Kernel 5.13 has a CVE, 5.12 is gone, plus 5.10, etc notes

Post here if you feel others can duplicate your so discovered "bug"

Moderator: Forum moderators

Post Reply
scsijon
Posts: 210
Joined: Fri Jul 24, 2020 10:11 am
Has thanked: 6 times
Been thanked: 21 times

Kernel 5.13 has a CVE, 5.12 is gone, plus 5.10, etc notes

Post by scsijon »

I'll top post for now, further notices may be added on the top or a new reply with the link on top, depending on needs.
-------------------------------------------------------------------------------
Just a little note that the stable branch 5.13 is up to 5.13.13, expect further updates to occur for things like CVE and major problems only.
AND
5.14 has been released but i'd recomend you wait a minor version (the zz in x.y.zz) update or two before trying it as it's still raw.

-------------------------------------------------------------------------------
Anyone on the 5.13 kernel stream please update to at least 5.13.12, NOT older, a CVE or three plus important bugfixes apply.
5.12 is now closed (past EOL) and should no longer be used, fixes will not ocurr. Please update to 5.13.12 or later.
5.10 LTS should be updated to 5.10.60 for the CVE fix.
Other CVE updated LTS are 5.2.142, 4.19.204, 4.14.244, 4.9.280 and 4.4.281.
Please note other kernel streams are no longer being supported or updated.
if anyone wants others included in these update lists, please advise with the reason in a reply post to this message.
I'll check this message before next updates occur.
regards
scsijon
Don't shoot the messanger, i'm just trying to help to keep you as safe as possible on the web!
------------------------------------------------------------------------------

Please be advised that kernel series 5.12 (currently .19) is at end-of-life, 5.13.4 is the step at this point of time.

Also most of the other series we seem to use have various CVE/SVE's now listed against them.
https://www.kernel.org/ lists series that are being fixed/maintained.
Please update to the latest revisions in your individual series or update to a maintained series if your not already as soon as possible as some of the CVE/SVE problems have been tracked back to 2014 and are nasty.

Last edited by scsijon on Tue Aug 31, 2021 7:55 am, edited 2 times in total.
ozsouth
Posts: 1713
Joined: Sun Jul 12, 2020 2:38 am
Location: S.E. Australia
Has thanked: 260 times
Been thanked: 781 times

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by ozsouth »

Peebee is updating 5.13 series upon release. I have recently restarted kernel production. I notice not many folk seem to bother downloading updates. As it takes me 2 hours minimum, I intend to update 5.10 series every 5-10 releases - about monthly/bimonthly (my current is 5.10.50).

dimkr
Posts: 2520
Joined: Wed Dec 30, 2020 6:14 pm
Has thanked: 53 times
Been thanked: 1273 times

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by dimkr »

The support window of regular kernel releases is short, and this makes it harder to stick with the latest kernel in a community distro like Puppy. Also, the frequent changes can break things and require update of the kernel configuration.

But longterm kernels (latest 5.4.x, 5.10.x, etc') are built every week at https://github.com/puppylinux-woof-CE/w ... el-kit.yml, and every Puppy that uses these kernels gets all security and CVE fixes 'for free'. All users, except those using super new hardware, can benefit from using these stable kernels.

User avatar
stemsee
Posts: 835
Joined: Sun Jul 26, 2020 8:11 am
Location: lattitude 8
Has thanked: 195 times
Been thanked: 144 times
Contact:

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by stemsee »

Hi dmkr

I compiled kernel 5.2.21-rt15 a while back and I'm using it on an Acer 714 chromebook, running fatdog, fossadog and fossapup. Of the various recent puppies these boot to a desktop, others get stuck in a blank screen, no prompt. Even fatdog's savefile chooser does not get displayed. The bootloader is visible, as it gets the kernel and initrd then, blanks until modules load, I guess ... as it's pre 'X', what video driver does it use, framebuffer? Anyway, most other pups get stuck in post boot, pre X, no prompt. Now, when I try to use the same config to compile a more recent kernel, it cannot boot to desktop or prompt! I hoped you might have some knowledge of the process to explain how to fix this. As this config, finds everything on the chromebook (kabylake) even sound and touchscreen (which doesn't get power and gets timed-out). So it would be great to figure this out!

cheers
stemsee

DOTconfig-5.2.21-x86_64.sfs
(40 KiB) Downloaded 33 times
scsijon
Posts: 210
Joined: Fri Jul 24, 2020 10:11 am
Has thanked: 6 times
Been thanked: 21 times

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by scsijon »

Those with version 5.10 should update to at least 5.10.52 to clear the CVE, 5.12 should update at least to 5.13.4 to clear the CVE/SVE. I won't list the problem, but as i said it was nasty.

dimkr
Posts: 2520
Joined: Wed Dec 30, 2020 6:14 pm
Has thanked: 53 times
Been thanked: 1273 times

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by dimkr »

scsijon wrote: Thu Jul 29, 2021 1:12 am

Those with version 5.10 should update to at least 5.10.52 to clear the CVE, 5.12 should update at least to 5.13.4 to clear the CVE/SVE. I won't list the problem, but as i said it was nasty.

The latest woof-CE run in https://github.com/puppylinux-woof-CE/w ... /build.yml already uses 5.10.53 :thumbup:

ozsouth
Posts: 1713
Joined: Sun Jul 12, 2020 2:38 am
Location: S.E. Australia
Has thanked: 260 times
Been thanked: 781 times

Re: Kernel 5.12 is at EOL and others have CVE/SVE's

Post by ozsouth »

I've made a 5.10.55 64bit kernel - see: viewtopic.php?p=32965#p32965

EDIT: have now made 5.10.61 kernel - see: viewtopic.php?p=35517#p35517

Last edited by ozsouth on Tue Aug 31, 2021 9:13 am, edited 2 times in total.
scsijon
Posts: 210
Joined: Fri Jul 24, 2020 10:11 am
Has thanked: 6 times
Been thanked: 21 times

Re: Kernel 5.13 has a CVE, 5.12 is gone, plus 5.10, etc notes

Post by scsijon »

updated first message

Thank you ozsouth for the 5.10 update

Post Reply

Return to “Bug Reports”