Commit Graph

139 Commits

Author SHA1 Message Date
Chuck Ebbert dda4c8ded1 bridge: Fix mglist corruption that leads to memory corruption (#650151) 2011-02-12 11:06:04 -05:00
Matthew Garrett 786d460759 - linux-2.6-acpi-fix-alias.patch: fix ACPI object aliasing (#608648) 2011-02-09 12:12:47 -05:00
Chuck Ebbert d9bdee82eb Linux 2.6.34.8 2011-02-05 10:38:36 -05:00
Kyle McMartin 365577d418 Revert "hostap_cs-fix-sleeping-function-called-from-invalid-context.patch"
... Apparently I already sucked it in. Doh.

This reverts commit 7c8aa2a2c4.
2011-01-31 12:29:52 -05:00
Kyle McMartin 7c8aa2a2c4 hostap_cs-fix-sleeping-function-called-from-invalid-context.patch
from Stanislaw Gruszka
2011-01-31 12:25:58 -05:00
Chuck Ebbert 455ee889cb Copy sunrpc oops fix from F14 2011-01-30 22:46:59 -05:00
Chuck Ebbert f4a2bd612d CVE-2011-0521: av7110 negative array offset 2011-01-26 12:20:30 -05:00
Chuck Ebbert 8cb12224b9 add missing files from previous commit 2011-01-26 09:59:03 -05:00
Chuck Ebbert c5251bc7fb TCP networking fixes from 2.6.36.3, including one CVE
CVE-2010-4165: possible kernel oops from user MSS
2011-01-26 09:58:08 -05:00
Chuck Ebbert ce15d645be Security updates
CVE-2010-4346: install_special_mapping skips security_file_mmap check
  CVE-2010-4649: IB/uverbs: Handle large number of entries in poll CQ
  CVE-2011-0006: ima: fix add LSM rule bug
  CVE-2010-4648: orinoco: fix TKIP countermeasure behaviour
  CVE-2010-4650: fuse: verify ioctl retries
2011-01-22 12:25:37 -05:00
Kyle McMartin a96313e196 hostap_cs-fix-sleeping-function-called-from-invalid-context.patch 2011-01-18 14:55:33 -05:00
Chuck Ebbert 16efe059d7 CVE-2010-4163 CVE-2010-4668: panic when submitting 0-length I/O requests 2011-01-10 09:25:06 -05:00
Kyle McMartin 5bd23aa290 fs-call-security_d_instantiate-in-d_obtain_alias (#662344) 2010-12-18 10:58:03 -05:00
Neil Horman 7907a3cd74 Enhance AF_PACKET to support using non-contiguous memory when allocating ring
buffer space.  This is a combined backport of the following commits from
net-next-2.6:
0e3125c755445664f00ad036e4fc2cd32fd52877
bbce5a59e4e0e6e1dbc85492caaf310ff6611309
0af55bb58f8fa7865004ac48d16affe125ac1b7f
920b8d913bd3d963d5c88bca160a272b71e0c95a

Resolves: bz637619
2010-12-17 13:35:36 -05:00
Chuck Ebbert 736de833de bump version 2010-12-15 01:33:16 -05:00
Chuck Ebbert 88a3381ac4 CVE-2010-3874: CAN sockets minor heap overflow 2010-12-15 01:21:28 -05:00
Chuck Ebbert 60a8a27c70 CVE-2010-4158 socket filters infoleak 2010-12-15 01:18:23 -05:00
Chuck Ebbert d7c19e06c0 CVE-2010-4157 gdth: integer overflow in ioc_general() 2010-12-14 20:09:28 -05:00
Chuck Ebbert 45a782f6d3 bump version 2010-12-14 09:13:06 -05:00
Chuck Ebbert 7a0a7db74d CVE-2010-4249 unix socket local dos 2010-12-14 08:54:54 -05:00
Chuck Ebbert 16bd76171d CVE-2010-4162 bio: integer overflow page count when mapping/copying user data 2010-12-14 08:40:24 -05:00
Chuck Ebbert 4d7c6b9018 minor specfile cleanup 2010-12-14 08:35:54 -05:00
Chuck Ebbert 6685a27880 CVE-2010-4169: perf_events: denial-of-service bug 2010-12-10 22:34:55 -05:00
Chuck Ebbert ed56c73082 CVE-2010-4258: failure to revert address limit override in OOPS error path 2010-12-10 22:25:38 -05:00
Chuck Ebbert fa44e9fd9f CVE-2010-3442: ALSA: prevent heap corruption in snd_ctl_new() 2010-12-10 17:06:38 -05:00
Chuck Ebbert 2c7b199d8c CVE-2010-3705: sctp: Fix out-of-bounds reading in sctp_asoc_get_hmac() 2010-12-10 17:01:14 -05:00
Chuck Ebbert 31ece0102d CVE-2010-3698: kvm: invalid selector in fs/gs causes kernel panic 2010-12-10 15:00:12 -05:00
Chuck Ebbert 5cef509b77 CVE-2010-2963: v4l: VIDIOCSMICROCODE arbitrary write 2010-12-10 14:53:22 -05:00
Chuck Ebbert c140072f7f CVE-2010-2962: arbitrary kernel memory write via i915 GEM ioctl 2010-12-10 14:47:45 -05:00
Kyle McMartin 7dec002956 use old macros in ioat2-catch-and-recover-from-broken-vtd-configurations.patch 2010-12-10 12:48:32 -05:00
Kyle McMartin 4b57f309c7 ioat2: catch and recover from broken vtd configurations v6 2010-12-09 17:53:54 -05:00
Kyle McMartin 4038895354 add patch missing from previous commit (Doh) 2010-12-09 17:10:00 -05:00
Kyle McMartin fd3a50f30a Copy tpm-fix-stall-on-boot.patch from rawhide tree. (#530393) 2010-12-09 17:09:29 -05:00
Kyle McMartin de118fdb83 drm/radeon/kms: MC vram map needs to be >= pci aperture size (#632310) 2010-12-09 12:52:01 -05:00
Kyle McMartin ce005fe2dc enable hpilo.ko on x86_64 2010-12-03 07:06:19 -05:00
Kyle McMartin c1c4696c55 allow ima to be opt-in like in f14 2010-11-29 22:22:51 -05:00
Kyle McMartin 9d066c5537 fix the korg bug with xfs backports 2010-11-29 22:17:46 -05:00
Kyle McMartin bc35d5cf3a quiet a build warning the INET_DIAG fix caused 2010-11-26 15:17:29 -05:00
Kyle McMartin ebd7718e1d plug various tty/serial stack leaks 2010-11-26 15:07:24 -05:00
kyle 081d17d5e9 ditto from every other branch 2010-11-26 11:41:06 -05:00
kyle 4dbe3951c0 r8169 fixes from sgruszka@redhat.com 2010-11-26 11:40:07 -05:00
John W. Linville 3e45ced8ed rtl8180: improve signal reporting for rtl8185 hardware
rtl8180: improve signal reporting for actual rtl8180 hardware
2010-11-24 10:54:37 -05:00
Kyle McMartin dcba3e47ae clear memory in viafb ioctl (CVE-2010-4082) 2010-11-23 12:14:16 -05:00
Kyle McMartin 54c8f25d8d posix-cpu-timers: workaround to suppress the problems with mt exec (rhbz#656264) 2010-11-23 11:37:56 -05:00
Kyle McMartin 92cce7f8f6 fix logic error in INET_DIAG bytecode auditing (CVE-2010-3880) 2010-11-23 11:14:11 -05:00
Kyle McMartin c35eb60a60 zero struct memory in ipc shm (CVE-2010-4072) 2010-11-23 10:59:21 -05:00
Kyle McMartin 9e245ead59 initialize struct memory to zero in ipc compat (CVE-2010-4073) 2010-11-23 10:12:48 -05:00
Kyle McMartin 8394f9abcf fix some tpm, rt2x00, and an rds security vulnerability 2010-10-22 10:43:01 -04:00
Kyle McMartin d5bf5dcc70 build 2.6.34.7-61 2010-10-18 23:36:07 -04:00
Kyle McMartin 4663ea7ac2 dmar: print a useful message when quirking iommu off 2010-10-18 22:44:09 -04:00