Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1
Date: Wed, 27 Nov 2013 19:04:15
Message-Id: 52964261.7020402@opensource.dyc.edu
In Reply to: [gentoo-hardened] New messages in log with hs-3.11.9-r1 by "Tóth Attila"
1 On 11/27/2013 01:49 PM, "Tóth Attila" wrote:
2 > After bumping the kernel and gradm versions, I see these in the log:
3 > grsec: denied exec of usermode helper binary
4 > /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
5 > The file is definitely located outside of /sbin. It belongs to openrc.
6 > What can be the best solution to handle this issue?
7 >
8 > Reloading policy knocks out the machine:
9 > https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
10 >
11
12 I should probably have emailed the list to warn people about 3.0. It is
13 fresh off the assembly line and there are issues. I hit one myself but
14 didn't report it yet because a new release just came out.
15
16 I will not stabilize a 3.0 anytime soon. Please use a 2.9.1 of the time
17 being:
18
19 1) any 2.6.32
20
21 2) <= 3.2.52-r6
22
23 3) <= 3.11.9
24
25 Currently the tree has only 2.9.1. The overlay has 3.0.
26
27 Thank you Toth for pushing that report upstream.
28
29 --
30 Anthony G. Basile, Ph. D.
31 Chair of Information Technology
32 D'Youville College
33 Buffalo, NY 14201
34 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1 "Tóth Attila" <atoth@××××××××××.hu>
Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1 "Tóth Attila" <atoth@××××××××××.hu>