Xenial update to 4.4.114 stable release
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Stefan Bader |
Bug Description
SRU Justification
Impact:
The upstream process for stable tree updates is quite similar
in scope to the Ubuntu SRU process, e.g., each patch has to
demonstrably fix a bug, and each patch is vetted by upstream
by originating either directly from a mainline/stable Linux tree or
a minimally backported form of that patch. The 4.4.114 upstream stable
patch set is now available. It should be included in the Ubuntu
kernel as well.
TEST CASE: TBD
The following patches from the 4.4.114 stable release shall be applied:
* x86/asm/32: Make sync_core() handle missing CPUID on all 32-bit kernels
* usbip: prevent vhci_hcd driver from leaking a socket pointer address
* usbip: Fix implicit fallthrough warning
* usbip: Fix potential format overflow in userspace tools
* x86/microcode/
* x86/retpoline: Fill RSB on context switch for affected CPUs
* sched/deadline: Use the revised wakeup rule for suspending constrained dl tasks
* can: af_can: can_rcv(): replace WARN_ONCE by pr_warn_once
* can: af_can: canfd_rcv(): replace WARN_ONCE by pr_warn_once
* PM / sleep: declare __tracedata symbols as char[] rather than char
* time: Avoid undefined behaviour in ktime_add_safe()
* timers: Plug locking race vs. timer migration
* Prevent timer value 0 for MWAITX
* drivers: base: cacheinfo: fix x86 with CONFIG_OF enabled
* drivers: base: cacheinfo: fix boot error message when acpi is enabled
* PCI: layerscape: Add "fsl,ls2085a-pcie" compatible ID
* PCI: layerscape: Fix MSG TLP drop setting
* mmc: sdhci-of-esdhc: add/remove some quirks according to vendor version
* fs/select: add vmalloc fallback for select(2)
* hwpoison, memcg: forcibly uncharge LRU pages
* cma: fix calculation of aligned offset
* mm, page_alloc: fix potential false positive in __zone_watermark_ok
* ipc: msg, make msgrcv work with LONG_MIN
* x86/ioapic: Fix incorrect pointers in ioapic_
* ACPI / processor: Avoid reserving IO regions too early
* ACPI / scan: Prefer devices without _HID/_CID for _ADR matching
* ACPICA: Namespace: fix operand cache leak
* netfilter: x_tables: speed up jump target validation
* netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in
64bit kernel
* netfilter: nf_dup_ipv6: set again FLOWI_FLAG_KNOWN_NH at flowi6_flags
* netfilter: nf_ct_expect: remove the redundant slash when policy name is empty
* netfilter: nfnetlink_queue: reject verdict request from different portid
* netfilter: restart search if moved to other chain
* netfilter: nf_conntrack_sip: extend request line validation
* netfilter: use fwmark_reflect in nf_send_reset
* ext2: Don't clear SGID when inheriting ACLs
* reiserfs: fix race in prealloc discard
* reiserfs: don't preallocate blocks for extended attributes
* reiserfs: Don't clear SGID when inheriting ACLs
* fs/fcntl: f_setown, avoid undefined behaviour
* scsi: libiscsi: fix shifting of DID_REQUEUE host byte
* Input: trackpoint - force 3 buttons if 0 button is reported
* usb: usbip: Fix possible deadlocks reported by lockdep
* usbip: fix stub_rx: get_pipe() to validate endpoint number
* usbip: fix stub_rx: harden CMD_SUBMIT path to handle malicious input
* usbip: prevent leaking socket pointer address in messages
* um: link vmlinux with -no-pie
* vsyscall: Fix permissions for emulate mode with KAISER/PTI
* eventpoll.h: add missing epoll event masks
* x86/microcode/
* hrtimer: Reset hrtimer cpu base proper on CPU hotplug
* dccp: don't restart ccid2_hc_
* ipv6: Fix getsockopt() for sockets with default IPV6_AUTOFLOWLABEL
* ipv6: fix udpv6 sendmsg crash caused by too small MTU
* ipv6: ip6_make_skb() needs to clear cork.base.dst
* lan78xx: Fix failure in USB Full Speed
* net: igmp: fix source address check for IGMPv3 reports
* tcp: __tcp_hdrlen() helper
* net: qdisc_pkt_
* pppoe: take ->needed_headroom of lower device into account on xmit
* r8169: fix memory corruption on retrieval of hardware statistics.
* sctp: do not allow the v4 socket to bind a v4mapped v6 address
* sctp: return error if the asoc has been peeled off in sctp_wait_
* vmxnet3: repair memory leak
* net: Allow neigh contructor functions ability to modify the primary_key
* ipv4: Make neigh lookup keys for loopback/
* flow_dissector: properly cap thoff field
* net: tcp: close sock if net namespace is exiting
* nfsd: auth: Fix gid sorting when rootsquash enabled
* Linux 4.4.114
tags: | added: kernel-stable-tracking-bug |
Changed in linux (Ubuntu Xenial): | |
assignee: | nobody → Stefan Bader (smb) |
importance: | Undecided → Medium |
status: | New → In Progress |
Changed in linux (Ubuntu): | |
status: | New → Invalid |
description: | updated |
Changed in linux (Ubuntu Xenial): | |
status: | In Progress → Fix Committed |
Deliberately skipping "Revert "module: Add retpoline tag to VERMAGIC"" because we decided we actually are fine with flagging things that way.
Skipping because already applied:
* Slow system response time due to a monitor bug (bug 1606147)
- x86/cpu/intel: Introduce macros for Intel family numbers
* CVE-2017-1000364
- mm/mmap.c: do not blow on PROT_NONE MAP_FIXED holes in the stack
* CVE-2017-17448
- netfilter: nfnetlink_cthelper: Add missing permission checks
* CVE-2017-17450
- netfilter: xt_osf: Add missing permission checks
We backported the following set for (bug 16407868):
* netfilter: x_tables: pass xt_counters struct instead of packet
counter
* netfilter: x_tables: pass xt_counters struct to counter allocator
* netfilter: x_tables: pack percpu counter allocations
this caused the following stable patch to be not needed in Xenial:
* netfilter: fix IS_ERR_VALUE usage
Skipped until later decision (Spectre v2 upstream):
* x86/retpoline: Fill RSB on context switch for affected CPUs
-> re-defines the SPEC_CTRL bit with a different name and does
some STUFF_RSB related things