[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#990897: unblock: linux/5.10.46-1



Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: unblock
X-Debbugs-Cc: carnil@debian.org,kibi@debian.org

Hi release team, hi Cyril (specifically for d-i)

Please unblock package linux

It contained a rebase of the 5.10.y series to 5.10.46 upstream and
included the following changes relevant to add additional HW support
and bugfxes. The upstream import to 5.10.46 contained fixes for
various CVEs.

The explicit other changes in the packaging are:

   * [armhf] drivers/bluetooth: Enable BT_HCIUART as a module, with support
     for all features already enabled in the generic config. (Closes: #987361)
   * [armhf] enable i.MX6 MIPI-CSI video capture device. (Closes: #987365)
     - drivers/mux: Enable MUX_MMIO as a module.
     - drivers/media/platform: Enable VIDEO_MUX as a module.
     - drivers/staging/media/imx: Enable VIDEO_IMX_MEDIA and VIDEO_IMX_CSI as
       modules.
   * [arm64] Update device tree for Kobol's helios64 from next
   * [rt] Refresh "net/Qdisc: use a seqlock instead seqcount"
   * Ignore some ABI changes that should not affect OOT modules
   * Bump ABI to 8
   * [rt] Refresh "tracing: Merge irqflags + preempt counter"
   * can: bcm: delay release of struct bcm_op after synchronize_rcu()
     (CVE-2021-3609)
   * Revert "PCI: PM: Do not read power state in pci_enable_device_flags()"
     (Closes: #990008)
   * [arm64] Add pwm-rockchip to fb-modules udeb.
   * [arm64] Add fusb302, tcpm and typec to usb-modules udeb.
   * [armhf] Add gpio-mxc to kernel-image udeb. Thanks to Rick Thomas.
     (Closes: #982270)

The relevant CVEs fixed were: CVE-2020-26141, CVE-2020-26145,
CVE-2021-33624, CVE-2021-34693, CVE-2021-3609, CVE-2020-24586,
CVE-2020-24587, CVE-2020-24588, CVE-2020-26139, CVE-2020-26147,
CVE-2021-28691, CVE-2021-3564, CVE-2021-3573 and CVE-2021-3587.
In particular this covered the fragattacks CVEs and the recently
published bpf related issues.

I guess at this point we want to delay any further 5.10.y imports to
the first bullseye point release, but let me know your toughts on
this.

Regards,
Salvatore


Reply to: