2026-05-14 15:00:01 <@q5sys:matrix.org> !startmeeting 2026-05-14 15:00:05 <@meetbot:fedora.im> Meeting started at 2026-05-14 15:00:01 UTC 2026-05-14 15:00:05 <@meetbot:fedora.im> The Meeting name is 'Fedora Meeting 3' 2026-05-14 15:00:07 <@q5sys:matrix.org> !meetingname security-sig 2026-05-14 15:00:10 <@meetbot:fedora.im> The Meeting Name is now security-sig 2026-05-14 15:00:13 <@q5sys:matrix.org> !link Issue Location : https://forge.fedoraproject.org/security/tickets 2026-05-14 15:00:20 <@q5sys:matrix.org> !link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security 2026-05-14 15:00:25 <@q5sys:matrix.org> !topic Open floor to discuss anything security related. (2026-05-14) 2026-05-14 15:00:27 <@thebeanogamer:fedora.im> !hi 2026-05-14 15:00:28 <@zodbot:fedora.im> Daniel Milnes: Daniel Milnes (thebeanogamer) - he / him / his 2026-05-14 15:00:33 <@q5sys:matrix.org> !topic Open floor to discuss anything security related. (2026-05-14) 2026-05-14 15:00:36 <@jforbes:fedora.im> !hi 2026-05-14 15:00:37 <@zodbot:fedora.im> jforbes: Justin Forbes (jforbes) - he / him / his 2026-05-14 15:00:38 <@q5sys:matrix.org> !info There are 3 open tickets in the main Security Forge: https://forge.fedoraproject.org/security/tickets/issues 2026-05-14 15:00:46 <@q5sys:matrix.org> !info There are 7 open tickets in the Security Docs Forge: https://forge.fedoraproject.org/security/docs/issues 2026-05-14 15:00:52 <@py0xc3:fedora.im> !hi 2026-05-14 15:00:53 <@zodbot:fedora.im> Chris (py0xc3): Christopher Klooz (py0xc3) - he / him / his 2026-05-14 15:01:35 <@q5sys:matrix.org> hey everybody 2026-05-14 15:02:06 <@thebeanogamer:fedora.im> 1) Can I have a proof read of https://forge.fedoraproject.org/security/docs/pulls/14/files please 2026-05-14 15:02:06 <@thebeanogamer:fedora.im> 👋 Only things from me are: 2026-05-14 15:02:06 <@thebeanogamer:fedora.im> 2) Do we want to do anything comms-related with the wave of kernel CVEs? 2026-05-14 15:02:14 <@jforbes:fedora.im> So... more kernels are coming. Upstream has found new code paths for fragnesia. I know a couple of people are looking at some still to see if they are exploitable. I am waiting to patch/push until that analysis is done. 2026-05-14 15:03:12 <@py0xc3:fedora.im> ...Your work on this is much appreciated... 2026-05-14 15:03:57 <@jforbes:fedora.im> I am guessing this will become common for a bit as people are using AI to analyse 2026-05-14 15:04:00 <@q5sys:matrix.org> jforbes any idea where the LTS topic will end up going (from the AI Dev Desktop discussion) 2026-05-14 15:04:27 <@jforbes:fedora.im> Though I do not understand why responsible disclosure is not a thing 2026-05-14 15:04:41 <@jforbes:fedora.im> q5sys: Fedora has no plans for an LTS kernel 2026-05-14 15:05:11 <@jforbes:fedora.im> Though I sent you a PM on Matrix yesterday with some details on RT 2026-05-14 15:05:41 <@q5sys:matrix.org> you might have and i Just missed it. I'll look for it. 2026-05-14 15:05:47 <@py0xc3:fedora.im> Have as many people working on it as possible, as as little bottlenecks as possible. The more work on it, the more likely it is that they will find the issue before attackers do. Now that the surface as such is generally known. 2026-05-14 15:05:54 <@py0xc3:fedora.im> That's at least my explanation / assumption 2026-05-14 15:06:04 <@py0xc3:fedora.im> about it 2026-05-14 15:06:23 <@q5sys:matrix.org> In the quest for attention and fanfare, I think some sec researches want to rush out findings. Becuase everything is becoming headline news when AI helps find an issue. 2026-05-14 15:06:25 <@jforbes:fedora.im> And for people who do want to build them, the fedora-6.18 branch is kept updated with upstream, so you can do your own LTS 2026-05-14 15:07:13 <@thebeanogamer:fedora.im> The disclosures have all had adverts of the slopcoding firms that found them at the bottom 2026-05-14 15:07:25 <@q5sys:matrix.org> I think some people have taken the "Attention is all you need" paper the wrong way 🤣 2026-05-14 15:07:26 <@jforbes:fedora.im> Well, previous disclosures have rarely been with a working exploit like this. 2026-05-14 15:08:17 <@jforbes:fedora.im> We are just being slowly given a list of companies who clearly only care about recognition and your money, and have no actual interest in public security 2026-05-14 15:08:40 <@jforbes:fedora.im> A list of security firms to avoid as it were 2026-05-14 15:09:05 <@q5sys:matrix.org> I personally dont need an LTS for my Fedora boxes. I do run LTS on my arch boxes becuase I prefer not to get the absolute latest. But I think Fedora has a good pace, so I'm happy with whatever we're shipping. 2026-05-14 15:09:55 <@jforbes:fedora.im> This string of emergencies is exactly one of the reasons we are not doing LTS. We do not need the extra load 2026-05-14 15:10:18 <@q5sys:matrix.org> Yup 2026-05-14 15:10:33 <@py0xc3:fedora.im> The one use case of LTS I know is in ask.fedora, as it occurs that we have users for whom a kernel is broken due to some eccentric hardware or so, and sometimes they get stuck with a kernel for a long time without being able to update. That has an ironic element: the more eccentric their hardware is, the more expressive their testing contribution is, but the more likely it is also that they are left alone when something breaks. Some drivers are badly maintained upstream unfortunantely :( 2026-05-14 15:11:21 <@py0xc3:fedora.im> But getting an official one would be not realistic unless we get much more contributions reliably persistently in this area o.O And not sure if the amount of cases so far would justify that (not that we have kernel devleopers waiting for us to call ...)... 2026-05-14 15:11:48 <@jforbes:fedora.im> The fedora-6.18 branch on kernel-ark is only kept up with upstream BTW. I am not backporting security fixes to it or anything else, so non of fragnesia is covered in the current branch 2026-05-14 15:14:50 <@py0xc3:fedora.im> It might be interesting though to get the project of kwizard a little more organized... officially is not a thing, but for the "lost cases", making this a team effort might be worth to discuss. backporting extreme cases like this for example, and maybe also do some basic testing 2026-05-14 15:15:43 <@jforbes:fedora.im> Upstream will have a fix soon. But I am spending enough time in emergency mode lately. This is exactly why we don't actually build/ship/support LTS 2026-05-14 15:15:56 <@py0xc3:fedora.im> 100% understanding from my side. 2026-05-14 15:16:37 <@jforbes:fedora.im> I did 6.19 rebuilds during the dirty frag stuff because pushing out a rebase with no feedback was problematic. But now we have feedback, and I think 7.0.6 fixed the majority of issues 2026-05-14 15:17:26 <@py0xc3:fedora.im> I assume the upstream 7.0.7 is assumed to also contain the fixes of what is already known, without the need to patch it, right? 2026-05-14 15:17:45 <@py0xc3:fedora.im> I assume the upstream 7.0.7 is assumed to also contain the fixes of what is already known (so the vulnerabilities), without the need to patch it, right? 2026-05-14 15:20:17 <@py0xc3:fedora.im> I have to test a few more patches for AMD, and other users too, so create some kernels that I/we can use for several days. On some systems, I would prefer to have the fixes contained, but also avoid to patch more than necessary myself, also to make it more expressive for AMD (the patches are just to get better and more expressive logs as a bug affecting many is not really understand, after about a year...) 2026-05-14 15:20:33 <@jforbes:fedora.im> No, 7.0.7 upstream has no fixes for fragnesia 2026-05-14 15:20:36 <@py0xc3:fedora.im> I have to test a few more patches for AMD, and other users too, so create some kernels that I/we can use for several days. On some systems, I would prefer to have the fixes contained, but also avoid to patch more than necessary myself, also to make it more expressive for AMD (the patches are just to get better and more expressive logs as a bug affecting many is not really understoond, after about a year...) 2026-05-14 15:21:08 <@jforbes:fedora.im> By policy, stable can't pull in a fix until it is in Linus' tree and there is still discussion on the proper fix. 2026-05-14 15:21:12 <@py0xc3:fedora.im> Dammit. But ok. It's just the two `net: skbuff: * shared-frag marker *` patches, right? 2026-05-14 15:21:14 <@jforbes:fedora.im> v3 came out this morning 2026-05-14 15:21:39 <@jforbes:fedora.im> https://lore.kernel.org/netdev/agW4vC0r8QOUKtRT@v4bel/ is the most recent fix 2026-05-14 15:22:42 <@py0xc3:fedora.im> Ok, then I wait for 7.0.7 and patch that one plus the amd patches... Thanks :) 2026-05-14 15:27:16 <@thebeanogamer:fedora.im> So returning to the original question, is there anything we can/should be doing to make users aware of these? Especially whilst they're being applied as patches on our tree 2026-05-14 15:28:20 <@py0xc3:fedora.im> Personally, I think the topic in Discourse suffices. 2026-05-14 15:28:40 <@py0xc3:fedora.im> I updated it today, and pinned it again. Those who search information find it. For the rest, do your daily updates 2026-05-14 15:28:53 <@jforbes:fedora.im> I am not sure the best way to get to user attention. Cross posting to reddit/socials/etc seems somewhat helpful 2026-05-14 15:28:54 <@py0xc3:fedora.im> I would not raise more, as most readers in magazine or other sources might not really be able to process it o.O 2026-05-14 15:30:11 <@py0xc3:fedora.im> You mean to open a channel there from the security sig? Not sure if anyone has the time to maintain that atm. Generally sharing related news is generally a good idea for evryone who has an account etc 2026-05-14 15:31:04 <@jforbes:fedora.im> No, I don't think opening a channel there is going to be beneficial, but posting on the channels that already exist is useful. 2026-05-14 15:31:12 <@py0xc3:fedora.im> Do you have anything specific in mind? 2026-05-14 15:31:22 <@py0xc3:fedora.im> Did you have anything specific in mind? 2026-05-14 15:31:38 <@py0xc3:fedora.im> Ah, ok. Yeah. I share when I am on some channels, though I have not many. 2026-05-14 15:31:54 <@py0xc3:fedora.im> Beyond, I'll keep an eye on the discourse topic 2026-05-14 15:32:14 <@thebeanogamer:fedora.im> I agree with jforbes that whatever we do should be existing channels, I don't know if there's interest in putting something on the blog/magazine, or just social media 2026-05-14 15:32:20 <@py0xc3:fedora.im> That's what we were doing during XZUtils too, though more organized back then. But it was more complex too from a user perspective. 2026-05-14 15:32:36 <@thebeanogamer:fedora.im> Presumably the Bodhi updates are being tagged with the CVEs? 2026-05-14 15:32:47 <@jforbes:fedora.im> Yes, when they exist 2026-05-14 15:33:06 <@jforbes:fedora.im> So copy.fail was not because we had fixes out long before the CVE existed, which was long before the public campaign 2026-05-14 15:33:08 <@py0xc3:fedora.im> 7.0.6 is arleady 2026-05-14 15:33:40 <@jforbes:fedora.im> But dirty frag and fragnesia have been. Not sure if there will be another CVE for the extension of fragnesia though 2026-05-14 15:33:46 <@py0xc3:fedora.im> I don't think I can spare the time for that, and my writing is not the best anyway. But if you can spare the time, you might contact @glb 2026-05-14 15:34:15 <@py0xc3:fedora.im> He's in Community Ops (matrix) or in their space in Discourse 2026-05-14 15:37:13 <@py0xc3:fedora.im> Daniel Milnes: it might be worth to mention that FIPS does partially decrease security by enforcing, in short, bad-practice crypto -> it replaces argon2 by the old pbkdf2. 2026-05-14 15:37:34 <@py0xc3:fedora.im> I discussed that already at the bootc docs with Timothee. He changed their Docs to make this a compliance document and no logner hardening. 2026-05-14 15:38:36 <@py0xc3:fedora.im> FIPS in many contexts sounds like it is something that increases security, just by its context of "comply to some security thing". That can be easily misunderstood. Therefore, it might be worth to be mentioned once that from a cryptography PoW, it actually sometimes decreases crypto security. 2026-05-14 15:38:57 <@jforbes:fedora.im> It is also important to mention that, while Fedora should work with FIPS mode, it will never be FIPS certified. The actual certification process takes longer than the lifespan of a Fedora release 2026-05-14 15:41:13 <@q5sys:matrix.org> Compliance and security do not always ride in the same cart. That's one of the reasons I got out of doing security professionally back in the day. I got annoyed with the 'following bad practices so we can be compliant" attitude. 2026-05-14 15:41:20 <@q5sys:matrix.org> I hope that's gotten better in the last decade or so. 2026-05-14 15:41:36 <@py0xc3:fedora.im> No :) 2026-05-14 15:41:52 <@q5sys:matrix.org> and I dont think there's much to be gained by Fedora being FIPS certified anyway. 2026-05-14 15:42:49 <@jforbes:fedora.im> I think a couple of labs are using Fedora, with requirements to run in FIPS mode, but I don't know if certification is supposed to be a requirement 2026-05-14 15:44:29 <@py0xc3:fedora.im> I have to leave a little earlier. See you later in the channel :) I'll skim later today over the rest of the conversation. 2026-05-14 15:44:36 <@py0xc3:fedora.im> 👋 2026-05-14 15:44:56 <@thebeanogamer:fedora.im> Yeah the docs page I wrote explicitly says enabling FIPS crypto doesn't make Fedora FIPS certified 2026-05-14 15:46:24 <@thebeanogamer:fedora.im> Anyhow, I can ask CommOps for their thoughts on this and we'll go from there 2026-05-14 15:56:11 <@thebeanogamer:fedora.im> I think let's leave the meeting there then 2026-05-14 15:56:25 <@py0xc3:fedora.im> I'm back... mixed up something in my calendar ... 2026-05-14 15:56:33 <@py0xc3:fedora.im> and 7.0.7 has just been released... 2026-05-14 15:57:52 <@py0xc3:fedora.im> Daniel Milnes: I meant glb as editor of the magazine, not commops in general. It's just a channel in which I know he is active in (in case you interpreted my comment to be commops related) 2026-05-14 15:58:11 <@py0xc3:fedora.im> Daniel Milnes: I meant glb as editor of the magazine, not commops in general. It's just a channel in which I know he is active/available in (in case you interpreted my comment to be commops related) 2026-05-14 15:59:04 <@q5sys:matrix.org> we're approaching the hour, so I'm going to call the meeting here shortly, but as always, continue any conversations in the security channel. 2026-05-14 16:00:27 <@py0xc3:fedora.im> Sure. 2026-05-14 16:06:01 <@q5sys:matrix.org> !endmeeting