I've just released Linux 2.4.36.5. The patch and changelog will appear soon at the following locations: ftp://ftp.all.kernel.org/pub/linux/kernel/v2.4/ ftp://ftp.all.kernel.org/pub/linux/kernel/v2.4/patch-2.4.36.5.bz2 ftp://ftp.all.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.36.5 Git repository: git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-v2.4.36.y.git http://www.kernel.org/pub/scm/linux/kernel/git/stable/linux-v2.4.36.y.git Git repository through the gitweb interface: http://git.kernel.org/?p=linux/kernel/git/stable/linux-v2.4.36.y.git It fixes 3 medium vulnerabilities : - sit: Add missing kfree_skb() on pskb_may_pull() failure (CVE-2008-2136) - sparc: Fix mmap VA span checking (CVE-2008-2137) - old buffer overflow in moxa driver (CVE-2005-0504) The remaining patches are minor backports and fixes. Given the nature of the vulnerabilities, it is recommended to upgrade. Regards, Willy -- Summary of changes from v2.4.36.4 to v2.4.36.5 ============================================ David S. Miller (2): sit: Add missing kfree_skb() on pskb_may_pull() failure (CVE-2008-2136) sparc: Fix mmap VA span checking (CVE-2008-2137) Gunnar Larisch (1): 3c980-TX needs EXTRA_PREAMBLE Li Zefan (1): ACPI: check a return value correctly in acpi_power_get_context() Roel Kluin (1): wireless, airo: waitbusy() won't delay Steve Rosenbluth (2): signal.h: use an explicit cast to silent compiler warnings fix build error with some flavours of gcc 2.95.3 Willy Tarreau (1): Change VERSION to 2.4.36.5 dann frazier (1): old buffer overflow in moxa driver (CVE-2005-0504) --
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Andrew Morton | Re: -mm merge plans for 2.6.23 -- sys_fallocate |
| Greg KH | Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching |
git: | |
| Gerrit Renker | [PATCH 03/37] dccp: List management for new feature negotiation |
| Arjan van de Ven | Re: [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Jarek Poplawski | Re: [BUG] New Kernel Bugs |
