Skip to content

Commit fdcc9d9

Browse files
authored
Merge pull request #4438 from microsoft/sammeluch/merge-crit-high-cve-fixes
Merge High or Critical CVE Fixes to 2.0 for sqlite, python3, kernel, and nodejs and an update to k3s Vendor Tarball for Dependencies.
2 parents 32cf2a2 + a8d9c5c commit fdcc9d9

File tree

66 files changed

+16167
-107
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

66 files changed

+16167
-107
lines changed

SPECS-SIGNED/kernel-hci-signed/kernel-hci-signed.spec

+7-1
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
%define uname_r %{version}-%{release}
55
Summary: Signed Linux Kernel for HCI
66
Name: kernel-hci-signed-%{buildarch}
7-
Version: 5.15.80.1
7+
Version: 5.15.82.1
88
Release: 1%{?dist}
99
License: GPLv2
1010
Vendor: Microsoft Corporation
@@ -149,6 +149,12 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg
149149
%exclude /module_info.ld
150150

151151
%changelog
152+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
153+
- Auto-upgrade to 5.15.82.1
154+
155+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
156+
- Auto-upgrade to 5.15.81.1
157+
152158
* Tue Nov 29 2022 Vince Perri <[email protected]> - 5.15.80.1-1
153159
- Original version for CBL-Mariner.
154160
- License verified

SPECS-SIGNED/kernel-signed/kernel-signed.spec

+10-1
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
%define uname_r %{version}-%{release}
1010
Summary: Signed Linux Kernel for %{buildarch} systems
1111
Name: kernel-signed-%{buildarch}
12-
Version: 5.15.80.1
12+
Version: 5.15.82.1
1313
Release: 1%{?dist}
1414
License: GPLv2
1515
Vendor: Microsoft Corporation
@@ -153,6 +153,15 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg
153153
%exclude /module_info.ld
154154

155155
%changelog
156+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
157+
- Auto-upgrade to 5.15.82.1
158+
159+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
160+
- Auto-upgrade to 5.15.81.1
161+
162+
* Mon Dec 05 2022 Betty Lakes <[email protected]> - 5.15.80.1-2
163+
- Bump release to match kernel
164+
156165
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
157166
- Auto-upgrade to 5.15.80.1
158167

SPECS/LICENSES-AND-NOTICES/LICENSES-MAP.md

+1-1
Large diffs are not rendered by default.

SPECS/LICENSES-AND-NOTICES/data/licenses.json

+2
Original file line numberDiff line numberDiff line change
@@ -2047,6 +2047,8 @@
20472047
"livepatch-5.15.77.1-1.cm2-signed",
20482048
"livepatch-5.15.79.1-1.cm2",
20492049
"livepatch-5.15.80.1-1.cm2",
2050+
"livepatch-5.15.81.1-1.cm2",
2051+
"livepatch-5.15.82.1-1.cm2",
20502052
"livepatching",
20512053
"lld",
20522054
"local-path-provisioner",

SPECS/hyperv-daemons/hyperv-daemons.signatures.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,6 @@
77
"hypervkvpd.service": "c1bb207cf9f388f8f3cf5b649abbf8cfe4c4fcf74538612946e68f350d1f265f",
88
"hypervvss.rules": "94cead44245ef6553ab79c0bbac8419e3ff4b241f01bcec66e6f508098cbedd1",
99
"hypervvssd.service": "22270d9f0f23af4ea7905f19c1d5d5495e40c1f782cbb87a99f8aec5a011078d",
10-
"kernel-5.15.80.1.tar.gz": "690c866bf52eb1afa660820d24893d799372b887963b3a6653551dea7a5466b5"
10+
"kernel-5.15.82.1.tar.gz": "30a0059b18ea04469340c6e9e21d27786692faf05b3947e3eb13d62e25632b15"
1111
}
1212
}

SPECS/hyperv-daemons/hyperv-daemons.spec

+7-1
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
%global udev_prefix 70
99
Summary: Hyper-V daemons suite
1010
Name: hyperv-daemons
11-
Version: 5.15.80.1
11+
Version: 5.15.82.1
1212
Release: 1%{?dist}
1313
License: GPLv2+
1414
Vendor: Microsoft Corporation
@@ -219,6 +219,12 @@ fi
219219
%{_sbindir}/lsvmbus
220220

221221
%changelog
222+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
223+
- Auto-upgrade to 5.15.82.1
224+
225+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
226+
- Auto-upgrade to 5.15.81.1
227+
222228
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
223229
- Auto-upgrade to 5.15.80.1
224230

SPECS/k3s/k3s-1.23.8.signatures.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
3-
"k3s-1.23.8-vendor.tar.gz": "3c96e864d0e89e318ecdd62e1750f787d1b622feeb240f7b86d9f3280447aeda",
3+
"k3s-1.23.8-vendor.tar.gz": "f6a8ca7fac181a606cf2ef0f09947160ab6037885c08fc8855249c7976762d11",
44
"k3s-1.23.8.tar.gz": "35ff7b3819cf9ff3b33497e335ccfd892a642acd4c5e4223585d225f11fe4b64"
55
}
66
}

SPECS/k3s/k3s-1.23.8.spec

+11-8
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,23 @@
11
Summary: Lightweight Kubernetes
22
Name: k3s
33
Version: 1.23.8
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: ASL 2.0
66
Group: System Environment/Base
77
URL: http://k3s.io
8-
Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+k3s1.tar.gz#/%{name}-%{version}.tar.gz
8+
Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+k3s2.tar.gz#/%{name}-%{version}.tar.gz
99
# Below is a manually created tarball, no download link.
1010
# We're using pre-populated Go modules from this tarball, since network is disabled during build time.
1111
# We are also pre-cloning 3 git repositories
1212
# How to re-build this file:
13-
# 1. wget https://github.com/k3s-io/%%{name}/archive/refs/tags/v%%{version}+k3s1.tar.gz -O %%{name}-%%{version}.tar.gz
13+
# 1. wget https://github.com/k3s-io/%%{name}/archive/refs/tags/v%%{version}+k3s2.tar.gz -O %%{name}-%%{version}.tar.gz
1414
# 2. tar -xf %%{name}-%%{version}.tar.gz
15-
# 3. cd %%{name}-%%{version}-k3s1
15+
# 3. cd %%{name}-%%{version}-k3s2
1616
# 4. go mod vendor
1717
# 5. pushd vendor
18-
# 6. git clone https://github.com/k3s-io/containerd -b v1.5.13-k3s1
19-
# 7. git clone https://github.com/rancher/plugins.git -b k3s-v1.1.1
20-
# 8. git clone https://github.com/opencontainers/runc.git -b v1.1.2
18+
# 6. git clone --single-branch --branch="v1.5.13-k3s1" --depth=1 https://github.com/k3s-io/containerd
19+
# 7. git clone -b "v1.1.1-k3s1" https://github.com/rancher/plugins.git
20+
# 8. git clone --single-branch --branch="v1.1.2" --depth=1 https://github.com/opencontainers/runc
2121
# 9. popd
2222
# 10. tar -cf %%{name}-%%{version}-vendor.tar.gz vendor
2323
Source1: %{name}-%{version}-vendor.tar.gz
@@ -79,6 +79,9 @@ exit 0
7979
%{install_sh}
8080

8181
%changelog
82+
* Thu Dec 08 2022 Vinayak Gupta <[email protected]> - 1.23.8-3
83+
- Update the vendor tarball with the corrected versions of the dependencies
84+
8285
* Tue Nov 01 2022 Olivia Crain <[email protected]> - 1.23.8-2
8386
- Bump release to rebuild with go 1.18.8
8487

@@ -104,4 +107,4 @@ exit 0
104107
- Initial CBL-Mariner import from Rancher (license: ASL 2.0).
105108

106109
* Mon Mar 2 2020 Erik Wilson <[email protected]> 0.1-1
107-
- Initial version
110+
- Initial version

SPECS/k3s/k3s-1.24.3.signatures.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
3-
"k3s-1.24.3-vendor.tar.gz": "af12595259cf8a732b687f8341526b680fbc9266c05e4d095f80c75d891a230f",
3+
"k3s-1.24.3-vendor.tar.gz": "5a4b75cb7bcedc96900126e16df985c0c2c7e4e45ea759dd11d487ddcaf71c32",
44
"k3s-1.24.3.tar.gz": "002fd919452e8fbc61182e1cbf90997a1f8b16a7b835e05e7c40bb52bf830f56"
55
}
66
}

SPECS/k3s/k3s-1.24.3.spec

+8-5
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Summary: Lightweight Kubernetes
22
Name: k3s
33
Version: 1.24.3
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: ASL 2.0
66
Group: System Environment/Base
77
URL: http://k3s.io
@@ -15,9 +15,9 @@ Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+
1515
# 3. cd %%{name}-%%{version}-k3s1
1616
# 4. go mod vendor
1717
# 5. pushd vendor
18-
# 6. git clone https://github.com/k3s.io/containerd.git -b 1.5.13-k3s1
19-
# 7. git clone https://github.com/rancher/plugins.git -b k3s-v1.1.1
20-
# 8. git clone https://github.com/opencontainers/runc.git -b v1.1.3
18+
# 6. git clone --single-branch --branch="v1.6.6-k3s1" --depth=1 https://github.com/k3s-io/containerd
19+
# 7. git clone -b "v1.1.1-k3s1" https://github.com/rancher/plugins.git
20+
# 8. git clone --single-branch --branch="v1.1.3" --depth=1 https://github.com/opencontainers/runc
2121
# 9. popd
2222
# 10. tar -cf %%{name}-%%{version}-vendor.tar.gz vendor
2323
Source1: %{name}-%{version}-vendor.tar.gz
@@ -79,6 +79,9 @@ exit 0
7979
%{install_sh}
8080

8181
%changelog
82+
* Thu Dec 08 2022 Vinayak Gupta <[email protected]> - 1.24.3-3
83+
- Update the vendor tarball with the corrected versions of the dependencies
84+
8285
* Tue Nov 01 2022 Olivia Crain <[email protected]> - 1.24.3-2
8386
- Bump release to rebuild with go 1.18.8
8487

@@ -107,4 +110,4 @@ exit 0
107110
- Initial CBL-Mariner import from Rancher (license: ASL 2.0).
108111

109112
* Mon Mar 2 2020 Erik Wilson <[email protected]> 0.1-1
110-
- Initial version
113+
- Initial version

SPECS/k3s/k3s.signatures.json

+4-4
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
2-
"Signatures": {
3-
"k3s-1.25.0-vendor.tar.gz": "b1acea5ca9c04919fae595162bac4e2761ad9ec500f03d6bec0822a60edb5aef",
4-
"k3s-1.25.0.tar.gz": "3078bfad9fa4402be143e8ba706dd7773e435cf64b67e58c936c26a1ad284e2f"
5-
}
2+
"Signatures": {
3+
"k3s-1.25.0-vendor.tar.gz": "6d6c58fb43e92dcb7d2f074767d415b81f870eecad3f0e2d4eac2fd55f58dc1f",
4+
"k3s-1.25.0.tar.gz": "3078bfad9fa4402be143e8ba706dd7773e435cf64b67e58c936c26a1ad284e2f"
5+
}
66
}

SPECS/k3s/k3s.spec

+8-5
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Summary: Lightweight Kubernetes
22
Name: k3s
33
Version: 1.25.0
4-
Release: 2%{?dist}
4+
Release: 3%{?dist}
55
License: ASL 2.0
66
Group: System Environment/Base
77
URL: http://k3s.io
@@ -15,9 +15,9 @@ Source0: https://github.com/k3s-io/%{name}/archive/refs/tags/v%{version}+
1515
# 3. cd %%{name}-%%{version}-k3s1
1616
# 4. go mod vendor
1717
# 5. pushd vendor
18-
# 6. git clone https://github.com/k3s.io/containerd.git -b 1.5.13-k3s2
19-
# 7. git clone https://github.com/rancher/plugins.git -b k3s-v1.1.1
20-
# 8. git clone https://github.com/opencontainers/runc.git -b v1.1.4
18+
# 6. git clone --single-branch --branch="v1.6.8-k3s1" --depth=1 https://github.com/k3s-io/containerd
19+
# 7. git clone -b "v1.1.1-k3s1" https://github.com/rancher/plugins.git
20+
# 8. git clone --single-branch --branch="v1.1.4" --depth=1 https://github.com/opencontainers/runc
2121
# 9. popd
2222
# 10. tar -cf %%{name}-%%{version}-vendor.tar.gz vendor
2323
Source1: %{name}-%{version}-vendor.tar.gz
@@ -79,6 +79,9 @@ exit 0
7979
%{install_sh}
8080

8181
%changelog
82+
* Thu Dec 08 2022 Vinayak Gupta <[email protected]> - 1.25.0-3
83+
- Update the vendor tarball with the corrected versions of the dependencies
84+
8285
* Tue Nov 01 2022 Olivia Crain <[email protected]> - 1.25.0-2
8386
- Bump release to rebuild with go 1.18.8
8487

@@ -110,4 +113,4 @@ exit 0
110113
- Initial CBL-Mariner import from Rancher (license: ASL 2.0).
111114

112115
* Mon Mar 2 2020 Erik Wilson <[email protected]> 0.1-1
113-
- Initial version
116+
- Initial version
+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
CVE-2022-1204 - Fix already backported to 5.15.35
2+
upstream commit ID 5352a761308397a0e6250fdc629bb3f615b94747 -> stable commit ID 1bf8946d5826788c82971977245bcd3313678eac
3+
upstream commit ID feef318c855a361a1eccd880f33e88c460eb63b4 -> stable commit ID b982492ec3a115e0a136856a1b2dbe32f2d21a0e
4+
upstream commit ID d01ffb9eee4af165d83b08dd73ebdf9fe94a519b -> stable commit ID 9af0fd5c4453a44c692be0cbb3724859b75d739b
5+
upstream commit ID 9fd75b66b8f68498454d685dc4ba13192ae069b0 -> stable commit ID 452ae92b99062d2f6a34324eaf705a3b7eac9f8b
6+
upstream commit ID 87563a043cef044fed5db7967a75741cc16ad2b1 -> stable commit ID bc706d89199b0d8ee5e2229e18fdb9c0720f6ba8
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-2785 - Introducing commit is not in stable tree. No fix necessary at this time.
2+
Upstream introducing commit - b1d18a7574d0df5eb4117c14742baf8bc2b9bb74
3+
Upstream fix commit - 86f44fcec22ce2979507742bc53db8400e454f46
+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
CVE-2022-3344 - Fix already backported 5.15.81.1
2+
Upstream: 16ae56d7e0528559bf8dc9070e3bfd8ba3de80df
3+
Stable: 3e87cb0caa25d667a9ca2fe15fef889e43ab8f95
4+
5+
Upstream: ed129ec9057f89d615ba0c81a4984a90345a1684
6+
Stable: 6425c590d0cc6914658a630a40b7f8226aa028c3
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-3586 - Fix already backported
2+
Upstream: 9efd23297cca530bb35e1848665805d3fcdd7889
3+
Stable: 1a889da60afc017050e1f517b3b976b462846668
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-3595 - Introducing commit is not in stable tree. No fix necessary at this time.
2+
Upstream introducing commit - a4e430c8c8ba96be8c6ec4f2eb108bb8bcbee069
3+
Upstream fix commit - b854b4ee66437e6e1622fda90529c814978cb4ca
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-3910 - Introducing commit is not in stable tree. No fix necessary at this time.
2+
Upstream introducing commit - aa184e8671f0f911fc2fb3f68cd506e4d7838faa
3+
Upstream fix commit - fc7222c3a9f56271fba02aabbfbae999042f1679
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-40768 - Fix already backported
2+
Upstream: 6022f210461fef67e6e676fd8544ca02d1bcfa7a
3+
Stable: 76efb4897bc38b2f16176bae27ae801037ebf49a
+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-4127 - Introducing commit is not in stable tree. No fix necessary at this time.
2+
Upstream introducing commit - a7c41b4687f5902af70cd559806990930c8a307b
3+
Upstream fix commit - d785a773bed966a75ca1f11d108ae1897189975b
+2
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
CVE-2022-41849 - Fix already backported 5.15.75
2+
upstream commit ID 5610bcfe8693c02e2e4c8b31427f1bdbdecc839c -> stable commit ID 2b0897e33682a332167b7d355eec28693b62119e
+2
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
CVE-2022-41850 - Fix already backported 5.15.75
2+
upstream commit ID cacdb14b1c8d3804a3a7d31773bc7569837b71a4 -> stable commit ID c61786dc727d1850336d12c85a032c9a36ae396d
+7
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
CVE-2022-43945 - Fix already backported
2+
upstream commit ID 90bfc37b5ab91c1a6165e3e5cfc49bf04571b762 -> stable commit ID 6b55707ff8b296243a9cf6636d6d8459b6a4a7f8
3+
upstream commit ID 1242a87da0d8cd2a428e96ca68e7ea899b0f4624 -> stable commit ID cedaf73c8bdaa666cd125257861155f273464a6f
4+
upstream commit ID 00b4492686e0497fdb924a9d4c8f6f99377e176c -> stable commit ID dc7f225090c29a5f3b9419b1af32846a201555e7
5+
upstream commit ID 640f87c190e0d1b2a0fcb2ecf6d2cd53b1c41991 -> stable commit ID 071a076fd1b763aa6fe478efa047e0a549ba9c22
6+
upstream commit ID 401bc1f90874280a80b93f23be33a0e7e2d1f912 -> stable commit ID 2be9331ca6061bc6ea32247266f45b8b21030244
7+
upstream commit ID fa6be9cc6e80ec79892ddf08a8c10cabab9baf38 -> stable commit ID 75d9de25a6f833dd0701ca546ac926cabff2b5af

SPECS/kernel-hci/config

+2-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
#
22
# Automatically generated file; DO NOT EDIT.
3-
# Linux/x86_64 5.15.80.1 Kernel Configuration
3+
# Linux/x86_64 5.15.82.1 Kernel Configuration
44
#
55
CONFIG_CC_VERSION_TEXT="gcc (GCC) 11.2.0"
66
CONFIG_CC_IS_GCC=y
@@ -1080,6 +1080,7 @@ CONFIG_INET_ESP=m
10801080
CONFIG_INET_ESP_OFFLOAD=m
10811081
# CONFIG_INET_ESPINTCP is not set
10821082
CONFIG_INET_IPCOMP=m
1083+
CONFIG_INET_TABLE_PERTURB_ORDER=16
10831084
CONFIG_INET_XFRM_TUNNEL=m
10841085
CONFIG_INET_TUNNEL=m
10851086
CONFIG_INET_DIAG=m
+2-2
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"Signatures": {
33
"cbl-mariner-ca-20211013.pem": "5ef124b0924cb1047c111a0ecff1ae11e6ad7cac8d1d9b40f98f99334121f0b0",
4-
"config": "fe32017659bbf9d2bdcc39269d165842f5df91c53d87e7ad6bc9d4570fbf3201",
5-
"kernel-5.15.80.1.tar.gz": "690c866bf52eb1afa660820d24893d799372b887963b3a6653551dea7a5466b5"
4+
"config": "3cf926491158fb0926e81ebea4f364d7052f6d21538c84e40773e87a3c5771d1",
5+
"kernel-5.15.82.1.tar.gz": "30a0059b18ea04469340c6e9e21d27786692faf05b3947e3eb13d62e25632b15"
66
}
77
}

SPECS/kernel-hci/kernel-hci.spec

+7-1
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88

99
Summary: Linux Kernel for HCI
1010
Name: kernel-hci
11-
Version: 5.15.80.1
11+
Version: 5.15.82.1
1212
Release: 1%{?dist}
1313
License: GPLv2
1414
Vendor: Microsoft Corporation
@@ -408,6 +408,12 @@ ln -sf linux-%{uname_r}.cfg /boot/mariner.cfg
408408
%{_sysconfdir}/bash_completion.d/bpftool
409409

410410
%changelog
411+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
412+
- Auto-upgrade to 5.15.82.1
413+
414+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
415+
- Auto-upgrade to 5.15.81.1
416+
411417
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
412418
- Auto-upgrade to 5.15.80.1
413419

Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
22
"Signatures": {
3-
"kernel-5.15.80.1.tar.gz": "690c866bf52eb1afa660820d24893d799372b887963b3a6653551dea7a5466b5"
3+
"kernel-5.15.82.1.tar.gz": "30a0059b18ea04469340c6e9e21d27786692faf05b3947e3eb13d62e25632b15"
44
}
55
}

SPECS/kernel-headers/kernel-headers.spec

+10-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
Summary: Linux API header files
22
Name: kernel-headers
3-
Version: 5.15.80.1
3+
Version: 5.15.82.1
44
Release: 1%{?dist}
55
License: GPLv2
66
Vendor: Microsoft Corporation
@@ -36,6 +36,15 @@ cp -rv usr/include/* /%{buildroot}%{_includedir}
3636
%{_includedir}/*
3737

3838
%changelog
39+
* Tue Dec 13 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.82.1-1
40+
- Auto-upgrade to 5.15.82.1
41+
42+
* Wed Dec 07 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.81.1-1
43+
- Auto-upgrade to 5.15.81.1
44+
45+
* Mon Dec 05 2022 Betty Lakes <[email protected]> - 5.15.80.1-2
46+
- Bump release to match kernel
47+
3948
* Tue Nov 29 2022 CBL-Mariner Servicing Account <[email protected]> - 5.15.80.1-1
4049
- Auto-upgrade to 5.15.80.1
4150

SPECS/kernel/CVE-2022-1204.nopatch

+6
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
CVE-2022-1204 - Fix already backported to 5.15.35
2+
upstream commit ID 5352a761308397a0e6250fdc629bb3f615b94747 -> stable commit ID 1bf8946d5826788c82971977245bcd3313678eac
3+
upstream commit ID feef318c855a361a1eccd880f33e88c460eb63b4 -> stable commit ID b982492ec3a115e0a136856a1b2dbe32f2d21a0e
4+
upstream commit ID d01ffb9eee4af165d83b08dd73ebdf9fe94a519b -> stable commit ID 9af0fd5c4453a44c692be0cbb3724859b75d739b
5+
upstream commit ID 9fd75b66b8f68498454d685dc4ba13192ae069b0 -> stable commit ID 452ae92b99062d2f6a34324eaf705a3b7eac9f8b
6+
upstream commit ID 87563a043cef044fed5db7967a75741cc16ad2b1 -> stable commit ID bc706d89199b0d8ee5e2229e18fdb9c0720f6ba8

SPECS/kernel/CVE-2022-2785.nopatch

+3
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
CVE-2022-2785 - Introducing commit is not in stable tree. No fix necessary at this time.
2+
Upstream introducing commit - b1d18a7574d0df5eb4117c14742baf8bc2b9bb74
3+
Upstream fix commit - 86f44fcec22ce2979507742bc53db8400e454f46

0 commit comments

Comments
 (0)