Alibaba Cloud Linux 3 Image Release Notes

更新时间:
复制 MD 格式

Alibaba Cloud regularly updates the Alibaba Cloud Linux 3 image with the latest operating system features, capabilities, and security patches. This topic lists the latest image versions and their release notes.

Background

  • Unless otherwise specified, updates apply to ECS in all available regions.

  • Alibaba Cloud Linux 3 images are compatible with most instance families. However, some images support only specific instance families, as follows:

    • SCC images (image IDs containing _scc_) support only the sccg7 and sccc7 instance families.

    • ARM images (image IDs containing _arm64_) support all ARM-based instances on Alibaba Cloud.

2026

Alibaba Cloud Linux 3.2104 U13.1

Version

Image ID

Release date

Key changes

Alibaba Cloud Linux 3.2104 U13.1

aliyun_3_x64_20G_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

aliyun_3_x64_20G_dengbao_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

aliyun_3_x64_20G_container_optimized_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3 64-bit Container-Optimized Edition base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

aliyun_3_arm64_20G_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit (ARM) base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

aliyun_3_arm64_20G_dengbao_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit (ARM) MLPS 2.0 Level 3 base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

aliyun_3_arm64_20G_container_optimized_alibase_20260513.vhd

2026-05-13

  • Updated the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

  • Updated the Alibaba Cloud Linux 3 64-bit Container-Optimized Edition (ARM) base image.

  • Fixed CVE-2024-31431 and CVE-2024-43284.

Updates

Highlights

Kernel

This release updates the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.5.al8.

New features

  1. [Storage] Introduced I/O attribute passthrough for guests. In Virtio-blk and NVMe scenarios, I/O read and write operations can pass request-level I/O flags to the back end. This enables the back end to identify the I/O model and optimize performance.

  2. [Storage] Enhanced ublk capabilities by aligning the ublk code base with the 6.6 upstream mainline.

  3. [Driver/Security] Added TSM API support.

Bug fixes

  1. Fixed an issue in the IPv4 network module where incorrect matching logic for RAW sockets in ICMP error handling caused network communication issues, such as traceroute failures.

  2. mm: Fixed an issue that prevented a large number of ext4_inode_cache entries from being reclaimed.

  3. fs/ext4: Fixed an issue that could trigger file system exceptions during the split extent process.

  4. cgroup/writeback: Fixed a race condition in cgroup writeback v1 radix tree operations.

  5. Fixed an issue where a soft lockup could be triggered during an unmount operation in scenarios with a large number of mount points.

  6. cgroup: Fixed an issue in the enhanced block throttle statistics where io_start_time_ns was not correctly set for throttled requests.

CVE fixes

CVE-2024-31402

CVE-2024-23455

CVE-2024-31399

CVE-2024-23450

CVE-2024-23420

CVE-2024-23456

CVE-2024-23449

CVE-2024-23457

CVE-2024-23452

CVE-2024-23038

CVE-2023-54068

CVE-2024-23398

Package updates

New features

  • Cloud application component updates:

    • Updated aliyun-cli from aliyun-cli-3.2.12-1.al8 to aliyun-cli-3.3.14-1.al8. This update is included in the image.

    • Updated ossfs from ossfs-1.91.8-1.al8 to ossfs-1.91.9-1.al8. This update is available in the yum repo.

  • OS-level capability enhancements:

    • Updated alinux-release from alinux-release-3.2104.13-1.al8 to alinux-release-3.2104.13.1-1.al8, which indicates the release of Alibaba Cloud Linux 3.2104 U13.1. This update is included in the image.

    • Updated kpatch from kpatch-0.9.7-2.0.4.al8 to kpatch-0.9.7-2.0.5.al8 and added the khotfix-view tool. This update is available in the yum repo.

    • Updated tzdata from tzdata-2025c-1.0.1.1.al8 to tzdata-2026a-1.0.1.1.al8. This update is included in the image.

  • Updates to in-house components:

    • Feature updates for cai:

      • Updated cryptpilot from cryptpilot-0.3.4-1.al8 to cryptpilot-0.7.0-1.al8. This update is available in the yum repo.

      • Updated trusted-network-gateway from trusted-network-gateway-2.4.0-1.al8 to trusted-network-gateway-2.5.0-1.al8. This update is available in the yum repo.

      • Updated trustee from trustee-1.7.6-1.al8 to trustee-1.8.3-1.al8. This update is available in the yum repo.

      • Updated trustiflux from trustiflux-1.4.8-1.al8 to trustiflux-1.5.0-1.al8. This update is available in the yum repo.

    • Java ecosystem updates:

      • Updated java-1.8.0-alibaba-dragonwell from 8.20.21.422 to 8.28.27.482. This update is available in the yum repo.

      • Updated java-11-alibaba-dragonwell from 11.0.24.21.21 to 11.0.30.27.27. This update is available in the yum repo.

      • Updated java-21-alibaba-dragonwell from 21.0.5.0.5 to 21.0.10.0.10. This update is available in the yum repo.

    • System O&M updates:

      • Updated sysak from sysak-3.10.0-1 to sysak-3.13.0-1. This update is included in the image.

Feature enhancements from Anolis OS 8:

Three components are synchronized from Anolis OS 8 and updated via the yum repo: java-1.8.0-openjdk-portable, java-17-openjdk-portable, and tzdata.

CVE fixes

This release fixes 106 unique CVEs across 51 packages. Key fixes include:

  • freerdp: Fixed 15 CVEs (CVE-2024-22852, CVE-2024-22854, CVE-2024-22856, CVE-2024-23490, CVE-2024-23732, CVE-2024-23865, CVE-2024-23868, CVE-2024-23893, CVE-2024-23948, CVE-2024-24491, CVE-2024-24675, CVE-2024-24676, CVE-2024-24679, CVE-2024-24681, CVE-2024-24683)

  • golang: Fixed 8 CVEs (CVE-2024-61731, CVE-2024-25679, CVE-2024-26955, CVE-2024-26965, CVE-2024-27140, CVE-2024-27143, CVE-2024-27144, CVE-2024-27622)

  • gstreamer1-plugins-base: Fixed 7 CVEs (CVE-2024-2920, CVE-2024-2921, CVE-2024-2922, CVE-2024-2923, CVE-2024-3082, CVE-2024-3083, CVE-2024-3085)

  • java-1.8.0-openjdk: Fixed 7 CVEs (CVE-2024-22007, CVE-2024-22013, CVE-2024-22016, CVE-2024-22018, CVE-2024-22021, CVE-2024-4111, CVE-2024-4177)

  • gstreamer1-plugins-good: Fixed 6 CVEs (CVE-2024-2920, CVE-2024-2921, CVE-2024-2922, CVE-2024-2923, CVE-2024-3082, CVE-2024-3083)

  • mysql: Fixed 6 CVEs (CVE-2024-21936, CVE-2024-21937, CVE-2024-21941, CVE-2024-21948, CVE-2024-21964, CVE-2024-21968)

  • openssh: Fixed 6 CVEs (CVE-2024-3497, CVE-2024-35385, CVE-2024-35386, CVE-2024-35387, CVE-2024-35388, CVE-2024-35414)

  • fontforge: Fixed 4 CVEs (CVE-2024-15269, CVE-2024-15270, CVE-2024-15275, CVE-2024-15279)

  • gimp: Fixed 4 CVEs (CVE-2024-0797, CVE-2024-2044, CVE-2024-2045, CVE-2024-2048)

  • nodejs: Fixed 4 CVEs (CVE-2024-21710, CVE-2024-26996, CVE-2024-27135, CVE-2024-27904)

  • python3: Fixed 4 CVEs (CVE-2024-0938, CVE-2024-4519, CVE-2024-4786, CVE-2024-11234)

  • vim: Fixed 4 CVEs (CVE-2024-28417, CVE-2024-28421, CVE-2024-33412, CVE-2024-33526)

  • tigervnc: Fixed 4 CVEs (CVE-2024-33999, CVE-2024-34001, CVE-2024-34003, CVE-2024-34352)

  • buildah, podman, and containernetworking-plugins: Fixed 3 CVEs (CVE-2024-61726, CVE-2024-61728, CVE-2024-68121)

  • libpng and mingw-libpng: Fixed 3 CVEs (CVE-2024-22695, CVE-2024-22801, CVE-2024-25646)

  • postgresql: Fixed 3 CVEs (CVE-2024-2004, CVE-2024-2005, CVE-2024-2006)

  • xorg-x11-server and xorg-x11-server-Xwayland: Fixed 3 CVEs (CVE-2024-33999, CVE-2024-34001, CVE-2024-34003)

  • sudo: Fixed 1 CVE (CVE-2024-35535)

  • libtiff: Fixed 1 CVE (CVE-2024-4775)

  • libxml2: Fixed 1 CVE (CVE-2024-9714)

This release changes a total of 67 source packages: 54 synchronized from Anolis OS 8 and 13 developed in-house for Alibaba Cloud Linux 3. No ABI changes are introduced.

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.2

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.2

aliyun_3_x64_20G_alibase_aiext_0.5.5.2_20260507.vhd

2026-05-08

  • Updates the kernel to kernel-5.10.134-19.201.al8 to fix CVE-2026-31431.

Alibaba Cloud Linux 3 AI Extension ARM Edition 0.5.5.2

aliyun_3_arm64_20G_alibase_aiext_0.5.5.2_20260507.vhd

2026-05-08

  • Updates the kernel to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

Updates

Important updates

  1. Kernel:

    1. Updates the x86_64 kernel to kernel-5.10.134-19.201.al8 to fix CVE-2026-31431.

    2. Updates the aarch64 kernel to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  2. Image:

    1. Updates kmod-fuse to kmod-fuse-5.10.134~19.201-1.2.4.6~2.al8 in the x86_64 image.

    2. Updates kmod-fuse to kmod-fuse-5.10.134~19.3.1-1.2.4.6~1.al8 in the aarch64 image.

Security updates

Package name

CVE ID

Updated version

kernel

kernel-5.10.134-19.3.al8.aarch64

kernel-5.10.134-19.201.al8.x86_64

CVE-2026-31431

gnutls

gnutls-3.6.16-8.0.2.al8.5

CVE-2025-14831

CVE-2025-9820

libarchive

libarchive-3.5.3-7.al8

CVE-2026-4111

util-linux

libblkid-2.32.1-48.0.1.4.al8

libfdisk-2.32.1-48.0.1.4.al8

libmount-2.32.1-48.0.1.4.al8

libsmartcols-2.32.1-48.0.1.4.al8

libuuid-2.32.1-48.0.1.4.al8

util-linux-2.32.1-48.0.1.4.al8

util-linux-user-2.32.1-48.0.1.4.al8

CVE-2025-14104

python3

python3-libs-3.6.8-75.0.1.1.al8

platform-python-3.6.8-75.0.1.1.al8

platform-python-devel-3.6.8-75.0.1.1.al8

CVE-2025-0938

CVE-2026-4519

openssh

openssh-8.0p1-28.0.1.1.al8

openssh-clients-8.0p1-28.0.1.1.al8

openssh-server-8.0p1-28.0.1.1.al8

CVE-2026-3497

vim

vim-common-8.0.1763-22.0.1.al8.1

vim-enhanced-8.0.1763-22.0.1.al8.1

vim-filesystem-8.0.1763-22.0.1.al8.1

vim-minimal-8.0.1763-22.0.1.al8.1

CVE-2026-28417

CVE-2026-28421

CVE-2026-33412

Alibaba Cloud Linux 3.2104 U13.0

Version number

Image ID

Release date

Changes

Alibaba Cloud Linux 3.2104 U13.0

aliyun_3_x64_20G_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest software versions.

aliyun_3_x64_20G_dengbao_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image to the latest software versions.

aliyun_3_x64_20G_container_optimized_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3 64-bit container-optimized version base image to the latest software versions.

aliyun_3_arm64_20G_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version base image to the latest software versions.

aliyun_3_arm64_20G_dengbao_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version MLPS 2.0 Level 3 base image to the latest software versions.

aliyun_3_arm64_20G_container_optimized_alibase_20260503.vhd

2026-05-03

  • Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

  • Updated the Alibaba Cloud Linux 3 64-bit container-optimized ARM version base image to the latest software versions.

Updates

Highlights

Kernel

Upgraded the kernel from kernel-5.10.134-19.3.al8 to kernel-5.10.134-19.3.1.al8 to fix CVE-2026-31431.

Feature updates

Software package

Previous version

New version

Description

alinux-release

alinux-release-3.2104.13-1.al8

alinux-release-3.2104.13-2.al8

Updated the image version identifier package. No functional impact.

aliyun-cli

aliyun-cli-3.2.12-1.al8

aliyun-cli-3.3.4-1.al8

A bug-fix release of an Alibaba Cloud proprietary component. No impact on system stability.

sysak

sysak-3.10.0-1

sysak-3.12.0-1

Updated an O&M component. This update has a low impact on system stability.

Bug fixes

Upgraded vim from 8.0.1763-22.0.1.al8 to 8.0.1763-22.0.1.al8.1, which includes six patches fixing issues including crash recovery, command injection, and netrw port handling.

Alibaba Cloud Linux 3.2104 U13

Version

Image ID

Release date

Release notes

Alibaba Cloud Linux 3.2104 U13

aliyun_3_x64_20G_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest version.

aliyun_3_x64_20G_dengbao_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image to the latest version.

aliyun_3_x64_20G_container_optimized_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3 64-bit container-optimized version base image to the latest version.

aliyun_3_arm64_20G_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version base image to the latest version.

aliyun_3_arm64_20G_dengbao_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version MLPS 2.0 Level 3 base image to the latest version.

aliyun_3_arm64_20G_container_optimized_alibase_20260326.vhd

2026-03-26

  • Upgraded the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

  • Updated software in the Alibaba Cloud Linux 3 64-bit container-optimized version (ARM) base image to the latest version.

Highlights

Kernel

This release updates the kernel from kernel-5.10.134-19.2.al8 to kernel-5.10.134-19.3.al8.

New features

  1. Adds support for hiding mount points for rich containers, allowing mountinfo to modify information about specified mount points.

  2. Adds sysinfo syscall handling for rich containers, allowing them to replace lxcfs functionality.

Important bug fixes

  1. Adds support for Runtime Measurement Registers (RTMR) and attestation for CSV3 virtual machines.

  2. Fixes issues in fs_dax and swiotlb.

  3. Adds support for the Hygon family 18h model 8h PMU.

  4. Fixes the EDAC address translation for Hygon family 18h model 4h.

  5. Fixes issues with the EDAC functionality for Hygon family 18h model 4h.

  6. Fixes a bug that caused the EDAC module to report a memory translation failure after a correctable error (CE) was injected into a Hygon Gen 2 machine.

  7. Fixes issues related to the x86 TSC.

  8. Fixes issues with the RAS functionality for Hygon family 18h model 6h.

CVE fixes

CVE-2025-38502

CVE-2024-49861

CVE-2024-26809

CVE-2025-40215

CVE-2025-39964

CVE-2025-38000

CVE-2024-58240

CVE-2025-38001

CVE-2024-57947

CVE-2024-26924

CVE-2023-5197

CVE-2024-26583

CVE-2024-26584

CVE-2025-21756

CVE-2025-37797

CVE-2025-21971

CVE-2025-40019

CVE-2025-40018

CVE-2025-38678

CVE-2025-38618

CVE-2025-38617

CVE-2025-38477

CVE-2025-38177

CVE-2025-38083

CVE-2025-37997

CVE-2025-37798

CVE-2025-37756

CVE-2024-53164

CVE-2024-26921

CVE-2023-52620

CVE-2025-37798

CVE-2025-37756

CVE-2024-53164

CVE-2024-26921

CVE-2023-52620

CVE-2025-37890

CVE-2025-39682

CVE-2025-39946

CVE-2025-40214

CVE-2025-40297

Drivers

  • Updates kmod-udma from kmod-udma-5.10.134~18-0.1.0~1.al8 to kmod-udma-5.10.134~19.2-0.1.0~1.al8 to fix an issue where the udma driver was missing in version 19.

  • Replaces kmod-intel-QAT20 with kmod-QAT20-5.10.134~19.3-L.1.2.30__00090~1.al8 on x86 platforms to provide the QAT driver.

Package updates

New features

  • Cloud application component updates:

    • The aliyun-cli component is updated in the image from aliyun-cli-3.2.0-1.al8 to aliyun-cli-3.2.6-1.al8.

  • OS-level capability enhancements:

    • The alinux-release component is updated in the image from alinux-release-3.2104.12-1.al8 to alinux-release-3.2104.13-1.al8, marking the release of Alinux 3.13.

    • The glibc component is updated in the image from glibc-2.32-1.22.al8 to glibc-2.32-1.23.al8 to improve performance on HYGON platforms.

    • The util-linux component is updated from util-linux-2.32.1-46.0.4.1.al8 to util-linux-2.32.1-48.0.1.4.al8, enabling the fstrim service in the ECS image.

    • The alinux-base-setup component is updated in the image from alinux-base-setup-3.2-11.al8 to alinux-base-setup-3.2-14.al8. This update enables the selinux-autorelabel-mark.service and fstrim.timer services to resolve an issue where SSH becomes unavailable after SELinux is enabled and to enable the scheduled fstrim storage task.

    • The dnf-plugin-kernel-install component is updated in the image from dnf-plugin-kernel-install-1.0-2.al8 to dnf-plugin-kernel-install-1.0-5.al8. This update provides a convenient tool for managing multiple kernels and automatically parsing kernel versions.

    • The edk2 component is updated in the yum repo from edk2-20220126gitbb1bba3d77-13.0.1.al8.7 to edk2-20220126gitbb1bba3d77-13.0.1.al8.8 to support the HYGON CSV3 dynamic measurement feature on QEMU.

    • The qemu-kvm component is updated in the yum repo from qemu-kvm-6.2.0-53.0.8.al8.4 to qemu-kvm-6.2.0-53.0.8.1.al8.5 to support the HYGON CSV3 dynamic measurement feature on QEMU.

    • The gnome-control-center component is updated in the yum repo from gnome-control-center-40.0-32.1.al8 to gnome-control-center-40.0-32.3.al8 to support domestic platforms.

  • Updates to in-house components:

    • Updates to kernel-related components:

      • Introduces ras-tools-0.2-2.al8, a toolset for Reliability, Availability, and Serviceability (RAS) monitoring and diagnostics. This toolset collects and analyzes hardware error information on Linux systems, such as memory ECC errors, PCIe AER, and CPU Machine Check events. This update is available in the yum repo.

    • Feature updates for cai:

      • The cryptpilot component is updated in the yum repo from cryptpilot-0.2.7-1.al8 to cryptpilot-0.3.4-1.al8.

      • The trusted-network-gateway component is updated in the yum repo from trusted-network-gateway-2.2.6-1.al8 to trusted-network-gateway-2.4.0-1.al8.

      • The trustee component is updated in the yum repo from trustee-1.7.0-1.al8 to trustee-1.7.6-1.al8.

      • The trustiflux component is updated in the yum repo from trustiflux-1.4.4-1.al8 to trustiflux-1.4.8-1.al8.

    • os-copilot updates:

      • The os-copilot component is updated in the yum repo from os-copilot-0.9.1-1.al8 to os-copilot-1.1.0-2.al8. This update introduces a multi-agent architecture to improve complex task processing, adds support for specifying backend Model Studio models and custom invocation parameters, and allows for custom MCP servers.

    • System operations updates:

      • The sysak component is updated in the yum repo from sysak-3.8.1-1 to sysak-3.10.0-1.

Feature enhancements from Anolis OS 8:

This release includes six updated components: one in the image and five via the yum repo. The following table details the changes.

Component name

Previous version

New version

Reason for update

Update method

java-1.8.0-openjdk-portable

java-1.8.0-openjdk-portable-1.8.0.472.b08-1.0.1.1.al8

java-1.8.0-openjdk-portable-1.8.0.482.b08-1.0.1.1.al8

Enables system FreeType and adds it to _privatelibs in a higher JDK version.

Available in the yum repo.

java-17-openjdk-portable

java-17-openjdk-portable-17.0.16.0.8-1.0.1.1.al8

java-17-openjdk-portable-17.0.18.0.8-1.0.2.1.al8

Updates the bundled libpng version. Provides: bundled(libpng) = 1.6.51.

Available in the yum repo.

osbuild

osbuild-141.2-1.0.1.al8

osbuild-158-1.0.1.al8

Improves build speed and stability through parallelized builds, caching, and resource isolation. Fixes compatibility issues with SELinux and Btrfs, addresses CVEs, enhances image signature verification, optimizes the osbuild-composer interface, and improves distributed build scheduling.

Available in the yum repo.

rasdaemon

rasdaemon-0.6.7-16.5.al8

rasdaemon-0.8.3-2.al8

Records the cause of the last CPU UE failure, logs CPU socket information, and distinguishes between CE, UE, and DE fault types in the logs.

Available in the yum repo.

sos

sos-4.8.2-1.0.1.1.al8

sos-4.10.0-4.0.1.1.al8

Improves postproc library obfuscation in two ways.

Available in the yum repo.

tzdata

tzdata-2025b-1.0.1.1.al8

tzdata-2025c-1.0.1.1.al8

Updates the expiration date of the leap second file.

Available in the image.

Bug fix

This release includes 3 bug fixes for Alinux 3. Two of the fixes are in the image and one is in the repo. The updates are as follows:

Component

Previous version

Updated version

Update method

alinux-base-setup

alinux-base-setup-3.2-11.al8

alinux-base-setup-3.2-14.al8

Updated in the image

gcc

gcc-10.2.1-3.8.al8

gcc-10.2.1-3.9.al8

Updated in the image

gcc-toolset-12

gcc-toolset-12-12.0-6.1.al8

gcc-toolset-12-12.0-6.2.al8

Updated in the yum repository

Defect fixes in Anolis OS 8:

This release contains updates for 6 components: five in the image and one in the repo. The updates are as follows:

Component

Previous version

Updated version

Method

coreutils

coreutils-8.30-15.0.3.al8

coreutils-8.30-16.0.1.al8

Updated in the image

dracut

dracut-049-233.git20240115.0.2.1.al8

dracut-049-239.git20251127.0.1.1.al8

Updated in the image

pam

pam-1.3.1-38.al8

pam-1.3.1-39.al8

Updated in the image

selinux-policy

selinux-policy-3.14.3-139.0.1.al8.1

selinux-policy-3.14.3-139.0.1.al8.2

Updated in the image

sudo

sudo-1.9.5p2-1.0.2.al8.1

sudo-1.9.5p2-1.0.2.al8.3

Updated in the image

unixODBC

unixODBC-2.3.7-1.2.al8

unixODBC-2.3.7-2.0.1.al8

Updated in the yum repo

CVE fixes for Anolis OS 8:

This release updates 45 components: nine are included in the image, and 36 are available in the repository. The following list details each update and its reason.

Component

Previous version

Updated version

Fixed CVE-ID

Update method

brotli

brotli-1.0.6-3.1.al8

brotli-1.0.6-4.al8

CVE-2025-6176

Image

cups

cups-2.2.6-64.0.1.al8

cups-2.2.6-66.0.1.al8

CVE-2025-58436

CVE-2025-61915

Image

glib2

glib2-2.68.4-16.0.1.al8.2

glib2-2.68.4-18.0.1.al8.1

CVE-2025-13601

Image

gnupg2

gnupg2-2.2.20-3.al8

gnupg2-2.2.20-4.al8

CVE-2025-68973

Image

libpng

libpng-1.6.34-5.2.al8

libpng-1.6.34-9.al8

CVE-2025-64720

CVE-2025-65018

CVE-2025-66293

Image

nfs-utils

nfs-utils-2.3.3-64.0.1.al8

nfs-utils-2.3.3-68.0.1.al8

CVE-2025-12801

Image

openssl

openssl-1.1.1k-14.0.2.al8

openssl-1.1.1k-15.0.1.al8

CVE-2025-9230

CVE-2025-69419

Image

python-urllib3

python-urllib3-1.24.2-8.al8

python-urllib3-1.24.2-9.al8

CVE-2025-66418

CVE-2025-66471

CVE-2026-21441

Image

python3

python3-3.6.8-71.0.1.1.al8

python3-3.6.8-73.0.1.1.al8

CVE-2025-12084

CVE-2025-15366

CVE-2025-15367

CVE-2026-0865

CVE-2026-1299

Image

buildah

buildah-1.33.12-2.al8

buildah-1.33.14-2.al8

CVE-2025-52881

CVE-2024-24785

CVE-2025-61729

CVE-2025-65637

Yum repository

containernetworking-plugins

containernetworking-plugins-1.4.0-6.0.1.al8

containernetworking-plugins-1.4.0-7.0.1.al8

CVE-2024-24785

CVE-2025-61729

CVE-2025-65637

Yum repository

freerdp

freerdp-2.11.7-1.0.1.al8

freerdp-2.11.7-3.0.1.al8

CVE-2026-23530

CVE-2026-23531

CVE-2026-23532

CVE-2026-23533

CVE-2026-23534

CVE-2026-23883

CVE-2026-23884

Yum repository

gimp

gimp-2.8.22-26.al8.3

gimp-2.8.22-26.al8.4

CVE-2025-14422

Yum repository

git-lfs

git-lfs-3.4.1-5.0.1.al8

git-lfs-3.4.1-8.0.1.al8

CVE-2025-26625

CVE-2025-61729

CVE-2025-61726

CVE-2025-68121

Yum repository

golang

golang-1.25.3-2.0.2.al8

golang-1.25.7-1.0.1.al8

CVE-2025-47906

CVE-2025-58183

CVE-2025-61729

CVE-2025-61726

CVE-2025-61728

CVE-2025-61732

CVE-2025-68121

Yum repository

grafana

grafana-9.2.10-25.0.1.al8

grafana-9.2.10-28.0.1.al8

CVE-2025-58183

CVE-2025-61729

CVE-2025-61726

CVE-2025-61728

CVE-2025-68121

Yum repository

grafana-pcp

grafana-pcp-5.1.1-10.al8

grafana-pcp-5.1.1-12.al8

CVE-2025-61729

CVE-2025-61726

CVE-2025-68121

Yum repository

iperf3

iperf3-3.9-13.al8.1

iperf3-3.9-14.al8.1

CVE-2025-54349

Yum repository

java-1.8.0-openjdk

java-1.8.0-openjdk-1.8.0.472.b08-1.0.1.1.al8

java-1.8.0-openjdk-1.8.0.482.b08-1.0.1.1.al8

CVE-2025-64720

CVE-2025-65018

CVE-2026-21925

CVE-2026-21933

CVE-2026-21945

Yum repository

java-17-openjdk

java-17-openjdk-17.0.17.0.10-1.0.2.1.al8

java-17-openjdk-17.0.18.0.8-1.0.2.1.al8

CVE-2025-64720

CVE-2025-65018

CVE-2026-21925

CVE-2026-21933

CVE-2026-21945

Yum repository

libpq

libpq-13.20-1.0.1.al8

libpq-13.23-1.0.1.al8

CVE-2025-12818

Yum repository

libsoup

libsoup-2.62.3-10.0.1.al8

libsoup-2.62.3-13.0.1.al8

CVE-2025-14523

CVE-2026-0719

CVE-2026-1761

Yum repository

libvpx

libvpx-1.7.0-12.0.1.al8

libvpx-1.7.0-13.0.1.al8

CVE-2026-2447

Yum repository

mariadb

mariadb-10.5.29-2.0.1.al8

mariadb-10.5.29-3.0.1.al8

CVE-2025-13699

Yum repository

mingw-fontconfig

mingw-fontconfig-2.12.6-3.1.al8

mingw-fontconfig-2.12.6-4.al8

CVE-2025-59375

Yum repository

mingw-libpng

mingw-libpng-1.6.29-4.1.al8

mingw-libpng-1.6.34-1.al8

CVE-2025-64720

CVE-2025-65018

CVE-2025-66293

Yum repository

munge

munge-0.5.13-2.1.al8

munge-0.5.13-3.0.1.al8

CVE-2026-25506

Yum repository

net-snmp

net-snmp-5.8-31.0.1.al8

net-snmp-5.8-33.0.1.al8

Evaluation engine order fix

CVE-2025-68615

Yum repository

nodejs

nodejs-20.19.2-1.1.al8

nodejs-20.20.0-1.1.al8

CVE-2025-55130

CVE-2025-55131

CVE-2025-55132

CVE-2025-59465

CVE-2025-59466

CVE-2026-21637

Yum repository

nodejs-packaging

nodejs-packaging-2021.06-4.al8

nodejs-packaging-2021.06-5.al8

CVE-2025-55130

CVE-2025-55131

CVE-2025-55132

CVE-2025-59465

CVE-2025-59466

CVE-2026-21637

Yum repository

open-vm-tools

open-vm-tools-12.3.5-2.al8.1

open-vm-tools-12.3.5-2.al8.2

CVE-2025-22247

Yum repository

osbuild-composer

osbuild-composer-132.2-3.0.1.al8

osbuild-composer-149-3.al8

CVE-2025-58183

Yum repository

pcs

pcs-0.10.18-2.0.1.1.al8.7

pcs-0.10.18-2.0.1.1.al8.8

CVE-2025-67725

CVE-2025-67726

Yum repository

php

php-7.4.33-2.0.1.al8

php-7.4.33-3.0.1.al8

CVE-2024-8929

CVE-2024-11233

CVE-2024-11234

CVE-2025-1217

CVE-2025-1219

CVE-2025-1220

CVE-2025-1734

CVE-2025-1735

CVE-2025-1736

CVE-2025-1861

CVE-2025-6491

CVE-2025-14177

CVE-2025-14178

Yum repository

podman

podman-4.9.4-23.0.1.al8

podman-4.9.4-28.0.1.al8

CVE-2025-52881

CVE-2025-47913

CVE-2024-24785

CVE-2025-61729

CVE-2025-65637

Yum repository

poppler

poppler-20.11.0-12.0.1.al8

poppler-20.11.0-13.0.1.al8

CVE-2025-32365

Yum repository

postgresql

postgresql-13.22-1.0.1.al8

postgresql-13.23-1.0.1.al8

CVE-2025-12817

CVE-2025-12818

Yum repository

python3.11

python3.11-3.11.13-2.0.1.al8

python3.11-3.11.13-4.0.1.al8

CVE-2025-12084

CVE-2025-13836

Yum repository

resource-agents

resource-agents-4.9.0-54.al8.16

resource-agents-4.9.0-54.al8.28

CVE-2025-66418

CVE-2025-66471

CVE-2026-21441

Yum repository

runc

runc-1.2.5-2.al8

runc-1.2.9-3.al8

CVE-2025-52881

Yum repository

skopeo

skopeo-1.14.5-4.0.1.al8

skopeo-1.14.5-6.al8

CVE-2025-52881

Yum repository

spice-client-win

spice-client-win-8.10-1.al8

spice-client-win-8.10-7.al8

CVE-2025-14523

CVE-2026-0719

CVE-2026-1761

Yum repository

toolbox

toolbox-0.0.99.5-2.0.1.al8

toolbox-0.0.99.5.1-1.0.1.al8

CVE-2024-24785

CVE-2025-61729

CVE-2025-65637

Yum repository

transfig

transfig-3.2.6a-4.1.al8

transfig-3.2.6a-5.al8

CVE-2025-46397

Yum repository

vsftpd

vsftpd-3.0.3-36.0.1.al8

vsftpd-3.0.3-36.0.1.al8.3

CVE-2025-14242

Yum repository

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.1

Version

Image ID

Release date

Release notes

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5.1

aliyun_3_x64_20G_alibase_aiext_0.5.5.1_20260326.vhd

2026-03-26

  • Updated kmod-fuse to kmod-fuse-5.10.134~19.200-1.2.4.6~1.al8.

aliyun_3_arm64_20G_alibase_aiext_0.5.5.1_20260326.vhd

2026-03-26

  • Updated kmod-fuse to kmod-fuse-5.10.134~19.3-1.2.4.6~1.al8.

Content updates

Important updates

  1. Kernel: Unchanged from version 0.5.5.

  2. Image: Updated kmod-fuse to version 1.2.4.6 to fix an issue where a process could occasionally enter the uninterruptible sleep (D) state. The issue was caused by a concurrency conflict between cached write operations and setattr (utimes/truncate) calls due to metadata optimization.

Security updates

Package name

CVE ID

Updated version

brotli

brotli-1.0.6-4.al8

CVE-2025-6176

grub2

grub2-common-2.02-170.0.1.1.al8.1

CVE-2025-61662

grub2-efi-x64-2.02-170.0.1.1.al8.1.x86_64

grub2-pc-2.02-170.0.1.1.al8.1.x86_64

grub2-pc-modules-2.02-170.0.1.1.al8.1.noarch

grub2-tools-2.02-170.0.1.1.al8.1

grub2-tools-efi-2.02-170.0.1.1.al8.1.x86_64

grub2-tools-extra-2.02-170.0.1.1.al8.1

grub2-tools-minimal-2.02-170.0.1.1.al8.1

grub2-efi-aa64-2.02-170.0.1.1.al8.1.aarch64

util-linux

libblkid-2.32.1-48.0.1.1.al8

CVE-2025-14104

libfdisk-2.32.1-48.0.1.1.al8

libmount-2.32.1-48.0.1.1.al8

libsmartcols-2.32.1-48.0.1.1.al8

libuuid-2.32.1-48.0.1.1.al8

util-linux-2.32.1-48.0.1.1.al8

util-linux-user-2.32.1-48.0.1.1.al8

nfs-utils

nfs-utils-2.3.3-68.0.1.al8

CVE-2025-12801

libnfsidmap-2.3.3-68.0.1.al8

libpng

libpng-1.6.34-10.al8

CVE-2026-22695

CVE-2026-22801

CVE-2026-25646

python3

python3-libs-3.6.8-73.0.1.1.al8

CVE-2025-12084

CVE-2025-15366

CVE-2025-15367

CVE-2026-0865

CVE-2026-1299

platform-python-3.6.8-73.0.1.1.al8

platform-python-devel-3.6.8-73.0.1.1.al8

openssl

openssl-1.1.1k-15.0.1.al8

CVE-2025-69419

openssl-libs-1.1.1k-15.0.1.al8

vim

vim-common-8.0.1763-22.0.1.al8

CVE-2026-25749

vim-enhanced-8.0.1763-22.0.1.al8

vim-filesystem-8.0.1763-22.0.1.al8

vim-minimal-8.0.1763-22.0.1.al8

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5

Version

Image ID

Release date

Release notes

Alibaba Cloud Linux 3 AI Extension Edition 0.5.5

aliyun_3_0_x64_20G_alibase_aiext_0.5.5_20260203.vhd

2026-02-03

  • Base image: Alibaba Cloud Linux 3 U12.2

  • Upgraded the kernel to 5.10.134-19.200.al8.

aliyun_3_0_arm64_20G_alibase_aiext_0.5.5_20260203.vhd

2026-02-03

  • Base image: Alibaba Cloud Linux 3 U12.2

  • Upgraded the kernel to 5.10.134-19.3.al8.

Updates

Important updates

  1. Upgraded the x86_64 kernel to 5.10.134-19.200.al8.x86_64:

    • Fixed an issue where a microcode hot-patch incorrectly attempted to fix the Zenbleed vulnerability on non-Zen2 architectures.

    • Fixed an issue where downstream devices could be used before their initialization was complete after a PCIe secondary bus reset. This could cause errors or take the devices offline.

    • Fixed a potential crash in the Group Balancer.

    • Fixed an issue that caused unexpected packet loss in virtio_net and vhost under specific conditions.

    • Addressed multiple CVEs. See the table below for details.

  2. Upgraded the aarch64 kernel to 5.10.134-19.3.al8.aarch64:

    • Added support for hiding mount points.

    • Added support for rich containers to replace lxcfs.

    • Addressed multiple CVEs. See the table below for details.

  3. Image updates

    • Updated glibc to glibc-2.32-1.22.al8 to fix an issue where pthread_cond_wait could miss a wakeup signal.

    • Updated systemd to systemd-239-82.0.4.4.al8.5 to fix a race condition between mount and reload operations.

    • Installed kmod-fuse-5.10.134~19.200-1.2.4.5~2.al8 by default on x86_64 images and kmod-fuse-5.10.134~19.3-1.2.4.5~1.al8 on aarch64 images to enhance support for FUSE over io_uring mode.

    • Addressed CVEs in various packages. See the table below for details.

Security updates

Package name

CVE ID

Updated version

kernel

CVE-2025-38502

CVE-2024-49861

CVE-2024-26809

CVE-2025-40215

CVE-2025-39964

CVE-2025-38000

CVE-2024-58240

CVE-2025-38001

CVE-2024-57947

CVE-2024-26924

CVE-2023-5197

CVE-2024-26583

CVE-2024-26584

CVE-2025-21756

CVE-2025-37797

CVE-2025-21971

CVE-2025-40019

CVE-2025-40018

CVE-2025-38678

CVE-2025-38618

CVE-2025-38617

CVE-2025-38477

CVE-2025-38177

CVE-2025-38083

CVE-2025-37997

CVE-2025-37798

CVE-2025-37756

CVE-2024-53164

CVE-2024-26921

CVE-2023-52620

CVE-2025-37890

CVE-2025-39682

CVE-2025-39946

CVE-2025-40214

CVE-2025-40297

kernel-5.10.134-19.200.al8.x86_64

kernel-5.10.134-19.3.al8.aarch64

bind

CVE-2025-8677

CVE-2025-40778

bind-export-libs-9.11.36-16.0.1.al8.6

cups

CVE-2025-58436

CVE-2025-61915

cups-client-2.2.6-66.0.1.al8

cups-libs-2.2.6-66.0.1.al8

curl

CVE-2025-9086

curl-7.61.1-35.0.2.al8.9

libcurl-7.61.1-35.0.2.al8.3

expat

CVE-2013-0340

CVE-2022-23990

CVE-2024-28757

CVE-2025-59375

expat-2.5.0-1.al8

gnutls

CVE-2025-32988

CVE-2025-32990

CVE-2025-6395

gnutls-3.6.16-8.0.2.al8.4

libpng

CVE-2025-64720

CVE-2025-65018

CVE-2025-66293

libpng-1.6.34-9.al8

libssh

CVE-2025-5372

libssh-0.9.6-16.0.1.al8

libssh-config-0.9.6-16.0.1.al8

sssd

CVE-2025-11561

libsss_idmap-2.9.4-5.al8.3

libsss_nss_idmap-2.9.4-5.al8.3

sssd-client-2.9.4-5.al8.3

openssh

CVE-2025-61984

CVE-2025-61985

openssh-8.0p1-27.0.1.1.al8

openssh-clients-8.0p1-27.0.1.1.al8

openssh-server-8.0p1-27.0.1.1.al8

vim

CVE-2025-53905

CVE-2025-53906

vim-common-8.0.1763-21.0.1.al8

vim-enhanced-8.0.1763-21.0.1.al8

vim-filesystem-8.0.1763-21.0.1.al8

vim-minimal-8.0.1763-21.0.1.al8

openssl

CVE-2025-9230

openssl-1.1.1k-14.0.2.al8.0.1

openssl-libs-1.1.1k-14.0.2.al8.0.1

Alibaba Cloud Linux 3.2104 U12.3

Version

Image ID

Release date

Description

Alibaba Cloud Linux 3.2104 U12.2

aliyun_3_x64_20G_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software packages.

aliyun_3_x64_20G_dengbao_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image with the latest software packages.

aliyun_3_x64_20G_container_optimized_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3 64-bit container-optimized edition base image with the latest software packages.

aliyun_3_arm64_20G_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software packages.

aliyun_3_arm64_20G_dengbao_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition MLPS 2.0 Level 3 base image with the latest software packages.

aliyun_3_arm64_20G_container_optimized_alibase_20260122.vhd

2026-01-22

  • Updates the Alibaba Cloud Linux 3 64-bit container-optimized ARM edition base image with the latest software packages.

Package updates

New features

  • Cloud application component updates:

    • The aliyun-cli component in the image has been updated from aliyun-cli-3.1.3-1.al8 to aliyun-cli-3.2.0-1.al8.

  • OS enhancements:

    • The alinux-release component in the image has been updated from alinux-release-3.2104.12.2-4.al8 to alinux-release-3.2104.12.3-1.al8, which marks the release of Alinux 3.12.3.

Bug fixes

Compatibility-related changes:

  • The kexec-tools component is updated from kexec-tools-2.0.26-14.0.1.7.al8.2 to kexec-tools-2.0.26-14.0.1.9.al8.2. This update adds pcie_ports=compat to the kdump cmdline configuration on x86 platforms to fix an issue where kdump hangs on 8th-generation instances.

  • The alinux-base-setup package is updated from alinux-base-setup-3.2-9.al8 to alinux-base-setup-3.2-10.al8. This update adds UUID support in /boot/efi/EFI/alinux/grub.cfg to bind the boot disk and fix boot issues on bare metal systems.

Component

Previous version

Updated version

Update method

glibc

glibc-2.32-1.21.al8

glibc-2.32-1.22.al8

Updated in the image

alinux-base-setup

alinux-base-setup-3.2-9.al8

alinux-base-setup-3.2-10.al8

Updated in the image

grub2

grub2-2.02-165.0.2.al8

grub2-2.02-165.0.2.1.al8

Updated in the image

kexec-tools

kexec-tools-2.0.26-14.0.1.7.al8.2

kexec-tools-2.0.26-14.0.1.9.al8.2

Updated in the image

systemd

systemd-239-82.0.4.4.al8.5

systemd-239-82.0.4.5.al8.5

Updated in the image

grubby

grubby-8.40-49.0.1.al8

grubby-8.40-49.0.1.1.al8

Updated in the image

kpatch

kpatch-0.9.7-2.0.1.al8

kpatch-0.9.7-2.0.4.al8

Updated via yum repository

The following table lists bug fixes from Anolis OS 8.

Component

Previous version

Updated version

Reason for update

Update method

quota

quota-4.09-2.0.1.al8

quota-4.09-4.0.1.al8

Fixes a memory leak.

Updated in the image

intel-ipp-crypto-mb

intel-ipp-crypto-mb-1.0.6-4.al8

intel-ipp-crypto-mb-1.0.6-5.al8

Fixes an issue where qatengine fails to install when the EPEL repository is configured.

Updated via yum repository

qatengine

qatengine-1.2.0-3.al8

qatengine-1.2.0-4.al8

Updated via yum repository

gnome-shell-extensions

gnome-shell-extensions-40.7-19.0.1.al8

gnome-shell-extensions-40.7-29.0.1.al8

Fixes an error in the window list reordering backport, resolves issues with the application grid and the Dash to Panel extension, and makes workspace names more prominent in workspaces.

Updated via yum repository

geoclue2

geoclue2-2.6.0-7.al8

geoclue2-2.6.0-8.al8.1

Migrates user and group management for geoclue2 from manual scripts to a sysusers.d file.

Updated via yum repository

evolution-data-server

evolution-data-server-3.40.4-9.0.1.al8

evolution-data-server-3.40.4-10.0.1.al8

Prevents the signal handler from printing output during execution.

Fixes runtime warnings caused by assertion failures.

Updated via yum repository

gsettings-desktop-schemas

gsettings-desktop-schemas-40.0-7.0.1.al8

gsettings-desktop-schemas-40.0-8.0.1.al8

Adds an option to disable password visibility on the login and lock screens.

Updated via yum repository

pulseaudio

pulseaudio-15.0-2.0.1.al8

pulseaudio-15.0-3.0.1.al8

Fixes an auto-start issue.

Updated via yum repository

The following table lists the CVE updates.

Component

Previous version

Updated version

Fixed CVE ID

Update method

cups

cups-2.2.6-63.0.2.al8

cups-2.2.6-64.0.1.al8

CVE-2025-58364

Updated in the image

curl

curl-7.61.1-35.0.2.al8.3

curl-7.61.1-35.0.2.al8.9

CVE-2025-9086

Updated in the image

openssh

openssh-8.0p1-26.0.1.1.al8

openssh-8.0p1-27.0.1.1.al8

CVE-2025-61984

CVE-2025-61985

Updated in the image

gimp

gimp-2.8.22-26.al8.2

gimp-2.8.22-26.al8.3

CVE-2025-10920

CVE-2025-10921

CVE-2025-10922

CVE-2025-10923

CVE-2025-10924

CVE-2025-10925

CVE-2025-10934

Updated via yum repository

abrt

abrt-2.10.9-24.0.1.al8

abrt-2.10.9-25.0.1.1.al8

CVE-2025-12744

Updated via yum repository

tomcat

tomcat-9.0.87-1.al8.6

tomcat-9.0.87-1.al8.7

CVE-2025-31651

CVE-2025-55752

Updated via yum repository

luksmeta

luksmeta-9-4.1.al8

luksmeta-9-4.2.al8.1

CVE-2025-11568

Updated via yum repository

webkit2gtk3

webkit2gtk3-2.46.6-2.0.1.al8

webkit2gtk3-2.50.4-1.0.1.al8

CVE-2025-43501

CVE-2025-43529

CVE-2025-43531

CVE-2025-43535

CVE-2025-43536

CVE-2025-43541

CVE-2024-44192

CVE-2024-54467

CVE-2024-54551

CVE-2025-13502

CVE-2025-13947

CVE-2025-24189

CVE-2025-24208

CVE-2025-24209

CVE-2025-24216

CVE-2025-30427

CVE-2025-31205

CVE-2025-31257

CVE-2025-31273

CVE-2025-31278

CVE-2025-43211

CVE-2025-43212

CVE-2025-43216

CVE-2025-43227

CVE-2025-43240

CVE-2025-43265

CVE-2025-43272

CVE-2025-43342

CVE-2025-43343

CVE-2025-43356

CVE-2025-43368

CVE-2025-43392

CVE-2025-43419

CVE-2025-43421

CVE-2025-43425

CVE-2025-43427

CVE-2025-43429

CVE-2025-43430

CVE-2025-43431

CVE-2025-43432

CVE-2025-43434

CVE-2025-43440

CVE-2025-43443

CVE-2025-43458

CVE-2025-6558

CVE-2025-66287

Updated via yum repository

golang

golang-1.24.6-1.0.1.al8

golang-1.25.3-2.0.2.al8

CVE-2025-47906

CVE-2025-58183

Updated via yum repository

delve

delve-1.24.1-1.0.2.al8

delve-1.25.2-1.0.2.al8

CVE-2025-47906

CVE-2025-58183

Updated via yum repository

httpd

httpd-2.4.37-655.0.1.al8.5

httpd-2.4.37-655.0.1.al8.6

CVE-2025-55753

CVE-2025-58098

CVE-2025-65082

CVE-2025-66200

Updated via yum repository

mysql

mysql-8.0.43-1.0.1.1.al8

mysql-8.0.44-1.0.1.1.al8

CVE-2025-53040

CVE-2025-53042

CVE-2025-53044

CVE-2025-53045

CVE-2025-53053

CVE-2025-53054

CVE-2025-53062

CVE-2025-53069

Updated via yum repository

Known issues

See the Known issues for Alibaba Cloud Linux 3.2104 U12.1.

2025

Alibaba Cloud Linux 3.2104 U12.2

Version

Image ID

Release date

Release summary

Alibaba Cloud Linux 3.2104 U12.2

aliyun_3_x64_20G_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

aliyun_3_x64_20G_dengbao_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image.

aliyun_3_x64_20G_container_optimized_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3 64-bit Container Optimized Edition base image.

aliyun_3_arm64_20G_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM base image.

aliyun_3_arm64_20G_dengbao_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM MLPS 2.0 Level 3 base image.

aliyun_3_arm64_20G_container_optimized_alibase_20251215.vhd

2026-01-05

  • Updated software packages in the Alibaba Cloud Linux 3 64-bit Container Optimized Edition ARM base image.

Content updates

Major updates

  • Kernel: The kernel package is kernel-5.10.134-19.2.al8.

  • Driver: The kmod-udma driver is updated to kmod-udma-5.10.134~19.2-0.1.0~1.al8 to ensure compatibility with kmod-intel-QAT20-5.10.134~19.2-L.0.9.4__00004~1.al8.

Package updates

New features

  • Cloud application component updates:

    • aliyun-cli is upgraded from aliyun-cli-3.0.305-1.al8 to aliyun-cli-3.1.3-1.al8. This update is included in the image.

  • Core OS enhancements:

    • alinux-release is upgraded to alinux-release-3.2104.12-4.al8, marking the release of Alinux 3.12.2. This update is included in the image.

    • intel-QAT20 is upgraded to intel-QAT20-L.0.9.4-00004.15.al8, adding support for the QAT VF device ID of 9th-generation GNR instances. This update is available in the yum repository.

Bug fix

  • Bug fixes for Alibaba Cloud Linux 3:

    • The systemd component is updated from systemd-239-82.0.4.3.al8.5 to systemd-239-82.0.4.4.al8.5 to backport a fix for a race condition between mount and reload. This update is included in the image.

    • The glibc component is updated from glibc-2.32-1.21.al8 to glibc-2.32-1.22.al8 to resolve a "missed wakeup" issue in pthread_cond_wait. This update is included in the image.

    • The tee-primitives component is updated from tee-primitives-1.0-2.al8 to tee-primitives-1.0-3.al8 to address an issue caused by a source code md5sum change. This update is available in the yum repository.

    • The qt5-qtmultimedia component is updated from qt5-qtmultimedia-5.15.3-1.al8 to qt5-qtmultimedia-5.15.3-1.1.al8 to resolve dependency issues. This update is available in the yum repository.

    • The dracut component is updated from dracut-049-233.git20240115.0.2.al8 to dracut-049-233.git20240115.0.2.1.al8 to fix an error when installing a 6.x kernel version on Alibaba Cloud Linux 3. This update is available in the yum repository.

    • The intel-QAT20 component is updated from intel-QAT20-L.0.9.4-00004.12.al8 to intel-QAT20-L.0.9.4-00004.15.al8 to resolve an issue with the Intel QAT VF device ID on 9th-generation GNR instances. This update is available in the yum repository.

    • The qatengine component is updated from qatengine-1.2.0-3.al8 to qatengine-1.2.0-4.al8 to resolve an issue where TLS v1.0 and v1.1 are unsupported when using OpenSSL 3. This update is available in the yum repository.

    • The intel-ipp-crypto-mb component is updated from intel-ipp-crypto-mb-1.0.6-4.al8 to intel-ipp-crypto-mb-1.0.6-5.al8 to resolve an issue where TLS v1.0 and v1.1 are unsupported when using OpenSSL 3. This update is available in the yum repository.

  • This release provides bug fixes for 12 Anolis OS 8 components. One is updated in the image, and 11 are available from the yum repository:

    Component

    Previous version

    New version

    Update reason

    Update method

    which

    which-2.21-20.0.1.al8

    which-2.21-21.0.1.al8

    Adds a readability check for /proc/$$/exe.

    Updated in the image

    dnsmasq

    dnsmasq-2.79-33.al8

    dnsmasq-2.79-35.al8

    Changes the behavior of repeated DNS queries.

    Updated from the yum repository

    gnome-session

    gnome-session-40.1.1-9.0.1.al8

    gnome-session-40.1.1-10.0.1.al8

    Reduces unnecessary log output during debugging.

    Updated from the yum repository

    gnome-settings-daemon

    gnome-settings-daemon-40.0.1-17.0.1.al8

    gnome-settings-daemon-40.0.1-19.0.1.al8

    Fixes the default power button action setting for servers.

    Fixes an issue that prevented a smart card from working without a cold plug.

    Updated from the yum repository

    java-1.8.0-openjdk-portable

    java-1.8.0-openjdk-portable-1.8.0.462.b08-1.0.1.1.al8

    java-1.8.0-openjdk-portable-1.8.0.472.b08-1.0.1.1.al8

    Resolves JDK-8202369.

    Updated from the yum repository

    ksh

    ksh-20120801-267.0.1.al8

    ksh-20120801-269.0.1.al8

    Fixes an issue with pasting long multi-byte characters via SSH.

    libdrm

    libdrm-2.4.121-1.0.1.al8

    libdrm-2.4.123-2.0.1.al8

    Fixes an issue where the libpciaccess PCI access library is unavailable on RHEL 9 for aarch64, ppc64le, and s390x.

    Updated from the yum repository

    motif

    motif-2.3.4-21.al8

    motif-2.3.4-24.al8

    Fixes a memory leak related to UTF-8 strings.

    Updated from the yum repository

    mysql-selinux

    mysql-selinux-1.0.13-1.al8

    mysql-selinux-1.0.14-1.al8

    Resolves rhbz#2380217 by upgrading to version 1.0.14 and updating related hash and release information.

    Updated from the yum repository

    net-snmp

    net-snmp-5.8-30.0.1.al8

    net-snmp-5.8-31.0.1.al8

    Fixes a "use after free" issue in a callback function.

    Updated from the yum repository

    intel-ipp-crypto-mb

    intel-ipp-crypto-mb-1.0.6-4.al8

    intel-ipp-crypto-mb-1.0.6-5.al8

    Resolves an issue with the installation dependency on OpenSSL 3.0.

    Updated from the yum repository

    qatengine

    qatengine-1.2.0-3.al8

    qatengine-1.2.0-4.al8

    Resolves an issue with the installation dependency on OpenSSL 3.0.

    Updated from the yum repository

  • This release addresses CVEs in 24 components: 4 are updated in the image and 20 are available via the yum repository.

    Component

    Previous version

    New version

    CVE ID

    Update method

    bind

    bind-9.11.36-16.0.1.al8.4

    bind-9.11.36-16.0.1.al8.6

    CVE-2025-40778

    Updated in the image

    expat

    expat-2.2.5-17.al8

    expat-2.5.0-1.al8

    CVE-2025-59375

    Updated in the image

    libssh

    libssh-0.9.6-12.al8

    libssh-0.9.6-16.0.1.al8

    CVE-2025-5318

    Updated in the image

    sssd

    sssd-2.9.4-5.al8.2

    sssd-2.9.4-5.al8.3

    CVE-2025-11561

    Updated in the image

    galera

    galera-26.4.20-1.al8

    galera-26.4.22-1.al8

    CVE-2023-52969

    CVE-2023-52970

    CVE-2025-21490

    CVE-2025-30693

    CVE-2025-30722

    Updated via yum repository

    haproxy

    haproxy-2.4.22-3.0.1.al8.1

    haproxy-2.8.14-1.0.1.al8.1

    CVE-2025-11230

    Updated via yum repository

    java-1.8.0-openjdk

    java-1.8.0-openjdk-1.8.0.462.b08-2.0.1.1.al8

    java-1.8.0-openjdk-1.8.0.472.b08-1.0.1.1.al8

    CVE-2025-53057

    CVE-2025-53066

    Updated via yum repository

    java-17-openjdk

    java-17-openjdk-17.0.16.0.8-2.0.1.1.al8

    java-17-openjdk-17.0.17.0.10-1.0.2.1.al8

    CVE-2025-53057

    CVE-2025-53066

    Updated via yum repository

    lasso

    lasso-2.6.0-13.0.1.al8

    lasso-2.6.0-14.0.1.al8

    CVE-2025-47151

    Updated via yum repository

    libsoup

    libsoup-2.62.3-9.0.1.al8

    libsoup-2.62.3-10.0.1.al8

    CVE-2025-11021

    CVE-2025-4945

    Updated via yum repository

    libtiff

    libtiff-4.4.0-12.0.3.al8

    libtiff-4.4.0-15.0.1.al8

    CVE-2025-8176

    CVE-2025-9900

    Updated via yum repository

    mariadb

    mariadb-10.5.27-1.0.1.al8

    mariadb-10.5.29-2.0.1.al8

    CVE-2023-52969

    CVE-2023-52970

    CVE-2025-21490

    CVE-2025-30693

    CVE-2025-30722

    Updated via yum repository

    mingw-expat

    mingw-expat-2.4.8-2.al8

    mingw-expat-2.5.0-1.al8

    CVE-2025-59375

    Updated via yum repository

    mingw-libtiff

    mingw-libtiff-4.0.9-2.1.al8

    mingw-libtiff-4.0.9-3.al8

    CVE-2025-8176

    CVE-2025-9900

    Updated via yum repository

    osbuild-composer

    osbuild-composer-132.2-2.0.1.al8

    osbuild-composer-132.2-3.0.1.al8

    CVE-2025-27144

    Updated via yum repository

    pcs

    pcs-0.10.18-2.0.1.1.al8.6

    pcs-0.10.18-2.0.1.1.al8.7

    CVE-2025-59830

    CVE-2025-61770

    CVE-2025-61771

    CVE-2025-61772

    CVE-2025-61919

    Updated via yum repository

    python-kdcproxy

    python-kdcproxy-0.4-5.3.al8.1

    python-kdcproxy-0.4-5.3.al8.2

    CVE-2025-59088

    CVE-2025-59089

    Updated via yum repository

    redis

    redis-6.2.19-1.0.1.1.al8

    redis-6.2.20-1.0.1.1.al8

    CVE-2025-46817

    CVE-2025-46818

    CVE-2025-46819

    CVE-2025-49844

    Updated via yum repository

    runc

    runc-1.1.12-6.0.1.al8

    runc-1.2.5-2.al8

    CVE-2025-31133

    CVE-2025-52565

    CVE-2025-52881

    Updated via yum repository

    squid

    squid-4.15-13.al8.5

    squid-4.15-13.al8.6

    CVE-2025-62168

    Updated via yum repository

    tigervnc

    tigervnc-1.15.0-7.al8

    tigervnc-1.15.0-8.al8

    CVE-2025-62229

    CVE-2025-62230

    CVE-2025-62231

    Updated via yum repository

    xorg-x11-server

    xorg-x11-server-1.20.11-26.0.1.al8

    xorg-x11-server-1.20.11-27.0.1.al8

    CVE-2025-62229

    CVE-2025-62230

    CVE-2025-62231

    Updated via yum repository

    xorg-x11-server-Xwayland

    xorg-x11-server-Xwayland-23.2.7-4.al8

    xorg-x11-server-Xwayland-23.2.7-5.al8

    CVE-2025-62229

    CVE-2025-62230

    CVE-2025-62231

    Updated via yum repository

    zziplib

    zziplib-0.13.71-11.0.1.al8

    zziplib-0.13.71-12.0.1.al8

    CVE-2018-17828

    Updated via yum repository

Known issues

See the known issues for Alibaba Cloud Linux 3.2104 U12.1.

Alibaba Cloud Linux 3.2104 U12.1

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U12.1

aliyun_3_x64_20G_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.x86_64.

aliyun_3_x64_20G_dengbao_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.x86_64.

aliyun_3_x64_20G_container_optimized_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3 64-bit container optimized edition base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.x86_64.

aliyun_3_arm64_20G_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.aarch64.

aliyun_3_arm64_20G_dengbao_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.aarch64.

aliyun_3_arm64_20G_container_optimized_alibase_20251030.vhd

2025-11-30

  • Refreshes the Alibaba Cloud Linux 3 64-bit container optimized edition for ARM base image with the latest packages.

  • Updates the kernel to kernel-5.10.134-19.2.al8.aarch64.

Updates

Important updates

This release updates the kernel to kernel-5.10.134-19.2.al8 and fixes the following issues:

  • Fixed an issue where the Zenbleed vulnerability patch was incorrectly applied to non-Zen2 architectures during a microcode hot-upgrade.

  • Added the swiotlb_any cmdline parameter to allow the system to allocate high-memory addresses as a bounce buffer for Confidential Computing scenarios.

  • Fixed an issue where memory was not correctly accepted during the EFI stub phase when booting a TDX VM.

  • Fixed a race condition following a PCIe secondary bus reset that allowed a downstream device to be used before its initialization was complete, potentially causing errors or taking the device offline.

  • Fixed issues in the DWC_PMU driver to prevent kernel startup failures on Yitian instance models when hardware link anomalies occur.

  • Fixed a potential crash in the Group Balancer.

  • Fixed unexpected packet loss when using virtio_net with vhost under specific conditions.

For detailed release information, see https://openanolis.cn/sig/Cloud-Kernel/doc/1388258453605187661

Package updates

New features

  • Secure CAI components are updated to support remote device attestation and Hygon CSV. These updates are available from the yum repository.

    • trustee is updated to trustee-1.7.0-1.al8.

    • trustiflux is updated to trustiflux-1.4.4-1.al8.

    • cryptpilot is updated to cryptpilot-0.2.7-1.al8.

    • trusted-network-gateway is updated to trusted-network-gateway-2.2.6-1.al8.

    • gocryptfs is now available as gocryptfs-2.4.0-2.al8.

    • tee-primitives is updated to tee-primitives-1.0-2.al8.

  • System O&M enhancements:

    • sysak is updated to sysak-3.8.0-1, enhancing System O&M capabilities.

  • Base OS capability enhancements:

    • alinux-base-setup is updated to alinux-release-3.2104.12-2.al8. For security, the rpcbind service is disabled by default.

    • alinux-release is updated to alinux-release-3.2104.12-2.al8, marking the release of Alinux 3.12.1.

    • NetworkManager is updated to NetworkManager-1.40.16-19.0.1.1.al8 to enable ipvlan.

    • systemd is updated to systemd-239-82.0.4.3.al8.5 to support the new NetworkNamespacePath feature in Systemd.

    • logrotate is updated to logrotate-3.14.0-6.0.1.1.al8 to optimize memory usage by compressing system logs.

    • tpm2-tss is updated to tpm2-tss-2.4.6-1.0.2.al8 to add runtime dependencies for confidential computing.

    • tpm2-tools is updated to tpm2-tools-4.1.1-5.0.6.al8 to add runtime dependencies for confidential computing.

    • tengine is updated to tengine-3.1.0-3.al8. This version integrates the nginx-module-vts plugin and enhances performance on the Yitian Processor.

    • gcc-toolset-12-gcc is updated to gcc-toolset-12-gcc-12.3.0-1.2.al8, adding newer GCC capabilities.

    • rasdaemon is updated to rasdaemon-0.6.7-16.5.al8 providing an RAS diagnostic and self-healing solution.

    • tracker is updated to tracker-3.1.2-3.0.1.1.al8. This update modifies compilation options to disable the SQLite version check.

    • ostree is updated to ostree-2022.2-11.al8 to deliver security updates for ContainerOS.

  • System tuning enhancements:

    • keentuned and keentune-target are released as version 3.2.0.

  • Kernel-related component updates:

    • smc-tools is updated to smc-tools-1.8.3-1.0.4.al8. This update adds monitoring and packet capture capabilities.

    • vtoa is updated to vtoa-2.1.1-1.al8 to provide forward and backward compatibility.

    • erofs-utils is updated to erofs-utils-1.8.10-1.al8. This update includes bug fixes.

  • Cloud application component updates:

    • aliyun-cli is updated to aliyun-cli-3.0.305-1.al8.

    • ossfs is updated to ossfs-1.91.8-1.al8, fixing issues with basic functionality.

  • OS Copilot updates:

    • os-copilot is updated to os-copilot-0.9.1-1.al8.

  • This release includes updates for 11 components synchronized from Anolis OS 8. Of these, three are updated in the image and eight are available from the yum repository.

Component

Previous version

Updated version

Description

Update method

libsemanage

libsemanage-2.9-10.0.1.al8

libsemanage-2.9-12.0.1.al8

Enhances storage and rebuild performance in semanage by reducing function calls during the reuse phase. This update is forward-compatible.

Included in the image

tzdata

tzdata-2024b-1.0.1.2.al8

tzdata-2025b-1.0.1.1.al8

Updates time zone data.

Included in the image

linux-firmware

linux-firmware-20241014-125.git06bad2f1.al8

linux-firmware-20250325-129.git710a336b.al8

Adds support for additional hardware types.

Included in the image

gnome-control-center

gnome-control-center-40.0-31.1.al8

gnome-control-center-40.0-32.1.al8

Adds an API to query device group information.

Updated via the yum repository

java-1.8.0-openjdk-portable

java-1.8.0-openjdk-portable-1.8.0.432.b06-1.0.2.1.al8

java-1.8.0-openjdk-portable-1.8.0.462.b08-1.0.1.1.al8

Now a build and installation dependency for newer Java components.

Updated via the yum repository

java-17-openjdk-portable

java-17-openjdk-portable-17.0.13.0.11-1.0.2.1.al8

java-17-openjdk-portable-17.0.16.0.8-1.0.1.1.al8

Now a build and installation dependency for newer Java components.

Updated via the yum repository

motif

motif-2.3.4-20.al8

motif-2.3.4-21.al8

Adds multi-screen support.

Updated via the yum repository

mysql-selinux

mysql-selinux-1.0.10-1.al8

mysql-selinux-1.0.13-1.al8

Includes new features and bug fixes.

Updated via the yum repository

scap-security-guide

scap-security-guide-0.1.75-1.0.1.al8

scap-security-guide-0.1.77-1.0.1.al8

Adds rules for the user namespace.

Updated via the yum repository

sos

sos-4.8.1-1.0.1.1.al8

sos-4.8.2-1.0.1.1.al8

Adds support for the walrus operator (:=) in Python 3.8 environments.

Updated via the yum repository

tzdata

tzdata-2024b-1.0.1.2.al8

tzdata-2025b-1.0.1.1.al8

Updates time zone data.

Included in the image

xorg-x11-drv-libinput

xorg-x11-drv-libinput-1.0.1-3.al8

xorg-x11-drv-libinput-1.0.1-4.al8

Adds a mapping for specific high keycodes to the FK20–FK23 range.

Updated via the yum repository

  • This release updates 27 components with bug fixes from Anolis OS 8: 12 in the image and 15 through the yum repository.

Component

Previous version

New version

Description

Update method

device-mapper-multipath

device-mapper-multipath-0.8.4-41.0.1.al8

device-mapper-multipath-0.8.4-42.0.1.al8

Fixed a memory leak in the external NVMe handler.

Updated in the image

dnf

dnf-4.7.0-20.0.1.1.al8

dnf-4.7.0-21.0.1.1.al8

Fixed functional and runtime issues in dnf-automatic and dnf.

Updated in the image

firewalld

firewalld-0.9.11-9.0.1.al8

firewalld-0.9.11-10.0.1.al8

Updated the Ceph port number in the service definition to prevent a port conflict.

Updated in the image

libdnf

libdnf-0.63.0-20.0.1.2.al8

libdnf-0.63.0-21.0.1.1.al8

Fixed an invalid memory access issue.

Updated in the image

libselinux

libselinux-2.9-9.1.al8

libselinux-2.9-10.1.al8

Fixed a null pointer dereference issue.

Updated in the image

lvm2

lvm2-2.03.14-14.0.1.al8

lvm2-2.03.14-15.0.1.al8

Fixed a thread-blocking issue in the dmeventd module during system shutdown. This update also adds a pre-check to exit if the /run/nologin file is detected.

Updated in the image

nfs-utils

nfs-utils-2.3.3-59.0.4.al8

nfs-utils-2.3.3-64.0.1.al8

Applied patches to fix and improve GSSD authentication, READDIRPLUS functionality, and mountstats tool behavior. Also updated the related documentation.

Updated in the image

nftables

nftables-1.0.4-4.al8

nftables-1.0.4-7.al8

Optimized compatibility expression handling for iptables-nft rules. Fixes include incorrect translation paths, an improved fallback printing mechanism, enhanced warnings for unsupported expressions, and better memory management.

Updated in the image

openldap

openldap-2.4.46-20.al8

openldap-2.4.46-21.al8

Fixed a file descriptor leak on failed LDAP over SSL connections and resolved an error that caused a file to be closed multiple times after a TLS connection failure.

Updated in the image

sssd

sssd-2.9.4-5.al8.1

sssd-2.9.4-5.al8.2

Fixed a memory leak in sssd_kcm, improved handling of large databases in the disk cache, and resolved case-mismatch failures when updating cache groups. This update also adds the ignore_group_members option to control the addition of group members.

Updated in the image

tar

tar-1.30-9.0.2.al8

tar-1.30-11.0.1.al8

Fixed a regression in the --no-overwrite-dir option introduced by a previous upstream fix (1.30-7). Reduced the frequency of the "file changed as we read it" warning. Added a downstream patch to fix a related failure in the filerem01 test.

Updated in the image

tuned

tuned-2.22.1-5.0.1.1.al8

tuned-2.22.1-6.0.1.1.al8

This update enables lazy loading for the hdparm device check and disables the amd.scheduler plugin instance in the PostgreSQL configuration.

Updated in the image

389-ds-base

389-ds-base-1.4.3.39-9.0.1.al8

389-ds-base-1.4.3.39-15.0.1.al8

Fixed functional issues in the str2filter and uiduniq modules.

Updated in the yum repository

autofs

autofs-5.1.4-114.0.1.al8.1

autofs-5.1.4-114.0.1.al8.2

Fixed a deadlock issue.

Updated in the yum repository

cups-filters

cups-filters-1.20.0-35.0.1.al8

cups-filters-1.20.0-36.0.1.al8

Fixed an issue where images were incorrectly rotated 90 degrees during printing.

Updated in the yum repository

curl

curl-7.61.1-35.0.2.al8

curl-7.61.1-35.0.2.al8.3

Applied a follow-up fix for CVE-2023-28321. The fix resolves an asynchronous timing issue by creating a wait condition in the thread.

Updated in the yum repository

haproxy

haproxy-2.4.22-3.0.1.al8

haproxy-2.4.22-3.0.1.al8.1

Cleared the retry flag in read and write functions to prevent CPU usage spikes. Fixed an error that prevented certificates from loading from a file.

Updated in the yum repository

jasper

jasper-2.0.14-5.0.1.al8

jasper-2.0.14-6.0.1.al8

Updated settings in the jasper configuration file.

Updated in the yum repository

libisoburn

libisoburn-1.5.4-4.al8

libisoburn-1.5.4-5.al8

Modified the post-installation script to fix an upgrade error.

Updated in the yum repository

mod_security_crs

mod_security_crs-3.3.4-3.al8

mod_security_crs-3.3.4-3.al8.2

Fixed rules that incorrectly blocked certain city and street names in forms.

Updated in the yum repository

mutter

mutter-40.9-22.0.1.al8

mutter-40.9-23.0.1.al8

Fixed an issue caused by rapidly switching windows.

Updated in the yum repository

portreserve

portreserve-0.0.5-19.2.al8

portreserve-0.0.5-20.0.1.al8

Updated the tmpfiles.d configuration to correct the systemd temporary file path for portreserve from the obsolete /var/run/ to /run.

Updated in the yum repository

samba

samba-4.19.4-6.1.al8

samba-4.19.4-9.1.al8

Fixed an issue with domain controller discovery after Windows netlogon hardening, resolved a memory leak in winbind, and addressed a potential kernel panic in fd_handle_destructor() within smbd_smb2_close().

Updated in the yum repository

squid

squid-4.15-13.al8.3

squid-4.15-13.al8.5

Fixed an issue that caused squid to add DNS entries to the cache even when the TTL was set to 0.

Updated in the yum repository

strace

strace-5.18-2.0.4.al8

strace-5.18-2.1.0.1.al8

Added support for the loongarch64 architecture.

Fixed incorrect system call name reporting in restart_syscall() when attaching to a process with PTRACE_GET_SYSCALL_INFO (RHEL-8570).

Updated net-yy-inet*, linkat--secontext_mismatch, and prctl-sve test cases.

Updated in the yum repository

traceroute

traceroute-2.1.0-6.2.0.3.al8

traceroute-2.1.0-9.0.1.al8

Fixed the polling logic in poll.c to improve robustness.

Updated in the yum repository

unzip

unzip-6.0-47.0.1.al8

unzip-6.0-48.0.1.al8

Fixed an extraction error affecting certain ZIP files.

Updated in the yum repository

  • This update addresses 116 CVEs:

Component

Previous version

Updated version

CVEs

aide

0.16-102.al8

0.16-103.al8.2

CVE-2025-54389

bind

9.11.36-16.0.1.al8

9.11.36-16.0.1.al8.4

CVE-2024-11187

bind-dyndb-ldap

11.6-5.al8

11.6-6.al8

CVE-2025-4404

bluez

5.63-3.0.1.al8

5.63-5.0.1.al8

CVE-2023-27349

CVE-2023-51589

buildah

1.33.11-1.al8

1.33.12-2.al8

CVE-2025-22871

CVE-2025-6032

bzip2

1.0.6-27.al8

1.0.6-28.al8

CVE-2019-12900

compat-libtiff3

3.9.4-13.2.al8

3.9.4-14.0.1.al8

CVE-2025-9900

compat-openssl10

1.0.2o-4.0.1.al8

1.0.2o-4.0.1.al8.1

CVE-2023-0286

containernetworking-plugins

1.4.0-5.0.1.al8

1.4.0-6.0.1.al8

CVE-2025-22871

CVE-2025-6032

corosync

3.1.8-2.al8

3.1.9-2.al8

CVE-2025-30472

cups

2.2.6-62.0.1.al8

2.2.6-63.0.1.al8

CVE-2025-58060

delve

1.22.1-1.0.2.al8

1.24.1-1.0.2.al8

CVE-2025-22871

CVE-2025-4673

doxygen

1.8.14-12.1.al8

1.8.14-13.al8

CVE-2020-11023

emacs

27.2-10.0.1.al8

27.2-14.0.1.al8.2

CVE-2024-53920

expat

2.2.5-16.al8

2.2.5-17.al8

CVE-2024-8176

fence-agents

4.10.0-76.0.1.al8.1

4.10.0-86.0.1.al8.7

CVE-2025-47273

freetype

2.10.4-9.al8

2.10.4-10.al8

CVE-2025-27363

galera

26.4.14-1.al8

26.4.20-1.al8

CVE-2023-22084

CVE-2024-21096

gcc-toolset-13-gcc

13.3.1-2.1.0.1.1.al8

13.3.1-2.2.0.1.1.al8

CVE-2020-11023

gdk-pixbuf2

2.42.6-4.0.1.al8

2.42.6-6.0.1.al8

CVE-2025-7345

ghostscript

9.54.0-18.al8

9.54.0-19.al8

CVE-2025-27832

gimp

2.8.22-25.al8

2.8.22-26.al8.2

CVE-2025-48797

CVE-2025-48798

CVE-2025-5473

git

2.43.5-2.0.1.al8

2.43.7-1.0.1.al8

CVE-2024-50349

CVE-2024-52006

CVE-2025-27613

CVE-2025-27614

CVE-2025-46835

CVE-2025-48384

CVE-2025-48385

git-lfs

3.4.1-3.0.1.al8

3.4.1-5.0.1.al8

CVE-2025-22871

glib2

2.68.4-14.0.2.al8

2.68.4-16.0.1.al8.2

CVE-2024-52533

CVE-2025-4373

glibc

2.32-1.16.al8

2.32-1.21.al8

CVE-2025-0395

CVE-2025-4802

CVE-2025-8058

gnome-remote-desktop

0.1.8-3.1.al8

0.1.8-4.0.1.al8

CVE-2025-5024

gnutls

3.6.16-8.0.2.al8.3

3.6.16-8.0.2.al8.4

CVE-2025-32988

CVE-2025-32990

CVE-2025-6395

go-toolset

1.22.9-1.al8

1.24.6-1.al8

CVE-2025-4674

golang

1.22.9-1.0.1.al8

1.24.6-1.0.1.al8

CVE-2025-4674

grafana

9.2.10-20.0.1.al8

9.2.10-25.0.1.al8

CVE-2025-22871

grafana-pcp

5.1.1-9.0.1.al8

5.1.1-10.al8

CVE-2025-22871

gstreamer1

1.22.1-2.0.1.al8

1.22.12-3.0.1.al8

CVE-2024-0444

CVE-2024-4453

gstreamer1-plugins-bad-free

1.22.1-4.0.1.al8

1.22.1-4.0.1.al8

#N/A

gstreamer1-plugins-base

1.22.1-3.0.1.al8

1.22.12-4.0.1.al8

CVE-2024-47541

CVE-2024-47542

CVE-2024-47600

CVE-2024-47835

httpd

2.4.37-65.0.1.al8.2

2.4.37-655.0.1.al8.5

CVE-2024-47252

CVE-2025-23048

CVE-2025-49630

CVE-2025-49812

ipa

4.9.13-14.0.1.1.al8

4.9.13-20.0.1.1.al8

CVE-2025-7493

ipa-healthcheck

0.12-4.al8

0.12-6.al8

CVE-2025-7493

jackson-annotations

2.14.2-1.al8

2.19.1-1.al8

CVE-2025-52999

jackson-core

2.14.2-1.al8

2.19.1-1.al8

CVE-2025-52999

jackson-databind

2.14.2-1.al8

2.19.1-1.al8

CVE-2025-52999

jackson-jaxrs-providers

2.14.2-1.al8

2.19.1-1.al8

CVE-2025-52999

java-1.8.0-openjdk

1.8.0.432.b06-2.0.2.1.al8

1.8.0.462.b08-2.0.1.1.al8

CVE-2025-30749

CVE-2025-30754

CVE-2025-30761

CVE-2025-50106

java-17-openjdk

17.0.13.0.11-3.0.2.1.al8

17.0.16.0.8-2.0.1.1.al8

CVE-2025-30749

CVE-2025-30754

CVE-2025-50059

CVE-2025-50106

jq

1.6-17.al8

1.6-17.al8.2

CVE-2024-23337

CVE-2025-48060

keepalived

2.2.8-3.al8

2.2.8-4.al8

CVE-2024-41184

krb5

1.18.2-30.0.1.al8

1.18.2-32.0.1.al8

CVE-2025-3576

libarchive

3.5.3-4.al8

3.5.3-6.al8

CVE-2025-5914

libblockdev

2.28-6.al8

2.28-7.al8

CVE-2025-6019

libcap

2.48-6.0.1.al8

2.48-6.0.2.al8

CVE-2025-1390

libpq

13.11-1.0.1.al8

13.20-1.0.1.al8

CVE-2025-1094

libreoffice

7.1.8.1-12.0.2.1.al8.1

7.1.8.1-15.0.1.1.al8.1

CVE-2025-1080

libsoup

2.62.3-6.0.1.al8

2.62.3-9.0.1.al8

CVE-2025-2784

CVE-2025-4948

CVE-2025-32049

CVE-2025-32914

libtasn1

4.13-4.0.1.al8

4.13-5.0.1.al8

CVE-2024-12133

libtpms

0.9.1-2.20211126git1ff6fe1f43.al8

0.9.1-3.20211126git1ff6fe1f43.al8

CVE-2025-49133

libvirt

8.0.0-23.3.0.2.al8

8.0.0-23.4.0.1.al8

CVE-2025-49133

libvpx

1.7.0-11.0.1.al8

1.7.0-12.0.1.al8

CVE-2025-5283

libxml2

2.9.7-18.0.3.1.al8

2.9.7-21.0.1.1.al8.3

CVE-2025-32415

libxslt

1.1.32-6.1.al8

1.1.32-6.2.0.1.al8

CVE-2023-40403

mariadb

10.5.22-1.0.1.al8

10.5.27-1.0.1.al8

CVE-2023-22084

CVE-2024-21096

mecab-ipadic

2.7.0.20070801-16.2.al8

2.7.0.20070801-17.0.1.al8

CVE-2024-11053

CVE-2024-21193

CVE-2024-21194

CVE-2024-21196

CVE-2024-21197

CVE-2024-21198

CVE-2024-21199

CVE-2024-21201

CVE-2024-21203

CVE-2024-21212

CVE-2024-21213

CVE-2024-21218

CVE-2024-21219

CVE-2024-21230

CVE-2024-21231

CVE-2024-21236

CVE-2024-21237

CVE-2024-21238

CVE-2024-21239

CVE-2024-21241

CVE-2024-21247

CVE-2024-37371

CVE-2024-5535

CVE-2024-7264

CVE-2025-21490

CVE-2025-21491

CVE-2025-21494

CVE-2025-21497

CVE-2025-21500

CVE-2025-21501

CVE-2025-21503

CVE-2025-21504

CVE-2025-21505

CVE-2025-21518

CVE-2025-21519

CVE-2025-21520

CVE-2025-21521

CVE-2025-21522

CVE-2025-21523

CVE-2025-21525

CVE-2025-21529

CVE-2025-21531

CVE-2025-21534

CVE-2025-21536

CVE-2025-21540

CVE-2025-21543

CVE-2025-21546

CVE-2025-21555

CVE-2025-21559

microcode_ctl

20240910-1.0.1.al8

20250512-1.0.1.al8

CVE-2024-28956

CVE-2024-43420

CVE-2024-45332

CVE-2025-20012

CVE-2025-20623

CVE-2025-24495

mingw-freetype

2.8-3.1.al8

2.8-3.1.al8.1

CVE-2025-27363

CVE-2025-32050

CVE-2025-32052

CVE-2025-32053

CVE-2025-32906

CVE-2025-32907

CVE-2025-32909

CVE-2025-32910

CVE-2025-32911

CVE-2025-32913

mingw-sqlite

3.26.0.0-1.1.al8

3.26.0.0-2.al8

CVE-2025-6965

mod_auth_openidc

2.4.9.4-6.al8

2.4.9.4-8.al8

CVE-2025-3891

mod_http2

1.15.7-10.al8.1

1.15.7-10.al8.4

CVE-2024-47252

CVE-2025-23048

CVE-2025-49630

CVE-2025-49812

mod_security

2.9.6-1.al8

2.9.6-2.al8

CVE-2025-47947

mysql

8.0.36-1.0.1.1.al8

8.0.43-1.0.1.1.al8

CVE-2025-21574

CVE-2025-21575

CVE-2025-21577

CVE-2025-21579

CVE-2025-21580

CVE-2025-21581

CVE-2025-21584

CVE-2025-21585

CVE-2025-30681

CVE-2025-30682

CVE-2025-30683

CVE-2025-30684

CVE-2025-30685

CVE-2025-30687

CVE-2025-30688

CVE-2025-30689

CVE-2025-30693

CVE-2025-30695

CVE-2025-30696

CVE-2025-30699

CVE-2025-30703

CVE-2025-30704

CVE-2025-30705

CVE-2025-30715

CVE-2025-30721

CVE-2025-30722

CVE-2025-50077

CVE-2025-50078

CVE-2025-50079

CVE-2025-50080

CVE-2025-50081

CVE-2025-50082

CVE-2025-50083

CVE-2025-50084

CVE-2025-50085

CVE-2025-50086

CVE-2025-50087

CVE-2025-50088

CVE-2025-50091

CVE-2025-50092

CVE-2025-50093

CVE-2025-50094

CVE-2025-50096

CVE-2025-50097

CVE-2025-50098

CVE-2025-50099

CVE-2025-50100

CVE-2025-50101

CVE-2025-50102

CVE-2025-50104

CVE-2025-53023

nodejs

20.16.0-1.1.al8

20.19.2-1.1.al8

CVE-2025-23165

CVE-2025-23166

CVE-2025-23167

nodejs-nodemon

2.0.20-3.al8

3.0.1-1.al8

CVE-2025-22150

CVE-2025-23083

CVE-2025-23085

nodejs-packaging

23-3.1.al8

2021.06-4.al8

CVE-2025-22150

CVE-2025-23083

CVE-2025-23085

open-vm-tools

12.3.5-2.al8

12.3.5-2.al8.1

CVE-2025-41244

opendnssec

2.1.7-1.1.al8

2.1.7-2.al8

CVE-2025-4404

openssh

8.0p1-25.0.1.1.al8

8.0p1-26.0.1.1.al8

CVE-2025-26465

osbuild

126-1.0.1.al8

141.2-1.0.1.al8

CVE-2024-34158

CVE-2024-9355

CVE-2024-1394

osbuild-composer

118-2.0.1.al8

132.2-2.0.1.al8

CVE-2025-22871

pam

1.3.1-36.al8

1.3.1-38.al8

CVE-2025-6020

pcs

0.10.18-2.0.1.1.al8.3

0.10.18-2.0.1.1.al8.6

CVE-2024-49761

perl

5.26.3-422.0.1.al8

5.26.3-423.0.1.al8

CVE-2025-40909

perl-CPAN

2.18-397.1.0.2.al8

2.18-402.0.1.al8

CVE-2020-16156

perl-FCGI

0.78-11.2.al8

0.78-12.al8

CVE-2025-40907

perl-File-Find-Rule

0.34-8.1.al8

0.34-9.al8

CVE-2011-10007

perl-JSON-XS

3.04-3.2.al8

3.04-4.al8

CVE-2025-40928

perl-YAML-LibYAML

0.70-1.1.al8

0.70-2.al8

CVE-2025-40908

podman

4.9.4-18.0.1.al8

4.9.4-23.0.1.al8

CVE-2025-9566

postgresql

13.18-1.0.1.al8

13.22-1.0.1.al8

CVE-2025-8714

CVE-2025-8715

python-cryptography

3.2.1-7.al8

3.2.1-8.al8

CVE-2023-49083

python-jinja2

2.10.1-3.0.3.al8

2.10.1-7.0.1.al8

CVE-2025-27516

python-requests

2.20.0-5.al8

2.20.0-6.al8

CVE-2024-47081

python-setuptools

39.2.0-8.al8.1

39.2.0-9.al8

CVE-2025-47273

python3

3.6.8-69.0.1.1.al8

3.6.8-71.0.1.1.al8

CVE-2025-8194

python3.11

3.11.11-1.0.1.al8

3.11.13-2.0.1.al8

CVE-2025-8194

python3.11-setuptools

65.5.1-3.al8

65.5.1-4.al8

CVE-2025-47273

qemu-kvm

6.2.0-53.0.1.al8.2

6.2.0-53.0.8.al8.4

CVE-2025-49133

redis

6.2.7-1.0.3.al8

6.2.19-1.0.1.1.al8

CVE-2025-32023

CVE-2025-48367

resource-agents

4.9.0-54.al8.6

4.9.0-54.al8.16

CVE-2024-47081

rsync

3.1.3-20.0.1.al8

3.1.3-23.0.1.al8

CVE-2016-9840

runc

1.1.12-5.0.1.al8

1.1.12-6.0.1.al8

CVE-2025-22869

skopeo

1.14.5-3.0.1.al8

1.14.5-4.0.1.al8

CVE-2025-22871

CVE-2025-6032

socat

1.7.4.1-1.0.1.al8

1.7.4.1-2.0.1.al8

CVE-2024-54661

spice-client-win

8.8-1.al8

8.10-1.al8

CVE-2025-27363

CVE-2025-32050

CVE-2025-32052

CVE-2025-32053

CVE-2025-32906

CVE-2025-32907

CVE-2025-32909

CVE-2025-32910

CVE-2025-32911

CVE-2025-32913

sqlite

3.26.0-19.al8

3.26.0-20.al8

CVE-2025-6965

sudo

1.9.5p2-1.0.2.al8

1.9.5p2-1.0.2.al8.1

CVE-2025-32462

tbb

2018.2-9.2.al8

2018.2-10.al8.1

CVE-2020-11023

tigervnc

1.13.1-14.al8

1.15.0-7.al8

CVE-2025-49175

CVE-2025-49176

CVE-2025-49178

CVE-2025-49179

CVE-2025-49180

tomcat

9.0.87-1.al8.2

9.0.87-1.al8.6

CVE-2025-48976

CVE-2025-48988

CVE-2025-48989

CVE-2025-49125

CVE-2025-52434

CVE-2025-52520

CVE-2025-53506

udisks2

2.9.0-16.0.1.1.al8

2.9.0-16.0.4.al8.1

CVE-2025-8067

unbound

1.16.2-7.al8

1.16.2-9.al8

CVE-2025-5994

varnish

6.0.13-1.0.1.1.al8

6.0.13-1.1.al8.1

CVE-2025-47905

vim

8.0.1763-19.0.2.al8.5

8.0.1763-21.0.1.al8

CVE-2025-53905

CVE-2025-53906

webkit2gtk3

2.46.5-1.0.1.al8

2.46.6-2.0.1.al8

CVE-2025-24201

xdg-utils

1.1.3-11.al8

1.1.3-13.al8

CVE-2022-4055

xmlrpc-c

1.51.0-10.0.1.al8

1.51.0-11.0.1.al8

CVE-2024-8176

xorg-x11-server

1.20.11-25.0.1.al8

1.20.11-26.0.1.al8

CVE-2025-49175

CVE-2025-49176

CVE-2025-49178

CVE-2025-49179

CVE-2025-49180

xorg-x11-server-Xwayland

23.2.7-1.al8

23.2.7-4.al8

CVE-2025-49175

CVE-2025-49176

CVE-2025-49178

CVE-2025-49179

CVE-2025-49180

yelp

40.3-2.al8

40.3-2.al8.1

CVE-2025-3155

yelp-xsl

40.2-1.0.1.al8

40.2-1.0.1.al8.1

CVE-2025-3155

Bug fixes

  • qemu-kvm version 6.2.0-53.0.8.al8.4 fixes an issue where SPICE was not supported on the arm64 architecture.

  • anaconda version 33.16.7.12-1.0.7.4.al8 changes /etc/timezone from a symbolic link to a text file.

  • cloud-init version 23.2.2-9.0.1.1.al8 fixes an issue where symbolic links remained after uninstallation.

  • kexec-tools version 2.0.26-14.0.1.7.al8.2 fixes an issue where Normal memory was not reserved for Node0 on c9i instances.

  • fuse version 2.9.7-19.1.al8 fixes an issue where OSS mount points were lost.

  • gcc-toolset-12 version 12.0-6.1.al8 fixes an issue where installing the pcp software incorrectly triggered a rebuild into the gcc-toolset-12 directory, which impaired functionality.

  • util-linux version 2.32.1-46.0.4.1.al8 fixes an "invalid parameter" error when setting the hardware clock.

Known issue

The NetworkManager-wait-online service fails to start on ebmhfr7.48xlarge16 ECS Bare Metal Instances. This occurs because the instance has a usb0 interface that is not managed by NetworkManager. To resolve this issue, you must manually create a configuration file and then reboot the system.

Solution

  1. Create the /etc/NetworkManager/conf.d/99-unmanaged-device.conf file with the following content:

    [device-usb0-unmanaged]
    match-device=interface-name:usb0
    managed=0
  2. After saving the file, reboot the system and verify that the NetworkManager-wait-online service starts correctly.

Alibaba Cloud Linux 3 AI Extension Edition 0.5.4

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3 AI Extension ARM Edition 0.5.4

aliyun_3_0_arm64_20G_alibase_aiext_0.5.4_20251031.vhd

2025-11-30

  • Base image: Alibaba Cloud Linux 3 U12.1

  • Upgraded the kernel to version 5.10.134-19.2.al8.

  • For more information, see Updates.

Updates

Important updates

Upgraded the kernel to 5.10.134-19.2.al8.aarch64.

  1. Kernel updates:

    • Fixed an issue where a microcode hot patch for the Zenbleed vulnerability was incorrectly applied to non-Zen2 architectures.

    • Added the swiotlb_any command-line parameter to enable the system to allocate high-memory addresses (>2 GB) as bounce buffers for Confidential Computing scenarios.

    • Fixed an issue where the EFI stub did not correctly accept memory when booting a TDX VM.

    • Fixed an issue where a downstream device could be used before its initialization was complete after a PCIe secondary bus reset, potentially causing errors or taking the device offline.

    • Fixed issues in the DWC_PMU driver to prevent kernel boot failures on Yitian-based instance types when hardware links are abnormal.

    • Fixed a potential crash in the Group Balancer.

    • Fixed unexpected packet loss in virtio_net when used with vhost under specific conditions.

  2. Image updates:

    • Installed python3.12-3.12.7-1.al8 by default and configured it as the default Python 3 version.

    • Added keentuned-3.4.1-1.al8 to provide Intelligent Tuning for AI workloads.

    • Installed kmod-fuse-5.10.134~19.2-1.2.5~1.al8 by default to enhance support for the fuse over io_uring mode and increase performance to 1 million IOPS and a cache read/write bandwidth of 40 GB/s.

Alibaba Cloud Linux 3 AI Extension Edition 0.5.3

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3 AI Extension Edition 0.5.3

aliyun_3_0_x64_20G_alibase_aiext_0.5.3_20251011.vhd

2025-10-11

  • The kernel is updated to 5.10.134-19.103.al8.x86_64.

  • For details, see Updates.

Updates

Important updates

  1. Kernel

    1. The kernel is upgraded to version 5.10.134-19.103.al8.x86_64.

    2. New features

      1. Adds support for five-level page tables to enable petabyte-scale memory management. For compatibility, user-mode applications must explicitly specify a high address as a hint during the mmap phase to enable allocation in the five-level page table space.

      2. Introduces the PCIe Resizable BAR feature, which lets you adjust the BAR size of PCIe devices without modifying BIOS settings.

      3. Enables the page table page reclaim feature by default via the reclaim_pt kernel command-line parameter. This feature reclaims page table pages in the MADV_DONTNEED path to save memory and prevent premature out-of-memory (OOM) errors.

      4. Hybrid deployment enhancements: Optimizes the load balancing policy for hybrid deployment scenarios and refactors the absolute preemption policy to grant online tasks absolute priority, preventing offline tasks from preempting their resources.

    3. Compatibility

      1. Backports patches to support UPI on GNR.

      2. The kernel kABI remains consistent with previous versions.

      3. Command line changes: The 'pci_quirk' parameter is enabled by default (disable with 'pci_quirk=disable'), and the 'drv_quirk' parameter is disabled by default (enable with 'drv_quirk=enable').

    4. Stability improvements

      1. Fixes a checksum error in virtio-net for both large and small packets.

      2. Fixes a use-after-free issue in the group balancer.

      3. Fixes a null pointer dereference in the nvme driver during system reboot or shutdown.

      4. Fixes a vhost thread exception.

  2. Image

    1. Adds the update-grubenv service. This service is enabled by default and runs automatically at system startup. It detects the current boot mode (UEFI or Legacy BIOS) and dynamically updates the /boot/grub2/grubenv configuration file to ensure that the GRUB environment variables match the actual boot mode.

    2. Upgraded keentuned to keentuned-3.4.0-1.al8.x86_64.

    3. Upgraded kmod-fuse to kmod-fuse-5.10.134~19.103-1.2.4.5~2.al8.x86_64.

    4. Removed drv_quirk=disable and drv_link_quirk=disable from the command line, and added reclaim_pt.

Security updates

Package name

CVE ID

Updated version

bind-export-libs

CVE-2024-11187

9.11.36-16.0.1.al8.4

bzip2

CVE-2019-12900

1.0.6-28.al8

bzip2-libs

1.0.6-28.al8

cups-client

CVE-2025-58060

2.2.6-63.0.1.al8

cups-libs

2.2.6-63.0.1.al8

expat

CVE-2024-8176

2.2.5-17.al8

freetype

CVE-2025-27363

2.10.4-10.al8

glib2

CVE-2024-52533

CVE-2025-4373

2.68.4-16.0.1.al8.2

glibc

CVE-2025-0395

CVE-2025-4802

CVE-2025-8058

2.32-1.21.al8

glibc-all-langpacks

2.32-1.21.al8

glibc-common

2.32-1.21.al8

glibc-devel

2.32-1.21.al8

glibc-headers-x86

2.32-1.21.al8

grub2-common

CVE-2025-0624

2.02-165.0.1.al8

grub2-efi-x64

2.02-165.0.1.al8

grub2-pc

2.02-165.0.1.al8

grub2-pc-modules

2.02-165.0.1.al8

grub2-tools

2.02-165.0.1.al8

grub2-tools-efi

2.02-165.0.1.al8

grub2-tools-extra

2.02-165.0.1.al8

grub2-tools-minimal

2.02-165.0.1.al8

krb5-libs

CVE-2025-3576

1.18.2-32.0.1.al8

libarchive

CVE-2025-5914

3.5.3-6.al8

libblockdev

CVE-2025-6019

2.28-7.al8

libblockdev-crypto

2.28-7.al8

libblockdev-fs

2.28-7.al8

libblockdev-loop

2.28-7.al8

libblockdev-mdraid

2.28-7.al8

libblockdev-part

2.28-7.al8

libblockdev-swap

2.28-7.al8

libblockdev-utils

2.28-7.al8

libcap

CVE-2025-1390

2.48-6.0.2.al8

libtasn1

CVE-2024-12133

4.13-5.0.1.al8

libudisks2

CVE-2025-8067

2.9.0-16.0.4.al8.1

libxml2

CVE-2025-32415

2.9.7-21.0.1.1.al8.3

nscd

CVE-2025-0395

CVE-2025-4802

CVE-2025-8058

2.32-1.21.al8

pam

CVE-2025-6020

CVE-2025-8941

1.3.1-38.al8

perl-Errno

CVE-2025-40909

1.28-423.0.1.al8

perl-interpreter

5.26.3-423.0.1.al8

perl-IO

1.38-423.0.1.al8

perl-libs

5.26.3-423.0.1.al8

perl-macros

5.26.3-423.0.1.al8

platform-python

CVE-2025-8194

3.6.8-71.0.1.1.al8

platform-python-devel

3.6.8-71.0.1.1.al8

platform-python-setuptools

CVE-2025-47273

39.2.0-9.al8

python3-cryptography

CVE-2023-49083

3.2.1-8.al8

python3-libs

CVE-2025-8194

3.6.8-71.0.1.1.al8

python3-libxml2

CVE-2025-32415

2.9.7-21.0.1.1.al8.3

python3-requests

CVE-2024-47081

2.20.0-6.al8

python3-setuptools

CVE-2025-47273

39.2.0-9.al8

python3-setuptools-wheel

39.2.0-9.al8

python3-unbound

CVE-2025-5994

1.16.2-9.al8

socat

CVE-2024-54661

1.7.4.1-2.0.1.al8

sqlite

CVE-2025-6965

3.26.0-20.al8

sqlite-libs

3.26.0-20.al8

tuned

CVE-2024-52337

2.22.1-5.0.1.1.al8

udisks2

CVE-2025-8067

2.9.0-16.0.4.al8.1

unbound-libs

CVE-2025-5994

1.16.2-9.al8

Alibaba Cloud Linux 3 AI Extension Edition 0.5.2

Version

Image ID

Release date

Description

Alibaba Cloud Linux 3 AI Extension Edition 0.5.2

aliyun_3_0_x64_20G_alibase_aiext_0.5.2_20250714.vhd

2025-07-14

  • Base image: Alibaba Cloud Linux 3 U11.1

  • Kernel upgraded to 5.10.134-19.101.al8.x86_64

  • Updates: For more information, see Updates.

Updates

Major updates

  • Compared to Ubuntu 22.04, Alibaba Cloud Linux 3 AI Extension Edition 0.5.2 delivers improved training and inference performance with standard community openclip/bevformer AI container images (AC2):

    • For bevformer_base training, the average throughput per step is 13% higher with FP32 precision and 12% to 18% higher with FP16 precision.

    • For openclip (RN50), the average training throughput per step is 26% higher, and the average inference throughput is 26% higher.

  • Replacing the community openclip/bevformer AI container images with Alibaba Cloud's optimized versions improves performance as follows:

    • For bevformer_base training, the average throughput per step is 22% higher with FP32 precision and 17% to 20% higher with FP16 precision.

    • For openclip (RN50), the average training throughput per step is 46% higher, and the average inference throughput is 26% higher.

This release upgrades the kernel to version 5.10.134-19.101.al8.x86_64.

  • Scheduling

    • Backports cluster scheduling features.

    • Adds support for configuring BVT for non-movable threads in the root group.

    • Adds support in Core Scheduling for independently configuring special properties for each cookie.

      • Allows sharing a core with normal tasks that do not have a cookie.

      • Prevents load balancing from packing tasks with the same cookie, ensuring they are distributed across different cores.

  • Memory

    • Enables Transparent Huge Pages (THP)-aligned address space allocation for mmap().

    • Adds support for the memmap_on_memory feature in virtio-mem to enable rapid container memory scaling.

    • Introduces a temporary file optimization feature that improves performance in model training scenarios.

    • Introduces a smooth reclamation feature for the pagecache limit that improves memory efficiency and performance in model training scenarios.

    • Introduces a page table page reclamation feature to improve memory efficiency and performance in model training scenarios. To enable this feature, add reclaim_pt to the cmdline.

    • Adds a switch to control the delayed release of shmem file pages.

    • Fixes various issues, including a stability issue in kfence and a THP counting issue for large code pages.

  • Network

    • Fixes various SMC issues, including link group and link use-after-free problems, and resolves smc-r device lookup failures in container scenarios.

  • Storage

    • erofs:

      • Backports several fixes for the erofs file system from the mainline branch.

      • Adds support for file-backed mounting and a 48-bit layout.

      • Adds support for sub-page blocks for compressed files.

    • Backports patches from the mainline stable branches for components such as ext4, block, blk-mq, and io_uring.

    • Introduces the virtio-blk passthrough feature for virtio-blk devices.

  • Driver

    • The NVMe driver now supports batch processing of completed polled I/O commands.

    • Adds support for differential configuration of NVMe driver parameters for cloud disks and local disks.

    • Merges PCIe driver bugfix patches to resolve issues such as incorrect space size calculation and root bus allocation.

  • BPF

    • Merges bugfix and CVE fix patches from community stable branches.

Packages

  • Includes python3.12-3.12.7-1.al8.x86_64 as the default Python 3 version.

  • Includes keentuned-3.2.4-2.al8.x86_64 to provide intelligent tuning for AI scenarios.

Known issues

  1. The NetworkManager-wait-online service fails to start on ecs.ebmgn8t.32xlarge instances.

    The instance includes a USB network device, which increases the startup time of the NetworkManager service. This causes the NetworkManager-wait-online service to time out and fail. If you do not use the USB network device, you can work around this issue by configuring NetworkManager to ignore usb0. To do so, add the following to the /etc/NetworkManager/conf.d/99-unmanaged-device.conf file:

    [device-usb0-unmanaged]
    match-device=interface-name:usb0
    managed=0

    Restart the NetworkManager service to apply the change. The NetworkManager-wait-online service will then start normally on the next system reboot.

  2. Using vhost-net may occasionally cause high CPU usage and network outages. To resolve this issue, install the following hotfix:

    yum install kernel-hotfix-22577883-5.10.134-19.101 -y
  3. When an NVMe device encounters a hardware exception, rebooting the system may trigger a null pointer error. To resolve this issue, install the following hotfix:

    yum install kernel-hotfix-22584571-5.10.134-19.101 -y

Alibaba Cloud Linux 3.2104 U12

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U12

aliyun_3_x64_20G_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.x86_64.

  • For details, see Updates.

aliyun_3_x64_20G_dengbao_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.x86_64.

  • For details, see Updates.

aliyun_3_x64_20G_container_optimized_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit Container Optimized Edition base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.x86_64.

  • For details, see Updates.

aliyun_3_arm64_20G_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.aarch64.

  • For details, see Updates.

aliyun_3_arm64_20G_dengbao_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.aarch64.

  • For details, see Updates.

aliyun_3_arm64_20G_container_optimized_alibase_20250629.vhd

2025-06-29

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit Container Optimized Edition for ARM base image with the latest software packages.

  • Upgraded the kernel to kernel-5.10.134-19.1.al8.aarch64.

  • For details, see Updates.

Content updates

Security updates

Package name

CVE ID

Updated version

buildah

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

buildah-1.33.8-4.al8

containernetworking-plugins

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

containernetworking-plugins-1.4.0-5.0.1.al8

containers-common

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

containers-common-1-82.0.1.al8

podman

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

podman-4.9.4-12.0.1.al8

python-podman

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

python-podman-4.9.0-2.al8

runc

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

runc-1.1.12-4.0.1.al8

skopeo

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

skopeo-1.14.5-3.0.1.al8

httpd

CVE-2023-27522

httpd-2.4.37-65.0.1.al8.2

git-lfs

CVE-2023-45288

CVE-2023-45289

CVE-2023-45290

CVE-2024-24783

git-lfs-3.4.1-2.0.1.al8

bind

CVE-2024-1975

CVE-2024-1737

bind-9.11.36-16.0.1.al8

python-setuptools

CVE-2024-6345

python-setuptools-39.2.0-8.al8.1

less

CVE-2022-48624

CVE-2024-32487

less-530-3.0.1.al8

java-17-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-17-openjdk-17.0.12.0.7-2.0.2.1.al8

java-11-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-11-openjdk-11.0.24.0.8-3.0.2.1.al8

postgresql

CVE-2024-7348

postgresql-13.16-1.0.1.al8

flatpak

CVE-2024-42472

flatpak-1.12.9-3.al8

bubblewrap

CVE-2024-42472

bubblewrap-0.4.0-2.2.al8

java-1.8.0-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-1.8.0-openjdk-1.8.0.422.b05-2.0.2.1.al8

fence-agents

CVE-2024-6345

fence-agents-4.10.0-62.0.2.al8.4

pcp

CVE-2024-45769

CVE-2024-45770

pcp-5.3.7-22.0.1.al8

delve

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

delve-1.21.2-4.0.1.al8

golang

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

golang-1.21.13-2.0.1.al8

go-toolset

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

go-toolset-1.21.13-1.al8

edk2

CVE-2023-45236

CVE-2023-45237

CVE-2024-1298

edk2-20220126gitbb1bba3d77-13.0.1.al8.2

curl

CVE-2024-2398

curl-7.61.1-35.0.2.al8

libvpx

CVE-2023-6349

CVE-2024-5197

libvpx-1.7.0-11.0.1.al8

resource-agents

CVE-2024-37891

CVE-2024-6345

resource-agents-4.9.0-54.al8.4

389-ds-base

CVE-2024-5953

389-ds-base-1.4.3.39-8.0.1.al8

python-urllib3

CVE-2024-37891

python-urllib3-1.24.2-8.al8

pcs

CVE-2024-41123

CVE-2024-41946

CVE-2024-43398

pcs-0.10.18-2.0.1.1.al8.2

grafana

CVE-2024-24788

CVE-2024-24789

CVE-2024-24790

grafana-9.2.10-17.0.1.al8

libuv

CVE-2024-24806

libuv-1.42.0-2.al8

c-ares

CVE-2024-25629

c-ares-1.13.0-11.al8

xmlrpc-c

CVE-2023-52425

xmlrpc-c-1.51.0-9.0.1.al8

yajl

CVE-2022-24795

CVE-2023-33460

yajl-2.1.0-13.0.1.al8

wpa_supplicant

CVE-2023-52160

wpa_supplicant-2.10-2.al8

cups

CVE-2024-35235

cups-2.2.6-60.0.1.al8

linux-firmware

CVE-2023-31346

linux-firmware-20240610-122.git90df68d2.al8

wget

CVE-2024-38428

wget-1.19.5-12.0.1.al8

poppler

CVE-2024-6239

poppler-20.11.0-12.0.1.al8

krb5

CVE-2024-37370

CVE-2024-37371

krb5-1.18.2-29.0.1.al8

git-lfs

CVE-2024-34156

git-lfs-3.4.1-3.0.1.al8

libreoffice

CVE-2024-3044

CVE-2024-6472

libreoffice-7.1.8.1-12.0.2.1.al8.1

orc

CVE-2024-40897

orc-0.4.28-4.al8

jose

CVE-2023-50967

CVE-2024-28176

jose-10-2.3.al8.3

openssh

CVE-2020-15778

CVE-2023-48795

CVE-2023-51385

openssh-8.0p1-25.0.1.1.al8

libnbd

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

libnbd-1.6.0-6.0.1.al8

qemu-kvm

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

qemu-kvm-6.2.0-53.0.1.al8

libvirt

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

libvirt-8.0.0-23.2.0.2.al8

osbuild-composer

CVE-2024-34156

osbuild-composer-101-2.0.1.al8

libreswan

CVE-2024-3652

libreswan-4.12-2.0.2.al8.4

mod_auth_openidc

CVE-2024-24814

mod_auth_openidc-2.4.9.4-6.al8

podman

CVE-2023-45290

CVE-2024-24783

CVE-2024-24784

CVE-2024-24788

CVE-2024-24791

podman-4.9.4-13.0.1.al8

ghostscript

CVE-2024-29510

CVE-2024-33869

CVE-2024-33870

ghostscript-9.54.0-18.al8

emacs

CVE-2024-39331

emacs-27.2-9.0.3.al8

dovecot

CVE-2024-23184

CVE-2024-23185

dovecot-2.3.16-5.0.1.al8

expat

CVE-2024-45490

CVE-2024-45491

CVE-2024-45492

expat-2.2.5-13.0.1.al8

glib2

CVE-2024-34397

glib2-2.68.4-14.0.2.al8

python-idna

CVE-2024-3651

python-idna-2.5-7.al8

openldap

CVE-2023-2953

openldap-2.4.46-19.al8

python-pillow

CVE-2024-28219

python-pillow-5.1.1-21.al8

nghttp2

CVE-2024-28182

nghttp2-1.33.0-6.0.1.al8.1

python-jinja2

CVE-2024-34064

python-jinja2-2.10.1-3.0.3.al8

opencryptoki

CVE-2024-0914

opencryptoki-3.22.0-3.al8

gdk-pixbuf2

CVE-2021-44648

CVE-2021-46829

CVE-2022-48622

gdk-pixbuf2-2.42.6-4.0.1.al8

rear

CVE-2024-23301

rear-2.6-13.0.1.al8

grub2

CVE-2023-4692

CVE-2023-4693

CVE-2024-1048

grub2-2.02-150.0.2.al8

nss

CVE-2023-5388

CVE-2023-6135

nss-3.101.0-7.0.1.al8

gnutls

CVE-2024-0553

CVE-2024-28834

gnutls-3.6.16-8.0.1.al8.3

python3

CVE-2024-4032

CVE-2024-6232

CVE-2024-6923

python3-3.6.8-67.0.1.2.al8

grafana

CVE-2024-24791

grafana-9.2.10-18.0.1.al8

cups-filters

CVE-2024-47076

CVE-2024-47175

CVE-2024-47176

CVE-2024-47850

cups-filters-1.20.0-35.0.1.al8

linux-firmware

CVE-2023-20584

CVE-2023-31315

CVE-2023-31356

linux-firmware-20240827-124.git3cff7109.al8

golang

CVE-2024-9355

golang-1.21.13-3.0.1.al8

openssl

CVE-2024-5535

openssl-1.1.1k-14.0.1.al8

nano

CVE-2024-5742

nano-2.9.8-2.0.1.al8

runc

CVE-2023-45290

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

runc-1.1.12-5.0.1.al8

OpenIPMI

CVE-2024-42934

OpenIPMI-2.0.32-5.0.1.al8

grafana

CVE-2024-47875

CVE-2024-9355

grafana-9.2.10-20.0.1.al8

java-11-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-11-openjdk-11.0.25.0.9-2.0.1.1.al8

java-1.8.0-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-1.8.0-openjdk-1.8.0.432.b06-2.0.2.1.al8

java-17-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-17-openjdk-17.0.13.0.11-3.0.2.1.al8

NetworkManager-libreswan

CVE-2024-9050

NetworkManager-libreswan-1.2.10-7.0.1.al8

ansible-core

CVE-2024-0690

ansible-core-2.16.3-2.0.1.al8

libtiff

CVE-2023-52356

libtiff-4.4.0-12.0.2.al8

krb5

CVE-2024-3596

krb5-1.18.2-30.0.1.al8

xorg-x11-server

CVE-2024-9632

xorg-x11-server-1.20.11-25.0.1.al8

xmlrpc-c

CVE-2024-45491

xmlrpc-c-1.51.0-10.0.1.al8

bzip2

CVE-2019-12900

bzip2-1.0.6-27.al8

bcc

CVE-2024-2314

bcc-0.25.0-9.0.1.al8

python3.11

CVE-2024-6232

python3.11-3.11.10-1.0.1.al8

buildah

CVE-2024-9341

CVE-2024-9407

CVE-2024-9675

buildah-1.33.10-1.al8

podman

CVE-2024-9341

CVE-2024-9407

CVE-2024-9675

podman-4.9.4-15.0.1.al8

libtiff

CVE-2024-7006

libtiff-4.4.0-12.0.3.al8

libsoup

CVE-2024-52530

CVE-2024-52532

libsoup-2.62.3-6.0.1.al8

gtk3

CVE-2024-6655

gtk3-3.24.31-5.0.2.1.al8

tigervnc

CVE-2024-9632

tigervnc-1.13.1-14.al8

emacs

CVE-2024-30203

CVE-2024-30204

CVE-2024-30205

emacs-27.2-10.0.1.al8

squid

CVE-2024-23638

CVE-2024-45802

squid-4.15-13.al8.3

gnome-shell-extensions

CVE-2024-36472

gnome-shell-extensions-40.7-19.0.1.al8

gnome-shell

CVE-2024-36472

gnome-shell-40.10-21.al8

osbuild-composer

CVE-2024-34156

osbuild-composer-118-2.0.1.al8

expat

CVE-2024-50602

expat-2.2.5-16.al8

iperf3

CVE-2023-7250

CVE-2024-26306

iperf3-3.9-13.al8

lldpd

CVE-2020-27827

CVE-2021-43612

CVE-2023-41910

lldpd-1.0.18-4.0.1.al8

xorg-x11-server-Xwayland

CVE-2024-31080

CVE-2024-31081

CVE-2024-31083

xorg-x11-server-Xwayland-23.2.7-1.al8

bpftrace

CVE-2024-2313

bpftrace-0.16.0-8.al8

perl-Convert-ASN1

CVE-2013-7488

perl-Convert-ASN1-0.27-17.1.0.1.al8

podman

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

podman-4.9.4-18.0.1.al8

grafana-pcp

CVE-2024-9355

grafana-pcp-5.1.1-9.0.1.al8

buildah

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

buildah-1.33.11-1.al8

python-podman

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

python-podman-4.9.0-3.al8

golang

CVE-2024-24790

golang-1.22.7-1.0.2.al8

delve

CVE-2024-24790

delve-1.22.1-1.0.2.al8

go-toolset

CVE-2024-24790

go-toolset-1.22.7-1.al8

pam

CVE-2024-10041

CVE-2024-10963

pam-1.3.1-36.al8

perl-App-cpanminus

CVE-2024-45321

perl-App-cpanminus-1.7044-6.al8

postgresql

CVE-2024-10976

CVE-2024-10978

CVE-2024-10979

postgresql-13.18-1.0.1.al8

python3

CVE-2024-11168

CVE-2024-9287

python3-3.6.8-69.0.1.1.al8

python3.11-cryptography

CVE-2023-49083

python3.11-cryptography-37.0.2-6.0.1.al8

python3.11-setuptools

CVE-2024-6345

python3.11-setuptools-65.5.1-3.al8

python3.11-pip

CVE-2007-4559

python3.11-pip-22.3.1-5.al8

python3.11

CVE-2024-9287

python3.11-3.11.11-1.0.1.al8

php

CVE-2023-0567

CVE-2023-0568

CVE-2023-3247

CVE-2023-3823

CVE-2023-3824

CVE-2024-2756

CVE-2024-3096

CVE-2024-5458

CVE-2024-8925

CVE-2024-8927

CVE-2024-9026

php-7.4.33-2.0.1.al8

pcs

CVE-2024-21510

pcs-0.10.18-2.0.1.1.al8.3

gstreamer1-plugins-good

CVE-2024-47537

CVE-2024-47539

CVE-2024-47540

CVE-2024-47606

CVE-2024-47613

gstreamer1-plugins-good-1.16.1-5.al8

gstreamer1-plugins-base

CVE-2024-47538

CVE-2024-47607

CVE-2024-47615

gstreamer1-plugins-base-1.22.1-3.0.1.al8

libsndfile

CVE-2024-50612

libsndfile-1.0.28-16.0.1.al8

tuned

CVE-2024-52337

tuned-2.22.1-5.0.1.1.al8

edk2

CVE-2024-38796

edk2-20220126gitbb1bba3d77-13.0.1.al8.4

bluez

CVE-2023-45866

bluez-5.63-3.0.1.al8

fontforge

CVE-2024-25081

CVE-2024-25082

fontforge-20200314-6.0.1.al8

mpg123

CVE-2024-10573

mpg123-1.32.9-1.al8

webkit2gtk3

CVE-2024-23271

CVE-2024-27820

CVE-2024-27838

CVE-2024-27851

CVE-2024-40779

CVE-2024-40780

CVE-2024-40782

CVE-2024-40789

CVE-2024-40866

CVE-2024-44185

CVE-2024-44187

CVE-2024-44244

CVE-2024-44296

CVE-2024-4558

webkit2gtk3-2.46.3-2.0.1.al8

python-requests

CVE-2024-35195

python-requests-2.20.0-5.al8

cups-filters

CVE-2024-47076

CVE-2024-47175

CVE-2024-47176

CVE-2024-47850

cups-filters-1.20.0-35.0.2.al8

openssh

CVE-2020-15778

CVE-2023-48795

CVE-2023-51385

openssh-8.0p1-25.0.1.2.al8

pam

CVE-2024-10041

CVE-2024-10963

pam-1.3.1-36.1.al8

webkit2gtk3

CVE-2024-23271

CVE-2024-27820

CVE-2024-27838

CVE-2024-27851

CVE-2024-40779

CVE-2024-40780

CVE-2024-40782

CVE-2024-40789

CVE-2024-40866

CVE-2024-44185

CVE-2024-44187

CVE-2024-44244

CVE-2024-44296

CVE-2024-44309

CVE-2024-4558

webkit2gtk3-2.46.5-1.0.1.al8

dpdk

CVE-2024-11614

dpdk-23.11-2.al8

cups

CVE-2024-47175

cups-2.2.6-62.0.1.al8

iperf3

CVE-2024-53580

iperf3-3.9-13.al8.1

cups

CVE-2024-47175

cups-2.2.6-62.0.2.al8

NetworkManager

CVE-2024-3661

NetworkManager-1.40.16-18.0.1.al8

raptor2

CVE-2024-57823

raptor2-2.0.15-17.0.1.al8

rsync

CVE-2024-12085

rsync-3.1.3-20.0.1.al8

fence-agents

CVE-2024-56201

CVE-2024-56326

fence-agents-4.10.0-76.0.1.al8.4

glibc

CVE-2022-23218

CVE-2022-23219

glibc-2.32-1.19.al8

glibc

CVE-2024-33602

CVE-2024-33601

CVE-2024-33600

CVE-2024-33599

glibc-2.32-1.20.al8

grafana

CVE-2025-21613

CVE-2025-21614

grafana-9.2.10-21.0.1.al8

redis

CVE-2022-24834

CVE-2022-35977

CVE-2022-36021

CVE-2023-22458

CVE-2023-25155

CVE-2023-28856

CVE-2023-45145

CVE-2024-31228

CVE-2024-31449

CVE-2024-46981

redis-6.2.17-1.0.1.1.al8

python-jinja2

CVE-2024-56326

python-jinja2-2.10.1-3.0.4.al8

bzip2

CVE-2019-12900

bzip2-1.0.6-28.al8

libsoup

CVE-2024-52531

libsoup-2.62.3-7.0.1.al8

git-lfs

CVE-2024-53263

git-lfs-3.4.1-4.0.1.al8

keepalived

CVE-2024-41184

keepalived-2.2.8-4.al8

unbound

CVE-2024-1488

CVE-2024-8508

unbound-1.16.2-8.al8

java-17-openjdk

CVE-2025-21502

java-17-openjdk-17.0.14.0.7-3.0.1.1.al8

galera

CVE-2023-22084

CVE-2024-21096

galera-26.4.20-1.al8

mariadb

CVE-2023-22084

CVE-2024-21096

mariadb-10.5.27-1.0.1.al8

doxygen

CVE-2020-11023

doxygen-1.8.14-13.al8

tbb

CVE-2020-11023

tbb-2018.2-10.al8.1

gcc-toolset-13-gcc

CVE-2020-11023

gcc-toolset-13-gcc-13.3.1-2.2.0.1.1.al8

nodejs

CVE-2025-22150

CVE-2025-23083

CVE-2025-23085

nodejs-20.18.2-1.1.al8

nodejs-packaging

CVE-2025-22150

CVE-2025-23083

CVE-2025-23085

nodejs-packaging-2021.06-4.al8

nodejs-nodemon

CVE-2025-22150

CVE-2025-23083

CVE-2025-23085

nodejs-nodemon-3.0.1-1.al8

podman

CVE-2024-11218

podman-4.9.4-19.0.1.al8

buildah

CVE-2024-11218

buildah-1.33.12-1.al8

libcap

CVE-2025-1390

libcap-2.48-6.0.2.al8

libxml2

CVE-2022-49043

libxml2-2.9.7-18.0.4.1.al8

bind

CVE-2024-11187

bind-9.11.36-16.0.1.al8.4

postgresql

CVE-2025-1094

postgresql-13.20-1.0.1.al8

libpq

CVE-2025-1094

libpq-13.20-1.0.1.al8

mecab-ipadic

CVE-2024-11053

CVE-2024-21193

CVE-2024-21194

CVE-2024-21196

CVE-2024-21197

CVE-2024-21198

CVE-2024-21199

CVE-2024-21201

CVE-2024-21203

CVE-2024-21212

CVE-2024-21213

CVE-2024-21218

CVE-2024-21219

CVE-2024-21230

CVE-2024-21231

CVE-2024-21236

CVE-2024-21237

CVE-2024-21238

CVE-2024-21239

CVE-2024-21241

CVE-2024-21247

CVE-2024-37371

CVE-2024-5535

CVE-2024-7264

CVE-2025-21490

CVE-2025-21491

CVE-2025-21494

CVE-2025-21497

CVE-2025-21500

CVE-2025-21501

CVE-2025-21503

CVE-2025-21504

CVE-2025-21505

CVE-2025-21518

CVE-2025-21519

CVE-2025-21520

CVE-2025-21521

CVE-2025-21522

CVE-2025-21523

CVE-2025-21525

CVE-2025-21529

CVE-2025-21531

CVE-2025-21534

CVE-2025-21536

CVE-2025-21540

CVE-2025-21543

CVE-2025-21546

CVE-2025-21555

CVE-2025-21559

mecab-ipadic-2.7.0.20070801-17.0.1.al8

mysql

CVE-2024-11053

CVE-2024-21193

CVE-2024-21194

CVE-2024-21196

CVE-2024-21197

CVE-2024-21198

CVE-2024-21199

CVE-2024-21201

CVE-2024-21203

CVE-2024-21212

CVE-2024-21213

CVE-2024-21218

CVE-2024-21219

CVE-2024-21230

CVE-2024-21231

CVE-2024-21236

CVE-2024-21237

CVE-2024-21238

CVE-2024-21239

CVE-2024-21241

CVE-2024-21247

CVE-2024-37371

CVE-2024-5535

CVE-2024-7264

CVE-2025-21490

CVE-2025-21491

CVE-2025-21494

CVE-2025-21497

CVE-2025-21500

CVE-2025-21501

CVE-2025-21503

CVE-2025-21504

CVE-2025-21505

CVE-2025-21518

CVE-2025-21519

CVE-2025-21520

CVE-2025-21521

CVE-2025-21522

CVE-2025-21523

CVE-2025-21525

CVE-2025-21529

CVE-2025-21531

CVE-2025-21534

CVE-2025-21536

CVE-2025-21540

CVE-2025-21543

CVE-2025-21546

CVE-2025-21555

CVE-2025-21559

mysql-8.0.41-1.0.1.1.al8

emacs

CVE-2025-1244

emacs-27.2-11.0.1.al8.1

webkit2gtk3

CVE-2024-54543

CVE-2025-24143

CVE-2025-24150

CVE-2025-24158

CVE-2025-24162

webkit2gtk3-2.46.6-1.0.1.al8

tigervnc

CVE-2025-26594

CVE-2025-26595

CVE-2025-26596

CVE-2025-26597

CVE-2025-26598

CVE-2025-26599

CVE-2025-26600

CVE-2025-26601

tigervnc-1.13.1-15.al8

rsync

CVE-2024-12087

CVE-2024-12088

CVE-2024-12747

rsync-3.1.3-21.0.1.al8

libxml2

CVE-2024-56171

CVE-2025-24928

libxml2-2.9.7-19.0.1.1.al8

krb5

CVE-2025-24528

krb5-1.18.2-31.0.1.al8

pcs

CVE-2024-52804

pcs-0.10.18-2.0.1.1.al8.4

webkit2gtk3

CVE-2025-24201

webkit2gtk3-2.46.6-2.0.1.al8

fence-agents

CVE-2025-27516

fence-agents-4.10.0-76.0.1.al8.6

podman

CVE-2025-22869

podman-4.9.4-20.0.1.al8

runc

CVE-2025-22869

runc-1.1.12-6.0.1.al8

libreoffice

CVE-2025-0624

libreoffice-7.1.8.1-15.0.1.1.al8.1

libreoffice

CVE-2025-1080

libreoffice-7.1.8.1-15.0.1.1.al8.1

freetype

CVE-2025-27363

freetype-2.10.4-10.al8

python-jinja2

CVE-2025-27516

python-jinja2-2.10.1-7.0.1.al8

libxslt

CVE-2024-55549

CVE-2025-24855

libxslt-1.1.32-6.1.0.1.al8

tomcat

CVE-2024-50379

CVE-2025-24813

tomcat-9.0.87-1.al8.3

expat

CVE-2024-8176

expat-2.2.5-17.al8

mod_auth_openidc

CVE-2025-31492

mod_auth_openidc-2.4.9.4-7.al8

xmlrpc-c

CVE-2024-8176

xmlrpc-c-1.51.0-11.0.1.al8

libtasn1

CVE-2024-12133

libtasn1-4.13-5.0.1.al8

bluez

CVE-2023-27349

CVE-2023-51589

bluez-5.63-5.0.1.al8

Package updates

New features

  • Introduced Confidential AI, which leverages Confidential Computing to enhance data security for AI model training and inference.

  • Added support for PCIe error injection through ras-tools.

  • Added 26 external device drivers for broader hardware compatibility. These drivers are not installed by default.

    • kmod-ast-5.10.134~19-1.14.4~1.al8.src.rpm

    • kmod-bnxt-5.10.134~19-1.10.3_231.0.162.0~2.al8.src.rpm

    • kmod-fic2-5.10.134~19-1.2.6~1.al8.src.rpm

    • kmod-hinic-5.10.134~19-1.0~1.al8.src.rpm

    • kmod-hns3-5.10.134~19-1.0~1.al8.src.rpm

    • kmod-i40e-5.10.134~19-2.23.17~1.al8.src.rpm

    • kmod-iavf-5.10.134~19-4.9.4~1.al8.src.rpm

    • kmod-ice-5.10.134~19-1.12.13.4~2.al8.src.rpm

    • kmod-igb-5.10.134~19-5.14.16~1.al8.src.rpm

    • kmod-intel-QAT20-5.10.134~19-L.0.9.4__00004~1.al8.src.rpm

    • kmod-irdma-5.10.134~19-1.13.43~1.al8.src.rpm

    • kmod-ixgbe-5.10.134~19-5.19.6~1.al8.src.rpm

    • kmod-ixgbevf-5.10.134~19-4.18.7~1.al8.src.rpm

    • kmod-ixgbevf-5.10.134~19-4.18.7~1.al8.src.rpm

    • kmod-kvdo-6.2.8.7-94.0.1.al8.src.rpm

    • kmod-lpfc-5.10.134~19-14.2.673.37~1.al8.src.rpm

    • kmod-mellanox-5.10.134~19-23.10~2.al8.src.rpm

    • kmod-mpi3mr-5.10.134~19-8.11.1.0.0~1.al8.src.rpm

    • kmod-mpt3sas-5.10.134~19-47.00.00.00~1.al8.src.rpm

    • kmod-ngbevf-5.10.134~19-1.2.2~2.al8.src.rpm

    • kmod-ps3stor-5.10.134~19-2.3.1.24~1.al8.src.rpm

    • kmod-ps3stor-5.10.134~19-2.3.1.24~1.al8.src.rpm

    • kmod-qla2xxx-5.10.134~19-10.02.09.00_k~1.al8.src.rpm

    • kmod-sfc-5.10.134~19-5.3.16.1004~2.al8.src.rpm

    • kmod-smartpqi-5.10.134~19-2.1.22_040~1.al8.src.rpm

    • kmod-sxe-5.10.134~19-1.3.1.1~1.al8.src.rpm

    • kmod-txgbevf-5.10.134~19-1.3.1~2.al8.src.rpm

    • kmod-xscale-5.10.134~19-1.2.0_367~2.al8.src.rpm

Important updates

Kernel

The kernel has been updated to kernel-5.10.134-19.1.al8.

  • Scheduling

    • Merged the cluster scheduling feature.

    • Enabled BVT configuration for non-migratable threads in the root cgroup.

    • Core sched now supports independent configuration of special properties for each cookie.

      • Enables sharing cores with regular tasks that do not have a cookie.

      • Prevents load balancing from automatically grouping tasks with the same cookie, ensuring they are distributed across different cores.

  • Memory

    • Fixed stability issues in kfence.

    • Fixed a transparent huge page (THP) accounting issue with code pages.

    • mmap() now supports THP-aligned address space allocation.

    • virtio-mem supports the memmap_on_memory feature, which facilitates the rapid scaling of container memory.

    • Merged several memory-related CVE patches.

  • Network

    • Fixed link group and link use-after-free issues.

    • Fixed an smc-r device lookup failure in container scenarios.

  • Storage

    • erofs

      • Merged several upstream erofs file system fixes.

      • Added support for file-backed mounting and a 48-bit layout.

      • Added sub-page block support for compressed files.

    • Merged upstream stable branch patches for ext4, block, blk-mq, and io_uring components.

    • Introduced the virtio-blk passthrough feature.

      • This feature adds a generic character device, /dev/vdXc0, for each virtio-blk block device. You can now send read/write commands directly to the virtio-blk driver layer using the uring_cmd method from the io_uring framework.

      • This feature also supports bidirectional commands for virtio-blk devices. In a single vectored read/write operation on the same base sector address, you can specify the number of both write and read buffers. A single I/O command can now complete both a write and a subsequent read operation. Currently, only the write-then-read sequence is supported.

      • Introduces ring_pair, a virtio_ring extension for virtio-blk. In this model, each hardware request queue for a virtio-blk device maps to two virtio_ring queues: a submission queue (SQ) and a completion queue (CQ). After a request is submitted, the driver can proactively reclaim the I/O command's slots to issue new requests. When the I/O operation completes, the backend populates the CQ, and the driver harvests the completions. This feature requires backend support for the ring_pair mode and currently supports only the vring split_queue+Indirect descriptor mode.

  • Driver

    • The NVMe driver now supports batch completion handling for polled I/O commands.

    • Fixed multiple issues in the HiSilicon SAS driver for SCSI and in libsas.

    • Merged PCIe driver bugfix patches, addressing issues such as incorrect space size calculation and root bus assignment.

  • BPF

    Merged bugfix and CVE patches from the upstream stable community.

  • Architecture

    Addressed CVEs in the x86 architecture.

Bug fixes

  • Updated alinux-base-setup to alinux-base-setup-3.2-8.al8 to fix an issue where Kdump failed to generate and grubby parameters were ineffective on the ARM architecture.

  • Updated gdm to gdm-40.0-27.0.1.1.al8 to fix an issue where the desktop failed to wake up from screen lock.

  • Updated alinux-release to alinux-release-3.2104.12-1.al8 to update the EULA file for Alibaba Cloud Linux.

  • Updated dump to dump-0.4-0.36.b46.3.al8 to fix an error that occurred when restoring an incremental backup created by dump.

  • Updated maven to maven-3.6.2-9.1.al8 to fix an issue where the mvn command was unavailable immediately after installation on Alibaba Cloud Linux 3.

  • Updated grub2 to grub2-2.02-165.0.2.al8 to fix an issue where grub2 reported errors in TDX scenarios on Alibaba Cloud Linux 3.

Known issue

The virtio-blk passthrough feature introduces a generic character device for virtio-blk devices, which can cause device detection issues in some user-space components.

Note

For a device such as /dev/vda, partitions start at 1. Therefore, /dev/vdac0 represents the character device for /dev/vda and is distinct from /dev/vdac. Additionally, /dev/vdac0 is a character device, not a block device. If you do not need this character channel, you can upgrade the kernel to kernel-5.10.134-19.1.al8 to prevent this interface from being exposed on virtio-blk cloud disks.

Alibaba Cloud Linux (Alinux) 3.2104 U11.1

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U11.1

aliyun_3_x64_20G_alibase_20250117.vhd

2025-01-17

  • Update the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest software packages

  • For more information, see Updates.

aliyun_3_x64_20G_dengbao_alibase_20250117.vhd

2025-01-17

  • Update the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition base image to the latest software packages

  • For more information, see Updates.

aliyun_3_arm64_20G_alibase_20250117.vhd

2025-01-17

  • Update the Alibaba Cloud Linux 3.2104 LTS 64-bit AMR version base image to the latest software version

  • For more information, see Updates.

aliyun_3_arm64_20G_dengbao_alibase_20250117.vhd

2025-01-17

  • Update the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 Edition base image to the latest software version

  • For more information, see Updates.

aliyun_3_x64_20G_container_optimized_20250117.vhd

2025-01-17

  • Update the Alibaba Cloud Linux 3.2104 64-bit Container-Optimized Edition base image to the latest software packages

  • For more information, see Updates.

Updates

Security updates

Package name

CVE ID

python-requests

CVE-2024-35195

cups

CVE-2024-47175

NetworkManager

CVE-2024-3661

Image updates

  • The loadmodules service is enabled by default.

  • The timedatex service is enabled by default.

2024

Alibaba Cloud Linux 3.2104 U11

Version

Image ID

Release date

Release highlights

Alibaba Cloud Linux 3.2104 U11

aliyun_3_x64_20G_alibase_20241218.vhd

2024-12-18

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest software version.

  • Updated the kernel version to 5.10.134-18.al8.x86_64.

  • For details, see Content updates.

aliyun_3_x64_20G_dengbao_alibase_20241218.vhd

2024-12-18

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition base image to the latest software version.

  • Updated the kernel version to 5.10.134-18.al8.x86_64.

  • For details, see Content updates.

aliyun_3_arm64_20G_alibase_20241218.vhd

2024-12-18

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM Edition base image to the latest software version.

  • Updated the kernel version to 5.10.134-18.al8.aarch64.

  • For details, see Content updates.

aliyun_3_arm64_20G_dengbao_alibase_20241218.vhd

2024-12-18

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM Edition MLPS 2.0 Level 3 Edition base image to the latest software version.

  • Updated the kernel version to 5.10.134-18.al8.aarch64.

  • For details, see Content updates.

aliyun_3_x64_20G_container_optimized_20241226.vhd

2024-12-26

  • Added the Alibaba Cloud Linux 3.2104 LTS 64-bit container-optimized edition image.

  • Updated the kernel version to 5.10.134-18.al8.x86_64.

  • For details, see Content updates.

Content updates

Security updates

Package name

CVE ID

Version

grafana

CVE-2024-47875

CVE-2024-9355

grafana-9.2.10-20.0.1.al8

java-11-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-11-openjdk-11.0.25.0.9-2.0.1.1.al8

java-1.8.0-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-1.8.0-openjdk-1.8.0.432.b06-2.0.2.1.al8

java-17-openjdk

CVE-2023-48161

CVE-2024-21208

CVE-2024-21210

CVE-2024-21217

CVE-2024-21235

java-17-openjdk-17.0.13.0.11-3.0.2.1.al8

NetworkManager-libreswan

CVE-2024-9050

NetworkManager-libreswan-1.2.10-7.0.1.al8

ansible-core

CVE-2024-0690

ansible-core-2.16.3-2.0.1.al8

krb5

CVE-2024-3596

krb5-1.18.2-30.0.1.al8

xorg-x11-server

CVE-2024-9632

xorg-x11-server-1.20.11-25.0.1.al8

xmlrpc-c

CVE-2024-45491

xmlrpc-c-1.51.0-10.0.1.al8

bzip2

CVE-2019-12900

bzip2-1.0.6-27.al8

bcc

CVE-2024-2314

bcc-0.25.0-9.0.1.al8

buildah

CVE-2024-9341

CVE-2024-9407

CVE-2024-9675

buildah-1.33.10-1.al8

libtiff

CVE-2024-7006

libtiff-4.4.0-12.0.3.al8

libsoup

CVE-2024-52530

CVE-2024-52532

libsoup-2.62.3-6.0.1.al8

gtk3

CVE-2024-6655

gtk3-3.24.31-5.0.2.1.al8

tigervnc

CVE-2024-9632

tigervnc-1.13.1-14.al8

emacs

CVE-2024-30203

CVE-2024-30204

CVE-2024-30205

emacs-27.2-10.0.1.al8

squid

CVE-2024-23638

CVE-2024-45802

squid-4.15-13.al8.3

gnome-shell-extensions

CVE-2024-36472

gnome-shell-extensions-40.7-19.0.1.al8

gnome-shell

CVE-2024-36472

gnome-shell-40.10-21.al8

osbuild-composer

CVE-2024-34156

osbuild-composer-118-2.0.1.al8

expat

CVE-2024-50602

expat-2.2.5-16.al8

iperf3

CVE-2023-7250

CVE-2024-26306

iperf3-3.9-13.al8

lldpd

CVE-2020-27827

CVE-2021-43612

CVE-2023-41910

lldpd-1.0.18-4.0.1.al8

xorg-x11-server-Xwayland

CVE-2024-31080

CVE-2024-31081

CVE-2024-31083

xorg-x11-server-Xwayland-23.2.7-1.al8

bpftrace

CVE-2024-2313

bpftrace-0.16.0-8.al8

perl-Convert-ASN1

CVE-2013-7488

perl-Convert-ASN1-0.27-17.1.0.1.al8

podman

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

podman-4.9.4-18.0.1.al8

grafana-pcp

CVE-2024-9355

grafana-pcp-5.1.1-9.0.1.al8

buildah

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

buildah-1.33.11-1.al8

python-podman

CVE-2021-33198

CVE-2021-4024

CVE-2024-9676

python-podman-4.9.0-3.al8

golang

CVE-2024-24790

golang-1.22.7-1.0.2.al8

delve

CVE-2024-24790

delve-1.22.1-1.0.2.al8

go-toolset

CVE-2024-24790

go-toolset-1.22.7-1.al8

pam

CVE-2024-10041

CVE-2024-10963

pam-1.3.1-36.al8

perl-App-cpanminus

CVE-2024-45321

perl-App-cpanminus-1.7044-6.al8

postgresql

CVE-2024-10976

CVE-2024-10978

CVE-2024-10979

postgresql-13.18-1.0.1.al8

python3

CVE-2024-11168

CVE-2024-9287

python3-3.6.8-69.0.1.1.al8

python3.11-cryptography

CVE-2023-49083

python3.11-cryptography-37.0.2-6.0.1.al8

python3.11-setuptools

CVE-2024-6345

python3.11-setuptools-65.5.1-3.al8

python3.11-pip

CVE-2007-4559

python3.11-pip-22.3.1-5.al8

python3.11

CVE-2024-9287

python3.11-3.11.11-1.0.1.al8

php

CVE-2023-0567

CVE-2023-0568

CVE-2023-3247

CVE-2023-3823

CVE-2023-3824

CVE-2024-2756

CVE-2024-3096

CVE-2024-5458

CVE-2024-8925

CVE-2024-8927

CVE-2024-9026

php-7.4.33-2.0.1.al8

pcs

CVE-2024-21510

pcs-0.10.18-2.0.1.1.al8.3

Package updates

New features

  • Adds support for confidential computing on AMD and NVIDIA GPUs.

  • Improves lscpu command performance on large-scale PCIe devices with util-linux-2.32.1-46.0.3.al8.

  • Adds erofs-utils-1.8.2-1.al8 to enable container storage.

  • Updates java-11-alibaba-dragonwell-11.0.24.21.21-1.1.al8 to optimize the BigDecimal class in big data scenarios.

  • Updates java-21-alibaba-dragonwell-21.0.4.0.4-1.1.al8 to improve Java performance.

  • Adds system-rpm-config-129-1.0.2.1.al8 to configure system macro variables.

Important updates

Kernel

The kernel is updated to version 5.10.134-18.al8.

  • New hardware support

    • Adds official support for the Intel GNR platform.

    • Adds official support for the AMD Turin platform.

  • Scheduling

    Adds support for cpu sli on cgroup v2, which includes container-level data such as cpuusage and loadavg.

  • Memory

    • Backports multiple memory bugfix patches from the kernel-5.10 stable branch to fix several related issues.

    • The pgtable_share feature is disabled by default.

    • The code segment now supports the direct collapse mode for huge pages, enabling rapid consolidation into a huge page during a page fault.

    • Backports the percpu chunk release optimization patch set to prevent chunk release failures caused by percpu fragmentation.

  • Network

    • Optimizes the RSS logic of virtio_net to align the RSS configuration with the device and ensure correct updates as the number of queues changes.

    • Adds support for 200 Gbps and 400 Gbps speeds for the bond 3ad mode.

  • Storage

    • io_uring

      • Fixes a race condition when concurrently creating percpu sqthread.

      • Validates the CPU configuration when enabling percpu sqthread.

      • Backports patches from the community stable branch to improve code quality.

    • fuse/virtio-fs

      • Adds support for resending pending requests.

      • Adds support for multiple queues to optimize fuse performance.

      • Optimizes read/write separation to prevent a large volume of write requests from blocking read requests.

      • Adds support for the failover feature. After an error, a fuse daemon can use an attach operation to reconnect to the original fuse connection, resend requests, and complete fault recovery.

      • Adds support for 4 MB write alignment to optimize performance.

      • Fixes an IO hang in virtio-fs caused by loading a module larger than 4 MB.

      • Adds tag and queue mapping sysfs interfaces to virtio-fs.

      • Backports patches from the community stable branch to improve code quality.

    • erofs

      • Fixes a UUID issue in erofs_statfs() and optimizes the DEFLATE stream allocation logic.

      • Backports patches from the community stable branch to improve code quality.

    • ext4

      • Optimizes the cleanup logic for EXT4_GROUP_INFO_WAS_TRIMMED_BIT.

      • Backports patches from the community stable branch to improve code quality.

    • xfs

      • Reduces reflink performance jitter caused by potential blocking for tens of milliseconds in xfs_log_force().

      • Fixes a compilation error that occurred when CONFIG_FS_DAX was disabled.

      • Ensures i_blocks is checked correctly when the atomic write feature is enabled.

    • block

      • Fixes an IO hang in the mq-deadline scheduler on devices with multiple hardware queues.

      • Fixes an issue where block throttling could fail because a negative value was calculated for bps throttling when updating the throttling configuration.

      • Removes the blk-mq "running from the wrong CPU" warning.

      • Backports patches from the community stable branch to improve code quality.

    • Misc

      Backports community stable branch patches for modules such as vfs, quota, overlayfs, nfs, cifs, ceph, dm/md, null_blk, nbd, loop, and virtio-blk to improve code quality.

  • Driver

    • Backports watchdog driver fixes from kernel-5.10 LTS to improve stability.

    • The NVMe driver now supports the latest Alibaba Cloud disk activation solution.

    • Backports NVMe driver fixes from kernel-5.10 LTS to improve stability.

    • Backports SCSI-related fixes from kernel-5.10 LTS to improve stability.

    • Backports ATA-related fixes from kernel-5.10 LTS to improve stability.

    • Introduces the sig_enforce_subsys parameter to enforce module signature verification for the block, net, and GPU subsystems.

    • Merges numerous bug fixes for txgbe and txgbevf into the NetXen NIC driver to improve code quality and stability.

  • Perf

    Fixes a pointer memory leak in the perf tool caused by backporting stable branch patches, preventing coredump failures.

  • BPF

    • Adds support for atomic operations in BPF programs.

    • Backports community stable and bugfix patches.

  • Architecture (x86)

    • Adds support for C-states on the Intel GNR platform.

    • Adds support for P-states on EMR and GNR platforms.

    • Updates intel-speed-select to version v1.20 to support new platforms.

    • Adds support for passing the PEBS feature through to a virtual machine.

    • Applies x86 bugfix patches for ACPI, APIC, power, and PMU to other architectures and systems.

    • Upgrades turbostate to version 2023.11.07 to support more features.

    • Adds support for SPR and EMR CXL PMON.

    • Adds support for AMD c2c.

    • Adds support for AMD HSMP.

    • Adds AMD IBRS enhancements.

    • Adds support for AMD ABMC.

Bug fixes

Packages

  • The systemd-239-82.0.3.4.al8.2 package fixes an issue that causes a pod to unexpectedly exit and a deployment to fail. This issue occurs when Delegate=yes is set, which causes systemd to reclaim a non-device cgroup subgroup within 20 seconds.

  • The ledmon-0.97-1.0.2.al8 package fixes a memory leak.

  • The tuned-2.22.1-5.0.1.1.al8 package improves data access efficiency on the Yitian platform.

  • Fixes an issue that causes some components to fail installation from the mirror.

Image

  • Modifies the crashkernel value of the x86 image to fix vmcore generation failures.

  • Changes the default value in /sys/kernel/mm/transparent_hugepage/defrag to defer to accelerate memory reclamation when using transparent huge pages.

Alibaba Cloud Linux 3.2104 U10.1

Version

Image ID

Release date

Description

Alibaba Cloud Linux 3.2104 U10.1

aliyun_3_x64_20G_alibase_20241103.vhd

2024-11-03

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software packages.

  • Upgrades the kernel to version 5.10.134-17.3.al8.x86_64.

  • For details, see Release notes.

aliyun_3_x64_20G_dengbao_alibase_20241103.vhd

2024-11-03

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition base image with the latest software packages.

  • Upgrades the kernel to version 5.10.134-17.3.al8.x86_64.

  • For details, see Release notes.

aliyun_3_arm64_20G_alibase_20241103.vhd

2024-11-03

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software packages.

  • Upgrades the kernel to version 5.10.134-17.3.al8.aarch64.

  • For details, see Release notes.

aliyun_3_arm64_20G_dengbao_alibase_20241103.vhd

2024-11-03

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition MLPS 2.0 Level 3 Edition base image with the latest software packages.

  • Upgrades the kernel to version 5.10.134-17.3.al8.aarch64.

  • For details, see Release notes.

Updates

Security updates

Package name

CVE ID

Version

buildah

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

buildah-1.33.8-4.al8

containernetworking-plugins

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

containernetworking-plugins-1.4.0-5.0.1.al8

containers-common

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

containers-common-1-82.0.1.al8

podman

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

podman-4.9.4-12.0.1.al8

python-podman

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

python-podman-4.9.0-2.al8

runc

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

runc-1.1.12-4.0.1.al8

skopeo

CVE-2023-45290

CVE-2024-1394

CVE-2024-3727

CVE-2024-6104

CVE-2024-24783

CVE-2024-24784

CVE-2024-24789

CVE-2024-37298

skopeo-1.14.5-3.0.1.al8

httpd

CVE-2023-27522

httpd-2.4.37-65.0.1.al8.2

git-lfs

CVE-2023-45288

CVE-2023-45289

CVE-2023-45290

CVE-2024-24783

git-lfs-3.4.1-2.0.1.al8

bind

CVE-2024-1975

CVE-2024-1737

bind-9.11.36-16.0.1.al8

python-setuptools

CVE-2024-6345

python-setuptools-39.2.0-8.al8.1

less

CVE-2022-48624

CVE-2024-32487

less-530-3.0.1.al8

java-17-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-17-openjdk-17.0.12.0.7-2.0.2.1.al8

java-11-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-11-openjdk-11.0.24.0.8-3.0.2.1.al8

postgresql

CVE-2024-7348

postgresql-13.16-1.0.1.al8

flatpak

CVE-2024-42472

flatpak-1.12.9-3.al8

bubblewrap

CVE-2024-42472

bubblewrap-0.4.0-2.2.al8

java-1.8.0-openjdk

CVE-2024-21131

CVE-2024-21138

CVE-2024-21140

CVE-2024-21144

CVE-2024-21145

CVE-2024-21147

java-1.8.0-openjdk-1.8.0.422.b05-2.0.2.1.al8

fence-agents

CVE-2024-6345

fence-agents-4.10.0-62.0.2.al8.4

pcp

CVE-2024-45769

CVE-2024-45770

pcp-5.3.7-22.0.1.al8

delve

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

delve-1.21.2-4.0.1.al8

golang

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

golang-1.21.13-2.0.1.al8

go-toolset

CVE-2024-24791

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

go-toolset-1.21.13-1.al8

edk2

CVE-2023-45236

CVE-2023-45237

CVE-2024-1298

edk2-20220126gitbb1bba3d77-13.0.1.al8.2

curl

CVE-2024-2398

curl-7.61.1-35.0.2.al8

libvpx

CVE-2023-6349

CVE-2024-5197

libvpx-1.7.0-11.0.1.al8

resource-agents

CVE-2024-37891

CVE-2024-6345

resource-agents-4.9.0-54.al8.4

389-ds-base

CVE-2024-5953

389-ds-base-1.4.3.39-8.0.1.al8

python-urllib3

CVE-2024-37891

python-urllib3-1.24.2-8.al8

pcs

CVE-2024-41123

CVE-2024-41946

CVE-2024-43398

pcs-0.10.18-2.0.1.1.al8.2

grafana

CVE-2024-24788

CVE-2024-24789

CVE-2024-24790

grafana-9.2.10-17.0.1.al8

libuv

CVE-2024-24806

libuv-1.42.0-2.al8

c-ares

CVE-2024-25629

c-ares-1.13.0-11.al8

xmlrpc-c

CVE-2023-52425

xmlrpc-c-1.51.0-9.0.1.al8

yajl

CVE-2022-24795

CVE-2023-33460

yajl-2.1.0-13.0.1.al8

wpa_supplicant

CVE-2023-52160

wpa_supplicant-2.10-2.al8

cups

CVE-2024-35235

cups-2.2.6-60.0.1.al8

linux-firmware

CVE-2023-31346

linux-firmware-20240610-122.git90df68d2.al8

wget

CVE-2024-38428

wget-1.19.5-12.0.1.al8

poppler

CVE-2024-6239

poppler-20.11.0-12.0.1.al8

krb5

CVE-2024-37370

CVE-2024-37371

krb5-1.18.2-29.0.1.al8

git-lfs

CVE-2024-34156

git-lfs-3.4.1-3.0.1.al8

libreoffice

CVE-2024-3044

CVE-2024-6472

libreoffice-7.1.8.1-12.0.2.1.al8.1

orc

CVE-2024-40897

orc-0.4.28-4.al8

jose

CVE-2023-50967

CVE-2024-28176

jose-10-2.3.al8.3

openssh

CVE-2020-15778

CVE-2023-48795

CVE-2023-51385

openssh-8.0p1-25.0.1.1.al8

libnbd

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

libnbd-1.6.0-6.0.1.al8

qemu-kvm

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

qemu-kvm-6.2.0-53.0.1.al8

libvirt

CVE-2024-3446

CVE-2024-7383

CVE-2024-7409

libvirt-8.0.0-23.2.0.2.al8

osbuild-composer

CVE-2024-34156

osbuild-composer-101-2.0.1.al8

libreswan

CVE-2024-3652

libreswan-4.12-2.0.2.al8.4

mod_auth_openidc

CVE-2024-24814

mod_auth_openidc-2.4.9.4-6.al8

podman

CVE-2023-45290

CVE-2024-24783

CVE-2024-24784

CVE-2024-24788

CVE-2024-24791

podman-4.9.4-13.0.1.al8

ghostscript

CVE-2024-29510

CVE-2024-33869

CVE-2024-33870

ghostscript-9.54.0-18.al8

emacs

CVE-2024-39331

emacs-27.2-9.0.3.al8

dovecot

CVE-2024-23184

CVE-2024-23185

dovecot-2.3.16-5.0.1.al8

expat

CVE-2024-45490

CVE-2024-45491

CVE-2024-45492

expat-2.2.5-13.0.1.al8

glib2

CVE-2024-34397

glib2-2.68.4-14.0.2.al8

python-idna

CVE-2024-3651

python-idna-2.5-7.al8

openldap

CVE-2023-2953

openldap-2.4.46-19.al8

python-pillow

CVE-2024-28219

python-pillow-5.1.1-21.al8

nghttp2

CVE-2024-28182

nghttp2-1.33.0-6.0.1.al8.1

python-jinja2

CVE-2024-34064

python-jinja2-2.10.1-3.0.3.al8

opencryptoki

CVE-2024-0914

opencryptoki-3.22.0-3.al8

gdk-pixbuf2

CVE-2021-44648

CVE-2021-46829

CVE-2022-48622

gdk-pixbuf2-2.42.6-4.0.1.al8

rear

CVE-2024-23301

rear-2.6-13.0.1.al8

grub2

CVE-2023-4692

CVE-2023-4693

CVE-2024-1048

grub2-2.02-150.0.2.al8

nss

CVE-2023-5388

CVE-2023-6135

nss-3.101.0-7.0.1.al8

gnutls

CVE-2024-0553

CVE-2024-28834

gnutls-3.6.16-8.0.1.al8.3

python3

CVE-2024-4032

CVE-2024-6232

CVE-2024-6923

python3-3.6.8-67.0.1.2.al8

grafana

CVE-2024-24791

grafana-9.2.10-18.0.1.al8

cups-filters

CVE-2024-47076

CVE-2024-47175

CVE-2024-47176

CVE-2024-47850

cups-filters-1.20.0-35.0.1.al8

linux-firmware

CVE-2023-20584

CVE-2023-31315

CVE-2023-31356

linux-firmware-20240827-124.git3cff7109.al8

golang

CVE-2024-9355

golang-1.21.13-3.0.1.al8

openssl

CVE-2024-5535

openssl-1.1.1k-14.0.1.al8

nano

CVE-2024-5742

nano-2.9.8-2.0.1.al8

runc

CVE-2023-45290

CVE-2024-34155

CVE-2024-34156

CVE-2024-34158

runc-1.1.12-5.0.1.al8

OpenIPMI

CVE-2024-42934

OpenIPMI-2.0.32-5.0.1.al8

Package updates

New features

  • Adds the libyang2 component.

  • Upgrades keentuned and keentune-target to version 3.1.1.

    • Adds a tuning option to control the number of network interface queues.

    • Adds a tuning option for priority control.

    • Removes the file-max and scheduler tuning options.

    • Removes insecure command execution.

  • Adds four API components to keentuned: keentune-bench, keentune-brain, keentune-ui, and keenopt.

  • Upgrades tcprt to version 1.1.0 to enhance TCP monitoring capabilities.

  • Upgrades Node.js to version 20.16, providing baseline version 20 capabilities for ACR Artifact Repository.

  • Upgrades erofs-utils to version 1.8.2 for bug fixes and improved EROFS support.

Important updates

Kernel

This release upgrades the kernel to version 5.10.134-17.3.al8.

  • Anolis-specific features

    • SMC (Shared Memory Communications)

      • Adds the AutoSplit feature to reduce latency for large packet transmissions.

      • Allows connections in an SMC Link Group to exclusively use an RDMA QP.

      • Adds shared memory watermark control.

      • Adds support for SMC-layer data dump.

    • swiotlb

      Adds the swiotlb=any kernel command-line parameter to reserve swiotlb across the entire memory space.

  • Upstream features

    • Backports sysctl settings related to SMC Limited Handshake.

    • Backports shared memory usage statistics for SMC LGR and net namespace.

  • TDX

    • Adds a TDX Guest RTMR update interface to support custom measurements for remote attestation.

    • Adds the ECDSA algorithm module.

Bug fixes

  • Updated util-linux to util-linux-2.32.1-46.0.3.al8 to fix slow lscpu performance on clusters with many pci devices.

  • Updated tzdata to tzdata-2024a-1.0.1.6.al8 to fix an issue where some time zone files were missing during migration.

  • Fixed division-by-zero errors, memory leaks, and other issues in the SMC module.

  • Fixed a defect in the ftrace subsystem that could cause a system crash when multiple security programs run concurrently.

  • Fixed a potential out-of-bounds memory access when using uprobe.

Alibaba Cloud Linux 3.2104 U10

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U10

aliyun_3_x64_20G_alibase_20240819.vhd

2024-08-19

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software packages.

  • Updated the kernel to 5.10.134-17.2.al8.x86_64.

  • For details, see Updates.

aliyun_3_x64_20G_dengbao_alibase_20240819.vhd

2024-08-19

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 base image with the latest software packages.

  • Updated the kernel to 5.10.134-17.2.al8.x86_64.

  • For details, see Updates.

aliyun_3_arm64_20G_alibase_20240819.vhd

2024-08-19

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image with the latest software packages.

  • Updated the kernel to 5.10.134-17.2.al8.aarch64.

  • For details, see Updates.

aliyun_3_arm64_20G_dengbao_alibase_20240819.vhd

2024-08-19

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 base image with the latest software packages.

  • Updated the kernel to 5.10.134-17.2.al8.aarch64.

  • For details, see Updates.

Updates

Security updates

Package

CVE ID

Version

adwaita-qt

  • CVE-2023-32573

  • CVE-2023-33285

  • CVE-2023-34410

  • CVE-2023-37369

  • CVE-2023-38197

1.4.2-1.al8

apr

CVE-2022-24963

1.7.0-12.al8

avahi

  • CVE-2021-3468

  • CVE-2023-1981

  • CVE-2023-38469

  • CVE-2023-38470

  • CVE-2023-38471

  • CVE-2023-38472

  • CVE-2023-38473

0.7-21.0.1.al8.1

bind

  • CVE-2023-4408

  • CVE-2023-50387

  • CVE-2023-50868

9.11.36-14.0.1.al8

c-ares

  • CVE-2020-22217

  • CVE-2023-31130

1.13.0-9.al8.1

cockpit

CVE-2024-2947

310.4-1.al8

cups

  • CVE-2023-32324

  • CVE-2023-34241

2.2.6-54.0.1.al8

cups-filters

CVE-2023-24805

1.20.0-32.0.1.al8

curl

CVE-2023-38546

7.61.1-34.0.1.al8

device-mapper-multipath

CVE-2022-41973

0.8.4-39.0.2.al8

dhcp

  • CVE-2023-4408

  • CVE-2023-50387

  • CVE-2023-50868

4.3.6-50.0.1.al8

dnsmasq

  • CVE-2023-50387

  • CVE-2023-50868

2.79-32.0.1.al8

edk2

  • CVE-2022-36763

  • CVE-2022-36764

  • CVE-2022-36765

  • CVE-2023-3446

  • CVE-2023-45229

  • CVE-2023-45230

  • CVE-2023-45231

  • CVE-2023-45232

  • CVE-2023-45233

  • CVE-2023-45234

  • CVE-2023-45235

20220126gitbb1bba3d77-13.0.1.al8

expat

CVE-2023-52425

2.2.5-13.al8

evolution-mapi

  • CVE-2022-1615

  • CVE-2022-2127

  • CVE-2023-34966

  • CVE-2023-34967

  • CVE-2023-34968

3.40.1-6.al8

flatpak

  • CVE-2023-28100

  • CVE-2023-28101

  • CVE-2024-32462

1.12.9-1.al8

frr

  • CVE-2023-31490

  • CVE-2023-41358

  • CVE-2023-41909

  • CVE-2023-46752

  • CVE-2023-46753

7.5.1-16.0.4.al8

fwupd

CVE-2022-3287

1.7.8-2.0.1.al8

ghostscript

CVE-2024-33871

9.54.0-16.al8

git

  • CVE-2024-32002

  • CVE-2024-32004

  • CVE-2024-32020

  • CVE-2024-32021

  • CVE-2024-32465

2.43.5-1.0.1.al8

glib2

  • CVE-2023-29499

  • CVE-2023-32611

  • CVE-2023-32665

2.68.4-11.al8

gmp

CVE-2021-43618

6.2.0-13.0.1.al8

gnutls

CVE-2023-5981

3.6.16-8.0.2.al8

grafana

  • CVE-2024-1313

  • CVE-2024-1394

9.2.10-16.0.1.al8

grafana-pcp

CVE-2024-1394

5.1.1-2.0.1.al8

gstreamer1-plugins-bad-free

  • CVE-2023-40474

  • CVE-2023-40475

  • CVE-2023-40476

  • CVE-2023-50186

1.22.1-4.0.1.al8

gstreamer1-plugins-base

CVE-2023-37328

1.22.1-2.0.1.al8

gstreamer1-plugins-good

CVE-2023-37327

1.16.1-4.al8

harfbuzz

CVE-2023-25193

2.7.4-10.0.1.al8

httpd

  • CVE-2023-31122

  • CVE-2023-45802

  • CVE-2024-27316

2.4.37-64.0.1.al8

mod_http2

  • CVE-2023-31122

  • CVE-2023-45802

  • CVE-2024-27316

1.15.7-10.al8

java-1.8.0-openjdk

  • CVE-2024-20918

  • CVE-2024-20919

  • CVE-2024-20921

  • CVE-2024-20926

  • CVE-2024-20945

  • CVE-2024-20952

  • CVE-2024-21011

  • CVE-2024-21068

  • CVE-2024-21085

  • CVE-2024-21094

1.8.0.412.b08-2.0.1.1.al8

java-11-openjdk

  • CVE-2024-20918

  • CVE-2024-20919

  • CVE-2024-20921

  • CVE-2024-20926

  • CVE-2024-20945

  • CVE-2024-20952

  • CVE-2024-21011

  • CVE-2024-21012

  • CVE-2024-21068

  • CVE-2024-21085

  • CVE-2024-21094

11.0.23.0.9-3.0.1.1.al8

libfastjson

CVE-2020-12762

0.99.9-5.al8

libjpeg-turbo

CVE-2021-29390

2.0.90-7.0.1.al8

liblouis

  • CVE-2023-26767

  • CVE-2023-26768

  • CVE-2023-26769

3.16.1-5.al8

libmicrohttpd

CVE-2023-27371

0.9.59-3.al8

libpq

CVE-2022-41862

13.11-1.0.1.al8

librabbitmq

CVE-2023-35789

0.11.0-7.0.1.al8

libreoffice

  • CVE-2022-26305

  • CVE-2022-26306

  • CVE-2022-26307

  • CVE-2022-3140

  • CVE-2022-38745

  • CVE-2023-0950

  • CVE-2023-1183

  • CVE-2023-2255

  • CVE-2023-6185

  • CVE-2023-6186

7.1.8.1-12.0.1.1.al8.1

libreswan

  • CVE-2023-2295

  • CVE-2023-30570

  • CVE-2023-38710

  • CVE-2023-38711

  • CVE-2023-38712

4.12-2.0.2.al8

libsndfile

CVE-2022-33065

1.0.28-13.0.2.al8

libssh

  • CVE-2023-48795

  • CVE-2023-6004

  • CVE-2023-6918

0.9.6-12.al8

libtiff

  • CVE-2022-2056

  • CVE-2022-2057

  • CVE-2022-2058

  • CVE-2022-2519

  • CVE-2022-2520

  • CVE-2022-2521

  • CVE-2022-2867

  • CVE-2022-2868

  • CVE-2022-2953

  • CVE-2022-3627

  • CVE-2022-3970

  • CVE-2022-48281

  • CVE-2023-0795

  • CVE-2023-0796

  • CVE-2023-0797

  • CVE-2023-0798

  • CVE-2023-0799

  • CVE-2023-0800

  • CVE-2023-0801

  • CVE-2023-0802

  • CVE-2023-0803

  • CVE-2023-0804

  • CVE-2023-26965

  • CVE-2023-26966

  • CVE-2023-2731

  • CVE-2023-3316

  • CVE-2023-3576

  • CVE-2022-40090

  • CVE-2023-3618

  • CVE-2023-40745

  • CVE-2023-41175

  • CVE-2023-6228

4.4.0-12.0.1.al8

libvirt

  • CVE-2021-3750

  • CVE-2023-3019

  • CVE-2023-3301

  • CVE-2023-3255

  • CVE-2023-5088

  • CVE-2023-6683

  • CVE-2023-6693

  • CVE-2024-2494

8.0.0-23.1.0.1.al8

qemu-kvm

  • CVE-2021-3750

  • CVE-2023-3019

  • CVE-2023-3301

  • CVE-2023-3255

  • CVE-2023-5088

  • CVE-2023-6683

  • CVE-2023-6693

  • CVE-2024-2494

6.2.0-49.0.1.al8

libX11

  • CVE-2023-43785

  • CVE-2023-43786

  • CVE-2023-43787

  • CVE-2023-3138

1.7.0-9.al8

libxml2

  • CVE-2023-39615

  • CVE-2024-25062

2.9.7-18.0.3.al8

libXpm

  • CVE-2023-43788

  • CVE-2023-43789

3.5.13-10.0.1.al8

linux-firmware

  • CVE-2022-46329

  • CVE-2023-20569

  • CVE-2023-20592

20240111-121.gitb3132c18.al8

motif

  • CVE-2023-43788

  • CVE-2023-43789

2.3.4-20.al8

openchange

  • CVE-2022-2127

  • CVE-2023-34966

  • CVE-2023-34967

  • CVE-2023-34968

2.3-32.0.1.al8

opensc

  • CVE-2023-40660

  • CVE-2023-40661

  • CVE-2023-5992

  • CVE-2023-2977

0.20.0-7.0.1.al8

openssh

CVE-2023-51385

8.0p1-20.0.1.al8

openssl

  • CVE-2023-3446

  • CVE-2023-3817

  • CVE-2023-5678

1.1.1k-12.0.1.al8

pam

CVE-2024-22365

1.3.1-28.al8

pcp

CVE-2024-3019

5.3.7-20.0.1.al8

perl-HTTP-Tiny

CVE-2023-31486

0.074-2.0.1.al8.1

pixman

CVE-2022-44638

0.40.0-6.al8

pmix

CVE-2023-41915

3.2.3-5.al8

poppler

CVE-2020-36024

20.11.0-10.0.2.al8

postgresql-jdbc

CVE-2024-1597

42.2.14-3.al8

procps-ng

CVE-2023-4016

3.3.15-14.0.1.al8

protobuf-c

CVE-2022-48468

1.3.0-7.al8

python-cryptography

CVE-2023-23931

3.2.1-7.al8

python-dns

CVE-2023-29483

1.15.0-12.al8

python-pillow

  • CVE-2023-50447

  • CVE-2023-44271

5.1.1-20.al8

python-pip

CVE-2007-4559

9.0.3-23.0.1.al8.1

python3

  • CVE-2007-4559

  • CVE-2022-48560

  • CVE-2022-48564

  • CVE-2023-27043

  • CVE-2023-40217

  • CVE-2023-6597

  • CVE-2024-0450

3.6.8-62.0.1.2.al8

qt5-qtbase

  • CVE-2023-33285

  • CVE-2023-34410

  • CVE-2023-37369

  • CVE-2023-38197

  • CVE-2023-51714

  • CVE-2024-25580

5.15.3-5.0.3.al8

qt5-qtsvg

CVE-2023-32573

5.15.3-2.al8

rpm

  • CVE-2021-35937

  • CVE-2021-35938

  • CVE-2021-35939

4.14.3-27.0.5.2.al8

samba

  • CVE-2023-3961

  • CVE-2023-4091

  • CVE-2023-42669

4.18.6-3.0.1.1.al8

shadow-utils

CVE-2023-4641

4.6-19.0.1.al8

shim

  • CVE-2023-40546

  • CVE-2023-40547

  • CVE-2023-40548

  • CVE-2023-40549

  • CVE-2023-40550

  • CVE-2023-40551

15.8-2.0.1.1.al8

sqlite

CVE-2023-7104

3.26.0-19.al8

squashfs-tools

  • CVE-2021-40153

  • CVE-2021-41072

4.3-20.1.0.3.al8

sssd

CVE-2023-3758

2.9.4-3.al8

sudo

  • CVE-2023-28486

  • CVE-2023-28487

  • CVE-2023-42465

1.9.5p2-1.0.1.al8

sysstat

CVE-2023-33204

11.7.3-11.0.1.al8

tang

CVE-2023-1672

7-8.al8

tcpdump

CVE-2021-41043

4.9.3-4.0.1.al8

tigervnc

  • CVE-2023-5380

  • CVE-2023-6816

  • CVE-2024-0229

  • CVE-2024-21885

  • CVE-2024-21886

  • CVE-2024-31080

  • CVE-2024-31081

  • CVE-2024-31083

1.13.1-10.0.1.al8

tpm2-tss

CVE-2023-22745

2.3.2-5.0.2.al8

traceroute

CVE-2023-46316

2.1.0-6.2.0.3.al8

unbound

CVE-2024-1488

1.16.2-7.al8

util-linux

CVE-2024-28085

2.32.1-45.0.1.1.al8.1

webkit2gtk3

  • CVE-2014-1745

  • CVE-2023-32359

  • CVE-2023-39928

  • CVE-2023-40414

  • CVE-2023-41983

  • CVE-2023-42852

  • CVE-2023-42883

  • CVE-2023-42890

  • CVE-2024-23206

  • CVE-2024-23213

2.42.5-1.0.1.al8

wireshark

  • CVE-2023-0666

  • CVE-2023-2856

  • CVE-2023-2858

  • CVE-2023-2952

2.6.2-17.al8

xorg-x11-server

  • CVE-2023-1393

  • CVE-2024-31080

  • CVE-2024-31081

  • CVE-2024-31083

1.20.11-16.0.4.al8

xorg-x11-server-Xwayland

  • CVE-2022-3550

  • CVE-2022-3551

  • CVE-2022-4283

  • CVE-2022-46340

  • CVE-2022-46341

  • CVE-2022-46342

  • CVE-2022-46343

  • CVE-2022-46344

  • CVE-2023-0494

  • CVE-2023-1393

  • CVE-2023-5367

  • CVE-2023-6377

  • CVE-2023-6478

  • CVE-2023-6816

  • CVE-2024-0229

  • CVE-2024-0408

  • CVE-2024-0409

  • CVE-2024-21885

  • CVE-2024-21886

22.1.9-5.al8

yajl

CVE-2023-33460

2.1.0-12.0.1.al8

zziplib

CVE-2020-18770

0.13.71-11.al8

buildah

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

  • CVE-2024-28176

1.33.7-2.al8

cockpit-podman

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

84.1-1.al8

conmon

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

2.1.10-1.al8

container-selinux

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

2.229.0-2.al8

containernetworking-plugins

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

1.4.0-2.0.1.al8

containers-common

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

1-81.0.1.al8

criu

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

3.18-5.0.1.al8

fuse-overlayfs

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

1.13-1.0.1.al8

podman

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

  • CVE-2024-28176

4.9.4-3.0.1.al8

runc

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

1.1.12-1.0.1.al8

slirp4netns

  • CVE-2022-27191

  • CVE-2022-2989

  • CVE-2022-3064

  • CVE-2022-41723

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-25173

  • CVE-2023-25809

  • CVE-2023-27561

  • CVE-2023-28642

  • CVE-2023-29400

  • CVE-2023-29406

  • CVE-2023-3978

  • CVE-2024-21626 CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

1.2.3-1.al8

libslirp

  • CVE-2018-25091

  • CVE-2021-33198

  • CVE-2021-34558

  • CVE-2022-2879

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2023-29409

  • CVE-2023-39318

  • CVE-2023-39319

  • CVE-2023-39321

  • CVE-2023-39322

  • CVE-2023-39326

  • CVE-2023-45287

  • CVE-2023-45803

  • CVE-2023-48795

  • CVE-2024-1753

  • CVE-2024-23650

  • CVE-2024-24786

  • CVE-2024-28180

4.4.0-2.al8

Package updates

New features

  • Rdma-core now supports eRDMA.

  • Rasdaemon now supports memory CE error isolation.

  • Nginx now uses OpenSSL 3.

  • Aliyun-cli is now version 3.0.210.

Important updates

Kernel

Upgraded the kernel to version 5.10.134-17.2.al8.

New features

  • Adds native kernel-level failover for FUSE to ensure uninterrupted file access.

  • Adds support for dynamic kernel preemption. This feature aligns with the upstream community's design and lets you switch the preemption model by using cmdline or sysfs. The supported models are none and voluntary. The full model is not yet supported.

  • Enhances perf to support performance metrics for CMN and DDR PMUs.

  • BPF features

    • New BPF helpers

      • bpf_for_each_map_elem: Iterates over BPF map elements.

      • bpf_snprintf: Formats strings.

      • bpf_timer: Triggers a callback function after a specified time.

      • bpf_loop: Removes the limitation of constant-bounded loops, enabling flexible loop implementation.

      • bpf_strncmp: Compares strings.

      • bpf_ktime_get_tai_ns: Gets the time based on the CLOCK_TAI clock source.

      • bpf_skb_load_bytes: Adds support for the raw_tp type, enabling programs of this type to read skb data, including non-linear data.

    • Enables attaching BPF trampoline features, including fentry, fexit, fmod_ret, and bpf_lsm, on the arm64 architecture to provide more powerful tracing, diagnostics, and security.

    • Allows bpf_trampoline to coexist with livepatch.

  • Virtio-net features

    • Adds support for retrieving virtio-net device statistics to improve troubleshooting and diagnostics.

    • Introduces a queue reset feature that resizes virtual machine queues to reduce packet loss and optimize latency.

    • Introduces dynamic interrupt moderation (netdim), which intelligently adjusts interrupt coalescing parameters based on real-time traffic to optimize data reception performance.

    • Optimizes virtio checksum handling by fixing a verification issue with the virtio network interface controller (NIC) under specific feature controls. As a result, the checksum no longer requires re-verification in the guest operating system in XDP applications, which significantly reduces CPU usage.

  • Enables failover support for the EROFS on-demand loading mode.

  • Fixes a semantic issue with O_DIRECT and O_SYNC in the ext4 file system. This issue has existed since the introduction of the iomap framework. The problem occurred because generic_write_sync() was called within the iomap framework, but the file size (i_disksize) was updated after iomap_dio_rw() completed. In append-write scenarios, the system failed to update the on-disk file size promptly. As a result, written data could become unreadable after a power failure.

  • Adds support for delayed inode invalidation to the XFS file system. This feature offloads inode reclamation to a background kworker process, reducing application stuttering from foreground delete operations.

  • FUSE features and optimizations

    • Adds support for shared memory mapping (mmap) in cache=none mode.

    • Adds a dynamic sysfs switch for the FUSE strict limit feature to resolve slow write-backs or stuttering that can occur in certain scenarios.

  • Optimizes kernfs global lock contention to reduce load spikes caused by concurrent access from monitoring programs.

  • Group Identity features

  • Group Identity 2.0 fine-grained priority

    • Adds support for the smc_pnet feature in Shared Memory Communications over RDMA (SMC-R) and eRDMA use cases.

    • Improves reachability checks in SMC and eRDMA scenarios to fix a rare kernel crash.

  • Calibrates the CPU share ratio for Group Identity 2.0.

  • Adds the force_idled_time metric for Group Identity 2.0.

  • Optimizes Group Identity's load control for tasks with different priorities.

  • Basic Group Balancer features

    • Adds support for passing zero-length iovec in rafsv6 mode.

    • Allows reclamation of dax mappings in rafsv6 mode. This prevents Out of memory (OOM) errors and FUSE hangs caused by pinned memory.

    • Uses kconfig to restrict rafsv6 usage to secure containers.

  • SMC optimizations and support

  • Adds a timeout mechanism for the control vq in virtio. This prevents continuous polling from consuming a virtual machine's CPU resources when a device becomes unresponsive. The default timeout is 7 days.

  • Adds a feature to isolate slab memory used by out-of-tree modules. This helps isolate memory corruption issues caused by out-of-tree modules.

  • Introduces a fast Out of memory (OOM) feature to prevent long periods of unresponsiveness in multi-core, large-memory environments when memory is low. This feature helps increase memory deployment density and improves stability for online services under high memory pressure.

  • EROFS support and optimizations

  • XFS adds support for fsdax reflink and dedupe, with specific optimizations for Tair PMEM instances. These optimizations include ensuring the contiguity of snapshot source files, improving dirty page write-back efficiency, and removing the dependency on the reverse-map B-tree to reduce page fault latency.

  • Adds support for cgroup writeback to fix an issue where memory cgroups were not released for long periods when lazytime was enabled. This issue could cause the number of memory cgroups to remain high in containerized environments, consuming memory and increasing sys CPU usage when iterating through cgroups.

  • Extends the cgroup v2 I/O SLI by adding blkio cgroup v2 metrics, including wait time, service time, complete time, io queued, and bytes queued.

  • When each bio_vec contains only a single 4 KB page, the 5.10 kernel supports a maximum I/O size of 1 MB. The additional logic for splitting I/O operations can impact performance in some scenarios.

  • Fixes an ABBA deadlock caused by a race condition when setting blk-iocost QoS parameters.

  • Adds support for configuring tcmu_loop device parameters, including can_queue, nr_hw_queues, cmd_per_lun, and sg_tablesize. Increasing these parameters on powerful backend devices can significantly improve performance.

Image updates

  • Operating system image

    • Added the spec_rstack_overflow=off boot parameter.

    • Added the kfence.sample_interval=100 kfence.booting_max=0-2G:0,2G-32G:2M,32G-:32M boot parameter.

    • Set the net.ipv4.tcp_retries2 parameter to 8.

    • Set the net.ipv4.tcp_syn_retries parameter to 4.

    • Removed the NTP server configuration for Classic Network.

  • Container image

    alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.2104U10

Bug fixes

  • Kernel

    • Fixed a linked list corruption caused by incorrect scheduling of the credits_announce_work work item in the smc kernel module.

    • Fixed a race condition in perf_cgroup_switch.

    • Prevented the Group Identity 2.0 Queue other time statistic from becoming negative.

    • Fixed incorrect cfs_rq runtime statistics.

    • Fixed an issue where cfs_rq->core could be NULL.

    • Enabled sound card drivers (CONFIG_SND).

    • Fixed a kernel crash caused by kfence when cgroup kmem accounting was enabled.

    • Fixed issues on the LoongArch architecture.

    • Improved EROFS stability in compression mode.

    • Improved erofs stability over fscache.

    • Improved SMC-related stability.

    • Fixed a writeback performance degradation when a BDI used the STRICTLIMIT feature and its share was set to 0.

    • Fixed a memory leak in seccomp.

    • Fixed an issue where the ZERO_PAGE reference count could be incorrect during certain user operations.

    • Fixed a potential recursive memory reclamation issue in TCMU.

    • Fixed a kernel crash caused by the ioasids subsystem when migrating kernel threads.

    • Fixed an issue where I/O operations were counted multiple times when no rate-limiting rules were configured.

    • Fixed an unexpected hardware signal hang during frequent communication between Phytium S2500 and certain BMC chips.

    • Fixed a kernel panic caused by enabling Group Identity and core scheduling simultaneously.

    • Changed the throttling mechanism for CFS bandwidth control from synchronous mode to asynchronous mode to optimize bandwidth control efficiency on systems with a large number of CPUs.

    • Fixed a potential race condition when disabling the global switch for core scheduling.

    • Fixed inaccurate SIB Idle statistics under high interrupt request (IRQ) loads.

    • Backported patches for NVMe over RDMA from newer versions to improve system stability.

    • Fixed a deadlock during the concurrent execution of nvme_reset and nvme_rescan.

    • Fixed a kernel crash caused by a use-after-free (UAF) issue related to Active-State Power Management (ASPM) in the PCIe driver.

    • Fixed a screen corruption issue on Phytium S5000C devices with AST2600 graphics cards.

    • Fixed a warning caused by asynchronous unthrottle to avoid a potential scheduling deadlock.

    • CVE-2023-52445

    • CVE-2023-6817

    • CVE-2024-0646

    • CVE-2023-20569

    • CVE-2023-51042

    • CVE-2023-6915

    • CVE-2023-6546

    • CVE-2022-38096

    • CVE-2024-0565

    • CVE-2024-26589

    • CVE-2024-23307

    • CVE-2024-22099

    • CVE-2024-24860

    • CVE-2024-1086

    • CVE-2023-51779

    • CVE-2024-26597

    • CVE-2024-24855

    • CVE-2023-52438

    • CVE-2023-4622

    • CVE-2023-6932

    • CVE-2023-20588

    • CVE-2023-5717

    • CVE-2023-6931

    • CVE-2023-28464

    • CVE-2023-39192

    • CVE-2023-6176

    • CVE-2023-45863

    • CVE-2023-5178

    • CVE-2023-45871

    • CVE-2023-4155

    • CVE-2023-20593

    • CVE-2023-3567

    • CVE-2023-3358

    • CVE-2023-0615

    • CVE-2023-31083

    • CVE-2023-4015

    • CVE-2023-42753

    • CVE-2023-4623

    • CVE-2023-4921

    • CVE-2023-2860

    • CVE-2023-1206

    • CVE-2023-3772

    • CVE-2023-42755

    • CVE-2023-3863

    • CVE-2022-3114

    • CVE-2023-31085

    • CVE-2023-4132

    • CVE-2022-3424

    • CVE-2022-3903

    • CVE-2022-45887

    • CVE-2023-3006

    • CVE-2023-42754

    • CVE-2023-0160

  • Image

    • Standardized the debuginfo repository names. You can now install the corresponding debuginfo packages by running the dnf debuginfo-install <package_name> command.

    • Extended the dnf-makecache service interval from 1 hour to 1 day to reduce disk and network usage.

    • The virtio_blk driver is now in-tree, so its module configuration has been removed from initramfs.

  • Package

    Fixed a bug in dnf-plugin-releasever-adapter where the dnf command could fail.

Alibaba Cloud Linux 3.2104 U9.1

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U9.1

aliyun_3_x64_20G_alibase_20240528.vhd

2024-05-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest version.

  • Upgrades the kernel to 5.10.134-16.3.al8.x86_64.

  • For details, see Content updates.

aliyun_3_arm64_20G_alibase_20240528.vhd

2024-05-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version base image to the latest version.

  • Upgrades the kernel to 5.10.134-16.3.al8.aarch64.

  • For details, see Content updates.

aliyun_3_x64_20G_dengbao_alibase_20240528.vhd

2024-05-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition base image to the latest version.

  • Upgrades the kernel to 5.10.134-16.3.al8.x86_64.

  • For details, see Content updates.

aliyun_3_arm64_20G_dengbao_alibase_20240528.vhd

2024-05-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM version MLPS 2.0 Level 3 Edition base image to the latest version.

  • Upgrades the kernel to 5.10.134-16.3.al8.aarch64.

  • For details, see Content updates.

Content updates

Security updates

Package name

CVE ID

Package version

kernel

  • CVE-2024-22099

  • CVE-2024-24860

  • CVE-2024-1086

  • CVE-2023-51779

  • CVE-2024-26597

  • CVE-2024-24855

  • CVE-2023-52438

  • CVE-2023-4622

  • CVE-2023-6932

  • CVE-2023-20588

  • CVE-2023-5717

  • CVE-2023-6931

  • CVE-2023-28464

  • CVE-2023-39192

  • CVE-2023-6176

  • CVE-2023-45863

  • CVE-2023-5178

  • CVE-2023-45871

5.10.134-16.3.al8

bind

CVE-2022-3094

9.11.36-11.0.1.al8

buildah

  • CVE-2023-25173

  • CVE-2022-41724

  • CVE-2022-41725

  • CVE-2023-24537

  • CVE-2023-24538

  • CVE-2023-24534

  • CVE-2023-24536

  • CVE-2022-41723

  • CVE-2023-24539

  • CVE-2023-24540

  • CVE-2023-29400

1.31.3-1.al8

dnsmasq

CVE-2023-28450

2.79-31.0.1.al8

edk2-20220126gitbb1bba3d77

CVE-2019-14560

6.0.2.al8

frr

  • CVE-2023-38406

  • CVE-2023-38407

  • CVE-2023-47235

  • CVE-2023-47234

7.5.1-16.0.2.al8

grafana

  • CVE-2023-3128

  • CVE-2023-39325

  • CVE-2023-44487

9.2.10-7.0.1.al8

grafana

CVE-2024-1394

9.2.10-7.0.1.al8

grafana-pcp

5.1.1-1.0.1.al8

gstreamer1-plugins-bad-free

CVE-2023-44429

1.22.1-2.0.1.al8

tigervnc

CVE-2023-44446

1.13.1-2.al8

unbound

  • CVE-2023-50387

  • CVE-2023-50868

1.16.2-6.al8

webkit2gtk3

CVE-2023-42917

2.40.5-1.0.2.al8.1

glibc

CVE-2024-2961

2.32-1.16.al8

python2-setuptools

CVE-2022-40897

39.0.1-13.1.module+al8+9+77049424

Package updates

Package name

Release version

cloud-init

23.2.2

container-selinux

2.229.0

ethtool

6.6

iproute

6.2.0

iptables

1.8.5

keentuned

2.4.0

keentune-target

2.4.0

rng-tools

6.16

sssd

2.9.1

sudo

1.9.5p2

sysak

2.4.0

Important updates

  • Kernel updates

    • Upgrades the kernel to 5.10.134-16.3.al8.

    • Adds support for smc_pnet in SMC-R and eRDMA scenarios.

    • Adds support for HWDRC, an RDT-based dynamic memory bandwidth control technology, to provide more precise control over resources like memory bandwidth and cache.

    • Optimizes Group Identity to better control workloads with different priorities.

  • New package features

    • Upgrades aliyun-cli to 3.0.204. You can now use yum or dnf to install and update aliyun-cli.

    • Upgrades cloud-init to 23.2.2 to support accessing instance metadata in hardened mode.

    • Upgrades ethtool to 6.6 to support the CMIS protocol.

    • Upgrades sysak to 2.4.0. This update optimizes diagnostic capabilities, introduces node monitoring, adds support for sysom observability on nodes, and includes several bug fixes.

    • Upgrades keentune to 2.4.0.

Image updates

  • Container images

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.9.1

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest

      Note

      After this release, the latest tag no longer points to the 3.9.1 image.

  • Virtual machine images

    The images are now UEFI-Preferred and support both UEFI and Legacy boot modes.

Bug fixes

  • Kernel

    • Improves the stability of erofs compression mode.

    • Improves the stability of erofs over fscache.

    • Improves SMC-related stability.

    • Fixes writeback performance degradation when BDI uses the STRICTLIMIT feature with a share of 0.

    • Fixes a memory leak in seccomp.

    • Fixes an incorrect ZERO_PAGE reference count caused by user operations.

    • Fixes a potential recursive memory reclamation issue in TCMU.

    • Fixes a kernel crash caused by the ioasids subsystem migrating a kernel thread.

    • Fixes duplicate I/O statistics when no throttling rules are configured.

    • Fixes an unexpected hardware signal hang caused by frequent communication between Phytium S2500 and certain BMC chips.

    • Fixes a kernel panic caused by enabling Group Identity and core scheduling simultaneously.

    • Changes the CFS bandwidth control's unthrottling mechanism from synchronous to asynchronous to optimize efficiency in high-CPU scenarios.

    • Fixes a potential race condition when the global core sched switch is disabled.

    • Fixes inaccurate sibidle statistics in high-IRQ scenarios.

  • Image

    Fixes an issue where a newly installed kernel failed to take effect after a system reboot.

2023

Alibaba Cloud Linux 3.2104 U9

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U9

aliyun_3_9_x64_20G_alibase_20231219.vhd

2023-12-19

  • Updates the software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Updates the kernel version to 5.10.134-16.1.al8.x86_64.

  • For details, see content updates.

aliyun_3_9_arm64_20G_alibase_20231219.vhd

2023-12-19

  • Updates the software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image.

  • Updates the kernel version to 5.10.134-16.1.al8.aarch64.

  • For details, see content updates.

aliyun_3_9_x64_20G_dengbao_alibase_20231219.vhd

2023-12-19

  • Updates the software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition base image.

  • Updates the kernel version to 5.10.134-16.1.al8.x86_64.

  • For details, see content updates.

aliyun_3_9_arm64_20G_dengbao_alibase_20231219.vhd

2023-12-19

  • Updates the software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 Edition base image.

  • Updates the kernel version to 5.10.134-16.1.al8.aarch64.

  • For details, see content updates.

aliyun_3_9_x64_20G_uefi_alibase_20231219.vhd

2023-12-19

  • Updates the software packages in the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition base image.

  • Updates the kernel version to 5.10.134-16.1.al8.x86_64.

  • For details, see content updates.

Content updates

Security updates

Parameter

CVE ID

Package version

kernel

  • CVE-2022-3108

  • CVE-2022-3114

  • CVE-2022-3424

  • CVE-2022-36280

  • CVE-2022-3903

  • CVE-2022-39188

  • CVE-2022-41850

  • CVE-2022-42432

  • CVE-2022-4379

  • CVE-2022-4382

  • CVE-2022-45887

  • CVE-2023-0045

  • CVE-2023-0160

  • CVE-2023-0458

  • CVE-2023-0459

  • CVE-2023-0615

  • CVE-2023-1078

  • CVE-2023-1206

  • CVE-2023-1382

  • CVE-2023-1670

  • CVE-2023-1829

  • CVE-2023-1855

  • CVE-2023-1859

  • CVE-2023-1989

  • CVE-2023-1990

  • CVE-2023-2002

  • CVE-2023-2006

  • CVE-2023-20569

  • CVE-2023-20593

  • CVE-2023-20928

  • CVE-2023-20938

  • CVE-2023-2124

  • CVE-2023-2156

  • CVE-2023-2162

  • CVE-2023-2177

  • CVE-2023-2194

  • CVE-2023-22995

  • CVE-2023-2483

  • CVE-2023-26607

  • CVE-2023-28327

  • CVE-2023-2860

  • CVE-2023-2985

  • CVE-2023-3006

  • CVE-2023-30772

  • CVE-2023-3090

  • CVE-2023-31083

  • CVE-2023-31084

  • CVE-2023-31085

  • CVE-2023-3111

  • CVE-2023-3117

  • CVE-2023-31248

  • CVE-2023-3161

  • CVE-2023-3212

  • CVE-2023-3220

  • CVE-2023-32269

  • CVE-2023-3268

  • CVE-2023-33288

  • CVE-2023-3358

  • CVE-2023-35001

  • CVE-2023-3567

  • CVE-2023-35788

  • CVE-2023-35823

  • CVE-2023-35824

  • CVE-2023-35825

  • CVE-2023-35828

  • CVE-2023-35829

  • CVE-2023-3609

  • CVE-2023-3610

  • CVE-2023-3611

  • CVE-2023-3772

  • CVE-2023-3773

  • CVE-2023-3776

  • CVE-2023-3812

  • CVE-2023-3863

  • CVE-2023-4004

  • CVE-2023-4015

  • CVE-2023-40283

  • CVE-2023-4128

  • CVE-2023-4132

  • CVE-2023-4147

  • CVE-2023-4155

  • CVE-2023-42753

  • CVE-2023-42754

  • CVE-2023-42755

  • CVE-2023-4563

  • CVE-2023-4623

  • CVE-2023-4921

5.10.134-16.1.al8

java-1.8.0-openjdk

  • CVE-2022-40433

  • CVE-2023-22067

  • CVE-2023-22081

1.8.0.392.b08-4.0.3.al8

java-11-openjdk

CVE-2023-22081

11.0.21.0.9-2.0.3.al8

mariadb

  • CVE-2022-32081

  • CVE-2022-32082

  • CVE-2022-32084

  • CVE-2022-32089

  • CVE-2022-32091

  • CVE-2022-38791

  • CVE-2022-47015

  • CVE-2023-5157

10.5.22-1.0.1.al8

open-vm-tools

  • CVE-2023-34058

  • CVE-2023-34059

12.2.5-3.al8.1

bind

CVE-2023-3341

9.11.36-8.al8.2

dmidecode-doc

CVE-2023-30630

3.3-5.0.2.al8

frr

CVE-2023-38802

7.5.1-8.0.1.al8

ghostscript

  • CVE-2023-28879

  • CVE-2023-38559

  • CVE-2023-4042

  • CVE-2023-43115

9.54.0-14.al8

glibc

CVE-2023-4911

2.32-1.12.al8

grafana

  • CVE-2023-39325

  • CVE-2023-44487

7.5.15-5.0.1

libvpx

  • CVE-2023-44488

  • CVE-2023-5217

1.7.0-10.0.1.al8

linux-firmware

CVE-2023-20593

20230404-117.git2e92a49f.al8

ncurses

CVE-2023-29491

6.1-10.20180224.0.1.al8

nghttp2

CVE-2023-44487

1.33.0-4.0.1.al8.1

  • qemu-kvm

  • seabios

  • CVE-2022-40284

  • CVE-2023-3354

  • 6.2.0-33.0.2.al8

  • 1.16.0-4.al8

tracker-miners

CVE-2023-5557

3.1.2-4.0.1.al8

Package updates

Package name

Release version

ca-certificates

2023.2.60_v7.0.306

firewalld

0.9.11

java-1.8.0-openjdk

1.8.0.392.b08

java-11-openjdk

11.0.21.0.9

libbpf

0.6.0

lz4

1.9.4

mariadb

10.5.22

nmstate

2.2.15

nspr

4.35.0

nss

3.90.0

open-vm-tools

12.2.5

openscap

1.3.8

scap-security-guide

0.1.69

sos

4.6.0

xz

5.4.4

Important updates

Kernel

  • New features

    • Core scheduling

      Backports the core scheduling security feature from the upstream community. It restricts processes running on a physical core's hyper-threads to a trusted group. This feature is incompatible with group identity; do not enable them simultaneously. It is disabled by default. To enable it, run sysctl -w kernel.sched_core=1.

    • eBPF trampoline on Arm64

      Backports the eBPF trampoline feature on Arm64 to support bpf struct ops. Note that because the relevant Arm64 ftrace features were not backported, the bpf fentry family of features remains unavailable.

    • MGLRU feature

      Adds support for Multi-Generational LRU (MGLRU) to improve memory page reclaim. This improves the speed and accuracy of memory reclaim in big data scenarios, boosting end-to-end performance.

    • Batch TLB flushing

      The batch migration feature improves kernel page migration performance by batching TLB flushing and page copy operations.

      This version refactors and optimizes the original batch migration feature based on upstream code. Major changes include the removal of the batch_migrate cmdline parameter and the /sys/kernel/mm/migrate/batch_migrate_enabled interface. Batch migration is now the default for page migration.

      Adds the /sys/kernel/mm/migrate/dma_migration_min_pages interface, which defaults to 32. This interface applies only when the DMA page copy feature is enabled. DMA page copy is used only if /sys/kernel/mm/migrate/dma_migrate_enabled is enabled and the number of pages to migrate meets the threshold set by /sys/kernel/mm/migrate/dma_migration_min_pages.

    • Cachestat backport

      Introduces the cachestat system call, which provides detailed page cache statistics for a specific file.

    • Enhanced kernel-mode RAS event triggering on Arm64

      Adds error recovery capabilities for RAS issues in various scenarios, including copy_{from/to}_user, {get/put}_user, Copy on Write (COW), and pagecache reading.

    • Proprietary SMC-D loopback feature

      Introduces the SMC-D loopback feature to accelerate local inter-process and inter-container TCP communication.

    • Proprietary page table core binding and cross-die statistics

      When memory is constrained, the page table core binding feature attempts to allocate page tables for QoS-sensitive services on the current NUMA node. This reduces memory access latency, enabling faster and more efficient memory access.

    • Proprietary code multi-copy enhancement

      Uses an asynchronous task to retry applying code multi-copy when it fails during process startup. Adds the memory.duptext_nodes kernel interface to restrict the memory allocation nodes for duptext.

    • Proprietary kfence enhancement

      • On the Arm64 architecture, you can dynamically enable or disable this enhanced proprietary kfence feature. It comprehensively captures memory corruption issues, facilitating both online detection and offline debugging.

      • You can now configure the system to panic immediately when a memory issue is detected, which helps developers analyze problems in a debugging environment. Enable it by setting the boot cmdline to kfence.fault=panic or by running echo panic > /sys/module/kfence/parameters/fault. The default value is report, which only logs the issue.

    • Proprietary memcg THP control interface

      Provides an interface to disable Transparent Huge Pages (THP) allocation for a specified memory cgroup (memcg).

    • Proprietary ACPU (Assess CPU) feature

      ACPU collects statistics on the idle time of a hyper-threading sibling while a task is running and provides per-cgroup statistics. This data helps evaluate hardware resource contention on shared CPU cores.

    • Proprietary HT-aware-quota feature

      This feature uses CFS bandwidth control and core scheduling to provide computing power stability in mixed deployment scenarios. It calibrates the quota by detecting if the hyper-threading sibling is idle, allowing compute-intensive tasks to receive more consistent computing power in each scheduling period.

    • Proprietary group identity 2.0

      Introduces a cgroup-level SCHED_IDLE feature. Setting the cpu.idle property on a target cgroup changes its scheduling policy to SCHED_IDLE. This is ideal for managing batches of offline tasks.

  • Behavioral changes

    • Module signing

      Adds signatures to kernel modules, helping developers identify and reject unsigned modules.

    • Spectre-BHB and Variant 4 mitigations disabled by default on Arm64

      Analysis indicates that Spectre-BHB and Variant 4 vulnerabilities are already mitigated by other means, such as Spectre v2 mitigation, disabling unprivileged eBPF, Site-Isolation technology, and disabling SharedArrayBuffer. To improve performance by reducing unnecessary overhead while maintaining security, this release adds the nospectre_bhb and ssbd=force-off parameters to the default cmdline on Arm64.

    • Support for TDX confidential virtual machines

New features in packages

  • erofs-utils 1.7.1

    erofs-utils is a tool for creating, checking, and compressing EROFS file systems. It supports compression algorithms such as LZ4, LZMA, and DEFLATE, and can convert TAR archives to the EROFS format.

  • stress-ng 0.15.00

  • Alibaba Cloud Compiler 13.0.1.4

    Alibaba Cloud Compiler is a C/C++ compiler developed by Alibaba Cloud. It is based on the open source Clang/LLVM 13 and inherits all its options and parameters. In addition, Alibaba Cloud Compiler is optimized for Alibaba Cloud infrastructure and provides unique features and optimizations for a superior C/C++ compiler experience.

  • GB18030-2022 support in glibc

  • Dragonwell 17 updated to 17.0.9.0.10.9. This update improves JIT compiler inlining performance by removing the logic that makes inlining decisions based on absolute call counts.

  • Dragonwell 8 updated to 8.15.16.372: Adds support for multiple coroutines to wait for read and write events on the same socket and fixes a bug in OkHttp scenarios.

  • plugsched 1.3

    plugsched is an SDK for scheduler hot-upgrades. Kernel scheduler developers can use this SDK to develop scheduler modules.

  • Sysak updated to 2.2.0. This version introduces application observability, with support for metrics and diagnostics for MySQL and Java applications, adds new monitoring metrics for container and cluster monitoring, and includes local monitoring capabilities.

  • keentune updated to 2.3.0: Updates x264/265 related scripts to support the latest FFmpeg; resolves XPS and RPS core binding errors; updates the default eRDMA settings in profiles.

  • Intel QAT/DLB/IAA accelerator software stack updated: Includes QAT driver bug fixes, a DLB driver upgrade, QAT and IAA user-space bug fixes, and a new unified user-space DMA memory management solution for cross-architecture accelerators.

  • smc-tools updated: Adds the smc-ebpf command, which supports controlling the effective scope of smc_run at the port granularity. Supported control modes include allowlist, blocklist, and intelligent scheduling.

Fixed issues

  • Fixed a kernel update issue where required RPM packages, such as kernel-modules-extra and kernel-modules-internal, were not automatically installed, disabling netfilter-related functions.

  • Fixed a reference counting issue with group identity during cgroup creation and deletion that sometimes prevented disabling the /proc/sys/kernel/sched_group_identity_enabled interface.

Image updates

  • Container images

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.9

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest

      Note

      After this release, the latest tag will no longer point to the 3.9 image version.

  • Virtual machine images

    • The default rpmdb format is now SQLite.

    • The keentune service is installed but not enabled by default.

    • The nfs-server service is not enabled by default.

Known issues

  • The kdump service may fail on ecs.g6r.large instances due to memory constraints. To work around this issue, adjust the crash parameter, for example, to 0M-2G:0M,2G-128G:256M,128G-:384M.

  • On an NFSv3 file system, if you add an S permission to a file, the group's S permission is lost when the file owner is changed under certain conditions.

    The patch to fix this issue is 2d8ae8c417("db nfsd: use vfs setgid helper"). However, applying this fix is deferred because the required helper functions differ significantly from the 5.10 kernel code base.

  • When using SMC to replace TCP, netperf tests may exit prematurely.

    SMC uses a fixed-size ring buffer. During transmission, the remaining buffer space may be smaller than the amount of data requested in a send() call. In this case, SMC returns the number of bytes that can be sent, which is typically less than the requested amount. netperf treats this behavior as an anomaly, which causes it to exit. Because the upstream maintainer strongly recommends keeping the current design to prevent connection stalls, this issue will not be fixed.

Alibaba Cloud Linux 3.2104 U8

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U8

aliyun_3_arm64_20G_alibase_20230731.vhd

2023-07-31

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image with the latest software packages.

  • Updates the kernel to 5.10.134-15.al8.aarch64.

  • For more information, see Content updates.

aliyun_3_x64_20G_alibase_20230727.vhd

2023-07-27

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software packages.

  • Updates the kernel to 5.10.134-15.al8.x86_64.

  • For more information, see Content updates.

aliyun_3_x64_20G_qboot_alibase_20230727.vhd

2023-07-27

  • Adds the Alibaba Cloud Linux 3.2104 64-bit Quick Launch Edition image.

  • This image is based on the Alibaba Cloud Linux 3.2104 64-bit base image (aliyun_3_x64_20G_alibase_20230727.vhd).

  • Updates the kernel to 5.10.134-15.al8.x86_64.

aliyun_3_x64_20G_uefi_alibase_20230727.vhd

2023-07-27

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition image with the latest software packages.

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit base image (aliyun_3_x64_20G_alibase_20230727.vhd).

  • This image boots in UEFI mode only.

  • Updates the kernel to 5.10.134-15.al8.x86_64.

aliyun_3_x64_20G_dengbao_alibase_20230727.vhd

2023-07-27

  • Adds the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition image.

  • This image is hardened for the Multi-Level Protection Scheme (MLPS) in accordance with GB/T 22239-2019 Information security technology—Baseline for classified protection of cybersecurity. You can use this image to meet the following MLPS compliance requirements without any additional configuration:

    • Identity authentication

    • Access control

    • Security audit

    • Intrusion prevention

    • Malicious code prevention

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit base image (aliyun_3_x64_20G_alibase_20230727.vhd).

  • Updates the kernel to 5.10.134-15.al8.x86_64.

aliyun_3_arm64_20G_dengbao_alibase_20230727.vhd

2023-07-27

  • Adds the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM MLPS 2.0 Level 3 Edition image.

  • This image is hardened for MLPS compliance based on GB/T 22239-2019 Information security technology—Baseline for classified protection of cybersecurity and meets the following compliance requirements by default:

    • Identity authentication

    • Access control

    • Security audit

    • Intrusion prevention

    • Malicious code prevention

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image (aliyun_3_arm64_20G_alibase_20230727.vhd).

  • Updates the kernel to 5.10.134-15.al8.aarch64.

Updates

Security updates

Package

CVE

Version

ctags

CVE-2022-4515

5.8-23.0.1.al8

gssntlmssp

  • CVE-2023-25563

  • CVE-2023-25564

  • CVE-2023-25565

  • CVE-2023-25566

  • CVE-2023-25567

1.2.0-1.0.1.al8

libtar

  • CVE-2021-33643

  • CVE-2021-33644

  • CVE-2021-33645

  • CVE-2021-33646

1.2.20-17.0.1.al8

device-mapper-multipath

CVE-2022-41973

0.8.4-37.0.1.al8

postgresql-jdbc

CVE-2022-41946

42.2.14-2.al8

freerdp

  • CVE-2022-39282

  • CVE-2022-39283

  • CVE-2022-39316

  • CVE-2022-39317

  • CVE-2022-39318

  • CVE-2022-39319

  • CVE-2022-39320

  • CVE-2022-39347

  • CVE-2022-41877

2.2.0-10.0.1.al8

tigervnc

  • CVE-2022-4283

  • CVE-2022-46340

  • CVE-2022-46341

  • CVE-2022-46342

  • CVE-2022-46343

  • CVE-2022-46344

1.12.0-15.al8

xorg-x11-server

  • CVE-2022-3550

  • CVE-2022-3551

  • CVE-2022-4283

  • CVE-2022-46340

  • CVE-2022-46341

  • CVE-2022-46342

  • CVE-2022-46343

  • CVE-2022-46344

  • CVE-2023-0494

1.20.11-15.0.1.al8

poppler

CVE-2022-38784

20.11.0-6.0.1.al8

wayland

CVE-2021-3782

1.21.0-1.al8

net-snmp

  • CVE-2022-44792

  • CVE-2022-44793

5.8-27.0.1.al8

dhcp

  • CVE-2022-2928

  • CVE-2022-2929

4.3.6-49.0.1.al8

python-mako

CVE-2022-40023

1.0.6-14.al8

curl

CVE-2023-27535

7.61.1-30.0.2.al8.2

  • go-toolset

  • golang

  • CVE-2023-29402

  • CVE-2023-29403

  • CVE-2023-29404

  • CVE-2023-29405

  • 1.19.10-1.al8

  • 1.19.10-1.0.1.al8

dnsmasq

CVE-2023-28450

2.79-27.al8

qt5

CVE-2022-25255

5.15.3-1.0.1.al8

autotrace

CVE-2022-32323

0.31.1-55.al8

bind

CVE-2023-2828

9.11.36-8.al8.1

  • libnbd

  • libtpms

  • libvirt

  • nbdkit

  • qemu-kvm

  • supermin

  • virt-v2v

  • CVE-2021-46790

  • CVE-2022-3165

  • CVE-2022-30784

  • CVE-2022-30786

  • CVE-2022-30788

  • CVE-2022-30789

  • CVE-2023-1018

  • libnbd-1.6.0-5.0.1.al8

  • libtpms-0.9.1-2.20211126git1ff6fe1f43.al8

  • libvirt-8.0.0-20.al8

  • nbdkit-1.24.0-5.al8

  • qemu-kvm-6.2.0-32.0.1.al8

  • supermin-5.2.1-2.0.2.al8

  • virt-v2v-1.42.0-22.al8

mysql

  • CVE-2022-21594

  • CVE-2022-21599

  • CVE-2022-21604

  • CVE-2022-21608

  • CVE-2022-21611

  • CVE-2022-21617

  • CVE-2022-21625

  • CVE-2022-21632

  • CVE-2022-21633

  • CVE-2022-21637

  • CVE-2022-21640

  • CVE-2022-39400

  • CVE-2022-39408

  • CVE-2022-39410

  • CVE-2023-21836

  • CVE-2023-21863

  • CVE-2023-21864

  • CVE-2023-21865

  • CVE-2023-21867

  • CVE-2023-21868

  • CVE-2023-21869

  • CVE-2023-21870

  • CVE-2023-21871

  • CVE-2023-21873

  • CVE-2023-21874

  • CVE-2023-21875

  • CVE-2023-21876

  • CVE-2023-21877

  • CVE-2023-21878

  • CVE-2023-21879

  • CVE-2023-21880

  • CVE-2023-21881

  • CVE-2023-21882

  • CVE-2023-21883

  • CVE-2023-21887

  • CVE-2023-21912

  • CVE-2023-21917

8.0.32-1.0.2.al8

ruby

  • CVE-2021-33621

  • CVE-2023-28755

  • CVE-2023-28756

2.7.8-139.0.1.al8

kernel

  • CVE-2021-33061

  • CVE-2021-3759

  • CVE-2022-3606

  • CVE-2022-36280

  • CVE-2022-3707

  • CVE-2022-39188

  • CVE-2022-4095

  • CVE-2022-41849

  • CVE-2022-42432

  • CVE-2022-4379

  • CVE-2022-4382

  • CVE-2022-4662

  • CVE-2022-4744

  • CVE-2022-47521

  • CVE-2022-47929

  • CVE-2023-0045

  • CVE-2023-0386

  • CVE-2023-0458

  • CVE-2023-0459

  • CVE-2023-0461

  • CVE-2023-0590

  • CVE-2023-0597

  • CVE-2023-1073

  • CVE-2023-1074

  • CVE-2023-1075

  • CVE-2023-1076

  • CVE-2023-1077

  • CVE-2023-1078

  • CVE-2023-1079

  • CVE-2023-1095

  • CVE-2023-1118

  • CVE-2023-1281

  • CVE-2023-1380

  • CVE-2023-1382

  • CVE-2023-1611

  • CVE-2023-1670

  • CVE-2023-1829

  • CVE-2023-1855

  • CVE-2023-1859

  • CVE-2023-1989

  • CVE-2023-1990

  • CVE-2023-2002

  • CVE-2023-20928

  • CVE-2023-20938

  • CVE-2023-2124

  • CVE-2023-2162

  • CVE-2023-2177

  • CVE-2023-2194

  • CVE-2023-2269

  • CVE-2023-22995

  • CVE-2023-23000

  • CVE-2023-23004

  • CVE-2023-2483

  • CVE-2023-25012

  • CVE-2023-26545

  • CVE-2023-26607

  • CVE-2023-28327

  • CVE-2023-28466

  • CVE-2023-2985

  • CVE-2023-30456

  • CVE-2023-30772

  • CVE-2023-3117

  • CVE-2023-31248

  • CVE-2023-31436

  • CVE-2023-3220

  • CVE-2023-32233

  • CVE-2023-32269

  • CVE-2023-3268

  • CVE-2023-33288

  • CVE-2023-35001

  • CVE-2023-35788

  • CVE-2023-35825

5.10.134-15.al8

webkit2gtk3

  • CVE-2023-32435

  • CVE-2023-32439

2.38.5-1.0.1.al8.5

libssh

  • CVE-2023-1667

  • CVE-2023-2283

0.9.6-7.al8

open-vm-tools

CVE-2023-20867

12.1.5-2.al8

grafana

  • CVE-2022-2880

  • CVE-2022-27664

  • CVE-2022-39229

  • CVE-2022-41715

7.5.15-4.0.2.al8

grafana-pcp

CVE-2022-27664

3.2.0-3.0.1.al8

frr

CVE-2022-37032

7.5.1-7.0.1.al8

sqlite

CVE-2020-24736

3.26.0-18.al8

git-lfs

  • CVE-2022-2880

  • CVE-2022-41715

  • CVE-2022-41717

3.2.0-2.0.1.al8

sysstat

CVE-2022-39377

11.7.3-9.0.1.al8

python3

CVE-2023-24329

3.6.8-51.0.1.al8.1

c-ares

CVE-2023-32067

1.13.0-6.al8.2

cups-filters

CVE-2023-24805

1.20.0-29.0.1.al8.2

webkit2gtk3

  • CVE-2023-28204

  • CVE-2023-32373

2.38.5-1.0.1.al8.4

delve

go-toolset

golang

CVE-2023-24540

delve-1.9.1-1.0.1.al8

go-toolset-1.19.9-1.al8

golang-1.19.9-1.0.1.al8

kernel

  • CVE-2022-47929

  • CVE-2023-0386

  • CVE-2023-1075

  • CVE-2023-1380

  • CVE-2023-26545

  • CVE-2023-28466

  • CVE-2023-30456

  • CVE-2023-32233

5.10.134-14.1.al8

git

  • CVE-2023-22490

  • CVE-2023-23946

  • CVE-2023-25652

  • CVE-2023-25815

  • CVE-2023-29007

2.39.3-1.1.al8

apr-util

CVE-2022-25147

1.6.1-6.2.al8.1

webkit2gtk3

CVE-2023-2203

2.38.5-1.0.1.al8.3

edk2

  • CVE-2022-4304

  • CVE-2022-4450

  • CVE-2023-0215

  • CVE-2023-0286

20220126gitbb1bba3d77-4.al8

mingw-expat

CVE-2022-40674

2.4.8-2.al8

Package updates

Parameter

Version

at

at-3.1.20-12.0.1.al8

audit

audit-3.0.7-2.0.1.al8.2

authselect

authselect-1.2.6-1.al8

bind

bind-9.11.36-8.al8.1

checkpolicy

checkpolicy-2.9-1.2.al8

cloud-utils-growpart

cloud-utils-growpart-0.33-0.0.1.al8

container-selinux

container-selinux-2.189.0-1.al8

coreutils

coreutils-8.30-13.al8

crypto-policies

crypto-policies-20221215-1.gitece0092.al8

cups

cups-2.2.6-51.0.1.al8

dbus

dbus-1.12.8-24.0.1.al8

ding-libs

ding-libs-0.6.1-40.al8

dnf

dnf-4.7.0-16.0.1.al8

dnf-plugins-core

dnf-plugins-core-4.0.21-14.1.al8

dracut

dracut-049-223.git20230119.al8

elfutils

elfutils-0.188-3.0.1.al8

emacs

emacs-27.2-8.0.3.al8.1

expat

expat-2.2.5-11.al8

file

file-5.33-24.al8

freetype

freetype-2.10.4-9.al8

fuse

fuse-2.9.7-16.al8

gmp

gmp-6.2.0-10.0.1.al8

gnupg2

gnupg2-2.2.20-3.al8

graphite2

graphite2-1.3.10-10.2.al8

grub2

grub2-2.02-148.0.1.al8

harfbuzz

harfbuzz-1.7.5-3.2.al8

hwdata

hwdata-0.314-8.16.al8

iproute

iproute-5.18.0-1.al8

iptables

iptables-1.8.4-24.0.1.al8

kernel

kernel-5.10.134-15.al8

kernel-hotfix-13383560-5.10.134-15

kernel-hotfix-13383560-5.10.134-15-1.0-20230724161633.al8

kexec-tools

kexec-tools-2.0.25-5.0.1.al8

kmod

kmod-25-19.0.2.al8

kpatch

kpatch-0.9.7-2.0.1.al8

libarchive

libarchive-3.5.3-4.al8

libffi

libffi-3.1-24.0.1.al8

libteam

libteam-1.31-4.0.1.al8

libuser

libuser-0.62-25.0.1.al8

libxml2

libxml2-2.9.7-16.0.1.al8

linux-firmware

linux-firmware-20230404-114.git2e92a49f.al8

logrotate

logrotate-3.14.0-6.0.1.al8

NetworkManager

NetworkManager-1.40.16-1.0.1.al8

nfs-utils

nfs-utils-2.3.3-59.0.2.al8

nftables

nftables-0.9.3-26.al8

oddjob

oddjob-0.34.7-3.0.1.al8

openssh

openssh-8.0p1-17.0.2.al8

openssl-pkcs11

openssl-pkcs11-0.4.10-3.0.1.al8

pam

pam-1.3.1-25.0.1.al8

pciutils

pciutils-3.7.0-3.0.1.al8

python-linux-procfs

python-linux-procfs-0.7.1-1.al8

python-rpm-generators

python-rpm-generators-5-8.al8

python-slip

python-slip-0.6.4-13.al8

rng-tools

rng-tools-6.15-3.0.1.al8

rpcbind

rpcbind-1.2.5-10.0.1.al8

rpm

rpm-4.14.3-26.0.1.al8

rsyslog

rsyslog-8.2102.0-13.al8

selinux-policy

selinux-policy-3.14.3-117.0.1.al8

setools

setools-4.3.0-3.al8

setup

setup-2.12.2-9.0.1.al8

sg3_utils

sg3_utils-1.44-6.0.1.al8

shared-mime-info

shared-mime-info-2.1-5.0.1.al8

sssd

sssd-2.8.2-2.0.1.al8

tpm2-tss

tpm2-tss-2.3.2-4.0.2.al8

unbound

unbound-1.16.2-5.al8

util-linux

util-linux-2.32.1-42.0.1.al8

virt-what

virt-what-1.25-3.al8

wget

wget-1.19.5-11.0.1.al8

which

which-2.21-18.0.1.al8

xfsprogs

xfsprogs-5.0.0-10.0.6.al8

Important updates

  • Kernel updates

    • Upstream backport

      • devlink supports subfunction management.

        A subfunction is a lightweight function. It is more lightweight than a PCIe virtual function. Unlike a virtual function, a subfunction is not an independent PCI device but shares the resources of its parent PCI device. However, a subfunction has all the resources related to network interface controller communication, such as send queues, receive queues, and completion queues (CQs). A subfunction appears as a complete network interface controller device in the Linux system. This update adds support for managing subfunctions on network interface controllers through devlink. By coordinating with the driver, you can create, destroy, and query subfunctions on supported network interface controllers.

      • io_uring supports NVMe passthrough.

        During storage device access, the overhead from the complex storage stack has a significant impact on latency and IOPS. As storage devices become faster, the overhead of this software stack becomes more significant. Accessing NVMe disks requires passing through multiple abstraction layers, such as the file system, block layer, and NVMe driver, before finally reaching the target device. This update backports the io_uring uring_cmd feature, which was added to the community mainline in v5.19. It passes the actual file operations to the kernel through io_uring. These operations are not parsed at the io_uring layer but are passed directly to the NVMe driver layer for processing. This bypasses the file system and block layers. Additionally, to support this feature, io_uring now supports the CQE32 data structure and the creation of NVMe character devices.

      • Adds fine-grained permission control for NVMe/SCSI Persistent Reservation.

        Previously, a process that performed a Persistent Reservation operation had to have the CAP_SYS_ADMIN permission. This prevented its use in some non-privileged scenarios, such as containers. This feature lets non-privileged processes (those without CAP_SYS_ADMIN permission) perform Persistent Reservation operations as long as they have write permission for the block device. This expands the use cases for the feature.

      • Optimizes IOPS throttling for large block I/O.

        The IOPS throttling capability in the current 5.10 kernel does not work well in large block I/O scenarios, such as with 1 MB blocks. The main reason is that large block I/O may be split, and the block throttle's IOPS throttling logic does not handle this well. This issue is especially noticeable in buffer I/O scenarios because buffer I/O first writes to the page cache and then writes back after a period. This process often merges I/O into large blocks. The community mainline refactored and optimized this in v5.18. This update backports patches from the community mainline to optimize IOPS throttling for large block I/O. It also fixes a bug that caused BPS to be counted multiple times.

      • Backports BPF support for lookup_and_delete_elem on hashmaps and adds the bloom filter feature.

        • Previously, the BPF lookup_and_delete_elem operation only supported maps of the queue and stack types. It now supports hash maps.

        • Adds a new map type, bloom filter, which is an efficient tool for set lookups.

      • Adds support for CPU and memory hot-plugging for QEMU Arm64 virtual machine guest OSs.

        • Supports hot-upgrading the number of vCPUs in a guest OS using the virsh setvcpus command.

        • Enables the CONFIG_MEMORY_HOTPLUG_DEFAULT_ONLINE configuration by default to prevent memhp_default_online_type from being in an offline state. This way, when memory is added via hot-plugging, it can be used automatically. This avoids memory hot-plug failures that occur when creating page descriptors for newly added memory leads to insufficient memory.

      • Enables Intel HWP boost for all Intel chips.

        HWP I/O boost technology can improve I/O performance. However, the kernel previously enabled this feature only for some Skylake platforms and enterprise servers. This patch removes the CPU type check and enables HWP boost for all CPUs by default.

      • Backports the community HVO feature.

        HVO stands for HugeTLB Vmemmap Optimization. It reduces the memory footprint of vmemmap corresponding to huge pages. The principle is to map the virtual addresses of all struct page entries for a huge page in vmemmap to the same physical address. This frees the physical memory occupied by the struct page entries.

      • Backports the memcg lru_lock optimization feature.

        This feature optimizes scenarios in the kernel that require a global lru_lock. Instead of the global lock, it uses the lock of the memcg where the page resides. These scenarios include page migration, memcg migration, swap-in, and swap-out. This feature significantly reduces contention caused by the global lru_lock. In test scenarios with multiple memcgs, performance improved by about 50%.

      • Adds support for the Intel TDX guest kernel.

        Supports running the Linux kernel in an Intel TDX guest. This provides the guest with memory encryption, memory integrity protection, CPU register protection, and remote attestation in a trusted environment.

      • Adds adaptations for the EMR platform.

        • Adds the EMR CPU ID to the PMU driver to enable PMU capabilities on the EMR platform.

        • Enables the In-Field Scan (IFS) Array Built-In Self-Test (BIST) capability. IFS is used to capture CPU errors that are difficult for Error-Correcting Code (ECC) to detect. It can check each core during runtime.

    • Self-developed features

      • Adds the capability to transparently accelerate TCP using the SMC kernel network protocol stack.

        Shared Memory Communications (SMC) is a high-performance kernel network protocol stack contributed by IBM to the upstream Linux kernel. It can work with various shared memory technologies, such as Remote Direct Memory Access (RDMA), to transparently accelerate TCP. On top of the upstream version, ANCK fixes many stability issues and adds several key features. It supports SMCv2 by default, SMCv2.1 protocol negotiation, the max_link`/`max_conn`/Alibaba vendor ID features, optimized link connection counts, RQ flow control, and RDMA Write With Immediate operations. ANCK also adds various diagnostic information, support for using the SMC protocol stack through the PF_INET protocol family, and support for transparent replacement via BPF.

      • Enhances the FUSE cache consistency model and adds statistics interfaces.

        • Adds a debugging interface in sysfs to print all requests that have been sent to the user-mode daemon and are awaiting processing for a specific FUSE file system.

        • Adds a data statistics interface in sysfs to count and report the number and processing time of each request type for a specific FUSE file system.

        • Enhances cache consistency in cache=always|auto mode to suit distributed file system backends that rely on strong consistency, such as Network File System (NFS).

          1. The user-mode daemon can notify the FUSE client to invalidate all directory entries in a directory.

          2. Implements the Close-To-Open (CTO) cache consistency model, including flush-on-close and invalidate-on-open semantics for data and metadata.

          3. Enhances the cache consistency model in FUSE failover mode.

      • EROFS supports mounting tar files directly and using uncompressed EROFS images with 4 KB block sizes on Arm64 platforms with 16 KB/64 KB page configurations.

        • Supports mounting uncompressed EROFS images with 4 KB block sizes on Arm64 platforms configured with 16 KB or 64 KB pages.

        • Supports using a tar file directly as a data source, allowing you to mount and access the tar data using EROFS metadata.

      • Adds support for passing FUSE mount points across namespaces.

        Supports propagating a FUSE mount point from a non-privileged sidecar container to an application container. This provides a FUSE-based solution for remote storage in cloud-native scenarios.

      • Resolves memory bloat issues caused by Transparent Huge Pages (THP).

        While THP improves performance, it can also cause memory bloat. Memory bloat can lead to Out of Memory (OOM) errors. For example, an application may only need two small pages, which is 8 KiB of memory, but the kernel allocates one transparent huge page. In this case, the remaining memory in the transparent huge page (510 small pages) is all zeros, except for the memory the application actually needs. This can increase the Resident Set Size (RSS) memory usage and eventually cause an OOM error.

        THP Zero Subpage Reclamation (ZSR) is designed to solve this memory bloat problem. When the kernel reclaims memory, this feature splits the transparent huge page into small pages and reclaims the all-zero subpages. This prevents rapid memory bloat from causing OOM errors.

  • System configuration updates

    • Sets tcp_max_tw_buckets to 5000.

    • Changes the default character set for mounting the vfat file system to iso8859-1.

  • Package updates

    • Includes aliyun-cli by default.

    • Includes container-selinux by default.

    • Adds the anolis-epao-release package. This allows Alibaba Cloud Linux 3 to use the Anolis OS epao repository to install applications such as AI tools.

Fixed issues

  • Fixed an issue that prevented the rngd.service from starting on Alibaba Cloud Linux 3 arm64 images.

  • Backported a community mainline fix to address a cgroup leak that occurs when a process fork fails.

  • Fixed a permission issue in overlayfs that occurred when a file or directory without read permission was accessed on a filesystem where all upperdir and lowerdir directories resided. A logic error in a previous performance optimization caused ovl_override_creds() to run incorrectly, preventing permissions from being elevated to those of the mounter. Consequently, the copy-up operation failed due to insufficient permissions.

  • Backported multiple fuse bug fixes from the community mainline to improve stability.

  • Backported multiple community mainline bug fixes for ext4 with the bigalloc feature enabled, significantly reducing online resizing time.

  • Backported a community mainline fix to prevent a potential data consistency issue caused by CONT-PTE/PMD.

  • Fixed an issue where resctrl did not work correctly on AMD instances.

  • Improved the stability of the IAX hardware compression and decompression accelerator.

  • Fixed CRC validation failures in the IAX hardware compression and decompression accelerator.

  • Fixed memory corruption caused by improper use of the swap_info_struct lock during highly concurrent swapoff and swapon operations. This fix has been merged into the community mainline.

  • Addressed an issue where the in-house zombie memcg reaper feature was ineffective in one-shot mode.

  • Addressed a potential stability issue with the MPAM memory bandwidth monitoring feature on Yitian 710 processors.

Image update

  • Container image

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:3.8

    • alibaba-cloud-linux-3-registry.cn-hangzhou.cr.aliyuncs.com/alinux3/alinux3:latest

      Note

      Once a new version is released, the latest tag no longer points to the 3.8 image.

  • Virtual machine image

Known issues

ANCK 5.10-015 incorporates a scheduler wakeup optimization from the upstream community. This change may cause a performance regression in certain edge cases, such as benchmarks under heavy load. However, this regression does not affect typical user workloads.

Alibaba Cloud Linux 3.2104 U7

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2104 U7

aliyun_3_x64_20G_alibase_20230516.vhd

2023-05-16

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest software packages.

  • Upgraded the kernel to version 5.10.134-14.al8.x86_64.

  • For more information, see Updates.

aliyun_3_arm64_20G_alibase_20230515.vhd

2023-05-15

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image to the latest software packages.

  • Upgraded the kernel to version 5.10.134-14.al8.aarch64.

  • For more information, see Updates.

Updates

  • Fixed kernel bugs and addressed critical security vulnerabilities (CVEs).

  • Added support for the multi-pcp feature to improve network packet reception performance by bypassing the buddy system's global lock.

    The multi-pcp feature improves network packet reception by reserving per-core memory pages with an order greater than 0. This avoids allocations through the zone buddy system for high-order memory pages, which bypasses the buddy system's global lock.

  • Enabled the Intel IAA accelerator driver to improve compression and decompression performance.

    The In-Memory Analytics Accelerator (IAA) is a hardware accelerator that combines basic data analytics functions with high-throughput compression and decompression. The driver code is adapted from the Intel code repository and includes bug fixes and modifications for ANCK.

  • Fixed an issue that caused silent data loss in shmem and hugetlb file systems due to page cache truncation.

    Previously, when a faulted page in a shmem or hugetlb file system was removed from the page cache, a subsequent access to that page's offset would allocate a new zero page, resulting in silent data loss. This update prevents silent data loss from page faults in shmem/tmpfs and hugetlb file systems.

  • Added support for the CoreSight ETE driver and the tools/perf utility.

  • Enhanced the signal handling mechanism in the KVM module on ARM64 platforms to prevent system crashes in scenarios such as RAS.

    If the CPU does not process the TIF_NOTIFY_RESUME flag before entering Guest mode, frequent RAS events can trigger exceptions and cause a system crash. This update implements the full generic entry infrastructure on ARM64 platforms to correctly handle pending task work.

  • Synchronized the CMN/DRW driver with the upstream Linux community version, added debugfs support, and fixed related bugs.

    Before version 5.10-014, the CMN/DRW driver diverged from the upstream Linux community version. To reduce future maintenance costs, version 5.10-014 synchronizes the driver with the upstream version and adds compatibility for the CMN700 on Yitian 710. This update also adds debugfs support and fixes, allowing you to view the CMN topology in user mode.

  • Added support for machine check exception (MCE) recovery for copy on write (COW) in kernel mode on x86 platforms.

    Previously, an uncorrectable error during a kernel copy on write (COW) operation would cause a system crash because the kernel lacked a recovery handler for such errors. This feature adds a recovery handler that sends a SIGBUS signal to the application to prevent a system crash.

  • Added support for top-down performance analysis using perf metrics to improve CPU PMU usability.

    Before version 5.10-014, perf metrics and top-down analysis were not supported. To improve CPU PMU usability and help users identify CPU performance bottlenecks, version 5.10-014 adds support for perf metrics and top-down analysis for Yitian 710, Kunpeng, and x86 platforms.

  • Added support for UDP Segment Offloading (USO) to virtio-net.

    Compared with UDP Fragment Offloading (UFO), USO improves packet reception performance and the forwarding performance of forwarding components in complex network environments. Starting from version 5.10-014, virtio-net supports USO. In business scenarios where the network conditions are unstable and incast or burst traffic is pronounced, USO can effectively reduce the packet loss rate caused by fragment reassembly and reduce the overhead of fragment reassembly on the receiver. In addition, packet loss and out-of-order packets reduce the efficiency of forwarding components by forcing fragment reassembly, an issue that USO effectively mitigates.

  • Fixed an issue that caused virtual address space exhaustion on the aarch64 architecture due to an unimplemented pci_iounmap function.

    Before version 5.10-014, the pci_iounmap function had an empty implementation because CONFIG_GENERIC_IOMAP was not configured. This prevented the system from releasing mapped memory, which led to virtual address space exhaustion. Version 5.10-014 fixes this issue by correctly implementing the pci_iounmap function.

  • Added support for high-performance ublk.

    ublk is a high-performance user mode block device that is implemented based on the io_uring passthrough mechanism. It allows agents to efficiently access distributed storage.

  • Added support for the following proprietary technologies of Alibaba Cloud:

    • Added a feature to lock code segments at the system-wide or memcg level.

      When the memory usage is higher than the low watermark, memory reclaim is triggered. During memory reclaim, the memory that holds code segments for critical applications may be reclaimed. As the applications run, the memory is reloaded from the disk. Frequent I/O operations increase the response latency of critical services and cause performance jitter. This feature prevents this issue by locking the code segment memory of critical applications within a specified cgroup to make the memory non-reclaimable. This feature also adds a quota that you can configure as a percentage to limit the amount of locked code segment memory.

    • Introduced a page cache usage limit to resolve Out of Memory (OOM) issues caused when the page cache grows faster than it is reclaimed.

      In containerized scenarios, the memory available to containers is limited. If the page cache consumes too much memory and triggers memory reclaim, an Out of Memory (OOM) error can occur if the reclaim rate is slower than the application's growing memory demand. This severely impacts application performance. This feature resolves this issue by limiting the page cache size for a container and proactively reclaiming memory that exceeds the limit. The solution supports cgroup-level and global page cache limits and offers both synchronous and asynchronous reclamation methods for flexibility.

    • Added support for dynamic CPU isolation.

      CPU isolation assigns different CPU cores or sets of cores to different tasks to prevent them from competing for CPU resources, which improves overall system performance and stability. You can isolate a subset of CPUs for critical tasks while other tasks share the remaining CPUs. However, the number of critical tasks can change during runtime. Isolating too many CPUs wastes resources and increases costs. This feature allows you to dynamically adjust the CPU isolation scope to better utilize CPU resources, save costs, and improve overall workload performance.

    • Added support for CPU Burst and tiered memory-low watermarks in cgroup v2.

      To promote the adoption of cgroup v2, this update adds interfaces for proprietary ANCK features in cgroup v2, including CPU Burst and tiered memory-low watermarks.

    • Enabled XDP sockets to allocate virtual memory for queues to prevent allocation failures caused by memory fragmentation.

      By default, XDP sockets use the __get_free_pages() function to allocate contiguous physical memory. If memory is severely fragmented, the allocation can fail, which prevents the XDP socket from being created. This feature uses the vmalloc() function to allocate memory, which reduces the likelihood of XDP socket creation failure.

Alibaba Cloud Linux 3.2104 U6.1

Version

Image id

Release date

Updates

Alibaba Cloud Linux 3.2104 U6.1

aliyun_3_x64_20G_alibase_20230424.vhd

2023-04-24

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest version.

  • Updated the kernel version to 5.10.134-13.1.al8.x86_64.

aliyun_3_arm64_20G_alibase_20230424.vhd

2023-04-24

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image to the latest version.

  • Updated the kernel version to 5.10.134-13.1.al8.aarch64.

aliyun_3_x64_20G_alibase_20230327.vhd

2023-03-27

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit base image to the latest version.

  • Updated the kernel version to 5.10.134-13.1.al8.x86_64.

aliyun_3_arm64_20G_alibase_20230327.vhd

2023-03-27

  • Updated the Alibaba Cloud Linux 3.2104 LTS 64-bit for ARM base image to the latest version.

  • Updated the kernel version to 5.10.134-13.1.al8.aarch64.

Alibaba Cloud Linux 3.2104 U6

Version

Image ID

Release date

Description

Alibaba Cloud Linux 3.2104 U6

aliyun_3_x64_20G_qboot_alibase_20230214.vhd

2023-02-14

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit Quick Launch Edition image.

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit base image (aliyun_3_x64_20G_alibase_20230110.vhd).

aliyun_3_x64_20G_dengbao_alibase_20230214.vhd

2023-02-14

  • Introduces the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition image.

  • This image is security-hardened to comply with GB/T 22239-2019 Information Security Technology—Baseline for Classified Protection of Cybersecurity. You can use this image to meet the following compliance requirements without additional configuration:

    • Identity authentication

    • Access control

    • Security auditing

    • Intrusion prevention

    • Malware protection

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit base image (aliyun_3_x64_20G_alibase_20230110.vhd).

  • The kernel is updated to 5.10.134-13.1.al8.x86_64 (the output of the uname -r command).

aliyun_3_arm64_20G_dengbao_alibase_20230214.vhd

2023-02-14

  • Introduces the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM Edition MLPS 2.0 Level 3 Edition.

  • This image is security-hardened to comply with GB/T 22239-2019 Information Security Technology—Baseline for Classified Protection of Cybersecurity. You can use this image to meet the following compliance requirements without additional configuration:

    • Identity authentication

    • Access control

    • Security auditing

    • Intrusion prevention

    • Malware protection

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM base image (aliyun_3_arm64_20G_alibase_20230110.vhd).

  • The kernel is updated to 5.10.134-13.1.al8.aarch64 (the output of the uname -r command).

aliyun_3_x64_20G_uefi_alibase_20230214.vhd

2023-02-14

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition image.

  • This image is based on the Alibaba Cloud Linux 3.2104 LTS 64-bit base image (aliyun_3_x64_20G_alibase_20230110.vhd).

  • This image boots in UEFI mode only.

aliyun_3_x64_20G_alibase_20230110.vhd

2023-01-10

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Adds the Plus debug repository configuration.

  • Kernel updates:

    • The kernel version is updated to 5.10.134-13.al8.x86_64.

    • Fixes kernel bugs and addresses critical security vulnerabilities (CVEs).

    • Adds support for user space /dev/ioasid.

      Before ANCK 5.10-013, user space pass-through frameworks like Virtual Function I/O (VFIO) and vDPA required custom logic to isolate untrusted Direct Memory Access (DMA) requests from user space. ANCK 5.10-013 introduces /dev/ioasid, which provides a unified interface for managing I/O page tables and simplifies the implementation of VFIO and vDPA.

    • Optimizes SWIOTLB performance.

      Previously, the Software I/O Translation Lookaside Buffer (SWIOTLB) mechanism used a single lock for memory allocation when communicating with peripherals. This release splits the lock into multiple configurable locks. This change primarily benefits confidential virtual machines (Intel TDX) on large-scale instances (for example, with more than 32 CPUs). In Redis and MySQL tests, this optimization increases I/O performance by up to 8x.

    • Optimizes TCP Small Queue performance by enabling napi.tx in virtio-net.

      Commit 3bedc5bca69d ('ck: Revert "virtio_net: enable napi_tx by default"') disabled this feature due to performance degradation caused by high softirq loads in some scenarios, which also prevented TCP Small Queue from working correctly. This release re-enables the feature.

    • Adds support for the AST2600 PCIe 2D VGA Driver.

      Previously, the kernel did not support the ASPEED AST2600 graphics card. This release adds support for the card, enabling proper display output on external monitors.

    • Adds support for dynamically enabling the Group Identity feature.

      ANCK 5.10-013 adds a global sysctl toggle for the Group Identity feature. It is disabled by default to reduce scheduling overhead for normal processes. To enable it, run the echo 1 > /proc/sys/kernel/sched_group_identity_enabled command.

    • Adjusts the default kernel boot cmdline for the ARM64 platform.

      Starting from version 5.10.134-013, the ARM64 platform adds the following parameters to the boot cmdline to improve performance.

      cgroup.memory=nokmem iommu.passthrough=1 iommu.strict=0
      • cgroup.memory=nokmem: Enabling cgroup.memory adds extra logic to the slab-managed page allocation and free paths, which can reduce performance. Disabling this feature improves performance. For more information, see the OpenAnolis community.

      • iommu.passthrough=1: This parameter sets IOMMU to pass-through mode, which reduces page table mapping overhead on physical machines. If not specified, the mode is controlled by the CONFIG_IOMMU_DEFAULT_PASSTHROUGH setting.

      • iommu.strict=0: This parameter sets TLB invalidation to lazy mode, where the kernel delays TLB invalidation during a DMA unmap operation to improve throughput. If the IOMMU driver does not support lazy mode, the system automatically falls back to strict mode (strict=1).

    • Adds support for the Compact NUMA-Aware (CNA) spinlock feature.

      Starting from version 5.10.134-013, qspinlock is NUMA-aware. You can enable this feature by adding numa_spinlock=on or numa_spinlock=auto to the boot cmdline.

      When enabled, if CPUs on different NUMA nodes contend for a spinlock, qspinlock attempts to hand the lock to a CPU on the same node. This reduces cross-NUMA traffic and improves performance. Sysbench and leveldb benchmarks show performance gains of over 10%.

    • Enhances the perf mem and perf c2c features on the ARM64 platform.

      Starting from version 5.10.134-013, these tools can show data sources for samples on the ARM64 platform, such as L1 hits. Enhancements to perf mem include support for aggregated memory events, aggregated instruction events, and total instruction latency information. Enhancements to perf c2c include node-level location information.

    • Adds log recovery support to fsck.xfs.

      After a crash, the file system may be inconsistent and its log may not be replayed. In xfsprogs versions 5.0.0-10.0.4 and earlier, fsck.xfs does not support log recovery. This could force the system into rescue mode on reboot, requiring manual intervention. Starting with xfsprogs version 5.0.0-10.0.5, log recovery is supported. To enable this feature, set the boot parameters fsck.mode=force and fsck.repair=yes. Note: This feature currently applies only to the system disk.

    • Adds adaptive on-demand huge pages for hugetext.

      Starting from version 5.10.134-013, to address the limitation on the x86 platform where 2 MB iTLB entries are scarce, the kernel introduces an adaptive handling feature for code huge pages. This feature controls the use of code huge pages by scanning the PTE heat in 2 MB regions and consolidating hotter areas into huge pages. In short, this feature controls the number of code huge pages used by each application to prevent performance loss from iTLB misses. This feature mainly targets Java applications and applications with large code segments, such as OceanBase and MySQL.

    • Adds support for SGX dynamic memory management.

      ANCK 5.10 adds support for SGX dynamic memory management (EDMM).

    • Enables the wireguard module.

      This release enables the wireguard module. WireGuard provides a secure, efficient, and simple alternative to IPsec, and is versatile enough for most use cases.

aliyun_3_arm64_20G_alibase_20230110.vhd

2023-01-10

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM Edition base image.

  • Adds the Plus debug repository configuration.

  • Kernel updates:

    • The kernel version is updated to 5.10.134-13.al8.aarch64.

    • Fixes kernel bugs and addresses critical security vulnerabilities (CVEs).

2022

Version

Image id

Release date

Updates

Alibaba Cloud Linux 3.5.2

aliyun_3_x64_20G_alibase_20221118.vhd

2022-11-18

Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

aliyun_3_arm64_20G_alibase_20221118.vhd

2022-11-18

Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

aliyun_3_x64_20G_alibase_20221102.vhd

2022-11-02

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Updates the kernel to 5.10.134-12.2.al8.x86_64.

aliyun_3_arm64_20G_alibase_20221102.vhd

2022-11-02

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Updates the kernel to 5.10.134-12.2.al8.aarch64.

Alibaba Cloud Linux 3.5

aliyun_3_x64_20G_alibase_20220907.vhd

2022-09-07

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.134-12.al8.x86_64.

    • Fixes kernel bugs and critical security vulnerabilities (CVEs).

    • Adds support for Yitian 710 processors.

    • Adds support for Panjiu M physical machines.

    • Optimizes baseline performance on the Yitian 710 platform.

    • Adds support for the Memory Partitioning and Monitoring (MPAM) feature on the ARM64 architecture.

    • Datop can now monitor cross-node Non-Uniform Memory Access (NUMA) and identify hot and cold memory at the process level.

    • Crashkernel can now reserve more than 4 GB of memory on the ARM64 architecture.

    • Adds support for hotfixing kernel modules on the ARM64 architecture.

    • Adds support for the ftrace osnoise tracer.

    • Adds the ext4 fast commit feature, which significantly improves performance for workloads with frequent fsync operations, such as MySQL and PostgreSQL databases. The corresponding e2fsprogs version is updated to 1.46.0.

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • Pads the unaligned 2 MB region at the end of executable binaries, improving performance by up to 2% in some scenarios.

      • Adds support for the XFS 16k atomic write feature. This feature improves performance by up to 50% and significantly reduces disk I/O compared with the default double-write buffer. The corresponding xfsprogs and MariaDB packages are also updated in the OpenAnolis yum repository. This software-based solution provides the following benefits over hardware-based atomic write solutions:

        • It uses the copy-on-write (CoW) mechanism.

        • It does not depend on specific hardware.

        • It does not depend on runtime I/O path configurations.

        This optimization can also be combined with the large page feature for code segments. For more information, see the MariaDB 16k atomic write usage guide.

      • Adds container image acceleration using nydus+erofs over fscache. This feature, contributed by the OpenAnolis Community, was merged into the mainline Linux kernel in version 5.19 and became the first natively supported container image acceleration solution in the Linux community. For more information, visit the OpenAnolis Community website.

      • Adds support for enhanced fd passthrough and fd attach features. The fd passthrough feature reduces I/O latency by 90% in common scenarios. The fd attach feature supports lossless recovery of FUSE mount point connections, which improves stability in production environments.

      • Kidled can now scan anonymous pages, file pages, and slab objects.

      • Adds the memory.use_priority_swap interface for cgroup priority-based memory swapping.

      • Enhances SMC with support for 1-RTT and RDMA DIM, optimizes CQ interrupt handling logic to improve data path QPS by 40%, introduces automated testing for SMC, and fixes dozens of stability issues.

aliyun_3_arm64_20G_alibase_20220907.vhd

2022-09-07

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.134-12.al8.aarch64.

    • Fixes kernel bugs and critical security vulnerabilities (CVEs).

    • Adds support for Yitian 710 processors.

    • Adds support for Panjiu M physical machines.

    • Optimizes baseline performance on the Yitian 710 platform.

    • Adds support for the Memory Partitioning and Monitoring (MPAM) feature on the ARM64 architecture.

    • Datop can now monitor cross-node Non-Uniform Memory Access (NUMA) and identify hot and cold memory at the process level.

    • Crashkernel can now reserve more than 4 GB of memory on the ARM64 architecture.

    • Adds support for hotfixing kernel modules on the ARM64 architecture.

    • Adds support for the ftrace osnoise tracer.

    • Adds the ext4 fast commit feature, which significantly improves performance for workloads with frequent fsync operations, such as MySQL and PostgreSQL databases. The corresponding e2fsprogs version is updated to 1.46.0.

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • Pads the unaligned 2 MB region at the end of executable binaries, improving performance by up to 2% in some scenarios.

      • Adds support for the XFS 16k atomic write feature. This feature improves performance by up to 50% and significantly reduces disk I/O compared with the default double-write buffer. The corresponding xfsprogs and MariaDB packages are also updated in the OpenAnolis yum repository. This software-based solution provides the following benefits over hardware-based atomic write solutions:

        • It uses the copy-on-write (CoW) mechanism.

        • It does not depend on specific hardware.

        • It does not depend on runtime I/O path configurations.

        This optimization can also be combined with the large page feature for code segments. For more information, see the MariaDB 16k atomic write usage guide.

      • Adds container image acceleration using nydus+erofs over fscache. This feature, contributed by the OpenAnolis Community, was merged into the mainline Linux kernel in version 5.19 and became the first natively supported container image acceleration solution in the Linux community. For more information, visit the OpenAnolis Community website.

      • Adds support for enhanced fd passthrough and fd attach features. The fd passthrough feature reduces I/O latency by 90% in common scenarios. The fd attach feature supports lossless recovery of FUSE mount point connections, which improves stability in production environments.

      • Kidled can now scan anonymous pages, file pages, and slab objects.

      • Adds the memory.use_priority_swap interface for cgroup priority-based memory swapping.

      • Enhances SMC with support for 1-RTT and RDMA DIM, optimizes CQ interrupt handling logic to improve data path QPS by 40%, introduces automated testing for SMC, and fixes dozens of stability issues.

aliyun_3_x64_20G_dengbao_alibase_20220914.vhd

2022-09-14

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition image.

  • This image is hardened according to GB/T 22239-2019: Information security technology—Baseline for classified protection of cybersecurity and meets the following MLPS compliance requirements out of the box:

    • identity authentication

    • access control

    • security audit

    • intrusion prevention

    • malware protection

  • This image is based on version aliyun_3_x64_20G_alibase_20220907.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Updates the kernel to 5.10.134-12.al8.x86_64 (as returned by the uname -r command).

  • Available in the following regions: China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Hangzhou), China (Shanghai), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Chengdu), and China (Hong Kong).

aliyun_3_x64_20G_qboot_alibase_20220907.vhd

2022-09-07

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit Quick Launch Edition image.

  • This image is based on version aliyun_3_x64_20G_alibase_20220907.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

aliyun_3_x64_20G_uefi_alibase_20220907.vhd

2022-09-07

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition image with the latest software.

  • This image is based on version aliyun_3_x64_20G_alibase_20220907.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Switches to a UEFI-only boot mode.

Alibaba Cloud Linux 3.4.2

aliyun_3_arm64_20G_alibase_20220819.vhd

2022-08-19

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Updates the kernel to 5.10.112-11.2.al8.aarch64.

aliyun_3_x64_20G_alibase_20220815.vhd

2022-08-15

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Updates the kernel to 5.10.112-11.2.al8.x86_64.

Alibaba Cloud Linux 3.4.1

aliyun_3_x64_20G_alibase_20220728.vhd

2022-07-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Updates the kernel to 5.10.112-11.1.al8.x86_64.

aliyun_3_arm64_20G_alibase_20220728.vhd

2022-07-28

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Updates the kernel to 5.10.112-11.1.al8.aarch64.

Alibaba Cloud Linux 3.4

aliyun_3_2104_x64_20G_dengbao_alibase_20220601.vhd

2022-06-01

  • Adds the Alibaba Cloud Linux 3.2104 LTS 64-bit MLPS 2.0 Level 3 Edition image.

  • This image is hardened according to GB/T 22239-2019: Information security technology—Baseline for classified protection of cybersecurity and meets the following MLPS compliance requirements out of the box:

    • identity authentication

    • access control

    • security audit

    • intrusion prevention

    • malware protection

  • This image is based on version aliyun_3_x64_20G_alibase_20220527.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Updates the kernel to 5.10.112-11.al8.x86_64 (as returned by the uname -r command).

  • Available in the following regions: China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Chengdu), and China (Hong Kong).

aliyun_3_x64_20G_alibase_20220527.vhd

2022-05-27

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.112-11.al8.x86_64.

    • Fixes kernel bugs and critical security vulnerabilities (CVEs).

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • The kernel code multi-copy feature.

      • Kernel code large page enhancement.

      • Kfence for detecting issues such as out-of-bounds memory access and use-after-free (UAF).

    • Adds support for the Hygon CSV2 confidential virtual machine feature.

    • The guest OS now supports up to 256 CPUs.

    • Improves SMC throughput and latency in multiple scenarios, accelerates connection establishment, and fixes multiple stability and compatibility issues.

    • Intel SPR now supports new features, including AMX, vAMX, IPI virtualization, UINTER, Intel_idle, and TDX.

    • Adds support for the ptdma, CPU frequency, k10temp, and EDAC features on AMD.

    • Alibaba Cloud Yitian 710 supports the following features: DDR PMU, PCIe PMU driver, CMN-700, and RAS.

    • Adds support for Coresight features.

    • The ARM architecture now supports ARM SPE perf memory profiling/c2c features.

    • virtiofs now supports file-level DAX.

    • Adds support for the smmu event polling feature.

aliyun_3_x64_20G_qboot_alibase_20220527.vhd

2022-05-27

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit Quick Launch Edition image.

  • This image is based on version aliyun_3_x64_20G_alibase_20220527.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

aliyun_3_x64_20G_uefi_alibase_20220527.vhd

2022-05-27

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition image with the latest software.

  • This image is based on version aliyun_3_x64_20G_alibase_20220527.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Switches to a UEFI-only boot mode.

aliyun_3_arm64_20G_alibase_20220526.vhd

2022-05-26

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.112-11.al8.aarch64.

    • Fixes kernel bugs and critical security vulnerabilities (CVEs).

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • The kernel code multi-copy feature.

      • Kernel code large page enhancement.

      • Kfence for detecting issues such as out-of-bounds memory access and use-after-free (UAF).

    • Adds support for the Hygon CSV2 confidential virtual machine feature.

    • The guest OS now supports up to 256 CPUs.

    • Improves SMC throughput and latency in multiple scenarios, accelerates connection establishment, and fixes multiple stability and compatibility issues.

    • Intel SPR now supports new features, including AMX, vAMX, IPI virtualization, UINTER, Intel_idle, and TDX.

    • Adds support for the ptdma, CPU frequency, k10temp, and EDAC features on AMD.

    • Alibaba Cloud Yitian 710 supports the following features: DDR PMU, PCIe PMU driver, CMN-700, and RAS.

    • Adds support for Coresight features.

    • The ARM architecture now supports ARM SPE perf memory profiling/c2c features.

    • virtiofs now supports file-level DAX.

    • Adds support for the smmu event polling feature.

Alibaba Cloud Linux 3.3.4

aliyun_3_x64_20G_alibase_20220413.vhd

2022-04-13

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.4.al8.x86_64.

    • Fixes the critical security vulnerabilities CVE-2022-1016 and CVE-2022-27666.

aliyun_3_arm64_20G_alibase_20220413.vhd

2022-04-13

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.4.al8.aarch64.

    • Fixes the critical security vulnerabilities CVE-2022-1016 and CVE-2022-27666.

Alibaba Cloud Linux 3.3.3

aliyun_3_x64_20G_alibase_20220315.vhd

2022-03-15

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software.

  • Fixes software package security vulnerabilities.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.3.al8.x86_64.

    • Fixes the CVE-2022-0435 and CVE-2022-0847 vulnerabilities.

aliyun_3_arm64_20G_alibase_20220315.vhd

2022-03-15

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit ARM edition base image with the latest software.

  • Fixes software package security vulnerabilities.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.3.al8.aarch64.

    • Fixes the CVE-2022-0435 and CVE-2022-0847 vulnerabilities.

Alibaba Cloud Linux 3.3.2

aliyun_3_x64_20G_alibase_20220225.vhd

2022-02-25

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit base image with the latest software and fixes software package security vulnerabilities.

  • Sets the Real Time Clock (RTC) to Coordinated Universal Time (UTC). For more information, see Linux time and time zones.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.2.al8.x86_64.

    • Fixes the CVE-2022-0492, CVE-2021-4197, CVE-2022-0330, CVE-2022-22942, and CVE-2022-0185 vulnerabilities.

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • The kernel code multi-copy feature.

      • The kernel code large page feature.

      • RDMA/SMC-R features.

    • Intel SPR now supports new features, including AMX, RAS, RCEC, bus lock detection and rate limiting, and uncore.

    • Adds the MCA-R feature for Intel Ice Lake processors.

    • Enables the Intel Data Streaming Accelerator (DSA) function.

    • virtio-net now supports the XDP socket feature.

    • Adds support for Chinese commercial cryptography to Kernel-based Transport Layer Security (KTLS).

    • Adds Kfence, a tool for detecting issues such as out-of-bounds memory access and use-after-free (UAF).

    • Optimizes the AVX/AVX2 implementation of the kernel SM4 algorithm.

    • Adds support for the Hygon CSV VM attestation feature.

    • Adds the perf c2c feature for ARM SPE.

    • Adds support for the i10nm_edac feature.

    • Backports the unevictable_pid feature.

    • Adds support for memory watermark adjustment.

    • Adds support for the adaptive sqpoll mode for IO_Uring.

    • Adds support for huge vmalloc mappings.

aliyun_3_x64_20G_qboot_alibase_20220225.vhd

2022-02-25

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit Quick Launch Edition image.

  • This image is based on version aliyun_3_x64_20G_alibase_20220225.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Sets the Real Time Clock (RTC) to Coordinated Universal Time (UTC). For more information, see Linux time and time zones.

aliyun_3_x64_20G_scc_alibase_20220225.vhd

2022-02-25

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit SCC Edition image with the latest software.

  • This image is based on version aliyun_3_x64_20G_alibase_20220225.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Switches to a UEFI-only boot mode.

  • Sets the Real Time Clock (RTC) to Coordinated Universal Time (UTC). For more information, see Linux time and time zones.

aliyun_3_arm64_20G_alibase_20220225.vhd

2022-02-25

  • Sets the Real Time Clock (RTC) to Coordinated Universal Time (UTC). For more information, see Linux time and time zones.

  • Kernel updates:

    • Updates the kernel to 5.10.84-10.2.al8.aarch64.

    • Fixes the CVE-2022-0492, CVE-2021-4197, CVE-2022-0330, CVE-2022-22942, and CVE-2022-0185 vulnerabilities.

    • Adds support for the following proprietary technologies from Alibaba Cloud:

      • The kernel code multi-copy feature.

      • The kernel code large page feature.

      • RDMA/SMC-R features.

    • Intel SPR now supports new features, including AMX, RAS, RCEC, bus lock detection and rate limiting, and uncore.

    • Adds the MCA-R feature for Intel Ice Lake processors.

    • Enables the Intel Data Streaming Accelerator (DSA) function.

    • virtio-net now supports the XDP socket feature.

    • Adds support for Chinese commercial cryptography to Kernel-based Transport Layer Security (KTLS).

    • Adds Kfence, a tool for detecting issues such as out-of-bounds memory access and use-after-free (UAF).

    • Optimizes the AVX/AVX2 implementation of the kernel SM4 algorithm.

    • Adds support for the Hygon CSV VM attestation feature.

    • Adds the perf c2c feature for ARM SPE.

    • Adds support for the i10nm_edac feature.

    • Backports the unevictable_pid feature.

    • Adds support for memory watermark adjustment.

    • Adds support for the adaptive sqpoll mode for IO_Uring.

    • Adds support for huge vmalloc mappings.

aliyun_3_x64_20G_uefi_alibase_20220225.vhd

2022-02-25

  • Updates the Alibaba Cloud Linux 3.2104 LTS 64-bit UEFI Edition image with the latest software.

  • This image is based on version aliyun_3_x64_20G_alibase_20220225.vhd of the Alibaba Cloud Linux 3.2104 LTS 64-bit base image.

  • Sets the Real Time Clock (RTC) to Coordinated Universal Time (UTC). For more information, see Linux time and time zones.

2021

Version

Image ID

Release date

Updates

Alibaba Cloud Linux 3.2

aliyun_3_x64_20G_qboot_alibase_20211214.vhd

2021-12-14

  • Added the Alibaba Cloud Linux 3.2104 64-bit Quick Launch Edition image.

  • This image is based on the aliyun_3_x64_20G_alibase_20210910.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

aliyun_3_x64_20G_scc_alibase_20211018.vhd

2021-10-18

  • Updated the Alibaba Cloud Linux 3.2104 64-bit SCC Edition image to the latest software versions.

  • This image is based on the aliyun_3_x64_20G_alibase_20210910.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

  • This image supports only the UEFI boot mode.

aliyun_3_x64_20G_alibase_20210910.vhd

2021-09-10

  • Updated the Alibaba Cloud Linux 3.2104 64-bit base image with the latest software and patched security vulnerabilities in packages.

  • Added the update-motd service and enabled it by default.

  • Enabled the Kdump service by default.

  • Enabled the atd service by default.

  • Kernel updates:

    • Upgraded the kernel to the mainline stable version 5.10.60. The current version is 5.10.60-9.al8.x86_64.

    • Fixed kernel bugs and addressed critical security vulnerabilities.

    • Added support for the following proprietary technologies from Alibaba Cloud:

      • eRDMA and eRDMA-based SMC-R technology

      • Resource isolation for OOM priority control

      • Memory KIDLED technology

      • Resource isolation for memcg zombie reaper

      • Rich container

      • Resource isolation for CPU Group Identity

      • UKFEF technology

    • Added support for Intel SPR CPUs.

    • Added support for AMD Milan cpupower.

    • Added support for a SEDI-based NMI watchdog on the ARM64 architecture.

    • Added support for Memory Partitioning and Monitoring (MPAM) on the ARM64 architecture.

    • Added support for memory hot-plugging on the ARM64 architecture.

    • Enhanced kernel fast boot technology.

    • Added support for x86 SGX2.

    • Optimized virtio-net performance.

    • Added support for the eBPF Linux Security Modules (LSM) technology.

    • Improved KVM virtualization with hardware-software co-optimization (supports PV-qspinlock).

aliyun_3_arm64_20G_alibase_20210910.vhd

2021-09-10

  • Updated the Alibaba Cloud Linux 3.2104 64-bit for ARM image to the latest software versions.

  • This image is based on the aliyun_3_arm64_20G_alibase_20210910.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

aliyun_3_x64_20G_uefi_alibase_20210910.vhd

2021-09-10

  • Updated the Alibaba Cloud Linux 3.2104 64-bit UEFI Edition image to the latest software versions.

  • This image is based on the aliyun_3_x64_20G_alibase_20210910.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

  • Available in the following regions: China (Hangzhou), China (Shanghai), China (Beijing), China (Ulanqab), China (Shenzhen), China (Heyuan), and Singapore.

Alibaba Cloud Linux 3.1

aliyun_3_arm64_20G_alibase_20210709.vhd

2021-07-09

  • Added the Alibaba Cloud Linux 3.2104 64-bit for ARM image.

  • Added support for Security Center integration.

  • Available in the China (Hangzhou) region.

aliyun_3_x64_20G_scc_alibase_20210806.vhd

2021-08-06

  • Added the Alibaba Cloud Linux 3.2104 64-bit SCC Edition image.

  • This image is based on the aliyun_3_x64_20G_alibase_20210425.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

  • This image supports only the UEFI boot mode.

  • Available in the following regions: China (Beijing), China (Hangzhou), China (Shanghai), and China (Shenzhen).

aliyun_3_x64_20G_alibase_20210425.vhd

2021-04-25

  • Updated the Alibaba Cloud Linux 3.2104 64-bit base image.

  • Kernel upgraded to version 5.10.23-5.al8.x86_64.

aliyun_3_x64_20G_uefi_alibase_20210425.vhd

2021-04-25

  • Added the Alibaba Cloud Linux 3.2104 64-bit UEFI Edition image.

  • This image is based on the aliyun_3_x64_20G_alibase_20210425.vhd version of the Alibaba Cloud Linux 3.2104 64-bit base image.

  • This image supports only the UEFI boot mode.

  • Available in the following regions: China (Beijing), China (Hangzhou), China (Shanghai), and China (Shenzhen).

Alibaba Cloud Linux 3.0

aliyun_3_x64_20G_alibase_20210415.vhd

2021-04-15

  • Released the Alibaba Cloud Linux 3.2104 64-bit base image.

  • Kernel details:

    • Based on the upstream Linux 5.10 Long Term Support (LTS) kernel; the initial version is 5.10.23-4.al8.x86_64.

    • The ARM64 architecture supports the PV-Panic, PV-Unhalt, and PV-Preempt features.

    • The ARM64 architecture supports kernel live patching.

    • Added support for TCP-RT.

    • Added support for asynchronous background reclaim for memcg.

    • The cgroup v1 interface supports memcg Quality of Service (QoS) and Pressure Stall Information (PSI).

    • Added support for cgroup writeback.

    • Improved monitoring and statistics for block I/O throttling.

    • Optimized the JBD2 interface for ext4

    • Optimized the Alibaba Cloud open source kernel and resolved issues in multiple subsystems, including the scheduler, memory, file system, and block layer.

    • Added support for CPU Burst.

  • Image details:

    • Compatible with the CentOS 8 and Red Hat Enterprise Linux (RHEL) 8 software ecosystems and includes patches for security vulnerabilities in packages.

    • Supports GCC 10.2.1 and glibc 2.32.

    • Supports Python 3.6 and Python 2.7.

    • Supports the new AppStream mechanism.

  • Available in the China (Hangzhou) region.

Related documents