Consider my position this way. It is true that the kernel team's ability
to maintain this package is limited. I agree that we should flag that to
users in some way. But what I'm saying is that this _is already flagged
as such_ by it being placed in the restricted archive component.

You are still on the hook for maintaining aspects of the package that
you can support, such as packaging, metadata, integration with other
packages and so forth. I resist you "moving" the package to multiverse
because I don't think it's acceptable for you to disclaim those aspects
as well, which is the effect I think it would have.

Setting that aside, there's a fundamental issue with the fact that you'd
only be moving the package to multiverse in the security and updates
pockets. It would remain in the release pocket in restricted anyway, so
users looking at that would still expect support.

On Tue, Jul 14, 2026 at 06:23:44PM -0000, Jose Ogando Justo wrote:
> I'm first focusing on what I believe is the main point of contention:
> the removal of the package and the security implications. (c, on your
> list)
> 
> The entity responsible for monitoring these binaries for vulnerabilities
> is NVIDIA itself.

That's not correct. Canonical is also reponsible for monitoring the
ecosystem for reports of vulnerabilities regardless of what help they
might get from upstream in doing that. This is how distributions have
worked for decades. It is a relatively new phenomenon that a corporate
entity takes responsibility upstream, but: 1) that only applies to
specific upstreams, not all of them; 2) generally only for a specific
length of time; 3) they can improve but otherwise do not impact the
fallback position of distributions managing security updates themselves.

Consider what the first package Ubuntu ever released in the restricted
archive component might have been. If it was a driver grabbed from
somewhere with no upstream commitment for security updates whatsover, I
think we would still have shipped it with the "restricted" warning, and
still taken best-effort responsibility it. The fact that Nvidia provides
some support beyond that baseline is great, but it does not absolve
Canonical from the best-effort promise of support it has always made
even when that extra support from Nvidia goes away.

> Since the 470 series reached end of life, NVIDIA has continued
> publishing Display GPU Driver security advisories that apply to newer
> releases (July 2024, October 2024, January 2025, April 2025, July 2025,
> October 2025, January 2026, and May 2026). These advisories include
> vulnerabilities rated High severity, covering issues such as privilege
> escalation, arbitrary code execution, denial of service, and information
> disclosure.

If there is an advisory that provides specifics of a vulnerability that
exists in the archive with enough detail that it is clear that we must
regress users to keep them safe, then please link to that advisory and
we can decide what to do on a case-by-case basis.

> We cannot determine with certainty which of these vulnerabilities affect
> the 470 branch because NVIDIA no longer analyzes or publishes security
> fixes for it. Equally, we cannot assume that vulnerabilities disclosed
> in supported branches are absent from the 470 branch simply because it
> is no longer evaluated. We are therefore not in a position to provide
> meaningful security support for this package.

If details aren't available or we aren't told if they apply to a
specific version of the package in are archive, then that would not be
actionable, and that's fine. It would be no different to someone saying
"there might be a security vulnerability" which is something we knew at
release time. The "restricted" warning effectively covers it.

> One key question is how Ubuntu policy defines "known severe." The fact
> that NVIDIA no longer evaluates or discloses vulnerabilities for the 470
> branch does not imply that the software is free of severe
> vulnerabilities. Rather, it means there is no longer an active upstream
> process identifying or remediating them. Accepting software unless there
> are known severe vulnerabilities is not covering hazardous scenarios.

It is the ecosystem norm that Free Software distributions ship software
even though there _might_ be security vulnerabilities in them that we do
not know about. This is the risk that everybody takes all the time. The
"restricted" label comes with the additional caveat that being source
unavailable precludes analysis in the way that you describe.

> Therefore, one could argue that there is a meaningful likelihood that
> one or more vulnerabilities already disclosed in supported NVIDIA driver
> branches are also present in the 470 branch, even if that cannot be
> conclusively demonstrated without upstream analysis. This is not
> something we can do on binary only.

This is indeed the downside of non-free software, and part of the risk
that our users choose to take by enabling the "restricted" archive
component.

It's important to remember that I still support you updating users of a
stable release with a newer, supported version from Nvidia via our
hardware enablement pipeline, so it's not like I'm arguing that we must
always force users to remain on an older version. The issue at hand is
whether we knowingly break users by dropping hardware support in an
upgrade. It is only in this case that I'm saying it's fine to leave
users on the same driver version given that there are no known specific
severe security vulnerabilities in that specific version, as regressing
them would be worse.

>  e) I might not understand your question. The package that was
published was a transitional.

We did some investigation and found that linux-modules-
nvidia-470-generic has been deleted, so users relying on that have been
regressed. This needs restoring to track the GA kernel updates.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2155202

Title:
  Latest Update Breaks Systems Using Nvidia 470

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/nvidia-graphics-drivers-470/+bug/2155202/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to