Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #71674 > unrolled thread
| Started by | Ola Lundqvist <ola@inguza.com> |
|---|---|
| First post | 2021-05-17 12:20 +0200 |
| Last post | 2021-05-19 09:40 +0200 |
| Articles | 4 — 2 participants |
Back to article view | Back to linux.debian.kernel
Firmware-nonfree update for buster? Ola Lundqvist <ola@inguza.com> - 2021-05-17 12:20 +0200
Re: Firmware-nonfree update for buster? Moritz Muehlenhoff <jmm@inutil.org> - 2021-05-17 12:50 +0200
Re: Firmware-nonfree update for buster? Ola Lundqvist <ola@inguza.com> - 2021-05-19 09:40 +0200
Re: Firmware-nonfree update for buster? Moritz Muehlenhoff <jmm@inutil.org> - 2021-05-19 09:40 +0200
| From | Ola Lundqvist <ola@inguza.com> |
|---|---|
| Date | 2021-05-17 12:20 +0200 |
| Subject | Firmware-nonfree update for buster? |
| Message-ID | <CfIvT-5D1-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hi firmware-nonfree maintainers I have a question from an LTS perspective about the possible security updates we have for the firmware-nonfree package. You can find them here: https://security-tracker.debian.org/tracker/source-package/firmware-nonfree I can see that all the related CVEs are marked as no-dsa for buster, simply because there is no security support for the non-free section. This rule also applies to LTS but with the exception of the firmware-nonfree package. My questions to you are the following: 1) Do you think any of the listed CVEs are important enough to warrant an upload to buster and/or stretch? 2) Do you plan to do this for buster? 3) Would you mind if some LTS developer does such an upload for buster? Having a later version in oldstable (compared to stable) is not a good practice so if any of them are important we should update both oldstable and stable. Thank you in advance, // Ola -- --- Inguza Technology AB --- MSc in Information Technology ---- | ola@inguza.com opal@debian.org | | http://inguza.com/ Mobile: +46 (0)70-332 1551 | ---------------------------------------------------------------
[toc] | [next] | [standalone]
| From | Moritz Muehlenhoff <jmm@inutil.org> |
|---|---|
| Date | 2021-05-17 12:50 +0200 |
| Message-ID | <CfIYV-5Mp-3@gated-at.bofh.it> |
| In reply to | #71674 |
On Mon, May 17, 2021 at 11:54:05AM +0200, Ola Lundqvist wrote:
> Hi firmware-nonfree maintainers
>
> I have a question from an LTS perspective about the possible security
> updates we have for the firmware-nonfree package.
>
> You can find them here:
> https://security-tracker.debian.org/tracker/source-package/firmware-nonfree
Did you even look at the CVEs in question? CVE-2020-1236[2,3,4] need
a kernel patch to actually allow to use the new firmware and that patch
isn't present in 4.19 (and ofc also not in 4.9)
Cheers,
Moritz
[toc] | [prev] | [next] | [standalone]
| From | Ola Lundqvist <ola@inguza.com> |
|---|---|
| Date | 2021-05-19 09:40 +0200 |
| Message-ID | <CgoYa-5Ey-13@gated-at.bofh.it> |
| In reply to | #71675 |
[Multipart message — attachments visible in raw view] — view raw
Hi Moritz I only briefly looked at the CVEs. I relied on that front-desk had considered that the package needs to be fixed. This means that we need to fix both the kernel and the firmware-nonfree packages to fix the problems. The question remains however, do you think these are important enough to warrant an update and do you plan to do that for stable? Cheers // Ola On Mon, 17 May 2021 at 12:43, Moritz Muehlenhoff <jmm@inutil.org> wrote: > On Mon, May 17, 2021 at 11:54:05AM +0200, Ola Lundqvist wrote: > > Hi firmware-nonfree maintainers > > > > I have a question from an LTS perspective about the possible security > > updates we have for the firmware-nonfree package. > > > > You can find them here: > > > https://security-tracker.debian.org/tracker/source-package/firmware-nonfree > > Did you even look at the CVEs in question? CVE-2020-1236[2,3,4] need > a kernel patch to actually allow to use the new firmware and that patch > isn't present in 4.19 (and ofc also not in 4.9) > > Cheers, > Moritz > > -- --- Inguza Technology AB --- MSc in Information Technology ---- | ola@inguza.com opal@debian.org | | http://inguza.com/ Mobile: +46 (0)70-332 1551 | ---------------------------------------------------------------
[toc] | [prev] | [next] | [standalone]
| From | Moritz Muehlenhoff <jmm@inutil.org> |
|---|---|
| Date | 2021-05-19 09:40 +0200 |
| Message-ID | <CgoYa-5Ey-15@gated-at.bofh.it> |
| In reply to | #71701 |
Ola Lundqvist wrote: > I only briefly looked at the CVEs. If you haven't even looked the issues properly don't waste other people's time.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web