Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2
Date: Fri, 27 Jan 2012 16:03:32
Message-Id: c42667915086fc252e9fab06c5eec029.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2 by "Anthony G. Basile"
1 I've just had this one while booting hardened-3.2.1:
2 Jan 27 16:40:29 atoth kernel: vmalloc: allocation failure: 0 bytes
3 Jan 27 16:40:29 atoth kernel: modprobe: page allocation failure: order:0,
4 mode:0x80d2
5 Jan 27 16:40:29 atoth kernel: Pid: 7460, comm: modprobe Not tainted
6 3.2.1-hardened #1
7 Jan 27 16:40:29 atoth kernel: Call Trace:
8 Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
9 Jan 27 16:40:29 atoth kernel: [<000a0e1f>] ? warn_alloc_failed+0xbf/0x100
10 Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
11 Jan 27 16:40:29 atoth kernel: [<000c3cc3>] ? __vmalloc_node_range+0x1a3/0x240
12 Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
13 Jan 27 16:40:29 atoth kernel: [<00637cb5>] ?
14 __mutex_lock_slowpath+0x1a5/0x240
15 Jan 27 16:40:29 atoth kernel: [<00020b8e>] ? module_alloc+0x7e/0x90
16 Jan 27 16:40:29 atoth kernel: [<000080d2>] ? match_id.clone.1+0x62/0x90
17 Jan 27 16:40:29 atoth kernel: [<000728a3>] ?
18 module_alloc_update_bounds_rw+0x13/0x60
19 Jan 27 16:40:29 atoth kernel: [<000728a3>] ?
20 module_alloc_update_bounds_rw+0x13/0x60
21 Jan 27 16:40:29 atoth kernel: [<00073196>] ? load_module+0x886/0x1b70
22 Jan 27 16:40:29 atoth kernel: [<00002c59>] ? __switch_to+0xb9/0x210
23 Jan 27 16:40:29 atoth kernel: [<000744ca>] ? sys_init_module+0x4a/0x1d0
24 Jan 27 16:40:29 atoth kernel: [<00010246>] ? switch_to_new_gdt+0x26/0x30
25 Jan 27 16:40:29 atoth kernel: [<00638d71>] ? syscall_call+0x7/0xb
26 Jan 27 16:40:29 atoth kernel: [<00002c59>] ? __switch_to+0xb9/0x210
27 Jan 27 16:40:29 atoth kernel: [<00010246>] ? switch_to_new_gdt+0x26/0x30
28
29 It's there for every module loading. Even though modules seems to work.
30 Strange. The kernel also didn't logged the first page of dmesg in
31 kernel.log.
32
33 I don't experience this using hardened-3.1.8.
34 I don't know if it's a known problem. I'll try hardened-3.2.2 later.
35
36 Thanks:
37 Dw.
38 --
39 dr Tóth Attila, Radiológus, 06-20-825-8057
40 Attila Toth MD, Radiologist, +36-20-825-8057
41
42 2012.Január 27.(P) 14:37 időpontban Anthony G. Basile ezt írta:
43 > Hi everyone,
44 >
45 > I just added hardened-sources 2.6.32-r88 and 3.2.2 to the tree. They
46 > address CVE-2012-0056. I've tested and they do indeed resist the
47 > exploit. I will be stabilizing them within 24 hours. However, I feel
48 > very uncomfortable doing so because I don't want to trade one set of
49 > problems with another. If anyone has time to test, let me know if you
50 > encounter any issues.
51 >
52 > --
53 > Anthony G. Basile, Ph. D.
54 > Chair of Information Technology
55 > D'Youville College
56 > Buffalo, NY 14201
57 > (716) 829-8197
58 >

Replies

Subject Author
Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2 "Tóth Attila" <atoth@××××××××××.hu>