[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Better communication about spectre/meltdown



On Sun, Apr 01, 2018 at 07:48:55AM -0400, Roberto C. Sánchez wrote:
> 
> At this point I feel like the packages are ready for upload, but it
> seems prudent to first wait for confirmation that the kernel build on
> wheezy works with this backported gcc. Once I receive that confirmation,
> I will proceed with uploading and releasing a DLA (patterned after
> DSA-4117-1). Is there anything special that will need to be done in
> order to introduce a new source package to wheezy?
> 
I have attached my proposed DLA text to this mail. Please feel free to
offer suggestions on improving the text.

Regards,

-Roberto

-- 
Roberto C. Sánchez
Package        : gcc-4.9
CVE ID         : not applicable

This update doesn't fix a vulnerability in GCC itself, but instead
provides support for building retpoline-enabled Linux kernel updates.

Special note: The gcc-4.9 package is new to Debian 7 "Wheezy" as of this
update. Attempts to patch gcc-4.6, the gcc package in Wheezy used to
build the Linux kernel, were to found to be infeasible. As a results, it
was decided to backport the gcc-4.9 package from Debian 8 "Jessie" to
enable building retpoline-enabled Linux kernel packages and to support
users who require gcc packages with retpoline support.

For Debian 7 "Wheezy", this problem has been fixed in version
4.9.2-10+deb7u1.

We recommend that you upgrade your gcc-4.9 packages.

For the detailed security status of gcc-4.9 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gcc-4.9


Reply to: