-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Aug 2021 07:50:50 +0200 Source: linux-signed-i386 Architecture: source Version: 5.10.46+4 Distribution: sid Urgency: medium Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: linux-signed-i386 (5.10.46+4) unstable; urgency=medium . * Sign kernel from linux 5.10.46-4 . * bpf: Introduce BPF nospec instruction for mitigating Spectre v4 (CVE-2021-34556, CVE-2021-35477) * bpf: Fix leakage due to insufficient speculative store bypass mitigation (CVE-2021-34556, CVE-2021-35477) * bpf: Remove superfluous aux sanitation on subprog rejection * Ignore ABI changes for bpf_offload_dev_create and bpf_verifier_log_write * bpf: Add kconfig knob for disabling unpriv bpf by default * init: Enable BPF_UNPRIV_DEFAULT_OFF (Closes: #990411) * linux-image: Add NEWS entry documenting that unprivileged calls to bpf() are disabled by default in Debian. * bpf: verifier: Allocate idmap scratch in verifier env * bpf: Fix pointer arithmetic mask tightening under state pruning Checksums-Sha1: 4a41c77c6996ddcf1cfd54e5b28f6e666074d7e1 14039 linux-signed-i386_5.10.46+4.dsc d9e30be3f7137ce9d29f7e6df582303faaf55964 3613800 linux-signed-i386_5.10.46+4.tar.xz Checksums-Sha256: 8c6194edcc5d89032392266830f973ab22e07bc9a6a887a22b9dd7321da3cba3 14039 linux-signed-i386_5.10.46+4.dsc 8c105a7da96681b8ff6ef8a75a84bf7b52b029dc6a82ca416587252f52b13165 3613800 linux-signed-i386_5.10.46+4.tar.xz Files: 1a7124ac1254654b06a2e461919129b9 14039 kernel optional linux-signed-i386_5.10.46+4.dsc 4653239c8297bddfb566c3c76fbe1ed5 3613800 kernel optional linux-signed-i386_5.10.46+4.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfKFfvHEI+gkU+E+di0FRiLdONzYFAmEJnHEACgkQi0FRiLdO NzZ6Zg/8CkG6jvpgqbXR00mFKqj2F3Ttr/B+0Ln9g/FI7ipD97Ni6yjOGze17CYy WsWsyYDNLAGWiNcfGqyvWa4njzg1Ffv0Hw3vlfebDxlaKWCxD6EEWu/FQdD6Alef zH3pMTc03sXcQj/gqlV6edkeiKPXOGAlgF69/u8yk9dvgc84mjE5M57+WhD8akvl IirGB523FXital1Tk8B/5MDUQLq2W2S4EGXIQPnRVFtZHczGEHi+tx/5+qmhb3xe PtwOJG3pWFITSzfFoKX8WVt/e6stPwJDD/3EvN14+aificqUUhv8OOFohcTxiAgw Vc+4zP0isRq9ANWdnTIEClqKNqUWVhx+vOqEHDgrDKD1j23Q23E7ZBobY9yd+lDo xfeM4T7/OFJCv2G7/6M1fl2gT2qLgHiQwk97Ep4fvPdfXZSySHYU56Xjcz3tvVna 2cnLyO0O21TI1wP/EtW5UoFGGdVxB3OKo93wiSgjo5Xf47Uav81mox9xsxAZl5Mv oKIymkvp9UMKCLRd1Ol6t61Bqegp2JZmQwLYhAbDVJEd2+Revy3Gn6/z+OEhS2QA H3b3I//AxkD9clMxLnk3wHnjtq9PMjVtIyHRIdhbKHL1/mLDV1QJJQtmRRLd+c2+ 91ZSLEq9t4+0VCRNhTwn5HnTDcuN7xIMJppOR01P82AT7OhT/Ic= =tFsL -----END PGP SIGNATURE-----