The following RPMs are included in this version:
| RPM | Issue |
|---|---|
|
|
|
| glib2-2.56.1-11.el7_9.x86_64.rpm | - Add patch for CVE-2025-13601 |
|
|
|
| glib2-devel-2.56.1-11.el7_9.x86_64.rpm | - Add patch for CVE-2025-13601 |
|
|
|
| gnupg2-2.0.22-5.el7_9.1.x86_64.rpm | - Fix CVE-2025-68973 (gpg.fail/memcpy) |
|
|
|
| java-1.8.0-openjdk-headless-1.8.0.482.b08-1.el7_9.x86_64.rpm | - Update to 8u482-b08 (GA). |
| - Update release notes for 8u482-b08. | |
| - Turn on system FreeType as on later JDK versions and add to _privatelibs | |
| - Set bundled FreeType version to 2.13.2 following JDK-8316028 | |
| - Bump LCMS 2 version to 2.14.0 following JDK-8297088 | |
| - Add test to ensure blocked.certs is valid (OPENJDK-4362) | |
| - Handle 'upgrade' as an alternative to 'update' in openjdk_news.sh | |
| - ** This tarball is embargoed until 2026-01-20 @ 1pm PT. ** | |
| - Resolves: RHEL-142688 | |
| - Resolves: RHEL-139512 | |
| - Resolves: RHEL-142692 | |
| - Resolves: RHEL-142695 | |
|
|
|
| kernel-3.10.0-1160.146.1.el7.x86_64.rpm | - i40e: fix idx validation in config queues msg (Arif Badar) [RHEL-123796] {CVE-2025-39971} |
| - i40e: add validation for ring_len param (Arif Badar) [RHEL-123796] {CVE-2025-39973} | |
| - i40e: increase max descriptors for XL710 (Arif Badar) [RHEL-123796] | |
| - e1000e: fix heap overflow in e1000_set_eeprom (Marc Milgram) [RHEL-123102] {CVE-2025-39898} | |
| - vsock: Ignore signal/timeout on connect() if already established (Xiubo Li) [RHEL-139263] {CVE-2025-40248} | |
| - vsock: remove vsock from connected table when connect is interrupted by a signal (Xiubo Li) [RHEL-139263] | |
| - vsock: avoid to close connected socket after the timeout (Xiubo Li) [RHEL-139263] | |
| - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CKI Backport Bot) [RHEL-126856] {CVE-2025-37823} | |
| - scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix possible desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] {CVE-2023-53675} | |
| - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() (John Pittman) [RHEL-121313] | |
| - libceph: fix potential use-after-free in have_mon_and_osd_map() (Xiubo Li) [RHEL-137390] {CVE-2025-68285} | |
| - ipv6: Fix out-of-bounds access in ipv6_find_tlv() (CKI Backport Bot) [RHEL-124738] {CVE-2023-53705} | |
|
|
|
| kernel-devel-3.10.0-1160.146.1.el7.x86_64.rpm | - i40e: fix idx validation in config queues msg (Arif Badar) [RHEL-123796] {CVE-2025-39971} |
| - i40e: add validation for ring_len param (Arif Badar) [RHEL-123796] {CVE-2025-39973} | |
| - i40e: increase max descriptors for XL710 (Arif Badar) [RHEL-123796] | |
| - e1000e: fix heap overflow in e1000_set_eeprom (Marc Milgram) [RHEL-123102] {CVE-2025-39898} | |
| - vsock: Ignore signal/timeout on connect() if already established (Xiubo Li) [RHEL-139263] {CVE-2025-40248} | |
| - vsock: remove vsock from connected table when connect is interrupted by a signal (Xiubo Li) [RHEL-139263] | |
| - vsock: avoid to close connected socket after the timeout (Xiubo Li) [RHEL-139263] | |
| - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CKI Backport Bot) [RHEL-126856] {CVE-2025-37823} | |
| - scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix possible desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] {CVE-2023-53675} | |
| - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() (John Pittman) [RHEL-121313] | |
| - libceph: fix potential use-after-free in have_mon_and_osd_map() (Xiubo Li) [RHEL-137390] {CVE-2025-68285} | |
| - ipv6: Fix out-of-bounds access in ipv6_find_tlv() (CKI Backport Bot) [RHEL-124738] {CVE-2023-53705} | |
|
|
|
| kernel-headers-3.10.0-1160.146.1.el7.x86_64.rpm | - i40e: fix idx validation in config queues msg (Arif Badar) [RHEL-123796] {CVE-2025-39971} |
| - i40e: add validation for ring_len param (Arif Badar) [RHEL-123796] {CVE-2025-39973} | |
| - i40e: increase max descriptors for XL710 (Arif Badar) [RHEL-123796] | |
| - e1000e: fix heap overflow in e1000_set_eeprom (Marc Milgram) [RHEL-123102] {CVE-2025-39898} | |
| - vsock: Ignore signal/timeout on connect() if already established (Xiubo Li) [RHEL-139263] {CVE-2025-40248} | |
| - vsock: remove vsock from connected table when connect is interrupted by a signal (Xiubo Li) [RHEL-139263] | |
| - vsock: avoid to close connected socket after the timeout (Xiubo Li) [RHEL-139263] | |
| - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CKI Backport Bot) [RHEL-126856] {CVE-2025-37823} | |
| - scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix possible desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] {CVE-2023-53675} | |
| - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() (John Pittman) [RHEL-121313] | |
| - libceph: fix potential use-after-free in have_mon_and_osd_map() (Xiubo Li) [RHEL-137390] {CVE-2025-68285} | |
| - ipv6: Fix out-of-bounds access in ipv6_find_tlv() (CKI Backport Bot) [RHEL-124738] {CVE-2023-53705} | |
|
|
|
| libsoup-2.62.2-10.el7_9.x86_64.rpm | - Backport patch for CVE-2025-14523 |
|
|
|
| net-snmp-5.7.2-49.el7_9.5.x86_64.rpm | - Fix out-of-bounds access in snmptrapd (CVE-2025-68615) |
|
|
|
| net-snmp-agent-libs-5.7.2-49.el7_9.5.x86_64.rpm | - Fix out-of-bounds access in snmptrapd (CVE-2025-68615) |
|
|
|
| net-snmp-libs-5.7.2-49.el7_9.5.x86_64.rpm | - Fix out-of-bounds access in snmptrapd (CVE-2025-68615) |
|
|
|
| net-snmp-utils-5.7.2-49.el7_9.5.x86_64.rpm | - Fix out-of-bounds access in snmptrapd (CVE-2025-68615) |
|
|
|
| openssl-1.0.2k-26.el7_9.1.x86_64.rpm | - Backport fix for openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| Fix CVE-2025-9230 | |
| Resolves: RHEL-128610 | |
|
|
|
| openssl-libs-1.0.2k-26.el7_9.1.x86_64.rpm | - Backport fix for openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap |
| Fix CVE-2025-9230 | |
| Resolves: RHEL-128610 | |
|
|
|
| python-2.7.5-94.el7_9.2.x86_64.rpm | - Fix: Security fix for CVE-2025-12084 |
| - Resolves: RHEL-135934 | |
| - Fix: Security fix for CVE-2025-8194 | |
| - Resolves: RHEL-106331 | |
|
|
|
| python-libs-2.7.5-94.el7_9.2.x86_64.rpm | - Fix: Security fix for CVE-2025-12084 |
| - Resolves: RHEL-135934 | |
| - Fix: Security fix for CVE-2025-8194 | |
| - Resolves: RHEL-106331 | |
|
|
|
| python-perf-3.10.0-1160.146.1.el7.x86_64.rpm | - i40e: fix idx validation in config queues msg (Arif Badar) [RHEL-123796] {CVE-2025-39971} |
| - i40e: add validation for ring_len param (Arif Badar) [RHEL-123796] {CVE-2025-39973} | |
| - i40e: increase max descriptors for XL710 (Arif Badar) [RHEL-123796] | |
| - e1000e: fix heap overflow in e1000_set_eeprom (Marc Milgram) [RHEL-123102] {CVE-2025-39898} | |
| - vsock: Ignore signal/timeout on connect() if already established (Xiubo Li) [RHEL-139263] {CVE-2025-40248} | |
| - vsock: remove vsock from connected table when connect is interrupted by a signal (Xiubo Li) [RHEL-139263] | |
| - vsock: avoid to close connected socket after the timeout (Xiubo Li) [RHEL-139263] | |
| - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CKI Backport Bot) [RHEL-126856] {CVE-2025-37823} | |
| - scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix possible desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] {CVE-2023-53675} | |
| - scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses (John Pittman) [RHEL-121313] | |
| - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() (John Pittman) [RHEL-121313] | |
| - libceph: fix potential use-after-free in have_mon_and_osd_map() (Xiubo Li) [RHEL-137390] {CVE-2025-68285} | |
| - ipv6: Fix out-of-bounds access in ipv6_find_tlv() (CKI Backport Bot) [RHEL-124738] {CVE-2023-53705} | |
|
|
|
| python-s3transfer-0.1.13-1.el7_9.5.noarch.rpm | - bundled urllib3: fix CVE-2025-66471 |
| Resolves: RHEL-139754 | |
| - bundled urllib3: fix CVE-2025-66418 | |
| Resolves: RHEL-136025 | |
|
|
|
| resource-agents-4.1.1-61.el7_9.22.x86_64.rpm | - bundled urllib3: fix CVE-2025-66471 |
| Resolves: RHEL-139755 | |
| - bundled urllib3: fix CVE-2025-66418 | |
| Resolves: RHEL-136026 | |
|
|
|
×