[ubuntu/precise-security] linux-lts-raring 3.8.0-33.48~precise1 (Accepted)
Adam Conrad
adconrad at 0c3.net
Fri Nov 8 00:36:04 UTC 2013
linux-lts-raring (3.8.0-33.48~precise1) precise; urgency=low
[ Brad Figg ]
* Release Tracking Bug
- LP: #1243887
[ Maximiliano Curia ]
* SAUCE: (no-up) Only let characters through when there are active
readers.
- LP: #1208740
[ Upstream Kernel Changes ]
* cciss: fix info leak in cciss_ioctl32_passthru()
- LP: #1188355
- CVE-2013-2147
* cpqarray: fix info leak in ida_locked_ioctl()
- LP: #1188355
- CVE-2013-2147
* mount: consolidate permission checks
- LP: #1226726
* get rid of full-hash scan on detaching vfsmounts
- LP: #1226726
* Smack: Fix the bug smackcipso can't set CIPSO correctly
- LP: #1236743
* ipvs: add backup_only flag to avoid loops
- LP: #1238494
* tuntap: correctly handle error in tun_set_iff()
- LP: #1229975
- CVE-2013-4343
* htb: fix sign extension bug
- LP: #1240580
* net: avoid to hang up on sending due to sysctl configuration overflow.
- LP: #1240580
* net: check net.core.somaxconn sysctl values
- LP: #1240580
* macvlan: validate flags
- LP: #1240580
* neighbour: populate neigh_parms on alloc before calling ndo_neigh_setup
- LP: #1240580
* bonding: modify only neigh_parms owned by us
- LP: #1240580
* fib_trie: remove potential out of bound access
- LP: #1240580
* bridge: don't try to update timers in case of broken MLD queries
- LP: #1240580
* tcp: cubic: fix overflow error in bictcp_update()
- LP: #1240580
* tcp: cubic: fix bug in bictcp_acked()
- LP: #1240580
* ipv6: don't stop backtracking in fib6_lookup_1 if subtree does not
match
- LP: #1240580
* 8139cp: Fix skb leak in rx_status_loop failure path.
- LP: #1240580
* tun: signedness bug in tun_get_user()
- LP: #1240580
* ipv6: remove max_addresses check from ipv6_create_tempaddr
- LP: #1240580
* ipv6: Store Router Alert option in IP6CB directly.
- LP: #1240580
* ipv6: drop packets with multiple fragmentation headers
- LP: #1240580
* tcp: set timestamps for restored skb-s
- LP: #1240580
* net: usb: Add HP hs2434 device to ZLP exception table
- LP: #1240580
* tcp: initialize rcv_tstamp for restored sockets
- LP: #1240580
* ipv4: sendto/hdrincl: don't use destination address found in header
- LP: #1240580
* tcp: tcp_make_synack() should use sock_wmalloc
- LP: #1240580
* tipc: set sk_err correctly when connection fails
- LP: #1240580
* net: bridge: convert MLDv2 Query MRC into msecs_to_jiffies for
max_delay
- LP: #1240580
* ICMPv6: treat dest unreachable codes 5 and 6 as EACCES, not EPROTO
- LP: #1240580
* tg3: Don't turn off led on 5719 serdes port 0
- LP: #1240580
* vhost_net: poll vhost queue after marking DMA is done
- LP: #1240580
* net: ipv6: tcp: fix potential use after free in tcp_v6_do_rcv
- LP: #1240580
* drm/radeon/si: Add support for CP DMA to CS checker for compute v2
- LP: #1240580
* sfc: Fix efx_rx_buf_offset() for recycled pages
- LP: #1240580
* cfq: explicitly use 64bit divide operation for 64bit arguments
- LP: #1240580
* drm/radeon/atom: workaround vbios bug in transmitter table on rs880
(v2)
- LP: #1240580
* drm/ast: fix the ast open key function
- LP: #1240580
* sched/fair: Fix small race where child->se.parent,cfs_rq might point to
invalid ones
- LP: #1240580
* tg3: Expand led off fix to include 5720
- LP: #1240580
* HID: provide a helper for validating hid reports
- LP: #1240580
* HID: zeroplus: validate output report details
- LP: #1240580
- CVE-2013-2889
* HID: LG: validate HID output report details
- LP: #1240580
- CVE-2013-2893
* HID: lenovo-tpkbd: validate output report details
- LP: #1240580
- CVE-2013-2894
* HID: validate feature and input report details
- LP: #1240580
- CVE-2013-2897
* HID: logitech-dj: validate output report details
- LP: #1240580
- CVE-2013-2895
* HID: multitouch: validate indexes details
- LP: #1240580
- CVE-2013-2897
* HID: lenovo-tpkbd: fix leak if tpkbd_probe_tp fails
- LP: #1240580
* drm/radeon: fix panel scaling with eDP and LVDS bridges
- LP: #1240580
* cifs: fix filp leak in cifs_atomic_open()
- LP: #1240580
* net: usb: cdc_ether: Use wwan interface for Telit modules
- LP: #1240580
* usb: gadget: fix a bug and a WARN_ON in dummy-hcd
- LP: #1240580
* drm/i915: do not update cursor in crtc mode set
- LP: #1240580
* drm/i915: Don't enable the cursor on a disable pipe
- LP: #1240580
* drm/ttm: fix the tt_populated check in ttm_tt_destroy()
- LP: #1240580
* PCI / ACPI / PM: Clear pme_poll for devices in D3cold on wakeup
- LP: #1240580
* serial: pch_uart: fix tty-kref leak in dma-rx path
- LP: #1240580
* x86, efi: Don't map Boot Services on i386
- LP: #1240580
* ALSA: compress: Fix compress device unregister.
- LP: #1240580
* dm snapshot: workaround for a false positive lockdep warning
- LP: #1240580
* dm-snapshot: fix performance degradation due to small hash size
- LP: #1240580
* drm/radeon: Make r100_cp_ring_info() and radeon_ring_gfx() safe (v2)
- LP: #1240580
* ARM: 7837/3: fix Thumb-2 bug in AES assembler code
- LP: #1240580
* x86/reboot: Add quirk to make Dell C6100 use reboot=pci automatically
- LP: #1240580
* drm/radeon: disable tests/benchmarks if accel is disabled
- LP: #1240580
* xhci: Fix oops happening after address device timeout
- LP: #1240580
* xhci: Ensure a command structure points to the correct trb on the
command ring
- LP: #1240580
* drm/i915/dp: increase i2c-over-aux retry interval on AUX DEFER
- LP: #1240580
* staging: vt6656: [BUG] main_usb.c oops on device_close move flag
earlier.
- LP: #1240580
* staging: vt6656: [BUG] iwctl_siwencodeext return if device not open
- LP: #1240580
* USB: UHCI: accept very late isochronous URBs
- LP: #1240580
* USB: OHCI: accept very late isochronous URBs
- LP: #1240580
* USB: fix PM config symbol in uhci-hcd, ehci-hcd, and xhci-hcd
- LP: #1240580
* usb/core/devio.c: Don't reject control message to endpoint with wrong
direction bit
- LP: #1240580
* hwmon: (applesmc) Check key count before proceeding
- LP: #1240580
* fsl/usb: Resolve PHY_CLK_VLD instability issue for ULPI phy
- LP: #1240580
* driver core : Fix use after free of dev->parent in device_shutdown
- LP: #1240580
* USB: Fix breakage in ffs_fs_mount()
- LP: #1240580
* usb: dwc3: pci: add support for BayTrail
- LP: #1240580
* usb: dwc3: add support for Merrifield
- LP: #1240580
* ASoC: max98095: a couple array underflows
- LP: #1240580
* ASoC: ab8500-codec: info leak in anc_status_control_put()
- LP: #1240580
* ASoC: 88pm860x: array overflow in snd_soc_put_volsw_2r_st()
- LP: #1240580
* Bluetooth: Add a new PID/VID 0cf3/e005 for AR3012.
- LP: #1240580
* Bluetooth: Fix security level for peripheral role
- LP: #1240580
* Bluetooth: Fix encryption key size for peripheral role
- LP: #1240580
* Bluetooth: Add support for BCM20702A0 [0b05, 17cb]
- LP: #1240580
* Bluetooth: Introduce a new HCI_RFKILLED flag
- LP: #1240580
* rtlwifi: Align private space in rtl_priv struct
- LP: #1240580
* p54usb: add USB ID for Corega WLUSB2GTST USB adapter
- LP: #1240580
* mwifiex: fix hang issue for USB chipsets
- LP: #1240580
* mwifiex: fix NULL pointer dereference in usb suspend handler
- LP: #1240580
* fs/binfmt_elf.c: prevent a coredump with a large vm_map_count from
Oopsing
- LP: #1240580
* nilfs2: fix issue with race condition of competition between segments
for dirty blocks
- LP: #1240580
* mm: avoid reinserting isolated balloon pages into LRU lists
- LP: #1240580
* USB: serial: option: Ignore card reader interface on Huawei E1750
- LP: #1240580
* gpio/omap: maintain GPIO and IRQ usage separately
- LP: #1240580
* gpio/omap: auto-setup a GPIO when used as an IRQ
- LP: #1240580
* ib_srpt: Destroy cm_id before destroying QP.
- LP: #1240580
* powerpc: Fix parameter clobber in csum_partial_copy_generic()
- LP: #1240580
* powerpc: Restore registers on error exit from
csum_partial_copy_generic()
- LP: #1240580
* powerpc/sysfs: Disable writing to PURR in guest mode
- LP: #1240580
* powerpc/iommu: Use GFP_KERNEL instead of GFP_ATOMIC in
iommu_init_table()
- LP: #1240580
* powerpc/vio: Fix modalias_show return values
- LP: #1240580
* ib_srpt: always set response for task management
- LP: #1240580
* xen/hvc: allow xenboot console to be used again
- LP: #1240580
* net: Update the sysctl permissions handler to test effective uid/gid
- LP: #1240580
* Linux 3.8.13.11
- LP: #1240580
linux (3.8.0-32.47) raring; urgency=low
[Steve Conklin]
* Release Tracking Bug
- LP: #1233777
[ Upstream Kernel Changes ]
* Revert "net/core/sock.c: add missing VSOCK string in
af_family_*_key_strings"
- LP: #1233227
* Input: cypress_ps2 - Return zero finger count if palm is detected.
- LP: #1229361
* isofs: Refuse RW mount of the filesystem instead of making it RO
- LP: #1228751
* udf: Standardize return values in mount sequence
- LP: #1228751
* udf: Refuse RW mount of the filesystem instead of making it RO
- LP: #1228751
* ARM: update FIQ support for relocation of vectors
- LP: #1233227
* ARM: Fix FIQ code on VIVT CPUs
- LP: #1233227
* regmap: Add another missing header for !CONFIG_REGMAP stubs
- LP: #1233227
* ALSA: hda - Add inverted digital mic fixup for Acer Aspire One
- LP: #1233227
* mac80211: add missing channel context release
- LP: #1233227
* iwl4965: fix rfkill set state regression
- LP: #1233227
* ath9k_htc: Restore skb headroom when returning skb to mac80211
- LP: #1233227
* ath9k: Enable PLL fix only for AR9340/AR9330
- LP: #1233227
* ALSA: hda - Fix NULL dereference with CONFIG_SND_DYNAMIC_MINORS=n
- LP: #1233227
* lparcfg: don't bother saving pointer to proc_dir_entry
- LP: #1233227
* powerpc/pseries/lparcfg: Fix possible overflow are more than 1026
- LP: #1233227
* powerpc: Don't Oops when accessing /proc/powerpc/lparcfg without
hypervisor
- LP: #1233227
* powerpc: Work around gcc miscompilation of __pa() on 64-bit
- LP: #1233227
* powerpc/hvsi: Increase handshake timeout from 200ms to 400ms.
- LP: #1233227
* net: Check the correct namespace when spoofing pid over SCM_RIGHTS
- LP: #1233227
* ALSA: opti9xx: Fix conflicting driver object name
- LP: #1233227
* SUNRPC: Fix memory corruption issue on 32-bit highmem systems
- LP: #1233227
* drivers/base/memory.c: fix show_mem_removable() to handle missing
sections
- LP: #1233227
* memcg: check that kmem_cache has memcg_params before accessing it
- LP: #1233227
* workqueue: cond_resched() after processing each work item
- LP: #1233227
* drm/i915: ivb: fix edp voltage swing reg val
- LP: #1233227
* drm/vmwgfx: Split GMR2_REMAP commands if they are to large
- LP: #1233227
* af_key: initialize satype in key_notify_policy_flush()
- LP: #1233227
* Linux 3.8.13.9
- LP: #1233227
* zram: allow request end to coincide with disksize
- LP: #1233227
* mtd: nand: fix NAND_BUSWIDTH_AUTO for x16 devices
- LP: #1233227
* HID: hidraw: correctly deallocate memory on device disconnect
- LP: #1233227
* xen-gnt: prevent adding duplicate gnt callbacks
- LP: #1233227
* ath9k: always clear ps filter bit on new assoc
- LP: #1233227
* ceph: Don't forget the 'up_read(&osdc->map_sem)' if met error.
- LP: #1233227
* libceph: unregister request in __map_request failed and nofail == false
- LP: #1233227
* usb: config->desc.bLength may not exceed amount of data returned by the
device
- LP: #1233227
* USB: cdc-wdm: fix race between interrupt handler and tasklet
- LP: #1233227
* powerpc: Handle unaligned ldbrx/stdbrx
- LP: #1233227
* intel-iommu: Fix leaks in pagetable freeing
- LP: #1233227
* drivers/misc/hpilo: Correct panic when an AUX iLO is detected
- LP: #1233227
* USB: handle LPM errors during device suspend correctly
- LP: #1233227
* xhci-plat: Don't enable legacy PCI interrupts.
- LP: #1233227
* ath9k: fix rx descriptor related race condition
- LP: #1233227
* ath9k: avoid accessing MRC registers on single-chain devices
- LP: #1233227
* brcmsmac: Fix WARNING caused by lack of calls to dma_mapping_error()
- LP: #1233227
* ext4: simplify truncation code in ext4_setattr()
- LP: #1233227
* ext4: fix lost truncate due to race with writeback
- LP: #1233227
* ASoC: wm8960: Fix PLL register writes
- LP: #1233227
* rculist: list_first_or_null_rcu() should use list_entry_rcu()
- LP: #1233227
* USB: mos7720: use GFP_ATOMIC under spinlock
- LP: #1233227
* USB: mos7720: fix big-endian control requests
- LP: #1233227
* arm64: perf: fix group validation when using enable_on_exec
- LP: #1233227
* arm64: perf: fix ARMv8 EVTYPE_MASK to include NSH bit
- LP: #1233227
* staging: comedi: dt282x: dt282x_ai_insn_read() always fails
- LP: #1233227
* usb: ehci-mxc: check for pdata before dereferencing
- LP: #1233227
* mmc: tmio_mmc_dma: fix PIO fallback on SDHI
- LP: #1233227
* proc: Restrict mounting the proc filesystem
- LP: #1233227
* usb: xhci: Disable runtime PM suspend for quirky controllers
- LP: #1233227
* USB: OHCI: Allow runtime PM without system sleep
- LP: #1233227
* pinctrl: at91: fix get_pullup/down function return
- LP: #1233227
* ACPI / EC: Add HP Folio 13 to ec_dmi_table in order to skip DSDT scan
- LP: #1233227
* ACPI / EC: Add ASUSTEK L4R to quirk list in order to validate ECDT
- LP: #1233227
* HID: validate HID report id size
- LP: #1233227
- CVE-2013-2888
* cpuidle: coupled: abort idle if pokes are pending
- LP: #1233227
* cpuidle: coupled: disable interrupts after entering safe state
- LP: #1233227
* cpuidle: coupled: fix race condition between pokes and safe state
- LP: #1233227
* of: Fix missing memory initialization on FDT unflattening
- LP: #1233227
* leds: wm831x-status: Request a REG resource
- LP: #1233227
* USB: fix build error when CONFIG_PM_SLEEP isn't enabled
- LP: #1233227
* clk: wm831x: Initialise wm831x pointer on init
- LP: #1233227
* drm/edid: add quirk for Medion MD30217PG
- LP: #1233227
* drm/radeon: fix endian bugs in hw i2c atom routines
- LP: #1233227
* drm/radeon: update line buffer allocation for dce4.1/5
- LP: #1233227
* drm/radeon: update line buffer allocation for dce6
- LP: #1233227
* drm/radeon: fix LCD record parsing
- LP: #1233227
* drm/radeon: fix resume on some rs4xx boards (v2)
- LP: #1233227
* drm/radeon: fix handling of variable sized arrays for router objects
- LP: #1233227
* radeon kms: fix uninitialised hotplug work usage in r100_irq_process()
- LP: #1233227
* pidns: Fix hang in zap_pid_ns_processes by sending a potentially extra
wakeup
- LP: #1233227
* x86, smap: Handle csum_partial_copy_*_user()
- LP: #1233227
* Introduce [compat_]save_altstack_ex() to unbreak x86 SMAP
- LP: #1233227
* drm: fix DRM_IOCTL_MODE_GETFB handle-leak
- LP: #1233227
* HID: picolcd: Prevent NULL pointer dereference on _remove()
- LP: #1233227
* HID: battery: don't do DMA from stack
- LP: #1233227
* ALSA: hda - hdmi: Fallback to ALSA allocation when selecting CA
- LP: #1233227
* fuse: postpone end_page_writeback() in fuse_writepage_locked()
- LP: #1233227
* fuse: invalidate inode attributes on xattr modification
- LP: #1233227
* media: coda: Fix DT driver data pointer for i.MX27
- LP: #1233227
* s5p-g2d: Fix registration failure
- LP: #1233227
* DocBook: upgrade media_api DocBook version to 4.2
- LP: #1233227
* v4l2: added missing mutex.h include to v4l2-ctrls.h
- LP: #1233227
* hdpvr: fix iteration over uninitialized lists in hdpvr_probe()
- LP: #1233227
* exynos-gsc: Register v4l2 device
- LP: #1233227
* fuse: readdir: check for slash in names
- LP: #1233227
* MIPS: ath79: Fix ar933x watchdog clock
- LP: #1233227
* libceph: use pg_num_mask instead of pgp_num_mask for pg.seed calc
- LP: #1233227
* HID: pantherlord: validate output report details
- LP: #1233227
- CVE-2013-2892
* HID: ntrig: validate feature report details
- LP: #1233227
- CVE-2013-2896
* HID: sensor-hub: validate feature report details
- LP: #1233227
- CVE-2013-2898
* HID: picolcd_core: validate output report details
- LP: #1233227
- CVE-2013-2899
* HID: check for NULL field when setting values
- LP: #1233227
* ARM: PCI: versatile: Fix map_irq function to match hardware
- LP: #1233227
* ARM: PCI: versatile: Fix PCI I/O
- LP: #1233227
* ARM: PCI: versatile: Fix SMAP register offsets
- LP: #1233227
* net: mvneta: properly disable HW PHY polling and ensure adjust_link()
works
- LP: #1233227
* drm/i915: try not to lose backlight CBLV precision
- LP: #1233227
* crypto: api - Fix race condition in larval lookup
- LP: #1233227
* cifs: ensure that srv_mutex is held when dealing with ssocket pointer
- LP: #1233227
* CIFS: Fix a memory leak when a lease break comes
- LP: #1233227
* ALSA: hda - Add Toshiba Satellite C870 to MSI blacklist
- LP: #1233227
* lguest: Point to the right directory for the lguest launcher
- LP: #1233227
* powerpc: Default arch idle could cede processor on pseries
- LP: #1233227
* ASoC: mc13783: add spi errata fix
- LP: #1233227
* sd: Fix potential out-of-bounds access
- LP: #1233227
* pidns: fix vfork() after unshare(CLONE_NEWPID)
- LP: #1233227
* ocfs2: fix the end cluster offset of FIEMAP
- LP: #1233227
* mm/huge_memory.c: fix potential NULL pointer dereference
- LP: #1233227
* mm: fix aio performance regression for database caused by THP
- LP: #1233227
* memcg: fix multiple large threshold notifications
- LP: #1233227
* Linux 3.8.13.10
- LP: #1233227
Date: 2013-10-24 16:26:14.519547+00:00
Changed-By: Brad Figg <brad.figg at canonical.com>
Signed-By: Adam Conrad <adconrad at 0c3.net>
https://launchpad.net/ubuntu/precise/+source/linux-lts-raring/3.8.0-33.48~precise1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Precise-changes
mailing list