Commit 2de2a2b
CKI KWF Bot
Merge: CVE-2025-38498 fix permission checks for mount propagation change
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-10/-/merge_requests/1373
JIRA: https://issues.redhat.com/browse/RHEL-107307
CVE: CVE-2025-38498
An inconsistent application of capabilities checking was discovered
in the kernel.
An initial patch was proposed and merged but regressions were reported.
An additional patch was posted that makes this permission checking
consistent over the two areas it's used and eliminates the regression.
The risk was that the reported regression would almost certainly have
serious affects for our container products (at the least) so we needed
to wait for this second patch.
Signed-off-by: Ian Kent <ikent@redhat.com>
Approved-by: Brian Foster <bfoster@redhat.com>
Approved-by: Miklos Szeredi <mszeredi@redhat.com>
Approved-by: Carlos Maiolino <cmaiolino@redhat.com>
Approved-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
Merged-by: CKI GitLab Kmaint Pipeline Bot <26919896-cki-kmaint-pipeline-bot@users.noreply.gitlab.com>1 file changed
+21
-11
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2673 | 2673 | | |
2674 | 2674 | | |
2675 | 2675 | | |
| 2676 | + | |
| 2677 | + | |
| 2678 | + | |
| 2679 | + | |
| 2680 | + | |
| 2681 | + | |
| 2682 | + | |
| 2683 | + | |
| 2684 | + | |
| 2685 | + | |
| 2686 | + | |
| 2687 | + | |
| 2688 | + | |
2676 | 2689 | | |
2677 | 2690 | | |
2678 | 2691 | | |
| |||
2709 | 2722 | | |
2710 | 2723 | | |
2711 | 2724 | | |
| 2725 | + | |
| 2726 | + | |
| 2727 | + | |
| 2728 | + | |
2712 | 2729 | | |
2713 | 2730 | | |
2714 | 2731 | | |
| |||
3102 | 3119 | | |
3103 | 3120 | | |
3104 | 3121 | | |
3105 | | - | |
3106 | | - | |
3107 | | - | |
3108 | | - | |
3109 | | - | |
3110 | | - | |
3111 | | - | |
3112 | | - | |
3113 | | - | |
3114 | | - | |
| 3122 | + | |
| 3123 | + | |
3115 | 3124 | | |
3116 | | - | |
| 3125 | + | |
| 3126 | + | |
3117 | 3127 | | |
3118 | 3128 | | |
3119 | 3129 | | |
| |||
0 commit comments