Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1
Date: Wed, 27 Nov 2013 20:24:08
Message-Id: 8331843a3e619d3a5d7c53b4a616ed83.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1 by "Anthony G. Basile"
1 I will refrain from using this new version of 3.0 grsec+gradm.
2 But will give it a try when a new version comes out, anyways.
3
4 I have to also prepare to invest some energy into connection tracking
5 helper assignments.
6
7 Dw.
8 --
9 dr Tóth Attila, Radiológus, 06-20-825-8057
10 Attila Toth MD, Radiologist, +36-20-825-8057
11
12 2013.November 27.(Sze) 20:05 időpontban Anthony G. Basile ezt írta:
13 > On 11/27/2013 01:49 PM, "Tóth Attila" wrote:
14 >> After bumping the kernel and gradm versions, I see these in the log:
15 >> grsec: denied exec of usermode helper binary
16 >> /lib64/rc/sh/cgroup-release-agent.sh located outside of /sbin
17 >> The file is definitely located outside of /sbin. It belongs to openrc.
18 >> What can be the best solution to handle this issue?
19 >>
20 >> Reloading policy knocks out the machine:
21 >> https://forums.grsecurity.net/viewtopic.php?f=3&t=3881
22 >>
23 >
24 > I should probably have emailed the list to warn people about 3.0. It is
25 > fresh off the assembly line and there are issues. I hit one myself but
26 > didn't report it yet because a new release just came out.
27 >
28 > I will not stabilize a 3.0 anytime soon. Please use a 2.9.1 of the time
29 > being:
30 >
31 > 1) any 2.6.32
32 >
33 > 2) <= 3.2.52-r6
34 >
35 > 3) <= 3.11.9
36 >
37 > Currently the tree has only 2.9.1. The overlay has 3.0.
38 >
39 > Thank you Toth for pushing that report upstream.
40 >
41 > --
42 > Anthony G. Basile, Ph. D.
43 > Chair of Information Technology
44 > D'Youville College
45 > Buffalo, NY 14201
46 > (716) 829-8197
47 >
48 >