Gentoo Archives: gentoo-hardened

From: Alexander Tsoy <alexander@××××.me>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened-sources wrt CVE-2014-3153 and CVE-2014-0196
Date: Sun, 08 Jun 2014 11:51:55
Message-Id: 20140608155146.17ec4638@home.puleglot
In Reply to: [gentoo-hardened] hardened-sources wrt CVE-2014-3153 and CVE-2014-0196 by "Anthony G. Basile"
1 ÷ Sat, 07 Jun 2014 09:07:23 -0400
2 "Anthony G. Basile" <basile@××××××××××××××.edu> ÐÉÛÅÔ:
3
4 > Hi everyone,
5 >
6 > This is one of those rare situations where there are enough serious
7 > bugs against the kernel that we may have to rapid stabilize
8 > hardened-sources-3.2.59-r5 and 3.14.5-r2. These are currently marked
9 > ~ because I need feedback from users. So please try to upgrade to
10 > either one (3.2 is preferred for mission critical) and give me
11 > feedback. The only caution is do not enable KSTACKOVERFLOW, a new
12 > option which is know to cause panics, eg virtio iface.
13
14 Hello,
15
16 3.14.5-r2 with KSTACKOVERFLOW disabled works fine on several tested
17 systems.
18
19 3.14.5-r2 with KSTACKOVERFLOW enabled:
20 - old Pentium D based system works fine;
21 - KVM VMs with realtek network interface works fine;
22 - on modern Opteron 43xx based system I see many errors in dmesg:
23 "kernel: AMD-Vi: Completion-Wait loop timed out" and experience
24 slowdowns;
25 - KVM VMs with virtio network interface completely crashes without any
26 error messages
27
28 --
29 Alexander Tsoy