Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Is this kernel security issue handled by gentoo?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Kernel & Hardware
View previous topic :: View next topic  
Author Message
devsk
Advocate
Advocate


Joined: 24 Oct 2003
Posts: 3003
Location: Bay Area, CA

PostPosted: Sun Sep 19, 2010 6:27 am    Post subject: Is this kernel security issue handled by gentoo? Reply with quote

http://www.h-online.com/security/news/item/Hole-in-Linux-kernel-provides-root-rights-1081317.html

Normal users can get a root shell by using the exploit code, which is really scary.

I don't see the change being made available in vanilla 2.6.35.X. Is gentoo-sources including it?
Back to top
View user's profile Send private message
PaulBredbury
Watchman
Watchman


Joined: 14 Jul 2005
Posts: 7310

PostPosted: Sun Sep 19, 2010 7:23 am    Post subject: Reply with quote

You can take a look.
Back to top
View user's profile Send private message
Yuu
Apprentice
Apprentice


Joined: 23 Dec 2008
Posts: 223
Location: France

PostPosted: Sun Sep 19, 2010 8:30 am    Post subject: Reply with quote

Thank you for the reply, I was worried too.

Maybe a little offtopic : how long did lastest hardened-sources (which include the CVE-2010-3301 fix) will stay on ~unstable, before it will go to +stable ?

Thank you :]
_________________
Main laptop : T8300 cpu | 200 GB hard drive | 2 GB of ram | 8600M GT | Gentoo x86_64
Server : Celeron 220 cpu | 250 GB hard drive | 2 GB of ram | SiS 662 VGA | Gentoo x86_64
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23333

PostPosted: Sun Sep 19, 2010 4:22 pm    Post subject: Reply with quote

It will show up in sys-kernel/vanilla-sources when someone, most likely Greg KH, releases a 2.6.x.y kernel that contains the fix.

See also x86_64 root sploit in Networking & Security.

The fix is relatively small, so concerned users could pull it into a custom kernel derived from their normal kernel sources if they have an urgent need for it before the corresponding maintainer can act. For example, if you cannot or will not upgrade an existing sys-kernel/hardened-sources to a version with the fix (due to concern about other changes made in the bump), the fix can be pulled into an existing version easily.
Back to top
View user's profile Send private message
devsk
Advocate
Advocate


Joined: 24 Oct 2003
Posts: 3003
Location: Bay Area, CA

PostPosted: Sun Sep 19, 2010 4:40 pm    Post subject: Reply with quote

I ended up pulling the fix manually into my /usr/src/linux-2.6.35.4.

I wish we could get rid of this 32-bit emulation business once and for all. But google went ahead and distribute their talk plugin binary in 32-bit. Interestingly, the plugin itself is 64-bit but the supporting binary /opt/google/talkplugin/GoogleTalkPlugin is 32-bit.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Kernel & Hardware All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum