<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="e6e2ffbd54ec927734c60e0c70947511"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sledp1-kernel-4471"
    timestamp="1191368998"
    engine="1.0">
  <yum:name>sledp1-kernel</yum:name>
  <summary lang="en">Security update for Linux kernel</summary>
  <summary lang="de">Security update for Linux kernel</summary>
  <description lang="en">This kernel update fixes the following security problems:

- - CVE-2007-4573: It was possible for local user to become
  root by exploiting a bug in the IA32 system call
  emulation. This affects x86_64 platforms with kernel
  2.4.x and 2.6.x before 2.6.22.7 only.

- - CVE-2007-4571: An information disclosure vulnerability
  in the ALSA driver can be exploited by local users to
  read sensitive data from the kernel memory.

and the following non security bugs:

- -  patches.xen/xen-blkback-cdrom: CDROM removable
  media-present attribute plus handling code   [#159907]
- -  patches.drivers/libata-add-pata_dma-kernel-parameter:
  libata: Add a drivers/ide style  DMA disable  [#229260]
  [#272786]
- -
  patches.drivers/libata-sata_via-kill-SATA_PATA_SHARING:
  sata_via: kill SATA_PATA_SHARING register handling
  [#254158] [#309069]
- -  patches.drivers/libata-sata_via-add-PCI-IDs:
  sata_via: add PCI IDs  [#254158] [#326647]
- -  supported.conf: Marked 8250 and 8250_pci as supported
  (only Xen kernels build them as modules) [#260686]
- -  patches.fixes/bridge-module-get-put.patch: Module use
  count must be updated as bridges are created/destroyed
  [#267651]
- -  patches.fixes/iscsi-netware-fix: Linux Initiator hard
  hangs writing files to NetWare target  [#286566] 
- -  patches.fixes/lockd-chroot-fix: Allow lockd to work
  reliably with applications in a chroot [#288376] [#305480]
- -  add patches.fixes/x86_64-hangcheck_timer-fix.patch fix
  monotonic_clock() and hangcheck_timer [#291633]
- -  patches.arch/sn_hwperf_cpuinfo_fix.diff: Correctly
  count CPU objects for SGI ia64/sn hwperf interface
  [#292240]
- -  Extend reiserfs to properly support file systems up to
  16 TiB  [#294754]
     - patches.fixes/reiserfs-signedness-fixes.diff:
reiserfs: fix usage of signed ints for block numbers
     - patches.fixes/reiserfs-fix-large-fs.diff:  reiserfs:
ignore s_bmap_nr on disk for file systems &gt;= 8 TiB 
- -  patches.suse/ocfs2-06-per-resource-events.diff:
  Deliver events without a specified resource
  unconditionally.  [#296606]
- -  patches.fixes/proc-readdir-race-fix.patch:  Fix the
  race in proc_pid_readdir  [#297232]
- -  patches.xen/xen3-patch-2.6.16.49-50: XEN: update to
  Linux 2.6.16.50 [#298719]
- -  patches.fixes/pm-ordering-fix.patch: PM: Fix ACPI
  suspend / device suspend ordering  [#302207]
- -  patches.drivers/ibmvscsi-slave_configure.patch add
  -&gt;slave_configure() to allow device restart  [#304138]
- -  patches.arch/ppc-power6-ebus-unique_location.patch
  Prevent bus_id collisions  [#306482]
- -  patches.xen/30-bit-field-booleans.patch: Fix packet
  loss in DomU xen netback driver  [#306896]
- -  config/i386/kdump: Enable ahci module  [#308556]
- -  update patches.drivers/ppc-power6-ehea.patch fix link
  state detection for bonding  [#309553]
- -  patches.drivers/ibmveth-fixup-pool_deactivate.patch
  patches.drivers/ibmveth-large-frames.patch
  patches.drivers/ibmveth-large-mtu.patch: fix serveral
  crashes when changing ibmveth sysfs values  [#326164]
- -
patches.drivers/libata-sata_sil24-fix-IRQ-clearing-race-on-I
  RQ_WOC: sata_sil24: fix IRQ clearing race when
  PCIX_IRQ_WOC is used [#327536]
- -  update patches.drivers/ibmvscsis.patch set blocksize
  to PAGE_CACHE_SIZE to fix flood of bio allocation
  warnings/failures [#328219]


Fixes for S/390:

- - IBM Patchcluster 17  [#330036]

    - Problem-ID:  38085 - zfcp: zfcp_scsi_eh_abort_handler
or zfcp_scsi_eh_device_reset_handler hanging after CHPID
off/on
    - Problem-ID:  38491 - zfcp: Error messages when LUN 0
is present
    - Problem-ID:  37390 - zcrypt: fix PCIXCC/CEX2C error
recovery [#306056]
    - Problem-ID:  38500 - kernel: too few page cache pages
in state volatile
    - Problem-ID:  38634 - qeth: crash during reboot after
failing online setting
    - Problem-ID:  38927 - kernel: shared memory may not be
volatile
    - Problem-ID:  39069 - cio: Disable channel path
measurements on shutdown/reboot
    - Problem-ID:  27787 - qeth: recognize &quot;exclusively
used&quot;-RC from Hydra3
    - Problem-ID:  38330 - qeth: make qeth driver loadable
without ipv6 module


    For further description of the named Problem-IDs,
please look to
http://www-128.ibm.com/developerworks/linux/linux390/october
2005_recommended.html
</description>
  <description lang="de">This kernel update fixes the following security problems:

- - CVE-2007-4573: It was possible for local user to become
  root by exploiting a bug in the IA32 system call
  emulation. This affects x86_64 platforms with kernel
  2.4.x and 2.6.x before 2.6.22.7 only.

- - CVE-2007-4571: An information disclosure vulnerability
  in the ALSA driver can be exploited by local users to
  read sensitive data from the kernel memory.

and the following non security bugs:

- -  patches.xen/xen-blkback-cdrom: CDROM removable
  media-present attribute plus handling code   [#159907]
- -  patches.drivers/libata-add-pata_dma-kernel-parameter:
  libata: Add a drivers/ide style  DMA disable  [#229260]
  [#272786]
- -
  patches.drivers/libata-sata_via-kill-SATA_PATA_SHARING:
  sata_via: kill SATA_PATA_SHARING register handling
  [#254158] [#309069]
- -  patches.drivers/libata-sata_via-add-PCI-IDs:
  sata_via: add PCI IDs  [#254158] [#326647]
- -  supported.conf: Marked 8250 and 8250_pci as supported
  (only Xen kernels build them as modules) [#260686]
- -  patches.fixes/bridge-module-get-put.patch: Module use
  count must be updated as bridges are created/destroyed
  [#267651]
- -  patches.fixes/iscsi-netware-fix: Linux Initiator hard
  hangs writing files to NetWare target  [#286566] 
- -  patches.fixes/lockd-chroot-fix: Allow lockd to work
  reliably with applications in a chroot [#288376] [#305480]
- -  add patches.fixes/x86_64-hangcheck_timer-fix.patch fix
  monotonic_clock() and hangcheck_timer [#291633]
- -  patches.arch/sn_hwperf_cpuinfo_fix.diff: Correctly
  count CPU objects for SGI ia64/sn hwperf interface
  [#292240]
- -  Extend reiserfs to properly support file systems up to
  16 TiB  [#294754]
     - patches.fixes/reiserfs-signedness-fixes.diff:
reiserfs: fix usage of signed ints for block numbers
     - patches.fixes/reiserfs-fix-large-fs.diff:  reiserfs:
ignore s_bmap_nr on disk for file systems &gt;= 8 TiB 
- -  patches.suse/ocfs2-06-per-resource-events.diff:
  Deliver events without a specified resource
  unconditionally.  [#296606]
- -  patches.fixes/proc-readdir-race-fix.patch:  Fix the
  race in proc_pid_readdir  [#297232]
- -  patches.xen/xen3-patch-2.6.16.49-50: XEN: update to
  Linux 2.6.16.50 [#298719]
- -  patches.fixes/pm-ordering-fix.patch: PM: Fix ACPI
  suspend / device suspend ordering  [#302207]
- -  patches.drivers/ibmvscsi-slave_configure.patch add
  -&gt;slave_configure() to allow device restart  [#304138]
- -  patches.arch/ppc-power6-ebus-unique_location.patch
  Prevent bus_id collisions  [#306482]
- -  patches.xen/30-bit-field-booleans.patch: Fix packet
  loss in DomU xen netback driver  [#306896]
- -  config/i386/kdump: Enable ahci module  [#308556]
- -  update patches.drivers/ppc-power6-ehea.patch fix link
  state detection for bonding  [#309553]
- -  patches.drivers/ibmveth-fixup-pool_deactivate.patch
  patches.drivers/ibmveth-large-frames.patch
  patches.drivers/ibmveth-large-mtu.patch: fix serveral
  crashes when changing ibmveth sysfs values  [#326164]
- -
patches.drivers/libata-sata_sil24-fix-IRQ-clearing-race-on-I
  RQ_WOC: sata_sil24: fix IRQ clearing race when
  PCIX_IRQ_WOC is used [#327536]
- -  update patches.drivers/ibmvscsis.patch set blocksize
  to PAGE_CACHE_SIZE to fix flood of bio allocation
  warnings/failures [#328219]


Fixes for S/390:

- - IBM Patchcluster 17  [#330036]

    - Problem-ID:  38085 - zfcp: zfcp_scsi_eh_abort_handler
or zfcp_scsi_eh_device_reset_handler hanging after CHPID
off/on
    - Problem-ID:  38491 - zfcp: Error messages when LUN 0
is present
    - Problem-ID:  37390 - zcrypt: fix PCIXCC/CEX2C error
recovery [#306056]
    - Problem-ID:  38500 - kernel: too few page cache pages
in state volatile
    - Problem-ID:  38634 - qeth: crash during reboot after
failing online setting
    - Problem-ID:  38927 - kernel: shared memory may not be
volatile
    - Problem-ID:  39069 - cio: Disable channel path
measurements on shutdown/reboot
    - Problem-ID:  27787 - qeth: recognize &quot;exclusively
used&quot;-RC from Hydra3
    - Problem-ID:  38330 - qeth: make qeth driver loadable
without ipv6 module


    For further description of the named Problem-IDs,
please look to
http://www-128.ibm.com/developerworks/linux/linux390/october
2005_recommended.html
</description>
  <yum:version ver="4471" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="kernel-bigsmp" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-default" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-smp" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-source" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-syms" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-xen" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
    <rpm:entry kind="atom" name="kernel-xenpae" epoch="0" ver="2.6.16.53" rel="0.16" flags="EQ"/>
  </rpm:requires>
  <reboot-needed/>
  <category>security</category>
    <license-to-confirm>
This update can be used to install a new kernel.
 
If you decide to use the kernel update, we recommend that you reboot
your system upon completion of the YaST Online Update, as additional
kernel modules may be needed which can only be loaded after the system
is rebooted.

If you are in the course of performing a new installation, the installer
will reboot the machine after installing the patch. If you do not want 
to reboot, deselect this patch.
    </license-to-confirm>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-bigsmp</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">1bd2ba49f592a15dfab160a798029c4709f3d437</checksum>
      <time file="1191487491" build="1191368998"/>
      <size package="18582587" installed="77927651" archive="74759708"/>
      <location xml:base="media://#1" href="suse/i586/kernel-bigsmp-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-bigsmp" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-bigsmp"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-default</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">9fb0c345018f03002b0554aaf5059dbe1ecb9ed2</checksum>
      <time file="1191487470" build="1191367050"/>
      <size package="18203206" installed="48795118" archive="45625060"/>
      <location xml:base="media://#1" href="suse/i586/kernel-default-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-default" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-default"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-smp</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">cf4be611d0e92532a31588fa84e43c0c6b4ec4de</checksum>
      <time file="1191487571" build="1191369611"/>
      <size package="18558548" installed="56485647" archive="53330920"/>
      <location xml:base="media://#1" href="suse/i586/kernel-smp-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-smp" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-smp"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-source</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">a01d9ced0af17b896db4daca849b4ece96a9f07e</checksum>
      <time file="1191487465" build="1191366092"/>
      <size package="45492330" installed="230729827" archive="234472500"/>
      <location xml:base="media://#1" href="suse/i586/kernel-source-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-source" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-source"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-syms</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">55732b81a8cc2ef970c53a29ee42a91432357aa3</checksum>
      <time file="1191487650" build="1191466514"/>
      <size package="2062202" installed="2947539" archive="2951848"/>
      <location xml:base="media://#1" href="suse/i586/kernel-syms-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-syms" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-syms"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-xen</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">72d9c283b1fba7cca30c3e0ef59e466b5581c5b4</checksum>
      <time file="1191487610" build="1191369675"/>
      <size package="19030774" installed="56738197" archive="53596492"/>
      <location xml:base="media://#1" href="suse/i586/kernel-xen-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-xen" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-xen"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>kernel-xenpae</name>
      <arch>i586</arch>
      <version epoch="0" ver="2.6.16.53" rel="0.16"/>
      <checksum type="sha" pkgid="YES">132fa6c198be61e8ccec92e72856476a2d7a4598</checksum>
      <time file="1191487628" build="1191371140"/>
      <size package="19103260" installed="56863241" archive="53713304"/>
      <location xml:base="media://#1" href="suse/i586/kernel-xenpae-2.6.16.54-0.2.5.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="kernel-xenpae" epoch="0" ver="2.6.16.53" rel="0.16" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="kernel-xenpae"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
