Gentoo Archives: gentoo-dev

From: Mike Pagano <mpagano@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] qa last rites multiple packages
Date: Wed, 07 Jan 2015 18:29:21
Message-Id: 20150107182914.GC29563@woodpecker.gentoo.org
In Reply to: Re: [gentoo-dev] qa last rites multiple packages by William Hubbs
1 On Wed, Jan 07, 2015 at 11:11:32AM -0600, William Hubbs wrote:
2 > On Wed, Jan 07, 2015 at 11:21:56AM -0500, Mike Pagano wrote:
3 > > On Tue, Jan 06, 2015 at 05:47:10PM -0600, William Hubbs wrote:
4 > > > All,
5 > > > #
6 > > > # Pinkie Pie discovered an issue in the futex subsystem that allows a
7 > > > # local user to gain ring 0 control via the futex syscall. An
8 > > > # unprivileged user could use this flaw to crash the kernel (resulting
9 > > > # in denial of service) or for privilege escalation.
10 > > > #
11 > > > # https://bugs.gentoo.org/show_bug.cgi?id=CVE-2014-3153
12 > > > =sys-kernel/gentoo-sources-3.2.58-r2
13 > > > ~sys-kernel/gentoo-sources-3.4.90
14 > > > =sys-kernel/gentoo-sources-3.4.91
15 > > > ~sys-kernel/gentoo-sources-3.10.40
16 > > > =sys-kernel/gentoo-sources-3.10.41
17 > > > ~sys-kernel/gentoo-sources-3.12.20
18 > > > =sys-kernel/gentoo-sources-3.12.21
19 > > > ~sys-kernel/gentoo-sources-3.14.4
20 > > > =sys-kernel/gentoo-sources-3.14.5
21 >
22 > Mike,
23 >
24 > since you responded here, what do you think about this p.mask entry?
25 > Should we keep these in the tree?
26
27 William,
28
29 At what point do we not care about users who have not upgraded and will
30 miss this security message?
31
32 Mike
33
34
35 --
36 Mike Pagano
37 Gentoo Developer - Kernel Project
38 Gentoo Sources - Lead
39 E-Mail : mpagano@g.o
40 GnuPG FP : EEE2 601D 0763 B60F 848C 9E14 3C33 C650 B576 E4E3
41 Public Key : http://pgp.mit.edu:11371/pks/lookup?search=0xB576E4E3&op=index

Replies

Subject Author
Re: [gentoo-dev] qa last rites multiple packages William Hubbs <williamh@g.o>