<@q5sys:matrix.org>
15:00:01
!startmeeting
<@meetbot:fedora.im>
15:00:05
Meeting started at 2026-05-14 15:00:01 UTC
<@meetbot:fedora.im>
15:00:05
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
15:00:07
!meetingname security-sig
<@meetbot:fedora.im>
15:00:10
The Meeting Name is now security-sig
<@q5sys:matrix.org>
15:00:13
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@q5sys:matrix.org>
15:00:20
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@q5sys:matrix.org>
15:00:25
!topic Open floor to discuss anything security related. (2026-05-14)
<@thebeanogamer:fedora.im>
15:00:27
!hi
<@zodbot:fedora.im>
15:00:28
Daniel Milnes: Daniel Milnes (thebeanogamer) - he / him / his
<@q5sys:matrix.org>
15:00:33
!topic Open floor to discuss anything security related. (2026-05-14)
<@jforbes:fedora.im>
15:00:36
!hi
<@zodbot:fedora.im>
15:00:37
jforbes: Justin Forbes (jforbes) - he / him / his
<@q5sys:matrix.org>
15:00:38
!info There are 3 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues
<@q5sys:matrix.org>
15:00:46
!info There are 7 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues
<@py0xc3:fedora.im>
15:00:52
!hi
<@zodbot:fedora.im>
15:00:53
Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
15:01:35
hey everybody
<@thebeanogamer:fedora.im>
15:02:06
1) Can I have a proof read of https://forge.fedoraproject.org/security/docs/pulls/14/files please
<@thebeanogamer:fedora.im>
15:02:06
👋 Only things from me are:
<@thebeanogamer:fedora.im>
15:02:06
2) Do we want to do anything comms-related with the wave of kernel CVEs?
<@jforbes:fedora.im>
15:02:14
So... more kernels are coming. Upstream has found new code paths for fragnesia. I know a couple of people are looking at some still to see if they are exploitable. I am waiting to patch/push until that analysis is done.
<@py0xc3:fedora.im>
15:03:12
...Your work on this is much appreciated...
<@jforbes:fedora.im>
15:03:57
I am guessing this will become common for a bit as people are using AI to analyse
<@q5sys:matrix.org>
15:04:00
jforbes any idea where the LTS topic will end up going (from the AI Dev Desktop discussion)
<@jforbes:fedora.im>
15:04:27
Though I do not understand why responsible disclosure is not a thing
<@jforbes:fedora.im>
15:04:41
q5sys: Fedora has no plans for an LTS kernel
<@jforbes:fedora.im>
15:05:11
Though I sent you a PM on Matrix yesterday with some details on RT
<@q5sys:matrix.org>
15:05:41
you might have and i Just missed it. I'll look for it.
<@py0xc3:fedora.im>
15:05:47
Have as many people working on it as possible, as as little bottlenecks as possible. The more work on it, the more likely it is that they will find the issue before attackers do. Now that the surface as such is generally known.
<@py0xc3:fedora.im>
15:05:54
That's at least my explanation / assumption
<@py0xc3:fedora.im>
15:06:04
about it
<@q5sys:matrix.org>
15:06:23
In the quest for attention and fanfare, I think some sec researches want to rush out findings. Becuase everything is becoming headline news when AI helps find an issue.
<@jforbes:fedora.im>
15:06:25
And for people who do want to build them, the fedora-6.18 branch is kept updated with upstream, so you can do your own LTS
<@thebeanogamer:fedora.im>
15:07:13
The disclosures have all had adverts of the slopcoding firms that found them at the bottom
<@q5sys:matrix.org>
15:07:25
I think some people have taken the "Attention is all you need" paper the wrong way 🤣
<@jforbes:fedora.im>
15:07:26
Well, previous disclosures have rarely been with a working exploit like this.
<@jforbes:fedora.im>
15:08:17
We are just being slowly given a list of companies who clearly only care about recognition and your money, and have no actual interest in public security
<@jforbes:fedora.im>
15:08:40
A list of security firms to avoid as it were
<@q5sys:matrix.org>
15:09:05
I personally dont need an LTS for my Fedora boxes. I do run LTS on my arch boxes becuase I prefer not to get the absolute latest. But I think Fedora has a good pace, so I'm happy with whatever we're shipping.
<@jforbes:fedora.im>
15:09:55
This string of emergencies is exactly one of the reasons we are not doing LTS. We do not need the extra load
<@q5sys:matrix.org>
15:10:18
Yup
<@py0xc3:fedora.im>
15:10:33
The one use case of LTS I know is in ask.fedora, as it occurs that we have users for whom a kernel is broken due to some eccentric hardware or so, and sometimes they get stuck with a kernel for a long time without being able to update. That has an ironic element: the more eccentric their hardware is, the more expressive their testing contribution is, but the more likely it is also that they are left alone when something breaks. Some drivers are badly maintained upstream unfortunantely :(
<@py0xc3:fedora.im>
15:11:21
But getting an official one would be not realistic unless we get much more contributions reliably persistently in this area o.O And not sure if the amount of cases so far would justify that (not that we have kernel devleopers waiting for us to call ...)...
<@jforbes:fedora.im>
15:11:48
The fedora-6.18 branch on kernel-ark is only kept up with upstream BTW. I am not backporting security fixes to it or anything else, so non of fragnesia is covered in the current branch
<@py0xc3:fedora.im>
15:14:50
It might be interesting though to get the project of kwizard a little more organized... officially is not a thing, but for the "lost cases", making this a team effort might be worth to discuss. backporting extreme cases like this for example, and maybe also do some basic testing
<@jforbes:fedora.im>
15:15:43
Upstream will have a fix soon. But I am spending enough time in emergency mode lately. This is exactly why we don't actually build/ship/support LTS
<@py0xc3:fedora.im>
15:15:56
100% understanding from my side.
<@jforbes:fedora.im>
15:16:37
I did 6.19 rebuilds during the dirty frag stuff because pushing out a rebase with no feedback was problematic. But now we have feedback, and I think 7.0.6 fixed the majority of issues
<@py0xc3:fedora.im>
15:17:26
I assume the upstream 7.0.7 is assumed to also contain the fixes of what is already known, without the need to patch it, right?
<@py0xc3:fedora.im>
15:17:45
I assume the upstream 7.0.7 is assumed to also contain the fixes of what is already known (so the vulnerabilities), without the need to patch it, right?
<@py0xc3:fedora.im>
15:20:17
I have to test a few more patches for AMD, and other users too, so create some kernels that I/we can use for several days. On some systems, I would prefer to have the fixes contained, but also avoid to patch more than necessary myself, also to make it more expressive for AMD (the patches are just to get better and more expressive logs as a bug affecting many is not really understand, after about a year...)
<@jforbes:fedora.im>
15:20:33
No, 7.0.7 upstream has no fixes for fragnesia
<@py0xc3:fedora.im>
15:20:36
I have to test a few more patches for AMD, and other users too, so create some kernels that I/we can use for several days. On some systems, I would prefer to have the fixes contained, but also avoid to patch more than necessary myself, also to make it more expressive for AMD (the patches are just to get better and more expressive logs as a bug affecting many is not really understoond, after about a year...)
<@jforbes:fedora.im>
15:21:08
By policy, stable can't pull in a fix until it is in Linus' tree and there is still discussion on the proper fix.
<@py0xc3:fedora.im>
15:21:12
Dammit. But ok. It's just the two `net: skbuff: * shared-frag marker *` patches, right?
<@jforbes:fedora.im>
15:21:14
v3 came out this morning
<@jforbes:fedora.im>
15:21:39
https://lore.kernel.org/netdev/agW4vC0r8QOUKtRT@v4bel/ is the most recent fix
<@py0xc3:fedora.im>
15:22:42
Ok, then I wait for 7.0.7 and patch that one plus the amd patches... Thanks :)
<@thebeanogamer:fedora.im>
15:27:16
So returning to the original question, is there anything we can/should be doing to make users aware of these? Especially whilst they're being applied as patches on our tree
<@py0xc3:fedora.im>
15:28:20
Personally, I think the topic in Discourse suffices.
<@py0xc3:fedora.im>
15:28:40
I updated it today, and pinned it again. Those who search information find it. For the rest, do your daily updates
<@jforbes:fedora.im>
15:28:53
I am not sure the best way to get to user attention. Cross posting to reddit/socials/etc seems somewhat helpful
<@py0xc3:fedora.im>
15:28:54
I would not raise more, as most readers in magazine or other sources might not really be able to process it o.O
<@py0xc3:fedora.im>
15:30:11
You mean to open a channel there from the security sig? Not sure if anyone has the time to maintain that atm. Generally sharing related news is generally a good idea for evryone who has an account etc
<@jforbes:fedora.im>
15:31:04
No, I don't think opening a channel there is going to be beneficial, but posting on the channels that already exist is useful.
<@py0xc3:fedora.im>
15:31:12
Do you have anything specific in mind?
<@py0xc3:fedora.im>
15:31:22
Did you have anything specific in mind?
<@py0xc3:fedora.im>
15:31:38
Ah, ok. Yeah. I share when I am on some channels, though I have not many.
<@py0xc3:fedora.im>
15:31:54
Beyond, I'll keep an eye on the discourse topic
<@thebeanogamer:fedora.im>
15:32:14
I agree with jforbes that whatever we do should be existing channels, I don't know if there's interest in putting something on the blog/magazine, or just social media
<@py0xc3:fedora.im>
15:32:20
That's what we were doing during XZUtils too, though more organized back then. But it was more complex too from a user perspective.
<@thebeanogamer:fedora.im>
15:32:36
Presumably the Bodhi updates are being tagged with the CVEs?
<@jforbes:fedora.im>
15:32:47
Yes, when they exist
<@jforbes:fedora.im>
15:33:06
So copy.fail was not because we had fixes out long before the CVE existed, which was long before the public campaign
<@py0xc3:fedora.im>
15:33:08
7.0.6 is arleady
<@jforbes:fedora.im>
15:33:40
But dirty frag and fragnesia have been. Not sure if there will be another CVE for the extension of fragnesia though
<@py0xc3:fedora.im>
15:33:46
I don't think I can spare the time for that, and my writing is not the best anyway. But if you can spare the time, you might contact @glb
<@py0xc3:fedora.im>
15:34:15
He's in Community Ops (matrix) or in their space in Discourse
<@py0xc3:fedora.im>
15:37:13
Daniel Milnes: it might be worth to mention that FIPS does partially decrease security by enforcing, in short, bad-practice crypto -> it replaces argon2 by the old pbkdf2.
<@py0xc3:fedora.im>
15:37:34
I discussed that already at the bootc docs with Timothee. He changed their Docs to make this a compliance document and no logner hardening.
<@py0xc3:fedora.im>
15:38:36
FIPS in many contexts sounds like it is something that increases security, just by its context of "comply to some security thing". That can be easily misunderstood. Therefore, it might be worth to be mentioned once that from a cryptography PoW, it actually sometimes decreases crypto security.
<@jforbes:fedora.im>
15:38:57
It is also important to mention that, while Fedora should work with FIPS mode, it will never be FIPS certified. The actual certification process takes longer than the lifespan of a Fedora release
<@q5sys:matrix.org>
15:41:13
Compliance and security do not always ride in the same cart. That's one of the reasons I got out of doing security professionally back in the day. I got annoyed with the 'following bad practices so we can be compliant" attitude.
<@q5sys:matrix.org>
15:41:20
I hope that's gotten better in the last decade or so.
<@py0xc3:fedora.im>
15:41:36
No :)
<@q5sys:matrix.org>
15:41:52
and I dont think there's much to be gained by Fedora being FIPS certified anyway.
<@jforbes:fedora.im>
15:42:49
I think a couple of labs are using Fedora, with requirements to run in FIPS mode, but I don't know if certification is supposed to be a requirement
<@py0xc3:fedora.im>
15:44:29
I have to leave a little earlier. See you later in the channel :) I'll skim later today over the rest of the conversation.
<@py0xc3:fedora.im>
15:44:36
👋
<@thebeanogamer:fedora.im>
15:44:56
Yeah the docs page I wrote explicitly says enabling FIPS crypto doesn't make Fedora FIPS certified
<@thebeanogamer:fedora.im>
15:46:24
Anyhow, I can ask CommOps for their thoughts on this and we'll go from there
<@thebeanogamer:fedora.im>
15:56:11
I think let's leave the meeting there then
<@py0xc3:fedora.im>
15:56:25
I'm back... mixed up something in my calendar ...
<@py0xc3:fedora.im>
15:56:33
and 7.0.7 has just been released...
<@py0xc3:fedora.im>
15:57:52
Daniel Milnes: I meant glb as editor of the magazine, not commops in general. It's just a channel in which I know he is active in (in case you interpreted my comment to be commops related)
<@py0xc3:fedora.im>
15:58:11
Daniel Milnes: I meant glb as editor of the magazine, not commops in general. It's just a channel in which I know he is active/available in (in case you interpreted my comment to be commops related)
<@q5sys:matrix.org>
15:59:04
we're approaching the hour, so I'm going to call the meeting here shortly, but as always, continue any conversations in the security channel.
<@py0xc3:fedora.im>
16:00:27
Sure.
<@q5sys:matrix.org>
16:06:01
!endmeeting