Your message dated Sun, 31 Mar 2019 14:43:53 +0000 with message-id <e1habgf-0005aq...@fasolo.debian.org> and subject line Bug#913467: fixed in nvidia-graphics-drivers 390.116-1 has caused the Debian Bug report #913467, regarding nvidia-graphics-drivers: CVE‑2018‑6260: access to application data processed on the GPU through a side channel exposed by the GPU performance counters to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 913467: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913467 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems
--- Begin Message ---Source: nvidia-graphics-drivers Version: 390.87 Severity: serious Tags: security upstream https://nvidia.custhelp.com/app/answers/detail/a_id/4738 "NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote attack vector." Details are still scarce at this point, the affected platforms and versions are not yet known so I've just pointed it to the version in unstable for now. -- Kind regards, Luca Boccassi
signature.asc
Description: This is a digitally signed message part
--- End Message ---
--- Begin Message ---Source: nvidia-graphics-drivers Source-Version: 390.116-1 We believe that the bug you reported is fixed in the latest version of nvidia-graphics-drivers, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 913...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Andreas Beckmann <a...@debian.org> (supplier of updated nvidia-graphics-drivers package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 12 Mar 2019 09:27:07 +0100 Source: nvidia-graphics-drivers Binary: nvidia-driver nvidia-driver-bin nvidia-driver-libs nvidia-driver-libs-i386 nvidia-driver-libs-nonglvnd nvidia-driver-libs-nonglvnd-i386 xserver-xorg-video-nvidia nvidia-legacy-check libglvnd0-nvidia libopengl0-glvnd-nvidia libglx0-glvnd-nvidia libglx-nvidia0 libgl1-glvnd-nvidia-glx libgl1-nvidia-glvnd-glx libgl1-nvidia-glx libnvidia-glcore libegl1-glvnd-nvidia libegl1-nvidia libegl-nvidia0 libgles1-glvnd-nvidia libgles1-nvidia libgles-nvidia1 libgles2-glvnd-nvidia libgles2-nvidia libgles-nvidia2 libnvidia-eglcore nvidia-egl-common nvidia-egl-icd nvidia-vulkan-common nvidia-vulkan-icd nvidia-nonglvnd-vulkan-common nvidia-nonglvnd-vulkan-icd libnvidia-cfg1 nvidia-alternative nvidia-kernel-support nvidia-kernel-dkms nvidia-kernel-source nvidia-vdpau-driver nvidia-smi nvidia-cuda-mps libcuda1 libcuda1-i386 libnvidia-compiler libnvidia-fatbinaryloader libnvidia-ptxjitcompiler1 libnvcuvid1 libnvidia-encode1 libnvidia-ifr1 libnvidia-fbc1 libnvidia-ml1 nvidia-opencl-common nvidia-opencl-icd nvidia-libopencl1 nvidia-detect Architecture: source Version: 390.116-1 Distribution: stretch Urgency: medium Maintainer: Debian NVIDIA Maintainers <pkg-nvidia-de...@lists.alioth.debian.org> Changed-By: Andreas Beckmann <a...@debian.org> Description: libcuda1 - NVIDIA CUDA Driver Library${nvidia:LegacyDesc} libcuda1-i386 - NVIDIA CUDA 32-bit runtime library${nvidia:LegacyDesc} libegl-nvidia0 - NVIDIA binary EGL library${nvidia:LegacyDesc} libegl1-glvnd-nvidia - Vendor neutral GL dispatch library -- libEGL libegl1-nvidia - NVIDIA binary EGL library (non-GLVND variant)${nvidia:LegacyDesc} libgl1-glvnd-nvidia-glx - Vendor neutral GL dispatch library -- libGL libgl1-nvidia-glvnd-glx - NVIDIA binary OpenGL/GLX library (GLVND variant)${nvidia:LegacyDe libgl1-nvidia-glx - NVIDIA binary OpenGL/GLX library (non-GLVND variant)${nvidia:Lega libgles-nvidia1 - NVIDIA binary OpenGL|ES 1.x library${nvidia:LegacyDesc} libgles-nvidia2 - NVIDIA binary OpenGL|ES 2.x library${nvidia:LegacyDesc} libgles1-glvnd-nvidia - NVIDIA binary OpenGL|ES 1.x GLVND stub library libgles1-nvidia - NVIDIA binary OpenGL|ES 1.x library (transitional)${nvidia:Legacy libgles2-glvnd-nvidia - NVIDIA binary OpenGL|ES 2.x GLVND stub library libgles2-nvidia - NVIDIA binary OpenGL|ES 2.x library (transitional)${nvidia:Legacy libglvnd0-nvidia - Vendor neutral GL dispatch library -- libGLdispatch libglx-nvidia0 - NVIDIA binary GLX library${nvidia:LegacyDesc} libglx0-glvnd-nvidia - Vendor neutral GL dispatch library -- libGLX libnvcuvid1 - NVIDIA CUDA Video Decoder runtime library${nvidia:LegacyDesc} libnvidia-cfg1 - NVIDIA binary OpenGL/GLX configuration library${nvidia:LegacyDesc libnvidia-compiler - NVIDIA runtime compiler library${nvidia:LegacyDesc} libnvidia-eglcore - NVIDIA binary EGL core libraries${nvidia:LegacyDesc} libnvidia-encode1 - NVENC Video Encoding runtime library${nvidia:LegacyDesc} libnvidia-fatbinaryloader - NVIDIA FAT binary loader${nvidia:LegacyDesc} libnvidia-fbc1 - NVIDIA OpenGL-based Framebuffer Capture runtime library${nvidia:L libnvidia-glcore - NVIDIA binary OpenGL/GLX core libraries${nvidia:LegacyDesc} libnvidia-ifr1 - NVIDIA OpenGL-based Inband Frame Readback runtime library${nvidia libnvidia-ml1 - NVIDIA Management Library (NVML) runtime library${nvidia:LegacyDe libnvidia-ptxjitcompiler1 - NVIDIA PTX JIT Compiler${nvidia:LegacyDesc} libopengl0-glvnd-nvidia - Vendor neutral GL dispatch library -- libOpenGL nvidia-alternative - allows the selection of NVIDIA as GLX provider${nvidia:LegacyDesc nvidia-cuda-mps - NVIDIA CUDA Multi Process Service (MPS) nvidia-detect - NVIDIA GPU detection utility nvidia-driver - NVIDIA metapackage${nvidia:LegacyDesc} nvidia-driver-bin - NVIDIA driver support binaries${nvidia:LegacyDesc} nvidia-driver-libs - NVIDIA metapackage (OpenGL/GLX/EGL/GLES libraries)${nvidia:Legacy nvidia-driver-libs-i386 - NVIDIA metapackage (OpenGL/GLX/EGL/GLES 32-bit libraries)${nvidia nvidia-driver-libs-nonglvnd - NVIDIA metapackage (non-GLVND OpenGL/GLX/EGL/GLES libraries)${nvi nvidia-driver-libs-nonglvnd-i386 - NVIDIA metapackage (non-GLVND OpenGL/EGL/etc. 32-bit libraries)${ nvidia-egl-common - NVIDIA binary EGL driver - common files nvidia-egl-icd - NVIDIA EGL installable client driver (ICD) nvidia-kernel-dkms - NVIDIA binary kernel module DKMS source${nvidia:LegacyDesc} nvidia-kernel-source - NVIDIA binary kernel module source${nvidia:LegacyDesc} nvidia-kernel-support - NVIDIA binary kernel module support files${nvidia:LegacyDesc} nvidia-legacy-check - check for NVIDIA GPUs requiring a legacy driver nvidia-libopencl1 - NVIDIA OpenCL ICD Loader library nvidia-nonglvnd-vulkan-common - NVIDIA Vulkan driver - common files (non-GLVND variant) nvidia-nonglvnd-vulkan-icd - NVIDIA Vulkan ICD (non-GLVND variant)${nvidia:LegacyDesc} nvidia-opencl-common - NVIDIA OpenCL driver - common files nvidia-opencl-icd - NVIDIA OpenCL installable client driver (ICD)${nvidia:LegacyDesc} nvidia-smi - NVIDIA System Management Interface${nvidia:LegacyDesc} nvidia-vdpau-driver - Video Decode and Presentation API for Unix - NVIDIA driver${nvidi nvidia-vulkan-common - NVIDIA Vulkan driver - common files nvidia-vulkan-icd - NVIDIA Vulkan installable client driver (ICD)${nvidia:LegacyDesc} xserver-xorg-video-nvidia - NVIDIA binary Xorg driver${nvidia:LegacyDesc} Closes: 913467 Changes: nvidia-graphics-drivers (390.116-1) stretch; urgency=medium . * New upstream legacy branch release 390.116 (2019-02-22). * Fixed CVE‑2018‑6260. (Closes: #913467) https://nvidia.custhelp.com/app/answers/detail/a_id/4772 - Fixed build failures which resulted in errors like "implicit declaration of function drm_...", when building the NVIDIA DRM kernel module for Linux kernel 5.0 release candidates. - Fixed a bug which could cause VK_KHR_external_semaphore_fd operations to fail. - Fixed a build failure, "implicit declaration of function 'vm_insert_pfn'", when building the NVIDIA DRM kernel module for Linux kernel 4.20 release candidates. - Fixed a build failure, "unknown type name 'ipmi_user_t'", when building the NVIDIA kernel module for Linux kernel 4.20 release candidates. - Fixed a bug that caused mode switches to fail when an SDI output board was connected. - Fixed a bug that could cause rendering corruption in Vulkan programs. - Fixed a bug that caused vkGetPhysicalDeviceDisplayPropertiesKHR() to occasionally return incorrect values for physicalResolution. * New upstream legacy branch release 340 series. - Fixed a build failure, "too many arguments to function 'get_user_pages'", when building the NVIDIA kernel module for Linux kernel v4.4.168. - Fixed a build failure, "implicit declaration of function do_gettimeofday", when building the NVIDIA kernel module for Linux kernel 5.0 release candidates. - Added a new kernel module parameter, NVreg_RestrictProfilingToAdminUsers, to allow restricting the use of GPU performance counters to system administrators only. . [ Luca Boccassi ] * Drop kmem_cache_create_usercopy.patch, drm-mode.patch, ipmi-user.patch, vm-insert-pfn.patch: fixed upstream. * Update symbols files. . [ Andreas Beckmann ] * nvidia-detect: stretch now has a 390.xx driver. * nvidia-kernel-source: Bump debhelper dependency to match Build-Depends. * Upload to stretch. Checksums-Sha1: 032506fa08d8d3d1f34768e8bda1ed82ab7c3f60 7934 nvidia-graphics-drivers_390.116-1.dsc af666ad82c38c09c4e68ae009ce0def458dc9d81 82246727 nvidia-graphics-drivers_390.116.orig-amd64.tar.gz 2e3b789b6b1e43cce7bcdc076b4e2a873a4fd2a0 28813421 nvidia-graphics-drivers_390.116.orig-armhf.tar.gz fe120f480c3c5c418a5c4fc9253127fda1b07e7e 47672343 nvidia-graphics-drivers_390.116.orig-i386.tar.gz 0e0f0a0a767ac9029504bd0ebb7224f487bc7dc0 138 nvidia-graphics-drivers_390.116.orig.tar.gz 5efc050a2fcb8bd226b01c75344fd75d3b4ba3c3 182504 nvidia-graphics-drivers_390.116-1.debian.tar.xz bef894991360a4be49a45f26b76db01d70d3f3bb 6956 nvidia-graphics-drivers_390.116-1_source.buildinfo Checksums-Sha256: da9fd2156fd1b336700da45adc30538d2bd9017b8a4a8f6064a0005d2d3cc704 7934 nvidia-graphics-drivers_390.116-1.dsc 33633275d63ed857f1162732dba3d0493c17011bd849914a758a8b34981496c9 82246727 nvidia-graphics-drivers_390.116.orig-amd64.tar.gz 4a11176248904df5922265a4e406774ee3f06fbf7aa0f4b8cbbde2172dd7516d 28813421 nvidia-graphics-drivers_390.116.orig-armhf.tar.gz c7c353725e61bf53a6ca6938dcb7d4abefb5639ec03dc8a6d2df4ce39eda85da 47672343 nvidia-graphics-drivers_390.116.orig-i386.tar.gz b63fd3f2ce52ae066a361280a57e5f6642ab9f6d12f0dcc1fdfbf7bbb7c26fb9 138 nvidia-graphics-drivers_390.116.orig.tar.gz e5d2b4a41f9737bccb70f9621dfcc0f01a6edd85d01fc5393ce6fbdc2e2ee922 182504 nvidia-graphics-drivers_390.116-1.debian.tar.xz 1dc77013f078bcede93f051c388567db9f5445f7d2139db163156e018014a9f2 6956 nvidia-graphics-drivers_390.116-1_source.buildinfo Files: 0e253f49c56931c5db9cba2fb843dfa3 7934 non-free/libs optional nvidia-graphics-drivers_390.116-1.dsc ff70bf987c1b0b97091d49482490ffe8 82246727 non-free/libs optional nvidia-graphics-drivers_390.116.orig-amd64.tar.gz e4c347bb67e0deeadf1493b406c640e8 28813421 non-free/libs optional nvidia-graphics-drivers_390.116.orig-armhf.tar.gz fcd5dc905722849e00c08659474df114 47672343 non-free/libs optional nvidia-graphics-drivers_390.116.orig-i386.tar.gz 0d7ac30723d79f4107d3a922af255bd3 138 non-free/libs optional nvidia-graphics-drivers_390.116.orig.tar.gz f177d9c5490e5a0b239dfa15b6d6b93b 182504 non-free/libs optional nvidia-graphics-drivers_390.116-1.debian.tar.xz d3b60fbcad1db339e5e1a2250903b02d 6956 non-free/libs optional nvidia-graphics-drivers_390.116-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEE6/MKMKjZxjvaRMaUX7M/k1np7QgFAlyHbxwQHGFuYmVAZGVi aWFuLm9yZwAKCRBfsz+TWentCMF/D/922oeyB0Y3NdmIvpPwE4duDnovjWYX8p+N RKDGiW061ZXuCjWR8XsJaZNW8bVe//VMs/PduCGXvpdOMgZSHkDdqcf/q4AveVQh v9US/06SZm39ADnCFP342RNjWyeKPz/DPvyImn3VUG6qu556qgG1c1I74RpROc79 xfqWoV/4vrYNFBp9nJldzQ8AyQdGLrPt3n6f5bK3ARNBUmbtPSUnDPRCt/q8UhWP N16AqjVpKqKztAWTn9mP8K97s+UjCkl8tnx9ED0qzp7WQ+/4A/kswhkblQa7khg9 +0M80oJAdpqpBnXF0Mmje/wsgDSSoXHyLJ/HNp5MlW99gXnhHeZLCvcBDilCWCvj yfIjaJ2lZAbyV2aSXUWRJ/eMDTnr7xq0Ab5AfcsMSI5WHce0Re8UTbxKW3kcnMGn LbuyPOqW3nkZZ3RbMT4DkzVD3mV72YKV485p8ndoQlYogOVwJcqWSZCHiUG9wXMm qjy6dG9BiTi3+s6IErK+F5h1iD/UR7B5+bNdgdX5u7+/0ICKG6gbFf+k6t2rnEre RyJiFHo2Q5Oq8E9gk/EogohdsnX4DRrgKIgzG8L33BoNArpwunIFnxq9Lq6yvPO/ SZAVynXmqiXf7TCIaCuGRhKDEQ9orybmNQOreGU0QRBLmnidOfQ4SF3gWB5OguH6 hPZ+ZauJFg== =lBN+ -----END PGP SIGNATURE-----
--- End Message ---