Alibaba Cloud regularly updates the Alibaba Cloud Linux 3 image with the latest operating system features, capabilities, and security patches. This topic lists the latest image versions and their release notes.
Background
-
Unless otherwise specified, updates apply to ECS in all available regions.
-
Alibaba Cloud Linux 3 images are compatible with most instance families. However, some images support only specific instance families, as follows:
-
SCC images (image IDs containing
_scc_) support only the sccg7 and sccc7 instance families. -
ARM images (image IDs containing
_arm64_) support all ARM-based instances on Alibaba Cloud.
-
2026
Alibaba Cloud Linux 3.2104 U13.1
|
Version |
Image ID |
Release date |
Key changes |
|
Alibaba Cloud Linux 3.2104 U13.1 |
aliyun_3_x64_20G_alibase_20260513.vhd |
2026-05-13 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20260513.vhd |
2026-05-13 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20260513.vhd |
2026-05-13 |
|
|
|
aliyun_3_arm64_20G_alibase_20260513.vhd |
2026-05-13 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20260513.vhd |
2026-05-13 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20260513.vhd |
2026-05-13 |
|
Updates
Highlights
Kernel
This release updates the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.
New features
-
[Storage] Introduced I/O attribute passthrough for guests. In Virtio-blk and NVMe scenarios, I/O read and write operations can pass request-level I/O flags to the back end. This enables the back end to identify the I/O model and optimize performance.
-
[Storage] Enhanced ublk capabilities by aligning the ublk code base with the 6.6 upstream mainline.
-
[Driver/Security] Added TSM API support.
Bug fixes
-
Fixed an issue in the IPv4 network module where incorrect matching logic for RAW sockets in ICMP error handling caused network communication issues, such as traceroute failures.
-
mm: Fixed an issue that prevented a large number of ext4_inode_cache entries from being reclaimed.
-
fs/ext4: Fixed an issue that could trigger file system exceptions during the split extent process.
-
cgroup/writeback: Fixed a race condition in cgroup writeback v1 radix tree operations.
-
Fixed an issue where a soft lockup could be triggered during an unmount operation in scenarios with a large number of mount points.
-
cgroup: Fixed an issue in the enhanced block throttle statistics where io_start_time_ns was not correctly set for throttled requests.
CVE fixes
CVE-2024-31402
CVE-2024-23455
CVE-2024-31399
CVE-2024-23450
CVE-2024-23420
CVE-2024-23456
CVE-2024-23449
CVE-2024-23457
CVE-2024-23452
CVE-2024-23038
CVE-2023-54068
CVE-2024-23398
Package updates
New features
-
Cloud application component updates:
-
Updated aliyun-cli from aliyun-cli-3.2.12-1.al8 to aliyun-cli-3.3.14-1.al8. This update is included in the image.
-
Updated ossfs from ossfs-1.91.8-1.al8 to ossfs-1.91.9-1.al8. This update is available in the yum repo.
-
-
OS-level capability enhancements:
-
Updated alinux-release from alinux-release-3.2104.13-1.al8 to alinux-release-3.2104.13.1-1.al8, which indicates the release of Alibaba Cloud Linux 3.2104 U13.1. This update is included in the image.
-
Updated kpatch from kpatch-0.9.7-2.0.4.al8 to kpatch-0.9.7-2.0.5.al8 and added the khotfix-view tool. This update is available in the yum repo.
-
Updated tzdata from tzdata-2025c-1.0.1.1.al8 to tzdata-2026a-1.0.1.1.al8. This update is included in the image.
-
-
Updates to in-house components:
-
Feature updates for cai:
-
Updated cryptpilot from cryptpilot-0.3.4-1.al8 to cryptpilot-0.7.0-1.al8. This update is available in the yum repo.
-
Updated trusted-network-gateway from trusted-network-gateway-2.4.0-1.al8 to trusted-network-gateway-2.5.0-1.al8. This update is available in the yum repo.
-
Updated trustee from trustee-1.7.6-1.al8 to trustee-1.8.3-1.al8. This update is available in the yum repo.
-
Updated trustiflux from trustiflux-1.4.8-1.al8 to trustiflux-1.5.0-1.al8. This update is available in the yum repo.
-
-
Java ecosystem updates:
-
Updated java-1.8.0-alibaba-dragonwell from 8.20.21.422 to 8.28.27.482. This update is available in the yum repo.
-
Updated java-11-alibaba-dragonwell from 11.0.24.21.21 to 11.0.30.27.27. This update is available in the yum repo.
-
Updated java-21-alibaba-dragonwell from 21.0.5.0.5 to 21.0.10.0.10. This update is available in the yum repo.
-
-
System O&M updates:
-
Updated sysak from sysak-3.10.0-1 to sysak-3.13.0-1. This update is included in the image.
-
-
Feature enhancements from Anolis OS 8:
Three components are synchronized from Anolis OS 8 and updated via the yum repo: java-1.8.0-openjdk-portable, java-17-openjdk-portable, and tzdata.
CVE fixes
This release fixes 106 unique CVEs across 51 packages. Key fixes include:
-
freerdp: Fixed 15 CVEs (CVE-2024-22852, CVE-2024-22854, CVE-2024-22856, CVE-2024-23490, CVE-2024-23732, CVE-2024-23865, CVE-2024-23868, CVE-2024-23893, CVE-2024-23948, CVE-2024-24491, CVE-2024-24675, CVE-2024-24676, CVE-2024-24679, CVE-2024-24681, CVE-2024-24683)
-
golang: Fixed 8 CVEs (CVE-2024-61731, CVE-2024-25679, CVE-2024-26955, CVE-2024-26965, CVE-2024-27140, CVE-2024-27143, CVE-2024-27144, CVE-2024-27622)
-
gstreamer1-plugins-base: Fixed 7 CVEs (CVE-2024-2920, CVE-2024-2921, CVE-2024-2922, CVE-2024-2923, CVE-2024-3082, CVE-2024-3083, CVE-2024-3085)
-
java-1.8.0-openjdk: Fixed 7 CVEs (CVE-2024-22007, CVE-2024-22013, CVE-2024-22016, CVE-2024-22018, CVE-2024-22021, CVE-2024-4111, CVE-2024-4177)
-
gstreamer1-plugins-good: Fixed 6 CVEs (CVE-2024-2920, CVE-2024-2921, CVE-2024-2922, CVE-2024-2923, CVE-2024-3082, CVE-2024-3083)
-
mysql: Fixed 6 CVEs (CVE-2024-21936, CVE-2024-21937, CVE-2024-21941, CVE-2024-21948, CVE-2024-21964, CVE-2024-21968)
-
openssh: Fixed 6 CVEs (CVE-2024-3497, CVE-2024-35385, CVE-2024-35386, CVE-2024-35387, CVE-2024-35388, CVE-2024-35414)
-
fontforge: Fixed 4 CVEs (CVE-2024-15269, CVE-2024-15270, CVE-2024-15275, CVE-2024-15279)
-
gimp: Fixed 4 CVEs (CVE-2024-0797, CVE-2024-2044, CVE-2024-2045, CVE-2024-2048)
-
nodejs: Fixed 4 CVEs (CVE-2024-21710, CVE-2024-26996, CVE-2024-27135, CVE-2024-27904)
-
python3: Fixed 4 CVEs (CVE-2024-0938, CVE-2024-4519, CVE-2024-4786, CVE-2024-11234)
-
vim: Fixed 4 CVEs (CVE-2024-28417, CVE-2024-28421, CVE-2024-33412, CVE-2024-33526)
-
tigervnc: Fixed 4 CVEs (CVE-2024-33999, CVE-2024-34001, CVE-2024-34003, CVE-2024-34352)
-
buildah, podman, and containernetworking-plugins: Fixed 3 CVEs (CVE-2024-61726, CVE-2024-61728, CVE-2024-68121)
-
libpng and mingw-libpng: Fixed 3 CVEs (CVE-2024-22695, CVE-2024-22801, CVE-2024-25646)
-
postgresql: Fixed 3 CVEs (CVE-2024-2004, CVE-2024-2005, CVE-2024-2006)
-
xorg-x11-server and xorg-x11-server-Xwayland: Fixed 3 CVEs (CVE-2024-33999, CVE-2024-34001, CVE-2024-34003)
-
sudo: Fixed 1 CVE (CVE-2024-35535)
-
libtiff: Fixed 1 CVE (CVE-2024-4775)
-
libxml2: Fixed 1 CVE (CVE-2024-9714)
This release changes a total of 67 source packages: 54 synchronized from Anolis OS 8 and 13 developed in-house for Alibaba Cloud Linux 3. No ABI changes are introduced.
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.2
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.2 |
aliyun_3_x64_20G_alibase_aiext_0.5.5.2_20260507.vhd |
2026-05-08 |
|
|
Alibaba Cloud Linux 3 AI Extension ARM Edition 0.5.5.2 |
aliyun_3_arm64_20G_alibase_aiext_0.5.5.2_20260507.vhd |
2026-05-08 |
|
Updates
Important updates
-
Kernel:
-
Updates the x86_64 kernel to
kernel-5.10.134-19.201.al8to fix CVE-2026-31431. -
Updates the aarch64 kernel to
kernel-5.10.134-19.3.1.al8to fix CVE-2026-31431.
-
-
Image:
-
Updates
kmod-fusetokmod-fuse-5.10.134~19.201-1.2.4.6~2.al8in the x86_64 image. -
Updates
kmod-fusetokmod-fuse-5.10.134~19.3.1-1.2.4.6~1.al8in the aarch64 image.
-
Security updates
|
Package name |
CVE ID |
Updated version |
|
kernel |
kernel-5.10.134-19.3.al8.aarch64 kernel-5.10.134-19.201.al8.x86_64 |
CVE-2026-31431 |
|
gnutls |
gnutls-3.6.16-8.0.2.al8.5 |
CVE-2025-14831 CVE-2025-9820 |
|
libarchive |
libarchive-3.5.3-7.al8 |
CVE-2026-4111 |
|
util-linux |
libblkid-2.32.1-48.0.1.4.al8 libfdisk-2.32.1-48.0.1.4.al8 libmount-2.32.1-48.0.1.4.al8 libsmartcols-2.32.1-48.0.1.4.al8 libuuid-2.32.1-48.0.1.4.al8 util-linux-2.32.1-48.0.1.4.al8 util-linux-user-2.32.1-48.0.1.4.al8 |
CVE-2025-14104 |
|
python3 |
python3-libs-3.6.8-75.0.1.1.al8 platform-python-3.6.8-75.0.1.1.al8 platform-python-devel-3.6.8-75.0.1.1.al8 |
CVE-2025-0938 CVE-2026-4519 |
|
openssh |
openssh-8.0p1-28.0.1.1.al8 openssh-clients-8.0p1-28.0.1.1.al8 openssh-server-8.0p1-28.0.1.1.al8 |
CVE-2026-3497 |
|
vim |
vim-common-8.0.1763-22.0.1.al8.1 vim-enhanced-8.0.1763-22.0.1.al8.1 vim-filesystem-8.0.1763-22.0.1.al8.1 vim-minimal-8.0.1763-22.0.1.al8.1 |
CVE-2026-28417 CVE-2026-28421 CVE-2026-33412 |
Alibaba Cloud Linux 3.2104 U13.0
|
Version number |
Image ID |
Release date |
Changes |
|
Alibaba Cloud Linux 3.2104 U13.0 |
aliyun_3_x64_20G_alibase_20260503.vhd |
2026-05-03 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20260503.vhd |
2026-05-03 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20260503.vhd |
2026-05-03 |
|
|
|
aliyun_3_arm64_20G_alibase_20260503.vhd |
2026-05-03 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20260503.vhd |
2026-05-03 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20260503.vhd |
2026-05-03 |
|
Updates
Highlights
Kernel
Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.
Feature updates
|
Software package |
Previous version |
New version |
Description |
|
alinux-release |
alinux-release-3.2104.13-1.al8 |
alinux-release-3.2104.13-2.al8 |
Updated the image version identifier package. No functional impact. |
|
aliyun-cli |
aliyun-cli-3.2.12-1.al8 |
aliyun-cli-3.3.4-1.al8 |
A bug-fix release of an Alibaba Cloud proprietary component. No impact on system stability. |
|
sysak |
sysak-3.10.0-1 |
sysak-3.12.0-1 |
Updated an O&M component. This update has a low impact on system stability. |
Bug fixes
Upgraded vim from 8.0.1763-22.0.1.al8 to 8.0.1763-22.0.1.al8.1, which includes six patches fixing issues including crash recovery, command injection, and netrw port handling.
Alibaba Cloud Linux 3.2104 U13
|
Version |
Image ID |
Release date |
Release notes |
|
Alibaba Cloud Linux 3.2104 U13 |
aliyun_3_x64_20G_alibase_20260326.vhd |
2026-03-26 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20260326.vhd |
2026-03-26 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20260326.vhd |
2026-03-26 |
|
|
|
aliyun_3_arm64_20G_alibase_20260326.vhd |
2026-03-26 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20260326.vhd |
2026-03-26 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20260326.vhd |
2026-03-26 |
|
Highlights
Kernel
This release updates the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.
New features
-
Adds support for hiding mount points for rich containers, allowing
mountinfoto modify information about specified mount points. -
Adds
sysinfosyscall handling for rich containers, allowing them to replacelxcfsfunctionality.
Important bug fixes
-
Adds support for Runtime Measurement Registers (RTMR) and attestation for CSV3 virtual machines.
-
Fixes issues in
fs_daxandswiotlb. -
Adds support for the Hygon family 18h model 8h PMU.
-
Fixes the EDAC address translation for Hygon family 18h model 4h.
-
Fixes issues with the EDAC functionality for Hygon family 18h model 4h.
-
Fixes a bug that caused the EDAC module to report a memory translation failure after a correctable error (CE) was injected into a Hygon Gen 2 machine.
-
Fixes issues related to the x86 TSC.
-
Fixes issues with the RAS functionality for Hygon family 18h model 6h.
CVE fixes
CVE-2025-38502
CVE-2024-49861
CVE-2024-26809
CVE-2025-40215
CVE-2025-39964
CVE-2025-38000
CVE-2024-58240
CVE-2025-38001
CVE-2024-57947
CVE-2024-26924
CVE-2023-5197
CVE-2024-26583
CVE-2024-26584
CVE-2025-21756
CVE-2025-37797
CVE-2025-21971
CVE-2025-40019
CVE-2025-40018
CVE-2025-38678
CVE-2025-38618
CVE-2025-38617
CVE-2025-38477
CVE-2025-38177
CVE-2025-38083
CVE-2025-37997
CVE-2025-37798
CVE-2025-37756
CVE-2024-53164
CVE-2024-26921
CVE-2023-52620
CVE-2025-37798
CVE-2025-37756
CVE-2024-53164
CVE-2024-26921
CVE-2023-52620
CVE-2025-37890
CVE-2025-39682
CVE-2025-39946
CVE-2025-40214
CVE-2025-40297
Drivers
-
Updates
kmod-udmafromkmod-udma-5.10.134~18-0.1.0~1.al8tokmod-udma-5.10.134~19.2-0.1.0~1.al8to fix an issue where the udma driver was missing in version 19. -
Replaces
kmod-intel-QAT20withkmod-QAT20-5.10.134~19.3-L.1.2.30__00090~1.al8on x86 platforms to provide the QAT driver.
Package updates
New features
-
Cloud application component updates:
-
The
aliyun-clicomponent is updated in the image fromaliyun-cli-3.2.0-1.al8toaliyun-cli-3.2.6-1.al8.
-
-
OS-level capability enhancements:
-
The
alinux-releasecomponent is updated in the image fromalinux-release-3.2104.12-1.al8toalinux-release-3.2104.13-1.al8, marking the release of Alinux 3.13. -
The
glibccomponent is updated in the image fromglibc-2.32-1.22.al8toglibc-2.32-1.23.al8to improve performance on HYGON platforms. -
The
util-linuxcomponent is updated fromutil-linux-2.32.1-46.0.4.1.al8toutil-linux-2.32.1-48.0.1.4.al8, enabling the fstrim service in the ECS image. -
The
alinux-base-setupcomponent is updated in the image fromalinux-base-setup-3.2-11.al8toalinux-base-setup-3.2-14.al8. This update enables theselinux-autorelabel-mark.serviceandfstrim.timerservices to resolve an issue where SSH becomes unavailable after SELinux is enabled and to enable the scheduled fstrim storage task. -
The
dnf-plugin-kernel-installcomponent is updated in the image fromdnf-plugin-kernel-install-1.0-2.al8todnf-plugin-kernel-install-1.0-5.al8. This update provides a convenient tool for managing multiple kernels and automatically parsing kernel versions. -
The
edk2component is updated in the yum repo fromedk2-20220126gitbb1bba3d77-13.0.1.al8.7toedk2-20220126gitbb1bba3d77-13.0.1.al8.8to support the HYGON CSV3 dynamic measurement feature on QEMU. -
The
qemu-kvmcomponent is updated in the yum repo fromqemu-kvm-6.2.0-53.0.8.al8.4toqemu-kvm-6.2.0-53.0.8.1.al8.5to support the HYGON CSV3 dynamic measurement feature on QEMU. -
The
gnome-control-centercomponent is updated in the yum repo fromgnome-control-center-40.0-32.1.al8tognome-control-center-40.0-32.3.al8to support domestic platforms.
-
-
Updates to in-house components:
-
Updates to kernel-related components:
-
Introduces
ras-tools-0.2-2.al8, a toolset for Reliability, Availability, and Serviceability (RAS) monitoring and diagnostics. This toolset collects and analyzes hardware error information on Linux systems, such as memory ECC errors, PCIe AER, and CPU Machine Check events. This update is available in the yum repo.
-
-
Feature updates for cai:
-
The
cryptpilotcomponent is updated in the yum repo fromcryptpilot-0.2.7-1.al8tocryptpilot-0.3.4-1.al8. -
The
trusted-network-gatewaycomponent is updated in the yum repo fromtrusted-network-gateway-2.2.6-1.al8totrusted-network-gateway-2.4.0-1.al8. -
The
trusteecomponent is updated in the yum repo fromtrustee-1.7.0-1.al8totrustee-1.7.6-1.al8. -
The
trustifluxcomponent is updated in the yum repo fromtrustiflux-1.4.4-1.al8totrustiflux-1.4.8-1.al8.
-
-
os-copilot updates:
-
The
os-copilotcomponent is updated in the yum repo fromos-copilot-0.9.1-1.al8toos-copilot-1.1.0-2.al8. This update introduces a multi-agent architecture to improve complex task processing, adds support for specifying backend Model Studio models and custom invocation parameters, and allows for custom MCP servers.
-
-
System operations updates:
-
The
sysakcomponent is updated in the yum repo fromsysak-3.8.1-1tosysak-3.10.0-1.
-
-
Feature enhancements from Anolis OS 8:
This release includes six updated components: one in the image and five via the yum repo. The following table details the changes.
|
Component name |
Previous version |
New version |
Reason for update |
Update method |
|
java-1.8.0-openjdk-portable |
java-1.8.0-openjdk-portable-1.8.0.472.b08-1.0.1.1.al8 |
java-1.8.0-openjdk-portable-1.8.0.482.b08-1.0.1.1.al8 |
Enables system FreeType and adds it to |
Available in the yum repo. |
|
java-17-openjdk-portable |
java-17-openjdk-portable-17.0.16.0.8-1.0.1.1.al8 |
java-17-openjdk-portable-17.0.18.0.8-1.0.2.1.al8 |
Updates the bundled libpng version. Provides: |
Available in the yum repo. |
|
osbuild |
osbuild-141.2-1.0.1.al8 |
osbuild-158-1.0.1.al8 |
Improves build speed and stability through parallelized builds, caching, and resource isolation. Fixes compatibility issues with SELinux and Btrfs, addresses CVEs, enhances image signature verification, optimizes the osbuild-composer interface, and improves distributed build scheduling. |
Available in the yum repo. |
|
rasdaemon |
rasdaemon-0.6.7-16.5.al8 |
rasdaemon-0.8.3-2.al8 |
Records the cause of the last CPU UE failure, logs CPU socket information, and distinguishes between CE, UE, and DE fault types in the logs. |
Available in the yum repo. |
|
sos |
sos-4.8.2-1.0.1.1.al8 |
sos-4.10.0-4.0.1.1.al8 |
Improves postproc library obfuscation in two ways. |
Available in the yum repo. |
|
tzdata |
tzdata-2025b-1.0.1.1.al8 |
tzdata-2025c-1.0.1.1.al8 |
Updates the expiration date of the leap second file. |
Available in the image. |
Bug fix
This release includes 3 bug fixes for Alinux 3. Two of the fixes are in the image and one is in the repo. The updates are as follows:
|
Component |
Previous version |
Updated version |
Update method |
|
alinux-base-setup |
alinux-base-setup-3.2-11.al8 |
alinux-base-setup-3.2-14.al8 |
Updated in the image |
|
gcc |
gcc-10.2.1-3.8.al8 |
gcc-10.2.1-3.9.al8 |
Updated in the image |
|
gcc-toolset-12 |
gcc-toolset-12-12.0-6.1.al8 |
gcc-toolset-12-12.0-6.2.al8 |
Updated in the yum repository |
Defect fixes in Anolis OS 8:
This release contains updates for 6 components: five in the image and one in the repo. The updates are as follows:
|
Component |
Previous version |
Updated version |
Method |
|
coreutils |
coreutils-8.30-15.0.3.al8 |
coreutils-8.30-16.0.1.al8 |
Updated in the image |
|
dracut |
dracut-049-233.git20240115.0.2.1.al8 |
dracut-049-239.git20251127.0.1.1.al8 |
Updated in the image |
|
pam |
pam-1.3.1-38.al8 |
pam-1.3.1-39.al8 |
Updated in the image |
|
selinux-policy |
selinux-policy-3.14.3-139.0.1.al8.1 |
selinux-policy-3.14.3-139.0.1.al8.2 |
Updated in the image |
|
sudo |
sudo-1.9.5p2-1.0.2.al8.1 |
sudo-1.9.5p2-1.0.2.al8.3 |
Updated in the image |
|
unixODBC |
unixODBC-2.3.7-1.2.al8 |
unixODBC-2.3.7-2.0.1.al8 |
Updated in the yum repo |
CVE fixes for Anolis OS 8:
This release updates 45 components: nine are included in the image, and 36 are available in the repository. The following list details each update and its reason.
|
Component |
Previous version |
Updated version |
Fixed CVE-ID |
Update method |
|
brotli |
brotli-1.0.6-3.1.al8 |
brotli-1.0.6-4.al8 |
CVE-2025-6176 |
Image |
|
cups |
cups-2.2.6-64.0.1.al8 |
cups-2.2.6-66.0.1.al8 |
CVE-2025-58436 CVE-2025-61915 |
Image |
|
glib2 |
glib2-2.68.4-16.0.1.al8.2 |
glib2-2.68.4-18.0.1.al8.1 |
CVE-2025-13601 |
Image |
|
gnupg2 |
gnupg2-2.2.20-3.al8 |
gnupg2-2.2.20-4.al8 |
CVE-2025-68973 |
Image |
|
libpng |
libpng-1.6.34-5.2.al8 |
libpng-1.6.34-9.al8 |
CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 |
Image |
|
nfs-utils |
nfs-utils-2.3.3-64.0.1.al8 |
nfs-utils-2.3.3-68.0.1.al8 |
CVE-2025-12801 |
Image |
|
openssl |
openssl-1.1.1k-14.0.2.al8 |
openssl-1.1.1k-15.0.1.al8 |
CVE-2025-9230 CVE-2025-69419 |
Image |
|
python-urllib3 |
python-urllib3-1.24.2-8.al8 |
python-urllib3-1.24.2-9.al8 |
CVE-2025-66418 CVE-2025-66471 CVE-2026-21441 |
Image |
|
python3 |
python3-3.6.8-71.0.1.1.al8 |
python3-3.6.8-73.0.1.1.al8 |
CVE-2025-12084 CVE-2025-15366 CVE-2025-15367 CVE-2026-0865 CVE-2026-1299 |
Image |
|
buildah |
buildah-1.33.12-2.al8 |
buildah-1.33.14-2.al8 |
CVE-2025-52881 CVE-2024-24785 CVE-2025-61729 CVE-2025-65637 |
Yum repository |
|
containernetworking-plugins |
containernetworking-plugins-1.4.0-6.0.1.al8 |
containernetworking-plugins-1.4.0-7.0.1.al8 |
CVE-2024-24785 CVE-2025-61729 CVE-2025-65637 |
Yum repository |
|
freerdp |
freerdp-2.11.7-1.0.1.al8 |
freerdp-2.11.7-3.0.1.al8 |
CVE-2026-23530 CVE-2026-23531 CVE-2026-23532 CVE-2026-23533 CVE-2026-23534 CVE-2026-23883 CVE-2026-23884 |
Yum repository |
|
gimp |
gimp-2.8.22-26.al8.3 |
gimp-2.8.22-26.al8.4 |
CVE-2025-14422 |
Yum repository |
|
git-lfs |
git-lfs-3.4.1-5.0.1.al8 |
git-lfs-3.4.1-8.0.1.al8 |
CVE-2025-26625 CVE-2025-61729 CVE-2025-61726 CVE-2025-68121 |
Yum repository |
|
golang |
golang-1.25.3-2.0.2.al8 |
golang-1.25.7-1.0.1.al8 |
CVE-2025-47906 CVE-2025-58183 CVE-2025-61729 CVE-2025-61726 CVE-2025-61728 CVE-2025-61732 CVE-2025-68121 |
Yum repository |
|
grafana |
grafana-9.2.10-25.0.1.al8 |
grafana-9.2.10-28.0.1.al8 |
CVE-2025-58183 CVE-2025-61729 CVE-2025-61726 CVE-2025-61728 CVE-2025-68121 |
Yum repository |
|
grafana-pcp |
grafana-pcp-5.1.1-10.al8 |
grafana-pcp-5.1.1-12.al8 |
CVE-2025-61729 CVE-2025-61726 CVE-2025-68121 |
Yum repository |
|
iperf3 |
iperf3-3.9-13.al8.1 |
iperf3-3.9-14.al8.1 |
CVE-2025-54349 |
Yum repository |
|
java-1.8.0-openjdk |
java-1.8.0-openjdk-1.8.0.472.b08-1.0.1.1.al8 |
java-1.8.0-openjdk-1.8.0.482.b08-1.0.1.1.al8 |
CVE-2025-64720 CVE-2025-65018 CVE-2026-21925 CVE-2026-21933 CVE-2026-21945 |
Yum repository |
|
java-17-openjdk |
java-17-openjdk-17.0.17.0.10-1.0.2.1.al8 |
java-17-openjdk-17.0.18.0.8-1.0.2.1.al8 |
CVE-2025-64720 CVE-2025-65018 CVE-2026-21925 CVE-2026-21933 CVE-2026-21945 |
Yum repository |
|
libpq |
libpq-13.20-1.0.1.al8 |
libpq-13.23-1.0.1.al8 |
CVE-2025-12818 |
Yum repository |
|
libsoup |
libsoup-2.62.3-10.0.1.al8 |
libsoup-2.62.3-13.0.1.al8 |
CVE-2025-14523 CVE-2026-0719 CVE-2026-1761 |
Yum repository |
|
libvpx |
libvpx-1.7.0-12.0.1.al8 |
libvpx-1.7.0-13.0.1.al8 |
CVE-2026-2447 |
Yum repository |
|
mariadb |
mariadb-10.5.29-2.0.1.al8 |
mariadb-10.5.29-3.0.1.al8 |
CVE-2025-13699 |
Yum repository |
|
mingw-fontconfig |
mingw-fontconfig-2.12.6-3.1.al8 |
mingw-fontconfig-2.12.6-4.al8 |
CVE-2025-59375 |
Yum repository |
|
mingw-libpng |
mingw-libpng-1.6.29-4.1.al8 |
mingw-libpng-1.6.34-1.al8 |
CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 |
Yum repository |
|
munge |
munge-0.5.13-2.1.al8 |
munge-0.5.13-3.0.1.al8 |
CVE-2026-25506 |
Yum repository |
|
net-snmp |
net-snmp-5.8-31.0.1.al8 |
net-snmp-5.8-33.0.1.al8 |
Evaluation engine order fix CVE-2025-68615 |
Yum repository |
|
nodejs |
nodejs-20.19.2-1.1.al8 |
nodejs-20.20.0-1.1.al8 |
CVE-2025-55130 CVE-2025-55131 CVE-2025-55132 CVE-2025-59465 CVE-2025-59466 CVE-2026-21637 |
Yum repository |
|
nodejs-packaging |
nodejs-packaging-2021.06-4.al8 |
nodejs-packaging-2021.06-5.al8 |
CVE-2025-55130 CVE-2025-55131 CVE-2025-55132 CVE-2025-59465 CVE-2025-59466 CVE-2026-21637 |
Yum repository |
|
open-vm-tools |
open-vm-tools-12.3.5-2.al8.1 |
open-vm-tools-12.3.5-2.al8.2 |
CVE-2025-22247 |
Yum repository |
|
osbuild-composer |
osbuild-composer-132.2-3.0.1.al8 |
osbuild-composer-149-3.al8 |
CVE-2025-58183 |
Yum repository |
|
pcs |
pcs-0.10.18-2.0.1.1.al8.7 |
pcs-0.10.18-2.0.1.1.al8.8 |
CVE-2025-67725 CVE-2025-67726 |
Yum repository |
|
php |
php-7.4.33-2.0.1.al8 |
php-7.4.33-3.0.1.al8 |
CVE-2024-8929 CVE-2024-11233 CVE-2024-11234 CVE-2025-1217 CVE-2025-1219 CVE-2025-1220 CVE-2025-1734 CVE-2025-1735 CVE-2025-1736 CVE-2025-1861 CVE-2025-6491 CVE-2025-14177 CVE-2025-14178 |
Yum repository |
|
podman |
podman-4.9.4-23.0.1.al8 |
podman-4.9.4-28.0.1.al8 |
CVE-2025-52881 CVE-2025-47913 CVE-2024-24785 CVE-2025-61729 CVE-2025-65637 |
Yum repository |
|
poppler |
poppler-20.11.0-12.0.1.al8 |
poppler-20.11.0-13.0.1.al8 |
CVE-2025-32365 |
Yum repository |
|
postgresql |
postgresql-13.22-1.0.1.al8 |
postgresql-13.23-1.0.1.al8 |
CVE-2025-12817 CVE-2025-12818 |
Yum repository |
|
python3.11 |
python3.11-3.11.13-2.0.1.al8 |
python3.11-3.11.13-4.0.1.al8 |
CVE-2025-12084 CVE-2025-13836 |
Yum repository |
|
resource-agents |
resource-agents-4.9.0-54.al8.16 |
resource-agents-4.9.0-54.al8.28 |
CVE-2025-66418 CVE-2025-66471 CVE-2026-21441 |
Yum repository |
|
runc |
runc-1.2.5-2.al8 |
runc-1.2.9-3.al8 |
CVE-2025-52881 |
Yum repository |
|
skopeo |
skopeo-1.14.5-4.0.1.al8 |
skopeo-1.14.5-6.al8 |
CVE-2025-52881 |
Yum repository |
|
spice-client-win |
spice-client-win-8.10-1.al8 |
spice-client-win-8.10-7.al8 |
CVE-2025-14523 CVE-2026-0719 CVE-2026-1761 |
Yum repository |
|
toolbox |
toolbox-0.0.99.5-2.0.1.al8 |
toolbox-0.0.99.5.1-1.0.1.al8 |
CVE-2024-24785 CVE-2025-61729 CVE-2025-65637 |
Yum repository |
|
transfig |
transfig-3.2.6a-4.1.al8 |
transfig-3.2.6a-5.al8 |
CVE-2025-46397 |
Yum repository |
|
vsftpd |
vsftpd-3.0.3-36.0.1.al8 |
vsftpd-3.0.3-36.0.1.al8.3 |
CVE-2025-14242 |
Yum repository |
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.1
|
Version |
Image ID |
Release date |
Release notes |
|
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.1 |
aliyun_3_x64_20G_alibase_aiext_0.5.5.1_20260326.vhd |
2026-03-26 |
|
|
aliyun_3_arm64_20G_alibase_aiext_0.5.5.1_20260326.vhd |
2026-03-26 |
|
Content updates
Important updates
-
Kernel: Unchanged from version 0.5.5.
-
Image: Updated kmod-fuse to version 1.2.4.6 to fix an issue where a process could occasionally enter the uninterruptible sleep (D) state. The issue was caused by a concurrency conflict between cached write operations and setattr (utimes/truncate) calls due to metadata optimization.
Security updates
|
Package name |
CVE ID |
Updated version |
|
brotli |
brotli-1.0.6-4.al8 |
CVE-2025-6176 |
|
grub2 |
grub2-common-2.02-170.0.1.1.al8.1 |
CVE-2025-61662 |
|
grub2-efi-x64-2.02-170.0.1.1.al8.1.x86_64 |
||
|
grub2-pc-2.02-170.0.1.1.al8.1.x86_64 |
||
|
grub2-pc-modules-2.02-170.0.1.1.al8.1.noarch |
||
|
grub2-tools-2.02-170.0.1.1.al8.1 |
||
|
grub2-tools-efi-2.02-170.0.1.1.al8.1.x86_64 |
||
|
grub2-tools-extra-2.02-170.0.1.1.al8.1 |
||
|
grub2-tools-minimal-2.02-170.0.1.1.al8.1 |
||
|
grub2-efi-aa64-2.02-170.0.1.1.al8.1.aarch64 |
||
|
util-linux |
libblkid-2.32.1-48.0.1.1.al8 |
CVE-2025-14104 |
|
libfdisk-2.32.1-48.0.1.1.al8 |
||
|
libmount-2.32.1-48.0.1.1.al8 |
||
|
libsmartcols-2.32.1-48.0.1.1.al8 |
||
|
libuuid-2.32.1-48.0.1.1.al8 |
||
|
util-linux-2.32.1-48.0.1.1.al8 |
||
|
util-linux-user-2.32.1-48.0.1.1.al8 |
||
|
nfs-utils |
nfs-utils-2.3.3-68.0.1.al8 |
CVE-2025-12801 |
|
libnfsidmap-2.3.3-68.0.1.al8 |
||
|
libpng |
libpng-1.6.34-10.al8 |
CVE-2026-22695 CVE-2026-22801 CVE-2026-25646 |
|
python3 |
python3-libs-3.6.8-73.0.1.1.al8 |
CVE-2025-12084 CVE-2025-15366 CVE-2025-15367 CVE-2026-0865 CVE-2026-1299 |
|
platform-python-3.6.8-73.0.1.1.al8 |
||
|
platform-python-devel-3.6.8-73.0.1.1.al8 |
||
|
openssl |
openssl-1.1.1k-15.0.1.al8 |
CVE-2025-69419 |
|
openssl-libs-1.1.1k-15.0.1.al8 |
||
|
vim |
vim-common-8.0.1763-22.0.1.al8 |
CVE-2026-25749 |
|
vim-enhanced-8.0.1763-22.0.1.al8 |
||
|
vim-filesystem-8.0.1763-22.0.1.al8 |
||
|
vim-minimal-8.0.1763-22.0.1.al8 |
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5
|
Version |
Image ID |
Release date |
Release notes |
|
Alibaba Cloud Linux 3 AI Extension Edition 0.5.5 |
aliyun_3_0_x64_20G_alibase_aiext_0.5.5_20260203.vhd |
2026-02-03 |
|
|
aliyun_3_0_arm64_20G_alibase_aiext_0.5.5_20260203.vhd |
2026-02-03 |
|
Updates
Important updates
-
Upgraded the x86_64 kernel to
5.10.134-19.200.al8.x86_64:-
Fixed an issue where a microcode hot-patch incorrectly attempted to fix the Zenbleed vulnerability on non-Zen2 architectures.
-
Fixed an issue where downstream devices could be used before their initialization was complete after a PCIe secondary bus reset. This could cause errors or take the devices offline.
-
Fixed a potential crash in the Group Balancer.
-
Fixed an issue that caused unexpected packet loss in virtio_net and vhost under specific conditions.
-
Addressed multiple CVEs. See the table below for details.
-
-
Upgraded the aarch64 kernel to
5.10.134-19.3.al8.aarch64:-
Added support for hiding mount points.
-
Added support for rich containers to replace lxcfs.
-
Addressed multiple CVEs. See the table below for details.
-
-
Image updates
-
Updated glibc to
glibc-2.32-1.22.al8to fix an issue wherepthread_cond_waitcould miss a wakeup signal. -
Updated systemd to
systemd-239-82.0.4.4.al8.5to fix a race condition between mount and reload operations. -
Installed
kmod-fuse-5.10.134~19.200-1.2.4.5~2.al8by default on x86_64 images andkmod-fuse-5.10.134~19.3-1.2.4.5~1.al8on aarch64 images to enhance support for FUSE over io_uring mode. -
Addressed CVEs in various packages. See the table below for details.
-
Security updates
|
Package name |
CVE ID |
Updated version |
|
kernel |
CVE-2025-38502 CVE-2024-49861 CVE-2024-26809 CVE-2025-40215 CVE-2025-39964 CVE-2025-38000 CVE-2024-58240 CVE-2025-38001 CVE-2024-57947 CVE-2024-26924 CVE-2023-5197 CVE-2024-26583 CVE-2024-26584 CVE-2025-21756 CVE-2025-37797 CVE-2025-21971 CVE-2025-40019 CVE-2025-40018 CVE-2025-38678 CVE-2025-38618 CVE-2025-38617 CVE-2025-38477 CVE-2025-38177 CVE-2025-38083 CVE-2025-37997 CVE-2025-37798 CVE-2025-37756 CVE-2024-53164 CVE-2024-26921 CVE-2023-52620 CVE-2025-37890 CVE-2025-39682 CVE-2025-39946 CVE-2025-40214 CVE-2025-40297 |
kernel-5.10.134-19.200.al8.x86_64 kernel-5.10.134-19.3.al8.aarch64 |
|
bind |
CVE-2025-8677 CVE-2025-40778 |
bind-export-libs-9.11.36-16.0.1.al8.6 |
|
cups |
CVE-2025-58436 CVE-2025-61915 |
cups-client-2.2.6-66.0.1.al8 cups-libs-2.2.6-66.0.1.al8 |
|
curl |
CVE-2025-9086 |
curl-7.61.1-35.0.2.al8.9 libcurl-7.61.1-35.0.2.al8.3 |
|
expat |
CVE-2013-0340 CVE-2022-23990 CVE-2024-28757 CVE-2025-59375 |
expat-2.5.0-1.al8 |
|
gnutls |
CVE-2025-32988 CVE-2025-32990 CVE-2025-6395 |
gnutls-3.6.16-8.0.2.al8.4 |
|
libpng |
CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 |
libpng-1.6.34-9.al8 |
|
libssh |
CVE-2025-5372 |
libssh-0.9.6-16.0.1.al8 libssh-config-0.9.6-16.0.1.al8 |
|
sssd |
CVE-2025-11561 |
libsss_idmap-2.9.4-5.al8.3 libsss_nss_idmap-2.9.4-5.al8.3 sssd-client-2.9.4-5.al8.3 |
|
openssh |
CVE-2025-61984 CVE-2025-61985 |
openssh-8.0p1-27.0.1.1.al8 openssh-clients-8.0p1-27.0.1.1.al8 openssh-server-8.0p1-27.0.1.1.al8 |
|
vim |
CVE-2025-53905 CVE-2025-53906 |
vim-common-8.0.1763-21.0.1.al8 vim-enhanced-8.0.1763-21.0.1.al8 vim-filesystem-8.0.1763-21.0.1.al8 vim-minimal-8.0.1763-21.0.1.al8 |
|
openssl |
CVE-2025-9230 |
openssl-1.1.1k-14.0.2.al8.0.1 openssl-libs-1.1.1k-14.0.2.al8.0.1 |
Alibaba Cloud Linux 3.2104 U12.3
|
Version |
Image ID |
Release date |
Description |
|
Alibaba Cloud Linux 3.2104 U12.2 |
aliyun_3_x64_20G_alibase_20260122.vhd |
2026-01-22 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20260122.vhd |
2026-01-22 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20260122.vhd |
2026-01-22 |
|
|
|
aliyun_3_arm64_20G_alibase_20260122.vhd |
2026-01-22 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20260122.vhd |
2026-01-22 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20260122.vhd |
2026-01-22 |
|
Package updates
New features
-
Cloud application component updates:
-
The
aliyun-clicomponent in the image has been updated fromaliyun-cli-3.1.3-1.al8toaliyun-cli-3.2.0-1.al8.
-
-
OS enhancements:
-
The
alinux-releasecomponent in the image has been updated fromalinux-release-3.2104.12.2-4.al8toalinux-release-3.2104.12.3-1.al8, which marks the release of Alinux 3.12.3.
-
Bug fixes
Compatibility-related changes:
-
The
kexec-toolscomponent is updated fromkexec-tools-2.0.26-14.0.1.7.al8.2tokexec-tools-2.0.26-14.0.1.9.al8.2. This update addspcie_ports=compatto the kdump cmdline configuration on x86 platforms to fix an issue where kdump hangs on 8th-generation instances. -
The
alinux-base-setuppackage is updated fromalinux-base-setup-3.2-9.al8toalinux-base-setup-3.2-10.al8. This update adds UUID support in/boot/efi/EFI/alinux/grub.cfgto bind the boot disk and fix boot issues on bare metal systems.
|
Component |
Previous version |
Updated version |
Update method |
|
glibc |
glibc-2.32-1.21.al8 |
glibc-2.32-1.22.al8 |
Updated in the image |
|
alinux-base-setup |
alinux-base-setup-3.2-9.al8 |
alinux-base-setup-3.2-10.al8 |
Updated in the image |
|
grub2 |
grub2-2.02-165.0.2.al8 |
grub2-2.02-165.0.2.1.al8 |
Updated in the image |
|
kexec-tools |
kexec-tools-2.0.26-14.0.1.7.al8.2 |
kexec-tools-2.0.26-14.0.1.9.al8.2 |
Updated in the image |
|
systemd |
systemd-239-82.0.4.4.al8.5 |
systemd-239-82.0.4.5.al8.5 |
Updated in the image |
|
grubby |
grubby-8.40-49.0.1.al8 |
grubby-8.40-49.0.1.1.al8 |
Updated in the image |
|
kpatch |
kpatch-0.9.7-2.0.1.al8 |
kpatch-0.9.7-2.0.4.al8 |
Updated via yum repository |
The following table lists bug fixes from Anolis OS 8.
|
Component |
Previous version |
Updated version |
Reason for update |
Update method |
|
quota |
quota-4.09-2.0.1.al8 |
quota-4.09-4.0.1.al8 |
Fixes a memory leak. |
Updated in the image |
|
intel-ipp-crypto-mb |
intel-ipp-crypto-mb-1.0.6-4.al8 |
intel-ipp-crypto-mb-1.0.6-5.al8 |
Fixes an issue where qatengine fails to install when the EPEL repository is configured. |
Updated via yum repository |
|
qatengine |
qatengine-1.2.0-3.al8 |
qatengine-1.2.0-4.al8 |
Updated via yum repository |
|
|
gnome-shell-extensions |
gnome-shell-extensions-40.7-19.0.1.al8 |
gnome-shell-extensions-40.7-29.0.1.al8 |
Fixes an error in the window list reordering backport, resolves issues with the application grid and the Dash to Panel extension, and makes workspace names more prominent in workspaces. |
Updated via yum repository |
|
geoclue2 |
geoclue2-2.6.0-7.al8 |
geoclue2-2.6.0-8.al8.1 |
Migrates user and group management for geoclue2 from manual scripts to a sysusers.d file. |
Updated via yum repository |
|
evolution-data-server |
evolution-data-server-3.40.4-9.0.1.al8 |
evolution-data-server-3.40.4-10.0.1.al8 |
Prevents the signal handler from printing output during execution. Fixes runtime warnings caused by assertion failures. |
Updated via yum repository |
|
gsettings-desktop-schemas |
gsettings-desktop-schemas-40.0-7.0.1.al8 |
gsettings-desktop-schemas-40.0-8.0.1.al8 |
Adds an option to disable password visibility on the login and lock screens. |
Updated via yum repository |
|
pulseaudio |
pulseaudio-15.0-2.0.1.al8 |
pulseaudio-15.0-3.0.1.al8 |
Fixes an auto-start issue. |
Updated via yum repository |
The following table lists the CVE updates.
|
Component |
Previous version |
Updated version |
Fixed CVE ID |
Update method |
|
cups |
cups-2.2.6-63.0.2.al8 |
cups-2.2.6-64.0.1.al8 |
CVE-2025-58364 |
Updated in the image |
|
curl |
curl-7.61.1-35.0.2.al8.3 |
curl-7.61.1-35.0.2.al8.9 |
CVE-2025-9086 |
Updated in the image |
|
openssh |
openssh-8.0p1-26.0.1.1.al8 |
openssh-8.0p1-27.0.1.1.al8 |
CVE-2025-61984 CVE-2025-61985 |
Updated in the image |
|
gimp |
gimp-2.8.22-26.al8.2 |
gimp-2.8.22-26.al8.3 |
CVE-2025-10920 CVE-2025-10921 CVE-2025-10922 CVE-2025-10923 CVE-2025-10924 CVE-2025-10925 CVE-2025-10934 |
Updated via yum repository |
|
abrt |
abrt-2.10.9-24.0.1.al8 |
abrt-2.10.9-25.0.1.1.al8 |
CVE-2025-12744 |
Updated via yum repository |
|
tomcat |
tomcat-9.0.87-1.al8.6 |
tomcat-9.0.87-1.al8.7 |
CVE-2025-31651 CVE-2025-55752 |
Updated via yum repository |
|
luksmeta |
luksmeta-9-4.1.al8 |
luksmeta-9-4.2.al8.1 |
CVE-2025-11568 |
Updated via yum repository |
|
webkit2gtk3 |
webkit2gtk3-2.46.6-2.0.1.al8 |
webkit2gtk3-2.50.4-1.0.1.al8 |
CVE-2025-43501 CVE-2025-43529 CVE-2025-43531 CVE-2025-43535 CVE-2025-43536 CVE-2025-43541 CVE-2024-44192 CVE-2024-54467 CVE-2024-54551 CVE-2025-13502 CVE-2025-13947 CVE-2025-24189 CVE-2025-24208 CVE-2025-24209 CVE-2025-24216 CVE-2025-30427 CVE-2025-31205 CVE-2025-31257 CVE-2025-31273 CVE-2025-31278 CVE-2025-43211 CVE-2025-43212 CVE-2025-43216 CVE-2025-43227 CVE-2025-43240 CVE-2025-43265 CVE-2025-43272 CVE-2025-43342 CVE-2025-43343 CVE-2025-43356 CVE-2025-43368 CVE-2025-43392 CVE-2025-43419 CVE-2025-43421 CVE-2025-43425 CVE-2025-43427 CVE-2025-43429 CVE-2025-43430 CVE-2025-43431 CVE-2025-43432 CVE-2025-43434 CVE-2025-43440 CVE-2025-43443 CVE-2025-43458 CVE-2025-6558 CVE-2025-66287 |
Updated via yum repository |
|
golang |
golang-1.24.6-1.0.1.al8 |
golang-1.25.3-2.0.2.al8 |
CVE-2025-47906 CVE-2025-58183 |
Updated via yum repository |
|
delve |
delve-1.24.1-1.0.2.al8 |
delve-1.25.2-1.0.2.al8 |
CVE-2025-47906 CVE-2025-58183 |
Updated via yum repository |
|
httpd |
httpd-2.4.37-655.0.1.al8.5 |
httpd-2.4.37-655.0.1.al8.6 |
CVE-2025-55753 CVE-2025-58098 CVE-2025-65082 CVE-2025-66200 |
Updated via yum repository |
|
mysql |
mysql-8.0.43-1.0.1.1.al8 |
mysql-8.0.44-1.0.1.1.al8 |
CVE-2025-53040 CVE-2025-53042 CVE-2025-53044 CVE-2025-53045 CVE-2025-53053 CVE-2025-53054 CVE-2025-53062 CVE-2025-53069 |
Updated via yum repository |
Known issues
See the Known issues for Alibaba Cloud Linux 3.2104 U12.1.
2025
Alibaba Cloud Linux 3.2104 U12.2
|
Version |
Image ID |
Release date |
Release summary |
|
Alibaba Cloud Linux 3.2104 U12.2 |
aliyun_3_x64_20G_alibase_20251215.vhd |
2026-01-05 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20251215.vhd |
2026-01-05 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20251215.vhd |
2026-01-05 |
|
|
|
aliyun_3_arm64_20G_alibase_20251215.vhd |
2026-01-05 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20251215.vhd |
2026-01-05 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20251215.vhd |
2026-01-05 |
|
Content updates
Major updates
-
Kernel: The kernel package is kernel-5.10.134-19.2.al8.
-
Driver: The kmod-udma driver is updated to kmod-udma-5.10.134~19.2-0.1.0~1.al8 to ensure compatibility with kmod-intel-QAT20-5.10.134~19.2-L.0.9.4__00004~1.al8.
Package updates
New features
-
Cloud application component updates:
-
aliyun-cli is upgraded from aliyun-cli-3.0.305-1.al8 to aliyun-cli-3.1.3-1.al8. This update is included in the image.
-
-
Core OS enhancements:
-
alinux-release is upgraded to alinux-release-3.2104.12-4.al8, marking the release of Alinux 3.12.2. This update is included in the image.
-
intel-QAT20 is upgraded to intel-QAT20-L.0.9.4-00004.15.al8, adding support for the QAT VF device ID of 9th-generation GNR instances. This update is available in the yum repository.
-
Bug fix
-
Bug fixes for Alibaba Cloud Linux 3:
-
The systemd component is updated from systemd-239-82.0.4.3.al8.5 to systemd-239-82.0.4.4.al8.5 to backport a fix for a race condition between mount and reload. This update is included in the image.
-
The glibc component is updated from glibc-2.32-1.21.al8 to glibc-2.32-1.22.al8 to resolve a "missed wakeup" issue in pthread_cond_wait. This update is included in the image.
-
The tee-primitives component is updated from tee-primitives-1.0-2.al8 to tee-primitives-1.0-3.al8 to address an issue caused by a source code md5sum change. This update is available in the yum repository.
-
The qt5-qtmultimedia component is updated from qt5-qtmultimedia-5.15.3-1.al8 to qt5-qtmultimedia-5.15.3-1.1.al8 to resolve dependency issues. This update is available in the yum repository.
-
The dracut component is updated from dracut-049-233.git20240115.0.2.al8 to dracut-049-233.git20240115.0.2.1.al8 to fix an error when installing a 6.x kernel version on Alibaba Cloud Linux 3. This update is available in the yum repository.
-
The intel-QAT20 component is updated from intel-QAT20-L.0.9.4-00004.12.al8 to intel-QAT20-L.0.9.4-00004.15.al8 to resolve an issue with the Intel QAT VF device ID on 9th-generation GNR instances. This update is available in the yum repository.
-
The qatengine component is updated from qatengine-1.2.0-3.al8 to qatengine-1.2.0-4.al8 to resolve an issue where TLS v1.0 and v1.1 are unsupported when using OpenSSL 3. This update is available in the yum repository.
-
The intel-ipp-crypto-mb component is updated from intel-ipp-crypto-mb-1.0.6-4.al8 to intel-ipp-crypto-mb-1.0.6-5.al8 to resolve an issue where TLS v1.0 and v1.1 are unsupported when using OpenSSL 3. This update is available in the yum repository.
-
-
This release provides bug fixes for 12 Anolis OS 8 components. One is updated in the image, and 11 are available from the yum repository:
Component
Previous version
New version
Update reason
Update method
which
which-2.21-20.0.1.al8
which-2.21-21.0.1.al8
Adds a readability check for /proc/$$/exe.
Updated in the image
dnsmasq
dnsmasq-2.79-33.al8
dnsmasq-2.79-35.al8
Changes the behavior of repeated DNS queries.
Updated from the yum repository
gnome-session
gnome-session-40.1.1-9.0.1.al8
gnome-session-40.1.1-10.0.1.al8
Reduces unnecessary log output during debugging.
Updated from the yum repository
gnome-settings-daemon
gnome-settings-daemon-40.0.1-17.0.1.al8
gnome-settings-daemon-40.0.1-19.0.1.al8
Fixes the default power button action setting for servers.
Fixes an issue that prevented a smart card from working without a cold plug.
Updated from the yum repository
java-1.8.0-openjdk-portable
java-1.8.0-openjdk-portable-1.8.0.462.b08-1.0.1.1.al8
java-1.8.0-openjdk-portable-1.8.0.472.b08-1.0.1.1.al8
Resolves JDK-8202369.
Updated from the yum repository
ksh
ksh-20120801-267.0.1.al8
ksh-20120801-269.0.1.al8
Fixes an issue with pasting long multi-byte characters via SSH.
libdrm
libdrm-2.4.121-1.0.1.al8
libdrm-2.4.123-2.0.1.al8
Fixes an issue where the libpciaccess PCI access library is unavailable on RHEL 9 for aarch64, ppc64le, and s390x.
Updated from the yum repository
motif
motif-2.3.4-21.al8
motif-2.3.4-24.al8
Fixes a memory leak related to UTF-8 strings.
Updated from the yum repository
mysql-selinux
mysql-selinux-1.0.13-1.al8
mysql-selinux-1.0.14-1.al8
Resolves rhbz#2380217 by upgrading to version 1.0.14 and updating related hash and release information.
Updated from the yum repository
net-snmp
net-snmp-5.8-30.0.1.al8
net-snmp-5.8-31.0.1.al8
Fixes a "use after free" issue in a callback function.
Updated from the yum repository
intel-ipp-crypto-mb
intel-ipp-crypto-mb-1.0.6-4.al8
intel-ipp-crypto-mb-1.0.6-5.al8
Resolves an issue with the installation dependency on OpenSSL 3.0.
Updated from the yum repository
qatengine
qatengine-1.2.0-3.al8
qatengine-1.2.0-4.al8
Resolves an issue with the installation dependency on OpenSSL 3.0.
Updated from the yum repository
-
This release addresses CVEs in 24 components: 4 are updated in the image and 20 are available via the yum repository.
Component
Previous version
New version
CVE ID
Update method
bind
bind-9.11.36-16.0.1.al8.4
bind-9.11.36-16.0.1.al8.6
CVE-2025-40778
Updated in the image
expat
expat-2.2.5-17.al8
expat-2.5.0-1.al8
CVE-2025-59375
Updated in the image
libssh
libssh-0.9.6-12.al8
libssh-0.9.6-16.0.1.al8
CVE-2025-5318
Updated in the image
sssd
sssd-2.9.4-5.al8.2
sssd-2.9.4-5.al8.3
CVE-2025-11561
Updated in the image
galera
galera-26.4.20-1.al8
galera-26.4.22-1.al8
CVE-2023-52969
CVE-2023-52970
CVE-2025-21490
CVE-2025-30693
CVE-2025-30722
Updated via yum repository
haproxy
haproxy-2.4.22-3.0.1.al8.1
haproxy-2.8.14-1.0.1.al8.1
CVE-2025-11230
Updated via yum repository
java-1.8.0-openjdk
java-1.8.0-openjdk-1.8.0.462.b08-2.0.1.1.al8
java-1.8.0-openjdk-1.8.0.472.b08-1.0.1.1.al8
CVE-2025-53057
CVE-2025-53066
Updated via yum repository
java-17-openjdk
java-17-openjdk-17.0.16.0.8-2.0.1.1.al8
java-17-openjdk-17.0.17.0.10-1.0.2.1.al8
CVE-2025-53057
CVE-2025-53066
Updated via yum repository
lasso
lasso-2.6.0-13.0.1.al8
lasso-2.6.0-14.0.1.al8
CVE-2025-47151
Updated via yum repository
libsoup
libsoup-2.62.3-9.0.1.al8
libsoup-2.62.3-10.0.1.al8
CVE-2025-11021
CVE-2025-4945
Updated via yum repository
libtiff
libtiff-4.4.0-12.0.3.al8
libtiff-4.4.0-15.0.1.al8
CVE-2025-8176
CVE-2025-9900
Updated via yum repository
mariadb
mariadb-10.5.27-1.0.1.al8
mariadb-10.5.29-2.0.1.al8
CVE-2023-52969
CVE-2023-52970
CVE-2025-21490
CVE-2025-30693
CVE-2025-30722
Updated via yum repository
mingw-expat
mingw-expat-2.4.8-2.al8
mingw-expat-2.5.0-1.al8
CVE-2025-59375
Updated via yum repository
mingw-libtiff
mingw-libtiff-4.0.9-2.1.al8
mingw-libtiff-4.0.9-3.al8
CVE-2025-8176
CVE-2025-9900
Updated via yum repository
osbuild-composer
osbuild-composer-132.2-2.0.1.al8
osbuild-composer-132.2-3.0.1.al8
CVE-2025-27144
Updated via yum repository
pcs
pcs-0.10.18-2.0.1.1.al8.6
pcs-0.10.18-2.0.1.1.al8.7
CVE-2025-59830
CVE-2025-61770
CVE-2025-61771
CVE-2025-61772
CVE-2025-61919
Updated via yum repository
python-kdcproxy
python-kdcproxy-0.4-5.3.al8.1
python-kdcproxy-0.4-5.3.al8.2
CVE-2025-59088
CVE-2025-59089
Updated via yum repository
redis
redis-6.2.19-1.0.1.1.al8
redis-6.2.20-1.0.1.1.al8
CVE-2025-46817
CVE-2025-46818
CVE-2025-46819
CVE-2025-49844
Updated via yum repository
runc
runc-1.1.12-6.0.1.al8
runc-1.2.5-2.al8
CVE-2025-31133
CVE-2025-52565
CVE-2025-52881
Updated via yum repository
squid
squid-4.15-13.al8.5
squid-4.15-13.al8.6
CVE-2025-62168
Updated via yum repository
tigervnc
tigervnc-1.15.0-7.al8
tigervnc-1.15.0-8.al8
CVE-2025-62229
CVE-2025-62230
CVE-2025-62231
Updated via yum repository
xorg-x11-server
xorg-x11-server-1.20.11-26.0.1.al8
xorg-x11-server-1.20.11-27.0.1.al8
CVE-2025-62229
CVE-2025-62230
CVE-2025-62231
Updated via yum repository
xorg-x11-server-Xwayland
xorg-x11-server-Xwayland-23.2.7-4.al8
xorg-x11-server-Xwayland-23.2.7-5.al8
CVE-2025-62229
CVE-2025-62230
CVE-2025-62231
Updated via yum repository
zziplib
zziplib-0.13.71-11.0.1.al8
zziplib-0.13.71-12.0.1.al8
CVE-2018-17828
Updated via yum repository
Known issues
See the known issues for Alibaba Cloud Linux 3.2104 U12.1.
Alibaba Cloud Linux 3.2104 U12.1
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U12.1 |
aliyun_3_x64_20G_alibase_20251030.vhd |
2025-11-30 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20251030.vhd |
2025-11-30 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20251030.vhd |
2025-11-30 |
|
|
|
aliyun_3_arm64_20G_alibase_20251030.vhd |
2025-11-30 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20251030.vhd |
2025-11-30 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20251030.vhd |
2025-11-30 |
|
Updates
Important updates
This release updates the kernel to kernel-5.10.134-19.2.al8 and fixes the following issues:
-
Fixed an issue where the Zenbleed vulnerability patch was incorrectly applied to non-Zen2 architectures during a microcode hot-upgrade.
-
Added the
swiotlb_any cmdlineparameter to allow the system to allocate high-memory addresses as a bounce buffer for Confidential Computing scenarios. -
Fixed an issue where memory was not correctly accepted during the EFI stub phase when booting a TDX VM.
-
Fixed a race condition following a PCIe secondary bus reset that allowed a downstream device to be used before its initialization was complete, potentially causing errors or taking the device offline.
-
Fixed issues in the DWC_PMU driver to prevent kernel startup failures on Yitian instance models when hardware link anomalies occur.
-
Fixed a potential crash in the Group Balancer.
-
Fixed unexpected packet loss when using virtio_net with vhost under specific conditions.
For detailed release information, see https://openanolis.cn/sig/Cloud-Kernel/doc/1388258453605187661
Package updates
New features
-
Secure CAI components are updated to support remote device attestation and Hygon CSV. These updates are available from the yum repository.
-
trusteeis updated totrustee-1.7.0-1.al8. -
trustifluxis updated totrustiflux-1.4.4-1.al8. -
cryptpilotis updated tocryptpilot-0.2.7-1.al8. -
trusted-network-gatewayis updated totrusted-network-gateway-2.2.6-1.al8. -
gocryptfsis now available asgocryptfs-2.4.0-2.al8. -
tee-primitivesis updated totee-primitives-1.0-2.al8.
-
-
System O&M enhancements:
-
sysakis updated tosysak-3.8.0-1, enhancing System O&M capabilities.
-
-
Base OS capability enhancements:
-
alinux-base-setupis updated toalinux-release-3.2104.12-2.al8. For security, therpcbindservice is disabled by default. -
alinux-releaseis updated toalinux-release-3.2104.12-2.al8, marking the release of Alinux 3.12.1. -
NetworkManageris updated toNetworkManager-1.40.16-19.0.1.1.al8to enableipvlan. -
systemdis updated tosystemd-239-82.0.4.3.al8.5to support the newNetworkNamespacePathfeature in Systemd. -
logrotateis updated tologrotate-3.14.0-6.0.1.1.al8to optimize memory usage by compressing system logs. -
tpm2-tssis updated totpm2-tss-2.4.6-1.0.2.al8to add runtime dependencies for confidential computing. -
tpm2-toolsis updated totpm2-tools-4.1.1-5.0.6.al8to add runtime dependencies for confidential computing. -
tengineis updated totengine-3.1.0-3.al8. This version integrates thenginx-module-vtsplugin and enhances performance on the Yitian Processor. -
gcc-toolset-12-gccis updated togcc-toolset-12-gcc-12.3.0-1.2.al8, adding newer GCC capabilities. -
rasdaemonis updated torasdaemon-0.6.7-16.5.al8providing an RAS diagnostic and self-healing solution. -
trackeris updated totracker-3.1.2-3.0.1.1.al8. This update modifies compilation options to disable the SQLite version check. -
ostreeis updated toostree-2022.2-11.al8to deliver security updates for ContainerOS.
-
-
System tuning enhancements:
-
keentunedandkeentune-targetare released as version 3.2.0.
-
-
Kernel-related component updates:
-
smc-toolsis updated tosmc-tools-1.8.3-1.0.4.al8. This update adds monitoring and packet capture capabilities. -
vtoais updated tovtoa-2.1.1-1.al8to provide forward and backward compatibility. -
erofs-utilsis updated toerofs-utils-1.8.10-1.al8. This update includes bug fixes.
-
-
Cloud application component updates:
-
aliyun-cliis updated toaliyun-cli-3.0.305-1.al8. -
ossfsis updated toossfs-1.91.8-1.al8, fixing issues with basic functionality.
-
-
OS Copilot updates:
-
os-copilotis updated toos-copilot-0.9.1-1.al8.
-
-
This release includes updates for 11 components synchronized from Anolis OS 8. Of these, three are updated in the image and eight are available from the yum repository.
|
Component |
Previous version |
Updated version |
Description |
Update method |
|
libsemanage |
libsemanage-2.9-10.0.1.al8 |
libsemanage-2.9-12.0.1.al8 |
Enhances storage and rebuild performance in semanage by reducing function calls during the reuse phase. This update is forward-compatible. |
Included in the image |
|
tzdata |
tzdata-2024b-1.0.1.2.al8 |
tzdata-2025b-1.0.1.1.al8 |
Updates time zone data. |
Included in the image |
|
linux-firmware |
linux-firmware-20241014-125.git06bad2f1.al8 |
linux-firmware-20250325-129.git710a336b.al8 |
Adds support for additional hardware types. |
Included in the image |
|
gnome-control-center |
gnome-control-center-40.0-31.1.al8 |
gnome-control-center-40.0-32.1.al8 |
Adds an API to query device group information. |
Updated via the yum repository |
|
java-1.8.0-openjdk-portable |
java-1.8.0-openjdk-portable-1.8.0.432.b06-1.0.2.1.al8 |
java-1.8.0-openjdk-portable-1.8.0.462.b08-1.0.1.1.al8 |
Now a build and installation dependency for newer Java components. |
Updated via the yum repository |
|
java-17-openjdk-portable |
java-17-openjdk-portable-17.0.13.0.11-1.0.2.1.al8 |
java-17-openjdk-portable-17.0.16.0.8-1.0.1.1.al8 |
Now a build and installation dependency for newer Java components. |
Updated via the yum repository |
|
motif |
motif-2.3.4-20.al8 |
motif-2.3.4-21.al8 |
Adds multi-screen support. |
Updated via the yum repository |
|
mysql-selinux |
mysql-selinux-1.0.10-1.al8 |
mysql-selinux-1.0.13-1.al8 |
Includes new features and bug fixes. |
Updated via the yum repository |
|
scap-security-guide |
scap-security-guide-0.1.75-1.0.1.al8 |
scap-security-guide-0.1.77-1.0.1.al8 |
Adds rules for the user namespace. |
Updated via the yum repository |
|
sos |
sos-4.8.1-1.0.1.1.al8 |
sos-4.8.2-1.0.1.1.al8 |
Adds support for the walrus operator (:=) in Python 3.8 environments. |
Updated via the yum repository |
|
tzdata |
tzdata-2024b-1.0.1.2.al8 |
tzdata-2025b-1.0.1.1.al8 |
Updates time zone data. |
Included in the image |
|
xorg-x11-drv-libinput |
xorg-x11-drv-libinput-1.0.1-3.al8 |
xorg-x11-drv-libinput-1.0.1-4.al8 |
Adds a mapping for specific high keycodes to the FK20–FK23 range. |
Updated via the yum repository |
-
This release updates 27 components with bug fixes from Anolis OS 8: 12 in the image and 15 through the yum repository.
|
Component |
Previous version |
New version |
Description |
Update method |
|
device-mapper-multipath |
device-mapper-multipath-0.8.4-41.0.1.al8 |
device-mapper-multipath-0.8.4-42.0.1.al8 |
Fixed a memory leak in the external NVMe handler. |
Updated in the image |
|
dnf |
dnf-4.7.0-20.0.1.1.al8 |
dnf-4.7.0-21.0.1.1.al8 |
Fixed functional and runtime issues in |
Updated in the image |
|
firewalld |
firewalld-0.9.11-9.0.1.al8 |
firewalld-0.9.11-10.0.1.al8 |
Updated the Ceph port number in the service definition to prevent a port conflict. |
Updated in the image |
|
libdnf |
libdnf-0.63.0-20.0.1.2.al8 |
libdnf-0.63.0-21.0.1.1.al8 |
Fixed an invalid memory access issue. |
Updated in the image |
|
libselinux |
libselinux-2.9-9.1.al8 |
libselinux-2.9-10.1.al8 |
Fixed a null pointer dereference issue. |
Updated in the image |
|
lvm2 |
lvm2-2.03.14-14.0.1.al8 |
lvm2-2.03.14-15.0.1.al8 |
Fixed a thread-blocking issue in the |
Updated in the image |
|
nfs-utils |
nfs-utils-2.3.3-59.0.4.al8 |
nfs-utils-2.3.3-64.0.1.al8 |
Applied patches to fix and improve GSSD authentication, |
Updated in the image |
|
nftables |
nftables-1.0.4-4.al8 |
nftables-1.0.4-7.al8 |
Optimized compatibility expression handling for |
Updated in the image |
|
openldap |
openldap-2.4.46-20.al8 |
openldap-2.4.46-21.al8 |
Fixed a file descriptor leak on failed LDAP over SSL connections and resolved an error that caused a file to be closed multiple times after a TLS connection failure. |
Updated in the image |
|
sssd |
sssd-2.9.4-5.al8.1 |
sssd-2.9.4-5.al8.2 |
Fixed a memory leak in |
Updated in the image |
|
tar |
tar-1.30-9.0.2.al8 |
tar-1.30-11.0.1.al8 |
Fixed a regression in the |
Updated in the image |
|
tuned |
tuned-2.22.1-5.0.1.1.al8 |
tuned-2.22.1-6.0.1.1.al8 |
This update enables lazy loading for the |
Updated in the image |
|
389-ds-base |
389-ds-base-1.4.3.39-9.0.1.al8 |
389-ds-base-1.4.3.39-15.0.1.al8 |
Fixed functional issues in the |
Updated in the yum repository |
|
autofs |
autofs-5.1.4-114.0.1.al8.1 |
autofs-5.1.4-114.0.1.al8.2 |
Fixed a deadlock issue. |
Updated in the yum repository |
|
cups-filters |
cups-filters-1.20.0-35.0.1.al8 |
cups-filters-1.20.0-36.0.1.al8 |
Fixed an issue where images were incorrectly rotated 90 degrees during printing. |
Updated in the yum repository |
|
curl |
curl-7.61.1-35.0.2.al8 |
curl-7.61.1-35.0.2.al8.3 |
Applied a follow-up fix for |
Updated in the yum repository |
|
haproxy |
haproxy-2.4.22-3.0.1.al8 |
haproxy-2.4.22-3.0.1.al8.1 |
Cleared the retry flag in read and write functions to prevent CPU usage spikes. Fixed an error that prevented certificates from loading from a file. |
Updated in the yum repository |
|
jasper |
jasper-2.0.14-5.0.1.al8 |
jasper-2.0.14-6.0.1.al8 |
Updated settings in the |
Updated in the yum repository |
|
libisoburn |
libisoburn-1.5.4-4.al8 |
libisoburn-1.5.4-5.al8 |
Modified the post-installation script to fix an upgrade error. |
Updated in the yum repository |
|
mod_security_crs |
mod_security_crs-3.3.4-3.al8 |
mod_security_crs-3.3.4-3.al8.2 |
Fixed rules that incorrectly blocked certain city and street names in forms. |
Updated in the yum repository |
|
mutter |
mutter-40.9-22.0.1.al8 |
mutter-40.9-23.0.1.al8 |
Fixed an issue caused by rapidly switching windows. |
Updated in the yum repository |
|
portreserve |
portreserve-0.0.5-19.2.al8 |
portreserve-0.0.5-20.0.1.al8 |
Updated the |
Updated in the yum repository |
|
samba |
samba-4.19.4-6.1.al8 |
samba-4.19.4-9.1.al8 |
Fixed an issue with domain controller discovery after Windows |
Updated in the yum repository |
|
squid |
squid-4.15-13.al8.3 |
squid-4.15-13.al8.5 |
Fixed an issue that caused |
Updated in the yum repository |
|
strace |
strace-5.18-2.0.4.al8 |
strace-5.18-2.1.0.1.al8 |
Added support for the Fixed incorrect system call name reporting in Updated |
Updated in the yum repository |
|
traceroute |
traceroute-2.1.0-6.2.0.3.al8 |
traceroute-2.1.0-9.0.1.al8 |
Fixed the polling logic in |
Updated in the yum repository |
|
unzip |
unzip-6.0-47.0.1.al8 |
unzip-6.0-48.0.1.al8 |
Fixed an extraction error affecting certain ZIP files. |
Updated in the yum repository |
-
This update addresses 116 CVEs:
|
Component |
Previous version |
Updated version |
CVEs |
|
aide |
0.16-102.al8 |
0.16-103.al8.2 |
CVE-2025-54389 |
|
bind |
9.11.36-16.0.1.al8 |
9.11.36-16.0.1.al8.4 |
CVE-2024-11187 |
|
bind-dyndb-ldap |
11.6-5.al8 |
11.6-6.al8 |
CVE-2025-4404 |
|
bluez |
5.63-3.0.1.al8 |
5.63-5.0.1.al8 |
CVE-2023-27349 CVE-2023-51589 |
|
buildah |
1.33.11-1.al8 |
1.33.12-2.al8 |
CVE-2025-22871 CVE-2025-6032 |
|
bzip2 |
1.0.6-27.al8 |
1.0.6-28.al8 |
CVE-2019-12900 |
|
compat-libtiff3 |
3.9.4-13.2.al8 |
3.9.4-14.0.1.al8 |
CVE-2025-9900 |
|
compat-openssl10 |
1.0.2o-4.0.1.al8 |
1.0.2o-4.0.1.al8.1 |
CVE-2023-0286 |
|
containernetworking-plugins |
1.4.0-5.0.1.al8 |
1.4.0-6.0.1.al8 |
CVE-2025-22871 CVE-2025-6032 |
|
corosync |
3.1.8-2.al8 |
3.1.9-2.al8 |
CVE-2025-30472 |
|
cups |
2.2.6-62.0.1.al8 |
2.2.6-63.0.1.al8 |
CVE-2025-58060 |
|
delve |
1.22.1-1.0.2.al8 |
1.24.1-1.0.2.al8 |
CVE-2025-22871 CVE-2025-4673 |
|
doxygen |
1.8.14-12.1.al8 |
1.8.14-13.al8 |
CVE-2020-11023 |
|
emacs |
27.2-10.0.1.al8 |
27.2-14.0.1.al8.2 |
CVE-2024-53920 |
|
expat |
2.2.5-16.al8 |
2.2.5-17.al8 |
CVE-2024-8176 |
|
fence-agents |
4.10.0-76.0.1.al8.1 |
4.10.0-86.0.1.al8.7 |
CVE-2025-47273 |
|
freetype |
2.10.4-9.al8 |
2.10.4-10.al8 |
CVE-2025-27363 |
|
galera |
26.4.14-1.al8 |
26.4.20-1.al8 |
CVE-2023-22084 CVE-2024-21096 |
|
gcc-toolset-13-gcc |
13.3.1-2.1.0.1.1.al8 |
13.3.1-2.2.0.1.1.al8 |
CVE-2020-11023 |
|
gdk-pixbuf2 |
2.42.6-4.0.1.al8 |
2.42.6-6.0.1.al8 |
CVE-2025-7345 |
|
ghostscript |
9.54.0-18.al8 |
9.54.0-19.al8 |
CVE-2025-27832 |
|
gimp |
2.8.22-25.al8 |
2.8.22-26.al8.2 |
CVE-2025-48797 CVE-2025-48798 CVE-2025-5473 |
|
git |
2.43.5-2.0.1.al8 |
2.43.7-1.0.1.al8 |
CVE-2024-50349 CVE-2024-52006 CVE-2025-27613 CVE-2025-27614 CVE-2025-46835 CVE-2025-48384 CVE-2025-48385 |
|
git-lfs |
3.4.1-3.0.1.al8 |
3.4.1-5.0.1.al8 |
CVE-2025-22871 |
|
glib2 |
2.68.4-14.0.2.al8 |
2.68.4-16.0.1.al8.2 |
CVE-2024-52533 CVE-2025-4373 |
|
glibc |
2.32-1.16.al8 |
2.32-1.21.al8 |
CVE-2025-0395 CVE-2025-4802 CVE-2025-8058 |
|
gnome-remote-desktop |
0.1.8-3.1.al8 |
0.1.8-4.0.1.al8 |
CVE-2025-5024 |
|
gnutls |
3.6.16-8.0.2.al8.3 |
3.6.16-8.0.2.al8.4 |
CVE-2025-32988 CVE-2025-32990 CVE-2025-6395 |
|
go-toolset |
1.22.9-1.al8 |
1.24.6-1.al8 |
CVE-2025-4674 |
|
golang |
1.22.9-1.0.1.al8 |
1.24.6-1.0.1.al8 |
CVE-2025-4674 |
|
grafana |
9.2.10-20.0.1.al8 |
9.2.10-25.0.1.al8 |
CVE-2025-22871 |
|
grafana-pcp |
5.1.1-9.0.1.al8 |
5.1.1-10.al8 |
CVE-2025-22871 |
|
gstreamer1 |
1.22.1-2.0.1.al8 |
1.22.12-3.0.1.al8 |
CVE-2024-0444 CVE-2024-4453 |
|
gstreamer1-plugins-bad-free |
1.22.1-4.0.1.al8 |
1.22.1-4.0.1.al8 |
#N/A |
|
gstreamer1-plugins-base |
1.22.1-3.0.1.al8 |
1.22.12-4.0.1.al8 |
CVE-2024-47541 CVE-2024-47542 CVE-2024-47600 CVE-2024-47835 |
|
httpd |
2.4.37-65.0.1.al8.2 |
2.4.37-655.0.1.al8.5 |
CVE-2024-47252 CVE-2025-23048 CVE-2025-49630 CVE-2025-49812 |
|
ipa |
4.9.13-14.0.1.1.al8 |
4.9.13-20.0.1.1.al8 |
CVE-2025-7493 |
|
ipa-healthcheck |
0.12-4.al8 |
0.12-6.al8 |
CVE-2025-7493 |
|
jackson-annotations |
2.14.2-1.al8 |
2.19.1-1.al8 |
CVE-2025-52999 |
|
jackson-core |
2.14.2-1.al8 |
2.19.1-1.al8 |
CVE-2025-52999 |
|
jackson-databind |
2.14.2-1.al8 |
2.19.1-1.al8 |
CVE-2025-52999 |
|
jackson-jaxrs-providers |
2.14.2-1.al8 |
2.19.1-1.al8 |
CVE-2025-52999 |
|
java-1.8.0-openjdk |
1.8.0.432.b06-2.0.2.1.al8 |
1.8.0.462.b08-2.0.1.1.al8 |
CVE-2025-30749 CVE-2025-30754 CVE-2025-30761 CVE-2025-50106 |
|
java-17-openjdk |
17.0.13.0.11-3.0.2.1.al8 |
17.0.16.0.8-2.0.1.1.al8 |
CVE-2025-30749 CVE-2025-30754 CVE-2025-50059 CVE-2025-50106 |
|
jq |
1.6-17.al8 |
1.6-17.al8.2 |
CVE-2024-23337 CVE-2025-48060 |
|
keepalived |
2.2.8-3.al8 |
2.2.8-4.al8 |
CVE-2024-41184 |
|
krb5 |
1.18.2-30.0.1.al8 |
1.18.2-32.0.1.al8 |
CVE-2025-3576 |
|
libarchive |
3.5.3-4.al8 |
3.5.3-6.al8 |
CVE-2025-5914 |
|
libblockdev |
2.28-6.al8 |
2.28-7.al8 |
CVE-2025-6019 |
|
libcap |
2.48-6.0.1.al8 |
2.48-6.0.2.al8 |
CVE-2025-1390 |
|
libpq |
13.11-1.0.1.al8 |
13.20-1.0.1.al8 |
CVE-2025-1094 |
|
libreoffice |
7.1.8.1-12.0.2.1.al8.1 |
7.1.8.1-15.0.1.1.al8.1 |
CVE-2025-1080 |
|
libsoup |
2.62.3-6.0.1.al8 |
2.62.3-9.0.1.al8 |
CVE-2025-2784 CVE-2025-4948 CVE-2025-32049 CVE-2025-32914 |
|
libtasn1 |
4.13-4.0.1.al8 |
4.13-5.0.1.al8 |
CVE-2024-12133 |
|
libtpms |
0.9.1-2.20211126git1ff6fe1f43.al8 |
0.9.1-3.20211126git1ff6fe1f43.al8 |
CVE-2025-49133 |
|
libvirt |
8.0.0-23.3.0.2.al8 |
8.0.0-23.4.0.1.al8 |
CVE-2025-49133 |
|
libvpx |
1.7.0-11.0.1.al8 |
1.7.0-12.0.1.al8 |
CVE-2025-5283 |
|
libxml2 |
2.9.7-18.0.3.1.al8 |
2.9.7-21.0.1.1.al8.3 |
CVE-2025-32415 |
|
libxslt |
1.1.32-6.1.al8 |
1.1.32-6.2.0.1.al8 |
CVE-2023-40403 |
|
mariadb |
10.5.22-1.0.1.al8 |
10.5.27-1.0.1.al8 |
CVE-2023-22084 CVE-2024-21096 |
|
mecab-ipadic |
2.7.0.20070801-16.2.al8 |
2.7.0.20070801-17.0.1.al8 |
CVE-2024-11053 CVE-2024-21193 CVE-2024-21194 CVE-2024-21196 CVE-2024-21197 CVE-2024-21198 CVE-2024-21199 CVE-2024-21201 CVE-2024-21203 CVE-2024-21212 CVE-2024-21213 CVE-2024-21218 CVE-2024-21219 CVE-2024-21230 CVE-2024-21231 CVE-2024-21236 CVE-2024-21237 CVE-2024-21238 CVE-2024-21239 CVE-2024-21241 CVE-2024-21247 CVE-2024-37371 CVE-2024-5535 CVE-2024-7264 CVE-2025-21490 CVE-2025-21491 CVE-2025-21494 CVE-2025-21497 CVE-2025-21500 CVE-2025-21501 CVE-2025-21503 CVE-2025-21504 CVE-2025-21505 CVE-2025-21518 CVE-2025-21519 CVE-2025-21520 CVE-2025-21521 CVE-2025-21522 CVE-2025-21523 CVE-2025-21525 CVE-2025-21529 CVE-2025-21531 CVE-2025-21534 CVE-2025-21536 CVE-2025-21540 CVE-2025-21543 CVE-2025-21546 CVE-2025-21555 CVE-2025-21559 |
|
microcode_ctl |
20240910-1.0.1.al8 |
20250512-1.0.1.al8 |
CVE-2024-28956 CVE-2024-43420 CVE-2024-45332 CVE-2025-20012 CVE-2025-20623 CVE-2025-24495 |
|
mingw-freetype |
2.8-3.1.al8 |
2.8-3.1.al8.1 |
CVE-2025-27363 CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909 CVE-2025-32910 CVE-2025-32911 CVE-2025-32913 |
|
mingw-sqlite |
3.26.0.0-1.1.al8 |
3.26.0.0-2.al8 |
CVE-2025-6965 |
|
mod_auth_openidc |
2.4.9.4-6.al8 |
2.4.9.4-8.al8 |
CVE-2025-3891 |
|
mod_http2 |
1.15.7-10.al8.1 |
1.15.7-10.al8.4 |
CVE-2024-47252 CVE-2025-23048 CVE-2025-49630 CVE-2025-49812 |
|
mod_security |
2.9.6-1.al8 |
2.9.6-2.al8 |
CVE-2025-47947 |
|
mysql |
8.0.36-1.0.1.1.al8 |
8.0.43-1.0.1.1.al8 |
CVE-2025-21574 CVE-2025-21575 CVE-2025-21577 CVE-2025-21579 CVE-2025-21580 CVE-2025-21581 CVE-2025-21584 CVE-2025-21585 CVE-2025-30681 CVE-2025-30682 CVE-2025-30683 CVE-2025-30684 CVE-2025-30685 CVE-2025-30687 CVE-2025-30688 CVE-2025-30689 CVE-2025-30693 CVE-2025-30695 CVE-2025-30696 CVE-2025-30699 CVE-2025-30703 CVE-2025-30704 CVE-2025-30705 CVE-2025-30715 CVE-2025-30721 CVE-2025-30722 CVE-2025-50077 CVE-2025-50078 CVE-2025-50079 CVE-2025-50080 CVE-2025-50081 CVE-2025-50082 CVE-2025-50083 CVE-2025-50084 CVE-2025-50085 CVE-2025-50086 CVE-2025-50087 CVE-2025-50088 CVE-2025-50091 CVE-2025-50092 CVE-2025-50093 CVE-2025-50094 CVE-2025-50096 CVE-2025-50097 CVE-2025-50098 CVE-2025-50099 CVE-2025-50100 CVE-2025-50101 CVE-2025-50102 CVE-2025-50104 CVE-2025-53023 |
|
nodejs |
20.16.0-1.1.al8 |
20.19.2-1.1.al8 |
CVE-2025-23165 CVE-2025-23166 CVE-2025-23167 |
|
nodejs-nodemon |
2.0.20-3.al8 |
3.0.1-1.al8 |
CVE-2025-22150 CVE-2025-23083 CVE-2025-23085 |
|
nodejs-packaging |
23-3.1.al8 |
2021.06-4.al8 |
CVE-2025-22150 CVE-2025-23083 CVE-2025-23085 |
|
open-vm-tools |
12.3.5-2.al8 |
12.3.5-2.al8.1 |
CVE-2025-41244 |
|
opendnssec |
2.1.7-1.1.al8 |
2.1.7-2.al8 |
CVE-2025-4404 |
|
openssh |
8.0p1-25.0.1.1.al8 |
8.0p1-26.0.1.1.al8 |
CVE-2025-26465 |
|
osbuild |
126-1.0.1.al8 |
141.2-1.0.1.al8 |
CVE-2024-34158 CVE-2024-9355 CVE-2024-1394 |
|
osbuild-composer |
118-2.0.1.al8 |
132.2-2.0.1.al8 |
CVE-2025-22871 |
|
pam |
1.3.1-36.al8 |
1.3.1-38.al8 |
CVE-2025-6020 |
|
pcs |
0.10.18-2.0.1.1.al8.3 |
0.10.18-2.0.1.1.al8.6 |
CVE-2024-49761 |
|
perl |
5.26.3-422.0.1.al8 |
5.26.3-423.0.1.al8 |
CVE-2025-40909 |
|
perl-CPAN |
2.18-397.1.0.2.al8 |
2.18-402.0.1.al8 |
CVE-2020-16156 |
|
perl-FCGI |
0.78-11.2.al8 |
0.78-12.al8 |
CVE-2025-40907 |
|
perl-File-Find-Rule |
0.34-8.1.al8 |
0.34-9.al8 |
CVE-2011-10007 |
|
perl-JSON-XS |
3.04-3.2.al8 |
3.04-4.al8 |
CVE-2025-40928 |
|
perl-YAML-LibYAML |
0.70-1.1.al8 |
0.70-2.al8 |
CVE-2025-40908 |
|
podman |
4.9.4-18.0.1.al8 |
4.9.4-23.0.1.al8 |
CVE-2025-9566 |
|
postgresql |
13.18-1.0.1.al8 |
13.22-1.0.1.al8 |
CVE-2025-8714 CVE-2025-8715 |
|
python-cryptography |
3.2.1-7.al8 |
3.2.1-8.al8 |
CVE-2023-49083 |
|
python-jinja2 |
2.10.1-3.0.3.al8 |
2.10.1-7.0.1.al8 |
CVE-2025-27516 |
|
python-requests |
2.20.0-5.al8 |
2.20.0-6.al8 |
CVE-2024-47081 |
|
python-setuptools |
39.2.0-8.al8.1 |
39.2.0-9.al8 |
CVE-2025-47273 |
|
python3 |
3.6.8-69.0.1.1.al8 |
3.6.8-71.0.1.1.al8 |
CVE-2025-8194 |
|
python3.11 |
3.11.11-1.0.1.al8 |
3.11.13-2.0.1.al8 |
CVE-2025-8194 |
|
python3.11-setuptools |
65.5.1-3.al8 |
65.5.1-4.al8 |
CVE-2025-47273 |
|
qemu-kvm |
6.2.0-53.0.1.al8.2 |
6.2.0-53.0.8.al8.4 |
CVE-2025-49133 |
|
redis |
6.2.7-1.0.3.al8 |
6.2.19-1.0.1.1.al8 |
CVE-2025-32023 CVE-2025-48367 |
|
resource-agents |
4.9.0-54.al8.6 |
4.9.0-54.al8.16 |
CVE-2024-47081 |
|
rsync |
3.1.3-20.0.1.al8 |
3.1.3-23.0.1.al8 |
CVE-2016-9840 |
|
runc |
1.1.12-5.0.1.al8 |
1.1.12-6.0.1.al8 |
CVE-2025-22869 |
|
skopeo |
1.14.5-3.0.1.al8 |
1.14.5-4.0.1.al8 |
CVE-2025-22871 CVE-2025-6032 |
|
socat |
1.7.4.1-1.0.1.al8 |
1.7.4.1-2.0.1.al8 |
CVE-2024-54661 |
|
spice-client-win |
8.8-1.al8 |
8.10-1.al8 |
CVE-2025-27363 CVE-2025-32050 CVE-2025-32052 CVE-2025-32053 CVE-2025-32906 CVE-2025-32907 CVE-2025-32909 CVE-2025-32910 CVE-2025-32911 CVE-2025-32913 |
|
sqlite |
3.26.0-19.al8 |
3.26.0-20.al8 |
CVE-2025-6965 |
|
sudo |
1.9.5p2-1.0.2.al8 |
1.9.5p2-1.0.2.al8.1 |
CVE-2025-32462 |
|
tbb |
2018.2-9.2.al8 |
2018.2-10.al8.1 |
CVE-2020-11023 |
|
tigervnc |
1.13.1-14.al8 |
1.15.0-7.al8 |
CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 |
|
tomcat |
9.0.87-1.al8.2 |
9.0.87-1.al8.6 |
CVE-2025-48976 CVE-2025-48988 CVE-2025-48989 CVE-2025-49125 CVE-2025-52434 CVE-2025-52520 CVE-2025-53506 |
|
udisks2 |
2.9.0-16.0.1.1.al8 |
2.9.0-16.0.4.al8.1 |
CVE-2025-8067 |
|
unbound |
1.16.2-7.al8 |
1.16.2-9.al8 |
CVE-2025-5994 |
|
varnish |
6.0.13-1.0.1.1.al8 |
6.0.13-1.1.al8.1 |
CVE-2025-47905 |
|
vim |
8.0.1763-19.0.2.al8.5 |
8.0.1763-21.0.1.al8 |
CVE-2025-53905 CVE-2025-53906 |
|
webkit2gtk3 |
2.46.5-1.0.1.al8 |
2.46.6-2.0.1.al8 |
CVE-2025-24201 |
|
xdg-utils |
1.1.3-11.al8 |
1.1.3-13.al8 |
CVE-2022-4055 |
|
xmlrpc-c |
1.51.0-10.0.1.al8 |
1.51.0-11.0.1.al8 |
CVE-2024-8176 |
|
xorg-x11-server |
1.20.11-25.0.1.al8 |
1.20.11-26.0.1.al8 |
CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 |
|
xorg-x11-server-Xwayland |
23.2.7-1.al8 |
23.2.7-4.al8 |
CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180 |
|
yelp |
40.3-2.al8 |
40.3-2.al8.1 |
CVE-2025-3155 |
|
yelp-xsl |
40.2-1.0.1.al8 |
40.2-1.0.1.al8.1 |
CVE-2025-3155 |
Bug fixes
-
qemu-kvm version 6.2.0-53.0.8.al8.4 fixes an issue where SPICE was not supported on the arm64 architecture.
-
anaconda version 33.16.7.12-1.0.7.4.al8 changes
/etc/timezonefrom a symbolic link to a text file. -
cloud-init version 23.2.2-9.0.1.1.al8 fixes an issue where symbolic links remained after uninstallation.
-
kexec-tools version 2.0.26-14.0.1.7.al8.2 fixes an issue where Normal memory was not reserved for Node0 on c9i instances.
-
fuse version 2.9.7-19.1.al8 fixes an issue where OSS mount points were lost.
-
gcc-toolset-12 version 12.0-6.1.al8 fixes an issue where installing the
pcpsoftware incorrectly triggered a rebuild into thegcc-toolset-12directory, which impaired functionality. -
util-linux version 2.32.1-46.0.4.1.al8 fixes an "invalid parameter" error when setting the hardware clock.
Known issue
The NetworkManager-wait-online service fails to start on ebmhfr7.48xlarge16 ECS Bare Metal Instances. This occurs because the instance has a usb0 interface that is not managed by NetworkManager. To resolve this issue, you must manually create a configuration file and then reboot the system.
Solution
-
Create the
/etc/NetworkManager/conf.d/99-unmanaged-device.conffile with the following content:[device-usb0-unmanaged] match-device=interface-name:usb0 managed=0 -
After saving the file, reboot the system and verify that the
NetworkManager-wait-onlineservice starts correctly.
Alibaba Cloud Linux 3 AI Extension Edition 0.5.4
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3 AI Extension ARM Edition 0.5.4 |
aliyun_3_0_arm64_20G_alibase_aiext_0.5.4_20251031.vhd |
2025-11-30 |
|
Updates
Important updates
Upgraded the kernel to 5.10.134-19.2.al8.aarch64.
-
Kernel updates:
-
Fixed an issue where a microcode hot patch for the Zenbleed vulnerability was incorrectly applied to non-Zen2 architectures.
-
Added the swiotlb_any command-line parameter to enable the system to allocate high-memory addresses (>2 GB) as bounce buffers for Confidential Computing scenarios.
-
Fixed an issue where the EFI stub did not correctly accept memory when booting a TDX VM.
-
Fixed an issue where a downstream device could be used before its initialization was complete after a PCIe secondary bus reset, potentially causing errors or taking the device offline.
-
Fixed issues in the DWC_PMU driver to prevent kernel boot failures on Yitian-based instance types when hardware links are abnormal.
-
Fixed a potential crash in the Group Balancer.
-
Fixed unexpected packet loss in virtio_net when used with vhost under specific conditions.
-
-
Image updates:
-
Installed
python3.12-3.12.7-1.al8by default and configured it as the default Python 3 version. -
Added
keentuned-3.4.1-1.al8to provide Intelligent Tuning for AI workloads. -
Installed
kmod-fuse-5.10.134~19.2-1.2.5~1.al8by default to enhance support for the fuse over io_uring mode and increase performance to 1 million IOPS and a cache read/write bandwidth of 40 GB/s.
-
Alibaba Cloud Linux 3 AI Extension Edition 0.5.3
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3 AI Extension Edition 0.5.3 |
aliyun_3_0_x64_20G_alibase_aiext_0.5.3_20251011.vhd |
2025-10-11 |
|
Updates
Important updates
-
Kernel
-
The kernel is upgraded to version
5.10.134-19.103.al8.x86_64. -
New features
-
Adds support for five-level page tables to enable petabyte-scale memory management. For compatibility, user-mode applications must explicitly specify a high address as a hint during the
mmapphase to enable allocation in the five-level page table space. -
Introduces the PCIe Resizable BAR feature, which lets you adjust the BAR size of PCIe devices without modifying BIOS settings.
-
Enables the page table page reclaim feature by default via the reclaim_pt kernel command-line parameter. This feature reclaims page table pages in the
MADV_DONTNEEDpath to save memory and prevent premature out-of-memory (OOM) errors. -
Hybrid deployment enhancements: Optimizes the load balancing policy for hybrid deployment scenarios and refactors the absolute preemption policy to grant online tasks absolute priority, preventing offline tasks from preempting their resources.
-
-
Compatibility
-
Backports patches to support UPI on GNR.
-
The kernel kABI remains consistent with previous versions.
-
Command line changes: The 'pci_quirk' parameter is enabled by default (disable with 'pci_quirk=disable'), and the 'drv_quirk' parameter is disabled by default (enable with 'drv_quirk=enable').
-
-
Stability improvements
-
Fixes a checksum error in virtio-net for both large and small packets.
-
Fixes a use-after-free issue in the group balancer.
-
Fixes a null pointer dereference in the nvme driver during system reboot or shutdown.
-
Fixes a vhost thread exception.
-
-
-
Image
-
Adds the
update-grubenvservice. This service is enabled by default and runs automatically at system startup. It detects the current boot mode (UEFI or Legacy BIOS) and dynamically updates the/boot/grub2/grubenvconfiguration file to ensure that the GRUB environment variables match the actual boot mode. -
Upgraded keentuned to
keentuned-3.4.0-1.al8.x86_64. -
Upgraded kmod-fuse to
kmod-fuse-5.10.134~19.103-1.2.4.5~2.al8.x86_64. -
Removed
drv_quirk=disableanddrv_link_quirk=disablefrom the command line, and addedreclaim_pt.
-
Security updates
|
Package name |
CVE ID |
Updated version |
|
bind-export-libs |
CVE-2024-11187 |
9.11.36-16.0.1.al8.4 |
|
bzip2 |
CVE-2019-12900 |
1.0.6-28.al8 |
|
bzip2-libs |
1.0.6-28.al8 |
|
|
cups-client |
CVE-2025-58060 |
2.2.6-63.0.1.al8 |
|
cups-libs |
2.2.6-63.0.1.al8 |
|
|
expat |
CVE-2024-8176 |
2.2.5-17.al8 |
|
freetype |
CVE-2025-27363 |
2.10.4-10.al8 |
|
glib2 |
CVE-2024-52533 CVE-2025-4373 |
2.68.4-16.0.1.al8.2 |
|
glibc |
CVE-2025-0395 CVE-2025-4802 CVE-2025-8058 |
2.32-1.21.al8 |
|
glibc-all-langpacks |
2.32-1.21.al8 |
|
|
glibc-common |
2.32-1.21.al8 |
|
|
glibc-devel |
2.32-1.21.al8 |
|
|
glibc-headers-x86 |
2.32-1.21.al8 |
|
|
grub2-common |
CVE-2025-0624 |
2.02-165.0.1.al8 |
|
grub2-efi-x64 |
2.02-165.0.1.al8 |
|
|
grub2-pc |
2.02-165.0.1.al8 |
|
|
grub2-pc-modules |
2.02-165.0.1.al8 |
|
|
grub2-tools |
2.02-165.0.1.al8 |
|
|
grub2-tools-efi |
2.02-165.0.1.al8 |
|
|
grub2-tools-extra |
2.02-165.0.1.al8 |
|
|
grub2-tools-minimal |
2.02-165.0.1.al8 |
|
|
krb5-libs |
CVE-2025-3576 |
1.18.2-32.0.1.al8 |
|
libarchive |
CVE-2025-5914 |
3.5.3-6.al8 |
|
libblockdev |
CVE-2025-6019 |
2.28-7.al8 |
|
libblockdev-crypto |
2.28-7.al8 |
|
|
libblockdev-fs |
2.28-7.al8 |
|
|
libblockdev-loop |
2.28-7.al8 |
|
|
libblockdev-mdraid |
2.28-7.al8 |
|
|
libblockdev-part |
2.28-7.al8 |
|
|
libblockdev-swap |
2.28-7.al8 |
|
|
libblockdev-utils |
2.28-7.al8 |
|
|
libcap |
CVE-2025-1390 |
2.48-6.0.2.al8 |
|
libtasn1 |
CVE-2024-12133 |
4.13-5.0.1.al8 |
|
libudisks2 |
CVE-2025-8067 |
2.9.0-16.0.4.al8.1 |
|
libxml2 |
CVE-2025-32415 |
2.9.7-21.0.1.1.al8.3 |
|
nscd |
CVE-2025-0395 CVE-2025-4802 CVE-2025-8058 |
2.32-1.21.al8 |
|
pam |
CVE-2025-6020 CVE-2025-8941 |
1.3.1-38.al8 |
|
perl-Errno |
CVE-2025-40909 |
1.28-423.0.1.al8 |
|
perl-interpreter |
5.26.3-423.0.1.al8 |
|
|
perl-IO |
1.38-423.0.1.al8 |
|
|
perl-libs |
5.26.3-423.0.1.al8 |
|
|
perl-macros |
5.26.3-423.0.1.al8 |
|
|
platform-python |
CVE-2025-8194 |
3.6.8-71.0.1.1.al8 |
|
platform-python-devel |
3.6.8-71.0.1.1.al8 |
|
|
platform-python-setuptools |
CVE-2025-47273 |
39.2.0-9.al8 |
|
python3-cryptography |
CVE-2023-49083 |
3.2.1-8.al8 |
|
python3-libs |
CVE-2025-8194 |
3.6.8-71.0.1.1.al8 |
|
python3-libxml2 |
CVE-2025-32415 |
2.9.7-21.0.1.1.al8.3 |
|
python3-requests |
CVE-2024-47081 |
2.20.0-6.al8 |
|
python3-setuptools |
CVE-2025-47273 |
39.2.0-9.al8 |
|
python3-setuptools-wheel |
39.2.0-9.al8 |
|
|
python3-unbound |
CVE-2025-5994 |
1.16.2-9.al8 |
|
socat |
CVE-2024-54661 |
1.7.4.1-2.0.1.al8 |
|
sqlite |
CVE-2025-6965 |
3.26.0-20.al8 |
|
sqlite-libs |
3.26.0-20.al8 |
|
|
tuned |
CVE-2024-52337 |
2.22.1-5.0.1.1.al8 |
|
udisks2 |
CVE-2025-8067 |
2.9.0-16.0.4.al8.1 |
|
unbound-libs |
CVE-2025-5994 |
1.16.2-9.al8 |
Alibaba Cloud Linux 3 AI Extension Edition 0.5.2
|
Version |
Image ID |
Release date |
Description |
|
Alibaba Cloud Linux 3 AI Extension Edition 0.5.2 |
aliyun_3_0_x64_20G_alibase_aiext_0.5.2_20250714.vhd |
2025-07-14 |
|
Updates
Major updates
-
Compared to Ubuntu 22.04, Alibaba Cloud Linux 3 AI Extension Edition 0.5.2 delivers improved training and inference performance with standard community openclip/bevformer AI container images (AC2):
-
For bevformer_base training, the average throughput per step is 13% higher with FP32 precision and 12% to 18% higher with FP16 precision.
-
For openclip (RN50), the average training throughput per step is 26% higher, and the average inference throughput is 26% higher.
-
-
Replacing the community openclip/bevformer AI container images with Alibaba Cloud's optimized versions improves performance as follows:
-
For bevformer_base training, the average throughput per step is 22% higher with FP32 precision and 17% to 20% higher with FP16 precision.
-
For openclip (RN50), the average training throughput per step is 46% higher, and the average inference throughput is 26% higher.
-
This release upgrades the kernel to version 5.10.134-19.101.al8.x86_64.
-
Scheduling
-
Backports cluster scheduling features.
-
Adds support for configuring BVT for non-movable threads in the root group.
-
Adds support in Core Scheduling for independently configuring special properties for each
cookie.-
Allows sharing a core with normal tasks that do not have a
cookie. -
Prevents load balancing from packing tasks with the same
cookie, ensuring they are distributed across different cores.
-
-
-
Memory
-
Enables Transparent Huge Pages (THP)-aligned address space allocation for
mmap(). -
Adds support for the
memmap_on_memoryfeature invirtio-memto enable rapid container memory scaling. -
Introduces a temporary file optimization feature that improves performance in model training scenarios.
-
Introduces a smooth reclamation feature for the
pagecache limitthat improves memory efficiency and performance in model training scenarios. -
Introduces a page table page reclamation feature to improve memory efficiency and performance in model training scenarios. To enable this feature, add
reclaim_ptto thecmdline. -
Adds a switch to control the delayed release of shmem file pages.
-
Fixes various issues, including a stability issue in
kfenceand a THP counting issue for large code pages.
-
-
Network
-
Fixes various SMC issues, including
link groupandlink use-after-freeproblems, and resolvessmc-rdevice lookup failures in container scenarios.
-
-
Storage
-
erofs:
-
Backports several fixes for the erofs file system from the mainline branch.
-
Adds support for file-backed mounting and a 48-bit layout.
-
Adds support for sub-page blocks for compressed files.
-
-
Backports patches from the mainline stable branches for components such as ext4, block, blk-mq, and io_uring.
-
Introduces the
virtio-blk passthroughfeature for virtio-blk devices.
-
-
Driver
-
The NVMe driver now supports batch processing of completed polled I/O commands.
-
Adds support for differential configuration of NVMe driver parameters for cloud disks and local disks.
-
Merges PCIe driver bugfix patches to resolve issues such as incorrect space size calculation and root bus allocation.
-
-
BPF
-
Merges bugfix and CVE fix patches from community stable branches.
-
Packages
-
Includes
python3.12-3.12.7-1.al8.x86_64as the default Python 3 version. -
Includes
keentuned-3.2.4-2.al8.x86_64to provide intelligent tuning for AI scenarios.
Known issues
-
The NetworkManager-wait-online service fails to start on ecs.ebmgn8t.32xlarge instances.
The instance includes a USB network device, which increases the startup time of the NetworkManager service. This causes the NetworkManager-wait-online service to time out and fail. If you do not use the USB network device, you can work around this issue by configuring NetworkManager to ignore usb0. To do so, add the following to the
/etc/NetworkManager/conf.d/99-unmanaged-device.conffile:[device-usb0-unmanaged] match-device=interface-name:usb0 managed=0Restart the NetworkManager service to apply the change. The NetworkManager-wait-online service will then start normally on the next system reboot.
-
Using
vhost-netmay occasionally cause high CPU usage and network outages. To resolve this issue, install the following hotfix:yum install kernel-hotfix-22577883-5.10.134-19.101 -y -
When an NVMe device encounters a hardware exception, rebooting the system may trigger a null pointer error. To resolve this issue, install the following hotfix:
yum install kernel-hotfix-22584571-5.10.134-19.101 -y
Alibaba Cloud Linux 3.2104 U12
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U12 |
aliyun_3_x64_20G_alibase_20250629.vhd |
2025-06-29 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20250629.vhd |
2025-06-29 |
|
|
|
aliyun_3_x64_20G_container_optimized_alibase_20250629.vhd |
2025-06-29 |
|
|
|
aliyun_3_arm64_20G_alibase_20250629.vhd |
2025-06-29 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20250629.vhd |
2025-06-29 |
|
|
|
aliyun_3_arm64_20G_container_optimized_alibase_20250629.vhd |
2025-06-29 |
|
Content updates
Security updates
|
Package name |
CVE ID |
Updated version |
|
buildah |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
buildah-1.33.8-4.al8 |
|
containernetworking-plugins |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
containernetworking-plugins-1.4.0-5.0.1.al8 |
|
containers-common |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
containers-common-1-82.0.1.al8 |
|
podman |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
podman-4.9.4-12.0.1.al8 |
|
python-podman |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
python-podman-4.9.0-2.al8 |
|
runc |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
runc-1.1.12-4.0.1.al8 |
|
skopeo |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
skopeo-1.14.5-3.0.1.al8 |
|
httpd |
CVE-2023-27522 |
httpd-2.4.37-65.0.1.al8.2 |
|
git-lfs |
CVE-2023-45288 CVE-2023-45289 CVE-2023-45290 CVE-2024-24783 |
git-lfs-3.4.1-2.0.1.al8 |
|
bind |
CVE-2024-1975 CVE-2024-1737 |
bind-9.11.36-16.0.1.al8 |
|
python-setuptools |
CVE-2024-6345 |
python-setuptools-39.2.0-8.al8.1 |
|
less |
CVE-2022-48624 CVE-2024-32487 |
less-530-3.0.1.al8 |
|
java-17-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-17-openjdk-17.0.12.0.7-2.0.2.1.al8 |
|
java-11-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-11-openjdk-11.0.24.0.8-3.0.2.1.al8 |
|
postgresql |
CVE-2024-7348 |
postgresql-13.16-1.0.1.al8 |
|
flatpak |
CVE-2024-42472 |
flatpak-1.12.9-3.al8 |
|
bubblewrap |
CVE-2024-42472 |
bubblewrap-0.4.0-2.2.al8 |
|
java-1.8.0-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-1.8.0-openjdk-1.8.0.422.b05-2.0.2.1.al8 |
|
fence-agents |
CVE-2024-6345 |
fence-agents-4.10.0-62.0.2.al8.4 |
|
pcp |
CVE-2024-45769 CVE-2024-45770 |
pcp-5.3.7-22.0.1.al8 |
|
delve |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
delve-1.21.2-4.0.1.al8 |
|
golang |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
golang-1.21.13-2.0.1.al8 |
|
go-toolset |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
go-toolset-1.21.13-1.al8 |
|
edk2 |
CVE-2023-45236 CVE-2023-45237 CVE-2024-1298 |
edk2-20220126gitbb1bba3d77-13.0.1.al8.2 |
|
curl |
CVE-2024-2398 |
curl-7.61.1-35.0.2.al8 |
|
libvpx |
CVE-2023-6349 CVE-2024-5197 |
libvpx-1.7.0-11.0.1.al8 |
|
resource-agents |
CVE-2024-37891 CVE-2024-6345 |
resource-agents-4.9.0-54.al8.4 |
|
389-ds-base |
CVE-2024-5953 |
389-ds-base-1.4.3.39-8.0.1.al8 |
|
python-urllib3 |
CVE-2024-37891 |
python-urllib3-1.24.2-8.al8 |
|
pcs |
CVE-2024-41123 CVE-2024-41946 CVE-2024-43398 |
pcs-0.10.18-2.0.1.1.al8.2 |
|
grafana |
CVE-2024-24788 CVE-2024-24789 CVE-2024-24790 |
grafana-9.2.10-17.0.1.al8 |
|
libuv |
CVE-2024-24806 |
libuv-1.42.0-2.al8 |
|
c-ares |
CVE-2024-25629 |
c-ares-1.13.0-11.al8 |
|
xmlrpc-c |
CVE-2023-52425 |
xmlrpc-c-1.51.0-9.0.1.al8 |
|
yajl |
CVE-2022-24795 CVE-2023-33460 |
yajl-2.1.0-13.0.1.al8 |
|
wpa_supplicant |
CVE-2023-52160 |
wpa_supplicant-2.10-2.al8 |
|
cups |
CVE-2024-35235 |
cups-2.2.6-60.0.1.al8 |
|
linux-firmware |
CVE-2023-31346 |
linux-firmware-20240610-122.git90df68d2.al8 |
|
wget |
CVE-2024-38428 |
wget-1.19.5-12.0.1.al8 |
|
poppler |
CVE-2024-6239 |
poppler-20.11.0-12.0.1.al8 |
|
krb5 |
CVE-2024-37370 CVE-2024-37371 |
krb5-1.18.2-29.0.1.al8 |
|
git-lfs |
CVE-2024-34156 |
git-lfs-3.4.1-3.0.1.al8 |
|
libreoffice |
CVE-2024-3044 CVE-2024-6472 |
libreoffice-7.1.8.1-12.0.2.1.al8.1 |
|
orc |
CVE-2024-40897 |
orc-0.4.28-4.al8 |
|
jose |
CVE-2023-50967 CVE-2024-28176 |
jose-10-2.3.al8.3 |
|
openssh |
CVE-2020-15778 CVE-2023-48795 CVE-2023-51385 |
openssh-8.0p1-25.0.1.1.al8 |
|
libnbd |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
libnbd-1.6.0-6.0.1.al8 |
|
qemu-kvm |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
qemu-kvm-6.2.0-53.0.1.al8 |
|
libvirt |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
libvirt-8.0.0-23.2.0.2.al8 |
|
osbuild-composer |
CVE-2024-34156 |
osbuild-composer-101-2.0.1.al8 |
|
libreswan |
CVE-2024-3652 |
libreswan-4.12-2.0.2.al8.4 |
|
mod_auth_openidc |
CVE-2024-24814 |
mod_auth_openidc-2.4.9.4-6.al8 |
|
podman |
CVE-2023-45290 CVE-2024-24783 CVE-2024-24784 CVE-2024-24788 CVE-2024-24791 |
podman-4.9.4-13.0.1.al8 |
|
ghostscript |
CVE-2024-29510 CVE-2024-33869 CVE-2024-33870 |
ghostscript-9.54.0-18.al8 |
|
emacs |
CVE-2024-39331 |
emacs-27.2-9.0.3.al8 |
|
dovecot |
CVE-2024-23184 CVE-2024-23185 |
dovecot-2.3.16-5.0.1.al8 |
|
expat |
CVE-2024-45490 CVE-2024-45491 CVE-2024-45492 |
expat-2.2.5-13.0.1.al8 |
|
glib2 |
CVE-2024-34397 |
glib2-2.68.4-14.0.2.al8 |
|
python-idna |
CVE-2024-3651 |
python-idna-2.5-7.al8 |
|
openldap |
CVE-2023-2953 |
openldap-2.4.46-19.al8 |
|
python-pillow |
CVE-2024-28219 |
python-pillow-5.1.1-21.al8 |
|
nghttp2 |
CVE-2024-28182 |
nghttp2-1.33.0-6.0.1.al8.1 |
|
python-jinja2 |
CVE-2024-34064 |
python-jinja2-2.10.1-3.0.3.al8 |
|
opencryptoki |
CVE-2024-0914 |
opencryptoki-3.22.0-3.al8 |
|
gdk-pixbuf2 |
CVE-2021-44648 CVE-2021-46829 CVE-2022-48622 |
gdk-pixbuf2-2.42.6-4.0.1.al8 |
|
rear |
CVE-2024-23301 |
rear-2.6-13.0.1.al8 |
|
grub2 |
CVE-2023-4692 CVE-2023-4693 CVE-2024-1048 |
grub2-2.02-150.0.2.al8 |
|
nss |
CVE-2023-5388 CVE-2023-6135 |
nss-3.101.0-7.0.1.al8 |
|
gnutls |
CVE-2024-0553 CVE-2024-28834 |
gnutls-3.6.16-8.0.1.al8.3 |
|
python3 |
CVE-2024-4032 CVE-2024-6232 CVE-2024-6923 |
python3-3.6.8-67.0.1.2.al8 |
|
grafana |
CVE-2024-24791 |
grafana-9.2.10-18.0.1.al8 |
|
cups-filters |
CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 CVE-2024-47850 |
cups-filters-1.20.0-35.0.1.al8 |
|
linux-firmware |
CVE-2023-20584 CVE-2023-31315 CVE-2023-31356 |
linux-firmware-20240827-124.git3cff7109.al8 |
|
golang |
CVE-2024-9355 |
golang-1.21.13-3.0.1.al8 |
|
openssl |
CVE-2024-5535 |
openssl-1.1.1k-14.0.1.al8 |
|
nano |
CVE-2024-5742 |
nano-2.9.8-2.0.1.al8 |
|
runc |
CVE-2023-45290 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
runc-1.1.12-5.0.1.al8 |
|
OpenIPMI |
CVE-2024-42934 |
OpenIPMI-2.0.32-5.0.1.al8 |
|
grafana |
CVE-2024-47875 CVE-2024-9355 |
grafana-9.2.10-20.0.1.al8 |
|
java-11-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-11-openjdk-11.0.25.0.9-2.0.1.1.al8 |
|
java-1.8.0-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-1.8.0-openjdk-1.8.0.432.b06-2.0.2.1.al8 |
|
java-17-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-17-openjdk-17.0.13.0.11-3.0.2.1.al8 |
|
NetworkManager-libreswan |
CVE-2024-9050 |
NetworkManager-libreswan-1.2.10-7.0.1.al8 |
|
ansible-core |
CVE-2024-0690 |
ansible-core-2.16.3-2.0.1.al8 |
|
libtiff |
CVE-2023-52356 |
libtiff-4.4.0-12.0.2.al8 |
|
krb5 |
CVE-2024-3596 |
krb5-1.18.2-30.0.1.al8 |
|
xorg-x11-server |
CVE-2024-9632 |
xorg-x11-server-1.20.11-25.0.1.al8 |
|
xmlrpc-c |
CVE-2024-45491 |
xmlrpc-c-1.51.0-10.0.1.al8 |
|
bzip2 |
CVE-2019-12900 |
bzip2-1.0.6-27.al8 |
|
bcc |
CVE-2024-2314 |
bcc-0.25.0-9.0.1.al8 |
|
python3.11 |
CVE-2024-6232 |
python3.11-3.11.10-1.0.1.al8 |
|
buildah |
CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 |
buildah-1.33.10-1.al8 |
|
podman |
CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 |
podman-4.9.4-15.0.1.al8 |
|
libtiff |
CVE-2024-7006 |
libtiff-4.4.0-12.0.3.al8 |
|
libsoup |
CVE-2024-52530 CVE-2024-52532 |
libsoup-2.62.3-6.0.1.al8 |
|
gtk3 |
CVE-2024-6655 |
gtk3-3.24.31-5.0.2.1.al8 |
|
tigervnc |
CVE-2024-9632 |
tigervnc-1.13.1-14.al8 |
|
emacs |
CVE-2024-30203 CVE-2024-30204 CVE-2024-30205 |
emacs-27.2-10.0.1.al8 |
|
squid |
CVE-2024-23638 CVE-2024-45802 |
squid-4.15-13.al8.3 |
|
gnome-shell-extensions |
CVE-2024-36472 |
gnome-shell-extensions-40.7-19.0.1.al8 |
|
gnome-shell |
CVE-2024-36472 |
gnome-shell-40.10-21.al8 |
|
osbuild-composer |
CVE-2024-34156 |
osbuild-composer-118-2.0.1.al8 |
|
expat |
CVE-2024-50602 |
expat-2.2.5-16.al8 |
|
iperf3 |
CVE-2023-7250 CVE-2024-26306 |
iperf3-3.9-13.al8 |
|
lldpd |
CVE-2020-27827 CVE-2021-43612 CVE-2023-41910 |
lldpd-1.0.18-4.0.1.al8 |
|
xorg-x11-server-Xwayland |
CVE-2024-31080 CVE-2024-31081 CVE-2024-31083 |
xorg-x11-server-Xwayland-23.2.7-1.al8 |
|
bpftrace |
CVE-2024-2313 |
bpftrace-0.16.0-8.al8 |
|
perl-Convert-ASN1 |
CVE-2013-7488 |
perl-Convert-ASN1-0.27-17.1.0.1.al8 |
|
podman |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
podman-4.9.4-18.0.1.al8 |
|
grafana-pcp |
CVE-2024-9355 |
grafana-pcp-5.1.1-9.0.1.al8 |
|
buildah |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
buildah-1.33.11-1.al8 |
|
python-podman |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
python-podman-4.9.0-3.al8 |
|
golang |
CVE-2024-24790 |
golang-1.22.7-1.0.2.al8 |
|
delve |
CVE-2024-24790 |
delve-1.22.1-1.0.2.al8 |
|
go-toolset |
CVE-2024-24790 |
go-toolset-1.22.7-1.al8 |
|
pam |
CVE-2024-10041 CVE-2024-10963 |
pam-1.3.1-36.al8 |
|
perl-App-cpanminus |
CVE-2024-45321 |
perl-App-cpanminus-1.7044-6.al8 |
|
postgresql |
CVE-2024-10976 CVE-2024-10978 CVE-2024-10979 |
postgresql-13.18-1.0.1.al8 |
|
python3 |
CVE-2024-11168 CVE-2024-9287 |
python3-3.6.8-69.0.1.1.al8 |
|
python3.11-cryptography |
CVE-2023-49083 |
python3.11-cryptography-37.0.2-6.0.1.al8 |
|
python3.11-setuptools |
CVE-2024-6345 |
python3.11-setuptools-65.5.1-3.al8 |
|
python3.11-pip |
CVE-2007-4559 |
python3.11-pip-22.3.1-5.al8 |
|
python3.11 |
CVE-2024-9287 |
python3.11-3.11.11-1.0.1.al8 |
|
php |
CVE-2023-0567 CVE-2023-0568 CVE-2023-3247 CVE-2023-3823 CVE-2023-3824 CVE-2024-2756 CVE-2024-3096 CVE-2024-5458 CVE-2024-8925 CVE-2024-8927 CVE-2024-9026 |
php-7.4.33-2.0.1.al8 |
|
pcs |
CVE-2024-21510 |
pcs-0.10.18-2.0.1.1.al8.3 |
|
gstreamer1-plugins-good |
CVE-2024-47537 CVE-2024-47539 CVE-2024-47540 CVE-2024-47606 CVE-2024-47613 |
gstreamer1-plugins-good-1.16.1-5.al8 |
|
gstreamer1-plugins-base |
CVE-2024-47538 CVE-2024-47607 CVE-2024-47615 |
gstreamer1-plugins-base-1.22.1-3.0.1.al8 |
|
libsndfile |
CVE-2024-50612 |
libsndfile-1.0.28-16.0.1.al8 |
|
tuned |
CVE-2024-52337 |
tuned-2.22.1-5.0.1.1.al8 |
|
edk2 |
CVE-2024-38796 |
edk2-20220126gitbb1bba3d77-13.0.1.al8.4 |
|
bluez |
CVE-2023-45866 |
bluez-5.63-3.0.1.al8 |
|
fontforge |
CVE-2024-25081 CVE-2024-25082 |
fontforge-20200314-6.0.1.al8 |
|
mpg123 |
CVE-2024-10573 |
mpg123-1.32.9-1.al8 |
|
webkit2gtk3 |
CVE-2024-23271 CVE-2024-27820 CVE-2024-27838 CVE-2024-27851 CVE-2024-40779 CVE-2024-40780 CVE-2024-40782 CVE-2024-40789 CVE-2024-40866 CVE-2024-44185 CVE-2024-44187 CVE-2024-44244 CVE-2024-44296 CVE-2024-4558 |
webkit2gtk3-2.46.3-2.0.1.al8 |
|
python-requests |
CVE-2024-35195 |
python-requests-2.20.0-5.al8 |
|
cups-filters |
CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 CVE-2024-47850 |
cups-filters-1.20.0-35.0.2.al8 |
|
openssh |
CVE-2020-15778 CVE-2023-48795 CVE-2023-51385 |
openssh-8.0p1-25.0.1.2.al8 |
|
pam |
CVE-2024-10041 CVE-2024-10963 |
pam-1.3.1-36.1.al8 |
|
webkit2gtk3 |
CVE-2024-23271 CVE-2024-27820 CVE-2024-27838 CVE-2024-27851 CVE-2024-40779 CVE-2024-40780 CVE-2024-40782 CVE-2024-40789 CVE-2024-40866 CVE-2024-44185 CVE-2024-44187 CVE-2024-44244 CVE-2024-44296 CVE-2024-44309 CVE-2024-4558 |
webkit2gtk3-2.46.5-1.0.1.al8 |
|
dpdk |
CVE-2024-11614 |
dpdk-23.11-2.al8 |
|
cups |
CVE-2024-47175 |
cups-2.2.6-62.0.1.al8 |
|
iperf3 |
CVE-2024-53580 |
iperf3-3.9-13.al8.1 |
|
cups |
CVE-2024-47175 |
cups-2.2.6-62.0.2.al8 |
|
NetworkManager |
CVE-2024-3661 |
NetworkManager-1.40.16-18.0.1.al8 |
|
raptor2 |
CVE-2024-57823 |
raptor2-2.0.15-17.0.1.al8 |
|
rsync |
CVE-2024-12085 |
rsync-3.1.3-20.0.1.al8 |
|
fence-agents |
CVE-2024-56201 CVE-2024-56326 |
fence-agents-4.10.0-76.0.1.al8.4 |
|
glibc |
CVE-2022-23218 CVE-2022-23219 |
glibc-2.32-1.19.al8 |
|
glibc |
CVE-2024-33602 CVE-2024-33601 CVE-2024-33600 CVE-2024-33599 |
glibc-2.32-1.20.al8 |
|
grafana |
CVE-2025-21613 CVE-2025-21614 |
grafana-9.2.10-21.0.1.al8 |
|
redis |
CVE-2022-24834 CVE-2022-35977 CVE-2022-36021 CVE-2023-22458 CVE-2023-25155 CVE-2023-28856 CVE-2023-45145 CVE-2024-31228 CVE-2024-31449 CVE-2024-46981 |
redis-6.2.17-1.0.1.1.al8 |
|
python-jinja2 |
CVE-2024-56326 |
python-jinja2-2.10.1-3.0.4.al8 |
|
bzip2 |
CVE-2019-12900 |
bzip2-1.0.6-28.al8 |
|
libsoup |
CVE-2024-52531 |
libsoup-2.62.3-7.0.1.al8 |
|
git-lfs |
CVE-2024-53263 |
git-lfs-3.4.1-4.0.1.al8 |
|
keepalived |
CVE-2024-41184 |
keepalived-2.2.8-4.al8 |
|
unbound |
CVE-2024-1488 CVE-2024-8508 |
unbound-1.16.2-8.al8 |
|
java-17-openjdk |
CVE-2025-21502 |
java-17-openjdk-17.0.14.0.7-3.0.1.1.al8 |
|
galera |
CVE-2023-22084 CVE-2024-21096 |
galera-26.4.20-1.al8 |
|
mariadb |
CVE-2023-22084 CVE-2024-21096 |
mariadb-10.5.27-1.0.1.al8 |
|
doxygen |
CVE-2020-11023 |
doxygen-1.8.14-13.al8 |
|
tbb |
CVE-2020-11023 |
tbb-2018.2-10.al8.1 |
|
gcc-toolset-13-gcc |
CVE-2020-11023 |
gcc-toolset-13-gcc-13.3.1-2.2.0.1.1.al8 |
|
nodejs |
CVE-2025-22150 CVE-2025-23083 CVE-2025-23085 |
nodejs-20.18.2-1.1.al8 |
|
nodejs-packaging |
CVE-2025-22150 CVE-2025-23083 CVE-2025-23085 |
nodejs-packaging-2021.06-4.al8 |
|
nodejs-nodemon |
CVE-2025-22150 CVE-2025-23083 CVE-2025-23085 |
nodejs-nodemon-3.0.1-1.al8 |
|
podman |
CVE-2024-11218 |
podman-4.9.4-19.0.1.al8 |
|
buildah |
CVE-2024-11218 |
buildah-1.33.12-1.al8 |
|
libcap |
CVE-2025-1390 |
libcap-2.48-6.0.2.al8 |
|
libxml2 |
CVE-2022-49043 |
libxml2-2.9.7-18.0.4.1.al8 |
|
bind |
CVE-2024-11187 |
bind-9.11.36-16.0.1.al8.4 |
|
postgresql |
CVE-2025-1094 |
postgresql-13.20-1.0.1.al8 |
|
libpq |
CVE-2025-1094 |
libpq-13.20-1.0.1.al8 |
|
mecab-ipadic |
CVE-2024-11053 CVE-2024-21193 CVE-2024-21194 CVE-2024-21196 CVE-2024-21197 CVE-2024-21198 CVE-2024-21199 CVE-2024-21201 CVE-2024-21203 CVE-2024-21212 CVE-2024-21213 CVE-2024-21218 CVE-2024-21219 CVE-2024-21230 CVE-2024-21231 CVE-2024-21236 CVE-2024-21237 CVE-2024-21238 CVE-2024-21239 CVE-2024-21241 CVE-2024-21247 CVE-2024-37371 CVE-2024-5535 CVE-2024-7264 CVE-2025-21490 CVE-2025-21491 CVE-2025-21494 CVE-2025-21497 CVE-2025-21500 CVE-2025-21501 CVE-2025-21503 CVE-2025-21504 CVE-2025-21505 CVE-2025-21518 CVE-2025-21519 CVE-2025-21520 CVE-2025-21521 CVE-2025-21522 CVE-2025-21523 CVE-2025-21525 CVE-2025-21529 CVE-2025-21531 CVE-2025-21534 CVE-2025-21536 CVE-2025-21540 CVE-2025-21543 CVE-2025-21546 CVE-2025-21555 CVE-2025-21559 |
mecab-ipadic-2.7.0.20070801-17.0.1.al8 |
|
mysql |
CVE-2024-11053 CVE-2024-21193 CVE-2024-21194 CVE-2024-21196 CVE-2024-21197 CVE-2024-21198 CVE-2024-21199 CVE-2024-21201 CVE-2024-21203 CVE-2024-21212 CVE-2024-21213 CVE-2024-21218 CVE-2024-21219 CVE-2024-21230 CVE-2024-21231 CVE-2024-21236 CVE-2024-21237 CVE-2024-21238 CVE-2024-21239 CVE-2024-21241 CVE-2024-21247 CVE-2024-37371 CVE-2024-5535 CVE-2024-7264 CVE-2025-21490 CVE-2025-21491 CVE-2025-21494 CVE-2025-21497 CVE-2025-21500 CVE-2025-21501 CVE-2025-21503 CVE-2025-21504 CVE-2025-21505 CVE-2025-21518 CVE-2025-21519 CVE-2025-21520 CVE-2025-21521 CVE-2025-21522 CVE-2025-21523 CVE-2025-21525 CVE-2025-21529 CVE-2025-21531 CVE-2025-21534 CVE-2025-21536 CVE-2025-21540 CVE-2025-21543 CVE-2025-21546 CVE-2025-21555 CVE-2025-21559 |
mysql-8.0.41-1.0.1.1.al8 |
|
emacs |
CVE-2025-1244 |
emacs-27.2-11.0.1.al8.1 |
|
webkit2gtk3 |
CVE-2024-54543 CVE-2025-24143 CVE-2025-24150 CVE-2025-24158 CVE-2025-24162 |
webkit2gtk3-2.46.6-1.0.1.al8 |
|
tigervnc |
CVE-2025-26594 CVE-2025-26595 CVE-2025-26596 CVE-2025-26597 CVE-2025-26598 CVE-2025-26599 CVE-2025-26600 CVE-2025-26601 |
tigervnc-1.13.1-15.al8 |
|
rsync |
CVE-2024-12087 CVE-2024-12088 CVE-2024-12747 |
rsync-3.1.3-21.0.1.al8 |
|
libxml2 |
CVE-2024-56171 CVE-2025-24928 |
libxml2-2.9.7-19.0.1.1.al8 |
|
krb5 |
CVE-2025-24528 |
krb5-1.18.2-31.0.1.al8 |
|
pcs |
CVE-2024-52804 |
pcs-0.10.18-2.0.1.1.al8.4 |
|
webkit2gtk3 |
CVE-2025-24201 |
webkit2gtk3-2.46.6-2.0.1.al8 |
|
fence-agents |
CVE-2025-27516 |
fence-agents-4.10.0-76.0.1.al8.6 |
|
podman |
CVE-2025-22869 |
podman-4.9.4-20.0.1.al8 |
|
runc |
CVE-2025-22869 |
runc-1.1.12-6.0.1.al8 |
|
libreoffice |
CVE-2025-0624 |
libreoffice-7.1.8.1-15.0.1.1.al8.1 |
|
libreoffice |
CVE-2025-1080 |
libreoffice-7.1.8.1-15.0.1.1.al8.1 |
|
freetype |
CVE-2025-27363 |
freetype-2.10.4-10.al8 |
|
python-jinja2 |
CVE-2025-27516 |
python-jinja2-2.10.1-7.0.1.al8 |
|
libxslt |
CVE-2024-55549 CVE-2025-24855 |
libxslt-1.1.32-6.1.0.1.al8 |
|
tomcat |
CVE-2024-50379 CVE-2025-24813 |
tomcat-9.0.87-1.al8.3 |
|
expat |
CVE-2024-8176 |
expat-2.2.5-17.al8 |
|
mod_auth_openidc |
CVE-2025-31492 |
mod_auth_openidc-2.4.9.4-7.al8 |
|
xmlrpc-c |
CVE-2024-8176 |
xmlrpc-c-1.51.0-11.0.1.al8 |
|
libtasn1 |
CVE-2024-12133 |
libtasn1-4.13-5.0.1.al8 |
|
bluez |
CVE-2023-27349 CVE-2023-51589 |
bluez-5.63-5.0.1.al8 |
Package updates
New features
-
Introduced Confidential AI, which leverages Confidential Computing to enhance data security for AI model training and inference.
-
Added support for PCIe error injection through
ras-tools. -
Added 26 external device drivers for broader hardware compatibility. These drivers are not installed by default.
-
kmod-ast-5.10.134~19-1.14.4~1.al8.src.rpm -
kmod-bnxt-5.10.134~19-1.10.3_231.0.162.0~2.al8.src.rpm -
kmod-fic2-5.10.134~19-1.2.6~1.al8.src.rpm -
kmod-hinic-5.10.134~19-1.0~1.al8.src.rpm -
kmod-hns3-5.10.134~19-1.0~1.al8.src.rpm -
kmod-i40e-5.10.134~19-2.23.17~1.al8.src.rpm -
kmod-iavf-5.10.134~19-4.9.4~1.al8.src.rpm -
kmod-ice-5.10.134~19-1.12.13.4~2.al8.src.rpm -
kmod-igb-5.10.134~19-5.14.16~1.al8.src.rpm -
kmod-intel-QAT20-5.10.134~19-L.0.9.4__00004~1.al8.src.rpm -
kmod-irdma-5.10.134~19-1.13.43~1.al8.src.rpm -
kmod-ixgbe-5.10.134~19-5.19.6~1.al8.src.rpm -
kmod-ixgbevf-5.10.134~19-4.18.7~1.al8.src.rpm -
kmod-ixgbevf-5.10.134~19-4.18.7~1.al8.src.rpm -
kmod-kvdo-6.2.8.7-94.0.1.al8.src.rpm -
kmod-lpfc-5.10.134~19-14.2.673.37~1.al8.src.rpm -
kmod-mellanox-5.10.134~19-23.10~2.al8.src.rpm -
kmod-mpi3mr-5.10.134~19-8.11.1.0.0~1.al8.src.rpm -
kmod-mpt3sas-5.10.134~19-47.00.00.00~1.al8.src.rpm -
kmod-ngbevf-5.10.134~19-1.2.2~2.al8.src.rpm -
kmod-ps3stor-5.10.134~19-2.3.1.24~1.al8.src.rpm -
kmod-ps3stor-5.10.134~19-2.3.1.24~1.al8.src.rpm -
kmod-qla2xxx-5.10.134~19-10.02.09.00_k~1.al8.src.rpm -
kmod-sfc-5.10.134~19-5.3.16.1004~2.al8.src.rpm -
kmod-smartpqi-5.10.134~19-2.1.22_040~1.al8.src.rpm -
kmod-sxe-5.10.134~19-1.3.1.1~1.al8.src.rpm -
kmod-txgbevf-5.10.134~19-1.3.1~2.al8.src.rpm -
kmod-xscale-5.10.134~19-1.2.0_367~2.al8.src.rpm
-
Important updates
Kernel
The kernel has been updated to kernel-5.10.134-19.1.al8.
-
Scheduling
-
Merged the cluster scheduling feature.
-
Enabled BVT configuration for non-migratable threads in the root cgroup.
-
Core sched now supports independent configuration of special properties for each cookie.
-
Enables sharing cores with regular tasks that do not have a cookie.
-
Prevents load balancing from automatically grouping tasks with the same cookie, ensuring they are distributed across different cores.
-
-
-
Memory
-
Fixed stability issues in
kfence. -
Fixed a transparent huge page (THP) accounting issue with code pages.
-
mmap()now supports THP-aligned address space allocation. -
virtio-memsupports thememmap_on_memoryfeature, which facilitates the rapid scaling of container memory. -
Merged several memory-related CVE patches.
-
-
Network
-
Fixed
link groupandlink use-after-freeissues. -
Fixed an
smc-rdevice lookup failure in container scenarios.
-
-
Storage
-
erofs
-
Merged several upstream erofs file system fixes.
-
Added support for file-backed mounting and a 48-bit layout.
-
Added sub-page block support for compressed files.
-
-
Merged upstream stable branch patches for ext4, block, blk-mq, and io_uring components.
-
Introduced the
virtio-blk passthroughfeature.-
This feature adds a generic character device,
/dev/vdXc0, for each virtio-blk block device. You can now send read/write commands directly to the virtio-blk driver layer using theuring_cmdmethod from the io_uring framework. -
This feature also supports bidirectional commands for virtio-blk devices. In a single vectored read/write operation on the same base sector address, you can specify the number of both write and read buffers. A single I/O command can now complete both a write and a subsequent read operation. Currently, only the write-then-read sequence is supported.
-
Introduces ring_pair, a virtio_ring extension for virtio-blk. In this model, each hardware request queue for a virtio-blk device maps to two virtio_ring queues: a submission queue (SQ) and a completion queue (CQ). After a request is submitted, the driver can proactively reclaim the I/O command's slots to issue new requests. When the I/O operation completes, the backend populates the CQ, and the driver harvests the completions. This feature requires backend support for the ring_pair mode and currently supports only the
vring split_queue+Indirect descriptormode.
-
-
-
Driver
-
The NVMe driver now supports batch completion handling for polled I/O commands.
-
Fixed multiple issues in the HiSilicon SAS driver for SCSI and in libsas.
-
Merged PCIe driver bugfix patches, addressing issues such as incorrect space size calculation and root bus assignment.
-
-
BPF
Merged bugfix and CVE patches from the upstream stable community.
-
Architecture
Addressed CVEs in the x86 architecture.
Bug fixes
-
Updated
alinux-base-setuptoalinux-base-setup-3.2-8.al8to fix an issue whereKdumpfailed to generate and grubby parameters were ineffective on the ARM architecture. -
Updated
gdmtogdm-40.0-27.0.1.1.al8to fix an issue where the desktop failed to wake up from screen lock. -
Updated
alinux-releasetoalinux-release-3.2104.12-1.al8to update the EULA file for Alibaba Cloud Linux. -
Updated
dumptodump-0.4-0.36.b46.3.al8to fix an error that occurred when restoring an incremental backup created bydump. -
Updated
maventomaven-3.6.2-9.1.al8to fix an issue where themvncommand was unavailable immediately after installation on Alibaba Cloud Linux 3. -
Updated
grub2togrub2-2.02-165.0.2.al8to fix an issue wheregrub2reported errors inTDXscenarios on Alibaba Cloud Linux 3.
Known issue
The virtio-blk passthrough feature introduces a generic character device for virtio-blk devices, which can cause device detection issues in some user-space components.
For a device such as /dev/vda, partitions start at 1. Therefore, /dev/vdac0 represents the character device for /dev/vda and is distinct from /dev/vdac. Additionally, /dev/vdac0 is a character device, not a block device. If you do not need this character channel, you can upgrade the kernel to kernel-5.10.134-19.1.al8 to prevent this interface from being exposed on virtio-blk cloud disks.
Alibaba Cloud Linux (Alinux) 3.2104 U11.1
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U11.1 |
aliyun_3_x64_20G_alibase_20250117.vhd |
2025-01-17 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20250117.vhd |
2025-01-17 |
|
|
|
aliyun_3_arm64_20G_alibase_20250117.vhd |
2025-01-17 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20250117.vhd |
2025-01-17 |
|
|
|
aliyun_3_x64_20G_container_optimized_20250117.vhd |
2025-01-17 |
|
Updates
Security updates
|
Package name |
CVE ID |
|
python-requests |
CVE-2024-35195 |
|
cups |
CVE-2024-47175 |
|
NetworkManager |
CVE-2024-3661 |
Image updates
-
The
loadmodulesservice is enabled by default. -
The
timedatexservice is enabled by default.
2024
Alibaba Cloud Linux 3.2104 U11
|
Version |
Image ID |
Release date |
Release highlights |
|
Alibaba Cloud Linux 3.2104 U11 |
aliyun_3_x64_20G_alibase_20241218.vhd |
2024-12-18 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20241218.vhd |
2024-12-18 |
|
|
|
aliyun_3_arm64_20G_alibase_20241218.vhd |
2024-12-18 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20241218.vhd |
2024-12-18 |
|
|
|
aliyun_3_x64_20G_container_optimized_20241226.vhd |
2024-12-26 |
|
Content updates
Security updates
|
Package name |
CVE ID |
Version |
|
grafana |
CVE-2024-47875 CVE-2024-9355 |
grafana-9.2.10-20.0.1.al8 |
|
java-11-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-11-openjdk-11.0.25.0.9-2.0.1.1.al8 |
|
java-1.8.0-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-1.8.0-openjdk-1.8.0.432.b06-2.0.2.1.al8 |
|
java-17-openjdk |
CVE-2023-48161 CVE-2024-21208 CVE-2024-21210 CVE-2024-21217 CVE-2024-21235 |
java-17-openjdk-17.0.13.0.11-3.0.2.1.al8 |
|
NetworkManager-libreswan |
CVE-2024-9050 |
NetworkManager-libreswan-1.2.10-7.0.1.al8 |
|
ansible-core |
CVE-2024-0690 |
ansible-core-2.16.3-2.0.1.al8 |
|
krb5 |
CVE-2024-3596 |
krb5-1.18.2-30.0.1.al8 |
|
xorg-x11-server |
CVE-2024-9632 |
xorg-x11-server-1.20.11-25.0.1.al8 |
|
xmlrpc-c |
CVE-2024-45491 |
xmlrpc-c-1.51.0-10.0.1.al8 |
|
bzip2 |
CVE-2019-12900 |
bzip2-1.0.6-27.al8 |
|
bcc |
CVE-2024-2314 |
bcc-0.25.0-9.0.1.al8 |
|
buildah |
CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 |
buildah-1.33.10-1.al8 |
|
libtiff |
CVE-2024-7006 |
libtiff-4.4.0-12.0.3.al8 |
|
libsoup |
CVE-2024-52530 CVE-2024-52532 |
libsoup-2.62.3-6.0.1.al8 |
|
gtk3 |
CVE-2024-6655 |
gtk3-3.24.31-5.0.2.1.al8 |
|
tigervnc |
CVE-2024-9632 |
tigervnc-1.13.1-14.al8 |
|
emacs |
CVE-2024-30203 CVE-2024-30204 CVE-2024-30205 |
emacs-27.2-10.0.1.al8 |
|
squid |
CVE-2024-23638 CVE-2024-45802 |
squid-4.15-13.al8.3 |
|
gnome-shell-extensions |
CVE-2024-36472 |
gnome-shell-extensions-40.7-19.0.1.al8 |
|
gnome-shell |
CVE-2024-36472 |
gnome-shell-40.10-21.al8 |
|
osbuild-composer |
CVE-2024-34156 |
osbuild-composer-118-2.0.1.al8 |
|
expat |
CVE-2024-50602 |
expat-2.2.5-16.al8 |
|
iperf3 |
CVE-2023-7250 CVE-2024-26306 |
iperf3-3.9-13.al8 |
|
lldpd |
CVE-2020-27827 CVE-2021-43612 CVE-2023-41910 |
lldpd-1.0.18-4.0.1.al8 |
|
xorg-x11-server-Xwayland |
CVE-2024-31080 CVE-2024-31081 CVE-2024-31083 |
xorg-x11-server-Xwayland-23.2.7-1.al8 |
|
bpftrace |
CVE-2024-2313 |
bpftrace-0.16.0-8.al8 |
|
perl-Convert-ASN1 |
CVE-2013-7488 |
perl-Convert-ASN1-0.27-17.1.0.1.al8 |
|
podman |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
podman-4.9.4-18.0.1.al8 |
|
grafana-pcp |
CVE-2024-9355 |
grafana-pcp-5.1.1-9.0.1.al8 |
|
buildah |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
buildah-1.33.11-1.al8 |
|
python-podman |
CVE-2021-33198 CVE-2021-4024 CVE-2024-9676 |
python-podman-4.9.0-3.al8 |
|
golang |
CVE-2024-24790 |
golang-1.22.7-1.0.2.al8 |
|
delve |
CVE-2024-24790 |
delve-1.22.1-1.0.2.al8 |
|
go-toolset |
CVE-2024-24790 |
go-toolset-1.22.7-1.al8 |
|
pam |
CVE-2024-10041 CVE-2024-10963 |
pam-1.3.1-36.al8 |
|
perl-App-cpanminus |
CVE-2024-45321 |
perl-App-cpanminus-1.7044-6.al8 |
|
postgresql |
CVE-2024-10976 CVE-2024-10978 CVE-2024-10979 |
postgresql-13.18-1.0.1.al8 |
|
python3 |
CVE-2024-11168 CVE-2024-9287 |
python3-3.6.8-69.0.1.1.al8 |
|
python3.11-cryptography |
CVE-2023-49083 |
python3.11-cryptography-37.0.2-6.0.1.al8 |
|
python3.11-setuptools |
CVE-2024-6345 |
python3.11-setuptools-65.5.1-3.al8 |
|
python3.11-pip |
CVE-2007-4559 |
python3.11-pip-22.3.1-5.al8 |
|
python3.11 |
CVE-2024-9287 |
python3.11-3.11.11-1.0.1.al8 |
|
php |
CVE-2023-0567 CVE-2023-0568 CVE-2023-3247 CVE-2023-3823 CVE-2023-3824 CVE-2024-2756 CVE-2024-3096 CVE-2024-5458 CVE-2024-8925 CVE-2024-8927 CVE-2024-9026 |
php-7.4.33-2.0.1.al8 |
|
pcs |
CVE-2024-21510 |
pcs-0.10.18-2.0.1.1.al8.3 |
Package updates
New features
-
Adds support for confidential computing on AMD and NVIDIA GPUs.
-
Improves
lscpucommand performance on large-scalePCIedevices withutil-linux-2.32.1-46.0.3.al8. -
Adds
erofs-utils-1.8.2-1.al8to enable container storage. -
Updates
java-11-alibaba-dragonwell-11.0.24.21.21-1.1.al8to optimize the BigDecimal class in big data scenarios. -
Updates
java-21-alibaba-dragonwell-21.0.4.0.4-1.1.al8to improve Java performance. -
Adds
system-rpm-config-129-1.0.2.1.al8to configure system macro variables.
Important updates
Kernel
The kernel is updated to version 5.10.134-18.al8.
-
New hardware support
-
Adds official support for the Intel GNR platform.
-
Adds official support for the AMD Turin platform.
-
-
Scheduling
Adds support for
cpu slioncgroup v2, which includes container-level data such ascpuusageandloadavg. -
Memory
-
Backports multiple memory
bugfixpatches from thekernel-5.10 stablebranch to fix several related issues. -
The
pgtable_sharefeature is disabled by default. -
The code segment now supports the
direct collapsemode for huge pages, enabling rapid consolidation into a huge page during apage fault. -
Backports the
percpu chunkrelease optimization patch set to preventchunkrelease failures caused bypercpufragmentation.
-
-
Network
-
Optimizes the RSS logic of
virtio_netto align the RSS configuration with the device and ensure correct updates as the number of queues changes. -
Adds support for 200 Gbps and 400 Gbps speeds for the bond 3ad mode.
-
-
Storage
-
io_uring
-
Fixes a
racecondition when concurrently creatingpercpu sqthread. -
Validates the CPU configuration when enabling
percpu sqthread. -
Backports patches from the community
stablebranch to improve code quality.
-
-
fuse/virtio-fs
-
Adds support for resending
pendingrequests. -
Adds support for multiple queues to optimize
fuseperformance. -
Optimizes read/write separation to prevent a large volume of write requests from blocking read requests.
-
Adds support for the
failoverfeature. After an error, afuse daemoncan use anattachoperation to reconnect to the originalfuse connection, resend requests, and complete fault recovery. -
Adds support for 4 MB write alignment to optimize performance.
-
Fixes an
IO hanginvirtio-fscaused by loading a module larger than 4 MB. -
Adds
tagandqueue mapping sysfsinterfaces tovirtio-fs. -
Backports patches from the community
stablebranch to improve code quality.
-
-
erofs
-
Fixes a UUID issue in
erofs_statfs()and optimizes the DEFLATE stream allocation logic. -
Backports patches from the community
stablebranch to improve code quality.
-
-
ext4
-
Optimizes the cleanup logic for EXT4_GROUP_INFO_WAS_TRIMMED_BIT.
-
Backports patches from the community
stablebranch to improve code quality.
-
-
xfs
-
Reduces
reflinkperformance jitter caused by potential blocking for tens of milliseconds inxfs_log_force(). -
Fixes a compilation error that occurred when CONFIG_FS_DAX was disabled.
-
Ensures
i_blocksis checked correctly when the atomic write feature is enabled.
-
-
block
-
Fixes an
IO hangin themq-deadlinescheduler on devices with multiple hardware queues. -
Fixes an issue where
blockthrottling could fail because a negative value was calculated forbpsthrottling when updating the throttling configuration. -
Removes the
blk-mq "running from the wrong CPU"warning. -
Backports patches from the community
stablebranch to improve code quality.
-
-
Misc
Backports community
stablebranch patches for modules such asvfs,quota,overlayfs,nfs,cifs,ceph,dm/md,null_blk,nbd,loop, andvirtio-blkto improve code quality.
-
-
Driver
-
Backports
watchdogdriver fixes fromkernel-5.10 LTSto improve stability. -
The NVMe driver now supports the latest Alibaba Cloud disk activation solution.
-
Backports NVMe driver fixes from
kernel-5.10 LTSto improve stability. -
Backports SCSI-related fixes from
kernel-5.10 LTSto improve stability. -
Backports ATA-related fixes from
kernel-5.10 LTSto improve stability. -
Introduces the
sig_enforce_subsysparameter to enforce module signature verification for theblock,net, and GPU subsystems. -
Merges numerous bug fixes for
txgbeandtxgbevfinto the NetXen NIC driver to improve code quality and stability.
-
-
Perf
Fixes a pointer memory leak in the
perftool caused by backportingstablebranch patches, preventingcoredumpfailures. -
BPF
-
Adds support for atomic operations in BPF programs.
-
Backports community
stableandbugfixpatches.
-
-
Architecture (x86)
-
Adds support for C-states on the Intel GNR platform.
-
Adds support for P-states on EMR and GNR platforms.
-
Updates
intel-speed-selectto versionv1.20to support new platforms. -
Adds support for passing the PEBS feature through to a virtual machine.
-
Applies
x86bugfixpatches for ACPI, APIC, power, and PMU to other architectures and systems. -
Upgrades
turbostateto version2023.11.07to support more features. -
Adds support for SPR and EMR CXL PMON.
-
Adds support for AMD c2c.
-
Adds support for AMD HSMP.
-
Adds AMD IBRS enhancements.
-
Adds support for AMD ABMC.
-
Bug fixes
Packages
-
The
systemd-239-82.0.3.4.al8.2package fixes an issue that causes a pod to unexpectedly exit and a deployment to fail. This issue occurs whenDelegate=yesis set, which causessystemdto reclaim a non-device cgroupsubgroup within 20 seconds. -
The
ledmon-0.97-1.0.2.al8package fixes a memory leak. -
The
tuned-2.22.1-5.0.1.1.al8package improves data access efficiency on the Yitian platform. -
Fixes an issue that causes some components to fail installation from the
mirror.
Image
-
Modifies the
crashkernelvalue of thex86image to fixvmcoregeneration failures. -
Changes the default value in
/sys/kernel/mm/transparent_hugepage/defragtodeferto accelerate memory reclamation when using transparent huge pages.
Alibaba Cloud Linux 3.2104 U10.1
|
Version |
Image ID |
Release date |
Description |
|
Alibaba Cloud Linux 3.2104 U10.1 |
aliyun_3_x64_20G_alibase_20241103.vhd |
2024-11-03 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20241103.vhd |
2024-11-03 |
|
|
|
aliyun_3_arm64_20G_alibase_20241103.vhd |
2024-11-03 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20241103.vhd |
2024-11-03 |
|
Updates
Security updates
|
Package name |
CVE ID |
Version |
|
buildah |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
buildah-1.33.8-4.al8 |
|
containernetworking-plugins |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
containernetworking-plugins-1.4.0-5.0.1.al8 |
|
containers-common |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
containers-common-1-82.0.1.al8 |
|
podman |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
podman-4.9.4-12.0.1.al8 |
|
python-podman |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
python-podman-4.9.0-2.al8 |
|
runc |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
runc-1.1.12-4.0.1.al8 |
|
skopeo |
CVE-2023-45290 CVE-2024-1394 CVE-2024-3727 CVE-2024-6104 CVE-2024-24783 CVE-2024-24784 CVE-2024-24789 CVE-2024-37298 |
skopeo-1.14.5-3.0.1.al8 |
|
httpd |
CVE-2023-27522 |
httpd-2.4.37-65.0.1.al8.2 |
|
git-lfs |
CVE-2023-45288 CVE-2023-45289 CVE-2023-45290 CVE-2024-24783 |
git-lfs-3.4.1-2.0.1.al8 |
|
bind |
CVE-2024-1975 CVE-2024-1737 |
bind-9.11.36-16.0.1.al8 |
|
python-setuptools |
CVE-2024-6345 |
python-setuptools-39.2.0-8.al8.1 |
|
less |
CVE-2022-48624 CVE-2024-32487 |
less-530-3.0.1.al8 |
|
java-17-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-17-openjdk-17.0.12.0.7-2.0.2.1.al8 |
|
java-11-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-11-openjdk-11.0.24.0.8-3.0.2.1.al8 |
|
postgresql |
CVE-2024-7348 |
postgresql-13.16-1.0.1.al8 |
|
flatpak |
CVE-2024-42472 |
flatpak-1.12.9-3.al8 |
|
bubblewrap |
CVE-2024-42472 |
bubblewrap-0.4.0-2.2.al8 |
|
java-1.8.0-openjdk |
CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21144 CVE-2024-21145 CVE-2024-21147 |
java-1.8.0-openjdk-1.8.0.422.b05-2.0.2.1.al8 |
|
fence-agents |
CVE-2024-6345 |
fence-agents-4.10.0-62.0.2.al8.4 |
|
pcp |
CVE-2024-45769 CVE-2024-45770 |
pcp-5.3.7-22.0.1.al8 |
|
delve |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
delve-1.21.2-4.0.1.al8 |
|
golang |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
golang-1.21.13-2.0.1.al8 |
|
go-toolset |
CVE-2024-24791 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
go-toolset-1.21.13-1.al8 |
|
edk2 |
CVE-2023-45236 CVE-2023-45237 CVE-2024-1298 |
edk2-20220126gitbb1bba3d77-13.0.1.al8.2 |
|
curl |
CVE-2024-2398 |
curl-7.61.1-35.0.2.al8 |
|
libvpx |
CVE-2023-6349 CVE-2024-5197 |
libvpx-1.7.0-11.0.1.al8 |
|
resource-agents |
CVE-2024-37891 CVE-2024-6345 |
resource-agents-4.9.0-54.al8.4 |
|
389-ds-base |
CVE-2024-5953 |
389-ds-base-1.4.3.39-8.0.1.al8 |
|
python-urllib3 |
CVE-2024-37891 |
python-urllib3-1.24.2-8.al8 |
|
pcs |
CVE-2024-41123 CVE-2024-41946 CVE-2024-43398 |
pcs-0.10.18-2.0.1.1.al8.2 |
|
grafana |
CVE-2024-24788 CVE-2024-24789 CVE-2024-24790 |
grafana-9.2.10-17.0.1.al8 |
|
libuv |
CVE-2024-24806 |
libuv-1.42.0-2.al8 |
|
c-ares |
CVE-2024-25629 |
c-ares-1.13.0-11.al8 |
|
xmlrpc-c |
CVE-2023-52425 |
xmlrpc-c-1.51.0-9.0.1.al8 |
|
yajl |
CVE-2022-24795 CVE-2023-33460 |
yajl-2.1.0-13.0.1.al8 |
|
wpa_supplicant |
CVE-2023-52160 |
wpa_supplicant-2.10-2.al8 |
|
cups |
CVE-2024-35235 |
cups-2.2.6-60.0.1.al8 |
|
linux-firmware |
CVE-2023-31346 |
linux-firmware-20240610-122.git90df68d2.al8 |
|
wget |
CVE-2024-38428 |
wget-1.19.5-12.0.1.al8 |
|
poppler |
CVE-2024-6239 |
poppler-20.11.0-12.0.1.al8 |
|
krb5 |
CVE-2024-37370 CVE-2024-37371 |
krb5-1.18.2-29.0.1.al8 |
|
git-lfs |
CVE-2024-34156 |
git-lfs-3.4.1-3.0.1.al8 |
|
libreoffice |
CVE-2024-3044 CVE-2024-6472 |
libreoffice-7.1.8.1-12.0.2.1.al8.1 |
|
orc |
CVE-2024-40897 |
orc-0.4.28-4.al8 |
|
jose |
CVE-2023-50967 CVE-2024-28176 |
jose-10-2.3.al8.3 |
|
openssh |
CVE-2020-15778 CVE-2023-48795 CVE-2023-51385 |
openssh-8.0p1-25.0.1.1.al8 |
|
libnbd |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
libnbd-1.6.0-6.0.1.al8 |
|
qemu-kvm |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
qemu-kvm-6.2.0-53.0.1.al8 |
|
libvirt |
CVE-2024-3446 CVE-2024-7383 CVE-2024-7409 |
libvirt-8.0.0-23.2.0.2.al8 |
|
osbuild-composer |
CVE-2024-34156 |
osbuild-composer-101-2.0.1.al8 |
|
libreswan |
CVE-2024-3652 |
libreswan-4.12-2.0.2.al8.4 |
|
mod_auth_openidc |
CVE-2024-24814 |
mod_auth_openidc-2.4.9.4-6.al8 |
|
podman |
CVE-2023-45290 CVE-2024-24783 CVE-2024-24784 CVE-2024-24788 CVE-2024-24791 |
podman-4.9.4-13.0.1.al8 |
|
ghostscript |
CVE-2024-29510 CVE-2024-33869 CVE-2024-33870 |
ghostscript-9.54.0-18.al8 |
|
emacs |
CVE-2024-39331 |
emacs-27.2-9.0.3.al8 |
|
dovecot |
CVE-2024-23184 CVE-2024-23185 |
dovecot-2.3.16-5.0.1.al8 |
|
expat |
CVE-2024-45490 CVE-2024-45491 CVE-2024-45492 |
expat-2.2.5-13.0.1.al8 |
|
glib2 |
CVE-2024-34397 |
glib2-2.68.4-14.0.2.al8 |
|
python-idna |
CVE-2024-3651 |
python-idna-2.5-7.al8 |
|
openldap |
CVE-2023-2953 |
openldap-2.4.46-19.al8 |
|
python-pillow |
CVE-2024-28219 |
python-pillow-5.1.1-21.al8 |
|
nghttp2 |
CVE-2024-28182 |
nghttp2-1.33.0-6.0.1.al8.1 |
|
python-jinja2 |
CVE-2024-34064 |
python-jinja2-2.10.1-3.0.3.al8 |
|
opencryptoki |
CVE-2024-0914 |
opencryptoki-3.22.0-3.al8 |
|
gdk-pixbuf2 |
CVE-2021-44648 CVE-2021-46829 CVE-2022-48622 |
gdk-pixbuf2-2.42.6-4.0.1.al8 |
|
rear |
CVE-2024-23301 |
rear-2.6-13.0.1.al8 |
|
grub2 |
CVE-2023-4692 CVE-2023-4693 CVE-2024-1048 |
grub2-2.02-150.0.2.al8 |
|
nss |
CVE-2023-5388 CVE-2023-6135 |
nss-3.101.0-7.0.1.al8 |
|
gnutls |
CVE-2024-0553 CVE-2024-28834 |
gnutls-3.6.16-8.0.1.al8.3 |
|
python3 |
CVE-2024-4032 CVE-2024-6232 CVE-2024-6923 |
python3-3.6.8-67.0.1.2.al8 |
|
grafana |
CVE-2024-24791 |
grafana-9.2.10-18.0.1.al8 |
|
cups-filters |
CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 CVE-2024-47850 |
cups-filters-1.20.0-35.0.1.al8 |
|
linux-firmware |
CVE-2023-20584 CVE-2023-31315 CVE-2023-31356 |
linux-firmware-20240827-124.git3cff7109.al8 |
|
golang |
CVE-2024-9355 |
golang-1.21.13-3.0.1.al8 |
|
openssl |
CVE-2024-5535 |
openssl-1.1.1k-14.0.1.al8 |
|
nano |
CVE-2024-5742 |
nano-2.9.8-2.0.1.al8 |
|
runc |
CVE-2023-45290 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 |
runc-1.1.12-5.0.1.al8 |
|
OpenIPMI |
CVE-2024-42934 |
OpenIPMI-2.0.32-5.0.1.al8 |
Package updates
New features
-
Adds the
libyang2component. -
Upgrades
keentunedandkeentune-targetto version 3.1.1.-
Adds a tuning option to control the number of network interface queues.
-
Adds a tuning option for priority control.
-
Removes the
file-maxandschedulertuning options. -
Removes insecure command execution.
-
-
Adds four API components to
keentuned:keentune-bench,keentune-brain,keentune-ui, andkeenopt. -
Upgrades
tcprtto version 1.1.0 to enhance TCP monitoring capabilities. -
Upgrades
Node.jsto version 20.16, providing baseline version 20 capabilities for ACR Artifact Repository. -
Upgrades
erofs-utilsto version 1.8.2 for bug fixes and improved EROFS support.
Important updates
Kernel
This release upgrades the kernel to version 5.10.134-17.3.al8.
-
Anolis-specific features
-
SMC (Shared Memory Communications)
-
Adds the
AutoSplitfeature to reduce latency for large packet transmissions. -
Allows connections in an SMC Link Group to exclusively use an RDMA QP.
-
Adds shared memory watermark control.
-
Adds support for SMC-layer data
dump.
-
-
swiotlb
Adds the
swiotlb=anykernel command-line parameter to reserveswiotlbacross the entire memory space.
-
-
Upstream features
-
Backports
sysctlsettings related to SMC Limited Handshake. -
Backports shared memory usage statistics for SMC LGR and net namespace.
-
-
TDX
-
Adds a TDX Guest RTMR update interface to support custom measurements for remote attestation.
-
Adds the ECDSA algorithm module.
-
Bug fixes
-
Updated util-linux to
util-linux-2.32.1-46.0.3.al8to fix slowlscpuperformance on clusters with manypcidevices. -
Updated tzdata to
tzdata-2024a-1.0.1.6.al8to fix an issue where some time zone files were missing during migration. -
Fixed division-by-zero errors, memory leaks, and other issues in the SMC module.
-
Fixed a defect in the
ftracesubsystem that could cause a system crash when multiple security programs run concurrently. -
Fixed a potential out-of-bounds memory access when using
uprobe.
Alibaba Cloud Linux 3.2104 U10
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U10 |
aliyun_3_x64_20G_alibase_20240819.vhd |
2024-08-19 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20240819.vhd |
2024-08-19 |
|
|
|
aliyun_3_arm64_20G_alibase_20240819.vhd |
2024-08-19 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20240819.vhd |
2024-08-19 |
|
Updates
Security updates
|
Package |
CVE ID |
Version |
|
adwaita-qt |
|
1.4.2-1.al8 |
|
apr |
CVE-2022-24963 |
1.7.0-12.al8 |
|
avahi |
|
0.7-21.0.1.al8.1 |
|
bind |
|
9.11.36-14.0.1.al8 |
|
c-ares |
|
1.13.0-9.al8.1 |
|
cockpit |
CVE-2024-2947 |
310.4-1.al8 |
|
cups |
|
2.2.6-54.0.1.al8 |
|
cups-filters |
CVE-2023-24805 |
1.20.0-32.0.1.al8 |
|
curl |
CVE-2023-38546 |
7.61.1-34.0.1.al8 |
|
device-mapper-multipath |
CVE-2022-41973 |
0.8.4-39.0.2.al8 |
|
dhcp |
|
4.3.6-50.0.1.al8 |
|
dnsmasq |
|
2.79-32.0.1.al8 |
|
edk2 |
|
20220126gitbb1bba3d77-13.0.1.al8 |
|
expat |
CVE-2023-52425 |
2.2.5-13.al8 |
|
evolution-mapi |
|
3.40.1-6.al8 |
|
flatpak |
|
1.12.9-1.al8 |
|
frr |
|
7.5.1-16.0.4.al8 |
|
fwupd |
CVE-2022-3287 |
1.7.8-2.0.1.al8 |
|
ghostscript |
CVE-2024-33871 |
9.54.0-16.al8 |
|
git |
|
2.43.5-1.0.1.al8 |
|
glib2 |
|
2.68.4-11.al8 |
|
gmp |
CVE-2021-43618 |
6.2.0-13.0.1.al8 |
|
gnutls |
CVE-2023-5981 |
3.6.16-8.0.2.al8 |
|
grafana |
|
9.2.10-16.0.1.al8 |
|
grafana-pcp |
CVE-2024-1394 |
5.1.1-2.0.1.al8 |
|
gstreamer1-plugins-bad-free |
|
1.22.1-4.0.1.al8 |
|
gstreamer1-plugins-base |
CVE-2023-37328 |
1.22.1-2.0.1.al8 |
|
gstreamer1-plugins-good |
CVE-2023-37327 |
1.16.1-4.al8 |
|
harfbuzz |
CVE-2023-25193 |
2.7.4-10.0.1.al8 |
|
httpd |
|
2.4.37-64.0.1.al8 |
|
mod_http2 |
|
1.15.7-10.al8 |
|
java-1.8.0-openjdk |
|
1.8.0.412.b08-2.0.1.1.al8 |
|
java-11-openjdk |
|
11.0.23.0.9-3.0.1.1.al8 |
|
libfastjson |
CVE-2020-12762 |
0.99.9-5.al8 |
|
libjpeg-turbo |
CVE-2021-29390 |
2.0.90-7.0.1.al8 |
|
liblouis |
|
3.16.1-5.al8 |
|
libmicrohttpd |
CVE-2023-27371 |
0.9.59-3.al8 |
|
libpq |
CVE-2022-41862 |
13.11-1.0.1.al8 |
|
librabbitmq |
CVE-2023-35789 |
0.11.0-7.0.1.al8 |
|
libreoffice |
|
7.1.8.1-12.0.1.1.al8.1 |
|
libreswan |
|
4.12-2.0.2.al8 |
|
libsndfile |
CVE-2022-33065 |
1.0.28-13.0.2.al8 |
|
libssh |
|
0.9.6-12.al8 |
|
libtiff |
|
4.4.0-12.0.1.al8 |
|
libvirt |
|
8.0.0-23.1.0.1.al8 |
|
qemu-kvm |
|
6.2.0-49.0.1.al8 |
|
libX11 |
|
1.7.0-9.al8 |
|
libxml2 |
|
2.9.7-18.0.3.al8 |
|
libXpm |
|
3.5.13-10.0.1.al8 |
|
linux-firmware |
|
20240111-121.gitb3132c18.al8 |
|
motif |
|
2.3.4-20.al8 |
|
openchange |
|
2.3-32.0.1.al8 |
|
opensc |
|
0.20.0-7.0.1.al8 |
|
openssh |
CVE-2023-51385 |
8.0p1-20.0.1.al8 |
|
openssl |
|
1.1.1k-12.0.1.al8 |
|
pam |
CVE-2024-22365 |
1.3.1-28.al8 |
|
pcp |
CVE-2024-3019 |
5.3.7-20.0.1.al8 |
|
perl-HTTP-Tiny |
CVE-2023-31486 |
0.074-2.0.1.al8.1 |
|
pixman |
CVE-2022-44638 |
0.40.0-6.al8 |
|
pmix |
CVE-2023-41915 |
3.2.3-5.al8 |
|
poppler |
CVE-2020-36024 |
20.11.0-10.0.2.al8 |
|
postgresql-jdbc |
CVE-2024-1597 |
42.2.14-3.al8 |
|
procps-ng |
CVE-2023-4016 |
3.3.15-14.0.1.al8 |
|
protobuf-c |
CVE-2022-48468 |
1.3.0-7.al8 |
|
python-cryptography |
CVE-2023-23931 |
3.2.1-7.al8 |
|
python-dns |
CVE-2023-29483 |
1.15.0-12.al8 |
|
python-pillow |
|
5.1.1-20.al8 |
|
python-pip |
CVE-2007-4559 |
9.0.3-23.0.1.al8.1 |
|
python3 |
|
3.6.8-62.0.1.2.al8 |
|
qt5-qtbase |
|
5.15.3-5.0.3.al8 |
|
qt5-qtsvg |
CVE-2023-32573 |
5.15.3-2.al8 |
|
rpm |
|
4.14.3-27.0.5.2.al8 |
|
samba |
|
4.18.6-3.0.1.1.al8 |
|
shadow-utils |
CVE-2023-4641 |
4.6-19.0.1.al8 |
|
shim |
|
15.8-2.0.1.1.al8 |
|
sqlite |
CVE-2023-7104 |
3.26.0-19.al8 |
|
squashfs-tools |
|
4.3-20.1.0.3.al8 |
|
sssd |
CVE-2023-3758 |
2.9.4-3.al8 |
|
sudo |
|
1.9.5p2-1.0.1.al8 |
|
sysstat |
CVE-2023-33204 |
11.7.3-11.0.1.al8 |
|
tang |
CVE-2023-1672 |
7-8.al8 |
|
tcpdump |
CVE-2021-41043 |
4.9.3-4.0.1.al8 |
|
tigervnc |
|
1.13.1-10.0.1.al8 |
|
tpm2-tss |
CVE-2023-22745 |
2.3.2-5.0.2.al8 |
|
traceroute |
CVE-2023-46316 |
2.1.0-6.2.0.3.al8 |
|
unbound |
CVE-2024-1488 |
1.16.2-7.al8 |
|
util-linux |
CVE-2024-28085 |
2.32.1-45.0.1.1.al8.1 |
|
webkit2gtk3 |
|
2.42.5-1.0.1.al8 |
|
wireshark |
|
2.6.2-17.al8 |
|
xorg-x11-server |
|
1.20.11-16.0.4.al8 |
|
xorg-x11-server-Xwayland |
|
22.1.9-5.al8 |
|
yajl |
CVE-2023-33460 |
2.1.0-12.0.1.al8 |
|
zziplib |
CVE-2020-18770 |
0.13.71-11.al8 |
|
buildah |
|
1.33.7-2.al8 |
|
cockpit-podman |
|
84.1-1.al8 |
|
conmon |
|
2.1.10-1.al8 |
|
container-selinux |
|
2.229.0-2.al8 |
|
containernetworking-plugins |
|
1.4.0-2.0.1.al8 |
|
containers-common |
|
1-81.0.1.al8 |
|
criu |
|
3.18-5.0.1.al8 |
|
fuse-overlayfs |
|
1.13-1.0.1.al8 |
|
podman |
|
4.9.4-3.0.1.al8 |
|
runc |
|
1.1.12-1.0.1.al8 |
|
slirp4netns |
|
1.2.3-1.al8 |
|
libslirp |
|
4.4.0-2.al8 |
Package updates
New features
-
Rdma-core now supports eRDMA.
-
Rasdaemon now supports memory CE error isolation.
-
Nginx now uses OpenSSL 3.
-
Aliyun-cli is now version 3.0.210.
Important updates
Kernel
Upgraded the kernel to version 5.10.134-17.2.al8.
New features
-
Adds native kernel-level failover for FUSE to ensure uninterrupted file access.
-
Adds support for dynamic kernel preemption. This feature aligns with the upstream community's design and lets you switch the preemption model by using
cmdlineorsysfs. The supported models arenoneandvoluntary. Thefullmodel is not yet supported. -
Enhances
perfto support performance metrics for CMN and DDR PMUs. -
BPF features
-
New BPF helpers
-
bpf_for_each_map_elem: Iterates over BPF map elements. -
bpf_snprintf: Formats strings. -
bpf_timer: Triggers a callback function after a specified time. -
bpf_loop: Removes the limitation of constant-bounded loops, enabling flexible loop implementation. -
bpf_strncmp: Compares strings. -
bpf_ktime_get_tai_ns: Gets the time based on theCLOCK_TAIclock source. -
bpf_skb_load_bytes: Adds support for theraw_tptype, enabling programs of this type to readskbdata, including non-linear data.
-
-
Enables attaching BPF trampoline features, including
fentry,fexit,fmod_ret, andbpf_lsm, on the arm64 architecture to provide more powerful tracing, diagnostics, and security. -
Allows
bpf_trampolineto coexist withlivepatch.
-
-
Virtio-net features
-
Adds support for retrieving
virtio-netdevice statistics to improve troubleshooting and diagnostics. -
Introduces a queue reset feature that resizes virtual machine queues to reduce packet loss and optimize latency.
-
Introduces dynamic interrupt moderation (netdim), which intelligently adjusts interrupt coalescing parameters based on real-time traffic to optimize data reception performance.
-
Optimizes
virtiochecksum handling by fixing a verification issue with the virtio network interface controller (NIC) under specific feature controls. As a result, the checksum no longer requires re-verification in the guest operating system in XDP applications, which significantly reduces CPU usage.
-
-
Enables failover support for the EROFS on-demand loading mode.
-
Fixes a semantic issue with
O_DIRECTandO_SYNCin the ext4 file system. This issue has existed since the introduction of the iomap framework. The problem occurred becausegeneric_write_sync()was called within the iomap framework, but the file size (i_disksize) was updated afteriomap_dio_rw()completed. In append-write scenarios, the system failed to update the on-disk file size promptly. As a result, written data could become unreadable after a power failure. -
Adds support for delayed inode invalidation to the XFS file system. This feature offloads inode reclamation to a background
kworkerprocess, reducing application stuttering from foreground delete operations. -
FUSE features and optimizations
-
Adds support for shared memory mapping (mmap) in
cache=nonemode. -
Adds a dynamic
sysfsswitch for the FUSEstrict limitfeature to resolve slow write-backs or stuttering that can occur in certain scenarios.
-
-
Optimizes
kernfsglobal lock contention to reduce load spikes caused by concurrent access from monitoring programs. -
Group Identity features
-
Group Identity 2.0 fine-grained priority
-
Adds support for the
smc_pnetfeature in Shared Memory Communications over RDMA (SMC-R) and eRDMA use cases. -
Improves reachability checks in SMC and eRDMA scenarios to fix a rare kernel crash.
-
-
Calibrates the CPU share ratio for Group Identity 2.0.
-
Adds the
force_idled_timemetric for Group Identity 2.0. -
Optimizes Group Identity's load control for tasks with different priorities.
-
Basic Group Balancer features
-
Adds support for passing zero-length
iovecinrafsv6mode. -
Allows reclamation of
daxmappings inrafsv6mode. This prevents Out of memory (OOM) errors and FUSE hangs caused by pinned memory. -
Uses
kconfigto restrictrafsv6usage to secure containers.
-
-
SMC optimizations and support
-
Adds a timeout mechanism for the
control vqinvirtio. This prevents continuous polling from consuming a virtual machine's CPU resources when a device becomes unresponsive. The default timeout is 7 days. -
Adds a feature to isolate slab memory used by out-of-tree modules. This helps isolate memory corruption issues caused by out-of-tree modules.
-
Introduces a fast Out of memory (OOM) feature to prevent long periods of unresponsiveness in multi-core, large-memory environments when memory is low. This feature helps increase memory deployment density and improves stability for online services under high memory pressure.
-
EROFS support and optimizations
-
XFS adds support for
fsdaxreflinkanddedupe, with specific optimizations for Tair PMEM instances. These optimizations include ensuring the contiguity of snapshot source files, improving dirty page write-back efficiency, and removing the dependency on the reverse-map B-tree to reduce page fault latency. -
Adds support for
cgroup writebackto fix an issue where memory cgroups were not released for long periods whenlazytimewas enabled. This issue could cause the number of memory cgroups to remain high in containerized environments, consuming memory and increasingsysCPU usage when iterating through cgroups. -
Extends the cgroup v2 I/O SLI by adding
blkiocgroup v2 metrics, includingwait time,service time,complete time,io queued, andbytes queued. -
When each
bio_veccontains only a single 4 KB page, the 5.10 kernel supports a maximum I/O size of 1 MB. The additional logic for splitting I/O operations can impact performance in some scenarios. -
Fixes an ABBA deadlock caused by a race condition when setting
blk-iocostQoS parameters. -
Adds support for configuring
tcmu_loopdevice parameters, includingcan_queue,nr_hw_queues,cmd_per_lun, andsg_tablesize. Increasing these parameters on powerful backend devices can significantly improve performance.
Image updates
-
Operating system image
-
Added the
spec_rstack_overflow=offboot parameter. -
Added the
kfence.sample_interval=100 kfence.booting_max=0-2G:0,2G-32G:2M,32G-:32Mboot parameter. -
Set the
net.ipv4.tcp_retries2parameter to8. -
Set the
net.ipv4.tcp_syn_retriesparameter to4. -
Removed the NTP server configuration for Classic Network.
-
-
Container image
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.2104U10
Bug fixes
-
Kernel
-
Fixed a linked list corruption caused by incorrect scheduling of the
credits_announce_workwork item in thesmckernel module. -
Fixed a race condition in
perf_cgroup_switch. -
Prevented the Group Identity 2.0
Queue other timestatistic from becoming negative. -
Fixed incorrect
cfs_rqruntime statistics. -
Fixed an issue where
cfs_rq->corecould be NULL. -
Enabled sound card drivers (
CONFIG_SND). -
Fixed a kernel crash caused by
kfencewhencgroup kmemaccounting was enabled. -
Fixed issues on the LoongArch architecture.
-
Improved EROFS stability in compression mode.
-
Improved
erofsstability overfscache. -
Improved SMC-related stability.
-
Fixed a writeback performance degradation when a BDI used the
STRICTLIMITfeature and its share was set to 0. -
Fixed a memory leak in
seccomp. -
Fixed an issue where the
ZERO_PAGEreference count could be incorrect during certain user operations. -
Fixed a potential recursive memory reclamation issue in
TCMU. -
Fixed a kernel crash caused by the
ioasidssubsystem when migrating kernel threads. -
Fixed an issue where I/O operations were counted multiple times when no rate-limiting rules were configured.
-
Fixed an unexpected hardware signal hang during frequent communication between
Phytium S2500and certain BMC chips. -
Fixed a kernel panic caused by enabling Group Identity and core scheduling simultaneously.
-
Changed the throttling mechanism for CFS bandwidth control from synchronous mode to asynchronous mode to optimize bandwidth control efficiency on systems with a large number of CPUs.
-
Fixed a potential race condition when disabling the global switch for core scheduling.
-
Fixed inaccurate
SIB Idlestatistics under high interrupt request (IRQ) loads. -
Backported patches for NVMe over RDMA from newer versions to improve system stability.
-
Fixed a deadlock during the concurrent execution of
nvme_resetandnvme_rescan. -
Fixed a kernel crash caused by a use-after-free (UAF) issue related to Active-State Power Management (ASPM) in the PCIe driver.
-
Fixed a screen corruption issue on
Phytium S5000Cdevices withAST2600graphics cards. -
Fixed a warning caused by asynchronous
unthrottleto avoid a potential scheduling deadlock. -
CVE-2023-52445
-
CVE-2023-6817
-
CVE-2024-0646
-
CVE-2023-20569
-
CVE-2023-51042
-
CVE-2023-6915
-
CVE-2023-6546
-
CVE-2022-38096
-
CVE-2024-0565
-
CVE-2024-26589
-
CVE-2024-23307
-
CVE-2024-22099
-
CVE-2024-24860
-
CVE-2024-1086
-
CVE-2023-51779
-
CVE-2024-26597
-
CVE-2024-24855
-
CVE-2023-52438
-
CVE-2023-4622
-
CVE-2023-6932
-
CVE-2023-20588
-
CVE-2023-5717
-
CVE-2023-6931
-
CVE-2023-28464
-
CVE-2023-39192
-
CVE-2023-6176
-
CVE-2023-45863
-
CVE-2023-5178
-
CVE-2023-45871
-
CVE-2023-4155
-
CVE-2023-20593
-
CVE-2023-3567
-
CVE-2023-3358
-
CVE-2023-0615
-
CVE-2023-31083
-
CVE-2023-4015
-
CVE-2023-42753
-
CVE-2023-4623
-
CVE-2023-4921
-
CVE-2023-2860
-
CVE-2023-1206
-
CVE-2023-3772
-
CVE-2023-42755
-
CVE-2023-3863
-
CVE-2022-3114
-
CVE-2023-31085
-
CVE-2023-4132
-
CVE-2022-3424
-
CVE-2022-3903
-
CVE-2022-45887
-
CVE-2023-3006
-
CVE-2023-42754
-
CVE-2023-0160
-
-
Image
-
Standardized the debuginfo repository names. You can now install the corresponding debuginfo packages by running the
dnf debuginfo-install <package_name>command. -
Extended the
dnf-makecacheservice interval from 1 hour to 1 day to reduce disk and network usage. -
The
virtio_blkdriver is now in-tree, so its module configuration has been removed frominitramfs.
-
-
Package
Fixed a bug in
dnf-plugin-releasever-adapterwhere thednfcommand could fail.
Alibaba Cloud Linux 3.2104 U9.1
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U9.1 |
aliyun_3_x64_20G_alibase_20240528.vhd |
2024-05-28 |
|
|
aliyun_3_arm64_20G_alibase_20240528.vhd |
2024-05-28 |
|
|
|
aliyun_3_x64_20G_dengbao_alibase_20240528.vhd |
2024-05-28 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20240528.vhd |
2024-05-28 |
|
Content updates
Security updates
|
Package name |
CVE ID |
Package version |
|
kernel |
|
5.10.134-16.3.al8 |
|
bind |
CVE-2022-3094 |
9.11.36-11.0.1.al8 |
|
buildah |
|
1.31.3-1.al8 |
|
dnsmasq |
CVE-2023-28450 |
2.79-31.0.1.al8 |
|
edk2-20220126gitbb1bba3d77 |
CVE-2019-14560 |
6.0.2.al8 |
|
frr |
|
7.5.1-16.0.2.al8 |
|
grafana |
|
9.2.10-7.0.1.al8 |
|
grafana |
CVE-2024-1394 |
9.2.10-7.0.1.al8 |
|
grafana-pcp |
5.1.1-1.0.1.al8 |
|
|
gstreamer1-plugins-bad-free |
CVE-2023-44429 |
1.22.1-2.0.1.al8 |
|
tigervnc |
CVE-2023-44446 |
1.13.1-2.al8 |
|
unbound |
|
1.16.2-6.al8 |
|
webkit2gtk3 |
CVE-2023-42917 |
2.40.5-1.0.2.al8.1 |
|
glibc |
CVE-2024-2961 |
2.32-1.16.al8 |
|
python2-setuptools |
CVE-2022-40897 |
39.0.1-13.1.module+al8+9+77049424 |
Package updates
|
Package name |
Release version |
|
cloud-init |
23.2.2 |
|
container-selinux |
2.229.0 |
|
ethtool |
6.6 |
|
iproute |
6.2.0 |
|
iptables |
1.8.5 |
|
keentuned |
2.4.0 |
|
keentune-target |
2.4.0 |
|
rng-tools |
6.16 |
|
sssd |
2.9.1 |
|
sudo |
1.9.5p2 |
|
sysak |
2.4.0 |
Important updates
-
Kernel updates
-
Upgrades the kernel to 5.10.134-16.3.al8.
-
Adds support for
smc_pnetin SMC-R and eRDMA scenarios. -
Adds support for HWDRC, an RDT-based dynamic memory bandwidth control technology, to provide more precise control over resources like memory bandwidth and cache.
-
Optimizes Group Identity to better control workloads with different priorities.
-
-
New package features
-
Upgrades
aliyun-clito 3.0.204. You can now useyumordnfto install and updatealiyun-cli. -
Upgrades
cloud-initto 23.2.2 to support accessing instance metadata in hardened mode. -
Upgrades
ethtoolto 6.6 to support the CMIS protocol. -
Upgrades
sysakto 2.4.0. This update optimizes diagnostic capabilities, introduces node monitoring, adds support for sysom observability on nodes, and includes several bug fixes. -
Upgrades
keentuneto 2.4.0.
-
Image updates
-
Container images
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.9.1
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest
NoteAfter this release, the
latesttag no longer points to the 3.9.1 image.
-
-
Virtual machine images
The images are now UEFI-Preferred and support both UEFI and Legacy boot modes.
Bug fixes
-
Kernel
-
Improves the stability of erofs compression mode.
-
Improves the stability of erofs over fscache.
-
Improves SMC-related stability.
-
Fixes writeback performance degradation when BDI uses the
STRICTLIMITfeature with a share of 0. -
Fixes a memory leak in seccomp.
-
Fixes an incorrect
ZERO_PAGEreference count caused by user operations. -
Fixes a potential recursive memory reclamation issue in TCMU.
-
Fixes a kernel crash caused by the
ioasidssubsystem migrating a kernel thread. -
Fixes duplicate I/O statistics when no throttling rules are configured.
-
Fixes an unexpected hardware signal hang caused by frequent communication between Phytium S2500 and certain BMC chips.
-
Fixes a kernel panic caused by enabling Group Identity and core scheduling simultaneously.
-
Changes the CFS bandwidth control's unthrottling mechanism from synchronous to asynchronous to optimize efficiency in high-CPU scenarios.
-
Fixes a potential race condition when the global
core schedswitch is disabled. -
Fixes inaccurate
sibidlestatistics in high-IRQ scenarios.
-
-
Image
Fixes an issue where a newly installed kernel failed to take effect after a system reboot.
2023
Alibaba Cloud Linux 3.2104 U9
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U9 |
aliyun_3_9_x64_20G_alibase_20231219.vhd |
2023-12-19 |
|
|
aliyun_3_9_arm64_20G_alibase_20231219.vhd |
2023-12-19 |
|
|
|
aliyun_3_9_x64_20G_dengbao_alibase_20231219.vhd |
2023-12-19 |
|
|
|
aliyun_3_9_arm64_20G_dengbao_alibase_20231219.vhd |
2023-12-19 |
|
|
|
aliyun_3_9_x64_20G_uefi_alibase_20231219.vhd |
2023-12-19 |
|
Content updates
Security updates
|
Parameter |
CVE ID |
Package version |
|
kernel |
|
5.10.134-16.1.al8 |
|
java-1.8.0-openjdk |
|
1.8.0.392.b08-4.0.3.al8 |
|
java-11-openjdk |
CVE-2023-22081 |
11.0.21.0.9-2.0.3.al8 |
|
mariadb |
|
10.5.22-1.0.1.al8 |
|
open-vm-tools |
|
12.2.5-3.al8.1 |
|
bind |
CVE-2023-3341 |
9.11.36-8.al8.2 |
|
dmidecode-doc |
CVE-2023-30630 |
3.3-5.0.2.al8 |
|
frr |
CVE-2023-38802 |
7.5.1-8.0.1.al8 |
|
ghostscript |
|
9.54.0-14.al8 |
|
glibc |
CVE-2023-4911 |
2.32-1.12.al8 |
|
grafana |
|
7.5.15-5.0.1 |
|
libvpx |
|
1.7.0-10.0.1.al8 |
|
linux-firmware |
CVE-2023-20593 |
20230404-117.git2e92a49f.al8 |
|
ncurses |
CVE-2023-29491 |
6.1-10.20180224.0.1.al8 |
|
nghttp2 |
CVE-2023-44487 |
1.33.0-4.0.1.al8.1 |
|
|
|
|
tracker-miners |
CVE-2023-5557 |
3.1.2-4.0.1.al8 |
Package updates
|
Package name |
Release version |
|
ca-certificates |
2023.2.60_v7.0.306 |
|
firewalld |
0.9.11 |
|
java-1.8.0-openjdk |
1.8.0.392.b08 |
|
java-11-openjdk |
11.0.21.0.9 |
|
libbpf |
0.6.0 |
|
lz4 |
1.9.4 |
|
mariadb |
10.5.22 |
|
nmstate |
2.2.15 |
|
nspr |
4.35.0 |
|
nss |
3.90.0 |
|
open-vm-tools |
12.2.5 |
|
openscap |
1.3.8 |
|
scap-security-guide |
0.1.69 |
|
sos |
4.6.0 |
|
xz |
5.4.4 |
Important updates
Kernel
-
New features
-
Core scheduling
Backports the core scheduling security feature from the upstream community. It restricts processes running on a physical core's hyper-threads to a trusted group. This feature is incompatible with group identity; do not enable them simultaneously. It is disabled by default. To enable it, run
sysctl -w kernel.sched_core=1. -
eBPF trampoline on Arm64
Backports the eBPF trampoline feature on Arm64 to support
bpf struct ops. Note that because the relevant Arm64ftracefeatures were not backported, thebpf fentryfamily of features remains unavailable. -
MGLRU feature
Adds support for Multi-Generational LRU (MGLRU) to improve memory page reclaim. This improves the speed and accuracy of memory reclaim in big data scenarios, boosting end-to-end performance.
-
Batch TLB flushing
The batch migration feature improves kernel page migration performance by batching TLB flushing and page copy operations.
This version refactors and optimizes the original batch migration feature based on upstream code. Major changes include the removal of the
batch_migratecmdline parameter and the/sys/kernel/mm/migrate/batch_migrate_enabledinterface. Batch migration is now the default for page migration.Adds the /sys/kernel/mm/migrate/dma_migration_min_pages interface, which defaults to 32. This interface applies only when the DMA page copy feature is enabled. DMA page copy is used only if
/sys/kernel/mm/migrate/dma_migrate_enabledis enabled and the number of pages to migrate meets the threshold set by/sys/kernel/mm/migrate/dma_migration_min_pages. -
Cachestat backport
Introduces the
cachestatsystem call, which provides detailed page cache statistics for a specific file. -
Enhanced kernel-mode RAS event triggering on Arm64
Adds error recovery capabilities for RAS issues in various scenarios, including
copy_{from/to}_user,{get/put}_user, Copy on Write (COW), and pagecache reading. -
Proprietary SMC-D loopback feature
Introduces the SMC-D loopback feature to accelerate local inter-process and inter-container TCP communication.
-
Proprietary page table core binding and cross-die statistics
When memory is constrained, the page table core binding feature attempts to allocate page tables for QoS-sensitive services on the current NUMA node. This reduces memory access latency, enabling faster and more efficient memory access.
-
Proprietary code multi-copy enhancement
Uses an asynchronous task to retry applying code multi-copy when it fails during process startup. Adds the
memory.duptext_nodeskernel interface to restrict the memory allocation nodes forduptext. -
Proprietary kfence enhancement
-
On the Arm64 architecture, you can dynamically enable or disable this enhanced proprietary
kfencefeature. It comprehensively captures memory corruption issues, facilitating both online detection and offline debugging. -
You can now configure the system to panic immediately when a memory issue is detected, which helps developers analyze problems in a debugging environment. Enable it by setting the boot cmdline to
kfence.fault=panicor by runningecho panic > /sys/module/kfence/parameters/fault. The default value isreport, which only logs the issue.
-
-
Proprietary memcg THP control interface
Provides an interface to disable Transparent Huge Pages (THP) allocation for a specified memory cgroup (memcg).
-
Proprietary ACPU (Assess CPU) feature
ACPU collects statistics on the idle time of a hyper-threading sibling while a task is running and provides per-cgroup statistics. This data helps evaluate hardware resource contention on shared CPU cores.
-
Proprietary HT-aware-quota feature
This feature uses CFS bandwidth control and core scheduling to provide computing power stability in mixed deployment scenarios. It calibrates the quota by detecting if the hyper-threading sibling is idle, allowing compute-intensive tasks to receive more consistent computing power in each scheduling period.
-
Proprietary group identity 2.0
Introduces a cgroup-level
SCHED_IDLEfeature. Setting thecpu.idleproperty on a target cgroup changes its scheduling policy toSCHED_IDLE. This is ideal for managing batches of offline tasks.
-
-
Behavioral changes
-
Module signing
Adds signatures to kernel modules, helping developers identify and reject unsigned modules.
-
Spectre-BHB and Variant 4 mitigations disabled by default on Arm64
Analysis indicates that Spectre-BHB and Variant 4 vulnerabilities are already mitigated by other means, such as Spectre v2 mitigation, disabling unprivileged eBPF, Site-Isolation technology, and disabling SharedArrayBuffer. To improve performance by reducing unnecessary overhead while maintaining security, this release adds the
nospectre_bhbandssbd=force-offparameters to the default cmdline on Arm64. -
Support for TDX confidential virtual machines
-
New features in packages
-
erofs-utils 1.7.1
erofs-utils is a tool for creating, checking, and compressing EROFS file systems. It supports compression algorithms such as LZ4, LZMA, and DEFLATE, and can convert TAR archives to the EROFS format.
-
stress-ng 0.15.00
-
Alibaba Cloud Compiler 13.0.1.4
Alibaba Cloud Compiler is a C/C++ compiler developed by Alibaba Cloud. It is based on the open source Clang/LLVM 13 and inherits all its options and parameters. In addition, Alibaba Cloud Compiler is optimized for Alibaba Cloud infrastructure and provides unique features and optimizations for a superior C/C++ compiler experience.
-
GB18030-2022 support in glibc
-
Dragonwell 17 updated to 17.0.9.0.10.9. This update improves JIT compiler inlining performance by removing the logic that makes inlining decisions based on absolute call counts.
-
Dragonwell 8 updated to 8.15.16.372: Adds support for multiple coroutines to wait for read and write events on the same socket and fixes a bug in OkHttp scenarios.
-
plugsched 1.3
plugsched is an SDK for scheduler hot-upgrades. Kernel scheduler developers can use this SDK to develop scheduler modules.
-
Sysak updated to 2.2.0. This version introduces application observability, with support for metrics and diagnostics for MySQL and Java applications, adds new monitoring metrics for container and cluster monitoring, and includes local monitoring capabilities.
-
keentune updated to 2.3.0: Updates x264/265 related scripts to support the latest FFmpeg; resolves XPS and RPS core binding errors; updates the default eRDMA settings in profiles.
-
Intel QAT/DLB/IAA accelerator software stack updated: Includes QAT driver bug fixes, a DLB driver upgrade, QAT and IAA user-space bug fixes, and a new unified user-space DMA memory management solution for cross-architecture accelerators.
-
smc-tools updated: Adds the
smc-ebpfcommand, which supports controlling the effective scope ofsmc_runat the port granularity. Supported control modes include allowlist, blocklist, and intelligent scheduling.
Fixed issues
-
Fixed a kernel update issue where required RPM packages, such as kernel-modules-extra and kernel-modules-internal, were not automatically installed, disabling netfilter-related functions.
-
Fixed a reference counting issue with group identity during cgroup creation and deletion that sometimes prevented disabling the
/proc/sys/kernel/sched_group_identity_enabledinterface.
Image updates
-
Container images
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.9
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest
NoteAfter this release, the
latesttag will no longer point to the 3.9 image version.
-
-
Virtual machine images
-
The default rpmdb format is now SQLite.
-
The keentune service is installed but not enabled by default.
-
The nfs-server service is not enabled by default.
-
Known issues
-
The kdump service may fail on
ecs.g6r.largeinstances due to memory constraints. To work around this issue, adjust the crash parameter, for example, to0M-2G:0M,2G-128G:256M,128G-:384M. -
On an
NFSv3file system, if you add anSpermission to a file, the group's S permission is lost when the file owner is changed under certain conditions.The patch to fix this issue is
2d8ae8c417("db nfsd: use vfs setgid helper"). However, applying this fix is deferred because the required helper functions differ significantly from the5.10kernel code base. -
When using
SMCto replaceTCP,netperftests may exit prematurely.SMCuses a fixed-size ring buffer. During transmission, the remaining buffer space may be smaller than the amount of data requested in asend()call. In this case,SMCreturns the number of bytes that can be sent, which is typically less than the requested amount.netperftreats this behavior as an anomaly, which causes it to exit. Because the upstream maintainer strongly recommends keeping the current design to prevent connection stalls, this issue will not be fixed.
Alibaba Cloud Linux 3.2104 U8
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U8 |
aliyun_3_arm64_20G_alibase_20230731.vhd |
2023-07-31 |
|
|
aliyun_3_x64_20G_alibase_20230727.vhd |
2023-07-27 |
|
|
|
aliyun_3_x64_20G_qboot_alibase_20230727.vhd |
2023-07-27 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20230727.vhd |
2023-07-27 |
|
|
|
aliyun_3_x64_20G_dengbao_alibase_20230727.vhd |
2023-07-27 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20230727.vhd |
2023-07-27 |
|
Updates
Security updates
|
Package |
CVE |
Version |
|
ctags |
CVE-2022-4515 |
5.8-23.0.1.al8 |
|
gssntlmssp |
|
1.2.0-1.0.1.al8 |
|
libtar |
|
1.2.20-17.0.1.al8 |
|
device-mapper-multipath |
CVE-2022-41973 |
0.8.4-37.0.1.al8 |
|
postgresql-jdbc |
CVE-2022-41946 |
42.2.14-2.al8 |
|
freerdp |
|
2.2.0-10.0.1.al8 |
|
tigervnc |
|
1.12.0-15.al8 |
|
xorg-x11-server |
|
1.20.11-15.0.1.al8 |
|
poppler |
CVE-2022-38784 |
20.11.0-6.0.1.al8 |
|
wayland |
CVE-2021-3782 |
1.21.0-1.al8 |
|
net-snmp |
|
5.8-27.0.1.al8 |
|
dhcp |
|
4.3.6-49.0.1.al8 |
|
python-mako |
CVE-2022-40023 |
1.0.6-14.al8 |
|
curl |
CVE-2023-27535 |
7.61.1-30.0.2.al8.2 |
|
|
|
|
dnsmasq |
CVE-2023-28450 |
2.79-27.al8 |
|
qt5 |
CVE-2022-25255 |
5.15.3-1.0.1.al8 |
|
autotrace |
CVE-2022-32323 |
0.31.1-55.al8 |
|
bind |
CVE-2023-2828 |
9.11.36-8.al8.1 |
|
|
|
|
mysql |
|
8.0.32-1.0.2.al8 |
|
ruby |
|
2.7.8-139.0.1.al8 |
|
kernel |
|
5.10.134-15.al8 |
|
webkit2gtk3 |
|
2.38.5-1.0.1.al8.5 |
|
libssh |
|
0.9.6-7.al8 |
|
open-vm-tools |
CVE-2023-20867 |
12.1.5-2.al8 |
|
grafana |
|
7.5.15-4.0.2.al8 |
|
grafana-pcp |
CVE-2022-27664 |
3.2.0-3.0.1.al8 |
|
frr |
CVE-2022-37032 |
7.5.1-7.0.1.al8 |
|
sqlite |
CVE-2020-24736 |
3.26.0-18.al8 |
|
git-lfs |
|
3.2.0-2.0.1.al8 |
|
sysstat |
CVE-2022-39377 |
11.7.3-9.0.1.al8 |
|
python3 |
CVE-2023-24329 |
3.6.8-51.0.1.al8.1 |
|
c-ares |
CVE-2023-32067 |
1.13.0-6.al8.2 |
|
cups-filters |
CVE-2023-24805 |
1.20.0-29.0.1.al8.2 |
|
webkit2gtk3 |
|
2.38.5-1.0.1.al8.4 |
|
delve go-toolset golang |
CVE-2023-24540 |
delve-1.9.1-1.0.1.al8 go-toolset-1.19.9-1.al8 golang-1.19.9-1.0.1.al8 |
|
kernel |
|
5.10.134-14.1.al8 |
|
git |
|
2.39.3-1.1.al8 |
|
apr-util |
CVE-2022-25147 |
1.6.1-6.2.al8.1 |
|
webkit2gtk3 |
CVE-2023-2203 |
2.38.5-1.0.1.al8.3 |
|
edk2 |
|
20220126gitbb1bba3d77-4.al8 |
|
mingw-expat |
CVE-2022-40674 |
2.4.8-2.al8 |
Package updates
|
Parameter |
Version |
|
at |
at-3.1.20-12.0.1.al8 |
|
audit |
audit-3.0.7-2.0.1.al8.2 |
|
authselect |
authselect-1.2.6-1.al8 |
|
bind |
bind-9.11.36-8.al8.1 |
|
checkpolicy |
checkpolicy-2.9-1.2.al8 |
|
cloud-utils-growpart |
cloud-utils-growpart-0.33-0.0.1.al8 |
|
container-selinux |
container-selinux-2.189.0-1.al8 |
|
coreutils |
coreutils-8.30-13.al8 |
|
crypto-policies |
crypto-policies-20221215-1.gitece0092.al8 |
|
cups |
cups-2.2.6-51.0.1.al8 |
|
dbus |
dbus-1.12.8-24.0.1.al8 |
|
ding-libs |
ding-libs-0.6.1-40.al8 |
|
dnf |
dnf-4.7.0-16.0.1.al8 |
|
dnf-plugins-core |
dnf-plugins-core-4.0.21-14.1.al8 |
|
dracut |
dracut-049-223.git20230119.al8 |
|
elfutils |
elfutils-0.188-3.0.1.al8 |
|
emacs |
emacs-27.2-8.0.3.al8.1 |
|
expat |
expat-2.2.5-11.al8 |
|
file |
file-5.33-24.al8 |
|
freetype |
freetype-2.10.4-9.al8 |
|
fuse |
fuse-2.9.7-16.al8 |
|
gmp |
gmp-6.2.0-10.0.1.al8 |
|
gnupg2 |
gnupg2-2.2.20-3.al8 |
|
graphite2 |
graphite2-1.3.10-10.2.al8 |
|
grub2 |
grub2-2.02-148.0.1.al8 |
|
harfbuzz |
harfbuzz-1.7.5-3.2.al8 |
|
hwdata |
hwdata-0.314-8.16.al8 |
|
iproute |
iproute-5.18.0-1.al8 |
|
iptables |
iptables-1.8.4-24.0.1.al8 |
|
kernel |
kernel-5.10.134-15.al8 |
|
kernel-hotfix-13383560-5.10.134-15 |
kernel-hotfix-13383560-5.10.134-15-1.0-20230724161633.al8 |
|
kexec-tools |
kexec-tools-2.0.25-5.0.1.al8 |
|
kmod |
kmod-25-19.0.2.al8 |
|
kpatch |
kpatch-0.9.7-2.0.1.al8 |
|
libarchive |
libarchive-3.5.3-4.al8 |
|
libffi |
libffi-3.1-24.0.1.al8 |
|
libteam |
libteam-1.31-4.0.1.al8 |
|
libuser |
libuser-0.62-25.0.1.al8 |
|
libxml2 |
libxml2-2.9.7-16.0.1.al8 |
|
linux-firmware |
linux-firmware-20230404-114.git2e92a49f.al8 |
|
logrotate |
logrotate-3.14.0-6.0.1.al8 |
|
NetworkManager |
NetworkManager-1.40.16-1.0.1.al8 |
|
nfs-utils |
nfs-utils-2.3.3-59.0.2.al8 |
|
nftables |
nftables-0.9.3-26.al8 |
|
oddjob |
oddjob-0.34.7-3.0.1.al8 |
|
openssh |
openssh-8.0p1-17.0.2.al8 |
|
openssl-pkcs11 |
openssl-pkcs11-0.4.10-3.0.1.al8 |
|
pam |
pam-1.3.1-25.0.1.al8 |
|
pciutils |
pciutils-3.7.0-3.0.1.al8 |
|
python-linux-procfs |
python-linux-procfs-0.7.1-1.al8 |
|
python-rpm-generators |
python-rpm-generators-5-8.al8 |
|
python-slip |
python-slip-0.6.4-13.al8 |
|
rng-tools |
rng-tools-6.15-3.0.1.al8 |
|
rpcbind |
rpcbind-1.2.5-10.0.1.al8 |
|
rpm |
rpm-4.14.3-26.0.1.al8 |
|
rsyslog |
rsyslog-8.2102.0-13.al8 |
|
selinux-policy |
selinux-policy-3.14.3-117.0.1.al8 |
|
setools |
setools-4.3.0-3.al8 |
|
setup |
setup-2.12.2-9.0.1.al8 |
|
sg3_utils |
sg3_utils-1.44-6.0.1.al8 |
|
shared-mime-info |
shared-mime-info-2.1-5.0.1.al8 |
|
sssd |
sssd-2.8.2-2.0.1.al8 |
|
tpm2-tss |
tpm2-tss-2.3.2-4.0.2.al8 |
|
unbound |
unbound-1.16.2-5.al8 |
|
util-linux |
util-linux-2.32.1-42.0.1.al8 |
|
virt-what |
virt-what-1.25-3.al8 |
|
wget |
wget-1.19.5-11.0.1.al8 |
|
which |
which-2.21-18.0.1.al8 |
|
xfsprogs |
xfsprogs-5.0.0-10.0.6.al8 |
Important updates
-
Kernel updates
-
Upstream backport
-
devlink supports subfunction management.
A subfunction is a lightweight function. It is more lightweight than a PCIe virtual function. Unlike a virtual function, a subfunction is not an independent PCI device but shares the resources of its parent PCI device. However, a subfunction has all the resources related to network interface controller communication, such as send queues, receive queues, and completion queues (CQs). A subfunction appears as a complete network interface controller device in the Linux system. This update adds support for managing subfunctions on network interface controllers through devlink. By coordinating with the driver, you can create, destroy, and query subfunctions on supported network interface controllers.
-
io_uring supports NVMe passthrough.
During storage device access, the overhead from the complex storage stack has a significant impact on latency and IOPS. As storage devices become faster, the overhead of this software stack becomes more significant. Accessing NVMe disks requires passing through multiple abstraction layers, such as the file system, block layer, and NVMe driver, before finally reaching the target device. This update backports the
io_uring uring_cmdfeature, which was added to the community mainline in v5.19. It passes the actual file operations to the kernel through io_uring. These operations are not parsed at the io_uring layer but are passed directly to the NVMe driver layer for processing. This bypasses the file system and block layers. Additionally, to support this feature, io_uring now supports the CQE32 data structure and the creation of NVMe character devices. -
Adds fine-grained permission control for NVMe/SCSI Persistent Reservation.
Previously, a process that performed a Persistent Reservation operation had to have the
CAP_SYS_ADMINpermission. This prevented its use in some non-privileged scenarios, such as containers. This feature lets non-privileged processes (those withoutCAP_SYS_ADMINpermission) perform Persistent Reservation operations as long as they have write permission for the block device. This expands the use cases for the feature. -
Optimizes IOPS throttling for large block I/O.
The IOPS throttling capability in the current 5.10 kernel does not work well in large block I/O scenarios, such as with 1 MB blocks. The main reason is that large block I/O may be split, and the block throttle's IOPS throttling logic does not handle this well. This issue is especially noticeable in buffer I/O scenarios because buffer I/O first writes to the page cache and then writes back after a period. This process often merges I/O into large blocks. The community mainline refactored and optimized this in v5.18. This update backports patches from the community mainline to optimize IOPS throttling for large block I/O. It also fixes a bug that caused BPS to be counted multiple times.
-
Backports BPF support for
lookup_and_delete_elemon hashmaps and adds the bloom filter feature.-
Previously, the BPF
lookup_and_delete_elemoperation only supported maps of the queue and stack types. It now supports hash maps. -
Adds a new map type, bloom filter, which is an efficient tool for set lookups.
-
-
Adds support for CPU and memory hot-plugging for QEMU Arm64 virtual machine guest OSs.
-
Supports hot-upgrading the number of vCPUs in a guest OS using the
virsh setvcpuscommand. -
Enables the
CONFIG_MEMORY_HOTPLUG_DEFAULT_ONLINEconfiguration by default to preventmemhp_default_online_typefrom being in an offline state. This way, when memory is added via hot-plugging, it can be used automatically. This avoids memory hot-plug failures that occur when creating page descriptors for newly added memory leads to insufficient memory.
-
-
Enables Intel HWP boost for all Intel chips.
HWP I/O boost technology can improve I/O performance. However, the kernel previously enabled this feature only for some Skylake platforms and enterprise servers. This patch removes the CPU type check and enables HWP boost for all CPUs by default.
-
Backports the community HVO feature.
HVO stands for HugeTLB Vmemmap Optimization. It reduces the memory footprint of vmemmap corresponding to huge pages. The principle is to map the virtual addresses of all
struct pageentries for a huge page in vmemmap to the same physical address. This frees the physical memory occupied by thestruct pageentries. -
Backports the memcg lru_lock optimization feature.
This feature optimizes scenarios in the kernel that require a global
lru_lock. Instead of the global lock, it uses the lock of the memcg where the page resides. These scenarios include page migration, memcg migration, swap-in, and swap-out. This feature significantly reduces contention caused by the globallru_lock. In test scenarios with multiple memcgs, performance improved by about 50%. -
Adds support for the Intel TDX guest kernel.
Supports running the Linux kernel in an Intel TDX guest. This provides the guest with memory encryption, memory integrity protection, CPU register protection, and remote attestation in a trusted environment.
-
Adds adaptations for the EMR platform.
-
Adds the EMR CPU ID to the PMU driver to enable PMU capabilities on the EMR platform.
-
Enables the In-Field Scan (IFS) Array Built-In Self-Test (BIST) capability. IFS is used to capture CPU errors that are difficult for Error-Correcting Code (ECC) to detect. It can check each core during runtime.
-
-
-
Self-developed features
-
Adds the capability to transparently accelerate TCP using the SMC kernel network protocol stack.
Shared Memory Communications (SMC) is a high-performance kernel network protocol stack contributed by IBM to the upstream Linux kernel. It can work with various shared memory technologies, such as Remote Direct Memory Access (RDMA), to transparently accelerate TCP. On top of the upstream version, ANCK fixes many stability issues and adds several key features. It supports SMCv2 by default, SMCv2.1 protocol negotiation, the
max_link`/`max_conn`/Alibaba vendor IDfeatures, optimized link connection counts, RQ flow control, and RDMA Write With Immediate operations. ANCK also adds various diagnostic information, support for using the SMC protocol stack through thePF_INETprotocol family, and support for transparent replacement via BPF. -
Enhances the FUSE cache consistency model and adds statistics interfaces.
-
Adds a debugging interface in
sysfsto print all requests that have been sent to the user-mode daemon and are awaiting processing for a specific FUSE file system. -
Adds a data statistics interface in
sysfsto count and report the number and processing time of each request type for a specific FUSE file system. -
Enhances cache consistency in
cache=always|automode to suit distributed file system backends that rely on strong consistency, such as Network File System (NFS).-
The user-mode daemon can notify the FUSE client to invalidate all directory entries in a directory.
-
Implements the Close-To-Open (CTO) cache consistency model, including flush-on-close and invalidate-on-open semantics for data and metadata.
-
Enhances the cache consistency model in FUSE failover mode.
-
-
-
EROFS supports mounting tar files directly and using uncompressed EROFS images with 4 KB block sizes on Arm64 platforms with 16 KB/64 KB page configurations.
-
Supports mounting uncompressed EROFS images with 4 KB block sizes on Arm64 platforms configured with 16 KB or 64 KB pages.
-
Supports using a tar file directly as a data source, allowing you to mount and access the tar data using EROFS metadata.
-
-
Adds support for passing FUSE mount points across namespaces.
Supports propagating a FUSE mount point from a non-privileged sidecar container to an application container. This provides a FUSE-based solution for remote storage in cloud-native scenarios.
-
Resolves memory bloat issues caused by Transparent Huge Pages (THP).
While THP improves performance, it can also cause memory bloat. Memory bloat can lead to Out of Memory (OOM) errors. For example, an application may only need two small pages, which is 8 KiB of memory, but the kernel allocates one transparent huge page. In this case, the remaining memory in the transparent huge page (510 small pages) is all zeros, except for the memory the application actually needs. This can increase the Resident Set Size (RSS) memory usage and eventually cause an OOM error.
THP Zero Subpage Reclamation (ZSR) is designed to solve this memory bloat problem. When the kernel reclaims memory, this feature splits the transparent huge page into small pages and reclaims the all-zero subpages. This prevents rapid memory bloat from causing OOM errors.
-
-
-
System configuration updates
-
Sets
tcp_max_tw_bucketsto 5000. -
Changes the default character set for mounting the
vfatfile system toiso8859-1.
-
-
Package updates
-
Includes
aliyun-cliby default. -
Includes
container-selinuxby default. -
Adds the
anolis-epao-releasepackage. This allows Alibaba Cloud Linux 3 to use the Anolis OS epao repository to install applications such as AI tools.
-
Fixed issues
-
Fixed an issue that prevented the rngd.service from starting on Alibaba Cloud Linux 3 arm64 images.
-
Backported a community mainline fix to address a cgroup leak that occurs when a process fork fails.
-
Fixed a permission issue in overlayfs that occurred when a file or directory without read permission was accessed on a filesystem where all upperdir and lowerdir directories resided. A logic error in a previous performance optimization caused ovl_override_creds() to run incorrectly, preventing permissions from being elevated to those of the mounter. Consequently, the copy-up operation failed due to insufficient permissions.
-
Backported multiple fuse bug fixes from the community mainline to improve stability.
-
Backported multiple community mainline bug fixes for ext4 with the bigalloc feature enabled, significantly reducing online resizing time.
-
Backported a community mainline fix to prevent a potential data consistency issue caused by CONT-PTE/PMD.
-
Fixed an issue where resctrl did not work correctly on AMD instances.
-
Improved the stability of the IAX hardware compression and decompression accelerator.
-
Fixed CRC validation failures in the IAX hardware compression and decompression accelerator.
-
Fixed memory corruption caused by improper use of the swap_info_struct lock during highly concurrent swapoff and swapon operations. This fix has been merged into the community mainline.
-
Addressed an issue where the in-house zombie memcg reaper feature was ineffective in one-shot mode.
-
Addressed a potential stability issue with the MPAM memory bandwidth monitoring feature on Yitian 710 processors.
Image update
-
Container image
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.8
-
alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest
NoteOnce a new version is released, the
latesttag no longer points to the 3.8 image.
-
Known issues
ANCK 5.10-015 incorporates a scheduler wakeup optimization from the upstream community. This change may cause a performance regression in certain edge cases, such as benchmarks under heavy load. However, this regression does not affect typical user workloads.
Alibaba Cloud Linux 3.2104 U7
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U7 |
aliyun_3_x64_20G_alibase_20230516.vhd |
2023-05-16 |
|
|
aliyun_3_arm64_20G_alibase_20230515.vhd |
2023-05-15 |
|
Updates
-
Fixed kernel bugs and addressed critical security vulnerabilities (CVEs).
-
Added support for the multi-pcp feature to improve network packet reception performance by bypassing the buddy system's global lock.
The multi-pcp feature improves network packet reception by reserving per-core memory pages with an order greater than 0. This avoids allocations through the zone buddy system for high-order memory pages, which bypasses the buddy system's global lock.
-
Enabled the Intel IAA accelerator driver to improve compression and decompression performance.
The In-Memory Analytics Accelerator (IAA) is a hardware accelerator that combines basic data analytics functions with high-throughput compression and decompression. The driver code is adapted from the Intel code repository and includes bug fixes and modifications for ANCK.
-
Fixed an issue that caused silent data loss in shmem and hugetlb file systems due to page cache truncation.
Previously, when a faulted page in a shmem or hugetlb file system was removed from the page cache, a subsequent access to that page's offset would allocate a new zero page, resulting in silent data loss. This update prevents silent data loss from page faults in shmem/tmpfs and hugetlb file systems.
-
Added support for the CoreSight ETE driver and the tools/perf utility.
-
Enhanced the signal handling mechanism in the KVM module on ARM64 platforms to prevent system crashes in scenarios such as RAS.
If the CPU does not process the
TIF_NOTIFY_RESUMEflag before entering Guest mode, frequent RAS events can trigger exceptions and cause a system crash. This update implements the full generic entry infrastructure on ARM64 platforms to correctly handle pending task work. -
Synchronized the CMN/DRW driver with the upstream Linux community version, added debugfs support, and fixed related bugs.
Before version 5.10-014, the CMN/DRW driver diverged from the upstream Linux community version. To reduce future maintenance costs, version 5.10-014 synchronizes the driver with the upstream version and adds compatibility for the CMN700 on Yitian 710. This update also adds debugfs support and fixes, allowing you to view the CMN topology in user mode.
-
Added support for machine check exception (MCE) recovery for copy on write (COW) in kernel mode on x86 platforms.
Previously, an uncorrectable error during a kernel copy on write (COW) operation would cause a system crash because the kernel lacked a recovery handler for such errors. This feature adds a recovery handler that sends a
SIGBUSsignal to the application to prevent a system crash. -
Added support for top-down performance analysis using perf metrics to improve CPU PMU usability.
Before version 5.10-014, perf metrics and top-down analysis were not supported. To improve CPU PMU usability and help users identify CPU performance bottlenecks, version 5.10-014 adds support for perf metrics and top-down analysis for Yitian 710, Kunpeng, and x86 platforms.
-
Added support for UDP Segment Offloading (USO) to virtio-net.
Compared with UDP Fragment Offloading (UFO), USO improves packet reception performance and the forwarding performance of forwarding components in complex network environments. Starting from version 5.10-014, virtio-net supports USO. In business scenarios where the network conditions are unstable and incast or burst traffic is pronounced, USO can effectively reduce the packet loss rate caused by fragment reassembly and reduce the overhead of fragment reassembly on the receiver. In addition, packet loss and out-of-order packets reduce the efficiency of forwarding components by forcing fragment reassembly, an issue that USO effectively mitigates.
-
Fixed an issue that caused virtual address space exhaustion on the aarch64 architecture due to an unimplemented
pci_iounmapfunction.Before version 5.10-014, the
pci_iounmapfunction had an empty implementation becauseCONFIG_GENERIC_IOMAPwas not configured. This prevented the system from releasing mapped memory, which led to virtual address space exhaustion. Version 5.10-014 fixes this issue by correctly implementing thepci_iounmapfunction. -
Added support for high-performance ublk.
ublk is a high-performance user mode block device that is implemented based on the
io_uringpassthrough mechanism. It allows agents to efficiently access distributed storage. -
Added support for the following proprietary technologies of Alibaba Cloud:
-
Added a feature to lock code segments at the system-wide or memcg level.
When the memory usage is higher than the low watermark, memory reclaim is triggered. During memory reclaim, the memory that holds code segments for critical applications may be reclaimed. As the applications run, the memory is reloaded from the disk. Frequent I/O operations increase the response latency of critical services and cause performance jitter. This feature prevents this issue by locking the code segment memory of critical applications within a specified cgroup to make the memory non-reclaimable. This feature also adds a quota that you can configure as a percentage to limit the amount of locked code segment memory.
-
Introduced a page cache usage limit to resolve Out of Memory (OOM) issues caused when the page cache grows faster than it is reclaimed.
In containerized scenarios, the memory available to containers is limited. If the page cache consumes too much memory and triggers memory reclaim, an Out of Memory (OOM) error can occur if the reclaim rate is slower than the application's growing memory demand. This severely impacts application performance. This feature resolves this issue by limiting the page cache size for a container and proactively reclaiming memory that exceeds the limit. The solution supports cgroup-level and global page cache limits and offers both synchronous and asynchronous reclamation methods for flexibility.
-
Added support for dynamic CPU isolation.
CPU isolation assigns different CPU cores or sets of cores to different tasks to prevent them from competing for CPU resources, which improves overall system performance and stability. You can isolate a subset of CPUs for critical tasks while other tasks share the remaining CPUs. However, the number of critical tasks can change during runtime. Isolating too many CPUs wastes resources and increases costs. This feature allows you to dynamically adjust the CPU isolation scope to better utilize CPU resources, save costs, and improve overall workload performance.
-
Added support for CPU Burst and tiered memory-low watermarks in cgroup v2.
To promote the adoption of cgroup v2, this update adds interfaces for proprietary ANCK features in cgroup v2, including CPU Burst and tiered memory-low watermarks.
-
Enabled XDP sockets to allocate virtual memory for queues to prevent allocation failures caused by memory fragmentation.
By default, XDP sockets use the
__get_free_pages()function to allocate contiguous physical memory. If memory is severely fragmented, the allocation can fail, which prevents the XDP socket from being created. This feature uses thevmalloc()function to allocate memory, which reduces the likelihood of XDP socket creation failure.
-
Alibaba Cloud Linux 3.2104 U6.1
|
Version |
Image id |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2104 U6.1 |
aliyun_3_x64_20G_alibase_20230424.vhd |
2023-04-24 |
|
|
aliyun_3_arm64_20G_alibase_20230424.vhd |
2023-04-24 |
|
|
|
aliyun_3_x64_20G_alibase_20230327.vhd |
2023-03-27 |
|
|
|
aliyun_3_arm64_20G_alibase_20230327.vhd |
2023-03-27 |
|
Alibaba Cloud Linux 3.2104 U6
|
Version |
Image ID |
Release date |
Description |
|
Alibaba Cloud Linux 3.2104 U6 |
aliyun_3_x64_20G_qboot_alibase_20230214.vhd |
2023-02-14 |
|
|
aliyun_3_x64_20G_dengbao_alibase_20230214.vhd |
2023-02-14 |
|
|
|
aliyun_3_arm64_20G_dengbao_alibase_20230214.vhd |
2023-02-14 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20230214.vhd |
2023-02-14 |
|
|
|
aliyun_3_x64_20G_alibase_20230110.vhd |
2023-01-10 |
|
|
|
aliyun_3_arm64_20G_alibase_20230110.vhd |
2023-01-10 |
|
2022
|
Version |
Image id |
Release date |
Updates |
|
Alibaba Cloud Linux 3.5.2 |
aliyun_3_x64_20G_alibase_20221118.vhd |
2022-11-18 |
Updates the |
|
aliyun_3_arm64_20G_alibase_20221118.vhd |
2022-11-18 |
Updates the |
|
|
aliyun_3_x64_20G_alibase_20221102.vhd |
2022-11-02 |
|
|
|
aliyun_3_arm64_20G_alibase_20221102.vhd |
2022-11-02 |
|
|
|
Alibaba Cloud Linux 3.5 |
aliyun_3_x64_20G_alibase_20220907.vhd |
2022-09-07 |
|
|
aliyun_3_arm64_20G_alibase_20220907.vhd |
2022-09-07 |
|
|
|
aliyun_3_x64_20G_dengbao_alibase_20220914.vhd |
2022-09-14 |
|
|
|
aliyun_3_x64_20G_qboot_alibase_20220907.vhd |
2022-09-07 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20220907.vhd |
2022-09-07 |
|
|
|
Alibaba Cloud Linux 3.4.2 |
aliyun_3_arm64_20G_alibase_20220819.vhd |
2022-08-19 |
|
|
aliyun_3_x64_20G_alibase_20220815.vhd |
2022-08-15 |
|
|
|
Alibaba Cloud Linux 3.4.1 |
aliyun_3_x64_20G_alibase_20220728.vhd |
2022-07-28 |
|
|
aliyun_3_arm64_20G_alibase_20220728.vhd |
2022-07-28 |
|
|
|
Alibaba Cloud Linux 3.4 |
aliyun_3_2104_x64_20G_dengbao_alibase_20220601.vhd |
2022-06-01 |
|
|
aliyun_3_x64_20G_alibase_20220527.vhd |
2022-05-27 |
|
|
|
aliyun_3_x64_20G_qboot_alibase_20220527.vhd |
2022-05-27 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20220527.vhd |
2022-05-27 |
|
|
|
aliyun_3_arm64_20G_alibase_20220526.vhd |
2022-05-26 |
|
|
|
Alibaba Cloud Linux 3.3.4 |
aliyun_3_x64_20G_alibase_20220413.vhd |
2022-04-13 |
|
|
aliyun_3_arm64_20G_alibase_20220413.vhd |
2022-04-13 |
|
|
|
Alibaba Cloud Linux 3.3.3 |
aliyun_3_x64_20G_alibase_20220315.vhd |
2022-03-15 |
|
|
aliyun_3_arm64_20G_alibase_20220315.vhd |
2022-03-15 |
|
|
|
Alibaba Cloud Linux 3.3.2 |
aliyun_3_x64_20G_alibase_20220225.vhd |
2022-02-25 |
|
|
aliyun_3_x64_20G_qboot_alibase_20220225.vhd |
2022-02-25 |
|
|
|
aliyun_3_x64_20G_scc_alibase_20220225.vhd |
2022-02-25 |
|
|
|
aliyun_3_arm64_20G_alibase_20220225.vhd |
2022-02-25 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20220225.vhd |
2022-02-25 |
|
2021
|
Version |
Image ID |
Release date |
Updates |
|
Alibaba Cloud Linux 3.2 |
aliyun_3_x64_20G_qboot_alibase_20211214.vhd |
2021-12-14 |
|
|
aliyun_3_x64_20G_scc_alibase_20211018.vhd |
2021-10-18 |
|
|
|
aliyun_3_x64_20G_alibase_20210910.vhd |
2021-09-10 |
|
|
|
aliyun_3_arm64_20G_alibase_20210910.vhd |
2021-09-10 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20210910.vhd |
2021-09-10 |
|
|
|
Alibaba Cloud Linux 3.1 |
aliyun_3_arm64_20G_alibase_20210709.vhd |
2021-07-09 |
|
|
aliyun_3_x64_20G_scc_alibase_20210806.vhd |
2021-08-06 |
|
|
|
aliyun_3_x64_20G_alibase_20210425.vhd |
2021-04-25 |
|
|
|
aliyun_3_x64_20G_uefi_alibase_20210425.vhd |
2021-04-25 |
|
|
|
Alibaba Cloud Linux 3.0 |
aliyun_3_x64_20G_alibase_20210415.vhd |
2021-04-15 |
|
Related documents
-
Third-party and open-source public image release notes
-
Use the latest Alibaba Cloud Linux 3 image to create an instance.