Hi all,
FYI:
RHEL and Rocky Linux already have fixed kernels available…
Hi all,
FYI:
RHEL and Rocky Linux already have fixed kernels available…
This matter appears to have been fixed in updates for AL 8 and 10, but not yet AL 9?
Search for “reflink” in https://errata.almalinux.org/ and only the former two show up…
At least xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193938] occurs on all three:
el8:
# dnf -q rq --changelog kernel-4.18.0-553.146.1.el8_10
Changelog for kernel-4.18.0-553.146.1.el8_10.x86_64
* Tue Jul 21 2026 Andrei Lukoshko <alukoshko@almalinux.org> - 4.18.0-553.146.1
- hpsa: bring back deprecated PCI ids #CFHack #CFHack2024
- mptsas: bring back deprecated PCI ids #CFHack #CFHack2024
- megaraid_sas: bring back deprecated PCI ids #CFHack #CFHack2024
- qla2xxx: bring back deprecated PCI ids #CFHack #CFHack2024
- qla4xxx: bring back deprecated PCI ids
- lpfc: bring back deprecated PCI ids
- be2iscsi: bring back deprecated PCI ids
- kernel/rh_messages.h: enable all disabled pci devices by moving to
unmaintained
* Tue Jul 21 2026 Eduard Abdullin <eabdullin@almalinux.org> - 4.18.0-553.146.1
- Use AlmaLinux OS secure boot cert
- Debrand for AlmaLinux OS
* Mon Jul 20 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.146.1.el8_10]
- RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (Gaurav Goklani) [RHEL-180153] {CVE-2026-46117}
- PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type (Herton R. Krzesinski) [RHEL-174916]
* Thu Jul 16 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [4.18.0-553.145.1.el8_10]
- Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CKI Backport Bot) [RHEL-188327] {CVE-2026-53071}
* Tue Jul 14 2026 Jan Stancek <jstancek@redhat.com> [4.18.0-553.144.1.el8_10]
- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (Sabrina Dubroca) [RHEL-180170] {CVE-2026-46116}
- xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193938]
- net: bridge: use a stable FDB dst snapshot in RCU readers (Mohammad Heib) [RHEL-179325] {CVE-2026-46086}
el9:
# dnf -q rq --changelog kernel-5.14.0-687.26.1.el9_8
Changelog for kernel-5.14.0-687.26.1.el9_8.x86_64
* Tue Jul 14 2026 Andrew Lukoshko <alukoshko@almalinux.org> - 5.14.0-687.26.1
- Recreate RHEL 5.14.0-687.26.1 from CentOS Stream 9 backports (1770)
- RHEL changelog for 687.26.1 follows:
* Mon Jul 13 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-687.26.1.el9_8]
- xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193937]
el10_2:
# dnf -q rq --changelog kernel-6.12.0-211.34.1.el10_2
Changelog for kernel-6.12.0-211.34.1.el10_2.x86_64_v2
* Wed Jul 15 2026 Andrew Lukoshko <alukoshko@almalinux.org> - 6.12.0-211.34.1
- Recreate RHEL 6.12.0-211.34.1 from CentOS Stream 10 and upstream stable backports (1456-1458)
- RHEL changelog for 211.34.1 follows:
* Mon Jul 13 2026 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [6.12.0-211.34.1.el10_2]
- crypto: ccp - copy IV using skcipher ivsize (CKI Backport Bot) [RHEL-188463] {CVE-2026-53016}
- xfs: resample the data fork mapping after cycling ILOCK (Carlos Maiolino) [RHEL-193945]
- xfrm: esp: restore combined single-frag length gate (CKI Backport Bot) [RHEL-178326]
Hi again,
might the absence of a timely AL 9 fix have been caused by the RHEL advisory being labeled just a bug fix instead of a security advisory?
Hi all,
quoting Andrew Lukoshko on Mattermost:
Everything was fixed before CVE was assigned, in kernel-5.14.0-687.26.1 https://git.almalinux.org/rpms/kernel/commit/c8142635f041baf75a18969c6fd896333e9e932b
For the record, the errata have been updated with that specific fix:
ALBA-2026-39332