openSUSE Recommended Update: ca-certificates-mozilla update
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0804-1
Rating: low
References: #760503
Affected Products:
openSUSE 12.1
openSUSE 11.4
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This updates includes the latest SSL root certificates
trusted by Mozilla as of 2012-04-25.
- new: EC_ACC.pem
- new:
Hellenic_Academic_and_Research_Institutions_RootCA_2011.pem
- new: Security_Communication_RootCA2.pem
- removed: TC_TrustCenter_Germany_Class_2_CA.pem
- removed: TC_TrustCenter_Germany_Class_3_CA.pem
- removed:
Verisign_Class_1_Public_Primary_Certification_Authority.1.pe
m
- removed:
Verisign_Class_2_Public_Primary_Certification_Authority.pem
- removed:
Verisign_Class_4_Public_Primary_Certification_Authority_G2.p
em
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-345
- openSUSE 11.4:
zypper in -t patch openSUSE-2012-345
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (noarch):
ca-certificates-mozilla-1.76-3.4.1
- openSUSE 11.4 (noarch):
ca-certificates-mozilla-1.76-6.1
References:
https://bugzilla.novell.com/760503
openSUSE Recommended Update: Documentation update
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0788-1
Rating: low
References: #703489 #706459 #706464 #706475 #706479 #708637
#758401 #763268
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that has 8 recommended fixes can now be installed.
Description:
This update fixes the following issues for daps,
suse-xsl-stylesheets and opensuse-manuals_ru:
daps:
- Version 1.0.2 (Bugfix Release):
* Important:
- in order to avoid confusion with short options for
daps itself (such as -d for --docconfig and --draft), the
subcommands only support long options now. The following
short options for subcommands are no longer supported:
-c (use --comments)
-d (use --draft)
-f (use --file)
-m (use --meta)
-n (use --name)
-p (use --pretty)
-r (use --remarks)
-s (use --show)
- the only short option that will remain is -h (help)
* Bugfixes:
- added proper help texts for subcommands
- target warn-images did not work
- target missinggraphics did not show all missing images
- daps failed with a useless error message when $MAIN
was not well-formed. The fix produces a useful error
message now
- --remarks option did not work with DocBook stylesheets
- paths specified on the command line or the config
file had to be absolute. The fix now allows to also specify
relative paths for all configurable directories and files
- COMMENTS_STR, DRAFT_STR and REMARK_STR were not
correctly unset when one of these modes was not set on the
command line but implied by another mode (e.g. --meta). The
result was a wrong filename
- target webhelp-dir-name was missing
- draft.png was not shown in PDF/HTML draft builds when
using the DocBook Stylesheets
- Due to a variable name mismatch, the --name option
did not work properly
- target showvariable exited with an error if requested
variable was empty
- config options FOP_CONFIG and XEP_CONFIG were not
used. The fix renames them to FOP_CONFIG_FILE and
XEP_CONFIG_FILE - these variables are used in the wrapper
scripts
- FOP_WRAPPER and XEP_WRAPPER were not set correctly
when DAPSROOT was set
- disabled Permalink generation for PDFs (this is an
HTML-only feature)
- images were not cerrectly references for target jsp
- the DEF file was not correctly packaged in target
locdrop
- fixed webhelp target. Wildcards do not work in
classpath expression, resolved them with $(wildcard
$(firstword())
- Warning message "DEF file is missing" was issued for
targets that do not have a --def-file option
- targets package-html and package-pdf failed with an
error on desktop files generation
- target remaininggraphics always returned an empty list
- SVG to SVG conversions generated useless error
messages
* Stylesheets:
- removed obsolete stuff for @role=productname,
productnumber, or productnameref
* Documentation:
- Quick Start Guide: Finished
- User Guide: Significant additions, but still work in
progress
- Updated README.upgrade_from_susedoc_4.x
- Version 1.0:
* Bugfix:
- Use XEP/FOP wrapper scripts by default
- Version 1.0 RC5:
* Bugfix:
- Setting stack size for FOP to 512k in wrapper script,
otherwise builds on i586 fail during hyphenation
- Version 1.0 RC4:
* Bugfix:
- Not all links were dereferenced with --static
- Version 1.0 RC3:
* Bugfixes:
- Issuing hint on missing formatter scripts only when
verbosity is >= 1
- spec-file: Fixed typo on suse-xsl-stylesheet
'recommends python-xml' needs to be a general requirement
- fixed path to callouts and style images for FO
* Lots of minor documentation fixes/enhancements
- Version 1.0 RC2:
* Bugfixes:
- issue a hint rather than exiting when XEP/FOP_WRAPPER
do not exist
- daps_xslt/yelp/*.xsl was not installed by make install
- Version 1.0 RC1:
* Bugfixes:
- fixed minor package building issues
- inkscape always returns 0, even in case of an error.
Added a workaround, so daps now exits when an image
conversion with inkscape fails
- --main option should work now
- Fixed errors on setting the fallback stylesheets
- comments and remarks did not show up in the docs when
requested (again ;-(( ) - this is fixed now
* much better error handling - daps will now exit when
wrong paths or a non existing ROOTID are entered in the
user config file or the DC file
* significant enhancements to the Documentation
(Reference and Quickstart)
- Target for index generation had wrong ending (.idx
instead of .ind)
- Typo in Makefile caused wrong catalog entries
- showvariable now only shows the result to make it better
suited for script usage
- Version 1.0beta2:
* Bugfix:
- Finally found the correct solution for
adding/removing catalog entries in the spec file
* Enhancement: webhelp suppport
- Version 1.0beta1:
* Rebuild large parts to make DAPS
distribution-independent.
- rewrote Makefile for automake/autoconf => configure;
make; make install is now supported
- thorough cross-distribution testing is still needed,
basic tests have been run on RedHat, Debian and Ubuntu
* removal of custom stylesheets
- DAPS no longer uses the SUSE stylesheets as a
default. It even no longer contains the SUSE stylesheets -
they are now available as a separate package
(suse-xsl-stylesheets in Documentation:Tools).
- By default DAPS uses the generic DocBook stylesheets
now
- Custom stylesheets such as the SUSE stylesheets can be
used by specifying up to four parameters on the command
line/the config files:
* Styleroot:
- Directory containing the custom stylesheets. Must
have the same directory structure as the original DocBook
stylesheet root directory. Does _not_ need to contain
stylesheets for all output formats. If stylesheets are not
found, DAPS will automatically fall back to the DocBook
stylesheets.
- Variable: STYLEROOT
- Parameter: --styleroot
- Value: absolute path to directory
* Fallback styleroot
- Custom fallback styleroot. If DAPS cannot find
styles for the given output format, it will automatically
fall back to the DocBook stylesheets. This config option
will add a custom fallback directory with higher priority.
The DocBook stylesheets will remain as a last resort,
however.
- Variable: FALLBACK_STYLEROOT
- Parameter: --fb_styleroot
- Value: absolute path to directory
* CSS files:
- Specify CSS files for HTML and/or CSS. By default
no CSS file will be used.
- Variables: HTML_CSS, EPUB_CSS
- Parameter: --css for html and epub targets (daps
-d DC html--css CSS )
- Value: absolute path to file
* rewrote FOP formatter handling - both supported
formatters (FOP/XEP) are now controlled by the
following variables:
- *_WRAPPER (wrapper script, libexec/daps-fop,
libexec/daps-xep by default)
- *_CONFIG (xml config file, etc/daps/xep/xep-daps.xml
and etc/daps/fop/fop-daps.xml by default. A specific
fop-daps.xml is installed for RedHat and SUSE by default)
- *_OPTIONS (Command line options)
* renaming of parameters and variables
- In order to make parameters and variables
"self-speaking" the following has been renamed:
- File ENV-file to DC-file (doc config file)
- Variable BASE_DIR to DOC_DIR (doc dir) =>
Terminology!
- Variable DTDROOT to DAPSROOT (daps installation
directory)
- Variable FOP_TYPE to FORMATTER
- command line switch --fop to --formatter
- command line switch -e/--envfile has been renamed to
-d/--docconfig (-e/--envfile will still be supported)
* global parameter --base_dir no longer supported
- Instead of specifying --base_dir with daps, you now
need to specify a full path (either relative or absolute)
to the DC-file. However, the "magic" that automatically
tries to determine the path to a DC-file when you do not
specify a path or not even a DC file, still applies.
Therefore you only need to specify a valid path to the
DC-file in cases where you would have used --base_dir with
previous DAPS versions.
* --main parameter / MAIN
- Instead of calling daps with -d/--docconfig you can
also directly specify a MAIN with --main=PATH. You need to
specify a valid relative or absolute path. If you just
specify a file name, ./xml/$MAIN is automatically assumed.
* packaging
The former DAPS version has been split into two packages:
- daps
- suse-xsl-stylesheets (SUSE stylesheets, NovDOC DTD,
SUSE aspell wordlist)
* other DAPS changes since 0.9.2 in brief:
- stylesheet images have been moved to fit the
directory structure used in the original stylesheets
- new variable STYLEDEVEL which can be used when
developing stylesheets. STYLEDEVEL _always_ takes
precedence over STYLEROOT and can be set in $USER_CONFIG
- Rewrote handling of profiling variables PROFARCH,
PROFCONDITION, PROFVENDOR, PROFOS - all 4 are now fully
supported (formerly only PROFOS and PROFARCH were fully
supported)
- created catalog entry to resolve stylesheets in
daps_xslt
- daps init has been moved to a separate script
bin/daps-init
- each SUSE stylesheet file now contains a short
overview of purpose and parameters
- lots of stylesheet bugfixes
- license: GPL 2.0 or 3.0 at your choice
- fixed target man for man-page generation; man pages
are not gzip'ed by default (unless you specify --nogzip);
manpage subdirectories (man1, man2,...) are no longer
created by default, but can rather be enabled via the
--subdirs switch
- new parameter --check for target epub checks build
with epubcheck
- added very basic DocBook5 support (with xslt 1.0
stylesheets only) still a lot to do on this front
- Default HTML format is now XHTML 1.0 (instead of HTML
4.01). Use --html4 to generate HTML 4.01
- auto generate SUSE HTML4 stylesheets from XHTML
stylesheets
- binaries that are only called from withion make have
been moved to libexec/
suse-xsl-stylesheets:
- Initial update for this package
- Adjusted rnc/rng generation in order to allow a custom
novdocx.rng that defines start tags allowed
- Version 1.9.6.1:
- Added new SUSE logo from Scott Corfield
- Version 1.9.6:
- fo: Fixed xref to external target; use article title
instead of book title
- fo: Make formal titles float, but don't indent screen
(or other objects) Removed test for xep.extensions and
moved float=none and clear=both attributes to
fo/mode-object.title.markup.xsl (only needed for XEP)
- Version 1.9.5:
- removes suse aspell wordlist
- package is norach again
- Version 1.9.4:
- Replace Obsolete PI Mechanism for product names and
numbers Preliminary, need to test it
- Added setinfo in set for Novdoc DTD
- Version 1.9.3:
- Improve Space Between Formal Titles and Verbatim Text
- SUSE Branding: Quick Start Layout (I)
- SUSE Branding: Quick Start Layout (II)
- SUSE Branding: Stylesheets produce invalid HTML 4.01
Transitional
- bnc#703489: Problems with Tables (reported upstream)
- bnc#706459: Distance Between Page Number and Left/Right
Footer
- bnc#706464: Space Between Figure/Procedure XYZ and Title
- bnc#706475: Some Issues with Callouts
- bnc#706479: Line Break in ulink Elements
- bnc#708637: susedoc/daps stylesheets produce invalid
HTML 4.01 Transitional (Moved to Ticket#68)
- Version 1.9.2:
- fixed SGML catalog entry generation when updating the
package
- fixed path to admon graphics in fo stylesheets
- added svg admonition graphics for fo builds
- Fixed empty fo:table-cell with fo:block to make FOP
happy
- Added missing booktitlepage.color.logo parameter to fo
stylesheets
- Renamed obsolete dtdroot to styleroot in fo stylesheets
- fixed broken callout generation for XEP and FOP
* Added more flexibilty to flyer layout: headline url can
now be set per suse-quickstart pi with attribute url
- fixed %postun routine, so catalog entries only get
removed on a real package installation
- Improved webhelp
- Fixed Toc in PDF
- Installing aspell wordlist to libdir makes this package
architecture-specific
- Fixed installation procedure for aspell wordlist
- aspell wordlist is now installed in teh correct place
- fixed path to fo draft image in fo stylesheets
- aspell-en-huge only seems to be available on x86-64,
making it a recommendation
- Moved suse-aspell wordlist from daps to this package
- Moved images/admon/* and images/navig/* to images/ in
order to restore compatability to the original DocBook
stylesheets
- Use absolute images paths in .fo files
- Added Catalog entries for the URI to
/etc/xml/suse-catalog.xml
- Created general URI for SUSE XSLT Stylesheets
- More path fixes
- Fixed import paths for flyer and pocket
- Created fo subdirectories for flyer and pocket
- Includes must _not_ point to daps-xslt
- Added missing profiling stylesheet
- First stable version
- Stylesheet files were not packed
- Initial version of a seperate SUSE stylesheets package
opensuse-manuals_ru:
- 758401: Manuals translate update for 12.1
- fix license to be in spdx format
- Update help_admin.xml
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-341
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (noarch):
daps-1.0.2-5.9
opensuse-kvm_ru-pdf-12.1.8762-3.6.1
opensuse-manuals_ru-12.1.8762-3.6.1
opensuse-reference_ru-pdf-12.1.8762-3.6.1
opensuse-security_ru-pdf-12.1.8762-3.6.1
opensuse-startup_ru-pdf-12.1.8762-3.6.1
opensuse-tuning_ru-pdf-12.1.8762-3.6.1
suse-xsl-stylesheets-1.9.6.2-2.3
References:
https://bugzilla.novell.com/703489https://bugzilla.novell.com/706459https://bugzilla.novell.com/706464https://bugzilla.novell.com/706475https://bugzilla.novell.com/706479https://bugzilla.novell.com/708637https://bugzilla.novell.com/758401https://bugzilla.novell.com/763268
openSUSE Security Update: python-httplib2 should use the system-wide CA
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:0787-1
Rating: moderate
References: #761162
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that contains security fixes can now be installed.
Description:
python-httplib2 used to ship it's own copy of Mozilla NSS
certificates, but should use the system-wide ones instead.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-340
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (noarch):
python-httplib2-0.7.1-3.4.1
References:
https://bugzilla.novell.com/761162
openSUSE Recommended Update: iscsitarget: Fix init file so it uses correct PIDFILE
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0786-1
Rating: low
References: #743562
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update fixes the following issue for iscsitarget:
- 743562: Fix init file so it uses correct PIDFILE
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-336
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (i586 x86_64):
iscsitarget-1.4.20.3-9.6.1
iscsitarget-debuginfo-1.4.20.3-9.6.1
iscsitarget-debugsource-1.4.20.3-9.6.1
iscsitarget-kmp-default-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-default-debuginfo-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-desktop-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-desktop-debuginfo-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-xen-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-xen-debuginfo-1.4.20.3_k3.1.10_1.9-9.6.1
- openSUSE 12.1 (i586):
iscsitarget-kmp-pae-1.4.20.3_k3.1.10_1.9-9.6.1
iscsitarget-kmp-pae-debuginfo-1.4.20.3_k3.1.10_1.9-9.6.1
References:
https://bugzilla.novell.com/743562
openSUSE Recommended Update: zsh: Fix ksh arrays regression
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0785-1
Rating: low
References: #747676
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update fixes the following issue for zsh:
- 747676: Fix ksh arrays regression
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-337
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (i586 x86_64):
zsh-4.3.12-6.4.1
zsh-debuginfo-4.3.12-6.4.1
zsh-debugsource-4.3.12-6.4.1
zsh-htmldoc-4.3.12-6.4.1
References:
https://bugzilla.novell.com/747676
openSUSE Recommended Update: sysvinit: fix deadlock of blogd on shutdown
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0784-1
Rating: low
References: #730193
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update fixes a deadlock in blogd that happens on
shutdown (bnc#730193).
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-338
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (i586 x86_64):
sysvinit-2.88+-66.61.1
sysvinit-debuginfo-2.88+-66.61.1
sysvinit-debugsource-2.88+-66.61.1
sysvinit-init-2.88+-66.61.1
sysvinit-init-debuginfo-2.88+-66.61.1
sysvinit-tools-2.88+-66.61.1
sysvinit-tools-debuginfo-2.88+-66.61.1
References:
https://bugzilla.novell.com/730193
openSUSE Recommended Update: SuSEfirewall2: Allow IPv6 multicast control packets
______________________________________________________________________________
Announcement ID: openSUSE-RU-2012:0783-1
Rating: low
References: #767392
Affected Products:
openSUSE 12.1
openSUSE 11.4
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
SuSEfirewall2 was updated to:
- Allow IPv6 Multicast Listener Discovery
- fix icmpv6 handling FW_SERVICES_*_*
Patch Instructions:
To install this openSUSE Recommended Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-339
- openSUSE 11.4:
zypper in -t patch openSUSE-2012-339
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (noarch):
SuSEfirewall2-3.6.282-1.7.1
- openSUSE 11.4 (noarch):
SuSEfirewall2-3.6.261-3.8.1
References:
https://bugzilla.novell.com/767392
openSUSE Security Update: Kernel update
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:0781-1
Rating: moderate
References: #700174 #716996 #731720 #732006 #735362 #736268
#745929 #747038 #747404 #748463 #748859 #752460
#754186 #756840 #757783 #757789 #758243 #758260
#758813 #759545 #759554 #760077 #760279 #760860
#760902 #761681 #762991 #762992 #765102 #765320
Cross-References: CVE-2009-4020 CVE-2011-3347 CVE-2012-2119
CVE-2012-2123 CVE-2012-2136 CVE-2012-2373
CVE-2012-2663
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that solves 7 vulnerabilities and has 23 fixes is
now available.
Description:
This kernel update of the openSUSE 12.1 kernel brings
various bug and security fixes.
Following issues were fixed:
- tcp: drop SYN+FIN messages (bnc#765102, CVE-2012-2663).
- net: sock: validate data_len before allocating skb in
sock_alloc_send_pskb() (bnc#765320, CVE-2012-2136).
- thp: avoid atomic64_read in pmd_read_atomic for 32bit PAE
(bnc#762991).
- be2net: non-member vlan pkts not received in promiscous
mode (bnc#732006 CVE-2011-3347).
- fcaps: clear the same personality flags as suid when
fcaps are used (bnc#758260 CVE-2012-2123).
- macvtap: zerocopy: validate vectors before building skb
(bnc#758243 CVE-2012-2119).
- macvtap: zerocopy: set SKBTX_DEV_ZEROCOPY only when skb
is built successfully (bnc#758243 CVE-2012-2119).
- macvtap: zerocopy: put page when fail to get all
requested user pages (bnc#758243 CVE-2012-2119).
- macvtap: zerocopy: fix offset calculation when building
skb (bnc#758243 CVE-2012-2119).
- Avoid reading past buffer when calling GETACL
(bnc#762992).
- Avoid beyond bounds copy while caching ACL (bnc#762992).
- Fix length of buffer copied in __nfs4_get_acl_uncached
(bnc#762992).
- hfsplus: Fix potential buffer overflows (bnc#760902
CVE-2009-4020).
- usb/net: rndis: merge command codes. only net/hyperv part
- usb/net: rndis: remove ambigous status codes. only
net/hyperv part
- usb/net: rndis: break out <linux/rndis.h> defines. only
net/hyperv part
- net/hyperv: Add flow control based on hi/low watermark.
- hv: fix return type of hv_post_message().
- Drivers: hv: util: Properly handle version negotiations.
- Drivers: hv: Get rid of an unnecessary check in
vmbus_prep_negotiate_resp().
- HID: hyperv: Set the hid drvdata correctly.
- HID: hid-hyperv: Do not use hid_parse_report() directly.
- [SCSI] storvsc: Properly handle errors from the host
(bnc#747404).
- Delete patches.suse/suse-hv-storvsc-ignore-ata_16.patch.
- patches.suse/suse-hv-pata_piix-ignore-disks.patch replace
our version of this patch with upstream variant:
ata_piix: defer disks to the Hyper-V drivers by default
libata: add a host flag to ignore detected ATA devices.
- mm: pmd_read_atomic: fix 32bit PAE pmd walk vs
pmd_populate SMP race condition (bnc#762991
CVE-2012-2373).
- xfrm: take net hdr len into account for esp payload size
calculation (bnc#759545).
- net/hyperv: Adding cancellation to ensure rndis filter is
closed.
- xfs: Fix oops on IO error during
xlog_recover_process_iunlinks() (bnc#761681).
- thp: reduce khugepaged freezing latency (bnc#760860).
- igb: fix rtnl race in PM resume path (bnc#748859).
- ixgbe: add missing rtnl_lock in PM resume path
(bnc#748859).
- cdc_ether: Ignore bogus union descriptor for RNDIS
devices (bnc#735362). Taking the fix from net-next
- Fix kABI breakage due to including proc_fs.h in
kernel/fork.c modversion changed because of changes in
struct proc_dir_entry (became defined) Refresh
patches.fixes/procfs-namespace-pid_ns-fix-leakage-on-fork-fa
ilure.
- Disabled MMC_TEST (bnc#760077).
- Input: ALPS - add semi-MT support for v3 protocol
(bnc#716996).
- Input: ALPS - add support for protocol versions 3 and 4
(bnc#716996).
- Input: ALPS - remove assumptions about packet size
(bnc#716996).
- Input: ALPS - add protocol version field in
alps_model_info (bnc#716996).
- Input: ALPS - move protocol information to Documentation
(bnc#716996).
- sysctl/defaults: kernel.hung_task_timeout ->
kernel.hung_task_timeout_secs (bnc#700174)
- btrfs: partial revert of truncation improvements
(FATE#306586 bnc#748463 bnc#760279).
- libata: skip old error history when counting probe trials.
- procfs, namespace, pid_ns: fix leakage upon fork()
failure (bnc#757783).
- cdc-wdm: fix race leading leading to memory corruption
(bnc#759554). This patch fixes a race whereby a pointer
to a buffer would be overwritten while the buffer was in
use leading to a double free and a memory leak. This
causes crashes. This bug was introduced in 2.6.34
- netfront: delay gARP until backend switches to Connected.
- xenbus: Reject replies with payload >
XENSTORE_PAYLOAD_MAX.
- xenbus: check availability of XS_RESET_WATCHES command.
- xenbus_dev: add missing error checks to watch handling.
- drivers/xen/: use strlcpy() instead of strncpy().
- blkfront: properly fail packet requests (bnc#745929).
- Linux 3.1.10.
- Update Xen config files.
- Refresh other Xen patches.
- tlan: add cast needed for proper 64 bit operation
(bnc#756840).
- dl2k: Tighten ioctl permissions (bnc#758813).
- mqueue: fix a vfsmount longterm reference leak
(bnc#757783).
- cciss: Add IRQF_SHARED back in for the non-MSI(X)
interrupt handler (bnc#757789).
- procfs: fix a vfsmount longterm reference leak
(bnc#757783).
- uwb: fix error handling (bnc#731720). This fixes a kernel
error on unplugging an uwb dongle
- uwb: fix use of del_timer_sync() in interrupt
(bnc#731720). This fixes a kernel warning on plugging in
an uwb dongle
- acer-wmi: Detect communication hot key number.
- acer-wmi: replaced the hard coded bitmap by the
communication devices bitmap from SMBIOS.
- acer-wmi: add ACER_WMID_v2 interface flag to represent
new notebooks.
- acer-wmi: No wifi rfkill on Sony machines.
- acer-wmi: No wifi rfkill on Lenovo machines.
- [media] cx22702: Fix signal strength.
- fs: cachefiles: Add support for large files in filesystem
caching (bnc#747038).
- Drivers: scsi: storvsc: Account for in-transit packets in
the RESET path.
- CPU hotplug, cpusets, suspend: Don't touch cpusets during
suspend/resume (bnc#752460).
- net: fix a potential rcu_read_lock() imbalance in
rt6_fill_node() (bnc#754186, bnc#736268).
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-335
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (i586 x86_64):
kernel-debug-3.1.10-1.13.1
kernel-debug-base-3.1.10-1.13.1
kernel-debug-base-debuginfo-3.1.10-1.13.1
kernel-debug-debuginfo-3.1.10-1.13.1
kernel-debug-debugsource-3.1.10-1.13.1
kernel-debug-devel-3.1.10-1.13.1
kernel-debug-devel-debuginfo-3.1.10-1.13.1
kernel-default-3.1.10-1.13.1
kernel-default-base-3.1.10-1.13.1
kernel-default-base-debuginfo-3.1.10-1.13.1
kernel-default-debuginfo-3.1.10-1.13.1
kernel-default-debugsource-3.1.10-1.13.1
kernel-default-devel-3.1.10-1.13.1
kernel-default-devel-debuginfo-3.1.10-1.13.1
kernel-desktop-3.1.10-1.13.1
kernel-desktop-base-3.1.10-1.13.1
kernel-desktop-base-debuginfo-3.1.10-1.13.1
kernel-desktop-debuginfo-3.1.10-1.13.1
kernel-desktop-debugsource-3.1.10-1.13.1
kernel-desktop-devel-3.1.10-1.13.1
kernel-desktop-devel-debuginfo-3.1.10-1.13.1
kernel-ec2-3.1.10-1.13.1
kernel-ec2-base-3.1.10-1.13.1
kernel-ec2-base-debuginfo-3.1.10-1.13.1
kernel-ec2-debuginfo-3.1.10-1.13.1
kernel-ec2-debugsource-3.1.10-1.13.1
kernel-ec2-devel-3.1.10-1.13.1
kernel-ec2-devel-debuginfo-3.1.10-1.13.1
kernel-ec2-extra-3.1.10-1.13.1
kernel-ec2-extra-debuginfo-3.1.10-1.13.1
kernel-syms-3.1.10-1.13.1
kernel-trace-3.1.10-1.13.1
kernel-trace-base-3.1.10-1.13.1
kernel-trace-base-debuginfo-3.1.10-1.13.1
kernel-trace-debuginfo-3.1.10-1.13.1
kernel-trace-debugsource-3.1.10-1.13.1
kernel-trace-devel-3.1.10-1.13.1
kernel-trace-devel-debuginfo-3.1.10-1.13.1
kernel-vanilla-3.1.10-1.13.1
kernel-vanilla-base-3.1.10-1.13.1
kernel-vanilla-base-debuginfo-3.1.10-1.13.1
kernel-vanilla-debuginfo-3.1.10-1.13.1
kernel-vanilla-debugsource-3.1.10-1.13.1
kernel-vanilla-devel-3.1.10-1.13.1
kernel-vanilla-devel-debuginfo-3.1.10-1.13.1
kernel-xen-3.1.10-1.13.1
kernel-xen-base-3.1.10-1.13.1
kernel-xen-base-debuginfo-3.1.10-1.13.1
kernel-xen-debuginfo-3.1.10-1.13.1
kernel-xen-debugsource-3.1.10-1.13.1
kernel-xen-devel-3.1.10-1.13.1
kernel-xen-devel-debuginfo-3.1.10-1.13.1
- openSUSE 12.1 (noarch):
kernel-devel-3.1.10-1.13.1
kernel-docs-3.1.10-1.13.2
kernel-source-3.1.10-1.13.1
kernel-source-vanilla-3.1.10-1.13.1
- openSUSE 12.1 (i586):
kernel-pae-3.1.10-1.13.1
kernel-pae-base-3.1.10-1.13.1
kernel-pae-base-debuginfo-3.1.10-1.13.1
kernel-pae-debuginfo-3.1.10-1.13.1
kernel-pae-debugsource-3.1.10-1.13.1
kernel-pae-devel-3.1.10-1.13.1
kernel-pae-devel-debuginfo-3.1.10-1.13.1
References:
http://support.novell.com/security/cve/CVE-2009-4020.htmlhttp://support.novell.com/security/cve/CVE-2011-3347.htmlhttp://support.novell.com/security/cve/CVE-2012-2119.htmlhttp://support.novell.com/security/cve/CVE-2012-2123.htmlhttp://support.novell.com/security/cve/CVE-2012-2136.htmlhttp://support.novell.com/security/cve/CVE-2012-2373.htmlhttp://support.novell.com/security/cve/CVE-2012-2663.htmlhttps://bugzilla.novell.com/700174https://bugzilla.novell.com/716996https://bugzilla.novell.com/731720https://bugzilla.novell.com/732006https://bugzilla.novell.com/735362https://bugzilla.novell.com/736268https://bugzilla.novell.com/745929https://bugzilla.novell.com/747038https://bugzilla.novell.com/747404https://bugzilla.novell.com/748463https://bugzilla.novell.com/748859https://bugzilla.novell.com/752460https://bugzilla.novell.com/754186https://bugzilla.novell.com/756840https://bugzilla.novell.com/757783https://bugzilla.novell.com/757789https://bugzilla.novell.com/758243https://bugzilla.novell.com/758260https://bugzilla.novell.com/758813https://bugzilla.novell.com/759545https://bugzilla.novell.com/759554https://bugzilla.novell.com/760077https://bugzilla.novell.com/760279https://bugzilla.novell.com/760860https://bugzilla.novell.com/760902https://bugzilla.novell.com/761681https://bugzilla.novell.com/762991https://bugzilla.novell.com/762992https://bugzilla.novell.com/765102https://bugzilla.novell.com/765320