linux-azure 4.13.0-1006.8 source package in Ubuntu
Changelog
linux-azure (4.13.0-1006.8) xenial; urgency=low * linux-azure: 4.13.0-1006.8 -proposed tracker (LP: #1742723) [ Ubuntu: 4.13.0-29.32 ] * linux: 4.13.0-29.32 -proposed tracker (LP: #1742722) * CVE-2017-5754 - Revert "x86/cpu: Implement CPU vulnerabilites sysfs functions" - Revert "sysfs/cpu: Fix typos in vulnerability documentation" - Revert "sysfs/cpu: Add vulnerability folder" - Revert "UBUNTU: [Config] updateconfigs to enable GENERIC_CPU_VULNERABILITIES" [ Ubuntu: 4.13.0-28.31 ] * CVE-2017-5753 - SAUCE: x86/kvm: Fix stuff_RSB() for 32-bit * CVE-2017-5715 - SAUCE: x86/kvm: Fix stuff_RSB() for 32-bit [ Ubuntu: 4.13.0-27.30 ] * CVE-2017-5753 - locking/barriers: introduce new memory barrier gmb() - bpf: prevent speculative execution in eBPF interpreter - x86, bpf, jit: prevent speculative execution when JIT is enabled - uvcvideo: prevent speculative execution - carl9170: prevent speculative execution - p54: prevent speculative execution - qla2xxx: prevent speculative execution - cw1200: prevent speculative execution - Thermal/int340x: prevent speculative execution - userns: prevent speculative execution - ipv6: prevent speculative execution - fs: prevent speculative execution - net: mpls: prevent speculative execution - udf: prevent speculative execution - x86/feature: Enable the x86 feature to control Speculation - x86/feature: Report presence of IBPB and IBRS control - x86/enter: MACROS to set/clear IBRS and set IBPB - x86/enter: Use IBRS on syscall and interrupts - x86/idle: Disable IBRS entering idle and enable it on wakeup - x86/idle: Disable IBRS when offlining cpu and re-enable on wakeup - x86/mm: Set IBPB upon context switch - x86/mm: Only set IBPB when the new thread cannot ptrace current thread - x86/entry: Stuff RSB for entry to kernel for non-SMEP platform - x86/kvm: add MSR_IA32_SPEC_CTRL and MSR_IA32_PRED_CMD to kvm - x86/kvm: Set IBPB when switching VM - x86/kvm: Toggle IBRS on VM entry and exit - x86/kvm: Pad RSB on VM transition - x86/spec_ctrl: Add sysctl knobs to enable/disable SPEC_CTRL feature - x86/spec_ctrl: Add lock to serialize changes to ibrs and ibpb control - x86/syscall: Clear unused extra registers on syscall entrance - x86/syscall: Clear unused extra registers on 32-bit compatible syscall entrance - x86/entry: Use retpoline for syscall's indirect calls - x86/cpu/AMD: Add speculative control support for AMD - x86/microcode: Extend post microcode reload to support IBPB feature - KVM: SVM: Do not intercept new speculative control MSRs - x86/svm: Set IBRS value on VM entry and exit - x86/svm: Set IBPB when running a different VCPU - KVM: x86: Add speculative control CPUID support for guests - x86/svm: Add code to clobber the RSB on VM exit - x86/svm: Add code to clear registers on VM exit - x86/cpu/AMD: Remove now unused definition of MFENCE_RDTSC feature - powerpc: add gmb barrier - s390/spinlock: add gmb memory barrier - x86/microcode/AMD: Add support for fam17h microcode loading * CVE-2017-5715 - locking/barriers: introduce new memory barrier gmb() - bpf: prevent speculative execution in eBPF interpreter - x86, bpf, jit: prevent speculative execution when JIT is enabled - uvcvideo: prevent speculative execution - carl9170: prevent speculative execution - p54: prevent speculative execution - qla2xxx: prevent speculative execution - cw1200: prevent speculative execution - Thermal/int340x: prevent speculative execution - userns: prevent speculative execution - ipv6: prevent speculative execution - fs: prevent speculative execution - net: mpls: prevent speculative execution - udf: prevent speculative execution - x86/feature: Enable the x86 feature to control Speculation - x86/feature: Report presence of IBPB and IBRS control - x86/enter: MACROS to set/clear IBRS and set IBPB - x86/enter: Use IBRS on syscall and interrupts - x86/idle: Disable IBRS entering idle and enable it on wakeup - x86/idle: Disable IBRS when offlining cpu and re-enable on wakeup - x86/mm: Set IBPB upon context switch - x86/mm: Only set IBPB when the new thread cannot ptrace current thread - x86/entry: Stuff RSB for entry to kernel for non-SMEP platform - x86/kvm: add MSR_IA32_SPEC_CTRL and MSR_IA32_PRED_CMD to kvm - x86/kvm: Set IBPB when switching VM - x86/kvm: Toggle IBRS on VM entry and exit - x86/kvm: Pad RSB on VM transition - x86/spec_ctrl: Add sysctl knobs to enable/disable SPEC_CTRL feature - x86/spec_ctrl: Add lock to serialize changes to ibrs and ibpb control - x86/syscall: Clear unused extra registers on syscall entrance - x86/syscall: Clear unused extra registers on 32-bit compatible syscall entrance - x86/entry: Use retpoline for syscall's indirect calls - x86/cpu/AMD: Add speculative control support for AMD - x86/microcode: Extend post microcode reload to support IBPB feature - KVM: SVM: Do not intercept new speculative control MSRs - x86/svm: Set IBRS value on VM entry and exit - x86/svm: Set IBPB when running a different VCPU - KVM: x86: Add speculative control CPUID support for guests - x86/svm: Add code to clobber the RSB on VM exit - x86/svm: Add code to clear registers on VM exit - x86/cpu/AMD: Remove now unused definition of MFENCE_RDTSC feature - powerpc: add gmb barrier - s390/spinlock: add gmb memory barrier - x86/microcode/AMD: Add support for fam17h microcode loading * CVE-2017-5754 - x86/pti: Enable PTI by default - x86/pti: Make sure the user/kernel PTEs match - x86/dumpstack: Fix partial register dumps - x86/dumpstack: Print registers for first stack frame - x86/process: Define cpu_tss_rw in same section as declaration - x86/mm: Set MODULES_END to 0xffffffffff000000 - x86/mm: Map cpu_entry_area at the same place on 4/5 level - x86/kaslr: Fix the vaddr_end mess - x86/events/intel/ds: Use the proper cache flush method for mapping ds buffers - x86/tlb: Drop the _GPL from the cpu_tlbstate export - x86/alternatives: Add missing '\n' at end of ALTERNATIVE inline asm - x86/pti: Rename BUG_CPU_INSECURE to BUG_CPU_MELTDOWN - x86/pti: Unbreak EFI old_memmap - x86/Documentation: Add PTI description - x86/cpufeatures: Add X86_BUG_SPECTRE_V[12] - sysfs/cpu: Add vulnerability folder - x86/cpu: Implement CPU vulnerabilites sysfs functions - x86/tboot: Unbreak tboot with PTI enabled - x86/mm/pti: Remove dead logic in pti_user_pagetable_walk*() - x86/cpu/AMD: Make LFENCE a serializing instruction - x86/cpu/AMD: Use LFENCE_RDTSC in preference to MFENCE_RDTSC - sysfs/cpu: Fix typos in vulnerability documentation - x86/alternatives: Fix optimize_nops() checking - x86/pti: Make unpoison of pgd for trusted boot work for real - s390: introduce CPU alternatives - s390: add ppa to kernel entry / exit - SAUCE: powerpc: Secure memory rfi flush - SAUCE: rfi-flush: Make DEBUG_RFI a CONFIG option - SAUCE: rfi-flush: Add HRFI_TO_UNKNOWN and use it in denorm - SAUCE: rfi-flush: kvmppc_skip_(H)interrupt returns to host kernel - SAUCE: KVM: Revert the implementation of H_GET_CPU_CHARACTERISTICS - SAUCE: rfi-flush: Implement congruence-first fallback flush - SAUCE: rfi-flush: Make l1d_flush_type bit flags - SAUCE: rfi-flush: Push the instruction selection down to the patching routine - SAUCE: rfi-flush: Expand the RFI section to two nop slots - SAUCE: rfi-flush: Support more than one flush type at once - SAUCE: rfi-flush: Allow HV to advertise multiple flush types - SAUCE: rfi-flush: Add speculation barrier before ori 30,30,0 flush - SAUCE: rfi-flush: Add barriers to the fallback L1D flushing - SAUCE: rfi-flush: Rework powernv logic to be more cautious - SAUCE: rfi-flush: Rework pseries logic to be more cautious - SAUCE: rfi-flush: Put the fallback flushes in the real trampoline section - SAUCE: rfi-flush: Fix the fallback flush to actually activate - SAUCE: rfi-flush: Fix HRFI_TO_UNKNOWN - SAUCE: rfi-flush: Refactor the macros so the nops are defined once - SAUCE: rfi-flush: Add no_rfi_flush and nopti comandline options - SAUCE: rfi-flush: Use rfi-flush in printks - SAUCE: rfi-flush: Fallback flush add load dependency - SAUCE: rfi-flush: Fix the 32-bit KVM build - SAUCE: rfi-flush: Fix some RFI conversions in the KVM code - SAUCE: rfi-flush: Make the fallback robust against memory corruption - [Config] Disable CONFIG_PPC_DEBUG_RFI - [Config] updateconfigs to enable GENERIC_CPU_VULNERABILITIES * powerpc: flush L1D on return to use (LP: #1742772) - SAUCE: powerpc: Secure memory rfi flush - SAUCE: rfi-flush: Make DEBUG_RFI a CONFIG option - SAUCE: rfi-flush: Add HRFI_TO_UNKNOWN and use it in denorm - SAUCE: rfi-flush: kvmppc_skip_(H)interrupt returns to host kernel - SAUCE: KVM: Revert the implementation of H_GET_CPU_CHARACTERISTICS - SAUCE: rfi-flush: Implement congruence-first fallback flush - SAUCE: rfi-flush: Make l1d_flush_type bit flags - SAUCE: rfi-flush: Push the instruction selection down to the patching routine - SAUCE: rfi-flush: Expand the RFI section to two nop slots - SAUCE: rfi-flush: Support more than one flush type at once - SAUCE: rfi-flush: Allow HV to advertise multiple flush types - SAUCE: rfi-flush: Add speculation barrier before ori 30,30,0 flush - SAUCE: rfi-flush: Add barriers to the fallback L1D flushing - SAUCE: rfi-flush: Rework powernv logic to be more cautious - SAUCE: rfi-flush: Rework pseries logic to be more cautious - SAUCE: rfi-flush: Put the fallback flushes in the real trampoline section - SAUCE: rfi-flush: Fix the fallback flush to actually activate - SAUCE: rfi-flush: Fix HRFI_TO_UNKNOWN - SAUCE: rfi-flush: Refactor the macros so the nops are defined once - SAUCE: rfi-flush: Add no_rfi_flush and nopti comandline options - SAUCE: rfi-flush: Use rfi-flush in printks - SAUCE: rfi-flush: Fallback flush add load dependency - SAUCE: rfi-flush: Fix the 32-bit KVM build - SAUCE: rfi-flush: Fix some RFI conversions in the KVM code - SAUCE: rfi-flush: Make the fallback robust against memory corruption - [Config] Disable CONFIG_PPC_DEBUG_RFI * s390: add ppa to kernel entry/exit (LP: #1742771) - s390: introduce CPU alternatives - s390: add ppa to kernel entry / exit -- Marcelo Henrique Cerri <email address hidden> Fri, 12 Jan 2018 10:09:43 -0200
Upload details
- Uploaded by:
- Marcelo Cerri
- Uploaded to:
- Xenial
- Original maintainer:
- Ubuntu Kernel Team
- Architectures:
- all amd64
- Section:
- devel
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
linux-azure_4.13.0.orig.tar.gz | 148.3 MiB | 9511260e17e474183b9c3b2ea601d5af256dde783e14dba4031854eaa98d5089 |
linux-azure_4.13.0-1006.8.diff.gz | 7.5 MiB | 517eace224dcaf136a5d34d9e5125a5c9608ed955a4580a00bf42f97c6b452bd |
linux-azure_4.13.0-1006.8.dsc | 3.4 KiB | c2c50bf086237419dd4c10db9f92da69d339bbd8b5e57e5f1ee2c5aa073767e3 |
Available diffs
- diff from 4.13.0-1005.7 to 4.13.0-1006.8 (3.1 MiB)
Binary packages built by this source
- linux-azure-cloud-tools-4.13.0-1006: Linux kernel version specific cloud tools for version 4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools for cloud tools for version 4.13.0-1006 on
64 bit x86.
You probably want to install linux-cloud-tools-4. 13.0-1006- <flavour> .
- linux-azure-cloud-tools-4.13.0-1006-dbgsym: debug symbols for package linux-azure-cloud-tools-4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools for cloud tools for version 4.13.0-1006 on
64 bit x86.
You probably want to install linux-cloud-tools-4. 13.0-1006- <flavour> .
- linux-azure-headers-4.13.0-1006: Header files related to Linux kernel version 4.13.0
This package provides kernel header files for version 4.13.0, for sites
that want the latest kernel headers. Please read
/usr/share/doc/linux- azure-headers- 4.13.0- 1006/debian. README. gz for details
- linux-azure-tools-4.13.0-1006: Linux kernel version specific tools for version 4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools (such as perf and x86_energy_perf_policy) for
version 4.13.0-1006 on
64 bit x86.
You probably want to install linux-tools-4.13.0- 1006-<flavour> .
- linux-azure-tools-4.13.0-1006-dbgsym: debug symbols for package linux-azure-tools-4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools (such as perf and x86_energy_perf_policy) for
version 4.13.0-1006 on
64 bit x86.
You probably want to install linux-tools-4.13.0- 1006-<flavour> .
- linux-cloud-tools-4.13.0-1006-azure: Linux kernel version specific cloud tools for version 4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools for cloud for version 4.13.0-1006 on
64 bit x86.
- linux-headers-4.13.0-1006-azure: Linux kernel headers for version 4.13.0 on 64 bit x86 SMP
This package provides kernel header files for version 4.13.0 on
64 bit x86 SMP.
.
This is for sites that want the latest kernel headers. Please read
/usr/share/doc/linux- headers- 4.13.0- 1006/debian. README. gz for details.
- linux-image-4.13.0-1006-azure: Linux kernel image for version 4.13.0 on 64 bit x86 SMP
This package contains the Linux kernel image for version 4.13.0 on
64 bit x86 SMP.
.
Also includes the corresponding System.map file, the modules built by the
packager, and scripts that try to ensure that the system is not left in an
unbootable state after an update.
.
Supports Azure processors.
.
Geared toward Azure systems.
.
You likely do not want to install this package directly. Instead, install
the linux-azure meta-package, which will ensure that upgrades work
correctly, and that supporting packages are also installed.
- linux-image-4.13.0-1006-azure-dbgsym: Linux kernel debug image for version 4.13.0 on 64 bit x86 SMP
This package provides a kernel debug image for version 4.13.0 on
64 bit x86 SMP.
.
This is for sites that wish to debug the kernel.
.
The kernel image contained in this package is NOT meant to boot from. It
is uncompressed, and unstripped. This package also includes the
unstripped modules.
- linux-image-extra-4.13.0-1006-azure: Linux kernel extra modules for version 4.13.0 on 64 bit x86 SMP
This package contains the Linux kernel extra modules for version 4.13.0 on
64 bit x86 SMP.
.
Also includes the corresponding System.map file, the modules built by the
packager, and scripts that try to ensure that the system is not left in an
unbootable state after an update.
.
Supports Azure processors.
.
Geared toward Azure systems.
.
You likely do not want to install this package directly. Instead, install
the linux-azure meta-package, which will ensure that upgrades work
correctly, and that supporting packages are also installed.
- linux-tools-4.13.0-1006-azure: Linux kernel version specific tools for version 4.13.0-1006
This package provides the architecture dependant parts for kernel
version locked tools (such as perf and x86_energy_perf_policy) for
version 4.13.0-1006 on
64 bit x86.