public inbox for stable@vger.kernel.org
 help / color / mirror / Atom feed
* Security fixes for 4.4
@ 2018-12-13 18:51 Ben Hutchings
  2018-12-13 18:52 ` Ben Hutchings
  2018-12-13 19:13 ` Greg Kroah-Hartman
  0 siblings, 2 replies; 18+ messages in thread
From: Ben Hutchings @ 2018-12-13 18:51 UTC (permalink / raw)
  To: Greg Kroah-Hartman, Sasha Levin; +Cc: stable

I've backported a number of fixes for security issues affecting 4.4-
stable.  All of these are already fixed in the newer stable branches.

For the BPF fix, I verified that the self-tests (taken from 4.14)
didn't regress and temporarily added logging to check that the
mitigation is applied when needed.

For the KVM changes, I verified that IBPB/IBRS are now exposed to and
used by a guest on Intel hardware.

I also verified that the current self-tests for timers, usercopy and vm
didn't regress.

Ben.

-- 
Ben Hutchings, Software Developer                         Codethink Ltd
https://www.codethink.co.uk/                 Dale House, 35 Dale Street
                                     Manchester, M1 2HF, United Kingdom

^ permalink raw reply	[flat|nested] 18+ messages in thread
* Security fixes for 4.4
@ 2017-11-15 21:10 Ben Hutchings
  2017-11-16 11:29 ` Greg Kroah-Hartman
                   ` (5 more replies)
  0 siblings, 6 replies; 18+ messages in thread
From: Ben Hutchings @ 2017-11-15 21:10 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: stable

[-- Attachment #1: Type: text/plain, Size: 762 bytes --]

Please apply the attached backported patches to 4.4-stable.  The
upstream commits are:

06bd3c36a733 ext4: fix data exposure after a crash
c8401dda2f0a KVM: x86: fix singlestepping over syscall
0d0e57697f16 bpf: don't let ldimm64 leak map addresses on unprivileged
089bc0143f48 xen-blkback: don't leak stack data via response ring
df80cd9b28b9 sctp: do not peel off an assoc from one netns to another one
2cb80187ba06 net: cdc_ether: fix divide by 0 on bad descriptors
7fd078337201 net: qmi_wwan: fix divide by 0 on bad descriptors

The last three are not in later stable branches yet.  The USB net
driver fixes are already in David Miller's queue for stable, and i have
asked him to add the sctp fix.

Ben.

-- 
Ben Hutchings
Software Developer, Codethink Ltd.

[-- Attachment #2: security-4.4.mbox --]
[-- Type: application/mbox, Size: 22890 bytes --]

^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2018-12-13 19:14 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-12-13 18:51 Security fixes for 4.4 Ben Hutchings
2018-12-13 18:52 ` Ben Hutchings
2018-12-13 19:13 ` Greg Kroah-Hartman
  -- strict thread matches above, loose matches on Subject: below --
2017-11-15 21:10 Ben Hutchings
2017-11-16 11:29 ` Greg Kroah-Hartman
2017-11-16 22:07   ` Theodore Ts'o
2017-11-17  8:10     ` Greg Kroah-Hartman
2017-11-17 13:30     ` Ben Hutchings
2017-11-20 14:02       ` Jan Kara
2017-11-17 12:06   ` Ben Hutchings
2017-11-17 12:25     ` Greg Kroah-Hartman
2017-11-16 11:31 ` Greg Kroah-Hartman
2017-11-16 11:32   ` Paolo Bonzini
2017-11-16 13:28     ` Greg Kroah-Hartman
2017-11-16 11:33 ` Greg Kroah-Hartman
2017-11-16 11:33 ` Greg Kroah-Hartman
2017-11-16 11:34 ` Greg Kroah-Hartman
2017-11-19 10:18 ` Greg Kroah-Hartman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox