Skip to content

Releases: microsoft/azurelinux

3.0.20260909

Choose a tag to compare

@jslobodzian jslobodzian released this 12 Sep 01:54

Generic Kernel version-release: kernel-6.6.150.1-1

Add Kubevirt sidecar-shim sub-package and golden container image
Add openvmm to SPECS/SPECS-EXTENDED
Fix atftp ptest
Fix containerd2
Fix glibc ptest
Fix kata-containers-cc
Fix libgit2 ptest
Fix memcached authentication token and binary protocol crash fixes
Fix openssl backport EVP_PKEY_Q_keygen support
Fix pango ptest
Fix poetry ptest
Fix rasdaemon
Fix tracelogging ptest
Patch apr-util for CVE-2026-32327, CVE-2026-34502, CVE-2026-34501, CVE-2025-49506
Patch bison for CVE-2026-56389, CVE-2026-56390
Patch bluez for CVE-2026-75032
Patch cert-manager for CVE-2026-73500
Patch cloud-provider-kubevirt for CVE-2026-73500
Patch cpio for CVE-2026-66486, CVE-2026-66485, CVE-2026-66484
Patch docker-cli for CVE-2026-17106
Patch edk2 for CVE-2026-75803, CVE-2026-63076, CVE-2026-63074, CVE-2026-63072, CVE-2026-42770
Patch emacs for CVE-2026-79992, CVE-2026-77219
Patch erlang for CVE-2026-75538, CVE-2026-74994, CVE-2026-74835, CVE-2026-73812, CVE-2026-73276, CVE-2026-73270, CVE-2026-71380, CVE-2026-70399, CVE-2026-69664, CVE-2026-66357, CVE-2026-55951, CVE-2026-53422, CVE-2026-54887, CVE-2026-55950, CVE-2026-59250
Patch expat for CVE-2026-76957, CVE-2026-76956, CVE-2026-76641, CVE-2026-66046
Patch flannel for CVE-2026-73500
Patch gawk for CVE-2026-40553, CVE-2026-40468, CVE-2026-40467
Patch gdb for CVE-2026-15003
Patch influxdb for CVE-2026-55969, CVE-2026-48586, CVE-2026-43871
Patch iperf3 for CVE-2026-71218, CVE-2026-71217
Patch kata-containers for CVE-2026-50540, CVE-2026-77176
Patch kata-containers-cc for CVE-2026-55969, CVE-2026-48586, CVE-2026-43871, CVE-2026-50540, CVE-2026-44210
Patch kbd for CVE-2026-72693
Patch keda for CVE-2026-79921, CVE-2026-73500
Patch keras for CVE-2026-12480
Patch kube-vip-cloud-provider for CVE-2026-73500
Patch kubernetes for CVE-2026-73500
Patch libgit2 for CVE-2026-53587, CVE-2026-53586, CVE-2026-53585, CVE-2026-53584, CVE-2026-53583
Patch libssh2 for CVE-2026-58051
Patch libvirt for CVE-2026-63623, CVE-2026-63622, CVE-2026-61477, CVE-2026-18917
Patch moby-engine for CVE-2026-61711, CVE-2026-61712, CVE-2026-75593, CVE-2026-17106
Patch mysql for CVE-2026-63388, CVE-2026-63387, CVE-2026-63385, CVE-2026-63384, CVE-2026-63383, CVE-2026-63382, CVE-2026-63381, CVE-2026-63379
Patch nmap for CVE-2026-72712
Patch nodejs for CVE-2026-15157
Patch ntfs-3g for CVE-2026-56136, CVE-2026-56135
Patch ntp for CVE-2026-63388, CVE-2026-63387, CVE-2026-63385, CVE-2026-63384, CVE-2026-63383, CVE-2026-63382, CVE-2026-63381, CVE-2026-63379
Patch openssh for CVE-2026-73283, CVE-2026-73282, CVE-2026-73281
Patch openssl for CVE-2026-75803, CVE-2026-63076, CVE-2026-63075, CVE-2026-63074, CVE-2026-63073, CVE-2026-63072, CVE-2026-54874
Patch packer for CVE-2026-19589, CVE-2026-71557, CVE-2026-71556
Patch perl for CVE-2026-15534, CVE-2026-19487
Patch prometheus-adapter for CVE-2026-73500, CVE-2026-33186
Patch python-cryptography for CVE-2026-69249
Patch python-lxml for CVE-2026-49825
Patch python-pip for CVE-2026-13346
Patch python-virtualenv for CVE-2026-13346
Patch pytorch for CVE-2026-63632
Patch rabbitmq-server for CVE-2026-65624, CVE-2026-59248, CVE-2026-43971
Patch rpm for CVE-2026-44605
Patch rsyslog for CVE-2026-19654
Patch ruby for CVE-2026-80213, CVE-2026-80212
Patch rust for CVE-2026-47143
Patch strongswan for CVE-2026-47895
Patch sudo for CVE-2026-82474
Patch swtpm for CVE-2026-75900
Patch systemd for CVE-2026-16742, CVE-2026-15059
Patch systemd-bootstrap for CVE-2026-15059
Patch telegraf for CVE-2026-79921, CVE-2026-54332
Patch vitess for CVE-2026-65959
Upgrade KubeVirt to 1.8.4, LibVirt to 11.9.0 and QEMU to 10.1.0
Upgrade ca-certificates Msft cert change (Picks up missing Go-Daddy Cert)
Upgrade clamav to 1.5.4 for CVE-2026-20348, CVE-2026-20347, CVE-2026-20346, CVE-2026-20345, CVE-2026-20339, CVE-2026-20338, CVE-2026-20337
Upgrade cloud-hypervisor to 52.0.152
Upgrade expat to 2.8.3 for CVE-2026-72522
Upgrade freeipmi to 1.6.19 for CVE-2026-85504, CVE-2026-85508, CVE-2026-85505, CVE-2026-85509, CVE-2026-85506, CVE-2026-85507
Upgrade gh to 2.98.0 for CVE-2026-72924
Upgrade golang to 1.26.7-1 (Previous Tip Version)
Upgrade golang to 1.27.1-2 (New Tip Version)
Upgrade libevent to 2.1.13 for CVE-2026-63388, CVE-2026-63381, CVE-2026-63387, CVE-2026-63385, CVE-2026-63382, CVE-2026-63379, CVE-2026-63383, CVE-2026-63384
Upgrade libgcrypt to 1.11.3
Upgrade libgpg-error to 1.49
Upgrade libkcapi to 1.5.1 for CVE-2026-71225, CVE-2026-71226, CVE-2026-71227
Upgrade libpcap to 1.10.7 for CVE-2026-18238, CVE-2026-31911, CVE-2026-18313, CVE-2026-6244, CVE-2026-31912, CVE-2026-0799, CVE-2026-6554
Upgrade mariadb to 10.11.19
Upgrade nodejs to 24.20.0
Upgrade p11-kit to 0.26.5 for CVE-2026-18938, CVE-2026-13757
Upgrade perl-DBI to 1.652 for CVE-2026-73193, CVE-2026-73194
Upgrade perl-HTTP-Date to 6.08 for CVE-2026-14741
Upgrade postgresql to 16.15 for CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471, CVE-2026-14662, CVE-2026-14663, CVE-2026-14664, CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14676, CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680, CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16238, CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408, CVE-2026-19385
Upgrade python-mistune to 3.3.4 for CVE-2026-76098
Upgrade python-webob to 1.8.11 for CVE-2026-54770
Upgrade python3 to 3.12.14 for CVE-2026-18503, CVE-2026-15308, CVE-2026-7210, CVE-2026-4224
Upgrade rsync to 3.5.0 for 33 CVEs
Upgrade rubygem-msgpack to 1.8.4 for CVE-2026-54522
Upgrade rust to 1.96.1
Upgrade shim to 16.1
Upgrade trident to 0.28.0
Upgrade tzdata to 2026c (Includes new British Columbia Time Zone change)
Upgrade unbound to 1.26.0
Upgrade valkey to 8.0.11 for CVE-2026-82631
Upgrade vim to 9.2.0976 for CVE-2026-73078, CVE-2026-73074, CVE-2026-73072, CVE-2026-73077, CVE-2026-73076, CVE-2026-73070, CVE-2026-73075, CVE-2026-73071 CVE-2026-73073
Enable CONFIG_PCI_P2PDMA, CONFIG_VFIO_PCI_DMABUF, CONFIG_IOMMUFD and CONFIG_IOMMUFD_VFIO_CONTAINER to support GPU pass-thru on arm64
e2fsprogs: backport fix for e2fsck skipping checks with orphan_file
imageconfig: marketplace-gen2-kernel-mshv: install nested virt packages
Toolkit: ImageGen tooling rebased from parted to sfdisk. Updated minimum Golang version to 1.25

3.0.20260809

Choose a tag to compare

@jslobodzian jslobodzian released this 13 Aug 02:32

Generic Kernel version-release: kernel-6.6.150.1-1

Upgrade ca-certificates Msft cert change
bcc: Backport profile tool from upstream
feat(kernel-hwe): Enable vmxnet3
feat(kernel): enable fscrypt configs for kernel and kernel-ipe
Fix container-publishing fixes via cherry-pick #18033 + #18034 to 3.0-dev
Fix golang version cap for nvidia container runtime
Fix ISO attendedinstaller to consume Disks section from attendedconfig.json
Fix ptest failures for multiple packages
Fix workflow permissions for 19 check/lint/quickstart workflows
golang: bump Go version to 1.25.12-1
Kernel upgrade to version 6.6.150.1
Merge PR Upgrade perl-DBI to 1.651 for CVE-2026-14380, CVE-2026-14739 & CVE-2026-14740
Patch application-gateway-kubernetes-ingress for CVE-2026-56852
Patch azcopy for CVE-2026-56852
Patch azurelinux-image-tools for CVE-2026-56852
Patch busybox for CVE-2026-38753, CVE-2026-38752, CVE-2026-38755, CVE-2026-38754
Patch cert-manager for CVE-2026-56852, CVE-2026-63308
Patch cf-cli for CVE-2026-56852
Patch cloud-provider-kubevirt for CVE-2026-56852
Patch containerd2 for CVE-2026-56852
Patch containerized-data-importer for CVE-2026-56852
Patch coredns for CVE-2026-56852
Patch coredns for CVE-2026-62299
Patch coredns for CVE-2026-62994
Patch coreutils for CVE-2025-5278
Patch cri-tools for CVE-2026-56852
Patch curl for CVE-2026-8932, CVE-2026-8927, CVE-2026-8926, CVE-2026-12064, CVE-2026-8458, CVE-2026-9079, CVE-2026-8286, CVE-2026-10536, CVE-2026-11856
Patch dcos-cli for CVE-2026-56852
Patch docker-buildx for CVE-2026-56852
Patch docker-cli for CVE-2026-56852
Patch docker-compose for CVE-2026-56852
Patch erlang for CVE-2026-54886
Patch erlang for CVE-2026-59251, CVE-2026-58227, CVE-2026-55953, CVE-2026-55737, CVE-2026-42792
Patch flannel for CVE-2026-56852
Patch gh for CVE-2026-59831
Patch git-lfs for CVE-2026-56852
Patch glib for CVE-2026-58016, CVE-2026-58015, CVE-2026-58014, CVE-2026-58013, CVE-2026-58012, CVE-2026-58011, CVE-2026-58010, CVE-2026-15588
Patch haproxy for CVE-2026-26081
Patch hdf5 for CVE-2025-44904
Patch hdf5 for CVE-2026-26199, CVE-2026-26197, CVE-2026-17574, CVE-2026-17573, CVE-2026-17572
Patch ignition-flatcar for CVE-2026-56852
Patch influxdb for CVE-2026-56852
Patch isns-utils for CVE-2026-55995
Patch jx for CVE-2026-56852
Patch kata-containers for CVE-2026-56852
Patch kata-containers-cc for CVE-2026-56852
Patch keda for CVE-2026-56852
Patch kube-vip-cloud-provider for CVE-2026-56852
Patch kubernetes for CVE-2024-7598
Patch kubernetes for CVE-2026-56852
Patch kubevirt for CVE-2026-56852
Patch kured for CVE-2026-56852
Patch libarchive for CVE-2026-14164
Patch libreswan for CVE-2026-50722, CVE-2026-50721, CVE-2026-12413
Patch libsndfile for CVE-2026-37555
Patch libsolv for CVE-2026-48863
Patch libssh for CVE-2026-59850, CVE-2026-59847, CVE-2026-59845, CVE-2026-59844, CVE-2026-59843, CVE-2026-59848
Patch libssh2 for CVE-2026-66035, CVE-2026-66034, CVE-2026-66033, CVE-2026-66032
Patch libtiff for CVE-2026-12912
Patch moby-containerd-cc for CVE-2026-46680, CVE-2026-53488, CVE-2026-56852
Patch moby-engine for CVE-2026-56852
Patch mtr for CVE-2026-14461
Patch multus for CVE-2026-56852
Patch nginx for CVE-2026-42055, CVE-2026-56434, CVE-2026-42533
Patch nodejs for CVE-2026-12151, CVE-2026-9679, CVE-2026-11525
Patch opa for CVE-2026-56852
Patch open-vm-tools for CVE-2025-41244
Patch openssh for CVE-2026-60002, CVE-2026-60001, CVE-2026-60000, CVE-2026-59999, CVE-2026-59997, CVE-2026-59996, CVE-2026-59995
Patch openssl for CVE-2026-45447, CVE-2026-42769, CVE-2026-42770
Patch packer for CVE-2026-56852, CVE-2026-45570, CVE-2026-45571
Patch patch for CVE-2026-56289, CVE-2026-56288
Patch perl for CVE-2026-57432, CVE-2026-13221, CVE-2026-57433
Patch perl-HTTP-Daemon for CVE-2026-8450
Patch prometheus-adapter for CVE-2026-56852
Patch prometheus-node-exporter for CVE-2026-56852
Patch prometheus-process-exporter for CVE-2026-56852
Patch python-msgpack for CVE-2026-57585
Patch python-pyasn1 for CVE-2026-59884, CVE-2026-59885, CVE-2026-59886
Patch python-setuptools for CVE-2026-59890
Patch python3 for CVE-2026-9669, CVE-2026-6879, CVE-2026-6100, CVE-2026-4786, CVE-2026-4360, CVE-2026-3644, CVE-2026-3276, CVE-2026-3087, CVE-2026-2297, CVE-2026-12003, CVE-2026-11972, CVE-2026-0864
Patch pytorch for CVE-2026-14647
Patch qemu for CVE-2026-3842
Patch qtbase for CVE-2026-15037
Patch rabbitmq-server for CVE-2026-43966, CVE-2026-44839, 11 CVE-2026-572xx
Patch rest for CVE-2026-16615
Patch rubygem-excon for CVE-2026-54171
Patch rust for CVE-2026-47143
Patch skopeo for CVE-2026-56852
Patch squid for CVE-2026-50012, CVE-2026-47729
Patch sriov-network-device-plugin for CVE-2026-56852
Patch telegraf for CVE-2026-56852, CVE-2026-58253, CVE-2026-58252, CVE-2026-58251, CVE-2026-58250, CVE-2026-58209, CVE-2026-58208, CVE-2026-58207, CVE-2026-54908, CVE-2025-29923, CVE-2025-46327
Patch vitess for CVE-2026-56852, CVE-2026-55969, CVE-2026-43871
Upgrade azurelinux-image-tools to version v1.6.0
Upgrade bind to 9.20.26 for CVE-2026-11331, CVE-2026-11721, CVE-2026-13321, CVE-2026-10723, CVE-2026-12617, CVE-2026-10822, CVE-2026-11605, CVE-2026-11622
Upgrade cifs-utils to 7.7 for CVE-2026-12505
Upgrade clamav to 1.5.3 for CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244, CVE-2026-14191
Upgrade etcd to 3.5.33 for CVE-2026-56852, CVE-2026-59818
Upgrade fwupd to v2.0.20 and promote to SPECS
Upgrade golang to 1.26.5-2
Upgrade iscsi-initiator-utils to version 2.1.12 for CVE-2026-44943, CVE-2026-44944
Upgrade kata-containers to 3.32.kata0
Upgrade kernel to version 6.18.38.2
Upgrade libXfont2 to 2.0.8 for CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
Upgrade nodejs to 24.18.1 for CVE-2026-56846, CVE-2026-56848, CVE-2026-58043, CVE-2026-56850, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58045, CVE-2026-56847, CVE-2026-58039, CVE-2026-58044
Upgrade perl-DBI to 1.651 for CVE-2026-14380, CVE-2026-14739, CVE-2026-14740
Upgrade PHP to 8.3.33 for CVE-2026-12184, CVE-2026-14355
Upgrade python-jwt to 2.13.0 for CVE-2026-32597, CVE-2026-48526, CVE-2026-48522, CVE-2026-48525, CVE-2026-48524
Upgrade rpcbind to 1.2.9 for CVE-2026-16277
Upgrade shim to v16.1 w/ dual signatures
Upgrade SymCrypt-OpenSSL to 1.10 with ML-KEM support
Upgrade thrift to 0.24.0 for CVE-2026-48144, CVE-2026-49158, CVE-2026-58023, CVE-2026-58662, CVE-2026-66053, CVE-2026-55970, CVE-2026-41608, CVE-2026-55969, CVE-2026-43871, CVE-2026-48586, CVE-2026-48145, CVE-2026-55971, CVE-2026-41606, CVE-2026-41607
Upgrade trident to 0.26.0
Upgrade unbound to 1.25.2 (24 CVEs)
Upgrade valkey to 8.0.10 for CVE-2026-56684, CVE-2026-63639
Upgrade vim to 9.2.0782 for CVE-2026-59856
Upgrade xorg-x11-server-Xwayland to 24.1.13 for CVE-2026-55999, CVE-2026-56000

3.0.20260706

Choose a tag to compare

@jslobodzian jslobodzian released this 08 Jul 20:04

Generic Kernel version-release: kernel-6.6.143.1-1

Add argparse-manpage to SPECS-EXTENDED
Add Koji message-bus packages to SPECS-EXTENDED
Add nftables patch to fix segfault when listing ruleset containing user-data (udata) in rule expressions
Add ukify-fix-insertion-of-padding-in-merged-sections patch to systemd
Fix failing core ptest in systemd and libguestfs
Fix gd ptest issue
Fix krb5 Backport upstream SPNEPO mechListMIC parsing fix (ticket 9183)
Fix libstoragemgmt: Address ptest and package installation failure
Fix openmpi runtime dependencies
Fix openmpi subpackages
Fix openmpi Restore openmpi-devel subpackages
Fix ptest failure in rng-tools
Fix ptest failures in perl-IO-Socket-SSL package
Fix ptest failures in python-beautifulsoup4 package
Fix ptest failures in python-zope-interface package
Fix ptest for gperftools
Fix ptest for python-omegaconf
Fix ptests failure in openvswitch package
Fix ptests failure in runc package
Fix ptests failure in subversion package
Fix selinux-policy to allow container engines to mmap runtime files
Fix selinux-policy to update policy for irqbalance v1.9.5
Fix waagent-network-setup.service failure and update to teardown the specific interface
freeradius: move from specs-extended to specs
libssh2: patch CVE-2026-55200 (OOB write in transport read)
Merge PR Patch perl for CVE-2026-48962, CVE-2026-48959, CVE-2026-42496, CVE-2025-15649
Merge PR Patch perl-DBI for CVE-2026-10879
mlnx-ofa_kernel-hwe-modules-signed: drop fwctl.ko (broken since DOCA 3.3.0 bump)
Patch bzip2 for CVE-2026-42250
Patch cf-cli for CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch cloud-provider-kubevirt for CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch cmake for CVE-2026-4873, CVE-2026-6276, CVE-2026-6253, CVE-2026-6429, CVE-2026-5545
Patch cni-plugins for CVE-2026-42506, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch containerd2 for CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch crash for CVE-2025-11083
Patch curl for CVE-2026-6253, CVE-2026-6429, CVE-2026-5545
Patch dasel for CVE-2026-42506, CVE-2026-27136, CVE-2026-25680, CVE-2026-42502, CVE-2026-25681
Patch dhcpcd for CVE-2026-14258, CVE-2026-56113, CVE-2026-56117, CVE-2026-56116, CVE-2026-56114
Patch docker-buildx for CVE-2026-39833, CVE-2026-46598, CVE-2026-42502, CVE-2026-39835, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch docker-compose for CVE-2026-46598, CVE-2026-42502, CVE-2026-39835, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch edk2 for CVE-2026-9076, CVE-2026-7383, CVE-2026-45447, CVE-2026-45445, CVE-2026-42767, CVE-2026-42766, CVE-2026-34182, CVE-2026-34180
Patch elixir for CVE-2026-49762
Patch gdb for CVE-2025-11083
Patch gh for CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch gh for CVE-2026-45803
Patch glib for CVE-2026-0988
Patch glib-networking for CVE-2026-10028
Patch gnupg2 for CVE-2026-57062
Patch golang & golang-1.25 for CVE-2026-39821
Patch gzip for CVE-2026-41992
Patch haproxy for CVE-2026-55204, CVE-2026-55203
Patch jq for CVE-2026-49839, CVE-2026-47770, CVE-2025-9403
Patch kata-containers for CVE-2025-58160 and CVE-2026-27171
Patch kata-containers-cc for CVE-2025-5791 and CVE-2025-4574, CVE-2026-42250
Patch keda for CVE-2026-41889, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch ldns for CVE-2026-10846
Patch libinput for CVE-2026-50292
Patch libnfs for CVE-2026-53689
Patch libsolv for CVE-2026-9150, CVE-2026-9149
Patch libsoup for CVE-2026-2708, CVE-2026-6324
Patch libssh2 for CVE-2026-55199, CVE-2025-15661
Patch libxml2 for CVE-2026-0989
Patch multus for CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch nginx for CVE-2026-49975, CVE-2026-48142
Patch nmap for CVE-2026-58058
Patch opensc for CVE-2026-10275
Patch openssh for CVE-2026-35387, CVE-2026-35414
Patch openssl for CVE-2026-34182, CVE-2026-9076, CVE-2026-7383, CVE-2026-45446, CVE-2026-45445, CVE-2026-42768, CVE-2026-42766, CVE-2026-34183, CVE-2026-34180, CVE-2026-42767
Patch opentelemetry-cpp for CVE-2026-44967
Patch packer for CVE-2026-39833, CVE-2026-45570, CVE-2026-45571
Patch perl for CVE-2026-48962, CVE-2026-48959, CVE-2026-42496, CVE-2025-15649, CVE-2026-12087, CVE-2026-8376
Patch perl-Bytes-Random-Secure for CVE-2026-11625
Patch perl-DBI for CVE-2026-10879, CVE-2026-9698
Patch perl-HTML-Parser for CVE-2026-8829
Patch poetry for CVE-2026-41140
Patch python-pip for CVE-2026-8643
Patch python-virtualenv for CVE-2026-8643
Patch python3 for CVE-2025-13462, CVE-2026-8328, CVE-2026-7774
Patch qemu for CVE-2026-3195, CVE-2026-3196, CVE-2026-48914
Patch rabbitmq-server for CVE-2026-43973
Patch rrdtool for CVE-2026-43958
Patch rust for CVE-2026-40034, CVE-2026-5222, CVE-2026-5223
Patch sqlite for CVE-2026-11822, CVE-2026-11824
Patch telegraf for CVE-2026-46598, CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch tmux for CVE-2026-11623
Patch util-linux for CVE-2026-13595
Prevent corruption from stale alias state on daemon-reload
refactor(openssl-fips-provider): Better align with openssl's fips provider
Upgrade acl to 2.4.0 for CVE-2026-54369, CVE-2026-54370, CVE-2026-54371
Upgrade alsa-lib to 1.2.16.1 for CVE-2026-56109
Upgrade attr to 2.6.0 for CVE-2026-54369, CVE-2026-54370, CVE-2026-54371
Upgrade azurelinux-image-tools to v1.5.0
Upgrade cloud-hypervisor to 51.1.101
Upgrade dnsmasq to 2.93 for CVE-2026-12969, CVE-2026-12725
Upgrade doca to 3.3.0
Upgrade erlang to 26.2.5.21 for CVE-2026-42789, CVE-2026-42790, CVE-2026-49760, CVE-2026-49759, CVE-2026-48860, CVE-2026-48858, CVE-2026-48856, CVE-2026-48855
Upgrade expat to 2.8.2 for multiple CVEs
Upgrade freeipmi to 1.6.18 for CVE-2026-50031
Upgrade gnutls to 3.8.13 for CVE-2026-42012, CVE-2026-42013, CVE-2026-5260
Upgrade golang to 1.25.11-1
Upgrade golang to 1.26.4-1
Upgrade httpd to 2.4.68 for CVE-2026-49975
Upgrade icu component version for package nodejs
Upgrade kernel-hwe to 6.18.36.1 and doca to 3.3.0 (first version with 6.18 series kernel)
Upgrade kernel to version 6.6.143.1
Upgrade kernel-mshv to 6.6.137.mshv2
Upgrade libslirp to 4.9.3 for CVE-2026-9539
Upgrade libusb to 1.0.30 for CVE-2026-23679, CVE-2026-47104
Upgrade libXpm to 3.5.19 for CVE-2026-4367
Upgrade lldpd to 1.0.22 for CVE-2026-46433
Upgrade mock to 6.7 and add dependent package argparse-manpage version 4.7
Upgrade nodejs to 24.17.0 for multiple CVEs
Upgrade openssl to 3.3.7
Upgrade openvswitch to 3.3.9
Upgrade postfix to 3.9.11 for CVE-2026-43964
Upgrade python-mistune to 3.3.0 for CVE-2026-49851
Upgrade python-webob to 1.8.10 for CVE-2026-44889
Upgrade radvd to 2.21 for CVE-2026-48715
Upgrade rubygem-concurrent-ruby to 1.3.7 for CVE-2026-54904, CVE-2026-54905, CVE-2026-54906
Upgrade rubygem-nokogiri to 1.19.4 for CVE-2026-57438, CVE-2026-57435, CVE-2026-57236, CVE-2026-57437, CVE-2026-57434, CVE-2026-57436, CVE-2026-57234, CVE-2026-57235
Upgrade runc to 1.3.6 for CVE-2026-41579
Upgrade trident to 0.24.0
Upgrade vim to 9.2.0735 for CVE-2026-52858, CVE-2026-52859, CVE-2026-52860, CVE-2026-47162, CVE-2026-47167, CVE-2026-57452, CVE-2026-57455, CVE-2026-55895, CVE-2026-55693, CVE-2026-57456, CVE-2026-55892, CVE-2026-57451, CVE-2026-57453, CVE-2026-57454
Upgrade xorg-x11-server-Xwayland to 24.1.12 for CVE-2026-50256, CVE-2026-50257, CVE-2026-50258, CVE-2026-50259, CVE-2026-50260, CVE-2026-50261, CVE-2026-50262 and CVE-2026-50263

3.0.20260616

Choose a tag to compare

@jslobodzian jslobodzian released this 24 Jun 00:20
35ec15a

Generic Kernel version-release: kernel-6.6.141.1-1

This targeted 3.0 release upgrades the kernel to 6.6.141.1 to reinstate the CX3 Driver support unintentionally dropped in the 6.6.139.1 kernel.

3.0.20260602

Choose a tag to compare

@jslobodzian jslobodzian released this 08 Jun 13:33

Generic Kernel version-release: kernel-6.6.139.1-1

Add gcab 1.6 cabinet archive library package
Add koji.
Add support for Azure Container Linux in WALinuxAgent
Enable edk2 aarch64 VMF build.
Enable missing kernel-mshv configs per customer request
Fix azcopy ptest
Fix azcopy ptests failure
Fix Cython ptest
Fix docs: remove/deprecate references to 2.0
Fix docs: update readme
Fix docs: update readme text
Fix git-lfs ptest
Fix git-lfs ptests failure
Fix haproxy config file overwrite on upgrade
Fix libical ptest
Fix librelp ptest
Fix lujavrite ptest
Fix ptest issue for libmicrohttpd
Fix python‑markdown ptest
Fix python‑tqdm ptest
Fix systemd unmanaged interface in networkd
Fix systemd unnecessary nftables initialization by backporting upstream
Patch application-gateway-kubernetes-ingress for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680, CVE-2026-33814
Patch azcopy for CVE-2026-39821
Patch azurelinux-image-tools for CVE-2026-39821, CVE-2026-33814
Patch binutils for CVE-2025-3198
Patch binutils for CVE-2026-6846
Patch cert-manager for CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680, CVE-2026-35469, CVE-2026-33814
Patch cf-cli for CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136
Patch cloud-provider-kubevirt for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136
Patch containerd2 for CVE-2026-27136, CVE-2026-39821, CVE-2026-39882, CVE-2026-33814, CVE-2026-42506,
Patch containerized-data-importer for CVE-2026-25681, CVE-2026-25680, CVE-2026-27136, CVE-2026-33814, CVE-2026-35469, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506,
Patch coredns for CVE-2026-32936, CVE-2026-32934, CVE-2026-33489, CVE-2026-33190, CVE-2026-39821
Patch cri-tools for CVE-2026-35469, CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch curl for CVE-2026-7168, CVE-2026-6276, CVE-2026-4873
Patch docker-buildx for CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39832, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136, CVE-2026-35469
Patch docker-cli for CVE-2026-39821
Patch docker-compose for CVE-2026-35469, CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39832, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136
Patch etcd for CVE-2026-39821, CVE-2026-29181
Patch fio for CVE-2026-30656
Patch firewalld for CVE-2026-4948
Patch flannel for CVE-2026-39821
Patch gdb for CVE-2025-1178, CVE-2025-1176, CVE-2026-6846
Patch gh for CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136
Patch git-lfs for CVE-2026-39821
Patch glibc for CVE-2026-4046
Patch gnutls for CVE-2026-33845, CVE-2026-3832, CVE-2026-33846, CVE-2026-42010, CVE-2026-42009
Patch ignition-flatcar for CVE-2026-29181, CVE-2026-33814, CVE-2026-39821
Patch influxdb for CVE-2026-41602, CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch jq for CVE-2026-43896, CVE-2026-43895, CVE-2026-41257, CVE-2026-41256, CVE-2026-40612, CVE-2026-44777
Patch jx for CVE-2026-39821
Patch kata-containers for CVE-2026-41602, CVE-2026-39821, CVE-2026-33814
Patch kata-containers-cc for CVE-2026-41602, CVE-2026-39821, CVE-2026-33814
Patch keda for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-35469
Patch kf-kcoreaddons for CVE-2026-41526
Patch krb5 for CVE-2026-40356
Patch kube-vip-cloud-provider for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch kubernetes for CVE-2026-46597, CVE-2026-42506, CVE-2026-39834, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-39835, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch kubevirt for CVE-2026-7374, CVE-2026-33814, CVE-2026-35469, CVE-2026-46597, CVE-2026-42506, CVE-2026-39829, CVE-2026-39834, CVE-2026-39830, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch kured for CVE-2026-35469, CVE-2026-39821
Patch libssh for CVE-2026-0968
Patch libyang for CVE-2026-41401, CVE-2026-44673
Patch memcached for CVE-2026-47783, CVE-2026-47784
Patch moby-containerd-cc for CVE-2026-35469, CVE-2026-39821
Patch moby-engine for CVE-2026-46597, CVE-2026-39834, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-39835, CVE-2026-39827
Patch multus for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136
Patch nano for CVE-2026-6843, CVE-2026-6842
Patch nginx for CVE-2026-8711, CVE-2026-9256,CVE-2026-42946, CVE-2026-42945, CVE-2026-42934, CVE-2026-40701, CVE-2026-40460
Patch nvidia-container-toolkit for CVE-2026-39834, CVE-2026-39830
Patch opa for CVE-2026-39821
Patch openvswitch for CVE-2026-34956
Patch packer for CVE-2026-33814, CVE-2026-46597, CVE-2026-42508, CVE-2026-42506, CVE-2026-39834, CVE-2026-39832, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136, CVE-2026-46598, CVE-2026-42502, CVE-2026-39835, CVE-2026-39828, CVE-2026-39827, CVE-2026-25681, CVE-2026-25680
Patch perl-XML-LibXML for CVE-2026-8177
Patch prometheus-adapter for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch prometheus-node-exporter for CVE-2026-39821
Patch prometheus-process-exporter for CVE-2026-39821
Patch python-click for CVE-2026-7246
Patch python-pip for CVE-2026-3219, CVE-2026-6357
Patch python-twisted for CVE-2026-42304
Patch python-urllib3 for CVE-2026-44431
Patch Python-virtualenv for CVE-2026-3219, CVE-2026-6357
Patch python3 for CVE-2026-1502
Patch pytorch for CVE-2025-51480
Patch rabbitmq-server for CVE-2026-8466, CVE-2026-7790, CVE-2026-43968
Patch rust-afterburn for CVE-2026-25541
Patch skopeo for CVE-2026-39821
Patch sriov-network-device-plugin for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136, CVE-2026-42502, CVE-2026-25681, CVE-2026-25680
Patch systemd for CVE-2026-40226, CVE-2026-40225
Patch telegraf for CVE-2026-41602, CVE-2026-42154, CVE-2026-46597, CVE-2026-42508, CVE-2026-42506, CVE-2026-39834, CVE-2026-39832, CVE-2026-39830, CVE-2026-39829, CVE-2026-39821, CVE-2026-27136, CVE-2026-42151, CVE-2026-41889
Patch thrift for CVE-2026-41636, CVE-2026-41605, CVE-2026-41603, CVE-2026-41602, CVE-2025-48431
Patch vitess for CVE-2026-39821
qemu: Enable user_static builds for providing user mode emulation.
Remove nodejs 20 package and make nodejs 24 as default nodejs package
Resolved ptest failure in azcopy package
Resolved ptest failure in git-lfs package
Resolved ptest failure in libical by upgrading to version 3.0.10
Resolved ptest failure in lujavrite package
Upgrade azurelinux-image-tools to 1.4.0 (fasttrack)
Upgrade bind to 9.20.23 for CVE-2026-3039, CVE-2026-3592, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950
Upgrade containerd2 to 2.2.4
Upgrade cups to 2.4.19 for CVE-2026-41079
Upgrade dnsmasq to 2.92 for CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, CVE-2026-5172
Upgrade etcd to 3.5.30 for CVE-2026-44283
Upgrade frr to 10.5.4 for CVE-2026-37457
Upgrade golang to 1.25.10-1
Upgrade golang to 1.26.3-1
Upgrade haveged to 1.9.22 for CVE-2026-41054
Upgrade httpd to 2.4.67 for CVE-2026-29168, CVE-2026-24072, CVE-2026-34059, CVE-2026-23918, CVE-2026-33857, CVE-2026-34032, CVE-2026-33006, CVE-2026-33007, CVE-2026-29169, CVE-2026-33523
Upgrade kernel-mshv and kernel-uvm to 6.6.137.mshv1
Upgrade libpng to 1.6.58 for a regression introduced in version 1.6.56 that caused to return stale palette data after applying gamma and background transforms in-place
Upgrade mariadb to 10.11.18 for CVE-2026-44168, CVE-2026-44169, CVE-2026-44170, CVE-2026-44171, CVE-2026-44172, CVE-2026-44173, CVE-2026-48165, CVE-2026-48163
Upgrade perl-libwww-perl to 6.83 for CVE-2026-8368
Upgrade pgbouncer to 1.25.2 for CVE-2026-6664, CVE-2026-6665, CVE-2026-6666, CVE-2026-6667
Upgrade php to 8.3.31 for CVE-2026-7261, CVE-2026-7258, CVE-2026-6722, CVE-2026-6735, CVE-2026-7262, CVE-2025-14179, CVE-2026-7568, CVE-2026-7259
Upgrade postgresql to 16.14 for CVE-2026-6473, CVE-2026-6479, CVE-2026-6638, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6472, CVE-2026-6637
Upgrade python-mistune to 3.2.1 for CVE-2026-33079
Upgrade rsync to 3.4.3 for CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232, CVE-2026-29518, CVE-2026-41035
Upgrade unbound to 1.25.1 for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390, CVE-2026-44608
Upgrade valkey to 8.0.9 for CVE-2026-23479, CVE-2026-25243, CVE-2026-23631
Upgrade vim to 9.2.0488 for CVE-2026-45130, CVE-2026-44656, CVE-2026-46483

3.0.20260517

Choose a tag to compare

@jslobodzian jslobodzian released this 20 May 01:02
120377d

Generic Kernel version-release: kernel-6.6.139.1-1

Upgrade kernel to 6.6.139.1-1 for CVE-2026-46333
Upgrade kernel-hwe to 6.12.89.1-1 for CVE-2026-46333

3.0.20260510

Choose a tag to compare

@jslobodzian jslobodzian released this 13 May 06:32
e86d0af

Generic Kernel version-release: kernel-6.6.138.1-1

This kernel only release is to resolve the "CopyFail2" aka "dirty-frag" security vulnerability: CVE-2026-43284 / CVE-2026-43500

Upgrade kernel to version 6.6.138.1-1
Upgrade kernel to version 6.12.87.1

3.0.20260506

Choose a tag to compare

@jslobodzian jslobodzian released this 09 May 15:43
d60b3e3

Generic Kernel version-release: kernel-6.6.137.1-2

Add extra macros parameter to PackageBuild.yml
Add ignition to SPECS/SPECS-EXTENDED
Add rust-afterburn to SPECS/SPECS-EXTENDED
Build Wireshark package with Lua support
Cleanup unwanted files for coreos-init
Enable CONFIG_IKCONFIG_PROC on arm64 kernel
Fix c-ares ptest
Fix check before copying cfg.SrpmsDir
Fix IC golden container pip install failure under CFSClean network isolation
Fix python-google-auth-oauthlib ptest
Fix python-pytest-xdist ptest
Fix qemu-guest-agent startup failure by replacing --blacklist with --block-rpcs
Fix shim update sbat csv to match architecture
Fix systemd pcrlock failure on Hyper-V VMs with vTPM
Improve Live Migration support in QEMU
Patch avahi for CVE-2026-34933
Patch binutils for CVE-2025-69652, CVE-2025-69649, CVE-2025-69646, CVE-2025-69645, CVE-2025-11839, CVE-2025-1148, CVE-2025-1147, CVE-2025-69647, CVE-2026-4647
Patch clamav for CVE-2026-33056, CVE-2026-33055
patch containerd2 for CVE-2026-35469, CVE-2026-34986
Patch containerized-data-importer for CVE-2026-32288
Patch crash for CVE-2026-4647
Patch curl for CVE-2026-3784, CVE-2026-3783, CVE-2026-1965
Patch edk2 for CVE-2026-28390, CVE-2026-28389
Patch emacs for CVE-2026-6861
Patch erlang for CVE-2026-28808, CVE-2026-32147
Patch expat for CVE-2026-32778, CVE-2026-32777, CVE-2026-32776
Patch fluent-bit for CVE-2025-63652 and CVE-2025-63657
Patch frr for CVE-2026-28532, CVE-2026-5107
Patch gdb for CVE-2026-4647
Patch gdk-pixbuf2 for CVE-2026-5201
Patch gh for CVE-2026-32288, CVE-2026-5160
Patch haproxy for CVE-2026-33555
Patch ignition-flatcar for CVE-2026-27141
Patch jq for CVE-2026-40164, CVE-2026-39979, CVE-2026-39956, CVE-2026-33948, CVE-2026-33947, CVE-2026-32316
Patch keras for CVE-2026-1669
Patch kubernetes for CVE-2026-35469
Patch lcms2 for CVE-2026-41254
Patch libarchive for CVE-2026-5121, CVE-2026-4426, CVE-2026-4424
Patch libcap for CVE-2026-4878
Patch libexif for CVE-2026-40386, CVE-2026-40385
Patch libgcrypt for CVE-2026-41989
Patch libsoup for CVE-2026-2436
Patch libssh for CVE-2026-0967, CVE-2026-0966, CVE-2026-0965, CVE-2026-0964
Patch libssh2 for CVE-2026-7598
Patch libtiff for CVE-2026-4775
Patch mesa for CVE-2026-40393
Patch moby-containerd-cc for CVE-2026-39882
Patch moby-engine for CVE-2026-32288, CVE-2026-39882
Patch nodejs for CVE-2026-21716, CVE-2026-21715, CVE-2026-21714, CVE-2026-21713, CVE-2026-21710
Patch nodejs24 for CVE-2026-33672, CVE-2026-33671, CVE-2026-21710, CVE-2026-21637, CVE-2026-21717, CVE-2026-21713, CVE-2026-21714, CVE-2026-21712, CVE-2026-21716, CVE-2026-21715
Patch ntfs-3g for CVE-2026-40706
Patch openssh for CVE-2026-35414, CVE-2026-35388, CVE-2026-35386, CVE-2026-35385
Patch openssl for ....
Patch perl-XML-Parser for CVE-2006-10003, CVE-2006-10002
Patch poetry for CVE-2026-34591
Patch protobuf for CVE-2026-6409
Patch python-lxml for CVE-2026-41066
Patch python-mako for CVE-2026-41205
Patch python-wheel for CVE-2026-24049
Patch pytorch for CVE-2026-34446, CVE-2026-34445
Patch rpm-ostree for CVE-2026-33056, CVE-2026-33055
Patch ruby for CVE-2026-27820
Patch rubygem-faraday for CVE-2026-25765
Patch rubygem-rdiscount for CVE-2026-35201
Patch rust for CVE-2026-2006, CVE-2026-33056, CVE-2026-33055, CVE-2026-34743
Patch sed for CVE-2026-5958
Patch skopeo for CVE-2026-32288
Patch sleuthkit for CVE-2026-40026, CVE-2026-40025, CVE-2026-40024
Patch sqlite for CVE-2025-70873
Patch sudo for CVE-2026-35535
Patch systemd-bootstrap for CVE-2026-29111
Patch telegraf for CVE-2026-33216, CVE-2026-29785 CVE-2026-5160
Patch util-linux for CVE-2026-3184, CVE-2026-27456
Patch vim for CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881, CVE-2026-41411
Patch xorg-x11-server-Xwayland for CVE-2026-34003, CVE-2026-34001, CVE-2026-33999
Patch xz for CVE-2026-34743
Update kernel-uvm-micro config to be able to start kata pod
Upgrade buildah to 1.43.1
upgrade clamav to 1.5.2
Upgrade cloud-hypervisor to v51.1.56
Upgrade containerd2 version to 2.1.6
Upgrade cups to 2.4.18 for CVE-2026-39316, CVE-2026-39314, CVE-2026-34979, CVE-2026-34980 and to fix cupsd crash if user does not exist.
Upgrade erlang to 26.2.5.20 for CVE-2026-28808 and CVE-2026-32147
Upgrade freeipmi to 1.6.17 for CVE-2026-33554
Upgrade golang to 1.26.2-1 and 1.25.9-1
Upgrade irqbalance to 1.9.5 and patch for ENOSPC handling
Upgrade kernel to 6.6.137.1
Upgrade kernel version-release: kernel-6.6.137.1-2
Upgrade kernel-mshv to 6.6.135.mshv2
Upgrade kernel-uvm to 6.6.130.mshv1
Upgrade libpng to 1.6.57 for CVE-2026-34757
Upgrade mysql to 8.0.46
Upgrade python-ecdsa to 0.19.2 for CVE-2026-33936
Upgrade rubygem-addressable to 2.9.0 for CVE-2026-35611
Upgrade vim to 9.2.0323 for CVE-2026-34714, CVE-2026-34982, CVE-2026-35177, CVE-2026-39881, CVE-2026-41411

Note

On the next monthly update (the June Update) the nodejs package will automatically redirect to nodejs24. nodejs20 is End of Life and no longer supported.

3.0.20260401

Choose a tag to compare

@jslobodzian jslobodzian released this 07 Apr 00:31
62b9480

Generic Kernel version-release: kernel-6.6.130.1-3

Add azure-vm-utils to SPECS/SPECS-EXTENDED
Add bootengine to SPECS/SPECS-EXTENDED
Add coreos-cloudinit to SPECS/SPECS-EXTENDED
Add coreos-init to SPECS/SPECS-EXTENDED
Add kata-containers-preview to SPECS/SPECS-EXTENDED
Add Kernel config validation tool
Add Nodejs24 container and distroless image
Add support for kernel flavor versioning
Add update-ssh-keys to SPECS/SPECS-EXTENDED
Add uvm micro kernel to SPECS/SPECS-EXTENDED
Enable crypto kernel configs in kernel version 6.12
Enable lz4, lz4hc and zstd zram compression
Fix Cisco Telegraf
Fix docker engine multiarch image push
Fix espeak-ng ptest
Fix fontconfig ptest
Fix libsoup with_check condition
Fix ntpdate-wrapper binary path
Fix python-daemon ptest regression
Fix python-fields ptest
Fix shim-unsigned-* separately from shim
Patch azurelinux-image-tools for CVE-2026-27141
Patch cmake for CVE-2026-27135
Patch coredns for CVE-2026-26018, CVE-2026-26017
Patch dcos-cli for CVE-2025-30204
Patch edk2 for CVE-2025-69419 and align edk2-hvloader-signed release
Patch flannel for CVE-2026-32241
Patch freetype for CVE-2026-23865
Patch giflib for CVE-2026-23868
Patch glibc for CVE-2026-4437, CVE-2026-4438
Patch grub2 for CVE-2025-0622 and increase SBAT to grub,5
Patch hdf5 for CVE-2025-2915
Patch kernel to enable CONFIG_TCP_CONG_BBR3
Patch kernel-mshv to enable CONFIG_WIREGUARD
Patch libarrow for CVE-2026-25087
Patch libarchive for CVE-2026-4111
Patch libexif for CVE-2026-32775
Patch libssh for CVE-2026-3731
Patch libsoup for CVE-2026-0716, CVE-2026-2443, CVE-2026-2369
Patch libvirt for TPM patches
Patch nasm for CVE-2022-46456
Patch ncurses for CVE-2025-69720
Patch netavark for CVE-2026-25541
Patch nghttp2 for CVE-2026-27135
Patch nodejs for CVE-2026-27135
Patch ocaml for CVE-2026-28364
Patch plexus-utils for CVE-2025-67030
Patch pyOpenSSL for CVE-2026-27459, CVE-2026-27448
Patch python-pyasn1 for CVE-2026-30922
Patch python3 for CVE-2026-4519
Patch python-requests for CVE-2026-25645
Patch python-virtualenv for CVE-2025-50181, CVE-2026-24049, CVE-2026-1703
Patch rpm-ostree for CVE-2026-25541, CVE-2025-58160
Patch rust for CVE-2026-25541, CVE-2026-25727, CVE-2023-48795
Patch skopeo for CVE-2026-24117
Patch squid for CVE-2026-33526, CVE-2026-33515, CVE-2026-32748
Patch strongswan for CVE-2026-25075
Patch telegraf for CVE-2026-4645
Patch vim for CVE-2026-32249 CVE-2026-33412
Upgrade bind to 9.20.21 for CVE-2026-3591, CVE-2026-3119, CVE-2026-3104, CVE-2026-1519
Upgrade erlang to 26.2.5.18 for CVE-2026-23941, CVE-2026-23942, CVE-2026-23943
Upgrade etcd to 3.5.28 for CVE-2026-33413, CVE-2026-33343
Upgrade frr to 10.5.0
Upgrade golang to 1.26.1-1
Upgrade kernel to 6.6.130.1 and reapply recent BBR3 and zram compressions. Includes crackarmor fix CVE-2026-23269
Upgrade kernel-hwe to 6.12.78.2.1 for CVE-2026-23269.
Upgrade KubeVirt to v1.7.1
Upgrade libpng to 1.6.56 for CVE-2026-33636, CVE-2026-33416
Upgrade mariadb to 10.11.16 for CVE-2026-3494
Upgrade nginx to 1.28.3 for CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755
Upgrade shim to v16.1
Upgrade SymCrypt-OpenSSL to 1.9.5
Upgrade trident to v0.22

Additional Notes:
Kernel-hwe was upgraded to 6.12.78.2.1 resulting in a rebuild of cuda-open-hwe OOT module (cuda-open-hwe-580.105.08-7_6.12.78.2.1.azl3.aarch64.rpm)

Note that in a bare metal test scenario, running nvidia-smi caused the kernel to crash with "Trying to vfree() nonexistent vm area (000000001f7525a8)". In virtualized scenarios all testing passed.

2.0.20260331

Choose a tag to compare

@jslobodzian jslobodzian released this 14 Apr 18:33

Generic Kernel version-release: kernel-5.15.202.1-1

Bump collectd and keepalived releases
Fix systemd ipc dbus communication issue
Patch cmake for CVE-2025-14524, CVE-2025-10966, CVE-2026-27135
Patch coredns for CVE-2026-26018, CVE-2026-26017
Patch erlang for CVE-2026-23943, CVE-2026-23942, CVE-2026-23941
Patch freetype for CVE-2026-23865
Patch giflib for CVE-2026-23868
Patch glib for CVE-2026-1489, CVE-2026-0988
Patch hdf5 for CVE-2025-2915
Patch libarchive for CVE-2026-4111
Patch libexif for CVE-2026-32775
Patch libsoup for CVE-2026-1801, CVE-2026-1761, CVE-2026-1467
Patch mariadb for CVE-2026-3494
Patch mysql for CVE-2025-0838, CVE-2024-2410
Patch nasm for CVE-2022-46456
Patch ncurses for CVE-2025-69720
Patch nghttp2 for CVE-2026-27135
Patch nginx for CVE-2026-32647, CVE-2026-28753, CVE-2026-27784, CVE-2026-27654, CVE-2026-27651, CVE-2026-28755
Patch nodejs18 for CVE-2026-27135
Patch ocaml for CVE-2026-28364
Patch openssl for PKCS12_item_decrypt_d2i_ex(): Check oct argument for NULL
Patch plexus-utils for CVE-2025-67030
Patch python-pyasn1 for CVE-2026-30922
Patch python-urllib3 for CVE-2025-66471
Patch python-virtualenv for CVE-2026-1703, CVE-2026-24049
Patch qemu for CVE-2024-8354
Patch qt5-qtdeclarative for CVE-2025-12385
Patch rook for CVE-2025-30204, CVE-2025-11065
Patch rust for CVE-2026-25541, CVE-2026-25727, CVE-2025-58160, CVE-2026-27171
Patch skopeo for CVE-2026-24117
Patch systemd-bootstrap for CVE-2026-29111
Patch telegraf for CVE-2026-4645
Patch terraform for CVE-2026-4645
Patch vim for CVE-2026-32249, CVE-2026-33412
Patch vitess for CVE-2026-27969, CVE-2026-27965
Rebuild lldpd & rsyslog for net-snmp-libs to version 5.9.5.2-1
Upgrade etcd to 3.5.28 for CVE-2026-33413, CVE-2026-33343
Upgrade libpng to 1.6.56 for CVE-2026-33636, CVE-2026-33416
Upgrade msft-golang to 1.25.8