Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-13 Thread Ben Hutchings
On Wed, 12 Jul 2023 10:05:03 +0200 Julian Andres Klode wrote: [...] > A reasonable compromise at a first step for a limited time is to > ensure that > > 1) the kernel refuses to load modules for a different ABI in lockdown, >    for example, the modprobe --force-vermagic does not work anymore.

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
On Wed, Jul 12, 2023 at 10:05:03AM +0200, Julian Andres Klode wrote: > Source: linux > Version: 6.3.0-7.7 > Severity: grave > Tags: security > X-Debbugs-Cc: j...@debian.org > > I know there's some work in progress but it appears we don't have a bug > for it yet. I raised this yesterday in our

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
Control: notfound -1 6.3.0-7.7 On Wed, Jul 12, 2023 at 10:05:03AM +0200, Julian Andres Klode wrote: > Source: linux > Version: 6.3.0-7.7 > Severity: grave > Tags: security > X-Debbugs-Cc: j...@debian.org Sorry about that, it picked up the version from my work system's Ubuntu kernel and I forgot

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
Source: linux Version: 6.3.0-7.7 Severity: grave Tags: security X-Debbugs-Cc: j...@debian.org I know there's some work in progress but it appears we don't have a bug for it yet. I raised this yesterday in our weekly upstream shim/grub cabal meetings and Debian's current approach to sign modules