Consider my position this way. It is true that the kernel team's ability to maintain this package is limited. I agree that we should flag that to users in some way. But what I'm saying is that this _is already flagged as such_ by it being placed in the restricted archive component.
You are still on the hook for maintaining aspects of the package that you can support, such as packaging, metadata, integration with other packages and so forth. I resist you "moving" the package to multiverse because I don't think it's acceptable for you to disclaim those aspects as well, which is the effect I think it would have. Setting that aside, there's a fundamental issue with the fact that you'd only be moving the package to multiverse in the security and updates pockets. It would remain in the release pocket in restricted anyway, so users looking at that would still expect support. On Tue, Jul 14, 2026 at 06:23:44PM -0000, Jose Ogando Justo wrote: > I'm first focusing on what I believe is the main point of contention: > the removal of the package and the security implications. (c, on your > list) > > The entity responsible for monitoring these binaries for vulnerabilities > is NVIDIA itself. That's not correct. Canonical is also reponsible for monitoring the ecosystem for reports of vulnerabilities regardless of what help they might get from upstream in doing that. This is how distributions have worked for decades. It is a relatively new phenomenon that a corporate entity takes responsibility upstream, but: 1) that only applies to specific upstreams, not all of them; 2) generally only for a specific length of time; 3) they can improve but otherwise do not impact the fallback position of distributions managing security updates themselves. Consider what the first package Ubuntu ever released in the restricted archive component might have been. If it was a driver grabbed from somewhere with no upstream commitment for security updates whatsover, I think we would still have shipped it with the "restricted" warning, and still taken best-effort responsibility it. The fact that Nvidia provides some support beyond that baseline is great, but it does not absolve Canonical from the best-effort promise of support it has always made even when that extra support from Nvidia goes away. > Since the 470 series reached end of life, NVIDIA has continued > publishing Display GPU Driver security advisories that apply to newer > releases (July 2024, October 2024, January 2025, April 2025, July 2025, > October 2025, January 2026, and May 2026). These advisories include > vulnerabilities rated High severity, covering issues such as privilege > escalation, arbitrary code execution, denial of service, and information > disclosure. If there is an advisory that provides specifics of a vulnerability that exists in the archive with enough detail that it is clear that we must regress users to keep them safe, then please link to that advisory and we can decide what to do on a case-by-case basis. > We cannot determine with certainty which of these vulnerabilities affect > the 470 branch because NVIDIA no longer analyzes or publishes security > fixes for it. Equally, we cannot assume that vulnerabilities disclosed > in supported branches are absent from the 470 branch simply because it > is no longer evaluated. We are therefore not in a position to provide > meaningful security support for this package. If details aren't available or we aren't told if they apply to a specific version of the package in are archive, then that would not be actionable, and that's fine. It would be no different to someone saying "there might be a security vulnerability" which is something we knew at release time. The "restricted" warning effectively covers it. > One key question is how Ubuntu policy defines "known severe." The fact > that NVIDIA no longer evaluates or discloses vulnerabilities for the 470 > branch does not imply that the software is free of severe > vulnerabilities. Rather, it means there is no longer an active upstream > process identifying or remediating them. Accepting software unless there > are known severe vulnerabilities is not covering hazardous scenarios. It is the ecosystem norm that Free Software distributions ship software even though there _might_ be security vulnerabilities in them that we do not know about. This is the risk that everybody takes all the time. The "restricted" label comes with the additional caveat that being source unavailable precludes analysis in the way that you describe. > Therefore, one could argue that there is a meaningful likelihood that > one or more vulnerabilities already disclosed in supported NVIDIA driver > branches are also present in the 470 branch, even if that cannot be > conclusively demonstrated without upstream analysis. This is not > something we can do on binary only. This is indeed the downside of non-free software, and part of the risk that our users choose to take by enabling the "restricted" archive component. It's important to remember that I still support you updating users of a stable release with a newer, supported version from Nvidia via our hardware enablement pipeline, so it's not like I'm arguing that we must always force users to remain on an older version. The issue at hand is whether we knowingly break users by dropping hardware support in an upgrade. It is only in this case that I'm saying it's fine to leave users on the same driver version given that there are no known specific severe security vulnerabilities in that specific version, as regressing them would be worse. > e) I might not understand your question. The package that was published was a transitional. We did some investigation and found that linux-modules- nvidia-470-generic has been deleted, so users relying on that have been regressed. This needs restoring to track the GA kernel updates. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2155202 Title: Latest Update Breaks Systems Using Nvidia 470 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nvidia-graphics-drivers-470/+bug/2155202/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
