buffer_dirty in split_leaf (bsc#1012452). - btrfs: remove unused function btrfs_assert() (bsc#1012452). - btrfs: rename and document compression workspace members (bsc#1012452). - btrfs: rename btrfs_find_device_by_user_input (bsc#1012452). - btrfs: rename btrfs_std_error to btrfs_handle_fs_error (bsc#1012452). - btrfs: rename __check_raid_min_devices (bsc#1012452). - btrfs: rename flags for vol args v2 (bsc#1012452). - btrfs: reorg btrfs_close_one_device() (bsc#1012452). - btrfs: Replace -ENOENT by -ERANGE in btrfs_get_acl() (bsc#1012452). - btrfs: Reset IO error counters before start of device replacing (bsc#1012452). - btrfs: reuse existing variable in scrub_stripe, reduce stack usage (bsc#1012452). - btrfs: Round down values which are written for total_bytes_size (bsc#1043912). - btrfs: s_bdev is not null after missing replace (bsc#1012452). - btrfs: scrub: Set bbio to NULL before calling btrfs_map_block (bsc#1012452). - btrfs: scrub: use GFP_KERNEL on the submission path (bsc#1012452). - btrfs: Search for all ordered extents that could span across a page (bsc#1012452). - btrfs: send: silence an integer overflow warning (bsc#1012452). - btrfs: send: use GFP_KERNEL everywhere (bsc#1012452). - btrfs: send: use temporary variable to store allocation size (bsc#1012452). - btrfs: send: use vmalloc only as fallback for clone_roots (bsc#1012452). - btrfs: send: use vmalloc only as fallback for clone_sources_tmp (bsc#1012452). - btrfs: send: use vmalloc only as fallback for read_buf (bsc#1012452). - btrfs: send: use vmalloc only as fallback for send_buf (bsc#1012452). - btrfs: Simplify conditions about compress while mapping btrfs flags to inode flags (bsc#1012452). - btrfs: sink gfp parameter to clear_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to clear_extent_dirty (bsc#1012452). - btrfs: sink gfp parameter to clear_record_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to convert_extent_bit (bsc#1012452). - btrfs: sink gfp parameter to set_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to set_extent_defrag (bsc#1012452). - btrfs: sink gfp parameter to set_extent_delalloc (bsc#1012452). - btrfs: sink gfp parameter to set_extent_new (bsc#1012452). - btrfs: sink gfp parameter to set_record_extent_bits (bsc#1012452). - btrfs: skip commit transaction if we do not have enough pinned bytes (bsc#1037186). - btrfs: subpage-blocksize: Rate limit scrub error message (bsc#1012452). - btrfs: switch to common message helpers in open_ctree, adjust messages (bsc#1012452). - btrfs: switch to kcalloc in btrfs_cmp_data_prepare (bsc#1012452). - btrfs: sysfs: protect reading label by lock (bsc#1012452). - btrfs: trace pinned extents (bsc#1012452). - btrfs: track transid for delayed ref flushing (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, document subvol flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move balance flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move BTRFS_LABEL_SIZE (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move feature flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move struct btrfs_ioctl_defrag_range_args (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, qgroup limit flags (bsc#1012452). - btrfs: uapi/linux/btrfs_tree.h migration, item types and defines (bsc#1012452). - btrfs: uapi/linux/btrfs_tree.h, use __u8 and __u64 (bsc#1012452). - btrfs: unsplit printed strings (bsc#1012452). - btrfs: untangle gotos a bit in __clear_extent_bit (bsc#1012452). - btrfs: untangle gotos a bit in convert_extent_bit (bsc#1012452). - btrfs: untangle gotos a bit in __set_extent_bit (bsc#1012452). - btrfs: update btrfs_space_info's bytes_may_use timely (bsc#1012452). - btrfs: Use correct format specifier (bsc#1012452). - btrfs: use correct offset for reloc_inode in prealloc_file_extent_cluster() (bsc#1012452). - btrfs: use dynamic allocation for root item in create_subvol (bsc#1012452). - btrfs: Use (eb->start, seq) as search key for tree modification log (bsc#1012452). - btrfs: use existing device constraints table btrfs_raid_array (bsc#1012452). - btrfs: use FLUSH_LIMIT for relocation in reserve_metadata_bytes (bsc#1012452). - btrfs: use fs_info directly (bsc#1012452). - btrfs: use new error message helper in qgroup_account_snapshot (bsc#1012452). - btrfs: use proper type for failrec in extent_state (bsc#1012452). - btrfs: use root when checking need_async_flush (bsc#1012452). - btrfs: use the correct struct for BTRFS_IOC_LOGICAL_INO (bsc#1012452). - btrfs: Use __u64 in exported linux/btrfs.h (bsc#1012452). - btrfs: warn_on for unaccounted spaces (bsc#1012452). - ceph: check i_nlink while converting a file handle to dentry (bsc#1039864). - ceph: Check that the new inode size is within limits in ceph_fallocate() (bsc#1037969). - ceph: Correctly return NXIO errors from ceph_llseek (git-fixes). - ceph: fix file open flags on ppc64 (bsc#1022266). - ceph: fix memory leak in __ceph_setxattr() (bsc#1036763). - ceph: fix potential use-after-free (bsc#1043371). - ceph: fix recursively call between ceph_set_acl and __ceph_setattr (bsc#1034902). - ceph: memory leak in ceph_direct_read_write callback (bsc#1041810). - cfq-iosched: fix the delay of cfq_group's vdisktime under iops mode (bsc#1012829). - cgroup: remove redundant cleanup in css_create (bsc#1012829). - cifs: backport prepath matching fix (bsc#799133). - cifs: small underflow in cnvrtDosUnixTm() (bnc#1043935). - clk: Make x86/ conditional on CONFIG_COMMON_CLK (4.4.68 stable queue). - cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores (4.4.68 stable queue). - crypto: algif_aead - Require setkey before accept(2) (bsc#1031717). - crypto: sha-mb - Fix load failure (bsc#1037384). - cxgb4: Add control net_device for configuring PCIe VF (bsc#1021424). - cxgb4: Add llseek operation for flash debugfs entry (bsc#1021424). - cxgb4: add new routine to get adapter info (bsc#1021424). - cxgb4: Add PCI device ID for new adapter (bsc#1021424). - cxgb4: Add port description for new cards (bsc#1021424). - cxgb4: Add support to enable logging of firmware mailbox commands (bsc#1021424). - cxgb4: Check for firmware errors in the mailbox command loop (bsc#1021424). - cxgb4: correct device ID of T6 adapter (bsc#1021424). - cxgb4/cxgb4vf: Add set VF mac address support (bsc#1021424). - cxgb4/cxgb4vf: Allocate more queues for 25G and 100G adapter (bsc#1021424). - cxgb4/cxgb4vf: Assign netdev->dev_port with port ID (bsc#1021424). - cxgb4/cxgb4vf: Display 25G and 100G link speed (bsc#1021424). - cxgb4/cxgb4vf: Remove deprecated module parameters (bsc#1021424). - cxgb4: DCB message handler needs to use correct portid to netdev mapping (bsc#1021424). - cxgb4: Decode link down reason code obtained from firmware (bsc#1021424). - cxgb4: Do not assume FW_PORT_CMD reply is always port info msg (bsc#1021424). - cxgb4: do not call napi_hash_del() (bsc#1021424). - cxgb4: Do not sleep when mbox cmd is issued from interrupt context (bsc#1021424). - cxgb4: Enable SR-IOV configuration via PCI sysfs interface (bsc#1021424). - cxgb4: Fix issue while re-registering VF mgmt netdev (bsc#1021424). - cxgb4: MU requested by Chelsio (bsc#1021424). - cxgb4: Properly decode port module type (bsc#1021424). - cxgb4: Refactor t4_port_init function (bsc#1021424). - cxgb4: Reset dcb state machine and tx queue prio only if dcb is enabled (bsc#1021424). - cxgb4: Support compressed error vector for T6 (bsc#1021424). - cxgb4: Synchronize access to mailbox (bsc#1021424). - cxgb4: update latest firmware version supported (bsc#1021424). - dell-laptop: Adds support for keyboard backlight timeout AC settings (bsc#1013561). - Disable CONFIG_POWER_SUPPLY_DEBUG in debug kernel (bsc#1031500). - dmaengine: dw: fix typo in Kconfig (bsc#1031717). - dm: fix dm_target_io leak if clone_bio() returns an error (bsc#1040125). - dm-mpath: fix race window in do_end_io() (bsc#1011044). - dm: remove dummy dm_table definition (bsc#1045307) - dm round robin: do not use this_cpu_ptr() without having preemption disabled (bsc#1040125). - dm verity fec: fix block calculation (bsc#1040125). - dm verity fec: fix bufio leaks (bsc#1040125). - dm verity fec: limit error correction recursion (bsc#1040125). - drivers: base: dma-mapping: Fix typo in dmam_alloc_non_coherent comments (bsc#1031717). - Drivers: hv: vmbus: Raise retry/wait limits in vmbus_post_msg() (fate#320485, bsc#1023287, bsc#1028217). - drivers/tty: 8250: only call fintek_8250_probe when doing port I/O (bsc#1031717). - drm/i915: Disable tv output on i9x5gm (bsc#1039700). - drm/i915: Do not touch NULL sg on i915_gem_object_get_pages_gtt() error (bsc#1031717). - drm/i915: Fix mismatched INIT power domain disabling during suspend (bsc#1031717). - drm/i915: Introduce Kabypoint PCH for Kabylake H/DT (bsc#1032581). - drm/i915: Nuke debug messages from the pipe update critical section (bsc#1031717). - drm/i915: Program iboost settings for HDMI/DVI on SKL (bsc#1031717). - drm/i915: relax uncritical udelay_range() (bsc#1031717). - drm/i915: relax uncritical udelay_range() settings (bsc#1031717). - drm/i915: Use pagecache write to prepopulate shmemfs from pwrite-ioctl (bsc#1040463). - drm/mgag200: Fix to always set HiPri for G200e4 (bsc#1015452, bsc#995542). - drm/nouveau/tmr: fully separate alarm execution/pending lists (bsc#1043467). - drm/ttm: fix use-after-free races in vm fault handling (4.4.68 stable queue). - e1000e: Do not return uninitialized stats (bug#1034635). - efi: Do not issue error message when booted under Xen (bnc#1036638). - enic: set skb->hash type properly (bsc#922871 fate#318754). - ext4: fix data corruption for mmap writes (bsc#1012829). - ext4: fix data corruption with EXT4_GET_BLOCKS_ZERO (bsc#1012829). - ext4: fix use-after-iput when fscrypt contexts are inconsistent (bsc#1012829). - f2fs: fix bad prefetchw of NULL page (bsc#1012829). - f2fs: sanity check segment count (4.4.68 stable queue). - Fix kabi after adding new field to struct mddev (bsc#1040351). - Fix soft lockup in svc_rdma_send (bsc#1044854). - fnic: Return 'DID_IMM_RETRY' if rport is not ready (bsc#1035920). - fs/block_dev: always invalidate cleancache in invalidate_bdev() (git-fixes). - fs: fix data invalidation in the cleancache during direct IO (git-fixes). - fs/xattr.c: zero out memory copied to userspace in getxattr (git-fixes). - ftrace: Make ftrace_location_range() global (FATE#322421). - fuse: fix clearing suid, sgid for chown() (bsc#1012829). - hpsa: limit transfer length to 1MB (bsc#1025461). - hwpoison, memcg: forcibly uncharge LRU pages (bnc#1046105). - ib/addr: Fix setting source address in addr6_resolve() (bsc#1044082). - ib/core: Fix kernel crash during fail to initialize device (bsc#1022595). - ib/core: For multicast functions, verify that LIDs are multicast LIDs (bsc#1022595). - ib/core: If the MGID/MLID pair is not on the list return an error (bsc#1022595). - ib/ipoib: Fix deadlock between ipoib_stop and mcast join flow (bsc#1022595). - ib/ipoib: Fix memory leak in create child syscall (bsc#1022595). - ib/mlx5: Assign DSCP for R-RoCE QPs Address Path (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Check supported flow table size (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Enlarge autogroup flow table (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Fix kernel to user leak prevention logic (bsc#966170 bsc#966172 bsc#966191). - ibmvnic: Activate disabled RX buffer pools on reset (bsc#1044767). - ibmvnic: Add set_link_state routine for setting adapter link state (fate#322021, bsc#1031512). - ibmvnic: Allocate number of rx/tx buffers agreed on by firmware (fate#322021, bsc#1031512). - ibmvnic: Allocate zero-filled memory for sub crqs (fate#322021, bsc#1031512). - ibmvnic: Call napi_disable instead of napi_enable in failure path (fate#322021, bsc#1031512). - ibmvnic: Check adapter state during ibmvnic_poll (fate#322021, bsc#1040855). - ibmvnic: Check for driver reset first in ibmvnic_xmit (fate#322021, bsc#1038297). - ibmvnic: Cleanup failure path in ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Clean up tx pools when closing (fate#322021, bsc#1038297). - ibmvnic: Client-initiated failover (bsc#1043990). - ibmvnic: Continue skb processing after skb completion error (fate#322021, bsc#1038297). - ibmvnic: Correct crq and resource releasing (fate#322021, bsc#1031512). - ibmvnic: Correct ibmvnic handling of device open/close (fate#322021, bsc#1031512). - ibmvnic: Correct return code checking for ibmvnic_init during probe (bsc#1045286). - ibmvnic: Create init and release routines for the bounce buffer (fate#322021, bsc#1031512). - ibmvnic: Create init and release routines for the rx pool (fate#322021, bsc#1031512). - ibmvnic: Create init and release routines for the tx pool (fate#322021, bsc#1031512). - ibmvnic: Create init/release routines for stats token (fate#322021, bsc#1031512). - ibmvnic: Deactivate RX pool buffer replenishment on H_CLOSED (fate#322021, bsc#1040855). - ibmvnic: Delete napi's when releasing driver resources (fate#322021, bsc#1038297). - ibmvnic: Disable irq prior to close (fate#322021, bsc#1031512). - ibmvnic: Do not disable IRQ after scheduling tasklet (fate#322021, bsc#1031512). - ibmvnic: driver initialization for kdump/kexec (bsc#1044772). - ibmvnic: Ensure that TX queues are disabled in __ibmvnic_close (bsc#1044767). - ibmvnic: Exit polling routine correctly during adapter reset (bsc#1044767). - ibmvnic: Fix assignment of RX/TX IRQ's (bsc#1046589). - ibmvnic: Fix cleanup of SKB's on driver close (fate#322021, bsc#1040855). - ibmvnic: Fix endian errors in error reporting output (fate#322021, bsc#1031512). - ibmvnic: Fix endian error when requesting device capabilities (fate#322021, bsc#1031512). - ibmvnic: Fix error handling when registering long-term-mapped buffers (bsc#1045568). - ibmvnic: Fix ibmvnic_change_mac_addr struct format (fate#322021, bsc#1031512). - ibmvnic: Fix incorrectly defined ibmvnic_request_map_rsp structure (bsc#1045568). - ibmvnic: Fix initial MTU settings (bsc#1031512). - ibmvnic: fix missing unlock on error in __ibmvnic_reset() (fate#322021, bsc#1038297, Fixes: ed651a10875f). - ibmvnic: Fix overflowing firmware/hardware TX queue (fate#322021, bsc#1031512). - ibmvnic: Fixup atomic API usage (fate#322021, bsc#1031512). - ibmvnic: Free skb's in cases of failure in transmit (fate#322021, bsc#1031512). - ibmvnic: Free tx/rx scrq pointer array when releasing sub-crqs (fate#322021, bsc#1031512). - ibmvnic: Halt TX and report carrier off on H_CLOSED return code (fate#322021, bsc#1040855). - ibmvnic: Handle failover after failed init crq (fate#322021, bsc#1040855). - ibmvnic: Handle processing of CRQ messages in a tasklet (fate#322021, bsc#1031512). - ibmvnic: Initialize completion variables before starting work (fate#322021, bsc#1031512). - ibmvnic: Insert header on VLAN tagged received frame (fate#322021, bsc#1031512). - ibmvnic: Make CRQ interrupt tasklet wait for all capabilities crqs (fate#322021, bsc#1031512). - ibmvnic: Merge the two release_sub_crq_queue routines (fate#322021, bsc#1031512). - ibmvnic: Move ibmvnic adapter intialization to its own routine (fate#322021, bsc#1031512). - ibmvnic: Move initialization of sub crqs to ibmvnic_init (fate#322021, bsc#1031512). - ibmvnic: Move initialization of the stats token to ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Move login and queue negotiation into ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Move login to its own routine (fate#322021, bsc#1031512). - ibmvnic: Move queue restarting in ibmvnic_tx_complete (fate#322021, bsc#1038297). - ibmvnic: Move resource initialization to its own routine (fate#322021, bsc#1038297). - ibmvnic: Non-fatal error handling (fate#322021, bsc#1040855). - ibmvnic: Only retrieve error info if present (fate#322021, bsc#1031512). - ibmvnic: Record SKB RX queue during poll (fate#322021, bsc#1038297). - ibmvnic: Remove debugfs support (fate#322021, bsc#1031512). - ibmvnic: Remove inflight list (fate#322021, bsc#1031512). - ibmvnic: Remove module author mailing address (bsc#1045467). - ibmvnic: Remove netdev notify for failover resets (bsc#1044120). - ibmvnic: Remove unused bouce buffer (fate#322021, bsc#1031512). - ibmvnic: Remove VNIC_CLOSING check from pending_scrq (bsc#1044767). - ibmvnic: Replace is_closed with state field (fate#322021, bsc#1038297). - ibmvnic: Report errors when failing to release sub-crqs (fate#322021, bsc#1031512). - ibmvnic: Reset sub-crqs during driver reset (fate#322021, bsc#1040855). - ibmvnic: Reset the CRQ queue during driver reset (fate#322021, bsc#1040855). - ibmvnic: Reset tx/rx pools on driver reset (fate#322021, bsc#1040855). - ibmvnic: Return failure on attempted mtu change (bsc#1043236). - ibmvnic: Return from ibmvnic_resume if not in VNIC_OPEN state (bsc#1045235). - ibmvnic: Sanitize entire SCRQ buffer on reset (bsc#1044767). - ibmvnic: Send gratuitous arp on reset (fate#322021, bsc#1040855). - ibmvnic: Set real number of rx queues (fate#322021, bsc#1031512). - ibmvnic: Split initialization of scrqs to its own routine (fate#322021, bsc#1031512). - ibmvnic: Track state of adapter napis (fate#322021, bsc#1040855). - ibmvnic: Unmap longer term buffer before free (fate#322021, bsc#1031512). - ibmvnic: Updated reset handling (fate#322021, bsc#1038297). - ibmvnic: Update main crq initialization and release (fate#322021, bsc#1031512). - ibmvnic: Use common counter for capabilities checks (fate#322021, bsc#1031512). - ibmvnic: use max_mtu instead of req_mtu for MTU range check (bsc#1031512). - ibmvnic: Validate napi exist before disabling them (fate#322021, bsc#1031512). - ibmvnic: Wait for any pending scrqs entries at driver close (fate#322021, bsc#1038297). - ibmvnic: Whitespace correction in release_rx_pools (fate#322021, bsc#1038297). - iio: hid-sensor: Store restore poll and hysteresis on S3 (bsc#1031717). - infiniband: avoid dereferencing uninitialized dst on error path (git-fixes). - iommu/arm-smmu: Disable stalling faults for all endpoints (bsc#1038843). - iommu/dma: Respect IOMMU aperture when allocating (bsc#1038842). - iommu/exynos: Block SYSMMU while invalidating FLPD cache (bsc#1038848). - iommu: Handle default domain attach failure (bsc#1038846). - iommu/vt-d: Do not over-free page table directories (bsc#1038847). - ipv4, ipv6: ensure raw socket message is big enough to hold an IP header (4.4.68 stable queue). - ipv6: Do not use ufo handling on later transformed packets (bsc#1042286). - ipv6: fix endianness error in icmpv6_err (bsc#1042286). - ipv6: initialize route null entry in addrconf_init() (4.4.68 stable queue). - ipv6: release dst on error in ip6_dst_lookup_tail (git-fixes). - ipv6: reorder ip6_route_dev_notifier after ipv6_dev_notf (4.4.68 stable queue). - isa: Call isa_bus_init before dependent ISA bus drivers register (bsc#1031717). - iscsi-target: Return error if unable to add network portal (bsc#1032803). - iw_cxgb4: Fix error return code in c4iw_rdev_open() (bsc#1026570). - iw_cxgb4: Guard against null cm_id in dump_ep/qp (bsc#1026570). - iwlwifi: 8000: fix MODULE_FIRMWARE input. - iwlwifi: 9000: increase the number of queues. - iwlwifi: add device ID for 8265. - iwlwifi: add device IDs for the 8265 device. - iwlwifi: add disable_11ac module param. - iwlwifi: add new 3168 series devices support. - iwlwifi: add new 8260 PCI IDs. - iwlwifi: add new 8265. - iwlwifi: add new 8265 series PCI ID. - iwlwifi: Add new PCI IDs for 9260 and 5165 series. - iwlwifi: Add PCI IDs for the new 3168 series. - iwlwifi: Add PCI IDs for the new series 8165. - iwlwifi: add support for 12K Receive Buffers. - iwlwifi: add support for getting HW address from CSR. - iwlwifi: avoid d0i3 commands when no/init ucode is loaded. - iwlwifi: bail out in case of bad trans state. - iwlwifi: block the queues when we send ADD_STA for uAPSD. - iwlwifi: change the Intel Wireless email address. - iwlwifi: change the Intel Wireless email address. - iwlwifi: check for valid ethernet address provided by OEM. - iwlwifi: clean up transport debugfs handling. - iwlwifi: clear ieee80211_tx_info->driver_data in the op_mode. - iwlwifi: Document missing module options. - iwlwifi: dump prph registers in a common place for all transports. - iwlwifi: dvm: advertise NETIF_F_SG. - iwlwifi: dvm: fix compare_const_fl.cocci warnings. - iwlwifi: dvm: handle zero brightness for wifi LED. - iwlwifi: dvm: remove a wrong dependency on m. - iwlwifi: dvm: remove Kconfig default. - iwlwifi: dvm: remove stray debug code. - iwlwifi: export the _no_grab version of PRPH IO functions. - iwlwifi: expose fw usniffer mode to more utilities. - iwlwifi: fix double hyphen in MODULE_FIRMWARE for 8000. - iwlwifi: Fix firmware name maximum length definition. - iwlwifi: fix name of ucode loaded for 8265 series. - iwlwifi: fix printf specifier. - iwlwifi: generalize d0i3_entry_timeout module parameter. - iwlwifi: mvm: adapt the firmware assert log to new firmware. - iwlwifi: mvm: add 9000-series RX API. - iwlwifi: mvm: add 9000 series RX processing. - iwlwifi: mvm: add a non-trigger window to fw dbg triggers. - iwlwifi: mvm: add an option to start rs from HT/VHT rates. - iwlwifi: mvm: Add a station in monitor mode. - iwlwifi: mvm: add bt rrc and ttc to debugfs. - iwlwifi: mvm: add bt settings to debugfs. - iwlwifi: mvm: add ctdp operations to debugfs. - iwlwifi: mvm: add CT-KILL notification. - iwlwifi: mvm: add debug print if scan config is ignored. - iwlwifi: mvm: add extended dwell time. - iwlwifi: mvm: add new ADD_STA command version. - iwlwifi: mvm: Add P2P client snoozing. - iwlwifi: mvm: add registration to cooling device. - iwlwifi: mvm: add registration to thermal zone. - iwlwifi: mvm: add support for negative temperatures. - iwlwifi: mvm: add tlv for multi queue rx support. - iwlwifi: mvm: add trigger for firmware dump upon TDLS events. - iwlwifi: mvm: add trigger for firmware dump upon TX response status. - iwlwifi: mvm: advertise NETIF_F_SG. - iwlwifi: mvm: Align bt-coex priority with requirements. - iwlwifi: mvm: allow to disable beacon filtering for AP/GO interface. - iwlwifi: mvm: avoid harmless -Wmaybe-uninialized warning. - iwlwifi: mvm: avoid panics with thermal device usage. - iwlwifi: mvm: avoid to WARN about gscan capabilities. - iwlwifi: mvm: bail out if CTDP start operation fails. - iwlwifi: mvm: bump firmware API to 21. - iwlwifi: mvm: bump max API to 20. - iwlwifi: mvm: change access to ieee80211_hdr. - iwlwifi: mvm: change iwl_mvm_get_key_sta_id() to return the station. - iwlwifi: mvm: change mcc update API. - iwlwifi: mvm: change name of iwl_mvm_d3_update_gtk. - iwlwifi: mvm: Change number of associated stations when station becomes associated. - iwlwifi: mvm: change protocol offload flows. - iwlwifi: mvm: change the check for ADD_STA status. - iwlwifi: mvm: check FW's response for nvm access write cmd. - iwlwifi: mvm: check iwl_mvm_wowlan_config_key_params() return value. - iwlwifi: mvm: check minimum temperature notification length. - iwlwifi: mvm: cleanup roc te on restart cleanup. - iwlwifi: mvm: Configure fragmented scan for scheduled scan. - iwlwifi: mvm: configure scheduled scan according to traffic conditions. - iwlwifi: mvm: constify the parameters of a few functions in fw-dbg.c. - iwlwifi: mvm: Disable beacon storing in D3 when WOWLAN configured. - iwlwifi: mvm: disable DQA support. - iwlwifi: mvm: do not ask beacons when P2P GO vif and no assoc sta. - iwlwifi: mvm: do not keep an mvm ref when the interface is down. - iwlwifi: mvm: do not let NDPs mess the packet tracking. - iwlwifi: mvm: do not restart HW if suspend fails with unified image. - iwlwifi: mvm: Do not switch to D3 image on suspend. - iwlwifi: mvm: do not try to offload AES-CMAC in AP/IBSS modes. - iwlwifi: mvm: drop low_latency_agg_frame_cnt_limit. - iwlwifi: mvm: dump more registers upon error. - iwlwifi: mvm: dump the radio registers when the firmware crashes. - iwlwifi: mvm: enable L3 filtering. - iwlwifi: mvm: Enable MPLUT only on supported hw. - iwlwifi: mvm: enable VHT MU-MIMO for supported hardware. - iwlwifi: mvm: extend time event duration. - iwlwifi: mvm: fix accessing Null pointer during fw dump collection. - iwlwifi: mvm: fix d3_test with unified D0/D3 images. - iwlwifi: mvm: fix debugfs signedness warning. - iwlwifi: mvm: fix extended dwell time. - iwlwifi: mvm: fix incorrect fallthrough in iwl_mvm_check_running_scans(). - iwlwifi: mvm: fix memory leaks in error paths upon fw error dump. - iwlwifi: mvm: fix netdetect starting/stopping for unified images. - iwlwifi: mvm: fix RSS key sizing. - iwlwifi: mvm: fix unregistration of thermal in some error flows. - iwlwifi: mvm: flush all used TX queues before suspending. - iwlwifi: mvm: forbid U-APSD for P2P Client if the firmware does not support it. - iwlwifi: mvm: handle pass all scan reporting. - iwlwifi: mvm: ignore LMAC scan notifications when running UMAC scans. - iwlwifi: mvm: infrastructure for frame-release message. - iwlwifi: mvm: kill iwl_mvm_enable_agg_txq. - iwlwifi: mvm: let the firmware choose the antenna for beacons. - iwlwifi: mvm: make collecting fw debug data optional. - iwlwifi: mvm: move fw-dbg code to separate file. - iwlwifi: mvm: only release the trans ref if d0i3 is supported in fw. - iwlwifi: mvm: prepare the code towards TSO implementation. - iwlwifi: mvm: refactor d3 key update functions. - iwlwifi: mvm: refactor the way fw_key_table is handled. - iwlwifi: mvm: remove an extra tab. - iwlwifi: mvm: Remove bf_vif from iwl_power_vifs. - iwlwifi: mvm: Remove iwl_mvm_update_beacon_abort. - iwlwifi: mvm: remove redundant d0i3 flag from the config struct. - iwlwifi: mvm: remove shadowing variable. - iwlwifi: mvm: remove stray nd_config element. - iwlwifi: mvm: remove the vif parameter of iwl_mvm_configure_bcast_filter(). - iwlwifi: mvm: remove unnecessary check in iwl_mvm_is_d0i3_supported(). - iwlwifi: mvm: remove useless WARN_ON and rely on cfg80211's combination. - iwlwifi: mvm: report wakeup for wowlan. - iwlwifi: mvm: reset mvm->scan_type when firmware is started. - iwlwifi: mvm: return the cooling state index instead of the budget. - iwlwifi: mvm: ROC: cleanup time event info on FW failure. - iwlwifi: mvm: ROC: Extend the ROC max delay duration & limit ROC duration. - iwlwifi: mvm: rs: fix a potential out of bounds access. - iwlwifi: mvm: rs: fix a theoretical access to uninitialized array elements. - iwlwifi: mvm: rs: fix a warning message. - iwlwifi: mvm: rs: fix TPC action decision algorithm. - iwlwifi: mvm: rs: fix TPC statistics handling. - iwlwifi: mvm: Send power command on BSS_CHANGED_BEACON_INFO if needed. - iwlwifi: mvm: set default new STA as non-aggregated. - iwlwifi: mvm: set the correct amsdu enum values. - iwlwifi: mvm: set the correct descriptor size for tracing. - iwlwifi: mvm: small update in the firmware API. - iwlwifi: mvm: support A-MSDU in A-MPDU. - iwlwifi: mvm: support beacon storing. - iwlwifi: mvm: support description for user triggered fw dbg collection. - iwlwifi: mvm: support rss queues configuration command. - iwlwifi: mvm: Support setting continuous recording debug mode. - iwlwifi: mvm: support setting minimum quota from debugfs. - iwlwifi: mvm: support sw queue start/stop from mvm. - iwlwifi: mvm: take care of padded packets. - iwlwifi: mvm: take the transport ref back when leaving. - iwlwifi: mvm: track low-latency sources separately. - iwlwifi: mvm: update GSCAN capabilities. - iwlwifi: mvm: update ucode status before stopping device. - iwlwifi: mvm: use build-time assertion for fw trigger ID. - iwlwifi: mvm: use firmware station lookup, combine code. - iwlwifi: mvm: various trivial cleanups. - iwlwifi: mvm: writing zero bytes to debugfs causes a crash. - iwlwifi: nvm: fix loading default NVM file. - iwlwifi: nvm: fix up phy section when reading it. - iwlwifi: pcie: add 9000 series multi queue rx DMA support. - iwlwifi: pcie: add infrastructure for multi-queue rx. - iwlwifi: pcie: add initial RTPM support for PCI. - iwlwifi: pcie: Add new configuration to enable MSIX. - iwlwifi: pcie: add pm_prepare and pm_complete ops. - iwlwifi: pcie: add RTPM support when wifi is enabled. - iwlwifi: pcie: aggregate Flow Handler configuration writes. - iwlwifi: pcie: allow the op_mode to block the tx queues. - iwlwifi: pcie: allow to pretend to have Tx CSUM for debug. - iwlwifi: pcie: avoid restocks inside rx loop if not emergency. - iwlwifi: pcie: buffer packets to avoid overflowing Tx queues. - iwlwifi: pcie: build an A-MSDU using TSO core. - iwlwifi: pcie: configure more RFH settings. - iwlwifi: pcie: detect and workaround invalid write ptr behavior. - iwlwifi: pcie: do not increment / decrement a bool. - iwlwifi: pcie: enable interrupts before releasing the NIC's CPU. - iwlwifi: pcie: enable multi-queue rx path. - iwlwifi: pcie: extend device reset delay. - iwlwifi: pcie: fine tune number of rxbs. - iwlwifi: pcie: fix a race in firmware loading flow. - iwlwifi: pcie: fix erroneous return value. - iwlwifi: pcie: fix global table size. - iwlwifi: pcie: fix identation in trans.c. - iwlwifi: pcie: fix RF-Kill vs. firmware load race. - iwlwifi: pcie: forbid RTPM on device removal. - iwlwifi: pcie: mark command queue lock with separate lockdep class. - iwlwifi: pcie: prevent skbs shadowing in iwl_trans_pcie_reclaim. - iwlwifi: pcie: refactor RXBs reclaiming code. - iwlwifi: pcie: remove ICT allocation message. - iwlwifi: pcie: remove pointer from debug message. - iwlwifi: pcie: re-organize code towards TSO. - iwlwifi: pcie: set RB chunk size back to 64. - iwlwifi: pcie: update iwl_mpdu_desc fields. - iwlwifi: print index in api/capa flags parsing message. - iwlwifi: refactor the code that reads the MAC address from the NVM. - iwlwifi: remove IWL_DL_LED. - iwlwifi: remove unused parameter from grab_nic_access. - iwlwifi: replace d0i3_mode and wowlan_d0i3 with more generic variables. - iwlwifi: set max firmware version of 7265 to 17. - iwlwifi: support ucode with d0 unified image - regular and usniffer. - iwlwifi: trans: make various conversion macros inlines. - iwlwifi: trans: support a callback for ASYNC commands. - iwlwifi: treat iwl_parse_nvm_data() MAC addr as little endian. - iwlwifi: tt: move ucode_loaded check under mutex. - iwlwifi: uninline iwl_trans_send_cmd. - iwlwifi: update host command messages to new format. - iwlwifi: Update PCI IDs for 8000 and 9000 series. - iwlwifi: update support for 3168 series firmware and NVM. - iwlwifi: various comments and code cleanups. - jump label: fix passing kbuild_cflags when checking for asm goto support (git-fixes). - kabi: Hide new include in arch/powerpc/kernel/process.c (fate#322421). - kabi: ignore fs_info parameter for tracepoints that didn't have it (bsc#1044912). - kABI: move and hide new cxgbi device owner field (bsc#1018885). - kABI: protect cgroup include in kernel/kthread (kabi). - kABI: protect struct fib_info (kabi). - kABI: protect struct mnt_namespace (kabi). - kABI: protect struct pglist_data (kabi). - kABI: protect struct snd_fw_async_midi_port (kabi). - kABI: protect struct xlog (bsc#1043598). - kABI: restore ttm_ref_object_add parameters (kabi). - kabi/severities: ignore kABi changes in iwlwifi stuff itself - kabi workaround for net: ipv6: Fix processing of RAs in presence of VRF (bsc#1042286). - kernel-binary.spec: Propagate MAKE_ARGS to %build (bsc#1012422) - kprobes/x86: Fix kernel panic when certain exception-handling addresses are probed (4.4.68 stable queue). - kvm: better MWAIT emulation for guests (bsc#1031142). - kvm: nVMX: do not leak PML full vmexit to L1 (4.4.68 stable queue). - kvm: nVMX: initialize PML fields in vmcs02 (4.4.68 stable queue). - kvm: svm: add support for RDTSCP (bsc#1033117). - l2tp: fix race in l2tp_recv_common() (bsc#1042286). - lan78xx: use skb_cow_head() to deal with cloned skbs (bsc#1045154). - leds: ktd2692: avoid harmless maybe-uninitialized warning (4.4.68 stable queue). - libata-scsi: Fixup ata_gen_passthru_sense() (bsc#1040125). - libceph: NULL deref on crush_decode() error path (bsc#1044015). - libcxgb: add library module for Chelsio drivers (bsc#1021424). - lib/mpi: mpi_read_raw_data(): fix nbits calculation (bsc#1003581). - lib/mpi: mpi_read_raw_data(): purge redundant clearing of nbits (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): do not include leading zero SGEs in nbytes (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): fix nbits calculation (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): fix out-of-bounds buffer access (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): purge redundant clearing of nbits (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): replace len argument by nbytes (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): sanitize meaning of indices (bsc#1003581). - libnvdimm, pfn: fix 'npfns' vs section alignment (bsc#1040125). - livepatch: Allow architectures to specify an alternate ftrace location (FATE#322421). - locking/ww_mutex: Fix compilation of __WW_MUTEX_INITIALIZER (bsc#1031717). - loop: Add PF_LESS_THROTTLE to block/loop device thread (bsc#1027101). - lpfc: remove incorrect lockdep assertion (bsc#1040125). - md: allow creation of mdNNN arrays via md_mod/parameters/new_array (bsc#1032339). - md.c:didn't unlock the mddev before return EINVAL in array_size_store (bsc#1038143). - md-cluster: fix potential lock issue in add_new_disk (bsc#1041087). - md: fix a null dereference (bsc#1040351). - md: handle read-only member devices better (bsc#1033281). - md: MD_CLOSING needs to be cleared after called md_set_readonly or do_md_stop (bsc#1038142). - md/raid1: avoid reusing a resync bio after error handling (Fate#311379). - md: support disabling of create-on-open semantics (bsc#1032339). - md: use a separate bio_set for synchronous IO (bsc#1040351). - media: am437x-vpfe: fix an uninitialized variable bug (bsc#1031717). - media: b2c2: use IS_REACHABLE() instead of open-coding it (bsc#1031717). - media: c8sectpfe: Rework firmware loading mechanism (bsc#1031717). - media: cx231xx-audio: fix NULL-deref at probe (bsc#1031717). - media: cx231xx-cards: fix NULL-deref at probe (bsc#1031717). - media: cx23885: uninitialized variable in cx23885_av_work_handler() (bsc#1031717). - media: DaVinci-VPBE: Check return value of a setup_if_config() call in vpbe_set_output() (bsc#1031717). - media: DaVinci-VPFE-Capture: fix error handling (bsc#1031717). - media: dib0700: fix NULL-deref at probe (bsc#1031717). - media: dvb-usb: avoid link error with dib3000m{b,c| (bsc#1031717). - media: exynos4-is: fix a format string bug (bsc#1031717). - media: gspca: konica: add missing endpoint sanity check (bsc#1031717). - media: lirc_imon: do not leave imon_probe() with mutex held (bsc#1031717). - media: pvrusb2: reduce stack usage pvr2_eeprom_analyze() (bsc#1031717). - media: rc: allow rc modules to be loaded if rc-main is not a module (bsc#1031717). - media: s5p-mfc: Fix unbalanced call to clock management (bsc#1031717). - media: sh-vou: clarify videobuf2 dependency (bsc#1031717). - media: staging: media: davinci_vpfe: unlock on error in vpfe_reqbufs() (bsc#1031717). - media: usbvision: fix NULL-deref at probe (bsc#1031717). - media: uvcvideo: Fix empty packet statistic (bsc#1031717). - media: vb2: Fix an off by one error in 'vb2_plane_vaddr' (bsc#1043231). - mem-hotplug: fix node spanned pages when we have a movable node (bnc#1034671). - mips: R2-on-R6 MULTU/MADDU/MSUBU emulation bugfix (4.4.68 stable queue). - mlx4: Fix memory leak after mlx4_en_update_priv() (bsc#966170 bsc#966172 bsc#966191). - mmc: debugfs: correct wrong voltage value (bsc#1031717). - mmc: Downgrade error level (bsc#1042536). - mm,compaction: serialize waitqueue_active() checks (bsc#971975). - mmc: sdhci-pxav3: fix higher speed mode capabilities (bsc#1031717). - mmc: sdhci: restore behavior when setting VDD via external regulator (bsc#1031717). - mm: fix stray kernel-doc notation (bnc#971975 VM -- git fixes). - mm: fix new crash in unmapped_area_topdown() (bnc#1039348). - mm/hugetlb: check for reserved hugepages during memory offline (bnc#971975 VM -- git fixes). - mm/hugetlb: fix incorrect hugepages count during mem hotplug (bnc#971975 VM -- git fixes). - module: fix memory leak on early load_module() failures (bsc#1043014). - mwifiex: Avoid skipping WEP key deletion for AP (4.4.68 stable queue). - mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print (4.4.68 stable queue). - mwifiex: pcie: fix cmd_buf use-after-free in remove/reset (bsc#1031717). - mwifiex: Removed unused 'pkt_type' variable (bsc#1031717). - mwifiex: remove redundant dma padding in AMSDU (4.4.68 stable queue). - mwifiex: Remove unused 'bcd_usb' variable (bsc#1031717). - mwifiex: Remove unused 'chan_num' variable (bsc#1031717). - mwifiex: Remove unused 'pm_flag' variable (bsc#1031717). - mwifiex: Remove unused 'sta_ptr' variable (bsc#1031717). - net: bridge: start hello timer only if device is up (bnc#1012382). - netfilter: nf_conntrack_sip: extend request line validation (bsc#1042286). - netfilter: nf_ct_expect: remove the redundant slash when policy name is empty (bsc#1042286). - netfilter: nf_dup_ipv6: set again FLOWI_FLAG_KNOWN_NH at flowi6_flags (bsc#1042286). - netfilter: nf_nat_snmp: Fix panic when snmp_trap_helper fails to register (bsc#1042286). - netfilter: nfnetlink_queue: reject verdict request from different portid (bsc#1042286). - netfilter: restart search if moved to other chain (bsc#1042286). - netfilter: use fwmark_reflect in nf_send_reset (bsc#1042286). - net: fix compile error in skb_orphan_partial() (bnc#1012382). - net: ibmvnic: Remove unused net_stats member from struct ibmvnic_adapter (fate#322021, bsc#1031512). - net: icmp_route_lookup should use rt dev to determine L3 domain (bsc#1042286). - net: ipv6: Fix processing of RAs in presence of VRF (bsc#1042286). - net: ipv6: set route type for anycast routes (bsc#1042286). - net: l3mdev: Add master device lookup by index (bsc#1042286). - net: make netdev_for_each_lower_dev safe for device removal (bsc#1042286). - net/mlx5: Do not unlock fte while still using it (bsc#966170 bsc#966172 bsc#966191). - net/mlx5e: Fix timestamping capabilities reporting (bsc#966170 bsc#1015342). - net/mlx5e: Modify TIRs hash only when it's needed (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Fix create autogroup prev initializer (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Prevent setting multicast macs for VFs (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Release FTE lock in error flow (bsc#966170 bsc#966172 bsc#966191). - net: vrf: Create FIB tables on link create (bsc#1042286). - net: vrf: Fix crash when IPv6 is disabled at boot time (bsc#1042286). - net: vrf: Fix dev refcnt leak due to IPv6 prefix route (bsc#1042286). - net: vrf: Fix dst reference counting (bsc#1042286). - net: vrf: protect changes to private data with rcu (bsc#1042286). - net: vrf: Switch dst dev to loopback on device delete (bsc#1042286). - netxen_nic: set rcode to the return status from the call to netxen_issue_cmd (bsc#966339 FATE#320150). - nfsd4: minor NFSv2/v3 write decoding cleanup (bsc#1034670). - nfsd: check for oversized NFSv2/v3 arguments (bsc#1034670). - nfsd: stricter decoding of write-like NFSv2/v3 ops (bsc#1034670). - nfs: Fix an LOCK/OPEN race when unlinking an open file (git-fixes). - nfs: Fix "Do not increment lock sequence ID after NFS4ERR_MOVED" (git-fixes). - nfs: Fix inode corruption in nfs_prime_dcache() (git-fixes). - nfs: Fix missing pg_cleanup after nfs_pageio_cond_complete() (git-fixes). - nfs: Use GFP_NOIO for two allocations in writeback (git-fixes). - nfsv4.1: Fix Oopsable condition in server callback races (git-fixes). - nfsv4: do not let hanging mounts block other mounts (bsc#1040364). - nfsv4: fix a reference leak caused WARNING messages (git-fixes). - nfsv4: Fix the underestimation of delegation XDR space reservation (git-fixes). - nsfs: mark dentry with DCACHE_RCUACCESS (bsc#1012829). - nvme: Delete created IO queues on reset (bsc#1031717). - nvme: submit nvme_admin_activate_fw to admin queue (bsc#1044532). - ocfs2/dlmglue: prepare tracking logic to avoid recursive cluster lock (bsc#1004003). - ocfs2: fix deadlock issue when taking inode lock at vfs entry points (bsc#1004003). - overlayfs: compat, fix incorrect dentry use in ovl_rename2 (bsc#1032400). - overlayfs: compat, use correct dentry to detect compat mode in ovl_compat_is_whiteout (bsc#1032400). - pci: pciehp: Prioritize data-link event over presence detect (bsc#1031040,bsc#1037483). - pci: Reverse standard ACS vs device-specific ACS enabling (bsc#1030057). - pci: Work around Intel Sunrise Point PCH incorrect ACS capability (bsc#1030057). - percpu: remove unused chunk_alloc parameter from pcpu_get_pages() (bnc#971975 VM -- git fixes). - perf/x86/intel/rapl: Make Knights Landings support functional (bsc#1042517). - perf/x86/intel/uncore: Remove SBOX support for Broadwell server (bsc#1035887). - phy: qcom-usb-hs: Add depends on EXTCON (4.4.68 stable queue). - pid_ns: Sleep in TASK_INTERRUPTIBLE in zap_pid_ns_processes (bnc#1012985). - PKCS#7: fix missing break on OID_sha224 case (bsc#1031717). - platform/x86: fujitsu-laptop: use brightness_set_blocking for LED-setting callbacks (bsc#1031717). - pm / QoS: Fix memory leak on resume_latency.notifiers (bsc#1043231). - pm / wakeirq: Enable dedicated wakeirq for suspend (bsc#1031717). - pm / wakeirq: Fix spurious wake-up events for dedicated wakeirqs (bsc#1031717). - pm / wakeirq: report a wakeup_event on dedicated wekup irq (bsc#1031717). - power: bq27xxx: fix register numbers of bq27500 (bsc#1031717). - powerpc/64: Fix flush_(d|i)cache_range() called from modules (bnc#863764 fate#315275, LTC#103998). - powerpc: Create a helper for getting the kernel toc value (FATE#322421). - powerpc/fadump: add reschedule point while releasing memory (bsc#1040609). - powerpc/fadump: avoid duplicates in crash memory ranges (bsc#1037669). - powerpc/fadump: avoid holes in boot memory area when fadump is registered (bsc#1037669). - powerpc/fadump: provide a helpful error message (bsc#1037669). - powerpc/fadump: Reserve memory at an offset closer to bottom of RAM (bsc#1032141). - powerpc/fadump: return error when fadump registration fails (bsc#1040567). - powerpc/fadump: Update fadump documentation (bsc#1032141). - powerpc/ftrace: Add Kconfig & Make glue for mprofile-kernel (FATE#322421). - powerpc/ftrace: Add support for -mprofile-kernel ftrace ABI (FATE#322421). - powerpc/ftrace: Pass the correct stack pointer for DYNAMIC_FTRACE_WITH_REGS (FATE#322421). - powerpc/ftrace: Use $(CC_FLAGS_FTRACE) when disabling ftrace (FATE#322421). - powerpc/ftrace: Use generic ftrace_modify_all_code() (FATE#322421). - powerpc: introduce TIF_KGR_IN_PROGRESS thread flag (FATE#322421). - powerpc/livepatch: Add livepatch header (FATE#322421). - powerpc/livepatch: Add live patching support on ppc64le (FATE#322421). - powerpc/livepatch: Add livepatch stack to struct thread_info (FATE#322421). - powerpc/module: Create a special stub for ftrace_caller() (FATE#322421). - powerpc/module: Mark module stubs with a magic value (FATE#322421). - powerpc/module: Only try to generate the ftrace_caller() stub once (FATE#322421). - powerpc/modules: Never restore r2 for a mprofile-kernel style mcount() call (FATE#322421). - powerpc/powernv: Fix opal_exit tracepoint opcode (4.4.68 stable queue). - power: supply: bq24190_charger: Call power_supply_changed() for relevant component (4.4.68 stable queue). - power: supply: bq24190_charger: Call set_mode_host() on pm_resume() (4.4.68 stable queue). - power: supply: bq24190_charger: Do not read fault register outside irq_handle_thread() (4.4.68 stable queue). - power: supply: bq24190_charger: Fix irq trigger to IRQF_TRIGGER_FALLING (4.4.68 stable queue). - power: supply: bq24190_charger: Handle fault before status on interrupt (4.4.68 stable queue). - power: supply: bq24190_charger: Install irq_handler_thread() at end of probe() (4.4.68 stable queue). - printk: Correctly handle preemption in console_unlock() (bsc#1046434). - printk: Switch to the sync mode when an emergency message is printed (bsc#1034995). - printk/xen: Force printk sync mode when migrating Xen guest (bsc#1043347). - quota: fill in Q_XGETQSTAT inode information for inactive quotas (bsc#1042356). - radix-tree: fix radix_tree_iter_retry() for tagged iterators (bsc#1012829). - ravb: Fix use-after-free on `ifconfig eth0 down` (git-fixes). - rdma/iw_cxgb4: Add missing error codes for act open cmd (bsc#1026570). - rdma/iw_cxgb4: Always wake up waiter in c4iw_peer_abort_intr() (bsc#1026570). - rdma/iw_cxgb4: Low resource fixes for Completion queue (bsc#1026570). - rdma/iw_cxgb4: only read markers_enabled mod param once (bsc#1026570). - regulator: isl9305: fix array size (bsc#1031717). - reiserfs: do not preallocate blocks for extended attributes (bsc#990682). - Revert "acpi, nfit, libnvdimm: fix interleave set cookie calculation (64-bit comparison)" (kabi). - Revert "btrfs: qgroup: Move half of the qgroup accounting time out of" (bsc#1017461 bsc#1033885). - Revert "KVM: nested VMX: disable perf cpuid reporting" (4.4.68 stable queue). - Revert "l2tp: take reference on sessions being dumped" (kabi). - Revert "mac80211: pass block ack session timeout to to driver" (kabi). - Revert "mac80211: RX BA support for sta max_rx_aggregation_subframes" (kabi). - Revert "wlcore: Add RX_BA_WIN_SIZE_CHANGE_EVENT event" (kabi). - rpm/kernel-spec-macros: Fix the check if there is no rebuild counter (bsc#1012060) - rpm/SLES-UEFI-SIGN-Certificate-2048.crt: Update the certificate (bsc#1035922) - rtnetlink: NUL-terminate IFLA_PHYS_PORT_NAME string (4.4.68 stable queue). - rtnl: reset calcit fptr in rtnl_unregister() (bsc#1042286). - s390/dasd: check if query host access feature is supported (bsc#1037871). - sbp-target: Fix second argument of percpu_ida_alloc() (bsc#1032803). - scsi: be2iscsi: Add FUNCTION_RESET during driver unload (bsc#1038458). - scsi: be2iscsi: Add IOCTL to check UER supported (bsc#1038458). - scsi: be2iscsi: Add TPE recovery feature (bsc#1038458). - scsi: be2iscsi: Add V1 of EPFW cleanup IOCTL (bsc#1038458). - scsi: be2iscsi: allocate enough memory in beiscsi_boot_get_sinfo() (bsc#1038458). - scsi: be2iscsi: Check all zeroes IP before issuing IOCTL (bsc#1038458). - scsi: be2iscsi: Fail the sessions immediately after TPE (bsc#1038458). - scsi: be2iscsi: Fix async PDU handling path (bsc#1038458). - scsi: be2iscsi: Fix bad WRB index error (bsc#1038458). - scsi: be2iscsi: Fix checks for HBA in error state (bsc#1038458). - scsi: be2iscsi: Fix gateway APIs to support IPv4 & IPv6 (bsc#1038458). - scsi: be2iscsi: Fix POST check and reset sequence (bsc#1038458). - scsi: be2iscsi: Fix queue and connection parameters (bsc#1038458). - scsi: be2iscsi: Fix release of DHCP IP in static mode (bsc#1038458). - scsi: be2iscsi: Fix to add timer for UE detection (bsc#1038458). - scsi: be2iscsi: Fix to make boot discovery non-blocking (bsc#1038458). - scsi: be2iscsi: Fix to use correct configuration values (bsc#1038458). - scsi: be2iscsi: Handle only NET_PARAM in iface_get_param (bsc#1038458). - scsi: be2iscsi: Move functions to right files (bsc#1038458). - scsi: be2iscsi: Move VLAN code to common iface_set_param (bsc#1038458). - scsi: be2iscsi: Reduce driver load/unload time (bsc#1038458). - scsi: be2iscsi: Remove alloc_mcc_tag & beiscsi_pci_soft_reset (bsc#1038458). - scsi: be2iscsi: Remove isr_lock and dead code (bsc#1038458). - scsi: be2iscsi: Rename iface get/set/create/destroy APIs (bsc#1038458). - scsi: be2iscsi: Replace _bh version for mcc_lock spinlock (bsc#1038458). - scsi: be2iscsi: Set and return right iface v4/v6 states (bsc#1038458). - scsi: be2iscsi: Update copyright information (bsc#1038458). - scsi: be2iscsi: Update iface handle before any set param (bsc#1038458). - scsi: be2iscsi: Update the driver version (bsc#1038458). - scsi: cxgb4i: libcxgbi: add missing module_put() (bsc#1018885). - scsi: cxgb4i: libcxgbi: cxgb4: add T6 iSCSI completion feature (bsc#1021424). - scsi: cxlflash: Remove the device cleanly in the system shutdown path (bsc#1028310, fate#321597, bsc#1034762). cherry-pick from SP3 - scsi_dh_alua: do not call BUG_ON when updating port group (bsc#1028340). - scsi_dh_alua: Do not retry for unmapped device (bsc#1012910). - scsi_error: count medium access timeout only once per EH run (bsc#993832, bsc#1032345). - scsi: fnic: Correcting rport check location in fnic_queuecommand_lck (bsc#1035920). - scsi: ipr: do not set DID_PASSTHROUGH on CHECK CONDITION (bsc#1034419). - scsi: ipr: Driver version 2.6.4 (bsc#1031555). - scsi: ipr: Error path locking fixes (bsc#1031555). - scsi: ipr: Fix abort path race condition (bsc#1031555). - scsi: ipr: Fix missed EH wakeup (bsc#1031555). - scsi: ipr: Fix SATA EH hang (bsc#1031555). - scsi: ipr: Remove redundant initialization (bsc#1031555). - scsi: mac_scsi: Fix MAC_SCSI=m option when SCSI=m (4.4.68 stable queue). - scsi: scsi_dh_alua: Check scsi_device_get() return value (bsc#1040125). - scsi: scsi_dh_emc: return success in clariion_std_inquiry() (4.4.68 stable queue). - scsi_transport_fc: do not call queue_work under lock (bsc#1013887). - scsi_transport_fc: fixup race condition in fc_rport_final_delete() (bsc#1013887). - scsi_transport_fc: return -EBUSY for deleted vport (bsc#1013887). - sctp: check af before verify address in sctp_addr_id2transport (git-fixes). - serial: 8250_omap: Fix probe and remove for PM runtime (4.4.68 stable queue). - smartpqi: limit transfer length to 1MB (bsc#1025461). - staging: emxx_udc: remove incorrect __init annotations (4.4.68 stable queue). - staging: rtl8188eu: prevent an underflow in rtw_check_beacon_data() (bsc#1031717). - staging: wlan-ng: add missing byte order conversion (4.4.68 stable queue). - sunrpc: Allow xprt->ops->timer method to sleep (git-fixes). - sunrpc: ensure correct error is reported by xs_tcp_setup_socket() (git-fixes). - sunrpc: fix UDP memory accounting (git-fixes). - sunrpc: Silence WARN_ON when NFSv4.1 over RDMA is in use (git-fixes). - supported.conf: added drivers/net/ethernet/chelsio/libcxgb/libcxgb - supported.conf: Bugzilla and FATE references for dcdbas and dell_rbu - sysfs: be careful of error returns from ops->show() (bsc#1028883). - tcp: account for ts offset only if tsecr not zero (bsc#1042286). - tcp: do not inherit fastopen_req from parent (4.4.68 stable queue). - tcp: do not underestimate skb->truesize in tcp_trim_head() (4.4.68 stable queue). - tcp: fastopen: accept data/FIN present in SYNACK message (bsc#1042286). - tcp: fastopen: avoid negative sk_forward_alloc (bsc#1042286). - tcp: fastopen: call tcp_fin() if FIN present in SYNACK (bsc#1042286). - tcp: fastopen: fix rcv_wup initialization for TFO server on SYN/data (bsc#1042286). - tcp: fix wraparound issue in tcp_lp (4.4.68 stable queue). - Temporarily disable iwlwifi-expose-default-fallback-ucode-api ... for updating iwlwifi stack - thp: fix MADV_DONTNEED vs. numa balancing race (bnc#1027974). - thp: reduce indentation level in change_huge_pmd() (bnc#1027974). - tpm: Downgrade error level (bsc#1042535). - tpm: fix checks for policy digest existence in tpm2_seal_trusted() (bsc#1034048, Pending fixes 2017-04-10). - tpm: fix RC value check in tpm2_seal_trusted (bsc#1034048, Pending fixes 2017-04-10). - tpm: fix: set continueSession attribute for the unseal operation (bsc#1034048, Pending fixes 2017-04-10). - tracing/kprobes: Enforce kprobes teardown after testing (bnc#1012985). - tty: Destroy ldisc instance on hangup (bnc#1043488). - tty: Fix ldisc crash on reopened tty (bnc#1043488). - tty: Handle NULL tty->ldisc (bnc#1043488). - tty: Move tty_ldisc_kill() (bnc#1043488). - tty: Prepare for destroying line discipline on hangup (bnc#1043488). - tty: Refactor tty_ldisc_reinit() for reuse (bnc#1043488). - tty: Reset c_line from driver's init_termios (bnc#1043488). - tty: Simplify tty_set_ldisc() exit handling (bnc#1043488). - tty: Use 'disc' for line discipline index name (bnc#1043488). - udp: avoid ufo handling on IP payload compression packets (bsc#1042286). - udplite: call proper backlog handlers (bsc#1042286). - Update config files: add CONFIG_IWLWIFI_PCIE_RTPM=y (FATE#323335) - Update patches.fixes/x86-pci-mark-broadwell-ep-home-agent-1-as-having-non-complian t-bars (bsc#1039214). Fix the wrong bsc number. - Update patches.fixes/xen-silence-efi-error-messge.patch (bnc#1039900). - Update ppc64le config files to use KGRAFT. - usb: chipidea: Handle extcon events properly (4.4.68 stable queue). - usb: chipidea: Only read/write OTGSC from one place (4.4.68 stable queue). - usb: host: ehci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths (4.4.68 stable queue). - usb: host: ohci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths (4.4.68 stable queue). - usb: musb: ux500: Fix NULL pointer dereference at system PM (bsc#1038033). - usb: serial: ark3116: fix open error handling (bnc#1038043). - usb: serial: ch341: add register and USB request definitions (bnc#1038043). - usb: serial: ch341: add support for parity, frame length, stop bits (bnc#1038043). - usb: serial: ch341: fix baud rate and line-control handling (bnc#1038043). - usb: serial: ch341: fix line settings after reset-resume (bnc#1038043). - usb: serial: ch341: fix modem-status handling (bnc#1038043). - usb: serial: ch341: reinitialize chip on reconfiguration (bnc#1038043). - usb: serial: digi_acceleport: fix incomplete rx sanity check (4.4.68 stable queue). - usb: serial: fix compare_const_fl.cocci warnings (bnc#1038043). - usb: serial: ftdi_sio: fix latency-timer error handling (4.4.68 stable queue). - usb: serial: io_edgeport: fix descriptor error handling (4.4.68 stable queue). - usb: serial: io_edgeport: fix epic-descriptor handling (bnc#1038043). - usb: serial: keyspan_pda: fix receive sanity checks (4.4.68 stable queue). - usb: serial: mct_u232: fix modem-status error handling (4.4.68 stable queue). - usb: serial: quatech2: fix control-message error handling (bnc#1038043). - usb: serial: sierra: fix bogus alternate-setting assumption (bnc#1038043). - usb: serial: ssu100: fix control-message error handling (bnc#1038043). - usb: serial: ti_usb_3410_5052: fix control-message error handling (4.4.68 stable queue). - Use make --output-sync feature when available (bsc#1012422). The mesages in make output can interleave making it impossible to extract warnings reliably. Since version 4 GNU Make supports --output-sync flag that prints output of each sub-command atomically preventing this issue. Detect the flag and use it if available. - Use up spare in struct module for livepatch (FATE#322421). - vmxnet3: segCnt can be 1 for LRO packets (bsc#988065). - vrf: remove slave queue and private slave struct (bsc#1042286). - vsock: Detach QP check should filter out non matching QPs (bsc#1036752). - x86/CPU/AMD: Fix Zen SMT topology (bsc#1027512). - x86/ioapic: Restore IO-APIC irq_chip retrigger callback (4.4.68 stable queue). - x86/pci-calgary: Fix iommu_free() comparison of unsigned expression >= 0 (4.4.68 stable queue). - x86/PCI: Mark Broadwell-EP Home Agent 1 as having non-compliant BARs (bsc#9048891). - x86/platform/intel-mid: Correct MSI IRQ line for watchdog device (4.4.68 stable queue). - x86/platform/uv/BAU: Add generic function pointers (bsc#1035024). - x86/platform/uv/BAU: Add payload descriptor qualifier (bsc#1035024). - x86/platform/uv/BAU: Add status mmr location fields to bau_control (bsc#1035024). - x86/platform/uv/BAU: Add UV4-specific functions (bsc#1035024). - x86/platform/uv/BAU: Add uv_bau_version enumerated constants (bsc#1035024). - x86/platform/uv/BAU: Add wait_completion to bau_operations (bsc#1035024). - x86/platform/uv/BAU: Clean up and update printks (bsc#1035024). - x86/platform/uv/BAU: Cleanup bau_operations declaration and instances (bsc#1035024). - x86/platform/uv/BAU: Clean up pq_init() (bsc#1035024). - x86/platform/uv/BAU: Clean up vertical alignment (bsc#1035024). - x86/platform/uv/BAU: Convert uv_physnodeaddr() use to uv_gpa_to_offset() (bsc#1035024). - x86/platform/uv/BAU: Disable software timeout on UV4 hardware (bsc#1035024). - x86/platform/uv/BAU: Fix HUB errors by remove initial write to sw-ack register (bsc#1035024). - x86/platform/uv/BAU: Fix payload queue setup on UV4 hardware (bsc#1035024). - x86/platform/uv/BAU: Implement uv4_wait_completion with read_status (bsc#1035024). - x86/platform/uv/BAU: Populate ->uvhub_version with UV4 version information (bsc#1035024). - x86/platform/uv/BAU: Use generic function pointers (bsc#1035024). - x86/platform/uv: Fix calculation of Global Physical Address (bsc#1031147). - xen: add sysfs node for guest type (bnc#1037840). - xen: adjust early dom0 p2m handling to xen hypervisor behavior (bnc#1031470). - xen-blkback: do not leak stack data via response ring (bsc#1042863 XSA-216). - xen/mce: do not issue error message for failed /dev/mcelog registration (bnc#1036638). - xfrm: Fix memory leak of aead algorithm name (bsc#1042286). - xfrm: Only add l3mdev oif to dst lookups (bsc#1042286). - xfs: add missing include dependencies to xfs_dir2.h (bsc#1042421). - xfs: do not assert fail on non-async buffers on ioacct decrement (bsc#1041160). - xfs: do not warn on buffers not being recovered due to LSN (bsc#1043598). - xfs: fix eofblocks race with file extending async dio writes (bsc#1040929). - xfs: Fix missed holes in SEEK_HOLE implementation (bsc#1041168). - xfs: fix off-by-one on max nr_pages in xfs_find_get_desired_pgoff() (bsc#1041168). - xfs: fix xfs_mode_to_ftype() prototype (bsc#1043598). - xfs: in _attrlist_by_handle, copy the cursor back to userspace (bsc#1041242). - xfs: log recovery tracepoints to track current lsn and buffer submission (bsc#1043598). - xfs: Make __xfs_xattr_put_listen preperly report errors (bsc#1041242). - xfs: only return -errno or success from attr ->put_listent (bsc#1041242). - xfs: pass current lsn to log recovery buffer validation (bsc#1043598). - xfs: refactor log record unpack and data processing (bsc#1043598). - xfs: replace xfs_mode_to_ftype table with switch statement (bsc#1042421). - xfs: rework log recovery to submit buffers on LSN boundaries (bsc#1043598). - xfs: rework the inline directory verifiers (bsc#1042421). - xfs: sanity check directory inode di_size (bsc#1042421). - xfs: sanity check inode di_mode (bsc#1042421). - xfs: Split default quota limits by quota type (bsc#1049421). - xfs: update metadata LSN in buffers during log recovery (bsc#1043598). - xfs: use ->b_state to fix buffer I/O accounting release race (bsc#1041160). - xfs: verify inline directory data forks (bsc#1042421). - zswap: do not param_set_charp while holding spinlock (VM Functionality, bsc#1042886). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1146=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1146=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1146=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1146=1 - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1146=1 - SUSE Linux Enterprise High Availability 12-SP2: zypper in -t patch SUSE-SLE-HA-12-SP2-2017-1146=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1146=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1146=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64): kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 kernel-default-extra-4.4.74-92.29.1 kernel-default-extra-debuginfo-4.4.74-92.29.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): kernel-obs-build-4.4.74-92.29.1 kernel-obs-build-debugsource-4.4.74-92.29.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (noarch): kernel-docs-4.4.74-92.29.3 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): kernel-default-4.4.74-92.29.1 kernel-default-base-4.4.74-92.29.1 kernel-default-base-debuginfo-4.4.74-92.29.1 kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 kernel-default-devel-4.4.74-92.29.1 kernel-syms-4.4.74-92.29.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): kernel-devel-4.4.74-92.29.1 kernel-macros-4.4.74-92.29.1 kernel-source-4.4.74-92.29.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): kernel-default-4.4.74-92.29.1 kernel-default-base-4.4.74-92.29.1 kernel-default-base-debuginfo-4.4.74-92.29.1 kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 kernel-default-devel-4.4.74-92.29.1 kernel-syms-4.4.74-92.29.1 - SUSE Linux Enterprise Server 12-SP2 (noarch): kernel-devel-4.4.74-92.29.1 kernel-macros-4.4.74-92.29.1 kernel-source-4.4.74-92.29.1 - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_74-92_29-default-1-4.1 - SUSE Linux Enterprise High Availability 12-SP2 (ppc64le s390x x86_64): cluster-md-kmp-default-4.4.74-92.29.1 cluster-md-kmp-default-debuginfo-4.4.74-92.29.1 cluster-network-kmp-default-4.4.74-92.29.1 cluster-network-kmp-default-debuginfo-4.4.74-92.29.1 dlm-kmp-default-4.4.74-92.29.1 dlm-kmp-default-debuginfo-4.4.74-92.29.1 gfs2-kmp-default-4.4.74-92.29.1 gfs2-kmp-default-debuginfo-4.4.74-92.29.1 kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 ocfs2-kmp-default-4.4.74-92.29.1 ocfs2-kmp-default-debuginfo-4.4.74-92.29.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): kernel-devel-4.4.74-92.29.1 kernel-macros-4.4.74-92.29.1 kernel-source-4.4.74-92.29.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): kernel-default-4.4.74-92.29.1 kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 kernel-default-devel-4.4.74-92.29.1 kernel-default-extra-4.4.74-92.29.1 kernel-default-extra-debuginfo-4.4.74-92.29.1 kernel-syms-4.4.74-92.29.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): kernel-default-4.4.74-92.29.1 kernel-default-debuginfo-4.4.74-92.29.1 kernel-default-debugsource-4.4.74-92.29.1 References: https://www.suse.com/security/cve/CVE-2017-1000365.html https://www.suse.com/security/cve/CVE-2017-1000380.html https://www.suse.com/security/cve/CVE-2017-7346.html https://www.suse.com/security/cve/CVE-2017-7487.html https://www.suse.com/security/cve/CVE-2017-7616.html https://www.suse.com/security/cve/CVE-2017-7618.html https://www.suse.com/security/cve/CVE-2017-8890.html https://www.suse.com/security/cve/CVE-2017-8924.html https://www.suse.com/security/cve/CVE-2017-8925.html https://www.suse.com/security/cve/CVE-2017-9074.html https://www.suse.com/security/cve/CVE-2017-9075.html https://www.suse.com/security/cve/CVE-2017-9076.html https://www.suse.com/security/cve/CVE-2017-9077.html https://www.suse.com/security/cve/CVE-2017-9150.html https://www.suse.com/security/cve/CVE-2017-9242.html https://bugzilla.suse.com/1003581 https://bugzilla.suse.com/1004003 https://bugzilla.suse.com/1011044 https://bugzilla.suse.com/1012060 https://bugzilla.suse.com/1012382 https://bugzilla.suse.com/1012422 https://bugzilla.suse.com/1012452 https://bugzilla.suse.com/1012829 https://bugzilla.suse.com/1012910 https://bugzilla.suse.com/1012985 https://bugzilla.suse.com/1013561 https://bugzilla.suse.com/1013887 https://bugzilla.suse.com/1015342 https://bugzilla.suse.com/1015452 https://bugzilla.suse.com/1017461 https://bugzilla.suse.com/1018885 https://bugzilla.suse.com/1020412 https://bugzilla.suse.com/1021424 https://bugzilla.suse.com/1022266 https://bugzilla.suse.com/1022595 https://bugzilla.suse.com/1023287 https://bugzilla.suse.com/1025461 https://bugzilla.suse.com/1026570 https://bugzilla.suse.com/1027101 https://bugzilla.suse.com/1027512 https://bugzilla.suse.com/1027974 https://bugzilla.suse.com/1028217 https://bugzilla.suse.com/1028310 https://bugzilla.suse.com/1028340 https://bugzilla.suse.com/1028883 https://bugzilla.suse.com/1029607 https://bugzilla.suse.com/1030057 https://bugzilla.suse.com/1030070 https://bugzilla.suse.com/1031040 https://bugzilla.suse.com/1031142 https://bugzilla.suse.com/1031147 https://bugzilla.suse.com/1031470 https://bugzilla.suse.com/1031500 https://bugzilla.suse.com/1031512 https://bugzilla.suse.com/1031555 https://bugzilla.suse.com/1031717 https://bugzilla.suse.com/1031796 https://bugzilla.suse.com/1032141 https://bugzilla.suse.com/1032339 https://bugzilla.suse.com/1032345 https://bugzilla.suse.com/1032400 https://bugzilla.suse.com/1032581 https://bugzilla.suse.com/1032803 https://bugzilla.suse.com/1033117 https://bugzilla.suse.com/1033281 https://bugzilla.suse.com/1033336 https://bugzilla.suse.com/1033340 https://bugzilla.suse.com/1033885 https://bugzilla.suse.com/1034048 https://bugzilla.suse.com/1034419 https://bugzilla.suse.com/1034635 https://bugzilla.suse.com/1034670 https://bugzilla.suse.com/1034671 https://bugzilla.suse.com/1034762 https://bugzilla.suse.com/1034902 https://bugzilla.suse.com/1034995 https://bugzilla.suse.com/1035024 https://bugzilla.suse.com/1035866 https://bugzilla.suse.com/1035887 https://bugzilla.suse.com/1035920 https://bugzilla.suse.com/1035922 https://bugzilla.suse.com/1036214 https://bugzilla.suse.com/1036638 https://bugzilla.suse.com/1036752 https://bugzilla.suse.com/1036763 https://bugzilla.suse.com/1037177 https://bugzilla.suse.com/1037186 https://bugzilla.suse.com/1037384 https://bugzilla.suse.com/1037483 https://bugzilla.suse.com/1037669 https://bugzilla.suse.com/1037840 https://bugzilla.suse.com/1037871 https://bugzilla.suse.com/1037969 https://bugzilla.suse.com/1038033 https://bugzilla.suse.com/1038043 https://bugzilla.suse.com/1038085 https://bugzilla.suse.com/1038142 https://bugzilla.suse.com/1038143 https://bugzilla.suse.com/1038297 https://bugzilla.suse.com/1038458 https://bugzilla.suse.com/1038544 https://bugzilla.suse.com/1038842 https://bugzilla.suse.com/1038843 https://bugzilla.suse.com/1038846 https://bugzilla.suse.com/1038847 https://bugzilla.suse.com/1038848 https://bugzilla.suse.com/1038879 https://bugzilla.suse.com/1038981 https://bugzilla.suse.com/1038982 https://bugzilla.suse.com/1039214 https://bugzilla.suse.com/1039348 https://bugzilla.suse.com/1039354 https://bugzilla.suse.com/1039700 https://bugzilla.suse.com/1039864 https://bugzilla.suse.com/1039882 https://bugzilla.suse.com/1039883 https://bugzilla.suse.com/1039885 https://bugzilla.suse.com/1039900 https://bugzilla.suse.com/1040069 https://bugzilla.suse.com/1040125 https://bugzilla.suse.com/1040182 https://bugzilla.suse.com/1040279 https://bugzilla.suse.com/1040351 https://bugzilla.suse.com/1040364 https://bugzilla.suse.com/1040395 https://bugzilla.suse.com/1040425 https://bugzilla.suse.com/1040463 https://bugzilla.suse.com/1040567 https://bugzilla.suse.com/1040609 https://bugzilla.suse.com/1040855 https://bugzilla.suse.com/1040929 https://bugzilla.suse.com/1040941 https://bugzilla.suse.com/1041087 https://bugzilla.suse.com/1041160 https://bugzilla.suse.com/1041168 https://bugzilla.suse.com/1041242 https://bugzilla.suse.com/1041431 https://bugzilla.suse.com/1041810 https://bugzilla.suse.com/1042286 https://bugzilla.suse.com/1042356 https://bugzilla.suse.com/1042421 https://bugzilla.suse.com/1042517 https://bugzilla.suse.com/1042535 https://bugzilla.suse.com/1042536 https://bugzilla.suse.com/1042863 https://bugzilla.suse.com/1042886 https://bugzilla.suse.com/1043014 https://bugzilla.suse.com/1043231 https://bugzilla.suse.com/1043236 https://bugzilla.suse.com/1043347 https://bugzilla.suse.com/1043371 https://bugzilla.suse.com/1043467 https://bugzilla.suse.com/1043488 https://bugzilla.suse.com/1043598 https://bugzilla.suse.com/1043912 https://bugzilla.suse.com/1043935 https://bugzilla.suse.com/1043990 https://bugzilla.suse.com/1044015 https://bugzilla.suse.com/1044082 https://bugzilla.suse.com/1044120 https://bugzilla.suse.com/1044125 https://bugzilla.suse.com/1044532 https://bugzilla.suse.com/1044767 https://bugzilla.suse.com/1044772 https://bugzilla.suse.com/1044854 https://bugzilla.suse.com/1044880 https://bugzilla.suse.com/1044912 https://bugzilla.suse.com/1045154 https://bugzilla.suse.com/1045235 https://bugzilla.suse.com/1045286 https://bugzilla.suse.com/1045307 https://bugzilla.suse.com/1045467 https://bugzilla.suse.com/1045568 https://bugzilla.suse.com/1046105 https://bugzilla.suse.com/1046434 https://bugzilla.suse.com/1046589 https://bugzilla.suse.com/799133 https://bugzilla.suse.com/863764 https://bugzilla.suse.com/922871 https://bugzilla.suse.com/939801 https://bugzilla.suse.com/966170 https://bugzilla.suse.com/966172 https://bugzilla.suse.com/966191 https://bugzilla.suse.com/966321 https://bugzilla.suse.com/966339 https://bugzilla.suse.com/971975 https://bugzilla.suse.com/988065 https://bugzilla.suse.com/989311 https://bugzilla.suse.com/990058 https://bugzilla.suse.com/990682 https://bugzilla.suse.com/993832 https://bugzilla.suse.com/995542 From sle-security-updates at lists.suse.com Fri Jul 14 07:10:12 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 15:10:12 +0200 (CEST) Subject: SUSE-SU-2017:1859-1: important: Security update for xorg-x11-server Message-ID: <20170714131012.8F1ECFF3A@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1859-1 Rating: important References: #1035283 Cross-References: CVE-2017-10971 CVE-2017-10972 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for xorg-x11-server provides the following fixes: - CVE-2017-10971: Fix endianess handling of GenericEvent to prevent a stack overflow by clients. (bnc#1035283) - Make sure the type of all events to be sent by ProcXSendExtensionEvent are in the allowed range. - CVE-2017-10972: Initialize the xEvent eventT with zeros to avoid information leakage. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1149=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1149=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1149=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): xorg-x11-server-7.6_1.15.2-53.3.1 xorg-x11-server-debuginfo-7.6_1.15.2-53.3.1 xorg-x11-server-debugsource-7.6_1.15.2-53.3.1 xorg-x11-server-extra-7.6_1.15.2-53.3.1 xorg-x11-server-extra-debuginfo-7.6_1.15.2-53.3.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): xorg-x11-server-7.6_1.15.2-53.3.1 xorg-x11-server-debuginfo-7.6_1.15.2-53.3.1 xorg-x11-server-debugsource-7.6_1.15.2-53.3.1 xorg-x11-server-extra-7.6_1.15.2-53.3.1 xorg-x11-server-extra-debuginfo-7.6_1.15.2-53.3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): xorg-x11-server-7.6_1.15.2-53.3.1 xorg-x11-server-debuginfo-7.6_1.15.2-53.3.1 xorg-x11-server-debugsource-7.6_1.15.2-53.3.1 xorg-x11-server-extra-7.6_1.15.2-53.3.1 xorg-x11-server-extra-debuginfo-7.6_1.15.2-53.3.1 References: https://www.suse.com/security/cve/CVE-2017-10971.html https://www.suse.com/security/cve/CVE-2017-10972.html https://bugzilla.suse.com/1035283 From sle-security-updates at lists.suse.com Fri Jul 14 07:10:41 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 15:10:41 +0200 (CEST) Subject: SUSE-SU-2017:1860-1: important: Security update for xorg-x11-server Message-ID: <20170714131041.11679FF3A@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1860-1 Rating: important References: #1035283 Cross-References: CVE-2017-10971 CVE-2017-10972 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for xorg-x11-server provides the following fixes: - CVE-2017-10971: Fix endianess handling of GenericEvent to prevent a stack overflow by clients. (bnc#1035283) - Make sure the type of all events to be sent by ProcXSendExtensionEvent are in the allowed range. - CVE-2017-10972: Initialize the xEvent eventT with zeros to avoid information leakage. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1148=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1148=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1148=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1148=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): xorg-x11-server-debuginfo-7.6_1.18.3-74.2 xorg-x11-server-debugsource-7.6_1.18.3-74.2 xorg-x11-server-sdk-7.6_1.18.3-74.2 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): xorg-x11-server-7.6_1.18.3-74.2 xorg-x11-server-debuginfo-7.6_1.18.3-74.2 xorg-x11-server-debugsource-7.6_1.18.3-74.2 xorg-x11-server-extra-7.6_1.18.3-74.2 xorg-x11-server-extra-debuginfo-7.6_1.18.3-74.2 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): xorg-x11-server-7.6_1.18.3-74.2 xorg-x11-server-debuginfo-7.6_1.18.3-74.2 xorg-x11-server-debugsource-7.6_1.18.3-74.2 xorg-x11-server-extra-7.6_1.18.3-74.2 xorg-x11-server-extra-debuginfo-7.6_1.18.3-74.2 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): xorg-x11-server-7.6_1.18.3-74.2 xorg-x11-server-debuginfo-7.6_1.18.3-74.2 xorg-x11-server-debugsource-7.6_1.18.3-74.2 xorg-x11-server-extra-7.6_1.18.3-74.2 xorg-x11-server-extra-debuginfo-7.6_1.18.3-74.2 References: https://www.suse.com/security/cve/CVE-2017-10971.html https://www.suse.com/security/cve/CVE-2017-10972.html https://bugzilla.suse.com/1035283 From sle-security-updates at lists.suse.com Fri Jul 14 07:11:05 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 15:11:05 +0200 (CEST) Subject: SUSE-SU-2017:1861-1: important: Security update for xorg-x11-server Message-ID: <20170714131105.ED3DAF7BE@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1861-1 Rating: important References: #1035283 Cross-References: CVE-2017-10971 CVE-2017-10972 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for xorg-x11-server fixes the following issues: - CVE-2017-10971: Fix endianess handling of GenericEvent to prevent a stack overflow by clients. (bnc#1035283) - Make sure the type of all events to be sent by ProcXSendExtensionEvent are in the allowed range. - CVE-2017-10972: Initialize the xEvent eventT with zeros to avoid information leakage. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1150=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1150=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): xorg-x11-server-7.6_1.15.2-30.22.1 xorg-x11-server-debuginfo-7.6_1.15.2-30.22.1 xorg-x11-server-debugsource-7.6_1.15.2-30.22.1 xorg-x11-server-extra-7.6_1.15.2-30.22.1 xorg-x11-server-extra-debuginfo-7.6_1.15.2-30.22.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): xorg-x11-server-7.6_1.15.2-30.22.1 xorg-x11-server-debuginfo-7.6_1.15.2-30.22.1 xorg-x11-server-debugsource-7.6_1.15.2-30.22.1 xorg-x11-server-extra-7.6_1.15.2-30.22.1 xorg-x11-server-extra-debuginfo-7.6_1.15.2-30.22.1 References: https://www.suse.com/security/cve/CVE-2017-10971.html https://www.suse.com/security/cve/CVE-2017-10972.html https://bugzilla.suse.com/1035283 From sle-security-updates at lists.suse.com Fri Jul 14 10:11:09 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 18:11:09 +0200 (CEST) Subject: SUSE-SU-2017:1862-1: moderate: Security update for libXdmcp Message-ID: <20170714161109.46973FF3A@maintenance.suse.de> SUSE Security Update: Security update for libXdmcp ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1862-1 Rating: moderate References: #1025046 Cross-References: CVE-2017-2625 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libXdmcp fixes the following issues: - CVE-2017-2625: The generation of session key in XDM using libXdmcp might have used weak entropy, making the session keys predictable (bsc#1025046) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1153=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1153=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1153=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1153=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libXdmcp-debugsource-1.1.1-10.1 libXdmcp-devel-1.1.1-10.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libXdmcp-debugsource-1.1.1-10.1 libXdmcp6-1.1.1-10.1 libXdmcp6-debuginfo-1.1.1-10.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): libXdmcp-debugsource-1.1.1-10.1 libXdmcp6-1.1.1-10.1 libXdmcp6-debuginfo-1.1.1-10.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libXdmcp6-32bit-1.1.1-10.1 libXdmcp6-debuginfo-32bit-1.1.1-10.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libXdmcp-debugsource-1.1.1-10.1 libXdmcp6-1.1.1-10.1 libXdmcp6-32bit-1.1.1-10.1 libXdmcp6-debuginfo-1.1.1-10.1 libXdmcp6-debuginfo-32bit-1.1.1-10.1 References: https://www.suse.com/security/cve/CVE-2017-2625.html https://bugzilla.suse.com/1025046 From sle-security-updates at lists.suse.com Fri Jul 14 13:11:07 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 21:11:07 +0200 (CEST) Subject: SUSE-SU-2017:1865-1: important: Security update for cryptctl Message-ID: <20170714191107.D519AFF3A@maintenance.suse.de> SUSE Security Update: Security update for cryptctl ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1865-1 Rating: important References: #1041963 Cross-References: CVE-2017-9270 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptctl fixes an issue that could have allowed a malicious administrator to craft RPC requests to overwrite files outside of key database. (bsc#1041963 / CVE-2017-9270) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2017-1158=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): cryptctl-1.2.6-5.3.11 cryptctl-debuginfo-1.2.6-5.3.11 cryptctl-debugsource-1.2.6-5.3.11 References: https://www.suse.com/security/cve/CVE-2017-9270.html https://bugzilla.suse.com/1041963 From sle-security-updates at lists.suse.com Fri Jul 14 13:11:29 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 21:11:29 +0200 (CEST) Subject: SUSE-SU-2017:1866-1: moderate: Security update for compat-libgcrypt11 Message-ID: <20170714191129.82EB2F7BE@maintenance.suse.de> SUSE Security Update: Security update for compat-libgcrypt11 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1866-1 Rating: moderate References: #1046607 Cross-References: CVE-2017-7526 Affected Products: SUSE Linux Enterprise Module for Legacy Software 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libgcrypt fixes the following security issue: - CVE-2017-7526: Hardening against local side-channel attack. (bsc#1046607) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Legacy Software 12: zypper in -t patch SUSE-SLE-Module-Legacy-12-2017-1157=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Module for Legacy Software 12 (s390x x86_64): compat-libgcrypt11-1.5.0-0.6.1 compat-libgcrypt11-debuginfo-1.5.0-0.6.1 compat-libgcrypt11-debugsource-1.5.0-0.6.1 References: https://www.suse.com/security/cve/CVE-2017-7526.html https://bugzilla.suse.com/1046607 From sle-security-updates at lists.suse.com Fri Jul 14 13:13:02 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 14 Jul 2017 21:13:02 +0200 (CEST) Subject: SUSE-SU-2017:1868-1: moderate: Security update for xorg-x11-libXdmcp Message-ID: <20170714191302.0F4DDF7BE@maintenance.suse.de> SUSE Security Update: Security update for xorg-x11-libXdmcp ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1868-1 Rating: moderate References: #1025046 Cross-References: CVE-2017-2625 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xorg-x11-libXdmcp fixes the following issues: - CVE-2017-2625: The generation of session key in XDM using libXdmcp might have used weak entropy, making the session keys predictable (bsc#1025046) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-xorg-x11-libXdmcp-13209=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-xorg-x11-libXdmcp-13209=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-xorg-x11-libXdmcp-13209=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libXdmcp-devel-7.4-3.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (ppc64 s390x x86_64): xorg-x11-libXdmcp-devel-32bit-7.4-3.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (x86_64): xorg-x11-libXdmcp-32bit-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libXdmcp-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): xorg-x11-libXdmcp-32bit-7.4-3.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): xorg-x11-libXdmcp-x86-7.4-3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): xorg-x11-libXdmcp-debuginfo-7.4-3.1 xorg-x11-libXdmcp-debugsource-7.4-3.1 References: https://www.suse.com/security/cve/CVE-2017-2625.html https://bugzilla.suse.com/1025046 From sle-security-updates at lists.suse.com Sat Jul 15 07:09:51 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Sat, 15 Jul 2017 15:09:51 +0200 (CEST) Subject: SUSE-SU-2017:1886-1: moderate: Security update for gnutls Message-ID: <20170715130951.EEB7BF7BE@maintenance.suse.de> SUSE Security Update: Security update for gnutls ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1886-1 Rating: moderate References: #1034173 #1038337 #1040621 Cross-References: CVE-2017-6891 CVE-2017-7869 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise High Availability Extension 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for gnutls fixes the following issues: - GNUTLS-SA-2017-3 / CVE-2017-7869: An out-of-bounds write in OpenPGP certificate decoding was fixed (bsc#1034173) - CVE-2017-6891: A potential stack buffer overflow in the bundled libtasn1 was fixed (bsc#1040621) - An address read of 4 bytes past the end of buffer in OpenPGP certificate parsing was fixed (bsc#1038337) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-gnutls-13212=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-gnutls-13212=1 - SUSE Linux Enterprise High Availability Extension 11-SP4: zypper in -t patch slehasp4-gnutls-13212=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-gnutls-13212=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libgnutls-devel-2.4.1-24.39.70.1 libgnutls-extra-devel-2.4.1-24.39.70.1 libgnutls-extra26-2.4.1-24.39.70.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): gnutls-2.4.1-24.39.70.1 libgnutls-extra26-2.4.1-24.39.70.1 libgnutls26-2.4.1-24.39.70.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libgnutls26-32bit-2.4.1-24.39.70.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libgnutls26-x86-2.4.1-24.39.70.1 - SUSE Linux Enterprise High Availability Extension 11-SP4 (i586 ia64 ppc64 s390x x86_64): libgnutls-extra26-2.4.1-24.39.70.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): gnutls-debuginfo-2.4.1-24.39.70.1 gnutls-debugsource-2.4.1-24.39.70.1 References: https://www.suse.com/security/cve/CVE-2017-6891.html https://www.suse.com/security/cve/CVE-2017-7869.html https://bugzilla.suse.com/1034173 https://bugzilla.suse.com/1038337 https://bugzilla.suse.com/1040621 From sle-security-updates at lists.suse.com Tue Jul 18 10:12:43 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 18 Jul 2017 18:12:43 +0200 (CEST) Subject: SUSE-SU-2017:1893-1: important: Security update for evince Message-ID: <20170718161243.39835FC6C@maintenance.suse.de> SUSE Security Update: Security update for evince ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1893-1 Rating: important References: #1046856 Cross-References: CVE-2017-1000083 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP2 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for evince fixes the following issues: - CVE-2017-1000083: Remote attackers could have used the comicbook mode of evince to inject shell code. (bsc#1046856, bgo#784630) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP2: zypper in -t patch SUSE-SLE-WE-12-SP2-2017-1171=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1171=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1171=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1171=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1171=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Workstation Extension 12-SP2 (x86_64): evince-debuginfo-3.20.1-6.14.1 evince-debugsource-3.20.1-6.14.1 typelib-1_0-EvinceDocument-3_0-3.20.1-6.14.1 typelib-1_0-EvinceView-3_0-3.20.1-6.14.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): evince-debuginfo-3.20.1-6.14.1 evince-debugsource-3.20.1-6.14.1 evince-devel-3.20.1-6.14.1 typelib-1_0-EvinceDocument-3_0-3.20.1-6.14.1 typelib-1_0-EvinceView-3_0-3.20.1-6.14.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): evince-3.20.1-6.14.1 evince-browser-plugin-3.20.1-6.14.1 evince-browser-plugin-debuginfo-3.20.1-6.14.1 evince-debuginfo-3.20.1-6.14.1 evince-debugsource-3.20.1-6.14.1 evince-plugin-djvudocument-3.20.1-6.14.1 evince-plugin-djvudocument-debuginfo-3.20.1-6.14.1 evince-plugin-dvidocument-3.20.1-6.14.1 evince-plugin-dvidocument-debuginfo-3.20.1-6.14.1 evince-plugin-pdfdocument-3.20.1-6.14.1 evince-plugin-pdfdocument-debuginfo-3.20.1-6.14.1 evince-plugin-psdocument-3.20.1-6.14.1 evince-plugin-psdocument-debuginfo-3.20.1-6.14.1 evince-plugin-tiffdocument-3.20.1-6.14.1 evince-plugin-tiffdocument-debuginfo-3.20.1-6.14.1 evince-plugin-xpsdocument-3.20.1-6.14.1 evince-plugin-xpsdocument-debuginfo-3.20.1-6.14.1 libevdocument3-4-3.20.1-6.14.1 libevdocument3-4-debuginfo-3.20.1-6.14.1 libevview3-3-3.20.1-6.14.1 libevview3-3-debuginfo-3.20.1-6.14.1 nautilus-evince-3.20.1-6.14.1 nautilus-evince-debuginfo-3.20.1-6.14.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): evince-lang-3.20.1-6.14.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le): evince-3.20.1-6.14.1 evince-browser-plugin-3.20.1-6.14.1 evince-browser-plugin-debuginfo-3.20.1-6.14.1 evince-debuginfo-3.20.1-6.14.1 evince-debugsource-3.20.1-6.14.1 evince-plugin-djvudocument-3.20.1-6.14.1 evince-plugin-djvudocument-debuginfo-3.20.1-6.14.1 evince-plugin-dvidocument-3.20.1-6.14.1 evince-plugin-dvidocument-debuginfo-3.20.1-6.14.1 evince-plugin-pdfdocument-3.20.1-6.14.1 evince-plugin-pdfdocument-debuginfo-3.20.1-6.14.1 evince-plugin-psdocument-3.20.1-6.14.1 evince-plugin-psdocument-debuginfo-3.20.1-6.14.1 evince-plugin-tiffdocument-3.20.1-6.14.1 evince-plugin-tiffdocument-debuginfo-3.20.1-6.14.1 evince-plugin-xpsdocument-3.20.1-6.14.1 evince-plugin-xpsdocument-debuginfo-3.20.1-6.14.1 libevdocument3-4-3.20.1-6.14.1 libevdocument3-4-debuginfo-3.20.1-6.14.1 libevview3-3-3.20.1-6.14.1 libevview3-3-debuginfo-3.20.1-6.14.1 nautilus-evince-3.20.1-6.14.1 nautilus-evince-debuginfo-3.20.1-6.14.1 - SUSE Linux Enterprise Server 12-SP2 (noarch): evince-lang-3.20.1-6.14.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): evince-3.20.1-6.14.1 evince-browser-plugin-3.20.1-6.14.1 evince-browser-plugin-debuginfo-3.20.1-6.14.1 evince-debuginfo-3.20.1-6.14.1 evince-debugsource-3.20.1-6.14.1 evince-plugin-djvudocument-3.20.1-6.14.1 evince-plugin-djvudocument-debuginfo-3.20.1-6.14.1 evince-plugin-dvidocument-3.20.1-6.14.1 evince-plugin-dvidocument-debuginfo-3.20.1-6.14.1 evince-plugin-pdfdocument-3.20.1-6.14.1 evince-plugin-pdfdocument-debuginfo-3.20.1-6.14.1 evince-plugin-psdocument-3.20.1-6.14.1 evince-plugin-psdocument-debuginfo-3.20.1-6.14.1 evince-plugin-tiffdocument-3.20.1-6.14.1 evince-plugin-tiffdocument-debuginfo-3.20.1-6.14.1 evince-plugin-xpsdocument-3.20.1-6.14.1 evince-plugin-xpsdocument-debuginfo-3.20.1-6.14.1 libevdocument3-4-3.20.1-6.14.1 libevdocument3-4-debuginfo-3.20.1-6.14.1 libevview3-3-3.20.1-6.14.1 libevview3-3-debuginfo-3.20.1-6.14.1 nautilus-evince-3.20.1-6.14.1 nautilus-evince-debuginfo-3.20.1-6.14.1 typelib-1_0-EvinceDocument-3_0-3.20.1-6.14.1 typelib-1_0-EvinceView-3_0-3.20.1-6.14.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): evince-lang-3.20.1-6.14.1 References: https://www.suse.com/security/cve/CVE-2017-1000083.html https://bugzilla.suse.com/1046856 From sle-security-updates at lists.suse.com Tue Jul 18 10:13:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Tue, 18 Jul 2017 18:13:08 +0200 (CEST) Subject: SUSE-SU-2017:1894-1: important: Security update for evince Message-ID: <20170718161308.128E2FF41@maintenance.suse.de> SUSE Security Update: Security update for evince ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1894-1 Rating: important References: #1046856 Cross-References: CVE-2017-1000083 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for evince fixes the following issues: - CVE-2017-1000083: Remote attackers could have used the comicbook mode of evince to inject shell code. (bsc#1046856, bgo#784630) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1170=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1170=1 - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1170=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1170=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1170=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): evince-3.10.3-2.3.1 evince-debuginfo-3.10.3-2.3.1 evince-debugsource-3.10.3-2.3.1 libevdocument3-4-3.10.3-2.3.1 libevdocument3-4-debuginfo-3.10.3-2.3.1 libevview3-3-3.10.3-2.3.1 libevview3-3-debuginfo-3.10.3-2.3.1 - SUSE OpenStack Cloud 6 (noarch): evince-lang-3.10.3-2.3.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): evince-3.10.3-2.3.1 evince-debuginfo-3.10.3-2.3.1 evince-debugsource-3.10.3-2.3.1 libevdocument3-4-3.10.3-2.3.1 libevdocument3-4-debuginfo-3.10.3-2.3.1 libevview3-3-3.10.3-2.3.1 libevview3-3-debuginfo-3.10.3-2.3.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): evince-lang-3.10.3-2.3.1 - SUSE Linux Enterprise Server for SAP 12 (x86_64): evince-3.10.3-2.3.1 evince-debuginfo-3.10.3-2.3.1 evince-debugsource-3.10.3-2.3.1 libevdocument3-4-3.10.3-2.3.1 libevdocument3-4-debuginfo-3.10.3-2.3.1 libevview3-3-3.10.3-2.3.1 libevview3-3-debuginfo-3.10.3-2.3.1 - SUSE Linux Enterprise Server for SAP 12 (noarch): evince-lang-3.10.3-2.3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): evince-3.10.3-2.3.1 evince-debuginfo-3.10.3-2.3.1 evince-debugsource-3.10.3-2.3.1 libevdocument3-4-3.10.3-2.3.1 libevdocument3-4-debuginfo-3.10.3-2.3.1 libevview3-3-3.10.3-2.3.1 libevview3-3-debuginfo-3.10.3-2.3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): evince-lang-3.10.3-2.3.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): evince-3.10.3-2.3.1 evince-debuginfo-3.10.3-2.3.1 evince-debugsource-3.10.3-2.3.1 libevdocument3-4-3.10.3-2.3.1 libevdocument3-4-debuginfo-3.10.3-2.3.1 libevview3-3-3.10.3-2.3.1 libevview3-3-debuginfo-3.10.3-2.3.1 - SUSE Linux Enterprise Server 12-LTSS (noarch): evince-lang-3.10.3-2.3.1 References: https://www.suse.com/security/cve/CVE-2017-1000083.html https://bugzilla.suse.com/1046856 From sle-security-updates at lists.suse.com Wed Jul 19 07:09:57 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 19 Jul 2017 15:09:57 +0200 (CEST) Subject: SUSE-SU-2017:1898-1: important: Security update for systemd, dracut Message-ID: <20170719130957.CDCECFF3A@maintenance.suse.de> SUSE Security Update: Security update for systemd, dracut ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1898-1 Rating: important References: #1032029 #1033238 #1037120 #1040153 #1040968 #1043900 #1045290 #1046750 #986216 Cross-References: CVE-2017-9445 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that solves one vulnerability and has 8 fixes is now available. Description: This update for systemd and dracut fixes the following issues: Security issues fixed: - CVE-2017-9445: Possible out-of-bounds write triggered by a specially crafted TCP payload from a DNS server. (bsc#1045290) Non-security issues fixed in systemd: - Automounter issue in combination with NFS volumes (bsc#1040968) - Missing symbolic link for SAS device in /dev/disk/by-path (bsc#1040153) - Add minimal support for boot.d/* scripts in systemd-sysv-convert (bsc#1046750) Non-security issues fixed in dracut: - Bail out if module directory does not exist. (bsc#1043900) - Suppress bogus error message. (bsc#1032029) - Fix module force loading with systemd. (bsc#986216) - Ship udev files required by systemd. (bsc#1040153) - Ignore module resolution errors (e.g. with kgraft). (bsc#1037120) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1174=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1174=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1174=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1174=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2017-1174=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libudev-devel-228-150.7.1 systemd-debuginfo-228-150.7.1 systemd-debugsource-228-150.7.1 systemd-devel-228-150.7.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): dracut-044.1-109.8.3 dracut-debuginfo-044.1-109.8.3 dracut-debugsource-044.1-109.8.3 dracut-fips-044.1-109.8.3 libsystemd0-228-150.7.1 libsystemd0-debuginfo-228-150.7.1 libudev1-228-150.7.1 libudev1-debuginfo-228-150.7.1 systemd-228-150.7.1 systemd-debuginfo-228-150.7.1 systemd-debugsource-228-150.7.1 systemd-sysvinit-228-150.7.1 udev-228-150.7.1 udev-debuginfo-228-150.7.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): systemd-bash-completion-228-150.7.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): dracut-044.1-109.8.3 dracut-debuginfo-044.1-109.8.3 dracut-debugsource-044.1-109.8.3 dracut-fips-044.1-109.8.3 libsystemd0-228-150.7.1 libsystemd0-debuginfo-228-150.7.1 libudev1-228-150.7.1 libudev1-debuginfo-228-150.7.1 systemd-228-150.7.1 systemd-debuginfo-228-150.7.1 systemd-debugsource-228-150.7.1 systemd-sysvinit-228-150.7.1 udev-228-150.7.1 udev-debuginfo-228-150.7.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libsystemd0-32bit-228-150.7.1 libsystemd0-debuginfo-32bit-228-150.7.1 libudev1-32bit-228-150.7.1 libudev1-debuginfo-32bit-228-150.7.1 systemd-32bit-228-150.7.1 systemd-debuginfo-32bit-228-150.7.1 - SUSE Linux Enterprise Server 12-SP2 (noarch): systemd-bash-completion-228-150.7.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): dracut-044.1-109.8.3 dracut-debuginfo-044.1-109.8.3 dracut-debugsource-044.1-109.8.3 libsystemd0-228-150.7.1 libsystemd0-32bit-228-150.7.1 libsystemd0-debuginfo-228-150.7.1 libsystemd0-debuginfo-32bit-228-150.7.1 libudev1-228-150.7.1 libudev1-32bit-228-150.7.1 libudev1-debuginfo-228-150.7.1 libudev1-debuginfo-32bit-228-150.7.1 systemd-228-150.7.1 systemd-32bit-228-150.7.1 systemd-debuginfo-228-150.7.1 systemd-debuginfo-32bit-228-150.7.1 systemd-debugsource-228-150.7.1 systemd-sysvinit-228-150.7.1 udev-228-150.7.1 udev-debuginfo-228-150.7.1 - SUSE Linux Enterprise Desktop 12-SP2 (noarch): systemd-bash-completion-228-150.7.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): dracut-044.1-109.8.3 dracut-debuginfo-044.1-109.8.3 dracut-debugsource-044.1-109.8.3 libsystemd0-228-150.7.1 libsystemd0-debuginfo-228-150.7.1 libudev1-228-150.7.1 libudev1-debuginfo-228-150.7.1 systemd-228-150.7.1 systemd-debuginfo-228-150.7.1 systemd-debugsource-228-150.7.1 systemd-sysvinit-228-150.7.1 udev-228-150.7.1 udev-debuginfo-228-150.7.1 References: https://www.suse.com/security/cve/CVE-2017-9445.html https://bugzilla.suse.com/1032029 https://bugzilla.suse.com/1033238 https://bugzilla.suse.com/1037120 https://bugzilla.suse.com/1040153 https://bugzilla.suse.com/1040968 https://bugzilla.suse.com/1043900 https://bugzilla.suse.com/1045290 https://bugzilla.suse.com/1046750 https://bugzilla.suse.com/986216 From sle-security-updates at lists.suse.com Wed Jul 19 19:10:46 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 03:10:46 +0200 (CEST) Subject: SUSE-SU-2017:1901-1: moderate: Security update for jasper Message-ID: <20170720011046.F2C5BFF3A@maintenance.suse.de> SUSE Security Update: Security update for jasper ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1901-1 Rating: moderate References: #1009994 #1010756 #1010757 #1010766 #1010774 #1010782 #1010968 #1010975 #1047958 Cross-References: CVE-2016-9262 CVE-2016-9388 CVE-2016-9389 CVE-2016-9390 CVE-2016-9391 CVE-2016-9392 CVE-2016-9393 CVE-2016-9394 CVE-2017-1000050 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: This update for jasper fixes the following issues: Security issues fixed: - CVE-2016-9262: Multiple integer overflows in the jas_realloc function in base/jas_malloc.c and mem_resize function in base/jas_stream.c allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities. (bsc#1009994) - CVE-2016-9388: The ras_getcmap function in ras_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010975) - CVE-2016-9389: The jpc_irct and jpc_iict functions in jpc_mct.c allow remote attackers to cause a denial of service (assertion failure). (bsc#1010968) - CVE-2016-9390: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010774) - CVE-2016-9391: The jpc_bitstream_getbits function in jpc_bs.c allows remote attackers to cause a denial of service (assertion failure) via a very large integer. (bsc#1010782) - CVE-2017-1000050: The jp2_encode function in jp2_enc.c allows remote attackers to cause a denial of service. (bsc#1047958) CVEs already fixed with previous update: - CVE-2016-9392: The calcstepsizes function in jpc_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010757) - CVE-2016-9393: The jpc_pi_nextrpcl function in jpc_t2cod.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010766) - CVE-2016-9394: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010756) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-jasper-13215=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-jasper-13215=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-jasper-13215=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libjasper-devel-1.900.14-134.33.3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): libjasper-1.900.14-134.33.3.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64 s390x x86_64): libjasper-32bit-1.900.14-134.33.3.1 - SUSE Linux Enterprise Server 11-SP4 (ia64): libjasper-x86-1.900.14-134.33.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): jasper-debuginfo-1.900.14-134.33.3.1 jasper-debugsource-1.900.14-134.33.3.1 References: https://www.suse.com/security/cve/CVE-2016-9262.html https://www.suse.com/security/cve/CVE-2016-9388.html https://www.suse.com/security/cve/CVE-2016-9389.html https://www.suse.com/security/cve/CVE-2016-9390.html https://www.suse.com/security/cve/CVE-2016-9391.html https://www.suse.com/security/cve/CVE-2016-9392.html https://www.suse.com/security/cve/CVE-2016-9393.html https://www.suse.com/security/cve/CVE-2016-9394.html https://www.suse.com/security/cve/CVE-2017-1000050.html https://bugzilla.suse.com/1009994 https://bugzilla.suse.com/1010756 https://bugzilla.suse.com/1010757 https://bugzilla.suse.com/1010766 https://bugzilla.suse.com/1010774 https://bugzilla.suse.com/1010782 https://bugzilla.suse.com/1010968 https://bugzilla.suse.com/1010975 https://bugzilla.suse.com/1047958 From sle-security-updates at lists.suse.com Thu Jul 20 07:10:05 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 15:10:05 +0200 (CEST) Subject: SUSE-SU-2017:1903-1: important: Security update for Linux Kernel Live Patch 8 for SLE 12 SP2 Message-ID: <20170720131005.97968FF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 8 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1903-1 Rating: important References: #1039348 #1039496 #1045340 #1045406 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 4.4.59-92_20 fixes several issues. The following bugs were fixed: - CVE-2017-1000364: The previous fix for the stack gap increase tracked by CVE-2017-1000364 had a regression, which is fixed by this follow up patch. (bsc#1039496) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1181=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_59-92_20-default-2-2.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039348 https://bugzilla.suse.com/1039496 https://bugzilla.suse.com/1045340 https://bugzilla.suse.com/1045406 From sle-security-updates at lists.suse.com Thu Jul 20 07:11:21 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 15:11:21 +0200 (CEST) Subject: SUSE-SU-2017:1904-1: important: Security update for Linux Kernel Live Patch 7 for SLE 12 SP2 Message-ID: <20170720131121.5D670FF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 7 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1904-1 Rating: important References: #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 4.4.59-92_17 fixes one issue. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1180=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_59-92_17-default-2-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 07:11:49 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 15:11:49 +0200 (CEST) Subject: SUSE-SU-2017:1905-1: important: Security update for Linux Kernel Live Patch 16 for SLE 12 Message-ID: <20170720131149.1CDE5FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 16 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1905-1 Rating: important References: #1012183 #1012759 #1012852 #1013543 #1014271 #1017589 #1025013 #1030575 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 8 fixes is now available. Description: This update for the Linux Kernel 3.12.60-52_57 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1178=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1178=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_60-52_57-default-7-3.1 kgraft-patch-3_12_60-52_57-xen-7-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_60-52_57-default-7-3.1 kgraft-patch-3_12_60-52_57-xen-7-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1012183 https://bugzilla.suse.com/1012759 https://bugzilla.suse.com/1012852 https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1017589 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 07:13:39 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 15:13:39 +0200 (CEST) Subject: SUSE-SU-2017:1906-1: important: Security update for Linux Kernel Live Patch 17 for SLE 12 Message-ID: <20170720131339.00E2BFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 17 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1906-1 Rating: important References: #1013543 #1014271 #1017589 #1025013 #1030575 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for the Linux Kernel 3.12.60-52_60 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1179=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1179=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_60-52_60-default-6-3.1 kgraft-patch-3_12_60-52_60-xen-6-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_60-52_60-default-6-3.1 kgraft-patch-3_12_60-52_60-xen-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1017589 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 10:11:30 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 18:11:30 +0200 (CEST) Subject: SUSE-SU-2017:1907-1: important: Security update for Linux Kernel Live Patch 1 for SLE 12 SP2 Message-ID: <20170720161130.C933CFF41@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 1 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1907-1 Rating: important References: #1012183 #1012759 #1012852 #1013543 #1014271 #1019079 #1025013 #1025254 #1030575 #1031481 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 10 fixes is now available. Description: This update for the Linux Kernel 4.4.21-81 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1183=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_21-81-default-7-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1012183 https://bugzilla.suse.com/1012759 https://bugzilla.suse.com/1012852 https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 10:13:42 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 18:13:42 +0200 (CEST) Subject: SUSE-SU-2017:1908-1: important: Security update for Linux Kernel Live Patch 0 for SLE 12 SP2 Message-ID: <20170720161342.65540FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 0 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1908-1 Rating: important References: #1008284 #1012183 #1012759 #1012852 #1013543 #1014271 #1019079 #1025013 #1025254 #1030575 #1031481 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 11 fixes is now available. Description: This update for the Linux Kernel 4.4.21-69 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1182=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_21-69-default-7-21.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1008284 https://bugzilla.suse.com/1012183 https://bugzilla.suse.com/1012759 https://bugzilla.suse.com/1012852 https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 13:10:49 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:10:49 +0200 (CEST) Subject: SUSE-SU-2017:1909-1: important: Security update for Linux Kernel Live Patch 9 for SLE 12 SP1 Message-ID: <20170720191049.3DE02FF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 9 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1909-1 Rating: important References: #1012183 #1012759 #1012852 #1013543 #1014271 #1021417 #1025013 #1025254 #1030575 #1031481 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 10 fixes is now available. Description: This update for the Linux Kernel 3.12.67-60_64_18 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1190=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1190=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_67-60_64_18-default-8-3.1 kgraft-patch-3_12_67-60_64_18-xen-8-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_67-60_64_18-default-8-3.1 kgraft-patch-3_12_67-60_64_18-xen-8-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1012183 https://bugzilla.suse.com/1012759 https://bugzilla.suse.com/1012852 https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1021417 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 13:12:24 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:12:24 +0200 (CEST) Subject: SUSE-SU-2017:1910-1: important: Security update for Linux Kernel Live Patch 8 for SLE 12 SP1 Message-ID: <20170720191224.A179DFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 8 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1910-1 Rating: important References: #1001487 #1012183 #1012759 #1012852 #1013543 #1014271 #1021417 #1025013 #1030575 #1031481 #1039496 #991667 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 11 fixes is now available. Description: This update for the Linux Kernel 3.12.62-60_64_8 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1189=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1189=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_62-60_64_8-default-9-3.1 kgraft-patch-3_12_62-60_64_8-xen-9-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_62-60_64_8-default-9-3.1 kgraft-patch-3_12_62-60_64_8-xen-9-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1001487 https://bugzilla.suse.com/1012183 https://bugzilla.suse.com/1012759 https://bugzilla.suse.com/1012852 https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1021417 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1039496 https://bugzilla.suse.com/991667 From sle-security-updates at lists.suse.com Thu Jul 20 13:14:10 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:14:10 +0200 (CEST) Subject: SUSE-SU-2017:1911-1: important: Security update for Linux Kernel Live Patch 5 for SLE 12 SP2 Message-ID: <20170720191410.CA7CFFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 5 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1911-1 Rating: important References: #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 4.4.49-92_11 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1186=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_49-92_11-default-4-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 13:14:54 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:14:54 +0200 (CEST) Subject: SUSE-SU-2017:1912-1: important: Security update for Linux Kernel Live Patch 22 for SLE 12 Message-ID: <20170720191454.A5BADFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 22 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1912-1 Rating: important References: #1039348 #1039496 #1045340 #1045406 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 3.12.61-52_77 fixes several issues. The following bugs were fixed: - CVE-2017-1000364: The previous fix for the stack gap increase tracked by CVE-2017-1000364 had a regression, which is fixed by this follow up patch. (bsc#1039496) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1188=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1188=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_61-52_77-default-2-2.1 kgraft-patch-3_12_61-52_77-xen-2-2.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_61-52_77-default-2-2.1 kgraft-patch-3_12_61-52_77-xen-2-2.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039348 https://bugzilla.suse.com/1039496 https://bugzilla.suse.com/1045340 https://bugzilla.suse.com/1045406 From sle-security-updates at lists.suse.com Thu Jul 20 13:15:55 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:15:55 +0200 (CEST) Subject: SUSE-SU-2017:1913-1: important: Security update for Linux Kernel Live Patch 2 for SLE 12 SP2 Message-ID: <20170720191555.72BC6FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 2 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1913-1 Rating: important References: #1013543 #1014271 #1019079 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 8 fixes is now available. Description: This update for the Linux Kernel 4.4.21-84 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1184=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_21-84-default-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 13:17:16 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:17:16 +0200 (CEST) Subject: SUSE-SU-2017:1914-1: important: Security update for Linux Kernel Live Patch 3 for SLE 12 SP2 Message-ID: <20170720191716.D8FAFFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 3 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1914-1 Rating: important References: #1019079 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for the Linux Kernel 4.4.21-90 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1185=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_21-90-default-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Thu Jul 20 13:18:19 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:18:19 +0200 (CEST) Subject: SUSE-SU-2017:1915-1: important: Security update for Linux Kernel Live Patch 16 for SLE 12 SP1 Message-ID: <20170720191819.23E19FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 16 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1915-1 Rating: important References: #1039348 #1039496 #1045340 #1045406 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 3.12.74-60_64_45 fixes several issues. The following bugs were fixed: - CVE-2017-1000364: The previous fix for the stack gap increase tracked by CVE-2017-1000364 had a regression, which is fixed by this follow up patch. (bsc#1039496) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1187=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1187=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_74-60_64_45-default-2-2.1 kgraft-patch-3_12_74-60_64_45-xen-2-2.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_74-60_64_45-default-2-2.1 kgraft-patch-3_12_74-60_64_45-xen-2-2.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039348 https://bugzilla.suse.com/1039496 https://bugzilla.suse.com/1045340 https://bugzilla.suse.com/1045406 From sle-security-updates at lists.suse.com Thu Jul 20 13:19:09 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Thu, 20 Jul 2017 21:19:09 +0200 (CEST) Subject: SUSE-SU-2017:1916-1: moderate: Security update for jasper Message-ID: <20170720191909.3EAE3FC3F@maintenance.suse.de> SUSE Security Update: Security update for jasper ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1916-1 Rating: moderate References: #1009994 #1010756 #1010757 #1010766 #1010774 #1010782 #1010968 #1010975 #1047958 Cross-References: CVE-2016-9262 CVE-2016-9388 CVE-2016-9389 CVE-2016-9390 CVE-2016-9391 CVE-2016-9392 CVE-2016-9393 CVE-2016-9394 CVE-2017-1000050 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: This update for jasper fixes the following issues: Security issues fixed: - CVE-2016-9262: Multiple integer overflows in the jas_realloc function in base/jas_malloc.c and mem_resize function in base/jas_stream.c allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities. (bsc#1009994) - CVE-2016-9388: The ras_getcmap function in ras_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010975) - CVE-2016-9389: The jpc_irct and jpc_iict functions in jpc_mct.c allow remote attackers to cause a denial of service (assertion failure). (bsc#1010968) - CVE-2016-9390: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. (bsc#1010774) - CVE-2016-9391: The jpc_bitstream_getbits function in jpc_bs.c allows remote attackers to cause a denial of service (assertion failure) via a very large integer. (bsc#1010782) - CVE-2017-1000050: The jp2_encode function in jp2_enc.c allows remote attackers to cause a denial of service. (bsc#1047958) CVEs already fixed with previous update: - CVE-2016-9392: The calcstepsizes function in jpc_dec.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010757) - CVE-2016-9393: The jpc_pi_nextrpcl function in jpc_t2cod.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010766) - CVE-2016-9394: The jas_seq2d_create function in jas_seq.c allows remote attackers to cause a denial of service (assertion failure) via a crafted file. (bsc#1010756) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1191=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1191=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1191=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1191=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): jasper-debuginfo-1.900.14-195.3.1 jasper-debugsource-1.900.14-195.3.1 libjasper-devel-1.900.14-195.3.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): jasper-debuginfo-1.900.14-195.3.1 jasper-debugsource-1.900.14-195.3.1 libjasper1-1.900.14-195.3.1 libjasper1-debuginfo-1.900.14-195.3.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): jasper-debuginfo-1.900.14-195.3.1 jasper-debugsource-1.900.14-195.3.1 libjasper1-1.900.14-195.3.1 libjasper1-debuginfo-1.900.14-195.3.1 - SUSE Linux Enterprise Server 12-SP2 (x86_64): libjasper1-32bit-1.900.14-195.3.1 libjasper1-debuginfo-32bit-1.900.14-195.3.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): jasper-debuginfo-1.900.14-195.3.1 jasper-debugsource-1.900.14-195.3.1 libjasper1-1.900.14-195.3.1 libjasper1-32bit-1.900.14-195.3.1 libjasper1-debuginfo-1.900.14-195.3.1 libjasper1-debuginfo-32bit-1.900.14-195.3.1 References: https://www.suse.com/security/cve/CVE-2016-9262.html https://www.suse.com/security/cve/CVE-2016-9388.html https://www.suse.com/security/cve/CVE-2016-9389.html https://www.suse.com/security/cve/CVE-2016-9390.html https://www.suse.com/security/cve/CVE-2016-9391.html https://www.suse.com/security/cve/CVE-2016-9392.html https://www.suse.com/security/cve/CVE-2016-9393.html https://www.suse.com/security/cve/CVE-2016-9394.html https://www.suse.com/security/cve/CVE-2017-1000050.html https://bugzilla.suse.com/1009994 https://bugzilla.suse.com/1010756 https://bugzilla.suse.com/1010757 https://bugzilla.suse.com/1010766 https://bugzilla.suse.com/1010774 https://bugzilla.suse.com/1010782 https://bugzilla.suse.com/1010968 https://bugzilla.suse.com/1010975 https://bugzilla.suse.com/1047958 From sle-security-updates at lists.suse.com Fri Jul 21 07:10:20 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 21 Jul 2017 15:10:20 +0200 (CEST) Subject: SUSE-SU-2017:1922-1: important: Security update for Linux Kernel Live Patch 18 for SLE 12 Message-ID: <20170721131020.CC29FFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 18 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1922-1 Rating: important References: #1017589 #1025013 #1030575 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has four fixes is now available. Description: This update for the Linux Kernel 3.12.60-52_63 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1194=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1194=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_60-52_63-default-6-3.1 kgraft-patch-3_12_60-52_63-xen-6-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_60-52_63-default-6-3.1 kgraft-patch-3_12_60-52_63-xen-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1017589 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Fri Jul 21 07:11:20 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 21 Jul 2017 15:11:20 +0200 (CEST) Subject: SUSE-SU-2017:1923-1: important: Security update for Linux Kernel Live Patch 4 for SLE 12 SP2 Message-ID: <20170721131120.A5D3EFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 4 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1923-1 Rating: important References: #1019079 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for the Linux Kernel 4.4.38-93 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1197=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_38-93-default-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1019079 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Fri Jul 21 07:12:32 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 21 Jul 2017 15:12:32 +0200 (CEST) Subject: SUSE-SU-2017:1924-1: important: Security update for Linux Kernel Live Patch 19 for SLE 12 Message-ID: <20170721131232.A18B2FF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 19 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1924-1 Rating: important References: #1025013 #1030575 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 3.12.61-52_66 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1195=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1195=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_61-52_66-default-5-3.1 kgraft-patch-3_12_61-52_66-xen-5-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_61-52_66-default-5-3.1 kgraft-patch-3_12_61-52_66-xen-5-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Fri Jul 21 07:13:20 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 21 Jul 2017 15:13:20 +0200 (CEST) Subject: SUSE-SU-2017:1925-1: important: Security update for Linux Kernel Live Patch 6 for SLE 12 SP2 Message-ID: <20170721131320.6E7CBFF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 6 for SLE 12 SP2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1925-1 Rating: important References: #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Live Patching 12 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for the Linux Kernel 4.4.49-92_14 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12: zypper in -t patch SUSE-SLE-Live-Patching-12-2017-1196=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Live Patching 12 (x86_64): kgraft-patch-4_4_49-92_14-default-3-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:10:36 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:10:36 +0200 (CEST) Subject: SUSE-SU-2017:1937-1: important: Security update for Linux Kernel Live Patch 12 for SLE 12 SP1 Message-ID: <20170724191036.B6E36FF3A@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 12 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1937-1 Rating: important References: #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 5 fixes is now available. Description: This update for the Linux Kernel 3.12.69-60_64_29 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1207=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1207=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_69-60_64_29-default-5-3.1 kgraft-patch-3_12_69-60_64_29-xen-5-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_69-60_64_29-default-5-3.1 kgraft-patch-3_12_69-60_64_29-xen-5-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:11:42 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:11:42 +0200 (CEST) Subject: SUSE-SU-2017:1938-1: moderate: Security update for apport Message-ID: <20170724191142.21AFDFF3A@maintenance.suse.de> SUSE Security Update: Security update for apport ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1938-1 Rating: moderate References: #947731 Cross-References: CVE-2015-1338 Affected Products: SUSE Linux Enterprise Server 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for apport fixes the following issues: Security issue fixed: - CVE-2015-1338: Insecurely created crash dumps could lead to a DoS or privilege escalation through malicious symlinks. (bsc#947731) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-apport-13220=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apport-0.114-12.8.3.1 apport-crashdb-sle-0.114-0.8.3.1 apport-gtk-0.114-12.8.3.1 References: https://www.suse.com/security/cve/CVE-2015-1338.html https://bugzilla.suse.com/947731 From sle-security-updates at lists.suse.com Mon Jul 24 13:12:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:12:08 +0200 (CEST) Subject: SUSE-SU-2017:1939-1: important: Security update for Linux Kernel Live Patch 21 for SLE 12 Message-ID: <20170724191208.E07F2FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 21 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1939-1 Rating: important References: #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 3.12.61-52_72 fixes one issue. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1206=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1206=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_61-52_72-default-2-3.1 kgraft-patch-3_12_61-52_72-xen-2-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_61-52_72-default-2-3.1 kgraft-patch-3_12_61-52_72-xen-2-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:13:54 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:13:54 +0200 (CEST) Subject: SUSE-SU-2017:1941-1: important: Security update for Linux Kernel Live Patch 13 for SLE 12 SP1 Message-ID: <20170724191354.B7708FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 13 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1941-1 Rating: important References: #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for the Linux Kernel 3.12.69-60_64_32 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1208=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1208=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_69-60_64_32-default-4-3.1 kgraft-patch-3_12_69-60_64_32-xen-4-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_69-60_64_32-default-4-3.1 kgraft-patch-3_12_69-60_64_32-xen-4-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:14:41 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:14:41 +0200 (CEST) Subject: SUSE-SU-2017:1942-1: important: Security update for Linux Kernel Live Patch 11 for SLE 12 SP1 Message-ID: <20170724191441.369E4FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 11 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1942-1 Rating: important References: #1021417 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for the Linux Kernel 3.12.67-60_64_24 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1211=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1211=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_67-60_64_24-default-6-3.1 kgraft-patch-3_12_67-60_64_24-xen-6-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_67-60_64_24-default-6-3.1 kgraft-patch-3_12_67-60_64_24-xen-6-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1021417 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:16:00 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:16:00 +0200 (CEST) Subject: SUSE-SU-2017:1943-1: important: Security update for Linux Kernel Live Patch 15 for SLE 12 SP1 Message-ID: <20170724191600.13BE5FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 15 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1943-1 Rating: important References: #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 3.12.74-60_64_40 fixes one issue. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1209=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1209=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_74-60_64_40-default-2-3.1 kgraft-patch-3_12_74-60_64_40-xen-2-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_74-60_64_40-default-2-3.1 kgraft-patch-3_12_74-60_64_40-xen-2-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:16:27 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:16:27 +0200 (CEST) Subject: SUSE-SU-2017:1944-1: important: Security update for Linux Kernel Live Patch 14 for SLE 12 SP1 Message-ID: <20170724191627.81ABEFC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 14 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1944-1 Rating: important References: #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for the Linux Kernel 3.12.69-60_64_35 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1210=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1210=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_69-60_64_35-default-3-3.1 kgraft-patch-3_12_69-60_64_35-xen-3-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_69-60_64_35-default-3-3.1 kgraft-patch-3_12_69-60_64_35-xen-3-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:17:04 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:17:04 +0200 (CEST) Subject: SUSE-SU-2017:1945-1: important: Security update for Linux Kernel Live Patch 20 for SLE 12 Message-ID: <20170724191704.BEF3FFC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 20 for SLE 12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1945-1 Rating: important References: #1025013 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12 SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for the Linux Kernel 3.12.61-52_69 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12: zypper in -t patch SUSE-SLE-SAP-12-2017-1205=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2017-1205=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12 (x86_64): kgraft-patch-3_12_61-52_69-default-3-3.1 kgraft-patch-3_12_61-52_69-xen-3-3.1 - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_61-52_69-default-3-3.1 kgraft-patch-3_12_61-52_69-xen-3-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Mon Jul 24 13:17:41 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Mon, 24 Jul 2017 21:17:41 +0200 (CEST) Subject: SUSE-SU-2017:1946-1: important: Security update for Linux Kernel Live Patch 10 for SLE 12 SP1 Message-ID: <20170724191741.9C763FC3F@maintenance.suse.de> SUSE Security Update: Security update for Linux Kernel Live Patch 10 for SLE 12 SP1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1946-1 Rating: important References: #1013543 #1014271 #1021417 #1025013 #1025254 #1030575 #1031481 #1031660 #1039496 Cross-References: CVE-2017-1000364 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that solves one vulnerability and has 8 fixes is now available. Description: This update for the Linux Kernel 3.12.67-60_64_21 fixes several issues. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed) (bsc#1039496). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2017-1212=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-1212=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_67-60_64_21-default-7-3.1 kgraft-patch-3_12_67-60_64_21-xen-7-3.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_67-60_64_21-default-7-3.1 kgraft-patch-3_12_67-60_64_21-xen-7-3.1 References: https://www.suse.com/security/cve/CVE-2017-1000364.html https://bugzilla.suse.com/1013543 https://bugzilla.suse.com/1014271 https://bugzilla.suse.com/1021417 https://bugzilla.suse.com/1025013 https://bugzilla.suse.com/1025254 https://bugzilla.suse.com/1030575 https://bugzilla.suse.com/1031481 https://bugzilla.suse.com/1031660 https://bugzilla.suse.com/1039496 From sle-security-updates at lists.suse.com Wed Jul 26 10:12:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 26 Jul 2017 18:12:08 +0200 (CEST) Subject: SUSE-SU-2017:1961-1: moderate: Security update for apache2 Message-ID: <20170726161208.4FC84FF41@maintenance.suse.de> SUSE Security Update: Security update for apache2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1961-1 Rating: moderate References: #1023616 #1043055 #1048576 Cross-References: CVE-2017-9788 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for apache2 fixes the following issues: Security issue fixed: - CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest. (bsc#1048576) Bug fixes: - Include individual sysconfig.d files instead of the whole sysconfig.d directory. - Include sysconfig.d/include.conf after httpd.conf is processed. (bsc#1023616, bsc#1043055) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2017-1220=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1220=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1220=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1220=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1220=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): apache2-debuginfo-2.4.23-29.3.2 apache2-debugsource-2.4.23-29.3.2 apache2-devel-2.4.23-29.3.2 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): apache2-debuginfo-2.4.23-29.3.2 apache2-debugsource-2.4.23-29.3.2 apache2-devel-2.4.23-29.3.2 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): apache2-2.4.23-29.3.2 apache2-debuginfo-2.4.23-29.3.2 apache2-debugsource-2.4.23-29.3.2 apache2-example-pages-2.4.23-29.3.2 apache2-prefork-2.4.23-29.3.2 apache2-prefork-debuginfo-2.4.23-29.3.2 apache2-utils-2.4.23-29.3.2 apache2-utils-debuginfo-2.4.23-29.3.2 apache2-worker-2.4.23-29.3.2 apache2-worker-debuginfo-2.4.23-29.3.2 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (noarch): apache2-doc-2.4.23-29.3.2 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le x86_64): apache2-2.4.23-29.3.2 apache2-debuginfo-2.4.23-29.3.2 apache2-debugsource-2.4.23-29.3.2 apache2-example-pages-2.4.23-29.3.2 apache2-prefork-2.4.23-29.3.2 apache2-prefork-debuginfo-2.4.23-29.3.2 apache2-utils-2.4.23-29.3.2 apache2-utils-debuginfo-2.4.23-29.3.2 apache2-worker-2.4.23-29.3.2 apache2-worker-debuginfo-2.4.23-29.3.2 - SUSE Linux Enterprise Server 12-SP3 (noarch): apache2-doc-2.4.23-29.3.2 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le x86_64): apache2-2.4.23-29.3.2 apache2-debuginfo-2.4.23-29.3.2 apache2-debugsource-2.4.23-29.3.2 apache2-example-pages-2.4.23-29.3.2 apache2-prefork-2.4.23-29.3.2 apache2-prefork-debuginfo-2.4.23-29.3.2 apache2-utils-2.4.23-29.3.2 apache2-utils-debuginfo-2.4.23-29.3.2 apache2-worker-2.4.23-29.3.2 apache2-worker-debuginfo-2.4.23-29.3.2 - SUSE Linux Enterprise Server 12-SP2 (noarch): apache2-doc-2.4.23-29.3.2 References: https://www.suse.com/security/cve/CVE-2017-9788.html https://bugzilla.suse.com/1023616 https://bugzilla.suse.com/1043055 https://bugzilla.suse.com/1048576 From sle-security-updates at lists.suse.com Wed Jul 26 14:25:15 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Wed, 26 Jul 2017 22:25:15 +0200 (CEST) Subject: SUSE-SU-2017:1964-1: moderate: Security update for containerd, docker, runc Message-ID: <20170726202515.1DD99FF3A@maintenance.suse.de> SUSE Security Update: Security update for containerd, docker, runc ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1964-1 Rating: moderate References: #1012568 #1019251 Cross-References: CVE-2016-9962 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Module for Containers 12 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for - containerd - docker to 1.12.6 - runc fixes the two issues. This security issue was fixed: - CVE-2016-9962: A difficult to exploit race condition caused by passing a file descriptor from the host's filesystem into the container could have allowed the guest to escape(bsc#1012568). For docker this non-security issue was fixed: - bsc#1019251: Waiting when starting the docker service Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2017-201=1 - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2017-201=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE OpenStack Cloud 6 (x86_64): containerd-0.2.5+gitr569_2a5e70c-15.3 containerd-debuginfo-0.2.5+gitr569_2a5e70c-15.3 containerd-debugsource-0.2.5+gitr569_2a5e70c-15.3 docker-1.12.6-87.2 docker-debuginfo-1.12.6-87.2 docker-debugsource-1.12.6-87.2 runc-0.1.1+gitr2819_50a19c6-15.2 runc-debuginfo-0.1.1+gitr2819_50a19c6-15.2 runc-debugsource-0.1.1+gitr2819_50a19c6-15.2 - SUSE Linux Enterprise Module for Containers 12 (ppc64le s390x x86_64): containerd-0.2.5+gitr569_2a5e70c-15.3 containerd-debuginfo-0.2.5+gitr569_2a5e70c-15.3 containerd-debugsource-0.2.5+gitr569_2a5e70c-15.3 docker-1.12.6-87.2 docker-debuginfo-1.12.6-87.2 docker-debugsource-1.12.6-87.2 runc-0.1.1+gitr2819_50a19c6-15.2 runc-debuginfo-0.1.1+gitr2819_50a19c6-15.2 runc-debugsource-0.1.1+gitr2819_50a19c6-15.2 References: https://www.suse.com/security/cve/CVE-2016-9962.html https://bugzilla.suse.com/1012568 https://bugzilla.suse.com/1019251 From sle-security-updates at lists.suse.com Fri Jul 28 07:07:12 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 15:07:12 +0200 (CEST) Subject: SUSE-SU-2017:1986-1: moderate: Security update for libquicktime Message-ID: <20170728130712.800AFFF3A@maintenance.suse.de> SUSE Security Update: Security update for libquicktime ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1986-1 Rating: moderate References: #1022805 Cross-References: CVE-2016-2399 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP3 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libquicktime fixes the following issues: Security issue fixed: - CVE-2016-2399: Adjust patch to prevent endless loop when there are less than 256 bytes to read. (bsc#1022805) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2017-1229=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1229=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1229=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1229=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1229=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-1229=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1229=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime-devel-1.2.4-14.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime-devel-1.2.4-14.3.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime0-1.2.4-14.3.1 libquicktime0-debuginfo-1.2.4-14.3.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime0-1.2.4-14.3.1 libquicktime0-debuginfo-1.2.4-14.3.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime0-1.2.4-14.3.1 libquicktime0-debuginfo-1.2.4-14.3.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime0-1.2.4-14.3.1 libquicktime0-debuginfo-1.2.4-14.3.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libquicktime-debugsource-1.2.4-14.3.1 libquicktime0-1.2.4-14.3.1 libquicktime0-debuginfo-1.2.4-14.3.1 References: https://www.suse.com/security/cve/CVE-2016-2399.html https://bugzilla.suse.com/1022805 From sle-security-updates at lists.suse.com Fri Jul 28 07:07:57 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 15:07:57 +0200 (CEST) Subject: SUSE-SU-2017:1988-1: moderate: Security update for libquicktime Message-ID: <20170728130757.84896FF3A@maintenance.suse.de> SUSE Security Update: Security update for libquicktime ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1988-1 Rating: moderate References: #1022805 #1044000 #1044002 #1044006 #1044008 #1044009 #1044077 #1044122 Cross-References: CVE-2016-2399 CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125 CVE-2017-9126 CVE-2017-9127 CVE-2017-9128 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for libquicktime fixes the following issues: Security issues fixed: - CVE-2017-9122: A DoS in quicktime_read_moov function in moov.c via a crafted mp4 file was fixed. (bsc#1044077) - CVE-2017-9123: An invalid memory read in lqt_frame_duration via a crafted mp4 file was fixed. (bsc#1044009) - CVE-2017-9124: A NULL pointer dereference in quicktime_match_32 via a crafted mp4 file was fixed. (bsc#1044008) - CVE-2017-9125: A DoS in lqt_frame_duration function in lqt_quicktime.c via crafted mp4 file was fixed. (bsc#1044122) - CVE-2017-9126: A heap-based buffer overflow in quicktime_read_dref_table via a crafted mp4 file was fixed. (bsc#1044006) - CVE-2017-9127: A heap-based buffer overflow in quicktime_user_atoms_read_atom via a crafted mp4 file was fixed. (bsc#1044002) - CVE-2017-9128: A heap-based buffer over-read in quicktime_video_width via a crafted mp4 file was fixed. (bsc#1044000) - CVE-2016-2399: Adjust fix to prevent endless loop when there are less than 256 bytes to read. (bsc#1022805) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-libquicktime-13222=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-libquicktime-13222=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libquicktime-1.0.3-6.5.1 libquicktime-devel-1.0.3-6.5.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): libquicktime-debuginfo-1.0.3-6.5.1 libquicktime-debugsource-1.0.3-6.5.1 References: https://www.suse.com/security/cve/CVE-2016-2399.html https://www.suse.com/security/cve/CVE-2017-9122.html https://www.suse.com/security/cve/CVE-2017-9123.html https://www.suse.com/security/cve/CVE-2017-9124.html https://www.suse.com/security/cve/CVE-2017-9125.html https://www.suse.com/security/cve/CVE-2017-9126.html https://www.suse.com/security/cve/CVE-2017-9127.html https://www.suse.com/security/cve/CVE-2017-9128.html https://bugzilla.suse.com/1022805 https://bugzilla.suse.com/1044000 https://bugzilla.suse.com/1044002 https://bugzilla.suse.com/1044006 https://bugzilla.suse.com/1044008 https://bugzilla.suse.com/1044009 https://bugzilla.suse.com/1044077 https://bugzilla.suse.com/1044122 From sle-security-updates at lists.suse.com Fri Jul 28 07:09:23 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 15:09:23 +0200 (CEST) Subject: SUSE-SU-2017:1989-1: moderate: Security update for libical Message-ID: <20170728130923.ECBD3FF3A@maintenance.suse.de> SUSE Security Update: Security update for libical ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1989-1 Rating: moderate References: #1015964 #1044995 #986631 #986639 Cross-References: CVE-2016-5824 CVE-2016-5827 CVE-2016-9584 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP3 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for libical fixes the following issues: Security issues fixed: - CVE-2016-5824: libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. (bsc#986639) - CVE-2016-5827: The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted string to the icalparser_parse_string function. (bsc#986631) - CVE-2016-9584: libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file. (bsc#1015964) Bug fixes: - libical crashes while parsing timezones (bsc#1044995) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2017-1230=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1230=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1230=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1230=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1230=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-1230=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1230=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libical-debugsource-1.0.1-16.3.1 libical-devel-1.0.1-16.3.1 libical-devel-static-1.0.1-16.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libical-debugsource-1.0.1-16.3.1 libical-devel-1.0.1-16.3.1 libical-devel-static-1.0.1-16.3.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libical-debugsource-1.0.1-16.3.1 libical1-1.0.1-16.3.1 libical1-debuginfo-1.0.1-16.3.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libical-debugsource-1.0.1-16.3.1 libical1-1.0.1-16.3.1 libical1-debuginfo-1.0.1-16.3.1 - SUSE Linux Enterprise Server 12-SP3 (s390x x86_64): libical1-32bit-1.0.1-16.3.1 libical1-debuginfo-32bit-1.0.1-16.3.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64): libical-debugsource-1.0.1-16.3.1 libical1-1.0.1-16.3.1 libical1-debuginfo-1.0.1-16.3.1 - SUSE Linux Enterprise Server 12-SP2 (s390x x86_64): libical1-32bit-1.0.1-16.3.1 libical1-debuginfo-32bit-1.0.1-16.3.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libical-debugsource-1.0.1-16.3.1 libical1-1.0.1-16.3.1 libical1-32bit-1.0.1-16.3.1 libical1-debuginfo-1.0.1-16.3.1 libical1-debuginfo-32bit-1.0.1-16.3.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libical-debugsource-1.0.1-16.3.1 libical1-1.0.1-16.3.1 libical1-32bit-1.0.1-16.3.1 libical1-debuginfo-1.0.1-16.3.1 libical1-debuginfo-32bit-1.0.1-16.3.1 References: https://www.suse.com/security/cve/CVE-2016-5824.html https://www.suse.com/security/cve/CVE-2016-5827.html https://www.suse.com/security/cve/CVE-2016-9584.html https://bugzilla.suse.com/1015964 https://bugzilla.suse.com/1044995 https://bugzilla.suse.com/986631 https://bugzilla.suse.com/986639 From sle-security-updates at lists.suse.com Fri Jul 28 07:10:23 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 15:10:23 +0200 (CEST) Subject: SUSE-SU-2017:1990-1: important: Security update for the Linux Kernel Message-ID: <20170728131023.7FE75FC6C@maintenance.suse.de> SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1990-1 Rating: important References: #1000092 #1003077 #1003581 #1004003 #1007729 #1007959 #1007962 #1008842 #1009674 #1009718 #1010032 #1010612 #1010690 #1011044 #1011176 #1011913 #1012060 #1012382 #1012422 #1012452 #1012829 #1012910 #1012985 #1013001 #1013561 #1013792 #1013887 #1013994 #1014120 #1014136 #1015342 #1015367 #1015452 #1015609 #1016403 #1017164 #1017170 #1017410 #1017461 #1017641 #1018100 #1018263 #1018358 #1018385 #1018419 #1018446 #1018813 #1018885 #1018913 #1019061 #1019148 #1019163 #1019168 #1019260 #1019351 #1019594 #1019614 #1019618 #1019630 #1019631 #1019784 #1019851 #1020048 #1020214 #1020412 #1020488 #1020602 #1020685 #1020817 #1020945 #1020975 #1021082 #1021248 #1021251 #1021258 #1021260 #1021294 #1021424 #1021455 #1021474 #1021762 #1022181 #1022266 #1022304 #1022340 #1022429 #1022476 #1022547 #1022559 #1022595 #1022785 #1022971 #1023101 #1023175 #1023287 #1023762 #1023866 #1023884 #1023888 #1024015 #1024081 #1024234 #1024508 #1024938 #1025039 #1025235 #1025461 #1025683 #1026024 #1026405 #1026462 #1026505 #1026509 #1026570 #1026692 #1026722 #1027054 #1027066 #1027101 #1027153 #1027179 #1027189 #1027190 #1027195 #1027273 #1027512 #1027565 #1027616 #1027974 #1028017 #1028027 #1028041 #1028158 #1028217 #1028310 #1028325 #1028340 #1028372 #1028415 #1028819 #1028883 #1028895 #1029220 #1029514 #1029607 #1029634 #1029986 #1030057 #1030070 #1030118 #1030213 #1030573 #1031003 #1031040 #1031052 #1031142 #1031147 #1031200 #1031206 #1031208 #1031440 #1031470 #1031500 #1031512 #1031555 #1031579 #1031662 #1031717 #1031796 #1031831 #1032006 #1032141 #1032339 #1032345 #1032400 #1032581 #1032673 #1032681 #1032803 #1033117 #1033281 #1033287 #1033336 #1033340 #1033885 #1034048 #1034419 #1034635 #1034670 #1034671 #1034762 #1034902 #1034995 #1035024 #1035866 #1035887 #1035920 #1035922 #1036214 #1036638 #1036752 #1036763 #1037177 #1037186 #1037384 #1037483 #1037669 #1037840 #1037871 #1037969 #1038033 #1038043 #1038085 #1038142 #1038143 #1038297 #1038458 #1038544 #1038842 #1038843 #1038846 #1038847 #1038848 #1038879 #1038981 #1038982 #1039348 #1039354 #1039700 #1039864 #1039882 #1039883 #1039885 #1039900 #1040069 #1040125 #1040182 #1040279 #1040351 #1040364 #1040395 #1040425 #1040463 #1040567 #1040609 #1040855 #1040929 #1040941 #1041087 #1041160 #1041168 #1041242 #1041431 #1041810 #1042200 #1042286 #1042356 #1042421 #1042517 #1042535 #1042536 #1042863 #1042886 #1043014 #1043231 #1043236 #1043347 #1043371 #1043467 #1043488 #1043598 #1043912 #1043935 #1043990 #1044015 #1044082 #1044120 #1044125 #1044532 #1044767 #1044772 #1044854 #1044880 #1044912 #1045154 #1045235 #1045286 #1045307 #1045340 #1045467 #1045568 #1046105 #1046434 #1046589 #799133 #863764 #870618 #922871 #951844 #966170 #966172 #966191 #966321 #966339 #968697 #969479 #969755 #970083 #971975 #982783 #985561 #986362 #986365 #987192 #987576 #988065 #989056 #989311 #990058 #990682 #991273 #993832 #995542 #995968 #998106 Cross-References: CVE-2016-10200 CVE-2016-2117 CVE-2016-4997 CVE-2016-4998 CVE-2016-7117 CVE-2016-9191 CVE-2017-1000364 CVE-2017-1000365 CVE-2017-1000380 CVE-2017-2583 CVE-2017-2584 CVE-2017-2596 CVE-2017-2636 CVE-2017-2671 CVE-2017-5551 CVE-2017-5576 CVE-2017-5577 CVE-2017-5897 CVE-2017-5970 CVE-2017-5986 CVE-2017-6074 CVE-2017-6214 CVE-2017-6345 CVE-2017-6346 CVE-2017-6347 CVE-2017-6353 CVE-2017-7184 CVE-2017-7187 CVE-2017-7261 CVE-2017-7294 CVE-2017-7308 CVE-2017-7346 CVE-2017-7374 CVE-2017-7487 CVE-2017-7616 CVE-2017-7618 CVE-2017-8890 CVE-2017-9074 CVE-2017-9075 CVE-2017-9076 CVE-2017-9077 CVE-2017-9150 CVE-2017-9242 Affected Products: SUSE Linux Enterprise Real Time Extension 12-SP2 ______________________________________________________________________________ An update that solves 43 vulnerabilities and has 282 fixes is now available. Description: The SUSE Linux Enterprise 12 SP2 Realtime kernel was updated to 4.4.74 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2017-1000364: An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010) (bnc#1039348). - CVE-2017-1000365: The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but did not take the argument and environment pointers into account, which allowed attackers to bypass this limitation. (bnc#1039354). - CVE-2017-1000380: sound/core/timer.c in the Linux kernel is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time (bnc#1044125). - CVE-2017-7346: The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel did not validate certain levels data, which allowed local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device (bnc#1031796). - CVE-2017-9242: The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel is too late in checking whether an overwrite of an skb data structure may occur, which allowed local users to cause a denial of service (system crash) via crafted system calls (bnc#1041431). - CVE-2017-9076: The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1039885). - CVE-2017-9077: The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1040069). - CVE-2017-9075: The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel mishandled inheritance, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890 (bnc#1039883). - CVE-2017-9074: The IPv6 fragmentation implementation in the Linux kernel did not consider that the nexthdr field may be associated with an invalid option, which allowed local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls (bnc#1039882). - CVE-2017-7487: The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel mishandled reference counts, which allowed local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface (bnc#1038879). - CVE-2017-8890: The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel allowed attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call (bnc#1038544). - CVE-2017-9150: The do_check function in kernel/bpf/verifier.c in the Linux kernel did not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allowed local users to obtain sensitive address information via crafted bpf system calls (bnc#1040279). - CVE-2017-7618: crypto/ahash.c in the Linux kernel allowed attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue (bnc#1033340). - CVE-2016-4997: The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement (bnc#986362). - CVE-2016-4998: The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allowed local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary (bnc#986365). - CVE-2017-7616: Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel allowed local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation (bnc#1033336). - CVE-2017-2671: The ping_unhash function in net/ipv4/ping.c in the Linux kernel is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allowed local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call (bnc#1031003). - CVE-2017-7184: The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel did not validate certain size data after an XFRM_MSG_NEWAE update, which allowed local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52 (bnc#1030573). - CVE-2017-7308: The packet_set_ring function in net/packet/af_packet.c in the Linux kernel did not properly validate certain block-size data, which allowed local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls (bnc#1031579). - CVE-2017-7294: The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel did not validate addition of certain levels data, which allowed local users to trigger an integer overflow and out-of-bounds write, and cause a denial of service (system hang or crash) or possibly gain privileges, via a crafted ioctl call for a /dev/dri/renderD* device (bnc#1031440). - CVE-2017-7261: The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel did not check for a zero value of certain levels data, which allowed local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device (bnc#1031052). - CVE-2017-7187: The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel allowed local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, leading to out-of-bounds write access in the sg_write function (bnc#1030213). - CVE-2017-7374: Use-after-free vulnerability in fs/crypto/ in the Linux kernel allowed local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely (bnc#1032006). - CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel allowed local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c (bnc#1028415). - CVE-2017-2636: Race condition in drivers/tty/n_hdlc.c in the Linux kernel allowed local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline (bnc#1027565). - CVE-2017-6345: The LLC subsystem in the Linux kernel did not ensure that a certain destructor exists in required circumstances, which allowed local users to cause a denial of service (BUG_ON) or possibly have unspecified other impact via crafted system calls (bnc#1027190). - CVE-2017-6346: Race condition in net/packet/af_packet.c in the Linux kernel allowed local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that made PACKET_FANOUT setsockopt system calls (bnc#1027189). - CVE-2017-6353: net/sctp/socket.c in the Linux kernel did not properly restrict association peel-off operations during certain wait states, which allowed local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986. (bnc#1027066). - CVE-2017-6214: The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel allowed remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag (bnc#1026722). - CVE-2016-2117: The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel incorrectly enables scatter/gather I/O, which allowed remote attackers to obtain sensitive information from kernel memory by reading packet data (bnc#968697). - CVE-2017-6347: The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel has incorrect expectations about skb data layout, which allowed local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmission (bnc#1027179). - CVE-2016-9191: The cgroup offline implementation in the Linux kernel mishandled certain drain operations, which allowed local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity (bnc#1008842). - CVE-2017-2583: The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel improperly emulates a "MOV SS, NULL selector" instruction, which allowed guest OS users to cause a denial of service (guest OS crash) or gain guest OS privileges via a crafted application (bnc#1020602). - CVE-2017-2584: arch/x86/kvm/emulate.c in the Linux kernel allowed local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgdt, and sidt (bnc#1019851). - CVE-2017-2596: The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel improperly emulates the VMXON instruction, which allowed KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references (bnc#1022785). - CVE-2017-6074: The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel mishandled DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allowed local users to obtain root privileges or cause a denial of service (double free) via an application that made an IPV6_RECVPKTINFO setsockopt system call (bnc#1026024). - CVE-2017-5986: Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel allowed local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state (bnc#1025235). - CVE-2017-5970: The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel allowed attackers to cause a denial of service (system crash) via (1) an application that made crafted system calls or possibly (2) IPv4 traffic with invalid IP options (bnc#1024938). - CVE-2017-5897: The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allowed remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access (bnc#1023762). - CVE-2016-7117: Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel allowed remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing (bnc#1003077). - CVE-2017-5576: Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel allowed local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call (bnc#1021294). - CVE-2017-5577: The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel did not set an errno value upon certain overflow detections, which allowed local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call (bnc#1021294). - CVE-2017-5551: The simple_set_acl function in fs/posix_acl.c in the Linux kernel preserves the setgid bit during a setxattr call involving a tmpfs filesystem, which allowed local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7097. (bnc#1021258). The following non-security bugs were fixed: - 9p: fix a potential acl leak (4.4.68 stable queue). - acpi / APEI: Add missing synchronize_rcu() on NOTIFY_SCI removal (bsc#1031717). - acpi: Do not create a platform_device for IOAPIC/IOxAPIC (bsc#1028819). - acpi, ioapic: Clear on-stack resource before using it (bsc#1028819). - acpi, nfit: fix acpi_nfit_flush_probe() crash (bsc#1031717). - acpi, nfit: fix bus vs dimm confusion in xlat_status (bsc#1023175). - acpi, nfit: fix extended status translations for ACPI DSMs (bsc#1031717). - acpi, nfit, libnvdimm: fix / harden ars_status output length handling (bsc#1023175). - acpi, nfit: validate ars_status output buffer size (bsc#1023175). - acpi: Remove platform devices from a bus on removal (bsc#1028819). - acpi / scan: Drop support for force_remove (bnc#1029607). - ahci: disable correct irq for dummy ports (bsc#1040125). - alsa: hda - Fix deadlock of controller device lock at unbinding (4.4.68 stable queue). - arm64: hugetlb: fix the wrong address for several functions (bsc#1032681). - arm64: hugetlb: fix the wrong return value for huge_ptep_set_access_flags (bsc#1032681). - arm64: hugetlb: remove the wrong pmd check in find_num_contig() (bsc#1032681). - arm64/numa: fix incorrect log for memory-less node (bsc#1019631). - arm64: Use full path in KBUILD_IMAGE definition (bsc#1010032). - arm: 8452/3: PJ4: make coprocessor access sequences buildable in Thumb2 mode (4.4.68 stable queue). - arm: OMAP5 / DRA7: Fix HYP mode boot for thumb2 build (4.4.68 stable queue). - arm: Use full path in KBUILD_IMAGE definition (bsc#1010032). - ASoC: cht_bsw_rt5645: Fix leftover kmalloc (bsc#1010690). - ASoC: Intel: Skylake: Uninitialized variable in probe_codec() (bsc#1043231). - ASoC: rt5640: use msleep() for long delays (bsc#1031717). - ASoC: sti: Fix error handling if of_clk_get() fails (bsc#1031717). - avoid including "mountproto=" with no protocol in /proc/mounts (bsc#1019260). - bcache: fix calling ida_simple_remove() with incorrect minor (bsc#1038085). - bcache: Make gc wakeup sane, remove set_task_state() (bsc#1021260). - bcache: partition support: add 16 minors per bcacheN device (bsc#1019784). - blacklist 61e8a0d5a027 powerpc/pci: Fix endian bug in fixed PHB numbering (bsc#989311) - blacklist.conf: a04a480d4392 net: Require exact match for TCP socket lookups if dif is l3mdev (v4.9-rc4) 10/11 conflicts are with code introduced by 74b20582ac38 ("net: l3mdev: Add hook in ip and ipv6", v4.7-rc1) which is not present in SP2. I think that either the problem was always there or was introduced by 74b20582ac38. If in the first case, the fix would have to be implemented differently; if in the second case, the fix is not needed in SP2. - blacklist.conf: blacklist reverted commit Commit 82486aa6f1b9 ("ipv4: restore rt->fi for reference counting") was later reverted and replaced by commit 3fb07daff8e9 ("ipv4: add reference counting to metrics"). This solution breaks kABI, though, and I'll need to look into it more carefully to see if it can be worked around easily. - blk-mq: Allow timeouts to run while queue is freezing (bsc#1020817). - blk-mq: Always schedule hctx->next_cpu (bsc#1020817). - blk-mq: Avoid memory reclaim when remapping queues (bsc#1020817). - blk-mq: do not overwrite rq->mq_ctx (bsc#1020817). - blk-mq: Fix failed allocation path when mapping queues (bsc#1020817). - blk-mq: improve warning for running a queue on the wrong CPU (bsc#1020817). - block: Change extern inline to static inline (bsc#1023175). - block: copy NOMERGE flag from bio to request (bsc#1030070). - block: get rid of blk_integrity_revalidate() (4.4.68 stable queue). - bluetooth: btmrvl: fix hung task warning dump (bsc#1018813). - bna: add missing per queue ethtool stat (bsc#966321 FATE#320156). - bna: avoid writing uninitialized data into hw registers (bsc#966321 FATE#320156). - bna: integer overflow bug in debugfs (bsc#966321 FATE#320156). - bnx2x: allow adding VLANs while interface is down (bsc#1027273). - bnx2x: Correct ringparam estimate when DOWN (bsc#1020214). - bnxt_en: allocate enough space for ->ntp_fltr_bmap (bsc#1020412 FATE#321671). - bonding: avoid defaulting hard_header_len to ETH_HLEN on slave removal (bsc#1042286). - bonding: do not use stale speed and duplex information (bsc#1042286). - bonding: fix 802.3ad aggregator reselection (bsc#1029514). - bonding: prevent out of bound accesses (bsc#1042286). - bpf, arm64: fix jit branch offset related to ldimm64 (4.4.68 stable queue). - brcmfmac: add fallback for devices that do not report per-chain values (bsc#1043231). - brcmfmac: avoid writing channel out of allocated array (bsc#1043231). - brcmfmac: Change error print on wlan0 existence (bsc#1000092). - brcmfmac: Ensure pointer correctly set if skb data location changes (4.4.68 stable queue). - brcmfmac: Make skb header writable before use (4.4.68 stable queue). - brcmfmac: restore stopping netdev queue when bus clogs up (bsc#1031717). - btrfs: add a flags field to btrfs_fs_info (bsc#1012452). - btrfs: add ASSERT for block group's memory leak (bsc#1012452). - btrfs: add btrfs_trans_handle->fs_info pointer (bsc#1012452). - btrfs: add bytes_readonly to the spaceinfo at once (bsc#1012452). - btrfs: add check to sysfs handler of label (bsc#1012452). - btrfs: add dynamic debug support (bsc#1012452). - btrfs: add error handling for extent buffer in print tree (bsc#1012452). - btrfs: add missing bytes_readonly attribute file in sysfs (bsc#1012452). - btrfs: add missing check for writeback errors on fsync (bsc#1012452). - btrfs: add more validation checks for superblock (bsc#1012452). - btrfs: Add ratelimit to btrfs printing (bsc#1012452). - btrfs: add read-only check to sysfs handler of features (bsc#1012452). - btrfs: add semaphore to synchronize direct IO writes with fsync (bsc#1012452). - btrfs: add support for RENAME_EXCHANGE and RENAME_WHITEOUT (bsc#1020975). - btrfs: add tracepoint for adding block groups (bsc#1012452). - btrfs: add tracepoints for flush events (bsc#1012452). - btrfs: add transaction space reservation tracepoints (bsc#1012452). - btrfs: add validadtion checks for chunk loading (bsc#1012452). - btrfs: add write protection to SET_FEATURES ioctl (bsc#1012452). - btrfs: allow balancing to dup with multi-device (bsc#1012452). - btrfs: allow unlink to exceed subvolume quota (bsc#1019614). - btrfs: always reserve metadata for delalloc extents (bsc#1012452). - btrfs: always use trans->block_rsv for orphans (bsc#1012452). - btrfs: avoid blocking open_ctree from cleaner_kthread (bsc#1012452). - btrfs: avoid deadlocks during reservations in btrfs_truncate_block (bsc#1012452). - btrfs: avoid overflowing f_bfree (bsc#1012452). - btrfs: avoid uninitialized variable warning (bsc#1012452). - btrfs: backref: Fix soft lockup in __merge_refs function (bsc#1017641). - btrfs: btrfs_abort_transaction, drop root parameter (bsc#1012452). - btrfs: __btrfs_buffered_write: Pass valid file offset when releasing delalloc space (bsc#1012452). - btrfs: __btrfs_buffered_write: Reserve/release extents aligned to block size (bsc#1012452). - btrfs: btrfs_check_super_valid: Allow 4096 as stripesize (bsc#1012452). - btrfs: btrfs_debug should consume fs_info when DEBUG is not defined (bsc#1012452). - btrfs: btrfs_ioctl_clone: Truncate complete page after performing clone operation (bsc#1012452). - btrfs: btrfs_page_mkwrite: Reserve space in sectorsized units (bsc#1012452). - btrfs: btrfs_relocate_chunk pass extent_root to btrfs_end_transaction (bsc#1012452). - btrfs: btrfs_submit_direct_hook: Handle map_length < bio vector length (bsc#1012452). - btrfs: build fixup for qgroup_account_snapshot (bsc#1012452). - btrfs: change BUG_ON()'s to ASSERT()'s in backref_cache_cleanup() (bsc#1012452). - btrfs: change delayed reservation fallback behavior (bsc#1012452). - btrfs: change how we calculate the global block rsv (bsc#1012452). - btrfs: change how we update the global block rsv (bsc#1012452). - btrfs: Change qgroup_meta_rsv to 64bit (bsc#1019614). - btrfs: check btree node's nritems (bsc#1012452). - btrfs: check if extent buffer is aligned to sectorsize (bsc#1012452). - btrfs: check inconsistence between chunk and block group (bsc#1012452). - btrfs: check reserved when deciding to background flush (bsc#1012452). - btrfs: clarify do_chunk_alloc()'s return value (bsc#1012452). - btrfs: Clean pte corresponding to page straddling i_size (bsc#1012452). - btrfs: clean the old superblocks before freeing the device (bsc#1012452). - btrfs: clean up and optimize __check_raid_min_device() (bsc#1012452). - btrfs: cleanup assigning next active device with a check (bsc#1012452). - btrfs: cleanup BUG_ON in merge_bio (bsc#1012452). - btrfs: Cleanup compress_file_range() (bsc#1012452). - btrfs: cleanup error handling in extent_write_cached_pages (bsc#1012452). - btrfs: clear uptodate flags of pages in sys_array eb (bsc#1012452). - btrfs: clone: use vmalloc only as fallback for nodesize bufer (bsc#1012452). - btrfs: Compute and look up csums based on sectorsized blocks (bsc#1012452). - btrfs: convert nodesize macros to static inlines (bsc#1012452). - btrfs: convert printk(KERN_* to use pr_* calls (bsc#1012452). - btrfs: convert pr_* to btrfs_* where possible (bsc#1012452). - btrfs: convert send's verbose_printk to btrfs_debug (bsc#1012452). - btrfs: copy_to_sk drop unused root parameter (bsc#1012452). - btrfs: create a helper function to read the disk super (bsc#1012452). - btrfs: create example debugfs file only in debugging build (bsc#1012452). - btrfs: create helper btrfs_find_device_by_user_input() (bsc#1012452). - btrfs: create helper function __check_raid_min_devices() (bsc#1012452). - btrfs: csum_tree_block: return proper errno value (bsc#1012452). - btrfs: detect corruption when non-root leaf has zero item (bsc#1012452). - btrfs: device add and remove: use GFP_KERNEL (bsc#1012452). - btrfs: Direct I/O read: Work on sectorsized blocks (bsc#1012452). - btrfs: divide btrfs_update_reserved_bytes() into two functions (bsc#1012452). - btrfs: do not background blkdev_put() (bsc#1012452). - btrfs: do not bother kicking async if there's nothing to reclaim (bsc#1012452). - btrfs: do not BUG_ON() in btrfs_orphan_add (bsc#1012452). - btrfs: do not create empty block group if we have allocated data (bsc#1012452). - btrfs: do not decrease bytes_may_use when replaying extents (bsc#1012452). - btrfs: do not do nocow check unless we have to (bsc#1012452). - btrfs: do not do unnecessary delalloc flushes when relocating (bsc#1012452). - btrfs: do not force mounts to wait for cleaner_kthread to delete one or more subvolumes (bsc#1012452). - btrfs: do not wait for unrelated IO to finish before relocation (bsc#1012452). - btrfs: do not WARN() in btrfs_transaction_abort() for IO errors (bsc#1035866). - btrfs: do not write corrupted metadata blocks to disk (bsc#1012452). - btrfs: end transaction if we abort when creating uuid root (bsc#1012452). - btrfs: enhance btrfs_find_device_by_user_input() to check device path (bsc#1012452). - btrfs: error out if generic_bin_search get invalid arguments (bsc#1012452). - btrfs: expand cow_file_range() to support in-band dedup and subpage-blocksize (bsc#1012452). - btrfs: extend btrfs_set_extent_delalloc and its friends to support in-band dedupe and subpage size patchset (bsc#1012452). - btrfs: extent same: use GFP_KERNEL for page array allocations (bsc#1012452). - btrfs: fallback to vmalloc in btrfs_compare_tree (bsc#1012452). - btrfs: fallocate: use GFP_KERNEL (bsc#1012452). - btrfs: fallocate: Work with sectorsized blocks (bsc#1012452). - btrfs: fill relocation block rsv after allocation (bsc#1012452). - btrfs: fix an integer overflow check (bsc#1012452). - btrfs: fix a possible umount deadlock (bsc#1012452). - btrfs: Fix block size returned to user space (bsc#1012452). - btrfs: fix btrfs_compat_ioctl failures on non-compat ioctls (bsc#1018100). - btrfs: fix btrfs_no_printk stub helper (bsc#1012452). - btrfs: Fix BUG_ON condition in scrub_setup_recheck_block() (bsc#1012452). - btrfs: fix BUG_ON in btrfs_mark_buffer_dirty (bsc#1012452). - btrfs: fix BUG_ON in btrfs_submit_compressed_write (bsc#1012452). - btrfs: fix build warning (bsc#1012452). - btrfs: fix callers of btrfs_block_rsv_migrate (bsc#1012452). - btrfs: fix check_direct_IO() for non-iovec iterators (bsc#1012452). - btrfs: fix check_shared for fiemap ioctl (bsc#1037177). - btrfs: fix crash when tracepoint arguments are freed by wq callbacks (bsc#1012452). - btrfs: fix data loss after truncate when using the no-holes feature (bsc#1036214). - btrfs: fix deadlock in delayed_ref_async_start (bsc#1012452). - btrfs: fix delalloc accounting after copy_from_user faults (bsc#1012452). - btrfs: fix delalloc reservation amount tracepoint (bsc#1012452). - btrfs: fix disk_i_size update bug when fallocate() fails (bsc#1012452). - btrfs: fix divide error upon chunk's stripe_len (bsc#1012452). - btrfs: fix double free of fs root (bsc#1012452). - btrfs: fix eb memory leak due to readpage failure (bsc#1012452). - btrfs: fix em leak in find_first_block_group (bsc#1012452). - btrfs: fix emptiness check for dirtied extent buffers at check_leaf() (bsc#1012452). - btrfs: fix error handling in map_private_extent_buffer (bsc#1012452). - btrfs: fix error return code in btrfs_init_test_fs() (bsc#1012452). - btrfs: fix extent_same allowing destination offset beyond i_size (bsc#1012452). - btrfs: fix free space calculation in dump_space_info() (bsc#1012452). - btrfs: fix fsfreeze hang caused by delayed iputs deal (bsc#1012452). - btrfs: fix fspath error deallocation (bsc#1012452). - btrfs: fix handling of faults from btrfs_copy_from_user (bsc#1012452). - btrfs: fix inode leak on failure to setup whiteout inode in rename (bsc#1020975). - btrfs: fix int32 overflow in shrink_delalloc() (bsc#1012452). - btrfs: Fix integer overflow when calculating bytes_per_bitmap (bsc#1012452). - btrfs: fix invalid dereference in btrfs_retry_endio (bsc#1040395). - btrfs: fix invalid reference in replace_path (bsc#1012452). - btrfs: fix listxattrs not listing all xattrs packed in the same item (bsc#1012452). - btrfs: fix lockdep deadlock warning due to dev_replace (bsc#1012452). - btrfs: fix lockdep warning about log_mutex (bsc#1021455). - btrfs: fix lock dep warning, move scratch dev out of device_list_mutex and uuid_mutex (bsc#1012452). - btrfs: fix lock dep warning move scratch super outside of chunk_mutex (bsc#1012452). - btrfs: fix lockdep warning on deadlock against an inode's log mutex (bsc#1021455). - btrfs: fix __MAX_CSUM_ITEMS (bsc#1012452). - btrfs: fix memory leak during RAID 5/6 device replacement (bsc#1012452). - btrfs: fix memory leak of block group cache (bsc#1012452). - btrfs: fix memory leak of reloc_root (bsc#1012452). - btrfs: fix mixed block count of available space (bsc#1012452). - btrfs: fix number of transaction units for renames with whiteout (bsc#1020975). - btrfs: fix one bug that process may endlessly wait for ticket in wait_reserve_ticket() (bsc#1012452). - btrfs: fix panic in balance due to EIO (bsc#1012452). - btrfs: fix race between block group relocation and nocow writes (bsc#1012452). - btrfs: fix race between device replace and block group removal (bsc#1012452). - btrfs: fix race between device replace and chunk allocation (bsc#1012452). - btrfs: fix race between device replace and discard (bsc#1012452). - btrfs: fix race between device replace and read repair (bsc#1012452). - btrfs: fix race between fsync and direct IO writes for prealloc extents (bsc#1012452). - btrfs: fix race between readahead and device replace/removal (bsc#1012452). - btrfs: fix race setting block group back to RW mode during device replace (bsc#1012452). - btrfs: fix race setting block group readonly during device replace (bsc#1012452). - btrfs: fix read_node_slot to return errors (bsc#1012452). - btrfs: fix release reserved extents trace points (bsc#1012452). - btrfs: fix segmentation fault when doing dio read (bsc#1040425). - btrfs: Fix slab accounting flags (bsc#1012452). - btrfs: fix truncate_space_check (bsc#1012452). - btrfs: fix unexpected return value of fiemap (bsc#1012452). - btrfs: fix unprotected assignment of the left cursor for device replace (bsc#1012452). - btrfs: fix WARNING in btrfs_select_ref_head() (bsc#1012452). - btrfs: flush_space: treat return value of do_chunk_alloc properly (bsc#1012452). - btrfs: Force stripesize to the value of sectorsize (bsc#1012452). - btrfs: free sys_array eb as soon as possible (bsc#1012452). - btrfs: GFP_NOFS does not GFP_HIGHMEM (bsc#1012452). - btrfs: Handle uninitialised inode eviction (bsc#1012452). - btrfs: hide test-only member under ifdef (bsc#1012452). - btrfs: improve check_node to avoid reading corrupted nodes (bsc#1012452). - btrfs: Improve FL_KEEP_SIZE handling in fallocate (bsc#1012452). - btrfs: incremental send, do not delay rename when parent inode is new (bsc#1028325). - btrfs: incremental send, do not issue invalid rmdir operations (bsc#1028325). - btrfs: introduce BTRFS_MAX_ITEM_SIZE (bsc#1012452). - btrfs: introduce device delete by devid (bsc#1012452). - btrfs: introduce raid-type to error-code table, for minimum device constraint (bsc#1012452). - btrfs: introduce ticketed enospc infrastructure (bsc#1012452). - btrfs: introduce tickets_id to determine whether asynchronous metadata reclaim work makes progress (bsc#1012452). - btrfs: ioctl: reorder exclusive op check in RM_DEV (bsc#1012452). - btrfs: kill BUG_ON in do_relocation (bsc#1012452). - btrfs: kill BUG_ON in run_delayed_tree_ref (bsc#1012452). - btrfs: kill BUG_ON()'s in btrfs_mark_extent_written (bsc#1012452). - btrfs: kill invalid ASSERT() in process_all_refs() (bsc#1012452). - btrfs: kill the start argument to read_extent_buffer_pages (bsc#1012452). - btrfs: kill unused writepage_io_hook callback (bsc#1012452). - btrfs: let callers of btrfs_alloc_root pass gfp flags (bsc#1012452). - btrfs: Limit inline extents to root->sectorsize (bsc#1012452). - btrfs: make find_workspace always succeed (bsc#1012452). - btrfs: make find_workspace warn if there are no workspaces (bsc#1012452). - btrfs: make mapping->writeback_index point to the last written page (bsc#1012452). - btrfs: make state preallocation more speculative in __set_extent_bit (bsc#1012452). - btrfs: make sure device is synced before return (bsc#1012452). - btrfs: make sure we stay inside the bvec during __btrfs_lookup_bio_sums (bsc#1012452). - btrfs: make use of btrfs_find_device_by_user_input() (bsc#1012452). - btrfs: make use of btrfs_scratch_superblocks() in btrfs_rm_device() (bsc#1012452). - btrfs: memset to avoid stale content in btree leaf (bsc#1012452). - btrfs: memset to avoid stale content in btree node block (bsc#1012452). - btrfs: move error handling code together in ctree.h (bsc#1012452). - btrfs: optimize check for stale device (bsc#1012452). - btrfs: Output more info for enospc_debug mount option (bsc#1012452). - btrfs: parent_start initialization cleanup (bsc#1012452). - btrfs: pass correct args to btrfs_async_run_delayed_refs() (bsc#1012452). - btrfs: pass number of devices to btrfs_check_raid_min_devices (bsc#1012452). - btrfs: pass the right error code to the btrfs_std_error (bsc#1012452). - btrfs: pin log earlier when renaming (bsc#1020975). - btrfs: pin logs earlier when doing a rename exchange operation (bsc#1020975). - btrfs: preallocate compression workspaces (bsc#1012452). - btrfs: Print Warning only if ENOSPC_DEBUG is enabled (bsc#1012452). - btrfs: qgroup: Move half of the qgroup accounting time out of commit trans (bsc#1017461). - btrfs: qgroups: Retry after commit on getting EDQUOT (bsc#1019614). - btrfs: Ratelimit "no csum found" info message (bsc#1012452). - btrfs: reada: add all reachable mirrors into reada device list (bsc#1012452). - btrfs: reada: Add missed segment checking in reada_find_zone (bsc#1012452). - btrfs: reada: Avoid many times of empty loop (bsc#1012452). - btrfs: reada: avoid undone reada extents in btrfs_reada_wait (bsc#1012452). - btrfs: reada: bypass adding extent when all zone failed (bsc#1012452). - btrfs: reada: Fix a debug code typo (bsc#1012452). - btrfs: reada: Fix in-segment calculation for reada (bsc#1012452). - btrfs: reada: ignore creating reada_extent for a non-existent device (bsc#1012452). - btrfs: reada: Jump into cleanup in direct way for __readahead_hook() (bsc#1012452). - btrfs: reada: limit max works count (bsc#1012452). - btrfs: reada: Move is_need_to_readahead contition earlier (bsc#1012452). - btrfs: reada: move reada_extent_put to place after __readahead_hook() (bsc#1012452). - btrfs: reada: Pass reada_extent into __readahead_hook directly (bsc#1012452). - btrfs: reada: reduce additional fs_info->reada_lock in reada_find_zone (bsc#1012452). - btrfs: reada: Remove level argument in severial functions (bsc#1012452). - btrfs: reada: simplify dev->reada_in_flight processing (bsc#1012452). - btrfs: reada: Use fs_info instead of root in __readahead_hook's argument (bsc#1012452). - btrfs: reada: use GFP_KERNEL everywhere (bsc#1012452). - btrfs: readdir: use GFP_KERNEL (bsc#1012452). - btrfs: refactor btrfs_dev_replace_start for reuse (bsc#1012452). - btrfs: Refactor btrfs_lock_cluster() to kill compiler warning (bsc#1012452). - btrfs: remove BUG() in raid56 (bsc#1012452). - btrfs: remove BUG_ON in start_transaction (bsc#1012452). - btrfs: remove BUG_ON()'s in btrfs_map_block (bsc#1012452). - btrfs: remove build fixup for qgroup_account_snapshot (bsc#1012452). - btrfs: remove redundant error check (bsc#1012452). - btrfs: remove save_error_info() (bsc#1012452). - btrfs: remove unnecessary btrfs_mark_buffer_dirty in split_leaf (bsc#1012452). - btrfs: remove unused function btrfs_assert() (bsc#1012452). - btrfs: rename and document compression workspace members (bsc#1012452). - btrfs: rename btrfs_find_device_by_user_input (bsc#1012452). - btrfs: rename btrfs_std_error to btrfs_handle_fs_error (bsc#1012452). - btrfs: rename __check_raid_min_devices (bsc#1012452). - btrfs: rename flags for vol args v2 (bsc#1012452). - btrfs: reorg btrfs_close_one_device() (bsc#1012452). - btrfs: Replace -ENOENT by -ERANGE in btrfs_get_acl() (bsc#1012452). - btrfs: Reset IO error counters before start of device replacing (bsc#1012452). - btrfs: reuse existing variable in scrub_stripe, reduce stack usage (bsc#1012452). - btrfs: s_bdev is not null after missing replace (bsc#1012452). - btrfs: scrub: Set bbio to NULL before calling btrfs_map_block (bsc#1012452). - btrfs: scrub: use GFP_KERNEL on the submission path (bsc#1012452). - btrfs: Search for all ordered extents that could span across a page (bsc#1012452). - btrfs: send, fix failure to rename top level inode due to name collision (bsc#1028325). - btrfs: send: silence an integer overflow warning (bsc#1012452). - btrfs: send: use GFP_KERNEL everywhere (bsc#1012452). - btrfs: send: use temporary variable to store allocation size (bsc#1012452). - btrfs: send: use vmalloc only as fallback for clone_roots (bsc#1012452). - btrfs: send: use vmalloc only as fallback for clone_sources_tmp (bsc#1012452). - btrfs: send: use vmalloc only as fallback for read_buf (bsc#1012452). - btrfs: send: use vmalloc only as fallback for send_buf (bsc#1012452). - btrfs: serialize subvolume mounts with potentially mismatching rw flags (bsc#951844 bsc#1024015) - btrfs: Simplify conditions about compress while mapping btrfs flags to inode flags (bsc#1012452). - btrfs: sink gfp parameter to clear_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to clear_extent_dirty (bsc#1012452). - btrfs: sink gfp parameter to clear_record_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to convert_extent_bit (bsc#1012452). - btrfs: sink gfp parameter to set_extent_bits (bsc#1012452). - btrfs: sink gfp parameter to set_extent_defrag (bsc#1012452). - btrfs: sink gfp parameter to set_extent_delalloc (bsc#1012452). - btrfs: sink gfp parameter to set_extent_new (bsc#1012452). - btrfs: sink gfp parameter to set_record_extent_bits (bsc#1012452). - btrfs: skip commit transaction if we do not have enough pinned bytes (bsc#1037186). - btrfs: subpage-blocksize: Rate limit scrub error message (bsc#1012452). - btrfs: switch to common message helpers in open_ctree, adjust messages (bsc#1012452). - btrfs: switch to kcalloc in btrfs_cmp_data_prepare (bsc#1012452). - btrfs: sysfs: protect reading label by lock (bsc#1012452). - btrfs: test_check_exists: Fix infinite loop when searching for free space entries (bsc#987192). - btrfs: trace pinned extents (bsc#1012452). - btrfs: track transid for delayed ref flushing (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, document subvol flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move balance flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move BTRFS_LABEL_SIZE (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move feature flags (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, move struct btrfs_ioctl_defrag_range_args (bsc#1012452). - btrfs: uapi/linux/btrfs.h migration, qgroup limit flags (bsc#1012452). - btrfs: uapi/linux/btrfs_tree.h migration, item types and defines (bsc#1012452). - btrfs: uapi/linux/btrfs_tree.h, use __u8 and __u64 (bsc#1012452). - btrfs: unpin log if rename operation fails (bsc#1020975). - btrfs: unpin logs if rename exchange operation fails (bsc#1020975). - btrfs: unsplit printed strings (bsc#1012452). - btrfs: untangle gotos a bit in __clear_extent_bit (bsc#1012452). - btrfs: untangle gotos a bit in convert_extent_bit (bsc#1012452). - btrfs: untangle gotos a bit in __set_extent_bit (bsc#1012452). - btrfs: update btrfs_space_info's bytes_may_use timely (bsc#1012452). - btrfs: Use correct format specifier (bsc#1012452). - btrfs: use correct offset for reloc_inode in prealloc_file_extent_cluster() (bsc#1012452). - btrfs: use dynamic allocation for root item in create_subvol (bsc#1012452). - btrfs: Use (eb->start, seq) as search key for tree modification log (bsc#1012452). - btrfs: use existing device constraints table btrfs_raid_array (bsc#1012452). - btrfs: use FLUSH_LIMIT for relocation in reserve_metadata_bytes (bsc#1012452). - btrfs: use fs_info directly (bsc#1012452). - btrfs: use new error message helper in qgroup_account_snapshot (bsc#1012452). - btrfs: use proper type for failrec in extent_state (bsc#1012452). - btrfs: use root when checking need_async_flush (bsc#1012452). - btrfs: use the correct struct for BTRFS_IOC_LOGICAL_INO (bsc#1012452). - btrfs: Use __u64 in exported linux/btrfs.h (bsc#1012452). - btrfs: warn_on for unaccounted spaces (bsc#1012452). - ceph: check i_nlink while converting a file handle to dentry (bsc#1039864). - ceph: Check that the new inode size is within limits in ceph_fallocate() (bsc#1037969). - ceph: Correctly return NXIO errors from ceph_llseek (git-fixes). - ceph: fix bad endianness handling in parse_reply_info_extra (bsc#1020488). - ceph: fix file open flags on ppc64 (bsc#1022266). - ceph: fix memory leak in __ceph_setxattr() (bsc#1036763). - ceph: fix potential use-after-free (bsc#1043371). - ceph: fix recursively call between ceph_set_acl and __ceph_setattr (bsc#1034902). - ceph: memory leak in ceph_direct_read_write callback (bsc#1041810). - cfq-iosched: fix the delay of cfq_group's vdisktime under iops mode (bsc#1012829). - cgroup/pids: remove spurious suspicious RCU usage warning (bnc#1031831). - cgroup: remove redundant cleanup in css_create (bsc#1012829). - cifs: backport prepath matching fix (bsc#799133). - cifs: small underflow in cnvrtDosUnixTm() (bnc#1043935). - clk: Make x86/ conditional on CONFIG_COMMON_CLK (4.4.68 stable queue). - clk: xgene: Add PMD clock (bsc#1019351). - clk: xgene: Do not call __pa on ioremaped address (bsc#1019351). - clk: xgene: Remove CLK_IS_ROOT (bsc#1019351). - config: enable Ceph kernel client modules for ppc64le (fate#321098) - config: enable Ceph kernel client modules for s390x (fate#321098) - cpupower: Fix turbo frequency reporting for pre-Sandy Bridge cores (4.4.68 stable queue). - crypto: algif_aead - Require setkey before accept(2) (bsc#1031717). - crypto: algif_hash - avoid zero-sized array (bnc#1007962). - crypto: drbg - do not call drbg_instantiate in healt test (bsc#1018913). - crypto: drbg - remove FIPS 140-2 continuous test (bsc#1018913). - crypto: FIPS - allow tests to be disabled in FIPS mode (bsc#1018913). - crypto: qat - fix bar discovery for c62x (bsc#1021251). - crypto: qat - zero esram only for DH85x devices (1021248). - crypto: rsa - allow keys >= 2048 bits in FIPS mode (bsc#1018913). - crypto: sha-mb - Fix load failure (bsc#1037384). - crypto: xts - consolidate sanity check for keys (bsc#1018913). - crypto: xts - fix compile errors (bsc#1018913). - cxgb4: Add control net_device for configuring PCIe VF (bsc#1021424). - cxgb4: Add llseek operation for flash debugfs entry (bsc#1021424). - cxgb4: add new routine to get adapter info (bsc#1021424). - cxgb4: Add PCI device ID for new adapter (bsc#1021424). - cxgb4: Add port description for new cards (bsc#1021424). - cxgb4: Add support to enable logging of firmware mailbox commands (bsc#1021424). - cxgb4: Check for firmware errors in the mailbox command loop (bsc#1021424). - cxgb4: correct device ID of T6 adapter (bsc#1021424). - cxgb4/cxgb4vf: Add set VF mac address support (bsc#1021424). - cxgb4/cxgb4vf: Allocate more queues for 25G and 100G adapter (bsc#1021424). - cxgb4/cxgb4vf: Assign netdev->dev_port with port ID (bsc#1021424). - cxgb4/cxgb4vf: Display 25G and 100G link speed (bsc#1021424). - cxgb4/cxgb4vf: Remove deprecated module parameters (bsc#1021424). - cxgb4: DCB message handler needs to use correct portid to netdev mapping (bsc#1021424). - cxgb4: Decode link down reason code obtained from firmware (bsc#1021424). - cxgb4: Do not assume FW_PORT_CMD reply is always port info msg (bsc#1021424). - cxgb4: do not call napi_hash_del() (bsc#1021424). - cxgb4: Do not sleep when mbox cmd is issued from interrupt context (bsc#1021424). - cxgb4: Enable SR-IOV configuration via PCI sysfs interface (bsc#1021424). - cxgb4: Fix issue while re-registering VF mgmt netdev (bsc#1021424). - cxgb4: MU requested by Chelsio (bsc#1021424). - cxgb4: Properly decode port module type (bsc#1021424). - cxgb4: Refactor t4_port_init function (bsc#1021424). - cxgb4: Reset dcb state machine and tx queue prio only if dcb is enabled (bsc#1021424). - cxgb4: Support compressed error vector for T6 (bsc#1021424). - cxgb4: Synchronize access to mailbox (bsc#1021424). - cxgb4: update latest firmware version supported (bsc#1021424). - cxgb4vf: do not offload Rx checksums for IPv6 fragments (bsc#1026692). - dax: fix deadlock with DAX 4k holes (bsc#1012829). - dax: fix device-dax region base (bsc#1023175). - Delete previous two fixes for i915 (bsc#1019061). These upstream fixes brought some regressions, so better to revert for now. - dell-laptop: Adds support for keyboard backlight timeout AC settings (bsc#1013561). - device-dax: check devm_nsio_enable() return value (bsc#1023175). - device-dax: fail all private mapping attempts (bsc#1023175). - device-dax: fix percpu_ref_exit ordering (bsc#1023175). - device-dax: fix private mapping restriction, permit read-only (bsc#1031717). - Disable CONFIG_POWER_SUPPLY_DEBUG in debug kernel (bsc#1031500). - dmaengine: dw: fix typo in Kconfig (bsc#1031717). - dm: fix dm_target_io leak if clone_bio() returns an error (bsc#1040125). - dm-mpath: fix race window in do_end_io() (bsc#1011044). - dm round robin: do not use this_cpu_ptr() without having preemption disabled (bsc#1040125). - dm verity fec: fix block calculation (bsc#1040125). - dm verity fec: fix bufio leaks (bsc#1040125). - dm verity fec: limit error correction recursion (bsc#1040125). - drivers: base: dma-mapping: Fix typo in dmam_alloc_non_coherent comments (bsc#1031717). - drivers: hv: util: do not forget to init host_ts.lock (bsc#1031206). - drivers: hv: vmbus: finally fix hv_need_to_signal_on_read() (fate#320485, bug#1018385). - drivers: hv: vmbus: Prevent sending data on a rescinded channel (fate#320485, bug#1028217). - drivers: hv: vmbus: Raise retry/wait limits in vmbus_post_msg() (fate#320485, bsc#1023287, bsc#1028217). - drivers: net: phy: mdio-xgene: Add hardware dependency (bsc#1019351). - drivers: net: phy: xgene: Fix 'remove' function (bsc#1019351). - drivers: net: xgene: Add change_mtu function (bsc#1019351). - drivers: net: xgene: Add flow control configuration (bsc#1019351). - drivers: net: xgene: Add flow control initialization (bsc#1019351). - drivers: net: xgene: Add helper function (bsc#1019351). - drivers: net: xgene: Add support for Jumbo frame (bsc#1019351). - drivers: net: xgene: Configure classifier with pagepool (bsc#1019351). - drivers: net: xgene: fix build after change_mtu function change (bsc#1019351). - drivers: net: xgene: fix: Coalescing values for v2 hardware (bsc#1019351). - drivers: net: xgene: fix: Disable coalescing on v1 hardware (bsc#1019351). - drivers: net: xgene: Fix MSS programming (bsc#1019351). - drivers: net: xgene: fix: RSS for non-TCP/UDP (bsc#1019351). - drivers: net: xgene: fix: Use GPIO to get link status (bsc#1019351). - drivers: net: xgene: uninitialized variable in xgene_enet_free_pagepool() (bsc#1019351). - drivers/tty: 8250: only call fintek_8250_probe when doing port I/O (bsc#1031717). - drm: Fix broken VT switch with video=1366x768 option (bsc#1018358). - drm/i915: Add intel_uncore_suspend / resume functions (bsc#1011913). - drm/i915: Disable tv output on i9x5gm (bsc#1039700). - drm/i915: Do not init hpd polling for vlv and chv from runtime_suspend() (bsc#1014120). - drm/i915: Do not touch NULL sg on i915_gem_object_get_pages_gtt() error (bsc#1031717). - drm-i915-dp-Restore-PPS-HW-state-from-the-encoder-re - drm/i915/dp: Restore PPS HW state from the encoder resume hook (bsc#1019061). - drm/i915: Fix crash after S3 resume with DP MST mode change (bsc#1029634). - drm/i915: Fix mismatched INIT power domain disabling during suspend (bsc#1031717). - drm/i915: Fix watermarks for VLV/CHV (bsc#1011176). - drm/i915: Force VDD off on the new power seqeuencer before starting to use it (bsc#1009674). - drm/i915/gen9: Fix PCODE polling during CDCLK change notification (bsc#1015367). - drm/i915: Introduce Kabypoint PCH for Kabylake H/DT (bsc#1032581). - drm/i915: Listen for PMIC bus access notifications (bsc#1011913). - drm/i915: Mark CPU cache as dirty when used for rendering (bsc#1015367). - drm/i915: Mark i915_hpd_poll_init_work as static (bsc#1014120). - drm/i915: Nuke debug messages from the pipe update critical section (bsc#1031717). - drm/i915: Only enable hotplug interrupts if the display interrupts are enabled (bsc#1031717). - drm-i915-Prevent-PPS-stealing-from-a-normal-DP-port - drm/i915: Prevent PPS stealing from a normal DP port on VLV/CHV (bsc#1019061). - drm/i915: Program iboost settings for HDMI/DVI on SKL (bsc#1031717). - drm/i915: relax uncritical udelay_range() (bsc#1031717). - drm/i915: relax uncritical udelay_range() settings (bsc#1031717). - drm/i915: Use pagecache write to prepopulate shmemfs from pwrite-ioctl (bsc#1040463). - drm/i915/vlv: Prevent enabling hpd polling in late suspend (bsc#1014120). - drm/i915: Workaround for DP DPMS D3 on Dell monitor (bsc#1019061). - drm/mgag200: Added support for the new device G200eH3 (bsc#1007959, fate#322780) - drm/mgag200: Fix to always set HiPri for G200e4 (bsc#1015452, bsc#995542). - drm/nouveau/tmr: fully separate alarm execution/pending lists (bsc#1043467). - drm/ttm: fix use-after-free races in vm fault handling (4.4.68 stable queue). - drm/vc4: Fix an integer overflow in temporary allocation layout (bsc#1021294). - drm-vc4-Fix-an-integer-overflow-in-temporary-allocation-layout.patch - drm/vc4: Return -EINVAL on the overflow checks failing (bsc#1021294). - drm-vc4-Return-EINVAL-on-the-overflow-checks-failing.patch - drm: virtio-gpu: get the fb from the plane state for atomic updates (bsc#1023101). - e1000e: Do not return uninitialized stats (bug#1034635). - edac, xgene: Fix spelling mistake in error messages (bsc#1019351). - efi: Do not issue error message when booted under Xen (bnc#1036638). - enic: set skb->hash type properly (bsc#922871 fate#318754). - ext4: fix data corruption for mmap writes (bsc#1012829). - ext4: fix data corruption with EXT4_GET_BLOCKS_ZERO (bsc#1012829). - ext4: fix fencepost in s_first_meta_bg validation (bsc#1029986). - ext4: fix use-after-iput when fscrypt contexts are inconsistent (bsc#1012829). - f2fs: fix bad prefetchw of NULL page (bsc#1012829). - f2fs: sanity check segment count (4.4.68 stable queue). - Fix a regression reported by bsc#1020048 in patches.fixes/0003-md-lockless-I-O-submission-for-RAID1.patch (bsc#982783,bsc#998106,bsc#1020048). - fnic: Return 'DID_IMM_RETRY' if rport is not ready (bsc#1035920). - fs/block_dev: always invalidate cleancache in invalidate_bdev() (git-fixes). - fs: fix data invalidation in the cleancache during direct IO (git-fixes). - fs/xattr.c: zero out memory copied to userspace in getxattr (git-fixes). - ftrace: Make ftrace_location_range() global (FATE#322421). - fuse: fix clearing suid, sgid for chown() (bsc#1012829). - futex: Add missing error handling to FUTEX_REQUEUE_PI (bsc#969755). - futex: Fix potential use-after-free in FUTEX_REQUEUE_PI (bsc#969755). - gpio: xgene: make explicitly non-modular (bsc#1019351). - hid: usbhid: Quirk a AMI virtual mouse and keyboard with ALWAYS_POLL (bsc#1022340). - hv: do not reset hv_context.tsc_page on crash (fate#320485, bnc#1007729). - hv: export current Hyper-V clocksource (bsc#1031206). - hv_utils: implement Hyper-V PTP source (bsc#1031206). - i2c: designware-baytrail: Acquire P-Unit access on bus acquire (bsc#1011913). - i2c: designware-baytrail: Call pmic_bus_access_notifier_chain (bsc#1011913). - i2c: designware-baytrail: Fix race when resetting the semaphore (bsc#1011913). - i2c: designware-baytrail: Only check iosf_mbi_available() for shared hosts (bsc#1011913). - i2c: designware: Disable pm for PMIC i2c-bus even if there is no _SEM method (bsc#1011913). - i2c: designware: fix wrong Tx/Rx FIFO for ACPI (bsc#1019351). - i2c: designware: Implement support for SMBus block read and write (bsc#1019351). - i2c-designware: increase timeout (bsc#1011913). - i2c: designware: Never suspend i2c-busses used for accessing the system PMIC (bsc#1011913). - i2c: designware: Rename accessor_flags to flags (bsc#1011913). - i2c: xgene: Fix missing code of DTB support (bsc#1019351). - i40e: Be much more verbose about what we can and cannot offload (bsc#985561). - ib/addr: Fix setting source address in addr6_resolve() (bsc#1044082). - ib/core: Fix kernel crash during fail to initialize device (bsc#1022595 FATE#322350). - ib/core: For multicast functions, verify that LIDs are multicast LIDs (bsc#1022595 FATE#322350). - ib/core: If the MGID/MLID pair is not on the list return an error (bsc#1022595 FATE#322350). - ib/ipoib: Fix deadlock between ipoib_stop and mcast join flow (bsc#1022595 FATE#322350). - ib/mlx5: Assign DSCP for R-RoCE QPs Address Path (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Check supported flow table size (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Enlarge autogroup flow table (bsc#966170 bsc#966172 bsc#966191). - ib/mlx5: Fix kernel to user leak prevention logic (bsc#966170 bsc#966172 bsc#966191). - ibmveth: calculate gso_segs for large packets (bsc#1019148). - ibmveth: check return of skb_linearize in ibmveth_start_xmit (bsc#1019148). - ibmveth: consolidate kmalloc of array, memset 0 to kcalloc (bsc#1019148). - ibmveth: set correct gso_size and gso_type (bsc#1019148). - ibmvnic: Activate disabled RX buffer pools on reset (bsc#1044767). - ibmvnic: Add set_link_state routine for setting adapter link state (fate#322021, bsc#1031512). - ibmvnic: Allocate number of rx/tx buffers agreed on by firmware (fate#322021, bsc#1031512). - ibmvnic: Allocate zero-filled memory for sub crqs (fate#322021, bsc#1031512). - ibmvnic: Call napi_disable instead of napi_enable in failure path (fate#322021, bsc#1031512). - ibmvnic: Check adapter state during ibmvnic_poll (fate#322021, bsc#1040855). - ibmvnic: Check for driver reset first in ibmvnic_xmit (fate#322021, bsc#1038297). - ibmvnic: Cleanup failure path in ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Clean up tx pools when closing (fate#322021, bsc#1038297). - ibmvnic: Client-initiated failover (bsc#1043990). - ibmvnic: Continue skb processing after skb completion error (fate#322021, bsc#1038297). - ibmvnic: Correct crq and resource releasing (fate#322021, bsc#1031512). - ibmvnic: Correct ibmvnic handling of device open/close (fate#322021, bsc#1031512). - ibmvnic: Create init and release routines for the bounce buffer (fate#322021, bsc#1031512). - ibmvnic: Create init and release routines for the rx pool (fate#322021, bsc#1031512). - ibmvnic: Create init and release routines for the tx pool (fate#322021, bsc#1031512). - ibmvnic: Create init/release routines for stats token (fate#322021, bsc#1031512). - ibmvnic: Deactivate RX pool buffer replenishment on H_CLOSED (fate#322021, bsc#1040855). - ibmvnic: Delete napi's when releasing driver resources (fate#322021, bsc#1038297). - ibmvnic: Disable irq prior to close (fate#322021, bsc#1031512). - ibmvnic: Do not disable IRQ after scheduling tasklet (fate#322021, bsc#1031512). - ibmvnic: driver initialization for kdump/kexec (bsc#1044772). - ibmvnic: Ensure that TX queues are disabled in __ibmvnic_close (bsc#1044767). - ibmvnic: Exit polling routine correctly during adapter reset (bsc#1044767). - ibmvnic: Fix cleanup of SKB's on driver close (fate#322021, bsc#1040855). - ibmvnic: Fix endian errors in error reporting output (fate#322021, bsc#1031512). - ibmvnic: Fix endian error when requesting device capabilities (fate#322021, bsc#1031512). - ibmvnic: Fix ibmvnic_change_mac_addr struct format (fate#322021, bsc#1031512). - ibmvnic: Fix initial MTU settings (bsc#1031512). - ibmvnic: fix missing unlock on error in __ibmvnic_reset() (fate#322021, bsc#1038297, Fixes: ed651a10875f). - ibmvnic: Fix overflowing firmware/hardware TX queue (fate#322021, bsc#1031512). - ibmvnic: Fixup atomic API usage (fate#322021, bsc#1031512). - ibmvnic: Free skb's in cases of failure in transmit (fate#322021, bsc#1031512). - ibmvnic: Free tx/rx scrq pointer array when releasing sub-crqs (fate#322021, bsc#1031512). - ibmvnic: Halt TX and report carrier off on H_CLOSED return code (fate#322021, bsc#1040855). - ibmvnic: Handle failover after failed init crq (fate#322021, bsc#1040855). - ibmvnic: Handle processing of CRQ messages in a tasklet (fate#322021, bsc#1031512). - ibmvnic: Initialize completion variables before starting work (fate#322021, bsc#1031512). - ibmvnic: Insert header on VLAN tagged received frame (fate#322021, bsc#1031512). - ibmvnic: Make CRQ interrupt tasklet wait for all capabilities crqs (fate#322021, bsc#1031512). - ibmvnic: Merge the two release_sub_crq_queue routines (fate#322021, bsc#1031512). - ibmvnic: Move ibmvnic adapter intialization to its own routine (fate#322021, bsc#1031512). - ibmvnic: Move initialization of sub crqs to ibmvnic_init (fate#322021, bsc#1031512). - ibmvnic: Move initialization of the stats token to ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Move login and queue negotiation into ibmvnic_open (fate#322021, bsc#1031512). - ibmvnic: Move login to its own routine (fate#322021, bsc#1031512). - ibmvnic: Move queue restarting in ibmvnic_tx_complete (fate#322021, bsc#1038297). - ibmvnic: Move resource initialization to its own routine (fate#322021, bsc#1038297). - ibmvnic: Non-fatal error handling (fate#322021, bsc#1040855). - ibmvnic: Only retrieve error info if present (fate#322021, bsc#1031512). - ibmvnic: Record SKB RX queue during poll (fate#322021, bsc#1038297). - ibmvnic: Remove debugfs support (fate#322021, bsc#1031512). - ibmvnic: Remove inflight list (fate#322021, bsc#1031512). - ibmvnic: Remove netdev notify for failover resets (bsc#1044120). - ibmvnic: Remove unused bouce buffer (fate#322021, bsc#1031512). - ibmvnic: Remove VNIC_CLOSING check from pending_scrq (bsc#1044767). - ibmvnic: Replace is_closed with state field (fate#322021, bsc#1038297). - ibmvnic: Report errors when failing to release sub-crqs (fate#322021, bsc#1031512). - ibmvnic: Reset sub-crqs during driver reset (fate#322021, bsc#1040855). - ibmvnic: Reset the CRQ queue during driver reset (fate#322021, bsc#1040855). - ibmvnic: Reset tx/rx pools on driver reset (fate#322021, bsc#1040855). - ibmvnic: Return failure on attempted mtu change (bsc#1043236). - ibmvnic: Sanitize entire SCRQ buffer on reset (bsc#1044767). - ibmvnic: Send gratuitous arp on reset (fate#322021, bsc#1040855). - ibmvnic: Set real number of rx queues (fate#322021, bsc#1031512). - ibmvnic: Split initialization of scrqs to its own routine (fate#322021, bsc#1031512). - ibmvnic: Track state of adapter napis (fate#322021, bsc#1040855). - ibmvnic: Unmap longer term buffer before free (fate#322021, bsc#1031512). - ibmvnic: Updated reset handling (fate#322021, bsc#1038297). - ibmvnic: Update main crq initialization and release (fate#322021, bsc#1031512). - ibmvnic: Use common counter for capabilities checks (fate#322021, bsc#1031512). - ibmvnic: use max_mtu instead of req_mtu for MTU range check (bsc#1031512). - ibmvnic: Validate napi exist before disabling them (fate#322021, bsc#1031512). - ibmvnic: Wait for any pending scrqs entries at driver close (fate#322021, bsc#1038297). - ibmvnic: Whitespace correction in release_rx_pools (fate#322021, bsc#1038297). - iio: hid-sensor: Store restore poll and hysteresis on S3 (bsc#1031717). - infiniband: avoid dereferencing uninitialized dst on error path (git-fixes). - iommu/arm-smmu: Disable stalling faults for all endpoints (bsc#1038843). - iommu/dma: Respect IOMMU aperture when allocating (bsc#1038842). - iommu/exynos: Block SYSMMU while invalidating FLPD cache (bsc#1038848). - iommu: Handle default domain attach failure (bsc#1038846). - iommu/vt-d: Do not over-free page table directories (bsc#1038847). - iommu/vt-d: Make sure IOMMUs are off when intel_iommu=off (bsc#1031208). - ipv4, ipv6: ensure raw socket message is big enough to hold an IP header (4.4.68 stable queue). - ipv6: Do not use ufo handling on later transformed packets (bsc#1042286). - ipv6: fix endianness error in icmpv6_err (bsc#1042286). - ipv6: initialize route null entry in addrconf_init() (4.4.68 stable queue). - ipv6: release dst on error in ip6_dst_lookup_tail (git-fixes). - ipv6: reorder ip6_route_dev_notifier after ipv6_dev_notf (4.4.68 stable queue). - isa: Call isa_bus_init before dependent ISA bus drivers register (bsc#1031717). - iscsi-target: Return error if unable to add network portal (bsc#1032803). - iw_cxgb4: Guard against null cm_id in dump_ep/qp (bsc#1026570). - iwlwifi: Expose the default fallback ucode API to module info (boo#1021082, boo#1023884). - jump label: fix passing kbuild_cflags when checking for asm goto support (git-fixes). - kabi: Hide new include in arch/powerpc/kernel/process.c (fate#322421). - kABI: move and hide new cxgbi device owner field (bsc#1018885). - kABI: protect cgroup include in kernel/kthread (kabi). - kABI: protect struct fib_info (kabi). - kABI: protect struct iscsi_conn (kabi). - kABI: protect struct mnt_namespace (kabi). - kABI: protect struct musb_platform_ops (kabi). - kABI: protect struct pglist_data (kabi). - kABI: protect struct se_node_acl (kabi). - kABI: protect struct snd_fw_async_midi_port (kabi). - kABI: protect struct tcp_fastopen_cookie (kabi). - kABI: protect struct user_fpsimd_state (kabi). - kABI: protect struct wake_irq (kabi). - kABI: protect struct xhci_hcd (kabi). - kABI: protect struct xlog (bsc#1043598). - kABI: restore can_rx_register parameters (kabi). - kABI: restore ttm_ref_object_add parameters (kabi). - kABI workaround 4.4.65 adding #include to kernel/sysctl.c - kabi workaround for net: ipv6: Fix processing of RAs in presence of VRF (bsc#1042286). - kernel-binary.spec: Propagate MAKE_ARGS to %build (bsc#1012422) - kernel: Fix invalid domain response handling (bnc#1009718, LTC#149851). - kgraft/iscsi-target: Do not block kGraft in iscsi_np kthread (bsc#1010612, fate#313296). - kgraft/xen: Do not block kGraft in xenbus kthread (bsc#1017410, fate#313296). - kgr: Mark eeh_event_handler() kthread safe using a timeout (bsc#1031662). - kgr/module: make a taint flag module-specific (fate#313296). - kgr: remove all arch-specific kgraft header files (fate#313296). - kprobes/x86: Fix kernel panic when certain exception-handling addresses are probed (4.4.68 stable queue). - kvm: better MWAIT emulation for guests (bsc#1031142). - kvm: nVMX: do not leak PML full vmexit to L1 (4.4.68 stable queue). - kvm: nVMX: initialize PML fields in vmcs02 (4.4.68 stable queue). - kvm: svm: add support for RDTSCP (bsc#1033117). - l2tp: fix address test in __l2tp_ip6_bind_lookup() (bsc#1028415). - l2tp: fix lookup for sockets not bound to a device in l2tp_ip (bsc#1028415). - l2tp: fix race in l2tp_recv_common() (bsc#1042286). - l2tp: fix racy socket lookup in l2tp_ip and l2tp_ip6 bind() (bsc#1028415). - l2tp: hold socket before dropping lock in l2tp_ip{, 6}_recv() (bsc#1028415). - l2tp: hold tunnel socket when handling control frames in l2tp_ip and l2tp_ip6 (bsc#1028415). - l2tp: lock socket before checking flags in connect() (bsc#1028415). - leds: ktd2692: avoid harmless maybe-uninitialized warning (4.4.68 stable queue). - libata-scsi: Fixup ata_gen_passthru_sense() (bsc#1040125). - libceph: NULL deref on crush_decode() error path (bsc#1044015). - libcxgb: add library module for Chelsio drivers (bsc#1021424). - lib/mpi: mpi_read_raw_data(): fix nbits calculation (bsc#1003581). - lib/mpi: mpi_read_raw_data(): purge redundant clearing of nbits (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): do not include leading zero SGEs in nbytes (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): fix nbits calculation (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): fix out-of-bounds buffer access (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): purge redundant clearing of nbits (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): replace len argument by nbytes (bsc#1003581). - lib/mpi: mpi_read_raw_from_sgl(): sanitize meaning of indices (bsc#1003581). - libnvdimm, pfn: fix align attribute (bsc#1023175). - libnvdimm, pfn: fix memmap reservation size versus 4K alignment (bsc#1031717). - libnvdimm, pfn: fix 'npfns' vs section alignment (bsc#1040125). - livepatch: Allow architectures to specify an alternate ftrace location (FATE#322421). - locking/semaphore: Add down_interruptible_timeout() (bsc#1031662). - locking/ww_mutex: Fix compilation of __WW_MUTEX_INITIALIZER (bsc#1031717). - lpfc: remove incorrect lockdep assertion (bsc#1040125). - mailbox: xgene-slimpro: Fix wrong test for devm_kzalloc (bsc#1019351). - md: allow creation of mdNNN arrays via md_mod/parameters/new_array (bsc#1032339). - md.c:didn't unlock the mddev before return EINVAL in array_size_store (bsc#1038143). - md-cluster: convert the completion to wait queue (fate#316335). - md-cluster: fix potential lock issue in add_new_disk (bsc#1041087). - md-cluster: protect md_find_rdev_nr_rcu with rcu lock (fate#316335). - md: ensure md devices are freed before module is unloaded (bsc#1022304). - md: fix refcount problem on mddev when stopping array (bsc#1022304). - md: handle read-only member devices better (bsc#1033281). - md linear: fix a race between linear_add() and linear_congested() (bsc#1018446). - md: MD_CLOSING needs to be cleared after called md_set_readonly or do_md_stop (bsc#1038142). - md/raid1: add rcu protection to rdev in fix_read_error (References: bsc#998106,bsc#1020048,bsc#982783). - md/raid1: avoid reusing a resync bio after error handling (Fate#311379). - md/raid1: fix a use-after-free bug (bsc#998106,bsc#1020048,bsc#982783). - md/raid1: handle flush request correctly (bsc#998106,bsc#1020048,bsc#982783). - md/raid1: Refactor raid1_make_request (bsc#998106,bsc#1020048,bsc#982783). - md: support disabling of create-on-open semantics (bsc#1032339). - media: am437x-vpfe: fix an uninitialized variable bug (bsc#1031717). - media: b2c2: use IS_REACHABLE() instead of open-coding it (bsc#1031717). - media: c8sectpfe: Rework firmware loading mechanism (bsc#1031717). - media: cx231xx-audio: fix NULL-deref at probe (bsc#1031717). - media: cx231xx-cards: fix NULL-deref at probe (bsc#1031717). - media: cx23885: uninitialized variable in cx23885_av_work_handler() (bsc#1031717). - media: DaVinci-VPBE: Check return value of a setup_if_config() call in vpbe_set_output() (bsc#1031717). - media: DaVinci-VPFE-Capture: fix error handling (bsc#1031717). - media: dib0700: fix NULL-deref at probe (bsc#1031717). - media: dvb-usb: avoid link error with dib3000m{b,c| (bsc#1031717). - media: exynos4-is: fix a format string bug (bsc#1031717). - media: gspca: konica: add missing endpoint sanity check (bsc#1031717). - media: lirc_imon: do not leave imon_probe() with mutex held (bsc#1031717). - media: pvrusb2: reduce stack usage pvr2_eeprom_analyze() (bsc#1031717). - media: rc: allow rc modules to be loaded if rc-main is not a module (bsc#1031717). - media: s5p-mfc: Fix unbalanced call to clock management (bsc#1031717). - media: sh-vou: clarify videobuf2 dependency (bsc#1031717). - media: staging: media: davinci_vpfe: unlock on error in vpfe_reqbufs() (bsc#1031717). - media: usbvision: fix NULL-deref at probe (bsc#1031717). - media: uvcvideo: Fix empty packet statistic (bsc#1031717). - media: uvcvideo: uvc_scan_fallback() for webcams with broken chain (bsc#1021474). - media: vb2: Fix an off by one error in 'vb2_plane_vaddr' (bsc#1043231). - mem-hotplug: fix node spanned pages when we have a movable node (bnc#1034671). - mips: R2-on-R6 MULTU/MADDU/MSUBU emulation bugfix (4.4.68 stable queue). - mlx4: Fix memory leak after mlx4_en_update_priv() (bsc#966170 bsc#966172 bsc#966191). - mmc: debugfs: correct wrong voltage value (bsc#1031717). - mmc: Downgrade error level (bsc#1042536). - mm,compaction: serialize waitqueue_active() checks (bsc#971975). - mmc: sdhci-of-arasan: Remove no-hispd and no-cmd23 quirks for sdhci-arasan4.9a (bsc#1019351). - mmc: sdhci-pxav3: fix higher speed mode capabilities (bsc#1031717). - mmc: sdhci: restore behavior when setting VDD via external regulator (bsc#1031717). - mm: fix stray kernel-doc notation (bnc#971975 VM -- git fixes). - mm: fix set pageblock migratetype in deferred struct page init (bnc#1027195). - mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp (bnc#1030118). - mm/hugetlb: check for reserved hugepages during memory offline (bnc#971975 VM -- git fixes). - mm/hugetlb: fix incorrect hugepages count during mem hotplug (bnc#971975 VM -- git fixes). - mm/memblock.c: fix memblock_next_valid_pfn() (bnc#1031200). - mm, memcg: do not retry precharge charges (bnc#1022559). - mm, page_alloc: fix check for NULL preferred_zone (bnc#971975 VM performance -- page allocator). - mm, page_alloc: fix fast-path race with cpuset update or removal (bnc#971975 VM performance -- page allocator). - mm, page_alloc: fix premature OOM when racing with cpuset mems update (bnc#971975 VM performance -- page allocator). - mm, page_alloc: keep pcp count and list contents in sync if struct page is corrupted (bnc#971975 VM performance -- page allocator). - mm, page_alloc: move cpuset seqcount checking to slowpath (bnc#971975 VM performance -- page allocator). - mm/page_alloc: Remove useless parameter of __free_pages_boot_core (bnc#1027195). - mm: page_alloc: skip over regions of invalid pfns where possible (bnc#1031200). - module: fix memory leak on early load_module() failures (bsc#1043014). - module: move add_taint_module() to a header file (fate#313296). - mountproto.patch: Add commit id - mwifiex: add missing check for PCIe8997 chipset (bsc#1018813). - mwifiex: Avoid skipping WEP key deletion for AP (4.4.68 stable queue). - mwifiex: debugfs: Fix (sometimes) off-by-1 SSID print (4.4.68 stable queue). - mwifiex: fix IBSS data path issue (bsc#1018813). - mwifiex: fix PCIe register information for 8997 chipset (bsc#1018813). - mwifiex: pcie: fix cmd_buf use-after-free in remove/reset (bsc#1031717). - mwifiex: Removed unused 'pkt_type' variable (bsc#1031717). - mwifiex: remove redundant dma padding in AMSDU (4.4.68 stable queue). - mwifiex: Remove unused 'bcd_usb' variable (bsc#1031717). - mwifiex: Remove unused 'chan_num' variable (bsc#1031717). - mwifiex: Remove unused 'pm_flag' variable (bsc#1031717). - mwifiex: Remove unused 'sta_ptr' variable (bsc#1031717). - net/af_iucv: do not use paged skbs for TX on HiperSockets (bnc#1020945, LTC#150566). - net: bridge: start hello timer only if device is up (bnc#1012382). - net/ena: change condition for host attribute configuration (bsc#1026509). - net/ena: change driver's default timeouts (bsc#1026509). - net: ena: change the return type of ena_set_push_mode() to be void (bsc#1026509). - net: ena: Fix error return code in ena_device_init() (bsc#1026509). - net/ena: fix ethtool RSS flow configuration (bsc#1026509). - net/ena: fix NULL dereference when removing the driver after device reset failed (bsc#1026509). - net/ena: fix potential access to freed memory during device reset (bsc#1026509). - net/ena: fix queues number calculation (bsc#1026509). - net/ena: fix RSS default hash configuration (bsc#1026509). - net/ena: reduce the severity of ena printouts (bsc#1026509). - net/ena: refactor ena_get_stats64 to be atomic context safe (bsc#1026509). - net/ena: remove ntuple filter support from device feature list (bsc#1026509). - net: ena: remove superfluous check in ena_remove() (bsc#1026509). - net: ena: Remove unnecessary pci_set_drvdata() (bsc#1026509). - net/ena: update driver version to 1.1.2 (bsc#1026509). - net/ena: use READ_ONCE to access completion descriptors (bsc#1026509). - net: ena: use setup_timer() and mod_timer() (bsc#1026509). - net: ethernet: apm: xgene: use phydev from struct net_device (bsc#1019351). - net: ethtool: Initialize buffer when querying device channel settings (bsc#969479 FATE#320634). - netfilter: allow logging from non-init namespaces (bsc#970083). - netfilter: nf_conntrack_sip: extend request line validation (bsc#1042286). - netfilter: nf_ct_expect: remove the redundant slash when policy name is empty (bsc#1042286). - netfilter: nf_dup_ipv6: set again FLOWI_FLAG_KNOWN_NH at flowi6_flags (bsc#1042286). - netfilter: nf_nat_snmp: Fix panic when snmp_trap_helper fails to register (bsc#1042286). - netfilter: nfnetlink_queue: reject verdict request from different portid (bsc#1042286). - netfilter: restart search if moved to other chain (bsc#1042286). - netfilter: use fwmark_reflect in nf_send_reset (bsc#1042286). - net: fix compile error in skb_orphan_partial() (bnc#1012382). - net: ibmvnic: Remove unused net_stats member from struct ibmvnic_adapter (fate#322021, bsc#1031512). - net: icmp_route_lookup should use rt dev to determine L3 domain (bsc#1042286). - net: implement netif_cond_dbg macro (bsc#1019168). - net: ipv6: Fix processing of RAs in presence of VRF (bsc#1042286). - net: ipv6: set route type for anycast routes (bsc#1042286). - net: l3mdev: Add master device lookup by index (bsc#1042286). - net: make netdev_for_each_lower_dev safe for device removal (bsc#1042286). - net/mlx4_core: Avoid command timeouts during VF driver device shutdown (bsc#1028017). - net/mlx4_core: Avoid delays during VF driver device shutdown (bsc#1028017). - net/mlx4_core: Fix racy CQ (Completion Queue) free (bsc#1028017). - net/mlx4_core: Fix when to save some qp context flags for dynamic VST to VGT transitions (bsc#1028017). - net/mlx4_core: Use cq quota in SRIOV when creating completion EQs (bsc#1028017). - net/mlx4_en: Fix bad WQE issue (bsc#1028017). - net/mlx5: Do not unlock fte while still using it (bsc#966170 bsc#966172 bsc#966191). - net/mlx5e: Modify TIRs hash only when it's needed (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Fix create autogroup prev initializer (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Prevent setting multicast macs for VFs (bsc#966170 bsc#966172 bsc#966191). - net/mlx5: Release FTE lock in error flow (bsc#966170 bsc#966172 bsc#966191). - net: remove useless memset's in drivers get_stats64 (bsc#1019351). - net: vrf: Create FIB tables on link create (bsc#1042286). - net: vrf: Fix crash when IPv6 is disabled at boot time (bsc#1042286). - net: vrf: Fix dev refcnt leak due to IPv6 prefix route (bsc#1042286). - net: vrf: Fix dst reference counting (bsc#1042286). - net: vrf: protect changes to private data with rcu (bsc#1042286). - net: vrf: Switch dst dev to loopback on device delete (bsc#1042286). - netvsc: add rcu_read locking to netvsc callback (fate#320485). - netxen_nic: set rcode to the return status from the call to netxen_issue_cmd (bsc#966339 FATE#320150). - net: xgene: avoid bogus maybe-uninitialized warning (bsc#1019351). - net: xgene: fix backward compatibility fix (bsc#1019351). - net/xgene: fix error handling during reset (bsc#1019351). - net: xgene: move xgene_cle_ptree_ewdn data off stack (bsc#1019351). - nfit: fail DSMs that return non-zero status by default (bsc#1023175). - nfsd4: minor NFSv2/v3 write decoding cleanup (bsc#1034670). - nfsd: check for oversized NFSv2/v3 arguments (bsc#1034670). - nfs: do not try to cross a mountpount when there isn't one there (bsc#1028041). - nfsd: stricter decoding of write-like NFSv2/v3 ops (bsc#1034670). - nfs: Fix an LOCK/OPEN race when unlinking an open file (git-fixes). - nfs: Fix "Do not increment lock sequence ID after NFS4ERR_MOVED" (git-fixes). - nfs: Fix inode corruption in nfs_prime_dcache() (git-fixes). - nfs: Fix missing pg_cleanup after nfs_pageio_cond_complete() (git-fixes). - nfs: Fix NFS4 nfs4_do_reclaim() might_sleep()/scheduling while atomic splats. Bug exists in all RT trees >= v3.16, was spotted/fixed in v4.8-rt, but with no stable-rt backport. Pick it up. - nfs: flush out dirty data on file fput() (bsc#1021762). - nfs: Use GFP_NOIO for two allocations in writeback (git-fixes). - nfsv4.1: Fix Oopsable condition in server callback races (git-fixes). - nfsv4: fix a reference leak caused WARNING messages (git-fixes). - nfsv4: Fix the underestimation of delegation XDR space reservation (git-fixes). - nsfs: mark dentry with DCACHE_RCUACCESS (bsc#1012829). - nvdimm: kabi protect nd_cmd_out_size() (bsc#1023175). - nvme: apply DELAY_BEFORE_CHK_RDY quirk at probe time too (bsc#1020685). - nvme: Delete created IO queues on reset (bsc#1031717). - nvme: Do not suspend admin queue that wasn't created (bsc#1026505). - nvme: submit nvme_admin_activate_fw to admin queue (bsc#1044532). - nvme: Suspend all queues before deletion (bsc#1026505). - ocfs2/dlmglue: prepare tracking logic to avoid recursive cluster lock (bsc#1004003). - ocfs2: fix deadlock issue when taking inode lock at vfs entry points (bsc#1004003). - overlayfs: compat, fix incorrect dentry use in ovl_rename2 (bsc#1032400). - overlayfs: compat, use correct dentry to detect compat mode in ovl_compat_is_whiteout (bsc#1032400). - pci: Add devm_request_pci_bus_resources() (bsc#1019351). - pci/AER: include header file (bsc#964944,FATE#319965). - pci: generic: Fix pci_remap_iospace() failure path (bsc#1019630). - pci: hv: Fix wslot_to_devfn() to fix warnings on device removal (fate#320485, bug#1028217). - pci: hv: Use device serial number as PCI domain (fate#320485, bug#1028217). - pci: pciehp: Prioritize data-link event over presence detect (bsc#1031040,bsc#1037483). - pci: Reverse standard ACS vs device-specific ACS enabling (bsc#1030057). - pci: Work around Intel Sunrise Point PCH incorrect ACS capability (bsc#1030057). - pci: xgene: Add local struct device pointers (bsc#1019351). - pci: xgene: Add register accessors (bsc#1019351). - pci: xgene: Free bridge resource list on failure (bsc#1019351). - pci: xgene: Make explicitly non-modular (bsc#1019351). - pci: xgene: Pass struct xgene_pcie_port to setup functions (bsc#1019351). - pci: xgene: Remove unused platform data (bsc#1019351). - pci: xgene: Request host bridge window resources (bsc#1019351). - percpu: remove unused chunk_alloc parameter from pcpu_get_pages() (bnc#971975 VM -- git fixes). - perf/x86/intel/rapl: Make Knights Landings support functional (bsc#1042517). - perf/x86/intel/uncore: Remove SBOX support for Broadwell server (bsc#1035887). - perf: xgene: Remove bogus IS_ERR() check (bsc#1019351). - phy: qcom-usb-hs: Add depends on EXTCON (4.4.68 stable queue). - phy: xgene: rename "enum phy_mode" to "enum xgene_phy_mode" (bsc#1019351). - pid_ns: Sleep in TASK_INTERRUPTIBLE in zap_pid_ns_processes (bnc#1012985). - ping: implement proper locking (bsc#1031003). - pkcs#7: fix missing break on OID_sha224 case (bsc#1031717). - platform/x86: fujitsu-laptop: use brightness_set_blocking for LED-setting callbacks (bsc#1031717). - pm / QoS: Fix memory leak on resume_latency.notifiers (bsc#1043231). - pm / wakeirq: Enable dedicated wakeirq for suspend (bsc#1031717). - pm / wakeirq: Fix spurious wake-up events for dedicated wakeirqs (bsc#1031717). - pm / wakeirq: report a wakeup_event on dedicated wekup irq (bsc#1031717). - power: bq27xxx: fix register numbers of bq27500 (bsc#1031717). - powerpc/64: Fix flush_(d|i)cache_range() called from modules (bnc#863764 fate#315275, LTC#103998). - powerpc: Blacklist GCC 5.4 6.1 and 6.2 (boo#1028895). - powerpc: Create a helper for getting the kernel toc value (FATE#322421). - powerpc/fadump: Fix the race in crash_fadump() (bsc#1022971). - powerpc/fadump: Reserve memory at an offset closer to bottom of RAM (bsc#1032141). - powerpc/fadump: Update fadump documentation (bsc#1032141). - powerpc/ftrace: Add Kconfig & Make glue for mprofile-kernel (FATE#322421). - powerpc/ftrace: Add support for -mprofile-kernel ftrace ABI (FATE#322421). - powerpc/ftrace: Use $(CC_FLAGS_FTRACE) when disabling ftrace (FATE#322421). - powerpc/ftrace: Use generic ftrace_modify_all_code() (FATE#322421). - powerpc: introduce TIF_KGR_IN_PROGRESS thread flag (FATE#322421). - powerpc/livepatch: Add livepatch header (FATE#322421). - powerpc/livepatch: Add live patching support on ppc64le (FATE#322421). - powerpc/livepatch: Add livepatch stack to struct thread_info (FATE#322421). - powerpc/module: Create a special stub for ftrace_caller() (FATE#322421). - powerpc/module: Mark module stubs with a magic value (FATE#322421). - powerpc/module: Only try to generate the ftrace_caller() stub once (FATE#322421). - powerpc/modules: Never restore r2 for a mprofile-kernel style mcount() call (FATE#322421). - powerpc/powernv: Fix opal_exit tracepoint opcode (4.4.68 stable queue). - power: reset: xgene-reboot: Unmap region obtained by of_iomap (bsc#1019351). - power: supply: bq24190_charger: Call power_supply_changed() for relevant component (4.4.68 stable queue). - power: supply: bq24190_charger: Call set_mode_host() on pm_resume() (4.4.68 stable queue). - power: supply: bq24190_charger: Do not read fault register outside irq_handle_thread() (4.4.68 stable queue). - power: supply: bq24190_charger: Fix irq trigger to IRQF_TRIGGER_FALLING (4.4.68 stable queue). - power: supply: bq24190_charger: Handle fault before status on interrupt (4.4.68 stable queue). - power: supply: bq24190_charger: Install irq_handler_thread() at end of probe() (4.4.68 stable queue). - printk: Switch to the sync mode when an emergency message is printed (bsc#1034995). - qeth: check not more than 16 SBALEs on the completion queue (bnc#1009718, LTC#148203). - quota: fill in Q_XGETQSTAT inode information for inactive quotas (bsc#1042356). - radix-tree: fix radix_tree_iter_retry() for tagged iterators (bsc#1012829). - raid1: a new I/O barrier implementation to remove resync window (bsc#998106,bsc#1020048,bsc#982783). - raid1: avoid unnecessary spin locks in I/O barrier code (bsc#998106,bsc#1020048,bsc#982783). - raid1: ignore discard error (bsc#1017164). - ravb: Fix use-after-free on `ifconfig eth0 down` (git-fixes). - rdma/iw_cxgb4: Add missing error codes for act open cmd (bsc#1026570). - rdma/iw_cxgb4: Low resource fixes for Completion queue (bsc#1026570). - rdma/iw_cxgb4: only read markers_enabled mod param once (bsc#1026570). - Refresh patches.suse/blk-timeout-no-round. Refresh patches.drivers/0041-block-add-ability-to-flag-write-back-caching-on-a-devi ce.patch Do not collide with QUEUE_FLAG_WC from upstream (bsc#1022547) - regulator: isl9305: fix array size (bsc#1031717). - reiserfs: fix race in prealloc discard (bsc#987576). - Revert "acpi, nfit, libnvdimm: fix interleave set cookie calculation (64-bit comparison)" (kabi). - Revert "btrfs: qgroup: Move half of the qgroup accounting time out of" (bsc#1017461 bsc#1033885). - Revert "btrfs: qgroup: Move half of the qgroup accounting time out of" This reverts commit f69c1d0f6254c73529a48fd2f87815d047ad7288. - Revert "give up on gcc ilog2() constant optimizations" (kabi). - Revert "KVM: nested VMX: disable perf cpuid reporting" (4.4.68 stable queue). - Revert "l2tp: take reference on sessions being dumped" (kabi). - Revert "mac80211: pass block ack session timeout to to driver" (kabi). - Revert "mac80211: RX BA support for sta max_rx_aggregation_subframes" (kabi). - Revert "net: introduce device min_header_len" (kabi). - Revert "net/mlx4_en: Avoid unregister_netdev at shutdown flow" (bsc#1028017). - Revert "nfit, libnvdimm: fix interleave set cookie calculation" (kabi). - Revert "RDMA/core: Fix incorrect structure packing for booleans" (kabi). - Revert "target: Fix NULL dereference during LUN lookup + active I/O shutdown" (kabi). - Revert "wlcore: Add RX_BA_WIN_SIZE_CHANGE_EVENT event" (kabi). - rpm/kernel-binary.spec.in: Fix installation of /etc/uefi/certs (bsc#1019594) - rpm/kernel-binary.spec: remove superfluous flags This should make build logs more readable and people adding more flags should have easier time finding a place to add them in the spec file. - rpm/kernel-spec-macros: Fix the check if there is no rebuild counter (bsc#1012060) - rpm/SLES-UEFI-SIGN-Certificate-2048.crt: Update the certificate (bsc#1035922) - rtc: cmos: avoid unused function warning (bsc#1022429). - rtc: cmos: Clear ACPI-driven alarms upon resume (bsc#1022429). - rtc: cmos: Do not enable interrupts in the middle of the interrupt handler (bsc#1022429). - rtc: cmos: Restore alarm after resume (bsc#1022429). - rtlwifi: rtl_usb: Fix missing entry in USB driver's private data (bsc#1026462). - rtnetlink: NUL-terminate IFLA_PHYS_PORT_NAME string (4.4.68 stable queue). - rtnl: reset calcit fptr in rtnl_unregister() (bsc#1042286). - s390/cpuinfo: show maximum thread id (bnc#1009718, LTC#148580). - s390/dasd: check if query host access feature is supported (bsc#1037871). - s390/kmsg: add missing kmsg descriptions (bnc#1025683, LTC#151573). - s390/mm: fix zone calculation in arch_add_memory() (bnc#1025683, LTC#152318). - s390/sysinfo: show partition extended name and UUID if available (bnc#1009718, LTC#150160). - s390/time: LPAR offset handling (bnc#1009718, LTC#146920). - s390/time: move PTFF definitions (bnc#1009718, LTC#146920). - sbp-target: Fix second argument of percpu_ida_alloc() (bsc#1032803). - sched: Allow hotplug notifiers to be setup early (bnc#1022476). - sched/core: Fix incorrect utilization accounting when switching to fair class (bnc#1022476). - sched/core: Fix set_user_nice() (bnc#1022476). - sched/core, x86/topology: Fix NUMA in package topology bug (bnc#1022476). - sched/cputime: Add steal time support to full dynticks CPU time accounting (bnc#1022476). - sched/cputime: Fix prev steal time accouting during CPU hotplug (bnc#1022476). - sched/deadline: Always calculate end of period on sched_yield() (bnc#1022476). - sched/deadline: Fix a bug in dl_overflow() (bnc#1022476). - sched/deadline: Fix lock pinning warning during CPU hotplug (bnc#1022476). - sched/deadline: Fix wrap-around in DL heap (bnc#1022476). - sched/fair: Avoid using decay_load_missed() with a negative value (bnc#1022476). - sched/fair: Fix fixed point arithmetic width for shares and effective load (bnc#1022476). - sched/fair: Fix load_above_capacity fixed point arithmetic width (bnc#1022476). - sched/fair: Fix min_vruntime tracking (bnc#1022476). - sched/fair: Fix the wrong throttled clock time for cfs_rq_clock_task() (bnc#1022476). - sched/fair: Improve PELT stuff some more (bnc#1022476). - sched/loadavg: Avoid loadavg spikes caused by delayed NO_HZ accounting (bsc#1018419). - sched: Make wake_up_nohz_cpu() handle CPUs going offline (bnc#1022476). - sched/rt: Fix PI handling vs. sched_setscheduler() (bnc#1022476). - sched/rt: Kick RT bandwidth timer immediately on start up (bnc#1022476). - sched/rt, sched/dl: Do not push if task's scheduling class was changed (bnc#1022476). - scsi: be2iscsi: Add FUNCTION_RESET during driver unload (bsc#1038458). - scsi: be2iscsi: Add IOCTL to check UER supported (bsc#1038458). - scsi: be2iscsi: Add TPE recovery feature (bsc#1038458). - scsi: be2iscsi: Add V1 of EPFW cleanup IOCTL (bsc#1038458). - scsi: be2iscsi: allocate enough memory in beiscsi_boot_get_sinfo() (bsc#1038458). - scsi: be2iscsi: Check all zeroes IP before issuing IOCTL (bsc#1038458). - scsi: be2iscsi: Fail the sessions immediately after TPE (bsc#1038458). - scsi: be2iscsi: Fix async PDU handling path (bsc#1038458). - scsi: be2iscsi: Fix bad WRB index error (bsc#1038458). - scsi: be2iscsi: Fix checks for HBA in error state (bsc#1038458). - scsi: be2iscsi: Fix gateway APIs to support IPv4 & IPv6 (bsc#1038458). - scsi: be2iscsi: Fix POST check and reset sequence (bsc#1038458). - scsi: be2iscsi: Fix queue and connection parameters (bsc#1038458). - scsi: be2iscsi: Fix release of DHCP IP in static mode (bsc#1038458). - scsi: be2iscsi: Fix to add timer for UE detection (bsc#1038458). - scsi: be2iscsi: Fix to make boot discovery non-blocking (bsc#1038458). - scsi: be2iscsi: Fix to use correct configuration values (bsc#1038458). - scsi: be2iscsi: Handle only NET_PARAM in iface_get_param (bsc#1038458). - scsi: be2iscsi: Move functions to right files (bsc#1038458). - scsi: be2iscsi: Move VLAN code to common iface_set_param (bsc#1038458). - scsi: be2iscsi: Reduce driver load/unload time (bsc#1038458). - scsi: be2iscsi: Remove alloc_mcc_tag & beiscsi_pci_soft_reset (bsc#1038458). - scsi: be2iscsi: Remove isr_lock and dead code (bsc#1038458). - scsi: be2iscsi: Rename iface get/set/create/destroy APIs (bsc#1038458). - scsi: be2iscsi: Replace _bh version for mcc_lock spinlock (bsc#1038458). - scsi: be2iscsi: Set and return right iface v4/v6 states (bsc#1038458). - scsi: be2iscsi: Update copyright information (bsc#1038458). - scsi: be2iscsi: Update iface handle before any set param (bsc#1038458). - scsi: be2iscsi: Update the driver version (bsc#1038458). - scsi: cxgb4i: libcxgbi: add missing module_put() (bsc#1018885). - scsi: cxgb4i: libcxgbi: cxgb4: add T6 iSCSI completion feature (bsc#1021424). - scsi: cxlflash: Remove the device cleanly in the system shutdown path (bsc#1028310, fate#321597, bsc#1034762). cherry-pick from SP3 - scsi_dh_alua: do not call BUG_ON when updating port group (bsc#1028340). - scsi_dh_alua: Do not modify the interval value for retries (bsc#1012910). - scsi_dh_alua: Do not retry for unmapped device (bsc#1012910). - scsi: do not print 'reservation conflict' for TEST UNIT READY (bsc#1027054). - scsi_error: count medium access timeout only once per EH run (bsc#993832, bsc#1032345). - scsi: fnic: Correcting rport check location in fnic_queuecommand_lck (bsc#1035920). - scsi: ipr: do not set DID_PASSTHROUGH on CHECK CONDITION (bsc#1034419). - scsi: ipr: Driver version 2.6.4 (bsc#1031555, fate#321595). - scsi: ipr: Error path locking fixes (bsc#1031555, fate#321595). - scsi: ipr: Fix abort path race condition (bsc#1031555, fate#321595). - scsi: ipr: Fix missed EH wakeup (bsc#1031555, fate#321595). - scsi: ipr: Fix SATA EH hang (bsc#1031555, fate#321595). - scsi: ipr: Remove redundant initialization (bsc#1031555, fate#321595). - scsi: mac_scsi: Fix MAC_SCSI=m option when SCSI=m (4.4.68 stable queue). - scsi: scsi_dh_alua: Check scsi_device_get() return value (bsc#1040125). - scsi: scsi_dh_emc: return success in clariion_std_inquiry() (4.4.68 stable queue). - scsi_transport_fc: do not call queue_work under lock (bsc#1013887). - scsi_transport_fc: fixup race condition in fc_rport_final_delete() (bsc#1013887). - scsi_transport_fc: return -EBUSY for deleted vport (bsc#1013887). - sctp: check af before verify address in sctp_addr_id2transport (git-fixes). - sd: always scan VPD pages if thin provisioning is enabled (bsc#1013792). - serial: 8250_omap: Fix probe and remove for PM runtime (4.4.68 stable queue). - series.conf cosmetic adjustment (missing rt version placeholders) - series.conf: remove silly comment - ses: Fix SAS device detection in enclosure (bsc#1016403). - sfc: reduce severity of PIO buffer alloc failures (bsc#1019168). - sfc: refactor debug-or-warnings printks (bsc#1019168). - softirq: Let ksoftirqd do its job (bsc#1019618). - staging: emxx_udc: remove incorrect __init annotations (4.4.68 stable queue). - staging: rtl8188eu: prevent an underflow in rtw_check_beacon_data() (bsc#1031717). - staging: wlan-ng: add missing byte order conversion (4.4.68 stable queue). - sunrpc: Allow xprt->ops->timer method to sleep (git-fixes). - sunrpc: ensure correct error is reported by xs_tcp_setup_socket() (git-fixes). - sunrpc: fix UDP memory accounting (git-fixes). - sunrpc: Silence WARN_ON when NFSv4.1 over RDMA is in use (git-fixes). - supported.conf: added drivers/net/ethernet/chelsio/libcxgb/libcxgb - supported.conf: Add tcp_westwood as supported module (fate#322432) - supported.conf: Bugzilla and FATE references for dcdbas and dell_rbu - sysfs: be careful of error returns from ops->show() (bsc#1028883). - taint/module: Clean up global and module taint flags handling (fate#313296). - target: add XCOPY target/segment desc sense codes (bsc#991273). - target: bounds check XCOPY segment descriptor list (bsc#991273). - target: bounds check XCOPY total descriptor list length (bsc#991273). - target: check for XCOPY parameter truncation (bsc#991273). - target: check XCOPY segment descriptor CSCD IDs (bsc#1017170). - target: return UNSUPPORTED TARGET/SEGMENT DESC TYPE CODE sense (bsc#991273). - target: simplify XCOPY wwn->se_dev lookup helper (bsc#991273). - target: support XCOPY requests without parameters (bsc#991273). - target: use XCOPY segment descriptor CSCD IDs (bsc#1017170). - target: use XCOPY TOO MANY TARGET DESCRIPTORS sense (bsc#991273). - tcp: account for ts offset only if tsecr not zero (bsc#1042286). - tcp: do not inherit fastopen_req from parent (4.4.68 stable queue). - tcp: do not underestimate skb->truesize in tcp_trim_head() (4.4.68 stable queue). - tcp: fastopen: accept data/FIN present in SYNACK message (bsc#1042286). - tcp: fastopen: avoid negative sk_forward_alloc (bsc#1042286). - tcp: fastopen: call tcp_fin() if FIN present in SYNACK (bsc#1042286). - tcp: fastopen: fix rcv_wup initialization for TFO server on SYN/data (bsc#1042286). - tcp: fix wraparound issue in tcp_lp (4.4.68 stable queue). - thp: fix MADV_DONTNEED vs. numa balancing race (bnc#1027974). - thp: reduce indentation level in change_huge_pmd() (bnc#1027974). - tpm: Downgrade error level (bsc#1042535). - tpm: fix checks for policy digest existence in tpm2_seal_trusted() (bsc#1034048, Pending fixes 2017-04-10). - tpm: fix RC value check in tpm2_seal_trusted (bsc#1034048, Pending fixes 2017-04-10). - tpm: fix: set continueSession attribute for the unseal operation (bsc#1034048, Pending fixes 2017-04-10). - tracing/kprobes: Enforce kprobes teardown after testing (bnc#1012985). - udp: avoid ufo handling on IP payload compression packets (bsc#1042286). - udplite: call proper backlog handlers (bsc#1042286). - Update mainline reference in patches.drivers/drm-ast-Fix-memleaks-in-error-path-in-ast_fb_create.patch S ee (bsc#1028158) for the context in which this was discovered upstream. - Update metadata for serial fixes (bsc#1013001) - Update patches.fixes/xen-silence-efi-error-messge.patch (bnc#1039900). - Update patches.kernel.org/patch-4.4.47-48 (bnc#1012382 bnc#1022181). Add a bnc reference. - usb: chipidea: Handle extcon events properly (4.4.68 stable queue). - usb: chipidea: Only read/write OTGSC from one place (4.4.68 stable queue). - usb: host: ehci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths (4.4.68 stable queue). - usb: host: ohci-exynos: Decrese node refcount on exynos_ehci_get_phy() error paths (4.4.68 stable queue). - usb: musb: ux500: Fix NULL pointer dereference at system PM (bsc#1038033). - usb: serial: ark3116: fix open error handling (bnc#1038043). - usb: serial: ch341: add register and USB request definitions (bnc#1038043). - usb: serial: ch341: add support for parity, frame length, stop bits (bnc#1038043). - usb: serial: ch341: fix baud rate and line-control handling (bnc#1038043). - usb: serial: ch341: fix line settings after reset-resume (bnc#1038043). - usb: serial: ch341: fix modem-status handling (bnc#1038043). - usb: serial: ch341: reinitialize chip on reconfiguration (bnc#1038043). - usb: serial: digi_acceleport: fix incomplete rx sanity check (4.4.68 stable queue). - usb: serial: fix compare_const_fl.cocci warnings (bnc#1038043). - usb: serial: ftdi_sio: fix latency-timer error handling (4.4.68 stable queue). - usb: serial: io_edgeport: fix descriptor error handling (4.4.68 stable queue). - usb: serial: io_edgeport: fix epic-descriptor handling (bnc#1038043). - usb: serial: keyspan_pda: fix receive sanity checks (4.4.68 stable queue). - usb: serial: mct_u232: fix modem-status error handling (4.4.68 stable queue). - usb: serial: quatech2: fix control-message error handling (bnc#1038043). - usb: serial: sierra: fix bogus alternate-setting assumption (bnc#1038043). - usb: serial: ssu100: fix control-message error handling (bnc#1038043). - usb: serial: ti_usb_3410_5052: fix control-message error handling (4.4.68 stable queue). - Use make --output-sync feature when available (bsc#1012422). The mesages in make output can interleave making it impossible to extract warnings reliably. Since version 4 GNU Make supports --output-sync flag that prints output of each sub-command atomically preventing this issue. Detect the flag and use it if available. - Use up spare in struct module for livepatch (FATE#322421). - vmxnet3: segCnt can be 1 for LRO packets (bsc#988065). - vrf: remove slave queue and private slave struct (bsc#1042286). - vsock: Detach QP check should filter out non matching QPs (bsc#1036752). - x86/apic/uv: Silence a shift wrapping warning (bsc#1023866). - x86/CPU/AMD: Fix Zen SMT topology (bsc#1027512). - x86/ioapic: Change prototype of acpi_ioapic_add() (bsc#1027153, bsc#1027616). - x86/ioapic: Fix incorrect pointers in ioapic_setup_resources() (bsc#1027153, bsc#1027616). - x86/ioapic: Fix IOAPIC failing to request resource (bsc#1027153, bsc#1027616). - x86/ioapic: fix kABI (hide added include) (bsc#1027153, bsc#1027616). - x86/ioapic: Fix lost IOAPIC resource after hot-removal and hotadd (bsc#1027153, bsc#1027616). - x86/ioapic: Fix setup_res() failing to get resource (bsc#1027153, bsc#1027616). - x86/ioapic: Ignore root bridges without a companion ACPI device (bsc#1027153, bsc#1027616). - x86/ioapic: Restore IO-APIC irq_chip retrigger callback (4.4.68 stable queue). - x86/ioapic: Simplify ioapic_setup_resources() (bsc#1027153, bsc#1027616). - x86/ioapic: Support hot-removal of IOAPICs present during boot (bsc#1027153, bsc#1027616). - x86/mce: Do not print MCEs when mcelog is active (bsc#1013994). - x86/MCE: Dump MCE to dmesg if no consumers (bsc#1013994). - x86/mce: Fix copy/paste error in exception table entries (fate#319858). - x86, mm: fix gup_pte_range() vs DAX mappings (bsc#1026405). - x86/mm/gup: Simplify get_user_pages() PTE bit handling (bsc#1026405). - x86/pci-calgary: Fix iommu_free() comparison of unsigned expression >= 0 (4.4.68 stable queue). - x86/PCI: Mark Broadwell-EP Home Agent 1 as having non-compliant BARs (bsc#9048891). - x86/platform/intel/iosf_mbi: Add a mutex for P-Unit access (bsc#1011913). - x86/platform/intel/iosf_mbi: Add a PMIC bus access notifier (bsc#1011913). - x86/platform/intel-mid: Correct MSI IRQ line for watchdog device (4.4.68 stable queue). - x86/platform: Remove warning message for duplicate NMI handlers (bsc#1029220). - x86/platform/UV: Add basic CPU NMI health check (bsc#1023866). - x86/platform/UV: Add Support for UV4 Hubless NMIs (bsc#1023866). - x86/platform/UV: Add Support for UV4 Hubless systems (bsc#1023866). - x86/platform/uv/BAU: Add generic function pointers (bsc#1035024). - x86/platform/uv/BAU: Add payload descriptor qualifier (bsc#1035024). - x86/platform/uv/BAU: Add status mmr location fields to bau_control (bsc#1035024). - x86/platform/uv/BAU: Add UV4-specific functions (bsc#1035024). - x86/platform/uv/BAU: Add uv_bau_version enumerated constants (bsc#1035024). - x86/platform/uv/BAU: Add wait_completion to bau_operations (bsc#1035024). - x86/platform/uv/BAU: Clean up and update printks (bsc#1035024). - x86/platform/uv/BAU: Cleanup bau_operations declaration and instances (bsc#1035024). - x86/platform/uv/BAU: Clean up pq_init() (bsc#1035024). - x86/platform/uv/BAU: Clean up vertical alignment (bsc#1035024). - x86/platform/uv/BAU: Convert uv_physnodeaddr() use to uv_gpa_to_offset() (bsc#1035024). - x86/platform/uv/BAU: Disable software timeout on UV4 hardware (bsc#1035024). - x86/platform/uv/BAU: Fix HUB errors by remove initial write to sw-ack register (bsc#1035024). - x86/platform/uv/BAU: Fix payload queue setup on UV4 hardware (bsc#1035024). - x86/platform/uv/BAU: Implement uv4_wait_completion with read_status (bsc#1035024). - x86/platform/uv/BAU: Populate ->uvhub_version with UV4 version information (bsc#1035024). - x86/platform/uv/BAU: Use generic function pointers (bsc#1035024). - x86/platform/UV: Clean up the NMI code to match current coding style (bsc#1023866). - x86/platform/UV: Clean up the UV APIC code (bsc#1023866). - x86/platform/UV: Ensure uv_system_init is called when necessary (bsc#1023866). - x86/platform/UV: Fix 2 socket config problem (bsc#1023866). - x86/platform/uv: Fix calculation of Global Physical Address (bsc#1031147). - x86/platform/UV: Fix panic with missing UVsystab support (bsc#1023866). - x86/platform/UV: Initialize PCH GPP_D_0 NMI Pin to be NMI source (bsc#1023866). - x86/platform/UV: Verify NMI action is valid, default is standard (bsc#1023866). - x86/ras/therm_throt: Do not log a fake MCE for thermal events (bsc#1028027). - xen: add sysfs node for guest type (bnc#1037840). - xen: adjust early dom0 p2m handling to xen hypervisor behavior (bnc#1031470). - xen-blkback: do not leak stack data via response ring (bsc#1042863 XSA-216). - xen-blkfront: correct maximum segment accounting (bsc#1018263). - xen-blkfront: do not call talk_to_blkback when already connected to blkback. - xen/blkfront: Fix crash if backend does not follow the right states. - xen-blkfront: free resources if xlvbd_alloc_gendisk fails. - xen/mce: do not issue error message for failed /dev/mcelog registration (bnc#1036638). - xen/netback: set default upper limit of tx/rx queues to 8 (bnc#1019163). - xen/netfront: set default upper limit of tx/rx queues to 8 (bnc#1019163). - xen: Use machine addresses in /sys/kernel/vmcoreinfo when PV (bsc#1014136) - xfrm: Fix memory leak of aead algorithm name (bsc#1042286). - xfrm: Only add l3mdev oif to dst lookups (bsc#1042286). - xfs: add missing include dependencies to xfs_dir2.h (bsc#1042421). - xfs_dmapi: fix the debug compilation of xfs_dmapi (bsc#989056). - xfs: do not allow di_size with high bit set (bsc#1024234). - xfs: do not assert fail on non-async buffers on ioacct decrement (bsc#1041160). - xfs: do not take the IOLOCK exclusive for direct I/O page invalidation (bsc#1015609). - xfs: do not warn on buffers not being recovered due to LSN (bsc#1043598). - xfs: exclude never-released buffers from buftarg I/O accounting (bsc#1024508). - xfs: fix broken multi-fsb buffer logging (bsc#1024081). - xfs: fix buffer overflow dm_get_dirattrs/dm_get_dirattrs2 (bsc#989056). - xfs: fix eofblocks race with file extending async dio writes (bsc#1040929). - xfs: Fix missed holes in SEEK_HOLE implementation (bsc#1041168). - xfs: fix off-by-one on max nr_pages in xfs_find_get_desired_pgoff() (bsc#1041168). - xfs: fix up xfs_swap_extent_forks inline extent handling (bsc#1023888). - xfs: fix xfs_mode_to_ftype() prototype (bsc#1043598). - xfs: in _attrlist_by_handle, copy the cursor back to userspace (bsc#1041242). - xfs: log recovery tracepoints to track current lsn and buffer submission (bsc#1043598). - xfs: Make __xfs_xattr_put_listen preperly report errors (bsc#1041242). - xfs: only return -errno or success from attr ->put_listent (bsc#1041242). - xfs: pass current lsn to log recovery buffer validation (bsc#1043598). - xfs: refactor log record unpack and data processing (bsc#1043598). - xfs: replace xfs_mode_to_ftype table with switch statement (bsc#1042421). - xfs: rework log recovery to submit buffers on LSN boundaries (bsc#1043598). - xfs: rework the inline directory verifiers (bsc#1042421). - xfs: sanity check directory inode di_size (bsc#1042421). - xfs: sanity check inode di_mode (bsc#1042421). - xfs: Split default quota limits by quota type (bsc#1040941). - xfs: track and serialize in-flight async buffers against unmount (bsc#1024508). - xfs: track and serialize in-flight async buffers against unmount - kABI (bsc#1024508). - xfs: update metadata LSN in buffers during log recovery (bsc#1043598). - xfs: use ->b_state to fix buffer I/O accounting release race (bsc#1041160). - xfs: verify inline directory data forks (bsc#1042421). - xgene_enet: remove bogus forward declarations (bsc#1032673). - zswap: do not param_set_charp while holding spinlock (VM Functionality, bsc#1042886). - blacklist.conf: add non-applicable fixes for iwlwifi (FATE#323335) - blacklist.conf: blacklist c34a69059d78 (bnc#1044880) - btrfs: disable possible cause of premature ENOSPC (bsc#1040182) - btrfs: Manually implement device_total_bytes getter/setter (bsc#1043912). - btrfs: Round down values which are written for total_bytes_size (bsc#1043912). - dm: remove dummy dm_table definition (bsc#1045307) - Fix soft lockup in svc_rdma_send (bsc#1044854). - fs/exec.c: account for argv/envp pointers (bnc#1039354, CVE-2017-1000365). - hpsa: limit transfer length to 1MB (bsc#1025461). - hwpoison, memcg: forcibly uncharge LRU pages (bnc#1046105). - IB/ipoib: Fix memory leak in create child syscall (bsc#1022595 FATE#322350). - ibmvnic: Correct return code checking for ibmvnic_init during probe (bsc#1045286). - ibmvnic: Fix assignment of RX/TX IRQ's (bsc#1046589). - ibmvnic: Fix error handling when registering long-term-mapped buffers (bsc#1045568). - ibmvnic: Fix incorrectly defined ibmvnic_request_map_rsp structure (bsc#1045568). - ibmvnic: Remove module author mailing address (bsc#1045467). - ibmvnic: Return from ibmvnic_resume if not in VNIC_OPEN state (bsc#1045235). - iw_cxgb4: Fix error return code in c4iw_rdev_open() (bsc#1026570). - iwlwifi: 8000: fix MODULE_FIRMWARE input. - iwlwifi: 9000: increase the number of queues. - iwlwifi: add device ID for 8265. - iwlwifi: add device IDs for the 8265 device. - iwlwifi: add disable_11ac module param. - iwlwifi: add new 3168 series devices support. - iwlwifi: add new 8260 PCI IDs. - iwlwifi: add new 8265. - iwlwifi: add new 8265 series PCI ID. - iwlwifi: Add new PCI IDs for 9260 and 5165 series. - iwlwifi: Add PCI IDs for the new 3168 series. - iwlwifi: Add PCI IDs for the new series 8165. - iwlwifi: add support for 12K Receive Buffers. - iwlwifi: add support for getting HW address from CSR. - iwlwifi: avoid d0i3 commands when no/init ucode is loaded. - iwlwifi: bail out in case of bad trans state. - iwlwifi: block the queues when we send ADD_STA for uAPSD. - iwlwifi: change the Intel Wireless email address. - iwlwifi: check for valid ethernet address provided by OEM. - iwlwifi: clean up transport debugfs handling. - iwlwifi: clear ieee80211_tx_info->driver_data in the op_mode. - iwlwifi: Document missing module options. - iwlwifi: dump prph registers in a common place for all transports. - iwlwifi: dvm: advertise NETIF_F_SG. - iwlwifi: dvm: fix compare_const_fl.cocci warnings. - iwlwifi: dvm: handle zero brightness for wifi LED. - iwlwifi: dvm: remove a wrong dependency on m. - iwlwifi: dvm: remove Kconfig default. - iwlwifi: dvm: remove stray debug code. - iwlwifi: export the _no_grab version of PRPH IO functions. - iwlwifi: expose fw usniffer mode to more utilities. - iwlwifi: fix double hyphen in MODULE_FIRMWARE for 8000. - iwlwifi: Fix firmware name maximum length definition. - iwlwifi: fix name of ucode loaded for 8265 series. - iwlwifi: fix printf specifier. - iwlwifi: generalize d0i3_entry_timeout module parameter. - iwlwifi: mvm: adapt the firmware assert log to new firmware. - iwlwifi: mvm: add 9000-series RX API. - iwlwifi: mvm: add 9000 series RX processing. - iwlwifi: mvm: add a non-trigger window to fw dbg triggers. - iwlwifi: mvm: add an option to start rs from HT/VHT rates. - iwlwifi: mvm: Add a station in monitor mode. - iwlwifi: mvm: add bt rrc and ttc to debugfs. - iwlwifi: mvm: add bt settings to debugfs. - iwlwifi: mvm: add ctdp operations to debugfs. - iwlwifi: mvm: add CT-KILL notification. - iwlwifi: mvm: add debug print if scan config is ignored. - iwlwifi: mvm: add extended dwell time. - iwlwifi: mvm: add new ADD_STA command version. - iwlwifi: mvm: Add P2P client snoozing. - iwlwifi: mvm: add registration to cooling device. - iwlwifi: mvm: add registration to thermal zone. - iwlwifi: mvm: add support for negative temperatures. - iwlwifi: mvm: add tlv for multi queue rx support. - iwlwifi: mvm: add trigger for firmware dump upon TDLS events. - iwlwifi: mvm: add trigger for firmware dump upon TX response status. - iwlwifi: mvm: advertise NETIF_F_SG. - iwlwifi: mvm: Align bt-coex priority with requirements. - iwlwifi: mvm: allow to disable beacon filtering for AP/GO interface. - iwlwifi: mvm: avoid harmless -Wmaybe-uninialized warning. - iwlwifi: mvm: avoid panics with thermal device usage. - iwlwifi: mvm: avoid to WARN about gscan capabilities. - iwlwifi: mvm: bail out if CTDP start operation fails. - iwlwifi: mvm: bump firmware API to 21. - iwlwifi: mvm: bump max API to 20. - iwlwifi: mvm: change access to ieee80211_hdr. - iwlwifi: mvm: change iwl_mvm_get_key_sta_id() to return the station. - iwlwifi: mvm: change mcc update API. - iwlwifi: mvm: change name of iwl_mvm_d3_update_gtk. - iwlwifi: mvm: Change number of associated stations when station becomes associated. - iwlwifi: mvm: change protocol offload flows. - iwlwifi: mvm: change the check for ADD_STA status. - iwlwifi: mvm: check FW's response for nvm access write cmd. - iwlwifi: mvm: check iwl_mvm_wowlan_config_key_params() return value. - iwlwifi: mvm: check minimum temperature notification length. - iwlwifi: mvm: cleanup roc te on restart cleanup. - iwlwifi: mvm: Configure fragmented scan for scheduled scan. - iwlwifi: mvm: configure scheduled scan according to traffic conditions. - iwlwifi: mvm: constify the parameters of a few functions in fw-dbg.c. - iwlwifi: mvm: Disable beacon storing in D3 when WOWLAN configured. - iwlwifi: mvm: disable DQA support. - iwlwifi: mvm: Do not switch to D3 image on suspend. - iwlwifi: mvm: don't ask beacons when P2P GO vif and no assoc sta. - iwlwifi: mvm: don't keep an mvm ref when the interface is down. - iwlwifi: mvm: don't let NDPs mess the packet tracking. - iwlwifi: mvm: don't restart HW if suspend fails with unified image. - iwlwifi: mvm: don't try to offload AES-CMAC in AP/IBSS modes. - iwlwifi: mvm: drop low_latency_agg_frame_cnt_limit. - iwlwifi: mvm: dump more registers upon error. - iwlwifi: mvm: dump the radio registers when the firmware crashes. - iwlwifi: mvm: enable L3 filtering. - iwlwifi: mvm: Enable MPLUT only on supported hw. - iwlwifi: mvm: enable VHT MU-MIMO for supported hardware. - iwlwifi: mvm: extend time event duration. - iwlwifi: mvm: fix accessing Null pointer during fw dump collection. - iwlwifi: mvm: fix d3_test with unified D0/D3 images. - iwlwifi: mvm: fix debugfs signedness warning. - iwlwifi: mvm: fix extended dwell time. - iwlwifi: mvm: fix incorrect fallthrough in iwl_mvm_check_running_scans(). - iwlwifi: mvm: fix memory leaks in error paths upon fw error dump. - iwlwifi: mvm: fix netdetect starting/stopping for unified images. - iwlwifi: mvm: fix RSS key sizing. - iwlwifi: mvm: fix unregistration of thermal in some error flows. - iwlwifi: mvm: flush all used TX queues before suspending. - iwlwifi: mvm: forbid U-APSD for P2P Client if the firmware doesn't support it. - iwlwifi: mvm: handle pass all scan reporting. - iwlwifi: mvm: ignore LMAC scan notifications when running UMAC scans. - iwlwifi: mvm: infrastructure for frame-release message. - iwlwifi: mvm: kill iwl_mvm_enable_agg_txq. - iwlwifi: mvm: let the firmware choose the antenna for beacons. - iwlwifi: mvm: make collecting fw debug data optional. - iwlwifi: mvm: move fw-dbg code to separate file. - iwlwifi: mvm: only release the trans ref if d0i3 is supported in fw. - iwlwifi: mvm: prepare the code towards TSO implementation. - iwlwifi: mvm: refactor d3 key update functions. - iwlwifi: mvm: refactor the way fw_key_table is handled. - iwlwifi: mvm: remove an extra tab. - iwlwifi: mvm: Remove bf_vif from iwl_power_vifs. - iwlwifi: mvm: Remove iwl_mvm_update_beacon_abort. - iwlwifi: mvm: remove redundant d0i3 flag from the config struct. - iwlwifi: mvm: remove shadowing variable. - iwlwifi: mvm: remove stray nd_config element. - iwlwifi: mvm: remove the vif parameter of iwl_mvm_configure_bcast_filter(). - iwlwifi: mvm: remove unnecessary check in iwl_mvm_is_d0i3_supported(). - iwlwifi: mvm: remove useless WARN_ON and rely on cfg80211's combination. - iwlwifi: mvm: report wakeup for wowlan. - iwlwifi: mvm: reset mvm->scan_type when firmware is started. - iwlwifi: mvm: return the cooling state index instead of the budget. - iwlwifi: mvm: ROC: cleanup time event info on FW failure. - iwlwifi: mvm: ROC: Extend the ROC max delay duration & limit ROC duration. - iwlwifi: mvm: rs: fix a potential out of bounds access. - iwlwifi: mvm: rs: fix a theoretical access to uninitialized array elements. - iwlwifi: mvm: rs: fix a warning message. - iwlwifi: mvm: rs: fix TPC action decision algorithm. - iwlwifi: mvm: rs: fix TPC statistics handling. - iwlwifi: mvm: Send power command on BSS_CHANGED_BEACON_INFO if needed. - iwlwifi: mvm: set default new STA as non-aggregated. - iwlwifi: mvm: set the correct amsdu enum values. - iwlwifi: mvm: set the correct descriptor size for tracing. - iwlwifi: mvm: small update in the firmware API. - iwlwifi: mvm: support A-MSDU in A-MPDU. - iwlwifi: mvm: support beacon storing. - iwlwifi: mvm: support description for user triggered fw dbg collection. - iwlwifi: mvm: support rss queues configuration command. - iwlwifi: mvm: Support setting continuous recording debug mode. - iwlwifi: mvm: support setting minimum quota from debugfs. - iwlwifi: mvm: support sw queue start/stop from mvm. - iwlwifi: mvm: take care of padded packets. - iwlwifi: mvm: take the transport ref back when leaving. - iwlwifi: mvm: track low-latency sources separately. - iwlwifi: mvm: update GSCAN capabilities. - iwlwifi: mvm: update ucode status before stopping device. - iwlwifi: mvm: use build-time assertion for fw trigger ID. - iwlwifi: mvm: use firmware station lookup, combine code. - iwlwifi: mvm: various trivial cleanups. - iwlwifi: mvm: writing zero bytes to debugfs causes a crash. - iwlwifi: nvm: fix loading default NVM file. - iwlwifi: nvm: fix up phy section when reading it. - iwlwifi: pcie: add 9000 series multi queue rx DMA support. - iwlwifi: pcie: add infrastructure for multi-queue rx. - iwlwifi: pcie: add initial RTPM support for PCI. - iwlwifi: pcie: Add new configuration to enable MSIX. - iwlwifi: pcie: add pm_prepare and pm_complete ops. - iwlwifi: pcie: add RTPM support when wifi is enabled. - iwlwifi: pcie: aggregate Flow Handler configuration writes. - iwlwifi: pcie: allow the op_mode to block the tx queues. - iwlwifi: pcie: allow to pretend to have Tx CSUM for debug. - iwlwifi: pcie: avoid restocks inside rx loop if not emergency. - iwlwifi: pcie: buffer packets to avoid overflowing Tx queues. - iwlwifi: pcie: build an A-MSDU using TSO core. - iwlwifi: pcie: configure more RFH settings. - iwlwifi: pcie: detect and workaround invalid write ptr behavior. - iwlwifi: pcie: don't increment / decrement a bool. - iwlwifi: pcie: enable interrupts before releasing the NIC's CPU. - iwlwifi: pcie: enable multi-queue rx path. - iwlwifi: pcie: extend device reset delay. - iwlwifi: pcie: fine tune number of rxbs. - iwlwifi: pcie: fix a race in firmware loading flow. - iwlwifi: pcie: fix erroneous return value. - iwlwifi: pcie: fix global table size. - iwlwifi: pcie: fix identation in trans.c. - iwlwifi: pcie: fix RF-Kill vs. firmware load race. - iwlwifi: pcie: forbid RTPM on device removal. - iwlwifi: pcie: mark command queue lock with separate lockdep class. - iwlwifi: pcie: prevent skbs shadowing in iwl_trans_pcie_reclaim. - iwlwifi: pcie: refactor RXBs reclaiming code. - iwlwifi: pcie: remove ICT allocation message. - iwlwifi: pcie: remove pointer from debug message. - iwlwifi: pcie: re-organize code towards TSO. - iwlwifi: pcie: set RB chunk size back to 64. - iwlwifi: pcie: update iwl_mpdu_desc fields. - iwlwifi: print index in api/capa flags parsing message. - iwlwifi: refactor the code that reads the MAC address from the NVM. - iwlwifi: remove IWL_DL_LED. - iwlwifi: remove unused parameter from grab_nic_access. - iwlwifi: replace d0i3_mode and wowlan_d0i3 with more generic variables. - iwlwifi: set max firmware version of 7265 to 17. - iwlwifi: support ucode with d0 unified image - regular and usniffer. - iwlwifi: trans: make various conversion macros inlines. - iwlwifi: trans: support a callback for ASYNC commands. - iwlwifi: treat iwl_parse_nvm_data() MAC addr as little endian. - iwlwifi: tt: move ucode_loaded check under mutex. - iwlwifi: uninline iwl_trans_send_cmd. - iwlwifi: update host command messages to new format. - iwlwifi: Update PCI IDs for 8000 and 9000 series. - iwlwifi: update support for 3168 series firmware and NVM. - iwlwifi: various comments and code cleanups. - kabi: ignore fs_info parameter for tracepoints that didn't have it (bsc#1044912). - kabi/severities: ignore kABi changes in iwlwifi stuff itself - lan78xx: use skb_cow_head() to deal with cloned skbs (bsc#1045154). - Linux 4.4.74 (CVE-2017-1000364 bnc#1012382 bnc#1039348 bnc#1045340 bsc#1031717 bsc#1043231). - loop: Add PF_LESS_THROTTLE to block/loop device thread (bsc#1027101). - md: fix a null dereference (bsc#1040351). - md: use a separate bio_set for synchronous IO (bsc#1040351). - mm: fix new crash in unmapped_area_topdown() (bnc#1039348). - mm: larger stack guard gap, between vmas (bnc#1039348, CVE-2017-1000364, bnc#1045340). - net/mlx5e: Fix timestamping capabilities reporting (bsc#966170 bsc#1015342). - NFSv4: don't let hanging mounts block other mounts (bsc#1040364). - powerpc/fadump: add reschedule point while releasing memory (bsc#1040609). - powerpc/fadump: avoid duplicates in crash memory ranges (bsc#1037669). - powerpc/fadump: avoid holes in boot memory area when fadump is registered (bsc#1037669). - powerpc/fadump: provide a helpful error message (bsc#1037669). - powerpc/fadump: return error when fadump registration fails (bsc#1040567). - powerpc/ftrace: Pass the correct stack pointer for DYNAMIC_FTRACE_WITH_REGS (FATE#322421). - printk: Correctly handle preemption in console_unlock() (bsc#1046434). - printk/xen: Force printk sync mode when migrating Xen guest (bsc#1043347). - RDMA/iw_cxgb4: Always wake up waiter in c4iw_peer_abort_intr() (bsc#1026570). - Reenable and refresh patches.suse/iwlwifi-expose-default-fallback-ucode-api. - reiserfs: don't preallocate blocks for extended attributes (bsc#990682). - smartpqi: limit transfer length to 1MB (bsc#1025461). - tty: Destroy ldisc instance on hangup (bnc#1043488). - tty: Fix ldisc crash on reopened tty (bnc#1043488). - tty: Handle NULL tty->ldisc (bnc#1043488). - tty: Move tty_ldisc_kill() (bnc#1043488). - tty: Prepare for destroying line discipline on hangup (bnc#1043488). - tty: Refactor tty_ldisc_reinit() for reuse (bnc#1043488). - tty: Reset c_line from driver's init_termios (bnc#1043488). - tty: Simplify tty_set_ldisc() exit handling (bnc#1043488). - tty: Use 'disc' for line discipline index name (bnc#1043488). - Update config files: add CONFIG_IWLWIFI_PCIE_RTPM=y (FATE#323335) - Update patches.fixes/xfs-split-default-quota-limits-by-quota-type.patch (bsc#1040941). Fix the bug nr used. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Real Time Extension 12-SP2: zypper in -t patch SUSE-SLE-RT-12-SP2-2017-1231=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Real Time Extension 12-SP2 (noarch): kernel-devel-rt-4.4.74-7.10.1 kernel-source-rt-4.4.74-7.10.1 - SUSE Linux Enterprise Real Time Extension 12-SP2 (x86_64): cluster-md-kmp-rt-4.4.74-7.10.1 cluster-md-kmp-rt-debuginfo-4.4.74-7.10.1 cluster-network-kmp-rt-4.4.74-7.10.1 cluster-network-kmp-rt-debuginfo-4.4.74-7.10.1 dlm-kmp-rt-4.4.74-7.10.1 dlm-kmp-rt-debuginfo-4.4.74-7.10.1 gfs2-kmp-rt-4.4.74-7.10.1 gfs2-kmp-rt-debuginfo-4.4.74-7.10.1 kernel-rt-4.4.74-7.10.1 kernel-rt-base-4.4.74-7.10.1 kernel-rt-base-debuginfo-4.4.74-7.10.1 kernel-rt-debuginfo-4.4.74-7.10.1 kernel-rt-debugsource-4.4.74-7.10.1 kernel-rt-devel-4.4.74-7.10.1 kernel-rt_debug-debuginfo-4.4.74-7.10.1 kernel-rt_debug-debugsource-4.4.74-7.10.1 kernel-rt_debug-devel-4.4.74-7.10.1 kernel-rt_debug-devel-debuginfo-4.4.74-7.10.1 kernel-syms-rt-4.4.74-7.10.1 ocfs2-kmp-rt-4.4.74-7.10.1 ocfs2-kmp-rt-debuginfo-4.4.74-7.10.1 References: https://www.suse.com/security/cve/CVE-2016-10200.html https://www.suse.com/security/cve/CVE-2016-2117.html https://www.suse.com/security/cve/CVE-2016-4997.html https://www.suse.com/security/cve/CVE-2016-4998.html https://www.suse.com/security/cve/CVE-2016-7117.html https://www.suse.com/security/cve/CVE-2016-9191.html https://www.suse.com/security/cve/CVE-2017-1000364.html https://www.suse.com/security/cve/CVE-2017-1000365.html https://www.suse.com/security/cve/CVE-2017-1000380.html https://www.suse.com/security/cve/CVE-2017-2583.html https://www.suse.com/security/cve/CVE-2017-2584.html https://www.suse.com/security/cve/CVE-2017-2596.html https://www.suse.com/security/cve/CVE-2017-2636.html https://www.suse.com/security/cve/CVE-2017-2671.html https://www.suse.com/security/cve/CVE-2017-5551.html https://www.suse.com/security/cve/CVE-2017-5576.html https://www.suse.com/security/cve/CVE-2017-5577.html https://www.suse.com/security/cve/CVE-2017-5897.html https://www.suse.com/security/cve/CVE-2017-5970.html https://www.suse.com/security/cve/CVE-2017-5986.html https://www.suse.com/security/cve/CVE-2017-6074.html https://www.suse.com/security/cve/CVE-2017-6214.html https://www.suse.com/security/cve/CVE-2017-6345.html https://www.suse.com/security/cve/CVE-2017-6346.html https://www.suse.com/security/cve/CVE-2017-6347.html https://www.suse.com/security/cve/CVE-2017-6353.html https://www.suse.com/security/cve/CVE-2017-7184.html https://www.suse.com/security/cve/CVE-2017-7187.html https://www.suse.com/security/cve/CVE-2017-7261.html https://www.suse.com/security/cve/CVE-2017-7294.html https://www.suse.com/security/cve/CVE-2017-7308.html https://www.suse.com/security/cve/CVE-2017-7346.html https://www.suse.com/security/cve/CVE-2017-7374.html https://www.suse.com/security/cve/CVE-2017-7487.html https://www.suse.com/security/cve/CVE-2017-7616.html https://www.suse.com/security/cve/CVE-2017-7618.html https://www.suse.com/security/cve/CVE-2017-8890.html https://www.suse.com/security/cve/CVE-2017-9074.html https://www.suse.com/security/cve/CVE-2017-9075.html https://www.suse.com/security/cve/CVE-2017-9076.html https://www.suse.com/security/cve/CVE-2017-9077.html https://www.suse.com/security/cve/CVE-2017-9150.html https://www.suse.com/security/cve/CVE-2017-9242.html https://bugzilla.suse.com/1000092 https://bugzilla.suse.com/1003077 https://bugzilla.suse.com/1003581 https://bugzilla.suse.com/1004003 https://bugzilla.suse.com/1007729 https://bugzilla.suse.com/1007959 https://bugzilla.suse.com/1007962 https://bugzilla.suse.com/1008842 https://bugzilla.suse.com/1009674 https://bugzilla.suse.com/1009718 https://bugzilla.suse.com/1010032 https://bugzilla.suse.com/1010612 https://bugzilla.suse.com/1010690 https://bugzilla.suse.com/1011044 https://bugzilla.suse.com/1011176 https://bugzilla.suse.com/1011913 https://bugzilla.suse.com/1012060 https://bugzilla.suse.com/1012382 https://bugzilla.suse.com/1012422 https://bugzilla.suse.com/1012452 https://bugzilla.suse.com/1012829 https://bugzilla.suse.com/1012910 https://bugzilla.suse.com/1012985 https://bugzilla.suse.com/1013001 https://bugzilla.suse.com/1013561 https://bugzilla.suse.com/1013792 https://bugzilla.suse.com/1013887 https://bugzilla.suse.com/1013994 https://bugzilla.suse.com/1014120 https://bugzilla.suse.com/1014136 https://bugzilla.suse.com/1015342 https://bugzilla.suse.com/1015367 https://bugzilla.suse.com/1015452 https://bugzilla.suse.com/1015609 https://bugzilla.suse.com/1016403 https://bugzilla.suse.com/1017164 https://bugzilla.suse.com/1017170 https://bugzilla.suse.com/1017410 https://bugzilla.suse.com/1017461 https://bugzilla.suse.com/1017641 https://bugzilla.suse.com/1018100 https://bugzilla.suse.com/1018263 https://bugzilla.suse.com/1018358 https://bugzilla.suse.com/1018385 https://bugzilla.suse.com/1018419 https://bugzilla.suse.com/1018446 https://bugzilla.suse.com/1018813 https://bugzilla.suse.com/1018885 https://bugzilla.suse.com/1018913 https://bugzilla.suse.com/1019061 https://bugzilla.suse.com/1019148 https://bugzilla.suse.com/1019163 https://bugzilla.suse.com/1019168 https://bugzilla.suse.com/1019260 https://bugzilla.suse.com/1019351 https://bugzilla.suse.com/1019594 https://bugzilla.suse.com/1019614 https://bugzilla.suse.com/1019618 https://bugzilla.suse.com/1019630 https://bugzilla.suse.com/1019631 https://bugzilla.suse.com/1019784 https://bugzilla.suse.com/1019851 https://bugzilla.suse.com/1020048 https://bugzilla.suse.com/1020214 https://bugzilla.suse.com/1020412 https://bugzilla.suse.com/1020488 https://bugzilla.suse.com/1020602 https://bugzilla.suse.com/1020685 https://bugzilla.suse.com/1020817 https://bugzilla.suse.com/1020945 https://bugzilla.suse.com/1020975 https://bugzilla.suse.com/1021082 https://bugzilla.suse.com/1021248 https://bugzilla.suse.com/1021251 https://bugzilla.suse.com/1021258 https://bugzilla.suse.com/1021260 https://bugzilla.suse.com/1021294 https://bugzilla.suse.com/1021424 https://bugzilla.suse.com/1021455 https://bugzilla.suse.com/1021474 https://bugzilla.suse.com/1021762 https://bugzilla.suse.com/1022181 https://bugzilla.suse.com/1022266 https://bugzilla.suse.com/1022304 https://bugzilla.suse.com/1022340 https://bugzilla.suse.com/1022429 https://bugzilla.suse.com/1022476 https://bugzilla.suse.com/1022547 https://bugzilla.suse.com/1022559 https://bugzilla.suse.com/1022595 https://bugzilla.suse.com/1022785 https://bugzilla.suse.com/1022971 https://bugzilla.suse.com/1023101 https://bugzilla.suse.com/1023175 https://bugzilla.suse.com/1023287 https://bugzilla.suse.com/1023762 https://bugzilla.suse.com/1023866 https://bugzilla.suse.com/1023884 https://bugzilla.suse.com/1023888 https://bugzilla.suse.com/1024015 https://bugzilla.suse.com/1024081 https://bugzilla.suse.com/1024234 https://bugzilla.suse.com/1024508 https://bugzilla.suse.com/1024938 https://bugzilla.suse.com/1025039 https://bugzilla.suse.com/1025235 https://bugzilla.suse.com/1025461 https://bugzilla.suse.com/1025683 https://bugzilla.suse.com/1026024 https://bugzilla.suse.com/1026405 https://bugzilla.suse.com/1026462 https://bugzilla.suse.com/1026505 https://bugzilla.suse.com/1026509 https://bugzilla.suse.com/1026570 https://bugzilla.suse.com/1026692 https://bugzilla.suse.com/1026722 https://bugzilla.suse.com/1027054 https://bugzilla.suse.com/1027066 https://bugzilla.suse.com/1027101 https://bugzilla.suse.com/1027153 https://bugzilla.suse.com/1027179 https://bugzilla.suse.com/1027189 https://bugzilla.suse.com/1027190 https://bugzilla.suse.com/1027195 https://bugzilla.suse.com/1027273 https://bugzilla.suse.com/1027512 https://bugzilla.suse.com/1027565 https://bugzilla.suse.com/1027616 https://bugzilla.suse.com/1027974 https://bugzilla.suse.com/1028017 https://bugzilla.suse.com/1028027 https://bugzilla.suse.com/1028041 https://bugzilla.suse.com/1028158 https://bugzilla.suse.com/1028217 https://bugzilla.suse.com/1028310 https://bugzilla.suse.com/1028325 https://bugzilla.suse.com/1028340 https://bugzilla.suse.com/1028372 https://bugzilla.suse.com/1028415 https://bugzilla.suse.com/1028819 https://bugzilla.suse.com/1028883 https://bugzilla.suse.com/1028895 https://bugzilla.suse.com/1029220 https://bugzilla.suse.com/1029514 https://bugzilla.suse.com/1029607 https://bugzilla.suse.com/1029634 https://bugzilla.suse.com/1029986 https://bugzilla.suse.com/1030057 https://bugzilla.suse.com/1030070 https://bugzilla.suse.com/1030118 https://bugzilla.suse.com/1030213 https://bugzilla.suse.com/1030573 https://bugzilla.suse.com/1031003 https://bugzilla.suse.com/1031040 https://bugzilla.suse.com/1031052 https://bugzilla.suse.com/1031142 https://bugzilla.suse.com/1031147 https://bugzilla.suse.com/1031200 https://bugzilla.suse.com/1031206 https://bugzilla.suse.com/1031208 https://bugzilla.suse.com/1031440 https://bugzilla.suse.com/1031470 https://bugzilla.suse.com/1031500 https://bugzilla.suse.com/1031512 https://bugzilla.suse.com/1031555 https://bugzilla.suse.com/1031579 https://bugzilla.suse.com/1031662 https://bugzilla.suse.com/1031717 https://bugzilla.suse.com/1031796 https://bugzilla.suse.com/1031831 https://bugzilla.suse.com/1032006 https://bugzilla.suse.com/1032141 https://bugzilla.suse.com/1032339 https://bugzilla.suse.com/1032345 https://bugzilla.suse.com/1032400 https://bugzilla.suse.com/1032581 https://bugzilla.suse.com/1032673 https://bugzilla.suse.com/1032681 https://bugzilla.suse.com/1032803 https://bugzilla.suse.com/1033117 https://bugzilla.suse.com/1033281 https://bugzilla.suse.com/1033287 https://bugzilla.suse.com/1033336 https://bugzilla.suse.com/1033340 https://bugzilla.suse.com/1033885 https://bugzilla.suse.com/1034048 https://bugzilla.suse.com/1034419 https://bugzilla.suse.com/1034635 https://bugzilla.suse.com/1034670 https://bugzilla.suse.com/1034671 https://bugzilla.suse.com/1034762 https://bugzilla.suse.com/1034902 https://bugzilla.suse.com/1034995 https://bugzilla.suse.com/1035024 https://bugzilla.suse.com/1035866 https://bugzilla.suse.com/1035887 https://bugzilla.suse.com/1035920 https://bugzilla.suse.com/1035922 https://bugzilla.suse.com/1036214 https://bugzilla.suse.com/1036638 https://bugzilla.suse.com/1036752 https://bugzilla.suse.com/1036763 https://bugzilla.suse.com/1037177 https://bugzilla.suse.com/1037186 https://bugzilla.suse.com/1037384 https://bugzilla.suse.com/1037483 https://bugzilla.suse.com/1037669 https://bugzilla.suse.com/1037840 https://bugzilla.suse.com/1037871 https://bugzilla.suse.com/1037969 https://bugzilla.suse.com/1038033 https://bugzilla.suse.com/1038043 https://bugzilla.suse.com/1038085 https://bugzilla.suse.com/1038142 https://bugzilla.suse.com/1038143 https://bugzilla.suse.com/1038297 https://bugzilla.suse.com/1038458 https://bugzilla.suse.com/1038544 https://bugzilla.suse.com/1038842 https://bugzilla.suse.com/1038843 https://bugzilla.suse.com/1038846 https://bugzilla.suse.com/1038847 https://bugzilla.suse.com/1038848 https://bugzilla.suse.com/1038879 https://bugzilla.suse.com/1038981 https://bugzilla.suse.com/1038982 https://bugzilla.suse.com/1039348 https://bugzilla.suse.com/1039354 https://bugzilla.suse.com/1039700 https://bugzilla.suse.com/1039864 https://bugzilla.suse.com/1039882 https://bugzilla.suse.com/1039883 https://bugzilla.suse.com/1039885 https://bugzilla.suse.com/1039900 https://bugzilla.suse.com/1040069 https://bugzilla.suse.com/1040125 https://bugzilla.suse.com/1040182 https://bugzilla.suse.com/1040279 https://bugzilla.suse.com/1040351 https://bugzilla.suse.com/1040364 https://bugzilla.suse.com/1040395 https://bugzilla.suse.com/1040425 https://bugzilla.suse.com/1040463 https://bugzilla.suse.com/1040567 https://bugzilla.suse.com/1040609 https://bugzilla.suse.com/1040855 https://bugzilla.suse.com/1040929 https://bugzilla.suse.com/1040941 https://bugzilla.suse.com/1041087 https://bugzilla.suse.com/1041160 https://bugzilla.suse.com/1041168 https://bugzilla.suse.com/1041242 https://bugzilla.suse.com/1041431 https://bugzilla.suse.com/1041810 https://bugzilla.suse.com/1042200 https://bugzilla.suse.com/1042286 https://bugzilla.suse.com/1042356 https://bugzilla.suse.com/1042421 https://bugzilla.suse.com/1042517 https://bugzilla.suse.com/1042535 https://bugzilla.suse.com/1042536 https://bugzilla.suse.com/1042863 https://bugzilla.suse.com/1042886 https://bugzilla.suse.com/1043014 https://bugzilla.suse.com/1043231 https://bugzilla.suse.com/1043236 https://bugzilla.suse.com/1043347 https://bugzilla.suse.com/1043371 https://bugzilla.suse.com/1043467 https://bugzilla.suse.com/1043488 https://bugzilla.suse.com/1043598 https://bugzilla.suse.com/1043912 https://bugzilla.suse.com/1043935 https://bugzilla.suse.com/1043990 https://bugzilla.suse.com/1044015 https://bugzilla.suse.com/1044082 https://bugzilla.suse.com/1044120 https://bugzilla.suse.com/1044125 https://bugzilla.suse.com/1044532 https://bugzilla.suse.com/1044767 https://bugzilla.suse.com/1044772 https://bugzilla.suse.com/1044854 https://bugzilla.suse.com/1044880 https://bugzilla.suse.com/1044912 https://bugzilla.suse.com/1045154 https://bugzilla.suse.com/1045235 https://bugzilla.suse.com/1045286 https://bugzilla.suse.com/1045307 https://bugzilla.suse.com/1045340 https://bugzilla.suse.com/1045467 https://bugzilla.suse.com/1045568 https://bugzilla.suse.com/1046105 https://bugzilla.suse.com/1046434 https://bugzilla.suse.com/1046589 https://bugzilla.suse.com/799133 https://bugzilla.suse.com/863764 https://bugzilla.suse.com/870618 https://bugzilla.suse.com/922871 https://bugzilla.suse.com/951844 https://bugzilla.suse.com/966170 https://bugzilla.suse.com/966172 https://bugzilla.suse.com/966191 https://bugzilla.suse.com/966321 https://bugzilla.suse.com/966339 https://bugzilla.suse.com/968697 https://bugzilla.suse.com/969479 https://bugzilla.suse.com/969755 https://bugzilla.suse.com/970083 https://bugzilla.suse.com/971975 https://bugzilla.suse.com/982783 https://bugzilla.suse.com/985561 https://bugzilla.suse.com/986362 https://bugzilla.suse.com/986365 https://bugzilla.suse.com/987192 https://bugzilla.suse.com/987576 https://bugzilla.suse.com/988065 https://bugzilla.suse.com/989056 https://bugzilla.suse.com/989311 https://bugzilla.suse.com/990058 https://bugzilla.suse.com/990682 https://bugzilla.suse.com/991273 https://bugzilla.suse.com/993832 https://bugzilla.suse.com/995542 https://bugzilla.suse.com/995968 https://bugzilla.suse.com/998106 From sle-security-updates at lists.suse.com Fri Jul 28 13:08:21 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 21:08:21 +0200 (CEST) Subject: SUSE-SU-2017:1997-1: moderate: Security update for apache2 Message-ID: <20170728190821.386C3FC3F@maintenance.suse.de> SUSE Security Update: Security update for apache2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1997-1 Rating: moderate References: #1041830 #1048576 #951692 Cross-References: CVE-2017-9788 Affected Products: SUSE Studio Onsite 1.3 SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update provides apache2 2.2.34, which brings many fixes and enhancements: Security issues fixed: - CVE-2017-9788: Uninitialized memory reflection in mod_auth_digest. (bsc#1048576) Bug fixes: - Remove /usr/bin/http2 link only during package uninstall, not upgrade. (bsc#1041830) - Don't put the backend in error state (by default) when 500/503 error code is overridden. (bsc#951692) - Allow single-char field names inadvertently disallowed in 2.2.32. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-apache2-13223=1 - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-apache2-13223=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-apache2-13223=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-apache2-13223=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.3 (x86_64): apache2-devel-2.2.34-70.5.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-devel-2.2.34-70.5.1 - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64): apache2-2.2.34-70.5.1 apache2-doc-2.2.34-70.5.1 apache2-example-pages-2.2.34-70.5.1 apache2-prefork-2.2.34-70.5.1 apache2-utils-2.2.34-70.5.1 apache2-worker-2.2.34-70.5.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-2.2.34-70.5.1 apache2-doc-2.2.34-70.5.1 apache2-example-pages-2.2.34-70.5.1 apache2-prefork-2.2.34-70.5.1 apache2-utils-2.2.34-70.5.1 apache2-worker-2.2.34-70.5.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): apache2-debuginfo-2.2.34-70.5.1 apache2-debugsource-2.2.34-70.5.1 References: https://www.suse.com/security/cve/CVE-2017-9788.html https://bugzilla.suse.com/1041830 https://bugzilla.suse.com/1048576 https://bugzilla.suse.com/951692 From sle-security-updates at lists.suse.com Fri Jul 28 13:09:08 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 21:09:08 +0200 (CEST) Subject: SUSE-SU-2017:1998-1: moderate: Security update for poppler Message-ID: <20170728190908.D58C9FF3A@maintenance.suse.de> SUSE Security Update: Security update for poppler ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1998-1 Rating: moderate References: #1042802 #1045719 #1045721 Cross-References: CVE-2017-9408 CVE-2017-9775 CVE-2017-9776 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for poppler fixes the following issues: Security issues fixed: - CVE-2017-9775: Fix a stack overflow bug in pdftocairo that could have been exploited in a denial of service attack through a specially crafted PDF document. (bsc#1045719) - CVE-2017-9776: Fix an integer overflow bug that could have been exploited in a denial of service attack through a specially crafted PDF document. (bsc#1045721) - CVE-2017-9408: Fix a memory leak that occurred when the parser tried to recover from a broken input file. (bsc#1042802) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2017-1236=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1236=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1236=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1236=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libpoppler44-0.24.4-14.6.1 libpoppler44-debuginfo-0.24.4-14.6.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libpoppler44-0.24.4-14.6.1 libpoppler44-debuginfo-0.24.4-14.6.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64): libpoppler44-0.24.4-14.6.1 libpoppler44-debuginfo-0.24.4-14.6.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libpoppler44-0.24.4-14.6.1 libpoppler44-debuginfo-0.24.4-14.6.1 References: https://www.suse.com/security/cve/CVE-2017-9408.html https://www.suse.com/security/cve/CVE-2017-9775.html https://www.suse.com/security/cve/CVE-2017-9776.html https://bugzilla.suse.com/1042802 https://bugzilla.suse.com/1045719 https://bugzilla.suse.com/1045721 From sle-security-updates at lists.suse.com Fri Jul 28 13:09:44 2017 From: sle-security-updates at lists.suse.com (sle-security-updates at lists.suse.com) Date: Fri, 28 Jul 2017 21:09:44 +0200 (CEST) Subject: SUSE-SU-2017:1999-1: moderate: Security update for poppler Message-ID: <20170728190944.362B7FC6C@maintenance.suse.de> SUSE Security Update: Security update for poppler ______________________________________________________________________________ Announcement ID: SUSE-SU-2017:1999-1 Rating: moderate References: #1041783 #1042802 #1042803 #1043088 #1045719 #1045721 Cross-References: CVE-2017-7511 CVE-2017-7515 CVE-2017-9406 CVE-2017-9408 CVE-2017-9775 CVE-2017-9776 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2 SUSE Linux Enterprise Desktop 12-SP3 SUSE Linux Enterprise Desktop 12-SP2 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for poppler fixes the following issues: Security issues fixed: - CVE-2017-9775: DoS stack buffer overflow in GfxState.cc in pdftocairo via a crafted PDF document (bsc#1045719) - CVE-2017-9776: DoS integer overflow leading to heap buffer overflow in JBIG2Stream.cc via a crafted PDF document (bsc#1045721) - CVE-2017-7515: Stack exhaustion due to infinite recursive call in pdfunite (bsc#1043088) - CVE-2017-7511: Null pointer dereference in pdfunite via crafted documents (bsc#1041783) - CVE-2017-9406: Memory leak in the gmalloc function in gmem.cc (bsc#1042803) - CVE-2017-9408: Memory leak in the Object::initArray function (bsc#1042802) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2017-1237=1 - SUSE Linux Enterprise Software Development Kit 12-SP2: zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-1237=1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2: zypper in -t patch SUSE-SLE-RPI-12-SP2-2017-1237=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1237=1 - SUSE Linux Enterprise Server 12-SP2: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-1237=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2017-1237=1 - SUSE Linux Enterprise Desktop 12-SP2: zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-1237=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libpoppler-cpp0-0.43.0-16.5.1 libpoppler-cpp0-debuginfo-0.43.0-16.5.1 libpoppler-devel-0.43.0-16.5.1 libpoppler-glib-devel-0.43.0-16.5.1 libpoppler-qt4-devel-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 typelib-1_0-Poppler-0_18-0.43.0-16.5.1 - SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 ppc64le s390x x86_64): libpoppler-cpp0-0.43.0-16.5.1 libpoppler-cpp0-debuginfo-0.43.0-16.5.1 libpoppler-devel-0.43.0-16.5.1 libpoppler-glib-devel-0.43.0-16.5.1 libpoppler-qt4-devel-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 typelib-1_0-Poppler-0_18-0.43.0-16.5.1 - SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (aarch64): libpoppler-glib8-0.43.0-16.5.1 libpoppler-glib8-debuginfo-0.43.0-16.5.1 libpoppler-qt4-4-0.43.0-16.5.1 libpoppler-qt4-4-debuginfo-0.43.0-16.5.1 libpoppler60-0.43.0-16.5.1 libpoppler60-debuginfo-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 poppler-tools-0.43.0-16.5.1 poppler-tools-debuginfo-0.43.0-16.5.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libpoppler-glib8-0.43.0-16.5.1 libpoppler-glib8-debuginfo-0.43.0-16.5.1 libpoppler-qt4-4-0.43.0-16.5.1 libpoppler-qt4-4-debuginfo-0.43.0-16.5.1 libpoppler60-0.43.0-16.5.1 libpoppler60-debuginfo-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 poppler-tools-0.43.0-16.5.1 poppler-tools-debuginfo-0.43.0-16.5.1 - SUSE Linux Enterprise Server 12-SP2 (aarch64 ppc64le s390x x86_64): libpoppler-glib8-0.43.0-16.5.1 libpoppler-glib8-debuginfo-0.43.0-16.5.1 libpoppler-qt4-4-0.43.0-16.5.1 libpoppler-qt4-4-debuginfo-0.43.0-16.5.1 libpoppler60-0.43.0-16.5.1 libpoppler60-debuginfo-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 poppler-tools-0.43.0-16.5.1 poppler-tools-debuginfo-0.43.0-16.5.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libpoppler-glib8-0.43.0-16.5.1 libpoppler-glib8-debuginfo-0.43.0-16.5.1 libpoppler-qt4-4-0.43.0-16.5.1 libpoppler-qt4-4-debuginfo-0.43.0-16.5.1 libpoppler60-0.43.0-16.5.1 libpoppler60-debuginfo-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 poppler-tools-0.43.0-16.5.1 poppler-tools-debuginfo-0.43.0-16.5.1 - SUSE Linux Enterprise Desktop 12-SP2 (x86_64): libpoppler-glib8-0.43.0-16.5.1 libpoppler-glib8-debuginfo-0.43.0-16.5.1 libpoppler-qt4-4-0.43.0-16.5.1 libpoppler-qt4-4-debuginfo-0.43.0-16.5.1 libpoppler60-0.43.0-16.5.1 libpoppler60-debuginfo-0.43.0-16.5.1 poppler-debugsource-0.43.0-16.5.1 poppler-qt-debugsource-0.43.0-16.5.1 poppler-tools-0.43.0-16.5.1 poppler-tools-debuginfo-0.43.0-16.5.1 References: https://www.suse.com/security/cve/CVE-2017-7511.html https://www.suse.com/security/cve/CVE-2017-7515.html https://www.suse.com/security/cve/CVE-2017-9406.html https://www.suse.com/security/cve/CVE-2017-9408.html https://www.suse.com/security/cve/CVE-2017-9775.html https://www.suse.com/security/cve/CVE-2017-9776.html https://bugzilla.suse.com/1041783 https://bugzilla.suse.com/1042802 https://bugzilla.suse.com/1042803 https://bugzilla.suse.com/1043088 https://bugzilla.suse.com/1045719 https://bugzilla.suse.com/1045721