Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 338317 - Please mark =sys-kernel/gentoo-sources-2.6.32-r18 and =sys-kernel/vanilla-sources-2.6.32.22 stable
Summary: Please mark =sys-kernel/gentoo-sources-2.6.32-r18 and =sys-kernel/vanilla-sou...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Kernel Bug Wranglers and Kernel Maintainers
URL:
Whiteboard:
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2010-09-21 23:27 UTC by Mike Pagano
Modified: 2010-10-20 00:24 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mike Pagano gentoo-dev 2010-09-21 23:27:10 UTC
Arch teams, please consider marking gentoo-sources-2.6.32-r18 and vanilla-sources-2.6.32.22 stable. These versions contain the fix for the recent root vulnerability described here: 

http://www.theregister.co.uk/2010/09/15/linux_kernel_regression_bug/

No wide affecting bugs exist at this time.
Comment 1 Anthony Basile gentoo-dev 2010-09-22 00:02:50 UTC
(In reply to comment #0)
> Arch teams, please consider marking gentoo-sources-2.6.32-r18 and
> vanilla-sources-2.6.32.22 stable. These versions contain the fix for the recent
> root vulnerability described here: 
> 
> http://www.theregister.co.uk/2010/09/15/linux_kernel_regression_bug/
> 
> No wide affecting bugs exist at this time.
> 

The exploit only affects amd64.  I got permission from that arch team to fast track stabilization of hardened-sources.  See bug #338273.  You may want to do the same Mike.

I'll help by testing them on my systems here are report back.

Comment 2 Anthony Basile gentoo-dev 2010-09-22 09:37:36 UTC
(In reply to comment #1)
> 
> I'll help by testing them on my systems here are report back.
> 

I've tested both gentoo-sources-2.6.32-r18 and vanilla-sources-2.6.32.22, compiling most modules and booting.  Both show no issues.  I also tested the public exploit and neither are vulnerable.
Comment 3 Marko Steinberger 2010-09-22 10:08:07 UTC
Maybe summary should be changed to include current gentoo-sources-2.6.34-r10. 

Tested gentoo-sources-2.6.34-r10 on amd64 desktop production system. Results fine, root exploit not working anymore.

Will provide results for additional test on server system in few hours.
Comment 4 Marko Steinberger 2010-09-22 11:21:51 UTC
gentoo-sources-2.6.34-r10 tested on amd64 production server system. Works fine.

Gentoo devs pls consider stabilization soon!
Comment 5 Raúl Porcel (RETIRED) gentoo-dev 2010-10-03 14:12:31 UTC
alpha/arm/ia64/sh/sparc stable
Comment 6 Markos Chandras (RETIRED) gentoo-dev 2010-10-09 17:02:43 UTC
amd64 done. Thanks Marko
Comment 7 Mike Pagano gentoo-dev 2010-10-20 00:24:06 UTC
Arch Teams who have yet to stabilize, please spend your time instead stabilizing 2.6.32-r20 in bug #341833