Gentoo Archives: gentoo-dev

From: William Hubbs <williamh@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] qa last rites multiple packages
Date: Wed, 07 Jan 2015 19:08:30
Message-Id: 20150107190821.GA7867@linux1
In Reply to: Re: [gentoo-dev] qa last rites multiple packages by Mike Pagano
1 On Wed, Jan 07, 2015 at 01:29:15PM -0500, Mike Pagano wrote:
2 > On Wed, Jan 07, 2015 at 11:11:32AM -0600, William Hubbs wrote:
3 > > On Wed, Jan 07, 2015 at 11:21:56AM -0500, Mike Pagano wrote:
4 > > > On Tue, Jan 06, 2015 at 05:47:10PM -0600, William Hubbs wrote:
5 > > > > All,
6 > > > > #
7 > > > > # Pinkie Pie discovered an issue in the futex subsystem that allows a
8 > > > > # local user to gain ring 0 control via the futex syscall. An
9 > > > > # unprivileged user could use this flaw to crash the kernel (resulting
10 > > > > # in denial of service) or for privilege escalation.
11 > > > > #
12 > > > > # https://bugs.gentoo.org/show_bug.cgi?id=CVE-2014-3153
13 > > > > =sys-kernel/gentoo-sources-3.2.58-r2
14 > > > > ~sys-kernel/gentoo-sources-3.4.90
15 > > > > =sys-kernel/gentoo-sources-3.4.91
16 > > > > ~sys-kernel/gentoo-sources-3.10.40
17 > > > > =sys-kernel/gentoo-sources-3.10.41
18 > > > > ~sys-kernel/gentoo-sources-3.12.20
19 > > > > =sys-kernel/gentoo-sources-3.12.21
20 > > > > ~sys-kernel/gentoo-sources-3.14.4
21 > > > > =sys-kernel/gentoo-sources-3.14.5
22 > >
23 > > Mike,
24 > >
25 > > since you responded here, what do you think about this p.mask entry?
26 > > Should we keep these in the tree?
27 >
28 > William,
29 >
30 > At what point do we not care about users who have not upgraded and will
31 > miss this security message?
32
33 I would say that's more up to you as the maintainer, but put something
34 to the affect in the mask comment.
35
36 # This mask will be removed <whenever>
37
38 William

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] qa last rites multiple packages Mike Pagano <mpagano@g.o>