Format: 1.8 Date: Fri, 26 Apr 2019 03:01:29 -0400 Source: linux-aws Binary: linux-aws-headers-4.15.0-1038 linux-aws-tools-4.15.0-1038 linux-aws-cloud-tools-4.15.0-1038 linux-image-4.15.0-1038-aws linux-modules-4.15.0-1038-aws linux-modules-extra-4.15.0-1038-aws linux-headers-4.15.0-1038-aws linux-image-4.15.0-1038-aws-dbgsym linux-tools-4.15.0-1038-aws linux-cloud-tools-4.15.0-1038-aws linux-udebs-aws linux-buildinfo-4.15.0-1038-aws Architecture: arm64 arm64_translations Version: 4.15.0-1038.40 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Khalid Elmously Description: linux-aws-cloud-tools-4.15.0-1038 - Linux kernel version specific cloud tools for version 4.15.0-1038 linux-aws-headers-4.15.0-1038 - Header files related to Linux kernel version 4.15.0 linux-aws-tools-4.15.0-1038 - Linux kernel version specific tools for version 4.15.0-1038 linux-buildinfo-4.15.0-1038-aws - Linux kernel buildinfo for version 4.15.0 on ARMv8 SMP linux-cloud-tools-4.15.0-1038-aws - Linux kernel version specific cloud tools for version 4.15.0-1038 linux-headers-4.15.0-1038-aws - Linux kernel headers for version 4.15.0 on ARMv8 SMP linux-image-4.15.0-1038-aws - Linux kernel image for version 4.15.0 on ARMv8 SMP linux-image-4.15.0-1038-aws-dbgsym - Linux kernel debug image for version 4.15.0 on ARMv8 SMP linux-modules-4.15.0-1038-aws - Linux kernel extra modules for version 4.15.0 on ARMv8 SMP linux-modules-extra-4.15.0-1038-aws - Linux kernel extra modules for version 4.15.0 on ARMv8 SMP linux-tools-4.15.0-1038-aws - Linux kernel version specific tools for version 4.15.0-1038 linux-udebs-aws - Metapackage depending on kernel udebs (udeb) Launchpad-Bugs-Fixed: 1786013 1798921 1812809 1813244 1814874 1818490 1819786 1819921 1820868 1821290 1821663 1822247 1822760 1822821 1822870 1823056 1823972 1824553 1825058 1825074 1825272 1825487 1826338 1826358 Changes: linux-aws (4.15.0-1038.40) bionic; urgency=medium . * linux-aws: 4.15.0-1038.40 -proposed tracker (LP: #1826338) . * Packaging resync (LP: #1786013) - [Packaging] resync git-ubuntu-log . [ Ubuntu: 4.15.0-49.53 ] . * linux: 4.15.0-49.53 -proposed tracker (LP: #1826358) * Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) - powerpc/64s: Add support for ori barrier_nospec patching - powerpc/64s: Patch barrier_nospec in modules - powerpc/64s: Enable barrier_nospec based on firmware settings - powerpc: Use barrier_nospec in copy_from_user() - powerpc/64: Use barrier_nospec in syscall entry - powerpc/64s: Enhance the information in cpu_show_spectre_v1() - powerpc/64: Disable the speculation barrier from the command line - powerpc/64: Make stf barrier PPC_BOOK3S_64 specific. - powerpc/64: Add CONFIG_PPC_BARRIER_NOSPEC - powerpc/64: Call setup_barrier_nospec() from setup_arch() - powerpc/64: Make meltdown reporting Book3S 64 specific - powerpc/lib/code-patching: refactor patch_instruction() - powerpc/lib/feature-fixups: use raw_patch_instruction() - powerpc/asm: Add a patch_site macro & helpers for patching instructions - powerpc/64s: Add new security feature flags for count cache flush - powerpc/64s: Add support for software count cache flush - powerpc/pseries: Query hypervisor for count cache flush settings - powerpc/powernv: Query firmware for count cache flush settings - powerpc/fsl: Add nospectre_v2 command line argument - KVM: PPC: Book3S: Add count cache flush parameters to kvmppc_get_cpu_char() - [Config] Add CONFIG_PPC_BARRIER_NOSPEC * Packaging resync (LP: #1786013) - [Packaging] resync git-ubuntu-log * autopkgtests run too often, too much and don't skip enough (LP: #1823056) - [Debian] Set +x on rebuild testcase. - [Debian] Skip rebuild test, for regression-suite deps. - [Debian] Make ubuntu-regression-suite skippable on unbootable kernels. - [Debian] make rebuild use skippable error codes when skipping. - [Debian] Only run regression-suite, if requested to. * bionic: fork out linux-snapdragon into its own topic kernel (LP: #1820868) - [Packaging] remove arm64 snapdragon from getabis - [Config] config changes for snapdragon split - packaging: arm64: disable building the snapdragon flavour - [Packaging] arm64: Drop snapdragon from kernel-versions * CVE-2017-5753 - KVM: arm/arm64: vgic: fix possible spectre-v1 in vgic_get_irq() - media: dvb_ca_en50221: prevent using slot_info for Spectre attacs - sysvipc/sem: mitigate semnum index against spectre v1 - libahci: Fix possible Spectre-v1 pmp indexing in ahci_led_store() - s390/keyboard: sanitize array index in do_kdsk_ioctl - arm64: fix possible spectre-v1 write in ptrace_hbp_set_event() - KVM: arm/arm64: vgic: Fix possible spectre-v1 write in vgic_mmio_write_apr() - pktcdvd: Fix possible Spectre-v1 for pkt_devs - net: socket: fix potential spectre v1 gadget in socketcall - net: socket: Fix potential spectre v1 gadget in sock_is_registered - drm/amdgpu/pm: Fix potential Spectre v1 - netlink: Fix spectre v1 gadget in netlink_create() - ext4: fix spectre gadget in ext4_mb_regular_allocator() - drm/i915/kvmgt: Fix potential Spectre v1 - net: sock_diag: Fix spectre v1 gadget in __sock_diag_cmd() - fs/quota: Fix spectre gadget in do_quotactl - hwmon: (nct6775) Fix potential Spectre v1 - mac80211_hwsim: Fix possible Spectre-v1 for hwsim_world_regdom_custom - switchtec: Fix Spectre v1 vulnerability - misc: hmc6352: fix potential Spectre v1 - tty: vt_ioctl: fix potential Spectre v1 - nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT - nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds - IB/ucm: Fix Spectre v1 vulnerability - RDMA/ucma: Fix Spectre v1 vulnerability - drm/bufs: Fix Spectre v1 vulnerability - usb: gadget: storage: Fix Spectre v1 vulnerability - ptp: fix Spectre v1 vulnerability - HID: hiddev: fix potential Spectre v1 - vhost: Fix Spectre V1 vulnerability - drivers/misc/sgi-gru: fix Spectre v1 vulnerability - ipv4: Fix potential Spectre v1 vulnerability - aio: fix spectre gadget in lookup_ioctx - ALSA: emux: Fix potential Spectre v1 vulnerabilities - ALSA: pcm: Fix potential Spectre v1 vulnerability - ip6mr: Fix potential Spectre v1 vulnerability - ALSA: rme9652: Fix potential Spectre v1 vulnerability - ALSA: emu10k1: Fix potential Spectre v1 vulnerabilities - KVM: arm/arm64: vgic: Fix off-by-one bug in vgic_get_irq() - drm/ioctl: Fix Spectre v1 vulnerabilities - char/mwave: fix potential Spectre v1 vulnerability - applicom: Fix potential Spectre v1 vulnerabilities - ipmi: msghandler: Fix potential Spectre v1 vulnerabilities - powerpc/ptrace: Mitigate potential Spectre v1 - cfg80211: prevent speculation on cfg80211_classify8021d() return - ALSA: rawmidi: Fix potential Spectre v1 vulnerability - ALSA: seq: oss: Fix Spectre v1 vulnerability * Bionic: Sync to Xenial (Spectre) (LP: #1822760) - x86/speculation/l1tf: Suggest what to do on systems with too much RAM - KVM: SVM: Add MSR-based feature support for serializing LFENCE - KVM: VMX: fixes for vmentry_l1d_flush module parameter - KVM: X86: Allow userspace to define the microcode version - SAUCE: [Fix] x86/KVM/VMX: Add L1D flush logic - SAUCE: [Fix] x86/speculation: Use ARCH_CAPABILITIES to skip L1D flush on vmentry * [SRU] [B/OEM] Fix ACPI bug that causes boot failure (LP: #1819921) - SAUCE: ACPI / bus: Add some Lenovo laptops in list of acpi table term list * Bionic update: upstream stable patchset for fuse 2019-04-12 (LP: #1824553) - fuse: fix double request_end() - fuse: fix unlocked access to processing queue - fuse: umount should wait for all requests - fuse: Fix oops at process_init_reply() - fuse: Don't access pipe->buffers without pipe_lock() - fuse: Fix use-after-free in fuse_dev_do_read() - fuse: Fix use-after-free in fuse_dev_do_write() - fuse: set FR_SENT while locked - fuse: fix blocked_waitq wakeup - fuse: fix leaked notify reply - fuse: fix possibly missed wake-up after abort - fuse: fix use-after-free in fuse_direct_IO() - fuse: continue to send FUSE_RELEASEDIR when FUSE_OPEN returns ENOSYS - fuse: handle zero sized retrieve correctly - fuse: call pipe_buf_release() under pipe lock - fuse: decrement NR_WRITEBACK_TEMP on the right page * Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) // Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) - powerpc64s: Show ori31 availability in spectre_v1 sysfs file not v2 - powerpc/fsl: Fix spectre_v2 mitigations reporting - powerpc: Avoid code patching freed init sections * Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) // Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) // Backport support for software count cache flush Spectre v2 mitigation. (CVE) (required for POWER9 DD2.3) (LP: #1822870) - powerpc/security: Fix spectre_v2 reporting * CVE-2019-3874 - sctp: use sk_wmem_queued to check for writable space - sctp: implement memory accounting on tx path - sctp: implement memory accounting on rx path * NULL pointer dereference when using z3fold and zswap (LP: #1814874) - z3fold: fix possible reclaim races * Kprobe event argument syntax in ftrace from ubuntu_kernel_selftests failed on B PowerPC (LP: #1812809) - selftests/ftrace: Add ppc support for kprobe args tests * The Realtek card reader does not enter PCIe 1.1/1.2 (LP: #1825487) - misc: rtsx: make various functions static - misc: rtsx: Enable OCP for rts522a rts524a rts525a rts5260 - SAUCE: misc: rtsx: Fixed rts5260 power saving parameter and sd glitch * headset-mic doesn't work on two Dell laptops. (LP: #1825272) - ALSA: hda/realtek - add two more pin configuration sets to quirk table * CVE-2018-16884 - sunrpc: use SVC_NET() in svcauth_gss_* functions - sunrpc: use-after-free in svc_process_common() * sky2 ethernet card don't work after returning from suspension (LP: #1798921) - sky2: Increase D3 delay again * CVE-2019-9500 - brcmfmac: assure SSID length from firmware is limited * CVE-2019-9503 - brcmfmac: add subtype check for event handling in data path * CVE-2019-3882 - vfio/type1: Limit DMA mappings per container * Intel I210 Ethernet card not working after hotplug [8086:1533] (LP: #1818490) - igb: Fix WARN_ONCE on runtime suspend * bionic, xenial/hwe: misses "fuse: fix initial parallel dirops" patch (LP: #1823972) - fuse: fix initial parallel dirops * amdgpu resume failure: failed to allocate wb slot (LP: #1825074) - drm/amdgpu: fix&cleanups for wb_clear * Pop noise when headset is plugged in or removed from GHS/Line-out jack (LP: #1821290) - ALSA: hda/realtek - Add unplug function into unplug state of Headset Mode for ALC225 - ALSA: hda/realtek - Disable headset Mic VREF for headset mode of ALC225 - ALSA: hda/realtek - Add support headset mode for DELL WYSE AIO - ALSA: hda/realtek - Add support headset mode for New DELL WYSE NB * mac80211_hwsim unable to handle kernel NULL pointer dereference at0000000000000000 (LP: #1825058) - mac80211_hwsim: Timer should be initialized before device registered * [regression][snd_hda_codec_realtek] repeating crackling noise after 19.04 upgrade (LP: #1821663) - ALSA: hda: Add Intel NUC7i3BNB to the power_save blacklist - ALSA: hda - add Lenovo IdeaCentre B550 to the power_save_blacklist - ALSA: hda - Add two more machines to the power_save_blacklist * ubuntu_nbd_smoke_test failed on P9 with Bionic kernel (LP: #1822247) - nbd: fix how we set bd_invalidated * TSC clocksource not available in nested guests (LP: #1822821) - kvmclock: fix TSC calibration for nested guests * 4.15 kernel ip_vs --ops causes performance and hang problem (LP: #1819786) - ipvs: fix refcount usage for conns in ops mode * systemd cause kernel trace "BUG: unable to handle kernel paging request at 6db23a14" on Cosmic i386 (LP: #1813244) // systemd cause kernel trace "BUG: unable to handle kernel paging request at 6db23a14" on Cosmic i386 (LP: #1813244) - openvswitch: fix flow actions reallocation Checksums-Sha1: 2b819909b1b29d80bb473fa26e8bd6a1a3557e40 63748 linux-aws-cloud-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb 585a84915fe3b379e98877bf2bfce623f793e1f0 3908436 linux-aws-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb 0a1abc94578cd976392101cb0734965422893c08 10491 linux-aws_4.15.0-1038.40_arm64.buildinfo b1c3bc49db0ce8abd9731a291a04b5ee285452a7 24482 linux-aws_4.15.0-1038.40_arm64_translations.tar.gz 43cbf1a6127bdeb68f39d40c3397d3afbb0d4d7d 240888 linux-buildinfo-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 90ba396112b7a757c972079a5933b8b4d3835026 1868 linux-cloud-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 2707e201f2cda1614e8975ed4df051e672039f39 731448 linux-headers-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 7b015312d1fa0eb625f14128ed1fc8efadcf1321 634076316 linux-image-4.15.0-1038-aws-dbgsym_4.15.0-1038.40_arm64.ddeb a7cc409c831b5f2aab3fd58bfe55de494db29adf 8363640 linux-image-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb a9f611e03494f410e5c84c365a5160b46c9e8d3d 11756156 linux-modules-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 364a55f5d00beb9c5fb3507a1f333a9415f45d00 1876 linux-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb Checksums-Sha256: 4f53bdcf2dc2a639e5733d9a40ae55971c89e8bed6bfb9e269cbc73ac02fd2e7 63748 linux-aws-cloud-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb efe3619f55a8988c58bf68b794fb217837dfcdd7880d58cba14ce66641966935 3908436 linux-aws-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb 71a1eae1604b54307d237ea9b44deaf59c13cd7c5564e0a7c60ea8672862572e 10491 linux-aws_4.15.0-1038.40_arm64.buildinfo 06845a1654a556b75e85409608450922347335f4980308e1a3d997dcc5d5df1a 24482 linux-aws_4.15.0-1038.40_arm64_translations.tar.gz 06f85be352d6da42d2bbb04cc010a1472bf843a072519f7a6f5e4104c8c026f7 240888 linux-buildinfo-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb c0a49f3faa2117e26f595ee7f21e21437aced91526811b379b805c3e336512d3 1868 linux-cloud-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb dcbfdf039a4febaf287fe18f128dd386b105501131c7a13e0b69da434230594d 731448 linux-headers-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb fd70beb4d8d5aa3d582f671f1f269b21849a6e5b3406995839c2e2c4b05f82ee 634076316 linux-image-4.15.0-1038-aws-dbgsym_4.15.0-1038.40_arm64.ddeb 5759d919805c7aed4a943b10d2fa1413ec07000ac3a5ebac5aa443e6c6a6d93c 8363640 linux-image-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 8bb8ab2b868f9dc678dee1704808172f6c2014d300af5fa342ae4926b490c1b6 11756156 linux-modules-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 8cb8f8da292afcfb3715c7c1c4a38b424ef207a4a5a25e6e1dcf26acab590f36 1876 linux-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb Files: 855bda633e6aeab0d50fd0f3df27b692 63748 devel optional linux-aws-cloud-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb 3545aaffe59fd5d4c0825d42317696da 3908436 devel optional linux-aws-tools-4.15.0-1038_4.15.0-1038.40_arm64.deb 3de5ff59bddf5572eac5bb90391b9357 10491 devel optional linux-aws_4.15.0-1038.40_arm64.buildinfo 6b678fc60e113eeeb243af281d0d87a4 24482 raw-translations - linux-aws_4.15.0-1038.40_arm64_translations.tar.gz 65217feb3c96f9c22d6e3ab97261e13e 240888 kernel optional linux-buildinfo-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 39f64a46aaf4f96b87d4f9375d12e428 1868 devel optional linux-cloud-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb b18e83012279b29b1db78d8ece4cb373 731448 devel optional linux-headers-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb d6a5b1a1cae93aa07e12c48eb6cd5d0e 634076316 devel optional linux-image-4.15.0-1038-aws-dbgsym_4.15.0-1038.40_arm64.ddeb 76e21e8901e2a66409d364a392f62aff 8363640 kernel optional linux-image-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb a9e9067226c840cb7fcbd0e2290cb766 11756156 kernel optional linux-modules-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb 587bfd8edf67422e720f41e73f8ad799 1876 devel optional linux-tools-4.15.0-1038-aws_4.15.0-1038.40_arm64.deb