-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 08 Aug 2023 04:35:25 +0200 Source: linux-signed-i386 Architecture: source Version: 4.19.289+2 Distribution: buster-security Urgency: high Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org> Changed-By: Ben Hutchings <benh@debian.org> Changes: linux-signed-i386 (4.19.289+2) buster-security; urgency=high . * Sign kernel from linux 4.19.289-2 . * [x86] Add mitigations for Gather Data Sampling (GDS) (CVE-2022-40982) - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - ARM: cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - init: Invoke arch_cpu_finalize_init() earlier - init, x86: Move mem_encrypt_init() into arch_cpu_finalize_init() - x86/fpu: Remove cpuinfo argument from init functions - x86/fpu: Mark init functions __init - x86/fpu: Move FPU initialization into arch_cpu_finalize_init() - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM - x86/xen: Fix secondary processors' FPU initialization - Documentation/x86: Fix backwards on/off logic about YMM support * [x86] cpu: Avoid ABI change for GDS mitigations Checksums-Sha1: 5e74bd6d86088fc380d1e2f3217eace81a3c069c 13506 linux-signed-i386_4.19.289+2.dsc 9a36a44301e5faf5ef036844be9c6fa41488c5c5 3565828 linux-signed-i386_4.19.289+2.tar.xz Checksums-Sha256: 117b44dbf3cdb31ec4f971a338a0d5c1d84e8fb7e6c601330fc842f74acf032a 13506 linux-signed-i386_4.19.289+2.dsc c12e031195d3df265300f4ecb60d31f3aa3a4ef1eb2b134dd4c97dacfd275d86 3565828 linux-signed-i386_4.19.289+2.tar.xz Files: e779dbd728e7acb101b6456721235cbe 13506 kernel optional linux-signed-i386_4.19.289+2.dsc a1fb88afc28736aca6a91b9d42d0bf41 3565828 kernel optional linux-signed-i386_4.19.289+2.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfKFfvHEI+gkU+E+di0FRiLdONzYFAmTUaQAACgkQi0FRiLdO NzaWJA/9F9oqMjKbuSngymC3VNHbiz2i33I7nB4fWJS7weF4uDVB4IDDeZyXZIGZ ZhPtDZxwC+wkefbq2NjwdLrJiH27n6Ix1DXxLYGH+ajM3sARyK9hM8pqd4YU8o4a F0BIMHA/Zn2+FGKgT4eiVl8+emF3BGSLreByN8SXWLjStcucGNy8PNRTBNI1sL3c vSVp9QmOF4y5D73s/ghBalhdt1re3iYAVP4MiLxVb1ujvYIRuyIKiyIHchC3p9WZ g0YBQq5q+qL/JJfdjtagO4wgZF3h2DcKCGLEVVF+Qwnj8LtfYRbSjHWMKOiSch3K QSajV5zGC884kbt9INr0en58AIzyJPd3pnGmTmBlPLq5oNs2cYin//iTgq9u0/d5 IQduGCN7sOeGtX1fInHfQcGm64781MoBYnKg/3sEJ8qZ1swnv8pamDrf6fblCvwv g2hWEqogmbqA+l2Bk1LJrOr9EgJNDM2dQbDBVDOb56XQRdpBqibSZW7Bgx4G6QwT YWqDUQVnKtiSKyZs74LBMaf+8EE/ADwhGsAjeiwt0tQpuTIg5B62yk033YAOPlAp 1v/FWset2mQmOGJyEz2n6o1cSMJBsXf0FVVRYNiR0Bsst7mJKpvDLfZbAbmys2nt Z1Oe0wCY8EZQ0+Ub0n6uqkZ4F0iQmxnbeSfDn8iCSkRA70gpyKI= =UPi2 -----END PGP SIGNATURE-----