Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Linux kernel on system image 1.2.0 might be almost 4 years old #22

Closed
ajorg opened this issue Aug 27, 2024 · 4 comments
Closed

Linux kernel on system image 1.2.0 might be almost 4 years old #22

ajorg opened this issue Aug 27, 2024 · 4 comments

Comments

@ajorg
Copy link

ajorg commented Aug 27, 2024

The Linux kernel reports version 5.10.4, which was released in December 2020. That means it's missing almost 4 years of critical security fixes. The system firmware needs to be maintained to be more current in order to be safe to use.

@ajorg
Copy link
Author

ajorg commented Aug 27, 2024

I think it's worth challenging, more generally, this notion (from System Overview):

Firmware updates include major system features and hardware adaptations. These need to be downloaded from GitHub and re-flashed onto the SD card, and are pushed less frequently.

Because of the number of components on the system image, and their use in other projects, security issues will be far more frequently found in components on the system image than in the application. Both need to be updated frequently, and given the difficulty of removing the SD card to flash it, and the loss of any configuration in this case, I think it would be good to use something like RAUC or SWUpdate, both of which are supported by Buildroot.

@AkechiShiro
Copy link

AkechiShiro commented Sep 9, 2024

I believe openssh is also vulnerable to an unauthenticated RCE OpenSSH 9.6 even after updating (on the web interface), it is still vulnerable, if glibc is being used then this CVE is impacting the latest nanoKVM release I believe :

Will check if I flash the latest pre release if openSSH has been bumped or not.

@lwbt
Copy link

lwbt commented Oct 25, 2024

See also #115

@wj-xiao
Copy link
Collaborator

wj-xiao commented Nov 8, 2024

I'm sorry I need to close this one. Please see #115 .

@wj-xiao wj-xiao closed this as completed Nov 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants