The last two patches in this series do a version upgrade with added
and changed APIs, which is typically not OK for an LTS release.
However I'd like to get some feedback on whether people think this is
an acceptable risk for the CVEs that it fixes.
To help with reviewing this, I've cut pasted the
From: Richard Purdie
rpm is close to release and give our release timings, update to the
rc1 of 4.18.
Includes fixes for CVE-2021-35937, CVE-2021-35938 and CVE-2021-35939
which can't be easily backported.
Add a PACKAGECONFIG option for a new readline dependency and disable
it by default since i