Format: 1.8 Date: Fri, 12 Jan 2018 14:39:25 -0800 Source: linux-aws Binary: linux-aws-headers-4.4.0-1049 linux-aws-tools-4.4.0-1049 linux-aws-cloud-tools-4.4.0-1049 linux-image-4.4.0-1049-aws linux-headers-4.4.0-1049-aws linux-image-4.4.0-1049-aws-dbgsym linux-tools-4.4.0-1049-aws linux-cloud-tools-4.4.0-1049-aws linux-udebs-aws Architecture: amd64 all amd64_translations Version: 4.4.0-1049.58 Distribution: xenial Urgency: low Maintainer: Launchpad Build Daemon Changed-By: Kamal Mostafa Description: linux-aws-cloud-tools-4.4.0-1049 - Linux kernel version specific cloud tools for version 4.4.0-1049 linux-aws-headers-4.4.0-1049 - Header files related to Linux kernel version 4.4.0 linux-aws-tools-4.4.0-1049 - Linux kernel version specific tools for version 4.4.0-1049 linux-cloud-tools-4.4.0-1049-aws - Linux kernel version specific cloud tools for version 4.4.0-1049 linux-headers-4.4.0-1049-aws - Linux kernel headers for version 4.4.0 on 64 bit x86 SMP linux-image-4.4.0-1049-aws - Linux kernel image for version 4.4.0 on 64 bit x86 SMP linux-image-4.4.0-1049-aws-dbgsym - Linux kernel debug image for version 4.4.0 on 64 bit x86 SMP linux-tools-4.4.0-1049-aws - Linux kernel version specific tools for version 4.4.0-1049 linux-udebs-aws - Metapackage depending on kernel udebs (udeb) Launchpad-Bugs-Fixed: 1742771 1742772 1742995 1743001 Changes: linux-aws (4.4.0-1049.58) xenial; urgency=low . * linux-aws: 4.4.0-1049.58 -proposed tracker (LP: #1743001) . [ Ubuntu: 4.4.0-110.133 ] . * linux: 4.4.0-110.133 -proposed tracker (LP: #1742995) * CVE-2017-5753 - x86/microcode/AMD: Add support for fam17h microcode loading - bpf: add bpf_patch_insn_single helper - bpf: prepare bpf_int_jit_compile/bpf_prog_select_runtime apis - bpf: add generic constant blinding for use in jits - locking/barriers: introduce new memory barrier gmb() - bpf: prevent speculative execution in eBPF interpreter - x86, bpf, jit: prevent speculative execution when JIT is enabled - uvcvideo: prevent speculative execution - carl9170: prevent speculative execution - qla2xxx: prevent speculative execution - Thermal/int340x: prevent speculative execution - userns: prevent speculative execution - ipv6: prevent speculative execution - fs: prevent speculative execution - net: mpls: prevent speculative execution - udf: prevent speculative execution - x86/feature: Enable the x86 feature to control Speculation - x86/feature: Report presence of IBPB and IBRS control - x86/enter: MACROS to set/clear IBRS and set IBPB - x86/enter: Use IBRS on syscall and interrupts - x86/idle: Disable IBRS entering idle and enable it on wakeup - x86/idle: Disable IBRS when offlining cpu and re-enable on wakeup - x86/mm: Set IBPB upon context switch - x86/mm: Only set IBPB when the new thread cannot ptrace current thread - x86/entry: Stuff RSB for entry to kernel for non-SMEP platform - x86/kvm: add MSR_IA32_SPEC_CTRL and MSR_IA32_PRED_CMD to kvm - x86/kvm: Set IBPB when switching VM - x86/kvm: Toggle IBRS on VM entry and exit - x86/kvm: Pad RSB on VM transition - x86/spec_ctrl: Add sysctl knobs to enable/disable SPEC_CTRL feature - x86/spec_ctrl: Add lock to serialize changes to ibrs and ibpb control - x86/syscall: Clear unused extra registers on syscall entrance - x86/syscall: Clear unused extra registers on 32-bit compatible syscall entrance - x86/entry: Use retpoline for syscall's indirect calls - x86/cpu/amd, kvm: Satisfy guest kernel reads of IC_CFG MSR - x86/cpu/AMD: Add speculative control support for AMD - x86/microcode: Extend post microcode reload to support IBPB feature - KVM: SVM: Do not intercept new speculative control MSRs - x86/svm: Set IBRS value on VM entry and exit - x86/svm: Set IBPB when running a different VCPU - KVM: x86: Add speculative control CPUID support for guests - x86/svm: Add code to clobber the RSB on VM exit - x86/svm: Add code to clear registers on VM exit - x86/cpu/AMD: Make the LFENCE instruction serialized - x86/cpu/AMD: Remove now unused definition of MFENCE_RDTSC feature - powerpc: add gmb barrier - s390/spinlock: add gmb memory barrier - SAUCE: x86/kvm: Fix stuff_RSB() for 32-bit - arm64: no gmb() implementation yet - arm: no gmb() implementation yet * CVE-2017-5715 - x86/microcode/AMD: Add support for fam17h microcode loading - bpf: add bpf_patch_insn_single helper - bpf: prepare bpf_int_jit_compile/bpf_prog_select_runtime apis - bpf: add generic constant blinding for use in jits - locking/barriers: introduce new memory barrier gmb() - bpf: prevent speculative execution in eBPF interpreter - x86, bpf, jit: prevent speculative execution when JIT is enabled - uvcvideo: prevent speculative execution - carl9170: prevent speculative execution - qla2xxx: prevent speculative execution - Thermal/int340x: prevent speculative execution - userns: prevent speculative execution - ipv6: prevent speculative execution - fs: prevent speculative execution - net: mpls: prevent speculative execution - udf: prevent speculative execution - x86/feature: Enable the x86 feature to control Speculation - x86/feature: Report presence of IBPB and IBRS control - x86/enter: MACROS to set/clear IBRS and set IBPB - x86/enter: Use IBRS on syscall and interrupts - x86/idle: Disable IBRS entering idle and enable it on wakeup - x86/idle: Disable IBRS when offlining cpu and re-enable on wakeup - x86/mm: Set IBPB upon context switch - x86/mm: Only set IBPB when the new thread cannot ptrace current thread - x86/entry: Stuff RSB for entry to kernel for non-SMEP platform - x86/kvm: add MSR_IA32_SPEC_CTRL and MSR_IA32_PRED_CMD to kvm - x86/kvm: Set IBPB when switching VM - x86/kvm: Toggle IBRS on VM entry and exit - x86/kvm: Pad RSB on VM transition - x86/spec_ctrl: Add sysctl knobs to enable/disable SPEC_CTRL feature - x86/spec_ctrl: Add lock to serialize changes to ibrs and ibpb control - x86/syscall: Clear unused extra registers on syscall entrance - x86/syscall: Clear unused extra registers on 32-bit compatible syscall entrance - x86/entry: Use retpoline for syscall's indirect calls - x86/cpu/amd, kvm: Satisfy guest kernel reads of IC_CFG MSR - x86/cpu/AMD: Add speculative control support for AMD - x86/microcode: Extend post microcode reload to support IBPB feature - KVM: SVM: Do not intercept new speculative control MSRs - x86/svm: Set IBRS value on VM entry and exit - x86/svm: Set IBPB when running a different VCPU - KVM: x86: Add speculative control CPUID support for guests - x86/svm: Add code to clobber the RSB on VM exit - x86/svm: Add code to clear registers on VM exit - x86/cpu/AMD: Make the LFENCE instruction serialized - x86/cpu/AMD: Remove now unused definition of MFENCE_RDTSC feature - powerpc: add gmb barrier - s390/spinlock: add gmb memory barrier - SAUCE: x86/kvm: Fix stuff_RSB() for 32-bit - arm64: no gmb() implementation yet - arm: no gmb() implementation yet * powerpc: flush L1D on return to use (LP: #1742772) - SAUCE: powerpc: Secure memory rfi flush - SAUCE: rfi-flush: Make DEBUG_RFI a CONFIG option - SAUCE: rfi-flush: Add HRFI_TO_UNKNOWN and use it in denorm - SAUCE: Fixup rfid in kvmppc_skip_Hinterrupt should be hrfid - SAUCE: rfi-flush: kvmppc_skip_(H)interrupt returns to host - SAUCE: KVM: Revert the implementation of H_GET_CPU_CHARACTERISTICS - SAUCE: rfi-flush: Implement congruence-first fallback flush - SAUCE: rfi-flush: Make l1d_flush_type bit flags - SAUCE: rfi-flush: Push the instruction selection down to the patching routine - SAUCE: rfi-flush: Expand the RFI section to two nop slots - SAUCE: rfi-flush: Support more than one flush type at once - SAUCE: rfi-flush: Allow HV to advertise multiple flush types - SAUCE: rfi-flush: Add speculation barrier before ori 30,30,0 flush - SAUCE: powerpc/asm: Allow including ppc_asm.h in asm files - SAUCE: Remove setup.h include file otherwise compilation complains about missing header file. - SAUCE: Fix compilation errors for arch/powerpc/lib/feature-fixups.c - SAUCE: rfi-flush: Add barriers to the fallback L1D flushing - SAUCE: rfi-flush: Rework powernv logic to be more cautious - SAUCE: rfi-flush: Rework pseries logic to be more cautious - SAUCE: rfi-flush: Fix the fallback flush to actually activate - SAUCE: rfi-flush: Fix HRFI_TO_UNKNOWN - SAUCE: rfi-flush: Refactor the macros so the nops are defined once - SAUCE: rfi-flush: Add no_rfi_flush and nopti comandline options - SAUCE: rfi-flush: Use rfi-flush in printks - SAUCE: rfi-flush: Fallback flush add load dependency - SAUCE: rfi-flush: Fix the 32-bit KVM build - SAUCE: rfi-flush: Fix some RFI conversions in the KVM code - SAUCE: UBUNTU: [Config] Disable CONFIG_PPC_DEBUG_RFI * s390: add ppa to kernel entry/exit (LP: #1742771) - s390: introduce CPU alternatives - s390: add ppa to kernel entry / exit * CVE-2017-5754 - x86/tlb: Drop the _GPL from the cpu_tlbstate export - Map the vsyscall page with _PAGE_USER - s390: introduce CPU alternatives - s390: add ppa to kernel entry / exit - SAUCE: powerpc: Secure memory rfi flush - SAUCE: rfi-flush: Make DEBUG_RFI a CONFIG option - SAUCE: rfi-flush: Add HRFI_TO_UNKNOWN and use it in denorm - SAUCE: Fixup rfid in kvmppc_skip_Hinterrupt should be hrfid - SAUCE: rfi-flush: kvmppc_skip_(H)interrupt returns to host - SAUCE: KVM: Revert the implementation of H_GET_CPU_CHARACTERISTICS - SAUCE: rfi-flush: Implement congruence-first fallback flush - SAUCE: rfi-flush: Make l1d_flush_type bit flags - SAUCE: rfi-flush: Push the instruction selection down to the patching routine - SAUCE: rfi-flush: Expand the RFI section to two nop slots - SAUCE: rfi-flush: Support more than one flush type at once - SAUCE: rfi-flush: Allow HV to advertise multiple flush types - SAUCE: rfi-flush: Add speculation barrier before ori 30,30,0 flush - SAUCE: powerpc/asm: Allow including ppc_asm.h in asm files - SAUCE: Remove setup.h include file otherwise compilation complains about missing header file. - SAUCE: Fix compilation errors for arch/powerpc/lib/feature-fixups.c - SAUCE: rfi-flush: Add barriers to the fallback L1D flushing - SAUCE: rfi-flush: Rework powernv logic to be more cautious - SAUCE: rfi-flush: Rework pseries logic to be more cautious - SAUCE: rfi-flush: Fix the fallback flush to actually activate - SAUCE: rfi-flush: Fix HRFI_TO_UNKNOWN - SAUCE: rfi-flush: Refactor the macros so the nops are defined once - SAUCE: rfi-flush: Add no_rfi_flush and nopti comandline options - SAUCE: rfi-flush: Use rfi-flush in printks - SAUCE: rfi-flush: Fallback flush add load dependency - SAUCE: rfi-flush: Fix the 32-bit KVM build - SAUCE: rfi-flush: Fix some RFI conversions in the KVM code - SAUCE: UBUNTU: [Config] Disable CONFIG_PPC_DEBUG_RFI Checksums-Sha1: 5661ec08e0e53b6d0d63fcbf93b46906bc44573a 844 linux-aws-cloud-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb 25d4c0140abc8edcd36433911c23843babefffff 38608 linux-aws-cloud-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb 94c8db034c16de20c3250966db22b48ede75fc8b 9936892 linux-aws-headers-4.4.0-1049_4.4.0-1049.58_all.deb 22c0147e63a36f6092371f6a23355d9df1e6cb73 866 linux-aws-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb e9a452b29b4b9ad72edb9ceca29f29628378b7ac 694436 linux-aws-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb 64787d797900b96bfa1383dd426dcf476fe4c405 24451 linux-aws_4.4.0-1049.58_amd64_translations.tar.gz fbe9b83a822905ef18aa21f20b474ffcb36a57d9 2554 linux-cloud-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb 17664af09ab0c2c98d375ed3d4e0282e028f1f4c 676274 linux-headers-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb 49ad1b552450c4980411a7ebec867166c440e41e 333258388 linux-image-4.4.0-1049-aws-dbgsym_4.4.0-1049.58_amd64.ddeb 93fa88c1ddaad92d8ffb8d800b4904664674ee3c 18861756 linux-image-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb f3800b5f2325ba05b4a619fe16901b46b81a85a6 2600 linux-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb Checksums-Sha256: 3718c74ed42bb3f5f62acfba567145eb3607ca515055924b5cd8e88500825d0c 844 linux-aws-cloud-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb 8e58116869faf8f264d0fc2f7ac0ef4da35dc55264d48566dd53cbc77f99a719 38608 linux-aws-cloud-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb a55f943d35ab4e4484bf39b1155f7dacf722c28eba9b7a71bf4c4abfcb1574f3 9936892 linux-aws-headers-4.4.0-1049_4.4.0-1049.58_all.deb 964d905f4cca6fa7268d88d91cd8449d314c743e90e9211a2b90f19a31c5b210 866 linux-aws-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb 4793635f6840170da28420703bc3ee4b5af9799c05aac602db36169dd863d52d 694436 linux-aws-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb 45e96d76707c599f61c057da1f31da695c699aed02b29a52145987b70f815f8b 24451 linux-aws_4.4.0-1049.58_amd64_translations.tar.gz cfcf597de8c71445a5a514d36ecca81455ea7c1ff34dd99169687eea0aec16d0 2554 linux-cloud-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb cae6f7ec0285d2060476254c95329a31323fad5f9320ad11fc60c88ae6264ced 676274 linux-headers-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb efae88003a9d606e590b3fdf7f3dec065ee68656d70c2dcaf4dc98ec62302d82 333258388 linux-image-4.4.0-1049-aws-dbgsym_4.4.0-1049.58_amd64.ddeb 43901fc3347a8700401519ee23760926c6bd5ae8db49fc1d55b74fd793ebae84 18861756 linux-image-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb 49330ff42d8022948311d89ff10d9a19c7be4ebed612d52490836732b3c30739 2600 linux-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb Files: 0444c82fe1fbaf42604e7374e951f3ac 844 devel extra linux-aws-cloud-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb bdd4191632068c98d0be22d05f4943a7 38608 devel optional linux-aws-cloud-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb 3f8d0db828399f886e719e59844b3ffa 9936892 devel optional linux-aws-headers-4.4.0-1049_4.4.0-1049.58_all.deb 84ba53a707fc78ec3e93ba5501f9e564 866 devel extra linux-aws-tools-4.4.0-1049-dbgsym_4.4.0-1049.58_amd64.ddeb aa7347ec54d6f1c9a26fcfc472da362f 694436 devel optional linux-aws-tools-4.4.0-1049_4.4.0-1049.58_amd64.deb e0885d2913106692d6b1489022eeb4b6 24451 raw-translations - linux-aws_4.4.0-1049.58_amd64_translations.tar.gz 78860730b6e1bf3a657b301d3d993043 2554 devel optional linux-cloud-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb d23332645c5e730d67f445961f8e2496 676274 devel optional linux-headers-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb f2d81a4c5c7e2698e12a8a939d0a188a 333258388 devel optional linux-image-4.4.0-1049-aws-dbgsym_4.4.0-1049.58_amd64.ddeb f997d6f09810a60ff7a04e8ae457e585 18861756 kernel optional linux-image-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb 6c2c7f0d25210b1424357b68424585ed 2600 devel optional linux-tools-4.4.0-1049-aws_4.4.0-1049.58_amd64.deb