historical-speck.lore.kernel.org archive mirror
 help / color / mirror / Atom feed
* [MODERATED] Debian problem with Slow Randomizing Boosts DoS
@ 2020-06-08 19:06 Salvatore Bonaccorso
  2020-06-08 20:08 ` [MODERATED] " Stewart, David C
  0 siblings, 1 reply; 2+ messages in thread
From: Salvatore Bonaccorso @ 2020-06-08 19:06 UTC (permalink / raw)
  To: speck

Hi

A human error caused today that the changelog entry for the planned
4.9.210-1+deb9u1 upload in Debian covering the SRBDS mitigation
changes were for a short time leaked on
https://tracker.debian.org/linux (the message was sent as well to 56
subscribers for the tracker entry).

The leaked information covers the following changelog entries:

 linux (4.9.210-1+deb9u1) stretch-security; urgency=high
[...]
   * [x86] Add support for mitigation of Special Register Buffer Data Sampling
     (SRBDS) (CVE-2020-0543):
     - x86/cpu: Add 'table' argument to cpu_matches()
     - x86/speculation: Add Special Register Buffer Data Sampling (SRBDS)
       mitigation
     - x86/speculation: Add SRBDS vulnerability and mitigation documentation
     - x86/speculation: Add Ivy Bridge to affected list
   * [x86] speculation: Do not match steppings, to avoid an ABI change
[...]

The packages itself were not exposed. The NEWS entry on
https://tracker.debian.org/linux was removed.

On behalf I want to apologies for this mistake, and steps were taken
to avoid this in future.

Salvatore

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [MODERATED] Re: Debian problem with Slow Randomizing Boosts DoS
  2020-06-08 19:06 [MODERATED] Debian problem with Slow Randomizing Boosts DoS Salvatore Bonaccorso
@ 2020-06-08 20:08 ` Stewart, David C
  0 siblings, 0 replies; 2+ messages in thread
From: Stewart, David C @ 2020-06-08 20:08 UTC (permalink / raw)
  To: speck

Salvatore - thank you for the heads up. We made folks here at Intel aware. Thanks also for the process improvement.

Dave

On 6/8/20, 12:07 PM, "speck for Salvatore Bonaccorso" <speck@linutronix.de> wrote:

> A human error caused today that the changelog entry for the planned
> 4.9.210-1+deb9u1 upload in Debian covering the SRBDS mitigation
> changes were for a short time leaked on
> https://tracker.debian.org/linux (the message was sent as well to 56
> subscribers for the tracker entry).

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2020-06-08 20:08 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-06-08 19:06 [MODERATED] Debian problem with Slow Randomizing Boosts DoS Salvatore Bonaccorso
2020-06-08 20:08 ` [MODERATED] " Stewart, David C

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).