-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 19 Dec 2021 00:20:10 +0100 Source: linux-signed-arm64 Architecture: source Version: 5.15.5+2 Distribution: sid Urgency: medium Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: linux-signed-arm64 (5.15.5+2) unstable; urgency=medium . * Sign kernel from linux 5.15.5-2 . * atlantic: Fix OOB read and write in hw_atl_utils_fw_rpc_wait (CVE-2021-43975) * fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) * USB: gadget: detect too-big endpoint 0 requests (CVE-2021-39685) * USB: gadget: zero allocate endpoint 0 buffers (CVE-2021-39685) * [x86] Revert "drm/i915: Implement Wa_1508744258" (Closes: #1001128) * nfsd: fix use-after-free due to delegation race (Closes: #988044) * bpf: Fix kernel address leakage in atomic fetch * bpf: Fix signed bounds propagation after mov32 * bpf: Make 32->64 bounds propagation slightly more robust * bpf: Fix kernel address leakage in atomic cmpxchg's r0 aux reg Checksums-Sha1: a57e8028a87a4e78722e6b4cc7772a3b90c3200e 7232 linux-signed-arm64_5.15.5+2.dsc 4078bb374a4e888ea65fcb162bddc42e874c2925 2508488 linux-signed-arm64_5.15.5+2.tar.xz Checksums-Sha256: 3028fc0e92caf2eacc7833c58c19400b5843291bb8261752a96e61803901f3d6 7232 linux-signed-arm64_5.15.5+2.dsc e338b94d828e0d50af885835c14f1cbef3bb069b8e4dc8f1c8edda5b87127172 2508488 linux-signed-arm64_5.15.5+2.tar.xz Files: a22b45804c9a6f27ce86d31306ac848c 7232 kernel optional linux-signed-arm64_5.15.5+2.dsc 4e2b344954ae544ec7ec18fde2a72f10 2508488 kernel optional linux-signed-arm64_5.15.5+2.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfKFfvHEI+gkU+E+di0FRiLdONzYFAmHDUm0ACgkQi0FRiLdO NzYj0w//dxCLu5hdBCseWkmxf5XmHJ2XkYVM1Isc2AHLXOD/Qxsyx4lxqwR6P2O4 OtaHnKwSBkDp/d2r8Y+s6GSZQ7j6RIlLVH9nrhz33olZTn6dm0/pTFVcAjXICJGe EFf2g/FAHgdLROnobzA1zTpWMHqLoLynBNUMaVZym4y9gJ+d1/eMq3Iem/1qYqXh lAV2BRAJNROvncTXK5oQ7i461B378P9Fj+tEtLPbn1RJv3dsqg5TSWkwYMZ+Ch6J jxKoRm96UX3TqSigP6qt6kI/lToquGwv+64Hp9aC4IIEqPj1CaIcpf1b1YSCqHvq lOetd0C1Dry44JpejSjgnQ0tBlMjJreQN0IXubbUV2vB+ViJQV9eNp+rskuR815+ kamUxWnOu/WeP+x124rZG8b3k/gWNPyLkBoAx7Gn/OOnrgRNhMXW88gLBlwqe0ee gvAD7XG6Vid66f692k+5YOFSieHasoRlPsl0nm0H11sG2iqdIco8eoLV/IwIw4kc r0hPUb7aPkSP5h4auAWUdbt8Lf1QxXB1DnQJfAjvZiiYgS37fYBuc6XAYLXRLjsb P5944BcfujX0khpr44HWi+HXJViaXhV9RAxyG5thbE3sAUB+ib65nsKdgZF2mQi9 u2JZ35QjGuqasIex42ijaZ3t8jaJo+ftAhlN4JNppw1zBo6jZvo= =HGvZ -----END PGP SIGNATURE-----