--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: linux-image-5.2.0-2-amd64: Kernel does not accept self-signed modules using UEFI db key
- From: Sven Willner <sven.willner@gmail.com>
- Date: Fri, 13 Sep 2019 16:01:05 +0200
- Message-id: <156838326570.20647.17448716775485254687.reportbug@casaubon>
Package: src:linux
Version: 5.2.9-2
Severity: important
Dear Maintainer,
I sign the kernel for UEFI secure boot with my own key and also do so for custom-build kernel modules such as "vboxdrv" for VirtualBox (package virtualbox-6.0). This worked without a flaw for linux-image-4.19.0-5-amd64, but this kernel version rejects the signature:
> sudo modprobe -v vboxdrv
insmod /lib/modules/5.2.0-2-amd64/misc/vboxdrv.ko
modprobe: ERROR: could not insert 'vboxdrv': Operation not permitted
In `dmesg` I see my key being loaded:
[ 1.609556] integrity: Loading X.509 certificate: UEFI:db
[ 1.609992] integrity: Loaded X.509 cert 'My kernel signing key: XXXXXXXXXXXXXXXXXXXXXX'
it also appears in `cat /proc/keys`, but is probably not trusted:
> sudo keyctl list "%:.builtin_trusted_keys"
2 keys in keyring:
813811236: ---lswrv 0 0 asymmetric: Debian Secure Boot CA: 6ccece7e4c6c0d1f6149f3dd27dfcc5cbb419ea1
915392374: ---lswrv 0 0 asymmetric: Debian Secure Boot Signer: 00a7468def
I suspect this is due to kernel config CONFIG_SECONDARY_TRUSTED_KEYRING not being set:
> grep CONFIG_SECONDARY_TRUSTED_KEYRING /boot/config-5.2.0-2-amd64
# CONFIG_SECONDARY_TRUSTED_KEYRING is not set
whereas
> grep CONFIG_SECONDARY_TRUSTED_KEYRING /boot/config-4.19.0-5-amd64
CONFIG_SECONDARY_TRUSTED_KEYRING=y
Could you please also set this configuration value in this version?
Thank you very much.
Best regards,
Sven
-- Package-specific info:
** Version:
Linux version 5.2.0-2-amd64 (debian-kernel@lists.debian.org) (gcc version 8.3.0 (Debian 8.3.0-21)) #1 SMP Debian 5.2.9-2 (2019-08-21)
** Command line:
resume=/dev/mapper/casaubon--vg-swap_1 root=/dev/mapper/casaubon--vg-root ro splash quiet loglevel=3 add_efi_memmap biosdevname=0 cgroup_enable=memory drm.vblankoffdelay=1 elevator=noop i915.enable_dc=2 i915.enable_fbc=1 i915.fastboot=1 net.ifnames=0 rd.systemd.show_status=auto rd.udev.log_priority=3 swapaccount=1 vga=current vt.global_cursor_default=0
** Tainted: U (64)
* Userspace-defined naughtiness.
** Kernel log:
Unable to read kernel log; any relevant messages should be attached
** Model information
sys_vendor: Dell Inc.
product_name: Latitude 7480
product_version:
chassis_vendor: Dell Inc.
chassis_version:
bios_vendor: Dell Inc.
bios_version: 1.6.5
board_vendor: Dell Inc.
board_name: 00F6D3
board_version: A00
** Loaded modules:
sha512_ssse3
sha512_generic
ipheth
xt_TPROXY
nf_tproxy_ipv6
nf_tproxy_ipv4
xt_tcpudp
xt_socket
nf_socket_ipv4
nf_socket_ipv6
nf_defrag_ipv6
nf_defrag_ipv4
xt_mark
nft_compat
nft_counter
nf_tables
nfnetlink
bnep
cdc_ether
usbnet
r8152
mii
snd_usb_audio
snd_usbmidi_lib
snd_rawmidi
snd_seq_device
uvcvideo
videobuf2_vmalloc
videobuf2_memops
videobuf2_v4l2
videobuf2_common
videodev
media
zram
zsmalloc
btusb
btrtl
btbcm
btintel
bluetooth
drbg
ansi_cprng
binfmt_misc
ecdh_generic
ecc
nls_ascii
nls_cp437
vfat
fat
arc4
snd_hda_codec_hdmi
snd_soc_skl
snd_soc_skl_ipc
snd_soc_sst_ipc
snd_soc_sst_dsp
snd_hda_ext_core
intel_rapl
snd_soc_acpi_intel_match
snd_hda_codec_realtek
snd_soc_acpi
snd_hda_codec_generic
snd_soc_core
iwlmvm
x86_pkg_temp_thermal
intel_powerclamp
dell_rbtn
snd_compress
mac80211
coretemp
kvm_intel
snd_hda_intel
dell_laptop
snd_hda_codec
mei_wdt
ledtrig_audio
kvm
watchdog
irqbypass
iwlwifi
snd_hda_core
dell_smm_hwmon
snd_hwdep
intel_cstate
efi_pstore
snd_pcm
intel_uncore
dell_wmi
snd_timer
dell_smbios
dcdbas
serio_raw
intel_wmi_thunderbolt
efivars
intel_rapl_perf
cfg80211
wmi_bmof
dell_wmi_descriptor
snd
soundcore
rtsx_pci_ms
rfkill
joydev
memstick
sg
mei_me
intel_pch_thermal
mei
idma64
processor_thermal_device
intel_soc_dts_iosf
battery
pcc_cpufreq
ac
intel_hid
acpi_pad
sparse_keymap
evdev
int3403_thermal
int340x_thermal_zone
int3400_thermal
acpi_thermal_rel
parport_pc
ppdev
lp
parport
efivarfs
ip_tables
x_tables
autofs4
ext4
crc16
mbcache
jbd2
crc32c_generic
dm_crypt
dm_mod
hid_lenovo
usbhid
hid_alps
hid_generic
sd_mod
crct10dif_pclmul
crc32_pclmul
crc32c_intel
ghash_clmulni_intel
i2c_designware_platform
i2c_designware_core
i915
rtsx_pci_sdmmc
mmc_core
aesni_intel
i2c_algo_bit
aes_x86_64
e1000e
ahci
crypto_simd
cryptd
glue_helper
libahci
drm_kms_helper
libata
ptp
pps_core
rtsx_pci
xhci_pci
drm
scsi_mod
xhci_hcd
i2c_i801
usbcore
intel_lpss_pci
i2c_hid
hid
usb_common
wmi
intel_lpss_acpi
video
intel_lpss
mfd_core
button
** PCI devices:
00:00.0 Host bridge [0600]: Intel Corporation Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Host Bridge/DRAM Registers [8086:1904] (rev 08)
Subsystem: Dell Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Host Bridge/DRAM Registers [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort+ >SERR- <PERR- INTx-
Latency: 0
Capabilities: <access denied>
Kernel driver in use: skl_uncore
00:02.0 VGA compatible controller [0300]: Intel Corporation Skylake GT2 [HD Graphics 520] [8086:1916] (rev 07) (prog-if 00 [VGA controller])
DeviceName: Onboard IGD
Subsystem: Dell Skylake GT2 [HD Graphics 520] [1028:07a0]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 133
Region 0: Memory at eb000000 (64-bit, non-prefetchable) [size=16M]
Region 2: Memory at a0000000 (64-bit, prefetchable) [size=256M]
Region 4: I/O ports at f000 [size=64]
[virtual] Expansion ROM at 000c0000 [disabled] [size=128K]
Capabilities: <access denied>
Kernel driver in use: i915
00:04.0 Signal processing controller [1180]: Intel Corporation Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Thermal Subsystem [8086:1903] (rev 08)
Subsystem: Dell Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Thermal Subsystem [1028:07a0]
Control: I/O- Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Interrupt: pin A routed to IRQ 16
Region 0: Memory at ec240000 (64-bit, non-prefetchable) [size=32K]
Capabilities: <access denied>
Kernel driver in use: proc_thermal
00:14.0 USB controller [0c03]: Intel Corporation Sunrise Point-LP USB 3.0 xHCI Controller [8086:9d2f] (rev 21) (prog-if 30 [XHCI])
Subsystem: Dell Sunrise Point-LP USB 3.0 xHCI Controller [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 129
Region 0: Memory at ec230000 (64-bit, non-prefetchable) [size=64K]
Capabilities: <access denied>
Kernel driver in use: xhci_hcd
00:14.2 Signal processing controller [1180]: Intel Corporation Sunrise Point-LP Thermal subsystem [8086:9d31] (rev 21)
Subsystem: Dell Sunrise Point-LP Thermal subsystem [1028:07a0]
Control: I/O- Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Interrupt: pin C routed to IRQ 18
Region 0: Memory at ec25a000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel_pch_thermal
00:15.0 Signal processing controller [1180]: Intel Corporation Sunrise Point-LP Serial IO I2C Controller #0 [8086:9d60] (rev 21)
Subsystem: Dell Sunrise Point-LP Serial IO I2C Controller [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 16
Region 0: Memory at ec259000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
00:15.1 Signal processing controller [1180]: Intel Corporation Sunrise Point-LP Serial IO I2C Controller #1 [8086:9d61] (rev 21)
Subsystem: Dell Sunrise Point-LP Serial IO I2C Controller [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin B routed to IRQ 17
Region 0: Memory at ec258000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
00:15.2 Signal processing controller [1180]: Intel Corporation Sunrise Point-LP Serial IO I2C Controller #2 [8086:9d62] (rev 21)
Subsystem: Dell Sunrise Point-LP Serial IO I2C Controller [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin C routed to IRQ 18
Region 0: Memory at ec257000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: intel-lpss
00:16.0 Communication controller [0780]: Intel Corporation Sunrise Point-LP CSME HECI #1 [8086:9d3a] (rev 21)
Subsystem: Dell Sunrise Point-LP CSME HECI [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 135
Region 0: Memory at ec256000 (64-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: mei_me
00:16.3 Serial controller [0700]: Intel Corporation Sunrise Point-LP Active Management Technology - SOL [8086:9d3d] (rev 21) (prog-if 02 [16550])
Subsystem: Dell Sunrise Point-LP Active Management Technology - SOL [1028:07a0]
Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap+ 66MHz+ UDF- FastB2B+ ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Interrupt: pin D routed to IRQ 19
Region 0: I/O ports at f0a0 [size=8]
Region 1: Memory at ec255000 (32-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: serial
00:17.0 SATA controller [0106]: Intel Corporation Sunrise Point-LP SATA Controller [AHCI mode] [8086:9d03] (rev 21) (prog-if 01 [AHCI 1.0])
Subsystem: Dell Sunrise Point-LP SATA Controller [AHCI mode] [1028:07a0]
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz+ UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 130
Region 0: Memory at ec250000 (32-bit, non-prefetchable) [size=8K]
Region 1: Memory at ec254000 (32-bit, non-prefetchable) [size=256]
Region 2: I/O ports at f090 [size=8]
Region 3: I/O ports at f080 [size=4]
Region 4: I/O ports at f060 [size=32]
Region 5: Memory at ec253000 (32-bit, non-prefetchable) [size=2K]
Capabilities: <access denied>
Kernel driver in use: ahci
00:1c.0 PCI bridge [0604]: Intel Corporation Sunrise Point-LP PCI Express Root Port #1 [8086:9d10] (rev f1) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 122
Bus: primary=00, secondary=01, subordinate=01, sec-latency=0
I/O behind bridge: None
Memory behind bridge: ec100000-ec1fffff [size=1M]
Prefetchable memory behind bridge: None
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort+ <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
00:1c.2 PCI bridge [0604]: Intel Corporation Sunrise Point-LP PCI Express Root Port #3 [8086:9d12] (rev f1) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin C routed to IRQ 123
Bus: primary=00, secondary=02, subordinate=02, sec-latency=0
I/O behind bridge: None
Memory behind bridge: ec000000-ec0fffff [size=1M]
Prefetchable memory behind bridge: None
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort+ <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
00:1c.4 PCI bridge [0604]: Intel Corporation Sunrise Point-LP PCI Express Root Port #5 [8086:9d14] (rev f1) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 124
Bus: primary=00, secondary=03, subordinate=3b, sec-latency=0
I/O behind bridge: 00002000-00004fff [size=12K]
Memory behind bridge: d4000000-ea0fffff [size=353M]
Prefetchable memory behind bridge: 00000000b0000000-00000000d1ffffff [size=544M]
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort+ <TAbort- <MAbort+ <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
00:1f.0 ISA bridge [0601]: Intel Corporation Sunrise Point-LP LPC Controller [8086:9d48] (rev 21)
Subsystem: Dell Sunrise Point-LP LPC Controller [1028:07a0]
Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
00:1f.2 Memory controller [0580]: Intel Corporation Sunrise Point-LP PMC [8086:9d21] (rev 21)
Subsystem: Dell Sunrise Point-LP PMC [1028:07a0]
Control: I/O- Mem- BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap- 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Region 0: Memory at ec24c000 (32-bit, non-prefetchable) [disabled] [size=16K]
00:1f.3 Audio device [0403]: Intel Corporation Sunrise Point-LP HD Audio [8086:9d70] (rev 21)
Subsystem: Dell Sunrise Point-LP HD Audio [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 32
Interrupt: pin B routed to IRQ 137
Region 0: Memory at ec248000 (64-bit, non-prefetchable) [size=16K]
Region 4: Memory at ec220000 (64-bit, non-prefetchable) [size=64K]
Capabilities: <access denied>
Kernel driver in use: snd_hda_intel
00:1f.4 SMBus [0c05]: Intel Corporation Sunrise Point-LP SMBus [8086:9d23] (rev 21)
Subsystem: Dell Sunrise Point-LP SMBus [1028:07a0]
Control: I/O+ Mem+ BusMaster- SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx-
Status: Cap- 66MHz- UDF- FastB2B+ ParErr- DEVSEL=medium >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Interrupt: pin A routed to IRQ 16
Region 0: Memory at ec252000 (64-bit, non-prefetchable) [size=256]
Region 4: I/O ports at f040 [size=32]
Kernel driver in use: i801_smbus
00:1f.6 Ethernet controller [0200]: Intel Corporation Ethernet Connection (4) I219-LM [8086:15d7] (rev 21)
Subsystem: Dell Ethernet Connection (4) I219-LM [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 131
Region 0: Memory at ec200000 (32-bit, non-prefetchable) [size=128K]
Capabilities: <access denied>
Kernel driver in use: e1000e
01:00.0 Unassigned class [ff00]: Realtek Semiconductor Co., Ltd. RTS525A PCI Express Card Reader [10ec:525a] (rev 01)
Subsystem: Dell RTS525A PCI Express Card Reader [1028:07a0]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 132
Region 1: Memory at ec100000 (32-bit, non-prefetchable) [size=4K]
Capabilities: <access denied>
Kernel driver in use: rtsx_pci
02:00.0 Network controller [0280]: Intel Corporation Wireless 8265 / 8275 [8086:24fd] (rev 78)
Subsystem: Intel Corporation Wireless 8265 / 8275 [8086:0050]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0
Interrupt: pin A routed to IRQ 136
Region 0: Memory at ec000000 (64-bit, non-prefetchable) [size=8K]
Capabilities: <access denied>
Kernel driver in use: iwlwifi
03:00.0 PCI bridge [0604]: Intel Corporation JHL6340 Thunderbolt 3 Bridge (C step) [Alpine Ridge 2C 2016] [8086:15da] (rev 02) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 125
Bus: primary=03, secondary=04, subordinate=3b, sec-latency=0
I/O behind bridge: 00002000-00003fff [size=8K]
Memory behind bridge: d4000000-ea0fffff [size=353M]
Prefetchable memory behind bridge: 00000000b0000000-00000000d1ffffff [size=544M]
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
04:00.0 PCI bridge [0604]: Intel Corporation JHL6340 Thunderbolt 3 Bridge (C step) [Alpine Ridge 2C 2016] [8086:15da] (rev 02) (prog-if 00 [Normal decode])
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 126
Bus: primary=04, secondary=05, subordinate=05, sec-latency=0
I/O behind bridge: None
Memory behind bridge: ea000000-ea0fffff [size=1M]
Prefetchable memory behind bridge: None
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
04:01.0 PCI bridge [0604]: Intel Corporation JHL6340 Thunderbolt 3 Bridge (C step) [Alpine Ridge 2C 2016] [8086:15da] (rev 02) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 127
Bus: primary=04, secondary=06, subordinate=3a, sec-latency=0
I/O behind bridge: 00002000-00002fff [size=4K]
Memory behind bridge: d4000000-e9efffff [size=351M]
Prefetchable memory behind bridge: 00000000b0000000-00000000d1ffffff [size=544M]
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
04:02.0 PCI bridge [0604]: Intel Corporation JHL6340 Thunderbolt 3 Bridge (C step) [Alpine Ridge 2C 2016] [8086:15da] (rev 02) (prog-if 00 [Normal decode])
Control: I/O+ Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 128
Bus: primary=04, secondary=3b, subordinate=3b, sec-latency=0
I/O behind bridge: 00003000-00003fff [size=4K]
Memory behind bridge: e9f00000-e9ffffff [size=1M]
Prefetchable memory behind bridge: None
Secondary status: 66MHz- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- <SERR- <PERR-
BridgeCtl: Parity- SERR+ NoISA- VGA- VGA16+ MAbort- >Reset- FastB2B-
PriDiscTmr- SecDiscTmr- DiscTmrStat- DiscTmrSERREn-
Capabilities: <access denied>
Kernel driver in use: pcieport
3b:00.0 USB controller [0c03]: Intel Corporation JHL6340 Thunderbolt 3 USB 3.1 Controller (C step) [Alpine Ridge 2C 2016] [8086:15db] (rev 02) (prog-if 30 [XHCI])
Subsystem: Device [2222:1111]
Control: I/O- Mem+ BusMaster+ SpecCycle- MemWINV- VGASnoop- ParErr- Stepping- SERR- FastB2B- DisINTx+
Status: Cap+ 66MHz- UDF- FastB2B- ParErr- DEVSEL=fast >TAbort- <TAbort- <MAbort- >SERR- <PERR- INTx-
Latency: 0, Cache Line Size: 128 bytes
Interrupt: pin A routed to IRQ 134
Region 0: Memory at e9f00000 (32-bit, non-prefetchable) [size=64K]
Capabilities: <access denied>
Kernel driver in use: xhci_hcd
** USB devices:
Bus 004 Device 003: ID 0bda:8153 Realtek Semiconductor Corp. RTL8153 Gigabit Ethernet Adapter
Bus 004 Device 002: ID 0424:5807 Standard Microsystems Corp. Hub
Bus 004 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
Bus 003 Device 005: ID 0424:2514 Standard Microsystems Corp. USB 2.0 Hub
Bus 003 Device 004: ID 0bda:4014 Realtek Semiconductor Corp.
Bus 003 Device 006: ID 05ac:12a8 Apple, Inc. iPhone5/5C/5S/6
Bus 003 Device 003: ID 17ef:6047 Lenovo USB2807 Hub
Bus 003 Device 002: ID 0424:2807 Standard Microsystems Corp. Hub
Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
Bus 001 Device 002: ID 0c45:6717 Microdia Integrated_Webcam_HD
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
-- System Information:
Debian Release: bullseye/sid
APT prefers testing
APT policy: (990, 'testing'), (20, 'stable'), (10, 'unstable')
Architecture: amd64 (x86_64)
Kernel: Linux 5.2.0-2-amd64 (SMP w/4 CPU cores)
Kernel taint flags: TAINT_USER
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages linux-image-5.2.0-2-amd64 depends on:
ii initramfs-tools [linux-initramfs-tool] 0.135
ii kmod 26-1
ii linux-base 4.6
Versions of packages linux-image-5.2.0-2-amd64 recommends:
ii apparmor 2.13.3-4
ii firmware-linux-free 3.4
Versions of packages linux-image-5.2.0-2-amd64 suggests:
pn debian-kernel-handbook <none>
pn grub-pc | grub-efi-amd64 | extlinux <none>
pn linux-doc-5.2 <none>
Versions of packages linux-image-5.2.0-2-amd64 is related to:
ii firmware-amd-graphics 20190717-1
pn firmware-atheros <none>
pn firmware-bnx2 <none>
pn firmware-bnx2x <none>
pn firmware-brcm80211 <none>
pn firmware-cavium <none>
ii firmware-intel-sound 20190717-1
pn firmware-intelwimax <none>
pn firmware-ipw2x00 <none>
pn firmware-ivtv <none>
ii firmware-iwlwifi 20190717-1
pn firmware-libertas <none>
ii firmware-linux-nonfree 20190717-1
ii firmware-misc-nonfree 20190717-1
pn firmware-myricom <none>
pn firmware-netxen <none>
pn firmware-qlogic <none>
pn firmware-realtek <none>
pn firmware-samsung <none>
pn firmware-siano <none>
pn firmware-ti-connectivity <none>
pn xen-hypervisor <none>
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: linux
Source-Version: 5.3.7-1
We believe that the bug you reported is fixed in the latest version of
linux, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 935945@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated linux package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 20 Oct 2019 00:56:32 +0200
Binary: linux-doc linux-doc-5.3 linux-headers-5.3.0-1-common linux-source linux-source-5.3 linux-support-5.3.0-1
Source: linux
Architecture: all source
Version: 5.3.7-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Kernel Team <debian-kernel@lists.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 935945 940530 940726
Description:
linux-doc - Linux kernel specific documentation (meta-package)
linux-doc-5.3 - Linux kernel specific documentation for version 5.3
linux-headers-5.3.0-1-common - Common header files for Linux 5.3.0-1
linux-source - Linux kernel source (meta-package)
linux-source-5.3 - Linux kernel source for version 5.3 with Debian patches
linux-support-5.3.0-1 - Support files for Linux 5.3
Changes:
linux (5.3.7-1) unstable; urgency=medium
.
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.3
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.4
- mISDN: enforce CAP_NET_RAW for raw sockets (CVE-2019-17055)
- appletalk: enforce CAP_NET_RAW for raw sockets (CVE-2019-17054)
- ax25: enforce CAP_NET_RAW for raw sockets (CVE-2019-17052)
- ieee802154: enforce CAP_NET_RAW for raw sockets (CVE-2019-17053)
- nfc: enforce CAP_NET_RAW for raw sockets (CVE-2019-17056)
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.5
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.6
- nl80211: validate beacon head (CVE-2019-16746)
https://www.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.3.7
.
[ Aurelien Jarno ]
* [riscv64] Enable SOC_SIFIVE. Do not select CLK_SIFIVE,
CLK_SIFIVE_FU540_PRCI, SIFIVE_PLIC, SERIAL_SIFIVE and
SERIAL_SIFIVE_CONSOLE as they are selected by SOC_SIFIVE.
* [riscv64] Install DTBS using dtbs_install target.
* [riscv64] Enable SPI_SIFIVE.
* [riscv64] Enable SERIAL_EARLYCON_RISCV_SBI.
* [riscv64] Enable MMC, MMC_SPI.
* [riscv64] udeb: Add mmc-core-modules and mmc-modules.
* [riscv64] Fix memblock reservation for device tree blob.
* [riscv64] Clear load reservations while restoring hart contexts.
.
[ Ben Hutchings ]
* [mips*] Revert "Only define MAX_PHYSMEM_BITS on Loongson-3"
* KEYS: Re-enable SECONDARY_TRUSTED_KEYRING, dropped in 5.2.6-1 by
mis-merge (Closes: #935945)
.
[ John Paul Adrian Glaubitz ]
* [m68k] Enable CONFIG_CRYPTO_MANAGER_DISABLE_TESTS
* [hppa] Enable CONFIG_CRYPTO_MANAGER_DISABLE_TESTS
* [sh4] Enable CONFIG_CRYPTO_MANAGER_DISABLE_TESTS
.
[ Salvatore Bonaccorso ]
* RDMA/cxgb4: Do not dma memory off of the stack (CVE-2019-17075)
* ath6kl: fix a NULL-ptr-deref bug in ath6kl_usb_alloc_urb_from_pipe()
(CVE-2019-15098)
.
[ Romain Perier ]
* [armel/rpi] Enable CONFIG_BRCMFMAC_SDIO (Closes: #940530)
.
[ Héctor Orón Martínez ]
* [x86] Enable ASoC: SOF sound driver (Closes: #940726)
Checksums-Sha1:
dd39fa2e65c62ec7c17add4d1578bbbff0429bd3 197683 linux_5.3.7-1.dsc
45d9f10d69dceefafb5e9d1e29ad3e6e58bb96ff 112780220 linux_5.3.7.orig.tar.xz
ca48db4fb3ff8e40daf4b8dbdfaa598e92f673b5 1161944 linux_5.3.7-1.debian.tar.xz
71a522cf99e7872587c484cb2722bc2a08c4c5ad 48127 linux_5.3.7-1_source.buildinfo
45a3592576cd34f2c145fec7cf078ee303eb0314 23082928 linux-doc-5.3_5.3.7-1_all.deb
5b297e8a819ae1e44c9c3ab779b492c25d76b642 916 linux-doc_5.3.7-1_all.deb
86212659324eaf57c5a595e3b5efda1705ced0f4 8241652 linux-headers-5.3.0-1-common_5.3.7-1_all.deb
5d01961c534b93f080166348857e291c466eeca8 111565576 linux-source-5.3_5.3.7-1_all.deb
b1f295b76ee1f3036bef1e2e250ba22142fa0a09 912 linux-source_5.3.7-1_all.deb
f8d8f14538bfcb93dbc2ddda3b4595d5c3c1a90d 83344 linux-support-5.3.0-1_5.3.7-1_all.deb
ad6e953567931073c23451652ceb12cec45789cc 53027 linux_5.3.7-1_all.buildinfo
Checksums-Sha256:
f725294a5feb858139b883e06173869822e13f3946416d0c2c59c40b05e34348 197683 linux_5.3.7-1.dsc
8a020a6770a87aa332be1f2cbf419b99b6c33bb578a27a91bea1011ec7ea860a 112780220 linux_5.3.7.orig.tar.xz
ce04f29431a3a8fb6cb17f6c2cdce6201130c99c24cd7e1ba0198f4334352de6 1161944 linux_5.3.7-1.debian.tar.xz
b48149c4befeda3f341dbe046efdb49e83434779a4109a7646d5984aa9fe8fcf 48127 linux_5.3.7-1_source.buildinfo
b10f9939021844b5556f84fba3713aa830020892d857c452e407b76aa7f7334d 23082928 linux-doc-5.3_5.3.7-1_all.deb
9d05cb498d530c8aab18d70784fdda212a16a90c5be5bed87d4dca2abd7a3c20 916 linux-doc_5.3.7-1_all.deb
8308c4de8557bfc5f5aacd4103b5c0a40e57c3f9e5f22a11d9e6681d813e6cae 8241652 linux-headers-5.3.0-1-common_5.3.7-1_all.deb
6ad099c99fe4b90dd65f0e75270fbca1e80ac4964a3a41afd58ab5f436d95f3e 111565576 linux-source-5.3_5.3.7-1_all.deb
fbf230a975ff9578713066afc2a2ae1382ae47ad1b3045a042d7ff9ab33b30a1 912 linux-source_5.3.7-1_all.deb
e38b36003e5de24817cf02b59cd7a125cfebbb0f09629087f25df1416fca8e3f 83344 linux-support-5.3.0-1_5.3.7-1_all.deb
8b7276033768df6531c0394b758319a9784261121b4382be1ca16bd47f77fbe8 53027 linux_5.3.7-1_all.buildinfo
Files:
224ae06dcf067d07244098801e5e6e50 197683 kernel optional linux_5.3.7-1.dsc
0c287d56961660bf8c8e22a552ce3f24 112780220 kernel optional linux_5.3.7.orig.tar.xz
d0372e61ee173e29920e571ca37298e3 1161944 kernel optional linux_5.3.7-1.debian.tar.xz
20071d3bfe471705adc486dced8e64a5 48127 kernel optional linux_5.3.7-1_source.buildinfo
8bbb3c27f0b062f027cf82197f25b165 23082928 doc optional linux-doc-5.3_5.3.7-1_all.deb
f09b6031409c84585c75241f9c429aa4 916 doc optional linux-doc_5.3.7-1_all.deb
b6cbc2cee8cbe6fa16d6cbecc6c8d909 8241652 kernel optional linux-headers-5.3.0-1-common_5.3.7-1_all.deb
1f29f7ab89f6eac21cc948101b2a105d 111565576 kernel optional linux-source-5.3_5.3.7-1_all.deb
190dbee7f69bd31fe636929d1debb758 912 kernel optional linux-source_5.3.7-1_all.deb
8c4918bc0b4c324acc9a4c5cff3c06f9 83344 devel optional linux-support-5.3.0-1_5.3.7-1_all.deb
de597c307bb08c7012faab98c841aa31 53027 kernel optional linux_5.3.7-1_all.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl2sqVNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ETysP/0JnTG3SxUF0Es5xIzyVPWUlD233kVFe
O9kP29f7nZW0ltFptAcdX6vTUmnPCjhVMbIwL2Y97EAxgK5mkttG/6AVPsy2cL50
3inrvppu1UiBJ1wgdZ6+XXlOIfbithTkjqtZxt1rx72xJfnPeGFSek/3729yMewP
+sG+VLVDIymx338KEYueq85XckxWtbYZ5z+eJfSaHum/cjSj1Xai6yCVK2+2Adlt
6H849i1E4Pqz/ua8BWMlBChIKxlp2mt5eQgglgI5h6seQOs01gdSIqo5SnWH1UBS
XpGV8OLyjAVAyMopNqhZXcO6H+Oj2PdW35MQH37Yn0tqgWA3M+U+ceRJmwr4i12r
pL444KJgTsrMJaNecEoNjLzd9GwZFc6MYQEczT7mRmswghKsd1ItEFCjYLCfOU+F
2HhzNixrXUa5ZaqkN1U51Lvm9rXRS+PL5zCUopg2mC3/KdgvmM/C8tbiUSrDBQSv
g/MzzlrMOjUujbwQGnv+h4jEiBT2fd9mdM2gU9DN1+U3pc/t9RA0eP/cC6++WrKx
yTr0DAgaz/TIrs8aVsP7XIJhCrsIf8RUBiT1M8n4Sz2i3p1bQymz67Ww/7zRnzDb
+svbF+DmZZ8VaqddSY0uP3spyMiM/5PgWtVqx/c+neUVbPKuYx31OkaYwFziJ5gp
UoFliekSmX2C
=jbPc
-----END PGP SIGNATURE-----
--- End Message ---