Package: release.debian.org
Severity: normal
Tags: bullseye
User: release.debian....@packages.debian.org
Usertags: pu

[ Reason ]
A new upstream release of the nvidia drivers in non-free is needed for
fixing a few new CVEs.
There are some tightened dependencies regarding libnvidia-glvkspirv. The
vulkan bits and corresponding internal (dlopen()ed) library have become
more important at some point in the past already.
There are more changelog updates from changelog unification between all
the driver series we support.

[ Impact ]
A proprietary graphics driver with open CVEs.

[ Tests ]
Only module building can be tested automatically, everything else would
require use of nvidia GPUs and driver.

[ Risks ]
Upgrading to a new upstream release from the same series is an
established practice in both stable and oldstable.

[ Checklist ]
  [*] *all* changes are documented in the d/changelog
  [*] I reviewed all changes and I approve them
  [*] attach debdiff against the package in (old)stable
  [*] the issue is verified as fixed in unstable

[ Changes ]
+  * New upstream LTS and Tesla branch release 470.256.02 (2024-06-04).
+    * Fixed CVE-2024-0090, CVE-2024-0092.  (Closes: #1072798)
+      https://nvidia.custhelp.com/app/answers/detail/a_id/5551
+    - Fixed a bug that could cause the X server to crash when graphics
+      applications requested single-buffered drawables while certain
+      features (such as Vulkan sharpening) are enabled.
+
+  [ Andreas Beckmann ]
+  * Refresh patches.
+  * xserver-xorg-video-nvidia: Recommend nvidia-vulkan-icd.
+  * Move the libnvidia-glvkspirv dependency to libnvidia-(e)glcore.
+    (Cf. #1064194)
+  * Bump Standards-Version to 4.7.0. No changes needed.

[ Other info ]
This is a no-change rebuild of the package from sid (or bookworm-pu).

Andreas

Attachment: ngd-tesla-470-470.256.02-1~deb11u1.diff.xz
Description: application/xz

Reply via email to