Bug 57625 - firmware-nonfree: Multiple issues (5.0)
Summary: firmware-nonfree: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P5 normal
Target Milestone: UCS 5.0-9-errata
Assignee: Quality Assurance
QA Contact: Christian Castens
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-09-30 10:07 CEST by Quality Assurance
Modified: 2024-10-07 14:53 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 0.0 () debian/changelog


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2024-09-30 10:07:41 CEST
New Debian firmware-nonfree 20190114+really20220913-0+deb10u3 fixes:
This update addresses the following issues:
20190114+really20220913-0+deb10u3 (Mon, 09 Sep 2024 21:30:54 +0200)
* Non-maintainer upload by the LTS Security Team.
* Update to linux-support-5.10.0-0.deb9.30
[ Arturo Borrero Gonzalez ]
* iwlwifi: update firmware files for: - CVE-2023-35061 - potential  information disclosure via adjacent access - CVE-2023-38417 - potential  denial of service via adjacent access -
CVE-2023-47210 - potential denial of service via adjacent access For affected
hardware details, see Intel advisories: - INTEL-SA-00947 (CVE-2023-35061) -
INTEL-SA-01039 (CVE-2023-38417 and CVE-2023-47210) New and updated firmware
files come from the upstream linux-firmware repository version tag 20240115.
The updated firmware files might need an updated kernel.
[ Tobias Frost ]
* Add metadata for updated/new firmware files.
* Updated firmware files: intel/ibt-0041-0041.sfi intel/ibt-17-16-1.sfi  intel/ibt-17-2.sfi intel/ibt-18-16-1.sfi intel/ibt-18-2.sfi  intel/ibt-19-0-0.sfi intel/ibt-19-0-1.sfi intel/ibt-19-0-4.sfi  intel/ibt-19-16-4.sfi intel/ibt-19-240-1.sfi intel/ibt-19-240-4.sfi  intel/ibt-19-32-0.sfi intel/ibt-19-32-1.sfi intel/ibt-19-32-4.sfi  intel/ibt-20-0-3.sfi intel/ibt-20-1-3.sfi intel/ibt-20-1-4.sfi  iwlwifi-Qu-b0-hr-b0-77.ucode iwlwifi-Qu-b0-jf-b0-77.ucode  iwlwifi-Qu-c0-hr-b0-77.ucode iwlwifi-Qu-c0-jf-b0-77.ucode  iwlwifi-QuZ-a0-hr-b0-77.ucode iwlwifi-QuZ-a0-jf-b0-77.ucode  iwlwifi-cc-a0-77.ucode iwlwifi-so-a0-gf-a0-84.ucode  iwlwifi-so-a0-gf-a0-86.ucode iwlwifi-so-a0-gf-a0.pnvm  iwlwifi-so-a0-gf4-a0-84.ucode iwlwifi-so-a0-gf4-a0-86.ucode  iwlwifi-so-a0-gf4-a0.pnvm iwlwifi-so-a0-hr-b0-83.ucode  iwlwifi-so-a0-hr-b0-84.ucode iwlwifi-so-a0-hr-b0-86.ucode  iwlwifi-ty-a0-gf-a0-84.ucode iwlwifi-ty-a0-gf-a0-86.ucode  iwlwifi-ty-a0-gf-a0.pnvm
Comment 1 Arvid Requate univentionstaff 2024-10-02 13:05:05 CEST
The piuparts automation had some connectivity issue (403) accessing bugzilla.

LGTM: http://piuparts.knut.univention.de/5.0-9/#151875019663082314

There's the known issue with:
* ipw2x00 and ivtv ask for interactive confirmation due to EULA requirements, but piuparts can not handle this
Comment 2 Christian Castens univentionstaff 2024-10-02 21:34:59 CEST
OK: bug
OK: yaml
OK: announce_errata
OK: patch
~OK: piuparts

[5.0-9] ed2ae36267 Bug #57625: firmware-nonfree 20190114+really20220913-0+deb10u3
 doc/errata/staging/firmware-nonfree.yaml | 39 ++++++++------------------------
 1 file changed, 9 insertions(+), 30 deletions(-)

[5.0-9] 05b5915376 Bug #57625: firmware-nonfree 20190114+really20220913-0+deb10u3
 doc/errata/staging/firmware-nonfree.yaml | 43 ++++++++++++++++++++++++++++++++
 1 file changed, 43 insertions(+)
Comment 3 Iván.Delgado univentionstaff 2024-10-07 14:53:25 CEST
<https://errata.software-univention.de/#/?erratum=5.0x1128>