diff --git a/NFS-populate-net-in-mount-data-when-remounting.patch b/NFS-populate-net-in-mount-data-when-remounting.patch deleted file mode 100644 index 223b50030..000000000 --- a/NFS-populate-net-in-mount-data-when-remounting.patch +++ /dev/null @@ -1,39 +0,0 @@ -Bugzilla: 1099761 -Upstream-status: 3.16 and CC'd for stable - -From a914722f333b3359d2f4f12919380a334176bb89 Mon Sep 17 00:00:00 2001 -From: Mateusz Guzik -Date: Tue, 10 Jun 2014 12:44:12 +0200 -Subject: [PATCH] NFS: populate ->net in mount data when remounting - -Otherwise the kernel oopses when remounting with IPv6 server because -net is dereferenced in dev_get_by_name. - -Use net ns of current thread so that dev_get_by_name does not operate on -foreign ns. Changing the address is prohibited anyway so this should not -affect anything. - -Signed-off-by: Mateusz Guzik -Cc: linux-nfs@vger.kernel.org -Cc: linux-kernel@vger.kernel.org -Cc: stable@vger.kernel.org # 3.4+ -Signed-off-by: Trond Myklebust ---- - fs/nfs/super.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/fs/nfs/super.c b/fs/nfs/super.c -index 1a6d7ac9d9d2..084af1060d79 100644 ---- a/fs/nfs/super.c -+++ b/fs/nfs/super.c -@@ -2260,6 +2260,7 @@ nfs_remount(struct super_block *sb, int *flags, char *raw_data) - data->nfs_server.addrlen = nfss->nfs_client->cl_addrlen; - data->version = nfsvers; - data->minorversion = nfss->nfs_client->cl_minorversion; -+ data->net = current->nsproxy->net_ns; - memcpy(&data->nfs_server.address, &nfss->nfs_client->cl_addr, - data->nfs_server.addrlen); - --- -1.9.3 - diff --git a/aio-fix-aio-request-leak-when-events-are-reaped-by-u.patch b/aio-fix-aio-request-leak-when-events-are-reaped-by-u.patch deleted file mode 100644 index fa93d6622..000000000 --- a/aio-fix-aio-request-leak-when-events-are-reaped-by-u.patch +++ /dev/null @@ -1,48 +0,0 @@ -Bugzilla: 1112975 -Upstream-status: 3.16 and CC'd to stable - -From f8567a3845ac05bb28f3c1b478ef752762bd39ef Mon Sep 17 00:00:00 2001 -From: Benjamin LaHaise -Date: Tue, 24 Jun 2014 13:12:55 -0400 -Subject: [PATCH] aio: fix aio request leak when events are reaped by userspace - -The aio cleanups and optimizations by kmo that were merged into the 3.10 -tree added a regression for userspace event reaping. Specifically, the -reference counts are not decremented if the event is reaped in userspace, -leading to the application being unable to submit further aio requests. -This patch applies to 3.12+. A separate backport is required for 3.10/3.11. -This issue was uncovered as part of CVE-2014-0206. - -Signed-off-by: Benjamin LaHaise -Cc: stable@vger.kernel.org -Cc: Kent Overstreet -Cc: Mateusz Guzik -Cc: Petr Matousek ---- - fs/aio.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/fs/aio.c b/fs/aio.c -index 4f078c054b41..6a9c7e489adf 100644 ---- a/fs/aio.c -+++ b/fs/aio.c -@@ -1021,6 +1021,7 @@ void aio_complete(struct kiocb *iocb, long res, long res2) - - /* everything turned out well, dispose of the aiocb. */ - kiocb_free(iocb); -+ put_reqs_available(ctx, 1); - - /* - * We have to order our ring_info tail store above and test -@@ -1100,8 +1101,6 @@ static long aio_read_events_ring(struct kioctx *ctx, - flush_dcache_page(ctx->ring_pages[0]); - - pr_debug("%li h%u t%u\n", ret, head, tail); -- -- put_reqs_available(ctx, ret); - out: - mutex_unlock(&ctx->ring_lock); - --- -1.9.3 - diff --git a/aio-fix-kernel-memory-disclosure-in-io_getevents-int.patch b/aio-fix-kernel-memory-disclosure-in-io_getevents-int.patch deleted file mode 100644 index 831a6a85f..000000000 --- a/aio-fix-kernel-memory-disclosure-in-io_getevents-int.patch +++ /dev/null @@ -1,46 +0,0 @@ -Bugzilla: 1112975 -Upstream-status: 3.16 and CC'd to stable - -From edfbbf388f293d70bf4b7c0bc38774d05e6f711a Mon Sep 17 00:00:00 2001 -From: Benjamin LaHaise -Date: Tue, 24 Jun 2014 13:32:51 -0400 -Subject: [PATCH] aio: fix kernel memory disclosure in io_getevents() - introduced in v3.10 - -A kernel memory disclosure was introduced in aio_read_events_ring() in v3.10 -by commit a31ad380bed817aa25f8830ad23e1a0480fef797. The changes made to -aio_read_events_ring() failed to correctly limit the index into -ctx->ring_pages[], allowing an attacked to cause the subsequent kmap() of -an arbitrary page with a copy_to_user() to copy the contents into userspace. -This vulnerability has been assigned CVE-2014-0206. Thanks to Mateusz and -Petr for disclosing this issue. - -This patch applies to v3.12+. A separate backport is needed for 3.10/3.11. - -Signed-off-by: Benjamin LaHaise -Cc: Mateusz Guzik -Cc: Petr Matousek -Cc: Kent Overstreet -Cc: Jeff Moyer -Cc: stable@vger.kernel.org ---- - fs/aio.c | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/fs/aio.c b/fs/aio.c -index 6a9c7e489adf..955947ef3e02 100644 ---- a/fs/aio.c -+++ b/fs/aio.c -@@ -1063,6 +1063,9 @@ static long aio_read_events_ring(struct kioctx *ctx, - if (head == tail) - goto out; - -+ head %= ctx->nr_events; -+ tail %= ctx->nr_events; -+ - while (ret < nr) { - long avail; - struct io_event *ev; --- -1.9.3 - diff --git a/elantech-Deal-with-clickpads-reporting-right-button-.patch b/elantech-Deal-with-clickpads-reporting-right-button-.patch deleted file mode 100644 index 4da9e65b6..000000000 --- a/elantech-Deal-with-clickpads-reporting-right-button-.patch +++ /dev/null @@ -1,79 +0,0 @@ -Bugzilla: 1103528 -Upstream-status: Sent for 3.16 - -From 3b629bf4b018ece0c7b4d1c03bdc0eb69c884531 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Thu, 5 Jun 2014 11:48:30 +0200 -Subject: [PATCH] elantech: Deal with clickpads reporting right button events - -At least the Dell Vostro 5470 elantech *clickpad* reports right button -clicks when clicked in the right bottom area. - -This is different from how (elantech) clickpads normally operate, -normally no matter where the user clicks on the pad the pad always reports -a left button event, since there is only 1 hardware button beneath the path. - -It is unknown if this is caused by Dell having put 2 buttons under the pad, -one under each bottom corner, or if this is something caused by the specific -firmware in this clickpad. - -Since this however still clearly is a real clickpad hardware-wise, we still -want to report it as such to userspace, so that things like finger movement -in the bottom area can be properly ignored as it should be on clickpads. - -So deal with this weirdness by simply mapping a right click to a left click -on elantech clickpads. As an added advantage this is something which we can -simply do on all elantech clickpads, so no need to add special quirks for -this weird model. - -Reported-by: Elder Marco -Signed-off-by: Hans de Goede ---- - drivers/input/mouse/elantech.c | 22 ++++++++++++++++++---- - 1 file changed, 18 insertions(+), 4 deletions(-) - -diff --git a/drivers/input/mouse/elantech.c b/drivers/input/mouse/elantech.c -index 4d79821..846926d 100644 ---- a/drivers/input/mouse/elantech.c -+++ b/drivers/input/mouse/elantech.c -@@ -473,8 +473,15 @@ static void elantech_report_absolute_v3(struct psmouse *psmouse, - input_report_key(dev, BTN_TOOL_FINGER, fingers == 1); - input_report_key(dev, BTN_TOOL_DOUBLETAP, fingers == 2); - input_report_key(dev, BTN_TOOL_TRIPLETAP, fingers == 3); -- input_report_key(dev, BTN_LEFT, packet[0] & 0x01); -- input_report_key(dev, BTN_RIGHT, packet[0] & 0x02); -+ -+ /* For clickpads map both buttons to BTN_LEFT */ -+ if (etd->fw_version & 0x001000) { -+ input_report_key(dev, BTN_LEFT, packet[0] & 0x03); -+ } else { -+ input_report_key(dev, BTN_LEFT, packet[0] & 0x01); -+ input_report_key(dev, BTN_RIGHT, packet[0] & 0x02); -+ } -+ - input_report_abs(dev, ABS_PRESSURE, pres); - input_report_abs(dev, ABS_TOOL_WIDTH, width); - -@@ -484,10 +491,17 @@ static void elantech_report_absolute_v3(struct psmouse *psmouse, - static void elantech_input_sync_v4(struct psmouse *psmouse) - { - struct input_dev *dev = psmouse->dev; -+ struct elantech_data *etd = psmouse->private; - unsigned char *packet = psmouse->packet; - -- input_report_key(dev, BTN_LEFT, packet[0] & 0x01); -- input_report_key(dev, BTN_RIGHT, packet[0] & 0x02); -+ /* For clickpads map both buttons to BTN_LEFT */ -+ if (etd->fw_version & 0x001000) { -+ input_report_key(dev, BTN_LEFT, packet[0] & 0x03); -+ } else { -+ input_report_key(dev, BTN_LEFT, packet[0] & 0x01); -+ input_report_key(dev, BTN_RIGHT, packet[0] & 0x02); -+ } -+ - input_mt_report_pointer_emulation(dev, true); - input_sync(dev); - } --- -2.0.0 - diff --git a/kernel.spec b/kernel.spec index ed5cc9476..f7f0878b7 100644 --- a/kernel.spec +++ b/kernel.spec @@ -74,7 +74,7 @@ Summary: The Linux kernel %if 0%{?released_kernel} # Do we have a -stable update to apply? -%define stable_update 9 +%define stable_update 11 # Is it a -stable RC? %define stable_rc 0 # Set rpm version accordingly @@ -755,26 +755,13 @@ Patch25096: drm-i915-set-backlight-duty-cycle-after-backlight-enable-for-gen4.pa Patch25097: e1000e-Fix-SHRA-register-access-for-82579.patch Patch25098: e1000e-Failure-to-write-SHRA-turns-on-PROMISC-mode.patch -#rhbz 1099761 -Patch25099: NFS-populate-net-in-mount-data-when-remounting.patch - #rhbz 1106856 Patch25100: dm-thin-update-discard_granularity-to-reflect-the-thin-pool-blocksize.patch -#rhbz 1103528 -Patch25101: elantech-Deal-with-clickpads-reporting-right-button-.patch - Patch25102: intel_pstate-Fix-setting-VID.patch Patch25103: intel_pstate-dont-touch-turbo-bit-if-turbo-disabled-or-unavailable.patch Patch25104: intel_pstate-Update-documentation-of-max-min_perf_pct-sysfs-files.patch -#CVE-2014-4508 rhbz 1111590 1112073 -Patch25106: x86_32-entry-Do-syscall-exit-work-on-badsys.patch - -#CVE-2014-0206 rhbz 1094602 1112975 -Patch25107: aio-fix-kernel-memory-disclosure-in-io_getevents-int.patch -Patch25108: aio-fix-aio-request-leak-when-events-are-reaped-by-u.patch - Patch25109: revert-input-wacom-testing-result-shows-get_report-is-unnecessary.patch #rhbz 1021036 @@ -1479,26 +1466,13 @@ ApplyPatch drm-i915-set-backlight-duty-cycle-after-backlight-enable-for-gen4.pat ApplyPatch e1000e-Fix-SHRA-register-access-for-82579.patch ApplyPatch e1000e-Failure-to-write-SHRA-turns-on-PROMISC-mode.patch -#rhbz 1099761 -ApplyPatch NFS-populate-net-in-mount-data-when-remounting.patch - #rhbz 1106856 ApplyPatch dm-thin-update-discard_granularity-to-reflect-the-thin-pool-blocksize.patch -#rhbz 1103528 -ApplyPatch elantech-Deal-with-clickpads-reporting-right-button-.patch - ApplyPatch intel_pstate-Fix-setting-VID.patch ApplyPatch intel_pstate-dont-touch-turbo-bit-if-turbo-disabled-or-unavailable.patch ApplyPatch intel_pstate-Update-documentation-of-max-min_perf_pct-sysfs-files.patch -#CVE-2014-4508 rhbz 1111590 1112073 -ApplyPatch x86_32-entry-Do-syscall-exit-work-on-badsys.patch - -#CVE-2014-0206 rhbz 1094602 1112975 -ApplyPatch aio-fix-kernel-memory-disclosure-in-io_getevents-int.patch -ApplyPatch aio-fix-aio-request-leak-when-events-are-reaped-by-u.patch - ApplyPatch revert-input-wacom-testing-result-shows-get_report-is-unnecessary.patch #rhbz 1021036 @@ -2317,6 +2291,11 @@ fi # and build. %changelog +* Mon Jul 7 2014 Justin M. Forbes - 3.14.11-100 +- Linux v3.14.11 +- Fixes CVE-2014-4715 (rhbz 1115767 1116362) +- Fixes CVE-2014-4699 (rhbz 1115927 1116477) + * Fri Jun 27 2014 Hans de Goede - Add patch to fix wifi on lenove yoga 2 series (rhbz#1021036) diff --git a/sources b/sources index 47520ceb0..42ea53bef 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ b621207b3f6ecbb67db18b13258f8ea8 linux-3.14.tar.xz -36afad9ad57386a409c8999e15541a7f patch-3.14.9.xz +5cf3d2cb0f552c2c6faf829b6630e84f patch-3.14.11.xz diff --git a/x86_32-entry-Do-syscall-exit-work-on-badsys.patch b/x86_32-entry-Do-syscall-exit-work-on-badsys.patch deleted file mode 100644 index c174e9453..000000000 --- a/x86_32-entry-Do-syscall-exit-work-on-badsys.patch +++ /dev/null @@ -1,130 +0,0 @@ -Bugzilla: 1112073 -Upstream-status: Sent for 3.16 and CC'd to stable -Delivered-To: jwboyer@gmail.com -Received: by 10.76.6.212 with SMTP id d20csp139586oaa; - Mon, 23 Jun 2014 14:28:15 -0700 (PDT) -X-Received: by 10.68.222.196 with SMTP id qo4mr32453892pbc.14.1403558895116; - Mon, 23 Jun 2014 14:28:15 -0700 (PDT) -Return-Path: -Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) - by mx.google.com with ESMTP id bm3si23587434pad.232.2014.06.23.14.27.47 - for ; - Mon, 23 Jun 2014 14:28:15 -0700 (PDT) -Received-SPF: none (google.com: stable-owner@vger.kernel.org does not designate permitted sender hosts) client-ip=209.132.180.67; -Authentication-Results: mx.google.com; - spf=neutral (google.com: stable-owner@vger.kernel.org does not designate permitted sender hosts) smtp.mail=stable-owner@vger.kernel.org -Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand - id S1752475AbaFWVWX (ORCPT + 73 others); - Mon, 23 Jun 2014 17:22:23 -0400 -Received: from mail-pb0-f42.google.com ([209.85.160.42]:39692 "EHLO - mail-pb0-f42.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org - with ESMTP id S1752518AbaFWVWW (ORCPT - ); Mon, 23 Jun 2014 17:22:22 -0400 -Received: by mail-pb0-f42.google.com with SMTP id ma3so6319797pbc.15 - for ; Mon, 23 Jun 2014 14:22:21 -0700 (PDT) -X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; - d=1e100.net; s=20130820; - h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to - :references:mime-version:content-type:content-transfer-encoding; - bh=7AW5eK5e3OhAcFYPrsffKoD56CbJdqfg9BcyF1JKfUE=; - b=iLlWTJCuH9FlKTif4N6XtFZNvj8a/fbsjuP4kWWD/gmHHGEOWI6bh2Jm8X3vcN6GtV - f7rqFO0SAMf197e66uME3pq8NzYFad4eRgJpBGON93P22+cPbqrsT9FZjMZqn2bJkEw4 - EDZZy2MFqm3Kx2m/5g76NLDV1tgafEnwbgL1vg6IxlbPi6J8inkXwKP3FdMoTcfRBO6p - dIcI1cV7VDNf6zKaMj+XS/ZiSxqpArhwvZ6xnXRmLfgD+x/JsxEcg2pX03BXHTKO9QNm - nixe+cuug0X0E5idHuiLJzV0Wf6IhYsvVz/FvjY16pggduecA2NgNU2e7txqb+IcTBZ/ - jBbA== -X-Gm-Message-State: ALoCoQlblcwmTrVjpekrIOzidDrxwB18p5Rfd5SObiPQifpOQZmSFUKrxzV0kxCjcW/wVwxOzAG7 -X-Received: by 10.68.197.8 with SMTP id iq8mr32930210pbc.124.1403558541680; - Mon, 23 Jun 2014 14:22:21 -0700 (PDT) -Received: from localhost (50-76-60-73-ip-static.hfc.comcastbusiness.net. [50.76.60.73]) - by mx.google.com with ESMTPSA id fl6sm99195659pab.43.2014.06.23.14.22.19 - for - (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); - Mon, 23 Jun 2014 14:22:20 -0700 (PDT) -From: Andy Lutomirski -Cc: "H. Peter Anvin" , - Richard Weinberger , X86 ML , - Eric Paris , - Linux Kernel , - security@kernel.org, Steven Rostedt , - Borislav Petkov , - =?UTF-8?q?Toralf=20F=C3=B6rster?= , - Andy Lutomirski , stable@vger.kernel.org, - Roland McGrath -Subject: [PATCH] x86_32,entry: Do syscall exit work on badsys (CVE-2014-4508) -Date: Mon, 23 Jun 2014 14:22:15 -0700 -Message-Id: -X-Mailer: git-send-email 1.9.3 -In-Reply-To: -References: -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit -To: unlisted-recipients:; (no To-header on input) -Sender: stable-owner@vger.kernel.org -Precedence: bulk -List-ID: -X-Mailing-List: stable@vger.kernel.org - -The bad syscall nr paths are their own incomprehensible route -through the entry control flow. Rearrange them to work just like -syscalls that return -ENOSYS. - -This fixes an OOPS in the audit code when fast-path auditing is -enabled and sysenter gets a bad syscall nr (CVE-2014-4508). - -This has probably been broken since Linux 2.6.27: -af0575bba0 i386 syscall audit fast-path - -Cc: stable@vger.kernel.org -Cc: Roland McGrath -Reported-by: Toralf Förster -Signed-off-by: Andy Lutomirski ---- - -I realize that the syscall audit fast path and badsys code, on 32-bit -x86 no less, is possibly one of the least fun things in the kernel to -review, but this is still a real security bug and should get fixed :( - -So I'm cc-ing a bunch of people and maybe someone will review it. - - arch/x86/kernel/entry_32.S | 10 ++++++++-- - 1 file changed, 8 insertions(+), 2 deletions(-) - -diff --git a/arch/x86/kernel/entry_32.S b/arch/x86/kernel/entry_32.S -index a2a4f46..f4258a5 100644 ---- a/arch/x86/kernel/entry_32.S -+++ b/arch/x86/kernel/entry_32.S -@@ -431,9 +431,10 @@ sysenter_past_esp: - jnz sysenter_audit - sysenter_do_call: - cmpl $(NR_syscalls), %eax -- jae syscall_badsys -+ jae sysenter_badsys - call *sys_call_table(,%eax,4) - movl %eax,PT_EAX(%esp) -+sysenter_after_call: - LOCKDEP_SYS_EXIT - DISABLE_INTERRUPTS(CLBR_ANY) - TRACE_IRQS_OFF -@@ -688,7 +689,12 @@ END(syscall_fault) - - syscall_badsys: - movl $-ENOSYS,PT_EAX(%esp) -- jmp resume_userspace -+ jmp syscall_exit -+END(syscall_badsys) -+ -+sysenter_badsys: -+ movl $-ENOSYS,PT_EAX(%esp) -+ jmp sysenter_after_call - END(syscall_badsys) - CFI_ENDPROC - /* --- -1.9.3 - --- -To unsubscribe from this list: send the line "unsubscribe stable" in -the body of a message to majordomo@vger.kernel.org -More majordomo info at http://vger.kernel.org/majordomo-info.html