1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Hi guys, |
5 |
|
6 |
This is a follow up on the "IA32 Syscall Entry Point Privilege |
7 |
Escalation" and "IA32 Emulation Stack Underflow". |
8 |
|
9 |
hardened-sources 2.6.32-r18 or 2.6.34-r6 have now been fast-track |
10 |
stabilized on amd64 arch only. Users of amd64 are encouraged to switch |
11 |
as soon as possible. |
12 |
|
13 |
Since the exploit affects only amd64, there was no need to stabilize |
14 |
x86, ppc or ppc64 early. These will be stabilized via the usual |
15 |
mechanism of waiting 30 days. |
16 |
|
17 |
There is at least one issue with the fast-track stabilization that may |
18 |
affect users, so a caveat is in order. Because of changes in the grsec |
19 |
patches for kernels > 2.6.32-r9, some packages may break. This is due |
20 |
to stricter requirements on mmap-ed pages. See ref [1]. It affects, |
21 |
among other thing, python's import ctypes. We are working on |
22 |
fast-tracking a fix for that, but in the mean time, amd64 users that |
23 |
wish to continue using hardened-sources-2.6.32-r9 may due so securely |
24 |
provided you follow the workaround discussed in ref [2]. |
25 |
|
26 |
|
27 |
Refs: |
28 |
[1] https://bugs.gentoo.org/329499 |
29 |
[2] http://bugs.gentoo.org/show_bug.cgi?id=326885 |
30 |
|
31 |
- -- |
32 |
Anthony G. Basile, Ph.D. |
33 |
Gentoo Developer |
34 |
-----BEGIN PGP SIGNATURE----- |
35 |
Version: GnuPG v2.0.16 (GNU/Linux) |
36 |
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ |
37 |
|
38 |
iEYEARECAAYFAkyZ2FsACgkQl5yvQNBFVTXouQCfd4DUjyI5PdhmzCJd/nf7zTIN |
39 |
orwAnRpzCENGINzd1JQctkLMYwn+qfEm |
40 |
=+Etu |
41 |
-----END PGP SIGNATURE----- |