Received: by 2002:a05:6a10:1d13:0:0:0:0 with SMTP id pp19csp2486732pxb; Mon, 23 Aug 2021 23:44:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwvIykiyDlfx9pnBHFqsQWsTCmbiLMFZ1Q3Ebry4hTRp8syaiJc31SPr3gqvbDgckKmjniW X-Received: by 2002:a05:6402:26d3:: with SMTP id x19mr9919082edd.173.1629787464551; Mon, 23 Aug 2021 23:44:24 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1629787464; cv=none; d=google.com; s=arc-20160816; b=haWcZsJrnAW8u8KoLRhOoLm4c/fUy0gWCpeDNvRsbu36rwHfRbWVqrTEbQpTbJStUw RmTIb+TuxItoLSBKfYItDo9DiDmJ9/Ha+9h2LONgoHBbBVcB9GX6U1l4j7BosvRLYdh+ BUeZjrv6xs0PixgjPbbqDsh5U93+9inl9GzgNoFBm/BO2Jykh8qP9hzutWjdJ6ETxea9 h7Cczjm4r0s5uNDHMrQucFaAOxFubFcHl1AvZTIwqfx8YgF1y1Moj8UJ5PRXl0GiIDrO TQq3zKdEozoGyHp3NR6+1gVBt6hGqYOuGmhceCe+Yx+rV5wwJPHWE01mw4uScWJRaPvD 8VyQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=kXcCT0IYLNBTDc/MpY+QvEoqnk7Er+wN7go/b/jrmDg=; b=W54xlLhha7kP7rvwfrTajxC7qZnkrjqSiZhe/iTCUtpg2AmdaevMAlxILIVg4YmlyZ ArrafRd+WvQf7gpSoF2WKIP6FgD5SGKYw7+fbmqMmcf2KIG8Yuc0qUhoF4Eb9GlyJ4NH qC6Wq04l8EvUMNW1mQsYE3mP4yj77R+XNQTZI9sb8GZiwe+s6trbAzPTDaAvzn4qxVQR oUrQ7C0q9lhsEP9vhY3753JSznDI8w6vKAsXkv0/hlHo3SE9/9NzDCQTGeU9vASpXeQ7 975JGOfq81EtjUKKNmwSvBHIuFOdjv6ZRLgmkKvU0gQsaUDatoZY18b3zp4EziLrBtNn jauw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=rxNm8D1o; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id p18si2067328eds.16.2021.08.23.23.43.55; Mon, 23 Aug 2021 23:44:24 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=rxNm8D1o; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231962AbhHXGoI (ORCPT + 99 others); Tue, 24 Aug 2021 02:44:08 -0400 Received: from mail.kernel.org ([198.145.29.99]:43414 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232040AbhHXGoE (ORCPT ); Tue, 24 Aug 2021 02:44:04 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id BD7B5610E9; Tue, 24 Aug 2021 06:43:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1629787400; bh=cZtsXgWO7DMRgYrwV9KWwAx/OrCZbrHnFx1TdQp61tU=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=rxNm8D1o3kX7Ib7W1EdRY814sVfTge1SM00Kn6O2t85PEOuhQP4SxvRhMOzxGwy8d 1f/vJD2+a4AupVKYBRw0SwTOF4pa2CW+s5jPDE/8Klks9V3W+/++0J8M3LWXZq+Xe6 Iqhck00sSapK4AtOUoK3TjAz85ttdEhTWBtsod1Q= Date: Mon, 23 Aug 2021 21:04:27 +0200 From: Greg KH To: Pali =?iso-8859-1?Q?Roh=E1r?= Cc: Sasha Levin , stable@vger.kernel.org, linux-wireless@vger.kernel.org Subject: Re: Drivers for Qualcomm wifi chips (ath*k) and security issues Message-ID: References: <20210823140844.q3kx6ruedho7jen5@pali> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20210823140844.q3kx6ruedho7jen5@pali> Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org On Mon, Aug 23, 2021 at 04:08:44PM +0200, Pali Roh?r wrote: > Hello Sasha and Greg! > > Last week I sent request for backporting ath9k wifi fixes for security > issue CVE-2020-3702 into stable LTS kernels because Qualcomm/maintainers > did not it for more months... details are in email: > https://lore.kernel.org/stable/20210818084859.vcs4vs3yd6zetmyt@pali/t/#u > > And now I got reports that in stable LTS kernels (4.14, 4.19) are > missing also other fixes for other Qualcomm wifi security issues, > covered by FragAttacks codename: CVE-2020-26145 CVE-2020-26139 > CVE-2020-26141 Then someone needs to provide us backports if they care about these very old kernels and these issues. Just like any other driver subsystem where patches are not able to be easily backported. Or just use a newer kernel, that's almost always a better idea. thanks, greg k-h