Why is newest kernel 5.14.0-503.19.1.el9 not yet released?

So been waiting for a while for kernel-5.14.0-503.19.1.el9_5.x86_64.rpm that was released 19th of December, ~19 days ago. It is available on Red Hat and Rocky repos but for some reason missing in the AlmaLinux repos. Anyone know why? All staff on Christmas break? :slight_smile:

1 Like

The latest packages in /mirror/almalinux.org/9/BaseOS/x86_64/os/Packages are from 2024-12-23 so does not make sense that the kernel release is not there since it was released 2024-12-19.

There are essentially two packages built 2024-12-23: glibc and pam.

The glibc changelog:

* Mon Dec 23 2024 Koichiro Iwao <meta@almalinux.org> - 2.34-125.1.alma.2
- Re-apply RHEL-25531
- Apply patch from upstream BZ #32470

* Mon Nov 25 2024 Andrew Lukoshko <alukoshko@almalinux.org> - 2.34-125.1.alma.1
- Revert: x86: Fix Zen3/Zen4 ERMS selection (RHEL-25531)

* Fri Sep 27 2024 Florian Weimer <fweimer@redhat.com> - 2.34-125.1
- Remove some unused ppc64le string functions (RHEL-49489)

The 2.34-125.1 was more directly from Red Hat, for 9.5 in November.
The 2.34-125.1.alma.2 is unique to AlmaLinux.

Red Hat did release pam-1.5.1-22.el9_5 2024-11-25. It has thus taken about a month to get patches and rebuild that package for AlmaLinux.

pam changelog:

* Thu Nov 21 2024 Iker Pedrosa <ipedrosa@redhat.com> - 1.5.1-22
- pam_access: rework resolving of tokens as hostname.
  Resolves: CVE-2024-10963 and RHEL-66245

* Wed Nov 06 2024 Diaa Sami <disami@redhat.com> - 1.5.1-21
- pam_unix: always run the helper to obtain shadow password file entries.
  CVE-2024-10041. Resolves: RHEL-62880

Would it be nice to se builds complete quicker? Yes.
Do we still get more than we pay for? Yes.

Did not realize AlmaLinux lagged so much until I noticed the kernel not getting released (fixes a nasty network KVM issue) . I guess I assumed Rocky Linux and AlmaLinux packages are delayed about the same amount compared to Red Hat, but guess not. So I guess it is just a matter of waiting another week or two…

The new kernel was released during the night (3 weeks behind Rocky Linux) so time to start some testing…
Seems the delay was noticed here as well → https://www.reddit.com/r/AlmaLinux/comments/1hqpbd6/missing_packages_for_rhsa202411486_kernel/

Very concering. Presume it’s just an oversight.

Is it good that they took 3 weeks to update the kernel? Perhaps not.

Is it concerning as there were many or serious security vulnerabilities involved? Eh… they don’t seem to be very damning, mostly bluetooth stuff… I mean, they are moderate at worst (as per Red Hat themselves).

Should we really complain? I’d say no, I don’t know how much you guys are paying for Alma Linux, but they give it for free, and if anyone responsible for that update was on a Christmas break I’m all for it… and I hope they enjoyed it! They have released an update now (well, a few days ago), we are all happy again. :slight_smile: