jammy/linux-gcp: 5.15.0-1014.19 -proposed tracker

Bug #1981217 reported by Stefan Bader
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kernel SRU Workflow
Fix Committed
Medium
Unassigned
Automated-testing
New
Medium
Canonical Kernel Team
Boot-testing
New
Medium
Unassigned
Certification-testing
Invalid
Medium
Unassigned
New-review
Fix Released
Medium
Andy Whitcroft
Prepare-package
Fix Committed
Medium
Khaled El Mously
Prepare-package-lrg
Fix Committed
Medium
Khaled El Mously
Prepare-package-lrm
Fix Committed
Medium
Khaled El Mously
Prepare-package-lrs
Fix Committed
Medium
Khaled El Mously
Prepare-package-meta
Fix Committed
Medium
Khaled El Mously
Prepare-package-signed
Fix Committed
Medium
Khaled El Mously
Promote-signing-to-proposed
Invalid
Medium
Unassigned
Promote-to-proposed
New
Medium
Ubuntu Stable Release Updates Team
Promote-to-security
New
Medium
Ubuntu Stable Release Updates Team
Promote-to-updates
New
Medium
Ubuntu Stable Release Updates Team
Regression-testing
New
Medium
Canonical Kernel Team
Security-signoff
New
Medium
Canonical Security Team
Signing-signoff
Invalid
Medium
Unassigned
Sru-review
Fix Released
Medium
Andy Whitcroft
Verification-testing
New
Medium
Canonical Kernel Team
linux-gcp (Ubuntu)
Jammy
Fix Released
Medium
Unassigned

Bug Description

This bug will contain status and test results related to a kernel source (or snap) as stated in the title.

For an explanation of the tasks and the associated workflow see:
  https://wiki.ubuntu.com/Kernel/kernel-sru-workflow

-- swm properties --
built:
  from: dd32a92f688e2b53
  route-entry: 1
delta:
  promote-to-proposed: [lrm, main, lrs, meta, signed, lrg]
issue: KSRU-4366
kernel-stable-master-bug: 1981243
packages:
  lrg: linux-restricted-generate-gcp
  lrm: linux-restricted-modules-gcp
  lrs: linux-restricted-signatures-gcp
  main: linux-gcp
  meta: linux-meta-gcp
  signed: linux-signed-gcp
phase: Packaging
phase-changed: Tuesday, 19. July 2022 05:45 UTC
reason:
  :prepare-packages: Ongoing -- building in ppa (main:B lrm:D lrg:D
    lrs:D* meta:D signed:D)
  prepare-package: Ongoing -- main package not yet fully built
  prepare-package-lrg: Ongoing -- lrg package not yet fully built
  prepare-package-lrm: Ongoing -- lrm package not yet fully built
  prepare-package-lrs: Ongoing -- lrs package not yet fully built
  prepare-package-meta: Ongoing -- meta package not yet fully built
  prepare-package-signed: Ongoing -- signed package not yet fully
    built
trackers:
  focal/linux-gcp-5.15: bug 1981216
variant: debs
versions:
  lrm: 5.15.0-1014.19
  main: 5.15.0-1014.19
  meta: 5.15.0.1014.12
  signed: 5.15.0-1014.19
~~:
  clamps:
    new-review: dd32a92f688e2b53
    self: 5.15.0-1014.19
    sru-review: dd32a92f688e2b53

Stefan Bader (smb)
tags: added: kernel-release-tracking-bug-live
description: updated
tags: added: kernel-sru-cycle-2022.07.11-1
description: updated
tags: added: kernel-sru-derivative-of-1981243
Changed in kernel-sru-workflow:
status: New → Confirmed
importance: Undecided → Medium
Changed in linux-gcp (Ubuntu Jammy):
importance: Undecided → Medium
Changed in kernel-sru-workflow:
status: Confirmed → Triaged
description: updated
Changed in kernel-sru-workflow:
status: Triaged → In Progress
Stefan Bader (smb)
description: updated
description: updated
tags: added: kernel-jira-issue-ksru-4366
description: updated
description: updated
summary: - jammy/linux-gcp: <version to be filled> -proposed tracker
+ jammy/linux-gcp: 5.15.0-1014.19 -proposed tracker
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Andy Whitcroft (apw)
tags: added: kernel-signing-bot
description: updated
description: updated
description: updated
Changed in kernel-sru-workflow:
status: In Progress → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (8.9 KiB)

This bug was fixed in the package linux-gcp - 5.15.0-1016.21

---------------
linux-gcp (5.15.0-1016.21) jammy; urgency=medium

  [ Ubuntu: 5.15.0-46.49 ]

  * CVE-2022-2585
    - SAUCE: posix-cpu-timers: Cleanup CPU timers before freeing them during exec
  * CVE-2022-2586
    - SAUCE: netfilter: nf_tables: do not allow SET_ID to refer to another table
    - SAUCE: netfilter: nf_tables: do not allow CHAIN_ID to refer to another table
    - SAUCE: netfilter: nf_tables: do not allow RULE_ID to refer to another chain
  * CVE-2022-2588
    - SAUCE: net_sched: cls_route: remove from list when handle is 0

linux-gcp (5.15.0-1015.20) jammy; urgency=medium

  * jammy/linux-gcp: 5.15.0-1015.20 -proposed tracker (LP: #1982273)

  [ Ubuntu: 5.15.0-45.48 ]

  * CVE-2022-29900 // CVE-2022-29901
    - x86/lib/atomic64_386_32: Rename things
    - x86: Prepare asm files for straight-line-speculation
    - x86: Prepare inline-asm for straight-line-speculation
    - x86/alternative: Relax text_poke_bp() constraint
    - kbuild: move objtool_args back to scripts/Makefile.build
    - x86: Add straight-line-speculation mitigation
    - kvm/emulate: Fix SETcc emulation function offsets with SLS
    - crypto: x86/poly1305 - Fixup SLS
    - objtool: Add straight-line-speculation validation
    - objtool: Fix SLS validation for kcov tail-call replacement
    - objtool: Fix objtool regression on x32 systems
    - objtool: Fix symbol creation
    - objtool: Introduce CFI hash
    - objtool: Default ignore INT3 for unreachable
    - x86, kvm: use proper ASM macros for kvm_vcpu_is_preempted
    - x86/traps: Use pt_regs directly in fixup_bad_iret()
    - x86/entry: Switch the stack after error_entry() returns
    - x86/entry: Move PUSH_AND_CLEAR_REGS out of error_entry()
    - x86/entry: Don't call error_entry() for XENPV
    - x86/entry: Remove skip_r11rcx
    - x86/realmode: build with -D__DISABLE_EXPORTS
    - x86/ibt,ftrace: Make function-graph play nice
    - x86/kvm/vmx: Make noinstr clean
    - x86/cpufeatures: Move RETPOLINE flags to word 11
    - x86/retpoline: Cleanup some #ifdefery
    - x86/retpoline: Swizzle retpoline thunk
    - x86/retpoline: Use -mfunction-return
    - x86: Undo return-thunk damage
    - x86,objtool: Create .return_sites
    - objtool: skip non-text sections when adding return-thunk sites
    - x86,static_call: Use alternative RET encoding
    - x86/ftrace: Use alternative RET encoding
    - x86/bpf: Use alternative RET encoding
    - x86/kvm: Fix SETcc emulation for return thunks
    - x86/vsyscall_emu/64: Don't use RET in vsyscall emulation
    - x86/sev: Avoid using __x86_return_thunk
    - x86: Use return-thunk in asm code
    - x86/entry: Avoid very early RET
    - objtool: Treat .text.__x86.* as noinstr
    - x86: Add magic AMD return-thunk
    - x86/bugs: Report AMD retbleed vulnerability
    - x86/bugs: Add AMD retbleed= boot parameter
    - x86/bugs: Enable STIBP for JMP2RET
    - x86/bugs: Keep a per-CPU IA32_SPEC_CTRL value
    - x86/entry: Add kernel IBRS implementation
    - x86/bugs: Optimize SPEC_CTRL MSR writes
    - x86/speculation: Add spectre_v2=ibrs option to support Kernel IBRS
    - x86/bugs: Split spectre_v2_select_m...

Read more...

Changed in linux-gcp (Ubuntu Jammy):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.