Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] AMD64: use security releases hardened-sources 2.6.32-r18 or 2.6.34-r6
Date: Wed, 22 Sep 2010 11:02:56
Message-Id: 4C99D85B.4020601@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Hi guys,
5
6 This is a follow up on the "IA32 Syscall Entry Point Privilege
7 Escalation" and "IA32 Emulation Stack Underflow".
8
9 hardened-sources 2.6.32-r18 or 2.6.34-r6 have now been fast-track
10 stabilized on amd64 arch only. Users of amd64 are encouraged to switch
11 as soon as possible.
12
13 Since the exploit affects only amd64, there was no need to stabilize
14 x86, ppc or ppc64 early. These will be stabilized via the usual
15 mechanism of waiting 30 days.
16
17 There is at least one issue with the fast-track stabilization that may
18 affect users, so a caveat is in order. Because of changes in the grsec
19 patches for kernels > 2.6.32-r9, some packages may break. This is due
20 to stricter requirements on mmap-ed pages. See ref [1]. It affects,
21 among other thing, python's import ctypes. We are working on
22 fast-tracking a fix for that, but in the mean time, amd64 users that
23 wish to continue using hardened-sources-2.6.32-r9 may due so securely
24 provided you follow the workaround discussed in ref [2].
25
26
27 Refs:
28 [1] https://bugs.gentoo.org/329499
29 [2] http://bugs.gentoo.org/show_bug.cgi?id=326885
30
31 - --
32 Anthony G. Basile, Ph.D.
33 Gentoo Developer
34 -----BEGIN PGP SIGNATURE-----
35 Version: GnuPG v2.0.16 (GNU/Linux)
36 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
37
38 iEYEARECAAYFAkyZ2FsACgkQl5yvQNBFVTXouQCfd4DUjyI5PdhmzCJd/nf7zTIN
39 orwAnRpzCENGINzd1JQctkLMYwn+qfEm
40 =+Etu
41 -----END PGP SIGNATURE-----