OSMC's November update is here with Kodi 21.3 - OSMC

Is there no support for raspberry 5 yet. I’m still using my Vero V but I want to use a raspberry pi for vacation. But I have just a raspberry pi 5.

I’m looking forward to pi 5 support and I will definitely still use my Vero V. I like that a lot.

Yours sincerely,

Laurens

Not at this time unfortunately

Sam

Thanks, was just curious as the update just popped up.

Not afraid it will die on the update. Just saying when it dies(it’s on 24/7 for years) I will be purchasing the Vero V.

You can install LibreELEC on a Pi 5. It’s almost as good as OSMC :slightly_smiling_face:

Thanks. Can you link to a few “major CVEs” you fixed?

For example, CVE-2022-0492 is a privilege escalation vulnerability from Mar 2022. It’s present in Linux before (<) 4.9.301. OSMC has has Linux 4.9.269. There are public exploits. Is this fixed in OSMC?

I never said I “want latest and greatest”. I said “My ‘specific need’ is to use software that’s supported.”

While I generally share your security concerns, I think in this context you are just totally have not understood that the kernel should be your last concern if you use OSMC in an environment that has high security requirements.

The OSMC user as well as the Media Center (Kodi) has full root access on OSMC. So a “privilege escalation” is kind of meaningless

1 Like

If you want privilege escalation you can just run sudo -s as the OSMC user.

Kodi is running with elevated privileges too..

CVEs are back ported by Android maintainers, SoC vendor and us. Some CVEs are also patched in user space (sysctl tightening for example).

Keep in mind that the kernel we use doesn’t come from kernel.org. It’s a downstream of a downstream (Android base). That’s why LTS and versioning is different. A bit like how Red Hat were maintaining 2.6.x kernels as late as 2020s.

oh my lord if you want to take the risk then take the risk, and if you don’t want to take the risk then either don’t use OSMC, or submit some patches!

3 Likes

To be Honest, @sam_nazarko @ Team are supporting their devices for years.
If compared to all the other devices I have at home, this is the one I care least about.
(Running linux since end 1992, build own distributions and created the C.I.T - Cluster installation tookit → predecessor of the Kickstart installer @ redhat 4 - at that time, not enterprise editions :wink: ).
The reason I never bothered to do anything special with the Vero devices, is that the guys here know what they are doing that will get things fixed IF required - AND - the Vero is a device that is supposed to run in an Enclave network (secured) anyway.

2 Likes