Debian Package Tracker
Register | Log in
Subscribe

firmware-nonfree

Choose email to subscribe with

general
  • source: firmware-nonfree (non-free-firmware)
  • version: 20260810-1
  • maintainer: Debian Kernel Team (archive) (DMD)
  • uploaders: Bastian Blank [DMD] – Ben Hutchings [DMD] – Salvatore Bonaccorso [DMD] – maximilian attems [DMD]
  • arch: all
  • std-ver: 4.3.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 20210315-3
  • oldstable: 20230210-5
  • old-bpo: 20250410-2~bpo12+1
  • stable: 20250410-2
  • stable-bpo: 20260410-1~bpo13+1
  • testing: 20260810-1
  • unstable: 20260810-1
versioned links
  • 20210315-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20230210-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20250410-2~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20250410-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20260410-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20260810-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • firmware-amd-graphics (10 bugs: 0, 10, 0, 0)
  • firmware-atheros (3 bugs: 0, 3, 0, 0)
  • firmware-bnx2
  • firmware-bnx2x
  • firmware-brcm80211 (2 bugs: 0, 2, 0, 0)
  • firmware-cavium
  • firmware-cirrus
  • firmware-intel-graphics
  • firmware-intel-misc
  • firmware-intel-sound (1 bugs: 0, 1, 0, 0)
  • firmware-ipw2x00
  • firmware-ivtv
  • firmware-iwlwifi (21 bugs: 0, 20, 1, 0)
  • firmware-libertas
  • firmware-linux
  • firmware-linux-nonfree (2 bugs: 0, 1, 1, 0)
  • firmware-marvell-prestera
  • firmware-mediatek (3 bugs: 0, 3, 0, 0)
  • firmware-misc-nonfree (11 bugs: 0, 8, 3, 0)
  • firmware-myricom
  • firmware-netronome
  • firmware-netxen (1 bugs: 0, 1, 0, 0)
  • firmware-nvidia-graphics (1 bugs: 0, 0, 1, 0)
  • firmware-qcom-soc
  • firmware-qlogic
  • firmware-realtek (7 bugs: 0, 7, 0, 0)
  • firmware-samsung
  • firmware-siano (1 bugs: 0, 1, 0, 0)
  • firmware-ti-connectivity (1 bugs: 0, 1, 0, 0)
action needed
A new upstream version is available: 20260916 high
A new upstream version 20260916 is available, you should consider packaging it.
Created: 2026-09-11 Last update: 2026-09-28 14:31
lintian reports 15 warnings high
Lintian reports 15 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-06-06 Last update: 2026-08-19 00:17
13 security issues in buster high

There are 13 open security issues in buster.

12 important issues:
  • CVE-2023-25951: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.
  • CVE-2023-26586: Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-28374: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-28720: Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..
  • CVE-2023-32642: Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-32644: Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-32651: Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-33875: Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..
  • CVE-2023-34983: Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-35061: Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
  • CVE-2023-38417: Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
  • CVE-2023-47210: Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
1 issue postponed or untriaged:
  • CVE-2023-4969: (postponed; to be fixed through a stable update) A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
Created: 2024-05-02 Last update: 2024-05-22 17:48
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs (3 if counting merged bugs), consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-28 19:30
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 20260916-1, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 6ccb53a9d85320fc3c65b7db3b66321dbda9ee67
Merge: 886edc3 fb02d2d
Author: Ben Hutchings <benh@debian.org>
Date:   Wed Sep 23 21:43:17 2026 +0200

    Merge branch 'update-20260916' into 'debian/latest'
    
    Update to 20260916; fix some license information
    
    See merge request kernel-team/firmware-nonfree!154

commit fb02d2df4e60c39e6083870987762f024addfac4
Author: Ben Hutchings <benh@debian.org>
Date:   Sun Sep 20 01:48:21 2026 +0200

    d/copyright: Change some short names to identify variants of the MIT license
    
    After adding SPDX's canonical MIT license text for the scripts added
    in 20260916, I looked and found 3 more license texts that fit the
    template.  Change their short names to clearly mark them as variants
    of the MIT license.

commit 888f0a2ea9df62184667203039f560250e9e6a81
Author: Ben Hutchings <benh@debian.org>
Date:   Sun Sep 20 01:07:50 2026 +0200

    d/copyright: Correct license text for Dell XPS13 9345 GPU firmware
    
    The Dell XPS13 9345 has a Qualcomm Snapdragon SoC and its GPU firmware
    was added under qcom/ in 20260410.  It is under a Dell license (even
    though no copyright is claimed by Dell!), not the default license for
    qcom/*.  Add yet another concatenation of license/copyright texts for
    it.

commit d3fdee8fe99ff23a2fb2a82576beca11a5c8456b
Author: Ben Hutchings <benh@debian.org>
Date:   Sun Sep 20 01:03:32 2026 +0200

    d/copyright: Update for new upstream version
    
    A few files were added under qcom/ that don't have the default license
    and aren't excluded, so add them to the appropriate file lists.
    
    Two new scripts were added under contrib/ with SPDX tags!  Add a new
    stanza and license text for them.

commit 7b015ebbaa1907832fc0dd944b4ec5b265b67342
Author: Ben Hutchings <benh@debian.org>
Date:   Sat Sep 19 22:51:16 2026 +0200

    Update to 20260916


https://salsa.debian.org/api/v4/projects/kernel-team%2Ffirmware-nonfree API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-23 Last update: 2026-09-23 20:30
AppStream hints: 1 warning for firmware-bnx2,firmware-intel-graphics,firmware-qlogic,firmware-nvidia-graphics,firmware-intel-sound,firmware-ipw2x00,firmware-amd-graphics,firmware-intel-misc,firmware-iwlwifi,firmware-samsung,firmware-realtek,firmware-libertas,firmware-ti-connectivity,firmware-mediatek,firmware-cavium,firmware-atheros,firmware-marvell-prestera,firmware-bnx2x,firmware-brcm80211,firmware-misc-nonfree,firmware-siano,firmware-myricom,firmware-qcom-soc,firmware-ivtv,firmware-cirrus,firmware-netronome,firmware-netxen normal
AppStream found metadata issues for packages:
  • firmware-ipw2x00: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2024-01-27 Last update: 2025-04-21 17:20
5 low-priority security issues in trixie low

There are 5 open security issues in trixie.

5 issues left for the package maintainer to handle:
  • CVE-2025-32735: (needs triaging) Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
  • CVE-2026-20731: (needs triaging) Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
  • CVE-2026-20769: (needs triaging) Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
  • CVE-2026-20783: (needs triaging) Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
  • CVE-2026-20786: (needs triaging) Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-02-11 Last update: 2026-09-01 22:00
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 20260810-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-06-06 Last update: 2026-08-18 19:33
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.3.0).
Created: 2023-05-16 Last update: 2026-08-18 15:20
news
[rss feed]
  • [2026-09-10] Accepted firmware-nonfree 20260810-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-08-31] firmware-nonfree 20260810-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-18] Accepted firmware-nonfree 20260810-1 (source) into unstable (Ben Hutchings)
  • [2026-07-25] Accepted firmware-nonfree 20260622-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-07-20] firmware-nonfree 20260622-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-14] Accepted firmware-nonfree 20260622-1 (source) into unstable (Ben Hutchings)
  • [2026-06-12] Accepted firmware-nonfree 20260519-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-06-12] firmware-nonfree 20260519-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-05] Accepted firmware-nonfree 20260519-1 (source) into unstable (Ben Hutchings)
  • [2026-04-28] Accepted firmware-nonfree 20260410-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-04-25] firmware-nonfree 20260410-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-20] Accepted firmware-nonfree 20260410-1 (source) into unstable (Ben Hutchings)
  • [2026-04-02] Accepted firmware-nonfree 20260309-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-03-31] firmware-nonfree 20260309-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-26] Accepted firmware-nonfree 20260221-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-03-26] Accepted firmware-nonfree 20260309-1 (source) into unstable (Ben Hutchings)
  • [2026-03-17] firmware-nonfree 20260221-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-14] Accepted firmware-nonfree 20260110-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-03-11] Accepted firmware-nonfree 20260221-1 (source) into unstable (Ben Hutchings)
  • [2026-02-28] firmware-nonfree 20260110-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-26] Accepted firmware-nonfree 20251111-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2026-02-04] Accepted firmware-nonfree 20260110-1 (source) into unstable (Ben Hutchings)
  • [2026-02-03] Accepted firmware-nonfree 20251125-1 (source) into unstable (Ben Hutchings)
  • [2025-11-30] firmware-nonfree 20251111-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-25] Accepted firmware-nonfree 20251021-1~bpo13+1 (source) into stable-backports (Ben Hutchings)
  • [2025-11-24] Accepted firmware-nonfree 20251111-1 (source) into unstable (Ben Hutchings)
  • [2025-11-08] firmware-nonfree 20251021-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-02] Accepted firmware-nonfree 20251021-1 (source) into unstable (Ben Hutchings)
  • [2025-11-02] Accepted firmware-nonfree 20251011-1 (source) into unstable (Ben Hutchings)
  • [2025-10-15] Accepted firmware-nonfree 20250917-1 (source) into unstable (Ben Hutchings)
  • 1
  • 2
bugs [bug history graph]
  • all: 71 74
  • RC: 0
  • I&N: 60 62
  • M&W: 11 12
  • F&P: 0
  • patch: 2 3
links
  • lintian (0, 15)
  • buildd: logs
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing