Your message dated Sat, 17 May 2025 09:37:58 +0000 with message-id <E1uGDzS-005KIa-Ap@coccia.debian.org> and subject line Close 1104893 has caused the Debian Bug report #1104893, regarding bookworm-pu: package nvidia-open-gpu-kernel-modules/535.247.01-1~deb12u1 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1104893: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1104893 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: bookworm-pu: package nvidia-open-gpu-kernel-modules/535.247.01-1~deb12u1
- From: Andreas Beckmann <anbe@debian.org>
- Date: Thu, 08 May 2025 01:12:04 +0200
- Message-id: <[🔎] 174665952436.3568751.12472479581347046213.reportbug@caipi>
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian.org@packages.debian.org Usertags: pu X-Debbugs-Cc: nvidia-open-gpu-kernel-modules@packages.debian.org Control: affects -1 + src:nvidia-open-gpu-kernel-modules [ Reason ] In order to fix a few CVEs we need to update src:nvidia-open-gpu-kernel-modules (and src:nvidia-graphics-drivers in lock-step for firmware-nvidia-gsp) to a new upstream release. [ Impact ] A proprietary graphics driver with unfixed CVEs. [ Tests ] autopkgtests for building the kernel module. [ Risks ] Updating the nvidia driver stack to a new upstream release in stable is an established procedure. [ Checklist ] [*] *all* changes are documented in the d/changelog [*] I reviewed all changes and I approve them [*] attach debdiff against the package in (old)stable only for the debian/ directory [*] the issue is verified as fixed in unstable [ Changes ] + * New upstream LTS and Tesla branch release 535.247.01 (2025-04-17). + * Fixed CVE-2025-23244. (Closes: #1104076) + https://nvidia.custhelp.com/app/answers/detail/a_id/5630 + * New upstream LTS and Tesla branch release 535.230.02 (2025-01-16). + * Fixed CVE-2024-0150, CVE-2024-0147, CVE-2024-53869, CVE-2024-0131, + CVE-2024-0149. (Closes: #1093916) + https://nvidia.custhelp.com/app/answers/detail/a_id/5614 + * Do not add -mfunction-return=thunk-extern flag, breaks backwards + compatibility with kernels built without this flag. + * Apply both patch sets manually. + * Backport NV_MODULE_IMPORT_NS_TAKES_STRING_LITERAL and + NV_CRYPTO_AKCIPHER_VERIFY_PRESENT changes from 550.144.03 and + NV_FOLIO_TEST_SWAPCACHE_PRESENT changes from 565.57.01 to fix open kernel + module build for Linux 6.13. + * Let pahole ignore language c++11 for BTF generation. (Closes: #1098812) + * Fix warnings during open module build. + * Build with more kernel hardening flags. + * Sync with src:nvidia-graphics-drivers. + * Bump Standards-Version to 4.7.2. No changes needed. + * New upstream Tesla branch release 535.216.03 (2024-11-19). [ Other info ] This is a rebuild of the package from sid with no further changes. AndreasAttachment: nvidia-open-gpu-kernel-modules_535.247.01-1~deb12u1.diff.xz
Description: application/xz
--- End Message ---
--- Begin Message ---
- To: 1104893-done@bugs.debian.org
- Subject: Close 1104893
- From: jmw@debian.org
- Date: Sat, 17 May 2025 09:37:58 +0000
- Message-id: <E1uGDzS-005KIa-Ap@coccia.debian.org>
Version: 12.11 This update has been released as part of 12.10. Thank you for your contribution.
--- End Message ---