Xenial update to 4.4.130 stable release

Bug #1768474 reported by Juerg Haefliger
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Invalid
Undecided
Unassigned
Xenial
Fix Released
Undecided
Unassigned

Bug Description

SRU Justification

Impact:
   The upstream process for stable tree updates is quite similar
   in scope to the Ubuntu SRU process, e.g., each patch has to
   demonstrably fix a bug, and each patch is vetted by upstream
   by originating either directly from a mainline/stable Linux tree
   or a minimally backported form of that patch. The 4.4.130 upstream
   stable stable patch set is now available. It should be included
   in the Ubuntu kernel as well.

   git://git.kernel.org/

TEST CASE: TBD

   The following patches from the 4.4.130 stable release shall be
   applied:
   * Linux 4.4.130
   * s390/uprobes: implement arch_uretprobe_is_alive()
   * s390/cio: update chpid descriptor after resource accessibility event
   * cdrom: information leak in cdrom_ioctl_media_changed()
   * scsi: mptsas: Disable WRITE SAME
   * ipv6: add RTA_TABLE and RTA_PREFSRC to rtm_ipv6_policy
   * net: af_packet: fix race in PACKET_{R|T}X_RING
   * tcp: md5: reject TCP_MD5SIG or TCP_MD5SIG_EXT on established sockets
   * net: fix deadlock while clearing neighbor proxy table
   * tipc: add policy for TIPC_NLA_NET_ADDR
   * llc: fix NULL pointer deref for SOCK_ZAPPED
   * llc: hold llc_sap before release_sock()
   * sctp: do not check port in sctp_inet6_cmp_addr
   * vlan: Fix reading memory beyond skb->tail in skb_vlan_tagged_multi
   * pppoe: check sockaddr length in pppoe_connect()
   * packet: fix bitfield update race
   * team: fix netconsole setup over team
   * team: avoid adding twice the same option to the event list
   * tcp: don't read out-of-bounds opsize
   * llc: delete timers synchronously in llc_sk_free()
   * net: validate attribute sizes in neigh_dump_table()
   * l2tp: check sockaddr length in pppol2tp_connect()
   * KEYS: DNS: limit the length of option strings
   * bonding: do not set slave_dev npinfo before slave_enable_netpoll in bond_enslave
   * s390: correct module section names for expoline code revert
   * s390: correct nospec auto detection init order
   * s390: add sysfs attributes for spectre
   * s390: report spectre mitigation via syslog
   * s390: add automatic detection of the spectre defense
   * s390: move nobp parameter functions to nospec-branch.c
   * s390/entry.S: fix spurious zeroing of r0
   * s390: do not bypass BPENTER for interrupt system calls
   * s390: Replace IS_ENABLED(EXPOLINE_*) with IS_ENABLED(CONFIG_EXPOLINE_*)
   * s390: introduce execute-trampolines for branches
   * s390: run user space and KVM guests with modified branch prediction
   * s390: add options to change branch prediction behaviour for the kernel
   * s390/alternative: use a copy of the facility bit mask
   * s390: add optimized array_index_mask_nospec
   * s390: scrub registers on kernel entry and KVM exit
   * KVM: s390: wire up bpb feature
   * s390: enable CPU alternatives unconditionally
   * s390: introduce CPU alternatives
   * Revert "ath10k: send (re)assoc peer command when NSS changed"
   * jbd2: fix use after free in kjournald2()
   * ath9k_hw: check if the chip failed to wake up
   * Input: drv260x - fix initializing overdrive voltage
   * r8152: add Linksys USB3GIGV1 id
   * staging: ion : Donnot wakeup kswapd in ion system alloc
   * perf: Return proper values for user stack errors
   * x86/tsc: Prevent 32bit truncation in calc_hpet_ref()
   * cifs: do not allow creating sockets except with SMB1 posix exensions

Juerg Haefliger (juergh)
Changed in linux (Ubuntu):
status: New → Invalid
Juerg Haefliger (juergh)
description: updated
Revision history for this message
Juerg Haefliger (juergh) wrote :

Skipped the following patch (already applied):
   * KVM: s390: wire up bpb feature

Changed in linux (Ubuntu Xenial):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (15.1 KiB)

This bug was fixed in the package linux - 4.4.0-128.154

---------------
linux (4.4.0-128.154) xenial; urgency=medium

  * linux: 4.4.0-128.154 -proposed tracker (LP: #1772960)

  * CVE-2018-3639 (x86)
    - x86/cpu: Make alternative_msr_write work for 32-bit code
    - x86/bugs: Fix the parameters alignment and missing void
    - KVM: SVM: Move spec control call after restore of GS
    - x86/speculation: Use synthetic bits for IBRS/IBPB/STIBP
    - x86/cpufeatures: Disentangle MSR_SPEC_CTRL enumeration from IBRS
    - x86/cpufeatures: Disentangle SSBD enumeration
    - x86/cpu/AMD: Fix erratum 1076 (CPB bit)
    - x86/cpufeatures: Add FEATURE_ZEN
    - x86/speculation: Handle HT correctly on AMD
    - x86/bugs, KVM: Extend speculation control for VIRT_SPEC_CTRL
    - x86/speculation: Add virtualized speculative store bypass disable support
    - x86/speculation: Rework speculative_store_bypass_update()
    - x86/bugs: Unify x86_spec_ctrl_{set_guest,restore_host}
    - x86/bugs: Expose x86_spec_ctrl_base directly
    - x86/bugs: Remove x86_spec_ctrl_set()
    - x86/bugs: Rework spec_ctrl base and mask logic
    - x86/speculation, KVM: Implement support for VIRT_SPEC_CTRL/LS_CFG
    - KVM: SVM: Implement VIRT_SPEC_CTRL support for SSBD
    - x86/bugs: Rename SSBD_NO to SSB_NO
    - KVM: VMX: Expose SSBD properly to guests.

  * [i915_bpo] Fix flickering issue after panel change (LP: #1770565)
    - drm/i915: Fix iboost setting for DDI with 4 lanes on SKL
    - drm/i915: Name the "iboost bit"
    - drm/i915: Program iboost settings for HDMI/DVI on SKL
    - drm/i915: Move bxt_ddi_vswing_sequence() call into intel_ddi_pre_enable()
      for HDMI
    - drm/i915: Explicitly use ddi buf trans entry 9 for hdmi
    - drm/i915: Split DP/eDP/FDI and HDMI/DVI DDI buffer programming apart
    - drm/i915: Get the iboost setting based on the port type
    - drm/i915: Simplify intel_ddi_get_encoder_port()
    - drm/i915: Fix iboost setting for SKL Y/U DP DDI buffer translation entry 2
    - drm/i915: KBL - Recommended buffer translation programming for DisplayPort
    - drm/i915: Ignore OpRegion panel type except on select machines

  * [SRU][Bionic/Artful] fix false positives in W+X checking (LP: #1769696)
    - init: fix false positives in W+X checking

  * [Ubuntu 16.04] kernel: fix rwlock implementation (LP: #1761674)
    - SAUCE: (no-up) s390: fix rwlock implementation

  * linux < 4.11: unable to use netfilter logging from non-init namespaces
    (LP: #1766573)
    - netfilter: allow logging from non-init namespaces

  * [LTC Test] Ubuntu 18.04: tm_sigreturn failed on P8 compat mode 16.04.04
    guest (LP: #1771439)
    - powerpc: signals: Discard transaction state from signal frames

  * QCA9377 requires more IRAM banks for its new firmware (LP: #1748345)
    - ath10k: update the IRAM bank number for QCA9377

  * i915/kbl_dmc_ver1.bin failed with error -2 package 1.157.17 kernel
    4.4.0-116-generic (LP: #1752536)
    - ubuntu: i915_bpo - Add MODULE_FIRMWARE for Geminilake's DMC

  * Xenial update to 4.4.131 stable release (LP: #1768825)
    - ext4: prevent right-shifting extents beyond EXT_MAX_BLOCKS
    - ext4: set h_journal if there is a failure...

Changed in linux (Ubuntu Xenial):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.