summaryrefslogtreecommitdiffstats
path: root/kernel.spec
diff options
context:
space:
mode:
authorThorsten Leemhuis <fedora@leemhuis.info>2019-04-27 11:03:42 +0200
committerThorsten Leemhuis <fedora@leemhuis.info>2019-04-27 11:03:42 +0200
commit9e37f3e199d2639e6240fb0440953d95cc371ab2 (patch)
tree58f0b7a513efd0c1df283f97a877db06ce7b0c91 /kernel.spec
parent2b7854205d1184ec5e7db6b0f0954066d52f745b (diff)
parent30d7934dfed61b96fbe15adbd75cf629970d7737 (diff)
downloadkernel-9e37f3e199d2639e6240fb0440953d95cc371ab2.tar.gz
kernel-9e37f3e199d2639e6240fb0440953d95cc371ab2.tar.xz
kernel-9e37f3e199d2639e6240fb0440953d95cc371ab2.zip
Merge remote-tracking branch 'origin/f29' into f29-user-thl-vanilla-fedora
Diffstat (limited to 'kernel.spec')
-rw-r--r--kernel.spec33
1 files changed, 27 insertions, 6 deletions
diff --git a/kernel.spec b/kernel.spec
index cc99200c0..aa5660be4 100644
--- a/kernel.spec
+++ b/kernel.spec
@@ -556,8 +556,6 @@ Patch122: Input-synaptics-pin-3-touches-when-the-firmware-repo.patch
Patch201: efi-lockdown.patch
-Patch202: KEYS-Allow-unrestricted-boot-time-addition-of-keys-t.patch
-
# bz 1497559 - Make kernel MODSIGN code not error on missing variables
Patch207: 0001-Make-get_cert_list-not-complain-about-cert-lists-tha.patch
Patch208: 0002-Add-efi_status_to_str-and-rework-efi_status_to_err.patch
@@ -628,15 +626,25 @@ Patch514: v3-tpm-fix-an-invalid-condition-in-tpm_common_poll.patch
# rhbz 1683382
Patch515: nfsv4.1-avoid-false-retries.patch
-# CVE-2019-9857 rhbz 1694758 1694759
-Patch516: 0001-inotify-Fix-fsnotify_mark-refcount-leak-in-inotify_u.patch
-
# CVE-2019-3882 rhbz 1689426 1695571
Patch517: vfio-type1-limit-dma-mappings-per-container.patch
# CVE-2019-9500 rhbz 1701224 1701226
Patch518: 0001-brcmfmac-assure-SSID-length-from-firmware-is-limited.patch
+# rhbz 1701077
+Patch519: nfsd-wake-waiters-blocked-on-file_lock-before-deleting-it.patch
+
+# CVE-2019-9503 rhbz 1701842 1701843
+Patch520: 0001-brcmfmac-add-subtype-check-for-event-handling-in-dat.patch
+
+# https://bugzilla.redhat.com/show_bug.cgi?id=1701096
+# Submitted upstream at https://lkml.org/lkml/2019/4/23/89
+Patch521: KEYS-Make-use-of-platform-keyring-for-module-signature.patch
+
+# CVE-2019-3900 rhbz 1698757 1702940
+Patch524: net-vhost_net-fix-possible-infinite-loop.patch
+
# END OF PATCH DEFINITIONS
%endif
@@ -1913,8 +1921,21 @@ fi
#
#
%changelog
+* Thu Apr 25 2019 Justin M. Forbes <jforbes@fedoraproject.org>
+- Fix CVE-2019-3900 (rhbz 1698757 1702940)
+
+* Tue Apr 23 2019 Jeremy Cline <jcline@redhat.com>
+- Allow modules signed by keys in the platform keyring (rbhz 1701096)
+
+* Tue Apr 23 2019 Justin M. Forbes <jforbes@fedoraproject.org>
+- Fix CVE-2019-9503 rhbz 1701842 1701843
+
+* Mon Apr 22 2019 Laura Abbott <labbott@redhat.com> - 5.0.9-200
+- Linux v5.0.9
+- Fix NFS server crash (rhbz 1701077)
+
* Thu Apr 18 2019 Justin M. Forbes <jforbes@fedoraproject.org>
-- Fix CVE-2019-9500 (rhbz 1701224 1701226)
+- Fix CVE-2019-9500 (rhbz 1701224 1701225)
* Wed Apr 17 2019 Laura Abbott <labbott@redhat.com> - 5.0.8-200
- Linux v5.0.8