Hi I would like to upload linux version 6.4.4-1 later the upcoming days to unstable. This is quite unfortunate as i wanted to have the security fixes from 6.3.11-1 for a while now in unstable, but transition is blocked due #1040178.
The new upload would consist of a new upstream version switching to the 6.4.y series in unstable. An ABi bump is included. Prominently the new version will finally fix CVE-2023-3269 (StackRot, cf. DSA-5448-1), and as well CVE-2023-31248 and CVE-2023-35001 in nf_tables. Apart from switching from 6.3.y to 6.4.y series there are additional changes covering: * [riscv64] enable CONFIG_SND_HDA_INTEL as module * Compile with gcc-13 on all architectures * [rt] Refresh "serial: 8250: implement non-BKL console" * kernel/trace: Enable FPROBE * d/rules.real: Fix CROSS_COMPILE definition for hppa native build (regression in 6.4~rc7-1~exp1) * Include kbuild package into ABI. (closes: #1040178) * [powerpc,riscv64,s390x] Enable DEBUG_INFO_BTF. * [riscv64] Enable devices added in 6.4 for StarFive JH7110 RISC-V SoC: SENSORS_SFCTEMP, MMC_DW, MMC_DW_STARFIVE and STARFIVE_WATCHDOG. * [hppa] Allow up to 16 CPUs with 32-bit kernel * [hppa] Build some more fbdev graphic card drivers as modules * Enable all RTW88 variants (USB + SDIO). (Closes: #1038409) * [rt] Update to 6.4-rt6 * [x86] drivers/platform/x86/hp: Enable X86_PLATFORM_DRIVERS_HP (Closes: #1038799) * mm: Enable Multi-Gen LRU implementation (by default) (Closes: #1030617) * linux-perf: Add libtraceevent-dev to Build-Depends (fixes FTBFS on several architectures) * linux-image: Define CROSS_COMPILE and CROSS_COMPILE_COMPAT more consistently * [hppa] linux-headers: Fix toolchain dependencies * [hppa] Make cross-builds work * [m68k] Fix invalid .section syntax (fixes FTBFS) * d/rules.real: Also remove executable bit from dtbo files * [mips*]: Enable more drivers for boston * [mips*]: Install dtbs for mipsel and mips64el * linux-perf: Update build rules and dependencies for change to demangling * linux-perf: Build C++ code with Debian standard compiler flags Having 6.3.11-1 into testing would really have been preferred but I understand people do not want to have #1040178 exposed, so let's try to move ahead with the 6.4.y series. Ben and Bastian, let me know loudly if you disagree on the plan to upload 6.4.4-1 for unstable. Regards, Salvatore
signature.asc
Description: PGP signature