Change log for linux-source-2.6.15 package in Ubuntu

150 of 73 results
Obsolete in dapper-security
Obsolete in dapper-updates
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-57.97) dapper-proposed; urgency=low

  [ Brad Figg ]

  * Release Tracking Bug
    - LP: #771895

  [Upstream Kernel Changes]

  * av7110: check for negative array offset, CVE-2011-0521
    - LP: #767526
    - CVE-2011-0521
  * af_unix: limit unix_tot_inflight, CVE-2010-4249
    - LP: #769182
    - CVE-2010-4249
  * IB/cm: Bump reference count on cm_id before invoking callback,
    CVE-2011-0695
    - LP: #770369
    - CVE-2011-0695
  * fs/partitions/ldm.c: fix oops caused by corrupted partition table,
    CVE-2011-1017
    - LP: #771382
    - CVE-2011-1017
  * ldm: corrupted partition table can cause kernel oops, CVE-2011-1017
    - LP: #771382
    - CVE-2011-1017

Available diffs

Superseded in dapper-proposed
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-57.95) dapper-proposed; urgency=low

  [ Brad Figg ]

  * Release Tracking Bug
    - LP: #736366

  [ Upstream Kernel Changes ]

  * do_exit(): make sure that we run with get_fs() == USER_DS,
    CVE-2010-4258
    - LP: #723945
    - CVE-2010-4258
  * [Dapper] x25: Prevent crashing when parsing bad X.25 facilities
    CVE-2010-4164
    - LP: #731199
    - CVE-2010-4164
 -- Brad Figg <email address hidden>   Wed, 16 Mar 2011 12:51:56 -0700

Available diffs

Superseded in dapper-security
Superseded in dapper-updates
Superseded in dapper-proposed
linux-source-2.6.15 (2.6.15-57.94) dapper-proposed; urgency=low

  [ Brad Figg ]

  * Tracking Bug
    - LP: #725090

  [ Upstream Kernel Changes ]

  * bluetooth: Fix missing NULL check, CVE-2010-4242
    - LP: #714846
    - CVE-2010-4242
  * bio: take care not overflow page count when mapping/copying user data,
    CVE-2010-4162
    - LP: #721441
    - CVE-2010-4162
  * filter: make sure filters dont read uninitialized memory
    - LP: #721282
    - CVE-2010-4158
  * tty: Make tiocgicount a handler, CVE-2010-4076, CVE-2010-4077
    - LP: #720189
    - CVE-2010-4077
  * block: check for proper length of iov entries earlier in
    blk_rq_map_user_iov(), CVE-2010-4163
    - LP: #721504
    - CVE-2010-4163
 -- Brad Figg <email address hidden>   Fri, 25 Feb 2011 08:05:54 -0800

Available diffs

Superseded in dapper-security
Superseded in dapper-updates
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-55.93) dapper-proposed; urgency=low

  [ Steve Conklin ]

  * Tracking Bug
    - LP: #716472

  [Upstream Kernel Changes]

  * net: Truncate recvfrom and sendto length to INT_MAX., CVE-2010-3859
    - LP: #711855, #708839
    - CVE-2010-4160
  * net: Limit socket I/O iovec total length to INT_MAX., CVE-2010-3859
    - LP: #711855, #708839
    - CVE-2010-4160
  * net: ax25: fix information leak to userland, CVE-2010-3875
    - LP: #710714
    - CVE-2010-3875
  * net: ax25: fix information leak to userland harder, CVE-2010-3875
    - LP: #710714
    - CVE-2010-3875
  * memory corruption in X.25 facilities parsing, CVE-2010-3873
    - LP: #709372
    - CVE-2010-3873
  * net: packet: fix information leak to userland, CVE-2010-3876
    - LP: #710714
    - CVE-2010-3876
  * x86: replace LOCK_PREFIX in futex.h, CVE-2010-3086
    - LP: #706060
    - CVE-2010-3086
  * gdth: integer overflow in ioctl, CVE-2010-4157
    - LP: #711797
    - CVE-2010-4157
  * ALSA: sound/pci/rme9652: prevent reading uninitialized stack memory,
    CVE-2010-4080, CVE-2010-4081
    - LP: #712723, #712737
    - CVE-2010-4081
  * sys_semctl: fix kernel stack leakage, CVE-2010-4083
    - LP: #712749
    - CVE-2010-4083
  * inet_diag: Make sure we actually run the same bytecode we audited,
    CVE-2010-3880
    - LP: #711865
    - CVE-2010-3880

Available diffs

Superseded in dapper-security
Superseded in dapper-updates
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-55.91) dapper-proposed; urgency=low

  [ Leann Ogasawara ]

  - LP: #683908
  * Revert "SAUCE: AF_ECONET saddr->cookie prevent NULL pointer
    dereference"
  * Revert "SAUCE: AF_ECONET SIOCSIFADDR ioctl does not check privileges"
  * Revert "SAUCE: AF_ECONET prevent kernel stack overflow"

  [Upstream Kernel Changes]

  * xfs: validate untrusted inode numbers during lookup
    - CVE-2010-2943
  * xfs: rename XFS_IGET_BULKSTAT to XFS_IGET_UNTRUSTED
    - CVE-2010-2943
  * xfs: remove block number from inode lookup code
    - CVE-2010-2943
  * xfs: fix untrusted inode number lookup
    - CVE-2010-2943
  * drivers/net/eql.c: prevent reading uninitialized stack memory
    - CVE-2010-3297
  * ipc: shm: fix information leak to userland
    - CVE-2010-4072
  * econet: disallow NULL remote addr for sendmsg(), fixes CVE-2010-3849
    - CVE-2010-3849
  * econet: fix CVE-2010-3850
    - CVE-2010-3850
  * econet: fix CVE-2010-3848
    - CVE-2010-3848
 -- Leann Ogasawara <email address hidden>   Wed, 01 Dec 2010 10:32:18 -0800
Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.90) dapper-security; urgency=low

  [ Leann Ogasawara ]

  * SAUCE: AF_ECONET prevent kernel stack overflow
    - CVE-2010-3848
  * SAUCE: AF_ECONET SIOCSIFADDR ioctl does not check privileges
    - CVE-2010-3850
  * SAUCE: AF_ECONET saddr->cookie prevent NULL pointer dereference
    - CVE-2010-3849
 -- Leann Ogasawara <email address hidden>   Fri, 19 Nov 2010 16:39:23 -0800

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.89) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * mm: Use helper to find real vma with stack guard page
    - LP: #646114
  * mm: Do not assume ENOMEM when looking at a split stack vma
    - LP: #646114
  * Fix pktcdvd ioctl dev_minor range check
    - CVE-2010-3437
  * sctp: Do not reset the packet during sctp_packet_config().
    - CVE-2010-3432
  * rose: Fix signedness issues wrt. digi count.
    - CVE-2010-3310
  * ALSA: seq/oss - Fix double-free at error path of snd_seq_oss_open()
    - CVE-2010-3080
  * aio: check for multiplication overflow in do_io_submit
    - CVE-2010-3067
  * jfs: don't allow os2 xattr namespace overlap with others
    - CVE-2010-2946
  * net sched: fix some kernel memory leaks
    - CVE-2010-2942
  * nfsd4: bug in read_buf
    - CVE-2010-2521
  * cifs: Fix a kernel BUG with remote OS/2 server (try #3)
    - CVE-2010-2248
 -- Steve Conklin <email address hidden>   Wed, 06 Oct 2010 16:11:41 +0100

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.88) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * compat: Make compat_alloc_user_space() incorporate the access_ok()
    - CVE-2010-3081
 -- Stefan Bader <email address hidden>   Thu, 16 Sep 2010 16:08:16 +0200
Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.87) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * mm: keep a guard page below a grow-down stack segment
    - CVE-2010-2240
  * mm: fix missing page table unmap for stack guard page failure case
    - CVE-2010-2240
  * mm: fix page table unmap for stack guard page properly
    - CVE-2010-2240
  * mm: fix up some user-visible effects of the stack guard page
    - CVE-2010-2240
  * x86: don't send SIGBUS for kernel page faults
    - CVE-2010-2240
  * mm: pass correct mm when growing stack
    - CVE-2010-2240
 -- Stefan Bader <email address hidden>   Wed, 18 Aug 2010 11:09:36 +0200

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.86) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * sctp: Fix skb_over_panic resulting from multiple invalid parameter
    errors (CVE-2010-1173) (v4)
    - CVE-2010-1173
  * sctp: fix append error cause to ERROR chunk correctly
    - CVE-2010-1173
  * KEYS: find_keyring_by_name() can gain access to a freed keyring
    - CVE-2010-1437
  * sparc64: Fix sun4u execute bit check in TSB I-TLB load.
    - CVE-2010-1451
  * nfsd: fix vm overcommit crash
    - CVE-2010-1643
  * nfsd: fix vm overcommit crash fix #2
    - CVE-2008-7256
 -- Stefan Bader <email address hidden>   Tue, 20 Jul 2010 18:19:52 +0200

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.84) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * USB: usbfs: properly clean up the as structure on error paths
    - CVE-2010-1083
  * Bluetooth: Fix potential bad memory access with sysfs files
    - CVE-2010-1084
  * dvb-core: Fix DoS bug in ULE decapsulation code that can be triggered
    by an invalid Payload Pointer
    - CVE-2010-1086
  * GFS2: Skip check for mandatory locks when unlocking
    - CVE-2010-0727
  * skb is unexpectedly freed.
    - CVE-2010-1188
  * idr: fix a critical misallocation bug, take#2
    - LP: #485556
  * NFS: Fix an Oops when truncating a file
    - CVE-2010-1087
  * r8169: Fix receive buffer length when MTU is between 1515 and 1536
    - CVE-2009-4537
  * r8169: offical fix for CVE-2009-4537 (overlength frame DMAs)
    - CVE-2009-4537
  * SCTP: drop SACK if ctsn is not less than the next tsn of assoc
    - CVE-2010-0008
  * SCTP: Clean up OOTB handling and fix infinite loop processing
    - CVE-2010-0008
  * Fix for CVE-2009-4271
    - CVE-2009-4271
 -- Stefan Bader <email address hidden>   Tue, 25 May 2010 11:54:31 +0200

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.83) dapper-security; urgency=low

  [ Stefan Bader ]

  * Revert "[Upstream] e1000: enhance frame fragment detection"
    - CVE-2009-4536

  [ Upstream Kernel Changes ]

  * e1000: enhance frame fragment detection
    - CVE-2009-4536
  * connector: Delete buggy notification code.
    - CVE-2010-0410
  * Split 'flush_old_exec' into two functions
    - CVE-2010-0307
  * Fix 'flush_old_exec()/setup_new_exec()' split
    - CVE-2010-0307
  * powerpc: TIF_ABI_PENDING bit removal
    - CVE-2010-0307
  * sparc: TIF_ABI_PENDING bit removal
    - CVE-2010-0307
  * x86: get rid of the insane TIF_ABI_PENDING bit
    - CVE-2010-0307
  * x86: set_personality_ia32() misses force_personality32
    - CVE-2010-0307
  * x86: Increase MIN_GAP to include randomized stack
    - LP: #504164
 -- Stefan Bader <email address hidden>   Thu, 04 Mar 2010 09:33:33 +0000

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.82) dapper-security; urgency=low

  [ Leann Ogasawara ]

  * [Upstream] e1000: enhance frame fragment detection
    - CVE-2009-4536

  [ Upstream Kernel Changes ]

  * hfs: fix a potential buffer overflow
    - CVE-2009-4020
  * fuse: prevent fuse_put_request on invalid pointer
    - CVE-2009-4021
  * netfilter: ebtables: enforce CAP_NET_ADMIN
    - CVE-2010-0007
  * untangle the do_mremap() mess
    - CVE-2010-0291
 -- Leann Ogasawara <email address hidden>   Tue, 19 Jan 2010 11:11:38 -0800

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.81) dapper-security; urgency=low

  [Upstream Kernel Changes]

  * [UBUNTU:debian] Start next release
  * net ax25: Fix signed comparison in the sockopt handler
    - CVE-2009-2909
  * x86: Don't leak 64-bit kernel register values to 32-bit processes
    - CVE-2009-2910
  * tc: Fix unitialized kernel memory leak
    - CVE-2009-3228
  * fs: pipe.c null pointer dereference
    - CVE-2009-3547
  * netlink: fix typo in initialization
    - CVE-2009-3612
  * r8169: use hardware auto-padding.
    - CVE-2009-3613
  * drm/r128: Add test for initialisation to all ioctls that require it
    - CVE-2009-3620
  * AF_UNIX: Fix deadlock on connecting to shutdown socket
    - CVE-2009-3621
  * NFSv4: Fix a problem whereby a buggy server can oops the kernel
    - CVE-2009-3726
  * NOMMU: Don't pass NULL pointers to fput() in do_mmap_pgoff()
    - CVE-2009-3888
  * isdn: hfc_usb: Fix read buffer overflow
    - CVE-2009-4005
  * gdth: Prevent negative offsets in ioctl CVE-2009-3080
    - CVE-2009-3080
 -- Leann Ogasawara <email address hidden>   Sun, 29 Nov 2009 15:36:02 -0800

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-55.80) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * missing capability check in z90crypt
    - CVE-2009-1883
  * Fix MSG_PROBE crash
    - CVE-2009-2698
  * parisc: isa-eeprom - Fix loff_t usage
    - CVE-2009-2846
  * do_sigaltstack: avoid copying 'stack_t' as a structure to user space
    - CVE-2009-2847
  * execve: must clear current->clear_child_tid
    - CVE-2009-2848
  * appletalk: Fix skb leak when ipddp interface is not loaded
    - CVE-2009-2903
  * NET: llc, zero sockaddr_llc struct
    - CVE-2009-3001
  * appletalk: fix atalk_getname() leak
    - CVE-2009-3002
  * econet: Fix econet_getname() leak
    - CVE-2009-3002
  * irda: Fix irda_getname() leak
    - CVE-2009-3002
  * netrom: Fix nr_getname() leak
    - CVE-2009-3002
  * rose: Fix rose_getname() leak
    - CVE-2009-3002
  * random: make get_random_int() more random
    - CVE-2009-3238
  * nfsd4: reindent do_open_lookup()
    - CVE-2009-3286
  * nfsd4: fix open-create permissions
    - CVE-2009-3286
  * nfsd4: turn nfsd4_open struct's iattr/verf union into separate fields
    - CVE-2009-3286

 -- Leann Ogasawara <email address hidden>   Tue, 06 Oct 2009 12:00:48 -0700

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-54.79) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * Make sock_sendpage() use kernel_sendpage()
    - CVE-2009-2692

 -- Stefan Bader <email address hidden>   Mon, 17 Aug 2009 16:48:18 +0000

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-54.78) dapper-security; urgency=low

  [ Upstream Kernel Changes ]

  * Add '-fno-delete-null-pointer-checks' to gcc CFLAGS
    - LP: #403647
  * r8169: fix crash when large packets are received
    - CVE-2009-1389

 -- Stefan Bader <email address hidden>   Thu, 23 Jul 2009 15:32:46 +0200

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-54.77) dapper-security; urgency=low

  [ Stefan Bader ]

  * cifs: backport buffer size fixes for CIFSGetDFSRefer()
    - CVE-2009-1633
  * backport: NFS: Fix an Oops in encode_lookup()
    - CVE-2009-1336

  [ Upstream Kernel Changes ]

  * Fix build failure in kernel/kexec.c
    - LP: #364430
  * nfsd: nfsd should drop CAP_MKNOD for non-root
    - CVE-2009-1072
  * exit_notify: kill the wrong capable(CAP_KILL) check
    - CVE-2009-1337
  * e1000: add missing length check to e1000 receive routine
    - CVE-2009-1385
  * Fix memory overwrite when saving nativeFileSystem field during mount
    - CVE-2009-1439
  * cifs: Increase size of tmp_buf in cifs_readdir to avoid potential
    overflows
    - CVE-2009-1633
  * agp: zero pages before sending to userspace
    - CVE-2009-1192
  * af_rose/x25: Sanity check the maximum user frame size
    - CVE-2009-1265
  * nfs: Fix NFS v4 client handling of MAY_EXEC in nfs_permission.
    - CVE-2009-1630

 -- Stefan Bader <email address hidden>   Tue, 21 Apr 2009 06:48:20 +0000

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-54.76) dapper-security; urgency=low

  [ Stefan Bader ]

  * Fixing up powerpc specific syscalls
    - CVE-2009-0029

  [ Upstream Kernel Changes ]

  * NFS: Remove the buggy lock-if-signalled case from do_setlk()
    - CVE-2008-4307
  * sctp: Avoid memory overflow while FWD-TSN chunk is received with bad
    stream ID
    - CVE-2009-0065
  * net: 4 bytes kernel memory disclosure in SO_BSDCOMPAT gsopt try #2
    - CVE-2009-0676
  * sparc: Fix mremap address range validation.
    - CVE-2008-6107
  * copy_process: fix CLONE_PARENT && parent_exec_id interaction
    - CVE-2009-0028
  * dell_rbu: use scnprintf() instead of less secure sprintf()
    - CVE-2009-0322
  * drivers/net/skfp: if !capable(CAP_NET_ADMIN): inverted logic
    - CVE-2009-0675
  * x86_64: Implement is_compat_task the right way
    - CVE-2009-0834
  * x86-64: syscall-audit: fix 32/64 syscall hole
    - CVE-2009-0834
  * x86-64: seccomp: fix 32/64 syscall hole
    - CVE-2009-0835
  * shm: fix shmctl(SHM_INFO) lockup with !CONFIG_SHMEM
    - CVE-2009-0859
  * udf: Fix oops when invalid character in
    filename occurs
    - LP: #321606
  * Convert all system calls to return a long
    - CVE-2009-0029
  * Rename old_readdir to sys_old_readdir
    - CVE-2009-0029
  * Remove __attribute__((weak)) from sys_pipe/sys_pipe2
    - CVE-2009-0029
  * Make sys_syslog a conditional system call
    - CVE-2009-0029
  * System call wrapper infrastructure
    - CVE-2009-0029
  * powerpc: Enable syscall wrappers for 64-bit
    - CVE-2009-0029
  * s390: enable system call wrappers
    - CVE-2009-0029
  * System call wrapper special cases
    - CVE-2009-0029
  * Bump ABI
  * System call wrappers part 01
    - CVE-2009-0029
  * System call wrappers part 02
    - CVE-2009-0029
  * System call wrappers part 03
    - CVE-2009-0029
  * System call wrappers part 04
    - CVE-2009-0029
  * System call wrappers part 05
    - CVE-2009-0029
  * System call wrappers part 06
    - CVE-2009-0029
  * System call wrappers part 07
    - CVE-2009-0029
  * System call wrappers part 08
    - CVE-2009-0029
  * System call wrappers part 09
    - CVE-2009-0029
  * System call wrappers part 10
    - CVE-2009-0029
  * System call wrappers part 11
    - CVE-2009-0029
  * System call wrappers part 12
    - CVE-2009-0029
  * System call wrappers part 13
    - CVE-2009-0029
  * System call wrappers part 14
    - CVE-2009-0029
  * System call wrappers part 15
    - CVE-2009-0029
  * System call wrappers part 16
    - CVE-2009-0029
  * System call wrappers part 17
    - CVE-2009-0029
  * System call wrappers part 18
    - CVE-2009-0029
  * System call wrappers part 19
    - CVE-2009-0029
  * System call wrappers part 20
    - CVE-2009-0029
  * System call wrappers part 21
    - CVE-2009-0029
  * System call wrappers part 22
    - CVE-2009-0029
  * System call wrappers part 23
    - CVE-2009-0029
  * System call wrappers part 24
    - CVE-2009-0029
  * System call wrappers part 25
    - CVE-2009-0029
  * System call wrappers part 26
    - CVE-2009-0029
  * System call wrappers part 27
    - CVE-2009-0029
  * System call wrappers part 28
    - CVE-2009-0029
  * System call wrappers part 29
    - CVE-2009-0029
  * System call wrappers part 32
    - CVE-2009-0029
  * System call wrappers part 33
    - CVE-2009-0029
  * s390 specific system call wrappers
    - CVE-2009-0029
  * sparc: Enable syscall wrappers for 64-bit (CVE-2009-0029)
    - CVE-2009-0029
  * syscall define: fix uml compile bug
    - CVE-2009-0029
  * Fixing up the syscall wrappers to match the Dapper (2.6.15) kernel
    - CVE-2009-0029

 -- Stefan Bader <email address hidden>   Mon, 16 Mar 2009 17:26:53 +0100

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-53.75) dapper-security; urgency=low

  [Upstream Kernel Changes]

  * Add preemption point in qdisc_run
    - CVE-2008-5713
  * Rationalise return value of qdisc_restart
    - CVE-2008-5079
  * Prevent multiple qdisc runs
    - CVE-2008-5079
  * ib700wdt.c - fix buffer_underflow bug
    - CVE-2008-5702
  * Enforce a minimum SG_IO timeout
    - CVE-2008-5700
  * net: Fix soft lockups/OOM issues w/ unix garbage collector
    - CVE-2008-5300
  * Fix inotify watch removal/umount races
    - CVE-2008-5182
  * ATM: CVE-2008-5079: duplicate listen() on socket corrupts the vcc table
    - CVE-2008-5079

 -- Stefan Bader <email address hidden>   Fri, 09 Jan 2009 15:17:58 +0100

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-53.74) dapper-security; urgency=low

  [Upstream Kernel Changes]

  * Remove suid/sgid bits on [f]truncate()
    - CVE-2008-4210
  * hfsplus: fix Buffer overflow with a corrupted image
    - CVE-2008-4933
  * hfsplus: check read_mapping_page() return value
    - CVE-2008-4934
  * net: Fix recursive descent in __scm_destroy().
    - CVE-2008-5029
  * security: avoid calling a NULL function pointer in drivers/video/tvaudio.c
    - CVE-2008-5033
  * hfs: fix namelength memory corruption
    - CVE-2008-5025
  * V4L/DVB (9621): Avoid writing outside shadow.bytes[] array

 -- Stefan Bader <email address hidden>   Wed, 19 Nov 2008 09:53:06 +0100

Available diffs

Superseded in dapper-security
Superseded in dapper-updates
Deleted in dapper-security (Reason: wrong component, needs re-copying)
linux-source-2.6.15 (2.6.15-52.73) dapper-security; urgency=low

  [Upstream Kernel Changes]

  * tmpfs: fix kernel BUG in shmem_delete_inode
    - CVE-2008-3534
  * wan: Missing capability checks in sbni_ioctl()
    - CVE-2008-3525
  * dio: zero struct dio with kzalloc instead of manually
    - CVE-2007-6716
  * direct-io: fix error-path crashes
    - CVE-2007-6716

 -- Stefan Bader <email address hidden>   Thu, 25 Sep 2008 23:40:24 +0000
Superseded in dapper-updates
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-52.72) dapper-proposed; urgency=low

  [Colin Ian King]
  * mm: fix zone pages min,max calculations
    - LP: #86778
  * fs: fix semaphore bug introduced by CVE-2007-2878
    - LP: #137978

 -- Stefan Bader <email address hidden>   Thu, 04 Sep 2008 15:27:37 +0000

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-52.71) dapper-security; urgency=low

  * mm: Fix zero length segment loop
    - LP: #249340
    follow-up for CVE-2008-0598

  [Upstream Kernel Changes]

  * Fix compiler warning on 64-bit
    follow-up for CVE-2008-1673

Available diffs

Superseded in dapper-updates
Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-52.69) dapper-security; urgency=low

  [Tim Gardner]

  * HPPA: Added __raw_write_can_lock to fix FTBS caused by
    CVE-2008-2365 patch.
  * Reverted the getabi modenization, instead fixed the path to
    retrieve binary debs.

 -- Tim Gardner <email address hidden>   Thu, 10 Jul 2008 21:02:58 -0600

Available diffs

Superseded in dapper-updates
Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-52.67) dapper-security; urgency=low

  [Upstream Kernel Changes]

  * Set CONFIG_SCSI=y for ia64.
  * [IA64] Fix unaligned handler for floating point instructions with base
    update
  * cifs: CVE-2007-5904: pass buffer size into SendReceive
  * CVE-2007-6694: [POWERPC] CHRP: Fix possible NULL pointer dereference
  * vm audit: add VM_DONTEXPAND to mmap for drivers that need it
    (CVE-2008-0007)
  * sys_setrlimit() cleanup
  * RLIMIT_CPU: fix handling of a zero limit
  * CVE-2008-1294: CPU time limit patch / setrlimit(RLIMIT_CPU, 0) cheat
    fix
  * fix SMP ordering hole in fcntl_setlk() (CVE-2008-1669)
  * Fix dnotify/close race (CVE-2008-1375)
  * cifs: fix up renamed define for small buffer size
  * Convert snd-page-alloc proc file to use seq_file (CVE-2007-4571)

 -- Ben Collins <email address hidden>   Tue, 20 May 2008 15:23:32 +0000

Available diffs

Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-51.66) dapper-security; urgency=low

  * Copy lds linker file (ia64) to headers package.

 -- Tim Gardner <email address hidden>   Mon, 11 Feb 2008 17:13:05 -0700
Superseded in dapper-updates
Deleted in dapper-proposed (Reason: moved to -updates)
linux-source-2.6.15 (2.6.15-51.64) dapper-proposed; urgency=low

  * Revert fix for megaraid, causes an oops/regression.

  [Trivial, non-functional changes]
  * mpspec_def.h: Remove extraneoush packed attribute, causing compiler
    warnings.
  * Makefile: Remove stack-protector from CFLAGS (newer compilers).

 -- Ben Collins <email address hidden>   Wed, 05 Dec 2007 13:22:37 -0500
Superseded in dapper-proposed
linux-source-2.6.15 (2.6.15-51.63) dapper-proposed; urgency=low

  * Fix kernel-versions for ABI bump
  * Fix for kernel crash on lvremove
    - LP: #103729
  * e1000: Disable MSI by default. Allow it to be enabled with module param.
    Some chip implementations seem to not work well with MSI.
    - LP: #56885
  * tg3: Backport from 2.6.16.y
    - LP: #72696
  * Add r1000 to nic-modules
    - LP: #81782
  * Add bnx2 to nic-modules
    - LP: #73647
  * usb-serial: Fix oops with pilot-link
    - LP: #39518
  * megaraid: Move AMI/Megaraid3 IDs from megaraid_mbox.ko to megaraid.ko
    - LP: #57233

 -- Ben Collins <email address hidden>   Tue, 23 Oct 2007 16:57:09 -0400
Superseded in dapper-proposed
linux-source-2.6.15 (2.6.15-51.62) dapper-proposed; urgency=low

  * Fix kernel-versions for ABI bump
  * Fix for kernel crash on lvremove
    - LP: #103729
  * e1000: Disable MSI by default. Allow it to be enabled with module param.
    Some chip implementations seem to not work well with MSI.
    - LP: #56885
  * tg3: Backport from 2.6.16.y
    - LP: #72696
  * Add r1000 to nic-modules
    - LP: #81782
  * Add bnx2 to nic-modules
    - LP: #73647
  * usb-serial: Fix oops with pilot-link
    - LP: #39518
  * megaraid: Move AMI/Megaraid3 IDs from megaraid_mbox.ko to megaraid.ko
    - LP: #57233

 -- Ben Collins <email address hidden>   Mon, 22 Oct 2007 10:08:49 -0400
Superseded in dapper-proposed
linux-source-2.6.15 (2.6.15-51.61) dapper-proposed; urgency=low

  * Fix for kernel crash on lvremove
    - LP: #103729
  * e1000: Disable MSI by default. Allow it to be enabled with module param.
    Some chip implementations seem to not work well with MSI.
    - LP: #56885
  * tg3: Backport from 2.6.16.y
    - LP: #72696
  * Add r1000 to nic-modules
    - LP: #81782
  * Add bnx2 to nic-modules
    - LP: #73647
  * usb-serial: Fix oops with pilot-link
    - LP: #39518
  * megaraid: Move AMI/Megaraid3 IDs from megaraid_mbox.ko to megaraid.ko
    - LP: #57233

 -- Ben Collins <email address hidden>   Mon, 22 Oct 2007 10:08:49 -0400
Superseded in dapper-updates
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-29.60) dapper-security; urgency=low

  * Re-add missing sparc abi files.
  * Fix getabis script so this won't happen again.

 -- Kyle McMartin <email address hidden>   Mon, 24 Sep 2007 12:22:17 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-29.58) dapper-security; urgency=low

  [ security ]

  * CVE-2007-3104: sysfs_readdir NULL ptr dereference causes kernel oops
  * CVE-2007-4308: aacraid: Fix security hole
  * CVE-2005-0504: sanity check dltmp.len size before all copy_from_user() calls
  * CVE-2007-3848: Reset current->pdeath_signal on SUID binary execution
  * CVE-2007-3105: random: fix bound check ordering
  * CVE-2007-2242: [IPV6]: Disallow RH0 by default.

 -- Kyle McMartin <email address hidden>   Wed, 29 Aug 2007 03:22:45 +0000
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-28.57) dapper-security; urgency=medium

  * Change maintainer field to me, for real this time.

  [ security ]

  * CVE-2007-2453: random: fix error in entropy extraction
  * CVE-2007-2453: random: fix seeding with zero entropy

 -- Kyle McMartin <email address hidden>   Wed, 18 Jul 2007 15:42:45 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-28.55) dapper-security; urgency=low

  * Change maintainer field to me.

  [ security ]

  * Brown paper bag fix for CVE-2007-1357.

 -- Kyle McMartin <email address hidden>   Thu, 10 May 2007 04:41:16 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-28.53) dapper-security; urgency=low

  [ Kyle McMartin ]

  * Disable irqs while applying alternative insns (i386/x86_64)

  [ David S. Miller ]

  * Fix mach64 with gcc-4.1 and later...

 -- Kyle McMartin <email address hidden>   Tue, 13 Mar 2007 14:34:21 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-28.51) dapper-security; urgency=low

  [ Security ]

  * CVE-2006-4814: Fix incorrect user space access locking in mincore()
  * CVE-2006-5749: Call init_timer() for ISDN PPP CCP reset state timer
  * CVE-2006-5753: fix memory corruption from misinterpreted bad_inode_ops return values
  * CVE-2006-5755: Don't leak NT bit into next task
  * CVE-2006-5757: grow_buffers() infinite loop fix
  * CVE-2006-5823: corrupted cramfs filesystems cause kernel oops
  * CVE-2006-6053: handle ext3 directory corruption better
  * CVE-2006-6054: ext2: skip pages past number of blocks in ext2_find_entry
  * CVE-2006-6056: hfs_fill_super returns success even if no root inode
  * CVE-2006-6106: [Bluetooth] Add packet size checks for CAPI messages
  * CVE-2006-4572: [NETFILTER]: Fix ip6_tables extension header bypass bug
  * CVE-2006-4572: [NETFILTER]: Fix ip6_tables protocol bypass bug

  [ David S. Miller ]

  * [SPARC64]: Set g4/g5 properly in sun4v dtlb-prot handling.

  [ Kyle McMartin ]

  * sky2: 88E803X transmit lockup
    - Upstream GIT-SHA: 470ea7eba4aaa517533f9b02ac9a104e77264548
  * scsi: handle ->slave_configure return value
    - Upstream GIT-SHA: 938050916f57f08e20595b1fa1c1e57c2fbf7243
    - Malone: #57265

 -- Kyle McMartin <email address hidden>   Mon, 22 Jan 2007 14:51:18 +0100
Superseded in dapper-proposed
linux-source-2.6.15 (2.6.15-50.61) dapper-proposed; urgency=low

  [NOTES]

  * This is the initial release of a line of kernels for dapper-proposed
    updates. This is meant as a means of testing non-security patches more
    thoroughly prior to releasing into mainline dapper.
  * The debian/changelog for dapper-proposed-updates kernel is rolling. This
    means that there will only even be the one changelog for the latest
    version, and it will only contain those changes that differ from the
    dapper proper kernel. Once changes are merged into dapper mainline, they
    will be removed from this top level rolling changelog group.

  [Kyle McMartin]

  * sound/pci/hda: Fix some ALSA typedefs
  * sound/pci/hda: Use old-style IRQ flags in request_irq
  * Fix rejects in 0001-ocfs2-fix-page-zeroing-during-simple-extends.txt,
    maintain ocfs2_data_lock from later kernels...
  * debian/d-i: Enable bnx2 module in installer
  * sky2: Backport v1.9
  * tg3: Backport v3.69
  * forcedeth: Backport v0.59
  * mptfusion: Backport v3.03.05

  [Fabio Massimo Di Nitto]

  * ocfs2: fix page zeroing during simple extends
  * ocfs2: cond_resched() in ocfs2_zero_extend()
  * debian/d-i: Update scsi-modules to include qlogicpti

  [Ben Collins]

  * ahci: Sync with edgy PCI list (add some ATI id's).
  * scsi: Ignore devices that fail slave_configure. Patch from bug report
    (matches same usage in edgy/2.6.17).
    - Malone: #57265
  * i386/io_apic: Fix timer_irq_works detection.
    - Malone: #53910
  * e1000: Disable MSI by default. Allow it to be enabled with module param.
    Some chip implementations seem to not work well with MSI.
    - Malone: #56885

  [Daniel T Chen]

  * sound/drivers/ Fix element typos in dummy driver.
  * sound/pci/hda/: Add missing sub{vendor,device} ids for Intel 915 and
    D102GGC boards
  * sound/pci/hda/: Fix headphone output for Intel 945 systems using
    Sigmatel HDA codec
  * sound/pci/ac97/: Fix non-working IEC958 output on ASUS P5P800-VM
  * sound/pci/hda/: #42600: Fix silent recording from microphone on Dell
    Inspiron 630m (and assorted models)
  * sound/pci/ac97/: Fix bad sound quality on VIA VT1617A
  * sound/usb/: Properly support non-standard sampling rates in USB audio
    driver
  * sound/ppc/: #25634: Fix gpio state detection for tumbler
  * sound/pci/hda/: Clean up hda-intel.c
  * sound/pci/: Fix maestro2 hardware volume control
  * sound/pci/rme9652/: Fix firmware autoupdate for hdsp
  * sound/pci/: Fix HP-only quirk for HP nc8000
  * sound/pci/hda/: Fix SPDIF subdevice for Realtek HDA codecs
  * sound/pci/hda/: Add IDs for LG LW25 laptop with ALC880 HDA codec
  * sound/pci/hda/: Fix speaker output on Acer Aspire 5600 (HDA Realtek 883)
  * sound/pci/hda/: #59715: Fix headphone volume control for generic
    HDA codec parser
  * sound/pci/hda/: Add Motorola and Conexant vendor IDs
  * sound/pci/hda/: Prefer 24-bit format instead of 20-bit for HDA
  * sound/usb/: usb-audio: increase number of packets per URB
  * sound/usb/: Add mixer control names for TerraTec Aureon 5.1 MkII USB
  * sound/pci/hda/: Add MSI support to HDA Intel
  * sound/core/: Fix dereference after free() in snd_hwdep_release()
  * sound/pci/hda/: Add ID for Nvidia MCP61
  * sound/pci/hda/: Add IDs for Acer laptops
  * sound/pci/hda/: Add IDs for Si3054 codec-based HDA modems
  * sound/pci/: Fix MUTE_LED quirk for HP NX 6120
  * sound/pci/: Add HP_MUTE_LED quirk for Dell Latitude D810
  * sound/pci/: Fix HP_MUTE_LED quirk for Dell Inspiron 6000
  * sound/pci/hda/: Backport Sigmatel HDA fixes and ID additions
  * sound/pci/hda/: Increase max DMA buffer size to 1024 MB to support
    multichannel
  * sound/pci/ac97/: Add EAPD hack for MSI L725
  * sound/pci/emu10k1/: Fix reversed argument list in
    snd_emu10k1_resume_regs()
  * sound/pci/hda/: Fix mic input for STAC92xx HDA codecs
  * sound/pci/hda/: Add support for multiple headphone pins
  * sound/pci/hda/: Fix suspend/resume for HDA when MSI is enabled
  * sound/pci/hda/: One more inverted-call-order fix for pci_disable_msi()
  * sound/pci/rme9652/: Add support for RME9632 rev 152
  * sound/isa/: Check kmalloc() return value
  * sound/pci/hda/: Fix mic capture with generic parser
  * sound/core/: Fix timer correction/calculation
  * sound/usb/: Fix analog capture by adding device_setup parameter (affects
    notably M-Audio Audiophile)
  * sound/usb/: Add multichannel support for Turtle Beach Roadie
  * {include/sound,sound/pci/ymfpci}/: Fix swap_rear for S/PDIF passthrough
  * sound/pci/hda/: Fix error checks in HDA Realtek and Analog Devices codecs
    for setting channel mode
  * sound/pci/hda/: Don't fail loading if modem can't be initialised
  * sound/pci/hda/: Fix PCM device assignment for Realtek HDA codecs
  * sound/pci/hda/: Add support for Medion laptops
  * sound/pci/hda/: Add IDs for Asus U5F and Z62F to HDA Analog Devices
  * sound/pci/ac97: #42919: Enable audible sound through MSI S250 laptop
    speakers
  * sound/pci/hda/: Backport support for various Toshiba laptops to HDA
    Realtek
  * sound/pci/hda/: Backport HDA fixes for MSI availability and polling mode
    for CORB/RIRB communication
  * sound/pci/hda/: Backport additions for Realtek ALC660, ALC262, and ALC883
  * sound/pci/hda/: Backport support for ASUS HDA models to Realtek ALC861
  * sound/pci/hda/: Add ID for HP q965 to Realtek HDA codec
  * sound/core/: Fix snd_pcm_playback_silence() semantics
  * sound/pci/hda/: Fix noise on Lenovo A60
  * sound/pci/: #68659: Disable DXS explicitly for 0x1458a002 (VIA-based)
  * sound/pci/rme9652/: Fix missing /proc interface for RME HDSP
  * sound/pci/rme9652/: Disable precise_ptr by default for RME HDSP
  * sound/pci/rme9652/: Add required DDS register support for RME9632
    revisions newer than 152
  * sound/pci/hda/: Add Nvidia HDA MCP67 IDs
  * sound/pci/hda/: #68556: Fix model for Samsung R55 XEH 2300
  * sound/usb/: #36788: Add support for Creative SB Live! 24-bit Ext
  * sound/pci/ac97/: Don't enumerate {HP,Line} Jack Sense elements for two
    models
  * sound/pci/hda/: #42600: Fix Dell system detection for STAC9200
  * sound/pci/hda/: Fix two IDs (ASUS M2N-MX & HP xw4400)

  [Steven Walter]

  * drivers/usb/net/atmel/at76c503-rfmd.c: Fix ad-hoc mode

  [Chuck Short]

  * scsi/ahci: Add JMicron support.
    - Malone: #57502
  * asus_acpi: Added W3V support.
    - Malone: #17125
  * pci: Add VIA PCI quirk for Enhanced/Extnended USB on VT8235 southbridge.
  * drivers/ide/: Old IDE, fix SATA detection for cabling
    - Malone: #59696
    - Upstream Git-SHA: 1a1276e7b6cba549553285f74e87f702bfff6fac

 -- Kyle McMartin <email address hidden>   Wed, 10 Jan 2007 11:23:28 -0500
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-27.50) dapper-security; urgency=low

  [security]

  * CVE-2006-5751: bridge: fix possible overflow in get_fdb_entries
  * CVE-2006-5701: Fix various fsfuzz triggered crashes
  * CVE-2006-5649: POWERPC: Make alignment exception always check
    exception table
  * CVE-2006-5619: [IPV6]: fix lockup via /proc/net/ip6_flowlabel
  * CVE-2006-5173: x86: save/restore eflags in context switch
  * CVE-2006-4997: [ATM] CLIP: Do not refer freed skbuff in clip_mkip()

  [Kyle McMartin]

  * squashfs: Update to version 3.1 from CVS

 -- Kyle McMartin <email address hidden>   Wed, 29 Nov 2006 22:59:43 -0500
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-27.48) dapper-security; urgency=low

  [Security]

  * CVE-2006-4535: Fix for SCTP SO_LINGER DoS.
    - Upstream GIT-SHA: b9ac86727fc02cc7117ef3fe518a4d51cd573c82
  * CVE-2006-4538: ia64 and sparc elf loader memory checking vulnerability.
    - Upstream GIT-SHA: 3a459756810912d2c2bf188cef566af255936b4d

  [Ben Collins]

  * Revert GIT-SHA: 5aae548f78f22a7069342fecad3f9e2e8d308c55
    - VIA Southbridge fixups
    - Malone: #52649
  * sbp2: Fix for lockup on device insertion.
    - Upstream GIT-SHA: 24c7cd0630f76f0eb081d539c53893d9f15787e8
    - Malone: #28647
  * Re-enable sky2 driver, but only for models not supported by the sk98lin
    driver.
    - Malone: #60271

 -- Ben Collins <email address hidden>   Mon, 11 Sep 2006 08:46:07 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-26.47) dapper-security; urgency=low

  [Security]

  * CVE-2006-3468: Exporting ext3 over NFS vulnerability.
    - Upstream GIT-SHA: 2ccb48ebb4de139eef4fcefd5f2bb823cb0d81b9
  * CVE-2006-3735: Buffer overflow in the sctp_make_abort_user() function
    of iptables' SCTP module
    - Upstream GIT-SHA: 96ec9da385cf72c5f775e5f163420ea92e66ded2
  * CVE-2006-4093: PowerPC HID0 DoS.
    - Upstream GIT-SHA: 9a936a2e0526089194159eae31238e36b1c19e74
  * CVE-2006-4145: Fix possible UDF deadlock and memory corruption.
    - Upstream GIT-SHA: 7127be29378b1230eb8dd8b84f18d6b69c56e959

  [Ben Collins]

  * zd1211: Update to latest version of driver
    - Malone: #37795
  * sata_mv: Disable MSI by default
    - Malone: #55234
    - Upstream GIT-SHA: ddef9bb367b19383df627e388cb4c01c86ddba6c
  * p4-clockmod. Lower n60 errata max down to 700Mhz instead of 2ghz.
    - Malone: ##51847
  * usb-hub: Always turn on power to hub ports, even if it doesn't support
    power switching.
    - Malone: #53293
    - Upstream GIT-SHA: 4489a5712b086621a6c3f669057d2996245cd3fb
  * unusual_devs: Add 60G Video iPod.
    - Malone: #54279
  * usb-core: Rate limit the over-current dev_err message.
    - Malone: #55253
  * gamecon: Fix crashes when accessing the device.
    - Malone: #55355
    - Upstrea GIT-SHA's (in order applied)
      - c7fd018d75cae2b0c1cf03003b38f4c76e3df826
      - 77fc46ca5b331df3fc0ffef24012ba0d51d601b3
  * uhci-hub: Increase port-reset completion delay for HP controllers.
    - Malone: #55495
    - Upstream GIT-SHA: ae55717584431761b70215d3d574c13fe97093f2
  * seccomp: Make the TSC disable purely paranoid feature optional, so by
    default seccomp returns absolutely zerocost.
    - Malone: #52272
  * skge: Update to version in 2.6.17, to obtain fixes and D-Link DGE-530T
    support.
    - Malone: #55847
  * ide/via82cxxx: Add vt8237a support.
  * acpi_sbs: Fix perms on capacity_mode module param.
    - Malone: #55806
  * sk98lin: Forward port driver from breezy (known working for sky2).
    - Malone: #38865
  * bluetooth: Rate limit SCO packet error message.
    - Malone: #39414
  * ieee80211: Fix race in wep/tkip crypt modules.
    - Malone: #56894
  * sched: Multi-core scheduler support.
    - Upstream GIT-SHA: 1e9f28fa1eb9773bf65bae08288c6a0a38eef4a7
  * dm-bbr: Device-Mapper Bad Block Relocator. This went missing in dapper
    (was in breezy).

  [Daniel T Chen]

  * sound/pci/hda: Add IDs for ASUS W6A, A7TC; fix support for HP model
    (patch_realtek)
  * sound/pci: Fix inaudible sound by default for ENS1371
  * {include/sound,sound/pci/ymfpci}: Fix PM and IEC958 output for ymfpci
  * sound/pci/ac97: #42194: Use hp_only quirk for Fujitsu Lifebook C1211D
  * sound/pci/hda: Fix sound for Uniwill M31
  * sound/pci/ice1712: Fix typo in sampling rate (16000 not 1600)
  * sound/pci/ac97: Fix inaudible sound for LG K1 Express
  * sound/pci{,/emu10k1}: Miscellaneous cleanups
  * sound/pci/hda: Fix inaudible sound on Sony VAIO AR 11B
  * sound/pci/hda: #56576: Fix inaudible sound on Sony VAIO AR 11S
  * sound/pci/hda: Backport support for HDA STAC9205 family

 -- Ben Collins <email address hidden>   Mon,  7 Aug 2006 13:02:48 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-26.46) dapper-security; urgency=low

  Security:

  * CVE-2006-2934: SCTP conntrack: fix crash triggered by packet without
    chunks.
    Upstream GIT-SHA: dd7271feba61d5dc0fab1cb5365db9926d35ea3a

  * CVE-2006-2935: cdrom: fix bad cgc.buflen assignment.
    Upstream GIT-SHA: 454d6fbc48374be8f53b9bafaa86530cf8eb3bc1

  * CVE-2006-2936: USB serial ftdi_sio: Prevent userspace DoS.
    Upstream GIT-SHA: 224654004ca688af67cec44d9300e8c3f647577c

  Changes by Ben Collins

  * Cherry pick fixes related to incorrect idle time on some processors. This
    may also fix the "no timer" errors in MacBook's.
    - Malone: #30557
    - GIT SHA's (in order applied):
      - 5a07a30c3cc4dc438494d6416ffa74008a2194b3
      - 6eb0a0fd059598ee0d49c6283ce25cccd743e9fc
      - d25bf7e5fe73b5b6d2246ab0be08ae35d718456b
      - 76b461c21468f41837283b7888d55f1c0671f719
      - bd6633476922b7b51227f7f704c2546e763ae5ed
      - 0b5c59a1e41636afa77b90d34e8c394d8d929733

  * Cherry pick fix for ali ide, broken CD burning with DMA turned on.
    - Malone: #53524
    - GIT SHA: 0d8a95efd878920e7f791d5bcfb9b70f107aadda

  * Cherry pick fix for HP laptop batteries.
    - Malone: #47561
    - GIT SHA: 49fee981fa98f3c0a21f3d6c8193eddcc15e84e9

  * Add Anydata device to usb-serial option driver. Disable anydata driver.
    - Malone: #38191

  * Added dazuko 2.2.1 driver.

  * Add RAZr unusual_dev entry.
    - Malone: #50859

  Changes by Daniel T Chen

  * sound/pci/emu10k1: Don't hang when Audigy 2 ZS (cardbus) is removed
  * sound/usb: Add quirks for Yamaha USB MIDI devices
  * sound/pci/{emu10k1,hda}: Add support for various newer HDA and Audigy
    2 ZS models
  * sound/pci: Correct dxs_support entries for various models
  * sound/pci/hda: Fix erroneous re-initialisation of pins
  * sound/pci/hda: Fix noisy HDA output when switch channel output mode
    (patch_{analog,realtek})

  Changes by David Miller

    * [SPARC64]: Fix typo in pgprot_noncached().
    * [SPARC64]: Fix quad-float multiply emulation.

 -- Ben Collins <email address hidden>   Wed,  2 Aug 2006 16:59:21 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-26.45) dapper-security; urgency=low

  Security:

  * Fix patch for CVE-2006-2451.
  * CVE-2006-3626: Fix suid root environ files in /proc
    - GIT Hashes (in order applied):
      - 4a7ac3ab06932949d3069c1811f6f2a310f656c4
      - 1d87a98f9db06b6c7fadd20f13ab092875d53801

  Changes by Ben Collins

  * usb: Fix oopses on device disconnects
  * prism54: Move PCI ID 10b7:6001 from prism54_softmac back to prism54.
    - Malone: #38278

  Changes by Daniel T Chen

  * sound/pci/hda: Fix/add Realtek ALC8{61,8[38]} codecs (hda_codec,patch_realtek)
  * sound/pci/hda: Fix MacMini's built-in speaker (patch_sigmatel)

  Changes by Andrew Straw

  * drivers/ieee1394: Fix incorrect video1394 timestamps.

 -- Ben Collins <email address hidden>   Tue, 11 Jul 2006 16:21:27 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-26.44) dapper-security; urgency=low

  Security:

  * CVE-2006-0039: Race condition in the do_add_counters
  * CVE-2006-2445: run_posix_cpu_timers: remove a bogus BUG_ON()
  * CVE-2006-2448: powerpc: Fix machine check problem on 32-bit kernels
  * CVE-????-????: IPC: access to unmapped vmalloc area in grow_ary()
  * CVE-2006-2451: Fix prctl() DoS and privilege escalation vulnerability.

  Changes by Ben Collins

  * hid: Add 0x0218 to list of powerbook quirks.
  * sky2: Update to latest version in linux-2.6.git.
  * sata_nv/amd74xx: Add mcp65 ID's.
  * Max freq stucks at low freq if reduced by _PPC and sysfs gov access.
    - Git-7970e08bf066900efcd7794a1a338c11eb8f5141
    - Malone #36014
  * i8042-x86ia64io.h: Backport some 2.6.17 blacklist entries.
  * forcedeth: Update to v0.54 from 2.6.17.
  * cx88-dvb: Revert: 3a580f39df8937f54976b2e7ce2ef54294da06f9
    - Malone #33096
  * tulip: Re-add removed PCI id's left to dmfe, just for sparc.
  * ipw3945: Update to 1.0.5
  * Enable CPUSETS
    - Malone: #50782
  * nsc-ircc: Fix usage of pnp_register_driver()
  * megaraid: Update to latest driver
    - Malone: #32752
  * Move VIA pci id's from ahci to sata_via.
    - Malone: #33030

  Changes by Chuck Short

  * i8042-x86ia64io: Blacklist IBM 2656.
  * via-agp: Add support for PT880ULTRA.
  * sundance: Added IP100A chipset support.
  * pci/quirks: VIA IRQ fixup should only run for VIA southbridges.
  * cdrom: Fix cdrom open
  * com20020_cs: Add SoHard SH ARC-PCMCIA card.
  * drm: Allow drm detection of new VIA chipsets.
  * via-ircc: Fix memory leak.
  * acpi/boot: Fix noapic for acpi.
  * acpi: Do not abort method execution if asked to release not acquired mutex.
  * ati_remote: Fix FILTER_TIME causing multiple button presses.
    - Malone #50593
  * CIFS: Fix suspend/resume problem which causes EIO on subsequent access to
    - Malone #42583

  Changes by Daniel T Chen

  * sound/pci/hda:
    - Add ID for Samsung X60 Chane (patch_analog)
    - Add support for Intel D965 boards using STAC9227 (patch_sigmatel)
  * acpi/boot: Requires acpi=off
  * hid-core: Fixes irq status on some keyboards and mices.
  * sound/isa/sb: Fix potential NULL pointer dereference in
    sb8_midi.c::snd_sb8dsp_midi_interrupt()
  * sound/pci/ac97: Don't erroneously attempt to create AC97 controls again
  * sound/pci: Update default sample rate for MSI K8T Neo2-FI (snd_via82xx)
  * sound/pci/ac97: Fix suspend/resume for AD1888 codec (ac97_patch)
  * sound/pci/hda: Add id for supported models
    - reinstate commit ba42a99e564f63b2d5506a6df0da0b37b2e4774f
      fixing audible support for Lenovo 3000 N100-07684JU (patch_analog.c)
  * sound/pci/ac97: Add codec ID to Jack Sense blacklist (ac97_patch)
  * sound/pci: Add AC97 quirk for Tyan Thunder K8WE (intel8x0)
  * sound/pci/hda: Don't use the AD1988A rev.2 workaround on AD1988B chips
  * sound/core: #34831: Fix hard freeze with timer {re,}store (timer)
  * sound/pci/cs46xx: Fix deadlock inversion in dsp_spos_scb_lib.c::cs46xx_dsp_remove_scb()
  * sound/pci/hda: Use the proper codec patch for SigmaTel 922[7-9] (patch_sigmatel)
  * sound/pci/hda: Fix missing terminators in AD1988 mixer models (patch_analog)

  Changes by Fabio M. Di Nitto

  * Add sata_mv to sata-modules udeb if available.

  * Add cassini driver to nic-modules udeb if available.
  (Closes Ubuntu: #52234)

  Changes by David Miller

  * Proper fix for Niagara memory corruption.

 -- Ben Collins <email address hidden>   Fri,  7 Jul 2006 12:29:51 -0400
Superseded in dapper-security
linux-source-2.6.15 (2.6.15-25.43) dapper-security; urgency=low

  Changes by Ben Collins

  * bcm43xx dma mask handling (> 1GB memory)
  - Add powerpc IOMMU handlers for dma masks
  - Sync updates to amd64 IOMMU to handle dma masks

  * Sync ide changes for better flash driver handling (flash isn't removable).

  Changes by David S. Miller

  * [SPARC64]: Temporary workaround for memory corruption on Niagara.

 -- Fabio M. Di Nitto <email address hidden>   Wed, 14 Jun 2006 11:05:57 +0200
Deleted in edgy-release (Reason: ROM obsolete)
Obsolete in dapper-release
linux-source-2.6.15 (2.6.15-23.39) dapper; urgency=low

  Changes by Fabio M. Di Nitto

  * Make sure that all RV350 will get the CHIP_NEW_MMAP flag.

  * Reenable all ABI checkers.

  * Update ABI files to fix FTBFS on i386.

  Changes by David S. Miller

  * Fix severe memory corruption when using sound on sparc64.

 -- Ben Collins <email address hidden>   Tue, 23 May 2006 07:17:42 -0400
Superseded in dapper-release
linux-source-2.6.15 (2.6.15-23.38) dapper; urgency=low

  * Ignore ABI change on sparc this time around.
  * amd64: Update configs.

 -- Ben Collins <email address hidden>   Mon, 22 May 2006 16:52:46 -0400
Superseded in dapper-release
linux-source-2.6.15 (2.6.15-23.37) dapper; urgency=low

  * Ignore ABI change on sparc this time around.
  * amd64: Update configs.

 -- Ben Collins <email address hidden>   Mon, 22 May 2006 12:41:53 -0400
Superseded in dapper-release
linux-source-2.6.15 (2.6.15-23.36) dapper; urgency=low

  Changes by Ben Collins

  * powerpc64: Enable HUGETLB
  * x86,amd64: Build-in rtc and genrtc on all but the 386 kernel.
  * sparc: Enable CONFIG_FB_RADEON_I2C and CONFIG_SND_ALI5451.

  Changes by Fabio M. Di Nitto

  * Fix drm/dri/radeonfb crash on ppc with input from Dave Airlie.

 -- Ben Collins <email address hidden>   Mon, 22 May 2006 10:12:30 -0400
Superseded in dapper-release
linux-source-2.6.15 (2.6.15-23.35) dapper; urgency=low

  This IS the final dapper kernel. There have been many kernels like this, but
  this one superceeds them all. The kernel you are about to install is the
  hard work of the following people:

  - Fabbione M. Di Nitto
  - Matthew Garrett
  - Daniel T. Chen
  - Chuck Short

  Give them all a big "Thank You" next time you email them or see them on IRC.
  If you happen to see them in real life, buy them a beer. Without their
  hardwork, your computer would be a wimpering pile circuits with little more
  use than as an egg timer to make sure you don't burn your precious
  breakfast.

  Changes by Ben Collins

  * ipw3945: Update to latest version, 1.0.3.
  * Merge with 2.6.15.7 (This takes care of a lot of CVE's that I haven't
    listed here yet).
  * sky2/skge/sk98lin: Sync with 2.6.16.13.
  * Update drm to 1.0.1, from 2.6.16.13. This reverts the PPC radeon patch
    aswell.
  * pcmcia: TI PCIxx12 CardBus controller support.
  * r1000: New realtek driver.
  * irda/sir[41589]: Add small timeout to kthread to reduce load.
  * powerpc[30273]: Add BootX support patch.
  * bcm43xx: Sync to latest source from wireless git.
  * Change lilo/grub Suggests to Recommends.
  * sky2: Add patch to fix IRQ masks.
  * sound/pcmcia[44283]: PCMCIA sound devices do not depend on ISA.
  * VFS: Ensure LOOKUP_CONTINUE flag is preserved by link_path_walk()
    - Bug #44783
  * Fix per zone pages, min-zone overflow
    - Bug #44782
  * asus_acpi: Disable extraneous error reading LCD status.
  * forcedeth: Let the driver work when no PHY is found. This matches the
    breezy behavior.
    - Bug #45257

  Changes by Matthew Garrett

  * acpi/sony: Add FN hotkey support
  * pcmcia/yenta[43881]: Fixup the subordinate number parent bridge of yenta Cardbus
    Bridges
  * imacfb: Disable if EFI is not available
  * vga16fb: Use 640x480 on certain machines. Specifically Apple and some Sony
    laptops.
  * PCI: MSI(X) save/restore for suspend/resume.

  Changes by Daniel T Chen

  * sound/pci: Add hp_only quirk for Dell D800 laptops
  * sound/pci/ca0106: Fix error handling for nonexistent mpu401 interface
    (ca0106 driver)
  * sound/pci:
    - Revert to hp_mute_led for HP n*8*0 laptops
    - Add hp_only quirk for another Dell laptop model
  * sound/pci/hda:
    - Use hp model for all HP laptops with AD1981HD codec
    - Fix support for Thinkpad *60s (patch_analog.c)
  * sound/pci: Fix possible OOPS with ALI5455 SPDIF-in
  * sound/pci/hda: Fix master mute switch on Vaio laptops using STAC7661
    HDA codec
  * sound/pci: Add Dell Inspiron 6000 to hp_only quirk list
  * sound/bluetooth: Fix suspend/hibernate in snd-bt-sco driver
  * sound/pci/hda: Really merge patch_realtek.c from upstream
    alsa-driver 1.0.11
  * sound/pci/ice1712: Backport fixes and cosmetic cleanups from alsa-driver
    1.0.11
  * sound/core: Minor optimisations from alsa-driver 1.0.11

  Changes by Fabio M. Di Nitto

  * Upstream informs us about 2 critical bugs in our cluster modules:
    - Update cman and dlm.
  * Backport inotify syscalls to hppa.

  Changes by Dave Airlie

  * DRM backport patches:
    - fixup r300 scratch on BE machines
    - add new radeon PCI ids..
    - read breadcrumb in IRQ handler
    - fixup i915 breadcrumb read/write
    - fixup improper cast.
    - rationalise some pci ids
    - Add general-purpose packet for manipulating scratch registers (r300)
    - rework radeon memory map (radeon 1.23)
    - update r300 register names
    - fixup PCI DMA support

 -- Ben Collins <email address hidden>   Thu, 18 May 2006 10:00:24 -0400
150 of 73 results