This update fixes the following security issues:
- A flaw was found in the way the Linux kernel's Event Poll (epoll)
subsystem handled large, nested epoll structures. A local, unprivileged
user could use this flaw to cause a denial of service. (CVE-2011-1083,
Moderate)
- A malicious Network File System version 4 (NFSv4) server could return a
crafted reply to a GETACL request, causing a denial of service on the
client. (CVE-2011-4131, Moderate)
Bugs fixed (http://bugzilla.redhat.com/):
542378 - fix suspend to disk of virtio block
596419 - capability check in pci_read_config() bypasses lsm/selinux
623913 - [virtio] virtio-serial doesn't work after s3/s4 in kvm guest.
624189 - [virtio] virtio-balloon doesn't work after s3/s4 in kvm guest.
624756 - idle time accounted for twice in /proc/stat for Xen guest
645365 - KVM: Implement emulation of emulated virtual PMU
681578 - CVE-2011-1083 kernel: excessive in kernel CPU consumption when creating large nested epoll structures
694801 - Guest fail to resume from S4 if guest using kvmclock
726369 - host reboot auto when run guest with cgroup charge_migrate enabled
727700 - Anomaly in mbind memory map causing Java Hotspot JVM Seg fault with NUMA aware ParallelScavange GC
729586 - xen: fix drive naming
735105 - ext4 corruption via Ceph userspace program
738151 - xHCI driver died after times of attach/detach usb3 hub(with usb3 device) from usb3 root hub
745713 - command-line clocksource override fails
745775 - Unable to unmount autofs filesystems inside a container
745952 - cxgb4: remove forgotten real_num_tx_queues inicialization
746929 - nVidia NVS 300 – won't boot
747034 - nVidia NVS 450 – won't boot
747106 - CVE-2011-4131 kernel: nfs4_getfacl decoding kernel oops
749117 - extN: new file created even if open(2) returned -EPERM
752137 - memcg: catch memcg page accounting leaks in debug kernel
755046 - max_segments in dm is always 128
756307 - Failed to boot RHEL6.2 hvm guest with three NICs when using xvdx disk
757040 - Network RPS miscellaneous bugs, RPS unusable
758707 - hpsa: Add IRQF_SHARED back in for the non-MSI(X) interrupt handler
766554 - ecryptfs keeps directory busy even after umount
767992 - nfnetlink_log.h - missing definitions in userspace
769652 - scsi_alloc_sdev can leak memory
770250 - readdir64_r calls fail with ELOOP
772317 - Disable LRO for all NICs that have LRO enabled
772874 - cifs: multiple process stuck waiting for page lock
773219 - Detach a busy block device for 64 bit pv guest sometimes crash
773705 - cifs: i/o error on copying file > 102336 bytes
781524 - AMD IOMMU driver hands out dma handles that are in the MSI address range
784351 - IMA audit events don't show success correctly
784856 - KVM: expose FMA4 & TBM to guest
786149 - CIFS DFS doesn't work in kernel versions 2.6.32-220.x.x.el6.x86_64
786610 - PCI device reset can cause a kernel bug
786693 - Fix recently identified races within the autofs kernel wait code
788562 - kvm guest hangs when hot-plugged vcpu is onlined due to uninitialized hv_clock
790418 - Request for kernal ABI additions
790961 - pNFS: Auto-load the pNFS kernel module
796099 - add myri10ge firmware
799075 - Fix setting of bio flags
800041 - iSER (iscsi rdma) connection can get broken as of missing receive buffers
801111 - [Mellanox 6.3 Feature]: update mlx4_en driver to support SRIOV
803132 - [Kernel-251] Guest got reboot instead of wakeup after resume from S3 with kvmclock
803187 - Guest mouse and keyboard got unresponsive after resume from S3 with virtio devices
803239 - Call Trace when use netfront NIC on RHEL6.3 HVM guest with xen_emul_unplug=never
803620 - backport vpmu fixes from upstream
807215 - after host S4 the guest can not work normally
807354 - xenpv guests fail to find root device
808571 - rhel 6.3 – add relevant wireless fixes from upstream 3.2.y tree
809231 - merged back raid image (with change tracking) doesn't appear to get synced properly
810222 - Revert "[virt] xen: mask MTRR feature from guest BZ#750758"
811669 - Suspend/resume of an out-of-sync RAID LV will cause the sync process to stall
812259 - add option to disable 5GHz band to iwlwifi
813550 - [REGRESSION] be2iscsi: fix softirq errors when logging in and doing IO
813678 - [FCoE Target] Please disable debug logging of "tcm_fc" "ft_dump_cmd 2700002a 00009aba 000000bc 00000000"
813948 - DM RAID: Reintegrating RAID1 devices causes fullsync even when partial would do
814302 - large writes to ext4 may return incorrect value
815751 - cifs: Show backupuid/gid in /proc/mounts
815785 - kdump fails with lapic error in xen hvm guest
816099 - Guest doesn't let host know of open virtio console ports after resume
816569 - Cannot un/mute audio via alsamixer for HDA codec CX20561 (Hermosa)
817236 - Regression since 2.6.32-266.el6 AMD host writes 150+ GB dmesg logs
818371 - kernel crashes when snapshots of mounted raid volumes are taken
820507 - idle field does not increase monotonically in /proc/stat
822189 - [RHEL6.3][kernel debug] Connectathon 'Special' test failures NFSv2,3
824287 - [REGRESSION] be2iscsi: fix dma free size mismatch
Ahh, lustre/Changelog in b2_3 has it right:
2.6.32-279.5.1.el6 (RHEL6)