-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 08 Aug 2023 02:33:54 +0200 Source: linux Binary: linux-doc linux-doc-5.10 linux-headers-5.10.0-24-common linux-headers-5.10.0-24-common-rt linux-source linux-source-5.10 linux-support-5.10.0-24 Architecture: all Version: 5.10.179-4 Distribution: bullseye-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Ben Hutchings Description: linux-doc - Linux kernel specific documentation (meta-package) linux-doc-5.10 - Linux kernel specific documentation for version 5.10 linux-headers-5.10.0-24-common - Common header files for Linux 5.10.0-24 linux-headers-5.10.0-24-common-rt - Common header files for Linux 5.10.0-24-rt linux-source - Linux kernel source (meta-package) linux-source-5.10 - Linux kernel source for version 5.10 with Debian patches linux-support-5.10.0-24 - Support files for Linux 5.10 Changes: linux (5.10.179-4) bullseye-security; urgency=high . [ Salvatore Bonaccorso ] * [x86] Add mitigations for Gather Data Sampling (GDS) (CVE-2022-40982) - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - ARM: cpu: Switch to arch_cpu_finalize_init() - ia64/cpu: Switch to arch_cpu_finalize_init() - m68k/cpu: Switch to arch_cpu_finalize_init() - mips/cpu: Switch to arch_cpu_finalize_init() - sh/cpu: Switch to arch_cpu_finalize_init() - sparc/cpu: Switch to arch_cpu_finalize_init() - um/cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - init: Invoke arch_cpu_finalize_init() earlier - init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init() - x86/fpu: Remove cpuinfo argument from init functions - x86/fpu: Mark init functions __init - x86/fpu: Move FPU initialization into arch_cpu_finalize_init() - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM - x86/xen: Fix secondary processors' FPU initialization - x86/mm: fix poking_init() for Xen PV guests - x86/mm: Use mm_alloc() in poking_init() - mm: Move mm_cachep initialization to mm_init() - x86/mm: Initialize text poking earlier . [ Ben Hutchings ] * Documentation/x86: Fix backwards on/off logic about YMM support * [x86] Add a Speculative RAS Overflow (SRSO) mitigation (CVE-2023-20569) - x86/cpu: Add VM page flush MSR availablility as a CPUID feature - x86/cpufeatures: Assign dedicated feature word for CPUID_0x8000001F[EAX] - tools headers cpufeatures: Sync with the kernel sources - x86/bugs: Increase the x86 bugs vector size to two u32s - x86/cpu, kvm: Add support for CPUID_80000021_EAX - x86/srso: Add a Speculative RAS Overflow mitigation - x86/srso: Add IBPB_BRTYPE support - x86/srso: Add SRSO_NO support - x86/srso: Add IBPB - x86/srso: Add IBPB on VMEXIT - x86/srso: Fix return thunks in generated code - x86/srso: Tie SBPB bit setting to microcode patch detection * Bump ABI to 24 Checksums-Sha1: 62cf169b3003565701606cc56f1c80af00451ba9 30364260 linux-doc-5.10_5.10.179-4_all.deb 92954512779c686d3ab1f764fdb543ea49d8c62e 1104 linux-doc_5.10.179-4_all.deb 5c65cfcb1a6a26bb59ea97917b79820a83a5bb5b 7441656 linux-headers-5.10.0-24-common-rt_5.10.179-4_all.deb 3e93fce6e1282e0fde24af4efb8c74d14bdc8e48 9105204 linux-headers-5.10.0-24-common_5.10.179-4_all.deb 51556a06ccfe76c0ef1dc525fdd76e9ca9ccd197 121330960 linux-source-5.10_5.10.179-4_all.deb 97d14401697af9742b45f5713ac2095d2b2bbf72 1104 linux-source_5.10.179-4_all.deb d552a434e090f9cd33a3961993d635b248b30532 635420 linux-support-5.10.0-24_5.10.179-4_all.deb ac59c95988512aee8c6ca8a13a2a48103814794d 12645 linux_5.10.179-4_all-buildd.buildinfo Checksums-Sha256: 20810e1580161de781f2e21c00990cbfd138c795b65015123e6852aa8e115acb 30364260 linux-doc-5.10_5.10.179-4_all.deb 22b62d19b3ec046435f889900193763bddaf8f6e94877d54b0675de148f66bdf 1104 linux-doc_5.10.179-4_all.deb 07feb0fb873b010a5ce32276ff9a0a98c5a25de391a99b00f773272a0df8d3d7 7441656 linux-headers-5.10.0-24-common-rt_5.10.179-4_all.deb 0cf252d5a8b69341d8757bfb75969073264f367d25aa5d53c95b4cc248b18043 9105204 linux-headers-5.10.0-24-common_5.10.179-4_all.deb facb0f02b7763cc8e792bedf1bc197781c5202a24099487cc3b82bf832a95eaf 121330960 linux-source-5.10_5.10.179-4_all.deb 01fda45f5f9c9917464fb455f71ebe8452c8e3338ef6d3e554cc47580593d579 1104 linux-source_5.10.179-4_all.deb 5475ea75b34075178edd744e17468ff104ac5ccc679842a11dc66ef2ec72a16f 635420 linux-support-5.10.0-24_5.10.179-4_all.deb 8ed3d4e4c0fb910be734715c67b3df15605226eb3e036829ed337499a9ba963f 12645 linux_5.10.179-4_all-buildd.buildinfo Files: ac801165f288113189d6aca927b7800d 30364260 doc optional linux-doc-5.10_5.10.179-4_all.deb 0d16a6bb95af416b870c2ee70d9d36d5 1104 doc optional linux-doc_5.10.179-4_all.deb 763609c3d92aa01827ec0362a5b56fa7 7441656 kernel optional linux-headers-5.10.0-24-common-rt_5.10.179-4_all.deb 4a887b99b41fba1b2b4819d30817afeb 9105204 kernel optional linux-headers-5.10.0-24-common_5.10.179-4_all.deb 00fdc9ac2cc381a84cb369c24896aa53 121330960 kernel optional linux-source-5.10_5.10.179-4_all.deb f90a99740f7331f54d6ac152eb9945f9 1104 kernel optional linux-source_5.10.179-4_all.deb e1d44a9446e1e6513d7b026fcd0db6da 635420 devel optional linux-support-5.10.0-24_5.10.179-4_all.deb 458478af1d97bee60d3f3a26b46a3c3a 12645 kernel optional linux_5.10.179-4_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzW1K1578DQd6MDTQEbLkkg2OS0oFAmTSDB0ACgkQEbLkkg2O S0pfKw/9G4/JKx0fZ/ghUqw+GwtEbgEqQe2JndIOMaPRONFb2ct6UPsv8tvB7uA6 Bzr5SXcC4cBYZt4QH4hEhKgLLs8pbsbxYwKtVofGtptGT6A1wbWRiY5x1PzawtKy rAHYf17x9K8xdZQCTV36HMLmppEUr9ciTh0J/KweGnl4FnxPP9PGykjnLplpCXCk IyHwXfdUkivVDZqV1KAleupJfL1ji7ouMLLSptl6bxdxQCgSOBsE3NtaZgyRTVV9 M4VtybvdtHUo88smf1mpovnIeRf+VIo3/oBRM8IUykG2jrvn48fNz5sDqs8KYAeZ r3BImc+3BrhKS1uPRaUEwDueUUZ+u4POUDGm/mTHI4MK+UKIieunAyIcB8txIO4f QGu1ZmULXPAgWSWDkkRLWB/rhm3QeqLg0YMZXEcWWYOSqIsaITSIYerky8X9qPJp KNkIn1+mY0XGDMOMkkTPgqVigcVTCf85g+niY2Vl1HZNENmONJAHQnYwjgg33Gip BbRH/nx+MgaPqxJ8zoQyfXjB622ScvtL6/+PQOQSoBWWAsnnIb8w7t8aWBHwM7T5 ywlnFnfqO9S01n2K+m7vxhVE1vdbb3Gt6ausj4HnGOlUh+5UcMu2Jgkhe8QKMfm8 Vd4QXom+RNWjpOskiAZ/bOHFBMnUkqDMeeQqg65DBXtcnx+eAqg= =n6yP -----END PGP SIGNATURE-----