Re: "Security Advisories" dead?

"\"Douglas R. Reno\"" ([email protected] via lfs-support Mailing List) <[email protected]> Thu, 15 May 2025 10:20:06 -0500
Newsgroups gmane.linux.lfs.support
Message-ID <[email protected]>
On 5/15/25 3:38 AM, Rainer Fiebig ([email protected] via lfs-support 
Mailing List) wrote:
> The last Security Advisory was as of 2025-03-14 for PHP.  The last SAs
> for Firefox and Thunderbird recommended updating to -128.08.0esr.  Both
> are at -128.10.0 already since a while.
>
> I consider the SAs a great service and hope that they have not been
> abandoned or can no longer be maintained.  But if so the LFS/BLFS
> community should be informed about it.  Thanks.
>
> Rainer
>
Hi Rainer!

The security advisories are alive and well. As Rahul alluded too I've 
had some other things going on, but that isn't the only reason.

Many of the new security updates have caused build bustages or 
regressions that I've had to deal with, and unfortunately several of 
them have been in large packages that take a long time to build. These 
include packages like QtWebEngine, Qt, libarchive, Expat, WebKitGTK, 
GhostScript, and Libreoffice, amongst some others. The security 
advisories are something I'm very passionate about, so anytime I receive 
a report of a build issue or regression I always take it seriously and 
investigate first. The current security landscape involving some 
packages has also made it extremely difficult to get the information 
needed to file an advisory, but Joe Locash got me the information for 
that package and mailed it to me privately so we have a comprehensive 
list of everything we need to cover in that advisory! Because of all of 
the regressions though many of the advisories will have additional text 
about things that need to be done to fix issues with them.

I currently have 8 security updates on my radar, and I'm going to start 
with finishing up OpenJDK. After that expect updates to screen, libsoup2 
(removal from BLFS, but patch available for BLFS <= 12.3 users), 
libsoup3, giflib, intel-microcode, node.js, OpenJDK, and another update 
to WebKitGTK (which hopefully will not cause more build issues!). I know 
OpenJDK is going to have issues with at least one package so I will need 
to resolve and test that at the same time.

In March I also got a new development system, and got it setup to 
replace my old machine (which was approaching 7 years old). The SSD 
failed in that system about two weeks later and I lost everything that I 
had worked on during that time, which included work on QtWebEngine 
regressions in particular, as well as the very recent GNOME update that 
I had put in. It took me a long time to get that caught back up, I think 
almost three weeks because I had to spend a lot of time building and 
dealing with more security update related regressions while trying to 
manage university stuff at the same time. I also had to deal with issues 
with packages like CMake-4 and libxml2-2.14 as well during the same 
time. That normally wouldn't be a big issue in late February/early March 
because I work hard to get ahead of everything in classes before release 
times, but late March/early April timing made it take longer, and I try 
to test everything new that comes in to make sure we're as regression 
free as we can be, though things happen! I have a handle on everything 
now and should be able to take care of these all soon. The machine has 
been very amazing to work with though and it's very fast, which should 
allow me to get to issues like we have today much faster.

I'm expecting to be filing advisories tomorrow or Saturday, and I will 
send an email about all of the updates afterwards as normal. I will also 
mention issues with a couple of other packages that should be taken 
seriously.

One more security related thing that I wanted to bring up here, that 
isn't security advisory related, is that I'll be probably adding fwupd 
to the book to assist users with firmware updates. Given the current 
landscape of firmware related vulnerabilities and minor hardware issues 
in new hardware, it might be useful for users to have the opportunity to 
get their BIOS updated through fwupd (since you'll get extra security 
fixes on Intel systems for the Management Engine for example). The 
caveat with fwupd though is that your hardware has to support it, but 
for users who can update it through there it will be extremely useful. 
Bruce has requested a writeup on how to build it and it's dependencies 
first for him to try so I'll give it to him first, and then we'll 
include it in the book probably in a week or two. I really need to take 
care of existing security issues, file advisories, and take care of some 
Texlive related problems first before I do that though.

Thank you for bringing it up!

- Doug

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-support
Unsubscribe: See the above information page