Commit Graph

14212 Commits

Author SHA1 Message Date
Ben Hutchings 22423990cd Drop "KVM: VMX: Zero out *all* general purpose registers after VM-Exit"
This is not needed to fix CVE-2019-3016, and is addressing an issue
that's so far theoretical.  It also needs a further fix to avoid
causing a more serious regression (depending on the compiler
behaviour).
2020-06-07 01:17:04 +01:00
Ben Hutchings ff5ad5a3d1 propagate_one(): mnt_set_mountpoint() needs mount_lock
A similar issue to CVE-2020-12114.
2020-06-07 00:46:11 +01:00
Salvatore Bonaccorso 6e26711704 Add fixes for CVE-2019-3016
Cherry-pick 11 commits from the 4.19.118 including prerequisited to
adress CVE-2019-3016.
2020-06-06 10:35:47 +02:00
Salvatore Bonaccorso 789f116fbc mm: Fix mremap not considering huge pmd devmap (CVE-2020-10757) 2020-06-05 12:34:34 +02:00
Salvatore Bonaccorso 50bf5b3b3d kernel/relay.c: handle alloc_percpu returning NULL in relay_open (CVE-2019-19462) 2020-06-05 12:30:40 +02:00
Salvatore Bonaccorso 7fc7c96d6e fs/binfmt_elf.c: allocate initialized memory in fill_thread_core_info() (CVE-2020-10732) 2020-06-03 07:42:07 +02:00
Salvatore Bonaccorso 2222852cc1 netlabel: cope with NULL catmap (CVE-2020-10711) 2020-06-02 20:27:49 +02:00
Salvatore Bonaccorso 888eb1f799 USB: gadget: fix illegal array access in binding with UDC (CVE-2020-13143) 2020-05-29 21:35:13 +02:00
Salvatore Bonaccorso aefd886eef scsi: sg: add sg_remove_request in sg_write (CVE-2020-12770) 2020-05-29 21:23:18 +02:00
Salvatore Bonaccorso 92ed2f689a [x86] KVM: SVM: Fix potential memory leak in svm_cpu_init() (CVE-2020-12768) 2020-05-29 14:03:17 +02:00
Salvatore Bonaccorso 2fe68e87e7 USB: core: Fix free-while-in-use bug in the USB S-Glibrary (CVE-2020-12464) 2020-05-29 13:49:18 +02:00
Salvatore Bonaccorso 34284455a6 fs/namespace.c: fix mountpoint reference counter race (CVE-2020-12114) 2020-05-28 23:34:11 +02:00
Salvatore Bonaccorso b3b40efebd selinux: properly handle multiple messages in selinux_netlink_send() (CVE-2020-10751) 2020-05-28 23:02:50 +02:00
Salvatore Bonaccorso a4fb2a7b76 include/uapi/linux/swab.h: fix userspace breakage, use __BITS_PER_LONG for swap
Closes: #960271
2020-05-13 17:45:56 +02:00
Ben Hutchings 195b1745c4 Avoid an ABI change for SRBDS
Adding the x86_cpu_id::steppings field is an ABI change.  It doesn't
seem worth the trouble of another ABI bump just to be able to report
some potential future CPU steppings as invulnerable.  Until we have
other change that require an ABI bump, we'll match the affected models
regardless of stepping.

Keep the reverted patch in the queue so that the reverting patch will
continue to be applied when we rebase onto a new stable update.
2020-05-05 02:21:33 +01:00
Ben Hutchings 0f2a83859c [x86] Add support for mitigation of SRBDS (CVE-2020-0543)
Apply the current version of the backport to 4.19.
2020-05-05 02:07:33 +01:00
Salvatore Bonaccorso 136062cf83 Prepare to release linux (4.19.118-2). 2020-04-29 11:38:42 +02:00
Salvatore Bonaccorso cfb6935a87 Add ABI reference for 4.19.0-9
Gbp-Dch: Ignore
2020-04-29 10:36:57 +02:00
Salvatore Bonaccorso c977ce99a1 Release linux (4.19.98-1+deb10u1).
-----BEGIN PGP SIGNATURE-----
 
 iQKmBAABCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl6maCdfFIAAAAAALgAo
 aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
 ZWJpYW4ub3JnAAoJEAVMuPMTQ89EBtYP/1W8Y1dU9kCrJyK3Nz+HFwEKoe/ha1+t
 vcjf4E1TOSUh30eaKaD6GVBp7iCK/tGDBxyfUerDltmilVRDt7f9mE/4CFt3e26y
 S4DtsI5paoL1O/1uqbpG+53E5TPDw7CCJNkZ22/vjK++YzToaOjJIsTtZnHNNYwd
 nMYtGqhn95NiZ//nNsV4wgSF9vXIgWuWvAEY80KdmfBYUVicUz8HyZB9Q5ErH1e7
 /Fi9n7U/0F+PgcZSyLhS9vwlMY36HuuemYYMBzN48J2xL/73ttwoe0MU4Aieu1yX
 iVMsrVc/X5JWjHiSpsrExCYvHrRXG9v4kWMOs+piD1yFi7oxD/fNy+043jJqmyOV
 hu+3RX6BkNrw1jhLzDRYbOTz8Z09BXrUnXhyWLD5Z1ZgM1K5tQV0vCsiZBqyBHTK
 owSVaOSDxHWTa9zSmIDTMPN6ljaQML2G1lF6F+AUKg4hqqjydlikgpJGSmjfs3Pd
 YN2I9rfCpSuovYIUQXl38g4yLZC5onhEzLqFBBfxHJClND/nf27HARs6c0f72RlU
 6aHrPgZpj2JPE/r1PoUej4lyhIbFzdJIOf2b26ZUvQC+sMUsxE0SonpFQqjDZggJ
 cAqM5p80gbR8zGtBStwGGo0QljHdHbrzbnYfNQC/uGph0uYTvL+6BscUzO+RnYmx
 9hKy2cqOWLez
 =akKy
 -----END PGP SIGNATURE-----

Merge tag 'debian/4.19.98-1+deb10u1' into buster

Release linux (4.19.98-1+deb10u1).
2020-04-28 23:07:38 +02:00
Salvatore Bonaccorso f6cd3dfc5b Prepare to release linux (4.19.98-1+deb10u1). 2020-04-27 07:05:40 +02:00
Salvatore Bonaccorso a8fc50657f [s390x] mm: fix page table upgrade vs 2ndary address mode accesses (CVE-2020-11884) 2020-04-26 21:03:38 +02:00
Salvatore Bonaccorso 3e765ace82 mm: mempolicy: require at least one nodeid for MPOL_PREFERRED (CVE-2020-11565) 2020-04-26 20:58:02 +02:00
Salvatore Bonaccorso 2c376b16e6 vhost: Check docket sk_family instead of call getname (CVE-2020-10942) 2020-04-26 20:53:46 +02:00
Salvatore Bonaccorso 241912ed84 vfs: fix do_last() regression 2020-04-26 20:53:45 +02:00
Salvatore Bonaccorso d3e1b6996d do_last(): fetch directory ->i_mode and ->i_uid before it's too late (CVE-2020-8428) 2020-04-26 20:53:45 +02:00
Salvatore Bonaccorso a688ee48fb KVM: nVMX: Don't emulate instructions in guest mode (CVE-2020-2732) 2020-04-26 20:53:45 +02:00
Salvatore Bonaccorso 5cdd44bf16 Add ABI reference for 4.19.0-8
Gbp-Dch: Ignore
2020-04-26 20:53:45 +02:00
Ben Hutchings f142b431b1 Prepare to release linux (4.19.118-1). 2020-04-26 14:04:11 +01:00
Salvatore Bonaccorso 65ba05e78d blktrace: fix dereference after null check 2020-04-26 11:28:32 +02:00
Salvatore Bonaccorso a5acdf855d blktrace: Protect q->blk_trace with RCU (CVE-2019-19768) 2020-04-26 11:25:38 +02:00
Salvatore Bonaccorso 6fe845e460 net: ipv6_stub: use ip6_dst_lookup_flow instead of ip6_dst_lookup (CVE-2020-1749) 2020-04-26 11:20:05 +02:00
Salvatore Bonaccorso 79c0009334 net: ipv6: add net argument to ip6_dst_lookup_flow 2020-04-26 11:14:36 +02:00
Salvatore Bonaccorso 765258c0c8 Update commit message for f2fs patch to include note on backport
Gbp-Dch: Ignore
2020-04-26 11:13:27 +02:00
Salvatore Bonaccorso cfa7bd0b02 f2fs: fix to avoid memory leakage in f2fs_listxattr (CVE-2020-0067) 2020-04-26 11:06:23 +02:00
Salvatore Bonaccorso 01ac87b05e Add CVE id reference for CVE-2020-11494 2020-04-24 05:55:07 +02:00
Salvatore Bonaccorso 1e0b8b17f3 Update to 4.19.118
Cleanup debian/changelog file

Refresh "firmware: Remove redundant log messages from drivers" for context changes in 4.19.118
2020-04-23 20:41:14 +02:00
Ben Hutchings 37343cff01 Merge branch 'buster+ksm' into 'buster'
[buster] cloud: enable CONFIG_KSM for cloud

See merge request kernel-team/linux!229
2020-04-22 13:35:13 +00:00
Ben Hutchings f248c110af Merge branch 'carnil/linux-4.19-stable-updates' into buster
WIP: 4.19 stable updates

See merge request kernel-team/linux!213
2020-04-22 14:33:44 +01:00
Ben Hutchings c2a32c869d Bump ABI to 9 2020-04-22 04:04:25 +01:00
Ben Hutchings efae16e787 debian/changelog: Comma-separate multiple CVE IDs for the same change 2020-04-22 04:02:55 +01:00
Ben Hutchings 9570b230d4 debian/changelog: Add/correct arch-qualifications for some stable changes
Model-specific quirks are only relevant to that model's CPU
architecture.
2020-04-22 04:02:01 +01:00
Ben Hutchings c73c46766b debian/changelog: Delete stable changes to disabled drivers
There's not much point in mentioning them.
2020-04-22 03:58:05 +01:00
Ben Hutchings ee533a5333 debian/changelog: Delete stable changes that got reverted
There's no point in listing changes that didn't make it into this
release.  Delete the summary lines for the original commits and revert
commits.
2020-04-22 03:03:04 +01:00
Ben Hutchings dd8b268c15 debian/changelog: Summarise the rt changes
There is no need to list every update of the rt patch set, or
resolution of conflicts that have now been resolved upstream.

However, significant changes to the patch set should be listed,
so mention the patch that was dropped.
2020-04-22 02:54:36 +01:00
Salvatore Bonaccorso 6431292225 [rt] Update to 4.19.115-rt48
Refresh patch "pci/switchtec: Don't use completion's wait queue" which was
already done as well in previous rt patchset, due to context changes in
4.19.116 caused by 12ce9fd7fc87 ("PCI/switchtec: Fix init_completion race
condition with poll_wait()").
2020-04-21 22:25:37 +02:00
Salvatore Bonaccorso 6440db7ed1 Update to 4.19.117
Cleanup debian/changelog file
2020-04-21 22:08:20 +02:00
Noah Meyerhans 57cd8ee0e1 cloud: enable CONFIG_KSM for cloud
Closes: 955366
2020-04-20 14:23:43 -07:00
Salvatore Bonaccorso 72fdde5342 [rt] Refresh "pci/switchtec: Don't use completion's wait queue" for context changes in 4.19.116 2020-04-18 11:09:04 +02:00
Salvatore Bonaccorso 1fb0eb7956 Update to 4.19.116
Add CVE id reference for CVE-2020-11669

Cleanup debian/changelog file
2020-04-18 11:09:02 +02:00
Ben Hutchings 31d17e0e53 debian/README.source: Refer to upload checklist in kernel-team.git
(cherry picked from commit 68456ebc6bfabc94b05ca0771d502a2e1e5f8040)
2020-04-17 01:32:57 +01:00
Salvatore Bonaccorso 5d322cdf20 [rt] Refresh "workqueue: rework" for context changes in 4.19.114 2020-04-16 23:44:57 +02:00
Salvatore Bonaccorso 70cac4105f [rt] Refresh "genirq: Handle missing work_struct in irq_set_affinity_notifier()" for context changes in 4.19.114 2020-04-16 23:38:59 +02:00
Salvatore Bonaccorso 970c295c4d [rt] Refresh "genirq: Do not invoke the affinity callback via a workqueue on RT" for context changes in 4.19.114 2020-04-16 23:38:32 +02:00
Salvatore Bonaccorso 4e3802ddec [rt] Refresh "genirq: Do not invoke the affinity callback via a workqueue on RT" for context changes in 4.19.114 2020-04-16 23:29:40 +02:00
Salvatore Bonaccorso 81ec71f423 Update to 4.19.115
Add CVE id reference for CVE-2020-11565

Cleanup debian/changelog file
2020-04-13 14:46:04 +02:00
Salvatore Bonaccorso b3e52c87a5 Update to 4.19.114
Add CVE id reference for CVE-2020-11608

Add CVE id reference for CVE-2020-11609

Add CVE id reference for CVE-2020-11668

Cleanup debian/changelog file
2020-04-11 21:01:46 +02:00
Salvatore Bonaccorso 3be8cdd484 Update to 4.19.113
Add Debian bug closer for #953017

Cleanup debian/changelog file
2020-04-10 11:38:19 +02:00
Salvatore Bonaccorso 03bc2f300f [rt] Refresh "signals: Allow rt tasks to cache one sigqueue struct" for context changes in 4.19.112 2020-04-09 21:55:44 +02:00
Salvatore Bonaccorso c65add4845 [rt] Refresh "workqueue: Use normal rcu" for context changes in 4.19.112 2020-04-09 21:50:20 +02:00
Salvatore Bonaccorso f3ef27b42b [rt] Update to 4.19.106-rt46 2020-04-09 21:46:12 +02:00
Salvatore Bonaccorso 5a1d3e0c9e Update to 4.19.112
Drop "wimax: i2400: fix memory leak"

Drop "wimax: i2400: Fix memory leak in i2400m_op_rfkill_sw_toggle"

Cleanup debian/changelog file
2020-04-09 21:46:10 +02:00
Salvatore Bonaccorso 1eda59f448 [rt] Refresh "workqueue: Use normal rcu" for context changes in 4.19.111 2020-03-28 17:29:01 +01:00
Salvatore Bonaccorso ac4eeb5f06 Update to 4.19.111
Cleanup debian/changelog file
2020-03-28 17:28:59 +01:00
Salvatore Bonaccorso 1cb724886c [rt] Update to 4.19.106-rt45 2020-03-28 14:01:17 +01:00
Salvatore Bonaccorso a045817180 Update to 4.19.110
Cleanup debian/changelog file
2020-03-25 09:15:48 +01:00
Salvatore Bonaccorso 427b49e4e6 Update to 4.19.109
Add CVE id reference for CVE-2020-8647 and CVE-2020-8649

Add CVE id reference for CVE-2020-8648

Cleanup debian/changelog file
2020-03-25 09:15:48 +01:00
Salvatore Bonaccorso 9eb65f991d Refresh "net: ena: add MAX_QUEUES_EXT get feature admin command" for context changes in 4.19.108 2020-03-25 09:15:48 +01:00
Salvatore Bonaccorso bc6c13f105 Update to 4.19.108
Cleanup debian/changelog file

Add CVE id reference for CVE-2020-10942
2020-03-25 09:15:44 +01:00
Salvatore Bonaccorso 8091970175 Update to 4.19.107
Add CVE id reference for CVE-2020-9383

Add CVE id reference for CVE-2020-2732

Cleanup debian/changelog file

Add CVE id reference for CVE-2020-0009
2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso f815dc7c72 [rt] Update to 4.19.106-rt44 2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso c9a94477f2 Drop "tools/lib/api/fs/fs.c: Fix misuse of strncpy()" 2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso 4eebdc341f Update to 4.19.106
Cleanup debian/changelog file
2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso 7d7d28f268 [rt] Refresh "arm64: fpsimd: use preemp_disable in addition to local_bh_disable()" for context changes in 4.19.105. 2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso c28b09c788 Update to 4.19.105
Cleanup debian/changelog file

Add CVE id reference for CVE-2020-8992
2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso 9e923c8434 [rt] Refresh "powerpc/pseries/iommu: Use a locallock instead local_irq_save()" for context changes in 4.19.104. 2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso 25fdae0539 Update to 4.19.104
Cleanup debian/changelog file
2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso 30aaabe6a8 [rt] Update to 4.19.103-rt42 2020-03-21 09:18:29 +01:00
Salvatore Bonaccorso ada12cc14b Update to 4.19.103
Add CVE id reference for CVE-2019-3016

Cleanup debian/changelog file
2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso ffc4ceb049 Update to 4.19.102
Drop "vfs: fix do_last() regression"

Cleanup debian/changelog file
2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso f003f0dba9 Update to 4.19.101
Cleanup debian/changelog file

Drop "random: try to actively add entropy rather than passively wait for it"
2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso c2975cd055 Update to 4.19.100
Add CVE id reference for CVE-2020-8428

Drop "libertas: Fix two buffer overflows at parsing bss descriptor"

Drop "do_last(): fetch directory ->i_mode and ->i_uid before it's too late"

Cleanup debian/changelog file
2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso 5454dfc211 Refresh "ARM: dts: bcm283x: Correct vchiq compatible string" for context changes in 4.19.99 2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso ae4f977a53 Refresh "Revert "objtool: Fix CONFIG_STACK_VALIDATION=y warning for out-of-tree modules"" for context changes in 4.19.99 2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso 6465b7bcb4 Update to 4.19.99
Add CVE id reference for CVE-2019-19046

Drop "powerpc: vdso: Make vdso32 installation conditional in vdso_install"

Drop "net: ena: fix: Free napi resources when ena_up() fails"

Drop "net: ena: fix incorrect test of supported hash function"

Drop "net: ena: fix ena_com_fill_hash_function() implementation"

Drop "net: ena: fix swapped parameters when calling"

Cleanup debian/changelog file
2020-03-21 09:18:28 +01:00
Salvatore Bonaccorso 483528dfb0 Refresh "efi: Lock down the kernel if booted in secure boot mode" 2020-03-21 09:13:10 +01:00
Ben Hutchings c0f84a03f2 [x86] Drop "Add a SysRq option to lift kernel lockdown" (Closes: #947021)
- This patch allowed remotely disabling lockdown using usbip
- Lockdown can be disabled by running "mokutil --disable-validation",
  rebooting, and confirming the change when prompted
2020-03-21 09:00:35 +01:00
Salvatore Bonaccorso 0283619ccb Adjust bracket for bug closer
Gbp-Dch: Ignore
2020-02-20 11:22:12 +01:00
Ben Hutchings 383accaff8 Merge branch '93sam/linux-add-hibmc' into buster
Include the Hisilicon Hibmc drm driver in fb-modules for buster

See merge request kernel-team/linux!209
2020-02-16 23:45:22 +00:00
Ben Hutchings 14665692cd Merge branch 'syq/linux-buster-fp64' into buster
mips: enable O32_FP64 and MSA

See merge request kernel-team/linux!199
2020-02-16 16:29:58 +00:00
Steve McIntyre b3a8ebd202 Include the Hisilicon Hibmc drm driver in fb-modules
Closes: #951274
2020-02-13 16:24:08 +00:00
Salvatore Bonaccorso 0e1bc339a1 vfs: fix do_last() regression 2020-02-01 21:15:56 +01:00
Salvatore Bonaccorso 3c5fa26ce0 Add ABI reference for 4.19.0-8
Gbp-Dch: Ignore
2020-01-31 06:21:56 +01:00
Salvatore Bonaccorso ff2a1c5362 do_last(): fetch directory ->i_mode and ->i_uid before it's too late (CVE-2020-8428) 2020-01-29 06:57:18 +01:00
Salvatore Bonaccorso 1e4f1969ad Prepare to release linux (4.19.98-1). 2020-01-26 21:01:13 +01:00
Salvatore Bonaccorso b712c4f536 Adjust CVE id in patch header for CVE-2019-19051 patch
Gbp-Dch: Ignore
2020-01-26 20:59:38 +01:00
Salvatore Bonaccorso a51474749d Revert "Prepare to release linux (4.19.98-1)."
This reverts commit 0f0b6cc326.
2020-01-26 20:58:55 +01:00
Salvatore Bonaccorso 0f0b6cc326 Prepare to release linux (4.19.98-1). 2020-01-26 20:54:10 +01:00
Aurelien Jarno fed7048d67 [mips*/malta] Enable POWER_RESET_PIIX4_POWEROFF. 2020-01-25 13:49:01 +01:00
Salvatore Bonaccorso 7b4f2d9864 Update to 4.19.98
Cleanup debian/changelog file
2020-01-24 06:57:36 +01:00
Ben Hutchings b9621ac966 [amd64/cloud-amd64] hwrandom: Enable HW_RANDOM_VIRTIO (Closes: #914511)
Instead of disabling HW_RANDOM, disable all the hwrandom drivers
except this one.

(cherry picked from commit 39bd3e2d43f3286235b0d269d05e7c9959bd8029)
2020-01-21 19:59:39 +00:00
Noah Meyerhans 428bd19863 random: try to actively add entropy rather than passively wait for it
Cherry pick 50ee7529ec45 from mainline.  This addresses a lack of early entropy
in certain environments.

Closes: #948519
2020-01-20 12:44:37 -08:00
Ben Hutchings 56dd5fa07e Add various security fixes not yet in 4.19-stable
All of these are already fixed in jessie, and upgrades shouldn't
regress.
2020-01-20 18:26:58 +00:00
Ben Hutchings af539cd9db Merge branch 'buster' into carnil/linux-carnil/4.19-stable-updates
Resolve the conflict in debian/changelog.
2020-01-19 04:46:49 +00:00
Ben Hutchings 98e9dde708 Bump ABI to 8 2020-01-19 01:11:21 +00:00
Ben Hutchings b65774c8d3 aufs: Update support patchset to aufs4.19.63+ 20200113; no functional changes
This drops some exports, but we intend to bump the ABI number anyway.
2020-01-19 01:03:02 +00:00
Ben Hutchings ef8d371cad [rt] Update to 4.19.94-rt38
Most of this is just resolving the same conflicts Salvatore already
handled locally.

"x86/ioapic: Don't let setaffinity unmask threaded EOI interrupt too
early" was refreshed instead of being dropped.
2020-01-19 00:54:59 +00:00
Ben Hutchings 8a81df4df4 debian/changelog: Note a change in 4.19.90-rt35 2020-01-19 00:44:23 +00:00
Ben Hutchings c0c469a1c6 debian/changelog: Qualify one model-specific quirk as x86-only 2020-01-19 00:34:01 +00:00
Ben Hutchings 1016f4dae9 Merge branch 'buster' into 'buster'
[buster] [cloud-amd64] tpm: Enable TPM drivers for Cloud (Closes: #946237)

See merge request kernel-team/linux!189
2020-01-18 23:59:40 +00:00
Salvatore Bonaccorso f4e9452435 [rt] Refresh 0199-net-move-xmit_recursion-to-per-task-variable-on-RT.patch (Context changes in 4.19.97) 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 69b7fea362 Cleanup debian/changelog file 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso c5a2f98b24 Add CVE id reference for CVE-2019-9445 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 404a161757 Add CVE id reference for CVE-2019-5108 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 8c48c6e453 Add CVE id reference for CVE-2019-20096 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 59d80dc0bc Add CVE id reference for CVE-2019-19927 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 1dc42110a2 Add CVE id reference for CVE-2019-19077 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso a6e91788f5 Add CVE id reference for CVE-2019-19059 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso 665007de06 Add CVE id reference for CVE-2019-19058 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso c8123e56d0 Add CVE id reference for CVE-2019-15217 2020-01-18 00:12:10 +01:00
Salvatore Bonaccorso cfe78f7064 Update to 4.19.97 2020-01-17 22:55:38 +01:00
Salvatore Bonaccorso 477e55f8cd Cleanup debian/changelog file 2020-01-17 15:04:15 +01:00
Salvatore Bonaccorso aa9f65ee62 Add CVE id reference for CVE-2019-19078 2020-01-15 00:03:28 +01:00
Salvatore Bonaccorso 6ea5b99739 Add CVE id reference for CVE-2019-19068 2020-01-15 00:02:59 +01:00
Salvatore Bonaccorso 6ef11c971e Add CVE id reference for CVE-2019-19066 2020-01-15 00:02:31 +01:00
Salvatore Bonaccorso c79d5ca882 Add CVE id reference for CVE-2019-19056 2020-01-15 00:02:03 +01:00
Salvatore Bonaccorso 1f119ff788 Add CVE id reference for CVE-2019-14895 2020-01-15 00:01:27 +01:00
Salvatore Bonaccorso 17a488f946 Add CVE id reference for CVE-2019-14615 2020-01-15 00:00:37 +01:00
Salvatore Bonaccorso 8fec41528b Update to 4.19.96 2020-01-14 23:59:05 +01:00
Salvatore Bonaccorso 217a44f064 Cleanup debian/changelog file 2020-01-14 23:58:22 +01:00
Salvatore Bonaccorso 1f1923e171 Add CVE id reference for CVE-2019-14901 2020-01-14 23:25:37 +01:00
Salvatore Bonaccorso e5cc95a17c Update to 4.19.95 2020-01-14 23:23:37 +01:00
Salvatore Bonaccorso febedce575 Cleanup debian/changelog file 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso b8f39ed155 Add CVE id reference for CVE-2019-19965 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso a5bf767a34 Add CVE id reference for CVE-2019-18809 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 4a8ae7c9d5 Update to 4.19.94 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 5510778373 Drop changelog entries for "powerpc/vcpu: Assume dedicated processors as non-preempt"
Gbp-Dch: Ignore
2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 8c12894795 Cleanup debian/changelog file 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso f96fb9cfd5 [rt] Refresh 0253-watchdog-prevent-deferral-of-watchdogd-wakeup-on-RT.patch (Context changes in 4.19.93) 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso be9871ff2f Refresh 0013-scsi-hisi_sas-Relocate-some-codes-to-avoid-an-unused.patch for context changes in 4.19.93. 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 6ea3bab2b2 Add CVE id reference for CVE-2019-10220 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso df1b718c9a Update to 4.19.93 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 5b421326ca [rt] Drop 0245-Revert-arm64-preempt-Fix-big-endian-when-checking-pr.patch 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 414985d41e [rt] Drop 0013-x86-ioapic-Don-t-let-setaffinity-unmask-threaded-EOI.patch
One part of the patch correspond to df4393424af3 ("x86/ioapic: Prevent
inconsistent state when moving an interrupt") in 5.5-rc1 and which got
backported to 4.19.92.

The other is corresponding to 2579a4eefc04 ("x86/ioapic: Rename misnamed
functions") in 5.5-rc1.
2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 88a4ba5bd0 [rt] Update to 4.19.90-rt35 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 60f99617aa Cleanup debian/changelog file 2020-01-14 21:01:16 +01:00
Salvatore Bonaccorso 903ee592c4 Add CVE id reference for CVE-2019-19947 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso ab30739ce0 Add CVE id reference for CVE-2019-19063 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso 476e9daab6 Add CVE id reference for CVE-2019-19057 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso 8c66e4c662 Add CVE id reference for CVE-2019-19037 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso d862bf8e49 Add CVE id reference for CVE-2019-18786 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso 3ecef40306 Update to 4.19.92 2020-01-14 21:01:15 +01:00
Salvatore Bonaccorso 5cd34a2914 Add CVE id reference for CVE-2019-19447 2020-01-14 21:01:15 +01:00
Ben Hutchings 02a0b3eb56 Update to 4.19.91
* Drop/refresh patches as appropriate
* Several ABI changes still need to be resolved
2019-12-28 01:36:27 +00:00
Ben Hutchings a13b44e33a debian/changelog: Clean up changes in 4.19.88 some more 2019-12-27 23:24:36 +00:00
YunQiang Su 947fbc6618 mips: enable O32_FP64 and MSA
CONFIG_MIPS_O32_FP64_SUPPORT is required to support MSA for O32.
It requires CPU >= mips32r1. It is OK for us: currently our
baseline is mips32r2/mips64r2.

Malta can use different CPUs, some of them may support MSA.
Loongson 3A/B 4000 will support MSA.
The only CPU currently we support has no MSA is octeon.

Commit-ID in master: b1d08a0cffbe181cbb94e3fc72a91c2e8a8a38e7
2019-12-27 17:34:42 +08:00
Salvatore Bonaccorso 79505b154a Cleanup debian/changelog file 2019-12-17 17:21:27 +01:00
Salvatore Bonaccorso 5d3c55e949 Add CVE id reference for CVE-2019-12614 2019-12-17 17:16:43 +01:00
Salvatore Bonaccorso b4817400ed Add CVE id reference for CVE-2019-19767 2019-12-17 17:15:13 +01:00
Salvatore Bonaccorso 96a8136906 [rt] Refresh 0199-net-move-xmit_recursion-to-per-task-variable-on-RT.patch (Context changes in 4.19.88) 2019-12-17 16:56:40 +01:00
Salvatore Bonaccorso 60468edbdf Drop 0028-RDMA-hns-Bugfix-for-the-scene-without-receiver-queue.patch 2019-12-17 16:56:40 +01:00
Salvatore Bonaccorso 9d10b57769 Drop 0027-RDMA-hns-Fix-the-bug-with-updating-rq-head-pointer-w.patch 2019-12-17 16:56:40 +01:00
Salvatore Bonaccorso b9568ec214 Refresh powerpc-fix-mcpu-options-for-spe-only-compiler.patch (Context changes in 4.19.88) 2019-12-17 16:56:40 +01:00
Salvatore Bonaccorso f73fafb39e Revert "arm64: preempt: Fix big-endian when checking preempt count in assembly" 2019-12-17 16:56:40 +01:00
Salvatore Bonaccorso 278eae7330 Update to 4.19.88 2019-12-14 22:00:25 +01:00
Salvatore Bonaccorso ff103bb4ad Add ABI reference for 4.19.0-7
Gbp-Dch: Ignore
2019-12-09 07:30:03 +01:00
Joe Richey 873d71775d [buster] [cloud-amd64] tpm: Enable TPM drivers for Cloud (Closes: #946237)
The bug has most of the context for this fix. Basically, the cloud image
disables TPM drives, and we want to reenable them.

I added the virt and hardware-agnostic drivers (TIS/CRB/XEN/VTPM), and
I explictly didn't add the hardware-specific drivers. I also didn't
bother with CONFIG_HW_RANDOM_TPM as we already set
CONFIG_RANDOM_TRUST_CPU=y which handles any early-boot RNG issues.

Signed-off-by: Joe Richey <joerichey@google.com>
2019-12-06 00:39:32 -08:00
Salvatore Bonaccorso 80865194b5 Prepare to release linux (4.19.87-1). 2019-12-03 06:58:41 +01:00
Salvatore Bonaccorso f9c7775f72 Add CVE id reference for CVE-2019-18683 2019-12-01 17:23:58 +01:00
Salvatore Bonaccorso 34cf1b0258 Add CVE id reference for CVE-2019-18660 2019-12-01 17:23:29 +01:00
Aurelien Jarno 1a33bc2ef8 Update to 4.19.87
Drop "net: ena: Fix Kconfig dependency on X86" applied upstream

Drop "scsi: hisi_sas: Feed back linkrate(max/min) when re-attached" applied upstream

Drop "scsi: hisi_sas: Fix the race between IO completion and timeout for SMP/internal IO" applied upstream

Drop "scsi: hisi_sas: Free slot later in slot_complete_vx_hw()" applied upstream

Drop "scsi: hisi_sas: Fix NULL pointer dereference" applied upstream

[rt] Refresh 0057-printk-Add-a-printk-kill-switch.patch (context changes in 4.19.87)

[rt] Refresh 0207-printk-Make-rt-aware.patch (context changes in 4.19.87)

Cleanup debian/changelog file
2019-12-01 17:19:47 +01:00
Aurelien Jarno c5c04abfa4 Update to 4.19.86
[rt] Refresh 0025-NFSv4-replace-seqcount_t-with-a-seqlock_t.patch (context changes in 4.19.86)

[rt] Refresh 0202-net-Qdisc-use-a-seqlock-instead-seqcount.patch (context changes in 4.19.86)

Cleanup debian/changelog file
2019-12-01 15:02:01 +01:00
Aurelien Jarno f78694b110 debian/changelog: wrap long 4.85 changelog entries 2019-12-01 13:43:12 +01:00
Aurelien Jarno 5ba5b367b7 Update to 4.19.85
Drop introduce is_pae_paging applied upstream

Cleanup debian/changelog file
2019-12-01 13:29:09 +01:00
Salvatore Bonaccorso b62aac68b4 [rt] Refresh 0011-sched-fair-Robustify-CFS-bandwidth-timer-locking.patch (context changes in 4.19.84) 2019-12-01 10:55:02 +01:00
Salvatore Bonaccorso ea17f6edde Update to 4.19.84
Drop TAA patches applied upstream

Drop ITLB_MULTIHIT patches applied upstream

Drop Intel i915 CVE fixes applied upstream

Add CVE id reference for CVE-2019-18813

Add CVE id reference for CVE-2019-19045

Add CVE id reference for CVE-2019-19052

Cleanup debian/changelog file
2019-12-01 10:54:59 +01:00
Salvatore Bonaccorso b69b28370c Update to 4.19.83
Add CVE id reference for CVE-2019-19049

Cleanup debian/changelog file
2019-11-30 17:30:31 +01:00
Salvatore Bonaccorso 1867067696 Update to 4.19.82
Add CVE id reference for CVE-2019-15098

Add CVE id reference for CVE-2019-17666

Add CVE id reference for CVE-2019-19048

Add CVE id reference for CVE-2019-19060

Add CVE id reference for CVE-2019-19065

Cleanup debian/changelog file
2019-11-30 14:42:27 +01:00
Salvatore Bonaccorso a84ef0f6e4 [x86] KVM: x86: introduce is_pae_paging (Regression in 4.19.77)
Fixes a regression in 4.19.81 while including backport of 16cfacc80857
("KVM: x86: Manually calculate reserved bits when loading PDPTRS") but
not  bf03d4f93347 ("KVM: x86: introduce is_pae_paging").
2019-11-25 17:52:40 +01:00
Ben Hutchings 098172cdc1 debian/changelog: Clean up list of changes from stable
* Delete changes that are irrelevant, were previously cherry-picked by
  us, or that cancel each other out
* Add architecture/flavour/featureset-qualifications
* Add CVE IDs
* Word-wrap
2019-11-25 03:26:11 +00:00
Ben Hutchings 8c4ce65f70 Drop "MIPS: tlbex: Fix build_restore_pagemask KScratch restore"
This was included in 4.19.81.
2019-11-25 01:09:29 +00:00
Ben Hutchings beb8c412e8 Merge branch 'buster-4.19.81' into 'buster'
Buster 4.19.81

See merge request kernel-team/linux!183
2019-11-25 01:06:06 +00:00
Ben Hutchings baa617cd99 [rt] Update to 4.19.82-rt30 2019-11-25 00:15:05 +00:00
Ben Hutchings 0965371222 debian/bin/genpatch-rt: Fix series generation from git 2019-11-24 23:58:14 +00:00
Noah Meyerhans 43eae8169a Remove obsolete patch
debian/abi/powerpc-avoid-abi-change-for-disabling-tm.patch let us postpone an
ABI bump. But with the 4.19.81 upstream release, we can no longer avoid it.
2019-11-24 23:50:30 +00:00
Noah Meyerhans 6f6f98f0d9 Bump ABI to 7 2019-11-24 23:50:30 +00:00
Ben Hutchings fc769a9bb3 Merge branch 'bpoirier-guest/linux-buster' into buster
tools/perf: Add python3 support to scripts

See merge request kernel-team/linux!184
2019-11-24 19:25:28 +00:00
Ben Hutchings 1b0a012af5 debian/patches: Fix broken Subject fields in the perf script patches
The Origin and Bug-Debian fields were inserted in the middle of the
word-wrapped Subject fields in a few patches.
2019-11-24 19:17:51 +00:00
Aurelien Jarno 9397b7ea0e [mips*] tlbex: Fix build_restore_pagemask KScratch restore. 2019-11-23 22:23:57 +01:00
Noah Meyerhans 8c9e9430c2 Refresh remaining patches 2019-11-20 16:24:37 -08:00
Noah Meyerhans 62e5e3199d Remove obsolete patches 2019-11-20 16:24:37 -08:00
Benjamin Poirier 016066336b tools/perf: Add python3 support to scripts 2019-11-20 15:04:24 +09:00
Noah Meyerhans c064eca42f New upstream version 4.19.81 2019-11-19 16:03:48 -08:00
Salvatore Bonaccorso 3e9a6acd20 ipv4: Return -ENETUNREACH if we can't create route but saddr is valid
Closes: #945023
2019-11-19 08:00:10 +01:00
Salvatore Bonaccorso 014f165375 Release linux (4.19.67-2+deb10u2).
-----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEErCspvTSmr92z9o8157/I7JWGEQkFAl3JkpgACgkQ57/I7JWG
 EQkwVhAAwN5/oNLjJcrhJjGvLW36QIcli05GoNH1hqLNlppwFwzxFYms5f4Y0uAn
 lu5wWo59jL2xqnZ0azNg7ukujVUyLuVEsBuShCBmkSWtt+3mXjKJay1lnwtEei1R
 w2WnXIsAFdSocpnCq7BfQi0sGgUetPJANkkXe019x8H7DmzugisnArp4hX7e7eU5
 JaRuugKTquYjPNN1mQaNS3/C6ODWRBZlTjafznZ3lTme9ku195oUAJWvyU6/AMDB
 +QB9lnaWVNsWkKt3Hx0yquY6sFHYhDhxxKXdULWDwjTW4r1Ye5DKJT433gbKjhTZ
 sILbbXMs2eEv9KM+NvMB96s32z+dc59q1KM3IeAKqQljsqngquqvBQtFRqJYtUCA
 k4HY0wO/2EapWnYnO0z7XekjolZlK7Nj6aldysZ8f6V1q13apPraYKscQyMLTAfy
 CXaUP3bsaxKZvEtlz4+x9OHIqKVrIzI8mLujcpgildz8E3bToXZCgK+CzIAFCdy+
 vY1wUoP5S/DCdgvAIzyT9g2VoFae3DNRNv2DSC53FMHaD1PRwE2wf4XgXSAc4hC+
 s3orsvA8PpHj7BpAa3D3JnrZbP/kAn+rFCqUha/6cs5npOUwpSs1SNdil60K130q
 dS9KcnWY2Do7fp6xc0T4WCRcR6osDJp3WzTmuHpHivfuP26VwXY=
 =aKic
 -----END PGP SIGNATURE-----

Merge tag 'debian/4.19.67-2+deb10u2' into buster

Release linux (4.19.67-2+deb10u2).
2019-11-19 07:42:38 +01:00
Ben Hutchings c3649501d0 Prepare to release linux (4.19.67-2+deb10u2). 2019-11-11 00:30:56 +00:00
Ben Hutchings 9a2df80e9d Drop "x86/cpu: Add Tremont to the cpu vulnerability whitelist"
We don't have this CPU ID, and I don't see the point in adding it
right now.
2019-11-11 00:29:38 +00:00
Ben Hutchings 6d8b0092bb [x86] drm/i915/cmdparser: Fix jump whitelist clearing
Fix a flaw I found in the mitigation for CVE-2019-0155.
2019-11-10 22:41:41 +00:00
Ben Hutchings feec1caa94 [x86] i915: Add mitigations for two hardware security flaws 2019-11-10 02:53:32 +00:00
Ben Hutchings c2443a2e97 [x86] Update TAA and NX fixes to pending stable backports 2019-11-09 20:17:15 +00:00
Salvatore Bonaccorso be004c1b69 x86/speculation/taa: Fix printing of TAA_MSG_SMT on IBRS_ALL CPUs 2019-11-08 00:14:38 +01:00