Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-dev@g.o
From: Robert Buchholz <rbu@g.o>
Subject: Re: 2.6.31 stable plans
Date: Thu, 5 Nov 2009 05:22:58 +0100
On Thursday 05 November 2009, Robert Bradbury wrote:
> There was discussion on /. today about there being a potential bug
> which allows users to obtain root privileges.  Apparently its been
> fixed in BSD but may still be a problem in RedHat distributions.  It
> is supposed to be fixed in the kernel but only as of 2.6.32.
>
> Is the fix being back-ported to 2.6.31 or should people plan/attempt
> to run the kernel directly from kernel.org sources before they make
> it into the Gentoo releases?

I am not part of the kernel maintainers, but from what I see stabling a 
2.6.31 release usually means stabling the latest released patch. I 
assume Linux stable maintainers (upstream) will incorporate the NULL 
dereference patch into an upcoming release (2.6.31.6?).

As far as exploitability is concerned, in default configurations of 
gentoo-, vanilla- and hardened-sources this bug cannot be exploited to 
escalate privileges beyond a kernel panic.

The security team is tracking the vulnerability in this bug:
https://bugs.gentoo.org/show_bug.cgi?id=291904

We have recently extended our team with Björn (asym) who will be working 
closer with our kernel maintainers and improve developer (and user!) 
tools to keep systems secure. But I won't spoil the fun of explaining 
that in detail and leave it to him.


Robert
Attachment:
signature.asc (This is a digitally signed message part.)
References:
2.6.31 stable plans
-- Mike Pagano
Re: 2.6.31 stable plans
-- Nirbheek Chauhan
Re: 2.6.31 stable plans
-- Robert Bradbury
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: 2.6.31 stable plans
Next by thread:
Re: 2.6.31 stable plans
Previous by date:
Re: [RFC] Improve policy of stabilizations
Next by date:
Re: Re: Lastrite (part 1): KDE3-only applications that won't build when KDE4 is installed


Updated Nov 21, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.