[Bug 1891061] [NEW] SRU: Bootable buildd images boot vulnerable kernels

Cody Shepherd 1891061 at bugs.launchpad.net
Mon Aug 10 16:49:46 UTC 2020


Public bug reported:

[Impact]

 * Bootable buildd images are currently built from the -release pocket only,
   leaving them vulnerable to issues fixed by -updates and/or -security.

 * MP: #387164 [1] should be backported to ensure updated packages are used
   when building the bootable buildd images.

[Test Case]

 * Inspect package manifest for bootable buildd images; verify outdated versions
   of packages

[Regression Potential]

 * updated packages could break current assumptions for bootable buildd images, and cause
   boot or runtime failures, though this has not been seen in testing.

1. https://code.launchpad.net/~codyshepherd/livecd-rootfs/+git/livecd-
rootfs/+merge/387164

** Affects: livecd-rootfs (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to livecd-rootfs in Ubuntu.
https://bugs.launchpad.net/bugs/1891061

Title:
  SRU: Bootable buildd images boot vulnerable kernels

Status in livecd-rootfs package in Ubuntu:
  New

Bug description:
  [Impact]

   * Bootable buildd images are currently built from the -release pocket only,
     leaving them vulnerable to issues fixed by -updates and/or -security.

   * MP: #387164 [1] should be backported to ensure updated packages are used
     when building the bootable buildd images.

  [Test Case]

   * Inspect package manifest for bootable buildd images; verify outdated versions
     of packages

  [Regression Potential]

   * updated packages could break current assumptions for bootable buildd images, and cause
     boot or runtime failures, though this has not been seen in testing.

  1. https://code.launchpad.net/~codyshepherd/livecd-rootfs/+git/livecd-
  rootfs/+merge/387164

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/1891061/+subscriptions



More information about the foundations-bugs mailing list