Gentoo Archives: gentoo-server

From: Kerin Millar <kerin@×××××××××××××××.net>
To: gentoo-server@g.o
Subject: Re: [gentoo-server] Root exploit in virtually all 2.4 kernels ... fixed
Date: Thu, 04 Dec 2003 16:32:43
Message-Id: 1070577204.3382.8.camel@kerfy.r2r.local
In Reply to: Re: [gentoo-server] Root exploit in virtually all 2.4 kernels ... fixed by Andy Dustman
1 On Thu, 2003-12-04 at 20:40, Andy Dustman wrote:
2 > Not all of the ebuilds have been bumped a revision number, so you won't
3 > get the patch with emerge --update world; you'll need to explicitly
4 > re-emerge.
5
6 Indeed. I can, to an extent, understand the reasoning behind that. After
7 all, if you re-merge the sources you're going to move to the latest
8 unmasked version (which presumably brings other benefits as well as the
9 do_brk patch). Nonetheless, I didn't make that point entirely clear so
10 yes, a veritable heads up.
11
12 > In particular, vanilla-sources were not bumped. wolk-sources
13 > were bumped (to 4.9-r2) within the last day (or moved to stable),
14 > although 4.9-r1 also has the patch. And I may be wrong but it appears
15 > redhat-sources does not have the fix unless it was previously
16 > incorporated by Red Hat. (I don't use that package so I can't say
17 > authoritatively).
18
19 You are absolutely correct, and I am grateful that you pointed this out.
20 I raised the topic with a developer, and with vanilla-sources the logic
21 is apparently much as I stated above. I also raised the matter of
22 redhat-sources, and the reply wasn't entirely to my satisfaction.
23 Basically, it looks as if these sources are unmaintained and they'll be
24 masked shortly. I don't see any reason why that that should prevent the
25 patch from being added ... however, that is the present situation.
26
27 As for WOLK, well as far as 4.10-pre7 was concerned there was an -r2
28 ebuild but the do_brk patch was completely unnecessary in the case of
29 that particular version. So I asked for it to be removed. The fix is
30 applicable to 4.9, so the presence of 4.9-r2 is merited as I understand
31 it.
32
33 --Kerin Francis Millar