Security update for the Linux Kernel

Announcement ID: SUSE-SU-2018:3689-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2018-14633 ( SUSE ): 8.8 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2018-14633 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • CVE-2018-14633 ( NVD ): 7.0 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • CVE-2018-18281 ( SUSE ): 5.6 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  • CVE-2018-18281 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • CVE-2018-18386 ( SUSE ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • CVE-2018-18386 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  • CVE-2018-18690 ( SUSE ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • CVE-2018-18690 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • CVE-2018-18710 ( SUSE ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVE-2018-18710 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVE-2018-9516 ( SUSE ): 6.7 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • CVE-2018-9516 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
  • SUSE CaaS Platform 3.0
  • SUSE Container as a Service Platform 1.0
  • SUSE Container as a Service Platform 2.0
  • SUSE Linux Enterprise Desktop 12 SP3
  • SUSE Linux Enterprise High Availability Extension 12 SP3
  • SUSE Linux Enterprise High Performance Computing 12 SP3
  • SUSE Linux Enterprise Live Patching 12-SP3
  • SUSE Linux Enterprise Server 12 SP3
  • SUSE Linux Enterprise Server for SAP Applications 12 SP3
  • SUSE Linux Enterprise Software Bootstrap Kit 12 12-SP3
  • SUSE Linux Enterprise Software Development Kit 12 SP3
  • SUSE Linux Enterprise Workstation Extension 12 12-SP3

An update that solves six vulnerabilities and has 100 security fixes can now be installed.

Description:

The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.162 to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2018-14633: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. (bnc#1107829).
  • CVE-2018-18281: The mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. (bnc#1113769).
  • CVE-2018-18386: drivers/tty/n_tty.c allowed local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ (bnc#1094825).
  • CVE-2018-18690: A local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandled ATTR_REPLACE operations with conversion of an attr from short to long form (bnc#1105025).
  • CVE-2018-18710: An issue was discovered in the Linux kernel An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940 and CVE-2018-16658 (bnc#1113751).
  • CVE-2018-9516: A lack of certain checks in the hid_debug_events_read() function in the drivers/hid/hid-debug.c file might have resulted in receiving userspace buffer overflow and an out-of-bounds write or to the infinite loop. (bnc#1108498).

The following non-security bugs were fixed:

  • 6lowpan: iphc: reset mac_header after decompress to fix panic (bnc#1012382).
  • alsa: bebob: use address returned by kmalloc() instead of kernel stack for streaming DMA mapping (bnc#1012382).
  • alsa: emu10k1: fix possible info leak to userspace on SNDRV_EMU10K1_IOCTL_INFO (bnc#1012382).
  • alsa: hda: Add AZX_DCAPS_PM_RUNTIME for AMD Raven Ridge (bnc#1012382).
  • alsa: hda - Fix cancel_work_sync() stall from jackpoll work (bnc#1012382).
  • alsa: hda/realtek - Cannot adjust speaker's volume on Dell XPS 27 7760 (bnc#1012382).
  • alsa: msnd: Fix the default sample sizes (bnc#1012382).
  • alsa: pcm: Fix snd_interval_refine first/last with open min/max (bnc#1012382).
  • alsa: usb-audio: Fix multiple definitions in AU0828_DEVICE() macro (bnc#1012382).
  • apparmor: remove no-op permission check in policy_unpack (git-fixes).
  • arc: build: Get rid of toolchain check (bnc#1012382).
  • arc: clone syscall to setp r25 as thread pointer (bnc#1012382).
  • arch/hexagon: fix kernel/dma.c build warning (bnc#1012382).
  • arc: [plat-axs*]: Enable SWAP (bnc#1012382).
  • arm64: bpf: jit JMP_JSET_{X,K} (bsc#1110613).
  • arm64: Correct type for PUD macros (bsc#1110600).
  • arm64: cpufeature: Track 32bit EL0 support (bnc#1012382).
  • arm64: dts: qcom: db410c: Fix Bluetooth LED trigger (bnc#1012382).
  • arm64: fix erroneous __raw_read_system_reg() cases (bsc#1110606).
  • arm64: Fix potential race with hardware DBM in ptep_set_access_flags() (bsc#1110605).
  • arm64: fpsimd: Avoid FPSIMD context leakage for the init task (bsc#1110603).
  • arm64: jump_label.h: use asm_volatile_goto macro instead of "asm goto" (bnc#1012382).
  • arm64: kasan: avoid bad virt_to_pfn() (bsc#1110612).
  • arm64: kasan: avoid pfn_to_nid() before page array is initialized (bsc#1110619).
  • arm64/kasan: do not allocate extra shadow memory (bsc#1110611).
  • arm64: kernel: Update kerneldoc for cpu_suspend() rename (bsc#1110602).
  • arm64: kgdb: handle read-only text / modules (bsc#1110604).
  • arm64: kvm: Sanitize PSTATE.M when being set from userspace (bnc#1012382).
  • arm64: kvm: Tighten guest core register access from userspace (bnc#1012382).
  • arm64/mm/kasan: do not use vmemmap_populate() to initialize shadow (bsc#1110618).
  • arm64: ptrace: Avoid setting compat FP[SC]R to garbage if get_user fails (bsc#1110601).
  • arm64: supported.conf: mark armmmci as not supported
  • arm64 Update config files. (bsc#1110468) Set MMC_QCOM_DML to build-in and delete driver from supported.conf
  • arm64: vdso: fix clock_getres for 4GiB-aligned res (bsc#1110614).
  • arm: dts: at91: add new compatibility string for macb on sama5d3 (bnc#1012382).
  • arm: dts: dra7: fix DCAN node addresses (bnc#1012382).
  • arm: exynos: Clear global variable on init error path (bnc#1012382).
  • arm: hisi: check of_iomap and fix missing of_node_put (bnc#1012382).
  • arm: hisi: fix error handling and missing of_node_put (bnc#1012382).
  • arm: hisi: handle of_iomap and fix missing of_node_put (bnc#1012382).
  • arm: mvebu: declare asm symbols as character arrays in pmsu.c (bnc#1012382).
  • ASoC: cs4265: fix MMTLR Data switch control (bnc#1012382).
  • ASoC: dapm: Fix potential DAI widget pointer deref when linking DAIs (bnc#1012382).
  • ASoC: sigmadsp: safeload should not have lower byte limit (bnc#1012382).
  • ASoC: wm8804: Add ACPI support (bnc#1012382).
  • ata: libahci: Correct setting of DEVSLP register (bnc#1012382).
  • ath10k: disable bundle mgmt tx completion event support (bnc#1012382).
  • ath10k: fix scan crash due to incorrect length calculation (bnc#1012382).
  • ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait (bnc#1012382).
  • ath10k: prevent active scans on potential unusable channels (bnc#1012382).
  • ath10k: protect ath10k_htt_rx_ring_free with rx_ring.lock (bnc#1012382).
  • audit: fix use-after-free in audit_add_watch (bnc#1012382).
  • autofs: fix autofs_sbi() does not check super block type (bnc#1012382).
  • binfmt_elf: Respect error return from `regset->active' (bnc#1012382).
  • bluetooth: Add a new Realtek 8723DE ID 0bda:b009 (bnc#1012382).
  • bluetooth: h5: Fix missing dependency on BT_HCIUART_SERDEV (bnc#1012382).
  • bluetooth: hidp: Fix handling of strncpy for hid->name information (bnc#1012382).
  • bnxt_en: Fix TX timeout during netpoll (bnc#1012382).
  • bonding: avoid possible dead-lock (bnc#1012382).
  • bpf: fix cb access in socket filter programs on tail calls (bsc#1012382).
  • bpf: fix map not being uncharged during map creation failure (bsc#1012382).
  • bpf, s390: fix potential memleak when later bpf_jit_prog fails (git-fixes).
  • bpf, s390x: do not reload skb pointers in non-skb context (git-fixes).
  • bsc#1106913: Replace with upstream variants
  • btrfs: add a comp_refs() helper (dependency for bsc#1031392).
  • btrfs: add missing initialization in btrfs_check_shared (Git-fixes bsc#1112262).
  • btrfs: add tracepoints for outstanding extents mods (dependency for bsc#1031392).
  • btrfs: add wrapper for counting BTRFS_MAX_EXTENT_SIZE (dependency for bsc#1031392).
  • btrfs: cleanup extent locking sequence (dependency for bsc#1031392).
  • btrfs: defrag: use btrfs_mod_outstanding_extents in cluster_pages_for_defrag (Follow up fixes for bsc#1031392).
  • btrfs: delayed-inode: Remove wrong qgroup meta reservation calls (bsc#1031392).
  • btrfs: delayed-inode: Use new qgroup meta rsv for delayed inode and item (bsc#1031392).
  • btrfs: Enhance btrfs_trim_fs function to handle error better (Dependency for bsc#1113667).
  • btrfs: Ensure btrfs_trim_fs can trim the whole filesystem (bsc#1113667).
  • btrfs: fix error handling in btrfs_dev_replace_start (bsc#1107535).
  • btrfs: fix invalid attempt to free reserved space on failure to cow range (dependency for bsc#1031392).
  • btrfs: fix missing error return in btrfs_drop_snapshot (Git-fixes bsc#1109919).
  • btrfs: Fix race condition between delayed refs and blockgroup removal (Git-fixes bsc#1112263).
  • btrfs: Fix wrong btrfs_delalloc_release_extents parameter (bsc#1031392).
  • btrfs: kill trans in run_delalloc_nocow and btrfs_cross_ref_exist (dependency for bsc#1031392).
  • btrfs: make the delalloc block rsv per inode (dependency for bsc#1031392).
  • btrfs: pass delayed_refs directly to btrfs_find_delayed_ref_head (dependency for bsc#1031392).
  • btrfs: qgroup: Add quick exit for non-fs extents (dependency for bsc#1031392).
  • btrfs: qgroup: Cleanup btrfs_qgroup_prepare_account_extents function (dependency for bsc#1031392).
  • btrfs: qgroup: Cleanup the remaining old reservation counters (bsc#1031392).
  • btrfs: qgroup: Commit transaction in advance to reduce early EDQUOT (bsc#1031392).
  • btrfs: qgroup: Do not use root->qgroup_meta_rsv for qgroup (bsc#1031392).
  • btrfs: qgroup: Fix wrong qgroup reservation update for relationship modification (bsc#1031392).
  • btrfs: qgroup: Introduce function to convert META_PREALLOC into META_PERTRANS (bsc#1031392).
  • btrfs: qgroup: Introduce helpers to update and access new qgroup rsv (bsc#1031392).
  • btrfs: qgroup: Make qgroup_reserve and its callers to use separate reservation type (bsc#1031392).
  • btrfs: qgroup: Skeleton to support separate qgroup reservation type (bsc#1031392).
  • btrfs: qgroups: opencode qgroup_free helper (dependency for bsc#1031392).
  • btrfs: qgroup: Split meta rsv type into meta_prealloc and meta_pertrans (bsc#1031392).
  • btrfs: qgroup: Update trace events for metadata reservation (bsc#1031392).
  • btrfs: qgroup: Update trace events to use new separate rsv types (bsc#1031392).
  • btrfs: qgroup: Use independent and accurate per inode qgroup rsv (bsc#1031392).
  • btrfs: qgroup: Use root::qgroup_meta_rsv_* to record qgroup meta reserved space (bsc#1031392).
  • btrfs: qgroup: Use separate meta reservation type for delalloc (bsc#1031392).
  • btrfs: remove type argument from comp_tree_refs (dependency for bsc#1031392).
  • btrfs: rework outstanding_extents (dependency for bsc#1031392).
  • btrfs: switch args for comp_*_refs (dependency for bsc#1031392).
  • btrfs: Take trans lock before access running trans in check_delayed_ref (Follow up fixes for bsc#1031392).
  • ceph: avoid a use-after-free in ceph_destroy_options() (bsc#1112007).
  • cfg80211: fix a type issue in ieee80211_chandef_to_operating_class() (bnc#1012382).
  • cfg80211: nl80211_update_ft_ies() to validate NL80211_ATTR_IE (bnc#1012382).
  • cfq: Give a chance for arming slice idle timer in case of group_idle (bnc#1012382).
  • cgroup: Fix deadlock in cpu hotplug path (bnc#1012382).
  • cgroup, netclassid: add a preemption point to write_classid (bnc#1098996).
  • cifs: check for STATUS_USER_SESSION_DELETED (bsc#1112902).
  • cifs: connect to servername instead of IP for IPC$ share (bsc#1106359).
  • cifs: fix memory leak in SMB2_open() (bsc#1112894).
  • cifs: Fix use after free of a mid_q_entry (bsc#1112903).
  • cifs: fix wrapping bugs in num_entries() (bnc#1012382).
  • cifs: integer overflow in in SMB2_ioctl() (bsc#1012382).
  • cifs: prevent integer overflow in nxt_dir_entry() (bnc#1012382).
  • cifs: read overflow in is_valid_oplock_break() (bnc#1012382).
  • clk: imx6ul: fix missing of_node_put() (bnc#1012382).
  • clocksource/drivers/ti-32k: Add CLOCK_SOURCE_SUSPEND_NONSTOP flag for non-am43 SoCs (bnc#1012382).
  • config.sh: set BUGZILLA_PRODUCT for SLE12-SP3
  • coresight: Handle errors in finding input/output ports (bnc#1012382).
  • coresight: tpiu: Fix disabling timeouts (bnc#1012382).
  • cpu/hotplug: Fix SMT supported evaluation (bsc#1089343).
  • crypto: mxs-dcp - Fix wait logic on chan threads (bnc#1012382).
  • crypto: sharah - Unregister correct algorithms for SAHARA 3 (bnc#1012382).
  • crypto: skcipher - Fix -Wstringop-truncation warnings (bnc#1012382).
  • Define dependencies of in-kernel KMPs statically This allows us to use rpm's internal dependency generator (bsc#981083).
  • Define early_radix_enabled() (bsc#1094244).
  • dmaengine: pl330: fix irq race with terminate_all (bnc#1012382).
  • dm cache: fix resize crash if user does not reload cache table (bnc#1012382).
  • dm thin metadata: fix __udivdi3 undefined on 32-bit (bnc#1012382).
  • dm thin metadata: try to avoid ever aborting transactions (bnc#1012382).
  • Do not ship firmware (bsc#1054239). Pull firmware from kernel-firmware instead.
  • drivers: net: cpsw: fix parsing of phy-handle DT property in dual_emac config (bnc#1012382).
  • drivers: net: cpsw: fix segfault in case of bad phy-handle (bnc#1012382).
  • drivers/tty: add error handling for pcmcia_loop_config (bnc#1012382).
  • drm/amdgpu: Fix SDMA HQD destroy error on gfx_v7 (bnc#1012382).
  • drm/amdkfd: Fix error codes in kfd_get_process (bnc#1012382).
  • drm/nouveau/drm/nouveau: Use pm_runtime_get_noresume() in connector_detect() (bnc#1012382).
  • drm/nouveau/TBDdevinit: do not fail when PMU/PRE_OS is missing from VBIOS (bnc#1012382).
  • drm/nouveau: tegra: Detach from ARM DMA/IOMMU mapping (bnc#1012382).
  • drm/virtio: fix bounds check in virtio_gpu_cmd_get_capset() (bsc#1106929)
  • Drop dtb-source.spec and move the sources to kernel-source (bsc#1011920)
  • e1000: check on netif_running() before calling e1000_up() (bnc#1012382).
  • e1000: ensure to free old tx/rx rings in set_ringparam() (bnc#1012382).
  • ebtables: arpreply: Add the standard target sanity check (bnc#1012382).
  • edac, thunderx: Fix memory leak in thunderx_l2c_threaded_isr() (bsc#1114648).
  • ethernet: ti: davinci_emac: add missing of_node_put after calling of_parse_phandle (bnc#1012382).
  • ethtool: Remove trailing semicolon for static inline (bnc#1012382).
  • ethtool: restore erroneously removed break in dev_ethtool (bsc#1114229).
  • ext4: avoid divide by zero fault when deleting corrupted inline directories (bnc#1012382).
  • ext4: do not mark mmp buffer head dirty (bnc#1012382).
  • ext4: fix online resize's handling of a too-small final block group (bnc#1012382).
  • ext4: fix online resizing for bigalloc file systems with a 1k block size (bnc#1012382).
  • ext4: recalucate superblock checksum after updating free blocks/inodes (bnc#1012382).
  • f2fs: do not set free of current section (bnc#1012382).
  • f2fs: fix to do sanity check with {sit,nat}_ver_bitmap_bytesize (bnc#1012382).
  • fbdev: Distinguish between interlaced and progressive modes (bnc#1012382).
  • fbdev: fix broken menu dependencies (bsc#1106929)
  • fbdev/omapfb: fix omapfb_memory_read infoleak (bnc#1012382).
  • fbdev/via: fix defined but not used warning (bnc#1012382).
  • floppy: Do not copy a kernel pointer to user memory in FDGETPRM ioctl (bnc#1012382).
  • fs/cifs: do not translate SFM_SLASH (U+F026) to backslash (bnc#1012382).
  • fs/cifs: suppress a string overflow warning (bnc#1012382).
  • fs/eventpoll: loosen irq-safety when possible (bsc#1096052).
  • gfs2: Special-case rindex for gfs2_grow (bnc#1012382).
  • gpio: adp5588: Fix sleep-in-atomic-context bug (bnc#1012382).
  • gpiolib: Mark gpio_suffixes array with __maybe_unused (bnc#1012382).
  • gpio: ml-ioh: Fix buffer underwrite on probe error path (bnc#1012382).
  • gpio: tegra: Move driver registration to subsys_init level (bnc#1012382).
  • gso_segment: Reset skb->mac_len after modifying network header (bnc#1012382).
  • hexagon: modify ffs() and fls() to return int (bnc#1012382).
  • hid: hid-ntrig: add error handling for sysfs_create_group (bnc#1012382).
  • hid: sony: Support DS4 dongle (bnc#1012382).
  • hid: sony: Update device ids (bnc#1012382).
  • hv: avoid crash in vmbus sysfs files (bnc#1108377).
  • hwmon: (adt7475) Make adt7475_read_word() return errors (bnc#1012382).
  • hwmon: (ina2xx) fix sysfs shunt resistor read access (bnc#1012382).
  • i2c: i2c-scmi: fix for i2c_smbus_write_block_data (bnc#1012382).
  • i2c: i801: Allow ACPI AML access I/O ports not reserved for SMBus (bnc#1012382).
  • i2c: i801: fix DNV's SMBCTRL register offset (bnc#1012382).
  • i2c: uniphier-f: issue STOP only for last message or I2C_M_STOP (bnc#1012382).
  • i2c: uniphier: issue STOP only for last message or I2C_M_STOP (bnc#1012382).
  • i2c: xiic: Make the start and the byte count write atomic (bnc#1012382).
  • i2c: xlp9xx: Add support for SMBAlert (bsc#1103308).
  • i2c: xlp9xx: Fix case where SSIF read transaction completes early (bsc#1103308).
  • i2c: xlp9xx: Fix issue seen when updating receive length (bsc#1103308).
  • i2c: xlp9xx: Make sure the transfer size is not more than I2C_SMBUS_BLOCK_SIZE (bsc#1103308).
  • ib/ipoib: Avoid a race condition between start_xmit and cm_rep_handler (bnc#1012382).
  • ib/srp: Avoid that sg_reset -d ${srp_device} triggers an infinite loop (bnc#1012382).
  • input: atakbd - fix Atari CapsLock behaviour (bnc#1012382).
  • input: atakbd - fix Atari keymap (bnc#1012382).
  • input: atmel_mxt_ts - only use first T9 instance (bnc#1012382).
  • input: elantech - enable middle button of touchpad on ThinkPad P72 (bnc#1012382).
  • iommu/amd: Return devid as alias for ACPI HID devices (bsc#1106105).
  • iommu/arm-smmu-v3: sync the OVACKFLG to PRIQ consumer register (bnc#1012382).
  • iommu/ipmmu-vmsa: Fix allocation in atomic context (bnc#1012382).
  • ip6_tunnel: be careful when accessing the inner header (bnc#1012382).
  • ipmi:ssif: Add support for multi-part transmit messages > 2 parts (bsc#1103308).
  • ip_tunnel: be careful when accessing the inner header (bnc#1012382).
  • ipv4: fix use-after-free in ip_cmsg_recv_dstaddr() (bnc#1012382).
  • ipv6: fix possible use-after-free in ip6_xmit() (bnc#1012382).
  • iw_cxgb4: only allow 1 flush on user qps (bnc#1012382).
  • ixgbe: pci_set_drvdata must be called before register_netdev (Git-fixes bsc#1109923).
  • jffs2: return -ERANGE when xattr buffer is too small (bnc#1012382).
  • KABI: move the new handler to end of machdep_calls and hide it from genksyms (bsc#1094244).
  • kABI: protect struct hnae_desc_cb (kabi).
  • kbuild: add .DELETE_ON_ERROR special target (bnc#1012382).
  • kernel-obs-build.spec.in: add --no-hostonly-cmdline to dracut invocation (boo#1062303). call dracut with --no-hostonly-cmdline to avoid the random rootfs UUID being added into the initrd's /etc/cmdline.d/95root-dev.conf
  • kernel-obs-build: use pae and lpae kernels where available (bsc#1073579).
  • kernel/params.c: downgrade warning for unsafe parameters (bsc#1050549).
  • kprobes/x86: Release insn_slot in failure path (bsc#1110006).
  • kthread: fix boot hang (regression) on MIPS/OpenRISC (bnc#1012382).
  • kthread: Fix use-after-free if kthread fork fails (bnc#1012382).
  • kvm: nVMX: Do not expose MPX VMX controls when guest MPX disabled (bsc#1106240).
  • kvm: nVMX: Do not flush TLB when vmcs12 uses VPID (bsc#1106240).
  • kvm: PPC: Book3S HV: Do not truncate HPTE index in xlate function (bnc#1012382).
  • kvm: x86: Do not re-{try,execute} after failed emulation in L2 (bsc#1106240).
  • kvm: x86: Do not use kvm_x86_ops->mpx_supported() directly (bsc#1106240).
  • kvm: x86: fix APIC page invalidation (bsc#1106240).
  • kvm: x86: remove eager_fpu field of struct kvm_vcpu_arch (bnc#1012382).
  • kvm/x86: remove WARN_ON() for when vm_munmap() fails (bsc#1106240).
  • kvm: x86: SVM: Call x86_spec_ctrl_set_guest/host() with interrupts disabled (bsc#1106240).
  • lib/test_hexdump.c: fix failure on big endian cpu (bsc#1106110).
  • locking/osq_lock: Fix osq_lock queue corruption (bnc#1012382).
  • locking/rwsem-xadd: Fix missed wakeup due to reordering of load (bnc#1012382).
  • lpfc: fixup crash in lpfc_els_unsol_buffer() (bsc#1107318).
  • mac80211: correct use of IEEE80211_VHT_CAP_RXSTBC_X (bnc#1012382).
  • mac80211: fix a race between restart and CSA flows (bnc#1012382).
  • mac80211: fix setting IEEE80211_KEY_FLAG_RX_MGMT for AP mode keys (bnc#1012382).
  • mac80211: Fix station bandwidth setting after channel switch (bnc#1012382).
  • mac80211_hwsim: correct use of IEEE80211_VHT_CAP_RXSTBC_X (bnc#1012382).
  • mac80211: mesh: fix HWMP sequence numbering to follow standard (bnc#1012382).
  • mac80211: restrict delayed tailroom needed decrement (bnc#1012382).
  • mac80211: shorten the IBSS debug messages (bnc#1012382).
  • mach64: detect the dot clock divider correctly on sparc (bnc#1012382).
  • macintosh/via-pmu: Add missing mmio accessors (bnc#1012382).
  • macros.kernel-source: define linux_arch for KMPs (boo#1098050). CONFIG_64BIT is no longer defined so KMP spec files need to include %{?linux_make_arch} in any make call to build modules or descent into the kernel directory for any reason.
  • macros.kernel-source: pass -b properly in kernel module package (bsc#1107870).
  • macros.kernel-source: pass -f properly in module subpackage (boo#1076393).
  • md-cluster: clear another node's suspend_area after the copy is finished (bnc#1012382).
  • md/raid1: exit sync request if MD_RECOVERY_INTR is set (git-fixes).
  • md/raid5: fix data corruption of replacements after originals dropped (bnc#1012382).
  • media: af9035: prevent buffer overflow on write (bnc#1012382).
  • media: exynos4-is: Prevent NULL pointer dereference in __isp_video_try_fmt() (bnc#1012382).
  • media: fsl-viu: fix error handling in viu_of_probe() (bnc#1012382).
  • media: omap3isp: zero-initialize the isp cam_xclk{a,b} initial data (bnc#1012382).
  • media: omap_vout: Fix a possible null pointer dereference in omap_vout_open() (bsc#1050431).
  • media: s3c-camif: ignore -ENOIOCTLCMD from v4l2_subdev_call for s_power (bnc#1012382).
  • media: soc_camera: ov772x: correct setting of banding filter (bnc#1012382).
  • media: tm6000: add error handling for dvb_register_adapter (bnc#1012382).
  • media: uvcvideo: Support realtek's UVC 1.5 device (bnc#1012382).
  • media: v4l: event: Prevent freeing event subscriptions while accessed (bnc#1012382).
  • media: videobuf2-core: check for q->error in vb2_core_qbuf() (bnc#1012382).
  • media: videobuf-dma-sg: Fix dma_{sync,unmap}_sg() calls (bsc#1050431).
  • mei: bus: type promotion bug in mei_nfc_if_version() (bnc#1012382).
  • memory_hotplug: cond_resched in __remove_pages (bnc#1114178).
  • mfd: omap-usb-host: Fix dts probe of children (bnc#1012382).
  • mfd: ti_am335x_tscadc: Fix struct clk memory leak (bnc#1012382).
  • misc: hmc6352: fix potential Spectre v1 (bnc#1012382).
  • misc: mic: SCIF Fix scif_get_new_port() error handling (bnc#1012382).
  • misc: ti-st: Fix memory leak in the error path of probe() (bnc#1012382).
  • mmc: mmci: stop building qcom dml as module (bsc#1110468).
  • mm: fix devmem_is_allowed() for sub-page System RAM intersections (bsc#1110006).
  • mm: get rid of vmacache_flush_all() entirely (bnc#1012382).
  • mm: madvise(MADV_DODUMP): allow hugetlbfs pages (bnc#1012382).
  • mm: /proc/pid/pagemap: hide swap entries from unprivileged users (Git-fixes bsc#1109907).
  • mm: shmem.c: Correctly annotate new inodes for lockdep (bnc#1012382).
  • mm/vmstat.c: fix outdated vmstat_text (bnc#1012382).
  • mm/vmstat.c: skip NR_TLB_REMOTE_FLUSH* properly (bnc#1012382).
  • mm/vmstat.c: skip NR_TLB_REMOTE_FLUSH* properly (git fixes).
  • module: exclude SHN_UNDEF symbols from kallsyms api (bnc#1012382).
  • mtdchar: fix overflows in adjustment of count (bnc#1012382).
  • mtd/maps: fix solutionengine.c printk format warnings (bnc#1012382).
  • neighbour: confirm neigh entries when ARP packet is received (bnc#1012382).
  • net/appletalk: fix minor pointer leak to userspace in SIOCFINDIPDDPRT (bnc#1012382).
  • net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx() (bnc#1012382).
  • net: dcb: For wild-card lookups, use priority -1, not 0 (bnc#1012382).
  • net: ethernet: mvneta: Fix napi structure mixup on armada 3700 (bsc#1110616).
  • net: ethernet: ti: cpsw: fix mdio device reference leak (bnc#1012382).
  • netfilter: x_tables: avoid stack-out-of-bounds read in xt_copy_counters_from_user (bnc#1012382).
  • net: hns: fix length and page_offset overflow when CONFIG_ARM64_64K_PAGES (bnc#1012382).
  • net: hp100: fix always-true check for link up state (bnc#1012382).
  • net: ipv4: update fnhe_pmtu when first hop's MTU changes (bnc#1012382).
  • net/ipv6: Display all addresses in output of /proc/net/if_inet6 (bnc#1012382).
  • netlabel: check for IPV4MASK in addrinfo_get (bnc#1012382).
  • net: macb: disable scatter-gather for macb on sama5d3 (bnc#1012382).
  • net/mlx4: Use cpumask_available for eq->affinity_mask (bnc#1012382).
  • net: mvneta: fix mtu change on port without link (bnc#1012382).
  • net: mvneta: fix mvneta_config_rss on armada 3700 (bsc#1110615).
  • net: mvpp2: Extract the correct ethtype from the skb for tx csum offload (bnc#1012382).
  • net: systemport: Fix wake-up interrupt race during resume (bnc#1012382).
  • net/usb: cancel pending work when unbinding smsc75xx (bnc#1012382).
  • nfc: Fix possible memory corruption when handling SHDLC I-Frame commands (bnc#1012382).
  • nfc: Fix the number of pipes (bnc#1012382).
  • nfs: add nostatflush mount option (bsc#1065726).
  • nfs: Avoid quadratic search when freeing delegations (bsc#1084760).
  • nfsd: fix corrupted reply to badly ordered compound (bnc#1012382).
  • nfs: Use an appropriate work queue for direct-write completion (bsc#1082519).
  • nfsv4.0 fix client reference leak in callback (bnc#1012382).
  • ocfs2: fix locking for res->tracking and dlm->tracking_list (bnc#1012382).
  • ocfs2: fix ocfs2 read block panic (bnc#1012382).
  • of: unittest: Disable interrupt node tests for old world MAC systems (bnc#1012382).
  • ovl: Copy inode attributes after setting xattr (bsc#1107299).
  • parport: sunbpp: fix error return code (bnc#1012382).
  • partitions/aix: append null character to print data from disk (bnc#1012382).
  • partitions/aix: fix usage of uninitialized lv_info and lvname structures (bnc#1012382).
  • Pass x86 as architecture on x86_64 and i386 (bsc#1093118).
  • pci: altera: Fix bool initialization in tlp_read_packet() (bsc#1109806).
  • pci: designware: Fix I/O space page leak (bsc#1109806).
  • pci: designware: Fix pci_remap_iospace() failure path (bsc#1109806).
  • pci: hv: Use effective affinity mask (bsc#1109772).
  • pci: OF: Fix I/O space page leak (bsc#1109806).
  • pci: pciehp: Fix unprotected list iteration in IRQ handler (bsc#1109806).
  • pci: Reprogram bridge prefetch registers on resume (bnc#1012382).
  • pci: shpchp: Fix AMD POGO identification (bsc#1109806).
  • pci: Supply CPU physical address (not bus address) to iomem_is_exclusive() (bsc#1109806).
  • pci: versatile: Fix I/O space page leak (bsc#1109806).
  • pci: versatile: Fix pci_remap_iospace() failure path (bsc#1109806).
  • pci: xgene: Fix I/O space page leak (bsc#1109806).
  • pci: xilinx: Add missing of_node_put() (bsc#1109806).
  • perf powerpc: Fix callchain ip filtering (bnc#1012382).
  • perf powerpc: Fix callchain ip filtering when return address is in a register (bnc#1012382).
  • perf probe powerpc: Ignore SyS symbols irrespective of endianness (bnc#1012382).
  • perf script python: Fix export-to-postgresql.py occasional failure (bnc#1012382).
  • perf tools: Allow overriding MAX_NR_CPUS at compile time (bnc#1012382).
  • phy: qcom-ufs: add MODULE_LICENSE tag (bsc#1110468).
  • pinctrl: qcom: spmi-gpio: Fix pmic_gpio_config_get() to be compliant (bnc#1012382).
  • pipe: actually allow root to exceed the pipe buffer limit (git-fixes).
  • platform/x86: alienware-wmi: Correct a memory leak (bnc#1012382).
  • platform/x86: toshiba_acpi: Fix defined but not used build warnings (bnc#1012382).
  • pm / core: Clear the direct_complete flag on errors (bnc#1012382).
  • powerpc/64s: move machine check SLB flushing to mm/slb.c (bsc#1094244).
  • powerpc/kdump: Handle crashkernel memory reservation failure (bnc#1012382).
  • powerpc/mce: Fix SLB rebolting during MCE recovery path (bsc#1094244).
  • powerpc/numa: Skip onlining a offline node in kdump path (bsc#1109784).
  • powerpc/numa: Use associativity if VPHN hcall is successful (bsc#1110363).
  • powerpc/perf/hv-24x7: Fix passing of catalog version number (bsc#1053043).
  • powerpc/powernv: opal_put_chars partial write fix (bnc#1012382).
  • powerpc/pseries: Defer the logging of rtas error to irq work queue (bsc#1094244).
  • powerpc/pseries: Define MC