[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#254325: kernel-source-2.4.22: DoS in OSS Sound Blaster Driver (CAN-2004-0178)



On Sat, Jun 19, 2004 at 03:27:59PM +0100, Martin Michlmayr wrote:
> * Horms <horms@debian.org> [2004-06-15 20:10]:
> > 1. If Herbet is no longer the maintainer, who is?
> 
> A group of people which use debian-kernel@lists.debian.org to
> communicate; the effort is led by William Irwin <wli@holomorphy.com>

Thanks, I have subsequently joined that list.

> > 3. Are there any plans to remove any of these packages in the near
> >    future.
> 
> There have been efforts to reduce the number of kernel source packages
> in Debian.  Andreas Barth has done some work on this and can tell you
> more.  The plan is to ship with one source package per major revision
> (2.2, 2.4, 2.6; there have been talks about removing 2.2, but it seems
> some architectures still need it.)

Thanks, that sounds good to me.

> > 5. Is there a mailing list / web page / whatever that outlines
> >    what kernels are currently available in what distribution,
> >    which are planned for removal, etc...
> 
> Maybe Andreas Barth has collected this information.
> 
> > 6. Does anyone check the CVEs and other vendor's updated kernel
> >    package advisories as they come out to make sure that the
> >    debian packages are up to date?
> 
> > 7. Is there any value in me refiling these bugs, and possibly other
> >    of a similar vein, against other kernel-source packages.
> >    And if so, which ones?
> 
> Against the newest 2.4 and 2.6, but obviously only if they still have
> those problems.

Of course. I will look into which of the bugs are still present.
I don't think that many of the ones that i originally listed are
present in the latest kernel.org kernel.

-- 
Horms



Reply to: