Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #71674 > unrolled thread

Firmware-nonfree update for buster?

Started byOla Lundqvist <ola@inguza.com>
First post2021-05-17 12:20 +0200
Last post2021-05-19 09:40 +0200
Articles 4 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  Firmware-nonfree update for buster? Ola Lundqvist <ola@inguza.com> - 2021-05-17 12:20 +0200
    Re: Firmware-nonfree update for buster? Moritz Muehlenhoff <jmm@inutil.org> - 2021-05-17 12:50 +0200
      Re: Firmware-nonfree update for buster? Ola Lundqvist <ola@inguza.com> - 2021-05-19 09:40 +0200
        Re: Firmware-nonfree update for buster? Moritz Muehlenhoff <jmm@inutil.org> - 2021-05-19 09:40 +0200

#71674 — Firmware-nonfree update for buster?

FromOla Lundqvist <ola@inguza.com>
Date2021-05-17 12:20 +0200
SubjectFirmware-nonfree update for buster?
Message-ID<CfIvT-5D1-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi firmware-nonfree maintainers

I have a question from an LTS perspective about the possible security
updates we have for the firmware-nonfree package.

You can find them here:
https://security-tracker.debian.org/tracker/source-package/firmware-nonfree

I can see that all the related CVEs are marked as no-dsa for buster, simply
because there is no security support for the non-free section. This rule
also applies to LTS but with the exception of the firmware-nonfree package.

My questions to you are the following:
1) Do you think any of the listed CVEs are important enough to warrant an
upload to buster and/or stretch?
2) Do you plan to do this for buster?
3) Would you mind if some LTS developer does such an upload for buster?

Having a later version in oldstable (compared to stable) is not a
good practice so if any of them are important we should update both
oldstable and stable.

Thank you in advance,

// Ola


-- 
 --- Inguza Technology AB --- MSc in Information Technology ----
|  ola@inguza.com                    opal@debian.org            |
|  http://inguza.com/                Mobile: +46 (0)70-332 1551 |
 ---------------------------------------------------------------

[toc] | [next] | [standalone]


#71675

FromMoritz Muehlenhoff <jmm@inutil.org>
Date2021-05-17 12:50 +0200
Message-ID<CfIYV-5Mp-3@gated-at.bofh.it>
In reply to#71674
On Mon, May 17, 2021 at 11:54:05AM +0200, Ola Lundqvist wrote:
> Hi firmware-nonfree maintainers
> 
> I have a question from an LTS perspective about the possible security
> updates we have for the firmware-nonfree package.
> 
> You can find them here:
> https://security-tracker.debian.org/tracker/source-package/firmware-nonfree

Did you even look at the CVEs in question? CVE-2020-1236[2,3,4] need
a kernel patch to actually allow to use the new firmware and that patch
isn't present in 4.19 (and ofc also not in 4.9)

Cheers,
        Moritz

[toc] | [prev] | [next] | [standalone]


#71701

FromOla Lundqvist <ola@inguza.com>
Date2021-05-19 09:40 +0200
Message-ID<CgoYa-5Ey-13@gated-at.bofh.it>
In reply to#71675

[Multipart message — attachments visible in raw view] — view raw

Hi Moritz

I only briefly looked at the CVEs. I relied on that front-desk had
considered that the package needs to be fixed.
This means that we need to fix both the kernel and the firmware-nonfree
packages to fix the problems.

The question remains however, do you think these are important enough to
warrant an update and do you plan to do that for stable?

Cheers

// Ola

On Mon, 17 May 2021 at 12:43, Moritz Muehlenhoff <jmm@inutil.org> wrote:

> On Mon, May 17, 2021 at 11:54:05AM +0200, Ola Lundqvist wrote:
> > Hi firmware-nonfree maintainers
> >
> > I have a question from an LTS perspective about the possible security
> > updates we have for the firmware-nonfree package.
> >
> > You can find them here:
> >
> https://security-tracker.debian.org/tracker/source-package/firmware-nonfree
>
> Did you even look at the CVEs in question? CVE-2020-1236[2,3,4] need
> a kernel patch to actually allow to use the new firmware and that patch
> isn't present in 4.19 (and ofc also not in 4.9)
>
> Cheers,
>         Moritz
>
>

-- 
 --- Inguza Technology AB --- MSc in Information Technology ----
|  ola@inguza.com                    opal@debian.org            |
|  http://inguza.com/                Mobile: +46 (0)70-332 1551 |
 ---------------------------------------------------------------

[toc] | [prev] | [next] | [standalone]


#71702

FromMoritz Muehlenhoff <jmm@inutil.org>
Date2021-05-19 09:40 +0200
Message-ID<CgoYa-5Ey-15@gated-at.bofh.it>
In reply to#71701
Ola Lundqvist wrote:
> I only briefly looked at the CVEs.

If you haven't even looked the issues properly don't waste other people's time.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web