=== arraybolt3_ is now known as arraybolt3 === chris15 is now known as chris14 [02:10] Hi, I have a question about Kernel Packages in Ubuntu Security Tracker and OVAL. [02:10] In the Web and in the Git Repository of Ubuntu Security Tracker, there is no information about `linux-signed-*` or `linux-meta-*`, but in the OVAL criterion. [02:10] How should I manage Kernel Packages such as `linux-signed-*` and `linux-meta-*` when I use the Ubuntu Security Tracker data? === chris15 is now known as chris14 [02:29] mainek00n: I don't think any of the binary packages created by linux-meta-* is worth worrying about, a very quick check of my local archive mirror shows that the largest one of those is 3568 bytes (linux-meta-azure-fde/linux-azure-fde_5.4.0.1100.106+cvm1.35_amd64.deb) === chris14- is now known as chris14 [02:30] mainek00n: the signed vs unsigned source packages and "" vs "unsigned" binary packages are pretty obnoxious to untangle, but I thought the usual oval tool had all the right pieces to be aware of which packages are which [02:49] For example, Ubuntu CVE Tracker - CVE-2022-2964(https://git.launchpad.net/ubuntu-cve-tracker/tree/active/CVE-2022-2964) mentions only linux-aws Package, but OVAL (https://security-metadata.canonical.com/oval/oci.com.ubuntu.focal.cve.oval.xml.bz2) mentions linux-aws, linux-signed-aws, and linux-meta-aws individually. [02:49] [02:49] [02:49] -ubottu:#ubuntu-security- A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. [02:49] [02:49] So, how should I manage `linux-meta-aws` and `linux-signed-aws` if I use only Ubuntu CVE Tracker data? [02:51] the ubuntu-cve-tracker doesn't track the -signed- or the -meta- packages because the one is generated from the -unsigned- versions and the other has no code at all [03:25] If OVAL is generated based on information from the Ubuntu CVE Tracker, how are the `linux-meta-aws` and `linux-signed-aws` criteria mentioned in OVAL determined? [03:36] the generator has some rules around that https://git.launchpad.net/ubuntu-cve-tracker/tree/scripts/generate-oval#n362 === chris15 is now known as chris14