Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 472734 - sys-kernel/hardened-sources-3.8.12 - Stable request (wrt the 3.8.6 vuln in bug 470214)
Summary: sys-kernel/hardened-sources-3.8.12 - Stable request (wrt the 3.8.6 vuln in bu...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Keywording and Stabilization (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Anthony Basile
URL:
Whiteboard:
Keywords: SECURITY, STABLEREQ
Depends on:
Blocks:
 
Reported: 2013-06-09 10:44 UTC by Roman Žilka
Modified: 2013-06-14 11:03 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Roman Žilka 2013-06-09 10:44:38 UTC
In bug 470214 we're inspecting an overflow ocucring in the now-stable 3.8.6-hardened. While no definitive answer has been given so far, it seems that the bug is not present in 3.8.12-hardened. Please stabilize 3.8.12. See 470214 for details (still classified).

Reproducible: Always
Comment 1 Roman Žilka 2013-06-09 10:46:12 UTC
Or, perhaps better yet, s/3.8.12/3.8.13/.
Comment 2 Anthony Basile gentoo-dev 2013-06-13 18:41:30 UTC
can you test 3.9.5
Comment 3 Roman Žilka 2013-06-13 20:30:54 UTC
A quick test that is known to have triggered the bug at least once in 3.8.6 doesn't ruffle 3.9.5. I'm switching to 3.9.5 as the main kernel and will report here if I hit something. 3.8.12 is better tested on my part.
Comment 4 Anthony Basile gentoo-dev 2013-06-14 11:03:14 UTC
(In reply to Roman Žilka from comment #3)
> A quick test that is known to have triggered the bug at least once in 3.8.6
> doesn't ruffle 3.9.5. I'm switching to 3.9.5 as the main kernel and will
> report here if I hit something. 3.8.12 is better tested on my part.

Thanks.  I'll target 3.9.5 as the next set to stabilize in 2 weeks.  There have been some small incremental fixes between 3.8.12 and 3.9.5.  The grsec/pax team drop support for their experimental 3.x.y branch as soon as there's a bump to 3.(x+1).z.  They have been long term maintaiing 2.6.32.u and 3.2.v.

Please reopen this bug if you hit this problem again.