focal/linux-kvm: 5.4.0-1051.53 -proposed tracker
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
Kernel SRU Workflow |
Fix Released
|
Medium
|
Unassigned | |||
Automated-testing |
Fix Released
|
Medium
|
Canonical Kernel Team | |||
Boot-testing |
Fix Released
|
Medium
|
Unassigned | |||
Certification-testing |
Invalid
|
Medium
|
Unassigned | |||
Prepare-package |
Fix Released
|
Medium
|
Kelsey Steele | |||
Prepare-package-meta |
Fix Released
|
Medium
|
Kelsey Steele | |||
Prepare-package-signed |
Fix Released
|
Medium
|
Kelsey Steele | |||
Promote-signing-to-proposed |
Invalid
|
Medium
|
Unassigned | |||
Promote-to-proposed |
Fix Released
|
Medium
|
Andy Whitcroft | |||
Promote-to-security |
Fix Released
|
Medium
|
Andy Whitcroft | |||
Promote-to-updates |
Fix Released
|
Medium
|
Andy Whitcroft | |||
Regression-testing |
Fix Released
|
Medium
|
Canonical Kernel Team | |||
Security-signoff |
Fix Released
|
Medium
|
Steve Beattie | |||
Sru-review |
Fix Released
|
Medium
|
Andy Whitcroft | |||
Verification-testing |
Fix Released
|
Medium
|
Canonical Kernel Team | |||
linux-kvm (Ubuntu) | ||||||
Focal |
Fix Released
|
Medium
|
Unassigned |
Bug Description
This bug will contain status and test results related to a kernel source (or snap) as stated in the title.
For an explanation of the tasks and the associated workflow see:
https:/
-- swm properties --
boot-testing-
bugs-spammed: true
built:
route-entry: 1
delta:
promote-
- main
- signed
- meta
promote-
promote-
- signed
- meta
- main
sru-review:
- main
- signed
- meta
issue: KSRU-539
kernel-
packages:
main: linux-kvm
meta: linux-meta-kvm
signed: linux-signed-kvm
phase: Complete
phase-changed: Tuesday, 04. January 2022 23:14 UTC
proposed-
proposed-
reason: {}
synthetic:
:promote-
variant: debs
versions:
main: 5.4.0-1051.53
meta: 5.4.0.1051.50
signed: 5.4.0-1051.53
source: 5.4.0-1051.53
CVE References
tags: | added: kernel-release-tracking-bug-live |
description: | updated |
tags: | added: kernel-sru-cycle-2021.11.29-1 |
description: | updated |
tags: | added: kernel-sru-derivative-of-1952316 |
Changed in kernel-sru-workflow: | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Changed in linux-kvm (Ubuntu Focal): | |
importance: | Undecided → Medium |
Changed in kernel-sru-workflow: | |
status: | Confirmed → Triaged |
description: | updated |
Changed in kernel-sru-workflow: | |
status: | Triaged → In Progress |
tags: | added: kernel-jira-issue-ksru-539 |
description: | updated |
description: | updated |
summary: |
- focal/linux-kvm: <version to be filled> -proposed tracker + focal/linux-kvm: 5.4.0-1051.53 -proposed tracker |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
tags: | added: kernel-signing-bot |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
This bug was fixed in the package linux-kvm - 5.4.0-1051.53
---------------
linux-kvm (5.4.0-1051.53) focal; urgency=medium
* focal/linux-kvm: 5.4.0-1051.53 -proposed tracker (LP: #1952303)
* Support builtin revoked certificates (LP: #1932029) SYSTEM_ REVOCATION_ KEYS with revoked keys
- [Config] kvm: Configure CONFIG_
* Re-enable DEBUG_INFO_BTF where it was disabled (LP: #1945632) DEBUG_INFO_ BTF on all arches
- [Config] kvm: Enable CONFIG_
* Packaging resync (LP: #1786013)
- [Packaging] update Ubuntu.md
* Enable multicast in the "kvm" kernels (LP: #1946672)
- [config] Enable CONFIG_IP_MULTICAST
[ Ubuntu: 5.4.0-92.103 ]
* focal/linux: 5.4.0-92.103 -proposed tracker (LP: #1952316) dkms-versions helper dkms-versions -- update from kernel-versions (main/2021.11.29) DEBUG_INFO_ BTF on all arches exec_ctrls( ) work again n_list' to gitignore revoked- certs.pem from branch/arch certs SYSTEM_ REVOCATION_ KEYS with revoked keys hash()
* Packaging resync (LP: #1786013)
- [Packaging] resync update-
- debian/
* CVE-2021-4002
- tlb: mmu_gather: add tlb_flush_*_range APIs
- hugetlbfs: flush TLBs correctly after huge_pmd_unshare
* Re-enable DEBUG_INFO_BTF where it was disabled (LP: #1945632)
- [Config] Enable CONFIG_
* Focal linux-azure: Vm crash on Dv5/Ev5 (LP: #1950462)
- KVM: VMX: eVMCS: make evmcs_sanitize_
- jump_label: Fix usage in module __init
* Support builtin revoked certificates (LP: #1932029)
- Revert "UBUNTU: SAUCE: (lockdown) Make get_cert_list() not complain about
cert lists that aren't present."
- integrity: Move import of MokListRT certs to a separate routine
- integrity: Load certs from the EFI MOK config table
- certs: Add ability to preload revocation certs
- integrity: Load mokx variables into the blacklist keyring
- certs: add 'x509_revocatio
- SAUCE: Dump stack when X.509 certificates cannot be loaded
- [Packaging] build canonical-
- [Packaging] Revoke 2012 UEFI signing certificate as built-in
- [Config] Configure CONFIG_
* Support importing mokx keys into revocation list from the mok table
(LP: #1928679)
- efi: Support for MOK variable config table
- efi: mokvar-table: fix some issues in new code
- efi: mokvar: add missing include of asm/early_ioremap.h
- efi/mokvar: Reserve the table only if it is in boot services data
- SAUCE: integrity: add informational messages when revoking certs
* Support importing mokx keys into revocation list from the mok table
(LP: #1928679) // CVE-2020-26541 when certificates are revoked via
MokListXRT.
- SAUCE: integrity: Load mokx certs from the EFI MOK config table
* Focal update: v5.4.157 upstream stable release (LP: #1951883)
- ARM: 9133/1: mm: proc-macros: ensure *_tlb_fns are 4B aligned
- ARM: 9134/1: remove duplicate memcpy() definition
- ARM: 9139/1: kprobes: fix arch_init_kprobes() prototype
- ARM: 9141/1: only warn about XIP address when not compile testing
- ipv6: use siphash in rt6_exception_
- ipv4: use siphash instead of Jenkins in fnhe_hashfun()
- usbnet: sanity check for maxpacket
- usbnet: fix error return code...