Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192672

Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

From Roberto C. Sánchez <roberto@debian.org>
Newsgroups linux.debian.user
Subject Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Date 2018-02-19 15:30 +0100
Message-ID <vkUC5-46d-13@gated-at.bofh.it> (permalink)
References <vkTwm-3uw-7@gated-at.bofh.it> <vkTPH-3AI-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, Feb 19, 2018 at 01:23:25PM +0000, Michael Fothergill wrote:
> 
>    ​Checkout the debian backports suite (kindly resourcefully suggested by
>    Andy Smith)
>    Easiest thing to do when requiring a newer kernel would be to check
>    the backports suite, so in this case in stretch-backports we find
>    linux-image-amd64:
> 
>        <[5]https://packages.debian.org/stretch-backports/linux-image-amd64>
> 
>    That's a virtual package that gets you the latest real kernel
>    package available in that suite, which right now is
>    linux-image-4.14.0-0.bpo.3-amd64:
> 
>        <[6]https://packages.debian.org/stretch-backports/linux-image-amd64>
> 
>    >From there, if you look on the right you will see the Debian
>    changelog link
>    <[7]http://ftp-master.metadata.debian.org/changelogs//main/l/linux/linux_4.14.13-1~bpo9+1_changelog>
>    which tells us that this corresponds to upstream release 4.14.13.
>    The upstream release was made on 10 January and this backports
>    package came on 14 January, so that's pretty swift.
> 
>    Newer kernels should be there now and there may well be one that deals
>    with both the meltdown and spectre vaulbnerabilities jointly.
> 
No!!!!!!!!!!

That is not at all how the backports repository is intended to be used.
I have been maintaining Debian packages for many years and I have on
occasion uploaded backports of my packages.

The packages in backports are not specifically supported by the security
team. They are supported only by the maintainer of the package (or the
uploader of the backport, as any Debain Developer can technically upload
backports of any package).

Security updates are nearly always handled by the security team,
somtimes with the support of the package maintainer (the kernel is a
good example where the maintainers do much of the heavy lifting). That
said, packages in the backports repository can easily be outdated (both
with respect the to the latest version in testing/unstable and with
respect to security fixes in stable).

Don't get me wrong, backports are immensely useful in some cases. In
particular, for the kernel, backports are quite handy when you need
support for newer hardware than what is available in stable. That said,
users of backports must understand that part of the cost of using
backports is that security fixes may be delayed, or may never arrive in
backports.

I understand what you are trying to advise the OP, but your reasoning is
all wrong. For someone running stable, the most secure configuration is
stable-only. In this particular instance it happens that there is a new
upstream release available in backports that addresses the specific
security vulnerability which concerns the OP. However, this is by far
the case for security vulnerabilities in general.

I would stronly recommend against your approach as a means to obtain
proper security fixes. It will inevitably lead to the mistaken
impression that a system is properly secured when it in fact may have
outstanding security vulnerabilities.

Regards,

-Roberto

-- 
Roberto C. Sánchez

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Is Debian Linux protected against the Meltdown and Spectre security flaws? Turritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com> - 2018-02-19 14:20 +0100
  Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 14:40 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 15:30 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:00 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-20 14:50 +0100
  Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 15:20 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:00 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 18:10 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:50 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 19:10 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:30 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 20:10 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 20:20 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 22:30 +0100
              Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:10 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 09:30 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 11:10 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 16:00 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-02-20 10:20 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 16:20 +0100
  Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 15:20 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 20:20 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-19 21:30 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 21:50 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 00:20 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-20 00:30 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Vincent Lefevre <vincent@vinc17.net> - 2018-02-27 17:10 +0100

csiph-web