On Saturday 16 May 2020 08:17:17 Ganapathi Bhat wrote:
> Hi Pali,
>
> Thanks for this notice. We will try to push the new firmware and also, fix the naming problem.
>
> Regards,
> Ganapathi
Hello Ganapathi!
According to publicly available information, firmware for these W8xxx
Marvell wifi chips is vulnerable to security issue CVE-2019-6496 [1].
Are you able to update firmwares to the last versions and give us some
information which (old) firmware versions are affected by that security
issue?
So Linux distribution would know if they are distributing older
vulnerable firmwares and should push security fixes with new firmware
versions.
[1] - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6496
Hi Pali,
> According to publicly available information, firmware for these W8xxx
> Marvell wifi chips is vulnerable to security issue CVE-2019-6496 [1].
>
> Are you able to update firmwares to the last versions and give us some
> information which (old) firmware versions are affected by that security issue?
>
> So Linux distribution would know if they are distributing older vulnerable
> firmwares and should push security fixes with new firmware versions.
>
88W8787, 88W8797, 88W8801, 88W8897, and 88W8997 models are all already updated, with one exception:
usb8897_uapsta.bin, which we will upstream soon;
Regards,
Ganapathi
On Friday 29 May 2020 08:43:56 Ganapathi Bhat wrote:
> Hi Pali,
>
> > According to publicly available information, firmware for these W8xxx
> > Marvell wifi chips is vulnerable to security issue CVE-2019-6496 [1].
> >
> > Are you able to update firmwares to the last versions and give us some
> > information which (old) firmware versions are affected by that security issue?
> >
> > So Linux distribution would know if they are distributing older vulnerable
> > firmwares and should push security fixes with new firmware versions.
> >
>
> 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997 models are all already updated, with one exception:
> usb8897_uapsta.bin, which we will upstream soon;
Hello Ganapathi! Thank you for information. Can you point me to git tree
or location where are firmware files already updated?
Hi Pali,
> Hello Ganapathi! Thank you for information. Can you point me to git tree or
> location where are firmware files already updated?
https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git
or
https://github.com/NXP/mwifiex-firmware
Regards,
Ganapathi
On Friday 29 May 2020 08:49:18 Ganapathi Bhat wrote:
> Hi Pali,
>
> > Hello Ganapathi! Thank you for information. Can you point me to git tree or
> > location where are firmware files already updated?
>
> https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git
>
> or
>
> https://github.com/NXP/mwifiex-firmware
Hello Ganapathi! Seems that on both locations is older version of
sdsd8997_combo_v4.bin firmware, not the latest one. On both location is
available just version 16.68.1.p179. But we have newer version
16.68.1.p197. Could you please recheck it?
Hi Pali,
> Hello Ganapathi! Seems that on both locations is older version of
> sdsd8997_combo_v4.bin firmware, not the latest one. On both location is
> available just version 16.68.1.p179. But we have newer version 16.68.1.p197.
> Could you please recheck it?
p179 do have the fix but we will try to upstream p197 also soon.
Regards,
Ganapathi
On Friday 29 May 2020 09:11:08 Ganapathi Bhat wrote:
> Hi Pali,
>
> > Hello Ganapathi! Seems that on both locations is older version of
> > sdsd8997_combo_v4.bin firmware, not the latest one. On both location is
> > available just version 16.68.1.p179. But we have newer version 16.68.1.p197.
> > Could you please recheck it?
>
> p179 do have the fix but we will try to upstream p197 also soon.
Thank you!
On Friday 29 May 2020 11:12:11 Pali Rohár wrote:
> On Friday 29 May 2020 09:11:08 Ganapathi Bhat wrote:
> > Hi Pali,
> >
> > > Hello Ganapathi! Seems that on both locations is older version of
> > > sdsd8997_combo_v4.bin firmware, not the latest one. On both location is
> > > available just version 16.68.1.p179. But we have newer version 16.68.1.p197.
> > > Could you please recheck it?
> >
> > p179 do have the fix but we will try to upstream p197 also soon.
>
> Thank you!
Hello Ganapathi! Do you have any updates about upstreaming new firmware version?