Format: 1.8 Date: Thu, 07 Oct 2021 09:39:35 -0300 Source: linux-azure-5.8 Architecture: source Version: 5.8.0-1043.46~20.04.1 Distribution: focal Urgency: medium Maintainer: Ubuntu Kernel Team Changed-By: Marcelo Henrique Cerri Launchpad-Bugs-Fixed: 1786013 1928679 1928921 1932029 1944902 1944903 1945707 1945987 Changes: linux-azure-5.8 (5.8.0-1043.46~20.04.1) focal; urgency=medium . * focal/linux-azure-5.8: 5.8.0-1043.46~20.04.1 -proposed tracker (LP: #1944902) . * Support builtin revoked certificates (LP: #1932029) - [Config] Configure CONFIG_SYSTEM_REVOCATION_KEYS with revoked keys . [ Ubuntu: 5.8.0-66.74 ] . * focal/linux-hwe-5.8: 5.8.0-66.74 -proposed tracker (LP: #1944903) * Packaging resync (LP: #1786013) - debian/dkms-versions -- update from kernel-versions (main/2021.09.27) * linux: btrfs: fix NULL pointer dereference when deleting device by invalid id (LP: #1945987) - btrfs: fix NULL pointer dereference when deleting device by invalid id * CVE-2021-38199 - NFSv4: Initialise connection to the server in nfs4_alloc_client() * BCM57800 SRIOV bug causes interfaces to disappear (LP: #1945707) - bnx2x: Fix enabling network interfaces without VFs * CVE-2021-3759 - memcg: enable accounting of ipc resources * CVE-2019-19449 - f2fs: fix wrong total_sections check and fsmeta check - f2fs: fix to do sanity check on segment/section count * Support builtin revoked certificates (LP: #1932029) - Revert "UBUNTU: SAUCE: Dump stack when X.509 certificates cannot be loaded" - integrity: Move import of MokListRT certs to a separate routine - integrity: Load certs from the EFI MOK config table - certs: Add EFI_CERT_X509_GUID support for dbx entries - certs: Move load_system_certificate_list to a common function - certs: Add ability to preload revocation certs - integrity: Load mokx variables into the blacklist keyring - certs: add 'x509_revocation_list' to gitignore - SAUCE: Dump stack when X.509 certificates cannot be loaded - [Packaging] build canonical-revoked-certs.pem from branch/arch certs - [Packaging] Revoke 2012 UEFI signing certificate as built-in - [Config] Configure CONFIG_SYSTEM_REVOCATION_KEYS with revoked keys * Support importing mokx keys into revocation list from the mok table (LP: #1928679) - efi: Support for MOK variable config table - efi: mokvar-table: fix some issues in new code - efi: mokvar: add missing include of asm/early_ioremap.h - efi/mokvar: Reserve the table only if it is in boot services data - SAUCE: integrity: add informational messages when revoking certs * Support importing mokx keys into revocation list from the mok table (LP: #1928679) // CVE-2020-26541 when certificates are revoked via MokListXRT. - SAUCE: integrity: Load mokx certs from the EFI MOK config table * CVE-2020-36311 - KVM: SVM: Periodically schedule when unregistering regions on destroy * CVE-2021-22543 - KVM: do not allow mapping valid but non-reference-counted pages * CVE-2021-3612 - Input: joydev - prevent use of not validated data in JSIOCSBTNMAP ioctl * CVE-2021-38207 - net: ll_temac: Fix TX BD buffer overwrite * CVE-2021-40490 - ext4: fix race writing to an inline_data file while its xattrs are changing * LRMv5: switch primary version handling to kernel-versions data set (LP: #1928921) - [Packaging] switch to kernel-versions Checksums-Sha1: 2a0668bdd102fe08daa91a3cb3c0e53ac91bc963 4131 linux-azure-5.8_5.8.0-1043.46~20.04.1.dsc f9aae27dbda04852a66517516f8ab4a0c8ae51eb 13607036 linux-azure-5.8_5.8.0-1043.46~20.04.1.diff.gz 31306d3ea8c980af0ce380eb0a53d7bfddf15ec4 9126 linux-azure-5.8_5.8.0-1043.46~20.04.1_source.buildinfo Checksums-Sha256: c7d20799fb4c14f9cb4ebd897c82cacbb8c3d212b7b94afbae7da752e242a32b 4131 linux-azure-5.8_5.8.0-1043.46~20.04.1.dsc 56da28250e9df6f817d4ca064eff78a8e94fd19e712216550de850f1dc3889f5 13607036 linux-azure-5.8_5.8.0-1043.46~20.04.1.diff.gz 60da07e22a77b34cef9328e64f05749a4120427ee6d3ea5ed26064ea56ccbacf 9126 linux-azure-5.8_5.8.0-1043.46~20.04.1_source.buildinfo Files: 4fb3ac1a92bf1ae7876401ce813923f1 4131 devel optional linux-azure-5.8_5.8.0-1043.46~20.04.1.dsc 9e9de874be0e45a6acb454e5f6680c0d 13607036 devel optional linux-azure-5.8_5.8.0-1043.46~20.04.1.diff.gz 126c0eeb9237705547f1e16e130fdc81 9126 devel optional linux-azure-5.8_5.8.0-1043.46~20.04.1_source.buildinfo