Gentoo Archives: gentoo-security

From: Calum <caluml@×××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Kernel Security Update Target Delay?
Date: Sun, 26 Sep 2010 18:03:52
Message-Id: AANLkTin91N0ZJe5o4D9HpDX7J3HF0aXqSRrdV8+mFXCF@mail.gmail.com
In Reply to: [gentoo-security] Kernel Security Update Target Delay? by Richard Freeman
1 On 26 September 2010 11:31, Richard Freeman <rich0@g.o> wrote:
2 > Gentoo has been vulnerable to a highly-publicized (Guardian, Slashdot,
3 > the works) local privilege escalation for almost two weeks now.  (Well,
4 > it has been vulnerable for years, but of course we didn't know about it
5 > until two weeks ago.)
6 >
7 > In the bugzilla thread tracking the problem it has been mentioned a few
8 > times that the kernel does not receive GLSA support:
9 > http://bugs.gentoo.org/show_bug.cgi?id=337645
10
11 Kernels used to be covered in GLSAs.
12 I mourned the loss of kernel GLSAs quite a while back.
13 http://blog.gmane.org/gmane.linux.gentoo.security/month=20070401
14
15 Kernels used to be included, but apparently it was too much work
16 getting all the version kernel versions in sync.
17 I used to have script that emailed me applicable GLSAs, and I never
18 heard that they stopped including the kernel, so I was miffed when I
19 found out.
20
21 I still don't understand why there isn't a single security alert point
22 of reference that covers everything on a Gentoo box though.
23 What would it take to get kernels included again?
24
25 /meh.
26
27 PS. Hardened Gentoo still rocks though.

Replies

Subject Author
Re: [gentoo-security] Kernel Security Update Target Delay? Alex Legler <a3li@g.o>