[Bug 1891061] Re: SRU: Bootable buildd images boot vulnerable kernels
Launchpad Bug Tracker
1891061 at bugs.launchpad.net
Mon Aug 24 17:23:43 UTC 2020
This bug was fixed in the package livecd-rootfs - 2.664.5
---------------
livecd-rootfs (2.664.5) focal; urgency=medium
[ Robert C Jennings ]
* Handle seeded lxd snap with channel name for ubuntu-cpc:minimized
(LP: #1889470)
[ Cody Shepherd ]
* Add dist-upgrade to bootable-buildd hook to ensure the built image
doesn't contain vulnerable kernels or other packages. LP: #1891061.
* Don't explicitly install grub-efi-amd64-signed, it's a dependency of
shim-signed.
-- Steve Langasek <steve.langasek at ubuntu.com> Tue, 04 Aug 2020
12:39:27 -0700
** Changed in: livecd-rootfs (Ubuntu Focal)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to livecd-rootfs in Ubuntu.
https://bugs.launchpad.net/bugs/1891061
Title:
SRU: Bootable buildd images boot vulnerable kernels
Status in livecd-rootfs package in Ubuntu:
Fix Released
Status in livecd-rootfs source package in Focal:
Fix Released
Bug description:
[Impact]
* Bootable buildd images are currently built from the -release pocket only,
leaving them vulnerable to issues fixed by -updates and/or -security.
* MP: #387164 [1] should be backported to ensure updated packages are used
when building the bootable buildd images.
[Test Case]
* Inspect package manifest for bootable buildd images; verify outdated versions
of packages
[Regression Potential]
* updated packages could break current assumptions for bootable buildd images, and cause
boot or runtime failures, though this has not been seen in testing.
1. https://code.launchpad.net/~codyshepherd/livecd-rootfs/+git/livecd-
rootfs/+merge/387164
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/1891061/+subscriptions
More information about the foundations-bugs
mailing list