Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 26507

Summary: SuSE Kernel security update for networking code
Product: Gentoo Linux Reporter: Gregor Lawatscheck <gpel>
Component: [OLD] Core systemAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: enhancement CC: solar, x86-kernel
Priority: High    
Version: unspecified   
Hardware: x86   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Gregor Lawatscheck 2003-08-12 16:21:32 UTC
The guys over at SuSE have released an updated kernel of theirs today addressing issues in the networking code:

From the suse-security-announce at suse.com list:
------- snip --------
1)  problem description, brief discussion, solution, upgrade information

    During the last weeks a couple of security relevant fixes have been
    accumulated for the kernel. These fix local vulnerabilities and
    remote DoS conditions. The list of the fixed vulnerabilities is
    as follows:

      - fix for a possible denial of service attack (DoS) in the routing code
      - fix for a possible attack of an unpriviledged user via ioport
      - fix for a re-binding problem of UDP port 2049 (NFS) sockets
      - fix for a kernel panic with pptpd when mss > mtu
      - fix for console redirect bug
      - fix for the execve() file read race vulnerability
      - fix for several race conditions in procfs
      - fix for possible DoS in netfilter code
      - fix for possible DoS in NFSv3 code

------- snip --------

Possibly some of these patches could be useful for the gentoo-sources, some of them may have already been included in the gentoo-sources.

What I propose is considering whether these security patches concerning network code from 
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/kernel-source-2.4.20.SuSE-100.i586.patch.rpm (file from 12. August 2003 at time of writing) are worth going into gentoo-sources or not.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Gregor Lawatscheck 2003-08-18 06:21:27 UTC
- fix for possible DoS in netfilter code
has probably been fixed by gentoo-sources 2.4.20-r6, not sure about the other ones
Comment 2 solar (RETIRED) gentoo-dev 2003-09-21 23:45:18 UTC
This bug was fixed and a GLSA went out. http://forums.gentoo.org/viewtopic.php?t=75555