1 |
On 26 September 2010 11:31, Richard Freeman <rich0@g.o> wrote: |
2 |
> Gentoo has been vulnerable to a highly-publicized (Guardian, Slashdot, |
3 |
> the works) local privilege escalation for almost two weeks now. (Well, |
4 |
> it has been vulnerable for years, but of course we didn't know about it |
5 |
> until two weeks ago.) |
6 |
> |
7 |
> In the bugzilla thread tracking the problem it has been mentioned a few |
8 |
> times that the kernel does not receive GLSA support: |
9 |
> http://bugs.gentoo.org/show_bug.cgi?id=337645 |
10 |
|
11 |
Kernels used to be covered in GLSAs. |
12 |
I mourned the loss of kernel GLSAs quite a while back. |
13 |
http://blog.gmane.org/gmane.linux.gentoo.security/month=20070401 |
14 |
|
15 |
Kernels used to be included, but apparently it was too much work |
16 |
getting all the version kernel versions in sync. |
17 |
I used to have script that emailed me applicable GLSAs, and I never |
18 |
heard that they stopped including the kernel, so I was miffed when I |
19 |
found out. |
20 |
|
21 |
I still don't understand why there isn't a single security alert point |
22 |
of reference that covers everything on a Gentoo box though. |
23 |
What would it take to get kernels included again? |
24 |
|
25 |
/meh. |
26 |
|
27 |
PS. Hardened Gentoo still rocks though. |