linux 4.17.15-1 source package in Debian

Changelog

linux (4.17.15-1) unstable; urgency=medium

  * New upstream stable update:
    https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.17.15
    - [hppa/parisc] Enable CONFIG_MLONGCALLS by default
    - [hppa/parisc] Define mb() and add memory barriers to assembler unlock
      sequences
    - Mark HI and TASKLET softirq synchronous
    - stop_machine: Disable preemption after queueing stopper threads
    - sched/deadline: Update rq_clock of later_rq when pushing a task
    - zram: remove BD_CAP_SYNCHRONOUS_IO with writeback feature
    - xen/netfront: don't cache skb_shinfo()
    - bpf, sockmap: fix leak in bpf_tcp_sendmsg wait for mem path
    - bpf, sockmap: fix bpf_tcp_sendmsg sock error handling
    - scsi: sr: Avoid that opening a CD-ROM hangs with runtime power
      management enabled
    - scsi: qla2xxx: Fix memory leak for allocating abort IOCB
    - init: rename and re-order boot_cpu_state_init()
    - root dentries need RCU-delayed freeing
    - make sure that __dentry_kill() always invalidates d_seq, unhashed or not
    - fix mntput/mntput race
    - fix __legitimize_mnt()/mntput() race
    - [armhf] dts: imx6sx: fix irq for pcie bridge
    - [x86] paravirt: Fix spectre-v2 mitigations for paravirt guests
    - [x86] speculation: Protect against userspace-userspace spectreRSB
    - [x86] kprobes/x86: Fix %p uses in error messages
    - [x86] irqflags: Provide a declaration for native_save_fl
    - [x86] speculation/l1tf: Increase 32bit PAE __PHYSICAL_PAGE_SHIFT
    - [x86] speculation/l1tf: Change order of offset/type in swap entry
    - [x86] speculation/l1tf: Protect swap entries against L1TF
    - [x86] speculation/l1tf: Protect PROT_NONE PTEs against speculation
    - [x86] speculation/l1tf: Make sure the first page is always reserved
    - [x86] speculation/l1tf: Add sysfs reporting for l1tf
    - [x86] speculation/l1tf: Disallow non privileged high MMIO PROT_NONE
      mappings
    - [x86] speculation/l1tf: Limit swap file size to MAX_PA/2
    - [x86] bugs: Move the l1tf function and define pr_fmt properly
    - sched/smt: Update sched_smt_present at runtime
    - [x86] smp: Provide topology_is_primary_thread()
    - [x86] topology: Provide topology_smt_supported()
    - cpu/hotplug: Make bringup/teardown of smp threads symmetric
    - cpu/hotplug: Split do_cpu_down()
    - cpu/hotplug: Provide knobs to control SMT
    - [x86] cpu: Remove the pointless CPU printout
    - [x86] cpu/AMD: Remove the pointless detect_ht() call
    - [x86] cpu/common: Provide detect_ht_early()
    - [x86] cpu/topology: Provide detect_extended_topology_early()
    - [x86] cpu/intel: Evaluate smp_num_siblings early
    - [x86] CPU/AMD: Do not check CPUID max ext level before parsing SMP info
    - [x86] cpu/AMD: Evaluate smp_num_siblings early
    - [x86] apic: Ignore secondary threads if nosmt=force
    - [x86] speculation/l1tf: Extend 64bit swap file size limit
    - [x86] cpufeatures: Add detection of L1D cache flush support.
    - [x86] CPU/AMD: Move TOPOEXT reenablement before reading smp_num_siblings
    - [x86] speculation/l1tf: Protect PAE swap entries against L1TF
    - [x86] speculation/l1tf: Fix up pte->pfn conversion for PAE
    - Revert "[x86] apic: Ignore secondary threads if nosmt=force"
    - cpu/hotplug: Boot HT siblings at least once
    - [x86] KVM: Warn user if KVM is loaded SMT and L1TF CPU bug being present
    - [x86] KVM/VMX: Add module argument for L1TF mitigation
    - [x86] KVM/VMX: Add L1D flush algorithm
    - [x86] KVM/VMX: Add L1D MSR based flush
    - [x86] KVM/VMX: Add L1D flush logic
    - [x86] KVM/VMX: Split the VMX MSR LOAD structures to have an host/guest
      numbers
    - [x86] KVM/VMX: Add find_msr() helper function
    - [x86] KVM/VMX: Separate the VMX AUTOLOAD guest/host number accounting
    - [x86] KVM/VMX: Extend add_atomic_switch_msr() to allow VMENTER only MSRs
    - [x86] KVM/VMX: Use MSR save list for IA32_FLUSH_CMD if required
    - cpu/hotplug: Online siblings when SMT control is turned on
    - [x86] litf: Introduce vmx status variable
    - [x86] kvm: Drop L1TF MSR list approach
    - [x86] l1tf: Handle EPT disabled state proper
    - [x86] kvm: Move l1tf setup function
    - [x86] kvm: Add static key for flush always
    - [x86] kvm: Serialize L1D flush parameter setter
    - [x86] kvm: Allow runtime control of L1D flush
    - cpu/hotplug: Expose SMT control init function
    - cpu/hotplug: Set CPU_SMT_NOT_SUPPORTED early
    - [x86] bugs, kvm: Introduce boot-time control of L1TF mitigations
    - Documentation: Add section about CPU vulnerabilities
    - [x86] speculation/l1tf: Unbreak !__HAVE_ARCH_PFN_MODIFY_ALLOWED
      architectures
    - [x86] KVM/VMX: Initialize the vmx_l1d_flush_pages' content
    - Documentation/l1tf: Fix typos
    - cpu/hotplug: detect SMT disabled by BIOS
    - [x86] KVM/VMX: Don't set l1tf_flush_l1d to true from vmx_l1d_flush()
    - [x86] KVM/VMX: Replace 'vmx_l1d_flush_always' with 'vmx_l1d_flush_cond'
    - [x86] KVM/VMX: Move the l1tf_flush_l1d test to vmx_l1d_flush()
    - [x86] irq: Demote irq_cpustat_t::__softirq_pending to u16
    - [x86] KVM/VMX: Introduce per-host-cpu analogue of l1tf_flush_l1d
    - [x86] Don't include linux/irq.h from asm/hardirq.h
    - [x86] irq: Let interrupt handlers set kvm_cpu_l1tf_flush_l1d
    - [x86] KVM/VMX: Don't set l1tf_flush_l1d from vmx_handle_external_intr()
    - Documentation/l1tf: Remove Yonah processors from not vulnerable list
    - [x86] speculation: Simplify sysfs report of VMX L1TF vulnerability
    - [x86] speculation: Use ARCH_CAPABILITIES to skip L1D flush on vmentry
    - KVM: VMX: Tell the nested hypervisor to skip L1D flush on vmentry
    - cpu/hotplug: Fix SMT supported evaluation
    - [x86] speculation/l1tf: Invert all not present mappings
    - [x86] speculation/l1tf: Make pmd/pud_mknotpresent() invert
    - [x86] mm/pat: Make set_memory_np() L1TF safe
    - [x86] mm/kmmio: Make the tracer robust against L1TF
    - tools headers: Synchronize prctl.h ABI header
    - tools headers: Synchronise x86 cpufeatures.h for L1TF additions
    - [x86] microcode: Allow late microcode loading with SMT disabled
    - [x86] smp: fix non-SMP broken build due to redefinition of
      apic_id_is_primary_thread
    - cpu/hotplug: Non-SMP machines do not make use of booted_once
    - [x86] init: fix build with CONFIG_SWAP=n
    - [x86] CPU/AMD: Have smp_num_siblings and cpu_llc_id always be present

  [ Ben Hutchings ]
  * serdev: Enable SERIAL_DEV_BUS, SERIAL_DEV_CTRL_TTYPORT as built-in
    (except on armel)
    - bluetooth: Re-enable BT_HCIUART_{BCM,LL} (Closes: #906048)
  * drivers/net/phy: Enable SFP as module (Closes: #906054)
  * Revert "net: increase fragment memory usage limits" (CVE-2018-5391)

  [ Salvatore Bonaccorso ]
  * [x86] l1tf: Fix build error seen if CONFIG_KVM_INTEL is disabled
  * [x86] i8259: Add missing include file
  * Bluetooth: hidp: buffer overflow in hidp_process_report (CVE-2018-9363)
  * Bump ABI to 3

 -- Salvatore Bonaccorso <email address hidden>  Fri, 17 Aug 2018 05:11:43 +0200

Upload details

Uploaded by:
Debian kernel team
Uploaded to:
Sid
Original maintainer:
Debian kernel team
Architectures:
linux-any all
Section:
kernel
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
linux_4.17.15-1.dsc 145.6 KiB 2e8222f8d41ab880d4c80489d27ff5c51b50a1b408ca5fb368c84744cfb12cb7
linux_4.17.15.orig.tar.xz 101.6 MiB d24bb5dcb8f8378fe3a13104572cef1efc44b08792231fc7e9da078a164bb36f
linux_4.17.15-1.debian.tar.xz 748.7 KiB 4392a791d277a51c75c4fb6573b67b531a3f2c4fd263b28d953ac9010d2d992a

No changes file available.

Binary packages built by this source