-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 14 May 2019 17:34:37 +0100 Source: linux-signed-amd64 Binary: kernel-image-4.19.0-5-amd64-di nic-modules-4.19.0-5-amd64-di nic-wireless-modules-4.19.0-5-amd64-di nic-shared-modules-4.19.0-5-amd64-di serial-modules-4.19.0-5-amd64-di usb-serial-modules-4.19.0-5-amd64-di ppp-modules-4.19.0-5-amd64-di pata-modules-4.19.0-5-amd64-di cdrom-core-modules-4.19.0-5-amd64-di firewire-core-modules-4.19.0-5-amd64-di scsi-core-modules-4.19.0-5-amd64-di scsi-modules-4.19.0-5-amd64-di scsi-nic-modules-4.19.0-5-amd64-di loop-modules-4.19.0-5-amd64-di btrfs-modules-4.19.0-5-amd64-di ext4-modules-4.19.0-5-amd64-di isofs-modules-4.19.0-5-amd64-di jfs-modules-4.19.0-5-amd64-di xfs-modules-4.19.0-5-amd64-di fat-modules-4.19.0-5-amd64-di md-modules-4.19.0-5-amd64-di multipath-modules-4.19.0-5-amd64-di usb-modules-4.19.0-5-amd64-di usb-storage-modules-4.19.0-5-amd64-di pcmcia-storage-modules-4.19.0-5-amd64-di fb-modules-4.19.0-5-amd64-di input-modules-4.19.0-5-amd64-di event-modules-4.19.0-5-amd64-di mouse-modules-4.19.0-5-amd64-di nic-pcmcia-modules-4.19.0-5-amd64-di pcmcia-modules-4.19.0-5-amd64-di nic-usb-modules-4.19.0-5-amd64-di sata-modules-4.19.0-5-amd64-di acpi-modules-4.19.0-5-amd64-di i2c-modules-4.19.0-5-amd64-di crc-modules-4.19.0-5-amd64-di crypto-modules-4.19.0-5-amd64-di crypto-dm-modules-4.19.0-5-amd64-di efi-modules-4.19.0-5-amd64-di ata-modules-4.19.0-5-amd64-di mmc-core-modules-4.19.0-5-amd64-di mmc-modules-4.19.0-5-amd64-di nbd-modules-4.19.0-5-amd64-di squashfs-modules-4.19.0-5-amd64-di speakup-modules-4.19.0-5-amd64-di uinput-modules-4.19.0-5-amd64-di sound-modules-4.19.0-5-amd64-di compress-modules-4.19.0-5-amd64-di udf-modules-4.19.0-5-amd64-di fuse-modules-4.19.0-5-amd64-di mtd-core-modules-4.19.0-5-amd64-di linux-image-4.19.0-5-amd64 linux-image-4.19.0-5-cloud-amd64 linux-image-4.19.0-5-rt-amd64 Architecture: source Version: 4.19.37+2 Distribution: sid Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Ben Hutchings <ben@decadent.org.uk> Description: acpi-modules-4.19.0-5-amd64-di - ACPI support modules (udeb) ata-modules-4.19.0-5-amd64-di - ATA disk modules (udeb) btrfs-modules-4.19.0-5-amd64-di - BTRFS filesystem support (udeb) cdrom-core-modules-4.19.0-5-amd64-di - CDROM support (udeb) compress-modules-4.19.0-5-amd64-di - lzo modules (udeb) crc-modules-4.19.0-5-amd64-di - CRC modules (udeb) crypto-dm-modules-4.19.0-5-amd64-di - devicemapper crypto module (udeb) crypto-modules-4.19.0-5-amd64-di - crypto modules (udeb) efi-modules-4.19.0-5-amd64-di - EFI modules (udeb) event-modules-4.19.0-5-amd64-di - Event support (udeb) ext4-modules-4.19.0-5-amd64-di - ext2/ext3/ext4 filesystem support (udeb) fat-modules-4.19.0-5-amd64-di - FAT filesystem support (udeb) fb-modules-4.19.0-5-amd64-di - Frame buffer support (udeb) firewire-core-modules-4.19.0-5-amd64-di - Core FireWire drivers (udeb) fuse-modules-4.19.0-5-amd64-di - FUSE modules (udeb) i2c-modules-4.19.0-5-amd64-di - i2c support modules (udeb) input-modules-4.19.0-5-amd64-di - Input devices support (udeb) isofs-modules-4.19.0-5-amd64-di - ISOFS filesystem support (udeb) jfs-modules-4.19.0-5-amd64-di - JFS filesystem support (udeb) kernel-image-4.19.0-5-amd64-di - Linux kernel image and core modules for the Debian installer (udeb) linux-image-4.19.0-5-amd64 - ${unsigned:DescriptionShort} (signed) linux-image-4.19.0-5-cloud-amd64 - ${unsigned:DescriptionShort} (signed) linux-image-4.19.0-5-rt-amd64 - ${unsigned:DescriptionShort} (signed) loop-modules-4.19.0-5-amd64-di - Loopback filesystem support (udeb) md-modules-4.19.0-5-amd64-di - RAID and LVM support (udeb) mmc-core-modules-4.19.0-5-amd64-di - MMC/SD/SDIO core modules (udeb) mmc-modules-4.19.0-5-amd64-di - MMC/SD card modules (udeb) mouse-modules-4.19.0-5-amd64-di - Mouse support (udeb) mtd-core-modules-4.19.0-5-amd64-di - MTD core (udeb) multipath-modules-4.19.0-5-amd64-di - Multipath support (udeb) nbd-modules-4.19.0-5-amd64-di - Network Block Device modules (udeb) nic-modules-4.19.0-5-amd64-di - NIC drivers (udeb) nic-pcmcia-modules-4.19.0-5-amd64-di - Common PCMCIA NIC drivers (udeb) nic-shared-modules-4.19.0-5-amd64-di - Shared NIC drivers (udeb) nic-usb-modules-4.19.0-5-amd64-di - USB NIC drivers (udeb) nic-wireless-modules-4.19.0-5-amd64-di - Wireless NIC drivers (udeb) pata-modules-4.19.0-5-amd64-di - PATA drivers (udeb) pcmcia-modules-4.19.0-5-amd64-di - Common PCMCIA drivers (udeb) pcmcia-storage-modules-4.19.0-5-amd64-di - PCMCIA storage drivers (udeb) ppp-modules-4.19.0-5-amd64-di - PPP drivers (udeb) sata-modules-4.19.0-5-amd64-di - SATA drivers (udeb) scsi-core-modules-4.19.0-5-amd64-di - Core SCSI subsystem (udeb) scsi-modules-4.19.0-5-amd64-di - SCSI drivers (udeb) scsi-nic-modules-4.19.0-5-amd64-di - SCSI drivers for converged NICs (udeb) serial-modules-4.19.0-5-amd64-di - Serial drivers (udeb) sound-modules-4.19.0-5-amd64-di - sound support (udeb) speakup-modules-4.19.0-5-amd64-di - speakup modules (udeb) squashfs-modules-4.19.0-5-amd64-di - squashfs modules (udeb) udf-modules-4.19.0-5-amd64-di - UDF modules (udeb) uinput-modules-4.19.0-5-amd64-di - uinput support (udeb) usb-modules-4.19.0-5-amd64-di - USB support (udeb) usb-serial-modules-4.19.0-5-amd64-di - USB serial drivers (udeb) usb-storage-modules-4.19.0-5-amd64-di - USB storage support (udeb) xfs-modules-4.19.0-5-amd64-di - XFS filesystem support (udeb) Changes: linux-signed-amd64 (4.19.37+2) unstable; urgency=high . * Sign kernel from linux 4.19.37-2 . * debian/bin: Fix Python static checker regressions (Closes: #928618) * Clean up speculation mitigations: - Documentation/l1tf: Fix small spelling typo - x86/cpu: Sanitize FAM6_ATOM naming - kvm: x86: Report STIBP on GET_SUPPORTED_CPUID - x86/msr-index: Cleanup bit defines - x86/speculation: Consolidate CPU whitelists - Documentation: Move L1TF to separate directory - cpu/speculation: Add 'mitigations=' cmdline option - x86/speculation: Support 'mitigations=' cmdline option - powerpc/speculation: Support 'mitigations=' cmdline option - s390/speculation: Support 'mitigations=' cmdline option - x86/speculation/mds: Add 'mitigations=' support for MDS * [x86] Mitigate Microarchitectural Data Sampling (MDS) vulnerabilities (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091): - x86/speculation/mds: Add basic bug infrastructure for MDS - x86/speculation/mds: Add BUG_MSBDS_ONLY - x86/kvm: Expose X86_FEATURE_MD_CLEAR to guests - x86/speculation/mds: Add mds_clear_cpu_buffers() - x86/speculation/mds: Clear CPU buffers on exit to user - x86/kvm/vmx: Add MDS protection when L1D Flush is not active - x86/speculation/mds: Conditionally clear CPU buffers on idle entry - x86/speculation/mds: Add mitigation control for MDS - x86/speculation/mds: Add sysfs reporting for MDS - x86/speculation/mds: Add mitigation mode VMWERV - Documentation: Add MDS vulnerability documentation - x86/speculation/mds: Add mds=full,nosmt cmdline option - x86/speculation: Move arch_smt_update() call to after mitigation decisions - x86/speculation/mds: Add SMT warning message - x86/speculation/mds: Fix comment - x86/speculation/mds: Print SMT vulnerable on MSBDS with mitigations off - x86/mds: Add MDSUM variant to the MDS documentation - Documentation: Correct the possible MDS sysfs values - x86/speculation/mds: Fix documentation typo * [x86] linux-cpupower: Update CPPFLAGS for change in <asm/msr-index.h> Checksums-Sha1: 2e4a84bb1ba8788ae6b7b2ce71d4543cce66d76e 7809 linux-signed-amd64_4.19.37+2.dsc 76bc1f5577b41f41d6e215bbadb61f89d96fb80d 2415676 linux-signed-amd64_4.19.37+2.tar.xz Checksums-Sha256: 8ac0d87ec5e0fea0851c2cf09471af6740fac70e7d42a08be341d82d50756afa 7809 linux-signed-amd64_4.19.37+2.dsc 44b028ce9386bb5b7872cc41ea2a1a5102fa307724ac751ad6d90ceb2bc501c5 2415676 linux-signed-amd64_4.19.37+2.tar.xz Files: 750d86b23852085ef65699a18df6cb96 7809 kernel optional linux-signed-amd64_4.19.37+2.dsc b882fd9e28e0aac337599feab577d4be 2415676 kernel optional linux-signed-amd64_4.19.37+2.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE8nXL3e4u3Tgu6Vp6qgZoiu+K+NUFAlzccnoACgkQqgZoiu+K +NUVNw//SIqYCdn0bxNxHNdl73wM+Ilekn8BYFYVYDXtnIfpuxCBVImbzJ+6f3oV KfeFH2JlAkoeIxKZWBUBVY7Eil3bXeZ7DJoJeJBB1HHfAbjV8Gm4scMKqDHHYOyl PqY9b55lWtEDzCF2Uq5IUgs60ezZlDwWDPdIf1JwOzVxI0Elhs2jzXJbjNr1C7IE vNkj4vJcxtfRs9GzKlVcOCZGciMH77QS4hFvEjEqcai2IWg8A7vpty8vypS2fWlA d4T7MBIAiG2gFsVLejvHeI3zxu5vsS10PqziAH0e5/5hyql2F1xPt5ctd3yepIIl eeWn5JhsenVtJGVjlfU64Go8popxIYu/Vec09PojMtaySyAJ9M+1u0hjW0Mm67fo nT2Ft2t6O0ycYxZ0tFtfCeKIXOakr2cm95nvdj6acJxCxk8RU0oxjlNPyoMekND7 8KI1WFZ3Cf7LKcqfBSdkcJcW9ayUywNH86Uc0KWVjBXTX1qAAcRJ2KxDdEfQBEbl wxrRoyupXTXDd2SRaZZD+FI23QJTzE9+Lm1gigpzlWRfGuWqTHuF8DIm3Gk7Gtn3 AF7j7RMT09g5glwSzPz6WXbB1YUEY9HmwPg/5GV1lqDfg5+VA7v8yA/Z9IqIT1Bn UaI/WtXHCgehStQExLCXNhZiEmwykMi9BBHW+yGVJLx+e+AlqzI= =DLoi -----END PGP SIGNATURE-----