Path: csiph.com!newsfeed.xs4all.nl!newsfeed7.news.xs4all.nl!feeds.phibee-telecom.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod From: maximilian attems Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#970395: firmware-nonfree: Please add AMD-SEV firmware files (amd-folder) to close CVE-2019-9836 on specific EPYC-CPUs Date: Fri, 25 Sep 2020 14:20:02 +0200 Message-ID: References: X-Original-To: Henrique de Moraes Holschuh X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Fri Sep 25 12:18:09 2020 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -4.199 Reply-To: maximilian attems , 970395@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Debian Kernel Team X-Debian-Pr-Message: followup 970395 X-Debian-Pr-Package: src:firmware-nonfree X-Debian-Pr-Source: firmware-nonfree X-Spam-Bayes: score:0.0000 Tokens: new, 12; hammy, 150; neutral, 161; spammy, 0. spammytokens: hammytokens:0.000-+--UD:kernel.org, 0.000-+--H*ct:application, 0.000-+--H*ct:protocol, 0.000-+--H*ct:micalg, 0.000-+--H*ct:signed MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="dDRMvlgZJXvWKvBx" Content-Disposition: inline X-Debian-Message: from BTS X-Mailing-List: archive/latest/1624580 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 100 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Cc: 970395@bugs.debian.org, debian-kernel@lists.debian.org, Michael Musenbrock X-Original-Date: Fri, 25 Sep 2020 14:14:09 +0200 X-Original-Message-ID: <20200925121409.GA502516@photino.stro.at> X-Original-References: <160018174325.43250.13621988053918949874.reportbug@ipa> <160018174325.43250.13621988053918949874.reportbug@ipa> <20200920083612.GA186746@photino.stro.at> <160018174325.43250.13621988053918949874.reportbug@ipa> <20200920083612.GA186746@photino.stro.at> Xref: csiph.com linux.debian.bugs.dist:1026386 linux.debian.kernel:68259 --dDRMvlgZJXvWKvBx Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Dear Henrique, It be great to get your input, hence repinging (; Especially as linux-firmware is the common upstream source, it be ideal to = ship the amd64 mircrocode out of our firmware packages. Thanks for letting us know. kind regards, maximilian On Sun, Sep 20, 2020 at 10:36:12AM +0200, maximilian attems wrote: > Dear Henrique, dear debian kernel maintainers, Cc: Michael, >=20 > Would you agree to generate the amd64-firmware packages directly out of t= he debian > linux-firmware source package? >=20 > This way the microcode would be updated on every linux-firmware non-free = upload? > I am asking as it keeps nugging me to have to outcomment the updates of t= hat > microcode in the changelog (there is again a new one for the upcoming 202= 00918). >=20 > Would you want to be added in counterpart to the uploaders of firmware-no= nfree? >=20 > Thank you very much for your amd64 microcode work. >=20 > kind regards, > maximilian >=20 > On Tue, Sep 15, 2020 at 04:55:43PM +0200, Michael Musenbrock wrote: > > Source: firmware-nonfree > > Severity: important > >=20 > > Dear maintainer, > >=20 > > first of all thanks for maintaining and packaging the linux-firmware fi= les repository as debian packages. > >=20 > > We currently need to manually obtain the linux-firmware.git:amd/amd_sev= _fam17h_model3xh.sbin [1] file on > > our AMD EPYC servers. The firmware files containing the AMD SEV firmwar= e closing security vulnerabilities [2] > > and fixes bugs and adds improvements to the AMD SEV implementation. > >=20 > > I'm most likely unqualified for legal questions but the LICENSE.amd-sev= [3] reads quite similar to the already > > added amdgpu license [4]. So I hope this is not the reason, why those f= iles were not added in the past. > >=20 > > The severity was choosen because it fixes a security vulnerability, ple= ase change accordingly if you think > > it is wrong. > >=20 > > Thanks in advance. Best regards, > > michael > >=20 > > [1] https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firm= ware.git/tree/amd > > [2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-9836 > > [3] https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firm= ware.git/tree/LICENSE.amd-sev > > [4] https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firm= ware.git/tree/LICENSE.amdgpu > >=20 --dDRMvlgZJXvWKvBx Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEtitdpKMURvAU+NZkECUuZTqR5ScFAl9t3wkACgkQECUuZTqR 5Scekw/9EBCdrUnnril/gTgcPmk16pxErjIT/4OCZ+kkl1LGkmPIGoK1I7/fZpuL FMiz3VVvBUadvh6jmeObghQBRwgVkSWX8AgTH0aRDLm1mv0LqH0CoTTVCpwXmQ+C qsMEGwGqwgdt3h7G0gQuVifzPSfNk4ln8pqbWgrT/7QjaJlo+LsI/cHljU7T6iiU //MVOV8jH7tkCpj8bIpOEYrVJ7KtH+1vs34AsNLwImn562qh3txxY4osTjKq1pdE BqtbZ5dehsy9ERsT7Osbv/z1H62KiF/3wa28nA+rRxfDnACffUJjpjRnxSM+DDaY d/axgtBYtiYmPEDjFBAjj+pNQiifeXv18iqGlN5iJ+PUAvdOgreOQgvFrjLXDMKF IgKpKU1RMaD7Lr1RegtJLbEJRSOTIyx0fu66Zlv/6gaW3bklHrZPXwy9Sgypqn7A js2GxGR1DyppjdNIYA8f/Uebrvr8s6K6o8fHKUWCOnJVxnA3ap4fRG9PRCkvh3sT XdCp/L+zx1JtcmnA+qC2z3gPF+ZttD9PaW0OcFvd1T11BDPwJ0MuQmsAZSXQVWh+ /mcFuW8j0GHduPBWM1Zn8OP5VwMke1/yO2JFwpljekIqkLfQpNPM7u1np/2iHC6g 95Dhs4y8ZBag5owVNrx35HGzapU/ltza+UwCFYFkNcqd8sGg/2M= =eXoC -----END PGP SIGNATURE----- --dDRMvlgZJXvWKvBx--