[ubuntu/xenial-proposed] linux-azure_4.13.0-1013.16_amd64.tar.gz - (Accepted)

Marcelo Henrique Cerri marcelo.cerri at canonical.com
Fri Mar 30 12:52:59 UTC 2018


linux-azure (4.13.0-1013.16) xenial; urgency=medium

  * linux-azure: 4.13.0-1013.16 -proposed tracker (LP: #1755773)

  * ubuntu/xr-usb-serial didn't get built in zesty and artful (LP: #1733281)
    - ubuntu: Only build ubuntu/xr-usb-serial when USB is enabled

  [ Ubuntu: 4.13.0-38.43 ]

  * linux: 4.13.0-38.43 -proposed tracker (LP: #1755762)
  * Servers going OOM after updating kernel from 4.10 to 4.13 (LP: #1748408)
    - i40e: Fix memory leak related filter programming status
    - i40e: Add programming descriptors to cleaned_count
  * [SRU] Lenovo E41 Mic mute hotkey is not responding (LP: #1753347)
    - platform/x86: ideapad-laptop: Increase timeout to wait for EC answer
  * fails to dump with latest kpti fixes (LP: #1750021)
    - kdump: write correct address of mem_section into vmcoreinfo
  * headset mic can't be detected on two Dell machines (LP: #1748807)
    - ALSA: hda/realtek - Support headset mode for ALC215/ALC285/ALC289
    - ALSA: hda - Fix headset mic detection problem for two Dell machines
    - ALSA: hda - Fix a wrong FIXUP for alc289 on Dell machines
  * CIFS SMB2/SMB3 does not work for domain based DFS (LP: #1747572)
    - CIFS: make IPC a regular tcon
    - CIFS: use tcon_ipc instead of use_ipc parameter of SMB2_ioctl
    - CIFS: dump IPC tcon in debug proc file
  * i2c-thunderx: erroneous error message "unhandled state: 0" (LP: #1754076)
    - i2c: octeon: Prevent error message on bus error
  * hisi_sas: Add disk LED support (LP: #1752695)
    - scsi: hisi_sas: directly attached disk LED feature for v2 hw
  * EDAC, sb_edac: Backport 1 patch to Ubuntu 17.10 (Fix missing DIMM sysfs
    entries with KNL SNC2/SNC4 mode) (LP: #1743856)
    - EDAC, sb_edac: Fix missing DIMM sysfs entries with KNL SNC2/SNC4 mode
  * [regression] Colour banding and artefacts appear system-wide on an Asus
    Zenbook UX303LA with Intel HD 4400 graphics (LP: #1749420)
    - drm/edid: Add 6 bpc quirk for CPT panel in Asus UX303LA
  * DVB Card with SAA7146 chipset not working (LP: #1742316)
    - vmalloc: fix __GFP_HIGHMEM usage for vmalloc_32 on 32b systems
  * [Asus UX360UA] battery status in unity-panel is not changing when battery is
    being charged (LP: #1661876) // AC adapter status not detected on Asus
    ZenBook UX410UAK (LP: #1745032)
    - ACPI / battery: Add quirk for Asus UX360UA and UX410UAK
  * ASUS UX305LA - Battery state not detected correctly (LP: #1482390)
    - ACPI / battery: Add quirk for Asus GL502VSK and UX305LA
  * support thunderx2 vendor pmu events (LP: #1747523)
    - perf pmu: Extract function to get JSON alias map
    - perf pmu: Pass pmu as a parameter to get_cpuid_str()
    - perf tools arm64: Add support for get_cpuid_str function.
    - perf pmu: Add helper function is_pmu_core to detect PMU CORE devices
    - perf vendor events arm64: Add ThunderX2 implementation defined pmu core
      events
    - perf pmu: Add check for valid cpuid in perf_pmu__find_map()
  * lpfc.ko module doesn't work (LP: #1746970)
    - scsi: lpfc: Fix loop mode target discovery
  * Ubuntu 17.10 crashes on vmalloc.c (LP: #1739498)
    - powerpc/mm/book3s64: Make KERN_IO_START a variable
    - powerpc/mm/slb: Move comment next to the code it's referring to
    - powerpc/mm/hash64: Make vmalloc 56T on hash
  * ethtool -p fails to light NIC LED on HiSilicon D05 systems (LP: #1748567)
    - net: hns: add ACPI mode support for ethtool -p
  * CVE-2017-17807
    - KEYS: add missing permission check for request_key() destination
  * [Artful SRU] Fix capsule update regression (LP: #1746019)
    - efi/capsule-loader: Reinstate virtual capsule mapping
  * [Artful/Bionic] [Config] enable EDAC_GHES for ARM64 (LP: #1747746)
    - Ubuntu: [Config] enable EDAC_GHES for ARM64
  * linux-tools: perf incorrectly linking libbfd (LP: #1748922)
    - SAUCE: tools -- add ability to disable libbfd
    - [Packaging] correct disablement of libbfd
  * Cherry pick c96f5471ce7d for delayacct fix (LP: #1747769)
    - delayacct: Account blkio completion on the correct task
  * Error in CPU frequency reporting when nominal and min pstates are same
    (cpufreq) (LP: #1746174)
    - cpufreq: powernv: Dont assume distinct pstate values for nominal and pmin
  * retpoline abi files are empty on i386 (LP: #1751021)
    - [Packaging] retpoline-extract -- instantiate retpoline files for i386
    - [Packaging] final-checks -- sanity checking ABI contents
    - [Packaging] final-checks -- check for empty retpoline files
  * [P9,Power NV][WSP][Ubuntu 1804] : "Kernel access of bad area " when grouping
    different pmu events using perf fuzzer . (perf:) (LP: #1746225)
    - powerpc/perf: Fix oops when grouping different pmu events
  * bnx2x_attn_int_deasserted3:4323 MC assert! (LP: #1715519) //
    CVE-2018-1000026
    - net: create skb_gso_validate_mac_len()
    - bnx2x: disable GSO where gso_size is too big for hardware
  * Ubuntu16.04.03: ISAv3 initialize MMU registers before setting partition
    table (LP: #1736145)
    - powerpc/64s: Initialize ISAv3 MMU registers before setting partition table
  * powerpc/powernv: Flush console before platform error reboot (LP: #1735159)
    - powerpc/powernv: Flush console before platform error reboot
  * Touchpad stops working after a few seconds in Lenovo ideapad 320
    (LP: #1732056)
    - pinctrl/amd: fix masking of GPIO interrupts
  * [Artful][Wyse 3040] System hang when trying to enable an offlined CPU core
    (LP: #1736393)
    - SAUCE: drm/i915:Don't set chip specific data
    - SAUCE: drm/i915: make previous commit affects Wyse 3040 only
  * ppc64el: Do not call ibm,os-term on panic (LP: #1736954)
    - powerpc: Do not call ppc_md.panic in fadump panic notifier
  * Artful update to 4.13.16 stable release (LP: #1744213)
    - tcp_nv: fix division by zero in tcpnv_acked()
    - net: vrf: correct FRA_L3MDEV encode type
    - tcp: do not mangle skb->cb[] in tcp_make_synack()
    - net: systemport: Correct IPG length settings
    - netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed
    - l2tp: don't use l2tp_tunnel_find() in l2tp_ip and l2tp_ip6
    - bonding: discard lowest hash bit for 802.3ad layer3+4
    - net: cdc_ether: fix divide by 0 on bad descriptors
    - net: qmi_wwan: fix divide by 0 on bad descriptors
    - qmi_wwan: Add missing skb_reset_mac_header-call
    - net: usb: asix: fill null-ptr-deref in asix_suspend
    - tcp: gso: avoid refcount_t warning from tcp_gso_segment()
    - tcp: fix tcp_fastretrans_alert warning
    - vlan: fix a use-after-free in vlan_device_event()
    - net/mlx5: Cancel health poll before sending panic teardown command
    - net/mlx5e: Set page to null in case dma mapping fails
    - af_netlink: ensure that NLMSG_DONE never fails in dumps
    - vxlan: fix the issue that neigh proxy blocks all icmpv6 packets
    - net: cdc_ncm: GetNtbFormat endian fix
    - fealnx: Fix building error on MIPS
    - net/sctp: Always set scope_id in sctp_inet6_skb_msgname
    - ima: do not update security.ima if appraisal status is not INTEGRITY_PASS
    - serial: omap: Fix EFR write on RTS deassertion
    - serial: 8250_fintek: Fix finding base_port with activated SuperIO
    - tpm-dev-common: Reject too short writes
    - rcu: Fix up pending cbs check in rcu_prepare_for_idle
    - ocfs2: fix cluster hang after a node dies
    - ocfs2: should wait dio before inode lock in ocfs2_setattr()
    - ipmi: fix unsigned long underflow
    - mm/page_alloc.c: broken deferred calculation
    - mm/page_ext.c: check if page_ext is not prepared
    - x86/cpu/amd: Derive L3 shared_cpu_map from cpu_llc_shared_mask
    - coda: fix 'kernel memory exposure attempt' in fsync
    - Linux 4.13.16
  * Artful update to 4.13.15 stable release (LP: #1744212)
    - media: imon: Fix null-ptr-deref in imon_probe
    - media: dib0700: fix invalid dvb_detach argument
    - crypto: dh - Fix double free of ctx->p
    - crypto: dh - Don't permit 'p' to be 0
    - crypto: dh - Don't permit 'key' or 'g' size longer than 'p'
    - USB: early: Use new USB product ID and strings for DbC device
    - USB: usbfs: compute urb->actual_length for isochronous
    - USB: Add delay-init quirk for Corsair K70 LUX keyboards
    - usb: gadget: f_fs: Fix use-after-free in ffs_free_inst
    - USB: serial: metro-usb: stop I/O after failed open
    - USB: serial: Change DbC debug device binding ID
    - USB: serial: qcserial: add pid/vid for Sierra Wireless EM7355 fw update
    - USB: serial: garmin_gps: fix I/O after failed probe and remove
    - USB: serial: garmin_gps: fix memory leak on probe errors
    - x86/MCE/AMD: Always give panic severity for UC errors in kernel context
    - platform/x86: peaq-wmi: Add DMI check before binding to the WMI interface
    - platform/x86: peaq_wmi: Fix missing terminating entry for peaq_dmi_table
    - HID: cp2112: add HIDRAW dependency
    - HID: wacom: generic: Recognize WACOM_HID_WD_PEN as a type of pen collection
    - staging: wilc1000: Fix bssid buffer offset in Txq
    - staging: ccree: fix 64 bit scatter/gather DMA ops
    - staging: greybus: spilib: fix use-after-free after deregistration
    - staging: vboxvideo: Fix reporting invalid suggested-offset-properties
    - staging: rtl8188eu: Revert 4 commits breaking ARP
    - Linux 4.13.15
  * time drifting on linux-hwe kernels (LP: #1744988)
    - x86/tsc: Future-proof native_calibrate_tsc()
    - x86/tsc: Fix erroneous TSC rate on Skylake Xeon
    - x86/tsc: Print tsc_khz, when it differs from cpu_khz
  * Please backport vmd suspend/resume patches to 16.04 hwe (LP: #1745508)
    - PCI: vmd: Free up IRQs on suspend path
  * CVE-2017-17448
    - netfilter: nfnetlink_cthelper: Add missing permission checks
  * Dell XPS 13 9360 bluetooth (Atheros) won't connect after resume
    (LP: #1744712)
    - Bluetooth: btusb: Restore QCA Rome suspend/resume fix with a "rewritten"
      version
  * [SRU] TrackPoint: middle button doesn't work on TrackPoint-compatible
    device. (LP: #1746002)
    - Input: trackpoint - force 3 buttons if 0 button is reported
  * TB16 dock ethernet corrupts data with hw checksum silently failing
    (LP: #1729674)
    - r8152: disable RX aggregation on Dell TB16 dock
  * [Artful] Realtek ALC225: 2 secs noise when a headset plugged in
    (LP: #1744058)
    - Revert "UBUNTU: SAUCE: ALSA: hda/realtek - Add support headset mode for DELL
      WYSE"
    - SAUCE: ALSA: hda/realtek - Add support headset mode for DELL WYSE
    - ALSA: hda/realtek - update ALC225 depop optimize
  * [A] skb leak in vhost_net / tun / tap (LP: #1738975)
    - vhost: fix skb leak in handle_rx()
    - tap: free skb if flags error
    - tun: free skb in early errors
  * Commit d9018976cdb6 missing in Kernels <4.14.x preventing lasting fix of
    Intel SPI bug on certain serial flash (LP: #1742696)
    - mfd: lpc_ich: Do not touch SPI-NOR write protection bit on Haswell/Broadwell
    - spi-nor: intel-spi: Fix broken software sequencing codes
  * CVE-2018-5332
    - RDS: Heap OOB write in rds_message_alloc_sgs()
  * [A] KVM Windows BSOD on 4.13.x (LP: #1738972)
    - KVM: x86: fix APIC page invalidation
  * elantech touchpad of Lenovo L480/580 failed to detect hw_version
    (LP: #1733605)
    - Input: elantech - add new icbody type 15
  * [SRU] External HDMI monitor failed to show screen on Lenovo X1 series
    (LP: #1738523)
    - SAUCE: drm/i915: Disable writing of TMDS_OE on Lenovo ThinkPad X1 series
  * ubuntu/xr-usb-serial didn't get built in zesty and artful (LP: #1733281)
    - SAUCE: make sure ubuntu/xr-usb-serial builds for x86
  * Disabling zfs does not always disable module checks for the zfs modules
    (LP: #1737176)
    - [Packaging] disable zfs module checks when zfs is disabled
  * CVE-2017-17806
    - crypto: hmac - require that the underlying hash algorithm is unkeyed
  * CVE-2017-17805
    - crypto: salsa20 - fix blkcipher_walk API usage
  * CVE-2017-16994
    - mm/pagewalk.c: report holes in hugetlb ranges
  * CVE-2017-17450
    - netfilter: xt_osf: Add missing permission checks
  * apparmor profile load in stacked policy container fails (LP: #1746463)
    - SAUCE: apparmor: fix display of .ns_name for containers
  * CVE-2017-15129
    - net: Fix double free and memory corruption in get_net_ns_by_id()
  * CVE-2018-5344
    - loop: fix concurrent lo_open/lo_release
  * CVE-2017-1000407
    - KVM: VMX: remove I/O port 0x80 bypass on Intel hosts
  * CVE-2017-0861
    - ALSA: pcm: prevent UAF in snd_pcm_info
  * perf stat segfaults on uncore events w/o -a (LP: #1745246)
    - perf xyarray: Save max_x, max_y
    - perf evsel: Fix buffer overflow while freeing events
  * Support cppc-cpufreq driver on ThunderX2 systems (LP: #1745007)
    - mailbox: PCC: Move the MAX_PCC_SUBSPACES definition to header file
    - ACPI / CPPC: Make CPPC ACPI driver aware of PCC subspace IDs
    - ACPI / CPPC: Fix KASAN global out of bounds warning
    - ACPI: CPPC: remove initial assignment of pcc_ss_data
  * P-state not working in kernel 4.13 (LP: #1743269)
    - x86 / CPU: Avoid unnecessary IPIs in arch_freq_get_on_cpu()
    - x86 / CPU: Always show current CPU frequency in /proc/cpuinfo
  * Regression: KVM no longer supports Intel CPUs without Virtual NMI
    (LP: #1741655)
    - kvm: vmx: Reinstate support for CPUs without virtual NMI
  * System hang with Linux kernel due to mainline commit 24247aeeabe
    (LP: #1733662)
    - x86/intel_rdt/cqm: Prevent use after free
  * $(LOCAL_ENV_CC) and $(LOCAL_ENV_DISTCC_HOSTS) should be properly quoted
    (LP: #1744077)
    - [Debian] pass LOCAL_ENV_CC and LOCAL_ENV_DISTCC_HOSTS properly
  * the wifi driver is always hard blocked on a lenovo laptop (LP: #1743672)
    - ACPI: EC: Fix possible issues related to EC initialization order
  * text VTs are unavailable on desktop after upgrade to Ubuntu 17.10
    (LP: #1724911)
    - drm/i915/fbdev: Always forward hotplug events
  * Samsung SSD 960 EVO 500GB refused to change power state (LP: #1705748)
    - nvme-pci: disable APST on Samsung SSD 960 EVO + ASUS PRIME B350M-A
  * [0cf3:e010] QCA6174A XR failed to pair with bt 4.0 device  (LP: #1741166)
    - Bluetooth: btusb: Add support for 0cf3:e010
  * CVE-2017-17741
    - KVM: Fix stack-out-of-bounds read in write_mmio
  * CVE-2018-5333
    - RDS: null pointer dereference in rds_atomic_free_op
  * [800 G3 SFF] [800 G3 DM]External microphone of headset(3-ring) is working,
    2-ring mic not working, both not shown in sound settings  (LP: #1740974)
    - ALSA: hda - Add MIC_NO_PRESENCE fixup for 2 HP machines
  * Two front mics can't work on a lenovo machine (LP: #1740973)
    - ALSA: hda - change the location for one mic on a Lenovo machine
  * No external microphone be detected via headset jack on a dell machine
    (LP: #1740972)
    - ALSA: hda - fix headset mic detection issue on a Dell machine
  *  Can't detect external headset via line-out jack on some Dell machines
    (LP: #1740971)
    - ALSA: hda/realtek - Fix Dell AIO LineOut issue
  * Support realtek new codec alc257 in the alsa hda driver  (LP: #1738911)
    - ALSA: hda/realtek - New codec support for ALC257
  * Add support for 16g huge pages on Ubuntu 16.04.2 PowerNV (LP: #1706247)
    - powerpc/mm/hugetlb: Allow runtime allocation of 16G.
    - powerpc/mm/hugetlb: Add support for reserving gigantic huge pages via kernel
      command line
    - mm/hugetlb: Allow arch to override and call the weak function
  * the kernel is blackholing IPv6 packets to linkdown nexthops (LP: #1738219)
    - ipv6: Do not consider linkdown nexthops during multipath
  * e1000e in 4.4.0-97-generic breaks 82574L under heavy load. (LP: #1730550)
    - e1000e: Avoid receiver overrun interrupt bursts
    - e1000e: Separate signaling for link check/link up
  * Ubuntu 17.10: Include patch "crypto: vmx - Use skcipher for ctr fallback"
    (LP: #1732978)
    - crypto: vmx - Use skcipher for ctr fallback
  * QCA Rome bluetooth can not wakeup after USB runtime suspended.
    (LP: #1737890)
    - Bluetooth: btusb: driver to enable the usb-wakeup feature
  * /dev/bcache/by-uuid links not created after reboot (LP: #1729145)
    - SAUCE: (no-up) bcache: decouple emitting a cached_dev CHANGE uevent
  * Some VMs fail to reboot with "watchdog: BUG: soft lockup - CPU#0 stuck for
    22s! [systemd:1]" (LP: #1730717)
    - SAUCE: exec: fix lockup because retry loop may never exit
  * Request to backport cxlflash patches to 16.04 HWE Kernel (LP: #1730515)
    - scsi: cxlflash: Use derived maximum write same length
    - scsi: cxlflash: Allow cards without WWPN VPD to configure
    - scsi: cxlflash: Derive pid through accessors
  * vagrant artful64 box filesystem too small (LP: #1726818)
    - block: factor out __blkdev_issue_zero_pages()
    - block: cope with WRITE ZEROES failing in blkdev_issue_zeroout()
  * Artful update to 4.13.14 stable release (LP: #1744121)
    - ppp: fix race in ppp device destruction
    - gso: fix payload length when gso_size is zero
    - ipv4: Fix traffic triggered IPsec connections.
    - ipv6: Fix traffic triggered IPsec connections.
    - netlink: do not set cb_running if dump's start() errs
    - net: call cgroup_sk_alloc() earlier in sk_clone_lock()
    - macsec: fix memory leaks when skb_to_sgvec fails
    - l2tp: check ps->sock before running pppol2tp_session_ioctl()
    - netlink: fix netlink_ack() extack race
    - sctp: add the missing sock_owned_by_user check in sctp_icmp_redirect
    - tcp/dccp: fix ireq->opt races
    - packet: avoid panic in packet_getsockopt()
    - geneve: Fix function matching VNI and tunnel ID on big-endian
    - net: bridge: fix returning of vlan range op errors
    - soreuseport: fix initialization race
    - ipv6: flowlabel: do not leave opt->tot_len with garbage
    - sctp: full support for ipv6 ip_nonlocal_bind & IP_FREEBIND
    - tcp/dccp: fix lockdep splat in inet_csk_route_req()
    - tcp/dccp: fix other lockdep splats accessing ireq_opt
    - net: dsa: check master device before put
    - net/unix: don't show information about sockets from other namespaces
    - tap: double-free in error path in tap_open()
    - net/mlx5: Fix health work queue spin lock to IRQ safe
    - net/mlx5e: Properly deal with encap flows add/del under neigh update
    - ipip: only increase err_count for some certain type icmp in ipip_err
    - ip6_gre: only increase err_count for some certain type icmpv6 in ip6gre_err
    - ip6_gre: update dst pmtu if dev mtu has been updated by toobig in
      __gre6_xmit
    - tcp: refresh tp timestamp before tcp_mtu_probe()
    - tap: reference to KVA of an unloaded module causes kernel panic
    - sctp: reset owner sk for data chunks on out queues when migrating a sock
    - net_sched: avoid matching qdisc with zero handle
    - l2tp: hold tunnel in pppol2tp_connect()
    - ipv6: addrconf: increment ifp refcount before ipv6_del_addr()
    - tcp: fix tcp_mtu_probe() vs highest_sack
    - mac80211: accept key reinstall without changing anything
    - mac80211: use constant time comparison with keys
    - mac80211: don't compare TKIP TX MIC key in reinstall prevention
    - usb: usbtest: fix NULL pointer dereference
    - Input: ims-psu - check if CDC union descriptor is sane
    - EDAC, sb_edac: Don't create a second memory controller if HA1 is not present
    - dmaengine: dmatest: warn user when dma test times out
    - Linux 4.13.14

  [ Ubuntu: 4.13.0-37.42 ]

  * linux: 4.13.0-37.42 -proposed tracker (LP: #1751798)
  * CVE-2017-5715 // CVE-2017-5753 // CVE-2017-5754
    - arm64: Add ASM_BUG()
    - arm64: consistently use bl for C exception entry
    - arm64: move non-entry code out of .entry.text
    - arm64: unwind: avoid percpu indirection for irq stack
    - arm64: unwind: disregard frame.sp when validating frame pointer
    - arm64: mm: Fix set_memory_valid() declaration
    - arm64: Convert __inval_cache_range() to area-based
    - arm64: Expose DC CVAP to userspace
    - arm64: Handle trapped DC CVAP
    - arm64: Implement pmem API support
    - arm64: uaccess: Implement *_flushcache variants
    - arm64/vdso: Support mremap() for vDSO
    - arm64: unwind: reference pt_regs via embedded stack frame
    - arm64: unwind: remove sp from struct stackframe
    - arm64: uaccess: Add the uaccess_flushcache.c file
    - arm64: fix pmem interface definition
    - arm64: compat: Remove leftover variable declaration
    - fork: allow arch-override of VMAP stack alignment
    - arm64: kernel: remove {THREAD,IRQ_STACK}_START_SP
    - arm64: factor out PAGE_* and CONT_* definitions
    - arm64: clean up THREAD_* definitions
    - arm64: clean up irq stack definitions
    - arm64: move SEGMENT_ALIGN to <asm/memory.h>
    - efi/arm64: add EFI_KIMG_ALIGN
    - arm64: factor out entry stack manipulation
    - arm64: assembler: allow adr_this_cpu to use the stack pointer
    - arm64: use an irq stack pointer
    - arm64: add basic VMAP_STACK support
    - arm64: add on_accessible_stack()
    - arm64: add VMAP_STACK overflow detection
    - arm64: Convert pte handling from inline asm to using (cmp)xchg
    - kvm: arm64: Convert kvm_set_s2pte_readonly() from inline asm to cmpxchg()
    - arm64: Move PTE_RDONLY bit handling out of set_pte_at()
    - arm64: Ignore hardware dirty bit updates in ptep_set_wrprotect()
    - arm64: Remove the !CONFIG_ARM64_HW_AFDBM alternative code paths
    - arm64: introduce separated bits for mm_context_t flags
    - arm64: cleanup {COMPAT_,}SET_PERSONALITY() macro
    - KVM: arm/arm64: Fix guest external abort matching
    - KVM: arm/arm64: vgic: constify seq_operations and file_operations
    - KVM: arm/arm64: vITS: Drop its_ite->lpi field
    - KVM: arm/arm64: Extract GICv3 max APRn index calculation
    - KVM: arm/arm64: Support uaccess of GICC_APRn
    - arm64: Use larger stacks when KASAN is selected
    - arm64: Define cputype macros for Falkor CPU
    - arm64: SW PAN: Point saved ttbr0 at the zero page when switching to init_mm
    - arm64: SW PAN: Update saved ttbr0 value on enter_lazy_tlb
    - x86/syscalls: Check address limit on user-mode return
    - arm/syscalls: Check address limit on user-mode return
    - arm64/syscalls: Check address limit on user-mode return
    - Revert "arm/syscalls: Check address limit on user-mode return"
    - syscalls: Use CHECK_DATA_CORRUPTION for addr_limit_user_check
    - arm/syscalls: Optimize address limit check
    - arm64/syscalls: Move address limit check in loop
    - futex: Remove duplicated code and fix undefined behaviour
    - arm64: KVM: Fix SMCCC handling of unimplemented SMC/HVC calls
    - arm64: syscallno is secretly an int, make it official
    - arm64: move TASK_* definitions to <asm/processor.h>
    - arm64: mm: Use non-global mappings for kernel space
    - arm64: mm: Temporarily disable ARM64_SW_TTBR0_PAN
    - arm64: mm: Move ASID from TTBR0 to TTBR1
    - arm64: mm: Remove pre_ttbr0_update_workaround for Falkor erratum #E1003
    - arm64: mm: Rename post_ttbr0_update_workaround
    - arm64: mm: Fix and re-enable ARM64_SW_TTBR0_PAN
    - arm64: mm: Allocate ASIDs in pairs
    - arm64: mm: Add arm64_kernel_unmapped_at_el0 helper
    - arm64: mm: Invalidate both kernel and user ASIDs when performing TLBI
    - arm64: entry: Add exception trampoline page for exceptions from EL0
    - arm64: mm: Map entry trampoline into trampoline and kernel page tables
    - arm64: entry: Explicitly pass exception level to kernel_ventry macro
    - arm64: entry: Hook up entry trampoline to exception vectors
    - arm64: erratum: Work around Falkor erratum #E1003 in trampoline code
    - arm64: cpu_errata: Add Kryo to Falkor 1003 errata
    - arm64: tls: Avoid unconditional zeroing of tpidrro_el0 for native tasks
    - arm64: entry: Add fake CPU feature for unmapping the kernel at EL0
    - arm64: kaslr: Put kernel vectors address in separate data page
    - arm64: use RET instruction for exiting the trampoline
    - arm64: Kconfig: Add CONFIG_UNMAP_KERNEL_AT_EL0
    - arm64: Kconfig: Reword UNMAP_KERNEL_AT_EL0 kconfig entry
    - arm64: Take into account ID_AA64PFR0_EL1.CSV3
    - arm64: capabilities: Handle duplicate entries for a capability
    - arm64: mm: Introduce TTBR_ASID_MASK for getting at the ASID in the TTBR
    - arm64: kpti: Fix the interaction between ASID switching and software PAN
    - arm64: cputype: Add MIDR values for Cavium ThunderX2 CPUs
    - arm64: Turn on KPTI only on CPUs that need it
    - arm64: kpti: Make use of nG dependent on arm64_kernel_unmapped_at_el0()
    - arm64: mm: Permit transitioning from Global to Non-Global without BBM
    - arm64: kpti: Add ->enable callback to remap swapper using nG mappings
    - arm64: Force KPTI to be disabled on Cavium ThunderX
    - arm64: entry: Reword comment about post_ttbr_update_workaround
    - arm64: idmap: Use "awx" flags for .idmap.text .pushsection directives
    - arm64: barrier: Add CSDB macros to control data-value prediction
    - arm64: Implement array_index_mask_nospec()
    - arm64: Make USER_DS an inclusive limit
    - arm64: Use pointer masking to limit uaccess speculation
    - arm64: entry: Ensure branch through syscall table is bounded under
      speculation
    - arm64: uaccess: Prevent speculative use of the current addr_limit
    - arm64: uaccess: Don't bother eliding access_ok checks in __{get, put}_user
    - arm64: uaccess: Mask __user pointers for __arch_{clear, copy_*}_user
    - arm64: futex: Mask __user pointers prior to dereference
    - arm64: cpufeature: __this_cpu_has_cap() shouldn't stop early
    - arm64: Run enable method for errata work arounds on late CPUs
    - arm64: cpufeature: Pass capability structure to ->enable callback
    - drivers/firmware: Expose psci_get_version through psci_ops structure
    - arm64: Move post_ttbr_update_workaround to C code
    - arm64: Add skeleton to harden the branch predictor against aliasing attacks
    - arm64: Move BP hardening to check_and_switch_context
    - arm64: KVM: Use per-CPU vector when BP hardening is enabled
    - arm64: entry: Apply BP hardening for high-priority synchronous exceptions
    - arm64: entry: Apply BP hardening for suspicious interrupts from EL0
    - arm64: cputype: Add missing MIDR values for Cortex-A72 and Cortex-A75
    - arm64: Implement branch predictor hardening for affected Cortex-A CPUs
    - arm64: Implement branch predictor hardening for Falkor
    - arm64: Branch predictor hardening for Cavium ThunderX2
    - arm64: KVM: Increment PC after handling an SMC trap
    - arm/arm64: KVM: Consolidate the PSCI include files
    - arm/arm64: KVM: Add PSCI_VERSION helper
    - arm/arm64: KVM: Add smccc accessors to PSCI code
    - arm/arm64: KVM: Implement PSCI 1.0 support
    - arm/arm64: KVM: Advertise SMCCC v1.1
    - arm64: KVM: Make PSCI_VERSION a fast path
    - arm/arm64: KVM: Turn kvm_psci_version into a static inline
    - arm64: KVM: Report SMCCC_ARCH_WORKAROUND_1 BP hardening support
    - arm64: KVM: Add SMCCC_ARCH_WORKAROUND_1 fast handling
    - firmware/psci: Expose PSCI conduit
    - firmware/psci: Expose SMCCC version through psci_ops
    - arm/arm64: smccc: Make function identifiers an unsigned quantity
    - arm/arm64: smccc: Implement SMCCC v1.1 inline primitive
    - arm64: Add ARM_SMCCC_ARCH_WORKAROUND_1 BP hardening support
    - arm64: Kill PSCI_GET_VERSION as a variant-2 workaround
    - [Config] UNMAP_KERNEL_AT_EL0=y && HARDEN_BRANCH_PREDICTOR=y
    - SAUCE: arm64: __idmap_cpu_set_reserved_ttbr1: fix !ARM64_PA_BITS_52 logic
    - arm64: Add missing Falkor part number for branch predictor hardening
    - arm64: mm: fix thinko in non-global page table attribute check
  * linux-image-4.13.0-26-generic / linux-image-extra-4.13.0-26-generic fail to
    boot (LP: #1742721)
    - staging: sm750fb: Fix parameter mistake in poke32

  [ Ubuntu: 4.13.0-36.40 ]

  * linux: 4.13.0-36.40 -proposed tracker (LP: #1750010)
  * Rebuild without "CVE-2017-5754 ARM64 KPTI fixes" patch set

Date: Thu, 29 Mar 2018 21:39:34 -0300
Changed-By: Marcelo Henrique Cerri <marcelo.cerri at canonical.com>
Maintainer: Launchpad Build Daemon <buildd at lcy01-amd64-030.buildd>

-------------- next part --------------
Format: 1.8
Date: Thu, 29 Mar 2018 21:39:34 -0300
Source: linux-azure
Binary: linux-azure-headers-4.13.0-1013 linux-azure-tools-4.13.0-1013 linux-azure-cloud-tools-4.13.0-1013 linux-image-4.13.0-1013-azure linux-image-extra-4.13.0-1013-azure linux-headers-4.13.0-1013-azure linux-image-4.13.0-1013-azure-dbgsym linux-tools-4.13.0-1013-azure linux-cloud-tools-4.13.0-1013-azure linux-udebs-azure
Architecture: amd64 all amd64_translations
Version: 4.13.0-1013.16
Distribution: xenial
Urgency: medium
Maintainer: Launchpad Build Daemon <buildd at lcy01-amd64-030.buildd>
Changed-By: Marcelo Henrique Cerri <marcelo.cerri at canonical.com>
Description:
 linux-azure-cloud-tools-4.13.0-1013 - Linux kernel version specific cloud tools for version 4.13.0-1013
 linux-azure-headers-4.13.0-1013 - Header files related to Linux kernel version 4.13.0
 linux-azure-tools-4.13.0-1013 - Linux kernel version specific tools for version 4.13.0-1013
 linux-cloud-tools-4.13.0-1013-azure - Linux kernel version specific cloud tools for version 4.13.0-1013
 linux-headers-4.13.0-1013-azure - Linux kernel headers for version 4.13.0 on 64 bit x86 SMP
 linux-image-4.13.0-1013-azure - Linux kernel image for version 4.13.0 on 64 bit x86 SMP
 linux-image-4.13.0-1013-azure-dbgsym - Linux kernel debug image for version 4.13.0 on 64 bit x86 SMP
 linux-image-extra-4.13.0-1013-azure - Linux kernel extra modules for version 4.13.0 on 64 bit x86 SMP
 linux-tools-4.13.0-1013-azure - Linux kernel version specific tools for version 4.13.0-1013
 linux-udebs-azure - Metapackage depending on kernel udebs (udeb)
Launchpad-Bugs-Fixed: 1482390 1661876 1705748 1706247 1715519 1724911 1726818 1729145 1729674 1730515 1730550 1730717 1732056 1732978 1733281 1733605 1733662 1735159 1736145 1736393 1736954 1737176 1737890 1738219 1738523 1738911 1738972 1738975 1739498 1740971 1740972 1740973 1740974 1741166 1741655 1742316 1742696 1742721 1743269 1743672 1743856 1744058 1744077 1744121 1744212 1744213 1744712 1744988 1745007 1745032 1745246 1745508 1746002 1746019 1746174 1746225 1746463 1746970 1747523 1747572 1747746 1747769 1748408 1748567 1748807 1748922 1749420 1750010 1750021 1751021 1751798 1752695 1753347 1754076 1755762 1755773
Changes:
 linux-azure (4.13.0-1013.16) xenial; urgency=medium
 .
   * linux-azure: 4.13.0-1013.16 -proposed tracker (LP: #1755773)
 .
   * ubuntu/xr-usb-serial didn't get built in zesty and artful (LP: #1733281)
     - ubuntu: Only build ubuntu/xr-usb-serial when USB is enabled
 .
   [ Ubuntu: 4.13.0-38.43 ]
 .
   * linux: 4.13.0-38.43 -proposed tracker (LP: #1755762)
   * Servers going OOM after updating kernel from 4.10 to 4.13 (LP: #1748408)
     - i40e: Fix memory leak related filter programming status
     - i40e: Add programming descriptors to cleaned_count
   * [SRU] Lenovo E41 Mic mute hotkey is not responding (LP: #1753347)
     - platform/x86: ideapad-laptop: Increase timeout to wait for EC answer
   * fails to dump with latest kpti fixes (LP: #1750021)
     - kdump: write correct address of mem_section into vmcoreinfo
   * headset mic can't be detected on two Dell machines (LP: #1748807)
     - ALSA: hda/realtek - Support headset mode for ALC215/ALC285/ALC289
     - ALSA: hda - Fix headset mic detection problem for two Dell machines
     - ALSA: hda - Fix a wrong FIXUP for alc289 on Dell machines
   * CIFS SMB2/SMB3 does not work for domain based DFS (LP: #1747572)
     - CIFS: make IPC a regular tcon
     - CIFS: use tcon_ipc instead of use_ipc parameter of SMB2_ioctl
     - CIFS: dump IPC tcon in debug proc file
   * i2c-thunderx: erroneous error message "unhandled state: 0" (LP: #1754076)
     - i2c: octeon: Prevent error message on bus error
   * hisi_sas: Add disk LED support (LP: #1752695)
     - scsi: hisi_sas: directly attached disk LED feature for v2 hw
   * EDAC, sb_edac: Backport 1 patch to Ubuntu 17.10 (Fix missing DIMM sysfs
     entries with KNL SNC2/SNC4 mode) (LP: #1743856)
     - EDAC, sb_edac: Fix missing DIMM sysfs entries with KNL SNC2/SNC4 mode
   * [regression] Colour banding and artefacts appear system-wide on an Asus
     Zenbook UX303LA with Intel HD 4400 graphics (LP: #1749420)
     - drm/edid: Add 6 bpc quirk for CPT panel in Asus UX303LA
   * DVB Card with SAA7146 chipset not working (LP: #1742316)
     - vmalloc: fix __GFP_HIGHMEM usage for vmalloc_32 on 32b systems
   * [Asus UX360UA] battery status in unity-panel is not changing when battery is
     being charged (LP: #1661876) // AC adapter status not detected on Asus
     ZenBook UX410UAK (LP: #1745032)
     - ACPI / battery: Add quirk for Asus UX360UA and UX410UAK
   * ASUS UX305LA - Battery state not detected correctly (LP: #1482390)
     - ACPI / battery: Add quirk for Asus GL502VSK and UX305LA
   * support thunderx2 vendor pmu events (LP: #1747523)
     - perf pmu: Extract function to get JSON alias map
     - perf pmu: Pass pmu as a parameter to get_cpuid_str()
     - perf tools arm64: Add support for get_cpuid_str function.
     - perf pmu: Add helper function is_pmu_core to detect PMU CORE devices
     - perf vendor events arm64: Add ThunderX2 implementation defined pmu core
       events
     - perf pmu: Add check for valid cpuid in perf_pmu__find_map()
   * lpfc.ko module doesn't work (LP: #1746970)
     - scsi: lpfc: Fix loop mode target discovery
   * Ubuntu 17.10 crashes on vmalloc.c (LP: #1739498)
     - powerpc/mm/book3s64: Make KERN_IO_START a variable
     - powerpc/mm/slb: Move comment next to the code it's referring to
     - powerpc/mm/hash64: Make vmalloc 56T on hash
   * ethtool -p fails to light NIC LED on HiSilicon D05 systems (LP: #1748567)
     - net: hns: add ACPI mode support for ethtool -p
   * CVE-2017-17807
     - KEYS: add missing permission check for request_key() destination
   * [Artful SRU] Fix capsule update regression (LP: #1746019)
     - efi/capsule-loader: Reinstate virtual capsule mapping
   * [Artful/Bionic] [Config] enable EDAC_GHES for ARM64 (LP: #1747746)
     - Ubuntu: [Config] enable EDAC_GHES for ARM64
   * linux-tools: perf incorrectly linking libbfd (LP: #1748922)
     - SAUCE: tools -- add ability to disable libbfd
     - [Packaging] correct disablement of libbfd
   * Cherry pick c96f5471ce7d for delayacct fix (LP: #1747769)
     - delayacct: Account blkio completion on the correct task
   * Error in CPU frequency reporting when nominal and min pstates are same
     (cpufreq) (LP: #1746174)
     - cpufreq: powernv: Dont assume distinct pstate values for nominal and pmin
   * retpoline abi files are empty on i386 (LP: #1751021)
     - [Packaging] retpoline-extract -- instantiate retpoline files for i386
     - [Packaging] final-checks -- sanity checking ABI contents
     - [Packaging] final-checks -- check for empty retpoline files
   * [P9,Power NV][WSP][Ubuntu 1804] : "Kernel access of bad area " when grouping
     different pmu events using perf fuzzer . (perf:) (LP: #1746225)
     - powerpc/perf: Fix oops when grouping different pmu events
   * bnx2x_attn_int_deasserted3:4323 MC assert! (LP: #1715519) //
     CVE-2018-1000026
     - net: create skb_gso_validate_mac_len()
     - bnx2x: disable GSO where gso_size is too big for hardware
   * Ubuntu16.04.03: ISAv3 initialize MMU registers before setting partition
     table (LP: #1736145)
     - powerpc/64s: Initialize ISAv3 MMU registers before setting partition table
   * powerpc/powernv: Flush console before platform error reboot (LP: #1735159)
     - powerpc/powernv: Flush console before platform error reboot
   * Touchpad stops working after a few seconds in Lenovo ideapad 320
     (LP: #1732056)
     - pinctrl/amd: fix masking of GPIO interrupts
   * [Artful][Wyse 3040] System hang when trying to enable an offlined CPU core
     (LP: #1736393)
     - SAUCE: drm/i915:Don't set chip specific data
     - SAUCE: drm/i915: make previous commit affects Wyse 3040 only
   * ppc64el: Do not call ibm,os-term on panic (LP: #1736954)
     - powerpc: Do not call ppc_md.panic in fadump panic notifier
   * Artful update to 4.13.16 stable release (LP: #1744213)
     - tcp_nv: fix division by zero in tcpnv_acked()
     - net: vrf: correct FRA_L3MDEV encode type
     - tcp: do not mangle skb->cb[] in tcp_make_synack()
     - net: systemport: Correct IPG length settings
     - netfilter/ipvs: clear ipvs_property flag when SKB net namespace changed
     - l2tp: don't use l2tp_tunnel_find() in l2tp_ip and l2tp_ip6
     - bonding: discard lowest hash bit for 802.3ad layer3+4
     - net: cdc_ether: fix divide by 0 on bad descriptors
     - net: qmi_wwan: fix divide by 0 on bad descriptors
     - qmi_wwan: Add missing skb_reset_mac_header-call
     - net: usb: asix: fill null-ptr-deref in asix_suspend
     - tcp: gso: avoid refcount_t warning from tcp_gso_segment()
     - tcp: fix tcp_fastretrans_alert warning
     - vlan: fix a use-after-free in vlan_device_event()
     - net/mlx5: Cancel health poll before sending panic teardown command
     - net/mlx5e: Set page to null in case dma mapping fails
     - af_netlink: ensure that NLMSG_DONE never fails in dumps
     - vxlan: fix the issue that neigh proxy blocks all icmpv6 packets
     - net: cdc_ncm: GetNtbFormat endian fix
     - fealnx: Fix building error on MIPS
     - net/sctp: Always set scope_id in sctp_inet6_skb_msgname
     - ima: do not update security.ima if appraisal status is not INTEGRITY_PASS
     - serial: omap: Fix EFR write on RTS deassertion
     - serial: 8250_fintek: Fix finding base_port with activated SuperIO
     - tpm-dev-common: Reject too short writes
     - rcu: Fix up pending cbs check in rcu_prepare_for_idle
     - ocfs2: fix cluster hang after a node dies
     - ocfs2: should wait dio before inode lock in ocfs2_setattr()
     - ipmi: fix unsigned long underflow
     - mm/page_alloc.c: broken deferred calculation
     - mm/page_ext.c: check if page_ext is not prepared
     - x86/cpu/amd: Derive L3 shared_cpu_map from cpu_llc_shared_mask
     - coda: fix 'kernel memory exposure attempt' in fsync
     - Linux 4.13.16
   * Artful update to 4.13.15 stable release (LP: #1744212)
     - media: imon: Fix null-ptr-deref in imon_probe
     - media: dib0700: fix invalid dvb_detach argument
     - crypto: dh - Fix double free of ctx->p
     - crypto: dh - Don't permit 'p' to be 0
     - crypto: dh - Don't permit 'key' or 'g' size longer than 'p'
     - USB: early: Use new USB product ID and strings for DbC device
     - USB: usbfs: compute urb->actual_length for isochronous
     - USB: Add delay-init quirk for Corsair K70 LUX keyboards
     - usb: gadget: f_fs: Fix use-after-free in ffs_free_inst
     - USB: serial: metro-usb: stop I/O after failed open
     - USB: serial: Change DbC debug device binding ID
     - USB: serial: qcserial: add pid/vid for Sierra Wireless EM7355 fw update
     - USB: serial: garmin_gps: fix I/O after failed probe and remove
     - USB: serial: garmin_gps: fix memory leak on probe errors
     - x86/MCE/AMD: Always give panic severity for UC errors in kernel context
     - platform/x86: peaq-wmi: Add DMI check before binding to the WMI interface
     - platform/x86: peaq_wmi: Fix missing terminating entry for peaq_dmi_table
     - HID: cp2112: add HIDRAW dependency
     - HID: wacom: generic: Recognize WACOM_HID_WD_PEN as a type of pen collection
     - staging: wilc1000: Fix bssid buffer offset in Txq
     - staging: ccree: fix 64 bit scatter/gather DMA ops
     - staging: greybus: spilib: fix use-after-free after deregistration
     - staging: vboxvideo: Fix reporting invalid suggested-offset-properties
     - staging: rtl8188eu: Revert 4 commits breaking ARP
     - Linux 4.13.15
   * time drifting on linux-hwe kernels (LP: #1744988)
     - x86/tsc: Future-proof native_calibrate_tsc()
     - x86/tsc: Fix erroneous TSC rate on Skylake Xeon
     - x86/tsc: Print tsc_khz, when it differs from cpu_khz
   * Please backport vmd suspend/resume patches to 16.04 hwe (LP: #1745508)
     - PCI: vmd: Free up IRQs on suspend path
   * CVE-2017-17448
     - netfilter: nfnetlink_cthelper: Add missing permission checks
   * Dell XPS 13 9360 bluetooth (Atheros) won't connect after resume
     (LP: #1744712)
     - Bluetooth: btusb: Restore QCA Rome suspend/resume fix with a "rewritten"
       version
   * [SRU] TrackPoint: middle button doesn't work on TrackPoint-compatible
     device. (LP: #1746002)
     - Input: trackpoint - force 3 buttons if 0 button is reported
   * TB16 dock ethernet corrupts data with hw checksum silently failing
     (LP: #1729674)
     - r8152: disable RX aggregation on Dell TB16 dock
   * [Artful] Realtek ALC225: 2 secs noise when a headset plugged in
     (LP: #1744058)
     - Revert "UBUNTU: SAUCE: ALSA: hda/realtek - Add support headset mode for DELL
       WYSE"
     - SAUCE: ALSA: hda/realtek - Add support headset mode for DELL WYSE
     - ALSA: hda/realtek - update ALC225 depop optimize
   * [A] skb leak in vhost_net / tun / tap (LP: #1738975)
     - vhost: fix skb leak in handle_rx()
     - tap: free skb if flags error
     - tun: free skb in early errors
   * Commit d9018976cdb6 missing in Kernels <4.14.x preventing lasting fix of
     Intel SPI bug on certain serial flash (LP: #1742696)
     - mfd: lpc_ich: Do not touch SPI-NOR write protection bit on Haswell/Broadwell
     - spi-nor: intel-spi: Fix broken software sequencing codes
   * CVE-2018-5332
     - RDS: Heap OOB write in rds_message_alloc_sgs()
   * [A] KVM Windows BSOD on 4.13.x (LP: #1738972)
     - KVM: x86: fix APIC page invalidation
   * elantech touchpad of Lenovo L480/580 failed to detect hw_version
     (LP: #1733605)
     - Input: elantech - add new icbody type 15
   * [SRU] External HDMI monitor failed to show screen on Lenovo X1 series
     (LP: #1738523)
     - SAUCE: drm/i915: Disable writing of TMDS_OE on Lenovo ThinkPad X1 series
   * ubuntu/xr-usb-serial didn't get built in zesty and artful (LP: #1733281)
     - SAUCE: make sure ubuntu/xr-usb-serial builds for x86
   * Disabling zfs does not always disable module checks for the zfs modules
     (LP: #1737176)
     - [Packaging] disable zfs module checks when zfs is disabled
   * CVE-2017-17806
     - crypto: hmac - require that the underlying hash algorithm is unkeyed
   * CVE-2017-17805
     - crypto: salsa20 - fix blkcipher_walk API usage
   * CVE-2017-16994
     - mm/pagewalk.c: report holes in hugetlb ranges
   * CVE-2017-17450
     - netfilter: xt_osf: Add missing permission checks
   * apparmor profile load in stacked policy container fails (LP: #1746463)
     - SAUCE: apparmor: fix display of .ns_name for containers
   * CVE-2017-15129
     - net: Fix double free and memory corruption in get_net_ns_by_id()
   * CVE-2018-5344
     - loop: fix concurrent lo_open/lo_release
   * CVE-2017-1000407
     - KVM: VMX: remove I/O port 0x80 bypass on Intel hosts
   * CVE-2017-0861
     - ALSA: pcm: prevent UAF in snd_pcm_info
   * perf stat segfaults on uncore events w/o -a (LP: #1745246)
     - perf xyarray: Save max_x, max_y
     - perf evsel: Fix buffer overflow while freeing events
   * Support cppc-cpufreq driver on ThunderX2 systems (LP: #1745007)
     - mailbox: PCC: Move the MAX_PCC_SUBSPACES definition to header file
     - ACPI / CPPC: Make CPPC ACPI driver aware of PCC subspace IDs
     - ACPI / CPPC: Fix KASAN global out of bounds warning
     - ACPI: CPPC: remove initial assignment of pcc_ss_data
   * P-state not working in kernel 4.13 (LP: #1743269)
     - x86 / CPU: Avoid unnecessary IPIs in arch_freq_get_on_cpu()
     - x86 / CPU: Always show current CPU frequency in /proc/cpuinfo
   * Regression: KVM no longer supports Intel CPUs without Virtual NMI
     (LP: #1741655)
     - kvm: vmx: Reinstate support for CPUs without virtual NMI
   * System hang with Linux kernel due to mainline commit 24247aeeabe
     (LP: #1733662)
     - x86/intel_rdt/cqm: Prevent use after free
   * $(LOCAL_ENV_CC) and $(LOCAL_ENV_DISTCC_HOSTS) should be properly quoted
     (LP: #1744077)
     - [Debian] pass LOCAL_ENV_CC and LOCAL_ENV_DISTCC_HOSTS properly
   * the wifi driver is always hard blocked on a lenovo laptop (LP: #1743672)
     - ACPI: EC: Fix possible issues related to EC initialization order
   * text VTs are unavailable on desktop after upgrade to Ubuntu 17.10
     (LP: #1724911)
     - drm/i915/fbdev: Always forward hotplug events
   * Samsung SSD 960 EVO 500GB refused to change power state (LP: #1705748)
     - nvme-pci: disable APST on Samsung SSD 960 EVO + ASUS PRIME B350M-A
   * [0cf3:e010] QCA6174A XR failed to pair with bt 4.0 device  (LP: #1741166)
     - Bluetooth: btusb: Add support for 0cf3:e010
   * CVE-2017-17741
     - KVM: Fix stack-out-of-bounds read in write_mmio
   * CVE-2018-5333
     - RDS: null pointer dereference in rds_atomic_free_op
   * [800 G3 SFF] [800 G3 DM]External microphone of headset(3-ring) is working,
     2-ring mic not working, both not shown in sound settings  (LP: #1740974)
     - ALSA: hda - Add MIC_NO_PRESENCE fixup for 2 HP machines
   * Two front mics can't work on a lenovo machine (LP: #1740973)
     - ALSA: hda - change the location for one mic on a Lenovo machine
   * No external microphone be detected via headset jack on a dell machine
     (LP: #1740972)
     - ALSA: hda - fix headset mic detection issue on a Dell machine
   *  Can't detect external headset via line-out jack on some Dell machines
     (LP: #1740971)
     - ALSA: hda/realtek - Fix Dell AIO LineOut issue
   * Support realtek new codec alc257 in the alsa hda driver  (LP: #1738911)
     - ALSA: hda/realtek - New codec support for ALC257
   * Add support for 16g huge pages on Ubuntu 16.04.2 PowerNV (LP: #1706247)
     - powerpc/mm/hugetlb: Allow runtime allocation of 16G.
     - powerpc/mm/hugetlb: Add support for reserving gigantic huge pages via kernel
       command line
     - mm/hugetlb: Allow arch to override and call the weak function
   * the kernel is blackholing IPv6 packets to linkdown nexthops (LP: #1738219)
     - ipv6: Do not consider linkdown nexthops during multipath
   * e1000e in 4.4.0-97-generic breaks 82574L under heavy load. (LP: #1730550)
     - e1000e: Avoid receiver overrun interrupt bursts
     - e1000e: Separate signaling for link check/link up
   * Ubuntu 17.10: Include patch "crypto: vmx - Use skcipher for ctr fallback"
     (LP: #1732978)
     - crypto: vmx - Use skcipher for ctr fallback
   * QCA Rome bluetooth can not wakeup after USB runtime suspended.
     (LP: #1737890)
     - Bluetooth: btusb: driver to enable the usb-wakeup feature
   * /dev/bcache/by-uuid links not created after reboot (LP: #1729145)
     - SAUCE: (no-up) bcache: decouple emitting a cached_dev CHANGE uevent
   * Some VMs fail to reboot with "watchdog: BUG: soft lockup - CPU#0 stuck for
     22s! [systemd:1]" (LP: #1730717)
     - SAUCE: exec: fix lockup because retry loop may never exit
   * Request to backport cxlflash patches to 16.04 HWE Kernel (LP: #1730515)
     - scsi: cxlflash: Use derived maximum write same length
     - scsi: cxlflash: Allow cards without WWPN VPD to configure
     - scsi: cxlflash: Derive pid through accessors
   * vagrant artful64 box filesystem too small (LP: #1726818)
     - block: factor out __blkdev_issue_zero_pages()
     - block: cope with WRITE ZEROES failing in blkdev_issue_zeroout()
   * Artful update to 4.13.14 stable release (LP: #1744121)
     - ppp: fix race in ppp device destruction
     - gso: fix payload length when gso_size is zero
     - ipv4: Fix traffic triggered IPsec connections.
     - ipv6: Fix traffic triggered IPsec connections.
     - netlink: do not set cb_running if dump's start() errs
     - net: call cgroup_sk_alloc() earlier in sk_clone_lock()
     - macsec: fix memory leaks when skb_to_sgvec fails
     - l2tp: check ps->sock before running pppol2tp_session_ioctl()
     - netlink: fix netlink_ack() extack race
     - sctp: add the missing sock_owned_by_user check in sctp_icmp_redirect
     - tcp/dccp: fix ireq->opt races
     - packet: avoid panic in packet_getsockopt()
     - geneve: Fix function matching VNI and tunnel ID on big-endian
     - net: bridge: fix returning of vlan range op errors
     - soreuseport: fix initialization race
     - ipv6: flowlabel: do not leave opt->tot_len with garbage
     - sctp: full support for ipv6 ip_nonlocal_bind & IP_FREEBIND
     - tcp/dccp: fix lockdep splat in inet_csk_route_req()
     - tcp/dccp: fix other lockdep splats accessing ireq_opt
     - net: dsa: check master device before put
     - net/unix: don't show information about sockets from other namespaces
     - tap: double-free in error path in tap_open()
     - net/mlx5: Fix health work queue spin lock to IRQ safe
     - net/mlx5e: Properly deal with encap flows add/del under neigh update
     - ipip: only increase err_count for some certain type icmp in ipip_err
     - ip6_gre: only increase err_count for some certain type icmpv6 in ip6gre_err
     - ip6_gre: update dst pmtu if dev mtu has been updated by toobig in
       __gre6_xmit
     - tcp: refresh tp timestamp before tcp_mtu_probe()
     - tap: reference to KVA of an unloaded module causes kernel panic
     - sctp: reset owner sk for data chunks on out queues when migrating a sock
     - net_sched: avoid matching qdisc with zero handle
     - l2tp: hold tunnel in pppol2tp_connect()
     - ipv6: addrconf: increment ifp refcount before ipv6_del_addr()
     - tcp: fix tcp_mtu_probe() vs highest_sack
     - mac80211: accept key reinstall without changing anything
     - mac80211: use constant time comparison with keys
     - mac80211: don't compare TKIP TX MIC key in reinstall prevention
     - usb: usbtest: fix NULL pointer dereference
     - Input: ims-psu - check if CDC union descriptor is sane
     - EDAC, sb_edac: Don't create a second memory controller if HA1 is not present
     - dmaengine: dmatest: warn user when dma test times out
     - Linux 4.13.14
 .
   [ Ubuntu: 4.13.0-37.42 ]
 .
   * linux: 4.13.0-37.42 -proposed tracker (LP: #1751798)
   * CVE-2017-5715 // CVE-2017-5753 // CVE-2017-5754
     - arm64: Add ASM_BUG()
     - arm64: consistently use bl for C exception entry
     - arm64: move non-entry code out of .entry.text
     - arm64: unwind: avoid percpu indirection for irq stack
     - arm64: unwind: disregard frame.sp when validating frame pointer
     - arm64: mm: Fix set_memory_valid() declaration
     - arm64: Convert __inval_cache_range() to area-based
     - arm64: Expose DC CVAP to userspace
     - arm64: Handle trapped DC CVAP
     - arm64: Implement pmem API support
     - arm64: uaccess: Implement *_flushcache variants
     - arm64/vdso: Support mremap() for vDSO
     - arm64: unwind: reference pt_regs via embedded stack frame
     - arm64: unwind: remove sp from struct stackframe
     - arm64: uaccess: Add the uaccess_flushcache.c file
     - arm64: fix pmem interface definition
     - arm64: compat: Remove leftover variable declaration
     - fork: allow arch-override of VMAP stack alignment
     - arm64: kernel: remove {THREAD,IRQ_STACK}_START_SP
     - arm64: factor out PAGE_* and CONT_* definitions
     - arm64: clean up THREAD_* definitions
     - arm64: clean up irq stack definitions
     - arm64: move SEGMENT_ALIGN to <asm/memory.h>
     - efi/arm64: add EFI_KIMG_ALIGN
     - arm64: factor out entry stack manipulation
     - arm64: assembler: allow adr_this_cpu to use the stack pointer
     - arm64: use an irq stack pointer
     - arm64: add basic VMAP_STACK support
     - arm64: add on_accessible_stack()
     - arm64: add VMAP_STACK overflow detection
     - arm64: Convert pte handling from inline asm to using (cmp)xchg
     - kvm: arm64: Convert kvm_set_s2pte_readonly() from inline asm to cmpxchg()
     - arm64: Move PTE_RDONLY bit handling out of set_pte_at()
     - arm64: Ignore hardware dirty bit updates in ptep_set_wrprotect()
     - arm64: Remove the !CONFIG_ARM64_HW_AFDBM alternative code paths
     - arm64: introduce separated bits for mm_context_t flags
     - arm64: cleanup {COMPAT_,}SET_PERSONALITY() macro
     - KVM: arm/arm64: Fix guest external abort matching
     - KVM: arm/arm64: vgic: constify seq_operations and file_operations
     - KVM: arm/arm64: vITS: Drop its_ite->lpi field
     - KVM: arm/arm64: Extract GICv3 max APRn index calculation
     - KVM: arm/arm64: Support uaccess of GICC_APRn
     - arm64: Use larger stacks when KASAN is selected
     - arm64: Define cputype macros for Falkor CPU
     - arm64: SW PAN: Point saved ttbr0 at the zero page when switching to init_mm
     - arm64: SW PAN: Update saved ttbr0 value on enter_lazy_tlb
     - x86/syscalls: Check address limit on user-mode return
     - arm/syscalls: Check address limit on user-mode return
     - arm64/syscalls: Check address limit on user-mode return
     - Revert "arm/syscalls: Check address limit on user-mode return"
     - syscalls: Use CHECK_DATA_CORRUPTION for addr_limit_user_check
     - arm/syscalls: Optimize address limit check
     - arm64/syscalls: Move address limit check in loop
     - futex: Remove duplicated code and fix undefined behaviour
     - arm64: KVM: Fix SMCCC handling of unimplemented SMC/HVC calls
     - arm64: syscallno is secretly an int, make it official
     - arm64: move TASK_* definitions to <asm/processor.h>
     - arm64: mm: Use non-global mappings for kernel space
     - arm64: mm: Temporarily disable ARM64_SW_TTBR0_PAN
     - arm64: mm: Move ASID from TTBR0 to TTBR1
     - arm64: mm: Remove pre_ttbr0_update_workaround for Falkor erratum #E1003
     - arm64: mm: Rename post_ttbr0_update_workaround
     - arm64: mm: Fix and re-enable ARM64_SW_TTBR0_PAN
     - arm64: mm: Allocate ASIDs in pairs
     - arm64: mm: Add arm64_kernel_unmapped_at_el0 helper
     - arm64: mm: Invalidate both kernel and user ASIDs when performing TLBI
     - arm64: entry: Add exception trampoline page for exceptions from EL0
     - arm64: mm: Map entry trampoline into trampoline and kernel page tables
     - arm64: entry: Explicitly pass exception level to kernel_ventry macro
     - arm64: entry: Hook up entry trampoline to exception vectors
     - arm64: erratum: Work around Falkor erratum #E1003 in trampoline code
     - arm64: cpu_errata: Add Kryo to Falkor 1003 errata
     - arm64: tls: Avoid unconditional zeroing of tpidrro_el0 for native tasks
     - arm64: entry: Add fake CPU feature for unmapping the kernel at EL0
     - arm64: kaslr: Put kernel vectors address in separate data page
     - arm64: use RET instruction for exiting the trampoline
     - arm64: Kconfig: Add CONFIG_UNMAP_KERNEL_AT_EL0
     - arm64: Kconfig: Reword UNMAP_KERNEL_AT_EL0 kconfig entry
     - arm64: Take into account ID_AA64PFR0_EL1.CSV3
     - arm64: capabilities: Handle duplicate entries for a capability
     - arm64: mm: Introduce TTBR_ASID_MASK for getting at the ASID in the TTBR
     - arm64: kpti: Fix the interaction between ASID switching and software PAN
     - arm64: cputype: Add MIDR values for Cavium ThunderX2 CPUs
     - arm64: Turn on KPTI only on CPUs that need it
     - arm64: kpti: Make use of nG dependent on arm64_kernel_unmapped_at_el0()
     - arm64: mm: Permit transitioning from Global to Non-Global without BBM
     - arm64: kpti: Add ->enable callback to remap swapper using nG mappings
     - arm64: Force KPTI to be disabled on Cavium ThunderX
     - arm64: entry: Reword comment about post_ttbr_update_workaround
     - arm64: idmap: Use "awx" flags for .idmap.text .pushsection directives
     - arm64: barrier: Add CSDB macros to control data-value prediction
     - arm64: Implement array_index_mask_nospec()
     - arm64: Make USER_DS an inclusive limit
     - arm64: Use pointer masking to limit uaccess speculation
     - arm64: entry: Ensure branch through syscall table is bounded under
       speculation
     - arm64: uaccess: Prevent speculative use of the current addr_limit
     - arm64: uaccess: Don't bother eliding access_ok checks in __{get, put}_user
     - arm64: uaccess: Mask __user pointers for __arch_{clear, copy_*}_user
     - arm64: futex: Mask __user pointers prior to dereference
     - arm64: cpufeature: __this_cpu_has_cap() shouldn't stop early
     - arm64: Run enable method for errata work arounds on late CPUs
     - arm64: cpufeature: Pass capability structure to ->enable callback
     - drivers/firmware: Expose psci_get_version through psci_ops structure
     - arm64: Move post_ttbr_update_workaround to C code
     - arm64: Add skeleton to harden the branch predictor against aliasing attacks
     - arm64: Move BP hardening to check_and_switch_context
     - arm64: KVM: Use per-CPU vector when BP hardening is enabled
     - arm64: entry: Apply BP hardening for high-priority synchronous exceptions
     - arm64: entry: Apply BP hardening for suspicious interrupts from EL0
     - arm64: cputype: Add missing MIDR values for Cortex-A72 and Cortex-A75
     - arm64: Implement branch predictor hardening for affected Cortex-A CPUs
     - arm64: Implement branch predictor hardening for Falkor
     - arm64: Branch predictor hardening for Cavium ThunderX2
     - arm64: KVM: Increment PC after handling an SMC trap
     - arm/arm64: KVM: Consolidate the PSCI include files
     - arm/arm64: KVM: Add PSCI_VERSION helper
     - arm/arm64: KVM: Add smccc accessors to PSCI code
     - arm/arm64: KVM: Implement PSCI 1.0 support
     - arm/arm64: KVM: Advertise SMCCC v1.1
     - arm64: KVM: Make PSCI_VERSION a fast path
     - arm/arm64: KVM: Turn kvm_psci_version into a static inline
     - arm64: KVM: Report SMCCC_ARCH_WORKAROUND_1 BP hardening support
     - arm64: KVM: Add SMCCC_ARCH_WORKAROUND_1 fast handling
     - firmware/psci: Expose PSCI conduit
     - firmware/psci: Expose SMCCC version through psci_ops
     - arm/arm64: smccc: Make function identifiers an unsigned quantity
     - arm/arm64: smccc: Implement SMCCC v1.1 inline primitive
     - arm64: Add ARM_SMCCC_ARCH_WORKAROUND_1 BP hardening support
     - arm64: Kill PSCI_GET_VERSION as a variant-2 workaround
     - [Config] UNMAP_KERNEL_AT_EL0=y && HARDEN_BRANCH_PREDICTOR=y
     - SAUCE: arm64: __idmap_cpu_set_reserved_ttbr1: fix !ARM64_PA_BITS_52 logic
     - arm64: Add missing Falkor part number for branch predictor hardening
     - arm64: mm: fix thinko in non-global page table attribute check
   * linux-image-4.13.0-26-generic / linux-image-extra-4.13.0-26-generic fail to
     boot (LP: #1742721)
     - staging: sm750fb: Fix parameter mistake in poke32
 .
   [ Ubuntu: 4.13.0-36.40 ]
 .
   * linux: 4.13.0-36.40 -proposed tracker (LP: #1750010)
   * Rebuild without "CVE-2017-5754 ARM64 KPTI fixes" patch set
Checksums-Sha1:
 12a0b38de9def46804fc85567341426866648432 844 linux-azure-cloud-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 476d0a13985bbe8121239e393d4e39763b1c22cc 34454 linux-azure-cloud-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 ca078cd1793213d3b52ad6f55773fa1275e273db 10735676 linux-azure-headers-4.13.0-1013_4.13.0-1013.16_all.deb
 1a5df15a99143e8aa1ba6b8d7a9fab56c64f97d6 864 linux-azure-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 63ebfd3a711a03c52b7511331e7342649aef279b 960048 linux-azure-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 35c6f23e0a96d31165e79509457a97834d7e2ae8 6839168 linux-azure_4.13.0-1013.16_amd64.tar.gz
 c25ab1903559068a3c1ba199461ca7946686d842 33978 linux-azure_4.13.0-1013.16_amd64_translations.tar.gz
 6f886d91ddbd2427d6ebc8a1924a0ddba9243eb3 1810 linux-cloud-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 3026a99022cea9a9895a4673765a97359565ab0a 523064 linux-headers-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 9817ec4d4b9f2900a854bedf5a16c47f27d8c4f7 312555242 linux-image-4.13.0-1013-azure-dbgsym_4.13.0-1013.16_amd64.ddeb
 957b5bf1661f251e08c5ee5dc345271054e8e4bb 18520180 linux-image-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 d10a6a08642d3e3d196c3fbeee25b6a6928baff8 9776492 linux-image-extra-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 91002a7dc239856fc2ccbf897c64f2ea5547102f 1882 linux-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
Checksums-Sha256:
 c2d3881c66445a2f119fbfb29f41b100c893853de64c1ed6cefcea5de1a7a499 844 linux-azure-cloud-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 9ad06b7b15021dbc26be6ab024c2fa4fd9b8897ff6fee4e5b023af0ccf694dba 34454 linux-azure-cloud-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 870740385c19aea7cc347b14f4de7daea0741f2c0d593832af1a44c7d13bd18a 10735676 linux-azure-headers-4.13.0-1013_4.13.0-1013.16_all.deb
 29672dff81b2f391963ee228bc4c280ae6e9998d1e149dba6be2b035493a58f9 864 linux-azure-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 29e93041b0ecdbd53394338e67622f3bc3e1479a455aec23ee7aaa6a332b5b56 960048 linux-azure-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 76bcaa9dde4ee4b46322fd9763dcf0b2565ff92ebe4ccbfb307a13a8dbf3b82a 6839168 linux-azure_4.13.0-1013.16_amd64.tar.gz
 fa501c138474a20442680f601c1a2bde8f160fb99f4ee977a92c6c54beffe358 33978 linux-azure_4.13.0-1013.16_amd64_translations.tar.gz
 63c7e6162e18bf331b817a0e17366af0ee93a131a1f71c1951caceca93fe56ba 1810 linux-cloud-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 1b194b9b9fd275031baf75f67bc01ca21079412621a6294ee41c92460f49eead 523064 linux-headers-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 48773a1afe5bd6303c2b878795393b60ea9d671ef6c9bce907df1fb62e0702ef 312555242 linux-image-4.13.0-1013-azure-dbgsym_4.13.0-1013.16_amd64.ddeb
 df74e605b86022fa78305910cc90b1a61a177a017959106a5510a0c63d7d711c 18520180 linux-image-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 9b7b150b34ae53b08b3f3ad0b17000bfc0a7b3319cf9352e98d1d1239a6aa603 9776492 linux-image-extra-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 f1827cb1f6c9f92c6b8de1041d4f43b3a099c641533fa3d609268b2fee7fb499 1882 linux-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
Files:
 1f5e0c79d6953a1b0a14bf0d4d165931 844 devel extra linux-azure-cloud-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 2f940ee0b078a18d7a190dc9c3119f7f 34454 devel optional linux-azure-cloud-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 cfeb7aaa04650531acc4223d3415fc4b 10735676 devel optional linux-azure-headers-4.13.0-1013_4.13.0-1013.16_all.deb
 e925fbf80e454b4edf363b2ebfd6c049 864 devel extra linux-azure-tools-4.13.0-1013-dbgsym_4.13.0-1013.16_amd64.ddeb
 62656ca2c359f727abf5e0bb572e2533 960048 devel optional linux-azure-tools-4.13.0-1013_4.13.0-1013.16_amd64.deb
 192a8168005dcca73f7a1aaecb878779 6839168 raw-uefi - linux-azure_4.13.0-1013.16_amd64.tar.gz
 f9fb61b82625176c60b2e27bd3cfc3bf 33978 raw-translations - linux-azure_4.13.0-1013.16_amd64_translations.tar.gz
 224389bd88c68a8688a1839bb12b675f 1810 devel optional linux-cloud-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 be78061c9d4e0055fa54572cbc755e35 523064 devel optional linux-headers-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 375b037530db979f8630dee7923e5ce1 312555242 devel optional linux-image-4.13.0-1013-azure-dbgsym_4.13.0-1013.16_amd64.ddeb
 bb661931c5a86a9d18fe3bf99c4a5b05 18520180 kernel optional linux-image-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 ea9bb1dbcc11f5d636027e2eba206e12 9776492 kernel optional linux-image-extra-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb
 cdd93105bdf119959932a3650bdde3de 1882 devel optional linux-tools-4.13.0-1013-azure_4.13.0-1013.16_amd64.deb


More information about the Xenial-changes mailing list