-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Aug 2021 07:50:50 +0200 Source: linux-signed-arm64 Architecture: source Version: 5.10.46+4 Distribution: sid Urgency: medium Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: linux-signed-arm64 (5.10.46+4) unstable; urgency=medium . * Sign kernel from linux 5.10.46-4 . * bpf: Introduce BPF nospec instruction for mitigating Spectre v4 (CVE-2021-34556, CVE-2021-35477) * bpf: Fix leakage due to insufficient speculative store bypass mitigation (CVE-2021-34556, CVE-2021-35477) * bpf: Remove superfluous aux sanitation on subprog rejection * Ignore ABI changes for bpf_offload_dev_create and bpf_verifier_log_write * bpf: Add kconfig knob for disabling unpriv bpf by default * init: Enable BPF_UNPRIV_DEFAULT_OFF (Closes: #990411) * linux-image: Add NEWS entry documenting that unprivileged calls to bpf() are disabled by default in Debian. * bpf: verifier: Allocate idmap scratch in verifier env * bpf: Fix pointer arithmetic mask tightening under state pruning Checksums-Sha1: 20ebe795b2af27df078182dc87edfad8051cb8bc 7240 linux-signed-arm64_5.10.46+4.dsc 3bf2161751ad70703e4f083161912d46ca6aab6c 2411704 linux-signed-arm64_5.10.46+4.tar.xz Checksums-Sha256: eab1d3f403e8d497659c98ebc7a7c7427ec52dd54288cc07a7c9f5014b58f0a7 7240 linux-signed-arm64_5.10.46+4.dsc b36d604bd74a447acf8c926dc9d82de86f091e76ad1b7278116b3b54dfe75709 2411704 linux-signed-arm64_5.10.46+4.tar.xz Files: 2f02c479fc95b14a8e808257cccf7f6a 7240 kernel optional linux-signed-arm64_5.10.46+4.dsc d98c1715a776820819a3422116985f27 2411704 kernel optional linux-signed-arm64_5.10.46+4.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfKFfvHEI+gkU+E+di0FRiLdONzYFAmEJdFsACgkQi0FRiLdO NzZScA/8CF6inz9sJJmMoXohv/1svNnbdoUKTQWqS3jKy5WdjUEIUEZ33JO4og0b c7J0d61vaVnds8vMQPhgCvaQd3nURLOnZI/iM+FMR4y+t+BcXFGl0qd4bwKhZ6bO YIbu/WILs01FnRV3bROmXZi/uqGboRJRtLBuRTzXPP2xAF6ybomI042RZFp3e0oL OAA9Mk/Y9tkAHEtqXRddzh5FxRbXLEtQ3pSizi76KfUQK5BKoViApyKd6cFTCNgE ASlm4qxJJ4BXo9wpCADRH8/jCeNVt4qGG3MQBl19nTaYWPcZ6JwcV77gUE7rTCJm Qywteg+m89kqRO27eKUd+b0JMgECtp6MDnU2qND7fERHcc/tP0SGmtwbqE2qjM7f Bj4OZXa++YMdpRgQKdM6AK7EtWUif2ZzlTS+MKX/0q/KTaMZGfKLOUJC2C6nFqQg bMnfIVbJkIi2GqWC21okUtgz9FMe1WX7EI4oxoIwXMkDIkhfctRAI2p52HrWVSSe x+4nONKvz7ZoCEf2f7sxMamYYJg/DHk6leotOUPT1zM4E40MtmjTmm3pJD3gW7SC wIDfV++FHaZGPoYpqcG230+N47somtLItkrj5ow6zdYT/L7aO/9Q4WxjYE7Inlu7 N2Y3NVEujVSbMRrvudNVBXX/+mgk8yNvOe6C061d67L57+Mp5u4= =IoVJ -----END PGP SIGNATURE-----