-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 07 Aug 2023 23:01:57 +0200 Source: linux Binary: bpftool bpftool-dbgsym hyperv-daemons hyperv-daemons-dbgsym libcpupower-dev libcpupower1 libcpupower1-dbgsym linux-compiler-gcc-12-x86 linux-config-6.1 linux-cpupower linux-cpupower-dbgsym linux-headers-6.1.0-11-amd64 linux-headers-6.1.0-11-cloud-amd64 linux-headers-6.1.0-11-rt-amd64 linux-image-6.1.0-11-amd64-dbg linux-image-6.1.0-11-amd64-unsigned linux-image-6.1.0-11-cloud-amd64-dbg linux-image-6.1.0-11-cloud-amd64-unsigned linux-image-6.1.0-11-rt-amd64-dbg linux-image-6.1.0-11-rt-amd64-unsigned linux-image-amd64-dbg linux-image-amd64-signed-template linux-image-cloud-amd64-dbg linux-image-rt-amd64-dbg linux-kbuild-6.1 linux-kbuild-6.1-dbgsym linux-libc-dev linux-perf linux-perf-dbgsym rtla usbip usbip-dbgsym Architecture: amd64 Version: 6.1.38-3 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Salvatore Bonaccorso Description: bpftool - Inspection and simple manipulation of BPF programs and maps hyperv-daemons - Support daemons for Linux running on Hyper-V libcpupower-dev - CPU frequency and voltage scaling tools for Linux (development fi libcpupower1 - CPU frequency and voltage scaling tools for Linux (libraries) linux-compiler-gcc-12-x86 - Compiler for Linux on x86 (meta-package) linux-config-6.1 - Debian kernel configurations for Linux 6.1 linux-cpupower - CPU power management tools for Linux linux-headers-6.1.0-11-amd64 - Header files for Linux 6.1.0-11-amd64 linux-headers-6.1.0-11-cloud-amd64 - Header files for Linux 6.1.0-11-cloud-amd64 linux-headers-6.1.0-11-rt-amd64 - Header files for Linux 6.1.0-11-rt-amd64 linux-image-6.1.0-11-amd64-dbg - Debug symbols for linux-image-6.1.0-11-amd64 linux-image-6.1.0-11-amd64-unsigned - Linux 6.1 for 64-bit PCs linux-image-6.1.0-11-cloud-amd64-dbg - Debug symbols for linux-image-6.1.0-11-cloud-amd64 linux-image-6.1.0-11-cloud-amd64-unsigned - Linux 6.1 for x86-64 cloud linux-image-6.1.0-11-rt-amd64-dbg - Debug symbols for linux-image-6.1.0-11-rt-amd64 linux-image-6.1.0-11-rt-amd64-unsigned - Linux 6.1 for 64-bit PCs, PREEMPT_RT linux-image-amd64-dbg - Debugging symbols for Linux amd64 configuration (meta-package) linux-image-amd64-signed-template - Template for signed linux-image packages for amd64 linux-image-cloud-amd64-dbg - Debugging symbols for Linux cloud-amd64 configuration (meta-packa linux-image-rt-amd64-dbg - Debugging symbols for Linux rt-amd64 configuration (meta-package) linux-kbuild-6.1 - Kbuild infrastructure for Linux 6.1 linux-libc-dev - Linux support headers for userspace development linux-perf - Performance analysis tools for Linux rtla - Real-Time Linux Analysis tools usbip - USB device sharing system over IP network Changes: linux (6.1.38-3) bookworm-security; urgency=high . [ Salvatore Bonaccorso ] * [x86] Add mitigations for Gather Data Sampling (GDS) (CVE-2022-40982) - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - ARM: cpu: Switch to arch_cpu_finalize_init() - ia64/cpu: Switch to arch_cpu_finalize_init() - loongarch/cpu: Switch to arch_cpu_finalize_init() - m68k/cpu: Switch to arch_cpu_finalize_init() - mips/cpu: Switch to arch_cpu_finalize_init() - sh/cpu: Switch to arch_cpu_finalize_init() - sparc/cpu: Switch to arch_cpu_finalize_init() - um/cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - init: Invoke arch_cpu_finalize_init() earlier - init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init() - x86/init: Initialize signal frame size late - x86/fpu: Remove cpuinfo argument from init functions - x86/fpu: Mark init functions __init - x86/fpu: Move FPU initialization into arch_cpu_finalize_init() - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM - x86/mem_encrypt: Unbreak the AMD_MEM_ENCRYPT=n build - x86/xen: Fix secondary processors' FPU initialization - x86/mm: fix poking_init() for Xen PV guests - x86/mm: Use mm_alloc() in poking_init() - mm: Move mm_cachep initialization to mm_init() - x86/mm: Initialize text poking earlier - Documentation/x86: Fix backwards on/off logic about YMM support * [x86] Add a Speculative RAS Overflow (SRSO) mitigation (CVE-2023-20569) - x86/bugs: Increase the x86 bugs vector size to two u32s - x86/srso: Add a Speculative RAS Overflow mitigation - x86/srso: Add IBPB_BRTYPE support - x86/srso: Add SRSO_NO support - x86/srso: Add IBPB - x86/srso: Add IBPB on VMEXIT - x86/srso: Fix return thunks in generated code - x86/srso: Add a forgotten NOENDBR annotation * Bump ABI to 11 . [ Ben Hutchings ] * [x86] Add missing pieces of SRSO mitigation: - x86/cpu, kvm: Add support for CPUID_80000021_EAX - x86/srso: Tie SBPB bit setting to microcode patch detection Checksums-Sha1: 6fb0c76ef9811bb95bd5ca31948994e7204c64b6 834328 bpftool-dbgsym_7.1.0+6.1.38-3_amd64.deb 739444787192df4d84514c99106959b5371d5bf8 917492 bpftool_7.1.0+6.1.38-3_amd64.deb ae4e5adc15b1df5b29adcf2448646cbf3ae43aea 48636 hyperv-daemons-dbgsym_6.1.38-3_amd64.deb 4cad75ee38f14fed9e1a33ef7d7a3904722b3735 683688 hyperv-daemons_6.1.38-3_amd64.deb 555af08b58276371ee70ba059802e10050a5120e 668816 libcpupower-dev_6.1.38-3_amd64.deb b7507aa03304eb9b5ba2d85d274b3b882a8205c7 25036 libcpupower1-dbgsym_6.1.38-3_amd64.deb f0682b15d39d1c177df2db1804086de75fa7b5fa 674144 libcpupower1_6.1.38-3_amd64.deb 21cc5b6a52c5601930af3b3c12b9a99d21352e19 666856 linux-compiler-gcc-12-x86_6.1.38-3_amd64.deb be8b8bc253a149fb04cd5c28dc128fd704203540 800844 linux-config-6.1_6.1.38-3_amd64.deb 0d45f63da67923416ac470611ba2fd5167e11160 210292 linux-cpupower-dbgsym_6.1.38-3_amd64.deb bff8105f65f729d4b5f8b4863e7fabb8e50a0a94 777264 linux-cpupower_6.1.38-3_amd64.deb 23bac26d8c8d723310cdce22c6213acdef91363e 1196652 linux-headers-6.1.0-11-amd64_6.1.38-3_amd64.deb 281cb130281d2013c5bef4f08c19e43d7d84ad54 949076 linux-headers-6.1.0-11-cloud-amd64_6.1.38-3_amd64.deb eab79fabf582cf9ad27debba8ebba81fac23a402 1195948 linux-headers-6.1.0-11-rt-amd64_6.1.38-3_amd64.deb 86414e82408a430acb5e9f91059177233b1602bf 848328688 linux-image-6.1.0-11-amd64-dbg_6.1.38-3_amd64.deb fb5ed38a0b4b9672a2395ecd21580c0cedd44245 67318156 linux-image-6.1.0-11-amd64-unsigned_6.1.38-3_amd64.deb 37e6827df721540f752d0aaea95d791d736551ac 277880224 linux-image-6.1.0-11-cloud-amd64-dbg_6.1.38-3_amd64.deb 9a4326fd104dae51f40e9733729526eb65b6cb41 25103688 linux-image-6.1.0-11-cloud-amd64-unsigned_6.1.38-3_amd64.deb 9dc90e2a4cc731d634a5fba19413186400fb4ac2 850481192 linux-image-6.1.0-11-rt-amd64-dbg_6.1.38-3_amd64.deb 9e4768c81c85ff6844448d085285adf651d9cc23 67321948 linux-image-6.1.0-11-rt-amd64-unsigned_6.1.38-3_amd64.deb b45cdd6f735e626bb974da5d1aa0573662ef50da 1296 linux-image-amd64-dbg_6.1.38-3_amd64.deb 5541c3ac46de69548af237e7bd6176e9b6d0959f 1220752 linux-image-amd64-signed-template_6.1.38-3_amd64.deb ba7c95345c1f75ab3d57f6bc6887832d9373cdcf 1320 linux-image-cloud-amd64-dbg_6.1.38-3_amd64.deb b63174de3f43a587b75bd8b0dc33c6d0d1311ac4 1316 linux-image-rt-amd64-dbg_6.1.38-3_amd64.deb 5411729001c9110cfd04fb12df658cd45c057703 1023700 linux-kbuild-6.1-dbgsym_6.1.38-3_amd64.deb d562a622830447b4bacc054cf7640eb4992f78ed 923064 linux-kbuild-6.1_6.1.38-3_amd64.deb c7a5baf5138b6016dee914ddfcc5b6f567e8d372 1811368 linux-libc-dev_6.1.38-3_amd64.deb b336538e8dad32e1401fd5834fba9c651680dfc2 8096860 linux-perf-dbgsym_6.1.38-3_amd64.deb 931cd8867827f52a313dbde390a695067c975593 2782364 linux-perf_6.1.38-3_amd64.deb 7f5de33d652055711e6d37b0ca0c81c5b03c7e80 19726 linux_6.1.38-3_amd64-buildd.buildinfo 416e73d8a195f6bf65413ffee24098aca128cc33 703900 rtla_6.1.38-3_amd64.deb db9585c3b016b56b77dd6bd56a492ed214514479 145320 usbip-dbgsym_2.0+6.1.38-3_amd64.deb 61d12ea6af7f2b319d760f5bcdc40d0ea904819b 708980 usbip_2.0+6.1.38-3_amd64.deb Checksums-Sha256: 2d54da85d71df72b69c508cb4f4af5d3d53153a92a67fa0cf67237b3ea99288a 834328 bpftool-dbgsym_7.1.0+6.1.38-3_amd64.deb aea1c7339fc3d8fe2cd5e880ad9f44bc60563ec6d7465a2b72de806ffc394237 917492 bpftool_7.1.0+6.1.38-3_amd64.deb db714bc6ccff5bd558f97849cd8a009ddc1392144119b113ec628c9f373657c4 48636 hyperv-daemons-dbgsym_6.1.38-3_amd64.deb a3b4ca430839c858c7b252b494305383ae962c9d3109fe6959b7cda4ff7deeb9 683688 hyperv-daemons_6.1.38-3_amd64.deb 687f20ae357694672c5d297fb756b07c42914971ef0f28d0c398c2a848ea6454 668816 libcpupower-dev_6.1.38-3_amd64.deb 0a01315619c3ac9c50d66491df30c91a3eb0ac21da43dc67866011908909bd62 25036 libcpupower1-dbgsym_6.1.38-3_amd64.deb 386a0c2cb47e3c6ba005bc659d0e44175ac7a0392aabf4725fbdf9cf5addef81 674144 libcpupower1_6.1.38-3_amd64.deb 9645030857496943df320b1316b921a759e00fede8dde0d8475300c20b13eb15 666856 linux-compiler-gcc-12-x86_6.1.38-3_amd64.deb 6166f9e1ab33efc3d9ec16048e45f3a1de4f9b62113e652444e2031703e86f89 800844 linux-config-6.1_6.1.38-3_amd64.deb 43e88d96e5da0b99306bb1d8c403d877722fc34893e0374dee47a4d5c567f5c3 210292 linux-cpupower-dbgsym_6.1.38-3_amd64.deb 3db408d63c66929b2f2b31c3f323da906eafdb0addcc81d6610ee8d2698409cf 777264 linux-cpupower_6.1.38-3_amd64.deb 5ffc9faf580b000c1c61f156c565c6ebff300c48ab8f16d38a6694a01796b311 1196652 linux-headers-6.1.0-11-amd64_6.1.38-3_amd64.deb 7b3a9c4a098bbc9cc6b50f2801f0e8752c26953ff6311c9f0860355d8a570185 949076 linux-headers-6.1.0-11-cloud-amd64_6.1.38-3_amd64.deb 12c90be8941d07aed7a758b5cedda588e10e1e7b88755e605e9971ab3812cc2b 1195948 linux-headers-6.1.0-11-rt-amd64_6.1.38-3_amd64.deb b62d6ec999d165ca55c96e0c81e98d5b4b8f09387dea1377f85bf6cbafa7bd82 848328688 linux-image-6.1.0-11-amd64-dbg_6.1.38-3_amd64.deb 36acf9fbef56c95cf4bc54200a07078df8c6b85060035f74266130720fdfb935 67318156 linux-image-6.1.0-11-amd64-unsigned_6.1.38-3_amd64.deb 4fadbc77a17880a977958ecd4933f75999fd0ec93e7831332384cc657d0f8d9f 277880224 linux-image-6.1.0-11-cloud-amd64-dbg_6.1.38-3_amd64.deb eea8ec8e15f493ec82b1e73e884b2378fe7639ca610e4a5aa284c400052eb29a 25103688 linux-image-6.1.0-11-cloud-amd64-unsigned_6.1.38-3_amd64.deb 4a3a5a4dcd4626adaca5b2169791eaf45a0d42a7b07f59ec46998198ec1a0dd3 850481192 linux-image-6.1.0-11-rt-amd64-dbg_6.1.38-3_amd64.deb e1ef7bf025d347f639e2c4d0d91e8cf5aa24644846ebcb977c053d7e00ed6ebe 67321948 linux-image-6.1.0-11-rt-amd64-unsigned_6.1.38-3_amd64.deb e629a6030cedcfe42ad9b640e52e939acbf60e8bf8ab26a320d3bd99d1e36f9e 1296 linux-image-amd64-dbg_6.1.38-3_amd64.deb 716937eb678b429c0a9409bc4089aa000029b722bf40b424d90bf47d58b84738 1220752 linux-image-amd64-signed-template_6.1.38-3_amd64.deb 47ab0843515e705c9fcd4a73cfe356e10c7d182848bd6ada94d16d3a7cc21bc8 1320 linux-image-cloud-amd64-dbg_6.1.38-3_amd64.deb 840c49f95c8f624145429a9381cee684115d3c00ea7d484106c6cc056e473159 1316 linux-image-rt-amd64-dbg_6.1.38-3_amd64.deb b540aca935da2cd3a58f4035e122be610d37f94f3151fbe51d455e8d22a3f962 1023700 linux-kbuild-6.1-dbgsym_6.1.38-3_amd64.deb b1ca7b4b257c112776224d81f5eed062bdefd019d626043a9233b462c0e44d9a 923064 linux-kbuild-6.1_6.1.38-3_amd64.deb c1be5492cd48187675f4c0e9083bec52c3d6db32cdb7e81dea2eb6ede9169306 1811368 linux-libc-dev_6.1.38-3_amd64.deb 4101a62716453ad132483c20a985ffd97f3066e7f346b5ee5f2922ad2d7ed59b 8096860 linux-perf-dbgsym_6.1.38-3_amd64.deb 61b743bde4c5a386a422f5c73cc029a18d3ccd3c014bf17c2391b73fe2025aee 2782364 linux-perf_6.1.38-3_amd64.deb 42b628303ffc780fa9255ea68fe119b4045c412e72eb9555ee2f9f9b7372e0a0 19726 linux_6.1.38-3_amd64-buildd.buildinfo b8101661b016f97f7b5f18fa99c7fa7f41bf28b3f67579814660e01ec4d501bb 703900 rtla_6.1.38-3_amd64.deb f732d2caa658e2f185f33c583a00c5ef651757e73f1a16e8a52982fdc267994f 145320 usbip-dbgsym_2.0+6.1.38-3_amd64.deb 7827c72ceb286d3b171036395df324b111d4f87f545ae08378cc00849e71e154 708980 usbip_2.0+6.1.38-3_amd64.deb Files: bd34eb2a929ea77e268d7f4a92db841e 834328 debug optional bpftool-dbgsym_7.1.0+6.1.38-3_amd64.deb f26ff4fbea1af2e057d60633b8a6c7b6 917492 devel optional bpftool_7.1.0+6.1.38-3_amd64.deb 863e2999f8a5e0f64c464f5a875e6515 48636 debug optional hyperv-daemons-dbgsym_6.1.38-3_amd64.deb 8f3270da70c6eed8b969bdb0228b63e9 683688 admin optional hyperv-daemons_6.1.38-3_amd64.deb 3d6cc17c803632f4e3f30bf4472c3bfe 668816 libdevel optional libcpupower-dev_6.1.38-3_amd64.deb fac9ce9a8458a17553c9385e1d9b2dce 25036 debug optional libcpupower1-dbgsym_6.1.38-3_amd64.deb d71433302ac6c3b3404c5c3ce07a8d03 674144 libs optional libcpupower1_6.1.38-3_amd64.deb c5c7f742d0bb75e04e51ed5245c01beb 666856 kernel optional linux-compiler-gcc-12-x86_6.1.38-3_amd64.deb 3c4b172c8ce2d11791a8ccd5a790c7a4 800844 kernel optional linux-config-6.1_6.1.38-3_amd64.deb c280e457c2e6cde640e865a8ba1ceb81 210292 debug optional linux-cpupower-dbgsym_6.1.38-3_amd64.deb 6e2788874d93b860f31133c382d04bc6 777264 admin optional linux-cpupower_6.1.38-3_amd64.deb 3a2ad0055e2f517b6390d7957456900f 1196652 kernel optional linux-headers-6.1.0-11-amd64_6.1.38-3_amd64.deb 33f72b766fdf1869bd18f7583e556c2f 949076 kernel optional linux-headers-6.1.0-11-cloud-amd64_6.1.38-3_amd64.deb 087b0443b739264dc2f2a8d30370c0c8 1195948 kernel optional linux-headers-6.1.0-11-rt-amd64_6.1.38-3_amd64.deb 04b793dbd5a57548b59a14e6fcddb91e 848328688 debug optional linux-image-6.1.0-11-amd64-dbg_6.1.38-3_amd64.deb 54fbecb17a7d2dd24f60afe420f39aa6 67318156 kernel optional linux-image-6.1.0-11-amd64-unsigned_6.1.38-3_amd64.deb 756ac5dcbccce69389b51c11ce82573b 277880224 debug optional linux-image-6.1.0-11-cloud-amd64-dbg_6.1.38-3_amd64.deb f022c5a74ae339e1db33948188e3dedc 25103688 kernel optional linux-image-6.1.0-11-cloud-amd64-unsigned_6.1.38-3_amd64.deb 8b3c2725c3d39d6e84ff11cc2a050c2a 850481192 debug optional linux-image-6.1.0-11-rt-amd64-dbg_6.1.38-3_amd64.deb 16ea4425f364d684158bf2b2d061aa4a 67321948 kernel optional linux-image-6.1.0-11-rt-amd64-unsigned_6.1.38-3_amd64.deb 74ca8da8ff706879b4f9d3a5d18a6fc8 1296 kernel optional linux-image-amd64-dbg_6.1.38-3_amd64.deb ad4fe47e7bcf61f6f45d78f827c9fb88 1220752 kernel optional linux-image-amd64-signed-template_6.1.38-3_amd64.deb af2b2e9c7cc6aaf25ca81b9742f9cfad 1320 kernel optional linux-image-cloud-amd64-dbg_6.1.38-3_amd64.deb 9448c49762a9c48775ff0619741b6ab2 1316 kernel optional linux-image-rt-amd64-dbg_6.1.38-3_amd64.deb 4b94039fc8ade0eb458eaba65794d4c7 1023700 debug optional linux-kbuild-6.1-dbgsym_6.1.38-3_amd64.deb 03c11ded1fe3f6944d7f6bfda69efac6 923064 kernel optional linux-kbuild-6.1_6.1.38-3_amd64.deb 14ffa9c0b12daefd1d6070a8f4c8a555 1811368 devel optional linux-libc-dev_6.1.38-3_amd64.deb 7a28d567d8f6f6f50d74db557eb2b872 8096860 debug optional linux-perf-dbgsym_6.1.38-3_amd64.deb 3f10f0b0e5db9eecabc985a0f4794e91 2782364 devel optional linux-perf_6.1.38-3_amd64.deb f31634bae91de864ad781d81c14d6109 19726 kernel optional linux_6.1.38-3_amd64-buildd.buildinfo bf69dabd80d34d686fd4f4d18812d861 703900 devel optional rtla_6.1.38-3_amd64.deb 0a812cdab382a3d02a78b668215c1977 145320 debug optional usbip-dbgsym_2.0+6.1.38-3_amd64.deb b20e64b340d6172399d9ed7a84f727a4 708980 admin optional usbip_2.0+6.1.38-3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE85oDfSLnwLkvY4Ibj5YjFeDZ0JMFAmTSMaIACgkQj5YjFeDZ 0JOzVA/+I2k8SJYZbwuPLV1OgMpnbi8jAVrpL7ntAF+llFQXnskqaU2LU89KVzxr QM3h16jR/pmJYBQxtGBT4BL9IkhPBU3WWCiNG1xvq2sK7kvYCdK+hpEjY4V9JWXb kiso5ecgY4f/Da3nHu0Ae0U2u8F9cC6LU96CNtgAEHK67nDuu5o2V0wntDxGy8AM zBWVrOExztfDXvszGbilG1EZspYAUfu91R1+qeaxH4RVWVXLh1NtBr1VWPVW/Kgu uLKfsAZDgJpF5o8J9UifXf+1TEEVQiecI/kqxqcM5K78Kvyho6+bWb3MeXixFWwg BRvt4xqRPfk42QRK01UnetO1/eRBiQs1oy9SlWmomFLuA5AQW6HmSI+il86L5V4l gvRr252TaUJc3xfiTfHvpICVjQwE8I0NvipRdaXSJeAjhCW3zKCc6gW3IQATgNAe xqA/sGLNq+Fw70wlajTmqNRa0Z3kNif8fygfRFJqmIh1JrHlyFkIWYtSnqwSWjXv tJByjFuAYCEdJ/g/NkfctLmctQ2CXZbuDLVELScLr6WywEmxfIsz90IUfVayxyev m7xIAsntwyAhK+fIRv8MJMtagrYn9valybICoPovZYwoh+j21MKGhv2+4Qu+UyNP TicPojiyPfa+B6Dw+y+AX3xYdq8OuElMAaweVCWUIYMuLHQU+xQ= =BQGW -----END PGP SIGNATURE-----