Bug 28475 - kernel-firmware-nonfree, radeon-firmware updates to newer snapshot
Summary: kernel-firmware-nonfree, radeon-firmware updates to newer snapshot
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-02-27 19:26 CET by David Walser
Modified: 2021-03-04 13:28 CET (History)
3 users (show)

See Also:
Source RPM: kernel-firmware-nonfree, radeon-firmware
CVE:
Status comment:


Attachments

Description David Walser 2021-02-27 19:26:30 CET
Fedora has issued an advisory on February 12:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OYMW2FLWDF4E2RZCDQTAWMIPXRIE4AY3/

I believe Thomas already updated this in Cauldron.
David Walser 2021-02-27 19:26:39 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Thomas Backlund 2021-02-27 19:38:34 CET
Mga8 and Cauldron have same snapshot currently, but I need to rework kernel-firmware-nonfree packaging a bit now that upstream tree started using the symlink info in whence...
Comment 2 Thomas Backlund 2021-02-27 20:37:47 CET
never mind... 
I forgot I already switched to relying on firmware Makefile some 10 months ago: http://svnweb.mageia.org/packages/cauldron/kernel-firmware-nonfree/current/SPECS/kernel-firmware-nonfree.spec?r1=1548625&r2=1566367

and that takes care of parsing the WHENCE and adds the necessary firmware symlnks..
Comment 3 Morgan Leijström 2021-03-01 01:45:10 CET
mga7-64 running OK on latest kernel, nvidia, etc according to
https://bugs.mageia.org/show_bug.cgi?id=28467#c2
Including
- kernel-firmware-nonfree-20210223-1.mga7.nonfree.x86_64
Also installed is
- radeon-firmware-20210211-1.mga7.nonfree.x86_64
But i have a nvidia GPU.

CC: (none) => fri

Thomas Backlund 2021-03-01 18:04:12 CET

Blocks: (none) => 28500

Thomas Backlund 2021-03-01 18:04:36 CET

Version: 8 => 7
Whiteboard: MGA7TOO => (none)

Comment 4 Thomas Backlund 2021-03-01 18:07:20 CET
SRPMS:
kernel-firmware-nonfree-20210223-1.mga7.nonfree.src.rpm
radeon-firmware-20210211-1.mga7.nonfree.src.rpm


noarch:
iwlwifi-firmware-20210223-1.mga7.nonfree.noarch.rpm
kernel-firmware-nonfree-20210223-1.mga7.nonfree.noarch.rpm
radeon-firmware-20210211-1.mga7.nonfree.noarch.rpm
ralink-firmware-20210223-1.mga7.nonfree.noarch.rpm
rtlwifi-firmware-20210223-1.mga7.nonfree.noarch.rpm

Assignee: tmb => qa-bugs
Blocks: 28500 => (none)

Comment 5 Thomas Backlund 2021-03-01 19:06:25 CET
advisory, added to svn:

type: security
subject: Updated nonfree firmware packages fix security vulnerability
CVE:
 - CVE-2019-15126
src:
  7:
   nonfree:
     - kernel-firmware-nonfree-20210223-1.mga7.nonfree
     - radeon-firmware-20210211-1.mga7.nonfree
description: |
  Updated nonfree firmwares fixees various issues, adds new / improved
  hardware support and fixes atleast the following security issue:

  An issue was discovered on Broadcom Wi-Fi client devices. Specifically
  timed and handcrafted traffic can cause internal errors (related to
  state transitions) in a WLAN device that lead to improper layer 2
  Wi-Fi encryption with a consequent possibility of information
  disclosure over the air for a discrete set of traffic (CVE-2019-15126).

  Full list of updates:
  * kernel-firmware-nonfree:
    - add firmware for Lontium LT9611UXC DSI to HDMI bridge
    - brcm: Add NVRAM for Vamrs 96boards Rock960
    - brcm: make AP6212 in bananpi m2 plus/zero work
    - brcm: Link RPi4's WiFi firmware with DMI machine name
    - brcm: Update Raspberry Pi 3B+/4B NVRAM for downstream changes
    - brcm: remove old brcm firmwares that have newer cypress variants
      (CVE-2019-15126)
    - cypress: Link the new cypress firmware to the old brcm files
      (CVE-2019-15126)
    - i915: Add GuC firmware v49.0.1 for all platforms
    - i915: Add GuC v49.0.1 for DG1
    - i915: Add HuC v7.7.1 for DG1
    - i915: Add DMC v2.01 for ADL-S
    - mediatek: update MT8173 VPU firmware to v1.1.6
    - mediatek: add firmware for MT7921
    - Mellanox: Add new mlxsw_spectrum firmware xx.2008.2304
    - QCA : Updated firmware files for WCN3991
    - qcom: add firmware files for Adreno a650
    - qcom: Add SM8250 Audio DSP firmware
    - qcom: Add SM8250 Compute DSP firmware
    - qcom: Add venus firmware files for VPU-1.0

  * iwlwifi-firmware:
    - Update firmware for Intel Bluetooth 9260, 9560 to 22.20.0.3
    - Update firmware for Intel Bluetooth AX200, AX201, AX210 to 22.30.0.4

  * rtlwifi-firmware:
    - rtl_bt: Update RTL8821C BT(USB I/F) FW to 0x829a_7644
    - rtl_bt: Update RTL8822C BT(USB I/F) FW to 0x099a_7253
    - rtl_bt: Update RTL8822C BT(UART I/F) FW to 0x059A_25CB
    - rtl_bt: Add firmware and config files for RTL8852A BT USB chip
    - rtw88: RTL8821C: Update firmware to v24.8 (for rfe type 2 support)
    - rtw88: RTL8822C: Update normal firmware to v9.9.5 (performance fixes)
    - rtw89: 8852a: add firmware v0.9.12.2

  * radeon-firmware:
    - amdgpu: add initial firmware for green sardine
references:
 - https://bugs.mageia.org/show_bug.cgi?id=28475

Keywords: (none) => advisory

Comment 6 Aurelien Oudelet 2021-03-04 11:30:40 CET
MGA7-64 Plasma, Intel AX200 WiFi  + Bluetooth 5.0

Updates OK.
WiFi + Bluetooth OK
No errors in system journal.

Also on another system with Intel AC 8260 WiFi 5 + Bluetooth 4.1.
Functionalities OK

MGA7-64-OK
Validating.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA7-64-OK
CC: (none) => ouaurelien, sysadmin-bugs

Comment 7 Mageia Robot 2021-03-04 13:28:24 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0103.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.